AWS Organizations Flashcards

1
Q

What benefits does AWS Organizations provide?

A

Consolidation of AWS billing (including using a single payment method).

Consolidation of reservations and volume discounts.

Service Control Policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a Management Account?

A

A Management Account is the account that you use to create the organization. From the organization’s management account, you can do the following:

  1. Create accounts in the organization
  2. Invite other existing accounts to the organization
  3. Remove accounts from the organization
  4. Designate delegated administrator accounts
  5. Manage invitations
  6. Apply policies to entities (roots, OUs, or accounts) within the organization
  7. Enable integration with supported AWS services to provide service functionality across all of the accounts in the organization.

The management account has the responsibilities of a payer account and is responsible for paying all charges that are accrued by the member accounts. You can’t change an organization’s management account.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What do you call an AWS account that joins an Organization?

A

A Member Account.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What can be contained in the Organization Root?

A

Organizational Units (OU) or AWS accounts (both the Management Account and Member Accounts).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the two ways to add an AWS account to an Organization?

A

By inviting an existing AWS account to join the Organization or by creating a new AWS account directly within the Organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does Role Switching do?

A

It allows a user to assume the role of another user within an Organization through the console GUI.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are Service Controls Policies (SCP)?

A

They establish permissions for a Member AWS account within an Organization. This has the effect of limiting what the root user of that account can do because the SCP limits the entire account. SCPs do not grant permission to identities within the account, they simply limit what the account as a whole can do.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Is the Management Account impacted by Service Control Policies?

A

No.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly