Account Management, Billing & Support Flashcards

1
Q

AWS Organizations

A

• Global service
• Allows to manage multiple AWS accounts

Cost Benefits:
• Consolidated Billing
• Pricing benefits from aggregated usage
• Pooling of Reserved EC2 instances for optimal savings

• API is available to automate AWS account creation
• Restrict account privileges using Service Control Policies (SCP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Multi Account Strategies

A

Create accounts per department, per cost center, per dev/test/ prod, based on regulatory restrictions (using SCP), for better resource isolation (ex: VPC), to have separate per-account service limits, isolated account for logging

Use tagging standards for billing purposes
• Enable CloudTrail on all accounts, send logs to central S3 account
• Send CloudWatch Logs to central logging account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Service Control Policies (SCP)

A

• Whitelist or blacklist IAM actions
• Applied at the OU or Account level
• Does not apply to the Master Account
• SCP is applied to all the Users and Roles of the Account, including Root user
• The SCP does not affect service-linked roles
• SCP must have an explicit Allow

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

AWS Organization – Consolidated Billing

A

• Combined Usage: combine the usage across all AWS accounts in the AWS Organization to share the volume pricing, Reserved Instances and Savings Plans discounts

• One Bill
• The management account can turn off Reserved Instances discount sharing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

AWS Control Tower

A

Easy way to set up and govern a secure and compliant multi-account AWS environment based on best practices

Benefits:
• Automate the set up of your environment in a few clicks
• Automate ongoing policy management using guardrails
• Detect policy violations and remediate them
• Monitor compliance through an interactive dashboard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Pricing Models in AWS

A

• Pay as you go: pay for what you use, remain agile, responsive, meet scale demands
• Save when you reserve: minimize risks, predictably manage budgets, comply with long-terms requirements
• Pay less by using more: volume-based discounts
• Pay less as AWS grows

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Free services & free tier in AWS

A

• IAM
• VPC
• Consolidated Billing
• Elastic Beanstalk
• CloudFormation
• Auto Scaling Groups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Compute Pricing – EC2

A

• Only charged for what you use
• Number of instances
• Instance configuration
• ELB running time and amount of data processed
• Detailed monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Compute Pricing – EC2 (Instances)

A

On-demand instances:
• Minimum of 60s
• Pay per second (Linux/Windows) or per hour

Reserved instances:
• Up to 75% discount compared to On-demand on hourly rate
• 1- or 3-years commitment • All upfront, partial upfront, no upfront

Spot instances:
• Up to 90% discount compared to On-demand on hourly rate
• Bid for unused capacity

Dedicated Host:
• On-demand
• Reservation for 1 year or 3 years commitment

Savings plans as an alternative to save on sustained usage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Compute Pricing – Lambda / ECS / Fargate

A

Lambda:
• Pay per call
• Pay per duration

ECS:
• EC2 Launch Type Model: No additional fees, you pay for AWS resources stored and created in your application

Fargate:
• Fargate Launch Type Model: Pay for vCPU and memory resources allocated to your applications in your containers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Storage Pricing – S3

A

• Storage class: S3 Standard, S3 Infrequent Access, S3 One-Zone IA, S3 Intelligent Tiering, S3 Glacier and S3 Glacier Deep Archive

• Number and size of objects: Price can be tiered (based on volume)
• Number and type of requests
• Data transfer OUT of the S3 region
• S3 Transfer Acceleration
• Lifecycle transitions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Storage Pricing – S3

A

• Storage class: S3 Standard, S3 Infrequent Access, S3 One-Zone IA, S3 Intelligent Tiering, S3 Glacier and S3 Glacier Deep Archive

• Number and size of objects: Price can be tiered (based on volume)
• Number and type of requests
• Data transfer OUT of the S3 region
• S3 Transfer Acceleration
• Lifecycle transitions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Storage Pricing - EBS

A

• Volume type (based on performance)
• Storage volume in GB per month provisionned
• IOPS (Input/Output Operations per Second)

Snapshots:
• Added data cost per GB per month

Data transfer:
• Outbound data transfer are tiered for volume discounts
• Inbound is free

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Database Pricing - RDS

A

• Per hour billing
• Database characteristics: Engine, Size & Memory class

Purchase type:
• On-demand
• Reserved instances with required up-front

• Backup Storage: There is no additional charge for backup storage up to 100% of your total database storage for a region.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Database Pricing - RDS 2

A

• Additional storage (per GB per month)
• Number of input and output requests per month

Deployment type (storage and I/O are variable):
• Single AZ • Multiple AZs

Data transfer:
• Outbound data transfer are tiered for volume discounts
• Inbound is free

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Content Delivery – CloudFront

A

• Pricing is different across different geographic regions
• Aggregated for each edge location, then applied to your bill
• Data Transfer Out (volume discount)
• Number of HTTP/HTTPS request

17
Q

Networking Costs in AWS per GB

A

• Use Private IP instead of Public IP for good savings and better network performance
• Use same AZ for maximum savings (at the cost of high availability)

18
Q

Savings Plan

A

• Commit a certain $ amount per hour for 1 or 3 years
• Easiest way to setup long-term commitments on AWS

EC2 Savings Plan:
• Up to 72% discount
• Commit to usage of individual instance families in a region
• Regardless of AZ, size, OS or tenancy

Compute Savings Plan
• Up to 66% discount
• Regardless of Family, Region, size, OS, tenancy, compute options
• Compute Options: EC2, Fargate, Lambda

• Setup from the AWS Cost Explorer console

19
Q

AWS Compute Optimizer

A

• Reduce costs and improve performance by recommending optimal AWS resources for your
workloads
• Helps you choose optimal configurations and right- size your workloads
• Uses Machine Learning to analyze your resources’ configurations and their utilization CloudWatch metrics
• Lower your costs by up to 25%
• Recommendations can be exported to S3

20
Q

Billing and Costing Tools

A

Estimating costs in the cloud:
• Pricing Calculator

Tracking costs in the cloud:
• Billing Dashboard
• Cost Allocation Tags
• Cost and Usage Reports
• Cost Explorer

Monitoring against costs plans:
• Billing Alarms • Budget

21
Q

AWS Pricing Calculator

A

Estimate the cost for your solution architecture

22
Q

AWS Billing Dashboard

A

Will show you all the cost actually for the month, the forecast, and the month-to-date

23
Q

Cost Allocation Tags

A

• Use cost allocation tags to track your AWS costs on a detailed level

AWS generated tags
• Automatically applied to the resource you create
• Starts with Prefix aws:

User-defined tags
• Defined by the user
• Starts with Prefix user:

24
Q

Tagging and Resource Groups

A

• Tags are used for organizing resources
• Free naming, common tags are: Name, Environment, Team …

Tags can be used to create Resource Groups:
• Create, maintain, and view a collection of resources that share common tags
• Manage these tags using the Tag Editor

25
Q

Cost and Usage Reports

A

• The AWS Cost & Usage Report contains the most comprehensive set of AWS cost and usage data available, including additional metadata about AWS services, pricing, and reservations
• Dive deeper into your AWS costs and usage
• Can be integrated with Athena, Redshift or QuickSight

26
Q

Cost Explorer

A

Visualize, understand, and manage your AWS costs and usage over time

Create custom reports that analyze cost and usage data.
• Analyze your data at a high level: total costs and usage across all accounts
• Or Monthly, hourly, resource level granularity
• Choose an optimal Savings Plan
• Forecast usage up to 12 months based on previous usage

27
Q

Billing Alarms in CloudWatch

A

Billing data metric is stored in CloudWatch us-east1
• Billing data are for overall worldwide AWS costs
• It’s for actual cost, not for projected costs

• Intended a simple alarm (not as powerful as AWS Budgets)

28
Q

AWS Budgets

A

Create budget and send alarms when costs exceeds the budget

• 3 types of budgets: Usage, Cost, Reservation
• Up to 5 SNS notifications per budget

29
Q

Trusted Advisor

A

Analyze your AWS accounts and provides
recommendation on 5 categories

• Cost optimization
• Performance
• Security
• Fault tolerance
• Service limits

30
Q

Trusted Advisor – Basic & Developer Support plan (7 CORE CHECKS)

A

Basic & Developer Support plan (7 CORE CHECKS)

• S3 Bucket Permissions
• Security Groups – Specific Ports Unrestricted
• IAM Use (one IAM user minimum)
• MFA on Root Account
• EBS Public Snapshots
• RDS Public Snapshots
• Service Limits

31
Q

Trusted Advisor – Business & Enterprise Support plan (FULL CHECKS)

A

• Full Checks available on the 5 categories
• Ability to set CloudWatch alarms when
reaching limits
• Programmatic Access using AWS Support API

32
Q

AWS Basic Support Plan

A

• Customer Service & Communities - 24x7 access to customer service, documentation, whitepapers, and support forums.
• AWS Trusted Advisor - Access to the 7 core Trusted Advisor checks and guidance to provision your resources following best practices
• AWS Personal Health Dashboard

33
Q

AWS Developer Support Plan

A

• All Basic Support Plan +
• Business hours email access to Cloud Support Associates
• Unlimited cases / 1 primary contact

Case severity / response times:
• General guidance: < 24 business hours
• System impaired: < 12 business hour

34
Q

AWS Business Support Plan (24/7)

A

• Intended to be used if you have production workloads
• Trusted Advisor – Full set of checks + API access
• 24x7 phone, email, and chat access to Cloud Support Engineers
• Unlimited cases / unlimited contacts
• Access to Infrastructure Event Management for additional fee.

Case severity / response times:
• General guidance: < 24 business hours
• System impaired: < 12 business hours
• Production system impaired: < 4 hours
• Production system down: < 1 hour

35
Q

AWS Enterprise On-Ramp Support Plan (24/7)

A

• Intended to be used if you have production or business critical workloads
• All of Business Support Plan +
• Access to a pool of Technical Account Managers (TAM)
• Concierge Support Team (for billing and account best practices)
• Infrastructure Event Management, Well-Architected & Operations Reviews

Case severity / response times:
• …
• Production system impaired: < 4 hours
• Production system down: < 1 hour
• Business-critical system down: < 30 minutes