IAM, Accounts, and AWS Organizations Flashcards

1
Q

what is a principal in the context of IAM?

A

An entity trying to authenticate to AWS (could be User, Application, etc)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a principal called after it’s authenticated?

A

Authenticated Identity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the purpose of ARN

A

a way to uniquely access a resource in aws

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

does the ARN arn:aws:s3:::catgifs/* refer to the bucket catgifs?

A

NO - only the objects within the bucket

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How many IAM users are allowed in each account?

A

5000

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How main groups can an IAM user be in?

A

10

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Is there a default “All users” IAM group in aws?

A

NO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How many users can be in an IAM group

A

5000 (effectively “unlimited” – but there is a hard limit on # of IAM users per account)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

⭐ Can groups be granted IAM access by an IAM resoure policy?

A

NO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a Service Control Policy

A

An access policy (similar to IAM) which can be attached to member account in an aws organization (or Organizational Unit)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Can a Service Control Policy be attached to the Management Account

A

NO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

⭐ How can you find the cloudtrail events from IAM, a global service?

A

You must first configure a cloudtrail trail with global events turned on in the us-east-1 region. Global events will flow here.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

how long could it take for a cloud trail event to appear in the logs?

A

up to 15 minutes!

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

are cloudtrail logs realtime?

A

no

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

how you ding

A

fine thanks!

How well did you know this?
1
Not at all
2
3
4
5
Perfectly