Identity and Access Management (IAM) - Advanced Flashcards
An account management service that enables you to consolidate multiple AWS accounts into a single unit that you create and centrally manage
AWS Organizations
A type of organization policy that you can use to manage permissions in your organization. This policy offers central control over the maximum available permissions for all accounts in your organization
Service Control Policies (SCPs)
True/False: Object level permission arns end with /* to represent all sub-objects.
True - ex: “Resource”:”arn:aws:s3:::test/*”
An advanced access management feature for using a managed policy to set the maximum permissions that an identity-based policy can grant to an IAM entity
Permissions boundaries
AWS Directory Service that lets you run Microsoft Active Directory (AD) as a managed service
AWS Managed Microsoft AD
A directory gateway with which you can redirect directory requests to your on-premises Microsoft Active Directory without caching any information in the cloud
Active Directory Connector
A standalone managed directory that is powered by a Samba 4 Active Directory Compatible Server
Simple Active Directory
AWS tool that orchestrates the capabilities of several other AWS services, including AWS Organizations, AWS Service Catalog, and AWS IAM Identity Center (successor to AWS Single Sign-On), to build a landing zone in less than an hour
AWS Control Tower
AWS Control Tower guardrail that uses SCPs to prevent accounts from doing something
Preventive Guardrail
AWS Control Tower guardrail that uses AWS Config to detect non-compliance
Detective Guardrail
What IAM condition key can use to allow API calls from a specified AWS region?
aws:RequestedRegion
This Resource Access Manager feature allows multiple AWS accounts to create their application resources into shared and centrally-managed Amazon Virtual Private Clouds (VPCs)
VPC sharing
Active Directory service that should be used if you only need to allow your on-premises users to log in to AWS applications and services with their Active Directory credentials
Active Directory (AD) Connector
Active Directory service that allows you to run directory-aware workloads in the AWS Cloud
AWS Managed Microsoft Active Directory (AD)
The least expensive Active Directory service and your best choice if you have 5,000 or fewer users and don’t need the more advanced Microsoft Active Directory features such as trust relationships with other domains
Simple Active Directory