Identity and Access Management (IAM) - Advanced Flashcards

1
Q

What is AWS Organizations?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How do Organizational Units relate to the AWS Organization?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are some examples of Organizational Units in AWS Organizations?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the advantages of using AWS Organizations?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are Service Control Policies (SCP) in AWS Organizations?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the hierarchy of Service Control Policies (SCP) in AWS Organizations?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

With Service Control Policies (SCP) in AWS Organizations, if you have both an explicit deny and an explicit allow policy applied, which takes precedence?

A

The deny, always

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What would a Service Control Policy (SCP) in AWS Organizations look like that allowed all access except DynamoDB (aka “Blocklist Strategy”)?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What would a Service Control Policy (SCP) in AWS Organizations look like that blocked everything except EC2 and CloudWatch (aka “Allowlist Strategy”)?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does a Policy in IAM look like that has a condition applied to restrict the client IP from which the API calls are being made?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does a Policy in IAM look like that has a condition applied to restrict the region the API calls are made to?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does a Policy in IAM look like that has a condition applied to restrict based on tags?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does a Policy in IAM look like that has a condition applied to to force MFA?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What does an IAM policy look like for a Bucket in S3 as opposed to an Object in S3?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

In IAM, what would an IAM policy look like that restricts access to accounts that are member of an AWS Organization?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the fundamental differences between IAM Roles vs Resource Based Policies as it relates to cross-account access?

17
Q

What are the fundamental differences between IAM Roles vs Resource Based Policies?

18
Q

When should you use IAM Roles vs Resource Based Policies when adding security in EventBridge?

19
Q

What are IAM Permission Boundaries?

20
Q

What are the use cases for IAM Permission Boundaries?

21
Q

How does the IAM Policy Evaluation Logic work?

22
Q

In AWS Organization SCP, is all access defaulted to implicit allow or implicit deny?

A

Implicit deny

23
Q

What is the AWS IAM Identity Center?

24
Q

What does the AWS IAM Identity Center login flow look like?

25
How does the AWS IAM Identity Center work?
26
How does everything in AWS IAM Identity Center relate for Organizations, Users and Groups (i.e. Permission Sets)?
27
How do AWS IAM Identity Center fine-grained Permissions and Assignments work?
28
What is Microsoft Active Directory (AD)?
29
What is AWS Directory Services?
30
How do you set-up Active Directory in IAM Identity Center?
31
What is AWS Control Tower?
32
How does AWS Control Tower Guardrails work?