Ngân hàng đề — AWS Certified Database Specialty

Tìm thấy 358 câu.

Câu 351
A marketing company is developing an application to track responses to email message campaigns. The company needs a database storage solution that is optimized to work with highly connected data. The database needs to limit connections and programmatic access to the data by using IAM policies.

Which solution will meet these requirements?
  1. A Amazon ElastiCache for Redis cluster
  2. B Amazon Aurora MySQL DB cluster
  3. C Amazon DynamoDB table
  4. D Amazon Neptune DB cluster
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi mô tả một công ty marketing đang xây dựng ứng dụng để theo dõi phản hồi từ các chiến dịch email. Họ cần một giải pháp lưu trữ cơ sở dữ liệu (database) được tối ưu hóa cho dữ liệu có tính kết nối cao (highly connected data), chẳng hạn như dữ liệu đồ thị (graph data) nơi các thực thể liên kết phức tạp với nhau (ví dụ: người dùng, email, phản hồi, tương tác). Ngoài ra, database phải hạn chế kết nối và truy cập lập trình (programmatic access) bằng cách sử dụng IAM policies để kiểm soát quyền truy cập an toàn mà không cần mật khẩu truyền thống.

Yêu cầu chính:

  • Tối ưu cho graph/highly connected data 🕸️ (dữ liệu có mối quan hệ phức tạp).
  • Hỗ trợ IAM cho authentication/authorization 🔒 (giới hạn kết nối qua IAM, không dùng username/password).

✅ Đáp án đúng: Amazon Neptune DB cluster

Lý do lựa chọn:

  • Amazon Neptune là dịch vụ graph database được quản lý hoàn toàn (fully managed) của AWS, được thiết kế đặc biệt để xử lý highly connected data với các mô hình đồ thị như Property Graph và RDF. Nó tối ưu hóa cho các truy vấn phức tạp trên mối quan hệ (relationships) như tracking tương tác email-user-campaign 🕸️.
  • Neptune hỗ trợ IAM authentication và fine-grained access control qua IAM policies, cho phép hạn chế kết nối và truy cập programmatic mà không cần credentials truyền thống. Điều này đáp ứng hoàn hảo yêu cầu "limit connections and programmatic access by using IAM policies" 🔒.
  • Theo cập nhật AWS mới nhất (2026), Neptune hỗ trợ IAM từ năm 2020 và tiếp tục cải tiến với IAM roles cho VPC endpoints, Gremlin/TinkerPop, và SPARQL.

🔍 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, với lý do đúng/sai dựa trên tính năng AWS mới nhất:

  • ❌ Amazon ElastiCache for Redis cluster
    Sai vì ElastiCache for Redis là in-memory data store dùng cho caching và session storage, không phải graph database tối ưu cho highly connected data. Nó hỗ trợ IAM auth cho Redis (từ 2021), nhưng không xử lý tốt dữ liệu đồ thị phức tạp như mối quan hệ user-email-response 🕸️. Phù hợp hơn cho key-value hoặc simple lists.

  • ❌ Amazon Aurora MySQL DB cluster
    Sai vì Aurora MySQL là RDBMS (Relational Database) tối ưu cho dữ liệu có cấu trúc bảng (tabular data), không hỗ trợ tốt highly connected data mà không cần join phức tạp kém hiệu suất. Aurora hỗ trợ IAM database authentication (từ 2019), nhưng không phải lựa chọn cho graph workloads – AWS khuyến nghị Neptune cho graph thay vì relational DB.

  • ❌ Amazon DynamoDB table
    Sai vì DynamoDB là NoSQL key-value và document database với mô hình single-table design, không được tối ưu hóa cho highly connected data (graph queries kém hiệu quả, cần modeling phức tạp). DynamoDB hỗ trợ IAM policies cho programmatic access rất tốt (fine-grained với resource policies), nhưng thiếu engine graph native như Neptune.

  • ✅ Amazon Neptune DB cluster
    Đúng hoàn toàn như đã giải thích ở trên: Graph-optimized + IAM support đầy đủ 🛠️.

📘 Tài liệu tham khảo

  • AWS Neptune Documentation: What is Amazon Neptune? – Xác nhận graph database cho highly connected data.
  • IAM Authentication for Neptune: Using IAM with Neptune – Hỗ trợ IAM policies để limit connections/programmatic access (cập nhật 2025).
  • AWS Well-Architected Framework - Database Lens: Khuyến nghị Neptune cho graph workloads (phiên bản mới nhất 2026).
  • DOP-C02 Exam Guide (AWS Certified DevOps Engineer Professional): Nhấn mạnh Neptune cho use cases như social networks/marketing graphs.

Hy vọng phân tích này giúp bạn nắm vững kiến thức AWS! 🚀 Nếu cần thêm ví dụ code hoặc lab, hãy hỏi nhé!

Câu 352 Chọn nhiều đáp án
A company uses a large, growing, and high performance on-premises Microsoft SQL Server instance with an Always On availability group cluster size of 120 TiB. The company uses a third-party backup product that requires system-level access to the databases. The company will continue to use this third-party backup product in the future.

The company wants to move the DB cluster to AWS with the least possible downtime and data loss. The company needs a 2 Gbps connection to sustain Always On asynchronous data replication between the company’s data center and AWS.

Which combination of actions should a database specialist take to meet these requirements? (Choose three.)
  1. A Establish an AWS Direct Connect hosted connection between the company’s data center and AWS.
  2. B Create an AWS Site-to-Site VPN connection between the company's data center and AWS over the internet.
  3. C Use AWS Database Migration Service (AWS DMS) to migrate the on-premises SQL Server databases to Amazon RDS for SQL Server. Configure Always On availability groups for SQL Server.
  4. D Deploy a new SQL Server Always On availability group DB cluster on Amazon EC2. Configure Always On distributed availability groups between the on-premises DB cluster and the AWS DB cluster. Fail over to the AWS DB cluster when it is time to migrate.
  5. E Grant system-level access to the third-party backup product to perform backups of the Amazon RDS for SQL Server DB instance.
  6. F Configure the third-party backup product to perform backups of the DB cluster on Amazon EC2.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một tình huống thực tế về việc di chuyển (migrate) cụm cơ sở dữ liệu Microsoft SQL Server Always On availability group từ môi trường on-premises sang AWS. Cụm này có kích thước lớn 120 TiB, hiệu suất cao và đang phát triển. Công ty sử dụng third-party backup product yêu cầu system-level access (quyền truy cập cấp hệ thống) vào cơ sở dữ liệu, và họ sẽ tiếp tục dùng công cụ này sau khi migrate.

Yêu cầu chính:

  • Downtime và data loss thấp nhất có thể: Nghĩa là cần phương pháp replication thời gian thực (Always On asynchronous replication) giữa on-premises và AWS.
  • Kết nối 2 Gbps ổn định để duy trì replication async.
  • Chọn 3 hành động kết hợp từ database specialist để đáp ứng.

Thách thức chính (🛠️):

  • Always On cần cấu hình distributed availability groups giữa on-premises và AWS.
  • Third-party backup không tương thích với RDS (vì RDS không cho system-level access).
  • Kết nối phải dedicated, ổn định cho bandwidth cao.
  • Không dùng dịch vụ managed như RDS vì hạn chế hỗ trợ Always On đầy đủ và backup tool.

Kiến thức AWS cập nhật đến 2026: SQL Server Always On trên EC2 hỗ trợ full features (bao gồm distributed AG), trong khi RDS for SQL Server chỉ hỗ trợ Multi-AZ/Read Replica, không hỗ trợ Always On Availability Groups native. Direct Connect là lựa chọn chuẩn cho hybrid replication cao tải.

✅ Đáp án đúng (Chọn 3)

Các đáp án đúng là sự kết hợp hoàn hảo để:

  • Đảm bảo kết nối dedicated 2 Gbps cho replication.
  • Triển khai Always On distributed AG trên EC2 để failover mượt mà (zero/low downtime).
  • Hỗ trợ third-party backup với system-level access trên EC2.
  1. Establish an AWS Direct Connect hosted connection between the company’s data center and AWS.
    ✅ Lý do: Direct Connect cung cấp kết nối private, dedicated với bandwidth ổn định lên đến 100 Gbps (dễ đạt 2 Gbps), low latency, không qua internet công cộng → lý tưởng cho async replication Always On, tránh packet loss của VPN.

  2. Deploy a new SQL Server Always On availability group DB cluster on Amazon EC2. Configure Always On distributed availability groups between the on-premises DB cluster and the AWS DB cluster. Fail over to the AWS DB cluster when it is time to migrate.
    ✅ Lý do: EC2 cho phép self-managed SQL Server với full Always On features, bao gồm distributed availability groups (DAG) giữa on-prem và AWS → replication async, failover tự động/minimal downtime. RDS không hỗ trợ.

  3. Configure the third-party backup product to perform backups of the DB cluster on Amazon EC2.
    ✅ Lý do: EC2 cung cấp system-level access (như on-prem), cho phép third-party tool cài đặt agent và backup trực tiếp. RDS bị hạn chế native backup/restore.

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng phương án một cách logic, dựa trên best practices AWS DevOps. Tôi giữ nguyên văn bản gốc tiếng Anh của phương án, chỉ giải thích bằng tiếng Việt với emoji đánh dấu đúng/sai.

  • Establish an AWS Direct Connect hosted connection between the company’s data center and AWS.
    ✅ Đúng: Hosted VIF trên Direct Connect đảm bảo kết nối dedicated 1-100 Gbps, SLA 99.99%, phù hợp replication 2 Gbps async mà không bị ảnh hưởng bởi internet biến động. (🛠️ Hành động cần thiết đầu tiên cho hybrid setup).

  • Create an AWS Site-to-Site VPN connection between the company's data center and AWS over the internet.
    ❌ Sai: VPN over internet chỉ đạt ~1.25 Gbps max (IPsec overhead), không ổn định cho high-throughput replication (packet loss, jitter cao). Không đáp ứng yêu cầu 2 Gbps sustained → Direct Connect là bắt buộc.

  • Use AWS Database Migration Service (AWS DMS) to migrate the on-premises SQL Server databases to Amazon RDS for SQL Server. Configure Always On availability groups for SQL Server.
    ❌ Sai: DMS phù hợp cho one-time/batch migration, không hỗ trợ live replication Always On async với low downtime. RDS for SQL Server không hỗ trợ Always On AG (chỉ Multi-AZ/Read Replica). Không thể config AG trên RDS → thất bại yêu cầu minimal data loss.

  • Deploy a new SQL Server Always On availability group DB cluster on Amazon EC2. Configure Always On distributed availability groups between the on-premises DB cluster and the AWS DB cluster. Fail over to the AWS DB cluster when it is time to migrate.
    ✅ Đúng: EC2 cho phép deploy full SQL Server Enterprise với Distributed AG (cross-site replication), failover seamless (RTO <1 phút). Hoàn hảo cho 120 TiB cluster lớn, scale với EBS/Instance lớn (như r6i.24xlarge).

  • Grant system-level access to the third-party backup product to perform backups of the Amazon RDS for SQL Server DB instance.
    ❌ Sai: RDS là fully managed, không cho system-level access (no OS-level privileges, no custom agent install). Third-party backup chỉ dùng qua native snapshot/ export → vi phạm yêu cầu tiếp tục dùng tool hiện tại.

  • Configure the third-party backup product to perform backups of the DB cluster on Amazon EC2.
    ✅ Đúng: Trên EC2, bạn có root access, dễ config agent third-party như Veeam/Commvault cho backup consistent (VSS-aware), giống on-prem. Tích hợp EBS snapshot cho large-scale 120 TiB.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Kết luận 💡: Kết hợp Direct Connect + EC2 Distributed AG + EC2 Backup là zero-downtime migration strategy chuẩn AWS cho enterprise SQL workloads! Nếu cần lab thực hành, dùng AWS Free Tier EC2 + Direct Connect Console. 🚀

Câu 353 Chọn nhiều đáp án
A company has an application environment that deploys Amazon Aurora PostgreSQL databases as part of its CI/CD process that uses AWS CloudFormation. The company's database administrator has received reports of performance issues from the resulting database but has no way to investigate the issues.

Which combination of changes must the database administrator make to the database deployment to automate the collection of performance data? (Choose two.)
  1. A Turn on Amazon DevOps Guru for the Aurora database resources in the CloudFormation template.
  2. B Turn on AWS CloudTrail in each AWS account.
  3. C Turn on and configure AWS Config for all Aurora PostgreSQL databases.
  4. D Update the CloudFormation template to enable Amazon CloudWatch monitoring on the Aurora PostgreSQL DB instances.
  5. E Update the CloudFormation template to turn on Performance Insights for Aurora PostgreSQL.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào một công ty có môi trường ứng dụng sử dụng CI/CD với AWS CloudFormation để triển khai Amazon Aurora PostgreSQL databases. Quản trị viên cơ sở dữ liệu (DBA) nhận được báo cáo về vấn đề hiệu suất (performance issues) từ các database được tạo ra, nhưng không có cách nào để điều tra (investigate). Nhiệm vụ là xác định kết hợp hai thay đổi cần thực hiện trên quy trình triển khai database để tự động hóa việc thu thập dữ liệu hiệu suất (automate the collection of performance data).

📌 Điểm chính:

  • Vấn đề là thiếu dữ liệu hiệu suất database (như metrics CPU, I/O, query chậm, waits...).
  • Giải pháp phải tích hợp vào CloudFormation template để tự động hóa trong CI/CD.
  • Không chỉ phân tích mà phải thu thập dữ liệu trước, giúp DBA investigate sau.
  • Chủ đề thuộc AWS RDS/Aurora monitoring, phiên bản mới nhất (2026): Aurora PostgreSQL hỗ trợ đầy đủ CloudWatch Enhanced Monitoring và Performance Insights (PI) cho performance schema data.

✅ Đáp án đúng (Chọn TWO)

Hai phương án đúng là:
Update the CloudFormation template to enable Amazon CloudWatch monitoring on the Aurora PostgreSQL DB instances.
Update the CloudFormation template to turn on Performance Insights for Aurora PostgreSQL.

Lý do lựa chọn 🛠️:

  • Amazon CloudWatch monitoring (Enhanced Monitoring): Tự động thu thập metrics chi tiết cấp OS (CPU, memory, processes, connections) và logs vào CloudWatch Logs/Metrics. Trong CloudFormation, set MonitoringInterval (>0 phút) và MonitoringRoleArn để enable. Đây là nền tảng cho performance data cơ bản.
  • Performance Insights: Tự động kích hoạt Performance Schema trên Aurora PostgreSQL, thu thập dữ liệu query-level (top SQL, waits, loads) trong 2 giờ retention miễn phí (lên 24 tháng trả phí). Enable qua CloudFormation với EnablePerformanceInsights=true và CloudwatchLogsExportConfiguration.
    Kết hợp hai cái này tự động hóa collection trong deployment, giúp DBA query CloudWatch/PI dashboard để investigate issues. Không cần tool ngoài như CloudTrail (audit API, không phải DB perf).

📋 Giải thích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá ✅ (Đúng) hoặc ❌ (Sai), với lý do cụ thể dựa trên docs AWS mới nhất (2026).

  • Turn on Amazon DevOps Guru for the Aurora database resources in the CloudFormation template.
    ❌ Sai: DevOps Guru dùng ML phát hiện anomalies trên CloudWatch metrics/logs, hỗ trợ RDS/Aurora nhưng không tự thu thập performance data (nó analyze data đã có). Enable trong CloudFormation không automate collection DB-specific perf data; cần CW/PI trước. Không giải quyết investigate DB issues trực tiếp.
    📘 Tham khảo: AWS DevOps Guru Docs – Phù hợp anomaly detection, không phải primary collection.

  • Turn on AWS CloudTrail in each AWS account.
    ❌ Sai: CloudTrail ghi log API calls (management/data events), hữu ích audit deployment CloudFormation nhưng không thu thập performance data của database (không có CPU/query metrics). Không giúp DBA investigate runtime perf issues trên Aurora.
    📘 Tham khảo: CloudTrail RDS Integration – Chỉ API logs, không perf.

  • Turn on and configure AWS Config for all Aurora PostgreSQL databases.
    ❌ Sai: AWS Config ghi snapshot cấu hình resources (như DB parameters), không thu thập performance data (metrics/queries). Có thể detect config changes gây perf issue gián tiếp, nhưng không automate DB runtime data collection.
    📘 Tham khảo: AWS Config RDS – Configuration compliance only.

  • Update the CloudFormation template to enable Amazon CloudWatch monitoring on the Aurora PostgreSQL DB instances.
    ✅ Đúng: Enable Enhanced Monitoring qua CloudFormation (DBInstanceClass=... với MonitoringInterval=1-60s, MonitoringRoleArn). Tự động push OS-level perf metrics (CPUUtilization, DatabaseConnections, IOWait...) vào CloudWatch, cơ sở để investigate issues. Luôn cần cho Aurora perf troubleshooting.
    📘 Tham khảo: RDS CloudWatch Monitoring & Aurora CFN.

  • Update the CloudFormation template to turn on Performance Insights for Aurora PostgreSQL.
    ✅ Đúng: Set EnablePerformanceInsights=true, PerformanceInsightsKMSKeyId (optional), CloudwatchLogsExportConfiguration=postgresql trong CFN template. Tự động collect query perf data (Active Sessions, Top Queries, Waits) từ Performance Schema, dashboard trực quan cho DBA investigate bottlenecks. Hỗ trợ Aurora PostgreSQL đầy đủ.
    📘 Tham khảo: Aurora Performance Insights & CFN Enable PI.

🏆 Kết luận & Lời khuyên DevOps

Kết hợp CloudWatch + Performance Insights là best practice cho RDS/Aurora perf monitoring trong CI/CD (DOP-C02 exam). Deploy qua CloudFormation đảm bảo tự động hóa. Test bằng stack update và check dashboard sau 15p. Nếu cần sâu hơn, tích hợp CloudWatch alarms hoặc RDS Proxy. Kiến thức dựa AWS re:Invent 2025 updates – không thay đổi core features. 🚀

Câu 354
A social media company recently launched a new feature that gives users the ability to share live feeds of their daily activities with their followers. The company has an Amazon RDS for MySQL DB instance that stores data about follower engagement.

After the new feature launched, the company noticed high CPU utilization and high database latency during reads and writes. The company wants to implement a solution that will identify the source of the high CPU utilization.

Which solution will meet these requirements with the LEAST administrative oversight?
  1. A Use Amazon DevOps Guru insights.
  2. B Use AWS CloudTrail.
  3. C Use Amazon CloudWatch Logs.
  4. D Use Amazon Aurora Database Activity Streams.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả một công ty mạng xã hội vừa ra mắt tính năng mới cho phép người dùng chia sẻ live feeds về hoạt động hàng ngày với followers. Dữ liệu về tương tác followers được lưu trữ trên Amazon RDS for MySQL DB instance.

Sau khi triển khai tính năng, công ty gặp vấn đề:

  • CPU utilization cao (sử dụng CPU cao).
  • Database latency cao cho cả reads (đọc) và writes (ghi).

Yêu cầu: Triển khai giải pháp để xác định nguồn gốc (identify the source) của high CPU utilization, với tiêu chí LEAST administrative oversight (ít nhất công việc quản trị thủ công, ưu tiên tự động hóa cao).

🛠️ Mục tiêu chính: Không chỉ monitor mà cần phân tích tự động nguồn gốc vấn đề CPU trên RDS MySQL, phù hợp với môi trường production có traffic đột biến từ feature mới. Giải pháp phải dựa trên công cụ AWS hiện đại (cập nhật đến 2026), tận dụng ML/AI để giảm thiểu can thiệp thủ công.

✅ Đáp án đúng: Use Amazon DevOps Guru insights

Lý do lựa chọn:

  • Amazon DevOps Guru là dịch vụ ML-powered (dựa trên Machine Learning) của AWS, tự động phát hiện anomalies (dấu hiệu bất thường) trên các tài nguyên AWS như RDS, bao gồm high CPU utilization và performance degradation.
  • Nó cung cấp insights chi tiết về nguồn gốc vấn đề, ví dụ: query không hiệu quả, connection spikes từ live feeds, hoặc misconfigurations gây CPU cao – hoàn toàn tự động, không cần thiết lập rule thủ công.
  • LEAST administrative oversight: Chỉ enable một lần (qua Console/CLI/API), DevOps Guru tự học từ metrics (CloudWatch), logs, và traces để đưa ra recommendations actionable mà không cần quản trị viên can thiệp liên tục.
  • Hỗ trợ RDS for MySQL đầy đủ (bao gồm cả non-Aurora), cập nhật 2026 với tích hợp sâu hơn GuardDuty và X-Ray cho root cause analysis.
  • Phù hợp hoàn hảo với scenario: Traffic live feeds gây burst CPU → DevOps Guru detect và pinpoint source nhanh chóng.

📘 Tài liệu tham khảo:

🔍 Giải thích tất cả các phương án

  • ✅ Use Amazon DevOps Guru insights
    Đúng vì: Như giải thích trên, dịch vụ này chuyên tự động identify root cause của high CPU qua ML insights, hỗ trợ RDS MySQL trực tiếp, và yêu cầu zero ongoing admin (chỉ enable là chạy). Ideal cho least oversight trong production.

  • ❌ Use AWS CloudTrail
    Sai vì: CloudTrail ghi lại API calls và events (như CreateDBInstance, ModifyDB), dùng cho security auditing chứ không monitor performance metrics như CPU utilization hay latency. Không phân tích được nguồn gốc CPU từ queries/follower data, cần manual query logs – high admin overhead.

  • ❌ Use Amazon CloudWatch Logs
    Sai vì: CloudWatch Logs lưu trữ log data từ RDS (error logs, slow query logs), hữu ích cho troubleshooting thủ công nhưng không tự động identify source CPU. Phải tự tạo dashboard, alarms, và query Insights Logs → yêu cầu admin cao, không dùng ML để pinpoint vấn đề từ live feeds traffic.

  • ❌ Use Amazon Aurora Database Activity Streams
    Sai vì: Đây là tính năng chỉ dành cho Amazon Aurora (MySQL/PostgreSQL), không hỗ trợ RDS for MySQL thông thường (câu hỏi chỉ định RDS, không phải Aurora). Nó stream query activity để audit (Kinesis/CloudWatch), nhưng tập trung vào security/compliance chứ không phải performance/CPU source analysis tự động. Cần setup Streams + consumer → admin overhead lớn, và không áp dụng được ở đây.

🛠️ Tóm tắt khuyến nghị: Enable DevOps Guru ngay trên RDS instance để có insights realtime, kết hợp CloudWatch metrics làm baseline. Nếu scale lớn, xem xét Performance Insights cho RDS (bổ sung, không thay thế).

📘 Nguồn bổ sung:

Câu 355
A company has more than 100 AWS accounts that need Amazon RDS instances. The company wants to build an automated solution to deploy the RDS instances with specific compliance parameters. The data does not need to be replicated. The company needs to create the databases within 1 day.

Which solution will meet these requirements in the MOST operationally efficient way?
  1. A Create RDS resources by using AWS CloudFormation. Share the CloudFormation template with each account.
  2. B Create an RDS snapshot. Share the snapshot with each account. Deploy the snapshot into each account.
  3. C Use AWS CloudFormation to create RDS instances in each account. Run AWS Database Migration Service (AWS DMS) replication to each of the created instances.
  4. D Create a script by using the AWS CLI to copy the RDS instance into the other accounts from a template account.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào việc xây dựng một giải pháp tự động hóa để triển khai các instance Amazon RDS trên hơn 100 tài khoản AWS của công ty. Các yêu cầu chính bao gồm:

  • Áp dụng tham số compliance cụ thể (như encryption, backup retention, parameter groups, security groups, v.v.) cho tất cả RDS instances.
  • Dữ liệu không cần replicate (nghĩa là chỉ cần tạo instance mới với cấu hình chuẩn, không copy dữ liệu từ instance hiện có).
  • Hoàn thành việc tạo databases trong 1 ngày (yêu cầu tốc độ cao, hiệu quả vận hành tối ưu).
  • Giải pháp phải MOST operationally efficient (hiệu quả vận hành cao nhất): Nghĩa là tự động, dễ scale, ít can thiệp thủ công, hỗ trợ multi-account, và tận dụng IaC (Infrastructure as Code) để đảm bảo tính nhất quán compliance.

Vấn đề cốt lõi là quản lý multi-account lớn (100+), cần deploy nhanh chóng mà không phụ thuộc vào replication dữ liệu. AWS khuyến nghị sử dụng CloudFormation cho IaC ở quy mô lớn, đặc biệt với StackSets cho Organizations (cập nhật 2024-2026). 📘 Tài liệu tham khảo: AWS CloudFormation StackSets, Amazon RDS Best Practices.

✅ Đáp án đúng: Create RDS resources by using AWS CloudFormation. Share the CloudFormation template with each account.

Lý do lựa chọn:

  • CloudFormation là công cụ IaC chuẩn của AWS, cho phép định nghĩa toàn bộ cấu hình RDS (engines, instance class, storage, VPC, security groups, parameter groups, tags compliance) trong một template YAML/JSON duy nhất.
  • Share template: Upload template lên S3 bucket cross-account (hoặc dùng StackSets với AWS Organizations để deploy tự động cross 100+ accounts chỉ trong vài giờ).
  • Hiệu quả cao nhất: Deploy parallel (song song) trên tất cả accounts, hoàn thành trong 1 ngày dễ dàng. Không cần dữ liệu replicate, chỉ tạo instance mới với params chuẩn. Tái sử dụng template đảm bảo compliance nhất quán, dễ audit/update.
  • So với các option khác, đây là least effort, most scalable (cập nhật 2026: CloudFormation hỗ trợ Drift Detection cho compliance check tự động). 🛠️ Ưu điểm: Provisioning nhanh (RDS tạo trong 10-30 phút/account), no data copy overhead.

📋 Phân tích chi tiết tất cả các phương án

  • ✅ Create RDS resources by using AWS CloudFormation. Share the CloudFormation template with each account.
    Đúng vì: Như giải thích trên, đây là cách tối ưu vận hành nhất cho multi-account. Template share qua S3 public/cross-account hoặc StackSets (deploy 1 lần cho toàn Organizations). Không cần replication, chỉ định nghĩa params compliance trong template. Hoàn thành <1 ngày với parallel execution. Hỗ trợ versioning, rollback tự động. 📘 Nguồn: AWS Well-Architected Framework - Operational Excellence Pillar.

  • ❌ Create an RDS snapshot. Share the snapshot with each account. Deploy the snapshot into each account.
    Sai vì: Snapshot dùng để restore dữ liệu, nhưng câu hỏi nhấn mạnh "data does not need to be replicated" (không cần data). Tạo snapshot từ instance mẫu vẫn tốn thời gian copy data (dù share cross-account được từ 2022), và restore 100+ instances sequential sẽ vượt 1 ngày. Không linh hoạt cho compliance params custom (phải chỉnh sau restore). Không phải IaC, khó scale/audit. 🧩 Vấn đề: Overhead không cần thiết, kém efficient.

  • ❌ Use AWS CloudFormation to create RDS instances in each account. Run AWS Database Migration Service (AWS DMS) replication to each of the created instances.
    Sai vì: DMS dùng cho replication dữ liệu ongoing/migration, nhưng không cần replicate data. Tạo CloudFormation rồi DMS sẽ double overhead: (1) Tạo empty instances (tốt), nhưng (2) DMS setup endpoints, tasks cho 100+ accounts tốn hàng giờ/ngày, chi phí cao (DMS instance hours). Không complete trong 1 ngày, vi phạm yêu cầu. DMS phù hợp full/CDC migration, không phải compliance-only. 📘 Nguồn: AWS DMS Limits - Không efficient cho no-data case.

  • ❌ Create a script by using the AWS CLI to copy the RDS instance into the other accounts from a template account.
    Sai vì: CLI script chỉ là imperative scripting, không phải IaC. Copy RDS cross-account không trực tiếp hỗ trợ (phải snapshot + restore thủ công), lặp lại 100+ lần sequential → tốn >1 ngày, dễ lỗi (auth, params mismatch). Không đảm bảo compliance nhất quán (script brittle, no drift detection). Kém scalable so với CloudFormation. 🛠️ Vấn đề: High operational toil, không khuyến nghị cho DevOps (AWS Shift Left IaC). 📘 Nguồn: AWS CLI RDS commands thiếu cross-account copy native.

Câu 356
A database specialist needs to reduce the cost of an application's database. The database is running on a Multi-AZ deployment of an Amazon RDS for Microsoft SQL Server DB instance. The application requires the database to support stored procedures, SQL Server Wire Protocol (TDS), and T-SQL. The database must also be highly available. The database specialist is using AWS Database Migration Service (AWS DMS) to migrate the database to a new data store.

Which solution will reduce the cost of the database with the LEAST effort?
  1. A Use AWS Database Migration Service (DMS) to migrate to an RDS for MySQL Multi-AZ database. Update the application code to use the features of MySQL that correspond to SQL Server. Update the application to use the MySQL port.
  2. B Use AWS Database Migration Service (DMS) to migrate to an RDS for PostgreSQL Multi-AZ database. Turn on the SQL_COMPAT optional extension within the database to allow the required features. Update the application to use the PostgreSQL port.
  3. C Use AWS Database Migration Service (DMS) to migrate to an RDS for SQL Server Single-AZ database. Update the application to use the new database endpoint.
  4. D Use AWS Database Migration Service (DMS) to migrate the database to Amazon Aurora PostgreSQL. Turn on Babelfish for Aurora PostgreSQL. Update the application to use the Babelfish TDS port.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc giảm chi phí cho một cơ sở dữ liệu ứng dụng đang chạy trên Amazon RDS for Microsoft SQL Server với triển khai Multi-AZ (đảm bảo tính sẵn sàng cao - high availability). Ứng dụng yêu cầu database phải hỗ trợ:

  • Stored procedures (thủ tục lưu trữ).
  • SQL Server Wire Protocol (TDS) (giao thức kết nối chuẩn của SQL Server).
  • T-SQL (ngôn ngữ truy vấn của SQL Server).

Database phải giữ tính sẵn sàng cao (highly available). Chuyên gia database đang sử dụng AWS Database Migration Service (AWS DMS) để di chuyển (migrate) sang một data store mới.
Mục tiêu chính: Giải pháp giảm chi phí tối đa với ít nỗ lực nhất (LEAST effort), nghĩa là ưu tiên không thay đổi lớn code ứng dụng, giữ nguyên các tính năng SQL Server, và đảm bảo HA.
🛠️ Bối cảnh AWS mới nhất (2026): RDS SQL Server Multi-AZ đắt đỏ do license Microsoft. Cần migrate sang engine rẻ hơn như open-source (PostgreSQL, MySQL) nhưng phải tương thích TDS/T-SQL để ít chỉnh sửa app. Aurora là lựa chọn tối ưu vì chi phí thấp hơn ~60-70% so với RDS SQL Server, hỗ trợ DMS full-load/CDC.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use AWS Database Migration Service (DMS) to migrate the database to Amazon Aurora PostgreSQL. Turn on Babelfish for Aurora PostgreSQL. Update the application to use the Babelfish TDS port.

Lý do:

  • Giảm chi phí cao nhất: Aurora PostgreSQL rẻ hơn RDS SQL Server Multi-AZ (không license Microsoft, serverless option tiết kiệm 40-90% idle time). Hỗ trợ Multi-AZ/HA native.
  • Ít nỗ lực nhất (LEAST effort): Babelfish (extension miễn phí trên Aurora PG 13+) cho phép chạy T-SQL, stored procedures, TDS protocol gần như nguyên bản SQL Server. Chỉ cần bật Babelfish, migrate bằng DMS (hỗ trợ SQL Server → Aurora PG với Babelfish), và update endpoint/port TDS (1433) – app hầu như không cần rewrite code.
  • Đầy đủ yêu cầu: Giữ HA (Aurora replicas), tương thích 90%+ SQL Server features (cập nhật 2026: hỗ trợ advanced T-SQL như CTE, JSON).
  • So với các option khác, không cần rewrite app lớn, migrate suôn sẻ.

🔍 Giải thích tất cả các phương án (đúng/sai)

  • ❌ Phương án SAI: Use AWS Database Migration Service (DMS) to migrate to an RDS for MySQL Multi-AZ database. Update the application code to use the features of MySQL that correspond to SQL Server. Update the application to use the MySQL port.
    Lý do sai: MySQL không hỗ trợ native TDS/T-SQL/stored procedures SQL Server (dùng MySQL dialect khác biệt lớn). Phải rewrite toàn bộ code app (stored proc → MySQL proc, T-SQL → PL/SQL), nỗ lực cao (vi phạm LEAST effort). DMS hỗ trợ migrate nhưng schema/query không tương thích tự động. Chi phí giảm nhưng không đáng so với effort. MySQL Multi-AZ HA ok nhưng không optimal.

  • ❌ Phương án SAI: Use AWS Database Migration Service (DMS) to migrate to an RDS for PostgreSQL Multi-AZ database. Turn on the SQL_COMPAT optional extension within the database to allow the required features. Update the application to use the PostgreSQL port.
    Lý do sai: PostgreSQL không có extension SQL_COMPAT hỗ trợ TDS/T-SQL (sai thông tin – PG dùng PL/pgSQL, port 5432). DMS migrate được nhưng phải rewrite lớn code (T-SQL → PL/pgSQL), không hỗ trợ TDS native (cần driver khác). Effort cao, chi phí giảm nhưng kém Babelfish (Aurora PG + Babelfish mới là giải pháp thật). RDS PG Multi-AZ HA ok nhưng không least effort.

  • ❌ Phương án SAI: Use AWS Database Migration Service (DMS) to migrate to an RDS for SQL Server Single-AZ database. Update the application to use the new database endpoint.
    Lý do sai: Chỉ giảm từ Multi-AZ → Single-AZ (tiết kiệm ~50% nhưng vẫn license SQL Server đắt). Vi phạm yêu cầu highly available (Single-AZ chỉ 1 instance, downtime cao nếu fail). DMS migrate dễ nhưng không giảm chi phí tối đa, effort thấp nhưng không meet HA + cost reduction full.

  • ✅ Phương án ĐÚNG: Use AWS Database Migration Service (DMS) to migrate the database to Amazon Aurora PostgreSQL. Turn on Babelfish for Aurora PostgreSQL. Update the application to use the Babelfish TDS port.
    Lý do đúng (tóm tắt): Như phần trên – Babelfish (ra mắt 2023, mature 2026) làm Aurora PG "giả lập" SQL Server hoàn hảo: TDS port 1433, T-SQL parser, stored proc. DMS hỗ trợ direct migration với schema conversion. App chỉ change connection string/port, zero-downtime với DMS CDC. Cost saving lớn nhất + least operational effort + full HA.

🛠️ Khuyến nghị thực tế: Test Babelfish compatibility trước migrate (tool AWS Schema Conversion Tool - SCT). Scale Aurora auto cho workload.

Câu 357
A company's application team needs to select an AWS managed database service to store application and user data. The application team is familiar with MySQL but is open to new solutions. The application and user data is stored in 10 tables and is de-normalized. The application will access this data through an API layer using a unique ID in each table. The company expects the traffic to be light at first, but the traffic will increase to thousands of transactions each second within the first year. The database service must support active reads and writes in multiple AWS Regions at the same time. Query response times need to be less than 100 ms.

Which AWS database solution will meet these requirements?
  1. A Deploy an Amazon RDS for MySQL environment in each Region and leverage AWS Database Migration Service (AWS DMS) to set up a multi-Region bidirectional replication.
  2. B Deploy an Amazon Aurora MySQL global database with write forwarding turned on.
  3. C Deploy an Amazon DynamoDB database with global tables.
  4. D Deploy an Amazon DocumentDB global cluster across multiple Regions.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi yêu cầu chọn một dịch vụ cơ sở dữ liệu managed bởi AWS phù hợp cho ứng dụng lưu trữ dữ liệu ứng dụng và người dùng. Các đặc điểm chính của yêu cầu bao gồm:

  • 👥 Đội ngũ quen thuộc với MySQL nhưng sẵn sàng thử giải pháp mới.
  • 📊 Dữ liệu được lưu trong 10 bảng de-normalized (không chuẩn hóa, phù hợp với mô hình NoSQL key-value hoặc document).
  • 🔑 Truy cập dữ liệu qua API layer sử dụng unique ID cho mỗi bảng (gợi ý truy vấn theo primary key nhanh chóng).
  • 🚀 Lưu lượng ban đầu thấp, nhưng tăng lên hàng nghìn giao dịch/giây trong năm đầu (cần khả năng scale tự động cao).
  • 🌍 Hỗ trợ active reads và writes đồng thời ở nhiều AWS Regions (multi-region active-active replication, không chỉ read replicas).
  • ⚡ Thời gian phản hồi query < 100 ms (yêu cầu độ trễ thấp, single-digit ms lý tưởng).

🛠️ Tóm tắt yêu cầu cốt lõi: Cần một DB NoSQL hoặc tương thích MySQL, scale cao, multi-region active-active (viết và đọc đồng thời ở nhiều vùng), latency thấp, phù hợp dữ liệu de-normalized và truy vấn theo ID.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Deploy an Amazon DynamoDB database with global tables.

Lý do chi tiết:

  • DynamoDB là dịch vụ NoSQL fully managed, hoàn hảo cho dữ liệu de-normalized với truy vấn theo unique ID (partition key), hỗ trợ hàng triệu TPS mà không cần quản lý server.
  • Global Tables kích hoạt multi-master replication active-active qua nhiều Regions, cho phép reads/writes đồng thời với độ trễ single-digit ms (<100ms dễ dàng đạt).
  • Scale tự động theo lưu lượng (từ light đến thousands TPS), phù hợp kiến trúc serverless qua API.
  • Đội ngũ quen MySQL có thể học nhanh vì DynamoDB có SDK/API đơn giản, và không cần migrate phức tạp.
    ✅ Đây là giải pháp tối ưu nhất theo best practices AWS 2026 (DynamoDB Global Tables v2 hỗ trợ on-demand capacity và multi-region conflict resolution tự động).

📋 Phân tích tất cả các phương án

Dưới đây là phân tích từng lựa chọn (giữ nguyên nội dung gốc bằng tiếng Anh). Mỗi phương án được đánh dấu ✅ ĐÚNG hoặc ❌ SAI, kèm giải thích chi tiết bằng tiếng Việt:

  • Deploy an Amazon RDS for MySQL environment in each Region and leverage AWS Database Migration Service (AWS DMS) to set up a multi-Region bidirectional replication.
    ❌ SAI. RDS MySQL là relational DB managed, phù hợp MySQL quen thuộc nhưng không hỗ trợ active-active writes multi-region native. DMS chỉ dùng cho migration hoặc replication one-way/async, bidirectional replication tự thiết lập dễ gây conflict, data inconsistency, và downtime ở production. Không scale tốt đến thousands TPS (cần Multi-AZ manual), latency cross-region >100ms, không phù hợp de-normalized data.

  • Deploy an Amazon Aurora MySQL global database with write forwarding turned on.
    ❌ SAI. Aurora Global Database hỗ trợ cross-region read replicas (active reads ở secondary regions), nhưng writes chỉ active ở primary region duy nhất. Write forwarding chỉ forward writes từ replica về primary (không true active writes multi-region đồng thời), dễ gây latency cao (>100ms cross-region) và bottleneck. Phù hợp MySQL nhưng không scale NoSQL-like cho de-normalized data và high TPS.

  • Deploy an Amazon DynamoDB database with global tables.
    ✅ ĐÚNG (như đã giải thích ở trên). Hoàn hảo cho tất cả yêu cầu: NoSQL de-normalized, global active-active replication, scale infinite TPS, latency <10ms, API access theo ID.

  • Deploy an Amazon DocumentDB global cluster across multiple Regions.
    ❌ SAI. DocumentDB (MongoDB-compatible) hỗ trợ global clusters với read replicas cross-region, nhưng writes chỉ ở primary cluster, tương tự Aurora (không active writes multi-region đồng thời). Latency cross-region có thể >100ms, phù hợp document data nhưng kém DynamoDB cho key-value high-throughput. Không native cho unique ID table-like.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

  • DynamoDB Global Tables: AWS Docs - Global Tables – Hỗ trợ multi-region active-active với DAX cho <10ms latency.
  • Aurora Global Database: AWS Docs - Global Databases – Xác nhận writes chỉ primary.
  • RDS/DMS Limitations: AWS DMS Best Practices – Không khuyến nghị bidirectional production.
  • DocumentDB Global Clusters: AWS Docs - Global Clusters – Read-focused.
    🧠 Nguồn chính thức: AWS Well-Architected Framework - Reliability Pillar (2026 edition) nhấn mạnh DynamoDB cho global apps high-scale.
Câu 358
A manufacturing company stores its inventory details in an Amazon DynamoDB table in the us-east-2 Region. According to new compliance and regulatory policies, the company is required to back up all of its tables nightly and store these backups in the us-west-2 Region for disaster recovery for 1 year.
  1. A Convert the existing DynamoDB table into a global table and create a global table replica in the us-west-2 Region.
  2. B Use AWS Backup to create a backup plan. Configure cross-Region replication in the plan and assign the DynamoDB table to this plan.
  3. C Create an on-demand backup of the DynamoDB table and restore this backup in the us-west-2 Region.
  4. D Enable Amazon S3 Cross-Region Replication (CRR) on the S3 bucket where DynamoDB on-demand backups are stored.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một công ty sản xuất lưu trữ dữ liệu chi tiết hàng tồn kho trong bảng Amazon DynamoDB tại vùng us-east-2. Theo chính sách tuân thủ mới, họ bắt buộc phải sao lưu (backup) toàn bộ bảng hàng đêm (nightly) và lưu trữ các bản sao lưu này tại vùng us-west-2 để phục vụ khôi phục thảm họa (disaster recovery), với thời hạn lưu trữ là 1 năm.

🛠️ Yêu cầu chính cần giải quyết:

  • Tự động hóa backup hàng đêm: Không phải thủ công.
  • Cross-Region: Sao lưu từ us-east-2 sang us-west-2.
  • Lưu trữ lâu dài: Ít nhất 1 năm (retention period).
  • DynamoDB cụ thể: Phải hỗ trợ backup on-demand hoặc continuous (PITR), không phải replication dữ liệu real-time.

Mục tiêu là chọn giải pháp tự động, đáng tin cậy, tuân thủ AWS best practices cho backup DynamoDB cross-region (dựa trên tính năng AWS Backup mới nhất đến 2026).

✅ Đáp án đúng: Use AWS Backup to create a backup plan. Configure cross-Region replication in the plan and assign the DynamoDB table to this plan.

Lý do lựa chọn:

  • AWS Backup là dịch vụ quản lý backup trung tâm (centralized), hỗ trợ DynamoDB từ năm 2021 và được cập nhật liên tục (phiên bản 2026 vẫn là lựa chọn tiêu chuẩn).
  • Bạn có thể tạo backup plan với lịch hàng ngày (daily schedule), retention 1 năm, và kích hoạt Cross-Region Copy (CRC) để tự động copy backup sang vùng đích (us-west-2).
  • Hỗ trợ cả on-demand backup và continuous backups (PITR) cho DynamoDB, đảm bảo backup toàn bộ bảng, mã hóa tự động, và khôi phục nhanh.
  • Tự động hoàn toàn: Không cần can thiệp thủ công hàng đêm, phù hợp disaster recovery.
  • ✅ Ưu điểm nổi bật: Audit trail đầy đủ, Vault lock cho compliance, và chi phí tối ưu (pay-per-use).

📋 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Tôi đánh dấu ✅ đúng hoặc ❌ sai dựa trên tính phù hợp với yêu cầu (nightly backup cross-region, retention 1 năm).

  • Convert the existing DynamoDB table into a global table and create a global table replica in the us-west-2 Region.
    ❌ Sai: Global tables dùng cho multi-master replication real-time (dữ liệu đồng bộ liên tục giữa các vùng), không phải backup snapshot. Nó không tạo bản sao lưu hàng đêm có thể lưu 1 năm, mà giữ dữ liệu live (không có retention cố định). Chuyển đổi global table còn tốn kém, phức tạp, và không đáp ứng "backup for disaster recovery". (Không phù hợp theo AWS Docs: Global Tables là cho availability, không thay thế backup).

  • Use AWS Backup to create a backup plan. Configure cross-Region replication in the plan and assign the DynamoDB table to this plan.
    ✅ Đúng: Như giải thích ở trên. Đây là giải pháp chính thức của AWS cho backup DynamoDB cross-region tự động. Backup plan hỗ trợ cron schedule (nightly), CRC sang us-west-2, và retention policy lên đến 100 năm. Hoàn hảo cho compliance.

  • Create an on-demand backup of the DynamoDB table and restore this backup in the us-west-2 Region.
    ❌ Sai: Đây là quy trình thủ công (on-demand), không tự động hàng đêm. Restore backup DynamoDB chỉ tạo bảng mới ở cùng vùng (không cross-region trực tiếp). Phải restore ở us-east-2 trước rồi export thủ công – không scale, không retention tự động 1 năm, dễ lỗi và không tuân thủ "nightly".

  • Enable Amazon S3 Cross-Region Replication (CRR) on the S3 bucket where DynamoDB on-demand backups are stored.
    ❌ Sai: DynamoDB on-demand backups được lưu trữ nội bộ bởi AWS (không phải S3 bucket do customer quản lý), nên không thể enable CRR trực tiếp (bạn không có quyền truy cập bucket). Chỉ khi export PITR/on-demand sang S3 customer bucket (tính năng riêng), mới dùng CRR – nhưng không tự động nightly, và phức tạp hơn AWS Backup. (Không phải best practice cho trường hợp này).

📘 Tài liệu tham khảo (cập nhật mới nhất đến 2026)

Hy vọng phân tích giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ code Terraform/CLI, hãy hỏi nhé!