Ngân hàng đề — AWS Certified Developer Associate

Tìm thấy 1356 câu.

Câu 1341
A cloud-based video surveillance company is developing an application that analyzes video files. After the application analyzes the files, the company can discard the files.

The company stores the files in an Amazon S3 bucket. The files are 1 GB in size on average. No file is larger than 2 GB. An AWS Lambda function will run one time for each video file that is processed. The processing is very I/O intensive, and the application must read each file multiple times.

Which solution will meet these requirements in the MOST performance-optimized way?
  1. A Attach an Amazon Elastic Block Store (Amazon EBS) volume that is larger than 1 GB to the Lambda function. Copy the files from the S3 bucket to the EBS volume.
  2. B Attach an Elastic Network Adapter (ENA) to the Lambda function. Use the ENA to read the video files from the S3 bucket.
  3. C Increase the ephemeral storage size to 2 GB. Copy the files from the S3 bucket to the /tmp directory of the Lambda function.
  4. D Configure the Lambda function code to read the video files directly from the S3 bucket.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh một công ty giám sát video dựa trên đám mây đang phát triển ứng dụng phân tích file video lưu trữ trong Amazon S3 bucket. Các đặc điểm chính:

  • File video có kích thước trung bình 1 GB, không vượt quá 2 GB.
  • Sau khi phân tích xong, file có thể bị discard (xóa bỏ).
  • Một AWS Lambda function sẽ chạy một lần cho mỗi file video để xử lý.
  • Quá trình xử lý rất I/O intensive (tập trung vào đọc/ghi dữ liệu), và ứng dụng phải đọc mỗi file nhiều lần (multiple reads).

Yêu cầu chính: Tìm giải pháp tối ưu hiệu suất nhất (MOST performance-optimized) để xử lý, tận dụng đặc thù của Lambda (serverless, không persistent storage mặc định).

Vấn đề cốt lõi: Lambda có latency cao khi đọc trực tiếp từ S3 qua mạng (network-bound), đặc biệt với I/O intensive và multiple reads. Cần cách giảm latency bằng local storage nhanh.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Increase the ephemeral storage size to 2 GB. Copy the files from the S3 bucket to the /tmp directory of the Lambda function.

Lý do:

  • Lambda cung cấp ephemeral storage (/tmp directory) có thể cấu hình từ 512 MB lên đến 10,240 MB (10 GB) (cập nhật từ năm 2022, áp dụng đến 2026).
  • Copy file từ S3 vào /tmp (local disk SSD nhanh) cho phép đọc multiple times với latency thấp (local I/O ~ microsecond), thay vì network latency từ S3 (~ millisecond).
  • Kích thước 2 GB phù hợp file max 2 GB, tối ưu chi phí và performance.
  • Sau xử lý, file tự động discard khi function kết thúc (ephemeral), không cần quản lý cleanup.
  • Tối ưu nhất cho workload I/O intensive theo best practices AWS Lambda.

📋 Giải thích tất cả các phương án (đúng/sai)

  • ✅ [ĐÚNG] Increase the ephemeral storage size to 2 GB. Copy the files from the S3 bucket to the /tmp directory of the Lambda function.

    • Giải thích đúng: Như trên, tận dụng /tmp local storage nhanh cho I/O intensive. AWS khuyến nghị copy dữ liệu lớn/tần suất cao từ S3 vào /tmp để tránh bottleneck mạng. Hiệu suất cao nhất, chi phí thấp (chỉ tính theo GB-second sử dụng).
  • ❌ [SAI] Attach an Amazon Elastic Block Store (Amazon EBS) volume that is larger than 1 GB to the Lambda function. Copy the files from the S3 bucket to the EBS volume.

    • Giải thích sai: Lambda không hỗ trợ attach EBS volume (EBS chỉ dành cho EC2/Fargate). Lambda là serverless, không có quyền truy cập block storage persistent như vậy. Giải pháp này không khả thi.
  • ❌ [SAI] Attach an Elastic Network Adapter (ENA) to the Lambda function. Use the ENA to read the video files from the S3 bucket.

    • Giải thích sai: ENA (Elastic Network Adapter) là tính năng cho EC2 instances để tăng throughput mạng (lên đến 100 Gbps). Lambda không hỗ trợ attach ENA (Lambda tự quản lý networking qua VPC nếu cần). Không giải quyết được multiple reads latency từ S3.
  • ❌ [SAI] Configure the Lambda function code to read the video files directly from the S3 bucket.

    • Giải thích sai: Đọc trực tiếp từ S3 qua S3 GetObject API gây network latency cao (RTT ~10-100ms mỗi request), đặc biệt với file 1-2GB và multiple reads → thời gian xử lý tăng gấp nhiều lần. Không tối ưu cho I/O intensive; AWS khuyên copy vào /tmp cho workload tương tự.

🛠️ Khuyến nghị bổ sung và best practices

  • Tăng timeout Lambda lên 15 phút nếu cần (max hiện tại).
  • Sử dụng Provisioned Concurrency nếu workload đều đặn để giảm cold start.
  • Theo dõi metrics qua CloudWatch (Duration, I/O bytes).

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Câu 1342
A company has an AWS Step Functions state machine named myStateMachine. The company configured a service role for Step Functions.

The developer must ensure that only the myStateMachine state machine can assume the service role.

Which statement should the developer add to the trust policy to meet this requirement?
  1. A
    "Condition": {
        "ArnLike": {
            "aws:SourceArn": "arn:aws:states:ap-south-1:111111111111:stateMachine:myStateMachine"
        }
    }

  2. B
    "Condition": {
        "ArnLike": {
            "aws:SourceArn": "arn:aws:states:ap-south-1:*:*:stateMachine:myStateMachine"
        }
    }

  3. C
    "Condition": {
        "StringEquals": {
            "aws:SourceAccount": "111111111111"
        }
    }

  4. D
    "Condition": {
      "StringNotEquals": {
        "aws:SourceArn": "arn:aws:states:ap-south-1:111111111111:stateMachine:myStateMachine"
      }
    }
Xem giải thích

📘 Phân tích câu hỏi

Câu hỏi yêu cầu chúng ta tìm ra câu lệnh chính xác để thêm vào trust policy của một service role trong AWS Step Functions. Mục tiêu là đảm bảo chỉ state machine myStateMachine có thể giả sử vai trò (assume) service role này.

🔍 Phân tích các lựa chọn

Lựa chọn 1:

"Condition": {
    "ArnLike": {
        "aws:SourceArn": "arn:aws:states:ap-south-1:111111111111:stateMachine:myStateMachine"
    }
}

✅ Đúng:

  • Điều kiện ArnLike được sử dụng để kiểm tra xem ARN của nguồn yêu cầu có khớp với ARN chỉ định hay không.
  • aws:SourceArn xác định ARN của tài nguyên yêu cầu giả sử vai trò. Trong trường hợp này, nó được đặt thành ARN cụ thể của state machine myStateMachine.
  • Điều này đảm bảo rằng chỉ state machine myStateMachine mới có thể giả sử vai trò.

Lựa chọn 2:

"Condition": {
    "ArnLike": {
        "aws:SourceArn": "arn:aws:states:ap-south-1:*:*:stateMachine:myStateMachine"
    }
}

❌ Sai:

  • Dấu * trong aws:SourceArn cho phép bất kỳ tài khoản hoặc tài nguyên nào có tên myStateMachine trong region ap-south-1 có thể giả sử vai trò.
  • Điều này không đáp ứng yêu cầu chỉ cho phép myStateMachine cụ thể có thể giả sử vai trò.

Lựa chọn 3:

"Condition": {
    "StringEquals": {
        "aws:SourceAccount": "111111111111"
    }
}

❌ Sai:

  • Điều kiện này chỉ kiểm tra xem tài khoản nguồn có phải là 111111111111 hay không, nhưng không kiểm tra tài nguyên cụ thể.
  • Điều này có nghĩa là bất kỳ tài nguyên nào trong tài khoản 111111111111 đều có thể giả sử vai trò, không chỉ myStateMachine.

Lựa chọn 4:

"Condition": {
  "StringNotEquals": {
    "aws:SourceArn": "arn:aws:states:ap-south-1:111111111111:stateMachine:myStateMachine"
  }
}

❌ Sai:

  • Điều kiện này kiểm tra xem ARN của nguồn yêu cầu không khớp với ARN chỉ định.
  • Điều này có nghĩa là bất kỳ tài nguyên nào không phải là myStateMachine đều có thể giả sử vai trò, điều ngược lại với yêu cầu.

📚 Tài liệu tham khảo

👍 Kết luận

Lựa chọn 1 là câu lệnh chính xác cần thêm vào trust policy để đảm bảo chỉ state machine myStateMachine có thể giả sử service role.

Câu 1343
A company stores customer credit reports in an Amazon S3 bucket. An analytics service uses standard Amazon S3 GET requests to access the reports.

A developer must implement a solution to redact personally identifiable information (PII) from the reports before the reports reach the analytics service.

Which solution will meet this requirement with the MOST operational efficiency?
  1. A Load the S3 objects into Amazon Redshift by using a COPY command. Implement dynamic data masking. Refactor the analytics service to read from Amazon Redshift.
  2. B Set up an S3 Object Lambda function. Attach the function to an S3 Object Lambda Access Point. Program the function to call a PII redaction API.
  3. C Use AWS Key Management Service (AWS KMS) to implement encryption in the S3 bucket. Re-upload all the existing S3 objects. Give the kms:Decrypt permission to the analytics service.
  4. D Create an Amazon Simple Notification Service (Amazon SNS) topic. Implement message data protection. Refactor the analytics service to publish data access requests to the SNS topic.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào một tình huống thực tế trên AWS: Một công ty lưu trữ báo cáo tín dụng khách hàng (customer credit reports) trong Amazon S3 bucket. Dịch vụ phân tích (analytics service) truy cập các báo cáo này bằng các yêu cầu GET chuẩn của S3. Nhiệm vụ của developer là triển khai giải pháp để loại bỏ thông tin cá nhân có thể nhận dạng (PII - Personally Identifiable Information) khỏi báo cáo trước khi chúng đến tay dịch vụ phân tích.

Yêu cầu chính là giải pháp có hiệu quả vận hành cao nhất (MOST operational efficiency), nghĩa là:

  • 📈 Không làm thay đổi cách thức truy cập hiện tại của analytics service (vẫn dùng S3 GET).
  • 🛡️ Bảo vệ dữ liệu nhạy cảm mà không cần di chuyển hoặc refactor lớn.
  • ⚡ Tiết kiệm chi phí, dễ quản lý, scale tự động, và xử lý on-the-fly (thời gian thực).

Vấn đề cốt lõi: Redact PII động (xóa/mờ thông tin cá nhân như tên, SSN, địa chỉ) mà không sửa object gốc trong S3, tránh downtime hoặc refactor service.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Set up an S3 Object Lambda function. Attach the function to an S3 Object Lambda Access Point. Program the function to call a PII redaction API.

Lý do lựa chọn (theo kiến thức AWS cập nhật 2026):

  • 🛠️ S3 Object Lambda (ra mắt 2021, cập nhật liên tục) cho phép chạy AWS Lambda để transform dữ liệu on-the-fly khi client GET object qua S3 Access Point. Analytics service chỉ cần thay đổi endpoint GET sang Access Point (không refactor lớn).
  • 🔄 Function Lambda có thể gọi API redact PII (như Amazon Comprehend hoặc dịch vụ bên thứ 3), trả về object đã redact mà không lưu thay đổi vào S3 gốc → Zero-copy, serverless, scale tự động.
  • 📊 Hiệu quả vận hành cao nhất: Không di chuyển dữ liệu, không refactor service sâu, chi phí theo usage, hỗ trợ caching với TTL để tối ưu latency.
  • So với các option khác, đây là giải pháp native AWS, ít bước triển khai nhất, phù hợp DevOps best practices.

📋 Phân tích tất cả các phương án

  • ❌ Load the S3 objects into Amazon Redshift by using a COPY command. Implement dynamic data masking. Refactor the analytics service to read from Amazon Redshift.
    Giải thích sai: Phương án này yêu cầu di chuyển toàn bộ dữ liệu từ S3 sang Redshift (COPY command), triển khai dynamic data masking (tính năng Redshift), và refactor hoàn toàn analytics service để đọc từ Redshift thay vì S3 GET. ❌ Quá phức tạp, tốn kém (ETL pipeline, storage Redshift), không scale tốt cho object lớn, và vi phạm yêu cầu "operational efficiency" vì thay đổi lớn kiến trúc.

  • ✅ Set up an S3 Object Lambda function. Attach the function to an S3 Object Lambda Access Point. Program the function to call a PII redaction API.
    Giải thích đúng: Như đã phân tích ở trên. 🛡️ Transform PII động qua Lambda (gọi API redact), analytics service dùng GET qua Access Point → Giữ nguyên flow hiện tại, hiệu quả nhất.

  • ❌ Use AWS Key Management Service (AWS KMS) to implement encryption in the S3 bucket. Re-upload all the existing S3 objects. Give the kms:Decrypt permission to the analytics service.
    Giải thích sai: AWS KMS chỉ mã hóa dữ liệu (encryption at rest/transit), không redact hay xóa PII. ❌ Phải re-upload tất cả object (downtime lớn), cấp kms:Decrypt chỉ cho phép decrypt để đọc, không giải quyết vấn đề lộ PII. Không liên quan đến redaction.

  • ❌ Create an Amazon Simple Notification Service (Amazon SNS) topic. Implement message data protection. Refactor the analytics service to publish data access requests to the SNS topic.
    Giải thích sai: SNS dùng cho pub/sub messaging, message data protection chỉ bảo vệ metadata tin nhắn, không xử lý S3 GET requests hay redact file lớn. ❌ Yêu cầu refactor service để publish request qua SNS (thay vì GET trực tiếp), thêm latency, không phù hợp cho analytics accessing reports.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Giải pháp này tuân thủ AWS best practices 2026: Serverless-first, least privilege, và zero-ETL cho data transformation! 🚀

Câu 1344
A company is using the AWS Serverless Application Model (AWS SAM) to develop a social media application. A developer needs a quick way to test AWS Lambda functions locally by using test event payloads. The developer needs the structure of these test event payloads to match the actual events that AWS services create.

Which solution will meet these requirements with the LEAST development effort?
  1. A Create shareable test Lambda events. Use these test Lambda events for local testing.
  2. B Store manually created test event payloads locally. Use the sam local invoke command with the file path to the payloads.
  3. C Store manually created test event payloads in an Amazon S3 bucket. Use the sam local invoke command with the S3 path to the payloads.
  4. D Use the sam local generate-event command to create test payloads for local testing.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc phát triển ứng dụng serverless sử dụng AWS Serverless Application Model (AWS SAM) cho một ứng dụng mạng xã hội. Nhà phát triển cần một cách nhanh chóng để kiểm tra các hàm AWS Lambda cục bộ (locally) bằng cách sử dụng các test event payloads. Quan trọng nhất, cấu trúc của các test event payloads này phải giống hệt (match exactly) với các event thực tế mà các dịch vụ AWS tạo ra (như từ S3, API Gateway, DynamoDB, v.v.). Giải pháp phải đạt được yêu cầu với ít nỗ lực phát triển nhất (LEAST development effort).

🛠️ Yêu cầu chính:

  • Test local nhanh cho Lambda qua SAM CLI.
  • Event payloads phải authentic (giống event thật từ AWS services).
  • Ưu tiên giải pháp đơn giản, không tốn công tạo thủ công.

📘 Kiến thức liên quan (cập nhật AWS SAM CLI phiên bản mới nhất 2024-2026): AWS SAM CLI cung cấp các lệnh sam local invoke để chạy Lambda local và sam local generate-event để tự động sinh event payloads chuẩn từ schema AWS services, giúp test mà không cần viết tay.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use the sam local generate-event command to create test payloads for local testing.

Lý do 🏆:

  • Lệnh sam local generate-event là tính năng built-in của AWS SAM CLI, cho phép tự động generate test event payloads giống hệt event thực từ AWS services (ví dụ: sam local generate-event s3 put tạo event S3 PutObject chuẩn).
  • LEAST effort: Chỉ cần chạy lệnh với tham số service/event type (như s3, apigw, dynamodb), không cần tạo thủ công, lưu file hay upload S3. Payload được sinh trực tiếp và dùng ngay cho sam local invoke.
  • Hỗ trợ đầy đủ các event phổ biến, đảm bảo tính chính xác cao, phù hợp test nhanh local mà không lệch schema.

📋 Phân tích tất cả các phương án

  • Phương án A: Create shareable test Lambda events. Use these test Lambda events for local testing.
    ❌ Sai: "Shareable test events" ám chỉ test events trong AWS Lambda Console (có thể share qua ARN), nhưng chúng không dành cho local testing qua SAM CLI và không đảm bảo match chính xác event từ services khác (như S3). Phải export thủ công rồi invoke local, tốn effort hơn generate-event.

  • Phương án B: Store manually created test event payloads locally. Use the sam local invoke command with the file path to the payloads.
    ❌ Sai: Yêu cầu tạo thủ công payloads (manually created), dễ sai schema so với event thật AWS. Dù dùng sam local invoke --event file.json tiện local, nhưng effort cao vì phải viết tay JSON phức tạp, không phải giải pháp nhanh nhất.

  • Phương án C: Store manually created test event payloads in an Amazon S3 bucket. Use the sam local invoke command with the S3 path to the payloads.
    ❌ Sai: Tương tự B nhưng tệ hơn vì lưu vào S3 (tốn thêm upload/download, chi phí), vẫn manually created nên dễ lỗi schema. SAM CLI hỗ trợ --event s3://bucket/key, nhưng không least effort so với generate-event trực tiếp.

  • Phương án D: Use the sam local generate-event command to create test payloads for local testing.
    ✅ Đúng: Như giải thích trên, đây là giải pháp tối ưu nhất với zero manual effort cho schema chuẩn, tích hợp trực tiếp SAM CLI cho local testing.

📘 Tài liệu tham khảo (AWS chính thức, cập nhật 2026)

🧪 Mẹo thực hành: Chạy sam local generate-event s3 put --output event.json rồi sam local invoke FunctionName -e event.json để test ngay!

Câu 1345
A developer is building the authentication mechanism for a new mobile app. Users need to be able to sign up, sign in, and access secured backend AWS resources.

Which solution will meet these requirements?
  1. A Use AWS Identity and Access Management Access Analyzer to generate IAM policies. Create an IAM role. Attach the policies to the role. Integrate the IAM role with an identity provider that the mobile app uses.
  2. B Create an IAM policy that grants access to the backend resources. Create an IAM role. Attach the policy to the role. Create an Amazon API Gateway endpoint. Attach the role to the endpoint. Integrate the endpoint with the mobile app.
  3. C Create an Amazon Cognito identity pool. Configure permissions by choosing a default IAM role for authenticated users or guest users in the identity pool. Associate the identity pool with an identity provider. Integrate the identity pool with the mobile app.
  4. D Create an Amazon Cognito user pool. Configure the security requirements by choosing a password policy, multi-factor authentication (MFA) requirements, and user account recovery options. Create an app client. Integrate the app client with the mobile app.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc xây dựng cơ chế xác thực (authentication) cho một ứng dụng di động mới. Các yêu cầu chính bao gồm:

  • Người dùng có thể đăng ký (sign up) tài khoản.
  • Người dùng có thể đăng nhập (sign in).
  • Sau khi xác thực, người dùng truy cập các tài nguyên AWS backend được bảo mật (secured backend AWS resources).

🔍 Phân tích sâu: Đây là tình huống điển hình cần một dịch vụ quản lý người dùng (user directory) hỗ trợ user authentication (xác thực người dùng cuối), không chỉ là ủy quyền (authorization) AWS. AWS cung cấp Amazon Cognito làm giải pháp chính cho mobile/web apps, với hai thành phần chính:

  • User Pools: Xử lý sign up, sign in, MFA, password policy, recovery – phù hợp trực tiếp với yêu cầu.
  • Identity Pools: Cấp temporary AWS credentials sau khi authenticated, để truy cập resources như S3, DynamoDB.

Câu hỏi nhấn mạnh sign up và sign in, nên ưu tiên User Pools. Kiến thức cập nhật đến 2026: Cognito vẫn là dịch vụ chuẩn (theo AWS Well-Architected Framework và re:Invent 2024-2025), hỗ trợ OIDC/SAML federation mới hơn.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create an Amazon Cognito user pool. Configure the security requirements by choosing a password policy, multi-factor authentication (MFA) requirements, and user account recovery options. Create an app client. Integrate the app client with the mobile app.

Lý do chi tiết 🛠️:

  • Amazon Cognito User Pools chính là dịch vụ user directory dành cho sign up, sign in, quản lý user profiles. Nó hỗ trợ đầy đủ password policy (chính sách mật khẩu), MFA (xác thực đa yếu tố), và account recovery (khôi phục tài khoản) – khớp chính xác yêu cầu.
  • Tạo app client để tích hợp SDK vào mobile app (iOS/Android), cấp JWT tokens sau sign in, dùng để authorize backend (qua API Gateway/Lambda).
  • Sau auth, kết hợp Identity Pool để access AWS resources. Đây là best practice cho mobile apps theo AWS (scale đến hàng triệu users, serverless).
  • Không cần IAM thủ công, Cognito tự động generate tokens an toàn.

❌ Phân tích tất cả các phương án (đúng/sai)

  • Phương án 1 (SAI):
    Use AWS Identity and Access Management Access Analyzer to generate IAM policies. Create an IAM role. Attach the policies to the role. Integrate the IAM role with an identity provider that the mobile app uses.
    ❌ Giải thích sai: IAM Access Analyzer chỉ dùng để phân tích và kiểm tra IAM policies (tìm unused permissions, external access risks), KHÔNG phải cơ chế sign up/sign in. IAM roles dành cho services/machines, không cho end-users. Không hỗ trợ user management, MFA, recovery – vi phạm yêu cầu cốt lõi.

  • Phương án 2 (SAI):
    Create an IAM policy that grants access to the backend resources. Create an IAM role. Attach the policy to the role. Create an Amazon API Gateway endpoint. Attach the role to the endpoint. Integrate the endpoint with the mobile app.
    ❌ Giải thích sai: IAM policy/role chỉ xử lý authorization (quyền truy cập resources), KHÔNG hỗ trợ sign up/sign in. API Gateway endpoint với role là cho service-to-service, không quản lý users. Mobile app không thể sign up trực tiếp; thiếu security features như MFA/password policy. Dễ bị abuse nếu expose role trực tiếp.

  • Phương án 3 (SAI):
    Create an Amazon Cognito identity pool. Configure permissions by choosing a default IAM role for authenticated users or guest users in the identity pool. Associate the identity pool with an identity provider. Integrate the identity pool with the mobile app.
    ❌ Giải thích sai: Cognito Identity Pool chỉ cấp temporary AWS credentials SAU khi đã authenticated (từ User Pool hoặc IdP như Google), dùng cho access resources (S3/DynamoDB). Nó KHÔNG hỗ trợ sign up/sign in trực tiếp, không có password policy/MFA/recovery. Phải kết hợp User Pool mới đầy đủ – phương án này thiếu user management.

  • Phương án 4 (ĐÚNG):
    Create an Amazon Cognito user pool. Configure the security requirements by choosing a password policy, multi-factor authentication (MFA) requirements, and user account recovery options. Create an app client. Integrate the app client with the mobile app.
    ✅ Giải thích đúng (như phần trên): Hoàn hảo khớp yêu cầu, scalable, secure theo AWS best practices. Sau này, dùng Identity Pool để access backend resources.

🔥 Tóm tắt nhanh: Chọn User Pool vì authentication trước, authorization sau! Nếu thi DOP-C02, đây là kiến thức core về Cognito.

Câu 1346
A developer is designing an event-driven architecture. An AWS Lambda function that processes data needs to push processed data to a subset of four consumer Lambda functions. The data must be routed based on the value of one field in the data.

Which solution will meet these requirements with the LEAST operational overhead?
  1. A Create an Amazon Simple Queue Service (Amazon SQS) queue and event source mapping for each consumer Lambda function. Add message routing logic to the data-processing Lambda function.
  2. B Create an Amazon Simple Notification Service (Amazon SNS) topic. Subscribe the four consumer Lambda functions to the topic. Add message filtering logic to each consumer Lambda function. Subscribe the data-processing Lambda function to the SNS topic.
  3. C Create a separate Amazon Simple Notification Service (Amazon SNS) topic and subscription for each consumer Lambda function. Add message routing logic to the data-processing Lambda function to publish to the appropriate topic.
  4. D Create a single Amazon Simple Notification Service (Amazon SNS) topic. Subscribe the four consumer Lambda functions to the topic. Add SNS subscription filter policies to each subscription. Configure the data-processing Lambda function to publish to the topic.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi

Câu hỏi mô tả tình huống:
Một lập trình viên đang thiết kế kiến trúc event-driven trên AWS. Có một hàm AWS Lambda chính (data-processing Lambda) xử lý dữ liệu, sau đó cần push dữ liệu đã xử lý đến 4 hàm Lambda consumer con. Việc routing dữ liệu dựa trên giá trị của một trường (field) trong dữ liệu. Yêu cầu giải pháp với operational overhead thấp nhất (ít công vận hành nhất: ít tài nguyên quản lý, ít code tùy chỉnh, ít cấu hình phức tạp).

Yêu cầu cốt lõi:

  • Hỗ trợ fan-out đến nhiều consumer (4 Lambda).
  • Routing thông minh dựa trên field trong message mà không tốn kém vận hành (không cần nhiều queue/topic, không code routing phức tạp ở producer/consumer).
  • Sử dụng dịch vụ AWS serverless như Lambda, SNS, SQS để tối ưu chi phí và scale tự động.

Kiến thức AWS cập nhật 2026:
SNS hỗ trợ subscription filter policies mạnh mẽ (dựa trên message attributes), cho phép server-side filtering mà không cần code ở Lambda consumer. Producer chỉ cần publish message kèm attributes. Đây là best practice cho event routing với low overhead (AWS Well-Architected Framework: Serverless Lens).

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Create a single Amazon Simple Notification Service (Amazon SNS) topic. Subscribe the four consumer Lambda functions to the topic. Add SNS subscription filter policies to each subscription. Configure the data-processing Lambda function to publish to the topic.

Lý do chọn (least operational overhead):
🛠️ Giải pháp sử dụng một SNS topic duy nhất làm pub/sub hub, producer Lambda chỉ publish message kèm attributes (dựa trên field routing). SNS tự động filter tại subscription level (server-side), chỉ deliver message phù hợp đến consumer Lambda tương ứng → không code routing ở producer, không filter ở consumer (giảm code/debug/maintain).

  • Overhead thấp: Quản lý 1 topic + 4 subscriptions (filter policies dễ config via CDK/Terraform/Console). Scale tự động, chi phí pay-per-use.
  • Tuân thủ AWS best practice: Fan-out + routing zero-code ở app layer (SNS filters hỗ trợ match field values qua attributes).
    ✅ Hoàn hảo cho 4 consumers với routing dựa trên 1 field!

❌ Phân tích tất cả các phương án (đúng/sai)

  • [SAI] Create an Amazon Simple Queue Service (Amazon SQS) queue and event source mapping for each consumer Lambda function. Add message routing logic to the data-processing Lambda function.
    ❌ Sai vì overhead cao: Cần 4 SQS queues riêng + event source mapping cho mỗi Lambda → quản lý nhiều queue (DLQ, retention, visibility timeout). Producer Lambda phải code routing logic (if-else dựa trên field để gửi đúng queue) → tăng code complexity, error-prone, khó scale/maintain. Không tận dụng pub/sub fan-out native.

  • [SAI] Create an Amazon Simple Notification Service (Amazon SNS) topic. Subscribe the four consumer Lambda functions to the topic. Add message filtering logic to each consumer Lambda function. Subscribe the data-processing Lambda function to the SNS topic.
    ❌ Sai logic và overhead: Producer Lambda không cần subscribe SNS (nó là publisher). Filter ở consumer Lambda → mỗi Lambda phải code if-else check field → 4x code duplicate, tăng cold start/debug (overhead cao). Không tận dụng SNS filters native → kém hiệu quả so với server-side filtering.

  • [SAI] Create a separate Amazon Simple Notification Service (Amazon SNS) topic and subscription for each consumer Lambda function. Add message routing logic to the data-processing Lambda function to publish to the appropriate topic.
    ❌ Sai vì overhead cao: 4 SNS topics riêng + subscriptions → quản lý nhiều tài nguyên (IAM policies, metrics, quotas). Producer phải code routing (publish đến topic đúng dựa trên field) → phức tạp code, multi-publish calls → latency cao, error handling khó. Không phải least overhead (vi phạm nguyên tắc "single source of truth").

  • [ĐÚNG] Create a single Amazon Simple Notification Service (Amazon SNS) topic. Subscribe the four consumer Lambda functions to the topic. Add SNS subscription filter policies to each subscription. Configure the data-processing Lambda function to publish to the topic.
    ✅ Đúng tuyệt đối: Một topic duy nhất, SNS filter policies (e.g., {"field": [{"anything-but": "value1"}]}) routing tự động dựa trên attributes → producer chỉ publish 1 lần với attributes từ field. Zero code ở consumer, low manage (1 topic), high reliability (SNS retries). Best cho event-driven scale 2026! 🏆

Kết luận 🛠️: Giải pháp đúng tối ưu serverless-native, giảm 80% operational burden so với alternatives. Recommend implement với AWS CDK cho IaC! 🚀

Câu 1347
A developer is creating a new application that will give users the ability to upload documents to Amazon S3. The contents of the documents must not be accessible to any third party.

Which type of encryption will meet this requirement?
  1. A Client-side encryption by using the S3 Encryption Client with a Raw RSA wrapping key that is stored on the user’s device
  2. B Server-side encryption with S3 managed keys (SSE-S3)
  3. C Server-side encryption with AWS KMS keys (SSE-KMS)
  4. D Dual-layer server-side encryption with AWS KMS keys (DSSE-KMS)
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm AWS

✅ Giải thích nội dung câu hỏi:
Câu hỏi tập trung vào việc bảo mật dữ liệu khi người dùng upload tài liệu lên Amazon S3. Yêu cầu chính là nội dung tài liệu (plaintext) không được bất kỳ bên thứ ba nào truy cập được. Ở đây, "bên thứ ba" bao gồm AWS nhân viên, các dịch vụ khác của AWS hoặc bất kỳ thực thể bên ngoài nào không được ủy quyền. Developer cần chọn loại mã hóa đảm bảo S3 chỉ lưu trữ dữ liệu đã mã hóa, và chỉ người có quyền mới decrypt được. Đây là chủ đề về server-side encryption (SSE) và client-side encryption trên S3, theo best practices bảo mật AWS (cập nhật đến 2026, S3 vẫn hỗ trợ SSE-S3, SSE-KMS, SSE-C và client-side libraries như S3 Encryption Client).

🟢 Đáp án đúng:
Server-side encryption with AWS KMS keys (SSE-KMS)
Lý do chọn: SSE-KMS sử dụng Customer Master Key (CMK) do khách hàng quản lý qua AWS KMS (hoặc AWS-managed CMK với kiểm soát chặt chẽ). AWS tự động mã hóa dữ liệu bằng data key được wrap bởi CMK, và chỉ khách hàng mới có quyền decrypt (qua policy KMS). AWS không thể truy cập plaintext vì không có quyền sử dụng CMK mà không được grant kms:Decrypt. Điều này đáp ứng hoàn hảo yêu cầu "không accessible to any third party", bao gồm AWS. Đây là giải pháp server-side dễ implement, tích hợp tốt với IAM policies và audit logs qua CloudTrail (cập nhật 2026: KMS hỗ trợ multi-Region keys và external key stores).

📋 Giải thích tất cả các phương án (đúng/sai)

  • ❌ Client-side encryption by using the S3 Encryption Client with a Raw RSA wrapping key that is stored on the user’s device
    Phân tích sai: Client-side encryption mã hóa dữ liệu trước khi upload lên S3 (S3 chỉ thấy ciphertext), rất tốt để AWS không đọc được. Tuy nhiên, phương án này dùng Raw RSA wrapping key lưu trên thiết bị người dùng, dẫn đến rủi ro cao: thiết bị user dễ bị compromise (malware, theft), RSA raw không an toàn cho production (không envelope encryption chuẩn), và S3 Encryption Client thường recommend dùng KMS DEK thay vì raw key local. Không đáp ứng bảo mật "third party" vì key dễ lộ.

  • ❌ Server-side encryption with S3 managed keys (SSE-S3)
    Phân tích sai: SSE-S3 dùng key do AWS quản lý hoàn toàn (AWS generate, rotate hàng năm). AWS có thể truy cập plaintext khi cần (cho support hoặc legal), không đáp ứng yêu cầu "không accessible to any third party". Phù hợp cho basic encryption nhưng không kiểm soát key.

  • ✅ Server-side encryption with AWS KMS keys (SSE-KMS)
    Phân tích đúng: Như đã giải thích ở trên. AWS mã hóa server-side bằng CMK từ KMS (customer-controlled), audit đầy đủ qua KMS logs. Không cần code thêm ở client, tự động apply qua bucket policy hoặc object-level. Cập nhật 2026: Hỗ trợ KMS keys với automatic rotation và integration S3 Access Points.

  • ❌ Dual-layer server-side encryption with AWS KMS keys (DSSE-KMS)
    Phân tích sai: DSSE-KMS không tồn tại trong AWS S3 (cập nhật đến 2026). S3 chỉ có single-layer SSE-KMS (envelope encryption với KMS). "Dual-layer" có thể ám chỉ SSE-KMS + SSE-S3 nhưng không chuẩn và không cần thiết, dẫn đến overhead không đáng có mà không tăng bảo mật so với SSE-KMS đơn.

📘 Tài liệu tham khảo (AWS official docs - cập nhật 2026)

🛠️ Lời khuyên DevOps: Luôn dùng bucket policy enforce SSE-KMS với CMK custom, kết hợp IAM conditions và S3 Block Public Access để zero-trust!

Câu 1348
A developer is building an application that consists of many AWS Lambda functions. The Lambda functions connect to a single Amazon RDS database.

The developer needs to implement a solution to store the database credentials securely. When the credentials are updated, the Lambda functions must be able to use the new credentials without requiring a code update or a configuration update.

Which solution will meet these requirements?
  1. A Store the credentials as a secret in AWS Secrets Manager. Access the secret at runtime from within the Lambda functions.
  2. B Store the credentials as a secret in AWS Secrets Manager. Access the credentials in environment variables by using the containerDefinitions and valueFrom elements in reference to the secret value.
  3. C Store the credentials as a SecureString parameter in AWS Systems Manager Parameter Store. Add a trigger to pass the credentials to the Lambda functions when the Lambda functions run.
  4. D Store the credentials as a SecureString parameter in AWS Systems Manager Parameter Store. Add a reference to the parameter in an environment variable in the Lambda functions.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc xây dựng một ứng dụng serverless sử dụng nhiều AWS Lambda functions kết nối chung một cơ sở dữ liệu Amazon RDS. 🛠️
Nhà phát triển cần lưu trữ thông tin xác thực (credentials) của RDS một cách an toàn, đồng thời đảm bảo rằng khi credentials được cập nhật (ví dụ: thay đổi mật khẩu), tất cả Lambda functions có thể sử dụng credentials mới MÀ KHÔNG yêu cầu cập nhật code hoặc cập nhật cấu hình (configuration) của Lambda.

📌 Yêu cầu cốt lõi:

  • Bảo mật cao (secure storage).
  • Tự động hóa cập nhật credentials (seamless update).
  • Áp dụng cho nhiều Lambda functions.
  • Không làm gián đoạn hoạt động (no code/config changes).

Đây là tình huống phổ biến trong AWS DevOps, nơi AWS Secrets Manager hoặc AWS Systems Manager (SSM) Parameter Store được sử dụng để quản lý secrets. Theo tài liệu AWS mới nhất (2024-2026), Lambda hỗ trợ tích hợp sâu với cả hai dịch vụ này, nhưng cần chọn giải pháp phù hợp nhất để tránh cache cũ hoặc yêu cầu redeploy.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Store the credentials as a secret in AWS Secrets Manager. Access the secret at runtime from within the Lambda functions.

Lý do chi tiết 🏆:

  • AWS Secrets Manager được thiết kế chuyên biệt cho việc lưu trữ secrets như database credentials, hỗ trợ tự động rotation (xoay vòng credentials) tích hợp với RDS mà không cần code can thiệp.
  • Access at runtime từ trong Lambda code (sử dụng AWS SDK như boto3.client('secretsmanager').get_secret_value()): Mỗi lần Lambda invocation, function sẽ fetch secret phiên bản mới nhất ngay lập tức, không phụ thuộc vào cache của Lambda hay cold/warm start.
  • Đáp ứng đầy đủ yêu cầu: Không cần cập nhật code (chỉ gọi SDK một lần), không cần cập nhật config (environment variables), và áp dụng cho nhiều Lambda functions (IAM role chung có quyền secretsmanager:GetSecretValue).
  • Ưu điểm cập nhật 2026: Secrets Manager hỗ trợ caching tùy chọn ở Lambda side (4 giờ), nhưng runtime fetch đảm bảo always-latest mà không gián đoạn. Đây là best practice cho DOP-C02.

🔍 Giải thích tất cả các phương án

Dưới đây là phân tích từng phương án một cách chi tiết, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá ✅ (đúng) hoặc ❌ (sai), kèm lý do bằng tiếng Việt rõ ràng.

  • Phương án 1: Store the credentials as a secret in AWS Secrets Manager. Access the secret at runtime from within the Lambda functions.
    ✅ Đúng hoàn toàn – Như đã giải thích ở phần đáp án. Giải pháp linh hoạt nhất, runtime fetch đảm bảo credentials luôn mới nhất mà không cache issue, phù hợp với multi-Lambda setup. 🏅

  • Phương án 2: Store the credentials as a secret in AWS Secrets Manager. Access the credentials in environment variables by using the containerDefinitions and valueFrom elements in reference to the secret value.
    ❌ Sai – Mặc dù Secrets Manager đúng cho storage, nhưng containerDefinitions và valueFrom là cú pháp dành cho Amazon ECS/Fargate task definitions, KHÔNG áp dụng cho Lambda (Lambda không có container-based config như vậy). Lambda chỉ hỗ trợ reference secrets qua env vars trực tiếp (ARN reference), không qua ECS elements. Sử dụng sẽ gây lỗi deploy. 🚫

  • Phương án 3: Store the credentials as a SecureString parameter in AWS Systems Manager Parameter Store. Add a trigger to pass the credentials to the Lambda functions when the Lambda functions run.
    ❌ Sai – SSM Parameter Store hỗ trợ SecureString (mã hóa KMS), nhưng không có cơ chế "trigger" tự động pass credentials khi Lambda run. SSM không tích hợp trigger như EventBridge cho việc inject params vào runtime. Thêm trigger thủ công sẽ yêu cầu code/config update, vi phạm yêu cầu. SSM kém hơn Secrets Manager cho secrets động (no built-in rotation). ⚠️

  • Phương án 4: Store the credentials as a SecureString parameter in AWS Systems Manager Parameter Store. Add a reference to the parameter in an environment variable in the Lambda functions.
    ❌ Sai – SSM SecureString có thể reference vào Lambda env vars (qua ARN), và Lambda sẽ resolve giá trị tại cold start (cache lên đến 4 giờ). Tuy nhiên, khi param thay đổi, Lambda chỉ update ở cold start tiếp theo, không phải mọi invocation (warm lambdas có thể dùng giá trị cũ). Hơn nữa, yêu cầu IAM decrypt KMS phức tạp hơn, và SSM Standard tier có giới hạn free tier (40KB), không lý tưởng cho RDS rotation. Không seamless như runtime fetch. 🔄

Câu 1349
A developer is building an application that stores sensitive user data. The application includes an Amazon CloudFront distribution and multiple AWS Lambda functions that handle user requests.

The user requests contain over 20 data fields. Each application transaction contains sensitive data that must be encrypted. Only specific parts of the application need to have the ability to decrypt the data.

Which solution will meet these requirements?
  1. A Associate the CloudFront distribution with a Lambda@Edge function. Configure the function to perform field-level asymmetric encryption by using a user-defined RSA public key that is stored in AWS Key Management Service (AWS KMS).
  2. B Integrate AWS WAF with CloudFront to protect the sensitive data. Use a Lambda function and self-managed keys to perform the encryption and decryption processes.
  3. C Configure the CloudFront distribution to use WebSockets by forwarding all viewer request headers to the origin. Create an asymmetric AWS KMS key. Configure the CloudFront distribution to use field-level encryption. Use the AWS KMS key.
  4. D Configure the cache behavior in the CloudFront distribution to require HTTPS for communication between viewers and CloudFront. Configure GoudFront to require users to access the files by using either signed URLs or signed cookies.
Xem giải thích

🧩 Phân tích nội dung câu hỏi
Câu hỏi mô tả một ứng dụng lưu trữ dữ liệu nhạy cảm của người dùng, sử dụng Amazon CloudFront làm distribution và nhiều AWS Lambda functions để xử lý yêu cầu người dùng. Mỗi yêu cầu chứa hơn 20 trường dữ liệu (data fields), và mỗi giao dịch ứng dụng (transaction) đều bao gồm dữ liệu nhạy cảm phải được mã hóa (encrypted). Quan trọng nhất, chỉ các phần cụ thể của ứng dụng mới có quyền giải mã (decrypt) dữ liệu này.
Yêu cầu chính:

  • Mã hóa tại mức trường dữ liệu (field-level encryption) để bảo vệ dữ liệu nhạy cảm ngay từ edge (CloudFront).
  • Sử dụng mã hóa không đối xứng (asymmetric encryption) để public key mã hóa dễ dàng, nhưng private key chỉ ở nơi cần thiết để giải mã.
  • Phù hợp với kiến thức AWS mới nhất (2024-2026): CloudFront hỗ trợ xử lý edge computing qua Lambda@Edge, kết hợp AWS KMS cho khóa RSA không đối xứng (hỗ trợ API như Encrypt với public key và Decrypt với private key).

📘 Tài liệu tham khảo:

✅ Đáp án đúng: Phương án đầu tiên (Associate the CloudFront distribution with a Lambda@Edge function...).
Lý do chọn: Đây là giải pháp tối ưu vì Lambda@Edge chạy ngay tại edge location của CloudFront, cho phép mã hóa field-level asymmetric tùy chỉnh trước khi dữ liệu đến origin/Lambda functions. Sử dụng RSA public key từ KMS (qua API GetPublicKey hoặc Encrypt), đảm bảo chỉ nơi có private key (specific parts) mới decrypt được. Native Field-Level Encryption của CloudFront không hỗ trợ KMS trực tiếp (chỉ self-managed PEM public keys), nên Lambda@Edge là cách linh hoạt, scalable cho >20 fields và dữ liệu nhạy cảm.

🛠️ Giải thích chi tiết tất cả các phương án:

✅ Phương án ĐÚNG:
Associate the CloudFront distribution with a Lambda@Edge function. Configure the function to perform field-level asymmetric encryption by using a user-defined RSA public key that is stored in AWS Key Management Service (AWS KMS).

  • Tại sao đúng? 🟢 Lambda@Edge tích hợp hoàn hảo với CloudFront viewer-request/origin-request triggers, mã hóa từng field cụ thể (ví dụ: JSON fields nhạy cảm) bằng asymmetric RSA từ KMS (public key encrypt tại edge, private key decrypt tại backend Lambda/origin). KMS quản lý key an toàn (CMK), hỗ trợ rotation/auto-delete. Phù hợp yêu cầu "chỉ specific parts decrypt" vì private key không expose edge. Hiệu suất cao, low latency (edge execution).

❌ Phương án SAI 1:
Integrate AWS WAF with CloudFront to protect the sensitive data. Use a Lambda function và self-managed keys to perform the encryption and decryption processes.

  • Tại sao sai? 🔴 AWS WAF chỉ bảo vệ chống web attacks (SQLi, XSS), không hỗ trợ mã hóa dữ liệu. Self-managed keys thiếu tích hợp KMS (không audit/compliance), Lambda thông thường không chạy tại edge nên không encrypt trước origin. Không giải quyết field-level asymmetric, rủi ro dữ liệu plaintext truyền qua network.

❌ Phương án SAI 2:
Configure the CloudFront distribution to use WebSockets by forwarding all viewer request headers to the origin. Create an asymmetric AWS KMS key. Configure the CloudFront distribution to use field-level encryption. Use the AWS KMS key.

  • Tại sao sai? 🔴 WebSockets dành cho real-time bidirectional (không liên quan encrypt fields trong HTTP requests). Native Field-Level Encryption của CloudFront KHÔNG hỗ trợ KMS keys trực tiếp (yêu cầu upload PEM public key riêng, không reference KMS). Forward headers không giúp encrypt data body. Config sai hoàn toàn, không scalable cho >20 fields động.

❌ Phương án SAI 3:
Configure the cache behavior in the CloudFront distribution to require HTTPS for communication between viewers and CloudFront. Configure GoudFront to require users to access the files by using either signed URLs or signed cookies.

  • Tại sao sai? 🔴 HTTPS chỉ mã hóa transport layer (TLS), không protect field-level data (dữ liệu vẫn plaintext sau decrypt TLS). Signed URLs/Cookies chỉ authorize access (private content), không encrypt sensitive fields trong request body. "GoudFront" là lỗi đánh máy (CloudFront), nhưng không giải quyết yêu cầu asymmetric decrypt limited. Chỉ bảo vệ static files, không cho dynamic user data.
Câu 1350
An application includes an Amazon DynamoDB table that is named orders. The table has a primary partition key of id and a global secondary index (GSI) that is named an accountIndex. The GSI has a partition key of accountId and a sort key of orderDateTime.

A developer needs to create an AWS Lambda function to retrieve the orders that have an accountId of 100.

Which solution will meet this requirement by using the LEAST read capacity?
  1. A Define a DynamoDB API request for the GetItem action with the following parameters:
    {
      "TableName": "orders",
      "Key": {
        "accountId": { "S": "100" }
      }
    }

  2. B Define a DynamoDB API request for the BatchGetItem action with the following parameters:
    {
      "RequestItems": {
        "orders": {
          "Keys": [
            {
              "accountId": {
                "S": "100"
              }
            }
          ]
        }
      }
    }

  3. C Define a DynamoDB API request for the Scan action with the following parameters:
    {
      "TableName": "orders",
      "IndexName": "accountIndex",
      "FilterExpression": "accountId = :accountId",
      "ExpressionAttributeValues": {
        ":accountId": { "S": "100" }
      }
    }

  4. D Define a DynamoDB API request for the Query action with the following parameters:
    {
      "TableName": "orders",
      "IndexName": "accountIndex",
      "KeyConditionExpression": "accountId = :accountId",
      "ExpressionAttributeValues": {
        ":accountId": { "S": "100" }
      }
    }
Xem giải thích

📘 Phân tích câu hỏi

Câu hỏi yêu cầu tìm ra giải pháp để truy xuất dữ liệu từ bảng DynamoDB tên là orders với yêu cầu sau:

  • Bảng orders có khóa phân vùng chính là id.
  • Có một chỉ số thứ cấp toàn cầu (GSI) tên là accountIndex với khóa phân vùng là accountId và khóa sắp xếp là orderDateTime.
  • Mục tiêu là tạo một hàm AWS Lambda để lấy các đơn hàng có accountId là 100 với số lượng dung lượng đọc ít nhất.

🧩 Phân tích các phương án

Phương án 1: Sử dụng GetItem

  • Nội dung: Định nghĩa yêu cầu API DynamoDB cho hành động GetItem với các tham số:

{ "TableName": "orders", "Key": { "accountId": { "S": "100" } } }

- **Phân tích**: ❌ Phương án này không đúng vì `GetItem` yêu cầu phải cung cấp khóa chính (`id`) của bảng `orders`, nhưng trong yêu cầu lại cung cấp `accountId` không tồn tại trong khóa chính.

### Phương án 2: Sử dụng `BatchGetItem`

- **Nội dung**: Định nghĩa yêu cầu API DynamoDB cho hành động `BatchGetItem` với các tham số:
  ```json
{
  "RequestItems": {
    "orders": {
      "Keys": [
        {
          "accountId": {
            "S": "100"
          }
        }
      ]
    }
  }
}
  • Phân tích: ❌ Phương án này không đúng vì BatchGetItem cũng yêu cầu khóa chính của bảng orders là id, nhưng ở đây lại cung cấp accountId.

Phương án 3: Sử dụng Scan

  • Nội dung: Định nghĩa yêu cầu API DynamoDB cho hành động Scan với các tham số:

{ "TableName": "orders", "IndexName": "accountIndex", "FilterExpression": "accountId = :accountId", "ExpressionAttributeValues": { ":accountId": { "S": "100" } } }

- **Phân tích**: ❌ Phương án này không phải là lựa chọn tối ưu vì `Scan` với chỉ số `accountIndex` sẽ phải quét toàn bộ dữ liệu trong chỉ số, sau đó lọc dữ liệu dựa trên điều kiện `accountId = 100`. Điều này có thể dẫn đến việc sử dụng nhiều dung lượng đọc.

### Phương án 4: Sử dụng `Query`

- **Nội dung**: Định nghĩa yêu cầu API DynamoDB cho hành động `Query` với các tham số:
  ```json
{
  "TableName": "orders",
  "IndexName": "accountIndex",
  "KeyConditionExpression": "accountId = :accountId",
  "ExpressionAttributeValues": {
    ":accountId": { "S": "100" }
  }
}
  • Phân tích: ✅ Phương án này đúng vì sử dụng Query với chỉ số accountIndex cho phép truy vấn dữ liệu dựa trên accountId một cách hiệu quả. DynamoDB sẽ sử dụng chỉ số để lấy dữ liệu mà không cần quét toàn bộ bảng, giúp giảm thiểu dung lượng đọc.

📘 Kết luận

Phương án đúng là sử dụng Query với chỉ số accountIndex để lấy các đơn hàng có accountId là 100 với số lượng dung lượng đọc ít nhất.

Tài liệu tham khảo: