nerdexam
Amazon

SCS-C03 · Question #25

A company needs a cloud-based, managed desktop solution for its workforce of remote employees. The company wants to ensure that the employees can access the desktops only by using company- provided…

The correct answer is D. Deploy Amazon WorkSpaces. Create client certificates, and deploy them to trusted devices. Amazon WorkSpaces is a fully managed desktop-as-a-service solution designed to minimize infrastructure and operational overhead. According to AWS Certified Security - Specialty documentation, WorkSpaces supports device trust by using client certificates to restrict access to…

Submitted by andres_qro· Mar 6, 2026Infrastructure Security

Question

A company needs a cloud-based, managed desktop solution for its workforce of remote employees. The company wants to ensure that the employees can access the desktops only by using company- provided devices. A security engineer must design a solution that will minimize cost and management overhead. Which solution will meet these requirements?

Options

  • ADeploy a custom virtual desktop infrastructure (VDI) solution with a restriction policy to allow
  • BDeploy a fleet of Amazon EC2 instances. Assign an instance to each employee with certificate-
  • CDeploy Amazon WorkSpaces. Set up a trusted device policy with IP blocking on the
  • DDeploy Amazon WorkSpaces. Create client certificates, and deploy them to trusted devices.

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    10% (3)
  • C
    3% (1)
  • D
    83% (24)

Explanation

Amazon WorkSpaces is a fully managed desktop-as-a-service solution designed to minimize infrastructure and operational overhead. According to AWS Certified Security - Specialty documentation, WorkSpaces supports device trust by using client certificates to restrict access to approved devices. By deploying client certificates only to company-managed devices and enforcing restricted access at the directory level, the organization ensures that only trusted endpoints can authenticate. This approach avoids the cost and complexity of building and maintaining a custom VDI or managing individual EC2 instances. Option A and B significantly increase management overhead. Option C is incorrect because IAM does not manage WorkSpaces authentication gateway policies or device trust. AWS best practices highlight Amazon WorkSpaces with certificate-based device trust as the most efficient solution for secure, managed desktops.

Topics

#Amazon WorkSpaces#client certificates#trusted devices#remote access

Community Discussion

No community discussion yet for this question.

Full SCS-C03 Practice