17. Advanced ID Flashcards

1
Q

What is AWS STS and what does it provide?

A

AWS STS (Security Token Service) provides temporary, limited-privileges credentials to access AWS resources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

True or False: AWS STS credentials are long-term and do not expire.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Fill in the blank: AWS STS is often used for _____, allowing external systems’ users temporary AWS access.

A

Identity federation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which AWS service allows user identity management for web and mobile applications without creating IAM users?

A

Amazon Cognito

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

List two common use cases for AWS STS.

A

Identity federation and IAM roles for cross/same account access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How does Amazon Cognito simplify identity for application users?

A

Cognito allows creating a database of users for web and mobile applications, with options for social login.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

True or False: AWS Directory Services includes AWS Managed Microsoft AD, AD Connector, and Simple AD.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the purpose of the AD Connector in AWS Directory Services?

A

It acts as a directory gateway, redirecting requests to on-premise Active Directory and supporting MFA.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Fill in the blank: AWS IAM Identity Center provides _____ for all AWS accounts and applications.

A

Single Sign-On (SSO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Name two types of identity providers supported by AWS IAM Identity Center.

A

Built-in identity store and third-party providers like Active Directory (AD), OneLogin, or Okta.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

True or False: AWS IAM Identity Center only supports AWS applications and cannot integrate with third-party cloud applications.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which AWS service is considered the successor to AWS Single Sign-On?

A

AWS IAM Identity Center

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Describe one key feature of Simple AD within AWS Directory Services.

A

Simple AD is an AD-compatible managed directory on AWS but cannot be joined with on-premise AD.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What does AWS Organizations help you manage?

A

It helps manage multiple AWS accounts within an organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Explain the purpose of AWS IAM within an AWS account.

A

AWS IAM (Identity and Access Management) is used to manage user identities and access permissions within an AWS account.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly