Every AWS account has a root user with complete control, including tasks no IAM policy can grant, such as changing account settings, closing the account or restoring a locked S3 bucket policy. Protecting it, and cleaning up long-term credentials in general, is basic hygiene the exam expects.
Free account
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 3 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.