Governance Flashcards

1
Q

What is AWS Audit Manager?

A

A tool that produces reports for PCI compliance, GDPR, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

When would you use AWS Artifact?

A

To get AWS security and compliance-related info, e.g. compliance reports.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

TRUE or FALSE:
SCPs don’t apply to the management account.

A

TRUE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

When it comes to billing, what advantages does AWS Organizations provide?

A
  • Only one bill for all accounts
  • Take advantage of savings plans and discounts across accounts
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the best practice for where to store CloudTrail logs?

A

In one single account.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does AWS RAM do?

A

Allows you to share resources in one account with other accounts inside or outside your organisation.

No need to create duplicate copies in different accounts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the pricing model of AWS RAM?

A

It’s free

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which AWS service would you use to check if your Reserved Instances or Savings Plans are under-utilized?

A

AWS Budgets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which AWS service would you use to let employees know that they are close to overspending?

A

AWS Budgets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What simple method can you use to create very specific budgets?

A

Tags

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does the Well-Architected Tool do?

A

Measures your architecture against AWS best practices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which service provides guides for making your workloads more reliable, secure, efficient, and cost-optimised?

A

AWS Well-Architected Tool

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

TRUE or FALSE:
The AWS Well-Architected Tool assists in documenting your architecture decisions.

A

TRUE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What tool would you use to monitor the state of your infrastructure?

A

AWS Config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

TRUE or FALSE:
AWS Config can prevent non-compliant changes being made to your infrastructure.

A

FALSE
It’s only a monitoring tool, but it can integrate with EventBridge to make changes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

TRUE or FALSE:
AWS Config is multi-region by default.

A

FALSE
You need to enable it in every region where you have resources you want to track.

16
Q

What’s the difference between Trusted Advisor and the Well-Architected Tool?

A

Trusted Advisor:
- Real-time operational insights
- Specific resource-level recommendations.
Well-Architected Tool
- Architectural reviews
- Strategic improvements

17
Q

What’s the only way to restrict what the root account can do?

A

By using a Service Control Policy

18
Q

TRUE or FALSE?
Trusted Advisor is strictly an auditing tool, it won’t make changes for you.

A

TRUE

19
Q

What’s the difference between AWS Artifact and Audit Manager?

A

Audit manager: For managing audits of your own AWS environment.

Artifact: A static repository of AWS’s own compliance reports.

20
Q

What is AWS Config?

A

An inventory management and control tool. Allows you to track your resources.