Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company's security policy requires that all IAM users must have multi-factor authentication (MFA) enabled. A SysOps administrator needs to automatically detect IAM users without MFA and generate a compliance report. Which AWS service should be used to meet this requirement with minimal operational overhead?

⚠ Common exam trap

Many exam-takers confuse AWS Config's compliance evaluation with CloudTrail's auditing or Trusted Advisor's checks, not realizing that only AWS Config offers a managed rule specifically for IAM user MFA enforcement with automated reporting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config

AWS Config provides managed rules such as `iam-user-mfa-enabled` that can continuously evaluate IAM users against the requirement for MFA. When a user is found without MFA, AWS Config can trigger an automatic remediation action or generate a compliance report via its dashboard or Amazon SNS notifications, meeting the detection and reporting need with minimal operational overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Config

    Why this is correct

    AWS Config is the correct service because it includes the managed rule iam-user-mfa-enabled, which continuously evaluates whether each IAM user has an MFA device registered. The rule is part of the CIS AWS Foundations Benchmark and can be configured to run periodically or on configuration changes, returning a noncompliant result for any user missing MFA. This makes AWS Config the appropriate service for automated compliance monitoring and reporting, not just logging or ad-hoc checks.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records tenant API activity as events for auditing, such as who made a request, from what IP, and when, but it does not assess configuration state or verify whether IAM users have MFA enabled. While CloudTrail can log authentication-related events, it provides no built-in compliance rules or status checks and cannot flag a user as noncompliant for lacking MFA. Therefore, CloudTrail is unsuitable for enforcing this security policy as a configuration check.

  • ✗

    IAM Access Analyzer

    Why it's wrong here

    IAM Access Analyzer is designed to analyze resource-based policies and identify when principals from outside the account are granted access to resources like S3 buckets, KMS keys, and IAM roles. It generates findings about unintended external access but has no mechanism to inspect IAM user attributes or verify the presence of an MFA device on a user. This makes it fundamentally different from a configuration-compliance tool and, therefore, not the correct choice for this requirement.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor provides best-practice checks across cost optimization, performance, security, fault tolerance, and service limits, but its security checks are focused on high-level items such as MFA on the root account, IAM use, and security group configurations. There is no Trusted Advisor check that evaluates whether every individual IAM user has MFA enabled, so it cannot satisfy the requirement for all IAM users. Thus, while Trusted Advisor can aid security posture, it is not the right service here.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.