An account's root user has multi-factor authentication enabled, but the physical MFA device was lost. A SysOps administrator must change the account's AWS Support plan. How should the administrator sign in to proceed?
Choose an answer
Tap an option to check your answer.
Correct answer: Sign in as the root user by verifying the account email and phone, then configure a new MFA device and update the root password..
Why this is the answer
If the root user's MFA device is lost, AWS provides a specific recovery process. The administrator must initiate the root user sign-in process. When prompted for the MFA code, they should select the option for a lost or unavailable MFA device. This triggers a verification process that typically involves verifying the account's registered email address and phone number. Once identity is confirmed, AWS allows the root user to proceed with signing in. After gaining access, the administrator should immediately configure a new MFA device for the root user to re-establish this critical security layer and then update the root password as a best practice. Signing in as an IAM user, even with administrator privileges, cannot reset the root user's MFA or resynchronize a lost root MFA token. IAM users do not have permissions to manage the root account's security credentials directly. The forgot-password workflow is primarily for resetting the password and doesn't directly address the lost MFA device scenario for the root user in the same way the dedicated MFA recovery process does.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed