Domain 4 · 16% of Exam

Identity & Access Management

Design and implement identity solutions, access controls, and permission management across AWS accounts.

About This Domain

Domain 4 — Identity & Access Management — accounts for 16% of the SCS-C02 certification exam. This domain evaluates your understanding of implement least-privilege access with iam policies and permission boundaries, design cross-account access patterns with iam roles and resource policies, implement identity federation (saml, oidc, iam identity center), and related concepts. Design and implement identity solutions, access controls, and permission management across AWS accounts. To pass this section you need practical knowledge of how these services and patterns work together in real-world architectures.

What You'll Be Tested On

  • Implement least-privilege access with IAM policies and permission boundaries
  • Design cross-account access patterns with IAM roles and resource policies
  • Implement identity federation (SAML, OIDC, IAM Identity Center)
  • Configure Cognito for application authentication and authorization
  • Analyze and remediate overly permissive access with Access Analyzer

Key AWS Services in This Domain

Study Strategy for Domain 4

While 16% might seem like a smaller portion of the exam, every point counts toward the passing score. Focus on understanding core concepts and common exam scenarios for this domain. Don't neglect it — even a few missed questions here can make the difference between pass and fail.

Exam Tips for Domain 4

💡

Know IAM policy evaluation logic: explicit deny → SCP → permission boundary → identity policy → resource policy

💡

Understand the difference between identity-based and resource-based policies

💡

Practice designing cross-account access for common scenarios

Frequently Asked Questions

How many questions on the SCS-C02 exam come from Domain 4?

Domain 4 (Identity & Access Management) makes up 16% of the SCS-C02 exam. The exam has 65 scored questions, so approximately 10 questions will come from this domain.

What services should I focus on for Domain 4?

The key services for this domain include IAM, IAM Identity Center, Cognito, Organizations. Make sure you understand how each service works, its use cases, and how they integrate with one another.

How should I prepare for Identity & Access Management questions?

Start by reviewing the key topics listed above, then practice with domain-specific questions. Focus on understanding real-world scenarios rather than memorizing facts. Use our practice quizzes to test your knowledge and review explanations for any questions you get wrong.

What's the best order to study the SCS-C02 domains?

Many candidates start with the highest-weighted domains first. For the SCS-C02 exam, the domains in order of weight are: Threat Detection & Incident Response (14%), Security Logging & Monitoring (18%), Infrastructure Security (20%), Identity & Access Management (16%), Data Protection (18%), Management & Security Governance (14%). However, start with whichever domain aligns best with your existing experience.

Practice Domain 4 Questions

Test your knowledge of Identity & Access Management with practice questions from our SCS-C02 question bank.

Start Practice Quiz →

Other SCS-C02 Domains