AWS Certified Solutions Architect – Professional (SAP-C02) — Question 25

A company is using an on-premises Active Directory service for user authentication. The company wants to use the same authentication service to sign in to the company’s AWS accounts, which are using AWS Organizations. AWS Site-to-Site VPN connectivity already exists between the on-premises environment and all the company’s AWS accounts.
The company’s security policy requires conditional access to the accounts based on user groups and roles. User identities must be managed in a single location.
Which solution will meet these requirements?

Answer options

Correct answer: A

Explanation

The correct answer, A, effectively utilizes AWS IAM Identity Center with SAML 2.0 for integration with Active Directory, allowing for centralized user management and conditional access through ABACs. Option B lacks the SAML integration, which is essential for the existing Active Directory setup. Options C and D are not suitable as they involve IAM users and roles that do not meet the requirement for centralized identity management and conditional access based on user groups and roles.