Courseiva
Security and Compliance →easyMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company has a security policy requiring that all IAM users use multi-factor authentication (MFA) to access the AWS Management Console. The DevOps engineer needs to enforce this policy. What is the simplest way to achieve this?

⚠ Common exam trap

DOP-C02 often tests the difference between IAM policy conditions and service-specific features, tricking candidates into picking Cognito or S3 MFA Delete when the question is about IAM user console MFA enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an IAM policy that denies all actions unless MFA is present, and attach it to all IAM users or groups.

The simplest enforcement is an IAM policy that denies all actions unless the request is made with MFA, attached to users or groups. This uses the aws:MultiFactorAuthPresent condition key in a Deny statement, which blocks console and API access for users who have not authenticated with MFA. It is a native IAM mechanism requiring no additional services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Amazon Cognito to require MFA for console access.

    Why it's wrong here

    Amazon Cognito user pools provide MFA for application end users, not for AWS Identity and Access Management (IAM) users. IAM users are authenticated by IAM itself, and Cognito identity pools can only exchange federated identities for temporary AWS credentials—they cannot enforce MFA on native IAM users' console logins or API calls. Thus, this approach does not meet a security policy requiring MFA for all IAM users.

  • ✓

    Create an IAM policy that denies all actions unless MFA is present, and attach it to all IAM users or groups.

    Why this is correct

    Create an IAM policy that uses the 'aws:MultiFactorAuthPresent' condition key to deny actions when MFA is not present, for example: 'Condition': {'Bool': {'aws:MultiFactorAuthPresent': 'false'}}. Attach this policy to all IAM users or groups so that any API call made without MFA is rejected, while requests made with MFA succeed. This enforces MFA globally across all AWS services for the attached identities. Be sure to grant users permission to manage their own MFA devices beforehand to avoid lockout.

  • ✗

    Enable MFA delete on the root account.

    Why it's wrong here

    MFA Delete is an Amazon S3 bucket feature that mandates MFA for critical S3 operations like permanently deleting object versions or changing bucket versioning state. It is configured at the S3 bucket level, not on the root account, and it provides zero control over IAM user console sign-ins or API actions outside S3. Therefore, enabling it does nothing to enforce MFA for all IAM users as the security policy requires.

  • ✗

    Enable MFA on the S3 bucket policy.

    Why it's wrong here

    An S3 bucket policy is a resource-based policy that can include the 'aws:MultiFactorAuthPresent' condition to require MFA when accessing a specific bucket, but it is scoped solely to S3 resources. It cannot be 'enabled' to enforce authentication for IAM users, and it has no effect on console logins, IAM operations, or other AWS services. MFA enforcement for all API calls must be done through identity-based IAM policies, not resource policies.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.