Open cardosec

Case 8666E1 · Cloud · L4 Advanced

Multi-Account Landing Zone

Practise as: Deep dive · Explain it
  1. 01 Context
  2. 02 Mechanism
  3. 03 Lessons
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Accounts are the strongest isolation boundary: split prod, dev, security tooling, logging and sandboxes
  2. An organization root applies guardrail policies (SCPs) centrally, such as region restrictions and no log deletion
  3. Centralized identity via SSO and permission sets instead of IAM users in each account
  4. Dedicated log archive and security accounts that workload admins cannot alter
  5. Blast radius: compromise of one workload account should not reach others without explicit cross-account trust

If the interviewer pushes back

  • What is your break-glass plan if the SSO identity provider is unavailable during an incident?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.