DAS-C01 · Question #31
A financial company hosts a data lake in Amazon S3 and a data warehouse on an Amazon Redshift cluster. The company uses Amazon QuickSight to build dashboards and wants to secure access from its…
The correct answer is A. Use an Active Directory connector and single sign-on (SSO) in a corporate network environment. Amazon QuickSight Enterprise Edition supports direct integration with Microsoft Active Directory (AD) via an AD Connector in AWS Directory Service. This allows users to authenticate with their existing on-premises AD credentials using Single Sign-On (SSO), meaning no separate…
Question
A financial company hosts a data lake in Amazon S3 and a data warehouse on an Amazon Redshift cluster. The company uses Amazon QuickSight to build dashboards and wants to secure access from its on-premises Active Directory to Amazon QuickSight. How should the data be secured?
Options
- AUse an Active Directory connector and single sign-on (SSO) in a corporate network environment.
- BUse a VPC endpoint to connect to Amazon S3 from Amazon QuickSight and an IAM role to
- CEstablish a secure connection by creating an S3 endpoint to connect Amazon QuickSight and a
- DPlace Amazon QuickSight and Amazon Redshift in the security group and use an Amazon S3
How the community answered
(32 responses)- A72% (23)
- B3% (1)
- C16% (5)
- D9% (3)
Explanation
Amazon QuickSight Enterprise Edition supports direct integration with Microsoft Active Directory (AD) via an AD Connector in AWS Directory Service. This allows users to authenticate with their existing on-premises AD credentials using Single Sign-On (SSO), meaning no separate QuickSight credentials are needed. This is the canonical and recommended approach for enterprise customers to federate identity from on-premises AD into QuickSight. Options B, C, and D describe network-level or IAM-based controls for S3 and Redshift access, which address data-layer security rather than the identity/authentication requirement stated in the question.
Topics
Community Discussion
No community discussion yet for this question.