Instiq

1Design Solutions for Organizational Complexity

Practice questions →Glossary →
  • 1.1Multi-Account Strategy and Governance

    Understand the foundation for large organizations: AWS Organizations, Organizational Units (OUs), Service Control Policies (SCPs), consolidated billing, and Control Tower. Operate many accounts securely and with governance.

  • 1.2Cross-Account Access and Identity Federation

    Understand secure access across accounts—cross-account IAM roles, IAM Identity Center (SSO), SAML/OIDC federation, and Resource Access Manager (RAM). Design org-wide access with least privilege.

  • 1.3Multi-Account and Hybrid Networking

    Understand large-scale connectivity—Transit Gateway, VPC peering, PrivateLink, Direct Connect, Site-to-Site VPN, and Route 53 Resolver. Interconnect many VPCs and on-premises efficiently.

  • 1.4Governance, Security, and End-User Services

    A catalog of supporting services for organizational complexity—certificates/keys (ACM, CloudHSM), identity and directories (Cognito, Directory Service), network defense (Firewall Manager, Network Firewall), audit/compliance (Artifact, Audit Manager), cost/governance tooling (Cost and Usage Report, License Manager, Service Catalog, Well-Architected Tool, Health Dashboard, Management Console, CLI), and virtual desktops (WorkSpaces, AppStream 2.0)—organized by definition, role, and when to choose.