Control Tower 3 Flashcards

1
Q

Baselines and Blueprints

What is Baselining?

A

Load all the stuff into a newly-created or newly-enrolled “blank” AWS Account.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Baselines and Blueprints

What is an account Baseline?

A

The resources that you just set up in a new account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Baselines and Blueprints

At it’s core, what is a Blueprint?

A

Just a CloudFormation Template

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Baselines and Blueprints

Where are Blueprints kept?

A

In a hub account (just a Blueprints term) as a Service Catalog item

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Baselines and Blueprints

What is a good candidate to be your hub account?

A

Not the CT Management account! Any other works

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Baselines and Blueprints

Where are Blueprints used?

A

Customization to a default Account Factory set up or update existing account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Baselines and Blueprints

Where can you get Blueprints?

A

Go to Service Catalog, choose CT Blueprints for pre-built Blueprints from AWS Partners

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Identity

How does Control Tower help with login and identity?

A

Uses IAM Identity Center to federate and manage all logins to all accounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Identity

How does Control Tower control logins across all accounts?

A

Sets up federation with IAM Identity Center (né SSO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Drift

What does Compliance mean in CT?

A

“In compliance” means resource has zero drift.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Drift

How is CT Compliance related to government compliance frameworks?

A

It isn’t. Name clash.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Drift

How does Drift work?

A

Happens automatically – detects when things change.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Drift

How is Drift surfaced?

A

CT in Member accounts posts to local SNS. Lambda pushes to audit account.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Drift

Why this two-stage drift notification?

A

So member account admins can get alerts for their account.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Drift

How does Control Tower automatically fix Drift?

A

It doesn’t.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Drift

How can you correct some types of Drift in an account?

A

Click “Repair” button on LZ Settings web page.

17
Q

Drift

How can you wholesale try to repair drift across many accounts?

A

Re-register an OU: all accounts get re-registered, re-applies account factory stuff.

18
Q

Drift

What things are detected by Drift scanning?

A

Controls set up by CT when the LZ/Account was created

19
Q

Landing Zone Accelerator

LZ Accelerator in a nutshell?

A

Extend Control Tower: set up MANY more AWS services, best practices for mulit-account + security

20
Q

Landing Zone Accelerator

How do you set up LZ Accelerator?

A

It’s a CloudFormation template, deploy it

21
Q

Landing Zone Accelerator

What’s the technical difference between LZA and Control Tower?

A

Control Tower is AWS service. LZA is open-source CF Template you deploy.

22
Q

Landing Zone Accelerator

What does LZA deploy into Organizations Management account?

A

CodeCommit, CodePipeline, CodeBuild, Lambda functions, DDB tables

23
Q

Landing Zone Accelerator

How do you use LZA to change things in your accounts?

A

Edit config files, commit to CodeCommit, pipeline CI/CD deploys the configuration across accounts.

24
Q

Landing Zone Accelerator

Does LZA need Control Tower?

A

No, can deploy LZA stand-alone. LZA complements CT.

25
Q

Landing Zone Accelerator

What’s the long-term plan for Control Tower vs. LZA?

A

Over time, an deprecate LZA features in favor of native AWS services

26
Q

Landing Zone Accelerator

Major feature of LZA for workload accounts?

A

Sets up streaming of CloudWatch Log Groups to Kineiss Data Stream in Log Archive account, store centrally in S3.