AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium
A financial services company wants to enforce that all IAM users must provide a second authentication factor when signing in to the AWS Management Console. Which feature should the company enable?
- AAWS Organizations service control policies
- BAWS Key Management Service (KMS) key policies
- CMulti-factor authentication (MFA) on IAM user accounts
- DIAM password policy minimum length requirement
Show answer & explanationAnswer & explanation
Correct answer: C. Multi-factor authentication (MFA) on IAM user accounts
Multi-factor authentication requires users to provide a second factor (such as a code from a virtual MFA device or hardware token) in addition to their password, directly addressing the requirement for stronger sign-in security.
Why the other options are wrong
- A. Service control policies restrict permissions across accounts but do not enforce a second authentication factor.
- B. KMS key policies control access to encryption keys, unrelated to console sign-in.
- D. Password length policies strengthen passwords but do not add a second factor.
Multi-Factor Authentication (MFA)
A security mechanism requiring users to present two or more verification factors to gain access, such as a password plus a one-time code.
- Should be enabled on the root user and privileged IAM users
- Supports virtual MFA apps, hardware tokens, and security keys
- Adds a critical layer of defense against compromised passwords
Memory trick: Something you know PLUS something you have.