A company's security policy requires that the AWS account root user must have multi-factor authentication (MFA) enabled. A SysOps administrator needs to continuously verify compliance and automatically notify the security team if the root user is not configured with MFA. Which AWS service can be used to create a compliance rule for this requirement?
AWS Config with the managed rule 'root-account-mfa-enabled' continuously evaluates the root user's MFA configuration against the rule's desired state. When the root account becomes non-compliant, AWS Config can publish configuration change notifications to Amazon SNS via EventBridge, allowing automated alerting and remediation. This rule is available as a managed rule and works across all supported regions and accounts with minimal setup, making it the correct choice for verifying and monitoring root MFA compliance.
Why this answer
AWS Config provides a managed rule called 'root-account-mfa-enabled' that continuously evaluates whether the root user has an MFA device configured. When the rule detects non-compliance, it can trigger an Amazon SNS notification to alert the security team, meeting the requirement for automated compliance verification and alerting.
Exam trap
The trap here is that candidates confuse AWS Trusted Advisor's security checks (which include a root MFA check but lack continuous evaluation and automated notification) with AWS Config's managed rules that provide ongoing compliance monitoring and event-driven alerts.
How to eliminate wrong answers
Option A is wrong because AWS Trusted Advisor provides best-practice checks and recommendations but does not offer continuous compliance rules with automated notifications for root user MFA status. Option C is wrong because IAM Access Analyzer analyzes resource policies for external access, not root user MFA configuration compliance. Option D is wrong because Amazon Inspector assesses vulnerabilities in EC2 instances and container workloads, not IAM user configurations.