AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium

A financial services company wants to enforce that all IAM users must provide a second authentication factor when signing in to the AWS Management Console. Which feature should the company enable?

  1. AAWS Organizations service control policies
  2. BAWS Key Management Service (KMS) key policies
  3. CMulti-factor authentication (MFA) on IAM user accounts
  4. DIAM password policy minimum length requirement
Show answer & explanation

Correct answer: C. Multi-factor authentication (MFA) on IAM user accounts

Multi-factor authentication requires users to provide a second factor (such as a code from a virtual MFA device or hardware token) in addition to their password, directly addressing the requirement for stronger sign-in security.

Why the other options are wrong

  • A. Service control policies restrict permissions across accounts but do not enforce a second authentication factor.
  • B. KMS key policies control access to encryption keys, unrelated to console sign-in.
  • D. Password length policies strengthen passwords but do not add a second factor.

Multi-Factor Authentication (MFA)

A security mechanism requiring users to present two or more verification factors to gain access, such as a password plus a one-time code.

  • Should be enabled on the root user and privileged IAM users
  • Supports virtual MFA apps, hardware tokens, and security keys
  • Adds a critical layer of defense against compromised passwords

Memory trick: Something you know PLUS something you have.

More Security and Compliance questions