PrepAway - Latest Free Exam Questions & Answers

Which technique can be used to integrate AWS IAM (Ident…

Which technique can be used to integrate AWS IAM (Identity and Access Management) with an on-premise
LDAP (Lightweight Directory Access Protocol) directory service?

PrepAway - Latest Free Exam Questions & Answers

A.
Use an IAM policy that references the LDAP account identifiers and the AWS credentials.

B.
Use SAML (Security Assertion Markup Language) to enable single sign-on between AWS and LDAP.

C.
Use AWS Security Token Service from an identity broker to issue short-lived AWS credentials.

D.
Use IAM roles to automatically rotate the IAM credentials when LDAP credentials are updated.

E.
Use the LDAP credentials to restrict a group of users from launching specific EC2 instance types.

Explanation:
https://d0.awsstatic.com/whitepapers/aws-whitepaper-single-sign-on-integrating-aws-open-ldap-andshibboleth.pdf

11 Comments on “Which technique can be used to integrate AWS IAM (Ident…

  1. Don says:

    Looking at the documentation, SAML is definitely the answer because STS is at the root. VMWare also uses SAML and STS is just the service that allow SAML integration.

    AWS Documentation » AWS Security Token Service » API Reference » Actions » AssumeRoleWithSAML




    0



    0

Leave a Reply

Your email address will not be published. Required fields are marked *