Ngân hàng đề — AWS Certified Advanced Networking Specialty

Tìm thấy 352 câu.

Câu 21 Chọn nhiều đáp án Manage, optimize, and troubleshoot the network

A social media company has installed an AWS Site-to-Site VPN and the networking team has noticed that the VPN tunnel is unstable or the tunnel status is frequently down on the customer gateway device.

Which steps should the networking team take to address this issue? (Select two)

  1. A

    Use a higher multi-exit discriminator (MED) value on the preferred path to prefer one tunnel

  2. B

    Create a host that sends ICMP requests to an instance in your VPC every 5 seconds

  3. C

    Disable dead peer detection (DPD) on the customer gateway device

  4. D

    Customer gateway device is configured to receive and respond to dead peer detection (DPD) messages

  5. E

    Use AS Path prepending on one path to cause all traffic to prefer one tunnel

Xem giải thích

Đáp án

B và D — dựng một máy gửi gói ICMP mỗi 5 giây, và cấu hình customer gateway nhận và trả lời thông điệp dead peer detection

Vì sao đúng

Đường hầm VPN của AWS tự đóng khi không có lưu lượng. Đây là nguyên nhân phổ biến nhất của triệu chứng "đường hầm chập chờn", và hai biện pháp dưới đây đánh vào đúng hai mặt của nó:

  • B. Sinh lưu lượng đều đặn — một máy trong mạng tại chỗ ping một instance trong VPC mỗi 5 giây giữ cho đường hầm luôn có dữ liệu đi qua, nên nó không bị coi là nhàn rỗi. Đây là khuyến nghị chính thức của AWS.
  • D. Bật dead peer detection trên customer gateway — AWS gửi thông điệp DPD để dò xem đầu bên kia còn sống không. Thiết bị phải trả lời; không trả lời thì AWS kết luận đối tác đã chết và đóng đường hầm.

Vì sao các phương án khác sai

  • C. Tắt dead peer detection — đi ngược hẳn: DPD chính là cơ chế phát hiện và khôi phục đường hầm hỏng. Tắt nó đi thì đường hầm chết vẫn được coi là sống.
  • A. Dùng giá trị MED cao hơn trên đường ưu tiên — MED hoạt động ngược chiều: giá trị thấp hơn mới được ưu tiên. Và dù sao đây là kỹ thuật chọn đường, không liên quan tới độ ổn định.
  • E. Dùng AS_PATH prepend để dồn lưu lượng về một đường hầm — cũng là kỹ thuật chọn đường; nó quyết định đi hầm nào, không làm hầm bớt rớt.
Câu 22 Chọn nhiều đáp án Design and implement AWS networks

A mobile-app based social media company is using Amazon CloudFront to deliver media-rich content to its audience across the world. The Content Delivery Network (CDN) offers a multi-tier cache by default, with regional edge caches that improve latency and lower the load on the origin servers when the object is not already cached at the edge. However, there are certain content types that bypass the regional edge cache and go directly to the origin.

Which of the following content types skip the regional edge cache? (Select two)

  1. A

    Proxy methods PUT/POST/PATCH/OPTIONS/DELETE go directly to the origin

  2. B

    User-generated videos

  3. C

    E-commerce assets such as product photos

  4. D

    Static content such as style sheets, JavaScript files

  5. E

    Dynamic content, as determined at request time (cache-behavior configured to forward all headers)

Xem giải thích

Đáp án

A và E — các phương thức proxy (PUT/POST/PATCH/OPTIONS/DELETE) và nội dung động

Vì sao đúng

Regional edge cache là tầng cache thứ hai nằm giữa edge location và origin, giúp giữ được những đối tượng ít được yêu cầu mà nếu chỉ có cache ở edge thì đã bị đẩy ra. Nhưng có hai loại nội dung đi thẳng tới origin, bỏ qua tầng này:

  • A. Các phương thức proxy — PUT, POST, PATCH, OPTIONS, DELETE là những thao tác thay đổi dữ liệu ở origin. Cache chúng là vô nghĩa và còn nguy hiểm, nên chúng đi thẳng.
  • E. Nội dung động — được xác định tại thời điểm yêu cầu, ví dụ khi cache behavior được cấu hình chuyển tiếp toàn bộ header. Chuyển tiếp mọi header nghĩa là mỗi tổ hợp header là một khoá cache khác nhau, nên tỷ lệ trúng cache gần bằng 0 — giữ ở regional cache chỉ tốn chỗ.

Vì sao các phương án khác sai

Ba phương án còn lại đều là nội dung tĩnh, dùng lại được, tức đúng thứ regional edge cache sinh ra để phục vụ:

  • B. Video do người dùng tải lên, C. Ảnh sản phẩm thương mại điện tử, D. Tệp CSS và JavaScript — tất cả đều được cache bình thường ở cả hai tầng.
Câu 23 Manage, optimize, and troubleshoot the network

A social media company is delivering web content from an Amazon EC2 instance in a public subnet with address 2021:db8:1:100::1. Users report they are unable to access the web content. The VPC Flow Logs for the subnet contain the following entries:

2 098765432112 eni-0596e500987654321 2021:db8:2:200::2 2021:db8:1:100::1 0 0 58 236 42336 1551200195 1551200434 ACCEPT OK 2 098765432112 eni-0596e500987654321 2021:db8:1:100::1 2021:db8:2:200::2 0 0 58 236 42336 1551200195 1551200434 REJECT OK

Which of the following actions will restore network reachability to the EC2 instance?

  1. A

    Update the security group associated with the subnet to allow outbound traffic

  2. B

    Update the network ACL associated with the subnet to allow outbound traffic

  3. C

    Update the security group associated with the eni-0596e500987654321 to allow outbound traffic

  4. D

    Update the network ACL associated with the eni-0596e500987654321 to allow outbound traffic

Xem giải thích

Đáp án

B — Sửa network ACL gắn với subnet để cho phép lưu lượng đi ra

Vì sao đúng

Nhật ký luồng chỉ ra chính xác vấn đề:

2021:db8:2:200::2 → 2021:db8:1:100::1   ACCEPT   ← chiều vào: được phép
2021:db8:1:100::1 → 2021:db8:2:200::2   REJECT   ← chiều VỀ: bị chặn

Chiều vào thông, lưu lượng phản hồi bị chặn — dấu hiệu đặc trưng của network ACL thiếu luật đi ra, vì NACL không có trạng thái:

Security Group Network ACL
Trạng thái Có (stateful) Không (stateless)
Lưu lượng phản hồi Tự động được phép Phải khai luật riêng
Gắn vào Elastic network interface Subnet

Vì sao các phương án khác sai

  • A và C. Sửa security group — security group có trạng thái, nên phản hồi đã tự động được phép; sửa nó không giải quyết gì.
  • *D. Sửa network ACL gắn với eni-0596e500987654321 — đúng loại tài nguyên nhưng sai chỗ gắn: NACL gắn với subnet, không gắn với network interface. Đây là bẫy tinh vi nhất của câu này vì phần "NACL, luật đi ra" đều đúng.
Câu 24 Configure network integration with application services

Consider a scenario where an EC2 instance in a private subnet reaches out to the internet via a NAT gateway in a public subnet. The EC2 instance sends a 1 GB file to one of the Amazon Simple Storage Service (Amazon S3) buckets via the NAT gateway. The EC2 instance, NAT gateway, and S3 Bucket are in the same AWS region. The NAT gateway and EC2 instance are in the same Availability Zone.

Which costs should be included when the total cost of this file transfer is calculated?

  1. A

    NAT Gateway Hourly Charge + NAT Gateway data processing charge for 1 GB of data transfer through the Gateway

  2. B

    NAT Gateway Hourly Charge + NAT Gateway data processing charge for 1 GB of data transfer through the Gateway + standard EC2 data transfer charge for 1 GB of data sent to S3 bucket

  3. C

    NAT Gateway Hourly Charge + NAT Gateway data processing charge for 1 GB of data transfer through the Gateway + The data transfer charges for 1 GB data between the NAT gateway and the EC2 instance

  4. D

    NAT Gateway Hourly Charge + NAT Gateway data processing charge for 1 GB of data transfer through the Gateway + standard EC2 data transfer charge for 1 GB of data sent to S3 bucket + The data transfer charges for 1 GB data between the NAT gateway and the EC2 instance

Xem giải thích

Đáp án

A — Phí giờ của NAT gateway + phí xử lý dữ liệu cho 1 GB đi qua gateway

Vì sao đúng

Chỉ có hai khoản phí phát sinh, vì mọi đoạn còn lại của đường đi đều miễn phí:

EC2 (private subnet)
   │  cùng Availability Zone với NAT → MIỄN PHÍ
   ▼
NAT Gateway                          → tính PHÍ GIỜ + PHÍ XỬ LÝ 1 GB
   │  tới S3 CÙNG REGION             → MIỄN PHÍ
   ▼
Amazon S3

Hai quy tắc cần nhớ:

  • Truyền dữ liệu từ EC2 sang S3 trong cùng Region là miễn phí.
  • Truyền dữ liệu trong cùng Availability Zone bằng IP riêng là miễn phí.

Vì sao các phương án khác sai

  • B cộng thêm phí truyền dữ liệu EC2 sang S3 — không có, vì cùng Region.
  • C cộng thêm phí giữa NAT gateway và EC2 — không có, vì cùng AZ.
  • D cộng cả hai khoản không tồn tại.

Lưu ý

Chính vì NAT gateway tính phí xử lý cho từng GB mà việc dùng S3 gateway endpoint thay cho NAT trở nên rất đáng giá: gateway endpoint không tính phí cả giờ lẫn dữ liệu.

Câu 25 Design and implement hybrid IT network architectures

A retail company has a data center with a 2 connection LAG. The networking team at the company wants to add 2 more connections.

How many Letters of Authorization (LOAs) would you need to complete for the given use case?

  1. A

    1

  2. B

    0

  3. C

    2

  4. D

    4

Xem giải thích

Đáp án

C — 2 LOA

Vì sao đúng

LOA-CFA (Letter of Authorization and Connecting Facility Assignment) là văn bản AWS cấp cho từng cổng vật lý — nó cho biết đấu vào rack nào, cổng nào tại cơ sở Direct Connect.

Vì vậy con số LOA luôn bằng số kết nối vật lý mới, không liên quan tới việc chúng có được gộp vào LAG hay không:

LAG hiện tại: 2 kết nối (đã có LOA từ trước)
Thêm mới:     2 kết nối  →  2 LOA

Link Aggregation Group chỉ là cách gộp nhiều kết nối vật lý thành một liên kết luận lý bằng LACP. Mỗi sợi cáp vẫn cần được đấu nối riêng, nên vẫn cần LOA riêng.

Vì sao các phương án khác sai

  • D. 4 — đếm cả hai kết nối đã có sẵn; chúng đã được đấu nối rồi.
  • A. 1 — LAG không gộp được nhiều cổng vật lý vào một văn bản uỷ quyền.
  • B. 0 — kết nối vật lý mới luôn cần LOA.
Câu 26 Chọn nhiều đáp án Design and implement AWS networks

A social media company is planning to release the major upgrade of its flagship application in a week. The development team is testing the alpha release of the application running on 10 EC2 instances managed by an Auto Scaling group in subnet 172.10.0.0/24 within VPC A having CIDR block 172.10.0.0/16. The team has noticed connection timeout errors in the application logs while connecting to a MySQL database running on an EC2 instance in the same region in subnet 172.40.0.0/24 within VPC B having CIDR block 172.40.0.0/16. The IP of the database instance is hard-coded in the application instances.

As a Networking Specialist, which of the following solutions would you suggest to the development team to solve the problem securely with minimal maintenance and overhead? (Select two)

  1. A

    Create and attach NAT gateways for both VPCs and set up routes to the NAT gateways for both VPCs. Assign an Elastic IP for the EC2 instance running MySQL database in VPC B. Update the application instances to connect to this Elastic IP

  2. B

    Create and attach virtual private gateways for both VPCs and set up default routes to the customer gateways for both VPCs. Assign an Elastic IP for the EC2 instance running MySQL database in VPC B. Update the application instances to connect to this Elastic IP

  3. C

    Set up a VPC peering connection between the two VPCs and add a route to the routing table of VPC A that points to the IP address range of 172.40.0.0/16

  4. D

    Create and attach internet gateways for both VPCs and set up default routes to the Internet gateways for both VPCs. Assign an Elastic IP for the EC2 instance running MySQL database in VPC B. Update the application instances to connect to this Elastic IP

  5. E

    Set up a VPC peering connection between the two VPCs and add a route to the routing table of VPC B that points to the IP address range of 172.10.0.0/16

Xem giải thích

Đáp án

C và E — thiết lập VPC peering, rồi thêm tuyến ở bảng định tuyến của cả hai VPC

Vì sao đúng

Hai VPC nằm cùng Region và có dải CIDR không chồng lấn (172.10.0.0/16 và 172.40.0.0/16), nên VPC peering là giải pháp đúng: lưu lượng đi trong mạng riêng của AWS, không ra Internet, không tốn phí giờ cho thiết bị nào, và gần như không có công vận hành.

Điểm mấu chốt là phải thêm tuyến ở cả hai phía:

  • C. Trong VPC A: tuyến 172.40.0.0/16 → pcx-... để yêu cầu đi tới được cơ sở dữ liệu.
  • E. Trong VPC B: tuyến 172.10.0.0/16 → pcx-... để gói phản hồi quay về được.

Thiếu một chiều là triệu chứng đúng như đề mô tả — connection timeout: gói đi tới nơi nhưng không có đường về.

Peering cũng giữ nguyên được địa chỉ IP riêng đang hard-code trong ứng dụng, nên không phải sửa mã.

Vì sao các phương án khác sai

Ba phương án còn lại (A, B, D) đều đi theo hướng gán Elastic IP cho máy chủ cơ sở dữ liệu rồi kết nối qua Internet. Cả ba đều hỏng ở cùng một chỗ: phơi cơ sở dữ liệu MySQL ra Internet, đi ngược yêu cầu "an toàn" của đề, đồng thời phải sửa lại cấu hình ứng dụng và trả thêm phí truyền dữ liệu.

Câu 27 Design and implement for security and compliance

A Network Engineer is designing a system on AWS that will leverage Amazon CloudFront for content caching and for protecting the underlying origin. The security team has flagged a concern of a probable attack on the origin server IP addresses, despite it being served by CloudFront.

Suggest a solution that provides the strongest level of protection to the origin server?

  1. A

    Configure an AWS Lambda@Edge function to validate that the traffic to the Application Load Balancer originates from CloudFront

  2. B

    Configure private access to content by using special CloudFront signed URLs or signed cookies

  3. C

    Configure CloudFront to use a custom header and configure an AWS WAF rule on the origin’s Application Load Balancer to accept only traffic that contains that header

  4. D

    Configure Origin Access Identity(OAI) on the origin server, which will only allow requests originating from CloudFront

Xem giải thích

Đáp án

C — Cấu hình CloudFront thêm một custom header, và đặt luật WAF trên Application Load Balancer của origin chỉ chấp nhận yêu cầu có header đó

Vì sao đúng

Vấn đề trong đề là kẻ tấn công có thể tìm ra IP của origin rồi gửi thẳng vào, bỏ qua CloudFront cùng mọi biện pháp bảo vệ đặt ở đó.

Cách chống mạnh nhất khi origin là ALB gồm hai lớp:

  1. CloudFront chèn một header bí mật vào mọi yêu cầu chuyển tới origin.
  2. WAF trên ALB từ chối mọi yêu cầu không mang header đó.

Vì header là bí mật chỉ CloudFront biết, yêu cầu gửi thẳng vào IP của ALB sẽ không có nó và bị chặn ngay tại tầng ứng dụng.

Nên kết hợp thêm: giới hạn security group của ALB theo dải IP của CloudFront (có sẵn trong danh sách prefix do AWS quản lý), và xoay vòng giá trị header định kỳ.

Vì sao các phương án khác sai

  • D. Dùng Origin Access Identity — OAI (và bản mới OAC) chỉ dùng được với origin là S3; đề nói origin là Application Load Balancer, nên phương án này không áp dụng được. Đây là bẫy chính vì OAI đúng là cơ chế "chỉ CloudFront mới truy cập được".
  • A. Dùng Lambda@Edge để kiểm tra lưu lượng tới ALB có xuất phát từ CloudFront không — Lambda@Edge chạy tại edge của CloudFront, tức là trước origin; nó không nhìn thấy được lưu lượng đi thẳng vào ALB.
  • B. Dùng signed URL hoặc signed cookie — kiểm soát ai được xem nội dung, không bảo vệ IP của origin.
Câu 28 Configure network integration with application services

A retail company has applications deployed in two different AWS Regions. These applications must securely communicate with each other by VPN. According to the organization's security team, the VPN must meet the following requirements:

AES 128-bit encryption

SHA-1 hashing

User access via SSL VPN

PFS using DH Group 2

Ability to maintain/rotate keys and passwords

Certificate-based authentication

Which solution would you recommend to address these requirements?

  1. A

    Third-party software VPN solution deployed from the AWS Marketplace

  2. B

    AWS Site-to-Site VPN between the virtual private gateways in the two AWS Regions

  3. C

    AWS Client VPN between the virtual private gateways in the two AWS Regions

  4. D

    AWS Site-to-Site VPN between the virtual private gateway and customer gateway

Xem giải thích

Đáp án

A — Giải pháp VPN phần mềm của bên thứ ba, triển khai từ AWS Marketplace

Vì sao đúng

Danh sách yêu cầu trong đề chứa hai điều mà AWS Site-to-Site VPN không đáp ứng được:

Yêu cầu Site-to-Site VPN của AWS
AES 128-bit, SHA-1, PFS DH Group 2 ✅ Hỗ trợ
Truy cập của người dùng qua SSL VPN ❌ — đây là VPN site-to-site, không phải VPN cho người dùng cuối
Xác thực bằng chứng chỉ ❌ — dùng khoá chia sẻ trước (pre-shared key)
Tự quản lý và xoay vòng khoá, mật khẩu ❌ — AWS quản lý phía đầu bên kia

Khi khách hàng cần kiểm soát toàn bộ tham số mật mã và cơ chế xác thực, cách duy nhất là tự vận hành thiết bị VPN — chạy trên EC2, lấy từ Marketplace. Bạn có toàn quyền, đổi lại phải tự lo tính sẵn sàng, vá lỗi và giám sát.

Vì sao các phương án khác sai

  • B. Site-to-Site VPN giữa hai virtual private gateway — không làm được: VPN của AWS cần một đầu là customer gateway, không nối được hai VGW với nhau.
  • D. Site-to-Site VPN giữa VGW và customer gateway — cấu hình hợp lệ, nhưng thiếu SSL VPN cho người dùng và xác thực bằng chứng chỉ.
  • C. AWS Client VPN giữa hai VGW — Client VPN dựng cho người dùng cá nhân kết nối vào VPC, không phải để nối hai Region với nhau.
Câu 29 Configure network integration with application services

A retail company wants to set up a hybrid cloud infrastructure between AWS Cloud and on-premises data center using Direct Connect as well as AWS Site-to-Site VPN. The networking team is working on configuring routing for this infrastructure and needs assistance with respect to the correct priority order for propagated and static routes for Direct Connect and Site-to-Site VPN when the prefixes are the same.

As an AWS Certified Networking Specialist, which of the following would you identify as the correct order of priority from the most preferred to the least preferred?

  1. A

    BGP propagated routes from an AWS Direct Connect connection > BGP propagated routes from a Site-to-Site VPN connection > Manually added static routes for a Site-to-Site VPN connection

  2. B

    BGP propagated routes from a Site-to-Site VPN connection > Manually added static routes for a Site-to-Site VPN connection > BGP propagated routes from an AWS Direct Connect connection

  3. C

    BGP propagated routes from an AWS Direct Connect connection > Manually added static routes for a Site-to-Site VPN connection > BGP propagated routes from a Site-to-Site VPN connection

  4. D

    Manually added static routes for a Site-to-Site VPN connection > BGP propagated routes from an AWS Direct Connect connection > BGP propagated routes from a Site-to-Site VPN connection

Xem giải thích

Đáp án

C — Tuyến BGP từ Direct Connect > Tuyến tĩnh khai tay cho Site-to-Site VPN > Tuyến BGP từ Site-to-Site VPN

Vì sao đúng

Khi nhiều tuyến có cùng prefix, VPC router chọn theo thứ tự ưu tiên cố định:

Ưu tiên Loại tuyến
1 Tuyến local của VPC
2 Tuyến tĩnh bạn tự thêm vào bảng định tuyến
3 BGP từ Direct Connect
4 Tuyến tĩnh cho Site-to-Site VPN
5 BGP từ Site-to-Site VPN

Điều đáng nhớ nhất: Direct Connect luôn được ưu tiên hơn VPN khi prefix giống nhau. Đó là hành vi mặc định và cũng là điều người ta mong muốn — Direct Connect ổn định và băng thông cao hơn.

Hệ quả thực tế: muốn dựng mô hình "Direct Connect chính, VPN dự phòng" thì không cần cấu hình gì thêm; chỉ cần cả hai cùng dùng một virtual private gateway và quảng bá cùng prefix.

Điểm hơi phản trực giác là tuyến tĩnh của VPN xếp trên tuyến BGP của VPN — logic chung của AWS là thứ bạn khai tay thắng thứ được học tự động, nhưng riêng Direct Connect thì vẫn vượt lên trên cả hai loại tuyến VPN.

Vì sao các phương án khác sai

  • A — đảo hai mục cuối: đặt BGP của VPN trên tuyến tĩnh của VPN.
  • B và D — đều xếp Direct Connect xuống dưới một loại tuyến VPN nào đó, sai với quy tắc quan trọng nhất.
Câu 30 Design and implement for security and compliance

A financial services application runs on a fleet of Amazon EC2 instances that are configured with an Auto Scaling Group (ASG). The instances are fronted by an Elastic Load Balancer (ELB). The security team has flagged an exploitable vulnerability in the encryption protocol and cipher that the application uses. The listener of the ELB is configured on an HTTPS protocol.

Which step will you take to secure the application from the newly detected vulnerability?

  1. A

    Create new SSL certificates for all web servers and replace the old ones with the new certificates created

  2. B

    Add a certificate list to add multiple certificates on the ELB for additional security

  3. C

    Create a strong custom security policy to cover the newly detected vulnerability and attach it to your Application Load Balancer

  4. D

    Update the security policy on the ELB to disable vulnerable protocols and ciphers

Xem giải thích

Đáp án

D — Cập nhật security policy trên ELB để tắt các giao thức và bộ mã hoá có lỗ hổng

Vì sao đúng

Vì listener được cấu hình là HTTPS, chính ELB là nơi kết thúc phiên TLS — nên nó cũng là nơi quyết định dùng giao thức và bộ mã nào. Sửa ở đúng chỗ đó là xong.

Security policy của ELB là một danh sách các giao thức TLS và bộ mã được chấp nhận. AWS duy trì sẵn nhiều chính sách; chọn một chính sách mới hơn sẽ loại bỏ những thứ đã lỗi thời (SSLv3, TLS 1.0, RC4, 3DES).

Ưu điểm lớn nhất: đây là thay đổi cấu hình, có hiệu lực ngay, không cần khởi động lại máy chủ nào và không đụng tới chứng chỉ.

Vì sao các phương án khác sai

  • C. Tạo security policy tuỳ chỉnh — không làm được với Application Load Balancer: ALB chỉ chọn được trong các chính sách dựng sẵn của AWS. (Chỉ Classic Load Balancer mới cho tạo chính sách tuỳ chỉnh.) Đây là bẫy chính vì nghe rất hợp lý.
  • A. Cấp lại chứng chỉ SSL cho mọi máy chủ web — lỗ hổng nằm ở giao thức và bộ mã, không nằm ở chứng chỉ; đổi chứng chỉ không sửa được gì.
  • B. Thêm nhiều chứng chỉ vào ELB — danh sách nhiều chứng chỉ dùng để phục vụ nhiều tên miền trên một listener, hoàn toàn không liên quan tới bảo mật giao thức.