Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company has a multi-account AWS environment with AWS Organizations. They use AWS IAM Identity Center (successor to AWS Single Sign-On) for workforce access. The security team wants to ensure that all federated users from the corporate identity provider (IdP) are automatically assigned to the appropriate permission sets based on their group membership in the IdP. The company uses SAML 2.0 federation with IAM Identity Center. Which configuration should the solutions architect implement to achieve automatic group-based permission set assignments?

⚠ Common exam trap

The trap here is assuming that SAML attribute mappings alone can drive permission set assignments, when in fact SCIM is required for automatic group synchronization and assignment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure SCIM synchronization between the IdP and IAM Identity Center, and map IdP groups to IAM Identity Center groups. Then assign permission sets to those groups.

SCIM synchronization automatically provisions users and groups from the corporate IdP into IAM Identity Center. By mapping IdP groups to IAM Identity Center groups and assigning permission sets to those groups, users receive the correct permissions based on their group membership without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure IAM Identity Center to use an external identity provider only for authentication, and use AWS Lambda functions triggered by IdP events to call the IAM Identity Center API to assign permission sets.

    Why it's wrong here

    This custom automation approach is complex and requires developing and maintaining Lambda functions and event integrations. It is not a native feature of IAM Identity Center and introduces potential delays and failures. SCIM provides a standardized, supported method for automatic synchronization.

  • ✓

    Configure SCIM synchronization between the IdP and IAM Identity Center, and map IdP groups to IAM Identity Center groups. Then assign permission sets to those groups.

    Why this is correct

    SCIM (System for Cross-domain Identity Management) automatically synchronizes users and groups from the IdP to IAM Identity Center. Once groups are synchronized, you can assign permission sets to those groups, and users inherit access based on group membership. This provides automatic provisioning and deprovisioning, meeting the requirement with minimal manual effort.

  • ✗

    Use SAML attribute mappings in IAM Identity Center to pass group names as session tags, and create IAM roles with trust policies that conditionally allow access based on those tags.

    Why it's wrong here

    SAML attribute mappings can pass group information as session tags, but this does not automatically assign permission sets. It requires creating and managing IAM roles with complex trust policies for each group, and does not integrate with IAM Identity Center's permission set model. This increases administrative complexity.

  • ✗

    Manually create IAM Identity Center groups that match the IdP group names, and assign permission sets to those groups. Update memberships manually when IdP groups change.

    Why it's wrong here

    Manual creation and maintenance of groups does not provide automatic assignment based on IdP group membership. It requires ongoing administrative effort to keep memberships in sync, which is error-prone and does not meet the requirement for automatic assignments. SCIM is the automated alternative.

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.