nerdexam
Amazon

SCS-C02 · Question #47

A security engineer is designing an IAM policy to protect AWS API operations. The policy must enforce multi-factor authentication (MFA) for IAM users to access certain services in the AWS production…

The correct answer is A. "Bool": {"aws:MultiFactorAuthPresent": "true"} C. "NumericLessThan": {"aws:MultiFactorAuthAge": "7200"}. https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa_configure-api-

Submitted by miguelv· Mar 6, 2026Identity and Access Management

Question

A security engineer is designing an IAM policy to protect AWS API operations. The policy must enforce multi-factor authentication (MFA) for IAM users to access certain services in the AWS production account. Each session must remain valid for only 2 hours. The current version of the IAM policy is as follows:

Which combination of conditions must the security engineer add to the IAM policy to meet these requirements? (Choose two.)

Exhibit

SCS-C02 question #47 exhibit

Options

  • A"Bool": {"aws:MultiFactorAuthPresent": "true"}
  • B"Bool": {"aws:MultiFactorAuthPresent": "false"}
  • C"NumericLessThan": {"aws:MultiFactorAuthAge": "7200"}
  • D"NumericGreaterThan": {"aws:MultiFactorAuthAge": "7200"}
  • E"NumericLessThan": {"MaxSessionDuration": "7200"}

How the community answered

(30 responses)
  • A
    77% (23)
  • B
    3% (1)
  • D
    7% (2)
  • E
    13% (4)

Explanation

https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa_configure-api-

Topics

#IAM policy conditions#MFA enforcement#MultiFactorAuthAge#session duration

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice