ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 439 - CLF-C02 discussion

Report
Export

Which actions are best practices for an AWS account root user? (Select TWO.)

A.
Share root user credentials with team members.
Answers
A.
Share root user credentials with team members.
B.
Create multiple root users for the account, separated by environment.
Answers
B.
Create multiple root users for the account, separated by environment.
C.
Enable multi-factor authentication (MFA) on the root user.
Answers
C.
Enable multi-factor authentication (MFA) on the root user.
D.
Create an IAM user with administrator privileges for daily administrative tasks, instead of using the root user.Use programmatic access instead of the root user and password.
Answers
D.
Create an IAM user with administrator privileges for daily administrative tasks, instead of using the root user.Use programmatic access instead of the root user and password.
Suggested answer: C, D

Explanation:

The AWS account root user is the identity that has complete access to all AWS services and resources in the account. It is accessed by signing in with the email address and password that were used to create the account1. The root user should be protected and used only for a few account and service management tasks that require it1. Therefore, the following actions are best practices for an AWS account root user:

Enable multi-factor authentication (MFA) on the root user. MFA is a security feature that requires users to provide two or more pieces of information to authenticate themselves, such as a password and a code from a device. MFA adds an extra layer of protection for the root user credentials, which can access sensitive information and perform critical operations in the account2.

Create an IAM user with administrator privileges for daily administrative tasks, instead of using the root user. IAM is a service that helps customers manage access to AWS resources for users and groups. Customers can create IAM users and assign them permissions to perform specific tasks on specific resources. Customers can also create IAM roles and policies to delegate access to other AWS services or external entities3. By creating an IAM user with administrator privileges, customers can avoid using the root user for everyday tasks and reduce the risk of accidental or malicious changes to the account1.

asked 16/09/2024
Mounir Mrabet
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first