Skip to main content
Your progress
0 of 5 lessons complete0%
T3 / M3.4 / Architect TIER / ~10 min

Multi-account architecture: module quiz

M3.4 module quiz

Ten questions. 80% to pass (8 of 10). Open book, unlimited retakes.

Answers are collapsed under each question. Answer first, then check.


Q1

The strongest argument for multi-account is:

A. Billing separation
B. Blast-radius isolation
C. Higher API quotas
D. Regional compliance rules

Show answer

Correct: B. Billing separation matters and is easier to explain to finance, but the account boundary is the hardest wall each cloud offers, and that is what limits the damage of a mistake.

Q2

The AWS external ID defends against:

A. Credential theft
B. Replay attacks
C. Privilege escalation inside the account
D. The confused-deputy problem

Show answer

Correct: D. A third party knowing your role ARN cannot assume it without the external ID. ZopNight derives the account from the STS-attested assumed-role ARN rather than the caller-supplied one.

Q3

An Azure tenant-scoped account:

A. Auto-discovers subscriptions and creates a child account per subscription, with cascading operations
B. Is a leaf node exactly like a subscription, so one credential covers only one billing boundary
C. Requires one credential per subscription, registered separately
D. Cannot be used for discovery, and only groups subscriptions

Show answer

Correct: A. The cascade is what surprises people during a credential rotation: rotating the parent rotates every child.

Q4

GCP’s Workload Identity Federation removes:

A. The need for a service account at all
B. Cross-project access to resources
C. The need to store a long-lived key
D. The IAM binding step at setup

Show answer

Correct: C. The service account still exists; what disappears is the exported key file, which is the artifact that leaks.

Q5

The most common multi-account anti-pattern is:

A. One separate account per microservice
B. Prod and non-prod mixed in one account
C. Per-engineer accounts
D. A shared services account

Show answer

Correct: B. It defeats the blast-radius argument that justified multi-account in the first place, and it makes non-prod scheduling risky because a mistake reaches production.

Q6

Per-engineer and per-microservice accounts are anti-patterns because they:

A. Multiply operational overhead without adding isolation that matters
B. Are forbidden by the providers’ own account limits
C. Break billing consolidation across the whole of the organisation
D. Cannot be discovered by the inventory APIs at all

Show answer

Correct: A. They are the over-correction: the isolation boundary is placed where nothing needs isolating, and every account carries setup, credential and monitoring cost.

Q7

Rollup and isolation views differ in that rollup:

A. Is faster to compute across a large and steadily growing number of cloud accounts
B. Excludes non-prod accounts from the total
C. Aggregates across accounts for a total; isolation keeps them separate for accountability
D. Uses billing cost only, never rack rate

Show answer

Correct: C. The audience decides which is right: leadership wants the total, a team wants their own account. Presenting the wrong one is how a cost review stalls.

Q8

AWS Organizations, GCP folders and Azure management groups all enable:

A. Cross-account networking between VPCs
B. Shared credentials across the accounts
C. Unified logging into one destination
D. Policy inheritance down a hierarchy

Show answer

Correct: D. Inheritance is what makes governance tractable at scale, and it is why the organisational hierarchy matters to cost attribution even though it is not itself a cost concept.

Q9

A shared-services account holds:

A. Nothing at all; the OU is purely a billing rollup construct here
B. Cross-cutting infrastructure such as networking, CI and shared tooling
C. Production workloads only, by convention
D. Backup copies of the other accounts

Show answer

Correct: B. Its cost then needs attributing back to consuming teams, which is why shared-resource attribution exists as a distinct problem in showback design.

Q10

Cross-account discovery timing on a large estate is bounded by:

A. The total number of resources discovered across all the accounts
B. The billing sync cadence for the organisation
C. The per-account credential assumption plus each account’s own discovery
D. Network latency between the account regions

Show answer

Correct: C. Which is why a many-account estate has a longer first-discovery than a single large account with the same resource count.


What’s next

Back to Multi-account architecture.

Start with the bill.

Foundations takes about five hours. The first lesson is nine minutes.

Open curriculum. No login. No paywall. 290 lessons across 7 courses, three publicly verifiable credentials. Read it on the train, take the exam on a Saturday, list the credential on your résumé Monday.

5h median time to finish Foundations
0 logins, paywalls, or marketing forms
open curriculum, public credential verifier
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·