A company with many member accounts in AWS Organizations is concerned about potential misuse of root user credentials. The company wants to ensure that even if root credentials are compromised, the account remains protected. Which solution meets this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Use service control policies (SCPs) to block service access for the root user..
Why this is the answer
Service control policies (SCPs) are a feature of AWS Organizations that allow you to manage permissions in your organization. You can use SCPs to set guardrails and define the maximum available permissions for all accounts in your organization, including the root user. By applying an SCP that explicitly denies specific high-risk actions for the root user, you can effectively limit the damage even if the root user credentials are compromised. Removing the root user's password is not possible; a root user always has a password. Deleting root access keys is a good security practice but doesn't prevent actions performed with the root user's password. Creating an Amazon EventBridge rule to detect root user API activity is a valuable monitoring tool but acts reactively, after an event occurs, rather than proactively preventing the actions.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed