Courseiva

SAP-C02 Practice Question: Accelerate Workload Migration and Modernization

A company is migrating a legacy application that uses a third-party identity provider (IdP) for authentication. The application currently uses SAML 2.0. The company wants to use AWS IAM Identity Center for centralized access management. What is the best approach to integrate the IdP with AWS?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure IAM Identity Center to use the existing IdP as the identity source via SAML 2.0 federation

AWS IAM Identity Center supports SAML 2.0 federation with external identity providers (IdPs). This allows centralized access management without duplicating identities. Option A is incorrect because AWS Directory Service for Microsoft AD is for Active Directory synchronization, not generic SAML federation. Option B is incorrect because creating IAM users for every employee would duplicate identities and increase administrative overhead. Option D is incorrect because Amazon Cognito user pools are designed for customer-facing applications, not for enterprise SSO with existing IdPs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Directory Service for Microsoft Active Directory to synchronize with the IdP

    Why it's wrong here

    Directory Service for Microsoft Active Directory synchronises directory objects, not SAML 2.0 authentication assertions, so it cannot federate the third-party IdP into IAM Identity Center. It is tempting because it integrates on-premises identities with AWS, and would be correct for AD-joined workloads needing domain authentication.

  • ✗

    Create IAM users for each employee and assign groups and permissions

    Why it's wrong here

    Creating IAM users bypasses the third-party IdP entirely, so SAML 2.0 authentication and IAM Identity Center's centralised access management are both lost. IAM users suit small numbers of standalone AWS identities with no external directory, not federating an existing corporate IdP.

  • ✓

    Configure IAM Identity Center to use the existing IdP as the identity source via SAML 2.0 federation

    Why this is correct

    IAM Identity Center can consume the existing IdP as its identity source through SAML 2.0 federation, so users authenticate against the third-party IdP while Identity Center handles centralised AWS access assignment. This preserves the current SAML 2.0 investment.

  • ✗

    Use Amazon Cognito user pools with the IdP as a SAML identity provider

    Why it's wrong here

    Cognito user pools federate SAML for customer-facing application sign-in, not workforce access to AWS accounts and permission sets. IAM Identity Center is the service that consumes the IdP's SAML assertions to issue AWS role credentials; Cognito cannot grant that account access.

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.