Ngân hàng đề — AWS Certified Advanced Networking Specialty

Tìm thấy 352 câu.

Câu 31 Design and implement AWS networks

A business has a web application (store.mybusiness.com) running on an EC2 instance with a single elastic network interface in a subnet in a VPC. As part of the network re-architecture, the CTO at the company wants the web application to be moved to a different subnet in the same Availability Zone.

Which of the following solutions would you suggest to meet these requirements?

  1. A

    Change the subnet of the EC2 instance to the new subnet via AWS Management Console

  2. B

    Change the subnet of the EC2 instance to the new subnet via AWS CLI

  3. C

    Provision an elastic network interface in the new subnet. Attach this new interface to the existing EC2 instance and detach the old interface

  4. D

    Launch a new instance in the new subnet via an AMI created from the old instance. Direct traffic to this new instance using Route 53 and then terminate the old instance

Xem giải thích

Đáp án

D — Tạo AMI từ instance cũ, khởi chạy instance mới trong subnet mới, chuyển lưu lượng bằng Route 53 rồi huỷ instance cũ

Vì sao đúng

Điểm cốt lõi cần nhớ: không thể đổi subnet của một EC2 instance đang tồn tại. Subnet được gán lúc khởi chạy và gắn liền với network interface chính, không sửa được — kể cả bằng Console hay CLI.

Vì vậy cách duy nhất là tạo instance mới:

1. Tạo AMI từ instance cũ         (giữ nguyên hệ điều hành, ứng dụng, cấu hình)
2. Khởi chạy instance mới từ AMI  trong subnet mới
3. Trỏ store.mybusiness.com sang instance mới bằng Route 53
4. Huỷ instance cũ

Bước 3 quan trọng vì nó cho phép chuyển đổi êm: giảm TTL của bản ghi DNS trước, đổi bản ghi, chờ lưu lượng rút hết rồi mới huỷ máy cũ.

Vì sao các phương án khác sai

  • A và B. Đổi subnet qua Console hoặc CLI — không có thao tác đó; đây là hai bẫy chính.
  • C. Tạo network interface mới trong subnet mới rồi gắn vào instance cũ, gỡ interface cũ — không làm được: network interface chính (eth0) không thể tháo rời khỏi instance. Interface phụ thì gắn thêm được, nhưng nó cũng phải nằm trong cùng Availability Zone và cùng VPC, và không thay được vai trò của interface chính.
Câu 32 Design and implement for security and compliance

As Network Engineer, you have just set up AWS WAF. You now need to configure WAF for comprehensive logging to store logs in Amazon S3 buckets.

Which AWS services do you need to enable WAF comprehensive logging?

  1. A

    Amazon S3, AWS Lambda, AWS Systems Manager

  2. B

    AWS WAF, Kinesis Data Streams, Amazon S3

  3. C

    AWS Systems Manager, AWS WAF, AWS Lambda

  4. D

    AWS WAF, Kinesis Data Firehose, Amazon S3

Xem giải thích

Đáp án

D — AWS WAF, Kinesis Data Firehose, Amazon S3

Vì sao đúng

Ghi log đầy đủ của WAF đi theo đúng một đường ống, và Kinesis Data Firehose là bắt buộc ở giữa:

AWS WAF  ──▶  Kinesis Data Firehose  ──▶  Amazon S3
(sinh log     (gom lô, nén, chuyển     (lưu trữ, phân tích
 từng yêu cầu)  đổi định dạng)          bằng Athena)

Firehose không phải lựa chọn tuỳ ý — đó là đích đến duy nhất mà WAF hỗ trợ cho log chi tiết (ngoài CloudWatch Logs và S3 trực tiếp ở các bản sau). Nó lo phần gom lô và nén, vốn cần thiết vì WAF sinh một bản ghi cho mỗi yêu cầu web.

Một chi tiết dễ vấp khi cấu hình: luồng Firehose phải cùng Region với web ACL và tên phải bắt đầu bằng aws-waf-logs-.

Vì sao các phương án khác sai

  • B. WAF, Kinesis Data Streams, S3 — sai loại dịch vụ Kinesis. Data Streams là hàng đợi sự kiện cần bạn tự viết consumer để ghi ra S3; Firehose thì tự chuyển giao. Đây là bẫy tinh vi nhất của câu này.
  • A và C — dùng Lambda và Systems Manager để tự dựng đường ống; làm lại thứ Firehose đã có, và Systems Manager là dịch vụ quản lý cấu hình máy chủ, không liên quan tới log của WAF.
Câu 33 Manage, optimize, and troubleshoot the network

The networking team at a company wants to do a Simple AD deployment and use it for the company's Microsoft Exchange email server. The team is having issues finding the AD server.

What is the most probable root cause behind this issue?

  1. A

    You need to contact AWS to receive an MX record for the Microsoft Exchange email server

  2. B

    TLS is not implemented

  3. C

    The Network Access Control List is blocking the traffic to the email server

  4. D

    Simple AD does not support Microsoft Exchange

Xem giải thích

Đáp án

D — Simple AD không hỗ trợ Microsoft Exchange

Vì sao đúng

Đây là giới hạn về tính năng của sản phẩm, không phải lỗi cấu hình — nên không có cách nào chỉnh mạng để chữa.

Simple AD là bản triển khai Samba 4 tương thích Active Directory, cố ý làm gọn nhẹ và giá rẻ. Nó thiếu nhiều thứ mà Exchange bắt buộc phải có:

Tính năng Simple AD AWS Managed Microsoft AD
Mở rộng schema ❌ ✅
Quan hệ tin cậy (trust) ❌ ✅
PowerShell cho AD ❌ ✅
Hỗ trợ Microsoft Exchange ❌ ✅

Dòng đầu là lý do gốc: Exchange phải mở rộng schema của Active Directory khi cài đặt, mà Simple AD không cho làm điều đó.

Giải pháp đúng là chuyển sang AWS Directory Service for Microsoft Active Directory (Managed Microsoft AD), vốn là Active Directory thật của Microsoft.

Vì sao các phương án khác sai

  • C. NACL chặn lưu lượng và B. Chưa triển khai TLS — đều là lỗi cấu hình mạng; nếu đúng vậy thì sửa xong Exchange sẽ chạy, nhưng ở đây sửa gì cũng vô ích.
  • A. Phải liên hệ AWS để nhận bản ghi MX — bản ghi MX là chuyện DNS của tên miền, do bạn tự tạo trong Route 53; AWS không cấp phát gì cả.
Câu 34 Design and implement hybrid IT network architectures

The CTO at an e-commerce company is pursuing an IT re-engineering effort to migrate from multiple on-premises data centers to the AWS Cloud. The current on-premises data centers are in different locations and are inter-linked via a private fiber. Due to the unique constraints of the existing legacy applications, using NAT is not an option. During the migration period, many critical applications will need access to other applications deployed in both the on-premises data centers and AWS Cloud.

As an AWS Certified Networking Specialist, which of the following options would you suggest to set up a hybrid network architecture that is highly available and supports high bandwidth for a multi-Region deployment post-migration?

  1. A

    Set up multiple hardware VPN connections between AWS cloud and the on-premises data centers. Configure each subnet's traffic through different VPN connections for redundancy. Make sure that no VPC CIDR blocks overlap one another or the on-premises network

  2. B

    Set up multiple software VPN connections between AWS cloud and the on-premises data centers. Configure each subnet's traffic through different VPN connections for redundancy. Make sure that no VPC CIDR blocks overlap one another or the on-premises network

  3. C

    Set up a Direct Connect as the primary connection for all on-premises data centers with another VPN as a backup. Configure both connections to use the same virtual private gateway and BGP. Make sure that no VPC CIDR blocks overlap one another or the on-premises network

  4. D

    Set up a Direct Connect to each on-premises data center from different service providers and configure routing to failover to the other on-premises data center's Direct Connect in case one connection fails. Make sure that no VPC CIDR blocks overlap one another or the on-premises network

Xem giải thích

Đáp án

D — Thiết lập Direct Connect tới từng trung tâm dữ liệu, từ các nhà cung cấp dịch vụ khác nhau, và cấu hình định tuyến để chuyển dự phòng qua Direct Connect của trung tâm dữ liệu kia khi một kết nối hỏng

Vì sao đúng

Đề đặt bốn ràng buộc, và phương án D là cái duy nhất thoả cả bốn:

Yêu cầu Vì sao D đạt
Băng thông cao Direct Connect cho băng thông ổn định tới 100 Gbps
Tính sẵn sàng cao Hai kết nối ở hai địa điểm, từ hai nhà cung cấp khác nhau — không có điểm hỏng chung
Không dùng NAT Direct Connect dùng định tuyến IP riêng đầu cuối, không cần NAT
Đa Region sau di trú Direct Connect gateway nối được tới VPC ở nhiều Region

Chi tiết "từ các nhà cung cấp khác nhau" là phần quan trọng nhất và cũng hay bị bỏ qua: hai đường thuê của cùng một nhà mạng rất dễ đi chung một tuyến cáp hoặc chung một trạm, nên một sự cố vẫn cắt cả hai.

Vì sao các phương án khác sai

  • C. Một Direct Connect làm chính, VPN làm dự phòng — có dự phòng, nhưng khi VPN gánh thì băng thông sụt hẳn (VPN của AWS giới hạn khoảng 1,25 Gbps mỗi đường hầm) và độ trễ không đoán trước được vì đi qua Internet. Không đạt yêu cầu băng thông cao. Đây là phương án nhiễu chính.
  • A và B. Nhiều kết nối VPN (phần cứng hoặc phần mềm) — cùng nhược điểm về băng thông, và cách chia "mỗi subnet đi một VPN" là kiểu dự phòng giả: nó chia tải chứ không tạo dự phòng thật.
Câu 35 Design and implement for security and compliance

The networking team at a company has noticed issues with Quality of Service (QoS) in the traffic to the EC2 instances hosting a VOIP program. The team needs to inspect the network packets to determine if it is a programming error or a networking error.

As an AWS Certified Networking Specialist, which of the following solutions would you recommend for the given use case?

  1. A

    Provision another EC2 instance with an ENI added to act as a monitoring interface. Configure the port to promiscuous mode and sniff the traffic to analyze the packets. Direct the output of this single stream to an S3 bucket for further analysis

  2. B

    Configure traffic mirroring on the source EC2 instances hosting the VOIP program, set up a network monitoring program on a target EC2 instance and stream the logs to an S3 bucket for further analysis

  3. C

    Use VPC Flow Logs to inspect the network packets

  4. D

    Use CloudWatch to inspect the network packets

Xem giải thích

Đáp án

B — Bật traffic mirroring trên các instance nguồn, dựng chương trình giám sát mạng trên một instance đích, rồi đẩy log sang S3

Vì sao đúng

Yêu cầu của đề là soi từng gói tin để phân biệt lỗi lập trình với lỗi mạng. Muốn vậy phải có nội dung gói, không chỉ siêu dữ liệu.

VPC Traffic Mirroring là tính năng duy nhất trong AWS làm được điều đó: nó sao chép nguyên gói tin từ elastic network interface của instance nguồn và gửi tới đích để phân tích bằng công cụ như Wireshark, tcpdump hay Suricata.

Với bài toán chất lượng dịch vụ VOIP thì đây đúng là thứ cần: bạn đo được jitter, mất gói, thứ tự gói đến, và đọc được cả trường DSCP trong header IP để biết đánh dấu QoS có được giữ nguyên không.

Nó cũng lọc được theo giao thức và cổng, nên chỉ sao chép lưu lượng VOIP thay vì toàn bộ.

Vì sao các phương án khác sai

  • C. VPC Flow Logs — chỉ ghi siêu dữ liệu của luồng: nguồn, đích, cổng, số byte, chấp nhận hay từ chối. Nó không chứa nội dung gói, nên không chẩn đoán được vấn đề chất lượng thoại. Đây là phương án nhiễu chính.
  • D. CloudWatch — lưu chỉ số và log ứng dụng, không phải công cụ bắt gói.
  • A. Dựng một EC2 với ENI ở chế độ promiscuous để nghe lén — không hoạt động trên AWS: mạng ảo của AWS không hỗ trợ chế độ promiscuous, network interface chỉ nhận được lưu lượng gửi cho chính nó. Đây chính là lý do Traffic Mirroring ra đời.
Câu 36 Design and implement AWS networks

A health care company has two web applications and wants to run them in separate, isolated VPCs. The company is looking at using Elastic Load Balancing to distribute requests between application instances. The security and compliance team at the company has imposed the following restrictions:

  1. Inbound HTTP requests to the application must be routed through a centralized VPC

  2. Application VPCs must not be exposed to any other inbound traffic

  3. Application VPCs cannot be allowed to initiate any outbound connections

  4. Internet gateways must not be attached to the application VPCs

Which of the following solutions would you recommend to address these requirements?

  1. A

    Configure the applications behind private Application Load Balancers (ALBs) in separate VPCs. Set up a public Network Load Balancer (NLB) in the centralized VPC and point the target groups to the ALBs. Set up host-based routing to route application traffic to the corresponding target group through the NLB

  2. B

    Configure the applications behind private Network Load Balancers (NLBs) in separate VPCs. Set up VPC Peering between application VPCs and the centralized VPC. Set up a public Application Load Balancer (ALB) in the centralized VPC and point the target groups to the private DNS names of the NLBs. Set up host-based routing to route application traffic to the corresponding target group through the ALB

  3. C

    Configure the applications behind private Application Load Balancers (ALBs) in separate VPCs. Set up a public Network Load Balancer (NLB) in the centralized VPC and point the target groups to the private IP addresses of the ALBs. Set up host-based routing to route application traffic to the corresponding target group through the NLB

  4. D

    Configure the applications behind private Network Load Balancers (NLBs) in separate VPCs. Set up each NLB as an AWS PrivateLink endpoint service with associated VPC endpoints in the centralized VPC. Set up a public Application Load Balancer (ALB) in the centralized VPC and point the target groups to the private IP addresses of each endpoint. Set up host-based routing to route application traffic to the corresponding target group through the ALB

Xem giải thích

Đáp án

D — Đặt ứng dụng sau Network Load Balancer riêng tư ở từng VPC, biến mỗi NLB thành AWS PrivateLink endpoint service với VPC endpoint tương ứng trong VPC trung tâm, rồi dựng ALB công khai ở VPC trung tâm

Vì sao đúng

Bốn ràng buộc của đội bảo mật rất chặt, đặc biệt là hai cái cuối: VPC ứng dụng không được khởi tạo kết nối đi ra và không được gắn internet gateway.

PrivateLink là công nghệ duy nhất thoả hết:

Internet ──▶ ALB công khai (VPC trung tâm)
                   │
                   ▼  VPC endpoint  ──── PrivateLink ────▶ Endpoint service (NLB riêng tư)
                                                                    │
                                                                    ▼
                                                              Ứng dụng (VPC riêng)

Ba tính chất khiến nó vượt qua các ràng buộc:

  • Kết nối một chiều — VPC trung tâm khởi tạo, VPC ứng dụng chỉ nhận; ứng dụng không bao giờ gọi ra ngoài.
  • Không cần internet gateway, không cần peering — lưu lượng đi qua hạ tầng PrivateLink của AWS.
  • Không cần CIDR tương thích — PrivateLink hoạt động cả khi dải IP của hai VPC chồng lấn, điều mà peering không làm được.

Vì sao các phương án khác sai

  • A và C. NLB công khai ở VPC trung tâm trỏ target group tới ALB riêng tư ở VPC khác — NLB không nhắm được tới tài nguyên ở VPC khác nếu không có peering hoặc PrivateLink; và phương án C còn nói tới "định tuyến theo host" trên NLB, vốn là tính năng tầng 7 mà NLB không có.
  • B. NLB riêng tư kèm VPC peering — peering tạo kết nối hai chiều, vi phạm thẳng yêu cầu "VPC ứng dụng không được khởi tạo kết nối đi ra".
Câu 37 Design and implement AWS networks

An ecommerce company is migrating its legacy web application to the AWS Cloud. Since the application is complex and may take several months to refactor, the CTO at the company tasked the development team to build an ad-hoc solution of using CloudFront with a custom origin pointing to the SSL endpoint URL for the legacy web application until the replacement is ready and deployed. The ad-hoc solution has worked for several weeks, however, all browser connections recently began showing an HTTP 502 Bad Gateway error with the header "X-Cache: Error from CloudFront". Network monitoring services show that the HTTPS port 443 on the legacy web application is open and responding to requests.

Which of the following will you attribute as the likely cause of the error and what is the solution to address this issue?

  1. A

    The SSL certificate on the legacy web application server has expired. Reissue the SSL certificate on the web server that is signed by a globally recognized certificate authority (CA). Install the full certificate chain onto the legacy web application server

  2. B

    The SSL certificate on the CloudFront distribution has expired. Reissue the SSL certificate on the CloudFront distribution via the AWS Certificate Manager (ACM) in the us-east-1 Region

  3. C

    The SSL certificate on the legacy web application server has expired. Install a new self-signed certificate along with the full certificate chain onto the legacy web application server

  4. D

    The SSL certificate on the legacy web application server has expired. Reissue the SSL certificate on the web server via the AWS Certificate Manager (ACM) in the us-east-1 Region

Xem giải thích

Đáp án

A — Chứng chỉ SSL trên máy chủ ứng dụng cũ đã hết hạn. Cấp lại chứng chỉ do một CA được công nhận toàn cầu ký, và cài đầy đủ chuỗi chứng chỉ lên máy chủ đó

Vì sao đúng

Ba manh mối trong đề ghép lại chỉ ra một nguyên nhân:

  • HTTP 502 Bad Gateway kèm header X-Cache: Error from CloudFront — nghĩa là CloudFront không kết nối được tới origin, chứ không phải origin trả về lỗi.
  • Cổng 443 vẫn mở và vẫn phản hồi — nên vấn đề không nằm ở mạng, mà ở bắt tay TLS.
  • Đã chạy tốt vài tuần rồi mới hỏng — đúng dấu hiệu của thứ hết hạn theo thời gian.

CloudFront luôn kiểm tra chứng chỉ của custom origin, và nó chỉ chấp nhận chứng chỉ do một CA công cộng được tin cậy ký, kèm chuỗi chứng chỉ trung gian đầy đủ. Thiếu chuỗi cũng gây đúng lỗi 502 này, dù chứng chỉ còn hạn.

Vì sao các phương án khác sai

  • *C. Cài chứng chỉ tự ký — CloudFront từ chối chứng chỉ tự ký cho custom origin; lỗi 502 vẫn nguyên.
  • *D. Cấp lại chứng chỉ cho máy chủ web bằng ACM — không làm được: chứng chỉ công cộng của ACM không xuất được khoá riêng, nên không cài lên máy chủ tuỳ ý. ACM chỉ gắn được vào các dịch vụ tích hợp sẵn (CloudFront, ELB, API Gateway).
  • B. Chứng chỉ trên chính CloudFront hết hạn — nếu vậy thì trình duyệt sẽ báo lỗi chứng chỉ, không phải 502; và chứng chỉ ACM gắn vào CloudFront tự gia hạn.
Câu 38 Configure network integration with application services

An online training application uses CloudFront distribution to share their content stored on Amazon S3 buckets. The team has a requirement to privately share hundreds of documents with some of their customers who will have access to these documents for a pre-defined time. The duration for which the document is shared is not the same for all clients or all documents.

What is the optimal way to configure this requirement with the least effort?

  1. A

    Create a CloudFront signed URL using a canned policy

  2. B

    Configure CloudFront to forward all headers to your origin and based on header information, present the data after verification

  3. C

    Create a CloudFront signed URL using a custom policy

  4. D

    Configure CloudFront to forward cookies to your origin server for sharing the documents privately

Xem giải thích

Đáp án

*A — Tạo CloudFront signed URL bằng canned policy

Vì sao đúng

Chữ khoá của đề là "ít công sức nhất", và đây là chỗ phân biệt hai loại chính sách của signed URL:

Canned policy Custom policy
Tuỳ chỉnh được Chỉ thời điểm hết hạn Thời điểm bắt đầu, hết hạn, dải IP, ký tự đại diện cho đường dẫn
Câu lệnh chính sách Không cần đưa vào URL Phải mã hoá và nhúng vào URL
Độ dài URL Ngắn hơn Dài hơn
Dùng lại cho nhiều tệp Không Có — nhờ ký tự đại diện

Yêu cầu của đề chỉ có một biến duy nhất là thời hạn, khác nhau theo từng khách và từng tài liệu. Canned policy làm được đúng điều đó — mỗi URL mang một thời điểm hết hạn riêng — mà không phải dựng câu lệnh chính sách JSON cho từng lượt.

Vì sao các phương án khác sai

  • C. Custom policy — làm được, nhưng thừa: bạn phải soạn, mã hoá base64 và ký một câu lệnh chính sách cho mỗi URL, trong khi không dùng tới bất kỳ tính năng thêm nào của nó. Đề hỏi cách ít công nhất. Đây là phương án nhiễu chính.
  • B. Chuyển tiếp toàn bộ header về origin rồi xác thực — đẩy việc kiểm tra quyền về origin, phá luôn khả năng cache của CloudFront.
  • D. Chuyển tiếp cookie về origin — cookie chuyển tiếp khác hẳn signed cookie; chuyển tiếp cookie chỉ đưa chúng tới origin chứ không tự giới hạn truy cập.
Câu 39 Configure network integration with application services

An Elastic Load Balancer (ELB) is configured with an Auto Scaling Group (ASG) having a minimum of 4, a maximum of 10, and a desired value of 4 instances. The ASG cooldown and the termination policies are configured to the default values. Monitoring reports indicate a general usage requirement of 4 instances, while any traffic spikes result in an additional 7-8 instances. Customers have been complaining of request timeouts and partially loaded pages.

Which configuration change will you suggest as the first line of troubleshooting to fix this issue?

  1. A

    Configure connection draining on ELB

  2. B

    Enable Sticky Sessions on ELB

  3. C

    Configure termination policies on ASG to determine which instances it terminates first during scale-in events

  4. D

    Add a lifecycle hook on scale-out event to your ASG, making sure that the instance is fully ready before it starts receiving traffic

Xem giải thích

Đáp án

A — Bật connection draining trên ELB

Vì sao đúng

Triệu chứng trong đề — yêu cầu hết giờ chờ và trang tải dở — xuất hiện ở đúng thời điểm Auto Scaling thu nhỏ đội máy sau khi hết đợt tải cao.

Không có connection draining, ELB ngắt ngay các kết nối đang mở tới instance sắp bị huỷ. Yêu cầu đang xử lý dở bị cắt giữa chừng — và đó chính là "trang tải một phần".

Connection draining (trên ALB và NLB gọi là deregistration delay) sửa đúng chỗ đó: khi một instance chuyển sang trạng thái sắp gỡ, ELB ngừng gửi yêu cầu mới nhưng cho phép yêu cầu đang xử lý chạy xong trong khoảng thời gian bạn đặt (mặc định 300 giây).

Vì sao các phương án khác sai

  • D. Thêm lifecycle hook cho sự kiện mở rộng (scale-out) — giải quyết đầu thêm máy: bảo đảm instance sẵn sàng trước khi nhận lưu lượng. Nhưng triệu chứng ở đây xảy ra lúc thu nhỏ. Đây là phương án nhiễu chính, và cần lifecycle hook cho scale-in thì mới đúng hướng.
  • C. Cấu hình chính sách kết thúc của Auto Scaling — quyết định máy nào bị huỷ trước, không thay đổi việc kết nối bị cắt đột ngột.
  • B. Bật sticky session — gắn người dùng với một instance cố định; điều đó khiến vấn đề nặng thêm khi instance đó bị huỷ.
Câu 40 Chọn nhiều đáp án Design and implement hybrid IT network architectures

A company wants to establish an AWS Direct Connect link to connect the AWS Cloud with the internal corporate network. Using AWS Direct Connect would enable the company to deliver on its performance benchmark requirements including a three-second or less response time for sending small documents across the internal network. To facilitate this goal, the company wants to be able to resolve DNS queries for any resources in the on-premises network from the AWS VPC and also resolve any DNS queries for resources in the AWS VPC from the on-premises network.

As an AWS Certified Networking Specialist, which of the following solutions would you recommend for this use case? (Select two)

  1. A

    Create an inbound endpoint on Route 53 Resolver and then DNS resolvers on the on-premises network can forward DNS queries to Route 53 Resolver via this endpoint

  2. B

    Create an outbound endpoint on Route 53 Resolver and then Route 53 Resolver can conditionally forward queries to resolvers on the on-premises network via this endpoint

  3. C

    Create an outbound endpoint on Route 53 Resolver and then DNS resolvers on the on-premises network can forward DNS queries to Route 53 Resolver via this endpoint

  4. D

    Create a universal endpoint on Route 53 Resolver and then Route 53 Resolver can receive and forward queries to resolvers on the on-premises network via this endpoint

  5. E

    Create an inbound endpoint on Route 53 Resolver and then Route 53 Resolver can conditionally forward queries to resolvers on the on-premises network via this endpoint

Xem giải thích

Đáp án

A và B — inbound endpoint để mạng tại chỗ hỏi vào AWS, outbound endpoint để AWS hỏi ra mạng tại chỗ

Vì sao đúng

Route 53 Resolver có hai loại endpoint, và tên gọi đi theo hướng nhìn từ phía VPC:

Mạng tại chỗ ──truy vấn──▶ INBOUND endpoint ──▶ Route 53 Resolver   (giải tên trong AWS)

Route 53 Resolver ──chuyển tiếp có điều kiện──▶ OUTBOUND endpoint ──▶ DNS tại chỗ
                                                                       (giải tên nội bộ)
  • A. Inbound endpoint — tạo network interface trong VPC với địa chỉ IP mà máy chủ DNS tại chỗ trỏ tới. Nhờ đó mạng tại chỗ phân giải được tên của tài nguyên trong VPC.
  • B. Outbound endpoint — cho phép Route 53 Resolver chuyển tiếp có điều kiện những truy vấn thuộc miền nội bộ (ví dụ corp.local) sang máy chủ DNS tại chỗ.

Cần cả hai vì đề yêu cầu phân giải theo cả hai chiều.

Vì sao các phương án khác sai

  • C và E — mỗi câu gán nhầm hướng cho một loại endpoint: gọi outbound là nơi mạng tại chỗ gửi truy vấn vào, hoặc gọi inbound là nơi Route 53 chuyển tiếp ra. Đây là hai bẫy chính, và cách nhớ là: inbound = truy vấn đi VÀO AWS, outbound = truy vấn đi RA khỏi AWS.
  • D. "Universal endpoint" — không tồn tại; Route 53 Resolver chỉ có hai loại endpoint.