Question 1 · choose 2
A company has a standalone AWS account that is not part of AWS Organizations. Which tasks can be performed only by signing in as the account's root user? (Choose TWO.)
- AClose the AWS account
- BChange the account name
- CActivate IAM access to the Billing and Cost Management console
- DCreate an IAM group and attach a managed policy to it
- EUpdate the account's alternate contacts
Show the answer and why
AClose the AWS account
Correct
Closing a standalone account requires root user credentials. Accounts in an organization can be closed from the management account instead.
BChange the account name
Incorrect
The account name is one of the settings that does not require root user credentials.
CActivate IAM access to the Billing and Cost Management console
Correct
Turning on IAM access to the billing console is on the list of tasks only the root user can perform.
DCreate an IAM group and attach a managed policy to it
Incorrect
Everyday administration like this is done by an administrative user, not the root user; it is not a root-only task.
EUpdate the account's alternate contacts
Incorrect
Alternate contacts are one of the account settings that do not require root user credentials.
The root user should do only the few tasks that require it. Everything else, including most account settings, belongs to IAM identities with the right permissions.
AWS documentation