Courseiva

SCS-C02 IAM Policy Conditions Practice Question

A security team needs to ensure that all IAM users in a production account use multi-factor authentication (MFA) before accessing the AWS Management Console. Which TWO steps should be taken? (Choose TWO.)

⚠ Common exam trap

This question asks to select two steps, but some candidates may incorrectly think there is a third correct step, such as configuring an IAM password policy or using AWS Config, but these do not enforce MFA for console access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable MFA for each IAM user.

To enforce MFA for console access, you need to enable MFA for each user (B) and attach an IAM policy that denies console access if MFA is not present (C). Option E is incorrect because the IAM password policy cannot require MFA; it only requires MFA for password changes, not console login. Option A is incorrect because AWS Config rules can detect users without MFA but cannot enforce it. Option D is incorrect because SCPs apply to accounts, not individual user console access; they cannot directly require MFA for console login.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Config rules to detect users without MFA.

    Why it's wrong here

    AWS Config rules such as iam-user-mfa-enabled assess whether each IAM user has an MFA device configured and report the account's compliance status, but they are purely detective controls. They do not intercept authentication requests or prevent a user from logging in without MFA; they only generate evaluation results and can trigger remediation actions that are not native to the login flow. Relying solely on Config leaves the unprotected access vectors open until manual or automated remediation completes, so this option does not ensure MFA enforcement for console access.

  • ✓

    Enable MFA for each IAM user.

    Why this is correct

    Enabling MFA for each IAM user is the foundational prerequisite because AWS IAM does not automatically assign MFA devices. An administrator must manually activate a virtual or hardware MFA device for every user, and without this step no conditional policy can ever evaluate successfully because the MFA condition would always be false. This direct action ensures the compliance goal is met at the source, not just enforced at login.

  • ✓

    Attach an IAM policy that denies console access if MFA is not present.

    Why this is correct

    Attaching an IAM policy that denies actions when aws:MultiFactorAuthPresent is false is a standard and effective enforcement mechanism. For console access, you can create a Deny statement for the aws:ConsoleLogin action or for all console actions with the condition "aws:MultiFactorAuthPresent": "false", which blocks the sign-in or immediately denies session actions until MFA is verified. This policy compels users to enroll in MFA because they cannot access the console without presenting a valid MFA code, thereby aligning perfectly with the goal of ensuring all users have MFA enabled.

  • ✗

    Apply an SCP that requires MFA for console access.

    Why it's wrong here

    SCPs in AWS Organizations apply to all principal requests for account-level AWS service API actions, but they do not govern the IAM console login event itself. The login request is processed by IAM's authentication system before any SCP is evaluated, and the SCP cannot inspect the user's MFA session state to deny the initial sign-in. At best, an SCP could deny subsequent API actions when MFA is absent, but it cannot prevent a non-MFA user from completing console authentication, making it an incomplete and incorrect solution.

  • ✗

    Configure an IAM password policy to require MFA.

    Why it's wrong here

    The IAM password policy exclusively governs password requirements such as length, rotation, and complexity, and its MFA-related setting only mandates that users provide MFA when changing their own passwords. It does not apply to the initial console login process, so a user could still sign in without MFA as long as they know their password. Thus, configuring the password policy to require MFA for password changes has no effect on console access enforcement.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.