nerdexam
Amazon

SCS-C02 · Question #228

A company controls user access by using IAM users and groups in AWS accounts across an organization in AWS Organizations. The company uses an external identity provider (IdP) for workforce single…

The correct answer is A. Enable AWS IAM Identity Center. Specify the external IdP as the identity source. AWS IAM Identity Center (formerly AWS Single Sign-On) provides a single management portal for accessing AWS accounts across an organization. It supports integration with external identity providers (IdPs) via SAML, allowing the external IdP to be used as the identity source…

Submitted by certguy· Mar 6, 2026Identity and Access Management

Question

A company controls user access by using IAM users and groups in AWS accounts across an organization in AWS Organizations. The company uses an external identity provider (IdP) for workforce single sign-on (SSO). The company needs to implement a solution to provide a single management portal to access accounts within the organization. The solution must support the external IdP as a federation source. Which solution will meet this requirement?

Options

  • AEnable AWS IAM Identity Center. Specify the external IdP as the identity source.
  • BEnable federation with AWS Identity and Access Management (IAM). Specify the external IdP as
  • CMigrate to Amazon Verified Permissions. Implement fine-grained access to AWS by using policy-
  • DMigrate users to AWS Directory Service. Use AWS Control Tower to centralize security across

How the community answered

(23 responses)
  • A
    83% (19)
  • B
    4% (1)
  • C
    4% (1)
  • D
    9% (2)

Explanation

AWS IAM Identity Center (formerly AWS Single Sign-On) provides a single management portal for accessing AWS accounts across an organization. It supports integration with external identity providers (IdPs) via SAML, allowing the external IdP to be used as the identity source. This approach enables users to access multiple AWS accounts in the organization from a centralized portal, meeting the requirements for single sign-on and external IdP integration.

Topics

#IAM Identity Center#SSO#external IdP#federation

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice