Which Services Will You Use?
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Users, Groups, and Roles
InnoMed Account
Group: Group: Group: Role:
Use the chart to document
users, groups, and roles
created.
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Users, Groups, and Roles
Group/Role # Group/Role Name Permissions
Group
Group
Group
Role
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Password Policy
Requirement Solution
Should be at least 8 characters and have
1 uppercase, 1 lowercase, 1 special
character, and a number.
Change passwords every 90 days and
ensure that the previous three
passwords can’t be re-used.
Administrator sign-in to the AWS
Management Console requires the use of
Virtual MFA.
All administrators require programmatic
access
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
VPC Details
VPC Region Purpose Subnets AZs CIDR range
1
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Production Subnet Details
Subnet Name VPC Subnet type (Public/private) AZ Subnet Address
#1
#1
#1
#1
#1
#1
#1
#1
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Test/Dev Subnet Details
Subnet Name VPC Subnet type (Public/private) AZ Subnet Address
#2
#2
#2
#2
#2
#2
#2
#2
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Instance Details
Describe the type, size, and justification for the instances you will use for each tier.
Tier Tag* OS Type Size Justification # of User
instances Data?
Key = Name
Web Value = web-tier
Key = Name
App Value = app-tier
Key = Name
DB Value = db-tier
* Tags must be configured as shown to meet the lab objectives
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Load Balancer and Instance Security Group Details
Load Name* External Subnets SG Name* Rule Source
Balancer /Internal
For Web web-elb web-elb-sg
Tier
For App app-elb app-elb-sg
Tier
Instance Tier SG Name* Rule Source
Web Tier web-tier-sg
App Tier app-tier-sg
Database Tier db-tier-sg
* Names must be configured as shown to meet the lab objectives
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Auto Scaling Launch Configuration
Tier OS Type Size Configuration Role Security
Name* Group
Web WebTier
App AppTier
* Name must be configured as shown to meet the lab objectives
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Auto Scaling Group
Tier Launch Group Group VPC Subnets ELB Tags
Configuration* Name* Size
Web WebTier WebTier
App AppTier AppTier
* Names must be configured as shown to meet the lab objectives
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Auditing Options
Q. How do you configure an account to create an audit trail for all executed API calls?
____________________________________________
Q. Where do you save your logs?
____________________________________________
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.