Chapter 4 · Identity and Access Management·v2.0.0·Updated 6/5/2026·~8 min
What's changed: Deepened SCS-C02 Chapter 4 (added comparison tables, scenarios, FAQs, exam traps, deep-dive paragraphs to each section; localized figures to Japanese)
4.4In-scope services for identity and access management
Key points
A roundup of in-scope SCS-C03 services for identity and access management.
4.4.1In-scope services for identity and access management
For identity and access management, beyond IAM/IAM Identity Center/STS/AssumeRole, know: Amazon Cognito (end-user authentication for web/mobile apps), AWS Directory Service (managed Active Directory), and Amazon Verified Permissions (externalize application authorization with the Cedar policy language).
4.4.2Section summary
- Auth/directory: Cognito (app user auth) / Directory Service (managed AD)
- Externalized authz: Verified Permissions (fine-grained authz via Cedar)
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

