AWS IAM Identity Center for Centralized Workforce Access

Identify AWS access management capabilities.
Answer Correct answer: D — Use AWS IAM Identity Center to centrally create and manage workforce user access across all AWS accounts and applications.

A company wants to manage sign-in security for workforce users. The company needs to create workforce users and centrally manage their access across all the company's AWS accounts and applications. Which AWS service will meet these requirements?

  1. AWS Audit Manager
  2. Amazon Cognito
  3. AWS Security Hub
  4. AWS IAM Identity Center (AWS Single Sign-On) Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the distinction between identity services: IAM Identity Center is for internal workforce management, while Amazon Cognito is primarily for customer-facing application authentication.

AWS IAM Identity Center (formerly AWS SSO) is the service designed for centrally managing workforce user access across multiple AWS accounts and applications, distinguishing it from Amazon Cognito which targets external app users.

Users often select Amazon Cognito because it handles sign-ins, but fail to recognize that 'workforce users' implies an enterprise directory context where IAM Identity Center is the correct centralized solution.

Community Discussion (8 comments)

ShaiTay 👍 1 Selected: D
D. AWS IAM Identity Center (AWS Single Sign-On)
Meow7 👍 1
would someone help with 392? much appreciation.
geocis 👍 2 Selected: D
Cognito = User authentication for Apps IAM Identity Center = Centralized access management for AWS and Apps The answer is D) AWS IAM Identity Center
chalaka 👍 2 Selected: D
D. AWS IAM Identity Center (AWS Single Sign-On) AWS IAM Identity Center, also known as AWS Single Sign-On (SSO), is a service that simplifies the management of access to AWS accounts and business applications by providing centralized identity and access management. With AWS SSO, companies can create and manage workforce users, control their access to AWS accounts and applications using single sign-on, and enforce multi-factor authentication for enhanced security. This service helps streamline access management and ensures consistent security practices across the organization's AWS environment.
Zerro 👍 1 Selected: D
I think it's D, as Cognito is more for third-part applications like credentials for facebook, etc.
rolling_potato_ 👍 3 Selected: D
I believe it's correct because "The AWS access portal provides IAM Identity Center users with single sign-on access to all their assigned AWS accounts and applications through a web portal." So it's centrally managed. And: ". Use IAM Identity Center with your existing identity source or create a new directory, and manage workforce access to part or all of your AWS environment."
69b322a 👍 1
Can someone please check if B is actually the right answer?
Lomtom 👍 1 Selected: B
Per Copilot: The AWS service that will meet these requirements is Amazon Cognito. It provides a comprehensive solution for managing sign-in security, user authentication, and access control across multiple AWS accounts and applications.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

AWS IAM Identity Center (AWS Single Sign-On) is specifically designed to manage access to AWS accounts and business applications centrally. It allows you to create workforce users in its integrated directory or sync with your existing identity provider (like Active Directory), providing a single portal for users to access all their assigned resources. This directly meets the requirement of creating and centrally managing workforce user access across all AWS accounts.

Why the Other Options Are Wrong

Amazon Cognito (Option B) is optimized for adding sign-up and sign-in functionality to web and mobile apps, typically targeting external customers rather than internal workforce employees. While it can handle authentication, it does not provide the same level of centralized multi-account access management for enterprise workforces as IAM Identity Center. AWS Security Hub (Option C) is a security posture management service that aggregates findings, not an identity service. AWS Audit Manager (Option A) helps automate audits and compliance checks, unrelated to user access management.

Community Comment Notes

Community consensus strongly supports D. One commenter noted that "IAM Identity Center = Centralized access management for AWS and Apps" contrasting it with Cognito's role. Another highlighted that Cognito is "more for third-part applications like credentials," reinforcing the workforce vs. customer distinction. Some users questioned if Cognito could be correct, but the specific mention of 'workforce users' and 'centrally manage... across all accounts' points definitively to IAM Identity Center.

Exam Strategy

When you see 'workforce', 'employees', or 'centralized access across AWS accounts', immediately think IAM Identity Center. Reserve Cognito for scenarios involving 'web/mobile apps', 'external users', or 'customer identities'.

Frequently Asked Questions

Why isn't Amazon Cognito the right answer?

Cognito is designed for external customer apps, whereas IAM Identity Center is built for internal workforce management and multi-account access.

What does 'workforce users' imply here?

It refers to internal employees who need access to corporate AWS accounts, requiring an enterprise-grade identity solution like IAM Identity Center.

Related Analysis

Practice All CLF-C02 Questions

Access 120 questions with complete answers and detailed explanations.

View Full CLF-C02 Practice Test →

← Back to CLF-C02 Study Guide