Trusted Advisor Flashcards
Trusted advisor
What is Trusted Advisor?
Real-time guidance help follow AWS Best Practices
Trusted advisor
What’s in the generated report?
ZIP file with CSV listing all filtered checks (and JSON summary)
Trusted advisor
How do you install the Agent?
Don’t. No agent, it just pokes around your AWS account.
Features and Support
Trusted Advisor w/ Basic support?
AWS console, only Service Limits catg + 7 basic, core checks
Features and Support
Trusted Advisor w/ Developer support?
AWS console, only Service Limits catg + 7 basic, core checks
Features and Support
Trusted Advisor w/ Business support?
All checks
Features and Support
Trusted Advisor w/ Enterprise support?
All checks
Features and Support
What’s special about Business or Enterprise support?
Get access to the support API; CloudWatch Events
Features and Support
What can you do with the support API?
see and close suppport cases, react to Trusted Advisor recommendations
Checks
What happens when a check triggers?
Use CloudWatch Events to trigger things
Checks
Kinds of check results?
Red (action recommended), Yellow (investigation recommended)
Checks
What is gray color all about?
You previously excluded some resources from the check, no recommendations
Checks
What does AWS show when a check is red?
Recommended ways to fix/improve
Checks
Why does a check show red, but the services looks ok?
Checks refreshed automatically only weekly
Checks
How are Config-backed TA check refreshed?
Can’t refresh them
Checks
How are Config-backed TA checks updated?
Config updates them based on Config triggers
AWS Organizations
What happens when you filter on something?
Changes display only, doesn’t affect running checks
AWS Organizations
Get TA to work in your Organizations?
Turn on from Mgmt acct, creates ServiceLinkedRoles everywhere
AWS Organizations
Requirement for using TA with Orgs?
Uses the support plan in each member acct for avail checks
TA and Other AWS Services
Relationship with AWS Config?
Config powers some of the TA checks
TA and Other AWS Services
How can you exclude resources from Config-powered TA checks?
Can’t
TA and Other AWS Services
How does TA and Secuirty Hub work together?
View security controls from SH in TA
TA and Other AWS Services
How do you get Security Hub to send results to TA?
Happens automatically once you turn them on
TA and Other AWS Services
How do Orgs, Secuirty Hub and TA interact?
Each member account has to turn on Security Hub to flow into TA
TA and Other AWS Services
How do you exclude resources for Security Hub checks in TA?
Can’t. Exclude resources in Security Hub.
TA and Other AWS Services
When does Security Hub send results to TA?
Depends on control – periodic or change-triggered like AWS Config
TA and Other AWS Services
Refresh Security Hub checks in TA?
Can’t, have to refresh in Security Hub, just like AWS Config