Ngân hàng đề — AWS Certified Developer Associate

Tìm thấy 1356 câu.

Câu 841 Chọn nhiều đáp án
A developer is building a web application that uses Amazon API Gateway to expose an AWS Lambda function to process requests from clients. During testing, the developer notices that the API Gateway times out even though the Lambda function finishes under the set time limit.
Which of the following API Gateway metrics in Amazon CloudWatch can help the developer troubleshoot the issue? (Choose two.)
  1. A CacheHitCount
  2. B IntegrationLatency
  3. C CacheMissCount
  4. D Latency
  5. E Count
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một lập trình viên đang xây dựng ứng dụng web sử dụng Amazon API Gateway để expose một AWS Lambda function, xử lý yêu cầu từ client. Trong quá trình testing, API Gateway bị timeout mặc dù Lambda function hoàn thành dưới thời hạn đã đặt.
📌 Vấn đề cốt lõi: Timeout xảy ra ở API Gateway (thường do integration timeout mặc định là 29 giây hoặc cấu hình tùy chỉnh), nhưng Lambda chạy nhanh (< thời hạn Lambda 15 phút). Nguyên nhân có thể là độ trễ ở lớp integration (gọi Lambda), overhead mạng, cold start Lambda, hoặc tổng thời gian xử lý request/response ở API Gateway.
🛠️ Mục tiêu: Chọn 2 metrics từ Amazon CloudWatch của API Gateway để troubleshoot, giúp xác định bottleneck ở đâu (ví dụ: thời gian gọi backend Lambda hoặc tổng latency).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng (chọn 2):

  • IntegrationLatency
  • Latency

Lý do chọn:
🧩 IntegrationLatency đo thời gian từ khi API Gateway gửi request đến backend (Lambda) cho đến khi nhận response từ backend (không bao gồm thời gian client nhận response). Giúp phát hiện nếu độ trễ ở Lambda integration cao (cold start, lỗi kết nối), dù Lambda tự báo hoàn thành nhanh.
🧩 Latency đo tổng thời gian từ khi API Gateway nhận request từ client đến khi gửi response về client (bao gồm integration + overhead API Gateway). Nếu Latency cao nhưng Lambda nhanh, có thể do timeout ở lớp Gateway.
📈 Những metrics này trực tiếp liên quan đến timeout issue, theo tài liệu AWS mới nhất (2024-2026), giúp debug hiệu quả mà không cần log sâu.

🔍 Giải thích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn. Tôi giữ nguyên nội dung phương án bằng tiếng Anh, đánh dấu ✅ (đúng) hoặc ❌ (sai), và giải thích bằng tiếng Việt:

  • CacheHitCount ❌
    ❌ Sai: Metric này đếm số request được phục vụ từ cache của API Gateway (khi enable caching). Không liên quan đến timeout integration với Lambda, vì issue là xử lý request mới (không cache), không phải cache hit.

  • IntegrationLatency ✅
    ✅ Đúng: Metric đo độ trễ integration cụ thể (thời gian backend Lambda xử lý). Rất hữu ích để kiểm tra nếu Lambda chậm hơn dự kiến (cold start, queueing), dẫn đến Gateway timeout dù Lambda báo finish nhanh (do đo lường khác nhau).

  • CacheMissCount ❌
    ❌ Sai: Metric đếm số request miss cache (phải gọi backend). Chỉ hữu ích cho caching performance, không giúp troubleshoot timeout ở Lambda integration trực tiếp.

  • Latency ✅
    ✅ Đúng: Metric tổng quát nhất, đo end-to-end latency của API Gateway. Giúp so sánh với IntegrationLatency để xác định overhead (như throttling, auth), nguyên nhân phổ biến của timeout dù Lambda nhanh.

  • Count ❌
    ❌ Sai: Metric chỉ đếm tổng số request (thành công/thất bại). Không cung cấp insight về thời gian xử lý hay độ trễ, vô dụng cho debug timeout cụ thể.

📘 Tài liệu tham khảo (cập nhật AWS 2024-2026)

Câu 842
A development team wants to build a continuous integration/continuous delivery (CI/CD) pipeline. The team is using AWS CodePipeline to automate the code build and deployment. The team wants to store the program code to prepare for the CI/CD pipeline.
Which AWS service should the team use to store the program code?
  1. A AWS CodeDeploy
  2. B AWS CodeArtifact
  3. C AWS CodeCommit
  4. D Amazon CodeGuru
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc xây dựng pipeline CI/CD (Continuous Integration/Continuous Delivery) sử dụng AWS CodePipeline để tự động hóa quá trình build và deploy code. Đội ngũ phát triển cần một dịch vụ AWS để lưu trữ mã nguồn chương trình (program code) làm nguồn đầu vào cho pipeline này.

📌 Chi tiết chính:

  • Mục tiêu: Lưu trữ code một cách an toàn, hỗ trợ version control (Git), và tích hợp mượt mà với CodePipeline ở giai đoạn Source.
  • Bối cảnh: CodePipeline yêu cầu source code từ một repository (kho mã nguồn) để kích hoạt pipeline tự động khi có thay đổi code.
  • Kiến thức cập nhật 2026: AWS CodePipeline (phiên bản mới nhất hỗ trợ multi-region, enhanced security với IAM roles và OIDC) tích hợp trực tiếp với các source như CodeCommit, GitHub, Bitbucket, S3. Không thay đổi cơ bản về source storage từ 2023-2026.

Nguồn tham khảo:

✅ Đáp án đúng: AWS CodeCommit

Lý do lựa chọn:

  • AWS CodeCommit là dịch vụ source control dựa trên Git của AWS, được thiết kế chuyên biệt để lưu trữ, quản lý và version code trong môi trường CI/CD.
  • Nó tích hợp trực tiếp và native với AWS CodePipeline ở giai đoạn Source: Khi có commit/push code mới, CodePipeline tự động trigger pipeline để build/deploy.
  • ✅ Ưu điểm nổi bật: Hỗ trợ branching, merging, pull requests; bảo mật cao với IAM/Fine-grained access; mã hóa dữ liệu mặc định; scale tự động; không giới hạn kích thước repo (cập nhật 2026: hỗ trợ large repos lên đến 5GB/file).
  • Đây là lựa chọn tối ưu nhất cho đội ngũ AWS-native, tránh phụ thuộc bên thứ 3 như GitHub.

🛠️ Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn giữ nguyên văn bản gốc bằng tiếng Anh, kèm giải thích sai/đúng bằng tiếng Việt dựa trên chức năng thực tế của từng service (dữ liệu cập nhật AWS 2026):

  • AWS CodeDeploy ❌ SAI
    AWS CodeDeploy là dịch vụ deploy ứng dụng tự động hóa việc triển khai code lên EC2, Lambda, ECS, EKS, on-premises. Nó KHÔNG lưu trữ code, mà chỉ lấy artifact từ source (như S3 hoặc CodePipeline) để deploy. Sử dụng ở giai đoạn Deploy của pipeline, không phải Source. Nếu dùng sai, pipeline không có nơi lưu code gốc.

  • AWS CodeArtifact ❌ SAI
    AWS CodeArtifact là repository quản lý package/artifact (Maven, Gradle, npm, NuGet, Python), dùng để lưu trữ và chia sẻ dependencies/libraries. Nó KHÔNG dành cho source code, mà chỉ cho binary packages sau build. Tích hợp với CodeBuild/CodePipeline ở giai đoạn Build/Artifact, không thay thế Git repo. Sai lầm phổ biến: nhầm lẫn artifact với source code.

  • AWS CodeCommit ✅ ĐÚNG
    Như đã giải thích ở phần đáp án: Đây là Git repository service lý tưởng để lưu trữ program code, hỗ trợ CI/CD full lifecycle với CodePipeline. ✅ Tích hợp liền mạch: Trigger webhook tự động, hỗ trợ encryption, approval gates, và multi-account (RAM integration mới 2025-2026).

  • Amazon CodeGuru ❌ SAI
    Amazon CodeGuru là dịch vụ review code bằng AI/ML (Profiler & Reviewer), phân tích code để phát hiện bug, security vulnerabilities, tối ưu performance. Nó KHÔNG lưu trữ code, mà scan code từ repo bên ngoài (CodeCommit/GitHub) hoặc ECR images. Dùng ở giai đoạn review/test, không phải storage.

Tóm tắt nhanh 📘: CodeCommit là "ngôi nhà" cho source code trong hệ sinh thái AWS DevOps (Developer Tools). Các service khác hỗ trợ các giai đoạn khác của pipeline: CodeArtifact (packages), CodeDeploy (deploy), CodeGuru (review).

Nguồn bổ sung:

Nếu cần ví dụ pipeline thực tế hoặc lab setup, hãy cho tôi biết! 🚀

Câu 843
A developer is designing an AWS Lambda function that creates temporary files that are less than 10 MB during invocation. The temporary files will be accessed and modified multiple times during invocation. The developer has no need to save or retrieve these files in the future.
Where should the temporary files be stored?
  1. A the /tmp directory
  2. B Amazon Elastic File System (Amazon EFS)
  3. C Amazon Elastic Block Store (Amazon EBS)
  4. D Amazon S3
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc thiết kế một hàm AWS Lambda tạo ra các tệp tạm thời (temporary files) có kích thước nhỏ hơn 10 MB trong quá trình thực thi (invocation). Những tệp này sẽ được truy cập và sửa đổi nhiều lần ngay trong một lần invocation duy nhất, nhưng không cần lưu trữ hoặc truy xuất sau này.

📌 Yêu cầu chính: Tìm vị trí lưu trữ phù hợp cho các tệp tạm thời này trong môi trường Lambda, đảm bảo hiệu suất cao, chi phí thấp và phù hợp với đặc tính "tạm thời" (không bền vững). AWS Lambda có không gian lưu trữ cục bộ hạn chế, và việc chọn sai có thể dẫn đến lỗi hoặc tăng chi phí không cần thiết.

🛠️ Bối cảnh AWS Lambda (cập nhật đến 2026): Lambda cung cấp không gian lưu trữ tạm thời qua thư mục /tmp, dung lượng từ 512 MB đến 10 GB (tùy cấu hình bộ nhớ). Tệp trong /tmp bị xóa tự động sau mỗi invocation, lý tưởng cho dữ liệu tạm thời.

✅ Đáp án đúng: the /tmp directory

Lý do lựa chọn:

  • Thư mục /tmp là không gian lưu trữ tạm thời tích hợp sẵn trong runtime của AWS Lambda, được thiết kế chính xác cho các tệp tạm thời như vậy.
  • ✅ Dung lượng đủ lớn (dễ dàng chứa <10 MB), hỗ trợ đọc/ghi nhiều lần với hiệu suất cao (local storage, độ trễ thấp).
  • ✅ Tệp tự động bị xóa sau invocation, phù hợp hoàn hảo với yêu cầu "không cần lưu trữ sau này".
  • ✅ Chi phí tối ưu (không tốn thêm phí lưu trữ ngoài ephemeral storage của Lambda).
  • Không cần cấu hình thêm, hoạt động ngay lập tức trên mọi runtime (Node.js, Python, Java, v.v.).

📋 Giải thích tất cả các phương án

  • ✅ the /tmp directory
    Như đã giải thích ở trên, đây là lựa chọn hoàn hảo cho tệp tạm thời nhỏ, đọc/ghi nhiều lần trong invocation. Hiệu suất cục bộ cao, không bền vững – khớp 100% yêu cầu. (AWS khuyến nghị chính thức cho temporary storage).

  • ❌ Amazon Elastic File System (Amazon EFS)
    Amazon EFS là hệ thống tệp chia sẻ bền vững (persistent), có thể mount vào Lambda qua File System. Tuy nhiên, không phù hợp vì: độ trễ cao hơn local storage (network-based), chi phí cao cho dữ liệu tạm thời, và yêu cầu cấu hình VPC/Access Point phức tạp. Không cần thiết khi tệp chỉ dùng trong một invocation và không lưu lâu dài.

  • ❌ Amazon Elastic Block Store (Amazon EBS)
    Amazon EBS là lưu trữ khối (block storage) dành cho EC2 instances, không hỗ trợ trực tiếp Lambda (Lambda chạy serverless, không attach EBS). Sử dụng EBS sẽ yêu cầu EC2 trung gian, làm phức tạp hóa và tăng chi phí. Hoàn toàn không khả thi cho temporary files trong Lambda.

  • ❌ Amazon S3
    Amazon S3 là object storage bền vững, phù hợp cho dữ liệu lâu dài. Không phù hợp vì: mỗi read/write là API call (độ trễ cao, không hiệu quả cho multiple access trong invocation), chi phí cho nhiều request nhỏ, và tệp sẽ tồn tại mãi trừ khi xóa thủ công. Lambda chỉ nên dùng S3 cho dữ liệu persistent.

📘 Tài liệu tham khảo (AWS Documentation - cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm ví dụ code, hỏi nhé!

Câu 844
A developer is designing a serverless application with two AWS Lambda functions to process photos. One Lambda function stores objects in an Amazon S3 bucket and stores the associated metadata in an Amazon DynamoDB table. The other Lambda function fetches the objects from the S3 bucket by using the metadata from the DynamoDB table. Both Lambda functions use the same Python library to perform complex computations and are approaching the quota for the maximum size of zipped deployment packages.
What should the developer do to reduce the size of the Lambda deployment packages with the LEAST operational overhead?
  1. A Package each Python library in its own .zip file archive. Deploy each Lambda function with its own copy of the library.
  2. B Create a Lambda layer with the required Python library. Use the Lambda layer in both Lambda functions.
  3. C Combine the two Lambda functions into one Lambda function. Deploy the Lambda function as a single .zip file archive.
  4. D Download the Python library to an S3 bucket. Program the Lambda functions to reference the object URLs.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh việc thiết kế một ứng dụng serverless trên AWS với hai AWS Lambda functions xử lý ảnh:

  • Lambda thứ nhất: Lưu trữ object vào Amazon S3 bucket và metadata liên quan vào Amazon DynamoDB table.
  • Lambda thứ hai: Lấy object từ S3 dựa trên metadata từ DynamoDB.

Cả hai Lambda đều sử dụng cùng một Python library để thực hiện các phép tính phức tạp, nhưng kích thước zipped deployment package đang tiến sát quota tối đa (hiện tại là 250 MB unzipped, 50 MB zipped theo docs AWS cập nhật 2024-2026).

Mục tiêu: Giảm kích thước deployment package với LEAST operational overhead (ít nỗ lực vận hành nhất, tránh phức tạp hóa code/architecture).
✅ Đây là vấn đề phổ biến trong Lambda khi chia sẻ thư viện lớn (như numpy, pandas, tensorflow), cần giải pháp tối ưu hóa code reuse mà không thay đổi logic ứng dụng.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create a Lambda layer with the required Python library. Use the Lambda layer in both Lambda functions.

Lý do:

  • Lambda Layers (tính năng từ 2018, cập nhật liên tục đến 2026) cho phép chia sẻ thư viện/code giữa nhiều Lambda functions mà không cần duplicate trong từng package.
  • Giảm kích thước deployment package chính xuống chỉ code cốt lõi (thường <10MB), layer chứa library lớn (lên đến 250MB unzipped).
  • Least operational overhead: Chỉ tạo layer một lần (qua AWS Console/CLI/CDK), attach vào cả hai functions → deploy nhanh, quản lý tập trung, tự động update layer cho tất cả. Không cần thay đổi code logic, hỗ trợ Python runtime mới nhất (3.12+).
  • Hiệu quả cao: Layers cached locally/on-disk, cold start nhanh hơn 20-50% theo benchmarks AWS.

📋 Giải thích tất cả các phương án (đúng/sai)

  • ❌ [SAI] Package each Python library in its own .zip file archive. Deploy each Lambda function with its own copy of the library.
    Phương án này tăng kích thước thay vì giảm: Mỗi function duplicate library → vượt quota nhanh hơn, tốn storage/traffic khi deploy. Overhead cao (deploy riêng lẻ, không chia sẻ), vi phạm nguyên tắc DRY (Don't Repeat Yourself). Không giải quyết gốc rễ.

  • ✅ [ĐÚNG] Create a Lambda layer with the required Python library. Use the Lambda layer in both Lambda functions.
    Như đã giải thích ở trên: Giải pháp tối ưu, reuse layer (max 5 layers/function), hỗ trợ versioning, publish private/public layers. Ít overhead nhất, scale tốt cho serverless.

  • ❌ [SAI] Combine the two Lambda functions into one Lambda function. Deploy the Lambda function as a single .zip file archive.
    Phá vỡ kiến trúc: Hai functions có trách nhiệm riêng (store vs fetch), merge thành một làm code monolithic, khó test/debug/scale độc lập. Overhead lớn (refactor code, xử lý event routing phức tạp), vi phạm single responsibility principle. Kích thước vẫn lớn do library + toàn bộ code.

  • ❌ [SAI] Download the Python library to an S3 bucket. Program the Lambda functions to reference the object URLs.
    Không khả thi và rủi ro: Lambda runtime Python không hỗ trợ dynamic import từ S3 URL trực tiếp (cần download runtime, parse ZIP – phức tạp, chậm cold start). Overhead cực cao (custom code loader, handle errors/network, security IAM). Vi phạm best practices AWS, dễ timeout/fail.

🛠️ Khuyến nghị thực hiện (best practices AWS 2026)

  • Tạo layer: aws lambda publish-layer-version --layer-name my-python-lib --zip-file fileb://lib.zip --compatible-runtimes python3.12 --region us-east-1.
  • Attach: Trong function config → Layers → Add layer ARN.
  • Theo dõi quota: CloudWatch Metrics (Duration, PackageSize).
  • Alternative nâng cao: Container images (đến 10GB, nhưng overhead cao hơn layers cho Python libs).

📘 Tài liệu tham khảo (AWS docs cập nhật 2024-2026)

Hy vọng phân tích giúp bạn nắm vững! 🚀 Nếu cần demo code, hỏi thêm nhé!

Câu 845
A developer is writing an AWS Lambda function. The developer wants to log key events that occur while the Lambda function runs. The developer wants to include a unique identifier to associate the events with a specific function invocation. The developer adds the following code to the Lambda function:
function handler(event, context) {
}

Which solution will meet this requirement?
  1. A Obtain the request identifier from the AWS request ID field in the context object. Configure the application to write logs to standard output.
  2. B Obtain the request identifier from the AWS request ID field in the event object. Configure the application to write logs to a file.
  3. C Obtain the request identifier from the AWS request ID field in the event object. Configure the application to write logs to standard output.
  4. D Obtain the request identifier from the AWS request ID field in the context object. Configure the application to write logs to a file.
Xem giải thích

Phân tích câu hỏi

Câu hỏi yêu cầu chúng ta tìm ra giải pháp để đáp ứng nhu cầu ghi nhật ký (logging) các sự kiện quan trọng trong một hàm AWS Lambda. Hàm Lambda này cần ghi lại các sự kiện quan trọng trong quá trình thực thi và bao gồm một định danh duy nhất để liên kết các sự kiện với một invocation cụ thể của hàm.

Giải pháp

Để giải quyết yêu cầu này, chúng ta cần xem xét cách thức mà AWS Lambda cung cấp thông tin về định danh duy nhất cho mỗi invocation và cách ghi nhật ký trong Lambda.

Đáp án đúng

✅ Obtain the request identifier from the AWS request ID field in the context object. Configure the application to write logs to standard output.

  • Giải thích:
    • Trong AWS Lambda, đối tượng context được truyền vào hàm xử lý (handler) của Lambda function. Đối tượng context này chứa thông tin về invocation, bao gồm cả awsRequestId, đây là định danh duy nhất cho mỗi invocation của hàm Lambda.
    • Để ghi nhật ký, ứng dụng có thể viết logs đến standard output. AWS Lambda tự động thu thập logs từ standard output và gửi chúng đến CloudWatch Logs.

Các phương án sai

❌ Obtain the request identifier from the AWS request ID field in the event object. Configure the application to write logs to a file.

  • Giải thích:
    • Đối tượng event không chứa trường awsRequestId. Trường này nằm trong đối tượng context.
    • Ghi logs vào file không phải là phương pháp được khuyến nghị cho AWS Lambda. Thay vào đó, nên viết logs đến standard output để AWS Lambda có thể thu thập và gửi chúng đến CloudWatch Logs.

❌ Obtain the request identifier from the AWS request ID field in the event object. Configure the application to write logs to standard output.

  • Giải thích:
    • Như đã đề cập, đối tượng event không chứa trường awsRequestId.
    • Viết logs đến standard output là đúng, nhưng việc lấy định danh từ đối tượng event là sai.

❌ Obtain the request identifier from the AWS request ID field in the context object. Configure the application to write logs to a file.

  • Giải thích:
    • Lấy định danh từ đối tượng context là đúng.
    • Tuy nhiên, ghi logs vào file là sai. Thay vào đó, nên viết logs đến standard output.

Dẫn nguồn tài liệu tham khảo

Kết luận

Bằng cách lấy định danh duy nhất từ trường awsRequestId trong đối tượng context và viết logs đến standard output, chúng ta có thể đáp ứng yêu cầu ghi nhật ký cho hàm AWS Lambda với định danh duy nhất cho mỗi invocation.

Câu 846
A developer is working on a serverless application that needs to process any changes to an Amazon DynamoDB table with an AWS Lambda function.
How should the developer configure the Lambda function to detect changes to the DynamoDB table?
  1. A Create an Amazon Kinesis data stream, and attach it to the DynamoDB table. Create a trigger to connect the data stream to the Lambda function.
  2. B Create an Amazon EventBridge rule to invoke the Lambda function on a regular schedule. Conned to the DynamoDB table from the Lambda function to detect changes.
  3. C Enable DynamoDB Streams on the table. Create a trigger to connect the DynamoDB stream to the Lambda function.
  4. D Create an Amazon Kinesis Data Firehose delivery stream, and attach it to the DynamoDB table. Configure the delivery stream destination as the Lambda function.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm AWS

📖 Nội dung câu hỏi:
Câu hỏi tập trung vào việc thiết lập một ứng dụng serverless trên AWS, nơi một hàm AWS Lambda cần tự động xử lý mọi thay đổi (như insert, update, delete) xảy ra trên một bảng Amazon DynamoDB. Cụ thể, developer cần cấu hình Lambda để phát hiện (detect) các thay đổi này một cách hiệu quả, không cần polling thủ công hay kiểm tra định kỳ. Đây là kịch bản phổ biến trong kiến trúc event-driven serverless, tận dụng các tính năng native của AWS để đảm bảo tính thời gian thực (real-time), độ tin cậy cao và chi phí tối ưu. Kiến thức này dựa trên các tính năng DynamoDB Streams (cập nhật đến 2026, vẫn là phương pháp chuẩn theo AWS Well-Architected Framework cho Serverless).

✅ Đáp án đúng và lý do chọn:
Enable DynamoDB Streams on the table. Create a trigger to connect the DynamoDB stream to the Lambda function.
🛠️ Lý do: DynamoDB Streams là dịch vụ native của AWS cho phép capture mọi thay đổi trên bảng DynamoDB dưới dạng stream các event (ordered by sequence number). Bạn chỉ cần enable Streams trên bảng (point-in-time recovery, chi phí thấp ~$0.02/100,000 read request units), sau đó tạo trigger trực tiếp từ DynamoDB Stream đến Lambda qua AWS Console, CDK, SAM hoặc Terraform. Lambda sẽ tự động scale, retry và xử lý batch events một cách asynchronous. Phương pháp này real-time, không mất dữ liệu, không cần code polling, phù hợp hoàn hảo cho serverless. (Cập nhật 2026: Hỗ trợ enhanced fan-out cho throughput cao hơn.)

🔍 Phân tích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá dựa trên tính chính xác, hiệu quả và best practice AWS (theo tài liệu chính thức).

  • Create an Amazon Kinesis data stream, and attach it to the DynamoDB table. Create a trigger to connect the data stream to the Lambda function.
    ❌ Sai: Kinesis Data Streams không thể attach trực tiếp vào DynamoDB table (DynamoDB chỉ hỗ trợ native Streams, không phải Kinesis). Bạn phải dùng Kinesis Agent hoặc Lambda để push dữ liệu từ DynamoDB sang Kinesis, dẫn đến phức tạp, latency cao hơn và chi phí thừa (Kinesis shard ~$0.015/giờ). Không phải cách native để detect changes.

  • Create an Amazon EventBridge rule to invoke the Lambda function on a regular schedule. Conned to the DynamoDB table from the Lambda function to detect changes.
    ❌ Sai: EventBridge rule chỉ schedule invoke Lambda định kỳ (ví dụ cron job), buộc Lambda phải poll/query DynamoDB để detect changes (sử dụng Scan/Query API). Điều này gây chi phí cao (DynamoDB RCU/WCU phí), không real-time (delay theo schedule), không scalable cho high-throughput, và vi phạm nguyên tắc serverless event-driven. (Lưu ý lỗi chính tả "Conned" có lẽ là "Connect", nhưng không ảnh hưởng phân tích).

  • Enable DynamoDB Streams on the table. Create a trigger to connect the DynamoDB stream to the Lambda function.
    ✅ Đúng: Như đã giải thích ở trên. Đây là best practice AWS cho real-time processing changes, với batch size configurable (1-10,000 records), exactly-once semantics qua Kinesis-like processing, và tích hợp seamless với Lambda (trigger tự động tạo qua AWS Console/CLI). Hỗ trợ shard iterator để parallel processing.

  • Create an Amazon Kinesis Data Firehose delivery stream, and attach it to the DynamoDB table. Configure the delivery stream destination as the Lambda function.
    ❌ Sai: Kinesis Data Firehose không hỗ trợ attach trực tiếp vào DynamoDB (Firehose dành cho streaming data ingestion từ sources như logs, không phải change data capture). Bạn phải dùng Lambda để transform/push từ DynamoDB Streams sang Firehose, thêm layer thừa, không real-time (batch + buffer time 60s-24h), và chi phí cao hơn cho delivery (S3/Redshift/ES). Không phù hợp detect changes.

📘 Tài liệu tham khảo (AWS chính thức, cập nhật 2026):

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần ví dụ code Terraform/CDK, hãy hỏi thêm.

Câu 847 Chọn nhiều đáp án
An application uses an Amazon EC2 Auto Scaling group. A developer notices that EC2 instances are taking a long time to become available during scale-out events. The UserData script is taking a long time to run.
The developer must implement a solution to decrease the time that elapses before an EC2 instance becomes available. The solution must make the most recent version of the application available at all times and must apply all available security updates. The solution also must minimize the number of images that are created. The images must be validated.
Which combination of steps should the developer take to meet these requirements? (Choose two.)
  1. A Use EC2 Image Builder to create an Amazon Machine Image (AMI). Install all the patches and agents that are needed to manage and run the application. Update the Auto Scaling group launch configuration to use the AMI.
  2. B Use EC2 Image Builder to create an Amazon Machine Image (AMI). Install the latest version of the application and all the patches and agents that are needed to manage and run the application. Update the Auto Scaling group launch configuration to use the AMI.
  3. C Set up AWS CodeDeploy to deploy the most recent version of the application at runtime.
  4. D Set up AWS CodePipeline to deploy the most recent version of the application at runtime.
  5. E Remove any commands that perform operating system patching from the UserData script.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào vấn đề tối ưu hóa thời gian khởi động EC2 instances trong Auto Scaling group (ASG) khi scale-out. Cụ thể:

  • Ứng dụng chạy trên ASG, nhưng instances mất nhiều thời gian để sẵn sàng vì UserData script chạy lâu (thường do install patches, agents hoặc app).
  • Yêu cầu giải pháp:
    • Giảm thời gian instances sẵn sàng (giảm tải UserData).
    • Luôn có phiên bản ứng dụng mới nhất (most recent version).
      Áp dụng tất cả security updates (patches).
    • Minimize số lượng AMI tạo ra (tránh tạo AMI mới thường xuyên).
    • AMI phải được validated (kiểm tra tính toàn vẹn).
  • Đây là câu hỏi chọn TWO (kết hợp 2 bước).
    Giải pháp lý tưởng theo best practice AWS (cập nhật 2026): Sử dụng pre-baked AMI cho patches/agents (giảm UserData), deploy app tại runtime để linh hoạt version mới mà không tạo AMI mới.

✅ Đáp án đúng (Chọn 2)

Hai lựa chọn đúng là sự kết hợp hoàn hảo để đáp ứng tất cả yêu cầu:

  1. Use EC2 Image Builder to create an Amazon Machine Image (AMI). Install all the patches and agents that are needed to manage and run the application. Update the Auto Scaling group launch configuration to use the AMI.
    🛠️ Lý do: EC2 Image Builder (tính năng mới nhất AWS 2026) tự động tạo AMI đã pre-install patches và agents, validate AMI (scan vulnerabilities), giảm thời gian UserData xuống mức tối thiểu. Không bake app version → minimize AMI (chỉ update AMI khi patches thay đổi, không phải mỗi app release). Update launch config ASG để dùng AMI mới → instances scale-out nhanh.

  2. Set up AWS CodeDeploy to deploy the most recent version of the application at runtime.
    🛠️ Lý do: CodeDeploy deploy app tại runtime (sau khi instance InService), đảm bảo latest app version luôn available mà không cần tạo AMI mới mỗi lần release → minimize images. Kết hợp với AMI pre-baked ở trên, instances sẵn sàng nhanh + app update linh hoạt.

Kết hợp này: AMI chỉ update hiếm khi (patches), app deploy động → scale-out <5 phút, an toàn, tuân thủ AWS Well-Architected Framework (Operational Excellence & Security).

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng lựa chọn (giữ nguyên văn bản gốc), với lý do đúng/sai dựa trên yêu cầu:

✅ Use EC2 Image Builder to create an Amazon Machine Image (AMI). Install all the patches and agents that are needed to manage and run the application. Update the Auto Scaling group launch configuration to use the AMI.
🛠️ Đúng vì: Pre-bake patches/agents vào AMI qua Image Builder (validate tự động với SSM & security scans). Giảm UserData → instances nhanh sẵn sàng. Không bake app → minimize AMI (app deploy riêng), áp dụng security updates đầy đủ.

❌ Use EC2 Image Builder to create an Amazon Machine Image (AMI). Install the latest version of the application and all the patches and agents that are needed to manage and run the application. Update the Auto Scaling group launch configuration to use the AMI.
🚫 Sai vì: Bake latest app version vào AMI → mỗi app release phải tạo AMI mới → KHÔNG minimize images. Vi phạm yêu cầu "most recent version at all times" linh hoạt (AMI rollout chậm, cần approve).

✅ Set up AWS CodeDeploy to deploy the most recent version of the application at runtime.
🛠️ Đúng vì: Deploy app runtime (post-launch via Deployment Groups trên ASG), luôn latest version mà không tạo AMI mới. Kết hợp Image Builder → hoàn hảo. Hỗ trợ blue/green/rolling để zero-downtime.

❌ Set up AWS CodePipeline to deploy the most recent version of the application at runtime.
🚫 Sai vì: CodePipeline là CI/CD orchestration (pipeline toàn bộ process: build/test/deploy), KHÔNG deploy runtime trực tiếp như CodeDeploy. Không giải quyết scale-out nhanh, chỉ là workflow cao cấp hơn.

❌ Remove any commands that perform operating system patching from the UserData script.
🚫 Sai vì: Loại bỏ patching → KHÔNG áp dụng security updates (vi phạm yêu cầu "apply all available security updates"). Instances scale-out nhanh hơn nhưng rủi ro bảo mật cao, không validated, không best practice (patches nên pre-bake AMI).

📘 Tài liệu tham khảo (AWS Docs cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 💪 Nếu cần thêm ví dụ thực tế, hỏi nhé!

Câu 848
A developer is creating an AWS Lambda function that needs credentials to connect to an Amazon RDS for MySQL database. An Amazon S3 bucket currently stores the credentials. The developer needs to improve the existing solution by implementing credential rotation and secure storage. The developer also needs to provide integration with the Lambda function.
Which solution should the developer use to store and retrieve the credentials with the LEAST management overhead?
  1. A Store the credentials in AWS Systems Manager Parameter Store. Select the database that the parameter will access. Use the default AWS Key Management Service (AWS KMS) key to encrypt the parameter. Enable automatic rotation for the parameter. Use the parameter from Parameter Store on the Lambda function to connect to the database.
  2. B Encrypt the credentials with the default AWS Key Management Service (AWS KMS) key. Store the credentials as environment variables for the Lambda function. Create a second Lambda function to generate new credentials and to rotate the credentials by updating the environment variables of the first Lambda function. Invoke the second Lambda function by using an Amazon EventBridge rule that runs on a schedule. Update the database to use the new credentials. On the first Lambda function, retrieve the credentials from the environment variables. Decrypt the credentials by using AWS KMS, Connect to the database.
  3. C Store the credentials in AWS Secrets Manager. Set the secret type to Credentials for Amazon RDS database. Select the database that the secret will access. Use the default AWS Key Management Service (AWS KMS) key to encrypt the secret. Enable automatic rotation for the secret. Use the secret from Secrets Manager on the Lambda function to connect to the database.
  4. D Encrypt the credentials by using AWS Key Management Service (AWS KMS). Store the credentials in an Amazon DynamoDB table. Create a second Lambda function to rotate the credentials. Invoke the second Lambda function by using an Amazon EventBridge rule that runs on a schedule. Update the DynamoDB table. Update the database to use the generated credentials. Retrieve the credentials from DynamoDB with the first Lambda function. Connect to the database.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào việc cải thiện giải pháp lưu trữ và quản lý credentials (tài khoản truy cập) cho một AWS Lambda function kết nối với Amazon RDS for MySQL. Hiện tại, credentials đang được lưu trong Amazon S3 bucket, điều này không an toàn và không hỗ trợ credential rotation (xoay vòng mật khẩu tự động). Yêu cầu chính là:

  • Secure storage (lưu trữ an toàn với mã hóa).
  • Automatic credential rotation (xoay vòng tự động).
  • Tích hợp dễ dàng với Lambda (Lambda có thể retrieve credentials mà không phức tạp).
  • LEAST management overhead (ít công sức quản lý nhất, tránh custom code hoặc nhiều service).

Mục tiêu là chọn giải pháp tối ưu nhất theo best practice AWS, giảm thiểu rủi ro bảo mật và vận hành. Kiến thức cập nhật đến 2026: AWS Secrets Manager vẫn là dịch vụ hàng đầu cho secrets rotation với RDS (hỗ trợ native integration từ phiên bản mới nhất).

📘 Tài liệu tham khảo:

✅ Đáp án đúng

Phương án thứ 3:
Store the credentials in AWS Secrets Manager. Set the secret type to Credentials for Amazon RDS database. Select the database that the secret will access. Use the default AWS Key Management Service (AWS KMS) key to encrypt the secret. Enable automatic rotation for the secret. Use the secret from Secrets Manager on the Lambda function to connect to the database.

Lý do chọn đáp án này 🛠️:

  • AWS Secrets Manager được thiết kế chuyên biệt cho việc lưu trữ database credentials (loại "Credentials for Amazon RDS"), hỗ trợ automatic rotation native với RDS MySQL mà KHÔNG cần code thêm. Lambda có thể retrieve secret qua SDK (như boto3), tích hợp trực tiếp qua environment variables hoặc IAM roles.
  • Least management overhead: Tự động xoay vòng (mặc định 30 ngày), mã hóa bằng KMS default, chọn DB cụ thể để rotation lambda tự update password trên RDS. Không cần second function hay scheduler thủ công.
  • Best practice 2026: Hỗ trợ zero-downtime rotation và caching trong Lambda runtime mới nhất.

📋 Phân tích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn theo thứ tự, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai với lý do cụ thể:

  1. ❌ Phương án SAI:
    Store the credentials in AWS Systems Manager Parameter Store. Select the database that the parameter will access. Use the default AWS Key Management Service (AWS KMS) key to encrypt the parameter. Enable automatic rotation for the parameter. Use the parameter from Parameter Store on the Lambda function to connect to the database.
    Giải thích: Parameter Store (SSM) hỗ trợ mã hóa KMS và tích hợp Lambda tốt, nhưng KHÔNG hỗ trợ automatic rotation cho database credentials native như Secrets Manager. "Enable automatic rotation" chỉ khả dụng cho một số loại (như IAM users), không phải RDS. Phải custom Lambda rotator, tăng overhead. Không phải lựa chọn least effort.

  2. ❌ Phương án SAI:
    Encrypt the credentials with the default AWS Key Management Service (AWS KMS) key. Store the credentials as environment variables for the Lambda function. Create a second Lambda function to generate new credentials and to rotate the credentials by updating the environment variables of the first Lambda function. Invoke the second Lambda function by using an Amazon EventBridge rule that runs on a schedule. Update the database to use the new credentials. On the first Lambda function, retrieve the credentials from the environment variables. Decrypt the credentials by using AWS KMS, Connect to the database.
    Giải thích: Giải pháp thủ công cao, cần second Lambda + EventBridge scheduler để rotate, update env vars (yêu cầu redeploy Lambda), và decrypt mỗi lần. Environment variables không lý tưởng cho secrets động (phải restart Lambda). Overhead lớn: code custom, manage permissions, error-prone, không phải best practice.

  3. ✅ Phương án ĐÚNG (đã giải thích ở trên) 🏆:
    Native support cho RDS credentials, automatic rotation 1-click enable, Lambda retrieve seamless. Least overhead hoàn hảo!

  4. ❌ Phương án SAI:
    Encrypt the credentials by using AWS Key Management Service (AWS KMS). Store the credentials in an Amazon DynamoDB table. Create a second Lambda function to rotate the credentials. Invoke the second Lambda function by using an Amazon EventBridge rule that runs on a schedule. Update the DynamoDB table. Update the database to use the generated credentials. Retrieve the credentials from DynamoDB with the first Lambda function. Connect to the database.
    Giải thích: DynamoDB KHÔNG phải nơi lưu secrets (thiếu auditing, rotation native). Cần custom second Lambda + EventBridge, query DB mỗi lần (latency cao, IAM phức tạp). Overhead cực lớn: manage table, indexes, costs, không an toàn bằng Secrets Manager. Vi phạm least management.

🛡️ Kết luận & Best Practice

✅ Chọn Secrets Manager để giảm thiểu rủi ro bảo mật (least privilege via IAM) và tự động hóa hoàn toàn. Tránh custom solutions vì dễ lỗi và tốn kém maintain. Trong DevOps Professional exam (DOP-C02), đây là pattern chuẩn cho secrets management! 🚀

Câu 849
A developer has written the following IAM policy to provide access to an Amazon S3 bucket:
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject",
        "s3:PutObject"
      ],
      "Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET/*"
    },
    {
      "Effect": "Deny",
      "Action": "s3:*",
      "Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET/secrets*"
    }
  ]
}

Which access does the policy allow regarding the s3:GetObject and s3:PutObject actions?
  1. A Access on all buckets except the “DOC-EXAMPLE-BUCKET” bucket
  2. B Access on all buckets that start with “DOC-EXAMPLE-BUCKET” except the “DOC-EXAMPLE-BUCKET/secrets” bucket
  3. C Access on all objects in the “DOC-EXAMPLE-BUCKET” bucket along with access to all S3 actions for objects in the “DOC-EXAMPLE-BUCKET” bucket that start with “secrets”
  4. D Access on all objects in the “DOC-EXAMPLE-BUCKET” bucket except on objects that start with “secrets”
Xem giải thích

📘 Phân tích câu hỏi:

Câu hỏi liên quan đến một chính sách IAM (Identity and Access Management) được viết để cấp quyền truy cập vào một bucket Amazon S3. Chính sách này bao gồm hai câu lệnh:

  1. Allow (cho phép) các hành động s3:GetObject và s3:PutObject trên tài nguyên arn:aws:s3:::DOC-EXAMPLE-BUCKET/*. Điều này có nghĩa là chính sách cho phép thực hiện các hành động này trên tất cả các đối tượng trong bucket DOC-EXAMPLE-BUCKET.

  2. Deny (từ chối) tất cả các hành động (s3:*) trên tài nguyên arn:aws:s3:::DOC-EXAMPLE-BUCKET/secrets*. Điều này có nghĩa là chính sách từ chối tất cả các hành động trên các đối tượng trong bucket DOC-EXAMPLE-BUCKET mà tên bắt đầu bằng secrets.

✨ Các lựa chọn và phân tích:

  • Access on all buckets except the “DOC-EXAMPLE-BUCKET” bucket: ❌ Sai, vì chính sách chỉ đề cập đến bucket DOC-EXAMPLE-BUCKET và không liên quan đến các bucket khác.

  • Access on all buckets that start with “DOC-EXAMPLE-BUCKET” except the “DOC-EXAMPLE-BUCKET/secrets” bucket: ❌ Sai, vì chính sách chỉ áp dụng cho bucket DOC-EXAMPLE-BUCKET cụ thể và không đề cập đến các bucket khác có tên bắt đầu bằng DOC-EXAMPLE-BUCKET.

  • Access on all objects in the “DOC-EXAMPLE-BUCKET” bucket along with access to all S3 actions for objects in the “DOC-EXAMPLE-BUCKET” bucket that start with “secrets”: ❌ Sai, vì câu lệnh thứ hai trong chính sách thực sự từ chối tất cả các hành động trên các đối tượng bắt đầu bằng secrets, không phải cấp quyền.

  • Access on all objects in the “DOC-EXAMPLE-BUCKET” bucket except on objects that start with “secrets”: ✅ Đúng, vì chính sách cho phép các hành động s3:GetObject và s3:PutObject trên tất cả các đối tượng trong bucket DOC-EXAMPLE-BUCKET, nhưng từ chối tất cả các hành động trên các đối tượng bắt đầu bằng secrets.

📚 Tài liệu tham khảo:

➡️ Đáp án đúng: Access on all objects in the “DOC-EXAMPLE-BUCKET” bucket except on objects that start with “secrets”.

Câu 850
A developer is creating a mobile app that calls a backend service by using an Amazon API Gateway REST API. For integration testing during the development phase, the developer wants to simulate different backend responses without invoking the backend service.
Which solution will meet these requirements with the LEAST operational overhead?
  1. A Create an AWS Lambda function. Use API Gateway proxy integration to return constant HTTP responses.
  2. B Create an Amazon EC2 instance that serves the backend REST API by using an AWS CloudFormation template.
  3. C Customize the API Gateway stage to select a response type based on the request.
  4. D Use a request mapping template to select the mock integration response.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào Amazon API Gateway REST API trong giai đoạn phát triển ứng dụng mobile. Nhà phát triển muốn mô phỏng (simulate) các phản hồi backend khác nhau để kiểm tra tích hợp (integration testing), mà không cần gọi thực tế đến dịch vụ backend. Yêu cầu chính là giải pháp có ít overhead vận hành nhất (LEAST operational overhead) – nghĩa là đơn giản, nhanh chóng triển khai, không cần tài nguyên bổ sung như server hay code riêng, và tận dụng tính năng native của AWS. 📱🔄

Điều này rất phổ biến trong DevOps, giúp test nhanh mà không phụ thuộc backend thực, giảm chi phí và thời gian. API Gateway hỗ trợ mock integrations từ lâu (cập nhật đến 2026 vẫn là best practice cho REST APIs, không thay đổi lớn ở HTTP APIs).

✅ Đáp án đúng: Use a request mapping template to select the mock integration response

Lý do lựa chọn:
Giải pháp này sử dụng tính năng Mock Integration native của API Gateway REST API 🛠️. Bạn chỉ cần:

  • Tạo method integration với type MOCK.
  • Sử dụng request mapping template (Velocity Template Language - VTL) để phân tích request (như query params, headers) và chọn response mock phù hợp (ví dụ: success, error 4xx/5xx).
    Least overhead vì: Không code Lambda, không deploy infra, chỉ config trong console/CLI/CDK/Serverless Framework. Triển khai ngay, scale tự động, chi phí thấp (chỉ API calls). Phù hợp testing development phase. 🚀

📋 Giải thích tất cả các phương án (đúng/sai)

  • ❌ [SAI] Create an AWS Lambda function. Use API Gateway proxy integration to return constant HTTP responses.
    Phương án này yêu cầu tạo Lambda function và proxy integration – overhead cao vì phải viết/deploy code Lambda (IAM roles, logs, cold starts). Chỉ return "constant" responses, không linh hoạt simulate "different" responses dựa trên request. Không phải mock thuần, vi phạm LEAST overhead. 🛑

  • ❌ [SAI] Create an Amazon EC2 instance that serves the backend REST API by using an AWS CloudFormation template.
    Overhead cực lớn: Tạo EC2 (provisioning, patching, scaling, security groups), dùng CloudFormation để deploy. Đây là full backend sim, không cần thiết cho testing, tốn chi phí/time/maintenance. Không tận dụng API Gateway native. 🚫

  • ❌ [SAI] Customize the API Gateway stage to select a response type based on the request.
    Stages chỉ dùng cho deployment variables, canary, logging – không hỗ trợ select response dựa trên request. Không có tính năng mapping response theo logic request ở stage level. Sai hoàn toàn về architecture. ❌

  • ✅ [ĐÚNG] Use a request mapping template to select the mock integration response.
    Như đã giải thích: Sử dụng mapping template trong Mock Integration để parse request và return response động (ví dụ: #set($inputRoot = $input.path('$')) để check params). Linh hoạt, zero infra, best practice AWS. Áp dụng ngay ở dev stage. 🎯

📘 Tài liệu tham khảo (AWS cập nhật 2026)

  • AWS API Gateway Developer Guide: Mock Integrations & Mapping Template Reference.
  • AWS Well-Architected Framework - DevOps Pillar: Nhấn mạnh mock/simulations để reduce dependencies.
  • Exam DOP-C02 (DevOps Pro 2023+): Topic API Gateway integrations thường test mock vs proxy.

Giải pháp này giúp CI/CD pipeline nhanh chóng! Nếu cần ví dụ code VTL cụ thể, hỏi thêm nhé. 😊