Instiq
Chapter 4 · Identity and Access Management·v2.0.0·Updated 6/5/2026·~8 min

What's changed: Deepened SCS-C02 Chapter 4 (added comparison tables, scenarios, FAQs, exam traps, deep-dive paragraphs to each section; localized figures to Japanese)

4.4In-scope services for identity and access management

Key points

A roundup of in-scope SCS-C03 services for identity and access management.

4.4.1In-scope services for identity and access management

For identity and access management, beyond IAM/IAM Identity Center/STS/AssumeRole, know: Amazon Cognito (end-user authentication for web/mobile apps), AWS Directory Service (managed Active Directory), and Amazon Verified Permissions (externalize application authorization with the Cedar policy language).

Diagram grouping app authentication (Amazon Cognito), directory (AWS Directory Service / managed AD), and externalized authorization (Amazon Verified Permissions / Cedar).
Identity/access management services

4.4.2Section summary

  • Auth/directory: Cognito (app user auth) / Directory Service (managed AD)
  • Externalized authz: Verified Permissions (fine-grained authz via Cedar)

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.