Courseiva
Security and Compliance →easyMultiple Choice

How to Protect the AWS Root User with Highest Security

A company is setting up their AWS account for the first time. What security action should they take immediately after creating the account?

⚠ Common exam trap

Candidates often think creating IAM users for all employees (Option A) is the immediate priority, but the exam tests the understanding that securing the root account with MFA and creating a single IAM admin user for daily operations is the first and most critical security step, not mass user creation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable MFA on the root account and create an IAM admin user for daily operations

The root user has unrestricted access to the AWS account, and enabling Multi-Factor Authentication (MFA) on the root account adds a critical second layer of security to prevent unauthorized access. Creating an IAM admin user for daily operations follows the principle of least privilege, ensuring that routine administrative tasks are performed using IAM roles or users with controlled permissions, rather than the highly privileged root user. This is a foundational security best practice recommended by AWS immediately after account creation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create IAM users for all employees immediately

    Why it's wrong here

    While IAM users are necessary for day-to-day access, creating them immediately on a new account leaves the root user unchanged and still vulnerable to password compromise. An attacker who compromises root can then modify IAM policies, delete users, or take full control of the account, nullifying any benefit of having initially created IAM users. The correct sequence is to first secure root with MFA, then create an IAM administrator user for daily operations, and finally provision IAM users or roles using IAM Identity Center for employees.

  • ✓

    Enable MFA on the root account and create an IAM admin user for daily operations

    Why this is correct

    Enabling MFA on the root account adds a critical second authentication factor, protecting the account even if the root password is accidentally leaked or brute-forced, and it is the first security best practice Amazon prescribes. Creating an IAM admin user with a scoped policy such as AdministratorAccess allows administrators to perform daily tasks without ever signing in as root, reducing the risk of unintended destructive actions. This approach directly addresses the account’s most sensitive credential and establishes a secure baseline for all subsequent IAM configuration.

  • ✗

    Create root access keys for programmatic access

    Why it's wrong here

    Root access keys are explicitly discouraged by AWS because they grant full, unconditional access to all AWS resources and cannot be restricted with IAM permission boundaries or policies. Once a root access key is created, there is no way to limit its actions, and it must be manually deleted if compromised, making it a persistent security risk. For programmatic access, you should instead create IAM users with least-privilege permissions or assign an IAM role to an EC2 instance or AWS service, which supports temporary credentials and automated rotation.

  • ✗

    Enable AWS Config in all regions

    Why it's wrong here

    AWS Config is a detective service that records resource configuration changes and evaluates compliance, but it does not protect the root account from compromise. On a newly created AWS account, the urgent security priority is to secure the root user with MFA and avoid root access keys, because root credentials have unrestricted access that cannot be limited by IAM. Enabling Config across all regions is valuable for auditing and governance later, but it is not the first action to prevent unauthorized administrative control.

About these practice questions

Courseiva writes every CLF-C02 question from scratch — 993 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.