nerdexam
Amazon

SOA-C02 · Question #79

A company uses AWS Organizations to host several applications across multiple AWS accounts. Several teams are responsible for building and maintaining the infrastructure of the applications across the

The correct answer is D. Use the built-in SSO directory as the identity source for IAM Identity Center. Copy the users and. https://docs.aws.amazon.com/singlesignon/latest/userguide/quick-start-default-idc.html

Submitted by deeparc· Mar 30, 2026Security and Compliance

Question

A company uses AWS Organizations to host several applications across multiple AWS accounts. Several teams are responsible for building and maintaining the infrastructure of the applications across the AWS accounts. A SysOps administrator must implement a solution to ensure that user accounts and permissions are centrally managed. The solution must be integrated with the company's existing on-premises Active Directory environment. The SysOps administrator already has enabled AWS IAM Identity Center (AWS Single Sign-On) and has set up an AWS Direct Connect connection. What is the MOST operationally efficient solution that meets these requirements?

Options

  • ACreate a Simple AD domain, and establish a forest trust relationship with the on-premises Active
  • BCreate an Active Directory domain controller on an Amazon EC2 instance that is joined to the on-
  • CCreate an AD Connector that is associated with the on-premises Active Directory domain. Set the
  • DUse the built-in SSO directory as the identity source for IAM Identity Center. Copy the users and

How the community answered

(32 responses)
  • A
    6% (2)
  • B
    13% (4)
  • C
    3% (1)
  • D
    78% (25)

Explanation

https://docs.aws.amazon.com/singlesignon/latest/userguide/quick-start-default-idc.html

Topics

#IAM Identity Center#AD Connector#Active Directory#SSO federation

Community Discussion

No community discussion yet for this question.

Full SOA-C02 Practice