Courseiva

SCS-C02 Identity and Access Management Practice Question

An organization wants to enforce multi-factor authentication (MFA) for all IAM users accessing the AWS Management Console. Which policy should be used?

⚠ Common exam trap

Test-takers frequently confuse the condition key evaluation — thinking a policy that 'allows when MFA is present' is sufficient, but without an explicit Deny for when MFA is absent, other policies could still grant access, making the enforcement incomplete.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A policy that denies all actions unless aws:MultiFactorAuthPresent is true.

It uses an IAM policy with a Deny effect on all actions when `aws:MultiFactorAuthPresent` is false (or not true). This ensures that any IAM user attempting to perform any action, including ConsoleLogin, must have authenticated with MFA; otherwise, the request is denied. This is the standard approach to enforce MFA for all AWS Management Console access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A policy that allows all actions and denies when aws:MultiFactorAuthPresent is true.

    Why it's wrong here

    This policy inverts the requirement: it places an explicit Deny on actions only when aws:MultiFactorAuthPresent is true, so users who have correctly authenticated with MFA are blocked, while requests without MFA do not match the deny condition and would fall through to the Allow all actions statement. Because explicit Deny overrides Allow, this actively breaks MFA enforcement rather than achieving it. The condition key must be used to deny when the value is false or absent, not when it is true.

  • ✗

    A policy that allows all actions except ConsoleLogin unless MFA is present.

    Why it's wrong here

    This approach confuses a CloudTrail console-login event with an IAM action: ConsoleLogin is not a valid action key in an IAM policy, and IAM policies authorize API, CLI, and SDK operations. Even if it were valid, restricting only the console sign-in would leave every programmatic request (for example, s3:PutObject or ec2:RunInstances) free to proceed without MFA. MFA enforcement must be applied to all actions via a condition key such as aws:MultiFactorAuthPresent, not to a single sign-in event.

  • ✗

    A policy that allows all actions when aws:MultiFactorAuthPresent is true.

    Why it's wrong here

    An Allow statement conditioned on aws:MultiFactorAuthPresent being true only permits actions when that condition is satisfied; it does nothing to stop access when the key is false or missing, because IAM's default-deny can be overridden by any other allowed policy attached to the same principal. In other words, if another statement grants the same action without the MFA condition, the request is allowed even without MFA. Enforcement requires an explicit Deny with a Bool or BoolIfExists condition so that no other policy can grant access.

  • ✓

    A policy that denies all actions unless aws:MultiFactorAuthPresent is true.

    Why this is correct

    This is the correct enforcement pattern: a Deny statement with the condition aws:MultiFactorAuthPresent equal to false (or using BoolIfExists to treat a missing key as false) explicitly blocks every action from principals that did not use MFA. Because explicit Deny statements take precedence over any Allow, attaching this policy ensures no other policy can accidentally allow unauthenticated-with-MFA access. This is the standard AWS-recommended way to enforce MFA across all AWS API actions.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.