Ngân hàng đề — AWS Certified Developer Associate
Tìm thấy 1356 câu.
Which solution will meet these requirements?
- A Store the database credentials as environment variables for the Lambda function. Set the environment variables to rotate automatically.
- B Store the database credentials in AWS Secrets Manager. Set up managed rotation on the database credentials.
- C Store the database credentials in AWS Systems Manager Parameter Store as secure string parameters. Set up managed rotation on the parameters.
- D Store the database credentials in the X-Amz-Security-Token parameter. Set up managed rotation on the parameter.
Xem giải thích
🔍 Giải thích nội dung câu hỏi
🧩 Câu hỏi tập trung vào việc một lập trình viên đang phát triển hàm AWS Lambda cần kết nối với instance Amazon RDS for MySQL. Yêu cầu chính là lưu trữ thông tin xác thực cơ sở dữ liệu (database credentials) sao cho:
- Chúng được mã hóa (encrypted) để đảm bảo an toàn.
- Mật khẩu cơ sở dữ liệu (database password) được tự động xoay vòng (rotated) định kỳ mà không cần can thiệp thủ công.
📌 Đây là tình huống thực tế trong DevOps AWS, nơi Lambda cần truy cập RDS an toàn, tuân thủ nguyên tắc "least privilege" và best practices bảo mật (như AWS Well-Architected Framework - Security Pillar). Giải pháp phải hỗ trợ tích hợp native với Lambda và RDS, sử dụng dịch vụ AWS chuyên biệt cho secrets management với tính năng rotation tự động cho RDS MySQL (theo phiên bản AWS mới nhất 2026, Secrets Manager hỗ trợ rotation cho RDS/MySQL 8.0+ và các engine tương thích).
✅ Đáp án đúng và lý do lựa chọn
Store the database credentials in AWS Secrets Manager. Set up managed rotation on the database credentials.
🛠️ Lý do: AWS Secrets Manager là dịch vụ lý tưởng nhất vì:
- Tự động mã hóa credentials bằng AWS KMS (mặc định hoặc custom key).
- Hỗ trợ managed rotation tích hợp sẵn cho Amazon RDS (bao gồm MySQL), nơi Lambda rotation function sẽ tự động cập nhật password trên RDS và secrets mà không downtime.
- Lambda có thể retrieve secrets qua SDK (boto3) mà không lưu hardcoded.
- Theo AWS 2026, rotation lambda được deploy tự động, hỗ trợ multi-account và VPC. Đây là recommended solution cho DB creds với rotation (AWS Prescriptive Guidance).
📋 Phân tích tất cả các phương án
-
[SAI] Store the database credentials as environment variables for the Lambda function. Set the environment variables to rotate automatically.
❌ Sai vì: Environment variables của Lambda có thể encrypt bằng KMS nhưng KHÔNG hỗ trợ automatic rotation native. Bạn phải tự viết code Lambda để rotate thủ công (không "set to rotate automatically"). RDS password không tự sync, dễ lỗi và không scale. Không phải best practice cho secrets động. -
[ĐÚNG] Store the database credentials in AWS Secrets Manager. Set up managed rotation on the database credentials.
✅ Đúng vì: Như giải thích trên, Secrets Manager cung cấp encryption (KMS), managed rotation full cho RDS MySQL (chạy lambda rotation mỗi 30 ngày mặc định, test trước rotate). Lambda dùngget_secret_value()dễ dàng, chi phí thấp (~$0.40/secret/tháng + API calls). Hỗ trợ audit logs qua CloudTrail. -
[SAI] Store the database credentials in AWS Systems Manager Parameter Store as secure string parameters. Set up managed rotation on the parameters.
❌ Sai vì: Parameter Store hỗ trợ SecureString (encrypt KMS), nhưng KHÔNG có managed rotation native cho DB creds như Secrets Manager. Rotation yêu cầu custom Lambda function (phức tạp hơn), không tự động cập nhật RDS password. AWS khuyến nghị dùng Secrets Manager cho trường hợp này (SSM phù hợp static params hơn). -
[SAI] Store the database credentials in the X-Amz-Security-Token parameter. Set up managed rotation on the parameter.
❌ Sai vì:X-Amz-Security-Tokenlà temporary STS token cho assumed roles (session ~1-36h), KHÔNG dùng lưu DB creds. Không encrypt persistent, không rotation cho passwords, và không liên quan RDS. Sử dụng sai sẽ vi phạm bảo mật cơ bản (temporary creds chỉ cho API calls).
📘 Tài liệu tham khảo
- AWS Secrets Manager Rotation: docs.aws.amazon.com/secretsmanager/latest/userguide/rotating-secrets.html (cập nhật 2026: hỗ trợ RDS Proxy integration).
- Lambda + Secrets Manager: docs.aws.amazon.com/lambda/latest/dg/configuration-secrets.html.
- AWS Best Practices: aws.amazon.com/blogs/security/ - "Rotate Amazon RDS database credentials automatically".
- Exam Topic DOP-C02 (DevOps Pro 2026): Secrets Management & Automation.
Which solution will meet these requirements?
- A Configure a weighted routing policy in Amazon Route 53. Associate the versions of the Lambda function with the weighted routing policy.
- B Create a function alias. Configure the alias to split the traffic between the two versions of the Lambda function.
- C Create an Application Load Balancer (ALB) that uses the Lambda function as a target. Configure the ALB to split the traffic between the two versions of the Lambda function.
- D Create the new version of the Lambda function as a Lambda layer on the existing version. Configure the function to split the traffic between the two layers.
Xem giải thích
🧩 Phân tích nội dung câu hỏi
Câu hỏi tập trung vào việc giảm rủi ro (reduce risk) khi triển khai phiên bản mới của một AWS Lambda function hiện có. Developer cần một giải pháp để chia lưu lượng traffic (split the traffic) giữa version hiện tại (existing version) và version mới (new version) nhằm test an toàn, thường gọi là canary deployment hoặc blue-green deployment cho serverless.
Điều này rất phổ biến trong DevOps trên AWS Lambda, nơi bạn có thể publish các Lambda versions (immutable snapshots của code/config) và sử dụng aliases để routing traffic động. Yêu cầu nhấn mạnh giải pháp native với Lambda, không cần dịch vụ bên ngoài phức tạp, đảm bảo tính đơn giản, chi phí thấp và tự động scale. Kiến thức dựa trên AWS Lambda phiên bản mới nhất (2026), hỗ trợ traffic shifting lên đến 100% giữa 2 versions qua aliases với gradual rollout.
✅ Đáp án đúng và lý do lựa chọn
Đáp án đúng: Create a function alias. Configure the alias to split the traffic between the two versions of the Lambda function.
Lý do:
- Lambda aliases là giải pháp native và được thiết kế chính xác cho việc split traffic giữa các versions (ví dụ: 90% traffic đến version cũ, 10% đến version mới cho canary testing).
- Bạn publish version mới bằng
aws lambda publish-version, sau đó tạo/edit alias (ví dụ: "PROD") với routing config chỉ định tỷ lệ traffic (traffic shifting). Alias hoạt động như một pointer động, tự động update mà không downtime. - Giảm rủi ro tối đa: Nếu version mới lỗi, rollback bằng cách adjust tỷ lệ về 100% version cũ chỉ trong giây lát. Hỗ trợ monitoring qua CloudWatch và tự động.
- Đây là best practice theo AWS Well-Architected Framework (Operational Excellence pillar). ✅ Hoàn hảo cho serverless deployments!
📋 Phân tích tất cả các phương án
Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá ✅ (đúng) hoặc ❌ (sai), kèm giải thích rõ ràng:
-
❌ Configure a weighted routing policy in Amazon Route 53. Associate the versions of the Lambda function with the weighted routing policy.
Sai vì: Route 53 weighted routing dùng cho DNS-level routing giữa các endpoint (như EC2, ALB), không trực tiếp hỗ trợ Lambda versions (Lambda invoke qua ARN, không phải DNS records). Lambda versions/aliases có ARN riêng, nhưng Route 53 không integrate native để split traffic nội bộ Lambda. Giải pháp này phức tạp, thêm latency DNS, chi phí cao và không atomic (không rollback nhanh). Không phù hợp cho Lambda invoke trực tiếp từ API Gateway/EventBridge. -
✅ Create a function alias. Configure the alias to split the traffic between the two versions of the Lambda function.
Đúng vì: Như đã giải thích ở trên, đây là feature built-in của Lambda từ 2017 và cập nhật liên tục (2026 vẫn là standard). Alias routing config cho phép precise percentage-based splitting (0-100%) giữa chính xác 2 versions, với gradual shift và versioning atomic. Invoke alias ARN (e.g.,arn:aws:lambda:region:account:function:name:alias) thay thế function ARN gốc. 🛠️ Best practice cho zero-downtime deployments! -
❌ Create an Application Load Balancer (ALB) that uses the Lambda function as a target. Configure the ALB to split the traffic between the two versions of the Lambda function.
Sai vì: ALB hỗ trợ Lambda targets (qua Lambda Target Group từ 2017), nhưng không native split traffic giữa Lambda versions – ALB chỉ route đến function ARN cụ thể, không hiểu versions/aliases nội bộ. Để split, cần 2 target groups riêng (một cho mỗi version), config weighted routing trên ALB listener – phức tạp, thêm chi phí ALB (~$0.0225/giờ), latency và single point of failure. Không khuyến khích cho pure Lambda workloads (API Gateway + Lambda alias hiệu quả hơn). -
❌ Create the new version of the Lambda function as a Lambda layer on the existing version. Configure the function to split the traffic between the two layers.
Sai vì: Lambda layers chỉ là immutable code packages (libraries, dependencies) chia sẻ giữa functions, không phải versions đầy đủ và không hỗ trợ traffic splitting. Layers attach vào function/version, không invoke độc lập hay route traffic. Không thể "split traffic giữa layers" vì layers không executable – đây là nhầm lẫn cơ bản. Layers hữu ích cho code reuse, không thay thế versioning/aliases.
📘 Tài liệu tham khảo (AWS mới nhất 2026)
- AWS Lambda Developer Guide - Function Versions: https://docs.aws.amazon.com/lambda/latest/dg/configuration-versions.html (Giải thích publish versions).
- AWS Lambda Aliases & Traffic Shifting: https://docs.aws.amazon.com/lambda/latest/dg/lambda-aliases.html (Chi tiết routing config, ví dụ CLI/SDK).
- AWS Well-Architected Framework - Lambda Best Practices: https://docs.aws.amazon.com/wellarchitected/latest/serverless-applications-lens/wal-serverless-operations.html (Canary/blue-green với aliases).
- Hands-on Lab: AWS Console > Lambda > Functions > Versions & Aliases tab để test trực tiếp.
Giải pháp alias giúp deploy an toàn 100%! Nếu cần demo code Terraform/ CDK, hỏi thêm nhé! 🚀
Which actions can the developer take to resolve this error? (Choose two.)
- A Submit a quota increase request to AWS Support to increase the function to the required size.
- B Use a compression algorithm that is more efficient than ZIP.
- C Break up the function into multiple smaller functions.
- D Zip the .zip file twice to compress the file more.
- E Move common libraries, function dependencies, and custom runtimes into Lambda layers.
Xem giải thích
🧩 Giải thích nội dung câu hỏi
Câu hỏi mô tả tình huống một lập trình viên đã tạo một AWS Lambda function lớn, nhưng quá trình triển khai (deployment) thất bại với lỗi InvalidParameterValueException. Thông báo lỗi cụ thể chỉ ra rằng kích thước unzipped (kích thước sau khi giải nén) của function vượt quá giá trị tối đa được hỗ trợ.
🛠️ Chi tiết kỹ thuật:
- AWS Lambda có giới hạn cứng (hard limit) về kích thước deployment package:
- File ZIP nén: Tối đa 50 MB nếu upload trực tiếp, hoặc 250 MB nếu upload qua Amazon S3.
- Kích thước unzipped (bao gồm code, dependencies, libraries): Tối đa 250 MB cho toàn bộ function (không tính layers riêng).
- Lỗi này xảy ra vì sau khi Lambda giải nén file ZIP, tổng kích thước code + thư viện + dependencies vượt quá 250 MB. Đây là giới hạn không thể thay đổi qua quota increase (dựa trên tài liệu AWS cập nhật đến năm 2024-2026).
- Câu hỏi yêu cầu chọn hai hành động (Choose TWO) mà developer có thể thực hiện để khắc phục, tập trung vào các giải pháp tối ưu hóa kích thước mà không vi phạm giới hạn.
📘 Ghi chú: Giới hạn này áp dụng cho tất cả runtime (Node.js, Python, Java, v.v.) và được xác nhận trong AWS Lambda limits mới nhất (không thay đổi đến 2026).
✅ Đáp án đúng và lý do lựa chọn
Hai đáp án đúng là:
- Break up the function into multiple smaller functions.
- Move common libraries, function dependencies, and custom runtimes into Lambda layers.
Lý do lựa chọn:
- ✅ Cả hai phương án đều trực tiếp giải quyết vấn đề giảm kích thước unzipped của function package, giúp tuân thủ giới hạn 250 MB mà không cần thay đổi quota (vốn không khả dụng cho limit này).
- Chúng tận dụng kiến trúc serverless tốt nhất: Modularization (chia nhỏ) và Layers (tách dependencies), giảm thời gian cold start và dễ maintain. Đây là best practice được AWS khuyến nghị cho large functions.
🔍 Phân tích chi tiết tất cả các phương án
Dưới đây là phân tích từng lựa chọn một cách rõ ràng, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh dấu ✅ (đúng) hoặc ❌ (sai), kèm giải thích đầy đủ bằng tiếng Việt dựa trên tài liệu AWS mới nhất.
-
❌ Submit a quota increase request to AWS Support to increase the function to the required size.
Giải thích sai: Không thể yêu cầu tăng quota cho kích thước unzipped deployment package vì đây là hard limit cố định 250 MB, không phải soft quota có thể điều chỉnh qua AWS Support. AWS chỉ cho phép quota increase cho số lượng function/concurrent executions, memory, v.v., nhưng không áp dụng cho kích thước package (xác nhận trong AWS Service Quotas và Lambda docs 2024). -
❌ Use a compression algorithm that is more efficient than ZIP.
Giải thích sai: AWS Lambda chỉ hỗ trợ định dạng ZIP cho deployment package (qua Console, CLI, SAM, hoặc S3). Không thể sử dụng algorithm nén khác như RAR, 7z hay gzip độc lập. Vấn đề cốt lõi là unzipped size (sau giải nén), không phải zipped size, nên nén tốt hơn cũng không giúp vượt giới hạn 250 MB unzipped. -
✅ Break up the function into multiple smaller functions.
Giải thích đúng: Chia function lớn thành nhiều function nhỏ hơn giúp mỗi package có unzipped size dưới 250 MB. Mỗi function độc lập, dễ scale và debug. Đây là best practice cho monolithic codebases lớn, tận dụng invocation chaining (gọi lẫn nhau) hoặc Step Functions để orchestrate. Giảm cold start time và tuân thủ limit hoàn hảo. -
❌ Zip the .zip file twice to compress the file more.
Giải thích sai: Việc nén ZIP hai lần (nested ZIP) không được Lambda hỗ trợ và không giảm được unzipped size – Lambda vẫn giải nén toàn bộ để đạt kích thước thực tế. Thậm chí có thể gây lỗi extraction. Đây là cách tiếp cận sai lầm, không hiệu quả và vi phạm quy trình deployment chuẩn của AWS. -
✅ Move common libraries, function dependencies, and custom runtimes into Lambda layers.
Giải thích đúng: Lambda Layers cho phép tách thư viện chung, dependencies (như npm modules, pip packages), custom runtimes ra khỏi function package chính. Layers có giới hạn riêng (tổng 5 layers/function, unzipped 250 MB/layer), giúp function code chỉ còn nhẹ (dưới 250 MB). Tái sử dụng layers giữa nhiều functions, tối ưu chi phí và deployment. Hỗ trợ lên đến 10 layers ở một số runtime mới (2024 updates).
📘 Tài liệu tham khảo
- AWS Lambda Limits: AWS Documentation - Lambda Resource Limits (cập nhật 2024, xác nhận 250 MB unzipped).
- Lambda Layers Best Practices: AWS re:Post - Optimizing Package Size và Lambda Layers Guide.
- Troubleshooting Deployment Errors: AWS Lambda Troubleshooting.
- Service Quotas: AWS Service Quotas Console – Không có quota cho deployment size.
Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm ví dụ code hoặc demo, hãy hỏi nhé!
There has been an increase in application usage. The third-party API frequently returns an HTTP 429 Too Many Requests error message. The error message prevents a significant number of messages from being processed successfully.
How can the developer resolve this issue?
- A Increase the SQS event source’s batch size setting.
- B Configure provisioned concurrency for the Lambda function based on the third-party API’s documented rate limits.
- C Increase the retry attempts and maximum event age in the Lambda function’s asynchronous configuration.
- D Configure maximum concurrency on the SQS event source based on the third-party service’s documented rate limits.
Xem giải thích
🧠 Phân tích câu hỏi trắc nghiệm AWS bởi AWS Certified DevOps Engineer Professional
📖 Giải thích nội dung câu hỏi một cách chi tiết và rõ ràng:
Câu hỏi mô tả một tình huống troubleshooting trong môi trường integration của ứng dụng AWS. Ứng dụng sử dụng Amazon SQS làm queue để nhận và lưu trữ messages, sau đó AWS Lambda function được trigger bởi SQS event source mapping để consume các messages này. Lambda sẽ transform (chuyển đổi) messages và gọi API của third-party service bên thứ ba.
🛠️ Vấn đề chính: Với sự gia tăng usage (lưu lượng sử dụng), third-party API thường xuyên trả về lỗi HTTP 429 Too Many Requests (quá nhiều request), dẫn đến nhiều messages không được xử lý thành công. Mục tiêu là resolve issue này bằng cách kiểm soát rate limiting từ phía Lambda để tránh vượt quá giới hạn của API third-party.
Đây là vấn đề phổ biến trong kiến trúc serverless, nơi Lambda scale tự động có thể gây overload downstream services nếu không có throttling (giới hạn concurrency). Kiến thức áp dụng từ phiên bản AWS Lambda mới nhất (2024-2026), tập trung vào SQS event source mapping với các controls như maximum concurrency để quản lý invocations đồng thời.
✅ Đáp án đúng và lý do lựa chọn:
Configure maximum concurrency on the SQS event source based on the third-party service’s documented rate limits.
Lý do: Đây là giải pháp tối ưu và trực tiếp nhất! Bằng cách set maximum concurrency trên SQS event source mapping (tính năng reservable concurrency dành riêng cho event source), developer có thể giới hạn chính xác số lượng Lambda invocations đồng thời từ queue này (ví dụ: chỉ 10-50 concurrent executions dựa trên rate limit của third-party API, như 100 requests/phút). Điều này ngăn chặn overload API mà không ảnh hưởng đến scale của Lambda function khác. SQS sẽ queue lại messages thừa, đảm bảo xử lý dần dần. Tính năng này được AWS khuyến nghị cho rate limiting downstream (cập nhật Lambda 2023+).
📘 Tài liệu tham khảo:
- AWS Lambda SQS Event Source Mapping (Maximum concurrency control).
- Lambda Function Concurrency Management (Reservable concurrency cho event sources).
- AWS Well-Architected Framework: Serverless Lens (Reliability pillar, 2024 edition).
🛠️ Phân tích chi tiết tất cả các phương án (đúng và sai):
Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá dựa trên hành vi thực tế của AWS services (cập nhật 2026), với lý do rõ ràng bằng tiếng Việt.
• Increase the SQS event source’s batch size setting.
❌ Sai: Tăng batch size (số messages/Lambda invocation, mặc định 10, max 10.000) sẽ làm Lambda xử lý nhiều messages hơn mỗi lần, dẫn đến tăng đột biến requests đến third-party API (ví dụ: 1 invocation gửi 100 requests thay vì 10). Điều này làm trầm trọng hóa lỗi 429, không giải quyết rate limiting mà còn tăng tải đồng thời. Không phù hợp cho throttling.
• Configure provisioned concurrency for the Lambda function based on the third-party API’s documented rate limits.
❌ Sai: Provisioned concurrency (pre-warm instances) chỉ đảm bảo scale nhanh và cold start thấp, nhưng không giới hạn tổng concurrent executions của function (vẫn scale unbounded nếu traffic cao). Nó ảnh hưởng toàn bộ function (không chỉ SQS source), lãng phí chi phí và không kiểm soát trực tiếp invocations từ SQS đến API third-party. Không giải quyết gốc rễ overload.
• Increase the retry attempts and maximum event age in the Lambda function’s asynchronous configuration.
❌ Sai: Cấu hình này dành cho async invocations (như SQS dead-letter queue retries), nhưng SQS event source là polling synchronous (Lambda poll queue trực tiếp). Tăng retry/max event age chỉ kéo dài thời gian retry lỗi, không giảm concurrent requests ban đầu gây 429. Có thể làm tích tụ messages nhiều hơn, tệ hơn!
• Configure maximum concurrency on the SQS event source based on the third-party service’s documented rate limits.
✅ Đúng: Như đã giải thích ở trên, đây là giải pháp chuẩn AWS để throttle chính xác tại event source level. Ví dụ: Set MaximumConcurrency: 20 nếu API limit 100 req/phút (giả sử mỗi invocation 3 req + buffer). Messages thừa ở lại SQS, được xử lý dần, đảm bảo reliability mà không cần code thay đổi. Hoàn hảo cho production scale! 🚀
During times of peak usage, the application’s performance degrades. When this performance degradation occurs, the DB instance’s ReadLatency metric in Amazon CloudWatch increases suddenly.
How should a developer modify the application to improve performance?
- A Use Amazon ElastiCache to cache query results.
- B Scale the ECS cluster to contain more ECS instances.
- C Add read capacity units (RCUs) to the DB instance.
- D Modify the ECS task definition to increase the task memory.
Xem giải thích
🧩 Phân tích chi tiết nội dung câu hỏi
Câu hỏi mô tả một ứng dụng ba tầng (three-tier application) được triển khai trên Amazon Elastic Container Service (Amazon ECS), sử dụng Amazon RDS for MySQL làm cơ sở dữ liệu. Đặc điểm nổi bật:
- Ứng dụng thực hiện nhiều thao tác đọc (reads) hơn viết (writes).
- Trong giờ cao điểm (peak usage), hiệu suất ứng dụng giảm sút, và metric ReadLatency trên Amazon CloudWatch của DB instance tăng đột ngột.
📈 Vấn đề cốt lõi: ReadLatency tăng cho thấy thời gian xử lý các truy vấn đọc dữ liệu từ RDS MySQL bị chậm, dẫn đến bottleneck ở lớp database. Câu hỏi yêu cầu modify the application (thay đổi ứng dụng) để cải thiện hiệu suất, tập trung vào việc giảm tải reads trên DB mà không thay đổi hạ tầng DB trực tiếp. Đây là tình huống phổ biến trong kiến trúc ECS + RDS, nơi caching là giải pháp tối ưu cho read-heavy workloads (theo best practices AWS năm 2024-2026).
✅ Đáp án đúng
Use Amazon ElastiCache to cache query results.
Lý do chọn đáp án này:
ElastiCache (hỗ trợ Redis hoặc Memcached) là dịch vụ caching managed của AWS, lý tưởng để lưu trữ tạm thời kết quả truy vấn đọc từ RDS MySQL. Vì ứng dụng có nhiều reads hơn writes, việc cache giúp:
- Giảm số lượng truy vấn đến DB thực tế (hit cache thay vì query DB).
- Giảm ReadLatency đột ngột bằng cách offload reads khỏi RDS.
- Modify application đơn giản: Thêm logic cache (ví dụ: dùng Redis client trong code app ECS tasks).
🛠️ Đây là giải pháp application-level phù hợp nhất, scalable với ECS, và được AWS khuyến nghị trong DOP-C02 exam blueprint (2024+).
🔍 Phân tích tất cả các phương án trả lời
-
✅ Use Amazon ElastiCache to cache query results.
Phương án ĐÚNG vì trực tiếp giải quyết vấn đề ReadLatency bằng cách cache reads, giảm tải DB lên đến 90% trong read-heavy apps. Tích hợp dễ dàng với ECS qua VPC, hỗ trợ serverless (ElastiCache Serverless từ 2023). Không ảnh hưởng writes, phù hợp workload mô tả. -
❌ Scale the ECS cluster to contain more ECS instances.
Phương án SAI vì scaling ECS cluster chỉ tăng compute resources cho application layer (nhiều tasks/instances), nhưng bottleneck ở DB ReadLatency – không phải CPU/memory của app. Thêm instances sẽ tăng concurrent reads đến DB, làm tình trạng tệ hơn (throttling RDS). -
❌ Add read capacity units (RCUs) to the DB instance.
Phương án SAI vì RCUs là khái niệm của DynamoDB (NoSQL), không áp dụng cho RDS MySQL (relational DB). RDS scale reads qua read replicas (Aurora cho auto-scaling reads), nhưng câu hỏi yêu cầu modify application, không phải DB config. Sai lầm phổ biến trong exam. -
❌ Modify the ECS task definition to increase the task memory.
Phương án SAI vì tăng memory cho ECS tasks chỉ giúp app xử lý workload lớn hơn (ví dụ: in-memory processing), nhưng không giải quyết ReadLatency từ DB. Vấn đề là DB chậm, không phải app hết memory – scaling vertical tasks không offload DB reads.
📘 Tài liệu tham khảo (cập nhật AWS 2024-2026)
- AWS ElastiCache Documentation: ElastiCache for Redis/Memcached with RDS – Best practices cho caching RDS reads.
- Amazon RDS Performance Insights: RDS Metrics & Read Replicas – Giải thích ReadLatency metric.
- AWS DOP-C02 Exam Guide: Domain 2: Storage & DBMS – Nhấn mạnh caching cho ECS+RDS workloads.
- AWS Well-Architected Framework (2024): Performance Efficiency Pillar – Khuyến nghị ElastiCache cho read-heavy apps.
Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ code ECS + ElastiCache, hãy hỏi nhé!
Which policy allows MINIMUM access to meet these requirements?
-
A
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:ListBucket", "Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET" }, { "Effect": "Allow", "Action": [ "s3:GetObject" ], "Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET/*" } ] }
-
B
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:ListBucket", "Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET" }, { "Effect": "Allow", "Action": [ "s3:*" ], "Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET/*" } ] }
-
C
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:ListBucket", "Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET" }, { "Effect": "Allow", "Action": [ "s3:GetObject", "s3:PutObject", "s3:DeleteObject" ], "Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET/*" } ] }
-
D
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:ListBucket", "Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET" }, { "Effect": "Deny", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET/*" } ] }
Xem giải thích
📘 Phân tích câu hỏi
Câu hỏi yêu cầu tìm một chính sách IAM (Identity and Access Management) cho phép truy cập tối thiểu (MINIMUM access) để ứng dụng web có thể liệt kê các đối tượng trong một bucket S3 tên là DOC-EXAMPLE-BUCKET và tải xuống các đối tượng thông qua chính sách IAM.
🧩 Yêu cầu chính sách
- Liệt kê các đối tượng trong bucket S3:
s3:ListBucket - Tải xuống các đối tượng trong bucket S3:
s3:GetObject
🛠️ Phân tích các lựa chọn
Lựa chọn 1: ĐÚNG
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "s3:ListBucket",
"Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET"
},
{
"Effect": "Allow",
"Action": [
"s3:GetObject"
],
"Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET/*"
}
]
}
✅ Lý do đúng:
- Chính sách này cho phép liệt kê các đối tượng trong bucket
DOC-EXAMPLE-BUCKETvới hành độngs3:ListBucket. - Cho phép tải xuống các đối tượng trong bucket với hành động
s3:GetObject. - Chỉ cấp quyền tối thiểu cần thiết để thực hiện các yêu cầu.
Lựa chọn 2: SAI
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "s3:ListBucket",
"Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET"
},
{
"Effect": "Allow",
"Action": [
"s3:*"
],
"Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET/*"
}
]
}
❌ Lý do sai:
- Hành động
s3:*cấp quyền thực hiện tất cả các hành động trên S3, bao gồm cả những hành động không cần thiết nhưs3:PutObject,s3:DeleteObject,... - Điều này không đáp ứng yêu cầu về quyền truy cập tối thiểu.
Lựa chọn 3: SAI
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "s3:ListBucket",
"Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET"
},
{
"Effect": "Allow",
"Action": [
"s3:GetObject",
"s3:PutObject",
"s3:DeleteObject"
],
"Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET/*"
}
]
}
❌ Lý do sai:
- Ngoài quyền tải xuống (
s3:GetObject), chính sách này còn cấp thêm quyềns3:PutObjectvàs3:DeleteObject, không đáp ứng yêu cầu về quyền truy cập tối thiểu.
Lựa chọn 4: SAI
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "s3:ListBucket",
"Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET"
},
{
"Effect": "Deny",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET/*"
}
]
}
❌ Lý do sai:
- Hành động
s3:GetObjectbị từ chối (Deny), điều này không đáp ứng yêu cầu cần tải xuống các đối tượng.
📘 Tài liệu tham khảo
✅ Kết luận: Lựa chọn 1 là chính sách IAM phù hợp để đáp ứng yêu cầu với quyền truy cập tối thiểu.
How can the developer implement the encryption in the application to meet these requirements?
- A Create a data key in AWS Key Management Service (AWS KMS). Use the AWS Encryption SDK to encrypt the files.
- B Create a Hash-Based Message Authentication Code (HMAC) key in AWS Key Management Service (AWS KMS). Use the AWS Encryption SDK to encrypt the files.
- C Create a data key pair in AWS Key Management Service (AWS KMS). Use the AWS CLI to encrypt the files.
- D Create a data key in AWS Key Management Service (AWS KMS). Use the AWS CLI to encrypt the files.
Xem giải thích
🧩 Phân tích nội dung câu hỏi
Câu hỏi tập trung vào việc một lập trình viên (developer) cần mã hóa các file bên ngoài AWS (client-side encryption) trước khi upload lên Amazon S3 bucket. Yêu cầu chính:
- Mã hóa phải là symmetric (đối xứng, sử dụng cùng một khóa để mã hóa và giải mã).
- Quá trình mã hóa phải diễn ra bên trong ứng dụng (inside the application), không phải trên AWS services.
- Mục tiêu: Sử dụng AWS KMS để quản lý khóa an toàn, kết hợp với công cụ phù hợp cho ứng dụng.
🛠️ Bối cảnh kỹ thuật: Đây là mô hình envelope encryption phổ biến, nơi tạo data key từ KMS (symmetric key ngắn hạn), dùng để mã hóa file trực tiếp trong app. File mã hóa (ciphertext + encrypted data key) sẽ được upload lên S3. Khi giải mã, app gọi KMS để decrypt data key. Phương pháp này đảm bảo an toàn, tuân thủ FIPS 140-2, và hỗ trợ multi-region (cập nhật AWS 2024-2026 với KMS multi-Region keys).
✅ Đáp án đúng và lý do lựa chọn
Đáp án đúng: Create a data key in AWS Key Management Service (AWS KMS). Use the AWS Encryption SDK to encrypt the files.
Lý do:
- Create a data key: Sử dụng API
GenerateDataKeyhoặcGenerateDataKeyWithoutPlaintextcủa KMS để tạo symmetric data key (AES-256-GCM hoặc tương tự). Data key này được mã hóa bởi KMS customer master key (CMK) và trả về plaintext để app dùng mã hóa file ngay lập tức (envelope encryption). - AWS Encryption SDK: Thư viện SDK chính thức của AWS (hỗ trợ Java, Python, JS, C#, Go, v.v.), tích hợp sẵn KMS provider. Nó tự động xử lý symmetric encryption, thêm authentication tag, và hỗ trợ key rotation. Hoàn hảo cho inside the application, không cần code thủ công.
- ✅ Đáp ứng đầy đủ: Symmetric, client-side, an toàn cao, và cập nhật mới nhất (Encryption SDK v3.x với hỗ trợ KMS hybrid post-quantum cryptography từ 2024).
📋 Giải thích tất cả các phương án
Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Tôi đánh dấu ✅ (đúng) hoặc ❌ (sai) kèm lý do cụ thể:
-
✅ Create a data key in AWS Key Management Service (AWS KMS). Use the AWS Encryption SDK to encrypt the files.
Như đã giải thích ở trên: Đây là cách chuẩn AWS khuyến nghị cho client-side symmetric encryption trong app. SDK xử lý toàn bộ quy trình envelope encryption, đảm bảo tính toàn vẹn và chống replay attacks. -
❌ Create a Hash-Based Message Authentication Code (HMAC) key in AWS Key Management Service (AWS KMS). Use the AWS Encryption SDK to encrypt the files.
Sai vì: KMS không hỗ trợ tạo HMAC key trực tiếp cho encryption (HMAC chỉ dùng cho message authentication/integrity, không phải symmetric encryption). Encryption SDK yêu cầu symmetric data key (AES), không phải HMAC. Dùng HMAC sẽ không mã hóa file mà chỉ tạo signature, vi phạm yêu cầu symmetric encryption. -
❌ Create a data key pair in AWS Key Management Service (AWS KMS). Use the AWS CLI to encrypt the files.
Sai vì:- KMS không có khái niệm data key pair (pair ám chỉ public/private key cho asymmetric encryption như RSA/ECDSA). Symmetric chỉ dùng data key đơn lẻ.
- AWS CLI (command-line tool) không chạy inside the application mà là external process, không phù hợp cho tích hợp code. CLI không hỗ trợ envelope encryption mượt mà như SDK.
-
❌ Create a data key in AWS Key Management Service (AWS KMS). Use the AWS CLI to encrypt the files.
Sai vì: Mặc dù tạo data key đúng, nhưng AWS CLI (lệnhaws kms generate-data-key+ công cụ mã hóa thủ công) không phải là giải pháp inside the application. CLI yêu cầu shell execution, không tích hợp trực tiếp vào code app, và thiếu tự động hóa encryption envelope như SDK.
📘 Tài liệu tham khảo (cập nhật đến 2026)
- AWS Encryption SDK Developer Guide: docs.aws.amazon.com/encryption-sdk – Hướng dẫn chi tiết envelope encryption với KMS data keys.
- AWS KMS Developer Guide (GenerateDataKey): docs.aws.amazon.com/kms/latest/APIReference/API_GenerateDataKey.html – Xác nhận symmetric data keys cho client-side.
- Best Practices S3 Client-Side Encryption: docs.aws.amazon.com/AmazonS3/latest/userguide/UsingClientSideEncryption.html – Khuyến nghị Encryption SDK.
- AWS re:Post & Whitepapers: Tìm "Client-side encryption with KMS" trên re:Post (cập nhật 2025 với PQ crypto support).
🛠️ Lời khuyên DevOps: Trong production, kết hợp IAM roles với least-privilege policy cho kms:GenerateDataKey, và test với S3 bucket versioning để tránh mất dữ liệu. Nếu scale lớn, dùng KMS multi-Region keys!
What should the developer do to meet these requirements in the MOST secure way?
- A Create an IAM user. Create an access key for the IAM user. Store the access key in the application’s environment variables.
- B Create an IAM role. Create an access key for the IAM role. Store the access key in the application’s environment variables.
- C Create an IAM role. Configure the IAM role to access the specific Amazon S3 API calls the application requires. Associate the IAM role with the EC2 instance.
- D Configure an S3 bucket policy for the S3 bucket. Configure the S3 bucket policy to allow access for the EC2 instance ID.
Xem giải thích
🧩 Phân tích nội dung câu hỏi
Câu hỏi tập trung vào một lập trình viên đang phát triển ứng dụng chạy trên Amazon EC2 instance, cần giải pháp chuyển file từ ứng dụng đến Amazon S3 bucket một cách an toàn nhất (MOST secure way).
🔍 Yêu cầu chính:
- Bảo mật cao nhất: Tránh lưu trữ credentials lâu dài (như access keys), giảm thiểu rủi ro lộ thông tin xác thực.
- Ngữ cảnh: Ứng dụng trên EC2 cần gọi API S3 (ví dụ: PutObject) để upload file.
- Mục tiêu: Áp dụng nguyên tắc least privilege (quyền hạn tối thiểu) và tạm thời credentials để tránh hardcode keys, phù hợp với best practices AWS DevOps (cập nhật đến 2026, IAM roles vẫn là tiêu chuẩn vàng cho workloads trên EC2).
🛠️ Vấn đề phổ biến cần tránh: Lưu access keys trong environment variables dễ bị lộ qua logs, misconfiguration hoặc tấn công (ví dụ: SSRF, insider threats).
📘 Đáp án đúng ✅:
Create an IAM role. Configure the IAM role to access the specific Amazon S3 API calls the application requires. Associate the IAM role with the EC2 instance.
Lý do chọn đáp án này:
- IAM Role cho EC2 cung cấp temporary security credentials (tự động rotate mỗi ~6 giờ), không cần lưu trữ access keys lâu dài.
- Least privilege: Chỉ grant quyền cụ thể cho API S3 cần thiết (ví dụ:
s3:PutObjecttrên bucket cụ thể), giảm bề mặt tấn công. - Tích hợp seamless: EC2 instance metadata service (IMDSv2 - khuyến nghị từ 2023) cung cấp credentials an toàn cho ứng dụng (qua SDK như boto3).
- Đây là best practice AWS cho workloads trên EC2, hỗ trợ OIDC nếu dùng EKS nhưng ở đây là EC2 thuần (cập nhật AWS Well-Architected Framework 2024-2026).
🔍 Phân tích tất cả các phương án
Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá dựa trên tính bảo mật, tuân thủ best practices và rủi ro thực tế.
-
Create an IAM user. Create an access key for the IAM user. Store the access key in the application’s environment variables.
❌ Sai: Tạo IAM user và lưu access key trong environment variables vi phạm nguyên tắc bảo mật cơ bản. Access keys là long-lived credentials, dễ bị lộ qua code repo, logs EC2 hoặc tấn công (ví dụ: đọc env vars qua SSRF). Không áp dụng temporary creds, tăng rủi ro compromise toàn bộ user. AWS khuyến cáo KHÔNG dùng IAM users cho applications (chỉ cho humans). -
Create an IAM role. Create an access key for the IAM role. Store the access key in the application’s environment variables.
❌ Sai: IAM roles KHÔNG hỗ trợ tạo access keys (chúng dành cho temporary creds). Việc cố tạo key cho role là lỗi kỹ thuật và không khả dụng. Lưu trữ key (nếu có) vẫn kém an toàn như phương án 1. Phá vỡ lợi ích cốt lõi của role: tự động hóa creds. -
Create an IAM role. Configure the IAM role to access the specific Amazon S3 API calls the application requires. Associate the IAM role with the EC2 instance.
✅ Đúng: Như giải thích trên. An toàn nhất nhờ temporary creds từ instance metadata (IMDSv2 bắt buộc từ 2024 cho new accounts), least privilege (chỉ API cụ thể nhưs3:PutObject), và zero-effort rotation. Ứng dụng dùng AWS SDK tự động detect role. -
Configure an S3 bucket policy for the S3 bucket. Configure the S3 bucket policy to allow access for the EC2 instance ID.
❌ Sai: Bucket policy KHÔNG hỗ trợ trực tiếp EC2 instance ID làm principal (chỉ hỗ trợ AWS account, IAM entities, hoặc public). Phải dùngaws:SourceVpchoặcaws:SourceVpcegián tiếp, nhưng KHÔNG cung cấp authentication - EC2 vẫn cần creds để gọi API. Dẫn đến bypass IAM, tăng rủi ro unauthorized access nếu instance bị hijack. Không phải giải pháp toàn diện.
📚 Tài liệu tham khảo (cập nhật AWS 2026)
- IAM Roles for Amazon EC2: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-roles-for-amazon-ec2.html (Best practice chính thức).
- AWS Well-Architected Framework - Security Pillar: https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/welcome.html (Nhấn mạnh roles > keys).
- IMDSv2 Best Practices: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configuring-instance-metadata-service.html (Bắt buộc từ 2024 để chống SSRF).
- S3 Security Best Practices: https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html (Bucket policy chỉ bổ sung, không thay thế IAM).
Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần ví dụ policy JSON cụ thể, hãy hỏi thêm.
What should the developer do to meet this requirement?
- A Add a listener rule to the listener to return a fixed response if the Authorization header is missing. Set the fixed response to 401 Unauthorized.
- B Create an authentication action for the listener rules of the ALSet the rule action type to authenticate-cognito. Set the OnUnauthenticatedRequest field to “deny.”
- C Create an Amazon API Gateway API. Configure all API methods to be forwarded to the ALB endpoint. Create an authorizer of the COGNITO_USER_POOLS type. Configure every API method to use that authorizer.
- D Create a new target group that includes an AWS Lambda function target that validates the Authorization header by using Amazon Cognito. Associate the target group with the listener.
Xem giải thích
🧩 Giải thích nội dung câu hỏi
Câu hỏi tập trung vào việc bảo mật một web API được triển khai sau Application Load Balancer (ALB) hướng ra internet (internet-facing) với HTTPS listener. Developer đã cấu hình Amazon Cognito user pool và muốn đảm bảo mọi request đến API đều phải được xác thực (authenticated) qua Cognito.
📌 Yêu cầu chính: Không chỉ authenticate mà còn chặn (deny) các request không xác thực, sử dụng tính năng tích hợp của AWS để đơn giản hóa quy trình, tránh code tùy chỉnh. Đây là kịch bản phổ biến trong DevOps trên AWS, tận dụng ALB authentication để offload việc xác thực khỏi ứng dụng backend, giảm tải và tăng bảo mật. Kiến thức dựa trên AWS ALB phiên bản mới nhất (2026), nơi authenticate-cognito action được hỗ trợ đầy đủ cho listener rules.
✅ Đáp án đúng và lý do lựa chọn
Đáp án đúng: Create an authentication action for the listener rules of the ALB. Set the rule action type to authenticate-cognito. Set the OnUnauthenticatedRequest field to “deny.”
🛠️ Lý do chi tiết:
- ALB hỗ trợ authentication action trực tiếp trên listener rules với loại authenticate-cognito, tích hợp liền mạch với Cognito user pool.
- Bước 1: Tạo rule với action type = authenticate-cognito, chỉ định Cognito user pool.
- Bước 2: Set OnUnauthenticatedRequest = "deny" để chặn hoàn toàn (return 401) các request không có JWT hợp lệ từ Cognito, đảm bảo mọi request đều authenticated.
- Ưu điểm: Không cần code thêm, tự động validate JWT trong Authorization header, forward token đến target nếu hợp lệ. Phù hợp best practice cho ALB + Cognito (scale cao, zero-trust).
📋 Phân tích tất cả các phương án
Dưới đây là phân tích từng lựa chọn (giữ nguyên văn bản gốc bằng tiếng Anh). Tôi đánh dấu ✅ đúng hoặc ❌ sai, kèm giải thích chi tiết bằng tiếng Việt dựa trên AWS docs 2026.
-
Phương án 1: Add a listener rule to the listener to return a fixed response if the Authorization header is missing. Set the fixed response to 401 Unauthorized.
❌ Sai vì: Chỉ kiểm tra header thiếu và return 401 fixed, nhưng không validate token Cognito (không authenticate thực sự). Request có header giả mạo vẫn pass, không an toàn. Đây chỉ là rule đơn giản, không tích hợp Cognito. -
Phương án 2: Create an authentication action for the listener rules of the ALB. Set the rule action type to authenticate-cognito. Set the OnUnauthenticatedRequest field to “deny.”
✅ Đúng vì: Chính xác sử dụng ALB native authentication với authenticate-cognito action trên listener rules. OnUnauthenticatedRequest = "deny" chặn hết request không valid (bao gồm thiếu/mã hóa sai token), forward X-AMZN-OIDC-* headers nếu pass. Hoàn hảo cho yêu cầu "mọi request authenticated". -
Phương án 3: Create an Amazon API Gateway API. Configure all API methods to be forwarded to the ALB endpoint. Create an authorizer of the COGNITO_USER_POOLS type. Configure every API method to use that authorizer.
❌ Sai vì: Thêm API Gateway trước ALB tạo 2 lớp proxy (latency cao, phức tạp, chi phí tăng). ALB đã có listener HTTPS, không cần Gateway. Dù Cognito authorizer tốt, nhưng không phải giải pháp tối ưu khi ALB hỗ trợ trực tiếp. -
Phương án 4: Create a new target group that includes an AWS Lambda function target that validates the Authorization header by using Amazon Cognito. Associate the target group with the listener.
❌ Sai vì: Yêu cầu code Lambda tùy chỉnh để validate header Cognito (phức tạp, dễ lỗi, scale kém). Vi phạm best practice (offload auth khỏi app), tăng cold start Lambda và chi phí. ALB có sẵn authenticate-cognito, không cần Lambda.
📘 Tài liệu tham khảo
- AWS Documentation (2026): Authenticate users with OIDC-compatible identity providers using Application Load Balancers – Chi tiết về
authenticate-cognitovàOnUnauthenticatedRequest. - AWS Well-Architected Framework – Security Pillar: Khuyến nghị ALB auth cho API backend.
- Cognito Developer Guide: Integrating with ALB.
- Exam Prep: AWS DOP-C02 blueprint, phần Networking & Security (ALB rules).
Hy vọng phân tích này giúp bạn ôn thi AWS Certified DevOps Engineer Professional hiệu quả! 🚀 Nếu cần ví dụ CloudFormation, comment nhé!
What are the MOST operationally efficient solutions to reduce the function throttling? (Choose two.)
- A Migrate the function to Amazon Elastic Kubernetes Service (Amazon EKS).
- B Increase the maximum age of events in Lambda.
- C Increase the function’s reserved concurrency.
- D Add the lambda:GetFunctionConcurrency action to the execution role.
- E Request a service quota change for increased concurrency.
Xem giải thích
🧩 Phân tích nội dung câu hỏi
Câu hỏi tập trung vào vấn đề throttling (giới hạn concurrency) của AWS Lambda function, được phát hiện qua metrics trong Amazon CloudWatch. Throttling xảy ra khi function vượt quá giới hạn số lượng invocation đồng thời (concurrency limit) ở mức account hoặc function cụ thể. AWS Lambda có quota mặc định là 1.000 concurrent executions ở mức account (có thể khác theo region và có thể tăng theo yêu cầu). Mục tiêu là tìm hai giải pháp operationally efficient nhất (hiệu quả vận hành cao, ít tốn kém và nhanh chóng triển khai) để giảm throttling.
📘 Kiến thức cập nhật đến 2026: Theo tài liệu AWS Lambda mới nhất (Lambda Developer Guide 2024-2026), concurrency bao gồm provisioned, reserved và unreserved; throttling có thể giảm bằng cách tối ưu reserved concurrency hoặc tăng quota account-level qua Service Quotas console/API (không còn gọi là "Limits" cũ).
✅ Đáp án đúng (Chọn TWO)
Hai đáp án đúng là:
Increase the function’s reserved concurrency.
Request a service quota change for increased concurrency.
Lý do lựa chọn:
🛠️ Reserved concurrency dành riêng tài nguyên concurrency cho function cụ thể, tránh bị function khác "chiếm" hết quota account (ví dụ: set 500 cho function này, đảm bảo ít nhất 500 invocation đồng thời). Đây là giải pháp nhanh, không tốn phí, chỉ dùng AWS Console/CLI.
🛠️ Tăng quota concurrency account-level (mặc định 1.000, có thể lên hàng nghìn) qua Service Quotas là giải pháp gốc rễ nếu quota tổng bị thiếu, hỗ trợ scale lớn. Cả hai đều operationally efficient vì không yêu cầu refactor code hay migrate, phù hợp DevOps best practices (least privilege và quota management).
📘 Nguồn: AWS Lambda Concurrency Documentation và Service Quotas for Lambda (cập nhật 2025).
🔍 Giải thích chi tiết tất cả các phương án
Dưới đây là phân tích từng lựa chọn, với lý do đúng/sai dựa trên cơ chế Lambda throttling (concurrency-based):
-
✅ Increase the function’s reserved concurrency.
Đúng: Phương án này phân bổ concurrency cố định cho function (từ 0 đến quota account), giảm throttling bằng cách ưu tiên tài nguyên. Ví dụ: CLIaws lambda put-function-concurrency --function-name myFunction --reserved-concurrent-executions 300. Hiệu quả cao, không ảnh hưởng function khác. ✅ Operationally efficient nhất cho trường hợp cụ thể. -
✅ Request a service quota change for increased concurrency.
Đúng: Tăng quota account-level (L-THR-A@1 hoặc tương tự) qua AWS Service Quotas console/API, hỗ trợ scale toàn account. Thời gian phê duyệt nhanh (thường <1 ngày cho tăng concurrency). Phù hợp khi nhiều function cùng throttle. ✅ Giải pháp scale lớn, recommended trong AWS Well-Architected Framework. -
❌ Migrate the function to Amazon Elastic Kubernetes Service (Amazon EKS).
Sai: Migrate sang EKS yêu cầu containerize code, setup cluster, autoscaling HPA, rất phức tạp và tốn kém (EKS ~$0.10/giờ/node + EC2). Không efficient cho Lambda thuần (serverless), vi phạm nguyên tắc "least change" để fix throttling. ❌ Không phải giải pháp nhanh gọn. -
❌ Increase the maximum age of events in Lambda.
Sai: Maximum event age (tối đa 6 giờ) chỉ kiểm soát thời gian event sống trong queue (như SQS), không liên quan trực tiếp đến concurrency throttling (là vấn đề invocation đồng thời). Tăng nó chỉ delay retry, có thể làm tình hình tệ hơn nếu queue backlog. ❌ Không giải quyết gốc rễ throttling. -
❌ Add the lambda:GetFunctionConcurrency action to the execution role.
Sai: Đây chỉ là IAM permission để đọc concurrency metrics (GetFunctionConcurrency API), không tăng hay quản lý concurrency. Execution role của Lambda dùng cho runtime access (như S3/DynamoDB), thêm permission này vô ích cho throttling. ❌ Không có tác động đến quota hoặc reserved concurrency.
Tóm tắt khuyến nghị DevOps 🚀: Luôn monitor CloudWatch metrics (Throttles, ConcurrentExecutions), dùng Lambda Insights để debug, và kết hợp Provisioned Concurrency nếu latency-sensitive (cập nhật 2025). Nếu cần, test với AWS Lambda Power Tuning tool!