nerdexam
Amazon

SCS-C03 · Question #22

A company uses AWS IAM Identity Center to manage access to its AWS accounts. The accounts are in an organization in AWS Organizations. A security engineer needs to set up delegated administration of…

The correct answer is B. Create a new IAM Identity Center directory in the organization's management account. D. Create permission sets for use only in the organization's management account. F. Create user assignments only in the organization's management account. AWS IAM Identity Center delegated administration requires foundational configuration to be completed in the organization's management account before delegation. According to the AWS Certified Security - Specialty documentation, IAM Identity Center must be enabled with a…

Submitted by khalil_dz· Mar 6, 2026Identity and Access Management

Question

A company uses AWS IAM Identity Center to manage access to its AWS accounts. The accounts are in an organization in AWS Organizations. A security engineer needs to set up delegated administration of IAM Identity Center in the organization's management account. Which combination of steps should the security engineer perform in IAM Identity Center before configuring delegated administration? (Select THREE.)

Options

  • AGrant least privilege access to the organization's management account.
  • BCreate a new IAM Identity Center directory in the organization's management account.
  • CSet up a second AWS Region in the organization's management account.
  • DCreate permission sets for use only in the organization's management account.
  • ECreate IAM users for use only in the organization's management account.
  • FCreate user assignments only in the organization's management account.

How the community answered

(26 responses)
  • A
    8% (2)
  • B
    69% (18)
  • C
    19% (5)
  • E
    4% (1)

Explanation

AWS IAM Identity Center delegated administration requires foundational configuration to be completed in the organization's management account before delegation. According to the AWS Certified Security - Specialty documentation, IAM Identity Center must be enabled with a directory in the management account before any delegation can occur. Permission sets must be created in the management account because they define the permissions that will later be delegated to member accounts. Additionally, user assignments must initially exist in the management account to establish baseline access control before delegation is Option A is too generic and not a required prerequisite step. Option C is unrelated to Identity Center delegation. Option E is incorrect because IAM Identity Center uses identities from its directory or external IdPs, not IAM users. AWS guidance clearly outlines directory creation, permission set definition, and initial user assignments as mandatory preparatory steps for delegated administration.

Topics

#IAM Identity Center#delegated administration#permission sets#Organizations management account

Community Discussion

No community discussion yet for this question.

Full SCS-C03 Practice