SCS-C02 Management and Security Governance Practice Question
A company wants to centralize the management of IAM users and groups for multiple AWS accounts. Which AWS service should be used to allow users to access multiple accounts with a single set of credentials?
⚠ Common exam trap
SCS-C02 often tests the distinction between AWS Organizations (account governance) and IAM Identity Center (workforce SSO) — candidates pick Organizations because it 'centralizes accounts' and miss that it has no identity store.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS IAM Identity Center (AWS SSO)
AWS IAM Identity Center (successor to AWS SSO) is purpose-built to centralize workforce access across multiple AWS accounts using a single set of credentials. It integrates with AWS Organizations to enumerate accounts and permission sets, and can federate with an external IdP (e.g., Okta, Microsoft Entra ID) or use its own identity store. Users sign in once and pick from assigned accounts/roles, eliminating per-account IAM users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Organizations
Why it's wrong here
AWS Organizations is primarily a suite of services for centrally governing accounts, such as consolidating billing, organizing accounts into OUs, and applying service control policies (SCPs). It does not store user identities or manage IAM user access; IAM users and their credentials still must be managed per account. Although Organizations can be integrated with IAM Identity Center for account-level access assignments, the organization service itself cannot centralize user identity and permission management for IAM users.
- ✗
IAM users and groups in each account
Why it's wrong here
Creating IAM users and groups in each individual account would replicate identity management across every account, requiring separate credentials, MFA devices, and password policies per account. This approach eliminates a single source of truth, complicates user lifecycle management, and fails to provide cross-account single sign-on. It also introduces security risk from credential proliferation and makes auditing and revocation inconsistent, which is the opposite of centralized management.
- ✗
Amazon Cognito
Why it's wrong here
Amazon Cognito is an identity service for customer-facing applications, providing sign-up/sign-in, user pools, and federated identity with social or enterprise IdPs. It is not intended for workforce identity or managing IAM users who need to access AWS console and API across multiple accounts. While Cognito identity pools can temporarily grant AWS credentials for mobile/web app users, they don't support centralized cross-account permission assignment or IAM user provisioning, making it unsuitable for this requirement.
- ✓
AWS IAM Identity Center (AWS SSO)
Why this is correct
AWS IAM Identity Center (successor to AWS SSO) is designed precisely for centralized management of workforce user access to multiple AWS accounts. It connects to external identity providers like Okta, Microsoft Entra ID, or its own built-in identity store, and assigns users and groups to accounts using permission sets that define granular IAM permissions. With IAM Identity Center, an organization can manage one user directory and control sign-in across all accounts, complete with MFA and auditing, eliminating the need to create IAM users in each account.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.