SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company wants to centralize management of IAM users and groups across multiple AWS accounts. The solution should allow users to access resources in any account without needing separate credentials. Which AWS service should be used?
⚠ Common exam trap
Many exam-takers confuse AWS Organizations with a user management service, but Organizations only manages accounts and policies, not user identities or authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS IAM Identity Center (AWS SSO)
AWS IAM Identity Center (formerly AWS SSO) is the correct service because it provides a centralized identity source that allows users to sign in once with a single set of credentials and then access multiple AWS accounts and applications. It integrates with AWS Organizations to manage user and group permissions across accounts, eliminating the need for separate IAM users in each account.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Identity and Access Management (IAM)
Why it's wrong here
IAM users and groups are account-scoped, so cross-account access still requires separate identities or role assumption per account, not centralised credentials. It is tempting because IAM does manage users, groups and roles within a single account, which is the right choice when only one account's identities need controlling.
- ✗
AWS Organizations
Why it's wrong here
AWS Organizations manages accounts, consolidated billing and service control policies, but it does not hold IAM users or issue credentials for cross-account resource access. It tempts because it centralises multi-account governance, yet identity federation requires IAM Identity Center or role assumption instead.
- ✓
AWS IAM Identity Center (AWS SSO)
Why this is correct
IAM Identity Center provides a single directory-backed sign-in and issues temporary credentials per account through permission sets, so users reach resources in any account without separate IAM users. This satisfies the constraint of centralised identity with no per-account credentials.
- ✗
AWS Directory Service for Microsoft Active Directory
Why it's wrong here
AWS Directory Service for Microsoft Active Directory provides a managed AD domain, not centralised IAM user and group management with cross-account access. It tempts because it supports federated identities, but the scenario needs IAM Identity Center to issue credentials usable across accounts without duplication.
Go deeper
Related to this question
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.