A solutions architect must provide secure Remote Desktop (RDP) access to Windows EC2 instances in a VPC, integrating centralized user management with the company’s on-premises Active Directory. Access to the VPC is over the internet, and the company can establish a Site-to-Site VPN using existing hardware. Which solution is the MOST cost-effective while meeting requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Integrate AWS IAM Identity Center (AWS Single Sign-On) with the on-premises Active Directory using AWS Directory Service’s AD Connector. Configure permission sets mapped to AD groups for access to AWS Systems Manager. Use Systems Manager Fleet Manager to perform RDP access to the target instances..
Why this is the answer
The most cost-effective solution is to leverage existing AWS services. AWS IAM Identity Center (formerly AWS SSO) integrates with on-premises Active Directory via AD Connector, providing centralized user management. AWS Systems Manager Fleet Manager allows RDP access to EC2 instances without opening inbound RDP ports or deploying bastion hosts, reducing security risks and operational overhead. This approach avoids the cost of dedicated RDP gateways or additional EC2 instances for bastions. Incorrect options: Deploying Managed AD and a bastion host adds cost and management overhead for the Managed AD and the bastion instance. A Site-to-Site VPN is mentioned as an option but the question asks for internet access to the VPC, and this option requires all connections to come over the VPN, which might not be practical for all users or devices. Deploying Managed AD and a Remote Desktop Gateway adds significant cost for Managed AD and the dedicated RDP Gateway instances, plus licensing for the RDP Gateway.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed