Ngân hàng đề — AWS Certified Advanced Networking Specialty

Tìm thấy 352 câu.

Câu 81 Design and implement for security and compliance

A retail company has set up an AWS Direct Connect connection which includes a private Virtual Interface (VIF) and a VPN connection to the on-premises data center. On the AWS side, the application environment is contained in a VPC and includes a virtual private gateway.

For traffic originating in the VPC, what is the order of BGP path selection from the MOST preferred to the LEAST preferred?

  1. A

    Longest prefix match, Static routes, Direct-Connect BGP routes, VPN BGP routes

  2. B

    Direct-Connect BGP routes, VPN BGP routes, Longest prefix match, Static routes

  3. C

    Static routes, Longest prefix match, Direct-Connect BGP routes, VPN BGP routes

  4. D

    Longest prefix match, Direct-Connect BGP routes, Static routes, VPN BGP routes

Xem giải thích

Đáp án

A — Longest prefix match → Tuyến tĩnh → Tuyến BGP của Direct Connect → Tuyến BGP của VPN

Vì sao đúng

Đây là thứ tự chọn đường đầy đủ cho lưu lượng xuất phát từ VPC, và điều quan trọng nhất là longest prefix match đứng trước mọi thứ khác:

Ưu tiên Tiêu chí Ghi chú
1 Longest prefix match Tuyến cụ thể hơn luôn thắng, bất kể nó thuộc loại gì
2 Tuyến tĩnh Bạn khai tay trong bảng định tuyến
3 BGP từ Direct Connect
4 BGP từ Site-to-Site VPN

Ba mức sau chỉ được xét khi prefix bằng nhau. Đây là chỗ nhiều người nhớ nhầm: họ thuộc thứ tự "tĩnh > Direct Connect > VPN" nhưng quên rằng một tuyến VPN với prefix /24 vẫn thắng một tuyến Direct Connect với prefix /16.

Hệ quả thực tế: nếu bạn định dựng mô hình Direct Connect chính và VPN dự phòng, phải bảo đảm cả hai quảng bá cùng một prefix; để VPN quảng bá prefix cụ thể hơn là vô tình biến nó thành đường chính.

Vì sao các phương án khác sai

  • D — đặt Direct Connect trên tuyến tĩnh; sai thứ tự hai mức giữa.
  • C — đặt tuyến tĩnh trên longest prefix match; sai ở tiêu chí quan trọng nhất.
  • B — bỏ longest prefix match xuống gần cuối, sai hẳn.
Câu 82
A company is planning to create a service that requires encryption in transit. The traffic must not be decrypted between the client and the backend of the service. The company will implement the service by using the gRPC protocol over TCP port 443. The service will scale up to thousands of simultaneous connections. The backend of the service will be hosted on an Amazon Elastic Kubernetes Service (Amazon EKS) duster with the Kubernetes Cluster Autoscaler and the Horizontal Pod Autoscaler configured. The company needs to use mutual TLS for two-way authentication between the client and the backend.
Which solution will meet these requirements?
  1. A Install the AWS Load Balancer Controller for Kubernetes. Using that controller, configure a Network Load Balancer with a TCP listener on port 443 to forward traffic to the IP addresses of the backend service Pods.
  2. B Install the AWS Load Balancer Controller for Kubernetes. Using that controller, configure an Application Load Balancer with an HTTPS listener on port 443 to forward traffic to the IP addresses of the backend service Pods.
  3. C Create a target group. Add the EKS managed node group's Auto Scaling group as a target Create an Application Load Balancer with an HTTPS listener on port 443 to forward traffic to the target group.
  4. D Create a target group. Add the EKS managed node group’s Auto Scaling group as a target. Create a Network Load Balancer with a TLS listener on port 443 to forward traffic to the target group.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh việc triển khai một dịch vụ trên Amazon EKS (Elastic Kubernetes Service) với các yêu cầu nghiêm ngặt về bảo mật và hiệu suất:

  • Encryption in transit: Dữ liệu phải được mã hóa trong quá trình truyền (TLS/mTLS).
  • Không decrypt giữa client và backend: Load balancer không được chấm dứt (terminate) TLS, mà phải passthrough traffic end-to-end để đảm bảo client và backend giao tiếp trực tiếp với mutual TLS (xác thực hai chiều).
  • gRPC protocol over TCP port 443: gRPC sử dụng HTTP/2 trên TCP 443, phù hợp với TLS passthrough (không dùng HTTP/HTTPS listener vì sẽ terminate TLS).
  • Scale lên thousands connections: Cần load balancer hỗ trợ high concurrency, low latency như NLB (Network Load Balancer).
  • Backend trên EKS với Cluster Autoscaler (CA) và Horizontal Pod Autoscaler (HPA): Pods động scale, nên load balancer phải target trực tiếp Pod IP (qua AWS Load Balancer Controller) để hỗ trợ dynamic scaling mà không phụ thuộc node instance.

Mục tiêu: Chọn giải pháp dùng mutual TLS cho two-way auth, passthrough TCP 443, và integrate tốt với EKS autoscaling. ✅ Kiến thức cập nhật 2026: AWS Load Balancer Controller (v2.7+) hỗ trợ NLB TCP passthrough cho gRPC/mTLS trên EKS, không terminate TLS (theo AWS EKS best practices).

✅ Đáp án đúng

Install the AWS Load Balancer Controller for Kubernetes. Using that controller, configure a Network Load Balancer with a TCP listener on port 443 to forward traffic to the IP addresses of the backend service Pods.

Lý do chọn đáp án này:

  • 🛠️ AWS Load Balancer Controller tự động provision NLB và target Pod IP trực tiếp (qua service.spec.type: LoadBalancer với annotations), hỗ trợ dynamic scaling của HPA/CA mà không cần đăng ký node ASG.
  • 📡 NLB với TCP listener port 443: Passthrough TCP traffic end-to-end, không decrypt/terminate TLS → client và backend Pods thực hiện mutual TLS trực tiếp.
  • 🚀 Hoàn hảo cho gRPC (HTTP/2 over TCP), scale thousands connections với low latency (<1ms), Zonal isolation.
  • Không dùng TLS/HTTPS listener để tránh termination.

📋 Giải thích tất cả các phương án

  • ✅ Install the AWS Load Balancer Controller for Kubernetes. Using that controller, configure a Network Load Balancer with a TCP listener on port 443 to forward traffic to the IP addresses of the backend service Pods.
    Giải thích: Như trên, đáp án đúng vì TCP passthrough đảm bảo end-to-end encryption và mTLS giữa client-backend. Hỗ trợ Pod IP dynamic với EKS autoscalers. ✅

  • ❌ Install the AWS Load Balancer Controller for Kubernetes. Using that controller, configure an Application Load Balancer with an HTTPS listener on port 443 to forward traffic to the IP addresses of the backend service Pods.
    Giải thích: ALB HTTPS listener terminate TLS tại LB (dùng cert từ ACM/secret), decrypt traffic rồi forward → vi phạm yêu cầu "không decrypt giữa client và backend". ALB không tối ưu cho gRPC raw TCP/high concurrency như NLB. ❌

  • ❌ Create a target group. Add the EKS managed node group's Auto Scaling group as a target Create an Application Load Balancer with an HTTPS listener on port 443 to forward traffic to the target group.
    Giải thích: Target node ASG (instance-level) thay vì Pod IP → không dynamic scale với HPA (Pods di chuyển giữa nodes gây mismatch). ALB HTTPS terminate TLS, decrypt traffic. Không dùng Load Balancer Controller, thủ công và kém linh hoạt với EKS. ❌

  • ❌ Create a target group. Add the EKS managed node group’s Auto Scaling group as a target. Create a Network Load Balancer with a TLS listener on port 443 to forward traffic to the target group.
    Giải thích: Target node ASG không hỗ trợ Pod-level scaling (HPA/CA). NLB TLS listener terminate TLS tại LB (dùng cert), re-encrypt đến backend → decrypt giữa client-backend, vi phạm yêu cầu end-to-end. Chỉ TCP listener mới passthrough. ❌

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Giải pháp đúng đảm bảo zero-downtime scaling và bảo mật tối ưu! 🚀

Câu 83
A company is deploying a new application in the AWS Cloud. The company wants a highly available web server that will sit behind an Elastic Load Balancer. The load balancer will route requests to multiple target groups based on the URL in the request. All traffic must use HTTPS. TLS processing must be offloaded to the load balancer. The web server must know the user’s IP address so that the company can keep accurate logs for security purposes.
Which solution will meet these requirements?
  1. A Deploy an Application Load Balancer with an HTTPS listener. Use path-based routing rules to forward the traffic to the correct target group. Include the X-Forwarded-For request header with traffic to the targets.
  2. B Deploy an Application Load Balancer with an HTTPS listener for each domain. Use host-based routing rules to forward the traffic to the correct target group for each domain. Include the X-Forwarded-For request header with traffic to the targets.
  3. C Deploy a Network Load Balancer with a TLS listener. Use path-based routing rules to forward the traffic to the correct target group. Configure client IP address preservation for traffic to the targets.
  4. D Deploy a Network Load Balancer with a TLS listener for each domain. Use host-based routing rules to forward the traffic to the correct target group for each domain. Configure client IP address preservation for traffic to the targets.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một công ty đang triển khai ứng dụng mới trên AWS Cloud, với các yêu cầu chính sau:

  • Web server highly available (có tính sẵn sàng cao) đặt sau một Elastic Load Balancer (ELB).
  • ELB phải route requests đến multiple target groups dựa trên URL trong request (tức là dựa trên đường dẫn/path của URL, ví dụ: /api/users → target group A, /api/orders → target group B).
  • Tất cả traffic phải dùng HTTPS, và TLS processing được offload (chuyển giao xử lý) cho load balancer (nghĩa là LB kết thúc kết nối TLS, targets có thể dùng HTTP).
  • Web server phải biết địa chỉ IP của user để ghi log chính xác cho mục đích bảo mật (vì LB sẽ thay thế IP nguồn bằng IP của LB, cần cơ chế bảo toàn IP gốc).

🛠️ Yêu cầu kỹ thuật cốt lõi: Cần LB hỗ trợ Layer 7 routing (dựa trên URL path), HTTPS/TLS termination, và bảo toàn client IP (qua header hoặc preservation). Đây là tình huống điển hình cho Application Load Balancer (ALB) vì khả năng content-based routing ở Layer 7.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Deploy an Application Load Balancer with an HTTPS listener. Use path-based routing rules to forward the traffic to the correct target group. Include the X-Forwarded-For request header with traffic to the targets.

Lý do chọn đáp án này (theo kiến thức AWS cập nhật đến 2026):

  • ALB với HTTPS listener: ALB (Layer 7) hỗ trợ listener HTTPS, offload TLS hoàn hảo (terminate TLS tại LB, forward HTTP đến targets).
  • Path-based routing rules: ALB hỗ trợ rules dựa trên URL path (ví dụ: if path is /api/* then forward to target group X), phù hợp chính xác với "route based on URL".
  • X-Forwarded-For header: ALB tự động thêm header này (X-Forwarded-For chứa client IP gốc), giúp web server (EC2 targets) biết IP user để log security. Đây là tính năng mặc định và có thể cấu hình explicitly.
  • Đáp án này đáp ứng tất cả yêu cầu, đảm bảo highly available (multi-AZ), scalable.

📘 Tài liệu tham khảo:

📋 Giải thích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Tôi đánh dấu ✅ cho đúng, ❌ cho sai, và giải thích lý do bằng tiếng Việt rõ ràng:

  • Deploy an Application Load Balancer with an HTTPS listener. Use path-based routing rules to forward the traffic to the correct target group. Include the X-Forwarded-For request header with traffic to the targets.
    ✅ Đúng hoàn toàn: Như đã giải thích ở trên. ALB hỗ trợ path-based routing chính xác cho URL path, HTTPS offload, và X-Forwarded-For bảo toàn client IP. Giải pháp tối ưu nhất.

  • Deploy an Application Load Balancer with an HTTPS listener for each domain. Use host-based routing rules to forward the traffic to the correct target group for each domain. Include the X-Forwarded-For request header with traffic to the targets.
    ❌ Sai: ALB hỗ trợ HTTPS listener (có thể multiple, nhưng không cần per domain), X-Forwarded-For OK. Tuy nhiên, host-based routing dựa trên Host header/domain (ví dụ: example.com vs api.example.com), KHÔNG dựa trên URL path. Câu hỏi yêu cầu route "based on the URL" (path), không phải domain. Không khớp yêu cầu.

  • Deploy a Network Load Balancer with a TLS listener. Use path-based routing rules to forward the traffic to the correct target group. Configure client IP address preservation for traffic to the targets.
    ❌ Sai: NLB (Layer 4) hỗ trợ TLS listener (offload TLS), và client IP preservation (giữ nguyên source IP). Nhưng NLB KHÔNG hỗ trợ path-based routing (chỉ TCP/UDP/TLS, không inspect HTTP URL path). Không thể route based on URL. Vi phạm yêu cầu cốt lõi.

  • Deploy a Network Load Balancer with a TLS listener for each domain. Use host-based routing rules to forward the traffic to the correct target group for each domain. Configure client IP address preservation for traffic to the targets.
    ❌ Sai: NLB hỗ trợ TLS listener (multiple OK), client IP preservation tốt. Nhưng NLB KHÔNG hỗ trợ host-based hoặc path-based routing (không Layer 7, không inspect Host header hay URL). Chỉ route based on IP/port. Không đáp ứng route based on URL/domain.

🧩 Tóm tắt so sánh: ALB là lựa chọn duy nhất hỗ trợ content-based routing (path-based) ở Layer 7 + X-Forwarded-For. NLB chỉ Layer 4, phù hợp low-latency nhưng thiếu routing rules phức tạp. Giải pháp này align với best practices AWS DOP-C02 (DevOps Professional 2024-2026).

Câu 84
A company has developed an application on AWS that will track inventory levels of vending machines and initiate the restocking process automatically. The company plans to integrate this application with vending machines and deploy the vending machines in several markets around the world. The application resides in a VPC in the us-east-1 Region. The application consists of an Amazon Elastic Container Service (Amazon ECS) cluster behind an Application Load Balancer (ALB). The communication from the vending machines to the application happens over HTTPS.
The company is planning to use an AWS Global Accelerator accelerator and configure static IP addresses of the accelerator in the vending machines for application endpoint access. The application must be accessible only through the accelerator and not through a direct connection over the internet to the ALB endpoint.
Which solution will meet these requirements?
  1. A Configure the ALB in a private subnet of the VPC. Attach an internet gateway without adding routes in the subnet route tables to point to the internet gateway. Configure the accelerator with endpoint groups that include the ALB endpoint. Configure the ALB’s security group to only allow inbound traffic from the internet on the ALB listener port.
  2. B Configure the ALB in a private subnet of the VPC. Configure the accelerator with endpoint groups that include the ALB endpoint. Configure the ALB's security group to only allow inbound traffic from the internet on the ALB listener port.
  3. C Configure the ALB in a public subnet of the VPAttach an internet gateway. Add routes in the subnet route tables to point to the internet gateway. Configure the accelerator with endpoint groups that include the ALB endpoint. Configure the ALB's security group to only allow inbound traffic from the accelerator's IP addresses on the ALB listener port.
  4. D Configure the ALB in a private subnet of the VPC. Attach an internet gateway. Add routes in the subnet route tables to point to the internet gateway. Configure the accelerator with endpoint groups that include the ALB endpoint. Configure the ALB's security group to only allow inbound traffic from the accelerator's IP addresses on the ALB listener port.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi xoay quanh việc triển khai một ứng dụng theo dõi hàng tồn kho cho máy bán hàng tự động (vending machines) trên AWS, sử dụng Amazon ECS sau Application Load Balancer (ALB) trong VPC tại region us-east-1. Ứng dụng nhận kết nối HTTPS từ các máy bán hàng toàn cầu. Công ty muốn sử dụng AWS Global Accelerator với static IP addresses được cấu hình cố định trên máy bán hàng để truy cập ứng dụng. Yêu cầu cốt lõi: Ứng dụng chỉ accessible qua Global Accelerator, không cho phép kết nối trực tiếp từ internet đến ALB endpoint (để tránh bypass accelerator, tăng bảo mật và hiệu suất).

Mục tiêu giải pháp:

  • Global Accelerator cung cấp anycast static IPs (2 IPv4/IPv6) làm entry point toàn cầu, route traffic tối ưu qua AWS edge locations đến ALB.
  • Ngăn direct access: Sử dụng network isolation (private subnet không route ra IGW) kết hợp security group (SG) phù hợp.
  • ALB phải là internet-facing để tương thích với Global Accelerator (theo docs AWS mới nhất 2024-2026), nhưng isolate ở layer mạng.

📘 Tài liệu tham khảo:

✅ Đáp án đúng

Phương án ĐÚNG là phương án đầu tiên (được đánh dấu [ĐÚNG] trong câu hỏi):

Configure the ALB in a private subnet of the VPC. Attach an internet gateway without adding routes in the subnet route tables to point to the internet gateway. Configure the accelerator with endpoint groups that include the ALB endpoint. Configure the ALB’s security group to only allow inbound traffic from the internet on the ALB listener port.

Lý do lựa chọn 🛠️:

  • Private subnet + IGW attached NHƯNG KHÔNG thêm route 0.0.0.0/0 → IGW trong RT: ALB không có public IP và không nhận direct inbound từ internet (isolate layer 3). Traffic direct đến ALB DNS sẽ fail.
  • Global Accelerator endpoint group chỉ định ALB: Traffic từ vending machines (static IPs của accelerator) → edge locations → AWS backbone → ALB private IP (internal routing, không qua public internet).
  • SG allow inbound from internet (0.0.0.0/0) trên listener port: Cần thiết vì traffic từ GA đến ALB "xuất hiện" như từ internet (source IPs động từ edge), nhưng network isolation đảm bảo chỉ GA mới đến được.
  • Giải pháp này chuẩn AWS best practice (2024-2026), đảm bảo ALB internet-facing tương thích GA mà vẫn secure 100%.

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng phương án một cách chi tiết (giữ nguyên text gốc tiếng Anh). Tôi đánh dấu ✅ đúng hoặc ❌ sai, kèm lý do bằng tiếng Việt rõ ràng:

  • ✅ Phương án ĐÚNG:

    Configure the ALB in a private subnet of the VPC. Attach an internet gateway without adding routes in the subnet route tables to point to the internet gateway. Configure the accelerator with endpoint groups that include the ALB endpoint. Configure the ALB’s security group to only allow inbound traffic from the internet on the ALB listener port.
    

    🛡️ Đúng vì: Kết hợp hoàn hảo network isolation (private subnet no route to IGW → block direct internet) + SG mở cho internet (cho phép GA traffic nội bộ). Đầy đủ các bước, khớp best practice AWS.

  • ❌ Phương án SAI:

    Configure the ALB in a private subnet of the VPC. Configure the accelerator with endpoint groups that include the ALB endpoint. Configure the ALB's security group to only allow inbound traffic from the internet on the ALB listener port.
    

    🚫 Sai vì: Thiếu attach IGW without routes to IGW. VPC có thể chưa có IGW hoặc subnet RT đã có route mặc định/public → ALB có nguy cơ nhận direct traffic nếu route tồn tại. Không isolate chắc chắn, vi phạm yêu cầu "only through accelerator".

  • ❌ Phương án SAI:

    Configure the ALB in a public subnet of the VPAttach an internet gateway. Add routes in the subnet route tables to point to the internet gateway. Configure the accelerator with endpoint groups that include the ALB endpoint. Configure the ALB's security group to only allow inbound traffic from the accelerator's IP addresses on the ALB listener port.
    

    🚫 Sai vì: Public subnet + routes to IGW → ALB fully public, dễ bypass (direct đến ALB DNS). SG chỉ allow accelerator IPs (2 static anycast IPs): Không work vì GA traffic đến ALB từ pool IPs động của edge locations (không chỉ 2 IPs), dẫn đến drop traffic hợp lệ. AWS không recommend whitelist như vậy.

  • ❌ Phương án SAI:

    Configure the ALB in a private subnet of the VPC. Attach an internet gateway. Add routes in the subnet route tables to point to the internet gateway. Configure the accelerator with endpoint groups that include the ALB endpoint. Configure the ALB's security group to only allow inbound traffic from the accelerator's IP addresses on the ALB listener port.
    

    🚫 Sai vì: Private subnet NHƯNG add routes to IGW → subnet trở thành public-like, ALB nhận direct internet traffic (bypass GA). SG chỉ accelerator IPs: Vẫn fail như trên do source IPs động. Không isolate đúng cách.

Kết luận 🎯: Giải pháp đúng tận dụng layer 3 isolation thay vì chỉ SG (dễ bypass và phức tạp whitelist). Áp dụng ngay cho production! Nếu cần lab, dùng AWS Free Tier với CloudFormation template từ AWS samples.

Câu 85
A global delivery company is modernizing its fleet management system. The company has several business units. Each business unit designs and maintains applications that are hosted in its own AWS account in separate application VPCs in the same AWS Region. Each business unit's applications are designed to get data from a central shared services VPC.
The company wants the network connectivity architecture to provide granular security controls. The architecture also must be able to scale as more business units consume data from the central shared services VPC in the future.
Which solution will meet these requirements in the MOST secure manner?
  1. A Create a central transit gateway. Create a VPC attachment to each application VPC. Provide full mesh connectivity between all the VPCs by using the transit gateway.
  2. B Create VPC peering connections between the central shared services VPC and each application VPC in each business unit's AWS account.
  3. C Create VPC endpoint services powered by AWS PrivateLink in the central shared services VPCreate VPC endpoints in each application VPC.
  4. D Create a central transit VPC with a VPN appliance from AWS Marketplace. Create a VPN attachment from each VPC to the transit VPC. Provide full mesh connectivity among all the VPCs.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả một công ty giao hàng toàn cầu đang hiện đại hóa hệ thống quản lý đội xe (fleet management system). Công ty có nhiều business units (đơn vị kinh doanh), mỗi đơn vị sở hữu AWS account riêng, triển khai ứng dụng trong VPC riêng (application VPCs) thuộc cùng một AWS Region. Các ứng dụng này cần lấy dữ liệu từ một VPC trung tâm chia sẻ dịch vụ (central shared services VPC).

Yêu cầu chính của kiến trúc mạng:

  • Cung cấp granular security controls (kiểm soát bảo mật chi tiết, tinh tế ở mức service hoặc resource).
  • Khả năng scale (mở rộng dễ dàng) khi thêm nhiều business units mới tiêu thụ dữ liệu từ VPC trung tâm.
  • Giải pháp phải là MOST secure (bảo mật cao nhất).

🛠️ Vấn đề cốt lõi: Cần kết nối mạng giữa VPC trung tâm (như hub) và nhiều VPC ứng dụng (như spokes) qua các account khác nhau, chỉ hướng một chiều (ứng dụng lấy data từ trung tâm, không cần full mesh giữa các VPC ứng dụng), ưu tiên bảo mật cao và scale tự động mà không expose dịch vụ ra ngoài.

📘 Kiến thức AWS cập nhật đến 2026: AWS khuyến nghị AWS PrivateLink cho việc chia sẻ dịch vụ private giữa VPCs cross-account trong cùng region, vì nó cung cấp endpoint services với policy-based access control granular, không cần mở route public/internet, và scale vô hạn mà không phụ thuộc peering hay transit đầy đủ (theo AWS Well-Architected Framework - Networking Pillar, phiên bản mới nhất 2024+).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create VPC endpoint services powered by AWS PrivateLink in the central shared services VPC. Create VPC endpoints in each application VPC.

Lý do:

  • Granular security: PrivateLink cho phép tạo VPC Endpoint Services (NLB-based) trong VPC trung tâm, với endpoint policy kiểm soát chi tiết quyền truy cập (IAM-like policies) đến từng service/resource cụ thể (ví dụ: chỉ cho phép đọc S3 bucket nào đó). Không expose service ra internet hoặc VPC peering.
  • Scale dễ dàng: Mỗi business unit chỉ cần tạo Interface VPC Endpoints (AWS PrivateLink endpoints) trong VPC của mình, tự động kết nối đến service trung tâm qua AWS backbone. Thêm business unit mới chỉ cần tạo endpoint mới, không cần thay đổi route table trung tâm hay peering từng cái.
  • MOST secure: Traffic luôn private (không qua internet/public IP), cross-account native, hỗ trợ encryption TLS, và audit qua CloudTrail. Phù hợp mô hình service producer-consumer (trung tâm là producer).
  • So với các lựa chọn khác, đây là cách ít expose nhất (không full mesh, không peering rủi ro leak route).

🔍 Giải thích chi tiết tất cả các phương án

  • Phương án 1: Create a central transit gateway. Create a VPC attachment to each application VPC. Provide full mesh connectivity between all the VPCs by using the transit gateway.
    ❌ Sai vì: Transit Gateway (TGW) lý tưởng cho hub-spoke topology scale lớn, nhưng không cung cấp granular security controls ở mức service. TGW chỉ route traffic full mesh (hoặc partial) giữa VPCs, nghĩa là các VPC ứng dụng có thể truy cập toàn bộ VPC trung tâm nếu route cho phép, dẫn đến rủi ro lateral movement. Không scale "granular" vì cần quản lý route/propagation tables phức tạp khi thêm VPC. Theo AWS docs (2026), TGW phù hợp connectivity lớn nhưng kém PrivateLink cho shared services private.
    Nguồn: AWS Transit Gateway.

  • Phương án 2: Create VPC peering connections between the central shared services VPC and each application VPC in each business unit's AWS account.
    ❌ Sai vì: VPC Peering hỗ trợ cross-account nhưng không scale tốt cho many-to-one (star topology): Phải tạo peering riêng từng VPC ứng dụng → quản lý thủ công nhiều peering, route tables leak route dễ dàng (non-transitive). Không granular (traffic full VPC-to-VPC, không limit service). Giới hạn 125 peering/VPC (2026 limit), và phức tạp khi thêm business units. Không phải MOST secure do rủi ro expose toàn bộ CIDR.
    Nguồn: AWS VPC Peering Limits.

  • Phương án 3 (Đúng): Create VPC endpoint services powered by AWS PrivateLink in the central shared services VPC. Create VPC endpoints in each application VPC.
    ✅ Đúng vì: Như giải thích ở trên. Đây là giải pháp AWS-native, serverless cho private service sharing, với zero-trust model qua policies. Scale tự động (hàng nghìn endpoints), traffic không rời AWS network, hỗ trợ Gateway Load Balancer cho advanced. Phù hợp chính xác yêu cầu "granular" và "MOST secure".
    Nguồn: AWS PrivateLink, Sharing Services via PrivateLink.

  • Phương án 4: Create a central transit VPC with a VPN appliance from AWS Marketplace. Create a VPN attachment from each VPC to the transit VPC. Provide full mesh connectivity among all the VPCs.
    ❌ Sai vì: Transit VPC + VPN appliance (như từ Marketplace) dùng cho hybrid/on-prem connectivity, không hiệu quả/secure cho intra-region VPC-to-VPC. VPN overhead cao (encryption/tunneling), full mesh không cần thiết (chỉ cần to central), và kém scale (phụ thuộc appliance throughput). Không granular (route-based), rủi ro single-point failure. AWS ưu tiên TGW/PrivateLink thay vì transit VPC legacy (deprecated pattern 2026).
    Nguồn: AWS Transit Solutions - khuyến nghị tránh VPN cho VPC internal.

🛡️ Kết luận: PrivateLink là lựa chọn tối ưu bảo mật và scale theo AWS best practices. Nếu triển khai thực tế, kết hợp với AWS RAM cho cross-account endpoint sharing!

Câu 86
A company uses a 4 Gbps AWS Direct Connect dedicated connection with a link aggregation group (LAG) bundle to connect to five VPCs that are deployed in the us-east-1 Region. Each VPC serves a different business unit and uses its own private VIF for connectivity to the on-premises environment. Users are reporting slowness when they access resources that are hosted on AWS.
A network engineer finds that there are sudden increases in throughput and that the Direct Connect connection becomes saturated at the same time for about an hour each business day. The company wants to know which business unit is causing the sudden increase in throughput. The network engineer must find out this information and implement a solution to resolve the problem.
Which solution will meet these requirements?
  1. A Review the Amazon CloudWatch metrics for VirtualInterfaceBpsEgress and VirtualInterfaceBpsIngress to determine which VIF is sending the highest throughput during the period in which slowness is observed. Create a new 10 Gbps dedicated connection. Shift traffic from the existing dedicated connection to the new dedicated connection.
  2. B Review the Amazon CloudWatch metrics for VirtualInterfaceBpsEgress and VirtualInterfaceBpsIngress to determine which VIF is sending the highest throughput during the period in which slowness is observed. Upgrade the bandwidth of the existing dedicated connection to 10 Gbps.
  3. C Review the Amazon CloudWatch metrics for ConnectionBpsIngress and ConnectionPpsEgress to determine which VIF is sending the highest throughput during the period in which slowness is observed. Upgrade the existing dedicated connection to a 5 Gbps hosted connection.
  4. D Review the Amazon CloudWatch metrics for ConnectionBpsIngress and ConnectionPpsEgress to determine which VIF is sending the highest throughput during the period in which slowness is observed. Create a new 10 Gbps dedicated connection. Shift traffic from the existing dedicated connection to the new dedicated connection.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi mô tả tình huống một công ty đang sử dụng kết nối AWS Direct Connect dedicated với băng thông 4 Gbps được cấu hình dưới dạng LAG bundle (nhóm liên kết tổng hợp) để kết nối từ on-premises đến 5 VPCs riêng biệt tại region us-east-1. Mỗi VPC đại diện cho một business unit khác nhau và sử dụng private Virtual Interface (VIF) riêng để kết nối.

Vấn đề chính:

  • Người dùng gặp slowness (chậm trễ) khi truy cập tài nguyên AWS.
  • Kỹ sư mạng phát hiện throughput tăng đột ngột, làm Direct Connect bị bão hòa (saturated) khoảng 1 giờ mỗi ngày làm việc.
  • Yêu cầu: Xác định business unit nào gây ra tăng throughput (tức là VPC/VIF nào), và triển khai giải pháp giải quyết vấn đề này một cách hiệu quả, tránh downtime và scale được traffic.

Mục tiêu là phân tích metrics để pinpoint nguyên nhân per VIF, sau đó tăng capacity cho kết nối Direct Connect. Kiến thức dựa trên AWS Direct Connect phiên bản mới nhất (2024-2026), hỗ trợ LAG lên đến 100Gbps/port, metrics CloudWatch chi tiết per VIF/Connection, và best practices từ AWS Well-Architected Framework cho Networking.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Review the Amazon CloudWatch metrics for VirtualInterfaceBpsEgress and VirtualInterfaceBpsIngress to determine which VIF is sending the highest throughput during the period in which slowness is observed. Create a new 10 Gbps dedicated connection. Shift traffic from the existing dedicated connection to the new dedicated connection.

Lý do 🛠️:

  • Xác định nguyên nhân: Sử dụng metrics VirtualInterfaceBpsEgress/Ingress (bytes/giây ra/vào per VIF) để pinpoint chính xác VIF nào (business unit nào) có throughput cao nhất trong khoảng thời gian slowness. Metrics Connection* chỉ aggregate toàn LAG, không phân biệt VIF.
  • Giải quyết: Tạo new 10 Gbps dedicated connection (scale từ 4Gbps lên 10Gbps) và shift traffic (di chuyển traffic dần dần, ví dụ qua BGP routing hoặc cutover) là best practice để tránh downtime. Với dedicated LAG, upgrade existing có thể yêu cầu reprovision port (downtime cao), trong khi new connection cho phép zero-downtime migration (AWS hỗ trợ LAG multi-connection).
  • Phù hợp high availability và scale đột ngột (tăng 1 giờ/ngày).

🔍 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn. Tôi giữ nguyên văn bản gốc tiếng Anh của phương án, chỉ giải thích bằng tiếng Việt với emoji đánh dấu đúng/sai.

  • ✅ Review the Amazon CloudWatch metrics for VirtualInterfaceBpsEgress and VirtualInterfaceBpsIngress to determine which VIF is sending the highest throughput during the period in which slowness is observed. Create a new 10 Gbps dedicated connection. Shift traffic from the existing dedicated connection to the new dedicated connection.
    Đúng hoàn toàn 🏆: Như giải thích trên, metrics VIF chính xác để identify business unit. Tạo new dedicated 10Gbps + shift traffic là giải pháp scale an toàn, hỗ trợ LAG bundle mới, tránh reprovision existing (có thể downtime). AWS khuyến nghị cho traffic bursty như thế này.

  • ❌ Review the Amazon CloudWatch metrics for VirtualInterfaceBpsEgress and VirtualInterfaceBpsIngress to determine which VIF is sending the highest throughput during the period in which slowness is observed. Upgrade the bandwidth of the existing dedicated connection to 10 Gbps.
    Sai một phần ⚠️: Phần review metrics VIF đúng (xác định được VIF cao nhất). Nhưng upgrade existing dedicated to 10Gbps không lý tưởng với LAG bundle 4Gbps – yêu cầu partner/AWS reprovision port speed (downtime ~ vài giờ), không hỗ trợ seamless scale như tạo new connection. Không giải quyết burst traffic một cách linh hoạt.

  • ❌ Review the Amazon CloudWatch metrics for ConnectionBpsIngress and ConnectionPpsEgress to determine which VIF is sending the highest throughput during the period in which slowness is observed. Upgrade the existing dedicated connection to a 5 Gbps hosted connection.
    Sai toàn bộ 🚫: Metrics ConnectionBpsIngress/PpsEgress chỉ aggregate toàn connection/LAG (không per VIF), nên không xác định được VIF/business unit nào. Upgrade sang 5Gbps hosted (thấp hơn 10Gbps, từ partner) không scale đủ (vẫn < hiện tại peak), và chuyển dedicated sang hosted phức tạp, không match yêu cầu saturation 4Gbps.

  • ❌ Review the Amazon CloudWatch metrics for ConnectionBpsIngress and ConnectionPpsEgress to determine which VIF is sending the highest throughput during the period in which slowness is observed. Create a new 10 Gbps dedicated connection. Shift traffic from the existing dedicated connection to the new dedicated connection.
    Sai một phần ⚠️: Phần tạo new 10Gbps dedicated + shift traffic đúng (scale tốt). Nhưng metrics ConnectionBpsIngress/PpsEgress aggregate toàn bộ, không thể pinpoint VIF cụ thể (chỉ biết tổng saturation, không biết business unit nào gây ra). PpsEgress là packets/giây, không trực tiếp chỉ throughput per VIF.

💡 Khuyến nghị bổ sung từ DevOps Engineer

  • Monitor liên tục: Thiết lập CloudWatch Alarms trên VirtualInterfaceBpsEgress > 80% capacity/VIF, kết hợp VPC Flow Logs để deep dive traffic patterns.
  • Scale tương lai: Sử dụng Transit Gateway + multiple DX connections cho HA, hoặc Direct Connect Gateway để broadcast routes.
  • Test: Simulate burst với AWS Fault Injection Simulator để verify migration.

Nếu cần lab hoặc demo code CDK/Terraform cho Direct Connect LAG, hãy cho tôi biết! 🚀

Câu 87 Chọn nhiều đáp án
A software-as-a-service (SaaS) provider hosts its solution on Amazon EC2 instances within a VPC in the AWS Cloud. All of the provider's customers also have their environments in the AWS Cloud.
A recent design meeting revealed that the customers have IP address overlap with the provider's AWS deployment. The customers have stated that they will not share their internal IP addresses and that they do not want to connect to the provider's SaaS service over the internet.
Which combination of steps is part of a solution that meets these requirements? (Choose two.)
  1. A Deploy the SaaS service endpoint behind a Network Load Balancer.
  2. B Configure an endpoint service, and grant the customers permission to create a connection to the endpoint service.
  3. C Deploy the SaaS service endpoint behind an Application Load Balancer.
  4. D Configure a VPC peering connection to the customer VPCs. Route traffic through NAT gateways.
  5. E Deploy an AWS Transit Gateway, and connect the SaaS VPC to it. Share the transit gateway with the customers. Configure routing on the transit gateway.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh một nhà cung cấp dịch vụ SaaS (Software-as-a-Service) đang triển khai giải pháp trên các instance Amazon EC2 trong một VPC trên AWS Cloud. Tất cả khách hàng của nhà cung cấp cũng có môi trường trên AWS Cloud. Vấn đề chính phát sinh từ cuộc họp thiết kế: Các khách hàng có địa chỉ IP chồng chéo (IP address overlap) với triển khai AWS của nhà cung cấp. Khách hàng không muốn chia sẻ địa chỉ IP nội bộ của họ và không muốn kết nối đến dịch vụ SaaS qua internet công khai.

Yêu cầu giải pháp: Tìm kết hợp 2 bước để đáp ứng các điều kiện này, đảm bảo kết nối private (không qua internet), tránh xung đột IP, và không cần chia sẻ thông tin IP nội bộ. Giải pháp phải tận dụng các tính năng AWS để kết nối VPC mà không cần peering trực tiếp hoặc routing phức tạp. 📘

Bối cảnh kỹ thuật (cập nhật đến 2026): Đây là tình huống điển hình sử dụng AWS PrivateLink (VPC Endpoint Services), cho phép khách hàng kết nối private đến dịch vụ SaaS mà không expose ra internet, không cần biết CIDR của nhau, và tránh overlap IP nhờ service endpoint abstraction. 🛠️

✅ Đáp án đúng (Chọn 2)

Hai lựa chọn đúng là sự kết hợp hoàn hảo để triển khai AWS PrivateLink:

  • Deploy the SaaS service endpoint behind a Network Load Balancer.
  • Configure an endpoint service, and grant the customers permission to create a connection to the endpoint service.

Lý do lựa chọn:

  • Network Load Balancer (NLB) là thành phần bắt buộc cho Endpoint Service trong PrivateLink (từ phiên bản AWS VPC 2016+, cập nhật ổn định đến 2026). NLB xử lý traffic TCP/UDP ở Layer 4, hỗ trợ kết nối private từ VPC khách hàng qua Interface VPC Endpoints mà không cần public IP hoặc NAT.
  • Endpoint Service (hay VPC Endpoint Service) được provider tạo trong VPC của mình, sau đó grant permission cho khách hàng (qua AWS Principal ARN) để họ tạo connection. Điều này cho phép khách hàng connect private DNS mà không biết CIDR provider, tránh overlap IP hoàn toàn.
  • Kết hợp này đảm bảo zero-trust connectivity, traffic luôn private trong AWS backbone, không qua internet, và scalable cho SaaS multi-tenant. ✅✅

📋 Phân tích tất cả các phương án (Đúng/Sai)

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá dựa trên yêu cầu (IP overlap, no internet, no IP sharing), sử dụng kiến thức AWS mới nhất (VPC, PrivateLink, Load Balancers - re:Post 2026).

  • ✅ Deploy the SaaS service endpoint behind a Network Load Balancer.
    Đúng: NLB là lựa chọn chuẩn cho AWS PrivateLink Endpoint Service (Layer 4 load balancing). Nó expose endpoint private cho khách hàng qua Interface Endpoint, hỗ trợ IP overlap vì traffic route qua AWS service name (không cần CIDR peering). Provider chỉ cần forward port (ví dụ TCP 443) đến NLB targets (EC2). Hoàn hảo cho SaaS high-throughput. 🛠️ (Kết hợp với endpoint service).

  • ✅ Configure an endpoint service, and grant the customers permission to create a connection to the endpoint service.
    Đúng: Đây là bước cốt lõi của VPC Endpoint Service (PrivateLink). Provider tạo service trong console/CLI (aws ec2 create-vpc-endpoint-service-configuration), associate với NLB, rồi accept connection requests từ khách hàng (qua RAM hoặc principal). Khách hàng tạo Interface VPC Endpoint trong VPC của họ để connect private, resolve DNS tự động (vpce-.vpce-svc-.vpce.amazonaws.com). Tránh hoàn toàn IP overlap và internet. 📘

  • ❌ Deploy the SaaS service endpoint behind an Application Load Balancer.
    Sai: Application Load Balancer (ALB) chỉ hỗ trợ HTTP/HTTPS Layer 7, KHÔNG được dùng cho PrivateLink Endpoint Service (AWS docs xác nhận chỉ NLB hoặc ALB với GWLB cho một số use-case, nhưng không chuẩn cho SaaS TCP/any-port như câu hỏi). ALB yêu cầu public subnet hoặc internet-facing, không giải quyết IP overlap private. Sử dụng ALB sẽ force traffic qua internet nếu không peering. 🚫

  • ❌ Configure a VPC peering connection to the customer VPCs. Route traffic through NAT gateways.
    Sai: VPC Peering thất bại ngay vì IP overlap (CIDR không được overlap theo AWS rule - peering rejected). NAT Gateway chỉ dùng cho outbound public internet (tăng latency/cost), không hỗ trợ private bidirectional cho SaaS. Khách hàng phải share CIDR (vi phạm yêu cầu), và peering không scalable cho multi-customer. ❌

  • ❌ Deploy an AWS Transit Gateway, and connect the SaaS VPC to it. Share the transit gateway with the customers. Configure routing on the transit gateway.
    Sai: Transit Gateway tốt cho hub-spoke multi-VPC, nhưng vẫn yêu cầu non-overlapping CIDR (routing conflict nếu overlap). Sharing qua RAM phức tạp, khách hàng vẫn cần biết/expose CIDR cho routing (vi phạm no IP sharing). Không private như PrivateLink, và overkill/costly cho SaaS simple endpoint. Không giải quyết core issue overlap. 🚫

📚 Tài liệu tham khảo (AWS Official - cập nhật 2026)

Câu 88 Chọn nhiều đáp án
A network engineer is designing the architecture for a healthcare company's workload that is moving to the AWS Cloud. All data to and from the on-premises environment must be encrypted in transit. All traffic also must be inspected in the cloud before the traffic is allowed to leave the cloud and travel to the on-premises environment or to the internet.
The company will expose components of the workload to the internet so that patients can reserve appointments. The architecture must secure these components and protect them against DDoS attacks. The architecture also must provide protection against financial liability for services that scale out during a DDoS event.
Which combination of steps should the network engineer take to meet all these requirements for the workload? (Choose three.)
  1. A Use Traffic Mirroring to copy all traffic to a fleet of traffic capture appliances.
  2. B Set up AWS WAF on all network components.
  3. C Configure an AWS Lambda function to create Deny rules in security groups to block malicious IP addresses.
  4. D Use AWS Direct Connect with MACsec support for connectivity to the cloud.
  5. E Use Gateway Load Balancers to insert third-party firewalls for inline traffic inspection.
  6. F Configure AWS Shield Advanced and ensure that it is configured on all public assets.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một kiến trúc mạng cho workload của công ty y tế chuyển sang AWS Cloud. Yêu cầu chính bao gồm:

  • Mã hóa dữ liệu in transit (mã hóa khi truyền) giữa on-premises và AWS Cloud.
  • Kiểm tra (inspection) tất cả traffic trong cloud trước khi cho phép traffic rời khỏi cloud đến on-premises hoặc internet.
  • Expose một số components ra internet để bệnh nhân đặt lịch hẹn, phải bảo mật chống DDoS và bảo vệ trách nhiệm tài chính nếu dịch vụ scale out trong DDoS attack (tránh chi phí tăng đột biến).

Đây là câu hỏi chọn 3 bước kết hợp để đáp ứng tất cả yêu cầu. Chủ đề tập trung vào network security, encryption, traffic inspection và DDoS protection trong AWS, sử dụng các dịch vụ networking cao cấp như Direct Connect, Load Balancers và Shield.

✅ Đáp án đúng (Chọn 3 phương án sau)

Các đáp án đúng là sự kết hợp hoàn hảo để đáp ứng đầy đủ yêu cầu:

  1. Use AWS Direct Connect with MACsec support for connectivity to the cloud.
  2. Use Gateway Load Balancers to insert third-party firewalls for inline traffic inspection.
  3. Configure AWS Shield Advanced and ensure that it is configured on all public assets.

Lý do lựa chọn 🛠️:

  • Kết hợp này đảm bảo mã hóa in transit (MACsec trên Direct Connect), inline inspection (Gateway Load Balancers với third-party firewalls), và DDoS protection với cost protection (Shield Advanced). Đây là best practice theo AWS Well-Architected Framework cho hybrid cloud security và high-scale workloads (cập nhật đến 2026, với MACsec là chuẩn Layer 2 encryption cho Direct Connect hosted connections).

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng phương án một cách đầy đủ, với ✅ đúng hoặc ❌ sai rõ ràng:

  • ❌ Use Traffic Mirroring to copy all traffic to a fleet of traffic capture appliances.
    Phương án này sai vì Traffic Mirroring chỉ copy traffic (mirror) để monitor hoặc capture, không phải inline inspection (kiểm tra trực tiếp và block realtime). Nó không chặn traffic độc hại trước khi rời cloud, chỉ dùng cho analysis sau sự kiện. Không đáp ứng yêu cầu "inspected in the cloud before leaving".

  • ❌ Set up AWS WAF on all network components.
    Phương án này sai vì AWS WAF (Web Application Firewall) chỉ bảo vệ HTTP/HTTPS traffic (Layer 7), không inspect tất cả traffic (bao gồm non-HTTP như TCP/UDP). Không phù hợp cho "all traffic" và không mã hóa in transit hay DDoS cho non-web components.

  • ❌ Configure an AWS Lambda function to create Deny rules in security groups to block malicious IP addresses.
    Phương án này sai vì Lambda + Security Groups chỉ block IP tĩnh, không scalable cho DDoS (hàng triệu IP thay đổi nhanh). Security Groups là stateful nhưng không phải tool inspection inline; dễ bị abuse và không có cost protection. Không phải best practice cho production DDoS mitigation.

  • ✅ Use AWS Direct Connect with MACsec support for connectivity to the cloud.
    Phương án này đúng vì AWS Direct Connect với MACsec (IEEE 802.1AE) cung cấp mã hóa Layer 2 in transit từ on-premises đến AWS, đảm bảo "all data encrypted in transit". Hỗ trợ trên hosted connections từ 2023, cập nhật 2026 với performance cao (100 Gbps+). Bắt buộc cho hybrid secure connectivity.

  • ✅ Use Gateway Load Balancers to insert third-party firewalls for inline traffic inspection.
    Phương án này đúng vì Gateway Load Balancers (GWLB) cho phép insert appliances ảo (như firewalls từ AWS Marketplace) vào traffic path để inline inspection (kiểm tra và block realtime) tất cả traffic trước khi rời cloud. Hoạt động ở Layer 3/4, scale tự động, lý tưởng cho "traffic inspected before leaving to on-premises or internet".

  • ✅ Configure AWS Shield Advanced and ensure that it is configured on all public assets.
    Phương án này đúng vì AWS Shield Advanced bảo vệ DDoS toàn diện (Layer 3/4/7) cho public assets (ELB, CloudFront, etc.), với cost protection (DDoS Cost Protection) tránh tài chính liability khi scale out. Phải config trên tất cả public endpoints expose cho internet (như ALB cho appointment booking).

📘 Tài liệu tham khảo (Cập nhật AWS 2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm chi tiết, hãy hỏi nhé!

Câu 89 Chọn nhiều đáp án
A retail company is running its service on AWS. The company’s architecture includes Application Load Balancers (ALBs) in public subnets. The ALB target groups are configured to send traffic to backend Amazon EC2 instances in private subnets. These backend EC2 instances can call externally hosted services over the internet by using a NAT gateway.
The company has noticed in its billing that NAT gateway usage has increased significantly. A network engineer needs to find out the source of this increased usage.
Which options can the network engineer use to investigate the traffic through the NAT gateway? (Choose two.)
  1. A Enable VPC flow logs on the NAT gateway's elastic network interface. Publish the logs to a log group in Amazon CloudWatch Logs. Use CloudWatch Logs Insights to query and analyze the logs.
  2. B Enable NAT gateway access logs. Publish the logs to a log group in Amazon CloudWatch Logs. Use CloudWatch Logs Insights to query and analyze the logs.
  3. C Configure Traffic Mirroring on the NAT gateway's elastic network interface. Send the traffic to an additional EC2 instance. Use tools such as tcpdump and Wireshark to query and analyze the mirrored traffic.
  4. D Enable VPC flow logs on the NAT gateway's elastic network interface. Publish the logs to an Amazon S3 bucket. Create a custom table for the S3 bucket in Amazon Athena to describe the log structure. Use Athena to query and analyze the logs.
  5. E Enable NAT gateway access logs. Publish the logs to an Amazon S3 bucket. Create a custom table for the S3 bucket in Amazon Athena to describe the log structure. Use Athena to query and analyze the logs.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một kiến trúc AWS điển hình của công ty bán lẻ:

  • Application Load Balancers (ALBs) nằm trong public subnets, nhận traffic từ internet.
  • Target groups của ALB forward traffic đến EC2 instances trong private subnets (không tiếp xúc trực tiếp internet).
  • Các EC2 backend gọi dịch vụ external qua internet bằng NAT Gateway (nằm trong public subnet để NAT traffic outbound).

📈 Vấn đề: Billing cho NAT Gateway tăng vọt do usage traffic outbound tăng cao. Network engineer cần điều tra nguồn gốc traffic qua NAT (ví dụ: EC2 instance nào đang generate nhiều traffic nhất?).
Yêu cầu chọn 2 options để investigate traffic qua NAT Gateway.
🛠️ Kiến thức cốt lõi (cập nhật 2026): NAT Gateway là managed service, không có metrics chi tiết về source IP/port của traffic. VPC Flow Logs là cách chính để capture flow-level data (src/dst IP, port, bytes, packets) trên Elastic Network Interface (ENI) của NAT. NAT không hỗ trợ access logs hay Traffic Mirroring trực tiếp.

✅ Đáp án đúng và lý do lựa chọn

Hai đáp án đúng là:

  1. Enable VPC flow logs on the NAT gateway's elastic network interface. Publish the logs to a log group in Amazon CloudWatch Logs. Use CloudWatch Logs Insights to query and analyze the logs.
  2. Enable VPC flow logs on the NAT gateway's elastic network interface. Publish the logs to an Amazon S3 bucket. Create a custom table for the S3 bucket in Amazon Athena to describe the log structure. Use Athena to query and analyze the logs.

Lý do chọn 🏆:

  • Cả hai đều sử dụng VPC Flow Logs trên ENI của NAT Gateway (ENI này nằm trong public subnet và capture toàn bộ outbound traffic từ private subnets). Logs bao gồm chi tiết như source IP (của EC2), destination IP/port, bytes transferred → dễ xác định EC2 nào gây tăng usage.
  • Publish to CloudWatch Logs + Insights: Query SQL-like nhanh chóng, real-time analysis.
  • Publish to S3 + Athena: Lưu trữ dài hạn, cost-effective cho big data, query SQL chuẩn.
    Đây là best practices từ AWS để troubleshoot NAT traffic (không có cách nào khác native).

📋 Phân tích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh:

  • ✅ Enable VPC flow logs on the NAT gateway's elastic network interface. Publish the logs to a log group in Amazon CloudWatch Logs. Use CloudWatch Logs Insights to query and analyze the logs.
    🟢 Đúng: VPC Flow Logs hỗ trợ trên ENI của NAT Gateway (tạo flow records cho ACCEPT/REJECT traffic). Publish đến CloudWatch Logs Insights cho phép query pattern như bytes > 1000000 để tìm high-usage flows. Lý tưởng cho real-time investigation.

  • ❌ Enable NAT gateway access logs. Publish the logs to a log group in Amazon CloudWatch Logs. Use CloudWatch Logs Insights to query and analyze the logs.
    🔴 Sai: NAT Gateway không hỗ trợ access logs (khác với ALB/NLB). Không có feature này trong AWS (cập nhật 2026). Chỉ có CloudWatch Metrics (tổng bytes, không chi tiết source).

  • ❌ Configure Traffic Mirroring on the NAT gateway's elastic network interface. Send the traffic to an additional EC2 instance. Use tools such as tcpdump and Wireshark to query and analyze the mirrored traffic.
    🔴 Sai: Traffic Mirroring chỉ hỗ trợ source là ENI của EC2 instances hoặc Transit Gateway ENI (không phải NAT Gateway ENI vì NAT là fully managed). NAT ENI không thể mirror packets. Phương án này không khả thi.

  • ✅ Enable VPC flow logs on the NAT gateway's elastic network interface. Publish the logs to an Amazon S3 bucket. Create a custom table for the S3 bucket in Amazon Athena to describe the log structure. Use Athena to query and analyze the logs.
    🟢 Đúng: Tương tự đáp án 1, nhưng lưu S3 cho phân tích lớn. Athena partition logs theo thời gian, query như SELECT srcAddr, dstAddr, bytes FROM nat_logs WHERE bytes > threshold để pinpoint source EC2.

  • ❌ Enable NAT gateway access logs. Publish the logs to an Amazon S3 bucket. Create a custom table for the S3 bucket in Amazon Athena to describe the log structure. Use Athena to query and analyze the logs.
    🔴 Sai: Lại sai vì NAT Gateway không có access logs. Feature không tồn tại, Athena setup vô ích.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

🛠️ Khuyến nghị thực tế: Kết hợp VPC Flow Logs + CloudWatch Contributor Insights để tự động detect top talkers!

Câu 90
A banking company is successfully operating its public mobile banking stack on AWS. The mobile banking stack is deployed in a VPC that includes private subnets and public subnets. The company is using IPv4 networking and has not deployed or supported IPv6 in the environment. The company has decided to adopt a third-party service provider's API and must integrate the API with the existing environment. The service provider’s API requires the use of IPv6.
A network engineer must turn on IPv6 connectivity for the existing workload that is deployed in a private subnet. The company does not want to permit IPv6 traffic from the public internet and mandates that the company's servers must initiate all IPv6 connectivity. The network engineer turns on IPv6 in the VPC and in the private subnets.
Which solution will meet these requirements?
  1. A Create an internet gateway and a NAT gateway in the VPC. Add a route to the existing subnet route tables to point IPv6 traffic to the NAT gateway.
  2. B Create an internet gateway and a NAT instance in the VPC. Add a route to the existing subnet route tables to point IPv6 traffic to the NAT instance.
  3. C Create an egress-only Internet gateway in the VPAdd a route to the existing subnet route tables to point IPv6 traffic to the egress-only internet gateway.
  4. D Create an egress-only internet gateway in the VPC. Configure a security group that denies all inbound traffic. Associate the security group with the egress-only internet gateway.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi xoay quanh một công ty ngân hàng đang vận hành stack mobile banking trên AWS trong một VPC sử dụng IPv4, với các private subnet và public subnet. Họ cần tích hợp API từ nhà cung cấp third-party yêu cầu IPv6, nhưng không muốn hỗ trợ IPv6 từ public internet và chỉ cho phép servers của công ty initiate (khởi tạo) tất cả kết nối IPv6 outbound (ra ngoài). Network engineer đã bật IPv6 cho VPC và private subnets.
📌 Yêu cầu chính: Bật IPv6 connectivity cho workload ở private subnet, đảm bảo chỉ egress (ra ngoài), không ingress (vào từ internet). Giải pháp phải tuân thủ nguyên tắc bảo mật cao (không expose IPv6 ra public).
🛠️ Bối cảnh AWS VPC IPv6 (cập nhật 2026): VPC hỗ trợ dual-stack IPv4/IPv6. Private subnets cần route IPv6 traffic (::/0) ra ngoài qua Egress-only Internet Gateway (EIGW) để chỉ cho phép outbound, chặn inbound từ internet. NAT Gateway chỉ hỗ trợ IPv4, không native IPv6.

✅ Đáp án đúng

Create an egress-only Internet gateway in the VPC. Add a route to the existing subnet route tables to point IPv6 traffic to the egress-only internet gateway.
Lý do chọn: Đây là giải pháp chuẩn AWS cho IPv6 egress-only từ private subnets. Egress-only Internet Gateway (EIGW) cho phép instances trong private subnet gửi IPv6 traffic ra internet (initiate connections), nhưng tự động chặn tất cả inbound IPv6 từ internet. Chỉ cần attach EIGW vào VPC, thêm route ::/0 -> eigw-xxxx vào route table của private subnet. Không cần IGW thông thường (vì IGW cho phép cả inbound/outbound).
📘 Nguồn: AWS VPC User Guide - Egress-only internet gateways (https://docs.aws.amazon.com/vpc/latest/userguide/egress-only-internet-gateway.html) và AWS re:Post (cập nhật 2025).

📋 Giải thích tất cả các phương án

  • ❌ [SAI] Create an internet gateway and a NAT gateway in the VPC. Add a route to the existing subnet route tables to point IPv6 traffic to the NAT gateway.
    Lý do sai: NAT Gateway không hỗ trợ IPv6 (chỉ IPv4 outbound). Internet Gateway (IGW) hỗ trợ IPv6 nhưng cho phép cả inbound/outbound, vi phạm yêu cầu "không permit IPv6 từ public internet". Route IPv6 đến NAT Gateway sẽ fail vì NAT không xử lý IPv6.

  • ❌ [SAI] Create an internet gateway and a NAT instance in the VPC. Add a route to the existing subnet route tables to point IPv6 traffic to the NAT instance.
    Lý do sai: NAT instance (EC2 tự quản) có thể custom hỗ trợ IPv6 qua software (như iptables), nhưng không phải giải pháp native AWS, phức tạp, không scalable và không đảm bảo chỉ egress (cần config thêm). IGW vẫn expose inbound IPv6, vi phạm yêu cầu bảo mật.

  • ✅ [ĐÚNG] Create an egress-only Internet gateway in the VPC. Add a route to the existing subnet route tables to point IPv6 traffic to the egress-only internet gateway.
    (Đã giải thích chi tiết ở phần đáp án đúng). Giải pháp tối ưu, đơn giản, bảo mật cao.

  • ❌ [SAI] Create an egress-only internet gateway in the VPC. Configure a security group that denies all inbound traffic. Associate the security group with the egress-only internet gateway.
    Lý do sai: Egress-only Internet Gateway không hỗ trợ attach security group (AWS không cho phép). EIGW đã tự động chặn inbound IPv6 rồi, không cần SG thêm. Lỗi này sẽ làm giải pháp fail khi implement.

🛠️ Lời khuyên thực hành: Sau khi deploy EIGW, test bằng ping6 google.com từ EC2 private subnet và kiểm tra CloudWatch metrics cho EIGW. Nếu cần inbound IPv6 (không áp dụng ở đây), dùng NAT64 hoặc public subnets với IGW.
📘 Tài liệu tham khảo bổ sung: AWS Well-Architected Framework - Networking Pillar (2026 ed.) và VPC FAQs IPv6 (https://aws.amazon.com/vpc/faqs/#IPv6).