Courseiva

SCS-C02 Identity and Access Management Practice Question

A security engineer is configuring AWS IAM Identity Center (successor to AWS Single Sign-On) for a company that uses an external identity provider (IdP) supporting SAML 2.0. The company wants to assign users to AWS accounts based on their groups in the IdP. The engineer has already configured the IdP and the SAML trust. What is the next step to ensure that users can access the correct AWS accounts with the appropriate permissions?

⚠ Common exam trap

The trap here is thinking that IAM users or manually created IAM roles are needed when using IAM Identity Center with an external IdP, when in fact permission sets and group assignments handle everything.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In IAM Identity Center, create permission sets that define the policies, then assign the IdP groups to AWS accounts with those permission sets.

After configuring the SAML trust with the external IdP, the next step in IAM Identity Center is to create permission sets that define the policies for access, and then assign those permission sets to the IdP groups for specific AWS accounts. This maps group memberships to AWS permissions without creating IAM users, enabling centralized and scalable access management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Organizations SCPs to grant permissions to IdP groups based on their group names.

    Why it's wrong here

    SCPs are used to set permission guardrails, not to grant permissions. They cannot grant access to IdP groups. Additionally, SCPs do not recognize IdP groups; they apply to accounts or OUs. Using SCPs for this purpose would not work and could inadvertently restrict access. The correct mechanism is permission sets and assignments in IAM Identity Center.

  • ✗

    Configure IAM roles in each AWS account with trust policies that allow the IdP to assume them, and then map groups to roles.

    Why it's wrong here

    While IAM Identity Center uses roles behind the scenes, manually configuring roles and trust policies is not the recommended approach. Identity Center automates the creation of roles and trust relationships. Manually managing roles would be error-prone and does not leverage the group mapping features of Identity Center. The engineer should use permission sets instead.

  • ✓

    In IAM Identity Center, create permission sets that define the policies, then assign the IdP groups to AWS accounts with those permission sets.

    Why this is correct

    This is the correct next step. Permission sets define the level of access (e.g., read-only, admin) and are assigned to IdP groups for specific AWS accounts. This leverages the group membership from the IdP to grant access without creating individual IAM users. It centralizes management and ensures that users get the right permissions in the right accounts.

  • ✗

    Create IAM users in each AWS account and map them to the IdP groups.

    Why it's wrong here

    IAM Identity Center does not require creating IAM users in each account. It uses permission sets and assignments to manage access. Creating IAM users would defeat the purpose of centralized identity management and introduce additional overhead. The correct approach is to use the Identity Center's built-in features to assign groups to accounts and permission sets.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.