Enforce MFA Using Service Control Policies
A company wants to enforce that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. Which policy should be attached to the IAM users or group to enforce this requirement?
⚠ Common exam trap
SCS-C02 often tests the difference between Allow and Deny in IAM policies, and candidates may incorrectly choose an Allow with a condition, not realizing that an explicit Deny is required to enforce MFA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deny access if MFA is not present
The correct policy is to explicitly deny access when MFA is not present. In IAM, an explicit Deny overrides any Allow, so attaching a policy with a Deny statement conditioned on 'aws:MultiFactorAuthPresent' being false ensures that users without MFA are blocked from accessing the console. This is the standard pattern to enforce MFA because it cannot be bypassed by other permissive policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allow access if MFA is present
Why it's wrong here
An allow statement with a condition that checks for MFA presence grants access only when the condition evaluates to true. However, when the condition is false because MFA is absent, the allow statement simply does not apply; it does not deny the request. If another policy grants the same action without the MFA condition, the user can still proceed, so this approach does not enforce MFA.
- ✓
Deny access if MFA is not present
Why this is correct
An explicit deny statement using the condition 'aws:MultiFactorAuthPresent' equals 'false' will reject any IAM user request that did not authenticate with MFA. Because AWS IAM evaluation logic gives explicit deny precedence over every allow, this pattern universally blocks non-MFA access while still permitting MFA-authenticated requests. Correctly scoped, this is the standard and reliable way to enforce MFA across all users, including those with other grants.
- ✗
Deny access if MFA is present
Why it's wrong here
This policy denies access precisely when MFA is present, meaning users who comply with MFA are blocked from the resource. Users without MFA are not explicitly denied here, so they may still be allowed through other policy statements that grant actions unconditionally. It inverts the intended security control and would effectively prevent all compliant users from working.
- ✗
Grant access with a condition requiring MFA
Why it's wrong here
A grant that uses a condition requiring MFA only authorizes requests that arrive with a valid MFA session, but it does not issue an explicit denial for requests lacking MFA. Without a corresponding deny statement, any other allow policy that applies to the same user and action can bypass the condition, leaving a gap in enforcement. This is a permissive check, not a mandatory control, so it cannot guarantee all IAM users adopt MFA.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.