AWS Training
Modules Listen Certification
0:00 0:00

← Platform Foundations

Q0 Lab — audit the account you actually have

Target: any real Amazon Quick / Quick Sight account you can read. An inherited one is ideal — the whole point is to discover what was decided before you arrived.

Cost: effectively zero. This lab is read-only except for Part 6, which is clearly marked and optional.

Write your answers down. Most people find at least one genuine surprise in their own environment, and the value is in the record, not the clicking.


Setup

export ACC=<your 12-digit account id>
export REG=<the region your Quick account lives in>

Q1. How did you determine REG? If you guessed, stop and read it out of the Quick console URL (https://<region>.quicksight.aws.amazon.com/...). Write down both the Region you assumed and the one you found.


Part 1 — Naming

Q2. Search AWS documentation for "Quick Sight data source quotas". Which of the three doc trees did your top result come from — /quicksight/latest/user/, /quick/latest/userguide/, or /quicksuite/latest/userguide/?

Q3. Take the same page path and swap the tree segment. Does the other tree also render? Do the page titles match?

Q4. Grep your own infrastructure code, scripts, and IAM policies for the string quick where it isn't followed by sight. Anything that isn't a comment is a bug:

grep -rniE '\bquick\b(?!sight)' --include='*.tf' --include='*.yaml' --include='*.yml' \
  --include='*.json' --include='*.sh' . 2>/dev/null | head -20

(If your grep lacks PCRE, use grep -rniE 'quick' … | grep -vi 'quicksight'.)


Part 2 — Edition and subscription

aws quicksight describe-account-settings --aws-account-id $ACC --region $REG

Q5. What edition is the account on? Did you expect that answer?

Q6. Given the edition, which of these are available to you today: VPC data sources, row-level security, column-level security, hourly refresh, incremental refresh, emailed reports?

Q7. What is the notification email set to? Is it a person or a distribution list? Is that person still at the company?

aws quicksight list-users --aws-account-id $ACC --namespace default --region $REG \
  --query 'UserList[].{Name:UserName,Role:Role,Email:Email,Active:Active}' --output table

Q8. Count users by role. How many Admins? Is that number defensible?

Q9. Are there any users you don't recognise, or any whose email domain isn't yours?


Part 3 — Who can actually do what

Q10. Using the admin split table from lesson 2: name the person or team in your organisation who can manage VPC connections and KMS keys (IAM side), and the person who can manage SPICE capacity (Quick admin role side).

Q11. Are those the same person? If not — who gets paged when an overnight refresh fails for lack of capacity, and can they fix it?

Q12. Try to open the SPICE capacity page yourself. Can you? Record the answer; it's the only proof that matters.


Part 4 — Regions

Q13. Change the Region in the AWS Management Console, then open Quick from it. Which Region does Quick open in? Does it match?

Q14. List your assets in your primary Region:

aws quicksight list-data-sets   --aws-account-id $ACC --region $REG \
  --query 'DataSetSummaries[].{Id:DataSetId,Name:Name,Mode:ImportMode}' --output table
aws quicksight list-dashboards  --aws-account-id $ACC --region $REG \
  --query 'DashboardSummaryList[].{Id:DashboardId,Name:Name}' --output table

Q15. Now run the same two commands against two other Regions you might plausibly have used. Anything there? Anything you'd forgotten about?

Q16. Where is your primary data — warehouse, lake, database? Is Quick Sight in the same Region? If not, what is that costing on every query or every refresh?


Part 5 — The asset inventory

Using the list-data-sets output from Q14:

Q17. How many datasets are SPICE and how many are DIRECT_QUERY? Was that split deliberate?

Q18. Now list data sources and analyses:

aws quicksight list-data-sources --aws-account-id $ACC --region $REG \
  --query 'DataSources[].{Id:DataSourceId,Name:Name,Type:Type}' --output table
aws quicksight list-analyses     --aws-account-id $ACC --region $REG \
  --query 'AnalysisSummaryList[].{Id:AnalysisId,Name:Name,Status:Status}' --output table

Q19. Compare the counts. Roughly how many datasets do you have per dashboard? If it's close to 1:1, you're paying the anti-pattern tax — estimate what consolidation would save in SPICE footprint.

Q20. Are any of your data sources of an uploaded-file type? For each one: what happens when the person who uploaded it leaves, and can that dataset ever be refreshed?

Q21. Pick your most business-critical dashboard. Trace it back: which analysis, which datasets, which data sources? Draw the chain. How long did that take, and is it written down anywhere?


Part 6 — Optional: the deliberate Region mistake ⚠️

Read-only accounts can skip this. It changes nothing permanently but does consume one ingestion call.

Deliberately run a command against the wrong Region:

aws quicksight describe-data-set --aws-account-id $ACC \
  --data-set-id <a real dataset id> --region <a region you do NOT use>

Q22. What error and HTTP status did you get? Would that error have told you the Region was wrong, if you didn't already know?

Q23. Write the one-line check you'd add to your team's troubleshooting runbook so nobody loses an hour to this.


Done when you can

Facilitator notes