#2 IAM, Accounts and AWS Organizations Flashcards

1
Q

Is there a limit to the number of IAM users in an AWS Account? if so, how many?

A

5000 per account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

An IAM User can be a member of how many groups?

A

10

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A concept within AWS that allows you to manage access and permissions for individuals or applications interacting with your AWS resources. Think of it like a digital ID card that gives a person or an application specific permissions to use different AWS services.

A

IAM Users (Identity and Access Management)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which of the following are features of IAM groups?

A. Admin groupings of IAM Users
B. Can hold identity Permissions
C. Can be used to login (Access Keys)
D. Can be used to login (Username and password)
F. Can be nested

A

A. Admin groupings of IAM Users
B. Can hold Identity Permissions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Within AWS policies, what is always a priority?

A

Explicit Deny

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What two policies are assigned to an IAM Role?

A
  1. Permissions Policy
  2. Trust Policy
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which of the following are true for IAM Roles?

A. Roles have associated Long Term Credentials (Access Keys)
B. Roles can be assumed
C. When assumed - temporary credentials are generated
D. Roles can be logged into
F. When an identity logs into a role - temporary credentials are generated

A

B. Roles can be assumed
C. When assumed - temporary credentials are generated.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What three features are provided by AWS Organizations?

A. Consolidated billing
B. Managed assistance for company and AWS account mergers
C. AWS Account restrictions using SCP
D. Account organization via OU’s
E. Protection against credential leaks
F. Company ID reports

A

A. Consolidated billing
C. AWS Account restrictions using SCP
D. Account organization via OU’s

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What functionality is provided by CloudTrail?

A

Account wide Auditing and API Logging

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Is it possible to restrict what the Account Root User can do?

A

If AWS Organizations are used .. but not the management account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Role Switching?

A

Assuming a role in another AWS account to access that account via the console UI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly