exam questions

Exam AWS Certified Cloud Practitioner CLF-C02 All Questions

View all questions & answers for the AWS Certified Cloud Practitioner CLF-C02 exam

Exam AWS Certified Cloud Practitioner CLF-C02 topic 1 question 39 discussion

A company is setting up AWS Identity and Access Management (IAM) on an AWS account.
Which recommendation complies with IAM security best practices?

  • A. Use the account root user access keys for administrative tasks.
  • B. Grant broad permissions so that all company employees can access the resources they need.
  • C. Turn on multi-factor authentication (MFA) for added security during the login process.
  • D. Avoid rotating credentials to prevent issues in production applications.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
TheFivePips
Highly Voted 1 year, 3 months ago
Selected Answer: C
A. Use the account root user access keys for administrative tasks: It is not recommended to use the root user's access keys for day-to-day administrative tasks. The root user has unrestricted access, and using its access keys poses security risks. B. Grant broad permissions so that all company employees can access the resources they need: It's advisable to follow the principle of least privilege, granting users only the permissions they need to perform their tasks. C. Turn on multi-factor authentication (MFA) for added security during the login process: Enabling multi-factor authentication (MFA) is a security best practice. It adds an extra layer of protection by requiring users to provide a second form of authentication in addition to their password. This helps prevent unauthorized access even if credentials are compromised. D. Avoid rotating credentials to prevent issues in production applications: Regularly rotating credentials, such as access keys and passwords, enhances security by reducing the window of opportunity for attackers.
upvoted 7 times
...
Sir_Kay
Most Recent 2 months ago
Selected Answer: C
nabling Multi-Factor Authentication (MFA) is a key IAM security best practice because it adds an extra layer of security by requiring a second form of authentication (such as a one-time code from an authenticator app or a hardware token) in addition to a password.
upvoted 1 times
...
Amin_013
3 months, 4 weeks ago
Selected Answer: C
C. Turn on multi-factor authentication (MFA) for added security during the login process.
upvoted 1 times
...
GPFT
8 months, 1 week ago
Selected Answer: C
c is ok
upvoted 1 times
...
Ruffyit
1 year, 2 months ago
https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html
upvoted 1 times
...
petercorn
1 year, 5 months ago
Selected Answer: C
https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html
upvoted 2 times
...
asdfcdsxdfc
1 year, 5 months ago
Selected Answer: C
C is correct
upvoted 1 times
...
lunamuller
1 year, 5 months ago
Selected Answer: C
Answer C is Correct.
upvoted 1 times
...
felixlugo06
1 year, 6 months ago
Turn on multi-factor authentication (MFA) for added security during the login process. Enabling multi-factor authentication (MFA) for user accounts, especially for users with administrative or high-privilege access, is a crucial security best practice. MFA adds an additional layer of security by requiring users to provide two or more verification factors (typically something they know, like a password, and something they have, like a temporary MFA code from a hardware token or mobile app) before gaining access. This significantly reduces the risk of unauthorized access, even if login credentials are compromised.
upvoted 2 times
...
Anyio
1 year, 6 months ago
Selected Answer: C
The answer is C.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago