SCS-C02 Identity and Access Management Practice Question
Which THREE AWS services can be used to authenticate users for accessing AWS resources?
⚠ Common exam trap
A common mix-up: candidates confuse AWS Secrets Manager as an authentication service because it stores credentials, but it does not authenticate users—it only provides secure storage for secrets that other services use.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Single Sign-On
AWS Single Sign-On (SSO) is a service that centrally manages access to multiple AWS accounts and business applications, authenticating users via an external identity provider (IdP) such as Microsoft Active Directory or Okta. It allows users to sign in once and gain federated access to assigned AWS resources, making it a valid authentication service for AWS resource access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Single Sign-On
Why this is correct
AWS Single Sign-On (now AWS IAM Identity Center) authenticates users by acting as a broker between AWS and a trusted external identity provider, such as Okta, Microsoft Entra ID, or a built-in identity store. It validates the user's credentials through the IdP and then issues temporary AWS credentials or federation tokens, making it a fully functional authentication service for workforce users.
- ✓
Amazon Cognito
Why this is correct
Amazon Cognito user pools provide an end-user identity store and complete authentication flow, including sign-up/sign-in, password verification, and multi-factor authentication. Cognito authenticates the user and issues ID tokens, access tokens, and refresh tokens for the application to validate, so it is a correct service for authenticating users in customer-facing applications.
- ✗
AWS Secrets Manager
Why it's wrong here
AWS Secrets Manager is a secrets management service that securely stores, rotates, and retrieves database credentials, API keys, and other sensitive data; it does not authenticate users. Merely retrieving a secret from Secrets Manager does not prove the identity of the caller, because the caller must already be authenticated by IAM before it can call secretsmanager:GetSecretValue.
- ✓
AWS Identity and Access Management (IAM)
Why this is correct
AWS Identity and Access Management (IAM) authenticates IAM users by verifying their username and password (for the AWS Management Console) or access key and secret key (for programmatic access). IAM also authenticates roles and federated principles after AWS has validated their identity, and then grants or denies authorization based on policies, making it a core authentication service for AWS API access.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail is an auditing and governance service that records API activity, including authentication events such as ConsoleLogin, but it does not perform authentication itself. CloudTrail captures logs about who made a request after the request has already been authenticated by another service, so it can never serve as the mechanism for authenticating users.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.