Governance Flashcards
Service is a free governance tool that allows you to create and manage multiple AWS accounts
AWS Organizations
Service allows you to control your accounts from a single location instead of having to jump from account to account
AWS Organizations
Account within AWS Organizations is also called the payer account. Is the primary account that hosts and manages the organization
Management Account
Can there be more than one Management account within AWS Organizations
No
Accounts within AWS Organizations that belong to everyone in the organization such as test, dev accounts
Member Account
Feature in AWS Organizations that rolls all bills up to the payer account. Simplifies that process by having a single payment method
Consolidated Billing
Feature in AWS Organizations that allows for aggregate discounts
Usage Discounts
Can you easily share reserved instances and savings plans across the organizations in AWS Organizations
Yes
Service allows you to easily achieve a multi-account design while maintaining centralized management
AWS Organizations
Logical grouping of multiple accounts to allow for easy management and separation within AWS Organizations
Organizational Unit (OU)
Policies within AWS Organizations that get applied to OUs or accounts to restrict actions
Service Control Policies (SCP)
Free service that allows you to share AWS resources with other accounts inside or outside your organization
Resource Access Manager (RAM)
Free service that allows you to easily share resources rather than having to create duplicate copies in your different accounts
Resource Access Manager (RAM)
Gives you the ability to set up temporary access you can easily control. Has temporary credentials that can be revoked as needed
Cross-account role access
Service is an inventory management and control tool that shows the configuration history of your infrastructure over time. Monitoring and assessment tool. Track AWS architecture and check for best practice violations
AWS Config
Service offers the ability to create rules to make sure resources conform to your requirements. Monitoring and assessment tool. Track AWS architecture and check for best practice violations
AWS Config
Can Config receive alerts via SNS?
Yes
Can AWS Config be configured cross-region?
No
Does AWS Config have to be configured per region?
Yes
Can the results of Config be aggregated across Regions and AWS Accounts?
Yes
Service that is used to gain a view of your infrastructure’s overall compliance at an entire organizational level. Track AWS architecture and check for best practice violations
AWS Config
Represent your ideal configuration settings in AWS Config. AWS-managed and custom. Evaluated by a schedule or trigger
Rules
Is AWS Config free?
No
Does AWS Config offer automatic remediation of non-compliant configurations?
Yes
AWS Config feature used for automatic remediation. Can be aws-managed or custom
SSM Automation Documents
Automation Documents that can leverage Lambda functions for custom logic
Custom
Can you enable a retry if auto-remediation fails in AWS Config
Yes
Can EventBridge send events from AWS Config to other AWS services like SQS and Lambda?
Yes
Service is a fully managed version of Active Directory. Allows you to offload the painful parts of keeping AD online and run AD inside of AWS
AWS Directory Service
Type of Directory Service that allows you to easily build out AD in AWS. Entire AD suit
Managed Microsoft AD