SOA-C02 Security and Compliance Practice Question
Which TWO IAM policy conditions can be used to enforce multi-factor authentication (MFA) for API calls? (Choose two.)
⚠ Common exam trap
The trap is assuming that any condition key containing 'Auth' or 'Token' enforces MFA; only aws:MultiFactorAuthPresent and aws:MultiFactorAuthAge are directly tied to MFA status.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aws:MultiFactorAuthPresent
Option B, aws:MultiFactorAuthPresent, is correct because this boolean condition key evaluates to true when the request is made with temporary credentials that were obtained through MFA, allowing a policy to explicitly deny or allow API calls based on whether MFA was used. Option C, aws:MultiFactorAuthAge, is correct because it checks the elapsed time (in seconds) since the MFA-authenticated session was established, enabling policies to require MFA to have occurred within a maximum age for API calls. Together these two conditions are the standard AWS mechanisms for enforcing MFA on API requests. Option A, aws:PrincipalType, only distinguishes between account, user, role, or federated principal types and does not indicate MFA usage. Option D, aws:TokenIssueTime, reflects when temporary credentials were issued but does not by itself prove MFA was performed. Option E, aws:SourceIp, restricts requests by source IP address and is unrelated to MFA enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
aws:PrincipalType
Why it's wrong here
aws:PrincipalType is a condition key that identifies the category of the principal making the request, such as User, Role, FederatedUser, or AssumedRole. It is a string value that describes the principal's type, not their authentication method. MFA status is unrelated to this value; a federated user or an IAM role can have MFA enabled or not. Therefore, using aws:PrincipalType cannot enforce multi-factor authentication because it does not provide information about whether MFA was used in the session.
- ✓
aws:MultiFactorAuthPresent
Why this is correct
aws:MultiFactorAuthPresent is a boolean condition key that returns true if the principal authenticated with multi-factor authentication, and false otherwise. It can be used with the Bool condition operator to require that MFA was used, for example, "Bool": {"aws:MultiFactorAuthPresent": "true"}. This is a straightforward way to enforce MFA but it only checks the presence, not the age, of the MFA authentication. One caveat is that this key is only meaningful for temporary credentials, so you must ensure callers use temporary sessions (e.g., via GetSessionToken) when applying this restriction.
- ✓
aws:MultiFactorAuthAge
Why this is correct
aws:MultiFactorAuthAge is a numeric condition key that specifies the number of seconds that have elapsed since the principal performed a multi-factor authentication. This allows you to enforce not just the presence of MFA but also its recency, by using operators like NumericLessThan. For example, you can require that MFA was verified within the last 10 minutes (600 seconds) for sensitive operations. This key is especially useful when you need to ensure that the session uses fresh MFA credentials, not simply any prior MFA event.
- ✗
aws:TokenIssueTime
Why it's wrong here
aws:TokenIssueTime is a condition key that records the time when the temporary security credentials were issued for the request. While it is a valid IAM condition key, it provides no direct indication of whether MFA was used to obtain those credentials. The token issuance time is related to the start of the session, not to the method of authentication. Therefore, this key cannot be used to enforce MFA, as a token could be issued without any MFA challenge even though its issue time is recent.
- ✗
aws:SourceIp
Why it's wrong here
aws:SourceIp is a condition key used to restrict access based on the IP address from which the request originates. It is commonly employed for network-level security, such as allowing only office IP addresses or blocking specific regions. This key does not carry any information about authentication factors like MFA. Even if a request comes from an allowed IP, it could still originate from a compromised session that did not use MFA, so aws:SourceIp cannot enforce multi-factor authentication.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.