Courseiva

SCS-C02 Identity and Access Management Practice Question

A company has a policy that requires all IAM users to use multi-factor authentication (MFA) to access the AWS Management Console. A user reports that they are unable to sign in even after configuring MFA. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The MFA device is not properly synchronized with AWS.

The most likely cause is that the MFA device is not properly synchronized with AWS. When an IAM user configures MFA, the device must be synchronized with AWS to generate valid tokens. If synchronization fails, the token entered during sign-in will be rejected, preventing console access. Option A is unlikely because if the policy explicitly denied console access, the user would not be able to sign in at all regardless of MFA, but the user specifically reported having configured MFA and still fails. Option B is incorrect because the root account does not require MFA for console access by default, and the user stated they are an IAM user. Option C is incorrect because MFA tokens do not expire; they are time-based and change every 30 seconds, but the token itself does not become permanently invalid after a period. The issue is synchronization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The IAM policy explicitly denies console access.

    Why it's wrong here

    An IAM policy that explicitly denies console access would produce a role-based denial after the user has authenticated, not a failure during MFA verification. AWS enforces MFA as a pre-authentication step, so the sign-in process never reaches IAM policy evaluation if the MFA code is rejected. Therefore, a policy deny could explain an “AccessDenied” page but not an error that the MFA code is invalid or a credential challenge failing.

  • ✗

    The user is using the root account instead of an IAM user.

    Why it's wrong here

    Signing in as the root account instead of an IAM user does not bypass MFA; the root user can have its own MFA device, and AWS strongly recommends applying MFA to root. If root has no MFA, it would simply not prompt for MFA, rather than prompting and then rejecting the entered token. The issue described is specifically a rejected MFA challenge, which points to the device or time synchronization, not to which account type is being used.

  • ✗

    The MFA token has expired.

    Why it's wrong here

    MFA tokens generated by TOTP (RFC 6238) are short-lived, usually 30 seconds, and are valid for only that single time step; they do not expire in the same way a password or access key does. If a user enters a previously used or stale code, AWS will reject it because it is outside the allowed time window, but this is a freshness or reuse problem, not a permanent expiration of the token. The fix is to use the current code shown in the authenticator app, not to wait out or renew an MFA token, so 'token has expired' is not a correct diagnostic.

  • ✓

    The MFA device is not properly synchronized with AWS.

    Why this is correct

    The most common cause of consistently rejected MFA codes is clock drift between the authenticator device and AWS’s TOTP server, so the 30-second time window computed by the device does not match AWS’s window. AWS compares the presented code with codes for the current time step and an allowed clock skew; if the device’s time is off by more than the skew, even a freshly generated code will fail. To fix this, synchronize the device clock (or re-register the MFA device), which is why 'MFA device is not properly synchronized with AWS' correctly describes the failure.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.