Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company wants to centrally manage IAM users across multiple AWS accounts using AWS IAM Identity Center (successor to AWS Single Sign-On). Which of the following are true? (Choose TWO.)

⚠ Common exam trap

Many candidates confuse permission sets with IAM roles in the management account, but permission sets are actually applied to roles created in the member accounts, not the management account.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Users can be granted access to multiple accounts from a central location.

Option A is correct because IAM Identity Center is designed for centralized multi-account access: from the management account you create permission sets and assign users/groups to multiple AWS accounts, and users then access those accounts through the AWS access portal without per-account IAM users. Option E is correct because Identity Center includes a built-in Identity Center directory where you can create and manage users and groups directly, in addition to connecting external identity sources such as Active Directory or SAML/OIDC providers. Option B is incorrect because Identity Center federates users into accounts via IAM roles, so users do not need to exist as IAM users in each account. Option C is incorrect because an on-premises Active Directory is optional, not required; the Identity Center directory or another external IdP can be used. Option D is incorrect because permission sets are not assigned to IAM roles in the management account; they are AWS-managed entities assigned to users/groups for target accounts, where Identity Center provisions corresponding IAM roles in those accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Users can be granted access to multiple accounts from a central location.

    Why this is correct

    AWS IAM Identity Center assigns users and groups to permission sets across every account in an AWS Organization from one administrative view, satisfying the centralised multi-account management requirement. This removes the need to create duplicate IAM users in each account, since identities exist once and are federated outward.

  • ✗

    Users must be IAM users in each account.

    Why it's wrong here

    Identity Center authenticates workforce identities from its own directory or a connected external IdP, then federates into accounts via permission sets; it does not require per-account IAM users. Per-account IAM users are the older pattern Identity Center replaces.

  • ✗

    Identity Center requires an on-premises Active Directory.

    Why it's wrong here

    Identity Center's built-in directory or any SAML 2.0 external identity provider can supply users; Active Directory is optional, via AD Connector or IAM Identity Center's AD sync. On-premises AD is required only when you specifically want to reuse those existing AD credentials.

  • ✗

    Permission sets are assigned to IAM roles in the management account.

    Why it's wrong here

    Permission sets are assigned to users or groups and provisioned as IAM roles in each target member account, not in the management account. Assigning to management-account roles is a plausible misreading of where the roles actually materialise.

  • ✓

    Users can be created in the Identity Center directory.

    Why this is correct

    Creating users directly in the Identity Center directory satisfies the centralised management constraint, since identities reside in one place and are permission-set-assigned across all accounts in the organisation. This avoids per-account IAM users, and the directory also supports Microsoft Entra ID or AD as an external identity source.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.