For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 1Question 17
    Medium1 markMultiple Choice
    Domain 1.2: Security ControlsSecurityIAM Identity CenterMulti-Account

    AWS SAP-C02 · Question 17 · Domain 1.2: Security Controls

    An enterprise uses AWS IAM Identity Center (AWS SSO) integrated with their on-premises Active Directory. Users are complaining that they cannot access a newly created AWS account within the organization. What is the MOST likely cause?

    Answer options:

    A.

    The new account has not been joined to the on-premises Active Directory domain.

    B.

    Permission sets have not been provisioned to the new account for the relevant AD groups.

    C.

    An SCP is blocking the sts:AssumeRoleWithSAML action in the new account.

    D.

    The Active Directory Connector needs to be restarted to sync the new account.

    How to approach this question

    Understand how IAM Identity Center grants access: Users/Groups + Permission Sets + Target Accounts.

    Full Answer

    B.Permission sets have not been provisioned to the new account for the relevant AD groups.✓ Correct
    Access in IAM Identity Center is granted by creating assignments, which map a User or Group to a Permission Set in a specific AWS Account.

    Common mistakes

    Assuming access is automatic when an account is created in Organizations.
    Question 16All questionsQuestion 18

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 1

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01An enterprise has 50 VPCs across two AWS Regions. They need to establish transitive routing betwe...HardQ02A company uses AWS Organizations. The security team wants to ensure that no IAM user or role can ...MediumQ03An application requires a relational database with an RPO of 1 second and an RTO of less than 1 m...HardQ04A company is setting up a new multi-account environment. They want to automate the provisioning o...MediumQ05An organization wants to allocate AWS costs to specific business units. They use AWS Organization...Hard
    View all 75 questions →