Question: A corporate web application is deployed within an Amazon VPC , and is connected to the corporate data center via IPSec VPN . The application
A corporate web application is deployed within an Amazon VPC and is connected to the corporate data center via IPSec VPN The application must authenticate against the onpremise LDAP server. Once authenticated, loggedin users can only access an S keyspace specific to the user.
Which two approaches can satisfy the objectives? Choose answers
A The application authenticates against LDAP. The application then calls the IAM Security Service to login to IAM using the LDAP credentials. The application can use the IAM temporary credentials to access the appropriate S bucket.
B The application authenticates against LDAP, and retrieves the name of an IAM role associated with the user. The application then calls the IAM Security Token Service to assume that IAM Role. The application can use the temporary credentials to access the appropriate S bucket.
C The application authenticates against IAM Security Token Service using the LDAP credentials. The application uses those temporary AWS security credentials to access the appropriate S bucket.
D Develop an identity broker which authenticates against LDAP, and then calls IAM Security Token Service to get IAM federated user credentials. The application calls the identity broker to get IAM federated user credentials
with access to the appropriate S bucket.
E Develop an identity broker which authenticates against IAM Security Token Service to assume an IAM Role to get temporary AWS security credentials. The application calls the identity broker to get AWS temporary security credentials with access to the appropriate S bucket.
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
