DOP-C02 Security and Compliance Practice Question
Which TWO actions should a DevOps engineer take to secure an AWS account root user? (Choose 2.)
⚠ Common exam trap
DOP-C02 often tests the misconception that the root user can be secured by creating an IAM role or that it should be used for administrative tasks, when in fact the root user cannot assume roles and should be used only for a limited set of account-level operations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Delete or disable the root user access keys.
Option C is correct because deleting or disabling the root user's access keys eliminates a long-lived, highly privileged credential that could be used for programmatic access; AWS best practice is to have no access keys on the root user at all. Option E is correct because enabling MFA on the root user adds a second authentication factor, so a compromised password alone cannot be used to sign in to the account's most powerful identity. Options A, B, and D are not appropriate: sharing the root password violates least privilege and accountability, IAM roles cannot be created for or assumed by the root user (roles are for IAM principals), and using root for daily administrative tasks contradicts the practice of using scoped IAM users or roles for routine work.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Share the root user password with the team.
Why it's wrong here
Sharing the root password grants every team member full unrestricted account control, defeating individual accountability and enabling untracked destructive changes. Credentials should stay with one accountable owner; teams use IAM users, roles and federation for daily access instead.
- ✗
Create an IAM role for the root user.
Why it's wrong here
The root user is an identity, not a principal that can assume a role; IAM roles are assumed by users, services or federated identities, and the root user cannot be given one. It is tempting because roles are the standard way to delegate permissions, and they would be correct for granting EC2 or Lambda access.
- ✓
Delete or disable the root user access keys.
Why this is correct
Deleting or disabling root user access keys removes long-lived credentials that cannot be scoped by IAM policies and are frequently exposed through code commits or misconfigured tooling. Since the root user bypasses permission boundaries entirely, eliminating its programmatic keys satisfies the stem's requirement to secure the account's most privileged identity.
- ✗
Use the root user for daily administrative tasks.
Why it's wrong here
Daily administrative work should be performed by federated or IAM identities with least privilege; the root user bypasses permission boundaries and cannot be restricted by IAM policies. It is tempting because the root user holds full account access, so it would be the correct choice only for the rare tasks that explicitly require root, such as changing the account email.
- ✓
Enable multi-factor authentication (MFA) for the root user.
Why this is correct
Enabling MFA on the root user adds a second authentication factor, so a compromised root password alone cannot grant full account control. This directly satisfies the stem's requirement to secure the root user, since MFA is the primary control protecting that unrestricted identity from credential-based takeover.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.