SCS-C02 Identity and Access Management Practice Question
A company uses AWS IAM Identity Center (SSO) for managing access to multiple AWS accounts. A user reports that they can log in to the SSO portal but cannot see any AWS accounts in their dashboard. What is the most likely cause?
⚠ Common exam trap
SCS-C02 often tests the distinction between authentication (can I log in?) and authorization (what can I see/do?) — a successful login with an empty dashboard points to missing assignments, not auth failure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user has not been assigned to any AWS accounts in IAM Identity Center.
In IAM Identity Center, users see AWS accounts in their portal only if they have been assigned to those accounts via account assignments (which link a user/group, a permission set, and an AWS account). If no account assignments exist, the user can authenticate successfully but will see an empty dashboard. This is the most common cause of the reported symptom.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The user has not been assigned to any AWS accounts in IAM Identity Center.
Why this is correct
This is correct because the user successfully authenticated to IAM Identity Center (the portal loaded and they can log in), but the portal only displays AWS accounts to which the user has been explicitly granted access. In IAM Identity Center, administrators must create an account assignment that pairs a principal (user or group) with a permission set for a specific AWS account. If no such assignment exists for this user, the login succeeds but the account list is empty, so the user sees no accounts to choose from.
- ✗
The user's identity source (e.g., Active Directory) is not synchronized correctly.
Why it's wrong here
This is incorrect because a synchronization problem with the identity source would typically prevent the user from authenticating at all—the user would not exist or would fail password validation against Active Directory or another IdP. Since the user can log in, their identity was successfully resolved from the source, which proves synchronization is working. A stale or mis-synchronized directory might cause missing group memberships or stale attributes, but it would not produce an empty account list while still allowing login.
- ✗
The user's session token has expired.
Why it's wrong here
This is incorrect because the user is already logged in and can access the IAM Identity Center portal, which means their current session token was valid at the time of login and is still active enough to render the portal. In IAM Identity Center, session tokens (created after SSO authentication) control access to the portal and downstream accounts; if the token had expired, the user would be prompted to re-authenticate or would receive an authentication error, not an empty account list. An expired session token would prevent the portal from loading or would show a 'session expired' message, but it would never present a successfully authenticated logged-in view with no accounts.
- ✗
The permission set assigned to the user does not grant any permissions.
Why it's wrong here
This is incorrect because a permission set defines what a user can do inside an account after they access it (e.g., which IAM policies are applied to the temporary session), not whether the account appears in the portal. To see an account in IAM Identity Center, the user must have an account assignment—a binding of the user or their group to a permission set for that account. Without that assignment, no account is visible regardless of what permissions any permission set might contain. If the user were assigned an account with an insufficient permission set, they would see the account but then encounter authorization errors when trying to use it.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.