AWS SAP-C02 · Question 58 · Domain 1.2: Security Controls
A company requires that all IAM users authenticate using Multi-Factor Authentication (MFA) before they can access any AWS APIs via the CLI. How can the Solutions Architect enforce this requirement globally across the AWS account?
Answer options:
Enable MFA in the AWS Management Console for all users.
Attach an IAM policy to all users that denies all actions unless the aws:MultiFactorAuthPresent condition key is true.
Use AWS Config to delete IAM users who do not have MFA enabled.
Configure AWS IAM Identity Center (AWS SSO) to require MFA.
75 questions · hints · full answers · grading