Which actions are recommended best practices for an AWS account root user? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Enable multi-factor authentication (MFA) on the root user., Create an IAM user with administrator privileges for routine administrative tasks instead of using the root user..
Why this is the answer
Enabling multi-factor authentication (MFA) on the root user significantly enhances security by requiring a second verification step, making it much harder for unauthorized users to gain access even if they have the password. Creating an IAM user with administrator privileges for routine tasks is a best practice because the root user has unrestricted access to all resources in the AWS account. Using an IAM user with specific permissions minimizes the potential impact of compromised credentials. Sharing root user credentials or creating multiple root users are severe security risks, as they broaden the attack surface and make accountability difficult. While programmatic access is important, it doesn't replace the need for secure root user practices.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed