AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementHard

A company is implementing a new compliance requirement that mandates all access to AWS resources must originate from corporate IP addresses, with the exception of specific mobile users who need to access resources from anywhere using multi-factor authentication (MFA). How can this be achieved using IAM policies?

  1. ACreate an IAM policy that explicitly denies access if the source IP is not from corporate ranges, and then create a separate policy for mobile users that allows access only if `aws:MultiFactorAuthPresent` is 'true'.
  2. BUse AWS WAF to block non-corporate IPs and rely on IAM policies for MFA enforcement.
  3. CCreate an IAM policy that includes a `Condition` to allow access only from corporate IP ranges and another `Condition` to allow access if MFA is present, applying this policy to all users.
  4. DCreate two separate IAM policies: one that denies access if the source IP is not from corporate ranges, and another that allows access only if MFA is present, attaching both to all users.
Show answer & explanation

Correct answer: A. Create an IAM policy that explicitly denies access if the source IP is not from corporate ranges, and then create a separate policy for mobile users that allows access only if `aws:MultiFactorAuthPresent` is 'true'.

IAM policies are evaluated in a specific order: explicit deny takes precedence over explicit allow, which takes precedence over implicit deny. By creating an explicit deny for non-corporate IPs and then a separate allow policy for mobile users that requires MFA, the system correctly enforces the corporate IP restriction while providing a specific, secure exception for mobile users. The explicit deny policy ensures that without the specific MFA 'allow' for mobile, all non-corporate IPs are blocked.

Why the other options are wrong

  • B. AWS WAF operates at the network level (e.g., for EC2, Application Load Balancer) and can filter IPs but is not an IAM policy and cannot enforce MFA for AWS API calls directly or integrate with IAM identity context for conditional access to all AWS resources. IAM policies are required for this level of access control.
  • C. Combining two `Condition` blocks with different requirements (IP AND MFA) in a single 'Allow' statement would require both to be true, which doesn't allow for the 'OR' logic of corporate IP *OR* MFA for mobile users. An 'Allow' with a 'NotIpAddress' condition would effectively be an implicit deny, which is overridden by an explicit allow.
  • D. Two separate policies with `Allow` statements won't achieve the 'deny by default unless specific conditions' logic as effectively. An `Allow` policy based on MFA presence would override an implicit deny by source IP if the MFA condition is met, but a general `Deny` for non-corporate IPs is the strongest starting point.

IAM Policy Evaluation Logic

The order in which IAM policies are evaluated: explicit deny > explicit allow > implicit deny (default).

  • Explicit Deny always overrides Explicit Allow.
  • Explicit Allow overrides Implicit Deny.
  • If no matching Allow policy, access is implicitly denied.

Memory trick: Deny is king, then Allow takes wing, if nothing, deny's the final thing.

More Domain 4: Identity and Access Management questions