Governance Flashcards

1
Q

Service is a free governance tool that allows you to create and manage multiple AWS accounts

A

AWS Organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Service allows you to control your accounts from a single location instead of having to jump from account to account

A

AWS Organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Account within AWS Organizations is also called the payer account. Is the primary account that hosts and manages the organization

A

Management Account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Can there be more than one Management account within AWS Organizations

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Accounts within AWS Organizations that belong to everyone in the organization such as test, dev accounts

A

Member Account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Feature in AWS Organizations that rolls all bills up to the payer account. Simplifies that process by having a single payment method

A

Consolidated Billing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Feature in AWS Organizations that allows for aggregate discounts

A

Usage Discounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Can you easily share reserved instances and savings plans across the organizations in AWS Organizations

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Service allows you to easily achieve a multi-account design while maintaining centralized management

A

AWS Organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Logical grouping of multiple accounts to allow for easy management and separation within AWS Organizations

A

Organizational Unit (OU)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Policies within AWS Organizations that get applied to OUs or accounts to restrict actions

A

Service Control Policies (SCP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Free service that allows you to share AWS resources with other accounts inside or outside your organization

A

Resource Access Manager (RAM)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Free service that allows you to easily share resources rather than having to create duplicate copies in your different accounts

A

Resource Access Manager (RAM)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Gives you the ability to set up temporary access you can easily control. Has temporary credentials that can be revoked as needed

A

Cross-account role access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Service is an inventory management and control tool that shows the configuration history of your infrastructure over time. Monitoring and assessment tool. Track AWS architecture and check for best practice violations

A

AWS Config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Service offers the ability to create rules to make sure resources conform to your requirements. Monitoring and assessment tool. Track AWS architecture and check for best practice violations

A

AWS Config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Can Config receive alerts via SNS?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Can AWS Config be configured cross-region?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Does AWS Config have to be configured per region?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Can the results of Config be aggregated across Regions and AWS Accounts?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Service that is used to gain a view of your infrastructure’s overall compliance at an entire organizational level. Track AWS architecture and check for best practice violations

A

AWS Config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Represent your ideal configuration settings in AWS Config. AWS-managed and custom. Evaluated by a schedule or trigger

A

Rules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Is AWS Config free?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Does AWS Config offer automatic remediation of non-compliant configurations?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
AWS Config feature used for automatic remediation. Can be aws-managed or custom
SSM Automation Documents
26
Automation Documents that can leverage Lambda functions for custom logic
Custom
27
Can you enable a retry if auto-remediation fails in AWS Config
Yes
28
Can EventBridge send events from AWS Config to other AWS services like SQS and Lambda?
Yes
29
Service is a fully managed version of Active Directory. Allows you to offload the painful parts of keeping AD online and run AD inside of AWS
AWS Directory Service
30
Type of Directory Service that allows you to easily build out AD in AWS. Entire AD suit
Managed Microsoft AD
31
Type of Directory Service that creates a tunnel between AWS and your on-premises AD
AD Connector
32
Type of Directory Service that is a simple authentication service
Simple AD
33
Service is an easy-to-use tool that allows you to visualize and analyze your cloud costs
Cost Explorer
34
Can you generate custom reports based on resource tags in Cost Explorer
Yes
35
Service that allows organizations to easily plan and set expectations around cloud costs
AWS Budgets
36
Service that can create alerts to let users know when they're close to exceeding their allotted spend
AWS Budgets
37
Service is the most comprehensive set of cost and usage data available for AWS spending
AWS Cost and Usage Reports (CUR)
38
Can AWS CUR publish billing reports to EC2?
No
39
Can AWS CUR publish billing reports to S3?
Yes
40
Do AWS CUR reports immediately update?
No, once a day
41
Service easily integrates with Athena, Redshift, or Quicksight to develop cost and usage billing reports
AWS Cost and Usage Reports (CUR)
42
Service used to monitor On-Demand capacity reservations
AWS Cost and Usage Reports (CUR)
43
Service used to track Savings Plans utilizations, charges, and allocations
AWS Cost and Usage Reports (CUR)
44
Service used to break down your AWS data transfer charges
AWS Cost and Usage Reports (CUR)
45
Service that analyzes configurations and utilization metrics of your AWS resources
AWS Compute Optimizer
46
Service that reports current usage optimizations and potential recommendations
AWS Compute Optimizer
47
Service that provides a graphical history data and projected utilization metrics
AWS Compute Optimizer
48
Service that works with EC2, ASGs, EBS, Lambda that analyzes configuration and utilization metics of your AWS resources
AWS Compute Optimizer
49
Is AWS Compute Optimizer enabled by default
No
50
Pricing model that offers flexible pricing for up to 72% savings on compute
Savings Plans
51
Pricing model that offers lower prices for EC2 instances regardless of instance family, size, os, tenancy, or regions
Savings Plans
52
Can the pricing model Savings Plans apply to Lambda or Fargate usage?
Yes
53
Can the pricing model Savings Plans apply to Sagemaker for lowering instance pricing?
Yes
54
Pricing model provides savings for long-term commitments in one-year or three-year pricing options. All upfront, Partial upfront, or No upfront.
Savings Plans
55
Type of Saving Plans that applies to any EC2 compute, Lambda, or Fargate usage. Up to 66% savings on compute
Compute Savings
56
Type of Savings Plans that applies only to EC2 instances of a specific instance family in specific regions. Offers 72% savings
EC2 Instance Savings
57
Type of Savings Plans that apply to SageMaker instances regardless of instance family or sizing. Up to 64% savings
SageMaker savings
58
Service is an easy way to set up and govern an AWS multi-account environment by automating account creation and security controls via other AWS services
AWS Control Tower
59
Service extends AWS Organizations to prevent governance drift and leverages different guardrails
AWS Control Tower
60
Service where users can provision new AWS accounts quickly using central admin-established compliance policies
AWS Control Tower
61
Service is the quickest way to create and manage a secure, compliant, multi-account environment based on best practices
AWS Control Tower
62
Feature of AWS Control tower that are high-level rules in plain language providing ongoing governance
Guardrails
63
Type of rules in Guardrails that ensure account maintain governance by disallowing violating actions
Preventive
64
Type of rules in Guardrails that detect and alert on non-compliant resources within all accounts from AWS Config
Detective
65
Shared accounts within the AWS Control Tower
Management, log archive, audit account
66
Service that simplifies managing software licenses with different vendors by centrally managing licenses across AWS accounts and on-premises environments
AWS License Manager
67
Service that provides visibility of resource performance and availability of AWS services or accounts. Provides visibility into service and resource health
AWS Health
68
Service that has near-instant delivery of notifications and alerts to speed up troubleshooting or prevention
AWS Health
69
Automate certain actions based on incoming events using
Amazon Eventbridge
70
Service is a fully managed best-practice auditing tool. It inspects your AWS environment and then makes recommendations when opportunities exist to save money.
AWS Trusted Advisor
71
Does AWS Trusted Advisor make recommendations based on the entire account?
Yes
72
One of the only ways to limit a root account
Service Control Policies (SCP)
73
Service used to simplify access management to multiple AWS accounts, AWS applications, and other SAML-enabled cloud applications.
AWS Identity Center
74
Service that allows organizations to create and centrally manage catalogs of approved IT services as CloudFormation templates
AWS Service Catalog
75
Service that creates and manages infrastructure (IaC) and deployment tooling for users as well as serverless and container-based applications
AWS Proton
76
Service is a tool for measuring current workload against established AWS best practices. Documents workload and architecture decisions
AWS Well-Architected Tool
77