DOP-C02 Security and Compliance Practice Question
Which TWO actions are best practices for securing an AWS account root user? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an IAM user with administrator access and use that instead
Best practices for root user include enabling MFA, using a strong password, and not using root for daily tasks. Deleting the root user is not possible. Access keys should not be created for root user.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the root user for daily administrative tasks
Why it's wrong here
The root user has unrestricted access to all resources and billing. AWS recommends against using root for routine tasks because it cannot be scoped down or audited granularly; any compromise of root credentials is catastrophic. Instead, create IAM users with least privilege and use root only for account-level tasks that require it.
- ✗
Create access keys for the root user to use with CLI
Why it's wrong here
Root access keys grant full, unrestricted API access and cannot be revoked without deleting the account. AWS documentation explicitly advises against creating root access keys because they bypass all IAM permissions and MFA policies. If needed, use IAM users with temporary credentials or role assumption via CLI.
- ✓
Create an IAM user with administrator access and use that instead
Why this is correct
This is a best practice because IAM users can have permissions scoped and credentials rotated independently. An administrator user with the AdministratorAccess managed policy can perform all tasks except account-level root-only actions, while enabling CloudTrail auditing, MFA, and password rotation. Avoid using root for daily work, as IAM users provide traceability and control.
- ✓
Enable multi-factor authentication (MFA) for the root user
Why this is correct
MFA adds a second authentication factor, dramatically reducing risk if root password is compromised. AWS strongly recommends MFA on the root account because root bypasses IAM policies, so stolen credentials grant unrestricted access. This is a foundational security step for any AWS account.
- ✗
Delete the root user after creating an IAM admin user
Why it's wrong here
The root user cannot be deleted; it is the account owner and is required for certain administrative tasks like changing account settings, closing the account, or managing AWS support plans. Attempting to delete root would lock you out of billing and support. Best practice is to protect root with MFA and store credentials securely, not delete it.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO actions can help protect an AWS account's root user? (Choose TWO.)
easy- ✓ A.Do not create access keys for the root user; use IAM users instead
- B.Delete the root user after creating administrative IAM users
- ✓ C.Enable multi-factor authentication (MFA) on the root user
- D.Rotate the root user password every 30 days
- E.Change the root user's email address to a group email
Why A: Not creating access keys for the root user is a best practice because root access keys have full permissions and cannot be restricted. Option C is correct: enabling MFA adds an extra layer of security. Option B is wrong: the root user cannot be deleted. Option D is wrong: rotating the password alone does not protect against unauthorized access; MFA is more important. Option E is wrong: changing the email to a group email does not inherently protect the account and may cause issues with account recovery.
Variation 2. Which TWO actions should a DevOps engineer take to secure an AWS account root user? (Choose 2.)
medium- A.Share the root user password with the team.
- B.Create an IAM role for the root user.
- ✓ C.Delete or disable the root user access keys.
- D.Use the root user for daily administrative tasks.
- ✓ E.Enable multi-factor authentication (MFA) for the root user.
Why C: Option C is correct because deleting or disabling the root user's access keys eliminates a long-lived, highly privileged credential that could be used for programmatic access; AWS best practice is to have no access keys on the root user at all. Option E is correct because enabling MFA on the root user adds a second authentication factor, so a compromised password alone cannot be used to sign in to the account's most powerful identity. Options A, B, and D are not appropriate: sharing the root password violates least privilege and accountability, IAM roles cannot be created for or assumed by the root user (roles are for IAM principals), and using root for daily administrative tasks contradicts the practice of using scoped IAM users or roles for routine work.
Variation 3. Which TWO actions are effective ways to protect an AWS account root user? (Choose 2)
medium- A.Use a strong, complex password and change it every 90 days.
- B.Use the root user for everyday administrative tasks.
- ✓ C.Enable multi-factor authentication (MFA) on the root user.
- D.Rotate the root user password every 30 days.
- ✓ E.Delete or disable the root user access keys.
Why C: Option C is correct because enabling MFA on the root user adds a second authentication factor, so a compromised password alone cannot be used to sign in to the highly privileged root account. Option E is correct because root user access keys grant programmatic access with full account privileges, and AWS best practice is to delete them or, if they cannot be deleted, disable and rotate them so they cannot be abused. Options A and D are not the recommended controls: AWS does not require or recommend periodic root password rotation as a primary protection, and password complexity alone does not mitigate credential theft. Option B is incorrect because using the root user for everyday administrative tasks violates least privilege and greatly increases the blast radius of a compromise; instead, create IAM users or roles with the needed permissions.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.