Courseiva
Security and Compliance →mediumMultiple Select

SOA-C02 Security and Compliance Practice Question

Which TWO IAM policy conditions can be used to enforce multi-factor authentication (MFA) for API calls? (Choose two.)

⚠ Common exam trap

The trap is assuming that any condition key containing 'Auth' or 'Token' enforces MFA; only aws:MultiFactorAuthPresent and aws:MultiFactorAuthAge are directly tied to MFA status.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aws:MultiFactorAuthPresent

Option B, aws:MultiFactorAuthPresent, is correct because this boolean condition key evaluates to true when the request is made with temporary credentials that were obtained through MFA, allowing a policy to explicitly deny or allow API calls based on whether MFA was used. Option C, aws:MultiFactorAuthAge, is correct because it checks the elapsed time (in seconds) since the MFA-authenticated session was established, enabling policies to require MFA to have occurred within a maximum age for API calls. Together these two conditions are the standard AWS mechanisms for enforcing MFA on API requests. Option A, aws:PrincipalType, only distinguishes between account, user, role, or federated principal types and does not indicate MFA usage. Option D, aws:TokenIssueTime, reflects when temporary credentials were issued but does not by itself prove MFA was performed. Option E, aws:SourceIp, restricts requests by source IP address and is unrelated to MFA enforcement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    aws:PrincipalType

    Why it's wrong here

    aws:PrincipalType is a condition key that identifies the category of the principal making the request, such as User, Role, FederatedUser, or AssumedRole. It is a string value that describes the principal's type, not their authentication method. MFA status is unrelated to this value; a federated user or an IAM role can have MFA enabled or not. Therefore, using aws:PrincipalType cannot enforce multi-factor authentication because it does not provide information about whether MFA was used in the session.

  • ✓

    aws:MultiFactorAuthPresent

    Why this is correct

    aws:MultiFactorAuthPresent is a boolean condition key that returns true if the principal authenticated with multi-factor authentication, and false otherwise. It can be used with the Bool condition operator to require that MFA was used, for example, "Bool": {"aws:MultiFactorAuthPresent": "true"}. This is a straightforward way to enforce MFA but it only checks the presence, not the age, of the MFA authentication. One caveat is that this key is only meaningful for temporary credentials, so you must ensure callers use temporary sessions (e.g., via GetSessionToken) when applying this restriction.

  • ✓

    aws:MultiFactorAuthAge

    Why this is correct

    aws:MultiFactorAuthAge is a numeric condition key that specifies the number of seconds that have elapsed since the principal performed a multi-factor authentication. This allows you to enforce not just the presence of MFA but also its recency, by using operators like NumericLessThan. For example, you can require that MFA was verified within the last 10 minutes (600 seconds) for sensitive operations. This key is especially useful when you need to ensure that the session uses fresh MFA credentials, not simply any prior MFA event.

  • ✗

    aws:TokenIssueTime

    Why it's wrong here

    aws:TokenIssueTime is a condition key that records the time when the temporary security credentials were issued for the request. While it is a valid IAM condition key, it provides no direct indication of whether MFA was used to obtain those credentials. The token issuance time is related to the start of the session, not to the method of authentication. Therefore, this key cannot be used to enforce MFA, as a token could be issued without any MFA challenge even though its issue time is recent.

  • ✗

    aws:SourceIp

    Why it's wrong here

    aws:SourceIp is a condition key used to restrict access based on the IP address from which the request originates. It is commonly employed for network-level security, such as allowing only office IP addresses or blocking specific regions. This key does not carry any information about authentication factors like MFA. Even if a request comes from an allowed IP, it could still originate from a compromised session that did not use MFA, so aws:SourceIp cannot enforce multi-factor authentication.

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.