Enabling multi-factor authentication (MFA) on all user accounts is a security best practice because it requires both the user's credentials and access to a physical device that generates a time-based code, significantly reducing the risk of unauthorized access. Rotating IAM credentials refers to changing access keys and passwords, which is also a best practice but does not involve the use of a physical device. IP whitelisting and enforced password complexity can enhance security but do not provide the same level of protection against compromised credentials as MFA does.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is multi-factor authentication (MFA)?
Open an interactive chat with Bash
How does MFA work in AWS?
Open an interactive chat with Bash
What are IAM credentials and why should they be rotated?