For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 2Question 20
    Hard1 markMultiple Choice
    Domain 1.2: Security ControlsIAM Identity CenterSSOSecurity

    AWS SAP-C02 · Question 20 · Domain 1.2: Security Controls

    An organization is using AWS IAM Identity Center (successor to AWS SSO) integrated with their on-premises Active Directory. Users are complaining about access denied errors when assuming roles in member accounts, despite being in the correct AD groups. Which TWO areas should the architect investigate? (Select TWO)

    Answer options:

    A.

    Check if the IAM users in the member accounts have the correct policies attached.

    B.

    Verify the VPC Peering connection between the member accounts and the on-premises AD.

    C.

    Review the Permission Sets assigned to the AD groups in IAM Identity Center.

    D.

    Check the Service Control Policies (SCPs) applied to the member accounts.

    E.

    Ensure the AWS Directory Service AD Connector is deployed in every member account.

    F.

    Verify the SAML metadata file is uploaded to each member account.

    How to approach this question

    Understand how IAM Identity Center permissions and Organizations SCPs interact.

    Full Answer

    Access issues in IAM Identity Center are typically caused by misconfigured Permission Sets (which define the role's policies) or restrictive SCPs at the Organization level that override the allowed permissions.

    Common mistakes

    Looking for IAM users or local SAML configurations in a centralized Identity Center setup.
    Question 19All questionsQuestion 21

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 2

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A company is setting up a multi-account AWS environment using AWS Organizations. They need to ens...EasyQ02An enterprise needs to connect its on-premises data center to AWS. They require a dedicated, priv...EasyQ03A company wants to share a single AWS Transit Gateway across multiple AWS accounts within their A...EasyQ04An architect needs to design a highly available database architecture that spans multiple AWS Reg...EasyQ05A global financial institution is migrating its core banking application to AWS. The application ...Medium
    View all 75 questions →