IAM MFA BoolIfExists Condition: Password Change Failure Due to Missing Key
Exhibit
Refer to the exhibit.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Deny",
"Action": "*",
"Resource": "*",
"Condition": {
"BoolIfExists": {
"aws:MultiFactorAuthPresent": "false"
}
}
},
{
"Effect": "Allow",
"Action": "iam:ChangePassword",
"Resource": "*"
}
]
}An IAM policy is attached to a user. The user is trying to change their own password in the IAM console but receives an 'Access Denied' error. The user has an MFA device configured and is logged in with MFA. Why is the password change failing?
Quick Answer
The correct answer is that the Deny statement uses the `BoolIfExists` condition operator, which evaluates to true when the `aws:MultiFactorAuthPresent` key is missing from the request context, even though the user has MFA configured and is logged in. In the IAM console, during the password change flow, this key may not be present in the request, causing `BoolIfExists` to treat the absent key as a false value—but because the policy uses a Deny with `BoolIfExists`, the absence triggers the Deny, blocking `iam:ChangePassword`. On the AWS Certified Security Specialty SCS-C02 exam, this tests your understanding of how `BoolIfExists` differs from `Bool`: it does not require the key to exist, so missing keys are treated as matching the condition. A common trap is assuming that being logged in with MFA guarantees the key is present in every API call, but the console’s password change request may omit it. Memory tip: “IfExists means if it’s missing, the condition still bites.”
⚠ Common exam trap
Many candidates assume `BoolIfExists` behaves like `Bool` and that MFA presence is always indicated in the request context, but `BoolIfExists` treats a missing key as true, causing the Deny to apply when the key is absent, such as in the IAM console's password change flow.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Deny statement uses 'BoolIfExists' which evaluates to true if the condition key is not present. In the IAM console, the 'aws:MultiFactorAuthPresent' key may not be set, causing the Deny to apply even when the user has MFA.
The Deny statement uses the `BoolIfExists` condition operator with the `aws:MultiFactorAuthPresent` key. In the IAM console, the `aws:MultiFactorAuthPresent` key may not be present in the request context (e.g., during the initial password change flow before MFA is re-validated), causing `BoolIfExists` to evaluate to true when the key is absent. This triggers the Deny even though the user has an MFA device and is logged in with MFA, blocking the `iam:ChangePassword` action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Allow statement for iam:ChangePassword is not sufficient because the Deny statement explicitly denies all actions.
Why it's wrong here
The Deny is conditional; if the condition is not met, the Deny does not apply. But the condition is met due to BoolIfExists.
- ✓
The Deny statement uses 'BoolIfExists' which evaluates to true if the condition key is not present. In the IAM console, the 'aws:MultiFactorAuthPresent' key may not be set, causing the Deny to apply even when the user has MFA.
Why this is correct
BoolIfExists returns true if the key does not exist, so the Deny applies, blocking all actions including password change.
- ✗
The Deny statement denies all actions unconditionally, so the Allow statement cannot override it.
Why it's wrong here
The Deny has a condition; it is not unconditional.
- ✗
The user does not have permission to change their own password because the Allow statement is not specific enough.
Why it's wrong here
The Allow statement allows iam:ChangePassword on all resources, which includes the user's own password.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 376-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SCS-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Refer to the exhibit. This IAM policy is attached to a user. The user attempts to assume the AdminRole without using MFA. What is the result?
hard- A.The user can assume the role because the Allow statement grants it
- ✓ B.The user cannot assume the role because the Deny statement blocks all actions when MFA is not present
- C.The user can assume the role because the Deny statement does not apply to sts:AssumeRole
- D.The user cannot assume the role because the Allow statement requires MFA
Why B: The Deny statement explicitly denies all actions when MFA is not present, overriding the Allow statement. Since the user is not using MFA, sts:AssumeRole is denied. Option A is incorrect because the Deny overrides the Allow. Option C is incorrect because the Deny applies to all actions, including sts:AssumeRole. Option D is incorrect because the Deny, not the Allow, imposes the MFA requirement.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.