AWS Identity and Access Management Flashcards

1
Q

A document that identifies one or more actions related to AWS resources.

A

IAM Policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Programmatically access your AWS environment

A

Access Keys

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Associate users with common job functions with access levels to perform work functions within the AWS environment.

A

IAM Groups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Temporary access of 12 hours allows users or services to access your account resources in your AWS environment.

A

IAM Roles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

AWS issues trusted IAM users temporary access of 12 hours using this security feature when assuming its new role

A

AWS Security Token Service (STS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Federated identity access for mobile or untrusted users allows for sign-up and grants temporary access while controlling that access based on the definition you set up.

A

Amazon Cognito

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Running in two AZs, this resource takes on the burden of taking care of all the necessary infrastructure for managing an AD server and moving it to the cloud

A

AWS Managed Microsoft AD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Acting as a gateway to redirect authentication requests from AWS service to your on-prem without caching any data on AWS.

A

AD Connector

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

This service works across multiple AWS accounts within an AWS organization. Streamlining authentication and authorizations using an existing Microsoft AD.

A

AWS Single Sign-On (SSO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

You can manage policy-based controls across multiple AWS accounts. Companies with more than one can use this feature to unify and integrate how assets are exposed and consumed.

A

AWS Organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

It enables tracking, rotation, and deletion of keys that protect your data in the AWS account. It also integrates with CloudTrail for compliance purposes.

A

AWS Key Management Service (KMS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

You can deliver credentials to applications on request, allowing Amazon to rotate the credentials, encrypting the delivery and using KMS for storage at rest.

A

AWS Secrets Manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

This service performs cryptographic operations on your web server’s behalf. Offloading the computational load is FIPS compliant, and HPC computation can be accelerated.

A

AWS CloudHSM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

The AWS feature enables sharing resources with users across multiple accounts within an organization or externally, allowing all authorized users to access shared resources in the same region without duplication.

A

AWS Resource Access Manager (AWS RAM)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

An access control policy allows for granular control at the organizational level, restricting or enforcing permissions across all accounts in AWS Organizations, ensuring uniform access control org-wide.

A

Service Control Policies (SCP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly