ADVANCED IDENTITIES & FEDERATION Flashcards

1
Q

What uses an identity from another provider to access AWS resources?

A

Identity Federation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the only way to access AWS resources?

A

AWS Credentials

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does SAML Mean?

A

Security Assertion Markup Language

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

When you use an Enterprise Identity Provider, they have to be?

A

SAML 2.0 Compatible

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Use SAML if you have an existing what?

A

Identity Management Team

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Use SAML if you have more than how many users?

A

5,000 users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

SAML uses what type of roles and credentials?

A

IAM Roles and AWS Temp Credentials

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How long does the SAML AWS Temporary Credentials last?

A

12 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

AWS SSO manages SSO for?

A

AWS Accounts and External Applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

AWS SSO has a what?

A

Flexible Identity Store

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

AWS SSO has a built in what?

A

Identity Store

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What AD is compatible with AWS SSO?

A

AWS Managed Microsoft AD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

AWS SSO On Premises Microsoft AD uses what 2 things?`

A

Two trust or AD Connector

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

AWS SSO is preferred by AWS for any what?

A

Workforce identity federation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

If an exam scenario is talking about customer identities such as web application using twitter, google, Facebook or any other web identity, what should you use?

A

AWS Cognito

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

If exam asking about enterprise or workplace identities what do you use?

A

AWS Single Sign on

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What provides Authentication, Authorization, and user management for web/mobile apps?

A

AWS Cognito

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

means to login to verify credentials in Cognito

A

Authentication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

means to manage access to services in Cognito

A

Authorization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

means to allow the creation and management of a serverless user database in Cognito

A

User Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What 2 parts are in Cognito

A

User Pools and Identity Pools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What part signs in and gets a JSON Web Token (JWT) in Cognito

A

User Pools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Most AWS Services cant use JSON Web Token (JWT) what do you need?

A

You need actual AWS Credentials

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

This part allows you to offer access to Temporary AWS Credentials in Cognito

A

Identity Pools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Unauthenticated Identities inside of Cognito Identity Pools are used for what?
Guest Users
26
What Swaps- Google Facebook, Twitter, SAML 2.0 & User Pool for short term AWS Credentials to access AWS Resources in Cognito
Federation Identities
27
are for joined signup and sign in experiences with user directory and profile management services in Cognito
User Pools
28
are for swapping either an unauthenticated or authenticated identity for AWS credentials ex. User Pool Identity in Cognito
Identity Pools
29
Is an Desktop as a Service (DaaS) for home working or office
Amazon Workspaces
30
Amazon Workspaces is similar to what?
Citrix and Remote Desktop hosted by AWS
31
Amazon Workspaces is an consistent Desktop from Anywhere. Apps and State are maintained True or False
True
32
Workspaces has various sizes and has access to what 2 Operating Systems?
Windows and Linux
33
Workspaces has what 2 pricing models?
Monthly and Hourly
34
The hourly billing model of workspaces is also charged what?
Base infrastructure Cost
35
What does the Hourly Billing Model of Workspaces allow you to do?
Suspend when not in use for cost saving
36
Workspaces uses which Directory Services?
Simple AD, AD Connector, and MS AD
37
What is Simple AD used for in Workspaces?
Proof of concept and isolated workspace deployment
38
What integrates with existing on premise AD with any directory infrastructure in AWS?
AD Connector
39
What do you use if you need to use a native Microsoft AD and want to integrate with Workspaces?
AWS Managed MS AD
40
What uses an ENI in a VPC and uses VPC networking
Workspaces
41
What can access FSx and EC2 Windows resources
Workspaces
42
What has an at rest encryption (EBS+KMS)?
Workspaces
43
What runs in AWS Managed VPCs and use ENIs injected into customer managed VPCs?
Workspaces and DS
44
How do customers connect to workspaces?
Client App using Shared Gateways
45
Are Workspaces Highly Available?
No they use a single subnet/AZ
46
If you need to run other apps within your VPC whether they are going to be accessed by workspaces or not, if it needs a native Active Directory implementation what do you use?
AWS Managed AD or AD Connector
47
AWS Managed Directory Service/ Microsoft AD support supports what?
Group Policies and Single Sign On
48
AWS Managed MS AD also supports for extension?
Schema Extension
49
AWS Managed MS AD which MS AD Aware Apps?
Sharepoint, SQL, and Distributed File System
50
What 2 Size does MS AD come in?
Standard 30,000 and Enterprise 500,000
51
Is AWS Managed Directory Service Highly Available?
Yes 2 AZ+
52
AWS Managed MS AD includes monitor, recovery, replication, snapshots, and maintenance -configurable ; managed by AWS True or False
True
53
Does AWS Managed MS AD support one and two way external and forest trusts with on premises active directory?
Yes
54
Directory in AWS can operate through a network link failure to any connected on premises systems True or False?
True
55
Directory in AWS supports for MFA
Radius Based MFA
56
It allows the quick and easy setup of multi account environments
AWS Control Tower
57
AWS Control Tower has a multi account environment. What is it called?
Loading Zone
58
AWS Control Tower has something that automates and standardizes new account creation. What is it called?
Account Factory
59
AWS Control Tower has something that detect and mandates rules and standards across all accounts. What is it called?
Guard Rail
60
Single page oversight of the entire environment is called what in AWS Control Tower?
Dashboard