1|Page
AWS SAA-C03 — IAM IDENTITY CENTER EXAM:
COMPREHENSIVE PRACTICE EXAMINATION STUDY GUIDE
| LATEST UPDATE 2025/2026 | ACTUAL EXAM PRACTICE
QUESTIONS AND ANSWERS | EXAM REVIEW | 100%
CORRECT ANSWERS | VERIFIED SOLUTIONS.
This comprehensive practice examination is designed for candidates preparing for the AWS
Certified Solutions Architect – Associate (SAA-C03) exam, with a focused emphasis on AWS
IAM Identity Center (formerly AWS Single Sign-On). IAM Identity Center is a critical service
within the "Design Secure Architectures" domain, which constitutes approximately 30% of
the SAA-C03 exam. This resource covers all aspects of IAM Identity Center, including
workforce identity federation, permission sets, multi-account access management, integration
with external identity providers, and the difference between IAM Identity Center and IAM.
Questions are written at the level expected for the certification examination, emphasizing real-
world scenario application, security best practices, and least privilege principles. This resource
is intended to help candidates assess their readiness, identify knowledge gaps, and strengthen
their preparation for the certification examination.
Table of Contents
1. IAM Identity Center Fundamentals and Core Concepts
2. Identity Sources and Federation
3. Permission Sets and Multi-Account Access
4. IAM Identity Center vs. IAM
5. AWS Organizations Integration
6. Session Duration and Temporary Credentials
7. Application Assignments and SSO
8. Security Best Practices and MFA
,2|Page
9. Troubleshooting and Common Scenarios
10. Comprehensive Scenario-Based Review
UNIT 1 – IAM IDENTITY CENTER FUNDAMENTALS AND CORE CONCEPTS
1. What is AWS IAM Identity Center?
A) A service for managing access to AWS resources for individual IAM users
B) A service that centrally manages workforce access to multiple AWS accounts and
applications
C) A service for managing customer identities in mobile applications
D) A service for managing API keys for AWS services
Correct Answer: B
Rationale: IAM Identity Center (formerly AWS Single Sign-On) is a service that centrally
manages workforce access to multiple AWS accounts and applications. It allows you to create
or connect your users and groups once and manage access across AWS Organizations
accounts and cloud applications.
2. What was the former name of AWS IAM Identity Center?
A) AWS Directory Service
B) AWS Single Sign-On (AWS SSO)
C) AWS Identity Management
D) AWS Federation Service
Correct Answer: B
Rationale: AWS IAM Identity Center was formerly known as AWS Single Sign-On (AWS
SSO). AWS renamed the service in 2022 to better reflect its integration with AWS Identity and
Access Management (IAM). Both names refer to the same service.
3. Which of the following is the primary use case for IAM Identity Center?
A) Managing customer identities for a mobile application
B) Managing workforce access to multiple AWS accounts and cloud applications
,3|Page
C) Managing IAM roles for EC2 instances
D) Managing API keys for programmatic access
Correct Answer: B
Rationale: IAM Identity Center is designed for managing workforce access to multiple AWS
accounts and applications. It is the recommended service for centralizing access management
for employees and contractors. Customer identities are managed with Amazon Cognito.
4. A company wants to allow employees to log into the AWS Management Console using
their existing corporate credentials from Microsoft Active Directory. Which service is
required?
A) AWS IAM
B) AWS IAM Identity Center
C) Amazon Cognito
D) AWS Directory Service
Correct Answer: B
Rationale: IAM Identity Center is the recommended service for managing workforce access to
AWS accounts and applications via federation with an existing identity provider, such as
Microsoft Active Directory. It allows employees to use their existing corporate credentials to
access the AWS Management Console.
5. Which statement about IAM Identity Center is true?
A) It is used to manage access for application end users
B) It is used to manage access for AWS workloads and services
C) It is used to centrally manage workforce access across multiple AWS accounts
D) It is used to manage IAM roles for EC2 instances
Correct Answer: C
Rationale: IAM Identity Center is used to centrally manage workforce access across multiple
AWS accounts. It is not for application end users (Cognito), AWS workloads (IAM roles), or
EC2 instance roles (IAM).
6. IAM Identity Center integrates with which AWS service to provide centralized access
management across multiple accounts?
, 4|Page
A) AWS Config
B) AWS CloudTrail
C) AWS Organizations
D) AWS Control Tower
Correct Answer: C
Rationale: IAM Identity Center integrates with AWS Organizations, which allows you to
configure your identity provider once and then grant access to existing and new accounts
managed in your organization. This integration is essential for multi-account access
management.
7. Which of the following is a key capability of IAM Identity Center?
A) Creating IAM users in each AWS account
B) Centrally managing access to multiple AWS accounts and applications
C) Managing access keys for programmatic access
D) Creating IAM roles for EC2 instances
Correct Answer: B
Rationale: IAM Identity Center provides centralized management of access to multiple AWS
accounts and applications. It avoids the need to create IAM users in each individual account.
8. For workforce access across multiple AWS accounts, which service is the default answer?
A) IAM
B) IAM Identity Center
C) Amazon Cognito
D) AWS Directory Service
Correct Answer: B
Rationale: For workforce access, the default answer is usually IAM Identity Center. It
provides centralized, MFA-friendly, multi-account access management. IAM is for individual
users within a single account, and Cognito is for application end users.
9. What is the relationship between IAM Identity Center and AWS Organizations?
A) IAM Identity Center replaces AWS Organizations
B) IAM Identity Center integrates with AWS Organizations to provide centralized access
AWS SAA-C03 — IAM IDENTITY CENTER EXAM:
COMPREHENSIVE PRACTICE EXAMINATION STUDY GUIDE
| LATEST UPDATE 2025/2026 | ACTUAL EXAM PRACTICE
QUESTIONS AND ANSWERS | EXAM REVIEW | 100%
CORRECT ANSWERS | VERIFIED SOLUTIONS.
This comprehensive practice examination is designed for candidates preparing for the AWS
Certified Solutions Architect – Associate (SAA-C03) exam, with a focused emphasis on AWS
IAM Identity Center (formerly AWS Single Sign-On). IAM Identity Center is a critical service
within the "Design Secure Architectures" domain, which constitutes approximately 30% of
the SAA-C03 exam. This resource covers all aspects of IAM Identity Center, including
workforce identity federation, permission sets, multi-account access management, integration
with external identity providers, and the difference between IAM Identity Center and IAM.
Questions are written at the level expected for the certification examination, emphasizing real-
world scenario application, security best practices, and least privilege principles. This resource
is intended to help candidates assess their readiness, identify knowledge gaps, and strengthen
their preparation for the certification examination.
Table of Contents
1. IAM Identity Center Fundamentals and Core Concepts
2. Identity Sources and Federation
3. Permission Sets and Multi-Account Access
4. IAM Identity Center vs. IAM
5. AWS Organizations Integration
6. Session Duration and Temporary Credentials
7. Application Assignments and SSO
8. Security Best Practices and MFA
,2|Page
9. Troubleshooting and Common Scenarios
10. Comprehensive Scenario-Based Review
UNIT 1 – IAM IDENTITY CENTER FUNDAMENTALS AND CORE CONCEPTS
1. What is AWS IAM Identity Center?
A) A service for managing access to AWS resources for individual IAM users
B) A service that centrally manages workforce access to multiple AWS accounts and
applications
C) A service for managing customer identities in mobile applications
D) A service for managing API keys for AWS services
Correct Answer: B
Rationale: IAM Identity Center (formerly AWS Single Sign-On) is a service that centrally
manages workforce access to multiple AWS accounts and applications. It allows you to create
or connect your users and groups once and manage access across AWS Organizations
accounts and cloud applications.
2. What was the former name of AWS IAM Identity Center?
A) AWS Directory Service
B) AWS Single Sign-On (AWS SSO)
C) AWS Identity Management
D) AWS Federation Service
Correct Answer: B
Rationale: AWS IAM Identity Center was formerly known as AWS Single Sign-On (AWS
SSO). AWS renamed the service in 2022 to better reflect its integration with AWS Identity and
Access Management (IAM). Both names refer to the same service.
3. Which of the following is the primary use case for IAM Identity Center?
A) Managing customer identities for a mobile application
B) Managing workforce access to multiple AWS accounts and cloud applications
,3|Page
C) Managing IAM roles for EC2 instances
D) Managing API keys for programmatic access
Correct Answer: B
Rationale: IAM Identity Center is designed for managing workforce access to multiple AWS
accounts and applications. It is the recommended service for centralizing access management
for employees and contractors. Customer identities are managed with Amazon Cognito.
4. A company wants to allow employees to log into the AWS Management Console using
their existing corporate credentials from Microsoft Active Directory. Which service is
required?
A) AWS IAM
B) AWS IAM Identity Center
C) Amazon Cognito
D) AWS Directory Service
Correct Answer: B
Rationale: IAM Identity Center is the recommended service for managing workforce access to
AWS accounts and applications via federation with an existing identity provider, such as
Microsoft Active Directory. It allows employees to use their existing corporate credentials to
access the AWS Management Console.
5. Which statement about IAM Identity Center is true?
A) It is used to manage access for application end users
B) It is used to manage access for AWS workloads and services
C) It is used to centrally manage workforce access across multiple AWS accounts
D) It is used to manage IAM roles for EC2 instances
Correct Answer: C
Rationale: IAM Identity Center is used to centrally manage workforce access across multiple
AWS accounts. It is not for application end users (Cognito), AWS workloads (IAM roles), or
EC2 instance roles (IAM).
6. IAM Identity Center integrates with which AWS service to provide centralized access
management across multiple accounts?
, 4|Page
A) AWS Config
B) AWS CloudTrail
C) AWS Organizations
D) AWS Control Tower
Correct Answer: C
Rationale: IAM Identity Center integrates with AWS Organizations, which allows you to
configure your identity provider once and then grant access to existing and new accounts
managed in your organization. This integration is essential for multi-account access
management.
7. Which of the following is a key capability of IAM Identity Center?
A) Creating IAM users in each AWS account
B) Centrally managing access to multiple AWS accounts and applications
C) Managing access keys for programmatic access
D) Creating IAM roles for EC2 instances
Correct Answer: B
Rationale: IAM Identity Center provides centralized management of access to multiple AWS
accounts and applications. It avoids the need to create IAM users in each individual account.
8. For workforce access across multiple AWS accounts, which service is the default answer?
A) IAM
B) IAM Identity Center
C) Amazon Cognito
D) AWS Directory Service
Correct Answer: B
Rationale: For workforce access, the default answer is usually IAM Identity Center. It
provides centralized, MFA-friendly, multi-account access management. IAM is for individual
users within a single account, and Cognito is for application end users.
9. What is the relationship between IAM Identity Center and AWS Organizations?
A) IAM Identity Center replaces AWS Organizations
B) IAM Identity Center integrates with AWS Organizations to provide centralized access