How to Protect the AWS Root User with Highest Security
A company is setting up their AWS account for the first time. What security action should they take immediately after creating the account?
⚠ Common exam trap
Candidates often think creating IAM users for all employees (Option A) is the immediate priority, but the exam tests the understanding that securing the root account with MFA and creating a single IAM admin user for daily operations is the first and most critical security step, not mass user creation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable MFA on the root account and create an IAM admin user for daily operations
The root user has unrestricted access to the AWS account, and enabling Multi-Factor Authentication (MFA) on the root account adds a critical second layer of security to prevent unauthorized access. Creating an IAM admin user for daily operations follows the principle of least privilege, ensuring that routine administrative tasks are performed using IAM roles or users with controlled permissions, rather than the highly privileged root user. This is a foundational security best practice recommended by AWS immediately after account creation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create IAM users for all employees immediately
Why it's wrong here
While IAM users are necessary for day-to-day access, creating them immediately on a new account leaves the root user unchanged and still vulnerable to password compromise. An attacker who compromises root can then modify IAM policies, delete users, or take full control of the account, nullifying any benefit of having initially created IAM users. The correct sequence is to first secure root with MFA, then create an IAM administrator user for daily operations, and finally provision IAM users or roles using IAM Identity Center for employees.
- ✓
Enable MFA on the root account and create an IAM admin user for daily operations
Why this is correct
Enabling MFA on the root account adds a critical second authentication factor, protecting the account even if the root password is accidentally leaked or brute-forced, and it is the first security best practice Amazon prescribes. Creating an IAM admin user with a scoped policy such as AdministratorAccess allows administrators to perform daily tasks without ever signing in as root, reducing the risk of unintended destructive actions. This approach directly addresses the account’s most sensitive credential and establishes a secure baseline for all subsequent IAM configuration.
- ✗
Create root access keys for programmatic access
Why it's wrong here
Root access keys are explicitly discouraged by AWS because they grant full, unconditional access to all AWS resources and cannot be restricted with IAM permission boundaries or policies. Once a root access key is created, there is no way to limit its actions, and it must be manually deleted if compromised, making it a persistent security risk. For programmatic access, you should instead create IAM users with least-privilege permissions or assign an IAM role to an EC2 instance or AWS service, which supports temporary credentials and automated rotation.
- ✗
Enable AWS Config in all regions
Why it's wrong here
AWS Config is a detective service that records resource configuration changes and evaluates compliance, but it does not protect the root account from compromise. On a newly created AWS account, the urgent security priority is to secure the root user with MFA and avoid root access keys, because root credentials have unrestricted access that cannot be limited by IAM. Enabling Config across all regions is valuable for auditing and governance later, but it is not the first action to prevent unauthorized administrative control.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CLF-C02 question from scratch — 993 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.