SCS-C02 Identity and Access Management Practice Question
A company wants to enforce that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. The security team creates an IAM policy that denies all actions unless MFA is present. However, users report they can still perform actions without MFA. What is the most likely reason for this?
⚠ Common exam trap
The trap here is assuming that simply creating a policy with a deny statement automatically enforces MFA, when in fact the policy must include the correct MFA condition key and be properly attached.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy does not include a condition to check for MFA, or the condition is incorrect.
The most likely reason is that the policy does not include a condition to check for MFA, or the condition is incorrect. To enforce MFA, the policy must include a Deny statement with a condition like 'aws:MultiFactorAuthPresent': 'false' or 'true' depending on the logic. If the condition is missing, the deny will not be effective. It is also important to ensure the policy is attached to all users or groups.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MFA policies only apply to API calls, not console access.
Why it's wrong here
This is incorrect. IAM policies with MFA conditions apply to both console and API access. The aws:MultiFactorAuthPresent condition is set to true when the user has authenticated with MFA, regardless of the access method. There is no distinction that would exempt console access. So this statement is false and not the reason for the issue.
- ✓
The policy does not include a condition to check for MFA, or the condition is incorrect.
Why this is correct
This is the most likely reason. To enforce MFA, the policy must include a condition such as 'aws:MultiFactorAuthPresent': 'true' in a Deny statement. If the condition is missing or misspelled, the deny will not trigger. Additionally, the condition must be in a policy that applies to the users' actions. Often, administrators forget to include the condition or use the wrong key, allowing actions without MFA.
- ✗
The users are using root account credentials, which bypass MFA policies.
Why it's wrong here
Root account credentials are not subject to IAM policies, so if users were using the root account, the policy would not apply. However, the scenario specifies IAM users, not the root user. It is unlikely that all users have root credentials. While root bypasses MFA policies, this is not the most likely reason given the scenario focuses on IAM users.
- ✗
The policy was attached to the wrong IAM group.
Why it's wrong here
If the policy were attached to the wrong group, it might not apply to the users. However, this is a possible but less likely cause compared to other issues. The question states the security team creates an IAM policy, but does not specify attachment. The most common reason for MFA policies failing is that the policy does not account for all actions or is not attached to the right entities, but the scenario implies the policy is in place yet users can still act. Attaching to the wrong group is a plausible distractor but not the primary technical reason.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.