AWS Certified Security – Specialty — Question 313

A company needs a cloud-based, managed desktop solution for its workforce of remote employees. The company wants to ensure that the employees can access the desktops only by using company-provided devices. A security engineer must design a solution that will minimize cost and management overhead.

Which solution will meet these requirements?

Answer options

Correct answer: D

Explanation

Amazon WorkSpaces is a managed desktop service that minimizes overhead compared to custom VDI solutions or managing individual Amazon EC2 instances. To restrict access to trusted devices, WorkSpaces natively supports importing client certificates and enforcing restricted access at the directory level. Other options either introduce high management overhead or use incorrect authentication mechanisms that do not natively validate trusted devices.