SOA-C02 Security and Compliance Practice Question
A company's security policy requires that all IAM users must authenticate with multi-factor authentication (MFA) before they can perform any actions on Amazon EC2 instances. The SysOps administrator needs to enforce this requirement using IAM policies. Which IAM policy condition key should the administrator use in the policy?
⚠ Common exam trap
Candidates often confuse `aws:MultiFactorAuthPresent` with `aws:SourceIp` or `iam:PassedToService`, mistakenly thinking IP-based or role-passing conditions can enforce MFA, when only the MFA-specific condition key works.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aws:MultiFactorAuthPresent
The `aws:MultiFactorAuthPresent` condition key allows the administrator to enforce MFA authentication by checking whether the user authenticated with a valid MFA device before allowing the action. When set to `true`, the policy denies access to EC2 actions unless the user has completed MFA. This directly satisfies the security policy requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
aws:MultiFactorAuthPresent
Why this is correct
The aws:MultiFactorAuthPresent condition key is a global IAM condition that evaluates to true when the principal authenticated with a valid MFA device. In a policy, adding "aws:MultiFactorAuthPresent": "true" to a condition ensures the action is permitted only if MFA was used, regardless of whether the request originates from the console, an API call, or temporary credentials. If MFA was not used, the key evaluates to false (or is absent), causing the condition to fail, which directly enforces the security policy that all IAM users must use MFA.
- ✗
aws:SourceIp
Why it's wrong here
The aws:SourceIp condition key restricts access based on the requester's IP address, such as allowing only traffic from a corporate CIDR range or blocking requests from a specific location. It has no knowledge of the authentication method; a request could come from an allowed IP address while the IAM user logged in with only a password and no MFA token. Thus, it is useful for network-level boundary control but cannot enforce an MFA requirement.
- ✗
iam:PassedToService
Why it's wrong here
The iam:PassedToService condition key is relevant only to the iam:PassRole action, where it controls which roles an IAM principal is allowed to pass to an AWS service like EC2 or Lambda. It constrains the role ARN in the request, not the caller's authentication context, so it cannot require the caller to have presented an MFA token. Even if this condition is satisfied, a user with a password-only login could still perform the action, making it unrelated to MFA enforcement.
- ✗
ec2:SourceInstanceARN
Why it's wrong here
The ec2:SourceInstanceARN condition key is designed for EC2 instance-based access, typically used in resource-based policies or to restrict actions to requests originating from a specific EC2 instance via its instance profile. It identifies the source instance by its ARN but says nothing about how the IAM user authenticated; a request from that instance could still come from a session without MFA. Accordingly, it is unrelated to enforcing MFA on IAM users and only provides a way to scope access by instance identity.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.