SOA-C02 Security and Compliance Practice Question
A company requires that all access to the AWS Management Console be protected by multi-factor authentication (MFA). The SysOps administrator has enabled an IAM policy that denies all actions if the user does not authenticate with MFA. However, some users report they cannot list their own MFA devices. What is the MOST likely cause?
⚠ Common exam trap
Watch out — candidates often assume the deny policy only applies to sensitive actions like modifying resources, but they overlook that even benign read actions like listing MFA devices are blocked because the policy uses a blanket Deny for all actions when MFA is not present, creating a circular dependency.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy denies the iam:ListMFADevices action without an MFA-authenticated session
The IAM policy that denies all actions unless the user is authenticated with MFA will also block the iam:ListMFADevices action because that API call is made without an MFA-authenticated session. When a user tries to list their own MFA devices, they have not yet passed the MFA challenge, so the session is not MFA-authenticated, and the deny policy applies. This creates a catch-22: the user cannot list their devices to manage MFA because listing requires MFA, but they need to list devices to set up MFA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The policy denies the iam:ListMFADevices action without an MFA-authenticated session
Why this is correct
The Deny clause for iam:ListMFADevices when the session lacks an MFA-authenticated condition blocks the AWS Management Console from displaying a user's existing MFA devices and prevents the self-service MFA enrollment flow from working. Because iam:ListMFADevices is one of the first API calls the console makes when a user attempts to manage or set up MFA, this Deny effectively locks out any user who has not yet enrolled MFA, making it impossible to satisfy the MFA requirement. A correctly designed MFA enforcement policy must explicitly allow iam:ListMFADevices (along with iam:CreateVirtualMFADevice and iam:EnableMFADevice) without requiring MFA, allowing users to bootstrap their first device.
- ✗
The policy is applied to the root user only
Why it's wrong here
IAM identity-based policies have no effect on the AWS account root user; root user permissions cannot be restricted by Deny statements. The scenario describes a policy applied to IAM users, which is why the MFA Deny is being evaluated for those users—not because it was placed on the root user. Even if the policy were mistakenly attached to a root user, it would simply be ignored, so the symptom would not occur in this way.
- ✗
Users are not using MFA-enabled access keys
Why it's wrong here
The MFA condition in the policy applies to any session making an AWS request, regardless of whether the credentials are access keys or console password sign-in. The scenario specifically involves the AWS Management Console, and iam:ListMFADevices is called via the console session, not via an access key. Furthermore, there is no such thing as 'MFA-enabled access keys'—MFA is used with STS temporary credentials, not with long-term access keys, so this explanation is incorrect.
- ✗
The policy is not applied in the us-east-1 region
Why it's wrong here
IAM is a global service and does not operate regionally; all IAM actions are evaluated in the global region partition (us-east-1 region is where IAM APIs are hosted, but not as a regional service). A policy's effect is not dependent on the AWS region where the request originates because IAM has no regional endpoints, and evaluation is global. Therefore, 'not applied in us-east-1' is not a valid explanation for a failure that occurs across all console sign-ins.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.