AWS Solutions Architect Associate (SAA-C03) · Free practice question 12 of 12
Root user protection best practices
A new AWS account has been created for Harrowgate Foods. The security lead wants to follow best practices for protecting the account's root user. Which TWO actions should be taken? (Select TWO.)
- A.Enable multi-factor authentication for the root user
- B.Use the root user for daily administrative tasks to avoid permission issues
- C.Store the root user password in a shared team document so that several leads can use it
- D.Create access keys for the root user so automation scripts can run with full permissions
- E.Avoid creating root user access keys and use IAM Identity Center users or IAM roles for everyday work
Show answer and explanation
Correct answers: A. Enable multi-factor authentication for the root user · E. Avoid creating root user access keys and use IAM Identity Center users or IAM roles for everyday work
Why: AWS recommends protecting the root user with MFA and not creating root access keys, using federated or IAM identities with least privilege for everyday work and reserving the root user for the few tasks that require it. Using the root user daily, sharing its password, or giving it access keys for automation all greatly increase the impact of a credential compromise.
More free AWS Solutions Architect Associate (SAA-C03) questions
- IAM explicit deny overrides allow
- VPC Flow Logs for connectivity troubleshooting
- Transit Gateway instead of peering mesh
- Scheduled scaling for predictable peaks
- RDS point-in-time restore
- Route 53 geolocation routing
- Data Lifecycle Manager for EBS snapshots
- DynamoDB Streams with Lambda
- Amazon MQ for broker migrations
- Graviton instances for price-performance
- Amazon Inspector vulnerability scanning