AWS Certified SysOps Administrator SOA-C01 – Question831

Each SysOps Administrator at a company has a unique IAM user account. Each user is a member of the SysOps IAM group that has an IAM policy applied. A recent change to the IT security policy states that employees must now use their on-premises Active Directory user accounts to access the AWS Management Console.
Which solution should be used to satisfy these requirements?

A.
Configure the on-premises Active Directory to use AWS Direct Connect.
B. Enable an Active Directory federation in an Amazon Route 53 private zone.
C. Implement a VPN tunnel and configure an Active Directory connector.
D. Implement multi-factor authentication for IAM and Active Directory.