What's changed: Deepened SCS-C02 Chapter 4 (added comparison tables, scenarios, FAQs, exam traps, deep-dive paragraphs to each section; localized figures to Japanese)
4.4In-scope services for identity and access management
A roundup of in-scope SCS-C03 services for identity and access management.
4.4.1In-scope services for identity and access management
For identity and access management, beyond IAM/IAM Identity Center/STS/AssumeRole, know: Amazon Cognito (end-user authentication for web/mobile apps), AWS Directory Service (managed Active Directory), and Amazon Verified Permissions (externalize application authorization with the Cedar policy language).
4.4.2Section summary
- Auth/directory: Cognito (app user auth) / Directory Service (managed AD)
- Externalized authz: Verified Permissions (fine-grained authz via Cedar)
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. Which service decouples authorization from app code and centrally manages fine-grained access control with the Cedar policy language?
Q2. Which provides sign-up/sign-in and a user directory for end users of web/mobile apps?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

