nerdexam
Amazon

SAA-C03 · Question #302

A company uses AWS to run its e-commerce platform, which is critical to its operations and experiences a high volume of traffic and transactions. The company has configured a multi-factor authenticati

The correct answer is B. Add multiple MFA devices for the root user account to handle the disaster scenario.. To prevent loss of access to the AWS root user account due to a lost MFA device, AWS recommends enabling multiple MFA devices for the root user. Multiple MFA Devices: AWS allows up to eight MFA devices (virtual, hardware, or security keys) to be associated with a single root user

Submitted by eva_at· Mar 4, 2026Design Secure Architectures

Question

A company uses AWS to run its e-commerce platform, which is critical to its operations and experiences a high volume of traffic and transactions. The company has configured a multi-factor authentication (MFA) device to secure its AWS account root user credentials. The company wants to ensure that it will not lose access to the root user account if the MFA device is lost. Which solution will meet these requirements?

Options

  • ASet up a backup administrator account that the company can use to log in if the company loses
  • BAdd multiple MFA devices for the root user account to handle the disaster scenario.
  • CCreate a new administrator account when the company cannot access the root account.
  • DAttach the administrator policy to another IAM user when the company cannot access the root

How the community answered

(54 responses)
  • A
    2% (1)
  • B
    93% (50)
  • C
    2% (1)
  • D
    4% (2)

Explanation

To prevent loss of access to the AWS root user account due to a lost MFA device, AWS recommends enabling multiple MFA devices for the root user. Multiple MFA Devices: AWS allows up to eight MFA devices (virtual, hardware, or security keys) to be associated with a single root user account. This redundancy ensures that if one device is lost, others can be used to authenticate and access the account. Security Best Practices: Implementing multiple MFA devices enhances account security and provides resilience against potential access issues. By proactively setting up multiple MFA devices, the company can maintain uninterrupted access to its critical AWS resources, even in the event of a lost or malfunctioning MFA device.

Community Discussion

No community discussion yet for this question.

Full SAA-C03 Practice