Which two of the following are AWS best-practice recommendations for using AWS Identity and Access Management (IAM)? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Rotate credentials on a regular schedule., Enable multi-factor authentication (MFA)..
Why this is the answer
Rotating credentials regularly minimizes the risk of unauthorized access if credentials are compromised, aligning with the principle of least privilege and defense in depth. Enabling multi-factor authentication (MFA) adds an extra layer of security by requiring a second verification method beyond just a password, significantly reducing the likelihood of account compromise. Using the root user for daily operations is a security risk as it has unrestricted access; instead, use IAM users with specific permissions. Access keys and secret keys should not be stored directly on EC2 instances; IAM roles are the secure method for granting permissions to applications running on EC2. Sharing access keys among administrators increases the attack surface and makes auditing difficult; each administrator should have their own unique credentials.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed