Case 8666E1 · Cloud · L4 Advanced
Multi-Account Landing Zone
Practise as: Deep dive · Explain it
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- Accounts are the strongest isolation boundary: split prod, dev, security tooling, logging and sandboxes
- An organization root applies guardrail policies (SCPs) centrally, such as region restrictions and no log deletion
- Centralized identity via SSO and permission sets instead of IAM users in each account
- Dedicated log archive and security accounts that workload admins cannot alter
- Blast radius: compromise of one workload account should not reach others without explicit cross-account trust
If the interviewer pushes back
- What is your break-glass plan if the SSO identity provider is unavailable during an incident?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.