Courseiva

SCS-C02 Management and Security Governance Practice Question

Which TWO actions are best practices for securing an AWS account root user? (Select TWO.)

⚠ Common exam trap

SCS-C02 often tests root user security; candidates may think the root user can be deleted or that access keys are acceptable, but the root user cannot be deleted and access keys should be avoided.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an IAM user with administrative privileges and use it instead of the root user.

Option D is correct because AWS best practice is to create an IAM user (or federated identity) with the required administrative permissions and use that identity for day-to-day administration, reserving the root user only for the few tasks that specifically require it, such as changing the account name, closing the account, or changing the support plan. Option E is correct because enabling multi-factor authentication (MFA) on the root user adds a second authentication factor, so a compromised root password alone is insufficient to sign in; AWS strongly recommends a hardware MFA device for the root user. Option A is wrong because using the root user for everyday administrative tasks violates least privilege and greatly increases the blast radius if those credentials are compromised. Option B is wrong because AWS advises against creating access keys for the root user; if root access keys already exist, they should be deleted, since long-lived root keys are a major security risk. Option C is wrong because the root user cannot be deleted; it is permanently tied to the account and can only be secured by protecting its credentials and limiting its use.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the root user for everyday administrative tasks.

    Why it's wrong here

    Using the root user for everyday administrative tasks is dangerous because the root user has unrestricted, irrevocable access to all AWS resources and cannot be scoped down by IAM policies. Any mistake, credential leak, or session hijack involving the root user therefore exposes the entire account to compromise. Best practice is to secure root credentials in a safe location, never use them for routine work, and instead operate through IAM roles or users with least-privilege permissions.

  • ✗

    Create access keys for the root user.

    Why it's wrong here

    Creating access keys for the root user is strongly discouraged because those keys are long-term credentials that inherit the root user's full administrative power and are not tied to any IAM permissions boundary. If leaked, they can be used to delete resources, exfiltrate data, or take over the account, and unlike IAM user access keys, they cannot be rotated through the IAM console in a controlled way. AWS recommends never creating root access keys; use IAM users or IAM roles with temporary credentials for programmatic access.

  • ✗

    Delete the root user to prevent unauthorized access.

    Why it's wrong here

    The root user cannot be deleted because it is the account owner and is required for certain account-level operations such as closing the account, changing support plans, or registering as a seller in the AWS Marketplace. Attempting to delete it is impossible; the only way to mitigate root-user risk is to enable MFA, use a strong password, and avoid using root credentials for daily tasks. In Organizations, you can apply a service control policy (SCP) to restrict root user actions, but the account owner identity itself remains.

  • ✓

    Create an IAM user with administrative privileges and use it instead of the root user.

    Why this is correct

    Creating an IAM user with administrative privileges and using that user for day-to-day management reduces the exposure of the root user credentials, which is a core AWS account security best practice. This allows you to enforce MFA, assign permissions via IAM policies, rotate credentials, and audit actions through CloudTrail, none of which are possible with the root user in a least-privilege manner. While AWS now recommends using IAM Identity Center with roles for human access, an admin IAM user protected by MFA is still a valid baseline for root-user credential protection.

  • ✓

    Enable MFA on the root user.

    Why this is correct

    Enabling MFA on the root user is a critical control because the root user has unrestricted access to all AWS resources and account settings, and a compromised root password alone could lead to full account takeover. MFA adds a second authentication factor that an attacker would need to bypass, significantly reducing the risk of unauthorized access even if the password is stolen or phished. AWS itself requires root user MFA as a best practice, and many compliance frameworks mandate it as an essential safeguarding step for cloud accounts.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.