Courseiva
Security and Compliance →easyMultiple Choice

CLF-C02 Security and Compliance Practice Question

A small e-commerce company wants its developers to sign in to the AWS Management Console using their existing corporate credentials and enforce multi-factor authentication centrally, without creating separate long-term IAM users for each person. Which AWS service should the company use?

⚠ Common exam trap

It's easy for candidates to confuse workforce identity for employees with customer identity for application end users, which is what Cognito provides.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS IAM Identity Center

IAM Identity Center is the AWS workforce identity service that federates corporate directories and identity providers, then maps users to permission sets across accounts. It enforces MFA at the identity layer and issues short-lived credentials, removing the need to create and rotate individual IAM users while simplifying multi-account access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Directory Service for Microsoft Active Directory

    Why it's wrong here

    AWS Managed Microsoft AD provides a hosted Active Directory domain for workloads that need LDAP or domain join, but it is not itself a workforce single sign-on portal for console access. Using it alone would not deliver federated console sessions or centralized MFA enforcement for developers.

  • ✓

    AWS IAM Identity Center

    Why this is correct

    IAM Identity Center connects to an external identity provider through SAML 2.0 or SCIM, or provides its own directory, and issues short-lived credentials for console and CLI access. It centralizes permission sets and MFA enforcement, so developers use corporate credentials without per-person IAM users, matching the company's requirement.

  • ✗

    Amazon Cognito user pools with hosted UI

    Why it's wrong here

    Cognito user pools are designed to authenticate end users of customer-facing applications, not employees accessing the AWS Management Console. It does not issue AWS console sessions or integrate with corporate directories for workforce sign-in, so it does not fit this scenario.

  • ✗

    AWS Identity and Access Management (IAM) groups with password policies

    Why it's wrong here

    IAM groups and password policies govern long-term IAM users, which is exactly what the company wants to avoid creating. They do not federate corporate credentials or provide a central SSO experience, so this approach adds administrative overhead rather than eliminating it.

About these practice questions

Courseiva writes every CLF-C02 question from scratch — 993 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.