Courseiva
Identity and Access ManagementeasyMultiple ChoiceObjective-mapped

SCS-C03 Identity and Access Management Practice Question

A company is using AWS IAM Identity Center (successor to AWS Single Sign-On) to manage access to their AWS accounts. They want to automate the process of adding and removing users based on their status in an external identity provider. Which protocol should they use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

SCIM (System for Cross-domain Identity Management)

AWS IAM Identity Center is the recommended service for managing single sign-on access to AWS accounts and business applications. It provides a centralized place to manage user identities and their access levels. For organizations with existing directories like Active Directory, Identity Center simplifies the process of provisioning users and mapping them to specific permission sets across the entire AWS Organization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • SAML 2.0 (Security Assertion Markup Language)

    Why it's wrong here

    SAML 2.0 is used for authentication and authorization—telling AWS who the user is and what they can do during a login session. However, it does not handle the automatic provisioning or deprovisioning of user accounts and groups within the IAM Identity Center store itself.

  • LDAP (Lightweight Directory Access Protocol)

    Why it's wrong here

    While LDAP is a common protocol for querying and modifying directory services, AWS IAM Identity Center does not use it directly for automated provisioning from external cloud identity providers. LDAP is more commonly used in traditional on-premises environments rather than modern cloud-to-cloud identity synchronization workflows.

  • OpenID Connect (OIDC)

    Why it's wrong here

    OIDC is an identity layer on top of the OAuth 2.0 protocol used for verifying the identity of the end-user. Like SAML, it is primarily used for authentication during the sign-on process and is not the standard protocol for the background synchronization of user identities and group memberships.

  • SCIM (System for Cross-domain Identity Management)

    Why this is correct

    SCIM is an open standard protocol specifically designed to automate the exchange of user identity information between identity domains or IT systems. AWS IAM Identity Center supports SCIM to allow external identity providers like Okta or Azure AD to automatically provision and deprovision users and groups.

About these practice questions

Courseiva writes every SCS-C03 question from scratch — 99 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C03 exam.