Security & ComplianceQuestion 48 of 100
Which of the following is an IAM best practice?
a.Attach permissions directly to each individual user
b.Use the root account for daily API calls
c.Disable MFA to simplify sign-in
d.Grant permissions using groups and roles rather than long-term keys where possible
Explanation
IAM best practices include using groups and roles to manage permissions, applying least privilege, enabling MFA, and rotating or avoiding long-term credentials. Managing permissions through groups scales better than per-user policies.
Practice all 100 questions free — no signup required.
Related questions on this topic
- A company wants to centrally manage multiple AWS accounts and apply guardrails that restrict which services accounts can use. Which combination helps?
- What does 'encryption in transit' protect?
- Which AWS service can be used to provision and manage SSL/TLS certificates for use with AWS services like load balancers and CloudFront?
- Which service aggregates security findings from services like GuardDuty, Inspector, and Macie into a single dashboard and runs automated best-practice checks?
- A customer stores objects in Amazon S3 and wants AWS to manage the encryption keys and apply encryption automatically. Which option fits?
- Which statement best distinguishes an IAM user from an IAM role?
Last reviewed: · editorial process
PrepPass Editorial Team · Verified against AWS Certified Cloud Practitioner (CLF-C02) · How we review