Which of the following is a best practice for handling root user access keys?
A. Store them only in an instances-protected .aws/ directory.
B. Delete them and instead use different user IAM credentials.
C. Only use them for API access but avoid console access.
D. Enable MFA Delete for when they are used in association with S3.