SOA-C02 exam dumps

SOA-C02 practice question 175 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 175

Single answer

Your company uses AWS to host several critical applications. The security team has identified a requirement to enforce MFA for all IAM users accessing the AWS Management Console. Additionally, they want to ensure IAM users who do not comply with this requirement are denied access. Which solution would you implement to meet this requirement?

  1. A

    Create an IAM policy with a condition that requires MFA authentication and attach it to all IAM users.

  2. B

    Create an IAM policy with a condition that requires MFA authentication and attach it to the root user.

  3. C

    Create an IAM policy with a condition that requires MFA authentication and attach it to a group containing all IAM users.

  4. D

    Enable MFA enforcement directly on the AWS Management Console for all IAM users.

Show answer and explanation

Correct answer: C

Explanation

To enforce MFA for IAM users, you need to create an IAM policy with a condition that requires MFA authentication (aws:MultiFactorAuthPresent condition key) and attach it to a group containing all IAM users. This approach ensures that access is denied to users who do not comply with the MFA requirement. Enforcing MFA directly through the AWS Management Console is not a feature provided by AWS.

  • A. Incorrect.

    This option will not work as attaching the policy directly to all IAM users can be cumbersome, and it is not a scalable or best practice solution. Instead, attaching the policy to a group containing all IAM users is more efficient.

  • B. Incorrect.

    IAM policies cannot be attached to the root user. Additionally, it is a best practice to avoid using the root user for day-to-day administrative tasks.

  • C. Correct.

    This is the correct answer. Attaching an IAM policy with a condition requiring MFA to a group containing all IAM users ensures that only users who comply with the MFA requirement can access the AWS Management Console.

  • D. Incorrect.

    There is no direct option in the AWS Management Console to enforce MFA for IAM users. MFA enforcement must be implemented using IAM policies with appropriate conditions.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam