Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

AWS Governance

Total questions: 20

Worksheet time: 20mins

Name
Class
Date
1.

What is the primary purpose of using permissions boundaries in AWS Identity and Access Management (IAM)?

a)

To assign fine-grained permissions to individual resources.

b)

To set the maximum permissions a user or group can have within an AWS account.

c)

To define network access controls for AWS resources.

d)

To configure cross-account access between AWS accounts.

2.

In AWS networking, what best describes the role of the "Hub" in a Hub & Spoke architecture?

a)

The central point connecting multiple VPCs.

b)

A VPC with limited connectivity to other VPCs.

c)

A VPC with direct connections to end-users.

d)

A region-specific virtual network.

3.

What is the key benefit of using Transit Gateway in AWS networking compared to traditional VPC peering?

a)

Reduced latency in communication between VPCs.

b)

Increased security with end-to-end encryption.

c)

Simplified management of VPC connections.

d)

Enhanced scalability of VPC resources.

4.

In AWS Organizations, what is the purpose of organizational units (OUs)?

a)

To define fine-grained permissions for individual users.

b)

To group AWS accounts for applying common policies.

c)

To establish direct network connections between accounts.

d)

To configure cross-region access for resources.

5.

What is the purpose of service control policies (SCPs) in AWS Organizations?

a)

To define fine-grained permissions for individual users.

b)

To restrict the maximum permissions across all AWS accounts.

c)

To establish direct network connections between accounts.

d)

To configure cross-region access for resources.

6.

What is the purpose of AWS Control Tower in AWS ?

a)

To manage permissions for IAM users.

b)

To automate the deployment and management of a secure, multi-account AWS environment.

c)

To configure network access controls for AWS resources.

d)

To establish direct connections between different VPCs.

7.

Which AWS service is responsible for providing a centralized location for users to access their AWS accounts, manage permissions, and view usage information?

a)

AWS Organizations

b)

AWS Identity and Access Management (IAM)

c)

AWS Control Tower

d)

AWS Identity Center

8.

How can AWS Organizations help in managing billing for multiple AWS accounts?

a)

By consolidating billing information for linked accounts.

b)

By defining fine-grained permissions for billing access.

c)

By obtaining more details about resource consumption.

d)

By adding features to export the data to other systems.

9.

What is the purpose of AWS Control Tower's "guardrails" (controls)?

a)

To define fine-grained permissions for individual users.

b)

To ensure end-to-end encryption for network traffic.

c)

To automate the enforcement of AWS best practices.

d)

To establish direct connections between VPCs.

10.

How can a Service Control Policy (SCP) affect the root identity of an AWS account?

a)

It can modify the root user's password.

b)

It can restrict the root user's permissions.

c)

It can create a new root user.

d)

It can delete the root user.

11.

How does AWS Organizations' centralized billing affect the utilization of AWS Saving Plans across linked accounts?

a)

Saving Plans are specific to individual accounts and cannot be shared across linked accounts.

b)

AWS Organizations' consolidated billing allows the pooling of Saving Plans, providing flexibility in utilization across linked accounts.

c)

AWS Organizations restricts the purchase of Saving Plans, limiting them to the account where they were initially created.

d)

Saving Plans automatically apply to all linked accounts, regardless of AWS Organizations settings.

12.

In an AWS Organizations setup with consolidated billing, how does the purchase of Reserved Instances (RIs) affect cost optimization for linked accounts?

a)

Reserved Instances are specific to individual accounts, and their benefits do not extend to linked accounts.

b)

AWS Organizations' consolidated billing ensures that Reserved Instance benefits are shared across linked accounts, maximizing cost savings.

c)

AWS Organizations requires separate Reserved Instance purchases for each linked account, limiting cost optimization.

d)

Reserved Instances are automatically applied to linked accounts, regardless of AWS Organizations settings.

13.

When considering AWS Organizations' consolidated billing, what is a key difference between Saving Plans and Reserved Instances?

a)

Reserved Instances provide greater flexibility in cost allocation across linked accounts.

b)

Savings Plans offer more predictable pricing with a commitment to a consistent amount of usage, while Reserved Instances require commitment to specific instance types.

c)

AWS Organizations' consolidated billing treats Savings Plans and Reserved Instances identically, without any differences in cost allocation.

d)

Saving Plans require upfront payments, while Reserved Instances offer a pay-as-you-go pricing model.

14.

What role do Detective Guardrails play in AWS Control Tower?

a)

They prevent the creation of new AWS accounts.

b)

They automatically remediate non-compliant resources.

c)

They analyze and report on potential policy violations for further investigation.

d)

They avoid the creation of new IAM Users and Groups.

15.

How do Preventive Guardrails in AWS Control Tower differ from Detective Guardrails?

a)

Preventive Guardrails analyze and report on potential policy violations, while Detective Guardrails enforce policies.

b)

Preventive Guardrails deny the creation of non-compliant resources, while Detective Guardrails provide insights for investigation.

c)

Preventive Guardrails establish network connections, while Detective Guardrails prevent the creation of new AWS accounts.

d)

There is no difference between Preventive and Detective Guardrails.

16.

What two other policies can be implemented with AWS Organizations?

a)

Backup Policies

b)

IAM Policies

c)

Tag Policies

d)

Network Policies

17.

Which three types of controls does AWS Control Tower Provides?

a)

Detective

b)

Reactive

c)

Proactive

d)

Preventive

18.

How can I deactivate the Control Tower Mandatory controls?

a)

With the Control Tower root user.

b)

Applying an SCP at the root account.

c)

You can not deactivate them.

d)

By delegating the control to another AWS Account.

19.

What is the primary difference between AWS Control Tower and AWS Organizations?

a)

AWS Control Tower focuses on automating the deployment and management of a secure, multi-account AWS environment, while AWS Organizations primarily manages consolidated billing and AWS Account hierarchy.

b)

AWS Control Tower provides fine-grained permissions and access controls for individual users and resources, whereas AWS Organizations focuses on defining organizational units and grouping AWS accounts.

c)

AWS Control Tower establishes network connectivity between VPCs, while AWS Organizations enforces governance and compliance through guardrails.

d)

AWS Control Tower and AWS Organizations serve identical purposes and have no distinct differences.

20.

What is a key benefit of employing a multi-account strategy in AWS instead of using a single AWS account for all organizational deployments?

a)

It simplifies billing by consolidating all charges into a single invoice.

b)

It enhances security by isolating workloads and controlling access at the account level.

c)

It provides better performance for all resources within the organization.

d)

It eliminates the need for AWS Identity and Access Management (IAM) roles.