Governance Flashcards
What is needed for creating AWS Organizations
Logging Account (which will hold S3 buckets for logging to Cloudtrail)
Primary Account for using for consolidated billing
How to create Global Policy for accounts in AWS Organizations and only way to restrict what root account can do
Service Control Policy (SCP)
How to Share RIs across multiple accounts
AWS Organizations
&
AWS RAM
Free service that allows you to share AWS resources with other accounts such as VPC and Transit Gateways
AWS RAM
TRUE or FALSE AWS RAM can only share resources with accounts in your AWS Organization
False, can also do it with accounts that are outside your org
If you need to share resources in the same region which AWS service should you use?
AWS RAM
If you need to share VPC resources cross-regionally what should you use?
VPC Peering
If I have a temp employee that needs access across my AWS accounts what can I do?
Give them temporary Role access
Inventory Management and control tool to see what you have in your AWS account, enforce standards, and notify you when state of architecture changes
AWS Config
3 Key functionalities of AWS Config
Query resources
Create Rules to enforce what is happening (prevent public S3 buckets) for compliance
Can tell history of env
TRUE or FALSE AWS Config Rules can have remediation steps taken automatically
True, can setup Automation Documents or use Lambda
Fully managed AD service for when we want to migrate everything to AWS for AD management
Microsoft AD
Fully managed AD for when we want to leave AD on-prem
AD Connector
Easy to use tool that allows us to visualize our cost in reports and can allocate costs on resource tags
AWS Cost Explorer
Service I can use to forcast how much I will spend based on my billing history.
AWS Cost Explorer
Allows Organizations to easily plan and set expectations across cost, allocate spend, and can set alerts when getting close to budget.
AWS Budgets
4 types of budgets that can be used with AWS Budgets
Cost Budgets
Usage Budgets
Reservations Budget
Savings Plan Budgets
Where does AWS CUR publish billing reports as CSV
To centralized S3 bucket
How can costs be broken down in AWS CUR
time span,
service and resource
tag
AWS service that has most comprehensive set of cost and usage data
AWS CUR (Cost and Usage Reports)
What services does AWS CUR integrate with?
Athena
Redshift
Quicksight
Services that work with AWS Compute Optimizer Resources
EC2
ASG
EBS
Lambda
Supported Account types with AWS Compute Optimizer Resources
Standalone
Member Account
Management Account in an Organization
Compatibile service with AWS Compute Savings Plans
EC2, Lambda, and Fargate