{"results":[{"id":"apigw-websocket-max-2-hours-idle-10-minutes","text":"API Gateway WebSocket connections have a maximum lifetime of 2 hours and a 10-minute idle timeout (close status 1001).","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"appsync-events-websocket-batch-limit-5","text":"AppSync Events WebSocket publish requests support a maximum of 5 events per batch.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"appsync-websocket-max-payload-240kb","text":"AWS AppSync pure WebSocket subscriptions support a maximum payload size of 240 KB.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"audit-manager-evidence-finder-retention-2yr-default-7yr-max","text":"Audit Manager evidence finder has a default retention of 2 years, configurable up to 7 years (2,555 days); it backfills 2 years of historical evidence upon enablement.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"aws-account-closure-10pct-rolling-limit","text":"Organizations have a 10% rolling 30-day limit on closing member accounts (minimum 10, maximum 1000 closures per period).","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"aws-managed-policy-max-five-versions","text":"AWS managed policies can have up to 5 versions with one designated as the default.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"backup-max-5-delegated-admins","text":"Up to 5 delegated administrator accounts can be registered for AWS Backup via the console.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"backup-plan-name-max-50-chars","text":"AWS Backup plan names have a maximum of 50 characters, allowing alphanumeric characters, dashes, underscores, and periods.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"backup-retention-semantics-conflict-across-storage-tiers","text":"AWS Backup cold storage requires a minimum 90-day retention beyond the warm-to-cold transition while continuous PITR backups max out at 35 days — organizations must plan for fundamentally different retention windows across backup tiers, and cannot unify continuous and archival retention into a single policy","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"backup-strategy-faces-conflicting-retention-and-state-reset","text":"AWS backup strategy faces compounding structural conflicts: cold storage demands 90+ day retention while PITR maxes at 35 days, AND recovery restores do not preserve PITR configuration — organizations must bridge a retention gap while manually re-enabling the very protection that would cover it.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"backup-vault-lock-grace-time-3-to-36500-days","text":"AWS Backup Vault Lock Compliance mode grace time (cooling-off period) ranges from a minimum of 3 days to a maximum of 36,500 days (~100 years); after it expires, the lock is permanently immutable.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"backup-vault-lock-retention-only-new-jobs","text":"AWS Backup Vault Lock retention period enforcement (min/max days) only affects new backup/copy jobs; existing recovery points are not affected retroactively.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"cfn-max-200-parameters-outputs-mappings","text":"CloudFormation templates are limited to 200 parameters, 200 outputs, and 200 mappings each per template.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"cfn-max-500-resources-per-template","text":"CloudFormation templates support a maximum of 500 resources; nested stacks are the standard workaround for exceeding this limit.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"cfn-max-60-dynamic-references-per-template","text":"CloudFormation templates support a maximum of 60 dynamic references (SSM Parameter Store, Secrets Manager) per template.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"cfn-stack-name-max-128-chars","text":"CloudFormation stack names have a maximum length of 128 characters, shorter than the 255-character limit for resource, parameter, output, and mapping names.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"cfn-stackset-max-10-dependencies","text":"Service-managed CloudFormation StackSets support a maximum of 10 dependencies (dependent StackSet ARNs).","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"cfn-stackset-max-concurrent-lte-failure-tolerance-plus-one","text":"In StackSet operations, `MaxConcurrentCount` must not exceed `FailureToleranceCount` + 1.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"cfn-stackset-percentage-settings-round-down","text":"Percentage-based StackSet operation settings (failure tolerance, max concurrent accounts) round down to the nearest whole number.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"cfn-stackset-strict-initial-concurrency-formula","text":"In Strict Failure Tolerance mode, initial StackSet concurrency equals the lower of `MaxConcurrentAccounts` or `FailureTolerance + 1`, not simply `MaxConcurrentAccounts`.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null}],"count":154,"limit":20,"offset":0}