SCS-C02 exam dumps

SCS-C02 practice question 439 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 439

Select 3

Your organization has recently set up a new AWS account. As a security best practice, what steps should you take to secure the root account of the AWS account?

  1. A

    Enable multi-factor authentication (MFA) for the root account.

  2. B

    Create an IAM user with administrative privileges and stop using the root account for day-to-day operations.

  3. C

    Share the root account credentials with trusted team members for backup access.

  4. D

    Delete the root account access keys if they are not needed.

  5. E

    Use the root account to manage IAM roles and policies on a regular basis.

Show answer and explanation

Correct answers: A, B, D

Explanation

Securing the root account is a critical security best practice in AWS. This includes enabling MFA to add an extra layer of protection, minimizing the use of the root account, and delegating administrative tasks to IAM users. Additionally, deleting unused root access keys reduces the risk of accidental or malicious use. Root account credentials should never be shared, and the root account should only be used for essential tasks such as creating the initial IAM user or setting up billing information.

  • A. Correct.

    Correct. Enabling MFA for the root account adds an additional layer of security to prevent unauthorized access.

  • B. Correct.

    Correct. It is recommended to create an IAM user with administrative privileges and use it for daily tasks instead of the root account, which should only be used for specific account management purposes.

  • C. Incorrect.

    Incorrect. Sharing root account credentials is a significant security risk and violates best practices. Root account credentials should never be shared.

  • D. Correct.

    Correct. If root account access keys are not needed, they should be deleted as they pose a security risk if compromised.

  • E. Incorrect.

    Incorrect. The root account should not be used for regular operations, such as managing IAM roles and policies. Use an IAM user with the appropriate permissions instead.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam