← AWS Certified Solutions Architect - Professional
AWS · objective · 26% of the exam
Design Solutions for Organizational Complexity — AWS Certified Solutions Architect - Professional
The official AWS documentation our Design Solutions for Organizational Complexity practice questions are cited to. Review the primary sources, then practise.
Official references for this objective
-
Amazon Web Services — Security best practices in IAM - AWS Identity and Access Management
Require human users to use federation with an identity provider to access AWS using temporary credentials
-
Amazon Web Services — How to improve cross-account access for SaaS applications accessing customer accounts | AWS Security Blog
a highly recommended approach is to use the external ID parameter when assuming roles in customers’ accounts
-
Amazon Web Services — Network connectivity - AWS Prescriptive Guidance
maintaining peering connections between all of the VPCs can become a maintenance burden. You might also be limited by the maximum number of VPC peering
-
Amazon Web Services — What is AWS Resource Access Manager? - AWS Resource Access Manager
the permissions attached to the resource share are the maximum permissions available to be granted to roles and users in those accounts. The administrator of
-
Amazon Web Services — Centralize network connectivity using AWS Transit Gateway - AWS Prescriptive Guidance
In the AWS Organizations management account, turn on sharing. To share the transit gateway with your organization or with certain organizational units, turn on sharing
-
Amazon Web Services — Cross account resource access in IAM - AWS Identity and Access Management
The customer creates an IAM role in their own account with a policy that allows access the Amazon S3 resources that the APN partner requires
-
Amazon Web Services — AWS Direct Connect and IPSec VPN - Hybrid Networking Lens - AWS Well-Architected Framework
This option is recommended if you can use public IP address for VPN connections.
-
Amazon Web Services — Configure fine-grained access to your resources shared using AWS Resource Access Manager | AWS Security Blog
This new version will be automatically set as the default version of your customer managed permission. As a result, new resource shares that use the
-
Amazon Web Services — Enforcing enterprise-wide preventive controls with AWS Organizations | AWS Cloud Operations Blog
you can ensure the configuration is always maintained across member accounts, even when the service introduces new features or APIs
-
Amazon Web Services — Networking integration - AWS Prescriptive Guidance
if you use Transit Gateway, you gain connectivity to thousands of VPCs over a pair of VPN tunnels. Additionally, Transit Gateway supports equal-cost multipath (ECMP)
-
Amazon Web Services — Service control policies (SCPs) - AWS Organizations
An SCP defines a permission guardrail, or sets limits, on the actions that the IAM users and IAM roles in your organization can perform.
-
Amazon Web Services — What Is AWS Control Tower? - AWS Control Tower
To help keep your organizations and accounts from drift , which is divergence from best practices, AWS Control Tower applies controls (sometimes called guardrails ).