Governance Flashcards

1
Q

Service is a free governance tool that allows you to create and manage multiple AWS accounts

A

AWS Organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Service allows you to control your accounts from a single location instead of having to jump from account to account

A

AWS Organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Account within AWS Organizations is also called the payer account. Is the primary account that hosts and manages the organization

A

Management Account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Can there be more than one Management account within AWS Organizations

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Accounts within AWS Organizations that belong to everyone in the organization such as test, dev accounts

A

Member Account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Feature in AWS Organizations that rolls all bills up to the payer account. Simplifies that process by having a single payment method

A

Consolidated Billing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Feature in AWS Organizations that allows for aggregate discounts

A

Usage Discounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Can you easily share reserved instances and savings plans across the organizations in AWS Organizations

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Service allows you to easily achieve a multi-account design while maintaining centralized management

A

AWS Organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Logical grouping of multiple accounts to allow for easy management and separation within AWS Organizations

A

Organizational Unit (OU)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Policies within AWS Organizations that get applied to OUs or accounts to restrict actions

A

Service Control Policies (SCP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Free service that allows you to share AWS resources with other accounts inside or outside your organization

A

Resource Access Manager (RAM)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Free service that allows you to easily share resources rather than having to create duplicate copies in your different accounts

A

Resource Access Manager (RAM)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Gives you the ability to set up temporary access you can easily control. Has temporary credentials that can be revoked as needed

A

Cross-account role access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Service is an inventory management and control tool that shows the configuration history of your infrastructure over time. Monitoring and assessment tool. Track AWS architecture and check for best practice violations

A

AWS Config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Service offers the ability to create rules to make sure resources conform to your requirements. Monitoring and assessment tool. Track AWS architecture and check for best practice violations

A

AWS Config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Can Config receive alerts via SNS?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Can AWS Config be configured cross-region?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Does AWS Config have to be configured per region?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Can the results of Config be aggregated across Regions and AWS Accounts?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Service that is used to gain a view of your infrastructure’s overall compliance at an entire organizational level. Track AWS architecture and check for best practice violations

A

AWS Config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Represent your ideal configuration settings in AWS Config. AWS-managed and custom. Evaluated by a schedule or trigger

A

Rules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Is AWS Config free?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Does AWS Config offer automatic remediation of non-compliant configurations?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

AWS Config feature used for automatic remediation. Can be aws-managed or custom

A

SSM Automation Documents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Automation Documents that can leverage Lambda functions for custom logic

A

Custom

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Can you enable a retry if auto-remediation fails in AWS Config

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Can EventBridge send events from AWS Config to other AWS services like SQS and Lambda?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Service is a fully managed version of Active Directory. Allows you to offload the painful parts of keeping AD online and run AD inside of AWS

A

AWS Directory Service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

Type of Directory Service that allows you to easily build out AD in AWS. Entire AD suit

A

Managed Microsoft AD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

Type of Directory Service that creates a tunnel between AWS and your on-premises AD

A

AD Connector

32
Q

Type of Directory Service that is a simple authentication service

A

Simple AD

33
Q

Service is an easy-to-use tool that allows you to visualize and analyze your cloud costs

A

Cost Explorer

34
Q

Can you generate custom reports based on resource tags in Cost Explorer

A

Yes

35
Q

Service that allows organizations to easily plan and set expectations around cloud costs

A

AWS Budgets

36
Q

Service that can create alerts to let users know when they’re close to exceeding their allotted spend

A

AWS Budgets

37
Q

Service is the most comprehensive set of cost and usage data available for AWS spending

A

AWS Cost and Usage Reports (CUR)

38
Q

Can AWS CUR publish billing reports to EC2?

A

No

39
Q

Can AWS CUR publish billing reports to S3?

A

Yes

40
Q

Do AWS CUR reports immediately update?

A

No, once a day

41
Q

Service easily integrates with Athena, Redshift, or Quicksight to develop cost and usage billing reports

A

AWS Cost and Usage Reports (CUR)

42
Q

Service used to monitor On-Demand capacity reservations

A

AWS Cost and Usage Reports (CUR)

43
Q

Service used to track Savings Plans utilizations, charges, and allocations

A

AWS Cost and Usage Reports (CUR)

44
Q

Service used to break down your AWS data transfer charges

A

AWS Cost and Usage Reports (CUR)

45
Q

Service that analyzes configurations and utilization metrics of your AWS resources

A

AWS Compute Optimizer

46
Q

Service that reports current usage optimizations and potential recommendations

A

AWS Compute Optimizer

47
Q

Service that provides a graphical history data and projected utilization metrics

A

AWS Compute Optimizer

48
Q

Service that works with EC2, ASGs, EBS, Lambda that analyzes configuration and utilization metics of your AWS resources

A

AWS Compute Optimizer

49
Q

Is AWS Compute Optimizer enabled by default

A

No

50
Q

Pricing model that offers flexible pricing for up to 72% savings on compute

A

Savings Plans

51
Q

Pricing model that offers lower prices for EC2 instances regardless of instance family, size, os, tenancy, or regions

A

Savings Plans

52
Q

Can the pricing model Savings Plans apply to Lambda or Fargate usage?

A

Yes

53
Q

Can the pricing model Savings Plans apply to Sagemaker for lowering instance pricing?

A

Yes

54
Q

Pricing model provides savings for long-term commitments in one-year or three-year pricing options. All upfront, Partial upfront, or No upfront.

A

Savings Plans

55
Q

Type of Saving Plans that applies to any EC2 compute, Lambda, or Fargate usage. Up to 66% savings on compute

A

Compute Savings

56
Q

Type of Savings Plans that applies only to EC2 instances of a specific instance family in specific regions. Offers 72% savings

A

EC2 Instance Savings

57
Q

Type of Savings Plans that apply to SageMaker instances regardless of instance family or sizing. Up to 64% savings

A

SageMaker savings

58
Q

Service is an easy way to set up and govern an AWS multi-account environment by automating account creation and security controls via other AWS services

A

AWS Control Tower

59
Q

Service extends AWS Organizations to prevent governance drift and leverages different guardrails

A

AWS Control Tower

60
Q

Service where users can provision new AWS accounts quickly using central admin-established compliance policies

A

AWS Control Tower

61
Q

Service is the quickest way to create and manage a secure, compliant, multi-account environment based on best practices

A

AWS Control Tower

62
Q

Feature of AWS Control tower that are high-level rules in plain language providing ongoing governance

A

Guardrails

63
Q

Type of rules in Guardrails that ensure account maintain governance by disallowing violating actions

A

Preventive

64
Q

Type of rules in Guardrails that detect and alert on non-compliant resources within all accounts from AWS Config

A

Detective

65
Q

Shared accounts within the AWS Control Tower

A

Management, log archive, audit account

66
Q

Service that simplifies managing software licenses with different vendors by centrally managing licenses across AWS accounts and on-premises environments

A

AWS License Manager

67
Q

Service that provides visibility of resource performance and availability of AWS services or accounts. Provides visibility into service and resource health

A

AWS Health

68
Q

Service that has near-instant delivery of notifications and alerts to speed up troubleshooting or prevention

A

AWS Health

69
Q

Automate certain actions based on incoming events using

A

Amazon Eventbridge

70
Q

Service is a fully managed best-practice auditing tool. It inspects your AWS environment and then makes recommendations when opportunities exist to save money.

A

AWS Trusted Advisor

71
Q

Does AWS Trusted Advisor make recommendations based on the entire account?

A

Yes

72
Q

One of the only ways to limit a root account

A

Service Control Policies (SCP)

73
Q

Service used to simplify access management to multiple AWS accounts, AWS applications, and other SAML-enabled cloud applications.

A

AWS Identity Center

74
Q

Service that allows organizations to create and centrally manage catalogs of approved IT services as CloudFormation templates

A

AWS Service Catalog

75
Q

Service that creates and manages infrastructure (IaC) and deployment tooling for users as well as serverless and container-based applications

A

AWS Proton

76
Q

Service is a tool for measuring current workload against established AWS best practices. Documents workload and architecture decisions

A

AWS Well-Architected Tool

77
Q
A