Courseiva
Security →hardMultiple Choice

DVA-C02 Security Practice Question

An organization wants to enforce that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. The security team needs to deny any console access if MFA is not enabled. Which IAM policy statement should be used?

⚠ Common exam trap

Many exam-takers confuse 'Deny' with 'Allow' logic or misuse 'BoolIfExists' thinking it handles missing keys, but for console access the key is always present, so 'Bool' is required to correctly enforce the denial.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deny action '*' if 'aws:MultiFactorAuthPresent' is false.

It uses a Deny statement with the condition 'aws:MultiFactorAuthPresent' set to 'false', which explicitly blocks any action when MFA is not present. This is the standard approach to enforce MFA for console access, as it overrides any Allow policies by default. The Deny effect ensures that even if other policies grant access, the lack of MFA results in denial.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deny action '*' unless 'aws:MultiFactorAuthPresent' is true.

    Why it's wrong here

    This statement denies action '*' unless the aws:MultiFactorAuthPresent condition evaluates to true, which means it blocks every action for users who HAVE authenticated with MFA and permits nothing for users without it either since Deny with a negated condition on a boolean key produces the opposite enforcement logic from what the requirement needs, effectively locking out MFA users too.

  • ✓

    Deny action '*' if 'aws:MultiFactorAuthPresent' is false.

    Why this is correct

    Because the aws:MultiFactorAuthPresent key is always populated with a true or false value during Management Console sign-in, a Deny statement using Bool with the condition set to false correctly and directly blocks every console action for any session that did not authenticate with MFA, which is exactly the explicit-deny enforcement the security team requires.

  • ✗

    Deny action '*' if 'aws:MultiFactorAuthPresent' is false using BoolIfExists.

    Why it's wrong here

    BoolIfExists is designed to still apply the Deny if the condition key is missing from the request context by treating it as satisfying the condition, but its purpose is to handle keys that might be absent; using it here is unnecessary and, depending on how it evaluates an explicitly-present false value versus a missing key, risks not producing the strict guaranteed denial that a plain Bool operator gives for a key that is always present.

  • ✗

    Allow action '*' if 'aws:MultiFactorAuthPresent' is true.

    Why it's wrong here

    An Allow statement conditioned on MFA being true only grants extra permissions to sessions that already used MFA; it contains no Deny logic whatsoever, so a user who signs in without MFA is simply left with whatever other Allow statements exist elsewhere in their policies, meaning console access without MFA is never explicitly blocked.

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.