A company wants to set up a multi-account environment on AWS. They need to automate the provisioning of new accounts with pre-configured security baselines. Additionally, they must manage user access by federating their existing external directory. Which combination of actions should a solutions architect recommend? (Select TWO.)
- Deploy a landing zone using AWS Control Tower and use Account Factory to provision new accounts.Cevap
- Configure AWS IAM Identity Center to federate user authentication from the external directory.Cevap
- CCreate individual IAM users in each member account with long-term credentials for the external directory users.
- DUse the AWS Organizations management account root user credentials to perform daily administrative tasks in member accounts.
- EApply restrictive SCPs directly to the management account root user to limit its administrative capabilities.
Cevap
Deploy a landing zone using AWS Control Tower to automate account provisioning, and configure AWS IAM Identity Center to federate user authentication from the external directory.
AWS Control Tower is designed to establish a landing zone and automate the creation of member accounts using Account Factory with pre-defined governance. AWS IAM Identity Center provides centralized federation to external directories, allowing users to authenticate once and access authorized member accounts.
Adım Adım Çözüm
Anahtar Kavram
Multi-account management and centralized federation in AWS Organizations.
Tahmini Süre:1m 0s