AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementMedium
A security team needs to enforce that all IAM users in a specific AWS account are forced to re-authenticate using Multi-Factor Authentication (MFA) if their last MFA authentication occurred more than 4 hours ago. This requirement applies to all actions on sensitive resources. Which IAM condition key should be used in an IAM policy to achieve this?
- Aaws:MultiFactorAuthPresent
- Baws:CurrentTime
- Caws:SourceIp
- Daws:MultiFactorAuthAge
Show answer & explanationAnswer & explanation
Correct answer: D. aws:MultiFactorAuthAge
The `aws:MultiFactorAuthAge` condition key allows you to specify the maximum number of seconds since the user's MFA device was last used to authenticate. By setting a value corresponding to 4 hours (14,400 seconds), you can enforce re-authentication if the MFA session is older than the specified duration.
Why the other options are wrong
- A. `aws:MultiFactorAuthPresent` simply checks if MFA was used at all, not how recently.
- B. `aws:CurrentTime` can check the current time but doesn't directly relate to MFA session age.
- C. `aws:SourceIp` restricts access based on the source IP address, unrelated to MFA session age.
IAM Condition Key: aws:MultiFactorAuthAge
The `aws:MultiFactorAuthAge` condition key allows you to specify the maximum age (in seconds) of a user's MFA authentication for an action to be allowed.
- Used to enforce MFA re-authentication.
- Value is in seconds.
- Helps implement time-based MFA requirements.
Memory trick: MFA Age is the clock for re-authentication.