Courseiva
Security and Compliance →easyMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company's security team requires that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. The SysOps administrator needs to create an IAM policy that denies all console actions if the user has not authenticated with MFA. Which IAM condition key should the administrator use?

⚠ Common exam trap

Test-takers frequently confuse `aws:MultiFactorAuthPresent` with `aws:MultiFactorAuthAge` (which checks how long ago MFA was used) or assume `SourceIp` can enforce MFA, but only the `MultiFactorAuthPresent` key directly evaluates MFA status for console access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aws:MultiFactorAuthPresent

The `aws:MultiFactorAuthPresent` condition key evaluates to `true` when the user has authenticated using MFA. By using this key in a `Deny` statement, the policy can block all console actions unless MFA is present, enforcing the security team's requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    aws:MultiFactorAuthPresent

    Why this is correct

    aws:MultiFactorAuthPresent is a boolean condition key that returns true when the caller authenticated with MFA. To enforce MFA for all IAM user console access, you attach an identity policy with a condition like "Bool": {"aws:MultiFactorAuthPresent": "true"}. This works with temporary credentials obtained via the console or sts:GetSessionToken, but it does not automatically apply to long-lived access keys unless the session is explicitly created with MFA.

  • ✗

    aws:SourceIp

    Why it's wrong here

    aws:SourceIp is a global condition key that evaluates the source IP address of the request, typically used to restrict access to a trusted network range (e.g., corporate VPN). It only verifies the network location, not the authentication method, so a user coming from an allowed IP without MFA would still satisfy this condition. It cannot be repurposed to detect whether an MFA device was used during authentication.

  • ✗

    iam:PassedToService

    Why it's wrong here

    iam:PassedToService is a service-specific condition key used to control which AWS services a role can be passed to when a principal performs iam:PassRole. It is relevant in cross-account or service-delegation scenarios, such as when launching an EC2 instance with a service-linked role. It has no bearing on the caller's authentication factor, so it cannot validate MFA status or enforce MFA usage.

  • ✗

    aws:RequestedRegion

    Why it's wrong here

    aws:RequestedRegion is a global condition key that checks which AWS Region the API call targets, allowing you to deny or allow actions in specific regions (e.g., restricting workloads to us-east-1). It is useful for data residency and compliance but provides no evidence of whether the user authenticated with MFA. An attacker without MFA could still make requests in an allowed region, so this key does not satisfy MFA enforcement requirements.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.