A security administrator needs to restrict use of root user credentials across member accounts in an AWS Organizations organization. All features are enabled. The management account is used only for billing and administration, not for operations. How can the administrator restrict member account root user usage across the organization?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an OU in Organizations, attach a service control policy (SCP) that restricts root user usage, and add all member accounts to the OU..
Why this is the answer
Service control policies (SCPs) are a feature of AWS Organizations that allow you to manage permissions in your organization. They can be used to restrict the actions that users and roles in member accounts can perform, including the root user. By creating an Organizational Unit (OU), attaching an SCP that explicitly denies actions for the root user, and then moving all member accounts into this OU, the administrator can effectively restrict root user usage across the organization. The other options are less effective: Disabling the root user at the organization root is not possible; the root user is fundamental. Enabling MFA for the root user is a good security practice but doesn't restrict its capabilities. IAM user policies apply to IAM users and roles, not the root user itself. CloudTrail and CloudWatch Logs integration with a metric filter helps monitor root user activity but does not prevent or restrict its usage.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed