passdrill
AWS SAA-C03 · IAM & Security · Card 021/024 easy

A newly created AWS account's root user currently has no MFA device configured and an active access key that a script uses to run a daily automated task. Which change best aligns with AWS root user security best practices?

  1. Keep using the root access key for the daily script, since only the root user can guarantee sufficient permissions, and add a second root access key for redundancy
  2. Enable MFA on the root user, delete the root user's access keys, and move the daily automated task to an IAM role or IAM user that has only the permissions it needs
  3. Disable MFA entirely on every user in the account including root, since MFA devices are a common cause of account lockouts
  4. Create several additional root users, one per team, so that no single team depends on the same root credentials
Next card → Shuffle