SCS-C02 Identity and Access Management Practice Question
A company wants to enforce that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. Which THREE steps should the company take?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an IAM policy that denies all actions if aws:MultiFactorAuthPresent is false.
The correct steps are to enable MFA for each IAM user (E), create an IAM policy that denies all actions if `aws:MultiFactorAuthPresent` is false (A), and attach the policy to all IAM users or groups (C). Enabling MFA per user is a prerequisite. The policy enforces MFA usage by denying API calls when MFA is not present. Attaching the policy ensures it applies to users. Option B (CloudTrail) is for auditing, not enforcement. Option D (password policy) does not enforce MFA for console access; it only sets password requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an IAM policy that denies all actions if aws:MultiFactorAuthPresent is false.
Why this is correct
This is the correct foundational enforcement mechanism: a Deny statement with a Bool condition on aws:MultiFactorAuthPresent. When the key evaluates to "false", the request is denied, so any API or console action by a user who did not authenticate with MFA fails. The policy can be scoped with NotAction to permit MFA self-management tasks, ensuring users can enroll without being locked out. This condition-based denial is what actually enforces MFA, unlike audit-only measures.
- ✗
Enable CloudTrail to monitor MFA usage.
Why it's wrong here
Enabling CloudTrail is an audit control, not a preventive one: it records management events, including whether MFA was present, but it never intercepts or blocks API calls. CloudTrail logs are useful for post-incident forensics and compliance reporting, yet they do not stop a user with missing MFA from performing actions. Therefore, it is an incorrect solution because it does not in any way force MFA usage at the time of the request.
- ✓
Attach the MFA enforcement policy to all IAM users or groups.
Why this is correct
Simply authoring the denial policy has no effect until it is attached to IAM principals; an unattached policy exists only as a JSON object in your account. By attaching it to all IAM users and groups, you ensure the condition is evaluated for every request made by those identities. This is a required implementation step alongside creating the policy, and group attachment also means new users automatically inherit the enforcement. Without this binding, the policy is inert and cannot influence authorization.
- ✗
Set the password policy to require MFA.
Why it's wrong here
The IAM password policy controls only password characteristics — minimum length, complexity, rotation, and reuse — and does not include a setting for MFA. IAM does not allow password policies to require MFA or to govern authentication factors beyond the password. Consequently, configuring the password policy for MFA is impossible, so this cannot satisfy the enforcement requirement.
- ✓
Enable MFA for each IAM user.
Why this is correct
Enabling MFA on each user is necessary because without an assigned, synced MFA device, the user cannot produce the second factor required by the Deny policy; otherwise they would be permanently denied access. This step involves creating or assigning a virtual or hardware MFA device and having the user complete the activation. It alone does not enforce MFA for API calls unless paired with the denial condition policy, so it is a per-user precondition rather than the enforcement rule.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.