SCS-C02 Management and Security Governance Practice Question
A company wants to ensure that all IAM users have multi-factor authentication (MFA) enabled. Which AWS service can be used to detect users without MFA and automatically send a notification?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
AWS Config is the correct answer because it provides a managed rule 'iam-user-mfa-enabled' that can evaluate whether IAM users have MFA enabled. When a non-compliant user is detected, AWS Config can trigger an SNS notification to alert administrators. AWS Trusted Advisor (option A) only checks MFA on the root account, not all IAM users. AWS CloudTrail (option B) records API activity but does not evaluate configuration rules. AWS IAM (option D) itself does not have automatic detection and notification capabilities for MFA status.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Trusted Advisor
Why it's wrong here
AWS Trusted Advisor provides a security check that verifies whether the root account has MFA enabled, but its standard checks do not scan every IAM user and report whether each one has an MFA device assigned. Trusted Advisor is an advisory service focused on cost optimization, performance, resilience, service limits, and a limited set of security best practices; it lacks a customizable rule engine for account-wide IAM user compliance. Therefore it cannot continuously evaluate and alert when any IAM user is missing MFA.
- ✗
AWS CloudTrail
Why it's wrong here
CloudTrail records IAM API events such as CreateVirtualMFADevice, EnableMFADevice, and DeactivateMFADevice, providing an audit trail of actions that change MFA status. However, it does not maintain or compare the current configuration of every IAM user against a desired state, so it cannot directly tell you whether all users currently have MFA enabled without complex log analysis. Because CloudTrail is not a configuration evaluation service, it will not generate a notification simply because an IAM user is noncompliant with MFA policy.
- ✓
AWS Config
Why this is correct
AWS Config continuously records configuration items for IAM users and supports the managed rule iam-user-mfa-enabled, which evaluates whether each IAM user has MFA enabled and marks noncompliant users in the Config dashboard. When a user becomes noncompliant, Config can publish evaluation results to Amazon SNS, triggering notifications or automated remediation via Systems Manager Automation. It also provides configuration history and snapshots so you can audit MFA status over time, making it the correct service for continuously verifying that all IAM users have multi-factor authentication.
- ✗
AWS IAM
Why it's wrong here
Within the IAM service you can manually view which users have MFA devices via the console's Users page or by calling ListMFADevices, but this requires a human or a custom script to inspect each IAM user individually. The IAM service has no built-in scheduled checks, compliance rules, or notification mechanism to alert you when an IAM user lacks MFA. IAM is designed to define identities, policies, and permissions, not to assess account-wide configuration against a security baseline, so it cannot automatically ensure that all users have MFA enabled.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.