Soru

Zorluk: KolayBilling, Cost Management, and Resource Sharing Strategy

A solutions architect needs to share a Transit Gateway from a production AWS account with an external partner's AWS account that is not part of the company's AWS Organization. Which of the following approaches is required to successfully share this resource using AWS Resource Access Manager (RAM)?

  1. A
    Create a resource share in AWS RAM, target the external partner's AWS account ID, and rely on the default settings which permit global sharing without additional configuration.
  2. B
    Attach a Service Control Policy (SCP) to the organization's root that explicitly permits AWS RAM to share resources with the external partner's AWS Organization ID.
  3. Enable sharing with external principals in the AWS RAM settings, create a resource share targeting the external partner's AWS account ID, and have the partner accept the resource share invitation.Cevap
  4. D
    Configure a resource share using an AWS-managed KMS key to encrypt the Transit Gateway transit data, then delegate key access directly to the external partner's IAM roles.

Cevap

Enable sharing with external principals in the AWS RAM settings, create a resource share targeting the external partner's AWS account ID, and have the partner accept the resource share invitation.
To share resources like a Transit Gateway with an external account not part of your AWS Organization, you must first enable sharing with external principals in the AWS RAM console settings. Once enabled, you can create a resource share targeting the external account. Because the account is external to the organization, an invitation is sent and must be explicitly accepted by the partner account before the shared resource can be accessed.

Adım Adım Çözüm

1
Enable external sharing in the AWS RAM settings.
AWS RAM is permitted to share supported resources with AWS accounts outside of its AWS Organization.
By default, AWS RAM restricts sharing to accounts within the same AWS Organization for security.
2
Create a resource share, select the Transit Gateway, and add the external partner's AWS account ID as the principal.
A resource share is created and an invitation is sent to the external partner's AWS account.
Sharing resources outside the AWS Organization requires specifying the individual destination account ID.
3
Have the external partner log into their AWS console, navigate to AWS RAM, and accept the resource share invitation.
The shared Transit Gateway becomes visible and usable in the partner's AWS account.
External accounts must explicitly accept resource shares to prevent unauthorized or unexpected resource placements.

Anahtar Kavram

AWS Resource Access Manager (RAM) external sharing requirements and workflow.
Tahmini Süre:1m 0s
Bu soruyu puanla