Advanced IAM Flashcards
AWS Directory Service, what are the five key points about this set of services?
- is a family of managed services
- connects aws resources with on premises AD (active directory)
- stand alone directory in the cloud
- uses existing corporate credentials
- SSO Single Sign On to any domain joined ec2 service.
What are the AD compatible services offered by aws?
- managed Microsoft AD
- AD connector
- Simple AD
What are the non AD compatible directory services that aws offers?
- cloud directory
- cognitive user pools
An ARN is a pointer to a unique aws resource, what are the key parts in this and in which order do they come in?
Partition = aws / aws-cdn etc
Service = the aws service such as s3 etc
Region = the region and az for example us-east-1
Account-Id =the account to which the resource belongs.
There are two types of policies in AWS these are…
Identity policies - for IAM users
Resource policies - for resources such as ec2 or lambda etc.
True or false, evaluating policies where more than one is attached to a resource or user, if some contain deny rules, how are they processed.
AWS merges all policies together, if any contain deny rules, these will supersede any allow rules for the same resource or action on that resource in aws.