Courseiva
Security and Compliance →easyMultiple Select

DOP-C02 Security and Compliance Practice Question

Which TWO actions can help protect an AWS account's root user? (Choose TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Do not create access keys for the root user; use IAM users instead

Not creating access keys for the root user is a best practice because root access keys have full permissions and cannot be restricted. Option C is correct: enabling MFA adds an extra layer of security. Option B is wrong: the root user cannot be deleted. Option D is wrong: rotating the password alone does not protect against unauthorized access; MFA is more important. Option E is wrong: changing the email to a group email does not inherently protect the account and may cause issues with account recovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Do not create access keys for the root user; use IAM users instead

    Why this is correct

    Root access keys are long-lived and carry unrestricted permissions that cannot be scoped down by any IAM policy. If they are leaked, the entire account is compromised, and because AWS does not allow you to restrict root credentials, the keys remain an unmanageable risk. Instead, create IAM users with only the necessary permissions, and use temporary credentials from AWS STS (roles) for programmatic access, so each request is authenticated with least privilege and can be audited.

  • ✗

    Delete the root user after creating administrative IAM users

    Why it's wrong here

    The root user is the account owner entity itself; it cannot be deleted or removed from the account, only closed with the entire AWS account. Even after you create fully privileged administrative IAM users, the root user still exists and is the ultimate fallback for account management, billing, and service limit changes. Trying to 'delete' it is not a supported or valid security control; you must instead secure the root user's credentials and limit its use.

  • ✓

    Enable multi-factor authentication (MFA) on the root user

    Why this is correct

    Enabling MFA on the root user ensures that even if the root user's password is stolen or guessed, an attacker must also possess the physical MFA device to sign in. Since root user actions are exempt from all IAM permission restrictions, MFA is the single most important safeguard for that identity. AWS recommends MFA on root and requires it for certain sensitive operations such as permanently deleting the account, adding virtual MFA, or closing the account.

  • ✗

    Rotate the root user password every 30 days

    Why it's wrong here

    Rotating the root password every 30 days does nothing to mitigate the primary threat vectors: leaked access keys or compromised MFA/credentials used for API calls. Password rotation is only a minor control for the console sign-in path, and root passwords are not generally a high-risk exposure compared to programmatic keys. AWS best practice is to avoid using the root user's password altogether by using IAM users with their own passwords, MFA, and least-privilege policies, rendering periodic rotation largely irrelevant.

  • ✗

    Change the root user's email address to a group email

    Why it's wrong here

    Changing the root user's email to a distribution list or shared group mailbox reduces accountability and expands the number of people with knowledge of the account's recovery channel. AWS sends sensitive security notifications, password reset links, and account alerts to that email address, so a shared recipient can intercept or mishandle those messages. Best practice is to keep a single, actively monitored, individually-owned email address as the root contact, and to enforce MFA and strong passwords on it.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.