Let CLI users satisfy an MFA-required policy with aws sts get-session-token and MFA parameters

Answer Correct answer: B — users run aws sts get-session-token with MFA serial and token code, then use the temporary credentials for CLI calls.

An AWS account administrator created an IAM group and applied the following managed policy to require that each individual user authenticate using multi-factor authentication: After implementing the policy, the administrator receives reports that users are unable to perform Amazon EC2 commands using the AWS CLI. What should the administrator do to resolve this problem while still enforcing multi-factor authentication? - image

  1. Change the value of aws:MultiFactorAuthPresent to true.
  2. Instruct users to run the aws sts get-session-token CLI command and pass the multi-factor authentication --serial-number and -token-code parameters. Use these resulting values to make API/CLI calls. Correct Answer
  3. Implement federated API/CLI access using SAML 2.0, then configure the identity provider to enforce multi-factor authentication.
  4. Create a role and enforce multi-factor authentication in the role trust policy. Instruct users to run the sts assume-role CLI command and pass --serial-number and --token-code parameters. Store the resulting values in environment variables. Add sts:AssumeRole to NotAction in the policy.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Long-term IAM user keys do not satisfy an MFA-required policy. sts get-session-token with MFA parameters returns short-term credentials whose requests are evaluated as MFA-present, so they pass the policy condition. The temporary access key, secret, and session token are used for the actual CLI calls.

An IAM group policy denies actions unless the request includes MFA (aws:MultiFactorAuthPresent), so users cannot run EC2 CLI commands with their long-term keys. The fix is for users to call aws sts get-session-token passing --serial-number and --token-code, producing temporary credentials that carry the MFA condition, then use those temporary credentials for subsequent CLI/API calls. This keeps MFA enforcement while restoring CLI access.

Setting aws:MultiFactorAuthPresent to true in the policy (option A)—that would weaken/break the enforcement, not help users authenticate. Or assuming federated SAML (C) or assume-role (D) is required; get-session-token is the direct CLI solution for an MFA-conditioned user policy.

Community Discussion (5 comments)

molerowan 👍 1 Selected: B
aws sts get-session-token with MFA parameters creates temporary credentials that include MFA verification These temporary credentials (access key, secret key, and session token) can be used for subsequent CLI calls The AWS CLI will then recognize these requests as being made with MFA authentication, satisfying the policy condition
nublit 👍 1 Selected: B
B for sure
awssecuritynewbie 👍 1 Selected: B
B for sure they required to enable CLI
sarcactus 👍 3 Selected: B
I agree with MikeRach comment.
MikeRach 👍 1
B https://www.examtopics.com/discussions/amazon/view/47596-exam-aws-certified-security-specialty-topic-1-question-225/

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The policy denies calls unless MFA is present, which long-term keys cannot satisfy. aws sts get-session-token with the MFA serial number and token code returns temporary credentials that are treated as MFA-authenticated; using those credentials for subsequent CLI calls satisfies the condition and restores EC2 command access without relaxing the policy.

Why the Other Options Are Wrong

A changes the policy value to true, which would defeat MFA enforcement rather than help users authenticate. C (SAML federation) and D (assume-role) are alternative architectures but unnecessary; get-session-token is the straightforward way for existing IAM users to obtain MFA-validated temporary credentials for the CLI. B is the correct, minimal fix.

Community Comment Notes

Community voted B (100). Commenters explained that get-session-token with MFA parameters yields temporary credentials recognized as MFA-present, satisfying the policy for CLI calls. The policy JSON is shown in the question image; the stated requirement (MFA enforcement) makes B the canonical solution.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide