Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon SOA-C03 Exam - Topic 1 Question 19 Discussion

A company that uses AWS Organizations recently implemented AWS Control Tower. The company now needs to centralize identity management. A CloudOps engineer must federate AWS IAM Identity Center with an external SAML 2.0 identity provider (IdP) to centrally manage access to all AWS accounts and cloud applications.Which prerequisites must the CloudOps engineer have so that the CloudOps engineer can connect to the external IdP? (Select TWO.)
A) A copy of the IAM Identity Center SAML metadata and B) The IdP metadata, including the public X.509 certificate
C) The IP address of the IdP
D) Root access to the management account
E) Administrative permissions to the member accounts of the organization

Amazon SOA-C03 Exam - Topic 1 Question 19 Discussion

Actual exam question for Amazon's SOA-C03 exam
Question #: 19
Topic #: 1
[All SOA-C03 Questions]

A company that uses AWS Organizations recently implemented AWS Control Tower. The company now needs to centralize identity management. A CloudOps engineer must federate AWS IAM Identity Center with an external SAML 2.0 identity provider (IdP) to centrally manage access to all AWS accounts and cloud applications.

Which prerequisites must the CloudOps engineer have so that the CloudOps engineer can connect to the external IdP? (Select TWO.)

Show Suggested Answer Hide Answer
Suggested Answer: A, B

According to the AWS Cloud Operations and Identity Management documentation, when configuring federation between IAM Identity Center (formerly AWS SSO) and an external SAML 2.0 identity provider, two key prerequisites are required:

The IAM Identity Center SAML metadata file --- This is uploaded to the external IdP to establish trust, define SAML endpoints, and enable identity federation.

The IdP metadata (including the public X.509 certificate) --- This information is imported into IAM Identity Center to validate authentication assertions and encryption signatures.

IAM Identity Center and the IdP exchange this metadata to mutually establish secure, bidirectional federation.

Network-level details such as IP addresses (Option C) are unnecessary. Root access (Option D) or permissions to member accounts (Option E) are not required; only Control Tower or IAM administrative permissions in the management account are needed for setup.

Thus, the correct answer is A and B --- the SAML metadata from both sides is required for federation.


Contribute your Thoughts:

0/2000 characters
Wilson
3 days ago
Agree with the need for admin permissions to member accounts. Super important!
upvoted 0 times
...
Meaghan
8 days ago
I thought root access was required for everything in AWS. Interesting!
upvoted 0 times
...
Vannessa
13 days ago
Not sure why you'd need the IP address of the IdP. Seems unnecessary.
upvoted 0 times
...
Lavonda
19 days ago
A copy of the IAM Identity Center SAML metadata is a must too!
upvoted 0 times
...
Stephaine
24 days ago
Definitely need the IdP metadata, including the public X.509 certificate.
upvoted 0 times
...
Eileen
29 days ago
I feel like the IAM Identity Center SAML metadata might be important too, but I'm not entirely sure if it's a strict requirement for the connection.
upvoted 0 times
...
Wilda
1 month ago
I think we practiced a similar question where we had to identify prerequisites for federating with an IdP. If I recall correctly, the IdP metadata was definitely one of the key requirements.
upvoted 0 times
...
Lemuel
1 month ago
I'm a bit unsure about needing root access to the management account. I thought administrative permissions would be sufficient for most configurations.
upvoted 0 times
...
Caitlin
1 month ago
I remember that we discussed the importance of having the IdP metadata, especially the public X.509 certificate, for establishing trust.
upvoted 0 times
...

Save Cancel