Skip to content
CBT Nuggets
DemoBook a Demo

Getting Started Right

The skill focuses on setting up and managing AWS Organizations, emphasizing the importance of creating a structured organizational unit (OU) layout for effective governance and account management. It covers the implementation of CloudTrail for logging API activity across accounts and the use of IAM Identity Center for secure user access management. The course is designed for those preparing for the AWS Solutions Architect Professional certification, highlighting the need for a broad understanding of AWS services and best practices in account management and security.

Full skill from AWS Certified Solutions Architect - Professional (SAP-C02). Preview the IT training 23,000+ organizations trust.

1h 5m

Skill 1 of 25 in AWS Certified Solutions Architect - Professional (SAP-C02)

Skill Introduction

Who This Course is For

First off, I just want to be sure that we're all on the same page as to who this course is designed for...

Passing the Solutions Architect Professional exam in no way means that you can actually architect things professionally on AWS. Likewise, there are plenty of brilliant cloud architects who have never bothered with certifications. It's easy to get lured into the credential trap and try to collect them like Pokémon cards. Instead, I really encourage you to use them as frameworks to help guide your learning journey.

Knowledge Check

True or False: The AWS Solutions Architect Professional exam is considered the most challenging AWS exam due to its broad scope.

README.md

Yes, I know, I know...you usually don't bother with reading the instructions because you're that kinda person. In this case, don't skip it.

If you don't have a portfolio yet, then I strongly suggest you create one. It can be a GitHub repo, a blog, a website...it can even be an old-school binder. First, it is invaluable when trying to demonstrate your abilities in the job search process. Hiring managers for senior cloud roles have seen those certification entries on resumes over and over again...even when some of the candidates may have, um, "stretched the truth" a bit. Having a portfolio of your own original work is a great way to differentiate yourself.

Note that I say original work. We live in an era of vibe coding and copy/paste/commit, so it's not difficult to sling out something that looks like skillful stuff. As a hiring manager, I would rather see how you struggled with a solution...the early, ugly versions and see your progression and learning journey as you refined it and made it better. You've heard it before: it's the journey, not the destination.

Knowledge Check

According to the content, which of the following levels of learning in Bloom's Taxonomy will be the focus of this course? (Choose FOUR)

Enabling AWS Organizations

AWS Organizations is probably the most useful tool in our toolbox when we're dealing with large AWS implementations.

It is not uncommon at all for some organizations to have hundreds or thousands of AWS accounts. I can't imagine trying to manage 5 accounts, let alone 100 accounts, without something like AWS Organizations. Sure, there are third-party tools, but AWS Organizations is very well integrated into many other AWS services aimed at large enterprises. It really is something that I consider required if you are dealing with more than one account. For my personal use, I use AWS Organizations with Control Tower (which we'll cover later) to spin up and tear down temporary accounts all the time.

There is one big caveat though with AWS Organizations. You might think.... "Hey, I can just create new accounts to have an unlimited supply of free tier usage." Think again. With AWS Organizations, the free tier eligibility for all member accounts begins on the day that the management account was created. Plus, all free tier usage is aggregated across all member accounts as well.

Knowledge Check

The account you are logged in as when you enable AWS Organizations will become the _______ account?

First OUs and Accounts

We can visualize our organizational layout, and now let's build it out in AWS-land.

Just a tip for creating lots of accounts: if your email system supports it, the '+' in the email address is a handy way to ensure you have unique and descriptive emails across accounts. In a production scenario, you probably want to configure your email addresses to go to a group list or something where you can have multiple people receiving those messages. Occasionally this account email will receive important service announcements for that account.

For member accounts created through Organizations, root credentials don't even exist initially. There's no password set. Ideally, you can just delete that root user, which you can via IAM as part of what AWS calls "centralized root access management." You can see the little pop-up card above in the first frame of this video advertising that as something that you might want to do.

I would recommend really thinking through how you design the OU structure for your organization. I would strongly recommend against trying to design it as a mirror of your org chart. Rather, you might design it by project, geography, division, cost center, profit center, etc. Most organizations find that it works better if you consider how value is created and not who reports to whom. Below is a link to what AWS considers the best practices when designing your OUs.

Knowledge Check

AWS recommends two foundational OUs be created within your Organization. What are they? (Choose TWO)

CloudTrail and Budget Alerts

CloudTrail and budget alerts are two must-enable items for our new organization. They are push-button easy and can really save your bacon.

The dedicated logging account pattern mentioned is something that you might consider if your organization is subject to heavy oversight or regulation. The idea here is that everything gets logged and is sent to a very locked-down isolated account...basically to serve as an escrow account until they are not needed anymore. By stashing them in the Management account, it is possible that some admin could either accidentally or purposefully adulterate the logs. This can have a range of implications from "Aw, darn it" to "This court sentences you to 20 years in prison and fines you 5 billion dollars".

With a separate account, you can delegate admin authority to someone outside the admin circles--such as an auditor or unaffiliated third party. That just improves the overall integrity of logging.

Knowledge Check

CloudTrail and CloudWatch are redundant and generally perform the same functions.

IAM Identity Center Setup

IAM users are so 2021. Get with the times!

If you use the AWS CLI, I would recommend that you switch over from access keys to SSO if you haven't done that yet. It's simple to set up and much less dangerous from a lost key standpoint. There have been several known malware attacks in the past that were specifically targeting the ~/.aws/credentials files in people's home directories. These weren't just someone clicking on a shady email...these were supply chain attacks where someone hid the malicious code deep in some common library.

You install some Python utility...it pulls down the library versions it needs, including the malware code...and your access keys and secrets are now in someone else's nefarious hands. SSO gets around this with temp credentials and dynamic environment variables. Not bulletproof but much less risky. With IAM Identity Center, it's dead easy to set up...aws sso login.

Knowledge Check

Which of the following statements about AWS IAM Identity Center and SSO are correct? (Choose TWO)

Goodbye Root

Here's the point in time when you hug your root account, wish it the best, and watch it sail away into the sunset--only to return for special occasions.

The list of things that actually require root credentials is shorter than most people think, and AWS has been actively shrinking it. Here's what you genuinely cannot do with an IAM user or Identity Center admin, no matter how many policies you attach:

  • Close a stand-alone AWS account (not in AWS Organizations)
  • Change the account name, root email address, or root password.
  • Enable or manage the root user's MFA device.
  • Restore IAM permissions when the only IAM admin accidentally locks themselves out.
  • View certain tax invoices and change payment methods in some scenarios.
  • Sign up for GovCloud.
  • Create a CloudFront key pair (the old style, not the newer trusted key groups).
  • Enable or disable STS endpoints in regions that have them disabled by default (though this one is increasingly handled through Organizations now).

That's basically it. Everything else—including creating IAM admins, managing Organizations, setting up billing alerts, and configuring SCPs—can be done by a properly permissioned IAM principal. If you remember nothing else: account closure = root, everything else probably isn't.

Knowledge Check

Where can you find the root password for child accounts created within AWS Organizations?

Validation

For the Validation section in each skill, I will craft some questions similar to how the exam might word questions. This serves two purposes: (1) reinforce the topics learned in this skill and (2) get you used to some of the tricks and traps that AWS question writers try to set for you. Yes, AWS does have a bag of tricks designed to weed out those who really know the stuff from those who just try to memorize answers. Once you get familiar with those tricks, you'll know how to deal with them.

Knowledge Check

A company has enabled AWS Organizations and created a Workloads OU with two member accounts. The security team wants to ensure that all API activity across every account—including any accounts created in the future—is captured without requiring any setup in the member accounts themselves. Which CloudTrail configuration achieves this?

Knowledge Check

An enterprise is migrating from shared IAM users to IAM Identity Center. Which response BEST describes the operational advantage of IAM Identity Center over manually configured cross-account role assumption for human users?

Knowledge Check

An enterprise has just enabled AWS Organizations and created a single "Workloads" OU with one member account. The organization currently has only two accounts total. Which statement accurately describes the purpose of creating an OU structure at this early stage?

Question Walkthroughs

View Transcript

Skill Introduction

0:00In 1972, Nolan Bushnell and his lead engineer, Al Alcorn, took a black and white TV, rigged it with

0:07some custom circuitry, and bolted it into a wooden cabinet. They left their prototype at a bar called

0:12Andy Capp's Tavern in Sunnyvale, California. The prototype was a game called Pong. A few days later,

0:19things stopped working, so Al made a service call. Well, the game itself was working just fine,

0:25but the plastic milk carton they had rigged up as a coin box was completely overflowing with coins.

0:32The success of Pong helped launch an entire industry, one which would eventually pull in

0:37more revenue than Hollywood and the music industry combined. And I can tell you,

0:42much of my adolescent lawn mowing money ended up at the arcade machines at Pasquale's,

0:47my local hometown pizza parlor. Most of those early arcade machines, Pac-Man, Galaga, Donkey Kong,

0:55all had one thing in common. Dual inline package switches, better known as dip switches.

1:01And that is how the operators could control the elements of the game. Difficulty, number of lives,

1:08coins per credit, crack open the cabinet, flip the switches you need, and close it back up.

1:13Sounds simple, but if you choose the wrong combination, your little money maker allows

1:19unlimited lives and free play, or worse, it doesn't even work. And that's a decent metaphor

1:25for what we're about to get into here. Amazon Web Services gives us a staggering number of switches,

1:33account structures, identity models, network topologies, encryption strategies, governance

1:39policies. None of them are especially hard to flip individually, but knowing which combination to use

1:46for the best outcome, while balancing a variety of aspects, resiliency, security, cost, efficiency,

1:53sustainability, that's where pro-level solutions architects earn their keep. I'm Scott,

2:00and this is the AWS Solutions Architect Professional Course. Let's get into it.

Who This Course is For

0:00All right, here we go. This is the AWS Certification Landscape, but chances are you probably already

0:06knew that because hopefully you have been researching this certification right here.

0:10That's why you have arrived at this course. But I did want to point out a few things here.

0:15Well, first of all, I wanted to point out that the machine learning specialty,

0:19its days are numbered or it has been completely removed. It has been replaced by the Gen AI

0:25developer there. And these right here comprise the pro level certifications for AWS and an AWS

0:33certifications pro level is the highest level of certification. That means they're the most

0:38challenging exams to take. And having taken all of these exams right here, I would say the

0:44solutions architect is probably for me anyway, it was the most challenging because it covers

0:51so much territory. And I say all this to say that if you're coming into this course without

0:58some of this experience down here, that you would develop going through one of these

1:02associate certifications, then I would highly recommend just put this course to the side,

1:08put it on the shelf, go pursue one of these down here, and then come back and try for your

1:15solutions architect professional. The reason is because there is knowledge that you are going to

1:20develop in these associate level certifications that are going to help you greatly in a professional

1:27level exam. And I am going to assume that you already have a lot of that knowledge that you

1:33should have developed either pursuing these certifications, or maybe just through hands-on

1:39work that you've done through on the job training or something like that. Now, how do you know if

1:44you're ready for this course? Well, if you read this sentence or this phrase here, your application

1:50needs to fail over across regions with submitted RPO, serve traffic from the nearest edge, and keep

1:57a consistent session state in DynamoDB Global Tables. If you do not understand anything in that

2:04particular sentence, then maybe you're not ready for this course. But if you kind of understand most

2:11of those things, and you can tell me what RPO is, you can tell me what DynamoDB, more specifically,

2:17what's a global table versus a kind of normal table, then I think you're ready for this course.

2:23Now, if you have looked at the exam blueprint, you have seen these, no doubt. We have domains. The

2:31exam blueprint is broken up into domains, organizational complexity, design for new

2:36solutions, continuous improvement, migration, and modernization. And roughly they're 25% or a quarter

2:44of the exam material each. This is all well and good. This is very cute. But never in the history

2:51of job interviews has anybody ever asked, hey, tell me about domain one. Tell me about domain three.

3:00No, people don't think like that. The real world doesn't work in domains like this. And so this

3:06course is not going to be organized around these domains. These domains are for exam developers

3:12and exam question writers. They are not for practitioners. You want to be a practitioner.

3:18You do not want to be just an exam passer. So we are going to cover all this stuff in due time,

3:26but we're going to cover it through some scenarios. We're not going to march through domain one, then

3:31domain two, and domain three, because what I've found is that's not a really logical way to cover

3:36stuff. And it doesn't really mirror how people design things in the real world. What is in scope?

3:42Well, it's probably easier to say what is out of scope for this exam. And this is one of the reasons

3:49why this is the most difficult AWS exam out there, in my opinion. Out of scope, game lift. That's it.

3:57Everything else, everything else is in scope. That means it is fair game to show up on questions

4:04in that exam. So we have to have a very broad understanding of AWS and more specifically,

4:13not just what those services are, but specifically where to use them and how to optimize them. And

4:20sadly, game lift is not in scope. Maybe they'll come out with a game lift certification or

4:26something like that. I don't know. What is this course not? Again, kind of the same way that I

4:32would say it's easier to say out of scope. It's probably easier to say what this course is not.

4:37This is not a course where I'm going to step you through VPC basics. I'm not going to step you

4:42through here's a VPC, here's subnets, that sort of thing. You should already come to the table

4:45knowing that stuff. You should already come to the table knowing S3 buckets and different

4:50storage classes, for example. You should already know how to launch an EC2 instance. And if you

4:57don't, that's okay. I'm just saying that the prerequisite for you to jump right in into this

5:03course is having a good set of AWS knowledge. If you're coming to the table with nothing from AWS,

5:11this is not the course for you. That doesn't mean that this is not the course at some point in the

5:16future for you. That just means that you're going to have to go elsewhere to develop that

5:20foundational knowledge and then come back here when you have that mastery. So I mentioned that

5:26we are going to do this learning here. There we go. Let me get rid of that. We are going to do

5:32this learning process here. We're going to learn all this stuff through some scenarios and to help

5:38facilitate that, I have created a fictitious company. That company is called Dip Switch

5:45Industries. And if you don't know, a dip switch looks like this. And these were used all over

5:52in electronics back in the 80s and 90s. They were on motherboards. They were on arcade machines.

5:58I think in some cases they're still on garage door openers today. These are little connectors

6:03here, and it has this little switch that you can switch on and off. And it allows electrons to flow

6:09through there or not flow through there, depending on what your switch setting is. So that is a dip

6:14switch. But our company here is Dip Switch Industries. They are a vintage arcade game

6:20company. They have a trusty old PHP site that's been running on their Colo server since 2009.

6:28They have three divisions, but right now they only have one AWS account. And guess what? Their

6:34root credentials are on a post-it note that's stuck to somebody's monitor. Does this sound

6:40like a company you know? Well, of course it does. I'm sure there's hundreds and thousands of companies

6:45out there just like that. All right. So here's the three divisions. They have a marketplace division.

6:49That's where they auction off parts. They have roughly 40,000 collectors that use that marketplace.

6:57We have a restoration division, and they have three cities with places where you can bring

7:02in your vintage arcade games, and they will restore them. And then they also have an events

7:08division. And this is for hosting corporate parties and tournaments and stuff like that.

7:14And each one of these divisions has specific needs. And through the course of this course,

7:21we will get to know each of these divisions, what their challenges are, and what we need to build

7:26them on AWS to optimize their type of business. Here's the situation. And no, I'm not talking about

7:35a cringeworthy reality TV show personality. I am talking about here is the situation we find

7:42ourselves in right now. We have that one AWS account and that root password is on a post-it.

7:48Here is the prerequisite. I want you to go out there and create an AWS account. I am not going

7:55to show you how to create an AWS account. You should already know how to do that. But

8:00for your starting point, I want you to create one AWS account and you're going to log in as

8:06root, but we're going to change that quickly through this first skill, but you should have

8:11root access. I understand that maybe you're part of an organization and maybe your organization

8:16has created a sandbox account for you, maybe under AWS organizations. That's okay too, but you're

8:23going to be somewhat limited with what you can do because my bet is when they created that AWS

8:29organization setup, they probably implemented some SCPs and we will cover SCPs in due time,

8:35but they probably implemented some security measures that may prevent you from doing some

8:40of the stuff we're going to do. So I would really recommend just create an account on your own.

8:45And when the course is over, you can delete it. And most of the stuff we're going to be doing is

8:50in the free tier. There's a few things that may cost you a few cents a month or something like

8:54that. But anyway, that is one of the prerequisites. They have some public S3 buckets, they have an IAM

9:01user admin, and they don't rotate the keys. They have no cloud trail, they have no budget,

9:06they have no guardrails. We are going to fix all this.

README.md

0:00All right, so I am going to call this video

0:02the readme.md file for this course.

0:07And it's basically how to use this course

0:09and some of the methods that we are going to use

0:12going through this course.

0:13And one of the things I like to use here up front

0:15in a lot of my courses is something called Bloom's Taxonomy.

0:19And what it is, is this just a way

0:21to describe how people learn.

0:24And the way to read it here is down here at the bottom,

0:27remember, that's kind of the most foundational way

0:31of learning, that's memorization, that sort of thing.

0:34Then you have to understand it

0:35and then you have to apply it.

0:38If you've ever heard the phrase,

0:40see one, do one, teach one,

0:42that's kind of this progression right here to apply.

0:45And then beyond that, you can analyze a problem,

0:49you can evaluate a problem.

0:50And then eventually you're able to create your own material.

0:54This is stuff made of whole cloth, for example.

0:58A lot of folks, when they come into AWS

0:59and they start talking about certifications

1:01and they go through some of the base level certifications

1:04like the practitioner or maybe even the associates,

1:07they focus a lot on this stage right here.

1:10Maybe this stage also,

1:12but I think a lot of people spend way too much time

1:15trying to memorize stuff in AWS.

1:19Not once have I ever been asked,

1:21okay, what is the EC2 machine type

1:24that has eight gigabytes of RAM

1:27and four vCPUs or something like that?

1:30That is not something that a employer should find valuable.

1:34If you get asked that question in an interview,

1:36I would probably decline that job

1:38because I'm not sure I would wanna work there.

1:40No, what employers are really after

1:42is can you apply this stuff at a minimum?

1:46More likely, if you're going for

1:48maybe a senior architecture role,

1:50can you analyze, evaluate, and create new architectures

1:55based on your abilities and knowledge?

1:57So going through this course,

1:58we are not gonna spend any time at all

2:00on this stuff down here.

2:02I mean, maybe I'll explain how something works

2:04if it's something that's maybe not very obvious,

2:07but we are going to focus mostly on the apply,

2:10analyze, and evaluate, everything above understand.

2:14My learning philosophy is more of a crawl, walk, run.

2:19I wanna start simple and then we're gonna build upon that.

2:22So one of the things that you will notice here

2:25through our different projects that we're going to undertake

2:28is we are going to start,

2:29and then that project is gonna carry over

2:32across multiple skills.

2:34So it's really, really hard

2:35if you just wanna dive into one skill

2:37right in the middle of the course,

2:39you're not gonna have some of the stuff

2:41that we've built previously.

2:42And I think that's very important

2:44because again, this mirrors how the real world works.

2:47You don't just get dropped in

2:48to click a few buttons here and there.

2:50You have to build something.

2:51You have to architect something and design it,

2:53and then actually put it into practice and then test it.

2:56So that's what we are going to do.

2:57We are gonna start simple

2:58and we're gonna build upon those things.

3:01You have to do this work.

3:02You're not gonna learn anything

3:04by just kicking back and watching me click around.

3:07You have to do this.

3:08And if you have to pause the video and figure it out,

3:11that's perfectly fine.

3:12I can tell you that you are going to become frustrated

3:15at one point or another in this course.

3:18That's part of the learning process.

3:20You may become frustrated at me.

3:21You may become frustrated at AWS,

3:23but that's part of the learning process

3:25because we all have to go through that,

3:27those kind of storm clouds

3:29to get to the sunny skies on the other side.

3:31So I do want you to follow along with me,

3:34but I also want you to feel free to make this your own.

3:38That's where the real learning happens.

3:40Anybody can just follow a recipe

3:42and you can just follow where I'm clicking

3:44and where I'm not clicking and stuff like that,

3:46but that's not really learning.

3:48Where real learning happens,

3:51especially if we go back here to Bloom's Taxonomy,

3:53is you take that stuff and you can apply it

3:55and analyze it on your own.

3:58You can apply it to your own problems.

4:01So a lot of students that I've talked to

4:03will take this stuff and they'll use it as a guideline

4:06and maybe they'll create a version

4:09that is applicable to something in their organization

4:12or some challenge that they have faced.

4:14And all this stuff is really good stuff for a portfolio.

4:19So I would really encourage you

4:20to build some sort of online portfolio

4:22and all the stuff we're doing, all the diagrams,

4:25any of the scripts or anything like that,

4:27record that, write that down,

4:28do a little blog post or something like that

4:30and record that in your portfolio

4:32and attach that portfolio via hyperlink

4:36or something like that to your resume

4:38because that is going to be very, very valuable

4:41because yes, they can see on your portfolio

4:43or on your resume that maybe you passed this certification,

4:47but if you can actually show them what you can do,

4:49that's a much better demonstration of your capabilities.

4:53And that's why I want to organize this course

4:56in portfolio projects because it's real stuff

5:00that you can show an employer.

5:02Really, think of the certification

5:04as just a pleasant side effect.

5:06This is not the end game.

5:07The certification is not the end game.

5:10Your knowledge is the end game

5:12and that's what AWS wants you to have.

5:15They don't just want you to have a piece of paper

5:17that says, yeah, I passed.

5:18They want you to have that knowledge.

5:20And each project that we are going to undertake

5:23spans multiple skills.

5:25And what I mean by that is we are not going to do a project

5:28that covers domain one

5:30and then another one that covers domain two.

5:31No, these are going to be cross-functional projects.

5:35Now, they're each gonna have a theme,

5:37but we're going to be working across all those domains

5:40for all these projects.

5:42So here are the projects.

5:44So the first project we're going to call FreePlay

5:47and that's going to be primarily

5:49a governance and identity-based project.

5:52We're gonna have multiplayer mode,

5:53which is gonna be a multi-region application.

5:56We're gonna have level up,

5:57which is a migration and modernization.

5:59And finally, we're gonna have cost security operations

6:03and we're gonna cover that

6:04under something we're calling the final boss.

6:07Now, I wanted to mention something else

6:09that trips people up all the time,

6:11especially if you've been in the industry a while

6:13and you've been working with AWS for a while.

6:15And it's something that I call the practitioner's curse.

6:18And this is the situation where you get into

6:21where you've been working on AWS for a long time

6:23in a practical setting.

6:25Then you sit down to take the exam and you're like,

6:28well, the exam is saying this answer,

6:30but in reality, I know it's this other answer.

6:33You have to leave that experience at the door

6:36when you go into the exam.

6:37I know it sucks, but it's just reality

6:40because the exam lives in this nice little walled garden

6:44inside AWS.

6:46It doesn't have to worry about any other clouds.

6:48It doesn't have to worry about any other legacy systems.

6:51So it is important to keep that in mind.

6:54Oftentimes, real world experience diverges

6:58from the answer that the AWS test writers

7:01want you to select.

7:03So you have to be very, very careful of that.

7:05And I'll try to call this out when this happens.

7:09So I just wanted to mention it

7:10because it's something that trips a lot of people up.

7:12They'll go into that exam saying,

7:13yeah, I have 10 years of AWS experience

7:16and I've used all the services and they go in there

7:18and they don't do well on the exam

7:20because they are bringing that experience in there

7:23when the exam itself is written in a very different way.

Enabling AWS Organizations

0:00All right, enough jibber jabber. Let's go start building.

0:02What we're building today is we are going to build an AWS organization.

0:06You're going to start with the account that I told you to create.

0:10You already have an account,

0:11or you will soon have an account that you have created on your own.

0:14We're going to log in as root and we're going to set up AWS organizations.

0:18Now a lot of courses save this to the very end. Like it's really,

0:21really difficult. No, no,

0:23it's not difficult at all to set up AWS organizations.

0:26Plus it enables a lot of other stuff that we can do.

0:29And when you're dealing with a pro level implementation,

0:32then you're most likely going to have AWS organizations in there because you're

0:36going to have multiple accounts.

0:38We do not want to use one account for everything.

0:41That's how an amateur does it. A pro does it with multiple accounts.

0:45So AWS organizations is going to help us set that up.

0:48We are also going to implement our first OU and some workload accounts.

0:53What is an OU? Organizational unit. I'll talk about that in a second.

0:56We're going to implement organization-wide cloud trail.

1:00We are going to set up a budget alert.

1:02We are also going to set up IAM identity center.

1:06The old school way is you create IAM accounts and you just log in there. No,

1:09no, no. That's not the way we do it today.

1:12Today we use IAM identity center. Now, yes, of course,

1:16you can still create IAM accounts. I don't like to do it.

1:20There are certain services that force us to do that, like code commit,

1:23for example,

1:24but the modern way of logging into our accounts is using some federation or

1:29IAM identity center. And we are going to say goodbye to our root user.

1:34Now we can't delete it,

1:35but we are not going to use it ever again in this course,

1:40because as a best practice,

1:42you should not use your root credentials to do much of anything.

1:46There are a few things,

1:47very few things that you must do with your root account.

1:51But what I want you to do is take that little multi-factor authentication key

1:55that you've set up for your root IAM, put it away, put it in a drawer,

1:59put it in a safe somewhere. And we are not going to use that.

2:03Instead,

2:03we are going to use our IAM identity center login to do all the stuff

2:08we need. So here is our target OU structure.

2:13We need a management account,

2:15and that is the account that I am telling you to create.

2:18That is going to assume the role of a management account.

2:21We are then going to create some different OUs down here.

2:25Now this follows AWS best practices.

2:28They say we should really create a security OU and an infrastructure OU,

2:32just to keep that stuff separate.

2:34Then we have our workloads and then we have our sandbox.

2:37Now you're free to create your OUs however you like.

2:40I've seen some people create it based on the divisions in their organization or

2:44maybe geographies.

2:46That's a really good way of doing it because a lot of times maybe you have

2:49different policies or different security measures that you have to implement

2:53across different geographies. But for us,

2:56for our dip switch industries company,

2:59we are going to create an infrastructure OU and then we're going to have an

3:02infrastructure account, a security account. And then for our workloads,

3:05we're going to have the three divisions down here,

3:08marketplace restoration and events. And then in our sandbox here,

3:12we're just going to have a sandbox account that we can just do experimental

3:16stuff. That is what we are going to create in skill number one.

3:21All right, so let's create an AWS organization.

3:24So here I am logged into my management account.

3:28This is going to be our kind of top level account.

3:31This is the account that you created. So to create an organization,

3:35it's pretty easy.

3:36We just go over here to AWS organizations and we create an organization.

3:40Now notice that this is a global service.

3:43So it doesn't really matter which region you start in to do this,

3:48but here it gives us some recommendations here.

3:51This account will become the management account. So in other words,

3:54the account you are logged in as will be the management account.

3:57And you cannot change that management account.

4:00Once this organization is created,

4:03what you actually have to do if you want to change the management account is you

4:06have to create a new organization, create a new account, go in there,

4:10create a new organization, then move all your stuff over.

4:12Then you can go back and delete this AWS organization.

4:16So we're going to create an organization. That's it.

4:19That's all we have to do to create an AWS organization.

4:24Now, if you look down here,

4:25it started us off with the root of our structure here,

4:29our organizational units, our OUs,

4:32and it put our account right there in the root. In the next video,

4:36what we are going to do is we're going to build out these OUs.

4:40To resemble what we showed in the slide earlier in this video.

First OUs and Accounts

0:00All right, let's create some OU.

0:02So, if we go back to our structure here, we have our management account,

0:05and we wanted to create a security OU, an infrastructure OU,

0:09workloads, and sandbox.

0:11So, to do that, we just go back out here to our AWS account,

0:15and we can click down here.

0:16Oops, we got to check that little box right there,

0:19and click down here, create a new organizational unit.

0:22So, let's create security first, create that, and look at that.

0:27So, it just drops it as a, basically, kind of like a subdirectory underneath this.

0:32Now, this hierarchy is important, and it doesn't,

0:36it's not something that we can't change in the future,

0:38but how we are going to arrange this has some implications later

0:43in how we choose to manage our accounts.

0:46But for right now, let's just create all the accounts that we need to here.

0:49Let's create another OU right here, and we'll call that infrastructure.

0:56Create that, click that again, and create new,

1:00and we're going to call this workloads.

1:03And the reason I'm calling it workloads is because there's kind of a best practice,

1:07maybe an unwritten rule, I'm not really sure what it is,

1:10but basically, we do not use this management account for anything.

1:15It is off limits for us to use for any sort of production workloads.

1:20Well, I mean, we can use it, but it's not best practice too.

1:24Think about it kind of like the landlord of our organization.

1:28Now, the landlord really doesn't live in the apartments.

1:31They live someplace else, but they take care of the apartments.

1:34So that's what this management account does.

1:37So we have infrastructure that's going to contain all of our infrastructure,

1:41all our stuff that we need to operate our business.

1:44We also have security, which is going to be focused on where we keep security stuff.

1:50And then we have workloads.

1:51Now, this is where we are going to put our workloads for different divisions.

1:56So underneath this one, I want to create three additional OUs here.

2:01Let's call the first one, if we go back over here, marketplace.

2:07And I'm going to create another one here.

2:13And we'll call this restoration.

2:16And then finally, we'll create a third one here called events.

2:22All right.

2:22So what we have here is we have our workloads, then we have our OUs here.

2:28Now, mind you, there are no accounts in these.

2:30This is just a logical organization of, think about it kind of like folders.

2:35Okay, let's say that maybe I created one by accident or maybe in the wrong place.

2:40Well, I can click on that and I can come up here and I can click on the account.

2:44I can click on that and I can come up here and I can rename it or I can just delete it.

2:48Now, notice I can't move it because these things aren't really things.

2:53They're just kind of imaginary metadata.

2:56So what we can move is accounts.

2:59That's the important thing.

3:00We can put these accounts in these different OUs and depending on which OU it is in,

3:06maybe it inherits certain abilities or inabilities to do stuff.

3:11So let's create our last one right here.

3:14Let's go up here, create new, and we're going to create a sandbox.

3:19Now, you may think sandbox, oh, that's just for playing around.

3:23Well, yes, but it also has an important function here because there are certain things

3:29that we can implement that apply to the OU.

3:32And we would not necessarily want to implement those things without testing them first.

3:37So if I were to implement an SCP, for example, and again, we're going to get to what an SCP is later.

3:43But if I were to implement an SCP here and apply it and it has some bugs

3:48or maybe I configured something wrong, I want to find that out in a non-production OU.

3:53So we can use sandbox for that.

3:55I've also seen people create specific testing OUs, which is perfectly fine as well.

4:00And there are a variety of ways that you can arrange these.

4:03You can arrange these based on workloads like we did,

4:07where we're just calling out the different division workloads.

4:10You can also arrange these as dev, prod, QA, and we can even create sub-OUs here of whatever we want.

4:18So there are many, many different ways to arrange your organizational structure.

4:22This is just one.

4:24Just to satisfy my OCD here, I don't really like anything hanging out at the root.

4:29And right now our management account is hanging out at the root.

4:32So I'm going to create a new organizational unit called management.

4:37And I'm going to move my account right here into management.

4:42So I'm going to go down here, move.

4:44And then I'm going to say, hey, I want you to go into management there, move account.

4:48And it has just moved that account into management.

4:53Next, we need to create some accounts.

4:55Now, I am going to not create every single account and make you watch me do that.

4:59I'm just going to do one here.

5:01And then you can just replicate that.

5:03So we want to create an account for infrastructure.

5:05We want to create an account for sandbox, security, so forth and so on.

5:09And down here for events and marketplace and restoration,

5:12I'm going to create an account for each one of those.

5:15Now, you may be thinking that's a lot of accounts.

5:17Well, yeah, that is a lot of accounts.

5:19But that is a best practice when you're dealing with a complex implementation.

5:24You want multiple accounts.

5:25And there's a variety of reasons.

5:27And we'll get into that, why you would want multiple accounts.

5:30First and foremost, it limits your blast radius.

5:33So if you make a mistake in one account,

5:36it's not going to wipe your organization out.

5:38It's just going to be limited.

5:40The damage is going to be limited to that one account.

5:43So let's go up here.

5:44And we can click add an AWS account.

5:47And we can invite an existing account.

5:50Maybe you have existing accounts.

5:52You can invite them to join your AWS organization.

5:54Or we can create a new one.

5:56So let's create one down here that says events.

5:59And now we have to give it an email address.

6:02This email address has to be unique.

6:05It cannot be used on another account.

6:07So there's a little trick here.

6:09Depending on your mail system, there's a trick

6:12that you can use that I've used pretty successfully

6:14with most mail systems.

6:16And that is to add a little plus here.

6:18So my address is spletcher at cbtnuggets.com.

6:22So spletcher plus.

6:24And then I'm going to say CSA events.

6:28That's Certified Solutions Architect Professional Events

6:32at cbtnuggets.com.

6:34And I'm going to leave this organizational role

6:36the same there.

6:38And I'm going to click AWS account, create account.

6:42And that is going to create an account.

6:44Now it's going to take a few minutes for that account

6:46to be created.

6:48And I'm just going to pause the video

6:49and wait for that to show up.

6:51But what's going to happen here is it's going to show up

6:52right here under root.

6:54And we are going to then move that.

6:56While I'm waiting for that,

6:58I'm going to go ahead and create all my other accounts

7:01and you should do the same as well.

7:03I'm just going to put you on pause right now

7:05until that account shows up

7:07and I'll show you how to move it.

7:08Okay, so I have created all my accounts.

7:11Now notice up here, I had one account creation request fail.

7:15And that was because the email that I entered,

7:17I had apparently already used that someplace else.

7:20So that's just something that can happen

7:22if you don't use a unique email.

7:25So I use that little trick,

7:26that plus trick to create unique emails.

7:28Now you're looking at this organization,

7:30you're saying, hey, where are my accounts?

7:32Well, if you click on list over here,

7:34here are your accounts.

7:35One of the things that I want to call out right up front,

7:38look at all these numbers.

7:39Oh my goodness, he's showing his account numbers.

7:41I don't really worry about it.

7:43AWS themselves said that they do not consider

7:45account numbers to be sensitive

7:48or something that needs to be hidden.

7:51Unless of course you are a consultant

7:53and you are creating publicly facing documents

7:57and you are using your account at that company

8:00to demonstrate stuff or create blog articles

8:03or something like that.

8:04I wouldn't want my customers' account numbers

8:07floating around out there.

8:09But these are my own account numbers

8:11and I know how to secure my systems well enough

8:14that that doesn't frighten me.

8:17Just a note here that you will see

8:19my account numbers throughout.

8:20And I'm not gonna go to the trouble of blurring them out

8:22because you really can't do much with them.

8:26If you secure your accounts properly.

8:29Here are my accounts.

8:31Now I am going to move these things

8:33into their respective OU.

8:36So I'm gonna click on Sandbox there

8:39and I'm gonna move that into that OU right there.

8:42And then I am just going to repeat that process.

8:45And I'm not gonna show you each and every one.

8:47I'll show you one more here.

8:50Move and we're gonna hand this over to infrastructure.

8:54And then you can see down here if we expand that out,

8:57our infrastructure account is under our infrastructure OU.

9:01So what we want is all those accounts

9:04all in their respective OU.

CloudTrail and Budget Alerts

0:00All right, so now our accounts have been created. They are in their respective OUs.

0:05The next thing I want to do is enable CloudTrail, and CloudTrail is going to log all API

0:10calls in and out of our accounts. So to get there, I'm just going to navigate over to CloudTrail.

0:17I'm going to not click on that little button down here that says create a trail. Instead,

0:21I'm going to go over here to trails, and that is a weird looking layout there. But anyway,

0:26I'm going to click on create trail, and let's just call this management events,

0:32the default. And I also want to enable for all accounts in my organization. There is some debate

0:39as to whether you should use your management account for CloudTrail, or maybe create a

0:44separate logging account. I'm kind of more in favor of creating a separate logging account,

0:49because then we could direct all those logs to that account and not have any other access into

0:54that account. So we can assure that our logs are not going to be tampered with and kind of maintain

1:00the integrity of those. But in our case, I think that's a bit much. But just know that if you're

1:06doing this for a large organization, that's probably a better way to go is you just create

1:10another account for logging, and then you would set up CloudTrail in that account and configure

1:16all your other accounts to route to that logging account there. So this is going to do it for us

1:22by checking that little box there. And we're going to go down here, we can create our own

1:26S3 bucket, or use an existing one, I'm just going to use an existing one here, I'm going to uncheck

1:33this encryption here, the SSE KMS encryption, I don't really need that log file validation,

1:39I don't really need that either. But you can absolutely enable that if you want to. And I

1:44would really recommend enabling encryption here. Here's one call out is that you definitely want

1:49to use a bucket key. If you're using a customer managed KMS key, then every single log activity

1:56writing out to that bucket is going to use up one of those API calls. And that can get very,

2:01very pricey. So definitely look into a bucket key, if you're doing that. And let's see everything else

2:07looks good. Let's try that. And I just want to record management events, you can absolutely

2:13record these other events if you want to. But I would recommend that you spend some time thinking

2:19through your log management strategy, you probably don't want to keep all that stuff out there

2:24indefinitely, because it could really rack up a lot of gigabytes on S3 and end up costing us some

2:29big money. So let's just leave everything default here. There we go, create trail. Alright, so it's

2:37going to go out and do its thing. Now, it's also in the background, deploying that configuration to

2:43all those other organizations, those other OUs and those other accounts. And they are going to be

2:49piping their stuff to this log. So I doubt we'll have anything out there right now. Yeah, we don't

2:57have anything out there. It usually takes maybe five to 10 minutes to start seeing stuff out here.

3:02And of course, it's also dependent on how much API activity you have going on with your account.

3:08So next, what we want to do is we want to hop over to the cost management area down in billing

3:14and cost management, and we want to create a budget for ourselves. So let's get rid of that.

3:21And we're going to go down here onto budgets right there. And we're going to create a budget.

3:27And we can use a template here, we'll just use that. And you have different templates that you

3:32can pick from here, a zero spend budget, that is good if you want to be sure that you're staying

3:37within the free tier. But I will say that's really hard to do. There's a few things, even if

3:42you have some objects out on S3, you're probably going to end up spending at least a penny. So

3:47zero budget, I usually don't use, I will use a monthly cost budget. And we'll just leave it at

3:52100 bucks, 50 bucks, whatever you want. And what it's going to do is there's a few different

3:57conditions that it's going to notify you. Well, first, if you go beyond that budget, that monthly

4:03budget, it's going to email you and say, Hey, you've gone beyond $100 a month. Second, if it

4:08looks like you are trending to exceed that budget, it will email you as well. So let's just set up

4:14an email here and create the budget. There we go. It's as easy as that. We have enabled CloudTrail,

4:23we've enabled a budget. Next, we need to set up IAM Identity Center.

IAM Identity Center Setup

0:00Okay, so back in the olden days, we used to come out here to IAM and we'd create IAM users

0:05and we would dole them out and people would have access keys and passwords and stuff like that.

0:11But no, we don't want to do that anymore. Right here it says managing human user access accounts,

0:16there's a better way and it kind of guides us toward Identity Center right here. And that is

0:21a smart move because we don't want to manage IAM users anymore. There are cases where you just

0:27can't help it. You have to do that. But in most cases, if we're dealing with people logging into

0:32our account like us, then we don't have to do that. One of the things I'll point out here is

0:37we get this big easy button right over here, enable, but the region that you're in does make

0:43a difference. There are certain products in AWS that integrate with Identity Center that are not

0:49necessarily compatible if you have Identity Center set up in a different region. So if you are

0:55considering WorkMail, for example, I think WorkMail right now is only available in U.S. East 1 and

1:01U.S. West 2 and then it has some location over in Europe. So if you enable that and you want to

1:07enable federated logins into WorkMail and make it really easy on yourself there, if you have your IAM

1:14Identity Center set up in Ohio, then that's not going to work. I don't really care. I've found

1:20very few cases where that is a problem. And even if that is a problem, you can still set up

1:25logins just with a little additional configuration. So I tend to work in U.S. East 2 because that's

1:32a relatively new region and it doesn't have some of the cobwebs and baggage that U.S. East 1

1:40does have. Plus it's closer to me geographically. So we are just going to click on enable right

1:46there and it's going to say, hey, is this the right region? Really, you want your AWS region to be

1:52whichever region is closest to you. Click on enable. And in a few minutes, oh, a few seconds

1:59rather, we have enabled AWS IAM Identity Center. And this is our own little registry that we can

2:07create users in. So if we scroll down here, we have our access portal. This is a URL that we can

2:14click on and it's going to bring us to our own customized login page. Now, if we were in a huge

2:20organization, maybe an organization that already had an identity provider like Okta, Google, or

2:26Encarta or something like that, then we can absolutely integrate that in as well. We just

2:32happen to be using Identity Center here because it's built into AWS. So first things first, let's

2:36create some users, actually a user. So I'm going to create my user right here. I'm going to give

2:42it my email address here and fill out some information here. And it gives me a display name.

2:50Now, it also has some other details here, and this would be important if you are setting up this as a

2:57directory. And there are some other things in here that we're going to deal with later down the road.

3:02If we wanted to use attribute-based authorization, for example, we could set some attributes here.

3:08We can set our department, our region, or whatever. So I think this is all I need. I'm going to click

3:13on next, and it's going to say, hey, what group do I want to assign this to? Well, I don't have any

3:19groups, so let me create a group. And I'm just going to call this admins, create that group.

3:27And if I go back over here, refresh, I'm going to add that to the admins group

3:34and add user. It is going to email that address that we entered there, and it's going to give us

3:40a hyperlink to click on. We're going to be prompted for entering a password and also MFA. So I'm going

3:47to move over to my email box, and I'm going to set my password and MFA for this particular user right

3:54now. And I'm just going to pause while I do that. All right, so I have set up my user right here,

4:00and it also asked me to set up an MFA method. Now, best practice is absolutely set up MFA. That

4:07should be non-negotiable, but I would probably set up multiple types of MFA. I happen to use

4:13YubiKeys, so I have several YubiKeys that I can set up there as my MFA device. I also use

4:20Bitwarden for my password vault, and I can set that up as a passkey as well. And of course,

4:26you have the one-time codes, that sort of thing. Now, one of the things I think you'll realize here,

4:31if we go under security, and let's say register device. One of the things you'll notice here is

4:39we do not have an option for SMS, and that is because SMS is not really secure. People can

4:46steal your phone number, they can hijack your SMS, that sort of thing, and AWS really doesn't support

4:52it. So we have authenticator app, security key, and a built-in authenticator. Maybe that's

4:58something like a fingerprint reader on your computer. But one of the things you'll notice

5:02here, so if we go back to our access portal, there we go, we do not have access to any accounts, and

5:08we do not have access to any applications. That's because we haven't set ourselves up to have that.

5:14So let's go back over here, and we're going to go down to permission sets, and this is how we can

5:20define what sort of permissions we're going to be allowed to have in our various accounts. Now,

5:26you can create very detailed permission sets. There are some predefined ones that I tend to use.

5:31So here are the predefined ones down here, and these kind of go along with different roles,

5:35but we want administrator access right here. So we're going to click on next, and for session

5:42duration, what I want to do is change this to eight hours. Normally, you want this session duration

5:49as short as possible. What this means is it is going to give you authorization, that authorization,

5:55this admin access for a period of session duration. So for a period of one hour, and then after one

6:02hour, you're going to have to re-authenticate yourself. You're going to have to log in again,

6:07but oftentimes I'm out here in the console for longer than that. So I just want to make this

6:13eight hours. I can also do a custom duration as well. The smaller, the more secure, the longer,

6:20the more dangerous it gets, but I definitely wouldn't have it past maybe 12 hours or something

6:25like that, and there are many other layers of security we can add on, such as geography. We can

6:32see if somebody is logging in from maybe a strange device, and we can block that log in there, but

6:37that's something for another day. We're not going to cover that right now. So click on next, and

6:43create. So we've just created this permission set right here, and then we can assign this permission

6:49set to our groups and or our users, and then also assign that to our accounts right here. So let's

6:56hop over to AWS accounts, and look at that. There's our AWS organization right there, and I want to

7:02assign users or groups. Oops, do that. Let's do all the accounts, assign users or groups, and we can

7:11assign users here or groups. I'm just going to use groups right there. Click on next, then it's going

7:18to ask us what permission set do we want to use. So this is going to allow that user, my user,

7:24administrator access to all seven accounts there, and that's exactly what I want. So click on next,

7:32and little confirmation screen, submit, and it's going to take a little while to deploy all this

7:37security. So we just, well, I guess it's done. That was quick. That's the fastest I've ever seen

7:42it deploy to seven accounts. So anyway, we have been provisioned for all those accounts. Now,

7:48notice you can do this by account. We can't really do it by OU, so that's a little bit of a quirk

7:53there. So now let's go back over here to our accounts, and we can either log out or log back

7:59in, or we can refresh, and look at that. We have all of our accounts, and we can click this little

8:04thing right here, and if we had more than one permission set assigned to us, we could see those

8:10down here. So for example, if we had billing assigned to us, we would see administrator access,

8:16then underneath that, billing, and whenever we click on that, that is going to log us in

8:21to that particular account with that access. Now also over here, we can click on access keys,

8:26and we can see how we can add access keys to maybe our CLI work. If you're doing CLI work,

8:33you would probably not use access keys here. There are some cases where you could, but I would

8:39probably set up the AWS SSO login, and that is going to take you to this little landing page.

8:45Let me go back over here. Dashboard is going to take you to this landing page right over here,

8:52and it is going to prompt you for logging in. So as a matter of fact, we can change this here. Let's

8:57say Fletcher CSAP. There we go. CSAP, and you just have to be sure that this is indeed unique,

9:07because you can't have what somebody else already has. So there we go. So we have an IPv4 only,

9:13and then we have a dual stack here, and if we click on that, it's going to take us over to our

9:19AWS portal here. Now I've already logged in, and because it's within eight hours, it's just going

9:24to go ahead and log me back in there. This is what I want you to set up, and this is the method

9:29we are going to use to get into our accounts, and we are going to say bye-bye to our root account

9:36in the next video.

Goodbye Root

0:00One last thing that we need to do before we say goodbye to our root account access,

0:06we're going to go over here and go into account. I'm going to have to blur out some of this screen

0:11because it shows some private contact information here. But from this screen, what you're going to

0:17do is scroll down, keep scrolling, keep scrolling, keep scrolling. There we go.

0:22We want to enable the IAM user enroll access for billing information. And this is going to

0:27let us see the spending on our account from our IAM identity center users. So let's click on edit,

0:36click on that, click on update. And then we have completed that access. So from here on out,

0:44we should be able to see the information, the cost information for what charges are being

0:50charged to this account. Now, just to double check here, let's go over here to security credentials

0:57and I want to be sure that we have MFA enabled. And there we do. You definitely want to have some

1:04MFA method enabled. Ideally, you're going to have one that is accessible by a few different people,

1:11because if one person's out on vacation or something like that, you don't want to have

1:14to wait until that person comes back from vacation to get the credentials to log in.

1:19So what I've seen here is you can either use some sort of password manager where you can share the

1:25credentials, or you can use a hardware token that gets kept in a central location in a vault or

1:31something like that. But there are several different ways to do that. And I would highly

1:34recommend, especially in production situations or production accounts, that you have several

1:39MFA alternatives in there.

Validation

0:00All right, let's go through these questions. Now at the end of every skill, I'm going to have a

0:04little question walk-through here where I walk through the validation questions and just give

0:08you my tips and tricks on how to maybe better approach these questions. And these are exam

0:15style questions. They're absolutely not the real exam questions. That would be completely unethical

0:20of me to share and I can get in big trouble. So never will you see any of the questions that are

0:27on the exam. These are just from my experience over the years of taking many AWS exams. Here's

0:32some of the tricks that they try to use to throw you off. And first off, here's one of the tricks,

0:37especially on the pro level exams, they have very long questions. And one of the important

0:44components of the pro level exams is time management. So they throw in these long questions

0:51just to kind of slow you down. I know it sounds a little devious and stuff, and it probably is, but

0:56the idea here is they want you to be able to know this stuff well enough that you can read through

1:00this and arrive at the right answer relatively quickly versus spending a whole lot of time. So

1:07that's why they include these things. And the second reason is they have to kind of build some

1:11rather complex scenarios to be able to test that you have that knowledge. So here we go. The first

1:17question. One of the things that I like to do is not read all this other stuff first. I'll go to

1:22the very end and try to figure out what exactly are they asking me? Which CloudTrail configuration

1:27achieves this? Okay. So I now know that we're talking about CloudTrail. Now I can go back up

1:32here and read through these things that are CloudTrail appropriate, or maybe relevant to

1:38CloudTrail. So a company, AWS organizations, they have some OUs with two member accounts.

1:45The security team wants to ensure that all API activity, well, that's exactly what CloudTrail does

1:50across every account, including any accounts created in the future, is captured without

1:55requiring any setup in the member accounts themselves. Now we are posed with four possible

2:02answers here. So let's start at the top here. Enable CloudTrail in an independent account

2:07outside the organization, which aggregates events. So I don't really think this is a good idea

2:13because we could absolutely do this, but why would we create an account outside of our organizations

2:20if our main priority was to manage the accounts inside that? So I'm going to just kind of X through

2:26that. I don't think that's a possible answer. Now, just like that, we're down to three. Create a trail

2:31in each member account configured to deliver logs to the shared S3 bucket. Well, that is a possibility.

2:37That is absolutely a possibility that we could do that, but what they're asking for up here is

2:43captured without requiring any setup in member account services themselves, especially in the

2:48future accounts. So if we were to do this, then we'd have to remember to go back out there

2:53every time we created a new account and set up that CloudTrail sending to that S3 bucket.

3:00So that is not going to fulfill our requirements. Create a trail in the management account that

3:04captures only management account events. Well, that doesn't make sense at all. I can probably

3:10eliminate that right off the bat because if I'm just capturing the management account events,

3:16then I'm not capturing the underling accounts. I don't know what you want to call it. The

3:20sub accounts, I guess. Use event bridge rules to do some other stuff. No, no, no, no. That's not a

3:27way. And that kind of leaves us with this option down here. Create an organization trail in the

3:31management account, which automatically captures management events from all current. Yes,

3:36this is the answer that I like. That's what I'm sticking to. Next question. Same deal here.

3:42Which response best describes the operational advantage of IAM Identity Center over manually

3:49configured cross account roles? You'll see this occasionally on AWS exam questions. They'll give

3:55you some possible answers down here and they'll ask you what is the best answer. And that's really

4:00important. And here's one of the cases where your practitioner's curse can kind of creep in there,

4:06because as you're reading through these things, you may say, hey, that's a perfectly valid way of

4:11doing this. And that's actually preferred when we're talking about maybe a multi-cloud environment.

4:16Well, you got to remember that AWS doesn't even acknowledge the fact that, hey, there's other

4:21clouds out there. It's certainly not in the exam setting. They certainly don't do that. But let's

4:25take a look here. IAM Identity Center credentials are encrypted with stronger algorithms. No,

4:31that's not true. We can get rid of that one right there. IAM Identity Center issues credentials that

4:38last 24 hours. Well, yeah, we could have credentials that last 24 hours while STS

4:43assume rule credentials expire after one hour and cannot be extended. Well, let's think about that.

4:50STS, that's a way to get temporary credentials. And that's one of those things that hopefully

4:55you should have learned about in one of the other courses or some of your earlier AWS work. STS,

5:02generally used to get short-term or temporary access to AWS and allowing some, maybe it's a CLI

5:10or some other script or something like that, to be able to assume a role. And it says here it

5:15expires after an hour and cannot be extended. Well, that's not the case. That is a falsehood

5:21right there. They absolutely can be extended. Well, they can be configured to be a certain

5:27duration and is definitely longer than an hour. It defaults to an hour, but you can have something

5:34that lasts longer than an hour. So just by the fact of we have a false statement in our answer

5:40here, we can eliminate that whole answer. So now, even if we're just guessing, we have a 50%

5:46chance. IAM provides a unified SSO portal where users authenticate once and see all the accounts

5:53and permissions available to them. Yes, that is exactly what IAM does. So that's a good answer

5:58right there. Let's keep on going because maybe there's a better answer. IAM Identity Center

6:02bypasses the need for MFA on cross-account access while STS assumes roles and always requires MFA.

6:10Okay. Well, this is maybe, I mean, I suppose you could, if you kind of squint, you could see that

6:16maybe that could be a possible answer, but that is not a good answer because STS assume rule does

6:23not always require MFA. Because think about it, if you're using STS in a script or something like

6:28that to grab some automated credentials, some short-term credentials, and you're prompted for

6:33an MFA, well, that's not going to work. The best answer here is this answer right there.

6:39Last question. All right. Which statement accurately describes the purpose of creating an

6:45OU structure early in this stage? They've just enabled AWS organizations much like our organization

6:52and they created a single workloads OU with one member account. All right. That's a good start.

6:57The organization currently only has two accounts total. So why would we bother setting up AWS

7:03organizations at this point? That's what they're asking us about. As a matter of fact, AWS says,

7:08hey, yeah, it's a best practice to set up AWS organizations if you have more than one account.

7:13Why? Why is that? So let's start at the bottom here. OUs provide the structure for applying

7:17governance policies to groups of accounts as the organization grows. Yes, that is a very strong

7:24answer right there. I'm going to put a little check beside that one. Let's keep going up. OUs

7:28are required by AWS organizations. You cannot create member accounts without first creating

7:33at least one OU to place them in. Well, no, this is not a true statement because if you remember,

7:40we created our AWS organization. We had root and we really didn't have any OUs underneath that.

7:46We could continue to create accounts, as many accounts as we want. They would just be sitting

7:50there at that top level root. So that is not a true answer here. OUs automatically isolate network

7:56traffic between accounts. OK, stop me just right there. That is not a true statement. So we can

8:02eliminate that one from consideration. OUs reduce costs by enabling consolidated billing discounts

8:08that only apply to accounts within the same OU and not across the entire organization. All right.

8:14So we are going to get a little bit more into cost optimization later. But one of the things that we

8:20can say right now is, yes, this enables consolidated billing. By default, your management account is

8:26the one that is going to pay the bill for all of your other accounts in your AWS organization.

8:32But we can absolutely pay the bills of other accounts under different OUs, under all the OUs,

8:39if we wanted to. So that is not a true statement. That second part is not a true statement and

8:44leaves this one down here, which is our correct answer. I hope this has been informative for you.

8:50And I'd like to thank you for viewing.

What's next?

Ready to keep going?

For your team

Bring this training to your team

See how CBT Nuggets helps IT teams close skills gaps, hit compliance targets, and prove training ROI.

Book a Demo
Just need AWS Certified Solutions Architect - Professional (SAP-C02)?

Learning on your own? Browse individual plans ($49/month, billed annually)

Not ready to buy?
with no purchase required. Already have an account?
Book a Demo