SOA-C02 Security and Compliance Practice Question
A company wants to centrally manage access to AWS accounts for its employees. Which AWS service should be used to create and manage users and groups across multiple accounts?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS IAM Identity Center
AWS IAM Identity Center (successor to AWS SSO) allows you to centrally create and manage users and groups and assign them single sign-on access to multiple AWS accounts. Option C is correct. Option A (AWS IAM) is wrong because IAM is per-account and not designed for cross-account user management. Option B (AWS Directory Service) is wrong because it provides managed Microsoft Active Directory, not multi-account user management. Option D (AWS Organizations) is wrong because it manages accounts and policies, not users and groups.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS IAM
Why it's wrong here
AWS IAM operates within a single AWS account; users, groups, roles, and policies are scoped to that account and cannot be shared or managed across multiple accounts without federating through another service. While you can manually create duplicate roles and configure cross-account trust, this approach is not a central management solution because each account's IAM configuration must be individually maintained. Centrally managing access for many accounts would require a purpose-built service like IAM Identity Center, not IAM alone.
- ✗
AWS Directory Service
Why it's wrong here
AWS Directory Service provides managed Microsoft Active Directory (or Simple AD) for authenticating users against a domain, but it does not define AWS account permissions or allow you to centrally assign users to accounts. It can serve as an identity source that another service consumes, but by itself it offers no mechanism for granting or revoking access to AWS resources across accounts. Therefore, while Directory Service may be part of an identity infrastructure, it is not a standalone solution for central AWS account access management.
- ✓
AWS IAM Identity Center
Why this is correct
AWS IAM Identity Center is the AWS-native service designed specifically to centralize user and group management across multiple AWS accounts and applications. It integrates with AWS Organizations so you can assign users or groups to accounts and apply permission sets that map to IAM roles, enabling single sign-on and consistent permission enforcement. With support for built-in identity stores or external identity providers, IAM Identity Center provides the exact capability needed to centrally manage access to AWS accounts.
- ✗
AWS Organizations
Why it's wrong here
AWS Organizations centralizes account governance by enabling consolidated billing, organizational units (OUs), and service control policies (SCPs) that guard what services and actions are allowed. However, it does not manage individual user identities or authenticate users; it operates at the account and policy level, not the user level. SCPs can restrict permissions but cannot grant a specific user access; identity-level management still requires a service like IAM Identity Center or IAM.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.