AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

An IAM administrator must create a managed policy that lets members of the DevOps group call dynamodb:DeleteItem on tables in the development account, but only when the users are authenticated with multi-factor authentication (MFA) for the current session. Which IAM policy condition will correctly enforce this requirement?

  • Add a StringEqualsIgnoreCase condition that checks whether sts:AuthenticationType equals "mfa".

  • Add a Bool condition that requires the key aws:SecureTransport to be set to "true".

  • Add a Bool condition that requires the key aws:MultiFactorAuthPresent to be set to "true".

  • Add a StringEquals condition that checks whether aws:MultiFactorAuthAge equals "0".

AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot