Courseiva

SCS-C02 Management and Security Governance Practice Question

Exhibit

Refer to the exhibit.

$ aws organizations list-accounts
{
    "Accounts": [
        {
            "Id": "111111111111",
            "Arn": "arn:aws:organizations::111111111111:account/o-exampleorgid/111111111111",
            "Email": "admin@company.com",
            "Name": "Management",
            "Status": "ACTIVE",
            "JoinedMethod": "CREATED",
            "JoinedTimestamp": 1570000000.0
        },
        {
            "Id": "222222222222",
            "Arn": "arn:aws:organizations::111111111111:account/o-exampleorgid/222222222222",
            "Email": "dev@company.com",
            "Name": "Development",
            "Status": "ACTIVE",
            "JoinedMethod": "INVITED",
            "JoinedTimestamp": 1570000001.0
        },
        {
            "Id": "333333333333",
            "Arn": "arn:aws:organizations::111111111111:account/o-exampleorgid/333333333333",
            "Email": "prod@company.com",
            "Name": "Production",
            "Status": "ACTIVE",
            "JoinedMethod": "INVITED",
            "JoinedTimestamp": 1570000002.0
        }
    ]
}

A security engineer is auditing the AWS Organizations structure. The engineer notices that the 'Management' account (111111111111) has a status of 'ACTIVE' and joined method 'CREATED'. The engineer is concerned about potential security risks. Which action should the engineer take to improve security?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable multi-factor authentication (MFA) for the root user of the management account.

The management account in AWS Organizations is the account that created the organization and has full administrative access. It is critical to secure this account, and enabling multi-factor authentication (MFA) for the root user is a fundamental security best practice. Option A is incorrect because you cannot remove the management account from the organization; it is the foundational account. Option B is incorrect because you cannot delete the management account; you would need to delete the entire organization. Option C is incorrect because you cannot delete the root user; it is a built-in user that cannot be removed. Therefore, enabling MFA on the root user of the management account is the appropriate action to improve security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remove the management account from the organization.

    Why it's wrong here

    In AWS Organizations, the management account is the foundational account that created the organization; it cannot be removed while the organization exists. Attempting to remove it would leave the organization without a root or payer account, and any member accounts, consolidated billing, and service control policies would become orphaned or lost. Closing or restructuring the organization is a completely separate process that still leaves the management account in place until a full shutdown.

  • ✗

    Delete the management account and create a new one.

    Why it's wrong here

    The management account is not just a regular account that can be deleted; it is the parent of the entire organization and its deletion would automatically close the organization and all member accounts. Even if you closed it and created a new account, you would lose all organization-wide policies, delegated administrators, and billing preferences, forcing a complete redesign. Furthermore, AWS prevents you from deleting an account that still has active member accounts, so this approach is neither feasible nor a security control.

  • ✗

    Create a new root user for the management account and delete the old one.

    Why it's wrong here

    The root user is the account-level identity tied to the primary email address and password of the management account; there is no mechanism to create a second root user or delete the original one. The root user is the only identity with unrestricted administrative permissions that cannot be revoked by an IAM policy, so it cannot be swapped out. The correct action is to secure the existing root user with MFA and rotate its password, not to attempt an impossible replacement.

  • ✓

    Enable multi-factor authentication (MFA) for the root user of the management account.

    Why this is correct

    Enabling multi-factor authentication (MFA) on the management account's root user is a mandatory security best practice because the root user holds unrestricted permissions across the entire organization, including billing and the ability to close accounts. Without MFA, a compromised password or access key for the root user grants an attacker complete control of the organization's structure and member accounts. MFA forces a second authentication factor, mitigating password theft or phishing attacks on that critical identity.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.