AWS Config Flashcards

1
Q

What is AWS Config?

A

Managed service that provides you with AWS resource inventory, configuration history, and configuration change notifications that enable security and governance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does AWS Config enable for compliance requirements?

A
  • Compliance auditing
  • Security Analysis
  • Resource Tracking
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does AWS Config provide for compliance and governance?

A
  • Configuration snapshots

- Automated compliance checking

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

True or false: AWS Config provides automated compliance checking through notifications when changes occur?

A

True.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

AWS Config is region specific; true or false?

A

True. AWS Config must be set up for each region as of 2019.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

in AWS Config, what is a Configuration item?

A

Point-in-time attributes of a resource

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

in AWS Config, what is a configuration snapshot?

A

A collection of config items

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

in AWS Config, what is a configuration stream?

A

A stream of changed config items

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

in AWS Config, what is a configuration history

A

A collection of config items for a resource over time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

in AWS Config, what is a configuration recorder

A

The configuration of Config that records and stores config items

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Where are AWS Config Recorder logs stored?

A

S3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

True or false: When AWS Config detects a change, AWS Config Recorder sends notifications through SES?

A

False: Config changes are sent via SNS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Does AWS Config allows you to see resource types?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

True or false, AWS Config displays resource IDs?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

True or false, AWS Config cannot show compliance status?

A

False. AWS Config is used for compliance monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

True or False: AWS Config Timeline displays Configuration details

A

True

17
Q

True or False: AWS Config Timeline displays relationships?

A

True

18
Q

True or False: AWS Config Timeline displays CloudWatch events?

A

False

19
Q

True or False: AWS Config Timeline displays changes made?

A

True

20
Q

True or False: AWS Config Timeline displays website performance metrics?

A

False

21
Q

True or False: AWS Config Timeline displays CloudTrail Events?

A

True

22
Q

True or False: AWS Config compliance checks have two kinds of triggers?

A

True

23
Q

What are the two types of AWS Config compliance triggers?

A
  • Periodic

- Configuration snapshop delivery

24
Q

How many AWS managed rules exist

A

About 40

25
Q

Permission settings for AWS Config

A
  • An IAM role with:
    • Read-only permissions to recorded resources,
    • Write access to S3 logging bucket
    • Publish access to SNS
26
Q

Should you give all users with monitor roles admin access to AWS Config?

A

No. Provide read-only access for day-to-day monitoring.

27
Q

Should AWS Config administrators be given read-only access to AWS Config?

A

No. Provide administrative access for AWS Config administrators.

28
Q

Should you check out the AWS Config FAQ?

A

Yes. https://aws.amazon.com/config/faq/