A security engineer discovers that the company does not enforce a minimum password length. The company uses the following identity providers: - AWS Identity and Access Management (IAM) federated with on-premises Active Directory - Amazon Cognito user pools that store users for a custom AWS Cloud application Which combination of actions will enforce a required minimum password length? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Update the minimum password length setting in the Amazon Cognito user pool configuration., Update the minimum password length policy in the on-premises Active Directory configuration..
Why this is the answer
To enforce a minimum password length for users in Amazon Cognito, you must update the password policy directly within the Amazon Cognito user pool configuration. This setting applies specifically to users managed by that Cognito user pool. For users federated from on-premises Active Directory, their password policies are managed by Active Directory itself. Therefore, to enforce a minimum password length for these users, you must update the password policy within the on-premises Active Directory configuration. Updating the IAM account password policy would only affect IAM users directly managed by AWS IAM, not federated users or Cognito users. Service Control Policies (SCPs) and IAM policies cannot directly enforce password complexity rules for Active Directory or Cognito user pools; they primarily control AWS service permissions and resource access.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed