A company requires that all Windows EC2 instances be joined to an Active Directory domain hosted on AWS, and it wants to enforce enhanced security (for example, MFA) using managed AWS services where possible. Which solution meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Deploy AWS Directory Service for Microsoft Active Directory. Launch an EC2 instance and use that EC2 instance to perform domain security configuration tasks..
Why this is the answer
The correct solution is to deploy AWS Directory Service for Microsoft Active Directory and launch an EC2 instance for configuration. AWS Directory Service for Microsoft Active Directory (also known as AWS Managed Microsoft AD) provides a highly available, managed Active Directory compatible with existing AD-aware applications and supports advanced features like MFA. An EC2 instance running Windows Server with the Remote Server Administration Tools (RSAT) installed is the standard and most direct way to manage an Active Directory domain, including configuring security policies. Using AWS Directory Service Simple AD is incorrect because Simple AD is a standalone directory that is not compatible with existing Active Directory deployments and does not support advanced features like MFA. Launching an Amazon WorkSpace for configuration is less ideal than an EC2 instance. While technically possible, WorkSpaces are primarily for end-user desktop virtualization, whereas an EC2 instance offers more flexibility and control for administrative tasks, often at a lower cost for this specific purpose.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed