Open cardosec

Case 2C9BCD · Cloud · L2 Practitioner

Root Account Login

Practise as: Incident drill

Live alertAlert: the AWS root user signed in to the console from a new country. Nobody on the team admits to it.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Root ignores IAM policies; SCPs still bind member-account root but not the management account. Treat unexplained use as critical
  2. Secure it: reset password, rotate MFA, remove any root access keys, and verify the account email is not hijacked
  3. Review CloudTrail for everything root did: billing changes, new users, account contact or support changes
  4. Check whether the root email mailbox itself was compromised, since it controls password resets
  5. Going forward: hardware MFA on root, no root keys, and alerting on any root sign-in

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.