When configuring AWS Identity and Access Management (IAM), which practice follows security best practices?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable multi-factor authentication (MFA) to add extra protection at sign-in..
Why this is the answer
Enabling multi-factor authentication (MFA) is a fundamental security best practice for AWS IAM. MFA adds an extra layer of security by requiring a second form of verification in addition to a password, significantly reducing the risk of unauthorized access even if credentials are stolen. Using the account root user access keys for administrative tasks is highly discouraged due to the extensive permissions of the root user; it should only be used for tasks that specifically require it. Granting broad permissions violates the principle of least privilege, which dictates that users should only have the minimum permissions necessary to perform their job functions. Avoiding credential rotation is a security risk, as regular rotation helps mitigate the impact of compromised credentials.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed