nerdexam
Amazon

SOA-C02 · Question #322

A company is creating a new multi-account architecture. A Sysops administrator must implement a login solution to centrally manage user access and permissions across all AWS accounts. The solution…

The correct answer is B. Enable and configure AWS Single Sign-On with the third-party IdP. AWS IAM Identity Center makes it easy to centrally manage federated access to multiple AWS accounts and business applications and provide users with single sign-on access to all their assigned accounts and applications from one place. You can use AWS IAM Identity Center for…

Submitted by wei.xz· Mar 30, 2026Security and Compliance

Question

A company is creating a new multi-account architecture. A Sysops administrator must implement a login solution to centrally manage user access and permissions across all AWS accounts. The solution must be integrated with AWS Organizations and must be connected to a third-party Security Assertion Markup Language (SAML) 2.0 identity provider (IdP). What should the SysOps administrator do to meet these requirements?

Options

  • AConfigure an Amazon Cognito user pool. Integrate the user pool with the third-party IdP.
  • BEnable and configure AWS Single Sign-On with the third-party IdP.
  • CFederate the third-party IdP with AWS Identity and Access Management (IAM) for each AWS
  • DIntegrate the third-party IdP directly with AWS Organizations.

How the community answered

(15 responses)
  • A
    13% (2)
  • B
    80% (12)
  • D
    7% (1)

Explanation

AWS IAM Identity Center makes it easy to centrally manage federated access to multiple AWS accounts and business applications and provide users with single sign-on access to all their assigned accounts and applications from one place. You can use AWS IAM Identity Center for identities in the AWS IAM Identity Center’s user directory, your existing corporate directory, or

Topics

#AWS SSO#SAML 2.0 federation#multi-account access#AWS Organizations integration

Community Discussion

No community discussion yet for this question.

Full SOA-C02 Practice