exam questions

Exam AWS DevOps Engineer Professional All Questions

View all questions & answers for the AWS DevOps Engineer Professional exam

Exam AWS DevOps Engineer Professional topic 1 question 152 discussion

Exam question from Amazon's AWS DevOps Engineer Professional
Question #: 152
Topic #: 1
[All AWS DevOps Engineer Professional Questions]

A company has an organization in AWS Organizations. The company has configured AWS Single Sign-On (AWS SSO) to centrally manage access to the AWS accounts in the organization. A DevOps engineer needs to ensure that all users sign in by using multi-factor authentication (MFA). Users must be allowed to manage their own MFA devices. Users also must be prompted for MFA every time they sign in.

What should the DevOps engineer do to meet these requirements?

  • A. In AWS SSO, configure always-on MFBlock user sign-in when a user does not yet have a registered MFA device.
  • B. In AWS SSO, configure always-on MFA. Require a user to register an MFA device at sign-in when the user does not yet have a registered MFA device.
  • C. In AWS SSO, configure context-aware MFA. Update the trust policy of all permission sets to include the aws:MultiFactorAuthPresent condition on the sts:AssumeRole action.
  • D. In AWS SSO, configure context-aware MFA. Block user sign-in when a user does not yet have a registered MFA device.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Dimidrol
Highly Voted 2 years, 3 months ago
Selected Answer: B
B for me. https://docs.aws.amazon.com/singlesignon/latest/userguide/mfa-enable-how-to.html
upvoted 5 times
...
Piccaso
Most Recent 2 years, 2 months ago
Selected Answer: B
Between "always-on" and "context-aware", we need to use "always-on" because of "must be prompted for MFA every time they sign in". C and D are eliminated https://docs.aws.amazon.com/singlesignon/latest/userguide/mfa-enable-how-to.html Between A and B, B is better https://docs.aws.amazon.com/singlesignon/latest/userguide/how-to-configure-mfa-device-enforcement.html
upvoted 2 times
...
Bulti
2 years, 3 months ago
Selected Answer: B
B is the right answer
upvoted 1 times
...
DerekKey
2 years, 3 months ago
Selected Answer: B
B: On the Configure multi-factor authentication page, under If a user does not yet have a registered MFA device choose one of the following choices: Require them to register an MFA device at sign in
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago