Control tower Flashcards
1
Q
Control Tower Definition
A
A tool for Orchestrating service for managing Multiple accounts Accounts at scale
2
Q
Control Tower Landing Zone
A
A collection of various accounts contols and guardrails
3
Q
Control Tower Pricing
A
Free, you only pay for the services
4
Q
Why set regions in AWS Control Tower
A
Guardrail can be set to restrict certain services/operations to a specific region
5
Q
Why AWS Control Tower?
A
- Set up a best-practices AWS environment in a few clicks
- Standardize account provisioning
- Centralize policy management
- Enforce governance and compliance proactively
- Enable end user self-service
- Get continuous visibility into your AWS environment
- Gain peace of mind
6
Q
Control Tower Landing zone
A
Landing zone - a preconfigured, secure, scalable, multi-account AWS environment based on best practice blueprints
7
Q
Components of Aws Control Tower
A
- Landing zone - a preconfigured, secure, scalable, multi-account AWS environment based on best practice blueprints.
- Multi-account management using AWS Organizations
- Identity and federated access management using AWS SSO
- Centralized log archive using AWS CLoudtrail and AWS Config.
- Cross-account audit access using AWS SSO and AWS IAM.
- End user account provisioning through AWS Service Catalog.
- Centralized monitoring and notifications using Amazon CloudWatch and Amazon SNS