[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"cheat-sheet---en":3,"domain-info---en":3,"topic-info----en":3,"lesson-aws-certified-cloudops-engineer-associate-security-and-compliance-multi-account-governance-trusted-advisor-remediation-en":4,"prev-aws-certified-cloudops-engineer-associate-security-and-compliance-multi-account-governance-trusted-advisor-remediation-en":20,"next-aws-certified-cloudops-engineer-associate-security-and-compliance-multi-account-governance-trusted-advisor-remediation-en":33},null,{"locked":5,"reason":6,"meta":7,"item":3},true,"paywall",{"title":8,"description":9,"isFree":10,"estimatedMinutes":11,"difficulty":12,"learningObjectives":13},"Trusted Advisor and Security Check Remediation","How to read Trusted Advisor security findings and act on them: what each check actually detects, which checks a Basic Support account gets, the refresh rules, and how to automate the response with EventBridge, Systems Manager, and organizational view.",false,22,"intermediate",[14,15,16,17,18,19],"Describe the 6 Trusted Advisor check categories and what the 4 status colors mean","Identify which checks are available on Basic Support and which require a paid support plan","Interpret the alert criteria for the main security checks and choose the correct remediation","Explain the refresh behavior of Trusted Advisor checks and when a manual refresh is possible","Automate a response to a check status change using EventBridge and Systems Manager Automation","Compare organizational view with Trusted Advisor Priority and state the prerequisites for each",{"locked":5,"reason":6,"meta":21,"item":3},{"title":22,"description":23,"isFree":10,"estimatedMinutes":24,"difficulty":12,"learningObjectives":25},"IAM Identity Center","How one identity source and a handful of permission sets replace per-account IAM users across an organization: instance types, assignments, the IAM roles Identity Center creates for you, session durations, and attribute-based access control.",25,[26,27,28,29,30,31,32],"Explain what problem IAM Identity Center solves that per-account IAM users cannot","Distinguish an organization instance from an account instance and state what each can manage","Describe the 3 identity source options and the effect of choosing an external provider","Trace what an assignment creates in a target account and what happens when a permission set changes","Differentiate the permission set session duration from the AWS access portal session duration","Configure attribute-based access control so one permission set serves several teams","Choose between IAM Identity Center, federation with IAM, and Cognito identity pools for a stated scenario",{"locked":5,"reason":6,"meta":34,"item":3},{"title":35,"description":36,"isFree":10,"estimatedMinutes":37,"difficulty":38,"learningObjectives":39},"AWS Config and Conformance Packs","How to turn a compliance requirement into a continuously evaluated control: the configuration recorder and configuration items, rule triggers and evaluation modes, automatic remediation through Systems Manager, and packaging rules for an entire organization.",30,"advanced",[40,41,42,43,44,45,46],"Explain what a configuration item is and how the configuration recorder produces one","Distinguish AWS Config from CloudTrail for a given evidence requirement","Select the correct rule trigger type and evaluation mode for a stated requirement","Interpret the 4 rule evaluation results, including NOT_APPLICABLE","Configure automatic remediation with a Systems Manager Automation document and describe its retry behavior","Deploy a conformance pack to an account or an organization and read its compliance score","Choose between an aggregator, an organization rule, and an organization conformance pack for a multi-account requirement"]