AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A CloudOps engineer must ensure that IAM users can start, stop, or terminate Amazon EC2 instances only when they are signed in with multi-factor authentication (MFA). Users access the AWS Management Console and the AWS CLI from the same account. Which approach satisfies this requirement with the least operational overhead?
Update the account password policy to require users to configure an MFA device before they can sign in to the console or CLI.
Create a service control policy (SCP) in AWS Organizations that blocks ec2:* unless the request context key "aws:authType" equals "MFA".
Enable MFA Delete on the account's S3 buckets so that any privileged operation requires an MFA code.
Attach a customer-managed IAM policy to all IAM users and groups that explicitly denies ec2:* actions when the condition Bool "aws:MultiFactorAuthPresent" is "false".
An IAM policy can include a Bool condition key called aws:MultiFactorAuthPresent. By attaching an explicit Deny statement that is triggered when this key is set to "false", any request made without a valid MFA session token is rejected. Because Deny overrides Allow, users keep their existing permissions but must authenticate with MFA before invoking the protected EC2 APIs. Password policies cannot enforce MFA, MFA Delete affects only S3 versioned buckets, and SCPs work only in an AWS Organizations hierarchy and would still need the same aws:MultiFactorAuthPresent condition to be effective.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the aws:MultiFactorAuthPresent condition key?
Open an interactive chat with Bash
How does Deny take precedence over Allow in IAM policies?
Open an interactive chat with Bash
Why can SCPs not enforce MFA outside AWS Organizations?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .