Security, Identity, and Compliance
CoreAWS IAM Identity Center
Explicit secure multi-account workforce-access example.
Key points
- IAM Identity Center maps workforce users and groups through permission sets to accounts.
Best-known use cases
- D4.1, D4.2, and D5.1: assign or troubleshoot named workforce access across the intended AWS accounts.
What candidates often confuse it with
- Identity Center manages workforce account access; IAM roles provide temporary sessions for workloads and other principals.
Key takeaway
Trace the user or group, permission set, account assignment, session, and applicable guardrails for an access failure.
Related services
- AWS Certificate Manager (ACM)
- Amazon EC2 security groups
- Egress-only internet gateways
Relevant exam tasks
- D4.1 — Task 4.1: Implement and manage security and compliance tools and policies.
- 4.1.1 — Implement IAM features (for example, password policies, multi-factor authentication [MFA], roles, federated identity, resource policies, policy conditions).
- D4.2 — Task 4.2: Implement strategies to protect data and infrastructure.
- 4.2.1 — Implement and enforce a data classification scheme.
- D5.1 — Task 5.1: Implement and optimize networking features and connectivity.
- 5.1.1 — Configure a VPC (for example, subnets, route tables, network ACLs, security groups, NAT gateways, internet gateway, egress-only internet gateway).