Multi-Factor Authentication
Requiring a second verification factor beyond a password to sign in.
Multi-Factor Authentication (MFA) adds a second identity check beyond a password, typically a time-based one-time code from a hardware device or virtual authenticator app. AWS supports MFA for IAM users and the root user, and now requires MFA for the root user across account types as part of a phased rollout. On the exam, remember scope: enabling root MFA protects the account’s most privileged identity, while MFA on individual IAM users is a strong best practice. Pairing MFA with least-privilege IAM policies illustrates defense in depth, layering multiple controls.
PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →