Identity and Access Management (IAM) - Advanced Flashcards

1
Q

What is AWS Organizations?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How do Organizational Units relate to the AWS Organization?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are some examples of Organizational Units in AWS Organizations?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the advantages of using AWS Organizations?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are Service Control Policies (SCP) in AWS Organizations?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the hierarchy of Service Control Policies (SCP) in AWS Organizations?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

With Service Control Policies (SCP) in AWS Organizations, if you have both an explicit deny and an explicit allow policy applied, which takes precedence?

A

The deny, always

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What would a Service Control Policy (SCP) in AWS Organizations look like that allowed all access except DynamoDB (aka “Blocklist Strategy”)?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What would a Service Control Policy (SCP) in AWS Organizations look like that blocked everything except EC2 and CloudWatch (aka “Allowlist Strategy”)?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does a Policy in IAM look like that has a condition applied to restrict the client IP from which the API calls are being made?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does a Policy in IAM look like that has a condition applied to restrict the region the API calls are made to?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does a Policy in IAM look like that has a condition applied to restrict based on tags?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does a Policy in IAM look like that has a condition applied to to force MFA?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What does an IAM policy look like for a Bucket in S3 as opposed to an Object in S3?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

In IAM, what would an IAM policy look like that restricts access to accounts that are member of an AWS Organization?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the fundamental differences between IAM Roles vs Resource Based Policies as it relates to cross-account access?

A
17
Q

What are the fundamental differences between IAM Roles vs Resource Based Policies?

A
18
Q

When should you use IAM Roles vs Resource Based Policies when adding security in EventBridge?

A
19
Q

What are IAM Permission Boundaries?

A
20
Q

What are the use cases for IAM Permission Boundaries?

A
21
Q

How does the IAM Policy Evaluation Logic work?

A
22
Q

In AWS Organization SCP, is all access defaulted to implicit allow or implicit deny?

A

Implicit deny

23
Q

What is the AWS IAM Identity Center?

A
24
Q

What does the AWS IAM Identity Center login flow look like?

A
25
Q

How does the AWS IAM Identity Center work?

A
26
Q

How does everything in AWS IAM Identity Center relate for Organizations, Users and Groups (i.e. Permission Sets)?

A
27
Q

How do AWS IAM Identity Center
fine-grained Permissions and Assignments work?

A
28
Q

What is Microsoft Active Directory (AD)?

A
29
Q

What is AWS Directory Services?

A
30
Q

How do you set-up Active Directory in IAM Identity Center?

A
31
Q

What is AWS Control Tower?

A
32
Q

How does AWS Control Tower Guardrails work?

A