Courseiva

SCS-C02 Management and Security Governance Practice Question

Which TWO actions should a security engineer take to protect root user credentials? (Select TWO.)

⚠ Common exam trap

Candidates often think the root user can be deleted or that using it only for billing is acceptable, but AWS explicitly prohibits deleting the root user and recommends using IAM users with billing permissions instead.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Do not create access keys for the root user

AWS strongly recommends that you do not create access keys for the root user. Access keys provide programmatic access to the AWS API, and if compromised, an attacker would have unrestricted access to all AWS resources and billing information. By not creating access keys, you eliminate this high-risk attack vector.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the root user only for billing

    Why it's wrong here

    Using the root user for billing tasks still exposes a credential with full administrative power to every AWS service. AWS's Well-Architected guidance explicitly says to use the root user only for tasks that require it, and such tasks are rare; billing should be handled with IAM policies granting billing access. Even a limited use case like billing should include MFA and monitoring.

  • ✗

    Share the root user credentials with the security team

    Why it's wrong here

    Sharing root user credentials multiplies the potential for misuse because every team member becomes a bearer of the account's highest-privilege credentials. It destroys auditability -- CloudTrail cannot attribute root-user actions to a specific individual, only to 'Root'. Instead, create individual IAM users, assign least-privilege permissions, and use roles for administrative tasks.

  • ✓

    Do not create access keys for the root user

    Why this is correct

    Access keys for the root user are long-term static credentials that bypass the password and MFA protections on the AWS console, enabling direct API calls with full account authority. AWS explicitly warns that root access keys cannot be rotated like IAM user keys and can only be deleted, making any leak a catastrophic risk. Avoiding root access keys entirely -- and using temporary credentials from IAM roles or federation -- is the recommended safeguard.

  • ✓

    Enable MFA on the root user account

    Why this is correct

    Enabling MFA on the root user adds a second authentication factor, so a stolen password alone is insufficient to sign in. This is a fundamental safeguard because root user credentials cannot be scoped down or deleted, and they grant access to all AWS services and resources. AWS strongly recommends, and the Well-Architected framework requires, MFA on the root account as a baseline control.

  • ✗

    Delete the root user account

    Why it's wrong here

    The root user is the account owner's identity and cannot be deleted; even after closing the account, the root user still exists and can in some cases be used to reopen it. Deleting credentials that cannot be removed leads to an unusable account or requires closing the entire AWS account, which is not a security measure. The correct approach is to protect the root user with MFA and avoid using its credentials for everyday operations.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.