SCS-C02 Identity and Access Management Practice Question
An organization wants to enforce that all IAM users must use MFA to access the AWS API. Which TWO steps should be taken?
⚠ Common exam trap
SCS-C02 often tests the misconception that SCPs or password policies can enforce MFA for IAM users, when in fact only IAM policies with the aws:MultiFactorAuthPresent condition key (attached to users/groups) achieve API-level MFA enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach the policy to all IAM users or to a group that all users belong to.
Option B is correct because an IAM policy that enforces MFA must actually be attached to the principals it should affect — either directly to each IAM user or, more manageably, to a group that all users belong to, so the deny-unless-MFA condition is evaluated for their API calls. Option C is correct because the standard way to enforce MFA on API access is an IAM policy with a Deny effect on all actions ("*") guarded by a condition such as "aws:MultiFactorAuthPresent": "true" (typically combined with a BoolIfExists or Null check to handle cases where the key is absent), which blocks any request not made with MFA-authenticated credentials. Option A is not required: rotating access keys improves key hygiene but does not enforce MFA on API calls. Option D is wrong because the account password policy controls password complexity, length, and rotation for console sign-in, not MFA requirements for API access. Option E is wrong because SCPs only apply to accounts within AWS Organizations and cannot require MFA for individual IAM users' API calls; MFA enforcement for users is done with IAM policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rotate all IAM user access keys.
Why it's wrong here
Rotating access keys simply invalidates old keys and issues new ones; it is a credential lifecycle process, not an access control mechanism. Even after rotation, a user can still sign API requests with the new access key and never present an MFA token, so MFA is not enforced. MFA enforcement requires a conditional statement that examines the aws:MultiFactorAuthPresent context key before allowing or denying the action.
- ✓
Attach the policy to all IAM users or to a group that all users belong to.
Why this is correct
Attaching the MFA enforcement policy to every IAM user, or to a group that all users belong to, is the required deployment step: IAM policies have no effect until they are attached to an identity. Using a group is the most maintainable approach because new users added to the group automatically receive the policy, and it prevents individual users from being missed. This distribution is what makes the deny-unless-MFA condition universally enforced across the account.
- ✓
Create an IAM policy with a condition that denies all actions unless aws:MultiFactorAuthPresent is true.
Why this is correct
Create an IAM policy statement with Effect: Deny and a condition such as BoolIfExists aws:MultiFactorAuthPresent = false; this denies every action when the request did not originate from a session that satisfied MFA. Using BoolIfExists ensures that requests missing the context key are treated as false and denied, preventing an attacker from bypassing by omitting the key. This policy, when attached to all users or the group, is the actual enforcement mechanism for an MFA requirement.
- ✗
Configure the account password policy to require MFA.
Why it's wrong here
The IAM account password policy controls console login parameters such as minimum length, required character classes, expiration, and password reuse, and it has no setting to require MFA. Even if a password policy exists, users can use IAM access keys for API calls without ever entering an MFA code. MFA enforcement must be done with a policy condition; password policy is orthogonal to API access and to MFA status.
- ✗
Create a service control policy (SCP) that requires MFA for all API calls.
Why it's wrong here
SCPs do not work for this scenario. An SCP is an organization-level guardrail that applies only to member accounts in AWS Organizations, and it cannot constrain IAM principals in the management account where the organization is rooted. Moreover, an SCP cannot 'require MFA' by itself—it can only deny API calls based on conditions for identities in member accounts; the organization would still need to attach the conditional IAM policy to all IAM users in the current account.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.