At CloudPrime Corp , the security team wants to minimize the number of users with administrative privileges at the organization level to reduce risk and enforce the principle of least privilege. Which two IAM roles should the team restrict to achieve this goal? (Choose two.)