SOA-C02 Security and Compliance Practice Question
A company's security team requires that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. The SysOps administrator needs to create an IAM policy that denies all console actions if the user has not authenticated with MFA. Which IAM condition key should the administrator use?
⚠ Common exam trap
Test-takers frequently confuse `aws:MultiFactorAuthPresent` with `aws:MultiFactorAuthAge` (which checks how long ago MFA was used) or assume `SourceIp` can enforce MFA, but only the `MultiFactorAuthPresent` key directly evaluates MFA status for console access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aws:MultiFactorAuthPresent
The `aws:MultiFactorAuthPresent` condition key evaluates to `true` when the user has authenticated using MFA. By using this key in a `Deny` statement, the policy can block all console actions unless MFA is present, enforcing the security team's requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
aws:MultiFactorAuthPresent
Why this is correct
aws:MultiFactorAuthPresent is a boolean condition key that returns true when the caller authenticated with MFA. To enforce MFA for all IAM user console access, you attach an identity policy with a condition like "Bool": {"aws:MultiFactorAuthPresent": "true"}. This works with temporary credentials obtained via the console or sts:GetSessionToken, but it does not automatically apply to long-lived access keys unless the session is explicitly created with MFA.
- ✗
aws:SourceIp
Why it's wrong here
aws:SourceIp is a global condition key that evaluates the source IP address of the request, typically used to restrict access to a trusted network range (e.g., corporate VPN). It only verifies the network location, not the authentication method, so a user coming from an allowed IP without MFA would still satisfy this condition. It cannot be repurposed to detect whether an MFA device was used during authentication.
- ✗
iam:PassedToService
Why it's wrong here
iam:PassedToService is a service-specific condition key used to control which AWS services a role can be passed to when a principal performs iam:PassRole. It is relevant in cross-account or service-delegation scenarios, such as when launching an EC2 instance with a service-linked role. It has no bearing on the caller's authentication factor, so it cannot validate MFA status or enforce MFA usage.
- ✗
aws:RequestedRegion
Why it's wrong here
aws:RequestedRegion is a global condition key that checks which AWS Region the API call targets, allowing you to deny or allow actions in specific regions (e.g., restricting workloads to us-east-1). It is useful for data residency and compliance but provides no evidence of whether the user authenticated with MFA. An attacker without MFA could still make requests in an allowed region, so this key does not satisfy MFA enforcement requirements.
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.