DOP-C02 Security and Compliance Practice Question
A company wants to centralize IAM user management across multiple AWS accounts. The company currently uses individual IAM users in each account. What is the BEST practice for centralized access control?
⚠ Common exam trap
The trap is confusing 'centralized access' with 'cross-account roles' — candidates pick option C because cross-account roles sound centralized, but the exam expects IAM Identity Center as the AWS-recommended best practice for multi-account user management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Organizations and AWS IAM Identity Center (AWS SSO) to manage users centrally.
AWS IAM Identity Center (successor to AWS SSO) combined with AWS Organizations is the AWS-recommended best practice for centralizing workforce identity and access across multiple accounts. It provides a single place to manage users and groups, assign permission sets to accounts/OUs, and federate to external IdPs if desired — eliminating per-account IAM user sprawl. This is the canonical 'centralized access management' answer for multi-account environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use AWS Organizations and AWS IAM Identity Center (AWS SSO) to manage users centrally.
Why this is correct
AWS IAM Identity Center (formerly AWS SSO) integrates natively with AWS Organizations, providing a single place to manage users and groups and then assign them access across multiple AWS accounts. It uses permission sets to define IAM policies that are applied consistently to accounts, and it issues short-term AWS credentials, eliminating the need to create and rotate IAM users. This is the only option that genuinely centralizes user management while preserving fine-grained, auditable access control.
- ✗
Create the same IAM users in each account with identical permissions.
Why it's wrong here
Recreating identical IAM users in every account duplicates identity data and introduces operational drift. Each duplicate user must receive its own set of access keys, password policy, and MFA devices, and if one account is updated, the others are easily forgotten, creating security and access inconsistencies. It also brings a proliferation of long-lived credentials and increases the blast radius of a compromised password, so it is neither scalable nor secure.
- ✗
Create IAM roles in each account and allow cross-account access from a central account.
Why it's wrong here
While cross-account roles with a central account can simplify the access path, the central account still needs its own IAM users or identity source to authenticate the principals. User creation, deletion, password management, and MFA must be handled separately for every identity in the central account, and users cannot be governed uniformly across accounts without a centralized identity service. This approach centralizes access paths but not user management, leaving the original problem unsolved.
- ✗
Use IAM federation with an external identity provider and assign permissions based on SAML attributes.
Why it's wrong here
IAM federation with an external identity provider authenticates users against an IdP you already control, but it does not create or manage IAM users inside AWS. SAML attributes can map to IAM roles for dynamic permission assignment, yet user lifecycle, group membership, and attribute governance remain external responsibilities. Because the federation setup only grants access based on attributes, it lacks a central place within AWS to administer users and does not centralize IAM user management itself.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.