Account Management, Billing & support Section Flashcards
ACCOUNT BEST PRACTICES
Organization
Operate multiple accounts
- Global service
- Consolidated billing: single payment, Combined usage, to share the volumes pricing, reserved instances and saving plans discounts
- Pooling of reserved EC2 instance for optimal saving
SCP ( service control police)
use to restrict account power
- Whitelist or blacklist IAM action
- Applied at the OU or Account level
- Must have an explicit allow ( does not allow anything by default)
- Which tool allows you to centrally manage all users and roles permissions in your organization?
SCP usecase
- Restrict access to certain service (EX can’t use emr )
- Enforce PCI compliance by explicitly disabling service
AWS control tower
easily setup multiple accounts with best-practices
- set up and govern a secure and compliant multi-account AWS environment
- Benefits:
Automate the setup of your environment in a few click
Automate ongoing policy management using guardrails
Detect policy violation and remediate them
Monitor compliance through an interactive dashboard
You would like to automatically set up and govern a secure multi-account AWS environment with best practices for your organization. Which AWS tool can you use?
Use tags & cost cost allocation tags
for easy management & billing
IAM guidelines
MFA, least- privilege, password policy, password rotation
Config
to record all resources configuration & compliance over time
Cloudformation
To deploy stacks across account and region
Trusted Advisor
To get insights, support plan adapted to your needs
S3 or Cloudwatch logs
Send service logs and Access logs
Cloudtrail
To record API calls made within your account
if your account is compromise:
change the root password, delete and rotate all the AWS support
Billing and Costing Tools
Compute optimizer
Recommends resources configuration to reduce cost
- Uses MAchine Learning to analyze your resource configuration and their utilization cloudwatch metrics
- Reduce costs and improve performance
- Which of the following options uses machine learning to recommend optimal AWS resources and therefore reduces costs?
TCO calculator
- from on-premises to AWS
- reducing the need to invest in large capital expenditures and providing a pay as you go model
- estimate the cost saving
- detailed set of report that can be used in executive presentations
- A company is not sure whether or not it is cost-effective to migrate to the AWS Cloud. Which service can help the executive board make a decision?
Simple Monthly calculator / pricing calculator
cost of service on AWS
- Estimate the cost for your architect solution
What can you use to estimate the cost of your architecture solution?