A development team uses AWS CodeCommit across multiple AWS accounts and is growing to include remote developers. The company must provide secure access to the repositories for these developers while minimizing operational overhead. Which solution best meets this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Use AWS IAM Identity Center (SSO) permission sets to grant developers access to the multiple accounts..
Why this is the answer
AWS IAM Identity Center (SSO) is the best solution because it centralizes access management across multiple AWS accounts and integrates with existing identity providers, simplifying user provisioning and access control. Permission sets allow you to define a common set of permissions once and apply them to multiple accounts, significantly reducing operational overhead. Developers can then use a single set of credentials to access CodeCommit repositories in different accounts. Creating individual IAM roles for each developer across multiple accounts would be cumbersome and increase operational overhead. Distributing AWS access keys is insecure and difficult to manage at scale. While public SSH keys can be used for CodeCommit, managing them for a growing team across multiple accounts is less efficient than using IAM Identity Center's centralized approach.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed