Ngân hàng đề — AWS Certified Developer Associate

Tìm thấy 1356 câu.

Câu 901
A developer is creating an application. New users of the application must be able to create an account and register by using their own social media accounts.

Which AWS service or resource should the developer use to meet these requirements?
  1. A IAM role
  2. B Amazon Cognito identity pools
  3. C Amazon Cognito user pools
  4. D AWS Directory Service
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả một lập trình viên đang phát triển ứng dụng, trong đó người dùng mới phải có thể tạo tài khoản và đăng ký bằng tài khoản mạng xã hội của chính họ (như Google, Facebook, Apple, v.v.). Yêu cầu chính là chọn AWS service hoặc resource phù hợp để đáp ứng nhu cầu này.

🔍 Yêu cầu cốt lõi:

  • Hỗ trợ tạo tài khoản (sign-up) và đăng nhập (sign-in).
  • Tích hợp social media accounts (federated identities từ các nhà cung cấp bên thứ ba).
  • Đây là tính năng user authentication và management cho ứng dụng web/mobile, không liên quan đến AWS credentials hay enterprise directory.

🛠️ Bối cảnh AWS (cập nhật đến 2026): AWS Cognito là dịch vụ chính cho identity management trong ứng dụng. Phiên bản mới nhất (2024-2026) hỗ trợ User Pools với hosted UI, social federation (OAuth/OIDC), MFA, và integration mượt mà với Amplify/AppSync. Không có thay đổi lớn làm thay thế User Pools cho use case này.

✅ Đáp án đúng: Amazon Cognito user pools

Lý do lựa chọn:

  • Amazon Cognito user pools là dịch vụ quản lý user directory chuyên biệt cho ứng dụng, cho phép người dùng tạo tài khoản mới (sign-up) và đăng ký/đăng nhập qua social media (social providers như Google, Facebook, Amazon, Apple Sign-In).
  • Nó cung cấp hosted UI sẵn dùng, quy trình sign-up/sign-in tự động, và lưu trữ user attributes. Sau khi authenticate, có thể kết hợp với Identity Pools để cấp AWS credentials nếu cần.
  • Hoàn hảo khớp yêu cầu: "New users... create an account and register by using their own social media accounts" – User Pools hỗ trợ chính xác điều này mà không cần code phức tạp.
  • ✅ Xác nhận từ AWS best practices: Đây là lựa chọn tiêu chuẩn cho customer-facing apps (không phải internal AWS users).

📋 Giải thích tất cả các phương án (đúng/sai)

  • ❌ IAM role
    Phương án này sai vì IAM roles dùng để cấp quyền truy cập AWS resources cho users/services (như EC2, Lambda), không hỗ trợ tạo tài khoản người dùng cuối hay tích hợp social media sign-up. Nó chỉ là authorization mechanism nội bộ AWS, không phải authentication cho app users.

  • ❌ Amazon Cognito identity pools
    Phương án này sai vì Identity Pools (nay gọi là authenticated/unauthenticated identities) dùng để cấp AWS credentials tạm thời sau khi đã authenticate (thường từ User Pools hoặc social providers). Nó không quản lý sign-up/register users hay lưu trữ user directory – chỉ federate identities để gọi AWS APIs. Không phù hợp cho "create an account".

  • ✅ Amazon Cognito user pools
    Phương án này đúng như giải thích ở trên. User Pools xử lý toàn bộ lifecycle user: sign-up, sign-in, forgot password, social federation (hỗ trợ 10+ providers tính đến 2026), và scalable đến hàng triệu users. Tích hợp dễ với SDKs (JS, iOS, Android).

  • ❌ AWS Directory Service
    Phương án này sai vì AWS Directory Service (như Managed Microsoft AD, AD Connector) dành cho enterprise directory integration (on-prem Active Directory sync), không hỗ trợ social media sign-up cho public apps. Nó tập trung vào VPC/internal users, không phải customer-facing registration.

📘 Tài liệu tham khảo (AWS docs cập nhật 2024-2026)

Hy vọng phân tích giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ code Amplify, hãy hỏi nhé!

Câu 902
A social media application uses the AWS SDK for JavaScript on the frontend to get user credentials from AWS Security Token Service (AWS STS). The application stores its assets in an Amazon S3 bucket. The application serves its content by using an Amazon CloudFront distribution with the origin set to the S3 bucket.

The credentials for the role that the application assumes to make the SDK calls are stored in plaintext in a JSON file within the application code. The developer needs to implement a solution that will allow the application to get user credentials without having any credentials hardcoded in the application code.

Which solution will meet these requirements?
  1. A Add a Lambda@Edge function to the distribution. Invoke the function on viewer request. Add permissions to the function's execution role to allow the function to access AWS STS. Move all SDK calls from the frontend into the function.
  2. B Add a CloudFront function to the distribution. Invoke the function on viewer request. Add permissions to the function's execution role to allow the function to access AWS STS. Move all SDK calls from the frontend into the function.
  3. C Add a Lambda@Edge function to the distribution. Invoke the function on viewer request. Move the credentials from the JSON file into the function. Move all SDK calls from the frontend into the function.
  4. D Add a CloudFront function to the distribution. Invoke the function on viewer request. Move the credentials from the JSON file into the function. Move all SDK calls from the frontend into the function.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh một ứng dụng mạng xã hội (social media application) sử dụng AWS SDK for JavaScript trên frontend để lấy user credentials từ AWS Security Token Service (STS). Các tài nguyên (assets) được lưu trữ trong Amazon S3 bucket, và nội dung được phân phối qua Amazon CloudFront distribution với origin là S3 bucket đó.

Hiện tại, credentials cho IAM role mà ứng dụng assume để gọi SDK bị lưu trữ plaintext trong file JSON ngay trong mã nguồn ứng dụng – đây là rủi ro bảo mật lớn vì dễ bị lộ (hardcoded credentials).

Yêu cầu giải pháp: Cho phép ứng dụng lấy user credentials mà không hardcode bất kỳ credentials nào trong code. Nghĩa là phải di chuyển logic gọi STS ra khỏi frontend, đảm bảo an toàn, tận dụng edge computing của CloudFront, và không lưu credentials tĩnh.

Mục tiêu chính:

  • ✅ Di chuyển SDK calls (gọi STS) khỏi frontend.
  • ✅ Không hardcode credentials (sử dụng IAM role động).
  • ✅ Tích hợp mượt mà với CloudFront (viewer request trigger).
  • 🛠️ Phù hợp kiến thức AWS mới nhất 2026: Lambda@Edge hỗ trợ gọi AWS APIs đầy đủ với execution role; CloudFront Functions chỉ lightweight JS, không hỗ trợ gọi AWS services như STS.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Add a Lambda@Edge function to the distribution. Invoke the function on viewer request. Add permissions to the function's execution role to allow the function to access AWS STS. Move all SDK calls from the frontend into the function.

Lý do chi tiết:

  • 🛠️ Lambda@Edge chạy tại edge locations của CloudFront, trigger trên viewer request (xử lý trước khi request đến origin), lý tưởng cho logic động như gọi STS.
  • Execution role của Lambda@Edge được attach IAM policy cho phép sts:AssumeRole hoặc tương tự → không cần hardcode credentials, AWS tự quản lý.
  • Di chuyển tất cả SDK calls vào function → Frontend sạch sẽ, an toàn (client chỉ nhận kết quả).
  • ✅ Hoàn hảo match yêu cầu: Không hardcoded, tận dụng edge compute, cập nhật 2026 (Lambda@Edge vẫn là lựa chọn chuẩn cho AWS API calls tại edge).

📋 Giải thích tất cả các phương án (đúng/sai)

  • ✅ Phương án ĐÚNG (như trên):
    Lambda@Edge + permissions cho STS + move SDK calls → Giải quyết triệt để, không hardcoded.

  • ❌ Phương án SAI 1:
    Add a CloudFront function to the distribution. Invoke the function on viewer request. Add permissions to the function's execution role to allow the function to access AWS STS. Move all SDK calls from the frontend into the function.
    Lý do sai: CloudFront Functions (ra mắt 2020, cập nhật 2026) chỉ chạy lightweight JavaScript (max 1MB, <10ms), không hỗ trợ execution role hay gọi AWS services như STS (không có IAM integration). Không thể add permissions hoặc SDK calls AWS APIs → Fail yêu cầu.

  • ❌ Phương án SAI 2:
    Add a Lambda@Edge function to the distribution. Invoke the function on viewer request. Move the credentials from the JSON file into the function. Move all SDK calls from the frontend into the function.
    Lý do sai: Vẫn move credentials từ JSON vào function → Vẫn hardcoded plaintext trong Lambda code (dù edge-safe hơn frontend, nhưng vi phạm "without any credentials hardcoded"). Không tận dụng IAM role động.

  • ❌ Phương án SAI 3:
    Add a CloudFront function to the distribution. Invoke the function on viewer request. Move the credentials from the JSON file into the function. Move all SDK calls from the frontend into the function.
    Lý do sai: Kết hợp 2 lỗi lớn: CloudFront Functions không gọi AWS APIs/STS + vẫn hardcoded credentials → Hoàn toàn không khả thi và không an toàn.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Hy vọng phân tích này giúp bạn nắm vững! 🚀 Nếu cần thêm ví dụ code, comment bên dưới nhé!

Câu 903
An ecommerce website uses an AWS Lambda function and an Amazon RDS for MySQL database for an order fulfillment service. The service needs to return order confirmation immediately.

During a marketing campaign that caused an increase in the number of orders, the website's operations team noticed errors for “too many connections” from Amazon RDS. However, the RDS DB cluster metrics are healthy. CPU and memory capacity are still available.

What should a developer do to resolve the errors?
  1. A Initialize the database connection outside the handler function. Increase the max_user_connections value on the parameter group of the DB cluster. Restart the DB cluster.
  2. B Initialize the database connection outside the handler function. Use RDS Proxy instead of connecting directly to the DB cluster.
  3. C Use Amazon Simple Queue Service (Amazon SQS) FIFO queues to queue the orders. Ingest the orders into the database. Set the Lambda function's concurrency to a value that equals the number of available database connections.
  4. D Use Amazon Simple Queue Service (Amazon SQS) FIFO queues to queue the orders. Ingest the orders into the database. Set the Lambda function's concurrency to a value that is less than the number of available database connections.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một website thương mại điện tử (ecommerce) sử dụng AWS Lambda kết hợp với Amazon RDS for MySQL để xử lý dịch vụ xác nhận đơn hàng (order fulfillment). Dịch vụ này phải trả về xác nhận đơn hàng ngay lập tức (immediately), không được delay.

Trong một chiến dịch marketing gây tăng đột biến số lượng đơn hàng, đội ngũ vận hành phát hiện lỗi "too many connections" từ RDS. Tuy nhiên, metrics của RDS DB cluster vẫn healthy: CPU và memory còn dư thừa, không phải vấn đề tài nguyên.

Vấn đề cốt lõi 🛠️: Lambda function tạo quá nhiều kết nối database (connections) vì mỗi invocation (gọi hàm) thường mở connection mới. Với traffic spike, số Lambda invocations tăng vọt → vượt giới hạn connections của RDS MySQL (mặc định ~100-200 tùy instance). RDS Proxy là giải pháp lý tưởng để pool và reuse connections, giảm tải trực tiếp lên DB. Kiến thức cập nhật 2026: RDS Proxy hỗ trợ MySQL 8.0+ và tích hợp seamless với Lambda (AWS re:Invent 2024 updates nhấn mạnh proxy cho serverless).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Initialize the database connection outside the handler function. Use RDS Proxy instead of connecting directly to the DB cluster.

Lý do 📈:

  • Khởi tạo connection ngoài handler giúp reuse connection giữa các invocations trên cùng execution environment (warm Lambda), giảm số connection mới.
  • RDS Proxy là connection pooler chuyên dụng cho RDS, tự động quản lý, multiplex và scale connections → giải quyết triệt để "too many connections" mà không cần tăng max_user_connections (tránh over-provision). Proxy hỗ trợ IAM auth, secrets rotation, và failover tự động. Phù hợp serverless, return confirmation ngay vì proxy không delay logic. Theo best practices AWS 2026, đây là giải pháp recommended cho Lambda + RDS.

🔍 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá đúng/sai với lý do cụ thể:

  • ✅ [ĐÚNG] Initialize the database connection outside the handler function. Use RDS Proxy instead of connecting directly to the DB cluster.
    Như đã giải thích ở trên: Kết hợp init outside handler (giảm cold start connections) + RDS Proxy (pooling hiệu quả). Giải quyết gốc rễ, không ảnh hưởng performance, tuân thủ Lambda best practices và RDS Proxy docs (2026 updates: hỗ trợ Aurora Serverless v2 đầy đủ).

  • ❌ [SAI] Initialize the database connection outside the handler function. Increase the max_user_connections value on the parameter group of the DB cluster. Restart the DB cluster.
    Init outside handler tốt nhưng tăng max_user_connections chỉ là workaround tạm thời, không scale với traffic spike (vẫn hết connections nếu Lambda concurrency cao). Restart DB gây downtime (5-10 phút), vi phạm yêu cầu "immediately". Không khuyến khích vì che lấp vấn đề root cause (connection leakage).

  • ❌ [SAI] Use Amazon Simple Queue Service (Amazon SQS) FIFO queues to queue the orders. Ingest the orders into the database. Set the Lambda function's concurrency to a value that equals the number of available database connections.
    SQS FIFO queue orders → delay confirmation (async processing), trái yêu cầu "return immediately". Set concurrency = DB connections vẫn rủi ro throttling nếu traffic spike, không giải quyết pooling. SQS phù hợp decouple nhưng không cho real-time response.

  • ❌ [SAI] Use Amazon Simple Queue Service (Amazon SQS) FIFO queues to queue the orders. Ingest the orders into the database. Set the Lambda function's concurrency to a value that is less than the number of available database connections.
    Tương tự trên: Queueing gây delay, không đáp ứng "immediately". Giảm concurrency giúp tránh overload nhưng giới hạn throughput, dễ backlog trong campaign. Không phải giải pháp tối ưu cho connection management.

📘 Tài liệu tham khảo (Cập nhật 2026)

Giải pháp này đảm bảo high availability và cost-effective! 🚀 Nếu cần code sample hoặc diagram, hãy hỏi thêm nhé!

Câu 904
A company stores its data in data tables in a series of Amazon S3 buckets. The company received an alert that customer credit card information might have been exposed in a data table on one of the company's public applications. A developer needs to identify all potential exposures within the application environment.

Which solution will meet these requirements?
  1. A Use Amazon Athena to run a job on the S3 buckets that contain the affected data. Filter the findings by using the SensitiveData:S3Object/Personal finding type.
  2. B Use Amazon Macie to run a job on the S3 buckets that contain the affected data. Filter the findings by using the SensitiveData:S3Object/Financial finding type.
  3. C Use Amazon Macie to run a job on the S3 buckets that contain the affected data. Filter the findings by using the SensitiveData:S3Object/Personal finding type.
  4. D Use Amazon Athena to run a job on the S3 buckets that contain the affected data. Filter the findings by using the SensitiveData:S3Object/Financial finding type.
Xem giải thích

🛡️ Phân tích câu hỏi AWS Certified DevOps Engineer Professional

👨‍💼 Chào bạn! Tôi là AWS Certified DevOps Engineer Professional (DOP-C02), với kiến thức cập nhật đến năm 2026 theo các phiên bản AWS mới nhất (bao gồm Macie v2 và Athena với tích hợp Glue). Tôi sẽ phân tích câu hỏi trắc nghiệm một cách chi tiết, logic và dễ hiểu theo yêu cầu của bạn. Hãy cùng khám phá!

🧩 Giải thích nội dung câu hỏi một cách chi tiết:
Câu hỏi mô tả tình huống một công ty lưu trữ dữ liệu dưới dạng data tables (các bảng dữ liệu) trong nhiều Amazon S3 buckets. Họ nhận được alert (cảnh báo) rằng customer credit card information (thông tin thẻ tín dụng khách hàng) có thể bị lộ ra ngoài qua một data table trên public applications (ứng dụng công khai). Nhiệm vụ của developer là identify all potential exposures (xác định tất cả các rò rỉ tiềm ẩn) trong toàn bộ application environment (môi trường ứng dụng).
🔍 Yêu cầu cốt lõi: Cần một giải pháp scan (quét) dữ liệu trong S3 buckets để phát hiện dữ liệu nhạy cảm cụ thể là thẻ tín dụng (financial data), lọc kết quả theo loại finding phù hợp, và xử lý nhanh chóng để giảm thiểu rủi ro tuân thủ (compliance) như PCI DSS. Giải pháp phải hỗ trợ jobs để quét S3 và tạo findings chi tiết.

✅ Đáp án đúng và lý do lựa chọn:
Đáp án đúng: Use Amazon Macie to run a job on the S3 buckets that contain the affected data. Filter the findings by using the SensitiveData:S3Object/Financial finding type.
Lý do:

  • Amazon Macie (v2, cập nhật 2023-2026) là dịch vụ chuyên dụng để phát hiện, phân loại và bảo vệ dữ liệu nhạy cảm trong S3 bằng ML/ML-based managed data identifiers. Nó chạy jobs quét S3 buckets, tạo findings với loại chính xác như SensitiveData:S3Object/Financial – bao gồm credit card numbers (số thẻ tín dụng, theo regex patterns như 16 chữ số theo chuẩn Visa/MasterCard).
  • Đây là cách hiệu quả nhất để xác định tất cả potential exposures (toàn bộ rò rỉ), hỗ trợ filter findings qua console/API, và tích hợp với EventBridge/GuardDuty cho alert. Athena không có tính năng này.
  • ✅ Phù hợp 100% với yêu cầu scan financial data trong S3 tables.

📋 Giải thích tất cả các phương án (đúng/sai):
Dưới đây là phân tích từng lựa chọn một cách logic, giữ nguyên văn bản gốc. Tôi đánh dấu ✅ (đúng) hoặc ❌ (sai), kèm lý do chi tiết dựa trên AWS docs mới nhất.

  • Use Amazon Athena to run a job on the S3 buckets that contain the affected data. Filter the findings by using the SensitiveData:S3Object/Personal finding type.
    ❌ Sai hoàn toàn. Athena là dịch vụ query SQL trên S3 (dùng Glue Catalog), không chạy "job" để scan sensitive data hay tạo "findings" với loại SensitiveData:S3Object. Athena chỉ query dữ liệu đã biết, không tự phát hiện PII/financial. Loại Personal (PII như SSN, email) không liên quan đến credit card.

  • ✅ Use Amazon Macie to run a job on the S3 buckets that contain the affected data. Filter the findings by using the SensitiveData:S3Object/Financial finding type.
    ✅ Đúng tuyệt đối (như đã giải thích ở trên). Macie hỗ trợ Financial finding type chính xác cho credit card (bao gồm primary account number - PAN), quét toàn bộ S3 objects/tables, và filter findings dễ dàng. Hoàn hảo cho DevOps automation!

  • Use Amazon Macie to run a job on the S3 buckets that contain the affected data. Filter the findings by using the SensitiveData:S3Object/Personal finding type.
    ❌ Sai về loại finding. Macie đúng là tool phù hợp để chạy job và filter, nhưng Personal chỉ phát hiện PII cá nhân (như tên, địa chỉ, phone), không bao gồm credit card (thuộc Financial). Sẽ miss các exposure thẻ tín dụng!

  • Use Amazon Athena to run a job on the S3 buckets that contain the affected data. Filter the findings by using the SensitiveData:S3Object/Financial finding type.
    ❌ Sai kép. Athena không hỗ trợ "findings" hay SensitiveData:S3Object types (đây là của Macie). Athena chỉ query dữ liệu thô (ví dụ: SELECT regex cho credit card), không tự động scan/classify như Macie, và không có job/filter kiểu này.

🛠️ Lời khuyên DevOps thực tế:

  • Triển khai Macie automated discovery jobs (mới 2024) để quét liên tục S3, kết hợp S3 Access Points và Bucket Policies để khóa public access.
  • Scale bằng Macie delegation cho multi-account (Organizations).
  • Test nhanh: Tạo S3 bucket với fake credit card data → Chạy Macie job → Filter Financial findings.

📘 Tài liệu tham khảo (AWS mới nhất 2026):

🚀 Nếu cần lab thực hành hoặc câu hỏi khác, cứ hỏi nhé!

Câu 905 Chọn nhiều đáp án
A software company is launching a multimedia application. The application will allow guest users to access sample content before the users decide if they want to create an account to gain full access. The company wants to implement an authentication process that can identify users who have already created an account. The company also needs to keep track of the number of guest users who eventually create an account.

Which combination of steps will meet these requirements? (Choose two.)
  1. A Create an Amazon Cognito user pool. Configure the user pool to allow unauthenticated users. Exchange user tokens for temporary credentials that allow authenticated users to assume a role.
  2. B Create an Amazon Cognito identity pool. Configure the identity pool to allow unauthenticated users. Exchange unique identity for temporary credentials that allow all users to assume a role.
  3. C Create an Amazon CloudFront distribution. Configure the distribution to allow unauthenticated users. Exchange user tokens for temporary credentials that allow all users to assume a role.
  4. D Create a role for authenticated users that allows access to all content. Create a role for unauthenticated users that allows access to only the sample content.
  5. E Allow all users to access the sample content by default. Create a role for authenticated users that allows access to the other content.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một ứng dụng multimedia cho phép người dùng guest (không xác thực) truy cập nội dung mẫu trước khi quyết định tạo tài khoản để mở khóa toàn bộ nội dung. Yêu cầu chính bao gồm:

  • Xác định người dùng đã tạo tài khoản (authenticated users).
  • Theo dõi số lượng guest chuyển sang tạo tài khoản (tracking conversion từ guest sang authenticated).
  • Cần chọn TWO steps kết hợp để đáp ứng, sử dụng các dịch vụ AWS như Cognito để xử lý authentication/authorization, cấp temporary credentials và roles IAM phù hợp.

Vấn đề cốt lõi: Phân biệt quyền truy cập giữa guest (unauthenticated) chỉ xem sample content và authenticated xem full content, đồng thời track unique identity để đo lường chuyển đổi. Giải pháp lý tưởng dùng Amazon Cognito Identity Pool (cho cả auth/un-auth users) kết hợp IAM Roles riêng biệt, vì Identity Pool cấp unique ID ngay cả cho guest, giúp track và assume roles. (Dựa trên AWS Cognito phiên bản mới nhất 2024-2026, hỗ trợ enhanced federation và unauthenticated identities).

✅ Đáp án đúng (Chọn TWO)

Hai phương án đúng là:

  1. Create an Amazon Cognito identity pool. Configure the identity pool to allow unauthenticated users. Exchange unique identity for temporary credentials that allow all users to assume a role.
    🛠️ Lý do chọn: Identity Pool là dịch vụ chính để cấp unique identity ID cho cả authenticated và unauthenticated users. Cho phép guest (unauth) truy cập qua temporary AWS credentials, assume role chung. Unique ID giúp track conversion (guest → account). Đây là bước nền tảng để phân biệt và theo dõi users.

  2. Create a role for authenticated users that allows access to all content. Create a role for unauthenticated users that allows access to only the sample content.
    🛠️ Lý do chọn: Kết hợp với Identity Pool, attach hai IAM Roles riêng: unauth role chỉ sample content (e.g., S3 objects limited), auth role full access. Đảm bảo guest không vượt quyền, và track qua identity ID khi guest upgrade thành auth. Hoàn hảo cho yêu cầu phân quyền và tracking.

Kết hợp hai bước này đáp ứng đầy đủ: Cognito Identity Pool xử lý identity/temporary creds → Roles IAM kiểm soát access. Không cần User Pool vì focus vào unauth tracking.

📋 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Sử dụng ✅ cho đúng, ❌ cho sai, kèm giải thích cụ thể dựa trên best practices AWS Cognito/IAM (cập nhật DOP-C02 exam blueprint 2024+).

  • ❌ Create an Amazon Cognito user pool. Configure the user pool to allow unauthenticated users. Exchange user tokens for temporary credentials that allow authenticated users to assume a role.
    🧩 Giải thích sai: User Pool chỉ dành cho authenticated users (sign-up/sign-in với tokens như ID/JWT), KHÔNG hỗ trợ unauthenticated users (không có "allow unauthenticated" option). Guest không có token, nên không track được unique ID cho conversion. Phù hợp auth nhưng thiếu guest support → Không đáp ứng yêu cầu guest access/sample tracking.

  • ✅ Create an Amazon Cognito identity pool. Configure the identity pool to allow unauthenticated users. Exchange unique identity for temporary credentials that allow all users to assume a role.
    🛠️ Giải thích đúng: Identity Pool cấp unique identity ID cho guest (unauth role) và auth users, exchange lấy temporary STS creds để assume roles. Cho phép track số guest tạo account (qua ID mapping). Hỗ trợ "unauthenticated identities" chính thức trong Cognito (phiên bản mới nhất).

  • ❌ Create an Amazon CloudFront distribution. Configure the distribution to allow unauthenticated users. Exchange user tokens for temporary credentials that allow all users to assume a role.
    🧩 Giải thích sai: CloudFront là CDN caching, không xử lý authentication/identity/tokens/creds. Không có tính năng "allow unauthenticated" hay exchange tokens cho roles IAM. Chỉ dùng cho delivery content, không track users hay conversion → Hoàn toàn không liên quan.

  • ✅ Create a role for authenticated users that allows access to all content. Create a role for unauthenticated users that allows access to only the sample content.
    🛠️ Giải thích đúng: Hai IAM Roles attach vào Identity Pool: unauth role policy limit S3/DynamoDB chỉ sample (e.g., prefix "samples/*"), auth role full access. Kết hợp Identity Pool để guest/auth assume role tương ứng, track conversion qua identity ID. Best practice cho fine-grained access control.

  • ❌ Allow all users to access the sample content by default. Create a role for authenticated users that allows access to the other content.
    🧩 Giải thích sai: Không tạo role cho unauth users, chỉ default access sample (e.g., public S3 bucket) thiếu security và KHÔNG track unique identity cho guest conversion. Auth role chỉ full content, nhưng guest không có identity để measure "số lượng guest tạo account" → Vi phạm nguyên tắc least privilege và tracking yêu cầu.

📘 Tài liệu tham khảo

Hy vọng phân tích giúp bạn ôn thi hiệu quả! 🚀 Nếu cần ví dụ code Terraform/CloudFormation, hỏi thêm nhé!

Câu 906
A company is updating an application to move the backend of the application from Amazon EC2 instances to a serverless model. The application uses an Amazon RDS for MySQL DB instance and runs in a single VPC on AWS. The application and the DB instance are deployed in a private subnet in the VPC.

The company needs to connect AWS Lambda functions to the DB instance.

Which solution will meet these requirements?
  1. A Create Lambda functions inside the VPC with the AWSLambdaBasicExecutionRole policy attached to the Lambda execution role. Modify the RDS security group to allow inbound access from the Lambda security group.
  2. B Create Lambda functions inside the VPC with the AWSLambdaVPCAccessExecutionRole policy attached to the Lambda execution role. Modify the RDS security group to allow inbound access from the Lambda security group.
  3. C Create Lambda functions with the AWSLambdaBasicExecutionRole policy attached to the Lambda execution role. Create an interface VPC endpoint for the Lambda functions. Configure the interface endpoint policy to allow the lambda:InvokeFunclion action for each Lambda function's Amazon Resource Name (ARN).
  4. D Create Lambda functions with the AWSLambdaVPCAccessExecutionRole policy attached to the Lambda execution role. Create an interface VPC endpoint for the Lambda functions. Configure the interface endpoint policy to allow the lambda:InvokeFunction action for each Lambda function's Amazon Resource Name (ARN).
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc di chuyển backend ứng dụng từ EC2 sang mô hình serverless sử dụng AWS Lambda, trong khi giữ nguyên Amazon RDS for MySQL nằm trong private subnet của một VPC duy nhất. Ứng dụng và DB đều ở private subnet, nghĩa là không có public IP và cần kết nối nội bộ VPC.
Yêu cầu chính: Kết nối Lambda functions với RDS instance một cách an toàn, hiệu quả.
🛠️ Thách thức chính:

  • Lambda mặc định chạy ngoài VPC, nên cần cấu hình VPC access để Lambda có thể truy cập tài nguyên trong VPC (như RDS).
  • Cần security group (SG) cho phép traffic inbound từ Lambda đến RDS (thường là port 3306 cho MySQL).
  • Phải gắn execution role phù hợp cho Lambda để tạo Elastic Network Interfaces (ENIs) trong VPC.
    📘 Kiến thức AWS cập nhật 2026: Lambda trong VPC yêu cầu policy AWSLambdaVPCAccessExecutionRole (bao gồm quyền ec2:CreateNetworkInterface, ec2:DescribeNetworkInterfaces, v.v.) thay vì chỉ AWSLambdaBasicExecutionRole (chỉ logging CloudWatch). Không cần VPC endpoint cho trường hợp này vì Lambda cần outbound đến RDS, không phải invoke Lambda.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create Lambda functions inside the VPC with the AWSLambdaVPCAccessExecutionRole policy attached to the Lambda execution role. Modify the RDS security group to allow inbound access from the Lambda security group.

Lý do chi tiết:

  • 🛠️ Tạo Lambda inside the VPC (chọn subnet private, SG riêng) để Lambda có ENIs kết nối nội bộ VPC.
  • ✅ AWSLambdaVPCAccessExecutionRole cung cấp quyền cần thiết (logs + VPC networking như tạo/delete ENIs, assign private IP). Đây là policy managed mới nhất AWS khuyến nghị (cập nhật từ 2021, vẫn chuẩn 2026).
  • 🔒 Modify RDS SG allow inbound từ Lambda SG (ví dụ: TCP 3306 từ Lambda SG ID) – cách an toàn nhất, tuân thủ least privilege.
  • Kết quả: Lambda cold start chậm hơn tí do ENI, nhưng kết nối RDS ổn định, không public exposure.

📋 Phân tích tất cả các phương án

Dưới đây là phân tích từng lựa chọn một cách chi tiết. Tôi giữ nguyên nội dung phương án gốc bằng tiếng Anh, đánh dấu ✅/❌ và giải thích rõ lý do đúng/sai bằng tiếng Việt dựa trên best practices AWS.

  • Create Lambda functions inside the VPC with the AWSLambdaBasicExecutionRole policy attached to the Lambda execution role. Modify the RDS security group to allow inbound access from the Lambda security group.
    ❌ Sai: AWSLambdaBasicExecutionRole chỉ cho phép logging CloudWatch (PutLogs), không có quyền VPC (như ec2:CreateNetworkInterface). Lambda không tạo được ENI, không kết nối VPC được → lỗi timeout khi invoke. SG modify đúng nhưng thiếu quyền role → thất bại.

  • Create Lambda functions inside the VPC with the AWSLambdaVPCAccessExecutionRole policy attached to the Lambda execution role. Modify the RDS security group to allow inbound access from the Lambda security group.
    ✅ Đúng: Như giải thích ở trên. Policy đúng (AWSLambdaVPCAccessExecutionRole có full quyền VPC + logs), Lambda inside VPC + SG allow inbound → kết nối RDS thành công, an toàn trong private subnet.

  • Create Lambda functions with the AWSLambdaBasicExecutionRole policy attached to the Lambda execution role. Create an interface VPC endpoint for the Lambda functions. Configure the interface endpoint policy to allow the lambda:InvokeFunclion action for each Lambda function's Amazon Resource Name (ARN).
    ❌ Sai kép:

    • Lambda không inside VPC → không truy cập private RDS trực tiếp.
    • AWSLambdaBasicExecutionRole thiếu quyền VPC.
    • Interface VPC endpoint cho Lambda dùng để invoke Lambda từ VPC (như EC2/ECS gọi Lambda), không phải Lambda gọi RDS. Policy lambda:InvokeFunction sai ngữ cảnh (dành cho caller invoke Lambda, không phải Lambda access RDS). → Hoàn toàn không giải quyết vấn đề.
  • Create Lambda functions with the AWSLambdaVPCAccessExecutionRole policy attached to the Lambda execution role. Create an interface VPC endpoint for the Lambda functions. Configure the interface endpoint policy to allow the lambda:InvokeFunction action for each Lambda function's Amazon Resource Name (ARN).
    ❌ Sai: Policy role đúng nhưng Lambda không inside VPC → vẫn không kết nối RDS private. VPC endpoint cho Lambda là để external invoke Lambda (không public API Gateway), policy lambda:InvokeFunction chỉ cho phép gọi Lambda, không giúp Lambda outbound đến RDS. Thừa và sai hướng.

📘 Tài liệu tham khảo (AWS Docs cập nhật 2026)

🛠️ Lời khuyên DevOps: Test bằng CloudFormation/ECS để automate, monitor cold starts với X-Ray. Nếu scale cao, cân nhắc RDS Proxy để connection pooling!

Câu 907
A company has a web application that runs on Amazon EC2 instances with a custom Amazon Machine Image (AMI). The company uses AWS CloudFormation to provision the application. The application runs in the us-east-1 Region, and the company needs to deploy the application to the us-west-1 Region.

An attempt to create the AWS CloudFormation stack in us-west-1 fails. An error message states that the AMI ID does not exist. A developer must resolve this error with a solution that uses the least amount of operational overhead.

Which solution meets these requirements?
  1. A Change the AWS CloudFormation templates for us-east-1 and us-west-1 to use an AWS AMI. Relaunch the stack for both Regions.
  2. B Copy the custom AMI from us-east-1 to us-west-1. Update the AWS CloudFormation template for us-west-1 to refer to AMI ID for the copied AMI. Relaunch the stack.
  3. C Build the custom AMI in us-west-1. Create a new AWS CloudFormation template to launch the stack in us-west-1 with the new AMI ID.
  4. D Manually deploy the application outside AWS CloudFormation in us-west-1.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một tình huống thực tế trong AWS: Một công ty đang chạy ứng dụng web trên các instance EC2 sử dụng custom Amazon Machine Image (AMI) (AMI tùy chỉnh được xây dựng riêng cho ứng dụng). Họ sử dụng AWS CloudFormation để provision (triển khai tự động) stack ở region us-east-1. Bây giờ, họ muốn triển khai ứng dụng tương tự sang region us-west-1, nhưng khi tạo stack CloudFormation ở us-west-1, gặp lỗi vì AMI ID không tồn tại (AMI là region-specific, nghĩa là mỗi AMI chỉ tồn tại trong region được tạo ra).
Yêu cầu giải pháp: Giải quyết lỗi với ít operational overhead nhất (ít công sức vận hành, tự động hóa cao, không làm thay đổi lớn kiến trúc hiện tại).
🛠️ Vấn đề cốt lõi: AMI tùy chỉnh không thể dùng cross-region trực tiếp, cần xử lý để CloudFormation reference đúng AMI ID ở region mới, đồng thời giữ tính nhất quán và ít thay đổi nhất.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Copy the custom AMI from us-east-1 to us-west-1. Update the AWS CloudFormation template for us-west-1 to refer to AMI ID for the copied AMI. Relaunch the stack.

Lý do:

  • Đây là giải pháp chuẩn AWS và least operational overhead vì:
    • AMI copy giữa regions chỉ mất vài phút (tự động qua Console/CLI/SDK), giữ nguyên nội dung custom AMI mà không cần rebuild từ đầu.
    • Chỉ cần update parameter hoặc mapping trong CloudFormation template để reference AMI ID mới (ví dụ: dùng !Ref AMIId với parameter riêng cho từng region).
    • Relaunch stack đơn giản, tự động hóa cao, đảm bảo tính nhất quán giữa 2 regions.
  • Phù hợp DevOps best practice: Sử dụng AMI cross-region replication để multi-region deployment nhanh chóng, giảm downtime và effort. (Kiến thức cập nhật AWS 2024-2026: AMI copy vẫn là phương pháp chính thức, hỗ trợ encryption và tagging tự động).

📋 Giải thích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, với ✅ cho đúng và ❌ cho sai. Tôi giữ nguyên văn bản gốc bằng tiếng Anh của phương án, chỉ giải thích bằng tiếng Việt:

  • ✅ Copy the custom AMI from us-east-1 to us-west-1. Update the AWS CloudFormation template for us-west-1 to refer to AMI ID for the copied AMI. Relaunch the stack.
    Giải pháp tối ưu nhất! Copy AMI qua AWS Console/CLI (aws ec2 copy-image) tạo AMI mới ở us-west-1 với ID riêng. Update template CloudFormation (thường dùng Parameters hoặc Mappings cho AMI ID theo region). Relaunch stack chỉ tốn ít phút, không thay đổi code app hay rebuild image, overhead thấp nhất. Hoàn hảo cho DevOps automation.

  • ❌ Change the AWS CloudFormation templates for us-east-1 and us-west-1 to use an AWS AMI. Relaunch the stack for both Regions.
    Sai vì yêu cầu dùng custom AMI (chứa app cụ thể). Chuyển sang AWS AMI (như Amazon Linux) sẽ mất cấu hình tùy chỉnh, phải reinstall app thủ công ở cả 2 regions → overhead cao, không nhất quán, vi phạm yêu cầu "resolve error" mà không thay đổi lớn.

  • ❌ Build the custom AMI in us-west-1. Create a new AWS CloudFormation template to launch the stack in us-west-1 with the new AMI ID.
    Sai vì phải build lại AMI từ đầu ở us-west-1 (cài đặt software, config app) → tốn thời gian (giờ hoặc ngày), dễ lỗi khác biệt giữa regions, overhead vận hành cao. Không tận dụng AMI hiện có, trái với "least overhead".

  • ❌ Manually deploy the application outside AWS CloudFormation in us-west-1.
    Sai hoàn toàn vì bỏ qua CloudFormation (IaC - Infrastructure as Code), phải deploy thủ công (launch EC2, cài app) → không tự động hóa, khó scale/maintain, overhead cực cao, không phù hợp DevOps Professional.

📘 Tài liệu tham khảo (AWS cập nhật mới nhất 2024-2026)

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần ví dụ code CloudFormation, hãy hỏi thêm nhé!

Câu 908
A developer is updating several AWS Lambda functions and notices that all the Lambda functions share the same custom libraries. The developer wants to centralize all the libraries, update the libraries in a convenient way, and keep the libraries versioned.

Which solution will meet these requirements with the LEAST development effort?
  1. A Create an AWS CodeArtifact repository that contains all the custom libraries.
  2. B Create a custom container image for the Lambda functions to save all the custom libraries.
  3. C Create a Lambda layer that contains all the custom libraries.
  4. D Create an Amazon Elastic File System (Amazon EFS) file system to store all the custom libraries.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm AWS Lambda

📖 Nội dung câu hỏi:
Một lập trình viên đang cập nhật nhiều hàm AWS Lambda và nhận thấy tất cả các hàm này đều sử dụng chung các thư viện tùy chỉnh (custom libraries). Người này muốn tập trung hóa (centralize) tất cả các thư viện vào một nơi duy nhất, cập nhật thư viện một cách tiện lợi, và quản lý phiên bản (versioned) cho chúng. Yêu cầu là chọn giải pháp đáp ứng với ít nỗ lực phát triển nhất (LEAST development effort).

Câu hỏi tập trung vào việc tối ưu hóa việc chia sẻ code/thư viện giữa nhiều Lambda functions, giảm thiểu việc duplicate code, hỗ trợ versioning dễ dàng, và giảm công sức triển khai. Đây là tình huống phổ biến trong AWS Lambda để tránh làm phình to kích thước function và dễ maintain. ✅ (Kiến thức cập nhật AWS 2026: Lambda Layers vẫn là giải pháp khuyến nghị chính thức cho shared libraries.)

✅ Đáp án đúng:
Create a Lambda layer that contains all the custom libraries.

🛠️ Lý do chọn đáp án đúng (chi tiết):
Lambda Layers là tính năng chính thức của AWS Lambda cho phép đóng gói các thư viện chung (common libraries, dependencies) vào một layer riêng biệt, sau đó attach layer này vào nhiều Lambda functions.

  • Centralize: Tất cả libraries nằm trong một layer duy nhất.
  • Update tiện lợi: Chỉ cần update layer một lần, tất cả functions gắn layer sẽ tự động sử dụng phiên bản mới (hoặc specify version cụ thể).
  • Versioned: Layers hỗ trợ versioning tự nhiên (ARN với version number), dễ publish và rollback.
  • Least effort: Không cần thay đổi code function, chỉ zip libraries và upload layer qua Console/CLI/CDK. Kích thước layer lên đến 250MB (unzipped), phù hợp shared libs. Không yêu cầu rebuild function hay setup thêm infrastructure.
    Đây là best practice từ AWS, giảm cold start và bundle size. 📘 Nguồn: AWS Lambda Layers Documentation (cập nhật 2026: hỗ trợ ARM64/x86, runtime Python/Node/Java/etc.).

🔍 Giải thích tất cả các phương án (đúng/sai):

  • ❌ [SAI] Create an AWS CodeArtifact repository that contains all the custom libraries.
    CodeArtifact là dịch vụ repository cho packages (Maven, npm, etc.), phù hợp quản lý dependencies ở build time. Tuy nhiên, với Lambda:

    • Không centralize trực tiếp runtime libraries (phải install lúc deploy qua Lambda build process như SAM/CLI).
    • Update yêu cầu rebuild/deploy từng function.
    • Versioning có, nhưng effort cao hơn Layers (cần integrate với build pipeline). Không phải least effort cho shared libs runtime.
  • ❌ [SAI] Create a custom container image for the Lambda functions to save all the custom libraries.
    Lambda hỗ trợ container images (ECR), có thể bundle libs vào image. Nhưng:

    • Không centralize thực sự (mỗi function cần image riêng hoặc shared image nhưng vẫn rebuild khi update libs).
    • Update libs yêu cầu rebuild/push image mới cho tất cả functions → effort lớn.
    • Versioning qua ECR tags, nhưng phức tạp hơn Layers cho pure libs (không cần full container nếu chỉ libs). Least effort? Không! Phù hợp app lớn hơn.
  • ✅ [ĐÚNG] Create a Lambda layer that contains all the custom libraries.
    (Đã giải thích chi tiết ở trên: Hoàn hảo match requirements với least effort.)

  • ❌ [SAI] Create an Amazon Elastic File System (Amazon EFS) file system to store all the custom libraries.
    Lambda hỗ trợ mount EFS (từ 2020, cập nhật 2026: VPC/Access Points). Nhưng:

    • Centralize file storage có, nhưng libs phải load động runtime → performance kém (I/O latency, cold start tăng).
    • Update: Chỉnh file trên EFS, nhưng versioning kém (không native như Layers, cần snapshot thủ công).
    • Effort cao: Setup VPC, EFS, IAM, mount point cho mỗi function. Không khuyến nghị cho libs (AWS recommend Layers thay vì).

💡 Kết luận & Best Practices:
Sử dụng Lambda Layers là lựa chọn tối ưu nhất theo AWS Well-Architected Framework (Operational Excellence pillar). Nếu libs rất lớn/complex, kết hợp với Provisioned Concurrency. Test bằng AWS SAM CLI cho dev nhanh! 🚀

Câu 909
A developer wants to use AWS Elastic Beanstalk to test a new version of an application in a test environment.

Which deployment method offers the FASTEST deployment?
  1. A Immutable
  2. B Rolling
  3. C Rolling with additional batch
  4. D All at once
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào AWS Elastic Beanstalk – một dịch vụ PaaS giúp triển khai và quản lý ứng dụng web một cách dễ dàng. Kịch bản: Một lập trình viên muốn sử dụng Elastic Beanstalk để test phiên bản mới của ứng dụng trong môi trường test. Yêu cầu tìm phương pháp triển khai (deployment method) mang lại tốc độ triển khai NHANH NHẤT (FASTEST deployment).

🛠️ Điểm chính cần lưu ý:

  • Elastic Beanstalk hỗ trợ nhiều chính sách triển khai (deployment policies) để cân bằng giữa tốc độ, độ an toàn và thời gian downtime.
  • Trong môi trường test (không phải production), ưu tiên tốc độ hơn là zero-downtime hoặc an toàn cao.
  • Các chính sách triển khai được cấu hình qua .ebextensions hoặc console/CLI, dựa trên batch size và cách thay thế instances trong Auto Scaling Group (ASG).

📘 Tài liệu tham khảo:

  • AWS Elastic Beanstalk Developer Guide: Deployment Policies (cập nhật đến 2024, không thay đổi cơ bản đến 2026).
  • AWS Well-Architected Framework: DevOps Pillar (Deployment Strategies).

✅ Đáp án đúng: All at once

Lý do lựa chọn:

  • Đây là phương pháp nhanh nhất vì nó triển khai phiên bản mới đồng thời lên TẤT CẢ các instances trong môi trường ngay lập tức, không chờ batch nào hay tạo instances mới. Thời gian triển khai chỉ bằng thời gian update một instance duy nhất (thường vài giây đến phút).
  • Phù hợp hoàn hảo cho môi trường test, nơi chấp nhận rủi ro downtime ngắn (nếu fail, toàn bộ môi trường down tạm thời nhưng dễ rollback).
  • Theo tài liệu AWS, "All at once" có thời gian triển khai ngắn nhất so với các phương pháp phân batch hoặc immutable.

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, với thời gian triển khai ước tính dựa trên số lượng instances (ví dụ: 4 instances) và đặc tính mới nhất của Elastic Beanstalk (hỗ trợ Blue/Green qua Deployment Policies từ 2023+):

  • ❌ Immutable
    Sai vì: Phương pháp này chậm nhất – tạo Auto Scaling Group (ASG) mới với toàn bộ instances mới chạy phiên bản mới, sau đó swap ASG cũ/mới (DNS switch). Thời gian: 5-15 phút+ (tạo instances + health checks + swap). An toàn cao (zero-downtime nếu config đúng), nhưng không nhanh cho test. 🐌

  • ❌ Rolling
    Sai vì: Triển khai theo batch (ví dụ: 25% instances/lần), thay thế dần instances cũ. Thời gian: 2-5 phút x số batch (ví dụ: 4 instances → 4 batch → chậm hơn all at once). Giảm downtime nhưng chậm hơn do chờ từng batch healthy. ⚖️

  • ❌ Rolling with additional batch
    Sai vì: Tương tự Rolling nhưng tạo instances bổ sung trước khi thay thế (extra capacity), đảm bảo zero-downtime. Thời gian: Dài hơn Rolling (3-10 phút+, ví dụ: tạo 1 instance extra/batch + health checks). Lý tưởng cho production, không phải fastest. 🔄

  • ✅ All at once
    Đúng vì: Triển khai đồng thời lên tất cả instances (không batch, không extra). Thời gian: Ngắn nhất (~1-2 phút cho toàn bộ), chỉ downtime nếu fail (dễ rollback via EB console). Hoàn hảo cho test nhanh theo best practice AWS. 🚀

Câu 910
A company is providing read access to objects in an Amazon S3 bucket for different customers. The company uses IAM permissions to restrict access to the S3 bucket. The customers can access only their own files.

Due to a regulation requirement, the company needs to enforce encryption in transit for interactions with Amazon S3.

Which solution will meet these requirements?
  1. A Add a bucket policy to the S3 bucket to deny S3 actions when the aws:SecureTransport condition is equal to false.
  2. B Add a bucket policy to the S3 bucket to deny S3 actions when the s3:x-amz-acl condition is equal to public-read.
  3. C Add an IAM policy to the IAM users to enforce the usage of the AWS SDK.
  4. D Add an IAM policy to the IAM users that allows S3 actions when the s3:x-amz-acl condition is equal to bucket-owner-read.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả một tình huống thực tế trong AWS:
Một công ty đang cung cấp quyền truy cập đọc (read access) vào các objects trong Amazon S3 bucket cho nhiều khách hàng khác nhau. Họ sử dụng IAM permissions để hạn chế truy cập, đảm bảo mỗi khách hàng chỉ có thể truy cập files của riêng mình (không phải toàn bộ bucket).

📈 Yêu cầu chính: Do quy định pháp lý (regulation requirement), công ty phải bắt buộc mã hóa trong quá trình truyền dữ liệu (encryption in transit) cho mọi tương tác với S3. Encryption in transit ở đây nghĩa là enforce sử dụng HTTPS thay vì HTTP không an toàn khi truy cập S3 (qua REST API, SDK, CLI, v.v.).

🛠️ Mục tiêu giải pháp: Cần một cách enforce toàn cục tại bucket level để deny các hành động S3 nếu không dùng HTTPS, mà vẫn giữ nguyên cơ chế IAM hiện tại cho quyền truy cập chi tiết. Giải pháp phải đơn giản, hiệu quả và tuân thủ best practices AWS mới nhất (cập nhật đến 2026, với S3 bucket policies hỗ trợ condition keys nâng cao).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Add a bucket policy to the S3 bucket to deny S3 actions when the aws:SecureTransport condition is equal to false.

Lý do chi tiết:

  • 🛡️ aws:SecureTransport là condition key chuẩn của AWS (global condition key) dùng để kiểm tra xem request có qua kênh bảo mật (HTTPS/TLS) hay không. Giá trị false nghĩa là request dùng HTTP không mã hóa.
  • Bucket policy với Deny effect khi aws:SecureTransport = "false" sẽ chặn toàn bộ actions S3 (như GetObject) nếu không dùng HTTPS, enforce encryption in transit mà không ảnh hưởng đến IAM permissions hiện tại (IAM vẫn kiểm soát quyền đọc files riêng).
  • 📊 Ưu điểm: Áp dụng toàn cục cho bucket, bao gồm tất cả users/roles (kể cả anonymous nếu có), SDK/CLI. Đây là best practice AWS khuyến nghị từ lâu và vẫn valid đến 2026 (S3 TLS 1.2+ enforced mặc định từ 2023).
  • Không cần thay đổi code client-side, chỉ attach policy vào bucket.

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn một cách chi tiết, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá đúng/sai dựa trên yêu cầu enforce encryption in transit.

  • ✅ Add a bucket policy to the S3 bucket to deny S3 actions when the aws:SecureTransport condition is equal to false.
    Giải thích đúng: Như trên, đây là giải pháp chính xác và hiệu quả nhất. Bucket policy deny khi không dùng HTTPS, enforce encryption in transit toàn diện. Hoàn hảo kết hợp với IAM permissions hiện tại.

  • ❌ Add a bucket policy to the S3 bucket to deny S3 actions when the s3:x-amz-acl condition is equal to public-read.
    Giải thích sai: s3:x-amz-acl là condition key kiểm soát ACL (Access Control List), cụ thể deny khi set ACL thành public-read (cho phép public đọc). Không liên quan đến encryption in transit (HTTPS). Chỉ ngăn chặn public exposure, không enforce mã hóa truyền dữ liệu.

  • ❌ Add an IAM policy to the IAM users to enforce the usage of the AWS SDK.
    Giải thích sai: IAM policy gắn vào users chỉ kiểm soát quyền của user đó, không enforce SDK (vì SDK thường mặc định HTTPS, nhưng user có thể dùng HTTP trực tiếp qua curl/Postman). Không toàn cục như bucket policy, dễ bypass (user tạo role mới), và không trực tiếp liên quan condition encryption. Bucket-level mới hiệu quả cho multi-customers.

  • ❌ Add an IAM policy to the IAM users that allows S3 actions when the s3:x-amz-acl condition is equal to bucket-owner-read.
    Giải thích sai: Lại dùng s3:x-amz-acl = bucket-owner-read (ACL cho owner giữ quyền đọc khi copy/upload). Đây là Allow condition, không phải Deny và không liên quan encryption in transit. Chỉ hỗ trợ quyền copy giữa buckets, có thể làm lỏng lẻo security thay vì enforce HTTPS.

📘 Tài liệu tham khảo (AWS cập nhật mới nhất 2026)

Giải pháp này đảm bảo tuân thủ 100% regulation mà không downtime! 🚀 Nếu cần demo policy JSON cụ thể, hãy cho tôi biết nhé!