Courseiva

Enforce MFA for IAM Users

A company wants to enforce that all IAM users in an AWS account must have multi-factor authentication (MFA) enabled. Which AWS service can be used to automatically detect and remediate non-compliant users?

⚠ Common exam trap

SCS-C02 often tests the difference between services that only detect (Trusted Advisor, Access Analyzer, CloudTrail) and services that both detect and remediate (AWS Config with remediation actions) — candidates pick Trusted Advisor because it sounds like a security advisor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config

AWS Config continuously records resource configurations and evaluates them against rules. A managed rule such as 'iam-user-mfa-enabled' detects IAM users without MFA, and Config remediation actions (via SSM Automation documents) can automatically enforce MFA or disable non-compliant users. This gives both detection and automated remediation in a single service, matching the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor includes a security check called 'MFA on Root Account', not a check that every IAM user has MFA enabled. It evaluates only the root user's MFA status and reports it as a recommendation, with no API or action that can automatically remediate an IAM user's missing MFA. Therefore, it does not satisfy the requirement to enforce MFA for all IAM users.

  • ✗

    AWS IAM Access Analyzer

    Why it's wrong here

    IAM Access Analyzer analyzes resource-based policies (such as S3 bucket policies or KMS key policies) for external principal access, so it can reveal when an IAM role or bucket policy is shared outside the account, but it cannot evaluate an IAM user's authentication settings or whether that user has enrolled an MFA device. It produces findings and does not remediate. Thus it is irrelevant to enforcing MFA on all IAM users.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    CloudTrail is an audit and evidence service; it records the user, event time, source IP, and API action for every call made in the account, but it does not compare IAM configurations to a desired state and cannot enforce or remediate anything. A trail may capture Deny logs when MFA conditions reject a request, but it can never require users to have MFA registered. So CloudTrail is useful for forensic review but not for enforcement.

  • ✓

    AWS Config

    Why this is correct

    AWS Config continuously evaluates resources such as AWS::IAM::User against managed rules, and the iam-user-mfa-enabled rule specifically designates IAM users without a registered MFA device as noncompliant. Config can then invoke an AWS Systems Manager Automation document or a custom remediation action to remediate noncompliant IAM users, making it the only listed service that can both detect and act on missing MFA across all IAM users.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.