Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon SCS-C03 Exam - Topic 5 Question 6 Discussion

A company uses an organization in AWS Organizations to manage multiple AWS accounts. The company wants to centrally give users the ability to access Amazon Q Developer.Which solution will meet this requirement?
A) Enable AWS IAM Identity Center and set up Amazon Q Developer as an AWS managed application.
B) Enable Amazon Cognito and create a new identity pool for Amazon Q Developer.
C) Enable Amazon Cognito and set up Amazon Q Developer as an AWS managed application.
D) Enable AWS IAM Identity Center and create a new identity pool for Amazon Q Developer.

Amazon SCS-C03 Exam - Topic 5 Question 6 Discussion

Actual exam question for Amazon's SCS-C03 exam
Question #: 6
Topic #: 5
[All SCS-C03 Questions]

A company uses an organization in AWS Organizations to manage multiple AWS accounts. The company wants to centrally give users the ability to access Amazon Q Developer.

Which solution will meet this requirement?

Show Suggested Answer Hide Answer
Suggested Answer: A

For centralized, organization-wide user access to AWS services and supported applications, AWS best practice is to useAWS IAM Identity Center(successor to AWS SSO). IAM Identity Center provides a single place to manage workforce identities, permission sets, and account assignments across AWS Organizations. Amazon Q Developer is integrated for centralized access using IAM Identity Center, where you can assign the relevant permissions to users and groups and enable access consistently across multiple AWS accounts. Setting Amazon Q Developer up as anAWS managed applicationaligns with IAM Identity Center's model for centrally provisioning and controlling access with minimal operational overhead.

Amazon Cognito is primarily intended forcustomer identity and application sign-up/sign-inscenarios, not for workforce access to AWS managed developer tools across multiple AWS accounts. ''Identity pools'' are a Cognito concept for exchanging identities for AWS credentials, which adds unnecessary complexity and is not the standard approach for centrally granting employees access to Amazon Q Developer in an organization. Therefore, enabling IAM Identity Center and configuring Amazon Q Developer as an AWS managed application is the correct solution.


Contribute your Thoughts:

0/2000 characters
Jerry
24 days ago
Not sure about A, isn’t Cognito better for user management?
upvoted 0 times
...
Tammy
29 days ago
I agree, AWS IAM Identity Center makes it easier!
upvoted 0 times
...
Staci
1 month ago
A) is the best choice for centralized access.
upvoted 0 times
...
Krissy
1 month ago
A) is definitely the most straightforward choice.
upvoted 0 times
...
Gail
1 month ago
I thought Cognito was the go-to for user management?
upvoted 0 times
...
Reita
2 months ago
Wait, can you really use IAM Identity Center for this?
upvoted 0 times
...
Edda
2 months ago
I disagree, B) could work too with Cognito.
upvoted 0 times
...
Clare
2 months ago
A) seems like the best option for centralized access.
upvoted 0 times
...
Selma
2 months ago
If I recall correctly, IAM Identity Center is typically used for centralized access, so I lean towards option A, but I need to double-check the details on managed applications.
upvoted 0 times
...
Dortha
2 months ago
I’m a bit confused about whether to use Amazon Cognito or IAM Identity Center here. I feel like I’ve seen both mentioned in similar scenarios.
upvoted 0 times
...
Louann
3 months ago
I remember a practice question where we had to set up user access for a managed application, and I think option A sounds familiar.
upvoted 0 times
...
Bernardo
3 months ago
I think enabling AWS IAM Identity Center is the right approach since it centralizes access management, but I'm not sure about the application setup part.
upvoted 0 times
...

Save Cancel