AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementMedium
A company policy dictates that all AWS IAM users must use strong, unique passwords and enable Multi-Factor Authentication (MFA). An AWS Config rule is in place to detect non-compliant MFA settings for IAM users. However, the security team needs a proactive measure to prevent users from disabling their MFA devices or changing their password policy settings after they have been configured correctly. Which IAM condition key should be used in an IAM policy to prevent these changes?
- Aaws:SourceIp
- Biam:MFAPresent
- Caws:MultiFactorAuthAge
- Daws:RequestedRegion
Show answer & explanationAnswer & explanation
Correct answer: B. iam:MFAPresent
The `iam:MFAPresent` condition key can be used in an IAM policy to require MFA for specific actions. By attaching a policy that denies actions like `iam:DeactivateMFADevice` or `iam:ChangePassword` unless `iam:MFAPresent` is 'true', users cannot disable their MFA or change password policies without MFA, providing a proactive control.
Why the other options are wrong
- A. `aws:SourceIp` restricts access based on the source IP address, not MFA status.
- C. `aws:MultiFactorAuthAge` checks how long ago MFA was performed, not if MFA is currently present for an action.
- D. `aws:RequestedRegion` restricts actions based on the AWS region, not MFA status.
IAM Condition Key: iam:MFAPresent
An IAM condition key that evaluates whether the principal making the request has authenticated with MFA.
- Used to enforce MFA for sensitive actions.
- Value is 'true' if MFA was used, 'false' otherwise.
- Can be used in a `Deny` statement to prevent actions without MFA.
Memory trick: Think of a 'secret handshake' (MFA) required before you can perform sensitive 'admin tasks'.