SAP on AWS
Landing Zones & Multi-Account Governance
45 flashcards · answers and spaced-repetition review in the KnowCard app
Why should you NOT run SAP workloads in the AWS Organizations management account?
If you apply an AWS Organizations tag policy requiring an SAP-Environment-Type tag, what does it actually enforce — and what still has to do the real work?
When AWS Organizations trusted access creates a service-linked role for another service, what surprising property does that role have for your guardrails?
You want every newly-vended SAP account customized AT creation time (not patched afterward). Which Control Tower customization option fits — and which is the wrong choice?
For accounts hosting SAP workloads, what does the AWS Organizations AI opt-out policy change — and what's the catch if you skip it?
You must PREVENT a non-compliant resource from ever being provisioned in an SAP account — which Control Tower guardrail type, and why not the others?
What are the key terms in AWS Service Catalog (product, portfolio, constraint, provisioned product)?
In an SAP landing zone's Shared Services OU, why is the backup vault its OWN account rather than folded into the logging or shared-services account?
Using AWS Service Catalog to deploy SAP consistently, what does the BASIS admin get to set — and what is deliberately locked away, and why?
An SAP account admin has full AdministratorAccess but still can't delete an S3 bucket. What's going on, and where is the control?
Why is a separate AWS ACCOUNT (not just a separate VPC/subnet) the blast-radius boundary regulated SAP customers mandate between prod and non-prod?
A baseline AWS landing zone for SAP segregates OUs by WHAT dimension — and what would that look like done wrong?
What is the contraindicated way to design AWS Organizations OUs, and what should drive the design instead?
Can an AWS account belong to two organizations at once — and what does that constraint imply for moving an SAP account between orgs?
The Control Tower Account Factory is implemented AS a Service Catalog product — what does that let you do that a bespoke vending tool wouldn't?
Under RISE with SAP, who builds the landing zone, and what are your only options to isolate PRD from non-PRD (and their catches)?
What is the relationship between AWS Control Tower and AWS Organizations — and what does that mean when you edit OUs/SCPs outside Control Tower?
What is an AWS landing zone, and what's the timing rule that defines when it must exist?
When AWS Control Tower sets up a landing zone, which account is NOT covered by the guardrails it applies — and why does that matter?
Beyond billing, what is the reason a multi-account AWS strategy is actually mandated for regulated SAP estates — and what makes the account the right boundary?
What single property makes an air-gapped (data-bunker) backup account actually protect SAP backups from ransomware — beyond just encrypting them?
What can you NOT do if your AWS Organizations is on the Consolidated Billing feature set instead of All Features?
Why use a delegated administrator in AWS Organizations for the SAP team, and what does it NOT let them do?
A teammate says they'll 'create an AWS account' so a developer has something to log in with. Why is that the wrong mental model, and what are they actually describing?
You need to script AWS Organizations tasks like moving an SAP account into its own OU. What are your programmatic options, and which one forces you to sign requests yourself?
Before AWS Control Tower existed, how were AWS landing zones delivered, and why did AWS replace that approach in 2019?
You're hand-setting non-overlapping VPC CIDR ranges in Account Factory for each SAP account. At what point does this manual approach break, and what replaces it?
In an AFC-based account vending flow, how does a customized SAP account actually get built, and what event chains the customization on top of the baseline?
You must confine an entire SAP estate's deployments to one AWS region. Which Control Tower control does this, and what's unusual about the scope where it applies?
Instead of one non-PROD OU, you split it into sandbox, DEV, and QA/Pre-Prod. What do you gain, and what costs does the book warn about?
When you set out to build an AWS landing zone for an SAP estate, what are the three ways to build it, and what does AWS specifically mean by a 'Partner'?
You need ongoing proof that every SAP account still meets your architectural guidelines — not a one-time check. Which AWS service records configuration history, and what SAP-relevant checks can it run?
You want two SAP accounts to use the SAME subnets and Transit Gateway instead of each duplicating its own networking. Which AWS service makes that possible, and at what scope can you share?
A fresh AWS account can't spin up as many EC2 instances as expected, and an estate of thousands of VMs keeps bumping ceilings. What's the mechanism, and how does going multi-account help?
Your partner delivers the 'baseline' AWS landing zone and calls the project done. Why is that framing wrong for an SAP estate?
In AWS Organizations, how do organization, root, OU, and policy fit together as the skeleton of a multi-account SAP landing zone?
Your SAP estate has unique security/compliance rules that AWS Control Tower can't satisfy. What are the two ways to implement an AWS landing zone, and which fits?
Who typically builds an SAP landing zone, how long does a baseline take, and what ownership model is common if you lack in-house cloud expertise?
Your company already runs an analytics landing zone on AWS. What does AWS recommend for the new SAP workloads, and the one exception?
Company A acquires Company B, both running SAP on AWS in separate organizations. What's the fast alternative to consolidating the two SAP systems?
Beyond prod-vs-non-prod isolation, name two team- or business-driven reasons to carve out a dedicated AWS account for SAP.
The Account Factory rolls out accounts on the default baseline, but your SAP accounts need partner tooling and network plumbing baked in. What kinds of customizations can Control Tower deploy into a vended account?
Beyond applying guardrails, how does Control Tower let you see whether your whole SAP landing zone is compliant, and how does keeping it patched relate to drift?
You're enabling trusted access so an AWS service can act across your SAP org. Why does AWS tell you to toggle it from the other service's console rather than from AWS Organizations?
AWS Control Tower is the default landing-zone tool for an SAP estate — when do you still need a custom-built landing zone instead?
Start learning today
Free to start — download the app or use it in your browser.
