Full AWS Practitioner Certification Question

Which of the following are valid best practices for using the AWS Identity and Access Management (IAM) service? (Select TWO.)