List of questions
Related questions
Question 298 - SCS-C02 discussion
A company has two AWS accounts: Account A and Account B. Account A has an IAM role that IAM users in Account B assume when they need to upload sensitive documents to Amazon S3 buckets in Account A.
A new requirement mandates that users can assume the role only if they are authenticated with multi-factor authentication (MFA). A security engineer must recommend a solution that meets this requirement with minimum risk and effort.
Which solution should the security engineer recommend?
A.
Add an aws:MultiFactorAuthPresent condition to therole's permissions policy.
B.
Add an aws:MultiFactorAuthPresent condition to therole's trust policy.
C.
Add an aws:MultiFactorAuthPresent condition to thesession policy.
D.
Add an aws:MultiFactorAuthPresent condition to theS3 bucket policies.
Your answer:
0 comments
Sorted by
Leave a comment first