SCS-C02 Management and Security Governance Practice Question
A security engineer is designing a system to centrally manage IAM users and roles across multiple AWS accounts. The company uses AWS Organizations. Which AWS service should be used to manage permissions across accounts?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS IAM Identity Center (AWS SSO)
AWS IAM Identity Center (formerly AWS SSO) is the service for centrally managing user access to multiple accounts. Option A is wrong because AWS Config is for resource compliance. Option B is wrong because AWS Artifact is for compliance reports. Option C is wrong because AWS CloudTrail is for auditing API activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config
Why it's wrong here
AWS Config records resource configurations and evaluates them against desired compliance rules, but it has no capability to issue, federate, or centrally administer user identities and permissions across accounts. While it can flag an S3 bucket or IAM policy that drifts from baseline, it only observes and remediates resource state. Therefore, it cannot serve as the central access management system for workforce identities.
- ✗
AWS Artifact
Why it's wrong here
AWS Artifact is the self-service repository for downloading AWS compliance reports, certifications, and legal agreements such as SOC 2, ISO 27001, and HIPAA; it exists solely as evidence documentation. It does not interact with authentication flows, create identities, or enforce authorization decisions. Selecting it would solve an audit-evidence need, not the need to centrally manage access across accounts.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records API activity by capturing who made a request, from which source, and what action was taken, making it essential for post-hoc auditing and forensic investigation. It does not manage access itself; it cannot assign permissions, federate identities, or configure single sign-on. CloudTrail should accompany a central access solution for accountability, but it is not the access manager.
- ✓
AWS IAM Identity Center (AWS SSO)
Why this is correct
AWS IAM Identity Center (formerly AWS SSO) is the service designed to centrally manage workforce identities and fine-grained access to multiple AWS accounts and business applications. It connects to your existing identity provider via SAML 2.0 or SCIM, and its permission sets define which IAM roles users or groups assume in each account. This unified access model is exactly what a central management solution requires, so this is the correct choice.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.