Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company wants to centralize management of IAM users and groups across multiple AWS accounts. The solution should allow users to access resources in any account without needing separate credentials. Which AWS service should be used?

⚠ Common exam trap

Many exam-takers confuse AWS Organizations with a user management service, but Organizations only manages accounts and policies, not user identities or authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS IAM Identity Center (AWS SSO)

AWS IAM Identity Center (formerly AWS SSO) is the correct service because it provides a centralized identity source that allows users to sign in once with a single set of credentials and then access multiple AWS accounts and applications. It integrates with AWS Organizations to manage user and group permissions across accounts, eliminating the need for separate IAM users in each account.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Identity and Access Management (IAM)

    Why it's wrong here

    IAM users and groups are account-scoped, so cross-account access still requires separate identities or role assumption per account, not centralised credentials. It is tempting because IAM does manage users, groups and roles within a single account, which is the right choice when only one account's identities need controlling.

  • ✗

    AWS Organizations

    Why it's wrong here

    AWS Organizations manages accounts, consolidated billing and service control policies, but it does not hold IAM users or issue credentials for cross-account resource access. It tempts because it centralises multi-account governance, yet identity federation requires IAM Identity Center or role assumption instead.

  • ✓

    AWS IAM Identity Center (AWS SSO)

    Why this is correct

    IAM Identity Center provides a single directory-backed sign-in and issues temporary credentials per account through permission sets, so users reach resources in any account without separate IAM users. This satisfies the constraint of centralised identity with no per-account credentials.

  • ✗

    AWS Directory Service for Microsoft Active Directory

    Why it's wrong here

    AWS Directory Service for Microsoft Active Directory provides a managed AD domain, not centralised IAM user and group management with cross-account access. It tempts because it supports federated identities, but the scenario needs IAM Identity Center to issue credentials usable across accounts without duplication.

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.