CLF-C02 Security and Compliance Practice Question
A company manages multiple AWS accounts using AWS Organizations. The company wants employees to sign in using their existing corporate credentials from an on-premises Microsoft Active Directory. The company also needs a single sign-on (SSO) experience so that each employee can access the AWS Management Console for any authorized account without needing separate passwords. Additionally, the company wants to centrally manage permissions across all accounts. Which AWS service should the company use to meet these requirements?
⚠ Common exam trap
Candidates often confuse AWS Directory Service with a complete SSO solution, but Directory Service only provides the directory infrastructure, not the centralized permission management or SSO portal that IAM Identity Center delivers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS IAM Identity Center (AWS SSO)
AWS IAM Identity Center (formerly AWS SSO) is the correct service because it provides a centralized place to manage single sign-on (SSO) access to multiple AWS accounts and applications. It integrates with an on-premises Microsoft Active Directory via the AWS Directory Service or an external identity provider, allowing employees to use their existing corporate credentials. IAM Identity Center also enables you to centrally define and manage permissions across all accounts in AWS Organizations, meeting all stated requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Identity and Access Management (IAM)
Why it's wrong here
IAM manages users and permissions within a single AWS account. It cannot centrally manage permissions across multiple accounts or provide single sign-on using corporate credentials across accounts without additional configuration like role switching, which is not the centralized SSO solution described.
When this WOULD be correct
A company needs to create individual IAM users with long-term credentials for direct AWS API access, and does not require federation with an external identity provider or SSO across multiple accounts.
- ✓
AWS IAM Identity Center (AWS SSO)
Why this is correct
AWS IAM Identity Center is the service that centrally manages single sign-on access to multiple AWS accounts and applications. It integrates with Microsoft Active Directory and allows employees to use their existing corporate credentials to access the AWS Management Console across all authorized accounts with a single sign-on experience, and it centralizes permission management.
- ✗
AWS Directory Service
Why it's wrong here
AWS Directory Service provides managed Microsoft Active Directory in the AWS cloud. While it can be used as a source of user identities, it does not natively provide the cross-account SSO and permission management features of IAM Identity Center. It would be a component of the solution but not the service that delivers the SSO experience across multiple accounts.
When this WOULD be correct
A company needs to extend its on-premises Active Directory to AWS for EC2 instances to join the domain, or to enable LDAP-based authentication for applications, without requiring SSO or multi-account permission management.
- ✗
Amazon Cognito
Why it's wrong here
Amazon Cognito is designed for customer identity and access management (CIAM) for web and mobile applications, such as sign-up and sign-in for end users. It is not intended for employee access to AWS accounts or for managing permissions across multiple AWS accounts.
When this WOULD be correct
A company builds a mobile app and wants to allow users to sign in with their social media accounts (e.g., Facebook, Google) or through a custom identity provider. Amazon Cognito user pools would be the correct service to handle authentication and provide temporary AWS credentials for accessing backend resources.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓AWS IAM Identity Center (AWS SSO)Correct answer▾
Why this is correct
AWS IAM Identity Center is the service that centrally manages single sign-on access to multiple AWS accounts and applications. It integrates with Microsoft Active Directory and allows employees to use their existing corporate credentials to access the AWS Management Console across all authorized accounts with a single sign-on experience, and it centralizes permission management.
✗AWS Identity and Access Management (IAM)Wrong answer — click to see why▾
Why this is wrong here
IAM does not provide SSO with corporate credentials or centralized permission management across multiple AWS accounts; it is designed for user and permission management within a single account.
★ When this WOULD be the correct answer
A company needs to create individual IAM users with long-term credentials for direct AWS API access, and does not require federation with an external identity provider or SSO across multiple accounts.
Why candidates choose this
Candidates may think IAM is the default AWS identity service and assume it can handle SSO and multi-account permissions, overlooking that IAM Identity Center is specifically built for these use cases.
✗AWS Directory ServiceWrong answer — click to see why▾
Why this is wrong here
AWS Directory Service provides managed Microsoft Active Directory but does not offer single sign-on (SSO) to the AWS Management Console or centralized permission management across multiple accounts; it only integrates with IAM for directory-based authentication.
★ When this WOULD be the correct answer
A company needs to extend its on-premises Active Directory to AWS for EC2 instances to join the domain, or to enable LDAP-based authentication for applications, without requiring SSO or multi-account permission management.
Why candidates choose this
Candidates see 'Microsoft Active Directory' and assume Directory Service is the solution, overlooking that the question specifically requires SSO and centralized permissions across accounts, which are provided by IAM Identity Center.
✗Amazon CognitoWrong answer — click to see why▾
Why this is wrong here
Amazon Cognito is designed for customer identity and access management (CIAM) for web and mobile apps, not for workforce SSO with corporate Active Directory. It does not integrate with AWS Organizations to centrally manage permissions across multiple AWS accounts.
★ When this WOULD be the correct answer
A company builds a mobile app and wants to allow users to sign in with their social media accounts (e.g., Facebook, Google) or through a custom identity provider. Amazon Cognito user pools would be the correct service to handle authentication and provide temporary AWS credentials for accessing backend resources.
Why candidates choose this
Candidates may confuse Amazon Cognito's ability to federate with external identity providers (like Active Directory) with the workforce SSO scenario, not realizing that Cognito is primarily for customer-facing apps, not for managing employee access to AWS accounts.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.