Amazon Redshift Third-Party IdP Authentication Setup
A company has implemented a lake house architecture in Amazon Redshift. The company needs to give users the ability to authenticate into Redshift query editor by using a third-party identity provider (IdP). A data engineer must set up the authentication mechanism. What is the first step the data engineer should take to meet this requirement?
Community Votes
68% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests knowledge of the specific order of operations for SAML integration in Redshift, often trapping candidates who assume a console-only GUI approach or misinterpret 'within' as database engine vs. cluster configuration.
This question addresses configuring Amazon Redshift for third-party identity provider (IdP) authentication via SAML. It establishes that the initial configuration step involves registering the IdP within the Redshift cluster settings using SQL statements.
Many candidates select Option A, believing they must first configure the IdP (e.g., Okta/Azure AD) to trust Redshift. While this is technically a prerequisite step in the broader setup, the AWS documentation and exam logic prioritize the Redshift-side registration command as the actionable answer for 'setting up the mechanism' in this context.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option B is the correct answer because it aligns with the AWS documentation's procedural description for enabling native IdP access. According to the official guide, after pre-requisites are met, the specific action to enable authentication in Redshift is to register the identity provider using SQL statements. The phrase 'from within Amazon Redshift' refers to executing these commands against the Redshift cluster, which is the distinct administrative action required on the AWS side.Why the Other Options Are Wrong
Option A describes configuring the external IdP console, which is a prerequisite but not the step performed in Redshift to enable the feature. Options C and D suggest using Secrets Manager or ACM for IdP authentication, which is incorrect; Secrets Manager is for password management, and ACM is for SSL/TLS certificates, neither of which handles SAML-based user authentication flows.Community Comment Notes
Community discussion highlights the ambiguity of the word 'first'. As noted by user PashoQ, the documentation explicitly states to 'register the identity provider with Amazon Redshift, using SQL statements.' User solopez_111 argues for Option A based on the chronological order of 'preliminary setup,' but the exam focuses on the Redshift-side implementation step. User YUICH points out that while the console allows uploading metadata, the underlying mechanism relies on the SQL registration described in Option B.Official Reference
Exam Strategy
When reading questions about 'setting up' a service feature, look for the option that describes the direct configuration action within that service, even if prerequisites exist elsewhere. Be wary of options that mix up security services like ACM or Secrets Manager when dealing with Identity Providers.
Frequently Asked Questions
Does 'from within' mean inside the SQL engine?
Yes, it refers to executing the CREATE IDENTITY_PROVIDER SQL command against the Redshift cluster, rather than just clicking buttons in the console without backend config.
Why isn't configuring the IdP itself the first step?
While you must configure the IdP to trust Redshift first, the question asks what the data engineer should do to set up the mechanism in Redshift. The exam key prioritizes the Redshift-side registration step.
Related Analysis
Practice All DEA-C01 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DEA-C01 Practice Test →