Who can manage the access keys for the AWS account root user in an environment using AWS Identity and Access Management (IAM)?
Choose an answer
Tap an option to check your answer.
Correct answer: The AWS account owner.
Why this is the answer
Only the AWS account owner has the authority to manage the access keys for the root user. This is a critical security measure to prevent unauthorized access to the most privileged identity in an AWS account. IAM users and roles, even with extensive permissions, cannot manage the root user's access keys. Their permissions are scoped to actions within the account, not to control the root user itself. This strict separation ensures that the root user remains a highly protected entity, distinct from any IAM identities created within the account.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed