ADVANCED IDENTITIES & FEDERATION Flashcards

1
Q

What uses an identity from another provider to access AWS resources?

A

Identity Federation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the only way to access AWS resources?

A

AWS Credentials

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does SAML Mean?

A

Security Assertion Markup Language

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

When you use an Enterprise Identity Provider, they have to be?

A

SAML 2.0 Compatible

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Use SAML if you have an existing what?

A

Identity Management Team

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Use SAML if you have more than how many users?

A

5,000 users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

SAML uses what type of roles and credentials?

A

IAM Roles and AWS Temp Credentials

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How long does the SAML AWS Temporary Credentials last?

A

12 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

AWS SSO manages SSO for?

A

AWS Accounts and External Applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

AWS SSO has a what?

A

Flexible Identity Store

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

AWS SSO has a built in what?

A

Identity Store

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What AD is compatible with AWS SSO?

A

AWS Managed Microsoft AD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

AWS SSO On Premises Microsoft AD uses what 2 things?`

A

Two trust or AD Connector

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

AWS SSO is preferred by AWS for any what?

A

Workforce identity federation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

If an exam scenario is talking about customer identities such as web application using twitter, google, Facebook or any other web identity, what should you use?

A

AWS Cognito

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

If exam asking about enterprise or workplace identities what do you use?

A

AWS Single Sign on

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What provides Authentication, Authorization, and user management for web/mobile apps?

A

AWS Cognito

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

means to login to verify credentials in Cognito

A

Authentication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

means to manage access to services in Cognito

A

Authorization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

means to allow the creation and management of a serverless user database in Cognito

A

User Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What 2 parts are in Cognito

A

User Pools and Identity Pools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What part signs in and gets a JSON Web Token (JWT) in Cognito

A

User Pools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Most AWS Services cant use JSON Web Token (JWT) what do you need?

A

You need actual AWS Credentials

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

This part allows you to offer access to Temporary AWS Credentials in Cognito

A

Identity Pools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Unauthenticated Identities inside of Cognito Identity Pools are used for what?

A

Guest Users

26
Q

What Swaps- Google Facebook, Twitter, SAML 2.0 & User Pool for short term AWS Credentials to access AWS Resources in Cognito

A

Federation Identities

27
Q

are for joined signup and sign in experiences with user directory and profile management services in Cognito

A

User Pools

28
Q

are for swapping either an unauthenticated or authenticated identity for AWS credentials ex. User Pool Identity in Cognito

A

Identity Pools

29
Q

Is an Desktop as a Service (DaaS) for home working or office

A

Amazon Workspaces

30
Q

Amazon Workspaces is similar to what?

A

Citrix and Remote Desktop hosted by AWS

31
Q

Amazon Workspaces is an consistent Desktop from Anywhere. Apps and State are maintained

True or False

A

True

32
Q

Workspaces has various sizes and has access to what 2 Operating Systems?

A

Windows and Linux

33
Q

Workspaces has what 2 pricing models?

A

Monthly and Hourly

34
Q

The hourly billing model of workspaces is also charged what?

A

Base infrastructure Cost

35
Q

What does the Hourly Billing Model of Workspaces allow you to do?

A

Suspend when not in use for cost saving

36
Q

Workspaces uses which Directory Services?

A

Simple AD, AD Connector, and MS AD

37
Q

What is Simple AD used for in Workspaces?

A

Proof of concept and isolated workspace deployment

38
Q

What integrates with existing on premise AD with any directory infrastructure in AWS?

A

AD Connector

39
Q

What do you use if you need to use a native Microsoft AD and want to integrate with Workspaces?

A

AWS Managed MS AD

40
Q

What uses an ENI in a VPC and uses VPC networking

A

Workspaces

41
Q

What can access FSx and EC2 Windows resources

A

Workspaces

42
Q

What has an at rest encryption (EBS+KMS)?

A

Workspaces

43
Q

What runs in AWS Managed VPCs and use ENIs injected into customer managed VPCs?

A

Workspaces and DS

44
Q

How do customers connect to workspaces?

A

Client App using Shared Gateways

45
Q

Are Workspaces Highly Available?

A

No they use a single subnet/AZ

46
Q

If you need to run other apps within your VPC whether they are going to be accessed by workspaces or not, if it needs a native Active Directory implementation what do you use?

A

AWS Managed AD or AD Connector

47
Q

AWS Managed Directory Service/ Microsoft AD support supports what?

A

Group Policies and Single Sign On

48
Q

AWS Managed MS AD also supports for extension?

A

Schema Extension

49
Q

AWS Managed MS AD which MS AD Aware Apps?

A

Sharepoint, SQL, and Distributed File System

50
Q

What 2 Size does MS AD come in?

A

Standard 30,000 and Enterprise 500,000

51
Q

Is AWS Managed Directory Service Highly Available?

A

Yes 2 AZ+

52
Q

AWS Managed MS AD includes monitor, recovery, replication, snapshots, and maintenance -configurable ; managed by AWS

True or False

A

True

53
Q

Does AWS Managed MS AD support one and two way external and forest trusts with on premises active directory?

A

Yes

54
Q

Directory in AWS can operate through a network link failure to any connected on premises systems

True or False?

A

True

55
Q

Directory in AWS supports for MFA

A

Radius Based MFA

56
Q

It allows the quick and easy setup of multi account environments

A

AWS Control Tower

57
Q

AWS Control Tower has a multi account environment. What is it called?

A

Loading Zone

58
Q

AWS Control Tower has something that automates and standardizes new account creation. What is it called?

A

Account Factory

59
Q

AWS Control Tower has something that detect and mandates rules and standards across all accounts. What is it called?

A

Guard Rail

60
Q

Single page oversight of the entire environment is called what in AWS Control Tower?

A

Dashboard