Case 2C9BCD · Cloud · L2 Practitioner
Root Account Login
Practise as: Incident drill
Live alertAlert: the AWS root user signed in to the console from a new country. Nobody on the team admits to it.
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Root ignores IAM policies; SCPs still bind member-account root but not the management account. Treat unexplained use as critical
- Secure it: reset password, rotate MFA, remove any root access keys, and verify the account email is not hijacked
- Review CloudTrail for everything root did: billing changes, new users, account contact or support changes
- Check whether the root email mailbox itself was compromised, since it controls password resets
- Going forward: hardware MFA on root, no root keys, and alerting on any root sign-in
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.