Best Free Actual Exam Prep Sources

Amazon (AWS) : SCS-C02 AWS Certified Security – Specialty Questions and Answers

Get Full PDF

Question.13
A security engineer is designing an IAM policy to protect AWS API operations. The policy must enforce multi-factor authentication (MFA) for IAM users to access certain services in the AWS production account. Each session must remain valid for only 2 hours. The current version of the IAM policy is as follows:

Which combination of conditions must the security engineer add to the IAM policy to meet these requirements? (Choose two.)
(A) “Bool”: {“aws:MultiFactorAuthPresent”: “true”}
(B) “Bool”: {“aws:MultiFactorAuthPresent”: “false”}
(C) “NumericLessThan”: {“aws:MultiFactorAuthAge”: “7200”}
(D) “NumericGreaterThan”: {“aws:MultiFactorAuthAge”: “7200”}
(E) “NumericLessThan”: {“MaxSessionDuration”: “7200”}

Scroll to Top