AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

Developers in your AWS account use IAM users and the AWS CLI. Management wants to allow them to run any read-only IAM operations at any time but block all IAM create, update, or delete API calls unless the request is authenticated with multi-factor authentication (MFA). Which approach meets this requirement while following AWS best practices?

  • Enable the AWS Config rule iam-user-mfa-enabled and set it to automatically remediate non-compliant users.

  • Create an account password policy that requires MFA and enforce it for the developer group.

  • Attach a policy to the developer group that contains an explicit Deny for IAM write actions and uses the condition BoolIfExists: {"aws:MultiFactorAuthPresent":"false"}.

  • Force developers to assume an IAM role and add a condition that compares aws:TokenIssueTime to deny requests older than 5 minutes.

AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot