SCS-C02 Identity and Access Management Practice Question
Which TWO services can be used to manage identity and access across multiple AWS accounts? (Choose TWO.)
⚠ Common exam trap
SCS-C02 often tests the distinction between services that manage identities and access versus those that monitor or audit, so candidates may incorrectly select AWS Config or CloudTrail for identity management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Organizations
AWS Organizations (B) is correct because it centrally manages multiple AWS accounts under a single organization, enabling consolidated billing and centralized policy-based governance through Service Control Policies (SCPs) that control access across all member accounts. AWS Single Sign-On (C) is correct because it provides centralized identity and access management across multiple AWS accounts, letting users sign in once with their existing corporate credentials and access assigned accounts and roles via permission sets. Amazon Cognito (A) is incorrect because it is a customer-facing identity service for web and mobile applications (user pools and identity pools), not for managing access across AWS accounts. AWS Config (D) is incorrect because it is a configuration compliance and auditing service that records resource changes, not an identity and access management service. AWS CloudTrail (E) is incorrect because it logs API activity and account events for auditing, not identity or access management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon Cognito
Why it's wrong here
Amazon Cognito is designed for customer identity and access management (CIAM), providing sign-up, sign-in, and user directory capabilities for end users of applications. It can issue temporary AWS credentials to authenticated customers, but it does not manage IAM roles, policies, or cross-account access for AWS administrators or workloads. Therefore, Cognito is not a service used to centrally manage identity and access across AWS accounts.
- ✓
AWS Organizations
Why this is correct
AWS Organizations is a governance service that lets you centrally manage multiple AWS accounts by organizing them into organizational units and applying service control policies (SCPs). SCPs define the maximum allowed permissions for every IAM principal in an account, effectively managing identity and access by creating guardrails at the organization level. This makes Organizations a correct service for managing identity and access across accounts.
- ✓
AWS Single Sign-On (SSO)
Why this is correct
AWS Single Sign-On, now known as AWS IAM Identity Center, centralizes identity and access management by connecting users and groups to AWS accounts and business applications. It allows administrators to create permission sets that map to IAM roles, assign users or groups to accounts, and enforce least-privilege access across an organization. This direct control over cross-account access makes SSO the second correct service for managing identity and access.
- ✗
AWS Config
Why it's wrong here
AWS Config is a configuration recording and evaluation service that tracks resource configurations, relationships, and changes over time for compliance and auditing. It can monitor IAM resources and detect noncompliant configuration rules, but it has no ability to create, modify, or enforce IAM policies, roles, or permissions. Because AWS Config is detective rather than preventive or administrative, it cannot manage identity and access.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records API activity and provides an audit log of actions taken by principals, services, and accounts, including identity and access management events. It captures who made a request and what the request was, which is essential for security analysis and operational troubleshooting. However, CloudTrail does not create policies, assign permissions, or define access controls; it only observes and logs activity, so it is not a service used to manage identity and access.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.