Courseiva
Cloud Technology and ServicesmediumMultiple ChoiceObjective-mapped

CLF-C02 Cloud Technology and Services Practice Question

A company needs to integrate their on-premises Active Directory with AWS to enable SSO for employees accessing AWS services. Which AWS service provides this federation capability?

⚠ Common exam trap

It's easy for candidates to confuse AWS Directory Service AD Connector (which only proxies authentication) with the full SSO and access management capabilities of IAM Identity Center, leading them to choose Option C.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS IAM Identity Center

AWS IAM Identity Center (formerly AWS SSO) is the correct service for integrating on-premises Active Directory with AWS to enable single sign-on (SSO) for employees accessing AWS services. It supports federation via SAML 2.0 or SCIM protocols, allowing you to connect your existing AD identity source and centrally manage user access to multiple AWS accounts and business applications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Amazon Cognito

    Why it's wrong here

    Amazon Cognito is designed for authenticating end users of customer-facing applications, not for managing employee access to AWS accounts and services. Its user pools and identity pools issue tokens for app sessions and can federate external IdPs, but they do not provide consolidated access management to AWS organizations or support IAM permission sets across multiple accounts. Therefore, Cognito would not satisfy the requirement for workforce SSO to a set of AWS accounts.

  • AWS IAM Identity Center

    Why this is correct

    AWS IAM Identity Center is the required AWS service for workforce single sign-on. It lets you integrate with your on-premises Active Directory through a directory source such as AWS Managed Microsoft AD or AD Connector, and then define permission sets that assign users and groups to roles across multiple AWS accounts. After authenticating once with their corporate credentials, users gain access to all AWS accounts and business applications they are permitted to use, without needing separate IAM sign-ins.

  • AWS Directory Service AD Connector

    Why it's wrong here

    AWS Directory Service AD Connector is only a lightweight proxy that redirects directory-related requests, such as LDAP or Kerberos, from AWS workloads to your on-premises Active Directory. It does not itself perform SSO or provide identity federation; it simply makes your existing directory available to AWS services that are explicitly configured to use it. As a result, AD Connector is a supporting component that IAM Identity Center can use to reach AD, not the service that delivers cross-account SSO.

  • AWS IAM roles

    Why it's wrong here

    While IAM roles enable permissions for AWS resources, they lack the identity brokering protocols—such as SAML 2.0 or OIDC—required to federate an external identity source like on-premises Active Directory. IAM roles are tempting because they directly grant cross-account or service access within AWS, and would be correct for delegating permissions between AWS accounts or to an already-federated user authenticated via Microsoft Entra ID.

About these practice questions

This CLF-C02 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.