SCS-C02 Identity and Access Management Practice Question
A company has multiple AWS accounts and wants to centrally manage access using IAM Identity Center (AWS SSO). Which feature allows the company to define permissions once and reuse them across multiple accounts?
⚠ Common exam trap
It's easy for candidates to confuse the assignment action (account assignments) with the reusable permission definition (permission sets), leading candidates to select 'Account assignments' because they focus on the deployment step rather than the reusable policy object.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Permission sets
Permission sets in IAM Identity Center define a collection of administrator-defined policies that grant specific permissions to users or groups. Once created, a permission set can be assigned to any number of AWS accounts within the organization, enabling centralized permission management and reuse across multiple accounts without duplicating policy definitions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Application assignments
Why it's wrong here
Application assignments in IAM Identity Center are tied to federation into third-party SaaS or on-premises applications (e.g., Salesforce, Box, Tableau), not to AWS accounts. They define who can launch a specific application but carry no AWS permissions. Choosing this would let a user reach the company SSO portal yet would not grant any access to the company's AWS accounts, so it cannot implement the central AWS access control the scenario requires.
- ✗
Identity providers
Why it's wrong here
Identity providers are the trusted external or built-in sources of identities (for example, Okta, Microsoft Entra ID, or the IAM Identity Center directory) that authenticate users into IAM Identity Center. Configuring an IdP establishes trust and allows identities to federate, but it does not define what those identities can do inside an AWS account. An IdP is a prerequisite for managing access, not a mechanism for assigning reusable AWS permissions, so it is not the right component to build the centralized access policy around.
- ✓
Permission sets
Why this is correct
Permission sets are the correct IAM Identity Center construct because they define reusable collections of AWS permissions, similar to IAM roles, that can be assigned to users or groups across multiple AWS accounts. You attach managed policies, customer managed policies, inline policies, permissions boundaries, and session duration to a permission set, then assign it to accounts and principals. Using permission sets lets you enforce least privilege consistently across the entire AWS Organization and change permissions in one place, which is exactly what a multi-account user-access solution requires.
- ✗
Account assignments
Why it's wrong here
Account assignments connect a user or group to a specific AWS account, but by themselves they do not define what actions that principal may perform. In IAM Identity Center, an account assignment always references a permission set to complete the access grant: it states 'who gets access to which account under which role.' Creating account assignments without permission sets would leave no actual IAM permissions provisioned, so this option identifies a necessary step but not the component that centrally defines and reuses the permissions.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.