Enforce MFA on S3 CLI access with STS temporary credentials

Answer Correct answer: D — Deny S3 actions unless MFA is present on the S3-access group and have engineers use STS temporary credentials in an S3 profile.

A solutions architect must provide a secure way for a team of cloud engineers to use the AWS CLI to upload objects into an Amazon S3 bucket. Each cloud engineer has an IAM user, IAM access keys, and a virtual multi-factor authentication (MFA) device. The IAM users for the cloud engineers are in a group that is named S3-access. The cloud engineers must use MFA to perform any actions in Amazon S3. Which solution will meet these requirements?

  1. Attach a policy to the S3 bucket to prompt the IAM user for an MFA code when the IAM user performs actions on the S3 bucket. Use IAM access keys with the AWS CLI to call Amazon S3.
  2. Update the trust policy for the S3-access group to require principals to use MFA when principals assume the group. Use IAM access keys with the AWS CLI to call Amazon S3.
  3. Attach a policy to the S3-access group to deny all S3 actions unless MFA is present. Use IAM access keys with the AWS CLI to call Amazon S3.
  4. Attach a policy to the S3-access group to deny all S3 actions unless MFA is present. Request temporary credentials from AWS Security Token Service (AWS STS). Attach the temporary credentials in a profile that Amazon S3 will reference when the user performs actions in Amazon S3. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Long-lived access keys carry no proof of MFA at the time of the call, so the enforcement point has to be a credential issued by AWS STS in an AssumeRole call that presents the MFA code, which yields temporary credentials that the CLI profile then uses.

Cloud engineers must upload objects to an S3 bucket using the AWS CLI with their own IAM user access keys, and every S3 action must require MFA. Each engineer already has a virtual MFA device and belongs to the S3-access group.

Relying on an S3 bucket policy to prompt for MFA. A bucket policy is an authorization control evaluated on the request, and it cannot force the CLI to present an MFA code, so the engineers could still authenticate with plain access keys and never be challenged.

Community Discussion (6 comments)

pangchn 👍 5 Selected: D
D STS seems to be the answer https://advancedweb.hu/aws-how-to-secure-access-keys-with-mfa/ https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa_configure-api-require.html
0b43291 👍 1 Selected: D
The other options have limitations or do not fully meet the requirements: Option A (bucket policy with MFA prompt) does not enforce MFA for all S3 actions and may not work consistently with the AWS CLI. Option B (trust policy update for the group) does not enforce MFA for S3 actions specifically and may not work as intended with the AWS CLI. Option C (deny policy without temporary credentials) would require the cloud engineers to use their long-term IAM access keys, which is less secure and does not follow the principle of least privilege. By using temporary credentials obtained from AWS STS with MFA enforcement and attaching them to a named profile in the AWS CLI, you can provide a secure way for the cloud engineers to perform S3 operations while ensuring that MFA is required for those actions.
AzureDP900 👍 1
Option D uses IAM access keys with the AWS CLI and requests temporary credentials from AWS Security Token Service (AWS STS) that include MFA. This solution ensures that cloud engineers must use MFA when performing actions in Amazon S3 while also providing a secure way to use the AWS CLI. This approach aligns with the requirements of using MFA for S3 actions, minimizing security risks, and ensuring compliance with organizational policies.
VerRi 👍 4 Selected: D
access keys with AWS CLI will just skip the MFA
Dgix 👍 1 Selected: D
D is the correct answer, as STS is required here.
CMMC 👍 1 Selected: D
A & C are incorrect - Using IAM access keys with the AWS CLI would bypass the requirement for MFA. Not B - MFA should be required for specific actions, not just when assuming a role or group.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A policy attached to the S3-access group denies all S3 actions unless MFA is present in the request context, and the context key it tests is only populated when the credentials were obtained through an AWS STS AssumeRole call that included an MFA code. So the engineer runs get-session-token or AssumeRole supplying the MFA code, receives temporary credentials, and configures those in a CLI profile. Every subsequent S3 call carries the resulting session, and because the session was issued with MFA present, the deny statement's condition is satisfied and the call is allowed. The temporary credentials also expire, which removes the standing long-lived key risk.

Why the Other Options Are Wrong

A: An S3 bucket policy is attached to the bucket, not to users, and more importantly a bucket policy cannot prompt for or validate an MFA code, so nothing forces the MFA challenge. B: A trust policy belongs on a role, and a group is not a role that can be assumed, so there is no trust relationship to attach a condition to. C: The deny-unless-MFA policy is correct, but using IAM access keys with the CLI bypasses it, because access key authentication does not produce a session context containing MFA. Only temporary credentials from STS do.

Community Comment Notes

The community voted 100 to 0 for D, and the reasoning was consistent: access keys used with the CLI simply skip the MFA requirement, so STS-issued temporary credentials are the only way to make the group policy's MFA condition effective. A commenter linked the AWS documentation on requiring MFA for API operations and another on securing access keys with MFA.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide