Question 1 · choose 1
An organization has turned on centralized root access, removed the root user credentials of its member accounts and not allowed password recovery for any of them. An engineer in a member account attached a bucket policy that denies every principal all S3 actions on a bucket, and now nobody can change or delete the policy. What should the security team do?
- ARecover the member account's root password by email and delete the policy as root
- BAttach an SCP to the member account that explicitly allows s3:DeleteBucketPolicy
- CRun the privileged root task that deletes the bucket policy from the management account
- DAttach a resource control policy that allows s3:DeleteBucketPolicy on the bucket
Show the answer and why
ARecover the member account's root password by email and delete the policy as root
Incorrect
With root credentials removed and account recovery not allowed, the member account cannot sign in as root or recover the password.
BAttach an SCP to the member account that explicitly allows s3:DeleteBucketPolicy
Incorrect
SCPs never grant permissions; they only set limits.
CRun the privileged root task that deletes the bucket policy from the management account
Correct
With centralized root access, the management account or IAM delegated administrator can perform privileged root tasks on a member account, including removing a misconfigured bucket policy.
DAttach a resource control policy that allows s3:DeleteBucketPolicy on the bucket
Incorrect
An RCP never grants permissions, so it cannot override the deny in the bucket policy.
Centralized root access replaces standing root credentials with short privileged tasks run from the management or delegated administrator account, such as unlocking a bucket policy that locks everyone out.
AWS documentation