AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard
A company using AWS Organizations wants to minimize risk from its management (payer) account, since actions taken there can affect all member accounts, including the ability to close accounts or leave the organization. What is the recommended security best practice for the management account's root user?
- AEnable MFA on the root user, avoid using it for daily tasks, and delegate operations to IAM roles or users with least privilege instead
- BUse the root user for daily administrative tasks since it has the broadest permissions
- CDelete the root user credentials entirely after account creation to prevent any misuse
- DShare the root user credentials among senior administrators for redundancy in case of emergencies
Show answer & explanationAnswer & explanation
Correct answer: A. Enable MFA on the root user, avoid using it for daily tasks, and delegate operations to IAM roles or users with least privilege instead
Best practice for the management account is to secure the root user with MFA, use it only for tasks that specifically require root, and delegate routine administration to IAM users/roles following least privilege, since compromise of the management account root user can impact the entire organization.
Why the other options are wrong
- B. Using root daily increases risk of accidental or malicious high-impact actions
- C. Root user credentials cannot be deleted; the root user account itself cannot be removed
- D. Sharing root credentials violates security best practices and eliminates accountability
Management Account Root Security
In AWS Organizations, the management account's root user has organization-wide power, so it must be secured with MFA and used minimally, delegating tasks to IAM roles/users.
- Management account actions can affect all member accounts
- Root user credentials cannot be deleted, only secured and restricted in use
- Best practice: enable MFA, use hardware key if possible, avoid routine use
Memory trick: The master key to the whole kingdom stays locked in a vault, not on a keychain.