Ngân hàng đề — AWS Certified Developer Associate

Tìm thấy 1356 câu.

Câu 1151 Chọn nhiều đáp án
A company has an internal website that contains sensitive data. The company wants to make the website public. The company must ensure that only employees who authenticate through the company's OpenID Connect (OIDC) identity provider (IdP) can access the website. A developer needs to implement authentication without editing the website.

Which combination of steps will meet these requirements? (Choose two.)
  1. A Create a public Network Load Balancer.
  2. B Create a public Application Load Balancer.
  3. C Configure a listener for the load balancer that listens on HTTPS port 443. Add a default authenticate action providing the OIDC IdP configuration.
  4. D Configure a listener for the load balancer that listens on HTTP port 80. Add a default authenticate action providing the OIDC IdP configuration.
  5. E Configure a listener for the load balancer that listens on HTTPS port 443. Add a default AWS Lambda action providing an Amazon Resource Name (ARN) to a Lambda authentication function.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc làm cho một website nội bộ chứa dữ liệu nhạy cảm trở thành public, nhưng chỉ cho phép nhân viên xác thực qua OpenID Connect (OIDC) Identity Provider (IdP) của công ty mới truy cập được. 📍 Yêu cầu chính:

  • Website không cần chỉnh sửa code (không edit website).
  • Sử dụng AWS services để implement authentication một cách không xâm lấn.
  • Chọn TWO steps (hai bước kết hợp).

🛠️ Giải pháp cốt lõi theo AWS (cập nhật đến 2026): Sử dụng Application Load Balancer (ALB) public kết hợp authentication action trên listener HTTPS. ALB hỗ trợ native OIDC integration qua cognito hoặc direct OIDC IdP mà không cần thay đổi backend website. Điều này tận dụng ALB Authentication feature, nơi ALB xử lý redirect đến IdP, lấy token và forward request nếu hợp lệ.

✅ Đáp án đúng (Chọn TWO)

Hai lựa chọn đúng là:

  1. Create a public Application Load Balancer.
  2. Configure a listener for the load balancer that listens on HTTPS port 443. Add a default authenticate action providing the OIDC IdP configuration.

Lý do lựa chọn:

  • ALB là lựa chọn lý tưởng vì hỗ trợ HTTP/HTTPS listeners với authenticate actions native cho OIDC (không cần Lambda custom). NLB không hỗ trợ tính năng này. 🛡️ ALB public expose website an toàn, chỉ forward traffic đã auth.
  • Listener HTTPS:443 với default authenticate action OIDC là bước chính: ALB redirect user đến OIDC IdP, validate JWT token, rồi proxy đến backend nếu thành công. HTTPS bắt buộc vì OIDC yêu cầu secure transport (TLS). Không edit code website vì auth xảy ra ở layer 7 (ALB). ✅ Hoàn hảo match yêu cầu!

📋 Phân tích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn một cách rõ ràng. Tôi giữ nguyên văn bản gốc tiếng Anh, đánh dấu ✅/❌ và giải thích bằng tiếng Việt dựa trên docs AWS mới nhất (ALB Authentication hỗ trợ OIDC từ 2018, ổn định đến 2026).

  • ❌ Create a public Network Load Balancer.
    Sai vì: Network Load Balancer (NLB) hoạt động ở layer 4 (TCP/UDP), không hỗ trợ authentication actions như OIDC hay Cognito. NLB chỉ forward traffic mà không inspect HTTP headers/tokens. Không đáp ứng yêu cầu auth mà không edit website. 🛑 Phải dùng ALB (layer 7).

  • ✅ Create a public Application Load Balancer.
    Đúng vì: ALB public hỗ trợ target group backend cho website nội bộ, kết hợp authentication integration với OIDC IdP trực tiếp. Làm website public an toàn, xử lý auth ở edge. Hoàn hảo cho scenario không edit code. 🟢

  • ✅ Configure a listener for the load balancer that listens on HTTPS port 443. Add a default authenticate action providing the OIDC IdP configuration.
    Đúng vì: HTTPS:443 là bắt buộc cho OIDC (secure token exchange). Action authenticate-oidc trên listener ALB config OIDC endpoints (Issuer, Authorization endpoint, Token endpoint, User info endpoint). ALB tự redirect/challenge/validate. Default action apply cho tất cả rules. 🎯 Match chính xác!

  • ❌ Configure a listener for the load balancer that listens on HTTP port 80. Add a default authenticate action providing the OIDC IdP configuration.
    Sai vì: ALB không hỗ trợ authenticate actions trên HTTP port 80 (chỉ HTTPS). OIDC yêu cầu TLS để tránh MITM attacks. Nếu config, sẽ lỗi hoặc không work. 🔒 AWS docs rõ ràng: Authentication requires HTTPS listener.

  • ❌ Configure a listener for the load balancer that listens on HTTPS port 443. Add a default AWS Lambda action providing an Amazon Resource Name (ARN) to a Lambda authentication function.
    Sai vì: Đây là custom Lambda authorizer (invoke Lambda để validate token), không phải native OIDC. Câu hỏi yêu cầu OIDC IdP trực tiếp mà không phức tạp hóa (không đề cập Lambda). Lambda auth cần code custom, có thể vi phạm "không edit website" gián tiếp (phải maintain Lambda). 🚫 Native OIDC tốt hơn.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ config Terraform/CLI, hỏi nhé!

Câu 1152
A developer is working on a web application that requires selective activation of specific features. The developer wants to keep the features hidden from end users until the features are ready for public access.

Which solution will meet these requirements?
  1. A Create a feature flag configuration profile in AWS AppSync. Store the feature flag values in the configuration profile. Activate and deactivate feature flags as needed.
  2. B Store prerelease data in an Amazon DynamoDB table. Enable Amazon DynamoDB Streams in the table. Toggle between hidden and visible states by using DynamoDB Streams.
  3. C Create a feature flag configuration profile in AWS AppConfig. Store the feature flag values in the configuration profile. Activate and deactivate feature flags as needed.
  4. D Store prerelease data in AWS Amplify DataStore. Toggle between hidden and visible states by using Amplify DataStore cloud synchronization.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm AWS

📖 Giải thích nội dung câu hỏi:
Câu hỏi mô tả một lập trình viên đang phát triển ứng dụng web cần kích hoạt chọn lọc các tính năng cụ thể (feature flags). Mục tiêu là giữ các tính năng này ẩn khỏi người dùng cuối cho đến khi chúng sẵn sàng công khai. Đây là yêu cầu phổ biến trong DevOps để triển khai dần dần (progressive delivery), kiểm soát rollout, A/B testing mà không cần deploy code mới. AWS cung cấp các dịch vụ quản lý cấu hình động để hỗ trợ feature flags, giúp thay đổi giá trị flag (true/false) mà không ảnh hưởng đến production traffic. ✅ Kiến thức cập nhật đến 2026: AWS AppConfig là dịch vụ chính thức hỗ trợ feature flags từ năm 2022 và vẫn là lựa chọn tối ưu nhất (AWS Well-Architected Framework - Operational Excellence pillar).

✅ Đáp án đúng và lý do lựa chọn:
Đáp án đúng: Create a feature flag configuration profile in AWS AppConfig. Store the feature flag values in the configuration profile. Activate and deactivate feature flags as needed.
🛠️ Lý do: AWS AppConfig được thiết kế chuyên biệt cho việc quản lý feature flags và cấu hình ứng dụng. Bạn có thể tạo profile feature flag, lưu giá trị (boolean, JSON), và kích hoạt/tắt động qua console, CLI, hoặc API mà không cần redeploy code. Hỗ trợ validation, monitoring với CloudWatch, và integration với Lambda, ECS, EKS. Điều này đáp ứng chính xác yêu cầu "selective activation" và "hidden until ready". Theo tài liệu AWS mới nhất (2026), AppConfig hỗ trợ freeform configuration và feature flags với targeting (segment users), lý tưởng cho web apps.

📘 Giải thích tất cả các phương án (đúng/sai):
Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh dấu ✅ (đúng) hoặc ❌ (sai), kèm giải thích chi tiết bằng tiếng Việt dựa trên best practices AWS.

  • ❌ Create a feature flag configuration profile in AWS AppSync. Store the feature flag values in the configuration profile. Activate and deactivate feature flags as needed.
    🧩 Giải thích sai: AWS AppSync là dịch vụ GraphQL API cho real-time data, không hỗ trợ native feature flags hoặc configuration profiles. Nó tập trung vào resolver mappings và data sources (như DynamoDB), không dùng để toggle features động toàn cục. Sử dụng AppSync sẽ phức tạp hóa, thiếu monitoring/validation chuyên dụng, vi phạm nguyên tắc single responsibility. Không phù hợp với yêu cầu quản lý flags cho web app.

  • ❌ Store prerelease data in an Amazon DynamoDB table. Enable Amazon DynamoDB Streams in the table. Toggle between hidden and visible states by using DynamoDB Streams.
    🧩 Giải thích sai: DynamoDB là NoSQL database, Streams chỉ capture changes để trigger Lambda/Kinesis, không phải công cụ cho feature flags. Lưu "prerelease data" ở đây sẽ yêu cầu custom logic polling/query từ app, gây latency cao, khó scale, và không có UI quản lý flags. Không hỗ trợ activation/deactivation dễ dàng, dễ dẫn đến race conditions hoặc inconsistent states.

  • ✅ Create a feature flag configuration profile in AWS AppConfig. Store the feature flag values in the configuration profile. Activate and deactivate feature flags as needed.
    🛠️ Giải thích đúng: Như đã nêu ở phần đáp án, đây là giải pháp chuẩn AWS. AppConfig cung cấp hosted configuration store, SDK integration (JS, Java, etc.) cho web apps, và rollout strategies (linear, canary). Đáp ứng đầy đủ: ẩn features (flag=false), kích hoạt khi ready (flag=true). Hỗ trợ validator để tránh lỗi config.

  • ❌ Store prerelease data in AWS Amplify DataStore. Toggle between hidden and visible states by using Amplify DataStore cloud synchronization.
    🧩 Giải thích sai: Amplify DataStore dành cho offline-first apps (GraphQL mutations/sync với AppSync), không phải feature flags. Nó lưu data models local rồi sync cloud, nhưng toggle states sẽ yêu cầu custom schema và sync logic phức tạp, không scalable cho flags toàn cục. Thiếu governance, monitoring so với AppConfig, chỉ phù hợp mobile/web với offline needs chứ không phải selective features.

🔗 Tài liệu tham khảo (AWS cập nhật 2026):

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀

Câu 1153 Chọn nhiều đáp án
A developer at a company writes an AWS CloudFormation template. The template refers to subnets that were created by a separate AWS CloudFormation template that the company's network team wrote. When the developer attempts to launch the stack for the first time, the launch fails.

Which template coding mistakes could have caused this failure? (Choose two.)
  1. A The developer's template does not use the Ref intrinsic function to refer to the subnets.
  2. B The developer's template does not use the ImportValue intrinsic function to refer to the subnets.
  3. C The Mappings section of the developer's template does not refer to the subnets.
  4. D The network team's template does not export the subnets in the Outputs section.
  5. E The network team's template does not export the subnets in the Mappings section.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi xoay quanh AWS CloudFormation, một dịch vụ quản lý hạ tầng dưới dạng code (IaC) của AWS. Một lập trình viên (developer) tạo template CloudFormation để triển khai stack, nhưng template này tham chiếu đến các subnet được tạo bởi một template riêng biệt từ đội ngũ mạng (network team). Khi developer lần đầu tiên launch stack, quá trình thất bại.

🔍 Nguyên nhân tiềm ẩn: Đây là tình huống cross-stack reference (tham chiếu giữa các stack khác nhau). CloudFormation yêu cầu cách xử lý đặc biệt để stack mới có thể "nhìn thấy" và sử dụng giá trị từ stack cũ. Lỗi xảy ra do lỗi coding trong template, và cần chọn hai sai lầm có thể gây ra failure này. Vấn đề phổ biến là thiếu export/import values đúng cách giữa các stack.

📘 Kiến thức cập nhật (AWS 2026): CloudFormation vẫn sử dụng cơ chế Fn::Export trong Outputs của stack nguồn và Fn::ImportValue trong stack đích để chia sẻ giá trị (như subnet ID). Không có thay đổi lớn từ phiên bản 2023-2026 (xem docs AWS).

✅ Đáp án đúng (Chọn TWO)

Hai phương án đúng là:
The developer's template does not use the ImportValue intrinsic function to refer to the subnets.
The network team's template does not export the subnets in the Outputs section.

Lý do lựa chọn:
🛠️ Để tham chiếu cross-stack, stack của network team phải export subnet ID qua Outputs với Fn::Export. Developer phải import bằng Fn::ImportValue`. Nếu thiếu một trong hai, CloudFormation không resolve được reference → stack fail khi create/update lần đầu. Đây là lỗi phổ biến trong DOP-C02 exam (DevOps Professional).

📋 Giải thích chi tiết từng phương án

Dưới đây là phân tích tất cả 5 phương án, giữ nguyên văn bản gốc bằng tiếng Anh. Tôi đánh dấu ✅ (đúng) hoặc ❌ (sai), kèm giải thích bằng tiếng Việt:

  • The developer's template does not use the Ref intrinsic function to refer to the subnets.
    ❌ Sai: Fn::Ref chỉ dùng để tham chiếu resources hoặc parameters trong cùng stack. Không áp dụng cho cross-stack (stack khác). Sử dụng Ref ở đây sẽ gây lỗi resolve ngay lập tức, nhưng không phải nguyên nhân chính vì developer cần ImportValue thay thế.

  • The developer's template does not use the ImportValue intrinsic function to refer to the subnets.
    ✅ Đúng: Developer bắt buộc phải dùng Fn::ImportValue để lấy giá trị export từ stack khác (như subnet ID). Nếu thiếu, CloudFormation không tìm thấy reference → failure khi launch stack lần đầu.

  • The Mappings section of the developer's template does not refer to the subnets.
    ❌ Sai: Mappings dùng cho giá trị conditional/select dựa trên Region/Key (như AMI ID theo AZ), không dùng để reference resources cross-stack. Thiếu Mappings không ảnh hưởng đến subnet reference.

  • The network team's template does not export the subnets in the Outputs section.
    ✅ Đúng: Stack nguồn (network team) phải export subnet ID trong Outputs bằng Fn::Export: { Name: "subnet-export" }. Nếu không export, developer không thể import → cross-reference fail hoàn toàn.

  • The network team's template does not export the subnets in the Mappings section.
    ❌ Sai: Mappings không hỗ trợ export (chỉ là static data). Export chỉ làm trong Outputs. Sử dụng Mappings ở đây là nhầm lẫn concept, không gây lỗi cross-stack.

📚 Tài liệu tham khảo

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần ví dụ code YAML, hãy hỏi thêm.

Câu 1154
A developer is running an application on an Amazon EC2 instance. When the application tries to read an Amazon S3 bucket, the application fails. The developer notices that the associated IAM role is missing the S3 read permission. The developer needs to give the application the ability to read the S3 bucket.

Which solution will meet this requirement with the LEAST application disruption?
  1. A Add the permission to the role. Terminate the existing EC2 instance. Launch a new EC2 instance.
  2. B Add the permission to the role so that the change will take effect automatically.
  3. C Add the permission to the role. Hibernate and restart the existing EC2 instance.
  4. D Add the permission to the S3 bucket. Restart the EC2 instance.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào tình huống một lập trình viên đang chạy ứng dụng trên Amazon EC2 instance, nhưng ứng dụng gặp lỗi khi cố gắng đọc dữ liệu từ Amazon S3 bucket. Nguyên nhân là IAM role gắn với EC2 instance thiếu quyền đọc S3 (S3 read permission). Yêu cầu là cấp quyền cho ứng dụng đọc S3 với mức độ gián đoạn ứng dụng thấp nhất (LEAST application disruption).

🛠️ Các khái niệm chính cần nắm:

  • IAM role cho EC2: EC2 sử dụng role để lấy temporary security credentials động qua Instance Metadata Service (IMDS). Credentials này tự động làm mới định kỳ (thường mỗi 6 giờ, nhưng có thể refresh nhanh hơn khi cần).
  • Khi cập nhật policy trên IAM role, thay đổi tự động áp dụng mà không cần restart instance, nhờ cơ chế refresh credentials (thường trong vòng vài giây đến 5 phút).
  • Mục tiêu: Giải pháp phải tối thiểu hóa downtime cho ứng dụng đang chạy.

📘 Kiến thức cập nhật AWS (đến 2026): Theo tài liệu AWS IAM và EC2 mới nhất (AWS re:Post và docs 2024-2026), cập nhật IAM role policy propagate tự động qua IMDSv2 mà không yêu cầu restart, hibernation hay terminate instance.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Add the permission to the role so that the change will take effect automatically.

Lý do 🏆:

  • Đây là giải pháp tối ưu nhất vì chỉ cần thêm S3 read permission (ví dụ: s3:GetObject) vào IAM role policy gắn với EC2. Thay đổi tự động hiệu lực nhờ EC2 fetch credentials mới từ metadata service mà không gián đoạn ứng dụng.
  • Không cần restart, hibernate hay terminate instance → LEAST disruption (downtime gần như zero).
  • Thời gian áp dụng: Thường <5 phút, ứng dụng tiếp tục đọc S3 ngay sau refresh.

📋 Phân tích tất cả các phương án (đúng/sai)

  • Add the permission to the role. Terminate the existing EC2 instance. Launch a new EC2 instance.
    ❌ Sai: Phương án này gián đoạn lớn nhất vì terminate instance sẽ mất toàn bộ trạng thái ứng dụng (nếu không dùng EBS snapshot hoặc AMI). Phải launch new instance → downtime dài (phút đến giờ), không phải LEAST disruption. Dù thêm permission vào role, cách làm này thừa thãi vì role update tự động.

  • Add the permission to the role so that the change will take effect automatically.
    ✅ Đúng: Như giải thích ở trên, đây là cách chuẩn AWS với zero manual intervention ngoài update policy. Credentials refresh tự động qua IMDS → ứng dụng seamless tiếp tục mà không downtime.

  • Add the permission to the role. Hibernate and restart the existing EC2 instance.
    ❌ Sai: Hibernate/restart gây gián đoạn không cần thiết (downtime vài phút để stop/start instance). Update role đã tự động, không cần hibernate (chỉ lưu trạng thái RAM, không refresh credentials nhanh hơn).

  • Add the permission to the S3 bucket. Restart the EC2 instance.
    ❌ Sai: "Add permission to S3 bucket" ám chỉ bucket policy, nhưng không giải quyết gốc rễ (IAM role của EC2 vẫn thiếu quyền). Bucket policy chỉ cho phép nếu role có quyền, nhưng restart vẫn gây downtime vô ích. Sai logic và không least disruption.

📘 Tài liệu tham khảo (AWS chính thức, cập nhật 2024-2026)

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ code policy, hỏi nhé!

Câu 1155 Chọn nhiều đáp án
A developer is writing a web application that is deployed on Amazon EC2 instances behind an internet-facing Application Load Balancer (ALB). The developer must add an Amazon CloudFront distribution in front of the ALB. The developer also must ensure that customer data from outside the VPC is encrypted in transit.

Which combination of CloudFront configuration settings should the developer use to meet these requirements? (Choose two.)
  1. A Restrict viewer access by using signed URLs.
  2. B Set the Origin Protocol Policy setting to Match Viewer.
  3. C Enable field-level encryption.
  4. D Enable automatic object compression.
  5. E Set the Viewer Protocol Policy setting to Redirect HTTP to HTTPS.
Xem giải thích

🧩 Giải thích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc cấu hình Amazon CloudFront để đặt trước Application Load Balancer (ALB) công khai (internet-facing), với ứng dụng web chạy trên EC2 instances trong VPC. Yêu cầu chính là thêm CloudFront làm cache và bảo vệ, đồng thời đảm bảo dữ liệu khách hàng từ bên ngoài VPC được mã hóa trong quá trình truyền (encrypted in transit).

  • Encrypted in transit nghĩa là toàn bộ dữ liệu từ client (khách hàng bên ngoài) đến CloudFront, và từ CloudFront đến origin (ALB) phải sử dụng HTTPS/TLS để tránh lộ thông tin.
  • Đây là câu hỏi chọn TWO (hai) cấu hình CloudFront phù hợp nhất, dựa trên các thiết lập protocol policy.
  • Bối cảnh AWS mới nhất (2026): CloudFront hỗ trợ tích hợp ALB làm custom origin, với các policy protocol linh hoạt để enforce HTTPS end-to-end. ALB hỗ trợ HTTPS listeners mặc định.

📘 Tài liệu tham khảo:

✅ Đáp án đúng (Chọn TWO)

Hai lựa chọn đúng là:

  • Set the Origin Protocol Policy setting to Match Viewer.
  • Set the Viewer Protocol Policy setting to Redirect HTTP to HTTPS.

Lý do lựa chọn 🛠️:

  • Set the Viewer Protocol Policy setting to Redirect HTTP to HTTPS: Thiết lập này buộc client (viewer) phải sử dụng HTTPS khi kết nối đến CloudFront. Nếu client thử HTTP, CloudFront sẽ tự động redirect sang HTTPS (301/302), đảm bảo dữ liệu từ bên ngoài VPC luôn được mã hóa ngay từ đầu đường truyền. Đây là bước đầu tiên và bắt buộc cho "encrypted in transit" từ client.
  • Set the Origin Protocol Policy setting to Match Viewer: Thiết lập này làm cho giao thức từ CloudFront đến origin (ALB) khớp với giao thức từ viewer đến CloudFront. Vì viewer đã dùng HTTPS (từ policy trên), CloudFront sẽ dùng HTTPS đến ALB, hoàn thiện chuỗi mã hóa end-to-end (client → CF → ALB). Nếu dùng HTTP-only, dữ liệu sẽ không an toàn giữa CF và ALB.

Kết hợp hai policy này tạo lớp bảo vệ HTTPS toàn diện, phù hợp với best practice AWS cho web app public-facing.

📋 Phân tích tất cả các phương án

  • ✅ Set the Origin Protocol Policy setting to Match Viewer.
    Đúng 🟢: Như giải thích trên, policy này đảm bảo HTTPS từ CloudFront đến ALB khớp với viewer, hỗ trợ encrypted in transit end-to-end. Lý tưởng cho ALB (custom origin) hỗ trợ HTTPS.

  • ✅ Set the Viewer Protocol Policy setting to Redirect HTTP to HTTPS.
    Đúng 🟢: Buộc redirect HTTP → HTTPS cho viewer, mã hóa dữ liệu từ client bên ngoài VPC ngay từ edge location của CloudFront.

  • ❌ Restrict viewer access by using signed URLs.
    Sai 🔴: Signed URLs dùng để kiểm soát truy cập thời hạn (private content), không liên quan đến mã hóa transit. Nó chỉ ký URL bằng private key, không enforce HTTPS.

  • ❌ Enable field-level encryption.
    Sai 🔴: Tính năng này mã hóa các trường dữ liệu cụ thể (như credit card) trước khi gửi đến origin, nhưng chỉ apply cho payload, không ảnh hưởng đến mã hóa toàn bộ kết nối transit (TLS layer).

  • ❌ Enable automatic object compression.
    Sai 🔴: Chỉ nén file (gzip/brotli) để giảm bandwidth, không cung cấp mã hóa. Nó tối ưu performance nhưng không bảo vệ dữ liệu transit khỏi eavesdropping.

Câu 1156
A developer is implementing an AWS Lambda function that will be invoked when an object is uploaded to Amazon S3. The developer wants to test the Lambda function in a local development machine before publishing the function to a production AWS account.

Which solution will meet these requirements with the LEAST operational overhead?
  1. A Upload an object to Amazon S3 by using the aws s3api put-object CLI command. Wait for the local Lambda invocation from the S3 event.
  2. B Create a sample JSON text file for a put object S3 event. Invoke the Lambda function locally. Use the aws lambda invoke CLI command with the JSON file and Lambda function name as arguments.
  3. C Use the sam local start-lambda CLI command to start Lambda. Use the sam local generate-event s3 put CLI command to create the Lambda test JSON file. Use the sam local invoke CLI command with the JSON file as the argument to invoke the Lambda function.
  4. D Create a JSON string for the put object S3 event. In the AWS Management Console, use the JSON string to create a test event for the local Lambda function. Perform the test.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc test một AWS Lambda function cục bộ (local development machine) trước khi deploy lên production AWS account. Lambda này được kích hoạt bởi sự kiện upload object lên Amazon S3 (S3 Put event). Yêu cầu chính là tìm giải pháp với LEAST operational overhead (ít overhead vận hành nhất), nghĩa là phương pháp đơn giản, nhanh chóng, không cần tài nguyên AWS thực tế, dễ thiết lập và không phụ thuộc vào cloud.

Chi tiết ngữ cảnh:

  • Developer cần mô phỏng sự kiện S3 PutObject một cách chân thực trên máy local (không dùng AWS account production).
  • Overhead thấp: Ưu tiên công cụ native AWS hỗ trợ local testing, tránh tạo resource thật trên AWS (như bucket S3), tránh console web phức tạp.
  • Kiến thức cập nhật 2026: AWS SAM CLI (v1.100+ theo docs 2025-2026) là công cụ chuẩn cho local Lambda dev/test, tích hợp Docker cho runtime emulation, hỗ trợ generate event tự động từ template S3.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use the sam local start-lambda CLI command to start Lambda. Use the sam local generate-event s3 put CLI command to create the Lambda test JSON file. Use the sam local invoke CLI command with the JSON file as the argument to invoke the Lambda function.

Lý do 🛠️:

  • Đây là quy trình chuẩn và tối ưu nhất từ AWS SAM CLI, được thiết kế dành riêng cho local testing Lambda với event sources như S3.
  • Least overhead: Chỉ cần install SAM CLI (một lần), generate event JSON tự động (chính xác format S3 Put), invoke local mà không cần AWS credentials, Docker tự động emulate runtime (Node/Python/Java/etc.).
  • Hoàn toàn offline, nhanh (giây), không tạo resource AWS nào. Phù hợp dev workflow 2026 với SAM build/deploy pipeline.

🔍 Phân tích chi tiết tất cả các phương án

  • ❌ Phương án SAI: Upload an object to Amazon S3 by using the aws s3api put-object CLI command. Wait for the local Lambda invocation from the S3 event.
    Giải thích: Phương án này yêu cầu upload thật lên S3 bucket trên AWS account (cần credentials và internet), nhưng Lambda local KHÔNG nhận event từ S3 cloud vì không có event bridge. Overhead cao: Phụ thuộc AWS, tốn chi phí S3 invocations, không test local thuần túy. Không khả thi cho "local development machine".

  • ❌ Phương án SAI: Create a sample JSON text file for a put object S3 event. Invoke the Lambda function locally. Use the aws lambda invoke CLI command with the JSON file and Lambda function name as arguments.
    Giải thích: aws lambda invoke chỉ invoke Lambda trên AWS (yêu cầu function ARN deployed), không hỗ trợ local function. Để invoke local cần SAM/Docker-Lambda, không phải AWS CLI. Overhead trung bình: Phải tự viết JSON thủ công (dễ lỗi format), không emulate đầy đủ runtime local.

  • ✅ Phương án ĐÚNG: Use the sam local start-lambda CLI command to start Lambda. Use the sam local generate-event s3 put CLI command to create the Lambda test JSON file. Use the sam local invoke CLI command with the JSON file as the argument to invoke the Lambda function.
    Giải thích: SAM CLI (sam local) là tool chính thức AWS cho local sim. generate-event s3 put auto-tạo JSON chuẩn (bucket/key/timestamp), invoke chạy function trong Docker container giống runtime AWS. start-lambda cho gateway sim nếu cần. Overhead thấp nhất: Tích hợp, chính xác 100%, hỗ trợ debug/logs realtime (2026 features như SAM Accelerate).

  • ❌ Phương án SAI: Create a JSON string for the put object S3 event. In the AWS Management Console, use the JSON string to create a test event for the local Lambda function. Perform the test.
    Giải thích: AWS Console chỉ test Lambda trên AWS (function phải deployed trước), không hỗ trợ "local Lambda function". Phải tự craft JSON (rủi ro sai), yêu cầu login AWS Console (web-based, chậm). Overhead cao: Không local, cần deploy tạm function test rồi xóa.

Kết luận 🎯: SAM CLI là best practice cho Lambda local testing theo AWS Well-Architected Framework (Operational Excellence pillar, 2026 edition). Khuyến nghị: Luôn dùng sam build && sam local invoke trong CI/CD pipeline!

Câu 1157
A developer is publishing critical log data to a log group in Amazon CloudWatch Logs. The log group was created 2 months ago. The developer must encrypt the log data by using an AWS Key Management Service (AWS KMS) key so that future data can be encrypted to comply with the company's security policy.

Which solution will meet this requirement with the LEAST effort?
  1. A Use the AWS Encryption SDK for encryption and decryption of the data before writing to the log group.
  2. B Use the AWS KMS console to associate the KMS key with the log group.
  3. C Use the AWS CLI aws logs create-log-group command, and specify the key Amazon Resource Name (ARN).
  4. D Use the AWS CLI aws logs associate-kms-key command, and specify the key Amazon Resource Name (ARN).
Xem giải thích

🔍 Phân tích chi tiết câu hỏi trắc nghiệm AWS

🧩 Nội dung câu hỏi được giải thích rõ ràng:
Câu hỏi xoay quanh tình huống một developer đang publish dữ liệu log quan trọng (critical log data) vào một log group trong Amazon CloudWatch Logs. Log group này đã được tạo từ 2 tháng trước (tức là đã tồn tại). Yêu cầu là phải mã hóa (encrypt) dữ liệu log bằng AWS Key Management Service (KMS) key, nhưng chỉ áp dụng cho dữ liệu tương lai (future data) để tuân thủ chính sách bảo mật của công ty. Giải pháp phải đạt LEAST effort (ít công sức nhất), nghĩa là không làm gián đoạn quy trình hiện tại, không cần tạo mới log group hay thay đổi code publish log.

Mục tiêu chính: Sử dụng server-side encryption của CloudWatch Logs với KMS (tính năng hỗ trợ từ năm 2020 và cập nhật ổn định đến 2026), nơi AWS tự động mã hóa dữ liệu mới khi ingest vào log group mà không cần can thiệp client-side. Log data cũ (đã publish trước) không bị ảnh hưởng, chỉ future data mới được encrypt.

✅ Đáp án đúng:
Use the AWS CLI aws logs associate-kms-key command, and specify the key Amazon Resource Name (ARN).

Lý do lựa chọn (chi tiết):
🚀 Đây là giải pháp ít effort nhất vì:

  • Log group đã tồn tại (không cần tạo mới).
  • Lệnh aws logs associate-kms-key cho phép liên kết (associate) KMS key với log group hiện có chỉ trong một lệnh CLI đơn giản, chỉ cần chỉ định --log-group-name và --kms-key-id (ARN của key).
  • Ngay lập tức, tất cả log data mới (future data) publish vào log group sẽ được server-side encryption tự động bằng KMS key mà không cần thay đổi code developer hay quy trình publish.
  • Không ảnh hưởng data cũ, phù hợp chính xác yêu cầu.
    ✅ Theo tài liệu AWS mới nhất (2026), đây là phương pháp khuyến nghị cho log group existing.

📋 Phân tích tất cả các phương án (đúng/sai):
Dưới đây là giải thích từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh, với lý do đúng/sai dựa trên best practice AWS CloudWatch Logs encryption (cập nhật 2026):

  • ❌ Use the AWS Encryption SDK for encryption and decryption of the data before writing to the log group.
    ❌ Sai vì: Phương án này yêu cầu client-side encryption (encrypt trước khi put log vào CloudWatch), đòi hỏi thay đổi toàn bộ code developer để sử dụng Encryption SDK + KMS, rồi decrypt khi đọc. Điều này tốn effort cao (phải maintain code, handle key rotation), không phải server-side tự động, và không "least effort". CloudWatch Logs ưu tiên server-side encryption.

  • ❌ Use the AWS KMS console to associate the KMS key with the log group.
    ❌ Sai vì: AWS KMS console chỉ quản lý keys (tạo/edit key), KHÔNG hỗ trợ associate key trực tiếp với CloudWatch log group. Phải dùng CloudWatch console/CLI/API. Không có tính năng này trong KMS console (xác nhận docs 2026), dẫn đến thất bại.

  • ❌ Use the AWS CLI aws logs create-log-group command, and specify the key Amazon Resource Name (ARN).
    ❌ Sai vì: Lệnh create-log-group chỉ dùng để tạo log group mới, với tham số --kms-key-id lúc tạo. Nhưng log group đã tồn tại 2 tháng, nên KHÔNG áp dụng (lệnh sẽ báo lỗi nếu group đã có). Yêu cầu tạo mới group sẽ tốn effort (migrate data cũ, update code publish), vi phạm "least effort".

  • ✅ Use the AWS CLI aws logs associate-kms-key command, and specify the key Amazon Resource Name (ARN).
    ✅ Đúng như giải thích ở trên: Least effort, hỗ trợ log group existing, encrypt future data tự động. Syntax: aws logs associate-kms-key --log-group-name my-log-group --kms-key-id arn:aws:kms:....

📘 Tài liệu tham khảo (AWS official docs - cập nhật 2026):

💡 Lời khuyên DevOps: Để kiểm tra, dùng aws logs describe-log-groups --log-group-name-prefix <prefix> xem kmsKeyId đã associate chưa. Key phải cùng region/account với log group! 🚀

Câu 1158
A developer is working on an app for a company that uses an Amazon DynamoDB table named Orders to store customer orders. The table uses OrderID as the partition key and there is no sort key. The table contains more than 100,000 records. The developer needs to add a functionality that will retrieve all Orders records that contain an OrderSource attribute with the MobileApp value.

Which solution will improve the user experience in the MOST efficient way?
  1. A Perform a Scan operation on the Orders table. Provide a QueryFilter condition to filter to only the items where the OrderSource attribute is equal to the MobileApp value.
  2. B Create a local secondary index (LSI) with OrderSource as the partition key. Perform a Query operation by using MobileApp as the key.
  3. C Create a global secondary index (GSI) with OrderSource as the sort key. Perform a Query operation by using MobileApp as the key.
  4. D Create a global secondary index (GSI) with OrderSource as the partition key. Perform a Query operation by using MobileApp as the key.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào Amazon DynamoDB, một dịch vụ NoSQL cơ sở dữ liệu serverless của AWS. Một lập trình viên đang phát triển ứng dụng sử dụng bảng Orders với partition key là OrderID (không có sort key), chứa hơn 100.000 bản ghi. Yêu cầu là thêm tính năng lấy tất cả các bản ghi Orders có thuộc tính OrderSource = "MobileApp" một cách hiệu quả nhất để cải thiện trải nghiệm người dùng (UX).

🔍 Thách thức chính:

  • Không thể sử dụng Query trực tiếp trên bảng chính vì OrderSource không phải là partition key hoặc sort key.
  • Với bảng lớn (>100k records), cần tránh các hoạt động tốn kém như Scan (quét toàn bộ bảng, tiêu tốn nhiều RCU/WCU và thời gian).
  • Giải pháp phải tối ưu hiệu suất (thấp độ trễ, tiết kiệm chi phí) theo best practices DynamoDB mới nhất (2024-2026), ưu tiên secondary indexes để hỗ trợ truy vấn nhanh trên thuộc tính không phải key.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do chọn

Đáp án đúng: Create a global secondary index (GSI) with OrderSource as the partition key. Perform a Query operation by using MobileApp as the key.

Lý do chi tiết 🛠️:

  • GSI linh hoạt: Có thể tạo sau khi bảng đã tồn tại (khác LSI), hỗ trợ partition key hoàn toàn khác so với bảng chính.
  • Query hiệu quả: Với OrderSource làm partition key của GSI, Query với key = "MobileApp" sẽ truy xuất trực tiếp tất cả items khớp (không scan toàn bộ), tiết kiệm RCU (Read Capacity Units), giảm độ trễ <10ms cho hàng triệu items.
  • Tối ưu UX: Phù hợp bảng lớn, scale tự động, chi phí chỉ tính trên dữ liệu truy vấn. Theo AWS 2025, GSI là lựa chọn hàng đầu cho truy vấn non-key attributes.

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn một cách chi tiết, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá dựa trên hiệu suất, tính khả thi và best practices DynamoDB (phiên bản mới nhất 2026).

  • ❌ Perform a Scan operation on the Orders table. Provide a QueryFilter condition to filter to only the items where the OrderSource attribute is equal to the MobileApp value.
    Phân tích sai 🚫: Scan quét toàn bộ bảng (>100k records), áp dụng filter sau → tốn kém RCU (1 RCU/4KB scanned), độ trễ cao (giây đến phút), không scale. Filter chỉ giảm dữ liệu trả về, không giảm scan cost. AWS khuyến cáo tránh Scan cho production với bảng lớn để tối ưu UX.

  • ❌ Create a local secondary index (LSI) with OrderSource as the partition key. Perform a Query operation by using MobileApp as the key.
    Phân tích sai 🚫: LSI bắt buộc dùng partition key giống bảng chính (OrderID), chỉ thay đổi sort key. Không thể dùng OrderSource làm partition key. Hơn nữa, LSI phải tạo cùng lúc với bảng, không thêm sau (bảng đã >100k records). Vi phạm design rules DynamoDB.

  • ❌ Create a global secondary index (GSI) with OrderSource as the sort key. Perform a Query operation by using MobileApp as the key.
    Phân tích sai 🚫: Query GSI yêu cầu partition key trước, sort key sau. Nếu OrderSource là sort key, cần chỉ định partition key (không có ở đây) → Query thất bại hoặc cần Scan (không hiệu quả). AWS docs xác nhận: Query chỉ hiệu quả khi khớp partition key chính xác.

  • ✅ Create a global secondary index (GSI) with OrderSource as the partition key. Perform a Query operation by using MobileApp as the key.
    Phân tích đúng 🏆: Như đã giải thích ở phần đáp án. GSI cho phép partition key mới (OrderSource), Query partition key = "MobileApp" lấy chính xác items cần, hiệu suất cao, chi phí thấp. Hỗ trợ on-demand capacity (mới 2025) cho UX mượt mà.

🔥 Lời khuyên thực hành: Sử dụng AWS Console/CLI tạo GSI: aws dynamodb update-table --table-name Orders --attribute-definitions AttributeName=OrderSource,AttributeType=S --global-secondary-index-updates file://gsi.json. Test với PartiQL cho Query nhanh!

Câu 1159
A company has an application that uses an AWS Lambda function to process data. A developer must implement encryption in transit for all sensitive configuration data, such as API keys, that is stored in the application. The developer creates an AWS Key Management Service (AWS KMS) customer managed key.

What should the developer do next to meet the encryption requirement?
  1. A Create parameters of the String type in AWS Systems Manager Parameter Store. For each parameter, specify the KMS key ID to encrypt the parameter in transit. Reference the GetParameter API call in the Lambda environment variables.
  2. B Create secrets in AWS Secrets Manager by using the customer managed KMS key. Create a new Lambda function and set up a Lambda layer. Configure the Lambda layer to retrieve the values from Secrets Manager.
  3. C Create objects in Amazon S3 for each sensitive data field. Specify the customer managed KMS key to encrypt the object. Configure the Lambda function to retrieve the objects from Amazon S3 during data processing.
  4. D Create encrypted Lambda environment variables. Specify the customer managed KMS key to encrypt the variables. Enable encryption helpers for encryption in transit. Grant permission to the Lambda function's execution role to access the KMS key.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai mã hóa trong quá trình truyền (encryption in transit) cho dữ liệu cấu hình nhạy cảm (như API keys) được lưu trữ trong ứng dụng chạy trên AWS Lambda. Công ty đã tạo một AWS KMS customer managed key (khóa KMS do khách hàng quản lý). Nhà phát triển cần thực hiện bước tiếp theo để đáp ứng yêu cầu này.

🔍 Yêu cầu cốt lõi:

  • Dữ liệu nhạy cảm phải được mã hóa trong quá trình truyền (in transit), nghĩa là bảo vệ khi dữ liệu di chuyển từ nơi lưu trữ đến Lambda runtime (không chỉ mã hóa tại chỗ - at rest).
  • Giải pháp phải tích hợp trực tiếp với Lambda, tận dụng KMS key đã có, đảm bảo Lambda có thể truy cập và giải mã dữ liệu một cách an toàn mà không cần code phức tạp thêm.
  • Đây là tình huống thực tế trong DevOps AWS, ưu tiên giải pháp native của Lambda để đơn giản, bảo mật và chi phí thấp.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create encrypted Lambda environment variables. Specify the customer managed KMS key to encrypt the variables. Enable encryption helpers for encryption in transit. Grant permission to the Lambda function's execution role to access the KMS key.

🛠️ Lý do chọn đáp án này:

  • Lambda hỗ trợ mã hóa environment variables trực tiếp bằng KMS key (tính năng native từ 2018, cập nhật ổn định đến 2026), đảm bảo dữ liệu được mã hóa at rest và in transit khi deploy và runtime.
  • Encryption helpers (tính năng tự động của Lambda runtime) giải mã biến môi trường tại runtime mà không cần code thủ công, bảo vệ in transit từ KMS đến Lambda execution environment qua HTTPS/TLS.
  • Cấp quyền cho execution role qua IAM policy (kms:Decrypt) là bước chuẩn, tích hợp liền mạch.
  • Giải pháp đơn giản nhất, không cần dịch vụ ngoài, phù hợp với "stored in the application" (lưu trực tiếp trong Lambda config).

📋 Phân tích tất cả các phương án (đúng/sai)

  • Create parameters of the String type in AWS Systems Manager Parameter Store. For each parameter, specify the KMS key ID to encrypt the parameter in transit. Reference the GetParameter API call in the Lambda environment variables.
    ❌ Sai vì: Parameter Store loại String chỉ mã hóa at rest cơ bản (không hỗ trợ KMS trực tiếp như SecureString). Không có khái niệm "encrypt in transit" native cho GetParameter API (dù dùng HTTPS, nhưng không dùng KMS cho transit). Tham chiếu qua env vars Lambda không mã hóa dữ liệu khi retrieve, vi phạm yêu cầu và thêm độ phức tạp không cần thiết.

  • Create secrets in AWS Secrets Manager by using the customer managed KMS key. Create a new Lambda function and set up a Lambda layer. Configure the Lambda layer to retrieve the values from Secrets Manager.
    ❌ Sai vì: Secrets Manager mã hóa secrets tốt với KMS (at rest/in transit via HTTPS), nhưng yêu cầu tạo Lambda layer mới và function riêng để retrieve là over-engineering, không trực tiếp "stored in the application". Phức tạp, tốn chi phí (Secrets Manager calls), không tận dụng native Lambda env vars. Không phải bước "next" tối ưu.

  • Create objects in Amazon S3 for each sensitive data field. Specify the customer managed KMS key to encrypt the object. Configure the Lambda function to retrieve the objects from Amazon S3 during data processing.
    ❌ Sai vì: S3 phù hợp lưu trữ lớn (SSE-KMS mã hóa at rest), nhưng không lý tưởng cho config data nhỏ như API keys (tốn chi phí GetObject, latency cao). Retrieve trong processing không đảm bảo "stored in the application" và encryption in transit chỉ qua HTTPS, không native như Lambda env vars. Thêm code xử lý S3 SDK, không an toàn bằng.

  • Create encrypted Lambda environment variables. Specify the customer managed KMS key to encrypt the variables. Enable encryption helpers for encryption in transit. Grant permission to the Lambda function's execution role to access the KMS key.
    ✅ Đúng vì: Đây là giải pháp native, bảo mật cao nhất của AWS Lambda (hỗ trợ KMS trực tiếp cho env vars). Encryption helpers tự động decrypt in transit/runtime, execution role IAM policy đơn giản (ví dụ: kms:Decrypt). Đáp ứng đầy đủ yêu cầu mà không cần dịch vụ ngoài, scale tốt đến 2026.

🧠 Lời khuyên DevOps: Luôn ưu tiên native features như Lambda env vars encrypted để giảm bề mặt tấn công (attack surface). Test bằng AWS Console hoặc CDK/Terraform để verify decryption! 🚀

Câu 1160
A developer is building an ecommerce application. When there is a sale event, the application needs to concurrently call three third-party systems to record the sale. The developer wrote three AWS Lambda functions. There is one Lambda function for each third-party system, which contains complex integration logic.

These Lambda functions are all independent. The developer needs to design the application so each Lambda function will run regardless of others' success or failure.

Which solution will meet these requirements?
  1. A Publish the sale event from the application to an Amazon Simple Queue Service (Amazon SQS) queue. Configure the three Lambda functions to poll the queue.
  2. B Publish the sale event from the application to an Amazon Simple Notification Service (Amazon SNS) topic. Subscribe the three Lambda functions to be triggered by the SNS topic.
  3. C Publish the sale event from the application to an Application Load Balancer (ALB). Add the three Lambda functions as ALB targets.
  4. D Publish the sale event from the application to an AWS Step Functions state machine. Move the logic from the three Lambda functions into the Step Functions state machine.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một ứng dụng ecommerce nơi developer cần xử lý sự kiện bán hàng (sale event) bằng cách gọi đồng thời (concurrently) ba hệ thống bên thứ ba (third-party systems) để ghi nhận giao dịch. Mỗi hệ thống có một AWS Lambda function riêng biệt chứa logic tích hợp phức tạp (complex integration logic). Các Lambda này hoàn toàn độc lập, nghĩa là mỗi function phải chạy bất kể thành công hay thất bại của các function khác (fire-and-forget pattern).

Yêu cầu thiết kế:

  • Phát hành sự kiện bán hàng từ ứng dụng (publish the sale event).
  • Đảm bảo ba Lambda chạy song song, không phụ thuộc lẫn nhau, và không bị ảnh hưởng bởi lỗi của nhau (ví dụ: thất bại của một Lambda không làm gián đoạn message đến Lambda khác).

Đây là kịch bản fan-out (phân phối một message đến nhiều consumer độc lập), thường dùng cho decoupling và high availability trong AWS serverless architecture. 📘

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Publish the sale event from the application to an Amazon Simple Notification Service (Amazon SNS) topic. Subscribe the three Lambda functions to be triggered by the SNS topic.

Lý do (🛠️ Giải thích chi tiết):

  • Amazon SNS là dịch vụ pub/sub messaging hỗ trợ fan-out tự nhiên: Một message publish vào topic sẽ được gửi đồng thời (concurrently) đến tất cả subscribers (ở đây là ba Lambda functions).
  • Mỗi Lambda được trigger độc lập qua SNS Lambda integration (async invocation), nên thất bại của một Lambda không ảnh hưởng đến message delivery của các Lambda khác – SNS đảm bảo at-least-once delivery cho từng subscriber riêng biệt.
  • Phù hợp với yêu cầu independent execution và complex logic trong Lambda, không cần polling.
  • Hiệu suất cao: SNS hỗ trợ lên đến hàng triệu message/giây, raw message delivery (delivery streams), và tích hợp trực tiếp với Lambda mà không cần code thêm.
  • Cập nhật 2026: SNS vẫn là lựa chọn chuẩn cho fan-out serverless (theo AWS Well-Architected Framework - Serverless Lens). ✅

🔍 Phân tích tất cả các phương án

Dưới đây là phân tích từng lựa chọn một cách chi tiết. Tôi giữ nguyên nội dung gốc bằng tiếng Anh, đánh dấu ✅/❌, và giải thích hoàn toàn bằng tiếng Việt dựa trên hành vi AWS thực tế:

  • ❌ [SAI] Publish the sale event from the application to an Amazon Simple Queue Service (Amazon SQS) queue. Configure the three Lambda functions to poll the queue.
    Giải thích sai: SQS là queue-based messaging (FIFO hoặc standard), khi nhiều Lambda poll cùng một queue, sẽ xảy ra race condition – chỉ một Lambda lấy message đầu tiên (visibility timeout), các Lambda khác không nhận được. Không đảm bảo concurrent execution cho tất cả ba Lambda với cùng một event. Nếu dùng SQS fan-out, cần SNS → multiple queues, nhưng option này chỉ dùng single queue nên thất bại. Lambda + SQS yêu cầu polling, không async như SNS. Không đáp ứng "independent regardless of success/failure".

  • ✅ [ĐÚNG] Publish the sale event from the application to an Amazon Simple Notification Service (Amazon SNS) topic. Subscribe the three Lambda functions to be triggered by the SNS topic.
    Giải thích đúng: Như phần trên – SNS topic fan-out ngay lập tức đến ba subscribers Lambda, mỗi cái chạy độc lập async. Failure một Lambda chỉ ảnh hưởng chính nó (có DLQ tùy chọn), message vẫn đến đầy đủ cho các cái khác. Tích hợp native, scale tự động. Hoàn hảo cho ecommerce high-volume events.

  • ❌ [SAI] Publish the sale event from the application to an Application Load Balancer (ALB). Add the three Lambda functions as ALB targets.
    Giải thích sai: ALB là HTTP/HTTPS load balancer cho web traffic, không phải messaging service. Lambda targets trên ALB dùng cho HTTP requests (qua Lambda@Edge hoặc IP targets), không phù hợp publish event (non-HTTP). ALB round-robin traffic đến targets, nhưng không fan-out đồng thời và không decoupling – nếu một Lambda fail, ALB có thể retry hoặc route sai. Không hỗ trợ complex integration events, vi phạm serverless best practices.

  • ❌ [SAI] Publish the sale event from the application to an AWS Step Functions state machine. Move the logic from the three Lambda functions into the Step Functions state machine.
    Giải thích sai: Step Functions dùng cho orchestration workflows (sequential/parallel states), nhưng yêu cầu move logic từ Lambda vào state machine – vi phạm vì logic phức tạp phải giữ nguyên trong Lambda. Dù có Parallel state, Step Functions theo dõi failure (có thể retry, catch, hoặc stop execution), không hoàn toàn independent (fire-and-forget). Không concurrent thực sự cho third-party calls mà không orchestration overhead.

📘 Tài liệu tham khảo (AWS cập nhật đến 2026)

Nếu cần thêm ví dụ code hoặc diagram, hãy cho tôi biết! 🚀