Ngân hàng đề — AWS Certified Developer Associate

Tìm thấy 1356 câu.

Câu 831
A developer has an application that stores data in an Amazon S3 bucket. The application uses an HTTP API to store and retrieve objects. When the PutObject API operation adds objects to the S3 bucket the developer must encrypt these objects at rest by using server-side encryption with Amazon S3 managed keys (SSE-S3).
Which solution will meet this requirement?
  1. A Create an AWS Key Management Service (AWS KMS) key. Assign the KMS key to the S3 bucket.
  2. B Set the x-amz-server-side-encryption header when invoking the PutObject API operation.
  3. C Provide the encryption key in the HTTP header of every request.
  4. D Apply TLS to encrypt the traffic to the S3 bucket.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi xoay quanh việc mã hóa dữ liệu tại chỗ (at-rest encryption) cho các object được lưu vào Amazon S3 bucket thông qua API PutObject. Ứng dụng sử dụng HTTP API để lưu và lấy object, và yêu cầu cụ thể phải sử dụng SSE-S3 (Server-Side Encryption with Amazon S3 managed keys).

✅ Yêu cầu chính: Khi gọi PutObject, object phải được mã hóa tự động bằng khóa do S3 quản lý (không phải khóa KMS tùy chỉnh). Điều này đảm bảo dữ liệu an toàn tại S3 mà không cần ứng dụng tự mã hóa trước (client-side). SSE-S3 là phương pháp đơn giản nhất cho mã hóa server-side với key xoay vòng tự động bởi AWS, áp dụng theo phiên bản AWS mới nhất (2024-2026) mà không thay đổi lớn về SSE-S3.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Set the x-amz-server-side-encryption header when invoking the PutObject API operation.

🛠️ Lý do: Đây là cách chính xác và trực tiếp để kích hoạt SSE-S3 cho từng PutObject request. Header x-amz-server-side-encryption: AES256 chỉ định S3 sử dụng khóa managed keys của mình để mã hóa object ngay khi nhận, trước khi lưu trữ. Phương pháp này linh hoạt, không cần cấu hình bucket-level, và phù hợp với ứng dụng gọi API động. AWS khuyến nghị cho các trường hợp cần mã hóa per-object mà không dùng SSE-KMS.

🧩 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, đánh dấu đúng/sai với lý do dựa trên tính năng AWS S3 encryption (cập nhật 2026):

  • Create an AWS Key Management Service (AWS KMS) key. Assign the KMS key to the S3 bucket.
    ❌ Sai: Phương án này mô tả SSE-KMS (sử dụng khóa KMS tùy chỉnh), không phải SSE-S3. SSE-S3 chỉ dùng khóa do S3 quản lý, không liên quan KMS. Gán KMS key vào bucket chỉ áp dụng bucket-level policy cho SSE-KMS, không đáp ứng yêu cầu SSE-S3 cụ thể.

  • Set the x-amz-server-side-encryption header when invoking the PutObject API operation.
    ✅ Đúng: Như đã giải thích ở trên, header này (x-amz-server-side-encryption: AES256) kích hoạt SSE-S3 per-request, mã hóa object tại server-side bằng S3 managed keys. Hoàn hảo cho ứng dụng API động.

  • Provide the encryption key in the HTTP header of every request.
    ❌ Sai: Đây là cách cho SSE-C (Server-Side Encryption with Customer-provided keys), nơi client cung cấp key trong header x-amz-server-side-encryption-customer-key. Không dùng cho SSE-S3 (S3 managed keys), và yêu cầu quản lý key thủ công, phức tạp hơn.

  • Apply TLS to encrypt the traffic to the S3 bucket.
    ❌ Sai: TLS chỉ mã hóa dữ liệu trong quá trình truyền (in-transit), không phải tại chỗ (at-rest). S3 mặc định hỗ trợ HTTPS/TLS, nhưng không đáp ứng yêu cầu mã hóa object sau khi lưu trữ bằng SSE-S3.

Câu 832
A developer needs to perform geographic load testing of an API. The developer must deploy resources to multiple AWS Regions to support the load testing of the API.
How can the developer meet these requirements without additional application code?
  1. A Create and deploy an AWS Lambda function in each desired Region. Configure the Lambda function to create a stack from an AWS CloudFormation template in that Region when the function is invoked.
  2. B Create an AWS CloudFormation template that defines the load test resources. Use the AWS CLI create-stack-set command to create a stack set in the desired Regions.
  3. C Create an AWS Systems Manager document that defines the resources. Use the document to create the resources in the desired Regions.
  4. D Create an AWS CloudFormation template that defines the load test resources. Use the AWS CLI deploy command to create a stack from the template in each Region.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi yêu cầu một lập trình viên (developer) thực hiện kiểm thử tải địa lý (geographic load testing) cho một API trên AWS. Để làm điều này, cần triển khai tài nguyên (resources) vào nhiều AWS Regions nhằm mô phỏng tải từ các vị trí địa lý khác nhau, hỗ trợ kiểm thử tải cho API. Yêu cầu quan trọng: Phải thực hiện mà không cần viết thêm mã ứng dụng (without additional application code).

Điều này nhấn mạnh vào việc sử dụng các công cụ tự động hóa native của AWS để triển khai nhanh chóng, nhất quán qua nhiều vùng (regions), tránh custom code như script hoặc ứng dụng riêng. Chủ đề liên quan đến DevOps automation với CloudFormation và multi-region deployment, phù hợp cho kỳ thi AWS Certified DevOps Engineer Professional (DOP-C02, cập nhật đến 2026).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create an AWS CloudFormation template that defines the load test resources. Use the AWS CLI create-stack-set command to create a stack set in the desired Regions.

🛠️ Lý do chi tiết:

  • AWS CloudFormation StackSets là tính năng chính thức (ra mắt từ 2017, cập nhật liên tục đến 2026) cho phép triển khai stack CloudFormation qua nhiều Regions từ một tài khoản/account duy nhất, mà không cần code thêm. Lệnh aws cloudformation create-stack-set tạo StackSet, sau đó tự động replicate stack vào các Regions chỉ định (qua parameter --regions hoặc execution configuration).
  • Điều này đáp ứng hoàn hảo: Định nghĩa resources trong template IaC (Infrastructure as Code), deploy multi-region tự động, không cần Lambda hay script custom. Hỗ trợ load testing bằng cách tạo resources như EC2 instances, Gateway Load Balancer, hoặc Artillery/JMeter runners ở nhiều Regions.
  • Ưu điểm: Quản lý lifecycle (update/delete) tập trung, delegation cho multi-account, và tích hợp Service-Managed permissions (mới nhất 2024-2026).

📋 Phân tích tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên nội dung gốc bằng tiếng Anh. Tôi đánh dấu ✅ (đúng) hoặc ❌ (sai), kèm giải thích bằng tiếng Việt:

  • ❌ Create and deploy an AWS Lambda function in each desired Region. Configure the Lambda function to create a stack from an AWS CloudFormation template in that Region when the function is invoked.
    🧨 Tại sao sai?: Phương án này yêu cầu deploy Lambda riêng ở mỗi Region và cấu hình code handler để invoke CloudFormation create-stack. Điều này vi phạm yêu cầu "without additional application code" vì phải viết Lambda function code (Python/Node.js) để gọi API CloudFormation. Không hiệu quả cho multi-region (phải manual deploy Lambda trước), dễ lỗi và không scale tốt so với StackSets.

  • ✅ Create an AWS CloudFormation template that defines the load test resources. Use the AWS CLI create-stack-set command to create a stack set in the desired Regions.
    🛠️ Tại sao đúng?: Như đã giải thích ở trên. StackSets là giải pháp native, zero-code cho multi-region CFN deployment. Lệnh CLI đơn giản: aws cloudformation create-stack-set --stack-set-name MyLoadTest --template-body file://template.yaml --regions us-east-1 eu-west-1 ap-southeast-1. Hỗ trợ self-managed hoặc service-managed permissions (cập nhật 2025-2026).

  • ❌ Create an AWS Systems Manager document that defines the resources. Use the document to create the resources in the desired Regions.
    🚫 Tại sao sai?: AWS Systems Manager (SSM) documents dùng cho automation/runbooks như run commands trên EC2/On-Prem, không phải để tạo resources mới như EC2, VPC cho load testing. SSM không hỗ trợ IaC multi-region deployment; chỉ automate operations trên instances hiện có. Không phù hợp và không "create resources" theo yêu cầu.

  • ❌ Create an AWS CloudFormation template that defines the load test resources. Use the AWS CLI deploy command to create a stack from the template in each Region.
    🔄 Tại sao sai?: Lệnh aws cloudformation deploy (từ CFN CLI v2) chỉ tạo một stack ở một Region mỗi lần chạy (cần loop script qua regions). Phải chạy lệnh lặp lại thủ công cho từng Region, vi phạm "without additional application code" (cần bash/Python script để automate loop). Không hiệu quả bằng StackSets cho multi-region.

📘 Tài liệu tham khảo

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần ví dụ template cụ thể, hãy hỏi thêm.

Câu 833
A developer is creating an application that includes an Amazon API Gateway REST API in the us-east-2 Region. The developer wants to use Amazon CloudFront and a custom domain name for the API. The developer has acquired an SSL/TLS certificate for the domain from a third-party provider.
How should the developer configure the custom domain for the application?
  1. A Import the SSL/TLS certificate into AWS Certificate Manager (ACM) in the same Region as the API. Create a DNS A record for the custom domain.
  2. B Import the SSL/TLS certificate into CloudFront. Create a DNS CNAME record for the custom domain.
  3. C Import the SSL/TLS certificate into AWS Certificate Manager (ACM) in the same Region as the API. Create a DNS CNAME record for the custom domain.
  4. D Import the SSL/TLS certificate into AWS Certificate Manager (ACM) in the us-east-1 Region. Create a DNS CNAME record for the custom domain.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc cấu hình custom domain name cho Amazon API Gateway REST API kết hợp với Amazon CloudFront, trong bối cảnh ứng dụng được triển khai ở Region us-east-2 (Ohio). Nhà phát triển đã sở hữu SSL/TLS certificate từ nhà cung cấp bên thứ ba và muốn sử dụng nó để bảo mật custom domain.

📌 Các yếu tố chính cần lưu ý:

  • API Gateway REST API hỗ trợ custom domain, nhưng khi kết hợp CloudFront (làm edge location để cache và phân phối), cấu hình certificate và DNS phải tuân thủ quy tắc toàn cầu của CloudFront.
  • CloudFront yêu cầu ACM certificate phải được import/store ở Region us-east-1 (N. Virginia) – đây là Region duy nhất hỗ trợ certificate cho CloudFront distributions (theo tài liệu AWS cập nhật đến 2026).
  • Custom domain cần trỏ DNS đến CloudFront distribution domain (không phải trực tiếp API Gateway).
  • Certificate từ third-party phải import vào ACM (không hỗ trợ trực tiếp import vào CloudFront).
  • Loại DNS record phù hợp là CNAME (vì CloudFront sử dụng domain alias-style như d123456789.cloudfront.net).

🛠️ Mục tiêu: Đảm bảo HTTPS endpoint với custom domain hoạt động mượt mà, tận dụng CloudFront cho hiệu suất cao và bảo mật.

✅ Đáp án đúng: Import the SSL/TLS certificate into AWS Certificate Manager (ACM) in the us-east-1 Region. Create a DNS CNAME record for the custom domain.

Lý do lựa chọn:

  • Import cert vào ACM us-east-1: CloudFront chỉ chấp nhận certificate từ ACM ở us-east-1 (global endpoint). Dù API ở us-east-2, cert vẫn phải ở đây để associate với CloudFront distribution (API Gateway custom domain sẽ route qua CloudFront).
  • DNS CNAME record: Custom domain (ví dụ: api.example.com) phải CNAME trỏ đến CloudFront domain (không dùng A record vì IP của CloudFront động).
  • Theo best practice AWS 2026, quy trình: Import cert → Tạo CloudFront distribution với origin là API Gateway → Associate custom domain + cert ở CloudFront → Route53/DNS provider tạo CNAME.

📋 Giải thích tất cả các phương án

  • ❌ [SAI] Import the SSL/TLS certificate into AWS Certificate Manager (ACM) in the same Region as the API. Create a DNS A record for the custom domain.
    Phân tích sai: ACM cert ở us-east-2 (same as API) không thể dùng cho CloudFront (chỉ hỗ trợ us-east-1). DNS A record không phù hợp vì CloudFront dùng domain alias động (CNAME mới đúng). Sẽ gây lỗi validation cert và DNS resolution thất bại.

  • ❌ [SAI] Import the SSL/TLS certificate into CloudFront. Create a DNS CNAME record for the custom domain.
    Phân tích sai: CloudFront không hỗ trợ import cert trực tiếp; phải qua ACM (us-east-1). CNAME đúng nhưng cert sai cách → CloudFront không deploy được distribution với custom SSL.

  • ❌ [SAI] Import the SSL/TLS certificate into AWS Certificate Manager (ACM) in the same Region as the API. Create a DNS CNAME record for the custom domain.
    Phân tích sai: ACM cert ở us-east-2 không tương thích với CloudFront (yêu cầu us-east-1). CNAME đúng nhưng cert region sai → Lỗi "Certificate not found" khi associate với CloudFront.

  • ✅ [ĐÚNG] Import the SSL/TLS certificate into AWS Certificate Manager (ACM) in the us-east-1 Region. Create a DNS CNAME record for the custom domain.
    Phân tích đúng: Hoàn hảo khớp quy tắc CloudFront: Cert global ở us-east-1 + CNAME trỏ domain. Đảm bảo HTTPS end-to-end từ custom domain → CloudFront → API Gateway us-east-2.

📘 Tài liệu tham khảo (cập nhật AWS 2026)

🛠️ Lời khuyên thực tế: Sử dụng AWS Console/CLI để import cert (aws acm import-certificate), validate DNS, và test với curl. Nếu dùng Route53, enable alias record thay CNAME cho apex domain!

Câu 834
A developer is creating a template that uses AWS CloudFormation to deploy an application. The application is serverless and uses Amazon API Gateway, Amazon DynamoDB, and AWS Lambda.
Which AWS service or tool should the developer use to define serverless resources in YAML?
  1. A CloudFormation serverless intrinsic functions
  2. B AWS Elastic Beanstalk
  3. C AWS Serverless Application Model (AWS SAM)
  4. D AWS Cloud Development Kit (AWS CDK)
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm AWS

📖 Nội dung câu hỏi:
Câu hỏi tập trung vào việc một lập trình viên đang tạo template sử dụng AWS CloudFormation để triển khai ứng dụng serverless bao gồm Amazon API Gateway, Amazon DynamoDB và AWS Lambda. Cụ thể, câu hỏi yêu cầu xác định dịch vụ hoặc công cụ AWS nào phù hợp nhất để định nghĩa các tài nguyên serverless trong định dạng YAML.
✅ Mục tiêu chính: CloudFormation là nền tảng cốt lõi cho IaC (Infrastructure as Code), nhưng với ứng dụng serverless, cần công cụ mở rộng để đơn giản hóa việc định nghĩa các tài nguyên như Lambda functions, API Gateway endpoints, DynamoDB tables... bằng YAML một cách ngắn gọn, thay vì viết đầy đủ CloudFormation thuần túy (rất dài dòng). Điều này giúp developer tập trung vào logic ứng dụng thay vì boilerplate code.
🛠️ Bối cảnh cập nhật 2026: Theo tài liệu AWS mới nhất (SAM phiên bản 1.140.0+ năm 2024-2026), AWS khuyến nghị sử dụng các framework như SAM cho serverless trên CloudFormation, hỗ trợ đầy đủ YAML cho các dịch vụ này mà không cần viết thủ công hàng trăm dòng resource definitions.

✅ Đáp án đúng: AWS Serverless Application Model (AWS SAM)
Lý do lựa chọn: AWS SAM là framework mã nguồn mở xây dựng trên CloudFormation, chuyên dụng để định nghĩa và triển khai ứng dụng serverless bằng YAML (file sam.yaml hoặc template.yaml). Nó cung cấp cú pháp rút gọn (shorthands) cho API Gateway, Lambda, DynamoDB – ví dụ: Type: AWS::Serverless::Function thay vì đầy đủ AWS::Lambda::Function + IAM roles + events. Developer có thể dùng lệnh sam deploy để build và deploy trực tiếp từ YAML template này lên CloudFormation stack. Đây là lựa chọn tối ưu nhất cho serverless trên CloudFormation theo best practices AWS.

🔍 Giải thích tất cả các phương án (đúng/sai)

  • ❌ CloudFormation serverless intrinsic functions
    Sai vì: Intrinsic functions (như Fn::Sub, Fn::If, Fn::GetAtt) chỉ là các hàm helper chung trong CloudFormation để xử lý tham số động, điều kiện, tham chiếu tài nguyên – không phải công cụ chuyên định nghĩa serverless resources. Chúng không cung cấp shorthand cho Lambda/API Gateway/DynamoDB, và YAML thuần CloudFormation sẽ rất phức tạp (hàng nghìn dòng). Không phù hợp cho serverless template.

  • ❌ AWS Elastic Beanstalk
    Sai vì: Elastic Beanstalk là PaaS để deploy ứng dụng có server (EC2-based, containerized), hỗ trợ auto-scaling nhưng không phải serverless và không dùng YAML template cho CloudFormation. Nó quản lý infrastructure tự động nhưng không định nghĩa API Gateway/Lambda/DynamoDB – trái ngược hoàn toàn với yêu cầu serverless.

  • ✅ AWS Serverless Application Model (AWS SAM)
    Đúng vì: Như đã giải thích ở trên, SAM transform CloudFormation template YAML với macros chuyên serverless (AWS::Serverless::Api, AWS::Serverless::Function, AWS::Serverless::SimpleTable cho DynamoDB). Hỗ trợ local testing (sam local invoke/start-api), CI/CD tích hợp GitHub Actions/CodePipeline. Best practice cho developer theo AWS Well-Architected Framework (Serverless Lens).

  • ❌ AWS Cloud Development Kit (AWS CDK)
    Sai vì: AWS CDK dùng code lập trình (TypeScript/Python/JavaScript/etc.) để tạo CloudFormation template, không phải trực tiếp viết YAML. Nó generate YAML/JSON từ code, phù hợp cho complex apps nhưng không phải "define in YAML" như yêu cầu. Với serverless, CDK có L2 constructs (như @aws-cdk/aws-lambda) nhưng vẫn cần compile sang CloudFormation, không đơn giản bằng SAM YAML.

📘 Tài liệu tham khảo (cập nhật 2026):

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm ví dụ YAML SAM, hãy hỏi nhé!

Câu 835
A developer wants to insert a record into an Amazon DynamoDB table as soon as a new file is added to an Amazon S3 bucket.
Which set of steps would be necessary to achieve this?
  1. A Create an event with Amazon EventBridge that will monitor the S3 bucket and then insert the records into DynamoDB.
  2. B Configure an S3 event to invoke an AWS Lambda function that inserts records into DynamoDB.
  3. C Create an AWS Lambda function that will poll the S3 bucket and then insert the records into DynamoDB.
  4. D Create a cron job that will run at a scheduled time and insert the records into DynamoDB.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc tự động hóa quy trình serverless trên AWS để chèn một bản ghi (record) vào bảng Amazon DynamoDB ngay lập tức (as soon as) khi một file mới được thêm vào bucket Amazon S3. 🛤️ Đây là kịch bản phổ biến trong kiến trúc event-driven, tận dụng các dịch vụ AWS để xử lý sự kiện thời gian thực mà không cần polling thủ công hay lịch trình định kỳ. Yêu cầu nhấn mạnh tính real-time và tự động, phù hợp với mô hình serverless hiện đại (cập nhật đến 2026, AWS vẫn ưu tiên S3 Event Notifications kết hợp Lambda cho hiệu suất cao và chi phí thấp).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Configure an S3 event to invoke an AWS Lambda function that inserts records into DynamoDB.

Lý do:

  • Amazon S3 hỗ trợ Event Notifications (sự kiện như s3:ObjectCreated:*) để kích hoạt trực tiếp AWS Lambda mà không cần trung gian, đảm bảo xử lý ngay lập tức khi file được upload (latency thấp, thường dưới giây). 🕒
  • Lambda function có thể dễ dàng sử dụng AWS SDK (như Boto3 cho Python) để insert record vào DynamoDB với PutItem hoặc BatchWriteItem.
  • Đây là giải pháp best practice theo AWS Well-Architected Framework (Pillar: Reliability & Operational Excellence), tiết kiệm chi phí (chỉ tính phí khi event xảy ra) và scalable tự động. Không cần quản lý server. 🚀

📋 Phân tích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai dựa trên tính khả thi, hiệu suất và phù hợp với yêu cầu "as soon as" (real-time).

  • Create an event with Amazon EventBridge that will monitor the S3 bucket and then insert the records into DynamoDB.
    ❌ Sai: Amazon EventBridge (trước đây là CloudWatch Events) không "monitor" trực tiếp S3 bucket như một agent; nó nhận events từ S3 qua S3 Event Notifications (tích hợp từ 2023), nhưng không insert trực tiếp vào DynamoDB. Bạn cần target như Lambda/SNS để xử lý, làm phức tạp hóa không cần thiết so với S3 direct-to-Lambda. Không hiệu quả cho real-time đơn giản. 🕳️

  • Configure an S3 event to invoke an AWS Lambda function that inserts records into DynamoDB.
    ✅ Đúng: Như đã giải thích ở trên, đây là cách tối ưu nhất với S3 Event Notifications (hỗ trợ PutObject, CompleteMultipartUpload). Lambda nhận event payload chứa metadata file (bucket/key), parse và insert vào DynamoDB. Hoàn hảo cho trigger real-time, idempotent và fault-tolerant (Lambda retries tự động). 🏆

  • Create an AWS Lambda function that will poll the S3 bucket and then insert the records into DynamoDB.
    ❌ Sai: Polling (kiểm tra định kỳ qua ListObjects API) không đảm bảo "as soon as" vì có độ trễ (delay giữa các lần poll), tốn kém (chi phí invocation + API calls cao), và không scalable cho bucket lớn. AWS khuyến cáo tránh polling, ưu tiên push-based events. Vi phạm nguyên tắc serverless efficiency. ⏳

  • Create a cron job that will run at a scheduled time and insert the records into DynamoDB.
    ❌ Sai: Cron job (qua EventBridge Scheduler hoặc EC2) chỉ chạy định kỳ (ví dụ: mỗi phút/giờ), không phản ứng real-time với file mới. Bỏ lỡ events nếu file thêm giữa các lần chạy, gây data loss hoặc delay lớn. Không phù hợp với event-driven architecture. 📅

📘 Tài liệu tham khảo (cập nhật mới nhất AWS 2026)

Giải pháp này giúp bạn đạt điểm cao trong kỳ thi AWS Certified DevOps Engineer Professional! 💪 Nếu cần code sample hoặc diagram, hãy hỏi thêm.

Câu 836 Chọn nhiều đáp án
A development team maintains a web application by using a single AWS CloudFormation template. The template defines web servers and an Amazon RDS database. The team uses the Cloud Formation template to deploy the Cloud Formation stack to different environments.
During a recent application deployment, a developer caused the primary development database to be dropped and recreated. The result of this incident was a loss of data. The team needs to avoid accidental database deletion in the future.
Which solutions will meet these requirements? (Choose two.)
  1. A Add a CloudFormation Deletion Policy attribute with the Retain value to the database resource.
  2. B Update the CloudFormation stack policy to prevent updates to the database.
  3. C Modify the database to use a Multi-AZ deployment.
  4. D Create a CloudFormation stack set for the web application and database deployments.
  5. E Add a Cloud Formation DeletionPolicy attribute with the Retain value to the stack.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh tình huống một đội phát triển duy trì ứng dụng web bằng một template AWS CloudFormation duy nhất, trong đó định nghĩa web servers và Amazon RDS database. Họ sử dụng template này để deploy CloudFormation stack vào các môi trường khác nhau (như dev, staging, prod).

Trong một lần deploy gần đây (application deployment), một developer đã vô tình khiến primary development database bị drop (xóa) và recreate (tạo lại), dẫn đến mất dữ liệu. Vấn đề cốt lõi là cần tránh xóa database ngẫu nhiên trong tương lai.

Yêu cầu chọn TWO solutions phù hợp để bảo vệ database khỏi bị xóa, tập trung vào các cơ chế bảo vệ trong CloudFormation. Đây là vấn đề phổ biến trong DevOps khi sử dụng IaC (Infrastructure as Code), nơi stack update hoặc stack deletion có thể gây thay thế/xóa resource RDS (RDS thường bị replace/delete khi properties thay đổi).

📘 Tài liệu tham khảo chính (cập nhật AWS 2024-2026):

✅ Đáp án đúng (Chọn TWO)

Hai đáp án đúng là:

  1. Add a CloudFormation Deletion Policy attribute with the Retain value to the database resource.
  2. Update the CloudFormation stack policy to prevent updates to the database.

Lý do lựa chọn:
🛠️ Đáp án 1: DeletionPolicy Retain áp dụng trực tiếp lên resource database (RDS), ngăn chặn việc xóa resource khi stack bị delete. RDS sẽ được giữ nguyên dữ liệu ngay cả khi stack bị xóa, tránh mất data vĩnh viễn. Đây là giải pháp chuẩn để bảo vệ resource cụ thể khỏi deletion.

🛠️ Đáp án 2: Stack Policy cho phép định nghĩa chính sách Deny trên resource database, ngăn chặn stack update thay đổi hoặc replace DB (ví dụ: thay đổi instance type dẫn đến drop/recreate). Sự cố trong câu hỏi xảy ra trong "application deployment" (thường là stack update), nên policy này trực tiếp ngăn ngừa.

Cả hai kết hợp bảo vệ toàn diện: chống deletion (stack delete) và chống replacement (stack update).

📋 Phân tích TẤT CẢ các phương án (Đúng/Sai)

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh:

  • ✅ Add a CloudFormation Deletion Policy attribute with the Retain value to the database resource.
    🧩 Đúng: Áp dụng DeletionPolicy: Retain vào resource RDS trong template YAML/JSON. Khi stack delete, RDS không bị xóa mà giữ nguyên (retained resource). Giải quyết trực tiếp rủi ro deletion, dữ liệu an toàn. Ví dụ: DeletionPolicy: Retain trong properties của AWS::RDS::DBInstance.

  • ✅ Update the CloudFormation stack policy to prevent updates to the database.
    🧩 Đúng: Sử dụng aws cloudformation set-stack-policy với JSON policy có Statement Deny trên resource RDS (e.g., "Effect": "Deny", "Action": "Update:*", "Resource": "logicalId-of-DB"). Ngăn stack update thay đổi DB, tránh drop/recreate trong deployment. Hoàn hảo cho môi trường dev nơi update thường xuyên.

  • ❌ Modify the database to use a Multi-AZ deployment.
    🧩 Sai: Multi-AZ chỉ tăng high availability (standby replica failover), không liên quan đến bảo vệ khỏi deletion/replacement trong CloudFormation. RDS Multi-AZ vẫn bị drop khi stack update/delete nếu không có policy bảo vệ.

  • ❌ Create a CloudFormation stack set for the web application and database deployments.
    🧩 Sai: StackSets dùng cho multi-account/region deployment, không giải quyết vấn đề deletion trong single stack. Nó chỉ scale deployment, không bảo vệ resource khỏi xóa ngẫu nhiên.

  • ❌ Add a Cloud Formation DeletionPolicy attribute with the Retain value to the stack.
    🧩 Sai: DeletionPolicy chỉ áp dụng cho resource, không phải stack. Stack không hỗ trợ attribute này (lỗi syntax). Để bảo vệ stack khỏi delete, dùng Termination Protection (aws cloudformation set-termination-protection), nhưng option này sai cú pháp và không chính xác.

Kết luận: Hai giải pháp đúng là cách tốt nhất để bảo vệ RDS trong CloudFormation, phù hợp best practices DevOps Professional! 🚀

Câu 837
A company has an Amazon S3 bucket that contains sensitive data. The data must be encrypted in transit and at rest. The company encrypts the data in the S3 bucket by using an AWS Key Management Service (AWS KMS) key. A developer needs to grant several other AWS accounts the permission to use the S3 GetObject operation to retrieve the data from the S3 bucket.
How can the developer enforce that all requests to retrieve the data provide encryption in transit?
  1. A Define a resource-based policy on the S3 bucket to deny access when a request meets the condition “aws:SecureTransport”: “false”.
  2. B Define a resource-based policy on the S3 bucket to allow access when a request meets the condition “aws:SecureTransport”: “false”.
  3. C Define a role-based policy on the other accounts' roles to deny access when a request meets the condition of “aws:SecureTransport”: “false”.
  4. D Define a resource-based policy on the KMS key to deny access when a request meets the condition of “aws:SecureTransport”: “false”.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc bảo mật dữ liệu nhạy cảm trong Amazon S3 bucket, nơi dữ liệu đã được mã hóa tại chỗ (at rest) bằng khóa AWS KMS. Công ty cần cấp quyền GetObject cho nhiều tài khoản AWS khác để truy xuất dữ liệu, nhưng phải ép buộc mã hóa trong quá trình truyền (in transit) – tức là tất cả các request phải sử dụng HTTPS thay vì HTTP không an toàn.

🔍 Chi tiết vấn đề:

  • S3 hỗ trợ mã hóa tại chỗ qua KMS (SSE-KMS).
  • Encryption in transit nghĩa là sử dụng TLS/HTTPS (cổng 443), không phải HTTP (cổng 80).
  • Developer cần một cơ chế policy-based để deny các request không an toàn từ các account bên ngoài.
  • Điều kiện chính: Sử dụng aws:SecureTransport (true cho HTTPS, false cho HTTP).
  • Mục tiêu: Áp dụng policy trên resource (S3 bucket) để kiểm soát toàn bộ access, không phụ thuộc vào identity của người gọi.

🛠️ Kiến thức AWS cập nhật (tính đến 2026): AWS tiếp tục khuyến nghị bucket policy với aws:SecureTransport để enforce HTTPS cho S3. Không có thay đổi lớn; S3 Block Public Access và VPC endpoints hỗ trợ nhưng không thay thế policy này. (Nguồn: AWS S3 Security Docs, Bucket Policy Examples).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Define a resource-based policy on the S3 bucket to deny access when a request meets the condition “aws:SecureTransport”: “false”.

Lý do 🏆:

  • Bucket policy (resource-based) là cách tối ưu và tập trung để kiểm soát access trên S3 bucket, áp dụng cho tất cả principal (bao gồm cross-account).
  • Điều kiện "aws:SecureTransport": "false" khớp với request HTTP không mã hóa → Deny sẽ chặn ngay, ép buộc tất cả GetObject phải dùng HTTPS.
  • Điều này không ảnh hưởng đến mã hóa KMS (at rest), chỉ enforce transit.
  • Hiệu quả cao: Một policy duy nhất quản lý nhiều account, dễ audit qua CloudTrail.

📋 Giải thích tất cả các phương án (đúng/sai)

  • ✅ Define a resource-based policy on the S3 bucket to deny access when a request meets the condition “aws:SecureTransport”: “false”.
    🟢 Đúng: Như giải thích trên, đây là best practice AWS. Policy mẫu:

    {
      "Statement": [
        {
          "Effect": "Deny",
          "Principal": "*",
          "Action": "s3:GetObject",
          "Resource": "arn:aws:s3:::your-bucket/*",
          "Condition": {
            "Bool": {"aws:SecureTransport": "false"}
          }
        }
      ]
    }
    

    (Nguồn: AWS Docs - Enforce Encryption in Transit).

  • ❌ Define a resource-based policy on the S3 bucket to allow access when a request meets the condition “aws:SecureTransport”: “false”.
    🔴 Sai: Ngược hoàn toàn! "Allow" khi false sẽ cho phép HTTP không an toàn, vi phạm yêu cầu enforce encryption in transit. Policy này còn có thể override các deny khác, dẫn đến lỗ hổng bảo mật lớn.

  • ❌ Define a role-based policy on the other accounts' roles to deny access when a request meets the condition of “aws:SecureTransport”: “false”.
    🔴 Sai:

    • "Role-based policy" ám chỉ identity policy gắn trên IAM roles ở account khác – không phải resource-based.
    • Không khả thi với "several other AWS accounts": Developer không kiểm soát được roles bên kia, phải yêu cầu từng account tự attach policy → phức tạp, dễ lỗi.
    • aws:SecureTransport chỉ hiệu quả ở resource policy (bucket), không áp dụng tốt ở identity policy cho S3 actions.
  • ❌ Define a resource-based policy on the KMS key to deny access when a request meets the condition of “aws:SecureTransport”: “false”.
    🔴 Sai: KMS key policy chỉ kiểm soát decryption (at rest) cho SSE-KMS, không liên quan đến transport (HTTPS/HTTP). GetObject có thể fail decryption nếu KMS deny, nhưng không enforce transit – request vẫn có thể dùng HTTP nếu bucket policy cho phép. (Nguồn: KMS Key Policies).

📘 Kết luận và khuyến nghị

  • Best practice: Kết hợp bucket policy deny này với S3 Block Public Access và CloudTrail logging để audit. Test bằng AWS CLI: aws s3 cp s3://bucket/object . --no-secure (nên fail).
  • Cập nhật 2026: AWS khuyến khích dùng S3 Access Points với policies tương tự cho fine-grained control.
  • Học thêm: Thi DOP-C02, tập trung S3 security trong domain Security (25%). 🚀
Câu 838
An application that is hosted on an Amazon EC2 instance needs access to files that are stored in an Amazon S3 bucket. The application lists the objects that are stored in the S3 bucket and displays a table to the user. During testing, a developer discovers that the application does not show any objects in the list.
What is the MOST secure way to resolve this issue?
  1. A Update the IAM instance profile that is attached to the EC2 instance to include the S3:* permission for the S3 bucket.
  2. B Update the IAM instance profile that is attached to the EC2 instance to include the S3:ListBucket permission for the S3 bucket.
  3. C Update the developer's user permissions to include the S3:ListBucket permission for the S3 bucket.
  4. D Update the S3 bucket policy by including the S3:ListBucket permission and by setting the Principal element to specify the account number of the EC2 instance.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một ứng dụng chạy trên Amazon EC2 instance cần truy cập vào các file lưu trữ trong Amazon S3 bucket. Ứng dụng này sẽ liệt kê (list) các objects trong bucket và hiển thị dưới dạng bảng cho người dùng. Tuy nhiên, trong quá trình testing, developer phát hiện ứng dụng không hiển thị bất kỳ object nào trong danh sách.
Vấn đề cốt lõi: EC2 instance thiếu quyền truy cập để thực hiện hành động ListBucket trên S3 bucket (vì listing objects yêu cầu quyền s3:ListBucket).
Mục tiêu: Tìm cách an toàn nhất (MOST secure) để khắc phục, ưu tiên nguyên tắc least privilege (quyền hạn tối thiểu) theo best practices của AWS IAM.
🛠️ Ngữ cảnh AWS cập nhật 2026: Sử dụng IAM roles cho EC2 qua instance profile là cách tiêu chuẩn, an toàn để cấp quyền tạm thời mà không dùng access keys dài hạn. Hành động s3:ListBucket chỉ cần thiết cho việc liệt kê, không cần quyền rộng hơn.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Update the IAM instance profile that is attached to the EC2 instance to include the S3:ListBucket permission for the S3 bucket.

Lý do chi tiết:

  • Đây là cách an toàn nhất vì:
    • Sử dụng IAM instance profile (role gắn vào EC2) để cấp quyền tạm thời, tự động, không cần hardcode credentials.
    • Chỉ cấp quyền cụ thể s3:ListBucket cho bucket cần thiết, tuân thủ least privilege – tránh over-permission.
    • Ứng dụng trên EC2 sẽ dùng role credentials để gọi S3 API (như ListObjectsV2), khắc phục ngay vấn đề listing objects.
  • Theo AWS best practices (IAM Access Analyzer và Service Control Policies), cách này giảm rủi ro exposure so với bucket policy hoặc user permissions.

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai kèm lý do cụ thể bằng tiếng Việt:

  • ❌ [SAI] Update the IAM instance profile that is attached to the EC2 instance to include the S3: permission for the S3 bucket.*
    Phương án này cấp quyền rộng s3:* (bao gồm tất cả actions như Delete, Put, Get trên bucket), vi phạm least privilege. Dù khắc phục được vấn đề listing, nhưng không an toàn nhất vì tăng rủi ro (ví dụ: app bị exploit có thể xóa data). AWS khuyến cáo chỉ cấp action cụ thể như ListBucket.

  • ✅ [ĐÚNG] Update the IAM instance profile that is attached to the EC2 instance to include the S3:ListBucket permission for the S3 bucket.
    Như đã giải thích ở phần đáp án đúng: An toàn tối ưu, chỉ cấp quyền cần thiết cho EC2 role, hỗ trợ listing objects qua API calls. Hoàn hảo cho production.

  • ❌ [SAI] Update the developer's user permissions to include the S3:ListBucket permission for the S3 bucket.
    Quyền của developer user IAM chỉ ảnh hưởng đến console/CLI của developer, không liên quan đến ứng dụng chạy trên EC2. App trên EC2 sử dụng instance profile riêng, nên cập nhật user permissions không giải quyết vấn đề và kém an toàn (user có thể access từ ngoài).

  • ❌ [SAI] Update the S3 bucket policy by including the S3:ListBucket permission and by setting the Principal element to specify the account number of the EC2 instance.
    Sai về kỹ thuật: EC2 instance không có "account number" (account là của AWS account, không phải instance). Principal phải là IAM role ARN (ví dụ: arn:aws:iam::account:role/EC2Role), không phải account number. Bucket policy phức tạp hơn IAM role và kém linh hoạt cho EC2 access, không phải cách an toàn nhất.

📘 Tài liệu tham khảo (AWS cập nhật mới nhất 2026)

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ code policy, hãy hỏi nhé!

Câu 839
A company is planning to securely manage one-time fixed license keys in AWS. The company's development team needs to access the license keys in automaton scripts that run in Amazon EC2 instances and in AWS CloudFormation stacks.
Which solution will meet these requirements MOST cost-effectively?
  1. A Amazon S3 with encrypted files prefixed with “config”
  2. B AWS Secrets Manager secrets with a tag that is named SecretString
  3. C AWS Systems Manager Parameter Store SecureString parameters
  4. D CloudFormation NoEcho parameters
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào việc quản lý an toàn các license keys cố định một lần (one-time fixed license keys) trong AWS một cách tiết kiệm chi phí nhất (MOST cost-effectively). Công ty cần dev team truy cập các key này từ automation scripts chạy trên Amazon EC2 instances và AWS CloudFormation stacks.

✅ Yêu cầu chính:

  • Bảo mật cao: Keys phải được mã hóa và quản lý an toàn, tránh lộ thông tin.
  • Tích hợp linh hoạt: Hỗ trợ truy cập tự động từ EC2 (qua agent hoặc IAM roles) và CloudFormation (qua intrinsic functions hoặc references).
  • Tiết kiệm chi phí: Ưu tiên giải pháp có pricing thấp nhất, không phát sinh phí lưu trữ/API calls lớn.
  • Kiến thức cập nhật (2026): Sử dụng AWS Systems Manager (SSM) Parameter Store phiên bản mới nhất với hỗ trợ KMS encryption tự động, tích hợp IAM và hybrid access, theo AWS Well-Architected Framework for DevOps (Reliability & Security Pillars).

🛠️ Bối cảnh thực tế: License keys là secrets nhạy cảm, không thay đổi thường xuyên, cần tránh hardcode trong code hoặc configs. Giải pháp phải hỗ trợ versioning, auditing qua CloudTrail.

📘 Tài liệu tham khảo:

✅ Đáp án đúng: AWS Systems Manager Parameter Store SecureString parameters

Lý do chọn:

  • 🛡️ Bảo mật tối ưu: SecureString tự động mã hóa bằng AWS-owned KMS key (miễn phí) hoặc customer-managed KMS, hỗ trợ versioning và ACL.
  • 🔄 Tích hợp hoàn hảo:
    • Trên EC2: Sử dụng SSM agent (pre-installed) với aws ssm get-parameter --name "/license/key" --with-decryption trong scripts, IAM role attach policy ssm:GetParameter.
    • Trên CloudFormation: Reference trực tiếp qua !Ref AWS::SSM::Parameter::Value<String> hoặc DynamicReference trong template.
  • 💰 Tiết kiệm chi phí nhất: Standard tier miễn phí (lên đến 10.000 parameters + 40.000 API calls/tháng/account/region). SecureString thuộc Advanced tier nhưng chỉ ~$0.05/parameter/tháng + $0.0001/API call (rẻ hơn Secrets Manager 8x), phù hợp keys cố định ít truy cập.
  • 🚀 Không có nhược điểm: Auditing qua CloudTrail, no rotation cần thiết cho fixed keys.

❌ Phân tích tất cả các phương án

  • Amazon S3 with encrypted files prefixed with “config”
    ❌ Sai vì: S3 không phải công cụ quản lý secrets chuyên dụng, chỉ lưu file encrypted (SSE-KMS/SSE-S3). Prefix "config" vô nghĩa cho security. Truy cập EC2 cần IAM policy phức tạp (s3:GetObject), CloudFormation chỉ reference bucket/key gián tiếp → không tự động decrypt trong scripts. Chi phí S3 thấp nhưng thiếu versioning/auditing secrets, dễ misconfig quyền → rủi ro cao. Không MOST cost-effective cho secrets management.

  • AWS Secrets Manager secrets with a tag that is named SecretString
    ❌ Sai vì: Secrets Manager xuất sắc cho secrets (mã hóa KMS, rotation tự động, VPC endpoints), tích hợp EC2/CloudFormation tốt (aws secretsmanager get-secret-value). Nhưng tag "SecretString" vô nghĩa (secrets luôn là string/JSON). Chi phí cao: $0.40/secret/tháng + $0.05/10.000 API calls → đắt gấp nhiều lần Parameter Store cho fixed keys ít dùng. Không cost-effective nhất.

  • AWS Systems Manager Parameter Store SecureString parameters
    ✅ Đúng (như giải thích ở trên). Giải pháp lý tưởng, cân bằng security/cost/integration.

  • CloudFormation NoEcho parameters
    ❌ Sai vì: NoEcho chỉ ẩn giá trị trong CloudFormation console/logs/outputs (không lưu trữ). Không thể truy cập từ EC2 scripts (chỉ trong stack runtime). Không mã hóa/persist keys → keys biến mất sau deploy. Hoàn toàn không đáp ứng yêu cầu lưu trữ/access automation, chỉ là UI masking tạm thời.

🧠 Kết luận: Parameter Store SecureString là lựa chọn DevOps best practice cho secrets fixed, scale tốt đến enterprise. Test real-world: Tạo param /prod/license/key → access từ EC2 user-data script thành công zero cost ban đầu!

Câu 840
A company has deployed infrastructure on AWS. A development team wants to create an AWS Lambda function that will retrieve data from an Amazon Aurora database. The Amazon Aurora database is in a private subnet in company's VPC. The VPC is named VPC1. The data is relational in nature. The Lambda function needs to access the data securely.
Which solution will meet these requirements?
  1. A Create the Lambda function. Configure VPC1 access for the function. Attach a security group named SG1 to both the Lambda function and the database. Configure the security group inbound and outbound rules to allow TCP traffic on Port 3306.
  2. B Create and launch a Lambda function in a new public subnet that is in a new VPC named VPC2. Create a peering connection between VPC1 and VPC2.
  3. C Create the Lambda function. Configure VPC1 access for the function. Assign a security group named SG1 to the Lambda function. Assign a second security group named SG2 to the database. Add an inbound rule to SG1 to allow TCP traffic from Port 3306.
  4. D Export the data from the Aurora database to Amazon S3. Create and launch a Lambda function in VPC1. Configure the Lambda function query the data from Amazon S3.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả tình huống thực tế trên AWS:
Một công ty đã triển khai hạ tầng trên AWS. Nhóm phát triển muốn tạo một hàm AWS Lambda để lấy dữ liệu từ cơ sở dữ liệu Amazon Aurora nằm trong private subnet của VPC tên VPC1. Dữ liệu có tính chất relational (dữ liệu quan hệ, như bảng với mối quan hệ). Hàm Lambda cần truy cập dữ liệu một cách bảo mật (securely).

Yêu cầu chính cần đáp ứng:

  • Lambda phải kết nối được với Aurora DB trong private subnet (không thể truy cập trực tiếp từ internet).
  • Đảm bảo kết nối an toàn qua VPC, sử dụng Security Group (SG) để kiểm soát traffic TCP trên port 3306 (port mặc định của Aurora MySQL-compatible).
  • Giải pháp phải đơn giản, hiệu quả, tuân thủ best practices AWS (không phức tạp hóa với peering VPC hay export dữ liệu).

📘 Kiến thức nền tảng AWS (cập nhật đến 2026):
Aurora là managed relational DB (MySQL/PostgreSQL compatible), hỗ trợ VPC integration. Lambda khi chạy trong VPC cần ENI (Elastic Network Interface) để kết nối tài nguyên private subnet. Best practice: Sử dụng cùng một Security Group cho Lambda và DB, với rule inbound/outbound cho phép traffic từ chính SG đó trên port DB (self-referencing rules).

Nguồn tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Phương án đầu tiên.

Lý do:
🛠️ Giải pháp này hoàn hảo vì:

  • Tạo Lambda và configure VPC1 access → Lambda chạy trong cùng VPC1, có thể truy cập private subnet qua ENI.
  • Attach cùng SG1 cho cả Lambda và DB → Cho phép traffic hai chiều (inbound/outbound) trên port 3306 từ chính SG1 (self-traffic), đảm bảo kết nối bảo mật mà không mở rộng ra ngoài.
  • Không cần NAT Gateway (vì private), tiết kiệm chi phí, và tuân thủ nguyên tắc least privilege. Đây là best practice AWS cho Lambda-RDS integration trong cùng VPC.

📋 Phân tích chi tiết TẤT CẢ các phương án

✅ Phương án ĐÚNG (Phương án 1):
Create the Lambda function. Configure VPC1 access for the function. Attach a security group named SG1 to both the Lambda function and the database. Configure the security group inbound and outbound rules to allow TCP traffic on Port 3306.

Giải thích đúng:
🟢 Hoàn toàn phù hợp yêu cầu. Lambda trong VPC1 kết nối trực tiếp Aurora qua cùng SG1. Rule inbound/outbound TCP:3306 từ SG1-to-SG1 (self-reference) cho phép Lambda (client) gửi request outbound đến DB và nhận response inbound. An toàn, hiệu suất cao, không lộ ra internet. ✅ Ideal solution!

❌ Phương án SAI (Phương án 2):
Create and launch a Lambda function in a new public subnet that is in a new VPC named VPC2. Create a peering connection between VPC1 and VPC2.

Giải thích sai:
🔴 Phức tạp và không bảo mật:

  • Tạo VPC2 mới + peering VPC là overkill (không cần thiết khi Lambda có thể chạy trực tiếp trong VPC1).
  • Public subnet cho Lambda dễ bị expose (cần IGW/NAT), không secure cho access private DB.
  • Peering thêm latency, chi phí quản lý route tables/SG cross-VPC. ❌ Vi phạm nguyên tắc đơn giản & secure.

❌ Phương án SAI (Phương án 3):
Create the Lambda function. Configure VPC1 access for the function. Assign a security group named SG1 to the Lambda function. Assign a second security group named SG2 to the database. Add an inbound rule to SG1 to allow TCP traffic from Port 3306.

Giải thích sai:
🔴 Sai logic Security Group rules:

  • Lambda trong VPC1 là tốt, nhưng dùng hai SG riêng (SG1 cho Lambda, SG2 cho DB) cần cross-reference: Outbound SG1 → Inbound SG2 (TCP:3306 from SG1), và Inbound SG1 → cho response từ DB.
  • Rule "inbound to SG1 allow TCP from Port 3306" sai vì: Inbound SG1 là traffic vào Lambda từ port 3306 (nhưng Lambda là client, không phải server nhận kết nối từ port 3306). DB mới là server lắng nghe 3306. ❌ Rule sai hướng, không kết nối được.

❌ Phương án SAI (Phương án 4):
Export the data from the Aurora database to Amazon S3. Create and launch a Lambda function in VPC1. Configure the Lambda function query the data from Amazon S3.

Giải thích sai:
🔴 Không phù hợp relational data & real-time access:

  • Export sang S3 là dữ liệu static/unstructured (CSV/Parquet), mất tính relational (queries JOIN, transactions).
  • Lambda query S3 không thay thế DB queries (S3 không hỗ trợ SQL real-time, cần Athena/Glue costly).
  • Không secure & inefficient cho "retrieve data" động từ Aurora. ❌ Thay đổi architecture không cần thiết.