ETExamTower
Q70Design Resilient Architectures

A company manages AWS accounts by using AWS Organizations. AWS IAM Identity Center (AWS Single Sign-On) and AWS Control Tower are configured for the accounts. The company wants to manage permissions for multiple users across all the accounts. The permissions will be used by multiple IAM users and must be separated between the developer and administrator teams. Each team needs different permissions. The company wants a solution that will also accommodate new users who are hired for either team. Which solution will meet these requirements with the **LEAST operational overhead**?

← → navigate · a answer
Community votes
C
100% (6)
A
0% (0)
B
0% (0)
D
0% (0)
Discussion · 6
3
The correct answer should be C
C 2
Correct is C
C 2
https://docs.aws.amazon.com/controltower/latest/userguide/sso.html
C 1
C is least overhead
C 1
Check out this one. https://www.youtube.com/watch?v=y_n9xN5mg1g
C 1
I would: 1. Use AWS IAM Identity Center (SSO) to centrally manage user access across all accounts. 2. Create Permission Sets in Identity Center: - One for the Developer Team, granting access to resources with developer-specific permissions (AmazonEC2FullAccess or custom policies or something). - Another one for the Administrator Team, granting administrator-specific permissions (AdministratorAccess or something). 3. Sync users and groups from the corporate identity provider (or manage groups directly in IAM Identity Center) to automatically apply these permissions. 4. Assign these Permission Sets to groups of users in Identity Center rather than individuals, ensuring new users automatically inherit the appropriate permissions based on their group. That's why you choose C, with the least operational overhead.