exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 625 discussion

Exam question from Amazon's AWS-SysOps
Question #: 625
Topic #: 1
[All AWS-SysOps Questions]

A SysOps Administrator needs to confirm that security best practices are being followed with the AWS account root user.
How should the Administrator ensure that this is done?

  • A. Change the root user password by using the AWS CLI routinely.
  • B. Periodically use the AWS CLI to rotate access keys and secret keys for the root user.
  • C. Use AWS Trusted Advisor security checks to review the configuration of the root user.
  • D. Periodically distribute the AWS compliance document from AWS Artifact that governs the root user configuration.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
karmaah
Highly Voted 3 years, 1 month ago
After long research, I also vote for ans C. MFA is also Part of root user security and AWS always enforces. So Trusted advisor will check whether the root account is enabled for MFA or not
upvoted 10 times
...
e45af42
Most Recent 4 months, 4 weeks ago
Selected Answer: C
Just like the other explanations here :) C is correct.
upvoted 1 times
...
albert_kuo
1 year, 3 months ago
Selected Answer: C
By using Trusted Advisor security checks, the Administrator can review the configuration of the root user and identify any security best practice violations or misconfigurations. Trusted Advisor will provide recommendations for improving the security posture of the AWS account, including suggestions related to the root user. Options A and B are not recommended because they involve changing access keys, secret keys, or passwords for the root user, which should be avoided whenever possible. The root user should have limited usage and should not be used for routine activities.
upvoted 1 times
...
gulu73
1 year, 8 months ago
Selected Answer: C
Answer should be C
upvoted 1 times
...
TroyMcLure
2 years, 12 months ago
Correct Answer: C
upvoted 1 times
...
alexsandroe
2 years, 12 months ago
C. Use AWS Trusted Advisor security checks to review the configuration of the root user.
upvoted 1 times
...
fqnn
2 years, 12 months ago
"A SysOps Administrator needs to confirm that security best practices are being followed with the AWS account root user." -> Trusted Advisor is used for this purpose so answer is C
upvoted 1 times
...
RicardoD
3 years ago
C is the answer Trusted advisor is the tool to use for security and compliance
upvoted 3 times
...
abhishek_m_86
3 years ago
C. Use AWS Trusted Advisor security checks to review the configuration of the root user.
upvoted 2 times
...
jackdryan
3 years ago
I'll go with C
upvoted 2 times
...
MFDOOM
3 years ago
C. Use AWS Trusted Advisor security checks to review the configuration of the root user. AWS Best practice is to never generate access keys for root user
upvoted 2 times
...
waterzhong
3 years ago
it is C Multi-factor authentication on root account (free) Checks the root account and warns if multi-factor authentication (MFA) is not enabled. For increased security, we recommend that you protect your account by using MFA, which requires a user to enter a unique authentication code from their MFA hardware or virtual device when interacting with the AWS console and associated websites.
upvoted 1 times
...
asim1982
3 years ago
C is right because question is asking for confirmation, B is wrong , you can rotate but how you will be sure its done , the only way is trusted advisor to confirm its been done and not deviation from standards. Well i may be wrong but i will choose C :)
upvoted 1 times
...
Tanglefoot12
3 years ago
B: "If you do have an access key for your AWS account root user, delete it. If you must keep it, rotate (change) the access key regularly."
upvoted 1 times
...
professor
3 years ago
Ans C: Use AWS Trusted Advisor security checks to review the configuration of the root user.
upvoted 2 times
...
AWSum1
3 years ago
C is the correct answer I've set and tried to look for some hard and fast answer on many pages on the web. Then I read the question a few times and it clicked. "confirm that security best practices are being followed" the question is not asking what you should to routinely or what will secure the root. It's asking you to confirm that security best PRACTICES(in plural) are being followed. So you would need the trusted advisor to point out any area in which best practices are not being followed.
upvoted 3 times
...
block933
3 years ago
B is wrong, the root account shouldnt have access keys. C is the best
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago