⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Senior DevOps / SRE [L2] Security Production Scenario [L2]

Q: Our company mandates MFA (Multi-Factor Authentication) for all AWS Console logins. However, developers are still using static AWS Access Keys in their local terminals which bypasses MFA. How do you enforce MFA for CLI access?

Static AWS CLI access keys are essentially single-factor authentication. To enforce MFA on the CLI:

#Security #Security #L2 #DevSecOps #Compliance #IAM
🎙️ Candidate Opening & Architectural Context
""In our DevSecOps implementation, we solved this by introducing automated security quality gates. The interviewer is testing: STS GetSessionToken, IAM condition keys for MFA.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Initial Diagnostics & Root Cause Analysis

Static AWS CLI access keys are essentially single-factor authentication. To enforce MFA on the CLI:

  • Apply an IAM Policy Condition to the developers' IAM Group that explicitly denies all actions unless the aws:MultiFactorAuthPresent boolean is set to true.
  • The developers must now use the aws sts get-session-token command, passing in their MFA device serial number and the 6-digit code from their authenticator app.
  • STS returns a temporary Access Key, Secret Key, and Session Token. These temporary credentials carry the MFA claim, allowing the developer to bypass the IAM deny policy for the duration of the token (typically 8-12 hours). Tooling like AWS SSO v2 handles this seamlessly via browser popups.
2️⃣

Remediation & Permanent Safeguards

💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Apply an IAM Policy Condition to the developers' IAM Group that explicitly denies all actions unless the aws:MultiFactorAuthPresen."
⚡ 60-Second Elevator Pitch Talking Points
  • Apply an IAM Policy Condition to the developers' IAM Group that explicitly denies all actions unl...
  • The developers must now use the aws sts get-session-token command, passing in their MFA device se...
  • STS returns a temporary Access Key, Secret Key, and Session Token. These temporary credentials ca...
Advertisement
Want more Security scenarios?
Explore our complete collection of scenario-based Security interview runbooks.
Browse All Security Questions →

📚 Related Production Scenarios in Security