Courseiva

SCS-C02 Permission set Practice Question

A company uses AWS IAM Identity Center (AWS SSO) to manage access. A user is assigned to a permission set that grants AdministratorAccess. However, when the user tries to access the AWS console, they receive an error that they are not authorized. What is a possible reason?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user is not assigned to the AWS account in Identity Center

In AWS IAM Identity Center, a user must be assigned to both a permission set and an AWS account. The error occurs when the user has the permission set but not the account assignment. Option B is incorrect because MFA is about authentication, not authorization; the user could be authenticated but still lack access to the account. Option C is incorrect because the permission set already includes AdministratorAccess, which provides full permissions; the issue is the account assignment. Option D is incorrect because the error is about accessing the console, not about managing permission sets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The user is not assigned to the AWS account in Identity Center

    Why this is correct

    In AWS IAM Identity Center, access to an AWS account is granted only after an account assignment links the user (or a group containing them) to a permission set in that account. The assignment is what provisions the temporary IAM role credentials, so without it the portal might still list the account but authorization fails because no IAM role exists for that user. This missing assignment is exactly the root cause and must be created in the console or CLI before access is possible.

  • ✗

    The user has not set up MFA

    Why it's wrong here

    AWS IAM Identity Center does not automatically require MFA for every user; MFA enforcement is a policy choice made in the permission set or organization's authentication settings. If the assigned permission set does not enable MFA, a user who has never configured MFA can still be authenticated by password and receive the role credentials. Even when MFA is required, it would prevent the initial login before any account access, not specifically stop the user from using the assigned AdministratorAccess permission, so this is not the likely root cause.

  • ✗

    The permission set does not include the necessary policies

    Why it's wrong here

    If the user were assigned the AdministratorAccess permission set, it includes the AWS managed AdministratorAccess policy, which grants full access to all AWS services and actions with no service- or resource-level restrictions. A permission set lacking necessary policies would typically cause denial on individual API calls (e.g., AccessDenied when trying to read S3), but it would still allow sign-in to the account and administrative actions from whatever policies are attached. Therefore the explanation that the permission set lacks policies contradicts the known AdministratorAccess assignment and cannot be responsible for the access failure.

  • ✗

    The user does not have permissions to manage permission sets

    Why it's wrong here

    Managing permission sets—creating, editing, provisioning, and assigning them—is an administrative task performed by IAM Identity Center administrators with permissions on the IAM Identity Center service. Ordinary users do not need and usually do not have these administrative permissions, and that has no effect on their ability to use an account assignment that already grants them a role. In other words, lacking IAM Identity Center management rights does not block an assigned user from assuming the provisioned role and accessing the account.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.