A financial services organization is deploying AWS Directory Service for Microsoft Active Directory (AWS Managed Microsoft AD) to enable single sign-on (SSO) for its cloud-based workloads. According to the AWS Shared Responsibility Model, which of the following tasks are the responsibility of the customer? (Select TWO.)
- Configuring trust relationships between the AWS Managed Microsoft AD domain and the organization's on-premises Active Directory domains.Answer
- Creating and managing Active Directory users, groups, and Group Policy Objects (GPOs) within the directory.Answer
- CApplying monthly security patches and operating system updates to the domain controller instances.
- DConfiguring stateless Network Access Control Lists (NACLs) to manage traffic at the instance level for individual domain controllers.
- EGenerating physical security compliance documentation for the AWS data centers where the directory servers reside.
Answer
The customer is responsible for configuring trust relationships between the AWS Managed AD domain and on-premises domains, and creating and managing Active Directory users, groups, and Group Policy Objects (GPOs) within the directory.
For AWS Managed Microsoft AD, the customer is responsible for defining directory configurations, which includes establishing trust relationships with on-premises directories and managing organizational units, users, groups, and Group Policy Objects (GPOs) inside the directory.
Step-by-Step Solution
Key Concept
Shared Responsibility Model for Managed Services
Estimated Time:2m 0s