Phase Verbs / Action Phrases
| Phrase | Meaning |
|---|---|
| protect (an account) | add security measures to prevent unauthorized access |
| compromise (an account) | gain unauthorized access to it |
| prevent password reuse | block users from reusing old passwords |
| require (a character type) | make something mandatory in a password |
| generate (a token) | produce a one-time code from an MFA device |
Technical Vocabulary
| Term | Definition |
|---|---|
| Password policy | A set of rules enforced by AWS for IAM user passwords (length, complexity, expiry, reuse) |
| MFA (Multi-Factor Authentication) | A security method combining something you know (password) + something you own (device) |
| Brute force attack | Trying many combinations of passwords to guess the correct one |
| Virtual MFA device | Software app on a phone that generates time-based one-time codes (e.g., Google Authenticator, Authy) |
| U2F Security Key | A physical USB/NFC key (e.g., YubiKey by Yubico) used as a second factor |
| Hardware key fob | A dedicated physical device that generates OTP codes (e.g., Gemalto device) |
| GovCloud | AWS regions dedicated to US government workloads; uses a special SurePassID key fob |
| One-Time Password (OTP) | A code valid for only one login attempt or a short time window |
| Root account | The master account in AWS — must always be protected with MFA |
Key Concepts
Defense Mechanism 1 — Password Policy
AWS lets you configure:
- Minimum password length
- Required character types: uppercase, lowercase, numbers, non-alphanumeric
- Allow/disallow IAM users to change their own passwords
- Password expiry (e.g., every 90 days)
- Prevent reuse of previous passwords
Purpose: protection against brute force attacks.
Defense Mechanism 2 — MFA
- What: password (what you know) + MFA device (what you own)
- Why: even if password is stolen, attacker cannot log in without the physical device
- Recommendation: enable MFA on the root account at minimum; ideally all IAM users
MFA Device Options
| Device | Type | Notes |
|---|---|---|
| Google Authenticator | Virtual MFA | One phone at a time |
| Authy | Virtual MFA | Multiple tokens/devices supported |
| YubiKey (U2F) | Physical hardware key | Supports multiple root/IAM users on one key; by Yubico |
| Gemalto key fob | Hardware OTP device | Third-party hardware device |
| SurePassID key fob | Hardware OTP device | For AWS GovCloud (US) only |
Exam Tips
- Know the two defense mechanisms: password policy + MFA
- Know all 4 MFA device types: Virtual (Authenticator/Authy), U2F hardware key, hardware key fob, GovCloud key fob
- Root account + IAM users should use MFA
- MFA = password AND a device — both are required