{"id":204,"date":"2021-01-10T10:30:02","date_gmt":"2021-01-10T10:27:37","guid":{"rendered":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/aws-certified-security-specialty-scs-c01-question195\/"},"modified":"2021-01-10T10:30:35","modified_gmt":"2021-01-10T10:30:35","slug":"aws-certified-security-specialty-scs-c01-question195","status":"publish","type":"post","link":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/aws-certified-security-specialty-scs-c01-question195\/","title":{"rendered":"AWS Certified Security &#8211; Specialty SCS-C01 &#8211; Question195"},"content":{"rendered":"<div class=\"question\">A company has an AWS account and allows a third-party contractor, who uses another AWS account, to assume certain IAM roles. The company wants to ensure that IAM roles can be assumed by the contractor only if the contractor has multi-factor authentication enabled on their IAM user accounts.<br \/>\nWhat should the company do to accomplish this? <br \/><strong><br \/>A.<\/strong> Add the following condition to the IAM policy attached to all IAM roles:<br \/>\n&quot;Effect&quot;: &quot;Deny&quot;,<br \/>\n&quot;Condition&quot; : { &quot;BoolItExists&quot; : { &quot;aws:MultiFactorAuthPresent&quot; : false } } <br \/><strong>B.<\/strong> Add the following condition to the IAM policy attached to all IAM roles:<br \/>\n&quot;Effect&quot;: &quot;Deny&quot;,<br \/>\n&quot;Condition&quot; : { &quot;Bool&quot; : { &quot;aws:MultiFactorAuthPresent&quot; : false } } <br \/><strong>C.<\/strong> Add the following condition to the IAM policy attached to all IAM roles:<br \/>\n&quot;Effect&quot;: &quot;Allow&quot;,<br \/>\n&quot;Condition&quot; : { &quot;Null&quot; : { &quot;aws:MultiFactorAuthPresent&quot; : false } } <br \/><strong>D.<\/strong> Add the following condition to the IAM policy attached to all IAM roles:<br \/>\n&quot;Effect&quot;: &quot;Allow&quot;,<br \/>\n&quot;Condition&quot; : { &quot;BoolItExists&quot; : { &quot;aws:MultiFactorAuthPresent&quot; : false } }<\/div>\n<p><\/p>\n<style> .hidden-div{ display:none } <\/style>\n<p>\t\t\t\t\t\t\t<button onclick=\"getElementById('hidden-div').style.display = 'block'\"> Show Answer <\/button> <button onclick=\"getElementById('hidden-div').style.display = 'none'\">Hide Answer<\/button><\/p>\n<div class=\"hidden-div\" id=\"hidden-div\"><span style=\"\"><\/p>\n<div class=\"answer\">Correct Answer: <strong>A<\/strong><\/div>\n<p><strong>Explanation:<\/strong> <\/p>\n<div class=\"explanation\">\nReference: <a href=\"https:\/\/aws-orgs.readthedocs.io\/_\/downloads\/en\/latest\/pdf\/\" title=\"External link\" rel=\"nofollow noopener\" target=\"_blank\">https:\/\/aws-orgs.readthedocs.io\/_\/downloads\/en\/latest\/pdf\/<\/a> (18)<\/div>\n<p><\/strong><\/span> <\/div>\n","protected":false},"excerpt":{"rendered":"<p>A company has an AWS account and allows a third-party contractor, who uses another AWS account, to assume certain IAM roles. The company wants to ensure that IAM roles can be assumed by the contractor only if the contractor has multi-factor authentication enabled on their IAM user accounts. What should the company do to accomplish [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3,197],"class_list":["post-204","post","type-post","status-publish","format-standard","hentry","category-aws-certified-security-specialty-scs-c01","tag-aws-certified-security-specialty-scs-c01","tag-question-195"],"_links":{"self":[{"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/posts\/204","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/comments?post=204"}],"version-history":[{"count":1,"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/posts\/204\/revisions"}],"predecessor-version":[{"id":256,"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/posts\/204\/revisions\/256"}],"wp:attachment":[{"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/media?parent=204"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/categories?post=204"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/tags?post=204"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}