Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company has a management account in AWS Organizations. It wants to delegate administration of AWS IAM Identity Center to a member account for user management. What is the correct way to achieve this?

⚠ Common exam trap

Many exam-takers confuse delegation with resource sharing via RAM or assume that SCPs can grant permissions, when in fact delegation is a specific AWS Organizations feature that must be configured through the IAM Identity Center console or API for that service.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the IAM Identity Center console to add the member account as a delegated administrator.

AWS IAM Identity Center allows you to designate a member account as a delegated administrator directly from the IAM Identity Center console in the management account. This grants the member account the necessary permissions to manage users, groups, and permission sets without requiring cross-account roles or resource sharing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Resource Access Manager to share the IAM Identity Center instance with the member account.

    Why it's wrong here

    RAM shares resources such as subnets and licences, not IAM Identity Center administration; delegation requires enabling it as a delegated administrator from the management account via Organizations. Sharing an instance is not a supported RAM resource type, so the member account gains no Identity Center management permissions.

  • ✓

    Use the IAM Identity Center console to add the member account as a delegated administrator.

    Why this is correct

    IAM Identity Center supports delegated administration, letting the management account register a member account directly through the console. That member then manages users and permission sets without needing management account access, satisfying the delegation requirement natively.

  • ✗

    Use a service control policy to allow the member account to manage IAM Identity Center.

    Why it's wrong here

    SCPs only set maximum permission guardrails within an organisation; they never grant permissions. Delegated administration needs the member account registered as an IAM Identity Center delegated administrator from the management account, which an SCP cannot perform or authorise.

  • ✗

    Create an IAM role in the management account and allow the member account to assume it.

    Why it's wrong here

    An IAM role in the management account grants access to management-account resources, not delegation of IAM Identity Center administration. It suits cross-account access to services. Delegated administration requires registering the member account as a delegated administrator through AWS Organizations.

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.