Courseiva
Security →easyMultiple Select

DVA-C02 Security Practice Question

A company wants to enforce multi-factor authentication (MFA) for all IAM users accessing the AWS Management Console. Which THREE actions are required?

⚠ Common exam trap

Candidates often think that password policies can enforce MFA, but AWS IAM password policies only control password complexity, expiration, and reuse. They cannot enforce MFA. Similarly, while SCPs can deny actions without MFA at the Organization level, they do not configure or enable MFA for individual IAM users.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Instruct users to use their MFA device when logging in

Option D is correct because MFA must first be enabled/assigned for each IAM user (via the IAM console, CLI, or API, associating a virtual or hardware MFA device) before it can be enforced. Option A is correct because users must actually supply the MFA code at sign-in; the AWS Management Console login flow prompts for the MFA token after the password, and without that second factor the session cannot be established. Option E is correct because an IAM policy using the aws:MultiFactorAuthPresent condition key (typically with a Deny statement, e.g., denying all actions when aws:MultiFactorAuthPresent is false) enforces MFA programmatically for console access. Option B is not correct because a password policy controls password complexity, length, reuse, and expiration—it has no MFA enforcement capability. Option C is not correct because SCPs apply only to AWS Organizations accounts (setting permission guardrails) and do not enforce MFA for individual IAM users in a single account.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Instruct users to use their MFA device when logging in

    Why this is correct

    This option describes the user's required action once MFA is properly configured and enforced. After an MFA device is associated with an IAM user and an IAM policy requires its use, users must actively provide the time-based one-time password (TOTP) from their virtual or hardware MFA device during the authentication process to successfully log into the AWS Management Console or make API calls. This is the final step in the MFA workflow from the user's perspective.

  • ✗

    Configure a password policy that requires MFA

    Why it's wrong here

    AWS IAM password policies are designed to enforce specific requirements for IAM user passwords, such as minimum length, character complexity (uppercase, lowercase, numbers, symbols), and rotation periods. These policies are strictly limited to password attributes and do not include any functionality or condition to mandate or check for the presence of Multi-Factor Authentication during user login. Therefore, configuring a password policy cannot enforce MFA.

  • ✗

    Create a service control policy (SCP) to enforce MFA

    Why it's wrong here

    Service Control Policies (SCPs) are a feature of AWS Organizations used to manage permissions across multiple AWS accounts. SCPs define the maximum available permissions for accounts within an Organizational Unit (OU) or the entire organization, acting as guardrails at the account level. They cannot directly enforce user-specific authentication mechanisms like MFA for individual IAM users or roles within those accounts, as their scope is at the account boundary, not the principal level.

  • ✓

    Enable MFA for each IAM user

    Why this is correct

    Enabling MFA for each IAM user involves the administrative step of associating a virtual MFA device (like Google Authenticator) or a hardware MFA device (like a YubiKey) with an individual IAM user account. This action registers the MFA device with the user's identity, making it available for use. While this is a crucial prerequisite, it does not, by itself, *enforce* the use of MFA; a separate IAM policy is required to mandate its presentation during authentication.

  • ✓

    Create an IAM policy that denies access unless MFA is present

    Why this is correct

    An IAM policy is the primary mechanism to enforce MFA usage by leveraging the `aws:MultiFactorAuthPresent` condition key within a `Deny` statement. This policy, when attached to an IAM user, group, or role, will explicitly block access to specified AWS services or actions if the user's authentication context does not include proof of MFA. This ensures that users must authenticate with their MFA device to perform sensitive operations or even log in.

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.