Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

A SysOps administrator notices that an IAM user can access the AWS Management Console but cannot use the AWS CLI. The user has a password and an access key. What is the most likely cause?

⚠ Common exam trap

Test-takers frequently assume CLI access is always tied to the access key's active status or password, rather than understanding that IAM policies with MFA conditions can selectively block API calls while allowing console access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IAM policy denies CLI access unless MFA is present

The most likely cause is that the user's IAM policy includes a condition that denies CLI access unless MFA is present. The AWS CLI uses access keys for authentication, and if a policy explicitly requires MFA for API calls (e.g., via `aws:MultiFactorAuthPresent` condition key), CLI requests will be denied even though console access (which can enforce MFA separately via a sign-in policy) remains functional. This scenario is common when an administrator has attached a policy like `DenyAllExceptWithMFA` to the user or a group.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The secret access key was not saved during creation

    Why it's wrong here

    If the secret access key was not saved during creation, the user would be unable to sign CLI requests because the secret key value is displayed only once; however, this is a transient credential loss, not a policy-based denial. The user or administrator could simply generate a new access key pair in the IAM console and reconfigure the CLI, which would immediately resolve the issue. Moreover, a missing secret key would result in an InvalidClientTokenId error, not a targeted denial of CLI access while the console remains usable, so this does not match the scenario.

  • ✗

    The user's access key is inactive

    Why it's wrong here

    An inactive access key causes CLI calls to fail with an InvalidClientTokenId error, but it does not explain why the same user can still access the AWS Management Console, because console sign-in uses the password and MFA, not access keys. The administrator could set the key state back to Active in the IAM console, making this a simple key-state issue rather than a persistent authorization problem. Since the symptom is limited to CLI access and the user's console session works, an inactive key alone is not a sufficient explanation when the policy selectively requires MFA for programmatic calls.

  • ✗

    The user is using the wrong password for the CLI

    Why it's wrong here

    The AWS CLI does not accept the IAM user's console password as an authentication credential; CLI requests are signed with access keys or temporary credentials obtained through assume-role calls. Using the wrong console password would only prevent interactive web console login, not affect programmatic commands, and would produce a login failure rather than an AccessDenied response from the service. Therefore, this option confuses the authentication mechanisms for the console with those used by the CLI and cannot account for a CLI-specific denial.

  • ✓

    The IAM policy denies CLI access unless MFA is present

    Why this is correct

    An IAM policy can include a condition key such as aws:MultiFactorAuthPresent with a value of 'false' to deny API actions when the user's session was not authenticated with MFA. The user may have properly authenticated with MFA for the console session, but if the CLI request was made without providing an MFA token, the condition evaluates to false and the policy denies the action. This explains why the console works while CLI commands return an AccessDenied error, and it is the only option that addresses the precise distinction between authenticated console access and unauthenticated programmatic access.

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.