Control Tower 2 Flashcards

1
Q

VPCs, Networking, Regions

What does Control Tower do with VPCs?

A

Deletes the default VPC. Creates new Control Tower VPC.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

VPCs, Networking, Regions

What’s in the Control Tower VPC?

A

3 AZs. Each has 1 public and 2 private subnets. IP space divided equally. No overlaps.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

VPCs, Networking, Regions

Control Tower and Regions?

A

Home Region is where you start. Have to tell Control Tower to move into new regions and manage them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

VPCs, Networking, Regions

Can accounts enrolled in Control Tower deploy into regions that aren’t enabled when setting up the Landing Zone?

A

Yes (but controls, auditing, etc. are not enabled, no data collected, nothing enforced)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

VPCs, Networking, Regions

What is Region Deny?

A

Can prevent users from accessing resources in Regions not governed by your LZ.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

VPCs, Networking, Regions

At what level do you set Region Deny?

A

Whole Organization. Can’t set at particular OUs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Controls

Another name for Controls?

A

Guardrails (an older term being phased out)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Controls

Where in Organizations do Controls live?

A

Anywhere! Per-OU, multiple OUs, inherited down

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Controls

Use Case for different Controls in different OUs?

A

Developer OU has wide open controls, production OU is locked-down tight

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Controls

Three categories of Controls?

A

Preventative (can’t happen), Proactive (Stop provisioning), Dectective (find an existing bad thing)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Controls

Example system providing Preventative Controls?

A

SCPs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Controls

Example system providing Proacrtive Controls?

A

CloudFormation hooks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Controls

Example system providing Dectective Controls?

A

Config rules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Controls

Three types of Control guidance?

A

Mandatory, Strongly Recommended, and Elective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Controls

Can you turn off or disable a Mandatory Control?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Controls

At what Org level are Mandatory Controls?

A

Root (everywhere)

17
Q

Controls

Are Mandatory Controls on by default in a new LZ?

A

Yes

18
Q

Controls

Can you turn off or disable a Strongly Recommended Control?

A

Yes

19
Q

Controls

At what Org level are Strongly Recommended Controls?

A

Any OUs you want

20
Q

Controls

Are Strongly Recommended Controls on by default in a new LZ?

A

No

21
Q

Controls

Can you turn off or disable an Elective Control?

A

Yes

22
Q

Controls

At what Org level are Elective Controls?

A

Any OUs you want

23
Q

Controls

Are Elective Controls on by default in a new LZ?

A

No

24
Q

Controls

What’s the differentiator between Strongly Recommended and Elective Controls?

A

Elective are for niche things, SR are generally good ideas across core workloads.

25
Q

Controls

What Controls are in effect in the CT Management account?

A

None: deliberately unrestricted

26
Q

Controls

What happens to the in-account Controls when you move an account to another OU?

A

You have some manual steps to get it all sorted out…no automatic.

27
Q

Controls

Examples of Mandatory Controls?

A

Can’t change things set up by CT, like notification SNS or AWS Config rules

28
Q

Controls

Example of Proactive Controls?

A

DB tables require PIT recovery turned on, S3 SSE turned on

29
Q

Controls

Example of Strongly Recommended Controls?

A

Encrypt EBS volumes, no public access to RDS databases

30
Q

Controls

Example of Elective Controls?

A

Turn on versioning for S3 buckets