passdrill
AWS SAA-C03 · IAM & Security · Card 008/014 easy

A security team wants an IAM policy statement that allows a sensitive action only when the calling principal authenticated with multi-factor authentication during the current session. Which policy element accomplishes this?

  1. A resource-based policy on the target service that checks the caller's password history
  2. A permissions boundary set to a built-in "MFA-only" mode
  3. A Condition element that tests the aws:MultiFactorAuthPresent context key against true
  4. A separate IAM group named "MFA-users" that AWS automatically enforces at the API layer
Next card → Shuffle