Courseiva

SCS-C02 Identity and Access Management Practice Question

An organization wants to enforce multi-factor authentication (MFA) for all IAM users who perform sensitive actions. Which condition key should be used in an IAM policy to require MFA?

⚠ Common exam trap

The trap is confusing 'aws:MultiFactorAuthPresent' with other condition keys like 'aws:SourceIp' or 'aws:CurrentTime', or not realizing that it only works with temporary credentials, leading to ineffective MFA enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aws:MultiFactorAuthPresent

The condition key 'aws:MultiFactorAuthPresent' is used in IAM policies to check whether the principal authenticated with MFA. When set to 'true' in a policy condition, it requires that the user has presented a valid MFA token for the request to be allowed, making it the correct choice for enforcing MFA on sensitive actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    aws:SourceIp

    Why it's wrong here

    The aws:SourceIp condition key evaluates the source IP address from which the AWS request originates, commonly used to restrict access to trusted networks such as a corporate VPN. However, it does not inspect any authentication factors; a user with only a valid password and no MFA token can still satisfy an IP-based policy. Therefore, using aws:SourceIp alone cannot enforce multi-factor authentication.

  • ✓

    aws:MultiFactorAuthPresent

    Why this is correct

    aws:MultiFactorAuthPresent is the correct global condition key because it is a Boolean request context key that indicates whether the principal authenticated with an MFA device. By adding a condition such as "Bool": {"aws:MultiFactorAuthPresent": "true"} to an IAM policy, administrators can require every matching request to come from a session that has completed MFA. This directly enforces the organization's MFA requirement and cannot be substituted by IP, client, or time-based checks.

  • ✗

    aws:UserAgent

    Why it's wrong here

    The aws:UserAgent condition key inspects the HTTP User-Agent header to identify the client software, such as a browser version or AWS SDK, but this value is client-supplied metadata that can be easily spoofed. It provides no information about whether a user presented an MFA code or used a hardware token. Restricting by User-Agent might block certain tools, but it has no bearing on the authentication factor actually used.

  • ✗

    aws:CurrentTime

    Why it's wrong here

    The aws:CurrentTime condition key provides the request timestamp and is intended for time-based restrictions, such as allowing access only during work hours or setting a policy expiration. It is not tied to the principal's credentials or authentication method, so it cannot reflect whether MFA was used. Even if a policy limits access to a specific time window, a user who authenticated with only a password would still be able to act during that window, making it an invalid mechanism for enforcing MFA.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.