AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementMedium

A company policy dictates that all AWS IAM users must use strong, unique passwords and enable multi-factor authentication (MFA). The security team wants to automate the enforcement of these policies and detect non-compliant users. Which combination of AWS services should be used?

  1. AAWS Config rules for password policy and IAM Access Analyzer for MFA.
  2. BIAM password policy for password strength and AWS Config rules for MFA.
  3. CIAM password policy for password strength and IAM user policies for MFA enforcement.
  4. DAWS Organizations Service Control Policies (SCPs) and IAM Access Analyzer.
Show answer & explanation

Correct answer: B. IAM password policy for password strength and AWS Config rules for MFA.

IAM password policies are native to IAM and enforce password complexity, rotation, and length. AWS Config rules can detect non-compliant resources, including IAM users without MFA enabled, using managed rules like `iam-user-mfa-enabled`. This combination provides both enforcement (password policy) and detection (Config).

Why the other options are wrong

  • A. IAM Access Analyzer is for identifying unintended external access to resources, not for enforcing internal user password policies or MFA. AWS Config can detect MFA compliance but IAM password policy handles password strength.
  • C. IAM user policies can be used to *force* MFA for actions (e.g., using `aws:MultiFactorAuthPresent` condition), but they don't *detect* if MFA is enabled on the user account itself. AWS Config is better suited for detection and reporting of MFA enablement status.
  • D. SCPs are preventive guardrails for maximum permissions across an organization; they cannot enforce password policies or detect MFA status of individual users. IAM Access Analyzer is for external access analysis.

IAM Password Policy & AWS Config for MFA

IAM password policies enforce password complexity and rotation, while AWS Config rules detect non-compliance with MFA requirements for IAM users.

  • IAM password policy is set at the account level.
  • AWS Config managed rules exist for MFA compliance (e.g., `iam-user-mfa-enabled`).
  • Config can provide continuous monitoring and remediation for MFA.
  • This combination provides both enforcement (passwords) and detection/monitoring (MFA).

Memory trick: Password policy sets the rules, Config checks for MFA tools.

More Domain 4: Identity and Access Management questions