AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementMedium

A security team needs to enforce that all IAM users in a specific AWS account are forced to re-authenticate using Multi-Factor Authentication (MFA) if their last MFA authentication occurred more than 4 hours ago. This requirement applies to all actions on sensitive resources. Which IAM condition key should be used in an IAM policy to achieve this?

  1. Aaws:MultiFactorAuthPresent
  2. Baws:CurrentTime
  3. Caws:SourceIp
  4. Daws:MultiFactorAuthAge
Show answer & explanation

Correct answer: D. aws:MultiFactorAuthAge

The `aws:MultiFactorAuthAge` condition key allows you to specify the maximum number of seconds since the user's MFA device was last used to authenticate. By setting a value corresponding to 4 hours (14,400 seconds), you can enforce re-authentication if the MFA session is older than the specified duration.

Why the other options are wrong

  • A. `aws:MultiFactorAuthPresent` simply checks if MFA was used at all, not how recently.
  • B. `aws:CurrentTime` can check the current time but doesn't directly relate to MFA session age.
  • C. `aws:SourceIp` restricts access based on the source IP address, unrelated to MFA session age.

IAM Condition Key: aws:MultiFactorAuthAge

The `aws:MultiFactorAuthAge` condition key allows you to specify the maximum age (in seconds) of a user's MFA authentication for an action to be allowed.

  • Used to enforce MFA re-authentication.
  • Value is in seconds.
  • Helps implement time-based MFA requirements.

Memory trick: MFA Age is the clock for re-authentication.

More Domain 4: Identity and Access Management questions