Courseiva
Security and ComplianceeasyMultiple ChoiceObjective-mapped

DOP-C02 Security and Compliance Practice Question

A company wants to centrally manage user access to multiple AWS accounts using federated identity. Which AWS service should be used to create a single sign-on (SSO) solution?

⚠ Common exam trap

Test-takers frequently confuse AWS Organizations (which manages accounts and policies) with IAM Identity Center (which manages user identities and SSO), or they think that Directory Service alone provides SSO across accounts, when in fact it only provides the directory backend and requires an additional federation service like IAM Identity Center to bridge authentication to multiple AWS accounts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS IAM Identity Center (AWS SSO)

AWS IAM Identity Center (formerly AWS SSO) is the correct service because it is purpose-built to centrally manage user access and permissions across multiple AWS accounts and applications from a single place. It allows you to create or connect your existing identity source (e.g., Active Directory, Okta, Azure AD) and then define fine-grained permission sets that map users or groups to specific roles in each account, enabling a true single sign-on (SSO) experience without needing to create IAM users in every account.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS IAM Identity Center (AWS SSO)

    Why this is correct

    AWS IAM Identity Center (formerly AWS SSO) is the correct service because it is purpose-built to centrally manage workforce user access and single sign-on across multiple AWS accounts, business applications, and SAML 2.0-enabled apps. It lets you define permission sets that map users or groups to IAM roles in different accounts, and it integrates with identity providers like Active Directory or Okta. This directly addresses the requirement to centrally manage user access to multiple AWS accounts with SSO.

  • AWS Organizations

    Why it's wrong here

    AWS Organizations is incorrect because its core function is to govern the structure of AWS accounts through organizational units, service control policies (SCPs), and consolidated billing. SCPs can restrict the maximum permissions that IAM policies grant, but Organizations does not authenticate users or provide a federation/single sign-on endpoint. User-level identity and session creation are outside its scope, so it cannot serve as the SSO mechanism for accessing multiple accounts.

  • AWS Directory Service for Microsoft Active Directory

    Why it's wrong here

    AWS Directory Service for Microsoft Active Directory is not the direct answer because it provides a managed Microsoft AD domain, which can act as an identity source for authentication and federation. While you could point IAM Identity Center at it to enable SSO, the managed AD service itself does not offer the cross-account access controls or SSO portal that the scenario requires. It is the underlying directory, not the central access-management layer for multiple AWS accounts.

  • Amazon Cognito

    Why it's wrong here

    Amazon Cognito is intended for customer-facing identity and access management, such as mobile app sign-in, social identity providers, and user pools for external application users. It is not designed as an enterprise single sign-on solution for granting workforce users access to AWS accounts through an SSO portal. Thus, while Cognito does handle authentication, it does not provide centralized AWS account access control, making it unsuitable for this requirement.

About these practice questions

One of 1,339 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.