# AWS244 Instructor Fault-Control Checklist

The supplied-evidence track is preferred. For an optional live sandbox only:

## Before

- Dedicated account/Region and named owner
- No production/shared dependency
- Architecture source committed and baseline tests passed
- Fault manifest, injection order, expected symptoms, and exact rollback recorded privately
- Snapshot/template/config backups verified
- Budget alarm and hard stop timer
- Course tags and cleanup query tested
- IAM least privilege and emergency access
- Student receives symptom/boundary, not fault list

## During

- One instructor injects only approved faults
- Record CloudTrail/request IDs and UTC
- Abort if boundary/charge/impact exceeds plan
- Preserve evidence before student changes
- Require hypothesis and approval before mutation
- Observe but do not disclose answer

## Recovery acceptance

- New positive and unauthorized negative transaction
- Restart/replacement test
- Dependency and target health
- SLO observation window
- Alarm/log/trace recovery
- Owner source reconciled; no console drift

## Cleanup

- Remove fault and temporary containment
- Delete/restore stacks, instances, volumes, snapshots, EIPs, LB/targets, DNS, NAT/endpoints, logs, alarms, parameters/secrets, IAM grants
- Query tagged and untagged dependencies
- Confirm billing/resource inventory after propagation
- Retain redacted evidence under approved expiry
- Never use a production account as proof of cleanup
