SOA-C02 Security and Compliance Practice Question
A company's security policy requires that all IAM users must have multi-factor authentication (MFA) enabled. A SysOps administrator needs to automatically detect IAM users without MFA and generate a compliance report. Which AWS service should be used to meet this requirement with minimal operational overhead?
⚠ Common exam trap
Many exam-takers confuse AWS Config's compliance evaluation with CloudTrail's auditing or Trusted Advisor's checks, not realizing that only AWS Config offers a managed rule specifically for IAM user MFA enforcement with automated reporting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
AWS Config provides managed rules such as `iam-user-mfa-enabled` that can continuously evaluate IAM users against the requirement for MFA. When a user is found without MFA, AWS Config can trigger an automatic remediation action or generate a compliance report via its dashboard or Amazon SNS notifications, meeting the detection and reporting need with minimal operational overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Config
Why this is correct
AWS Config is the correct service because it includes the managed rule iam-user-mfa-enabled, which continuously evaluates whether each IAM user has an MFA device registered. The rule is part of the CIS AWS Foundations Benchmark and can be configured to run periodically or on configuration changes, returning a noncompliant result for any user missing MFA. This makes AWS Config the appropriate service for automated compliance monitoring and reporting, not just logging or ad-hoc checks.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records tenant API activity as events for auditing, such as who made a request, from what IP, and when, but it does not assess configuration state or verify whether IAM users have MFA enabled. While CloudTrail can log authentication-related events, it provides no built-in compliance rules or status checks and cannot flag a user as noncompliant for lacking MFA. Therefore, CloudTrail is unsuitable for enforcing this security policy as a configuration check.
- ✗
IAM Access Analyzer
Why it's wrong here
IAM Access Analyzer is designed to analyze resource-based policies and identify when principals from outside the account are granted access to resources like S3 buckets, KMS keys, and IAM roles. It generates findings about unintended external access but has no mechanism to inspect IAM user attributes or verify the presence of an MFA device on a user. This makes it fundamentally different from a configuration-compliance tool and, therefore, not the correct choice for this requirement.
- ✗
AWS Trusted Advisor
Why it's wrong here
AWS Trusted Advisor provides best-practice checks across cost optimization, performance, security, fault tolerance, and service limits, but its security checks are focused on high-level items such as MFA on the root account, IAM use, and security group configurations. There is no Trusted Advisor check that evaluates whether every individual IAM user has MFA enabled, so it cannot satisfy the requirement for all IAM users. Thus, while Trusted Advisor can aid security posture, it is not the right service here.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.