Courseiva
Security and Compliance →easyMultiple Select

SOA-C02 Security and Compliance Practice Question

Which TWO measures help protect an AWS account root user? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a strong, complex password for the root user.

Options D and E are correct. Using a strong, complex password and enabling MFA for the root user are essential security measures to protect the account. Option A is incorrect because using the root user regularly increases the risk of compromise; it should be used only for tasks that require root privileges. Option B is incorrect because creating an access key for the root user exposes long-term credentials that can be misused; root user access keys should be avoided. Option C is incorrect because granting other IAM users full administrator access does not directly protect the root user; it reduces dependency on the root user but is not a security measure for the root user itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the root user regularly for administrative tasks.

    Why it's wrong here

    Using the root user for routine administrative tasks contradicts AWS's least-privilege model: the root user is not constrained by any IAM policy, so every session is an all-powerful blast radius if credentials are exposed. Best practice is to lock down root and instead operate daily through IAM roles or users with narrowly scoped permissions, reserving root only for specific account-owner actions.

  • ✗

    Create an access key for the root user for programmatic access.

    Why it's wrong here

    Root user access keys cannot be restricted by IAM policies—they are effectively a second, non-rotating administrative credential that grants full API access to every service in the account. Unlike IAM roles, these keys also cannot be tied to a rotation schedule or condition keys, making them a standing risk. AWS explicitly discourages creating root access keys; if they are ever created, they should be deleted.

  • ✗

    Grant other IAM users full administrator access.

    Why it's wrong here

    Replacing root-user logins with IAM users is generally encouraged, but granting those users full administrator access is not a protection for the root account itself: it merely shifts the privileged identity to somewhere else, and full AdministratorAccess violates least privilege. The root user's security remains solely dependent on its own password, MFA, and absence of access keys. Thus this option is an indirect and overly broad IAM strategy rather than a valid root-protection measure.

  • ✓

    Use a strong, complex password for the root user.

    Why this is correct

    A strong, complex password for the root user is a core, direct defensive control because the root account bypasses all IAM policies, so the console password is the only baseline barrier against unauthorized sign-ins. A long mix of characters, coupled with the absence of the password being reused elsewhere, materially reduces the risk of credential-stuffing and forced-entry attacks. AWS recommends a minimum of 14 characters for the root password.

  • ✓

    Enable multi-factor authentication (MFA) for the root user.

    Why this is correct

    Enabling multi-factor authentication (MFA) on the root user adds a second authentication requirement, so knowledge of the password alone is insufficient to access the account. Because root has irrevocable permissions over billing, IAM, and every service, MFA is the single highest-impact control to mitigate password theft or leakage. AWS explicitly mandates MFA for root in its best-practice documentation.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.