AWS Certified Security – Specialty (SCS-C02) — Question 59

A company needs a security engineer to implement a scalable solution for multi-account authentication and authorization. The solution should not introduce additional user-managed architectural components. Native AWS features should be used as much as possible. The security engineer has set up AWS Organizations with all features activated and AWS IAM Identity Center (AWS Single Sign-On) enabled.
Which additional steps should the security engineer take to complete the task?

Answer options

Correct answer: B

Explanation

The correct answer is B because using the IAM Identity Center default directory allows for a streamlined approach to managing users and groups without requiring additional components. Options A, C, and D involve either unnecessary complexity or do not utilize the IAM Identity Center effectively, which is crucial for the scalable solution needed.