SCS-C03 · Question #25
A company needs a cloud-based, managed desktop solution for its workforce of remote employees. The company wants to ensure that the employees can access the desktops only by using company- provided…
The correct answer is D. Deploy Amazon WorkSpaces. Create client certificates, and deploy them to trusted devices. Amazon WorkSpaces is a fully managed desktop-as-a-service solution designed to minimize infrastructure and operational overhead. According to AWS Certified Security - Specialty documentation, WorkSpaces supports device trust by using client certificates to restrict access to…
Question
A company needs a cloud-based, managed desktop solution for its workforce of remote employees. The company wants to ensure that the employees can access the desktops only by using company- provided devices. A security engineer must design a solution that will minimize cost and management overhead. Which solution will meet these requirements?
Options
- ADeploy a custom virtual desktop infrastructure (VDI) solution with a restriction policy to allow
- BDeploy a fleet of Amazon EC2 instances. Assign an instance to each employee with certificate-
- CDeploy Amazon WorkSpaces. Set up a trusted device policy with IP blocking on the
- DDeploy Amazon WorkSpaces. Create client certificates, and deploy them to trusted devices.
How the community answered
(29 responses)- A3% (1)
- B10% (3)
- C3% (1)
- D83% (24)
Explanation
Amazon WorkSpaces is a fully managed desktop-as-a-service solution designed to minimize infrastructure and operational overhead. According to AWS Certified Security - Specialty documentation, WorkSpaces supports device trust by using client certificates to restrict access to approved devices. By deploying client certificates only to company-managed devices and enforcing restricted access at the directory level, the organization ensures that only trusted endpoints can authenticate. This approach avoids the cost and complexity of building and maintaining a custom VDI or managing individual EC2 instances. Option A and B significantly increase management overhead. Option C is incorrect because IAM does not manage WorkSpaces authentication gateway policies or device trust. AWS best practices highlight Amazon WorkSpaces with certificate-based device trust as the most efficient solution for secure, managed desktops.
Topics
Community Discussion
No community discussion yet for this question.