Soru

Zorluk: KolayMulti-Account Management and Governance

A company wants to set up a multi-account environment on AWS. They need to automate the provisioning of new accounts with pre-configured security baselines. Additionally, they must manage user access by federating their existing external directory. Which combination of actions should a solutions architect recommend? (Select TWO.)

  1. Deploy a landing zone using AWS Control Tower and use Account Factory to provision new accounts.Cevap
  2. Configure AWS IAM Identity Center to federate user authentication from the external directory.Cevap
  3. C
    Create individual IAM users in each member account with long-term credentials for the external directory users.
  4. D
    Use the AWS Organizations management account root user credentials to perform daily administrative tasks in member accounts.
  5. E
    Apply restrictive SCPs directly to the management account root user to limit its administrative capabilities.

Cevap

Deploy a landing zone using AWS Control Tower to automate account provisioning, and configure AWS IAM Identity Center to federate user authentication from the external directory.
AWS Control Tower is designed to establish a landing zone and automate the creation of member accounts using Account Factory with pre-defined governance. AWS IAM Identity Center provides centralized federation to external directories, allowing users to authenticate once and access authorized member accounts.

Adım Adım Çözüm

1
Evaluate the requirement for automating multi-account provisioning with security guardrails.
Identify AWS Control Tower as the primary service for creating a landing zone and provisioning accounts via Account Factory.
AWS Control Tower automates the setup of a secure, multi-account AWS environment using best practices.
2
Evaluate the requirement for central identity federation using an external corporate directory.
Identify AWS IAM Identity Center as the service to connect the external directory and manage centralized single sign-on access.
AWS IAM Identity Center allows federated users to access multiple AWS accounts without managing credentials locally in IAM.

Anahtar Kavram

Multi-account management and centralized federation in AWS Organizations.
Tahmini Süre:1m 0s
Bu soruyu puanla