AWS SAA-C03 · Question 05 · Domain 1.1: Secure Access
A security team wants to enforce MFA for all IAM users before they can terminate EC2 instances. How can a Solutions Architect implement this requirement?
Answer options:
Enable MFA Delete on the EC2 instances.
Create an IAM policy with a condition 'aws:MultiFactorAuthPresent': 'true' for the ec2:TerminateInstances action.
Use AWS Organizations SCPs to enforce MFA for all API calls.
Configure AWS CloudTrail to block termination requests lacking MFA.
65 questions · hints · full answers · grading