Ngân hàng đề — AWS Certified Advanced Networking Specialty
Tìm thấy 352 câu.
To meet security requirements the company's accounts must have separate cloud infrastructure.
Which solution will meet these requirements MOST cost-effectively?
- A Create one Direct Connect gateway in us-east-1. Use AWS Resource Access Manager (AWS RAM) to share the Direct Connect gateway with each account. Create a transit VIF for Account Associate the four transit gateways in Account A to the Direct Connect gateway. Create a transit VIF for Account B. Associate the three transit gateways in Account В to the Direct Connect gateway.
- B Create one Direct Connect gateway in us-east-1 for Account A. Create a second Direct Connect gateway in us-east-1 for Account Create a transit VIF for Account A. Associate the four transit gateways in Account A to the Direct Connect gateway in Account A. Create a transit VIF for Account Associate the three transit gateways in Account В to the Direct Connect gateway in Account В.
- C Create one Direct Connect gateway in us-east-1. Use AWS Resource Access Manager (AWS RAM) to share the Direct Connect gateway with each account. Create a transit VIF for Account A. Associate the four transit gateways in Account A to the Direct Connect gateway. Order a new 10 Gbps Direct Connect dedicated connection for Account B. Create a transit VIF on the new Direct Connect connection for Account B. Associate the three transit gateways in Account В to the Direct Connect gateway.
- D Create one Direct Connect gateway in us-east-1 for Account A. Create a second Direct Connect gateway in us-east-1 for Account B. Create a transit VIF for Account A. Associate the four transit gateways in Account A to the Direct Connect gateway in Account A. Order a new 10 Gbps Direct Connect dedicated connection for Account В. Create a transit VIF on the new Direct Connect connection for Account В. Associate the three transit gateways in Account В to the Direct Connect gateway in Account В.
Xem giải thích
🧩 Phân tích chi tiết nội dung câu hỏi
Câu hỏi xoay quanh việc thiết lập kết nối hybrid cloud từ môi trường on-premises đến AWS Region us-east-1 sử dụng một kết nối AWS Direct Connect dedicated 10 Gbps duy nhất. Công ty có hai AWS accounts riêng biệt:
- Account A: Có Transit Gateways ở 4 Regions.
- Account B: Có Transit Gateways ở 3 Regions.
- Công ty không có kế hoạch mở rộng (không thêm Regions hoặc accounts).
Yêu cầu chính:
- Đảm bảo bảo mật: Hai accounts phải có hạ tầng cloud riêng biệt (separate cloud infrastructure), nghĩa là không chia sẻ tài nguyên chung giữa accounts để tránh rủi ro bảo mật và tuân thủ isolation.
- Giải pháp phải cost-effective nhất (tiết kiệm chi phí nhất), tận dụng kết nối Direct Connect hiện có mà không cần mua thêm tài nguyên đắt đỏ như kết nối mới.
Các khái niệm cốt lõi (dựa trên tài liệu AWS cập nhật 2024-2026):
- Direct Connect Gateway (DX Gateway): Cho phép một Virtual Interface (VIF) kết nối đến nhiều Transit Gateways/Virtual Private Gateways ở nhiều Regions/accounts.
- Transit VIF: Loại VIF dành riêng cho Transit Gateway, hỗ trợ kết nối high-throughput.
- Một kết nối Direct Connect dedicated 10 Gbps có thể host nhiều VIFs (bao gồm nhiều Transit VIFs) mà không cần port vật lý riêng.
- AWS RAM (Resource Access Manager): Dùng để share DX Gateway giữa accounts, nhưng có thể vi phạm yêu cầu "separate infrastructure".
- Chi phí chính: DX Gateway (~0.30 USD/giờ mỗi cái), Transit VIF (data transfer), kết nối mới 10 Gbps rất đắt (port fee hàng tháng cao).
📘 Tài liệu tham khảo:
- AWS Direct Connect Gateway (cập nhật 2025).
- Transit Gateway với Direct Connect.
- DX VIF limits (hỗ trợ multiple VIFs trên 1 connection).
✅ Đáp án đúng và lý do lựa chọn
Đáp án đúng:
Create one Direct Connect gateway in us-east-1 for Account A. Create a second Direct Connect gateway in us-east-1 for Account Create a transit VIF for Account A. Associate the four transit gateways in Account A to the Direct Connect gateway in Account A. Create a transit VIF for Account Associate the three transit gateways in Account В to the Direct Connect gateway in Account В.
Lý do chọn đáp án này 🛠️:
- ✅ Tách biệt hoàn toàn hạ tầng: Mỗi account có DX Gateway riêng (Account A: 4 TGs; Account B: 3 TGs), không share qua RAM → Đáp ứng "separate cloud infrastructure".
- ✅ Tiết kiệm chi phí nhất: Dùng chung 1 kết nối 10 Gbps, tạo 2 Transit VIFs riêng trên cùng connection (không giới hạn số VIFs trên port 10Gbps). Không cần connection mới (tiết kiệm hàng nghìn USD/tháng port fee).
- ✅ Hiệu suất cao: Transit VIF hỗ trợ full 10Gbps aggregate, route traffic riêng biệt qua DX Gateway tương ứng.
- ✅ Không mở rộng: Phù hợp quy mô cố định (7 TGs tổng).
- So với các option khác, đây là MOST cost-effectively vì tránh DX Gateway share (vi phạm security) và connection mới (đắt đỏ).
📋 Phân tích tất cả các phương án (giữ nguyên văn bản gốc)
-
Phương án 1 ❌ SAI
Create one Direct Connect gateway in us-east-1. Use AWS Resource Access Manager (AWS RAM) to share the Direct Connect gateway with each account. Create a transit VIF for Account Associate the four transit gateways in Account A to the Direct Connect gateway. Create a transit VIF for Account B. Associate the three transit gateways in Account В to the Direct Connect gateway.
Giải thích sai: Dùng 1 DX Gateway chung share qua RAM → Vi phạm yêu cầu separate cloud infrastructure (các accounts chia sẻ resource chung, rủi ro bảo mật cross-account). Mặc dù tiết kiệm (chỉ 1 DXG + 2 VIFs trên 1 connection), nhưng không đáp ứng security → Không phù hợp. -
Phương án 2 ✅ ĐÚNG (như phân tích trên)
Create one Direct Connect gateway in us-east-1 for Account A. Create a second Direct Connect gateway in us-east-1 for Account Create a transit VIF for Account A. Associate the four transit gateways in Account A to the Direct Connect gateway in Account A. Create a transit VIF for Account Associate the three transit gateways in Account В to the Direct Connect gateway in Account В.
Giải thích đúng: Hoàn hảo về isolation + chi phí (2 DXGs riêng, 2 VIFs trên 1 connection 10Gbps). Traffic Account A/B route riêng biệt, không giao thoa. -
Phương án 3 ❌ SAI
Create one Direct Connect gateway in us-east-1. Use AWS Resource Access Manager (AWS RAM) to share the Direct Connect gateway with each account. Create a transit VIF for Account A. Associate the four transit gateways in Account A to the Direct Connect gateway. Order a new 10 Gbps Direct Connect dedicated connection for Account B. Create a transit VIF on the new Direct Connect connection for Account B. Associate the three transit gateways in Account В to the Direct Connect gateway.
Giải thích sai: Share 1 DXG qua RAM → Vi phạm separate infrastructure. Thêm connection mới 10Gbps cho Account B → Rất đắt (port fee ~2,000-5,000 USD/tháng tùy provider), không cost-effective dù isolation cho connection. -
Phương án 4 ❌ SAI
Create one Direct Connect gateway in us-east-1 for Account A. Create a second Direct Connect gateway in us-east-1 for Account B. Create a transit VIF for Account A. Associate the four transit gateways in Account A to the Direct Connect gateway in Account A. Order a new 10 Gbps Direct Connect dedicated connection for Account В. Create a transit VIF on the new Direct Connect connection for Account В. Associate the three transit gateways in Account В to the Direct Connect gateway in Account В.
Giải thích sai: Isolation tốt (2 DXGs riêng), nhưng connection mới cho Account B → Chi phí cao gấp đôi (2 ports 10Gbps), thừa thãi vì 1 connection có thể host 2 VIFs. Không phải "MOST cost-effectively".
Kết luận 🎯: Phương án 2 là optimal, tận dụng multiple VIFs trên single DX connection (confirmed trong AWS limits 2025). Nếu implement, test BGP peering và route propagation qua Transit Gateway! 🚀
A network engineer needs to gather metrics for the latency between the existing. Regions and the new Region. The network engineer must gather metrics for at least the previous 30 days.
Which solution will meet these requirements?
- A Configure an AWS Network Access Analyzer Network Access Scope, and use the analysis to review the latency.
- B Set up AWS Network Manager Infrastructure Performance. Publish network performance metrics to Amazon CloudWatch.
- C Use an Amazon VPC Reachability Analyzer path to review the latency.
- D Set up VPC Flow Logs. Publish log metrics to Amazon CloudWatch.
Xem giải thích
🧩 Phân tích chi tiết nội dung câu hỏi
Câu hỏi tập trung vào một tình huống thực tế trong AWS: Một công ty đang chạy ứng dụng đa Region (nhiều AWS Regions) và đa Availability Zones (AZs). Họ muốn mở rộng sang một Region AWS mới, và độ trễ thấp (low latency) là yếu tố then chốt cho ứng dụng hoạt động tốt.
Nhiệm vụ của network engineer là thu thập metrics về độ trễ (latency) giữa các Region hiện tại và Region mới, với yêu cầu dữ liệu ít nhất 30 ngày trước đó (historical metrics).
🛠️ Yêu cầu chính cần giải quyết:
- Metrics cụ thể: Latency giữa các Region (inter-Region).
- Thời gian: Ít nhất 30 ngày lịch sử.
- Mục tiêu: Đánh giá hiệu suất mạng toàn cầu để đảm bảo low latency khi mở rộng.
Đây là chủ đề liên quan đến giám sát hiệu suất mạng global trong AWS (DevOps Engineer Professional level), sử dụng các công cụ monitoring network performance. Kiến thức cập nhật đến 2026: AWS Network Manager đã được nâng cấp mạnh mẽ với Infrastructure Performance để hỗ trợ metrics chi tiết inter-Region, bao gồm latency, packet loss, và throughput, với retention lên đến 400 ngày (dễ dàng cover 30 ngày).
📘 Tài liệu tham khảo:
- AWS Network Manager Documentation (Infrastructure Performance section).
- Amazon CloudWatch Metrics for Network Manager.
- AWS Well-Architected Framework: Networking Pillar (Reliability & Performance).
✅ Đáp án đúng và lý do lựa chọn
Đáp án đúng: Set up AWS Network Manager Infrastructure Performance. Publish network performance metrics to Amazon CloudWatch.
Lý do chi tiết 🟢:
- AWS Network Manager với tính năng Infrastructure Performance được thiết kế chuyên biệt để monitor hiệu suất mạng giữa các Region và Availability Zones, bao gồm latency metrics (độ trễ) một cách tự động và historical.
- Nó publish metrics trực tiếp đến CloudWatch, cho phép truy vấn dữ liệu lên đến 400 ngày (dễ dàng đáp ứng 30 ngày yêu cầu).
- Cách hoạt động: Tạo global network, thêm Regions, thiết lập probes (điểm đo) để thu thập latency giữa existing Regions và new Region. Metrics như
Latency,Jitter,PacketLossđược lưu trữ và visualize trong CloudWatch dashboard. - Phù hợp nhất: Low latency critical → Network Manager cung cấp insights real-time + historical cho multi-Region expansion. Đây là giải pháp recommended trong AWS best practices cho global networking (cập nhật 2025-2026).
📋 Giải thích tất cả các phương án (đúng/sai)
Dưới đây là phân tích từng phương án một cách chi tiết, giữ nguyên văn bản gốc tiếng Anh. Tôi đánh dấu ✅/❌ và giải thích rõ ràng bằng tiếng Việt dựa trên chức năng thực tế của từng dịch vụ.
-
Configure an AWS Network Access Analyzer Network Access Scope, and use the analysis to review the latency.
❌ Phương án SAI. AWS Network Access Analyzer (nay là Network Access Scope trong GuardDuty) dùng để phân tích quyền truy cập mạng và bảo mật (security findings như unauthorized access), KHÔNG hỗ trợ metrics latency hay historical performance. Nó chỉ kiểm tra reachability/security paths, không đo độ trễ thời gian thực hoặc 30 ngày. -
Set up AWS Network Manager Infrastructure Performance. Publish network performance metrics to Amazon CloudWatch.
✅ Phương án ĐÚNG (như đã giải thích ở trên). Hoàn hảo cho inter-Region latency monitoring với historical data và CloudWatch integration. -
Use an Amazon VPC Reachability Analyzer path to review the latency.
❌ Phương án SAI. VPC Reachability Analyzer chỉ kiểm tra khả năng kết nối (reachability) giữa hai endpoints trong cùng VPC hoặc giữa VPCs (intra/inter-VPC), KHÔNG đo latency và KHÔNG có historical metrics 30 ngày. Nó chỉ trả về "reachable/unreachable" snapshot, không phù hợp cho multi-Region performance. -
Set up VPC Flow Logs. Publish log metrics to Amazon CloudWatch.
❌ Phương án SAI. VPC Flow Logs ghi lại traffic metadata (source/dest IP, ports, bytes), có thể extract metrics như packet count qua CloudWatch Logs Insights. Tuy nhiên, KHÔNG được thiết kế cho inter-Region latency (chỉ intra-VPC/VPC peering), historical extraction phức tạp và không chính xác cho độ trễ (cần custom parsing), không hiệu quả cho 30 ngày multi-Region so với Network Manager.
🛠️ Tóm tắt khuyến nghị: Sử dụng AWS Network Manager để setup nhanh chóng, dashboard-ready, và scale global. Nếu cần demo, có thể test qua AWS Console → Network Manager → Global Networks → Infrastructure Performance! 🚀