Ngân hàng đề — AWS Certified Developer Associate

Tìm thấy 1356 câu.

Câu 941
A developer wants to add request validation to a production environment Amazon API Gateway API. The developer needs to test the changes before the API is deployed to the production environment. For the test, the developer will send test requests to the API through a testing tool.

Which solution will meet these requirements with the LEAST operational overhead?
  1. A Export the existing API to an OpenAPI file. Create a new API. Import the OpenAPI file. Modify the new API to add request validation. Perform the tests. Modify the existing API to add request validation. Deploy the existing API to production.
  2. B Modify the existing API to add request validation. Deploy the updated API to a new API Gateway stage. Perform the tests. Deploy the updated API to the API Gateway production stage.
  3. C Create a new API. Add the necessary resources and methods, including new request validation. Perform the tests. Modify the existing API to add request validation. Deploy the existing API to production
  4. D Clone the existing API. Modify the new API to add request validation. Perform the tests. Modify the existing API to add request validation. Deploy the existing API to production.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi xoay quanh việc một lập trình viên muốn thêm tính năng request validation (xác thực yêu cầu đầu vào) vào một API Amazon API Gateway đang chạy ở môi trường production. Yêu cầu chính là kiểm tra thay đổi trước khi deploy vào production, bằng cách gửi các test requests qua công cụ testing (như Postman hoặc curl). Giải pháp phải có operational overhead thấp nhất (ít công sức vận hành nhất), nghĩa là tránh các bước phức tạp, tạo mới tài nguyên thừa, hoặc downtime không cần thiết.

📘 Bối cảnh AWS cập nhật đến 2026: API Gateway (phiên bản REST API hoặc HTTP API) hỗ trợ request validation qua models và schemas (OpenAPI 3.0 hoặc JSON Schema). Best practice là sử dụng stages để deploy version khác nhau của API mà không ảnh hưởng production, giúp test an toàn với endpoint riêng (ví dụ: api-dev.execute-api.region.amazonaws.com). Điều này giảm thiểu overhead so với tạo API mới hoặc export/import.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Modify the existing API to add request validation. Deploy the updated API to a new API Gateway stage. Perform the tests. Deploy the updated API to the API Gateway production stage.

🛠️ Lý do chọn đáp án này (least operational overhead):

  • Chỉ sửa trực tiếp trên API hiện có (thêm request validator vào integration request hoặc method request).
  • Deploy vào stage mới (ví dụ: "test-stage") để có endpoint riêng test mà không ảnh hưởng production stage.
  • Test xong, chỉ cần deploy lại vào production stage (promote changes).
  • Overhead thấp nhất: Không tạo API mới, không export/import, không clone. Sử dụng native feature stages của API Gateway (hỗ trợ canary/blue-green deployments từ 2023+). Thời gian: vài phút qua Console/CLI/CDK. Tránh rủi ro inconsistency giữa API cũ/mới.

📋 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn. Tôi giữ nguyên văn bản gốc bằng tiếng Anh, đánh dấu ✅/❌, và giải thích hoàn toàn bằng tiếng Việt.

  • Phương án 1:
    Export the existing API to an OpenAPI file. Create a new API. Import the OpenAPI file. Modify the new API to add request validation. Perform the tests. Modify the existing API to add request validation. Deploy the existing API to production.
    ❌ Sai vì: Overhead cao do phải export OpenAPI file (cần export toàn bộ spec), tạo API mới hoàn toàn, import rồi test trên API mới. Sau đó còn phải sửa lại API gốc và deploy riêng. Quá nhiều bước thủ công, dễ lỗi config (như IAM roles, custom domains), và không tận dụng stages native. Thời gian lâu hơn, không phải best practice.

  • Phương án 2 (ĐÚNG):
    Modify the existing API to add request validation. Deploy the updated API to a new API Gateway stage. Perform the tests. Deploy the updated API to the API Gateway production stage.
    ✅ Đúng vì: Như đã giải thích ở trên. Đây là workflow chuẩn của API Gateway: sửa config → deploy stage test → test → promote to prod. Hỗ trợ traffic shifting (canary 10% traffic test trước). Overhead tối thiểu, chỉ dùng CLI lệnh aws apigateway create-deployment hoặc Console.

  • Phương án 3:
    Create a new API. Add the necessary resources and methods, including new request validation. Perform the tests. Modify the existing API to add request validation. Deploy the existing API to production.
    ❌ Sai vì: Phải tạo API mới từ đầu (recreate resources/methods/integrations), test trên đó, rồi sửa API gốc riêng. Overhead cực cao: mất thời gian setup lại (authorizers, models, VPC links), dễ miss config, và cần quản lý 2 API song song. Không hiệu quả so với stages.

  • Phương án 4:
    Clone the existing API. Modify the new API to add request validation. Perform the tests. Modify the existing API to add request validation. Deploy the existing API to production.
    ❌ Sai vì: API Gateway không hỗ trợ "clone" trực tiếp (tính năng này không có native từ 2024-2026; chỉ có export/import gián tiếp qua OpenAPI, tương đương phương án 1). Dù dùng CDK/Terraform để "clone", vẫn phải sửa 2 API riêng → overhead cao, rủi ro drift config. Stages tốt hơn vì giữ 1 API duy nhất với nhiều versions.

🔗 Tài liệu tham khảo (AWS Docs cập nhật 2026)

Giải pháp này đảm bảo zero-downtime và DevOps best practices! 🚀

Câu 942
An online food company provides an Amazon API Gateway HTTP API to receive orders for partners. The API is integrated with an AWS Lambda function. The Lambda function stores the orders in an Amazon DynamoDB table.

The company expects to onboard additional partners. Some of the partners require additional Lambda functions to receive orders. The company has created an Amazon S3 bucket. The company needs to store all orders and updates in the S3 bucket for future analysis.

How can the developer ensure that all orders and updates are stored to Amazon S3 with the LEAST development effort?
  1. A Create a new Lambda function and a new API Gateway API endpoint. Configure the new Lambda function to write to the S3 bucket. Modify the original Lambda function to post updates to the new API endpoint.
  2. B Use Amazon Kinesis Data Streams to create a new data stream. Modify the Lambda function to publish orders to the data stream. Configure the data stream to write to the S3 bucket.
  3. C Enable DynamoDB Streams on the DynamoDB table. Create a new Lambda function. Associate the stream’s Amazon Resource Name (ARN) with the Lambda function. Configure the Lambda function to write to the S3 bucket as records appear in the table's stream.
  4. D Modify the Lambda function to publish to a new Amazon Simple Notification Service (Amazon SNS) topic as the Lambda function receives orders. Subscribe a new Lambda function to the topic. Configure the new Lambda function to write to the S3 bucket as updates come through the topic.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào một kịch bản thực tế trong hệ thống AWS của công ty thức ăn trực tuyến trực tuyến:

  • Họ sử dụng Amazon API Gateway HTTP API để nhận đơn hàng (orders) từ các đối tác (partners).
  • API này tích hợp trực tiếp với AWS Lambda function, và Lambda này lưu trữ orders vào Amazon DynamoDB table.
  • Công ty sắp onboard thêm partners, một số yêu cầu thêm Lambda functions riêng để xử lý orders (nghĩa là hệ thống sẽ có nhiều Lambda hơn, không chỉ một cái hiện tại).
  • Họ đã tạo sẵn Amazon S3 bucket để lưu tất cả orders và updates (cập nhật) cho mục đích phân tích tương lai (future analysis).

Mục tiêu chính: Đảm bảo tất cả dữ liệu orders và updates được lưu vào S3 với ÍT NHIỀU NHẤT nỗ lực phát triển (LEAST development effort).
🛠️ Yêu cầu then chốt: Giải pháp phải tự động capture mọi thay đổi (bao gồm cả từ Lambda hiện tại và các Lambda mới), không cần sửa code nhiều trong các Lambda gốc, tận dụng cơ chế native của AWS để giảm thiểu code mới và bảo trì. Điều này phù hợp với best practice DevOps: loose coupling, scalability, và event-driven architecture (theo AWS Well-Architected Framework cập nhật 2024-2026).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Enable DynamoDB Streams on the DynamoDB table. Create a new Lambda function. Associate the stream’s Amazon Resource Name (ARN) with the Lambda function. Configure the Lambda function to write to the S3 bucket as records appear in the table's stream.

Lý do chọn đáp án này 🏆:

  • Least development effort: Chỉ cần kích hoạt DynamoDB Streams (một tính năng native, không mất phí thêm ngoài throughput) trên bảng DynamoDB hiện tại. Streams sẽ tự động capture mọi INSERT/UPDATE/DELETE (orders và updates) từ tất cả Lambda functions (cả cũ lẫn mới khi onboard partners), bất kể bao nhiêu Lambda viết vào cùng bảng.
  • Tạo một Lambda function mới duy nhất làm trigger từ Stream ARN (qua event source mapping), code Lambda mới chỉ cần đọc records từ stream và putObject vào S3 – rất đơn giản, chỉ vài dòng code.
  • Scalable & reliable: Streams hỗ trợ exactly-once processing với Lambda (từ 2023), batching lên đến 10.000 records, và replay nếu cần. Không ảnh hưởng đến Lambda gốc (zero changes ở code hiện tại).
  • Phù hợp với multi-partner: Mọi orders từ partners mới (qua Lambda mới) vẫn đổ vào cùng DynamoDB → Stream tự handle.
    📈 Đây là giải pháp event-driven tối ưu, giảm latency và chi phí so với polling.

📋 Phân tích chi tiết tất cả các phương án

Dưới đây là phân tích từng phương án theo thứ tự trong câu hỏi. Tôi giữ nguyên văn bản gốc tiếng Anh của phương án, chỉ đánh dấu ✅/❌ và giải thích hoàn toàn bằng tiếng Việt.

  • Phương án 1:
    Create a new Lambda function and a new API Gateway API endpoint. Configure the new Lambda function to write to the S3 bucket. Modify the original Lambda function to post updates to the new API endpoint.
    ❌ Sai: Yêu cầu sửa code Lambda gốc (modify original Lambda để post updates qua API mới), vi phạm "least development effort". Khi onboard partners mới (thêm Lambda), phải sửa tất cả Lambda để gọi API endpoint mới – không scalable, tăng coupling và maintenance cao. API Gateway endpoint mới còn tốn kém và phức tạp hơn cần thiết.

  • Phương án 2:
    Use Amazon Kinesis Data Streams to create a new data stream. Modify the Lambda function to publish orders to the data stream. Configure the data stream to write to the S3 bucket.
    ❌ Sai: Phải sửa code Lambda gốc (modify để publish vào Kinesis), và khi thêm Lambda partners mới, phải sửa tất cả để publish tương tự – effort lớn, không "least". Kinesis Streams phù hợp real-time analytics nhưng overkill cho simple storage S3, tốn shard provisioning và chi phí cao hơn DynamoDB Streams (không native với DynamoDB).

  • Phương án 3 (Đúng ✅):
    Enable DynamoDB Streams on the DynamoDB table. Create a new Lambda function. Associate the stream’s Amazon Resource Name (ARN) with the Lambda function. Configure the Lambda function to write to the S3 bucket as records appear in the table's stream.
    ✅ Đúng (như giải thích ở phần trên): Zero changes ở Lambda gốc, tự động capture tất cả từ DynamoDB, chỉ code mới đơn giản cho một Lambda. Ít effort nhất, scalable với partners mới.

  • Phương án 4:
    Modify the Lambda function to publish to a new Amazon Simple Notification Service (Amazon SNS) topic as the Lambda function receives orders. Subscribe a new Lambda function to the topic. Configure the new Lambda function to write to the S3 bucket as updates come through the topic.
    ❌ Sai: Phải sửa code tất cả Lambda (cũ + mới khi onboard) để publish vào SNS topic – effort cao, fan-out SNS có thể duplicate nếu nhiều Lambda cùng publish. SNS là pub/sub async nhưng không capture "updates" tự động (chỉ orders khi receive), kém hiệu quả hơn Streams cho change data capture (CDC).

📘 Tài liệu tham khảo (AWS cập nhật mới nhất 2026)

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ code Lambda, hãy hỏi nhé!

Câu 943 Chọn nhiều đáp án
A company’s website runs on an Amazon EC2 instance and uses Auto Scaling to scale the environment during peak times. Website users across the world are experiencing high latency due to static content on the EC2 instance, even during non-peak hours.

Which combination of steps will resolve the latency issue? (Choose two.)
  1. A Double the Auto Scaling group’s maximum number of servers.
  2. B Host the application code on AWS Lambda.
  3. C Scale vertically by resizing the EC2 instances.
  4. D Create an Amazon CloudFront distribution to cache the static content.
  5. E Store the application’s static content in Amazon S3.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi mô tả một tình huống thực tế trong AWS: Website của công ty chạy trên Amazon EC2 instance với Auto Scaling để mở rộng quy mô trong giờ cao điểm. Tuy nhiên, người dùng trên toàn thế giới gặp latency cao (độ trễ lớn) do static content (nội dung tĩnh như hình ảnh, CSS, JS) được phục vụ trực tiếp từ EC2, ngay cả ngoài giờ cao điểm.

🛠️ Vấn đề cốt lõi: EC2 thường nằm ở một hoặc vài Region cụ thể, dẫn đến việc truyền tải static content xa xôi gây độ trễ. Auto Scaling chỉ scale số lượng instance (horizontal scaling) nhưng không giải quyết vấn đề global distribution của static assets. Câu hỏi yêu cầu chọn TWO steps (hai bước kết hợp) để khắc phục latency này một cách hiệu quả, tập trung vào việc tối ưu hóa phân phối nội dung tĩnh.

✅ Đáp án đúng và lý do lựa chọn

Hai đáp án đúng là:

  • Create an Amazon CloudFront distribution to cache the static content.
  • Store the application’s static content in Amazon S3.

Lý do chọn:

  • Kết hợp Amazon S3 lưu trữ static content (rẻ, bền vững, scalable vô hạn) và Amazon CloudFront (CDN - Content Delivery Network) để cache và phân phối nội dung từ edge locations gần người dùng toàn cầu.
  • Điều này giảm tải EC2 (chỉ phục vụ dynamic content), giảm latency đáng kể (thường dưới 100ms), và hoạt động hiệu quả cả trong lẫn ngoài giờ cao điểm. Đây là best practice tiêu chuẩn của AWS cho website có traffic global (theo AWS Well-Architected Framework - Performance Efficiency Pillar, cập nhật 2024-2026).

📋 Phân tích chi tiết tất cả các phương án

  • Double the Auto Scaling group’s maximum number of servers.
    ❌ Sai: Việc tăng gấp đôi số lượng instance tối đa chỉ scale out (thêm server) để xử lý traffic cao hơn, nhưng static content vẫn được phục vụ từ các EC2 ở Region gốc, không giải quyết latency global do khoảng cách địa lý. Điều này tăng chi phí mà không cải thiện độ trễ ngoài giờ cao điểm.

  • Host the application code on AWS Lambda.
    ❌ Sai: Lambda phù hợp cho serverless dynamic workloads (code chạy theo sự kiện), nhưng không tối ưu cho static content (cần storage riêng). Chuyển toàn bộ app sang Lambda không giải quyết vấn đề phân phối global static assets, và có thể phức tạp hóa kiến trúc hiện tại với EC2 + Auto Scaling.

  • Scale vertically by resizing the EC2 instances.
    ❌ Sai: Vertical scaling (tăng CPU/RAM instance) chỉ cải thiện performance cục bộ của từng server, không xử lý latency do network distance từ người dùng toàn cầu đến Region EC2. Static content vẫn gây bottleneck, và phương pháp này không scalable lâu dài (có giới hạn instance size).

  • Create an Amazon CloudFront distribution to cache the static content.
    ✅ Đúng: CloudFront là CDN phân phối nội dung từ edge locations (hàng trăm điểm trên thế giới, cập nhật mới nhất 2026 với Lambda@Edge và Field-Level Encryption). Nó cache static content, giảm latency >90% bằng cách phục vụ gần user, tích hợp dễ với EC2/S3. Phải kết hợp với S3 để offload hoàn toàn.

  • Store the application’s static content in Amazon S3.
    ✅ Đúng: S3 là object storage lý tưởng cho static assets (99.999999999% durability, infinite scalability). Upload static content lên S3 public bucket, enable static website hosting hoặc dùng làm origin cho CloudFront. Giảm tải EC2 hoàn toàn, chi phí thấp (pay-per-use), và hỗ trợ versioning/encryption mới nhất 2026.

📘 Tài liệu tham khảo

🛠️ Khuyến nghị triển khai: Configure S3 bucket → Tạo CloudFront distribution với S3 origin → Update app code trên EC2 để reference CloudFront URLs cho static assets. Test với CloudWatch + X-Ray để verify latency giảm!

Câu 944
A company has an Amazon S3 bucket containing premier content that it intends to make available to only paid subscribers of its website. The S3 bucket currently has default permissions of all objects being private to prevent inadvertent exposure of the premier content to non-paying website visitors.

How can the company limit the ability to download a premier content file in the S3 bucket to paid subscribers only?
  1. A Apply a bucket policy that allows anonymous users to download the content from the S3 bucket.
  2. B Generate a pre-signed object URL for the premier content file when a paid subscriber requests a download.
  3. C Add a bucket policy that requires multi-factor authentication for requests to access the S3 bucket objects.
  4. D Enable server-side encryption on the S3 bucket for data protection against the non-paying website visitors.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi xoay quanh việc bảo vệ nội dung premium trong một bucket Amazon S3, nơi bucket hiện đang đặt private mặc định (tất cả objects đều private để tránh lộ nội dung cho người dùng không trả phí). Công ty muốn chỉ cho phép tải xuống file premium bởi các subscriber đã trả phí trên website.

Vấn đề cốt lõi là cần một cơ chế kiểm soát truy cập tạm thời, an toàn mà không làm thay đổi quyền bucket tổng thể, đồng thời tích hợp với quy trình xác thực người dùng (paid subscribers). Đây là tình huống phổ biến trong DevOps AWS, sử dụng S3 để lưu trữ nội dung nhạy cảm và kiểm soát truy cập động. Kiến thức cập nhật đến 2026: AWS vẫn khuyến nghị pre-signed URLs cho trường hợp chia sẻ tạm thời với người dùng đã xác thực (theo AWS Well-Architected Framework - Security Pillar).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Generate a pre-signed object URL for the premier content file when a paid subscriber requests a download.

🛠️ Lý do chi tiết:

  • Khi subscriber trả phí yêu cầu tải, ứng dụng backend (ví dụ: Lambda hoặc EC2) tạo pre-signed URL bằng AWS SDK (như boto3 cho Python). URL này cấp quyền tạm thời (GET object) mà không cần credentials AWS của người dùng cuối.
  • Bucket vẫn private, chỉ URL được ký (signed) mới cho phép tải trong thời hạn (ví dụ: 1 giờ), đảm bảo chỉ paid subscribers (đã xác thực qua website) mới nhận được.
  • An toàn cao: URL hết hạn tự động, chống chia sẻ vĩnh viễn. Hỗ trợ HTTPS, tích hợp IAM roles. Đây là best practice theo AWS re:Post và docs S3 (cập nhật 2026 không thay đổi cơ bản).

📋 Phân tích tất cả các phương án

Dưới đây là phân tích từng lựa chọn, với nội dung gốc giữ nguyên tiếng Anh. Tôi đánh dấu ✅ đúng hoặc ❌ sai, kèm giải thích rõ ràng bằng tiếng Việt:

  • ❌ Apply a bucket policy that allows anonymous users to download the content from the S3 bucket.
    Sai vì: Bucket policy cho phép anonymous users (không xác thực) tải toàn bộ sẽ vi phạm yêu cầu bảo mật, làm lộ nội dung cho mọi người (bao gồm non-paying visitors). Bucket policy là quyền tĩnh, không phân biệt paid subscribers, dẫn đến rủi ro cao về data exposure.

  • ✅ Generate a pre-signed object URL for the premier content file when a paid subscriber requests a download.
    Đúng vì: Như giải thích trên, đây là cách động, tạm thời chỉ cấp quyền cho subscriber đã xác thực. Bucket private vẫn giữ nguyên, URL được tạo on-demand qua AWS Signature Version 4 (SigV4), hỗ trợ S3 Object Lock nếu cần.

  • ❌ Add a bucket policy that requires multi-factor authentication for requests to access the S3 bucket objects.
    Sai vì: MFA là cho IAM users/console, không áp dụng cho end-users (website visitors). Bucket policy không hỗ trợ MFA trực tiếp cho public requests (chỉ STS/MFA cho assumed roles). Điều này không kiểm soát paid subscribers mà làm phức tạp hóa truy cập không cần thiết.

  • ❌ Enable server-side encryption on the S3 bucket for data protection against the non-paying website visitors.
    Sai vì: SSE (Server-Side Encryption, như SSE-S3 hoặc SSE-KMS) chỉ mã hóa data at-rest, không kiểm soát ai được tải xuống. Non-paying visitors vẫn có thể truy cập nếu có quyền, mã hóa chỉ bảo vệ nếu data bị đánh cắp vật lý/backup, không giải quyết vấn đề access control.

📘 Tài liệu tham khảo

  • AWS S3 User Guide: Sharing objects using presigned URLs (cập nhật 2024-2026).
  • AWS Well-Architected Framework - Security Pillar: S3 Security Best Practices.
  • AWS re:Post: Các case study về pre-signed URLs cho subscription content (tìm "S3 presigned URL paid access").
  • Exam Prep DOP-C02 (DevOps Pro 2024+): Topic S3 Access Management.

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ code (boto3), hãy hỏi nhé!

Câu 945
A developer is creating an AWS Lambda function that searches for items from an Amazon DynamoDB table that contains customer contact information. The DynamoDB table items have the customer’s email_address as the partition key and additional properties such as customer_type, name and job_title.

The Lambda function runs whenever a user types a new character into the customer_type text input. The developer wants the search to return partial matches of all the email_address property of a particular customer_type. The developer does not want to recreate the DynamoDB table.

What should the developer do to meet these requirements?
  1. A Add a global secondary index (GSI) to the DynamoDB table with customer_type as the partition key and email_address as the sort key. Perform a query operation on the GSI by using the begins_with key condition expression with the email_address property.
  2. B Add a global secondary index (GSI) to the DynamoDB table with email_address as the partition key and customer_type as the sort key. Perform a query operation on the GSI by using the begins_with key condition expression with the email_address property.
  3. C Add a local secondary index (LSI) to the DynamoDB table with customer_type as the partition key and email_address as the sort key. Perform a query operation on the LSI by using the begins_with key condition expression with the email_address property.
  4. D Add a local secondary index (LSI) to the DynamoDB table with job_title as the partition key and email_address as the sort key. Perform a query operation on the LSI by using the begins_with key condition expression with the email_address property.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh việc tối ưu hóa truy vấn DynamoDB trong một AWS Lambda function để hỗ trợ tìm kiếm partial matches (khớp một phần, ví dụ: begins_with) trên thuộc tính email_address của các items thuộc một customer_type cụ thể.

📋 Chi tiết yêu cầu:

  • Bảng DynamoDB hiện tại: Partition key (PK) là email_address. Các thuộc tính khác: customer_type, name, job_title.
  • Kịch bản sử dụng: Lambda chạy mỗi khi user nhập ký tự mới vào ô input customer_type. Lúc này, cần truy vấn các email_address khớp một phần (partial matches) chỉ thuộc customer_type đang nhập.
  • Ràng buộc quan trọng: Không được recreate (tái tạo) bảng DynamoDB, nghĩa là phải sử dụng cơ chế index hiện có của DynamoDB để hỗ trợ query hiệu quả.
  • Mục tiêu: Sử dụng Query operation với key condition expression begins_with trên email_address để đạt hiệu suất cao (O(log n) thay vì Scan kém hiệu quả).

🛠️ Thách thức kỹ thuật (dựa trên DynamoDB best practices 2026):

  • DynamoDB chỉ hỗ trợ Query hiệu quả trên primary key hoặc index keys (PK + SK).
  • begins_with chỉ áp dụng trên sort key (SK) trong Query.
  • Không thể Query trực tiếp trên PK email_address vì cần filter theo customer_type trước, rồi partial match email_address.
  • Giải pháp: Tạo index với customer_type làm PK (để filter theo type), email_address làm SK (để partial match).

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Add a global secondary index (GSI) to the DynamoDB table with customer_type as the partition key and email_address as the sort key. Perform a query operation on the GSI by using the begins_with key condition expression with the email_address property.

Lý do chi tiết 🏆:

  • GSI linh hoạt: GSI cho phép thay đổi hoàn toàn PK (customer_type) và SK (email_address), không phụ thuộc vào PK gốc (email_address).
  • Query logic hoàn hảo:
    • PK = customer_type → Filter chính xác theo customer_type đang nhập (ví dụ: "premium").
    • SK = email_address → Sử dụng begins_with(email_address, "userinput") để partial match.
  • Hiệu suất: Query GSI chỉ scan partition cụ thể, RCU/WCU riêng biệt, hỗ trợ up to 10 GSI/table (2026 limit).
  • Không vi phạm ràng buộc: Không cần recreate table, chỉ thêm GSI (online operation).

📝 Giải thích tất cả các phương án (Đúng/Sai)

  • Add a global secondary index (GSI) to the DynamoDB table with customer_type as the partition key and email_address as the sort key. Perform a query operation on the GSI by using the begins_with key condition expression with the email_address property.
    ✅ Đúng (như đã giải thích ở trên). Đây là cách chuẩn theo DynamoDB design patterns cho composite queries.

  • Add a global secondary index (GSI) to the DynamoDB table with email_address as the partition key and customer_type as the sort key. Perform a query operation on the GSI by using the begins_with key condition expression with the email_address property.
    ❌ Sai:

    • PK = email_address → Không filter được theo customer_type đầu tiên (phải Query exact email_address, không partial).
    • SK = customer_type → begins_with áp dụng trên SK, nhưng yêu cầu partial trên email_address (PK), không hỗ trợ. Dẫn đến phải Scan toàn bộ hoặc Filter kém hiệu quả.
  • Add a local secondary index (LSI) to the DynamoDB table with customer_type as the partition key and email_address as the sort key. Perform a query operation on the LSI by using the begins_with key condition expression with the email_address property.
    ❌ Sai:

    • LSI bắt buộc phải dùng cùng PK với base table (email_address), không thể thay đổi thành customer_type. LSI chỉ thay đổi SK.
    • Tạo LSI với PK khác → Lỗi provisioning ngay lập tức (DynamoDB rule từ 2016-2026).
  • Add a local secondary index (LSI) to the DynamoDB table with job_title as the partition key and email_address as the sort key. Perform a query operation on the LSI by using the begins_with key condition expression with the email_address property.
    ❌ Sai:

    • Tương tự trên, LSI không hỗ trợ PK mới (job_title), phải giữ PK gốc.
    • Hơn nữa, job_title không liên quan đến yêu cầu (chỉ dùng customer_type), làm index vô ích và tốn WCU.

🧪 Lời khuyên thực hành: Test bằng AWS Console hoặc CDK/Terraform để provision GSI. Sử dụng aws dynamodb query CLI với --key-condition "customer_type = :type AND begins_with(email_address, :prefix)". Tránh Scan để tiết kiệm chi phí! 🚀

Câu 946
A developer is building an application that uses AWS API Gateway APIs, AWS Lambda functions, and AWS DynamoDB tables. The developer uses the AWS Serverless Application Model (AWS SAM) to build and run serverless applications on AWS. Each time the developer pushes changes for only to the Lambda functions, all the artifacts in the application are rebuilt.

The developer wants to implement AWS SAM Accelerate by running a command to only redeploy the Lambda functions that have changed.

Which command will meet these requirements?
  1. A sam deploy --force-upload
  2. B sam deploy --no-execute-changeset
  3. C sam package
  4. D sam sync --watch
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh việc tối ưu hóa quy trình triển khai serverless sử dụng AWS Serverless Application Model (AWS SAM) trong một ứng dụng bao gồm AWS API Gateway, AWS Lambda và AWS DynamoDB.

  • Vấn đề hiện tại 🚨: Nhà phát triển chỉ thay đổi code Lambda functions, nhưng khi push changes, toàn bộ artifacts của ứng dụng (bao gồm cả API Gateway và DynamoDB) đều bị rebuild và redeploy, dẫn đến thời gian triển khai lâu và không hiệu quả.
  • Yêu cầu 🎯: Triển khai AWS SAM Accelerate – một tính năng nâng cao của AWS SAM CLI (cập nhật mới nhất đến năm 2026) – để chỉ redeploy những Lambda functions đã thay đổi bằng một lệnh duy nhất, giúp phát triển nhanh hơn (live development với hot-reload cho Lambda code).
  • Bối cảnh kỹ thuật 🛠️: AWS SAM Accelerate hỗ trợ tăng tốc phát triển local-to-cloud bằng cách đồng bộ hóa (sync) chỉ những thay đổi cụ thể, tránh rebuild toàn bộ stack CloudFormation. Lệnh cần hỗ trợ chế độ theo dõi (watch) để tự động detect và deploy changes.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: sam sync --watch

  • Lý do chi tiết 💡: Lệnh sam sync --watch là tính năng cốt lõi của AWS SAM Accelerate (ra mắt từ năm 2021 và được cải tiến liên tục đến 2026). Nó:
    • Theo dõi (watch) các thay đổi trong source code Lambda theo thời gian thực.
    • Chỉ sync và redeploy những Lambda functions đã thay đổi (qua lambda-sync mode), mà không chạm đến các tài nguyên khác như API Gateway hay DynamoDB.
    • Tạo changeset tối thiểu trong CloudFormation và deploy nhanh chóng (thường dưới 1 giây cho code changes).
    • Hoàn hảo cho iterative development, giải quyết chính xác vấn đề "chỉ changes cho Lambda" mà câu hỏi đề cập.
  • Cách sử dụng 📝: Chạy sam sync --watch --stack-name <stack-name> --region <region> sau khi build template SAM.

🛠️ Giải thích tất cả các phương án (đúng/sai)

  • ❌ sam deploy --force-upload
    Phương án này sai vì --force-upload chỉ buộc upload tất cả artifacts lên S3 (bỏ qua cache), nhưng vẫn triển khai toàn bộ stack (bao gồm rebuild tất cả resources như API Gateway và DynamoDB). Nó không hỗ trợ SAM Accelerate, không watch changes, và làm chậm hơn thay vì tối ưu cho chỉ Lambda changes.

  • ❌ sam deploy --no-execute-changeset
    Phương án này sai vì --no-execute-changeset chỉ tạo changeset mà không execute (dry-run mode), dùng để preview thay đổi CloudFormation. Nó không deploy gì cả, không watch real-time changes, và không thuộc SAM Accelerate – hoàn toàn không đáp ứng yêu cầu redeploy Lambda.

  • ❌ sam package
    Phương án này sai vì sam package chỉ đóng gói template SAM và artifacts thành CloudFormation package (upload lên S3 bucket). Nó là bước đầu tiên trong pipeline truyền thống (package rồi deploy), không deploy/deploy changes, không watch, và không dùng Accelerate – chỉ làm một phần nhỏ, không giải quyết vấn đề rebuild toàn bộ.

  • ✅ sam sync --watch
    Như đã giải thích ở trên, đây là lựa chọn đúng duy nhất, tận dụng SAM Accelerate để chỉ sync/deploy Lambda changes mà không ảnh hưởng resources khác.

📘 Tài liệu tham khảo (cập nhật mới nhất đến 2026)

Hy vọng phân tích này giúp bạn nắm vững AWS SAM Accelerate! 🚀 Nếu cần demo code, hãy hỏi thêm nhé!

Câu 947
A developer is building an application that gives users the ability to view bank accounts from multiple sources in a single dashboard. The developer has automated the process to retrieve API credentials for these sources. The process invokes an AWS Lambda function that is associated with an AWS CloudFormation custom resource.

The developer wants a solution that will store the API credentials with minimal operational overhead.

Which solution will meet these requirements in the MOST secure way?
  1. A Add an AWS Secrets Manager GenerateSecretString resource to the CloudFormation template. Set the value to reference new credentials for the CloudFormation resource.
  2. B Use the AWS SDK ssm:PutParameter operation in the Lambda function from the existing custom resource to store the credentials as a parameter. Set the parameter value to reference the new credentials. Set the parameter type to SecureString.
  3. C Add an AWS Systems Manager Parameter Store resource to the CloudFormation template. Set the CloudFormation resource value to reference the new credentials. Set the resource NoEcho attribute to true.
  4. D Use the AWS SDK ssm:PutParameter operation in the Lambda function from the existing custom resource to store the credentials as a parameter. Set the parameter value to reference the new credentials. Set the parameter NoEcho attribute to true.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm AWS

📖 Nội dung câu hỏi được giải thích rõ ràng:
Câu hỏi mô tả một developer đang xây dựng ứng dụng cho phép người dùng xem tài khoản ngân hàng từ nhiều nguồn khác nhau trong một dashboard duy nhất. Quá trình tự động hóa việc lấy API credentials từ các nguồn này được thực hiện qua một AWS Lambda function liên kết với AWS CloudFormation custom resource.
Yêu cầu chính là lưu trữ các API credentials này một cách BẬT NHẤT (MOST secure) và với chi phí vận hành THỦY TỐI THIỂU (minimal operational overhead).
🛠️ Bối cảnh kỹ thuật: Lambda function trong custom resource CloudFormation đang xử lý việc retrieve credentials, nên giải pháp cần tích hợp mượt mà vào quy trình này mà không cần thay đổi lớn, ưu tiên bảo mật cao (mã hóa dữ liệu nhạy cảm) và dễ quản lý.

✅ Đáp án ĐÚNG: Use the AWS SDK ssm:PutParameter operation in the Lambda function from the existing custom resource to store the credentials as a parameter. Set the parameter value to reference the new credentials. Set the parameter type to SecureString.

Lý do chọn đáp án này (bằng tiếng Việt):
Phương án này sử dụng AWS Systems Manager (SSM) Parameter Store qua API ssm:PutParameter trực tiếp trong Lambda function hiện tại (không cần thêm tài nguyên CloudFormation mới).

  • Bảo mật cao nhất: Loại SecureString tự động mã hóa dữ liệu tại chỗ (at-rest encryption) bằng AWS KMS (mặc định hoặc custom key), hỗ trợ truy cập kiểm soát qua IAM policies.
  • Minimal operational overhead: Không tốn phí lưu trữ (standard parameters miễn phí), tích hợp liền mạch với Lambda/CloudFormation custom resource, không cần quản lý rotation phức tạp trừ khi cần.
  • Phù hợp quy trình: Credentials được retrieve trong Lambda rồi lưu ngay, tham chiếu dễ dàng sau này qua ARN hoặc tên parameter.
    Đây là giải pháp tối ưu theo best practices AWS DevOps (cập nhật 2026), vì SSM Parameter Store được khuyến nghị cho secrets ngắn hạn/credentials với chi phí thấp hơn Secrets Manager.

🛠️ Giải thích TẤT CẢ các phương án (Đúng/Sai)

  • ❌ Phương án SAI: Add an AWS Secrets Manager GenerateSecretString resource to the CloudFormation template. Set the value to reference new credentials for the CloudFormation resource.
    Phương án này sử dụng tài nguyên AWS::SecretsManager::Secret với GenerateSecretString trong CloudFormation template, nhưng GenerateSecretString chỉ dùng để TẠO random secrets mới, không phù hợp để lưu credentials đã retrieve từ external sources. Việc thêm resource mới vào template tăng operational overhead (cần update stack, quản lý rotation tự động), và không tích hợp trực tiếp với Lambda custom resource hiện tại. Ngoài ra, Secrets Manager tốn phí (~$0.40/secret/tháng + API calls), kém "minimal" hơn SSM.

  • ✅ Phương án ĐÚNG: Use the AWS SDK ssm:PutParameter operation in the Lambda function from the existing custom resource to store the credentials as a parameter. Set the parameter value to reference the new credentials. Set the parameter type to SecureString.
    (Đã giải thích chi tiết ở phần trên). Giải pháp này an toàn nhất vì mã hóa SecureString + kiểm soát IAM, dễ triển khai trong Lambda code hiện tại, và tiết kiệm (miễn phí cho standard tier).

  • ❌ Phương án SAI: Add an AWS Systems Manager Parameter Store resource to the CloudFormation template. Set the CloudFormation resource value to reference the new credentials. Set the resource NoEcho attribute to true.
    Phương án thêm AWS::SSM::Parameter resource vào CloudFormation template, đặt giá trị credentials và NoEcho: true. Tuy nhiên, NoEcho chỉ che giấu giá trị trong CloudFormation console/logs khi stack create/update, KHÔNG mã hóa dữ liệu (mặc định là String, không encrypt). Credentials sẽ lưu plaintext nếu không chỉ định SecureString, vi phạm yêu cầu "MOST secure". Thêm resource mới còn tăng overhead (update template/stack).

  • ❌ Phương án SAI: Use the AWS SDK ssm:PutParameter operation in the Lambda function from the existing custom resource to store the credentials as a parameter. Set the parameter value to reference the new credentials. Set the parameter NoEcho attribute to true.
    Tương tự phương án trước, sử dụng ssm:PutParameter trong Lambda là tốt, nhưng NoEcho KHÔNG phải là attribute hợp lệ cho API PutParameter (NoEcho chỉ dùng trong CloudFormation resource definition). Không đặt Type: SecureString nên parameter lưu plaintext, thiếu mã hóa → không secure. Phương án này gần đúng nhưng sai sót kỹ thuật cơ bản.

📘 Tài liệu tham khảo (AWS cập nhật mới nhất 2026)

Hy vọng phân tích này giúp bạn ôn thi AWS DevOps Engineer Professional hiệu quả! 🚀 Nếu cần thêm ví dụ code Lambda, hãy hỏi nhé!

Câu 948
A developer is trying to get data from an Amazon DynamoDB table called demoman-table. The developer configured the AWS CLI to use a specific IAM user’s credentials and ran the following command:

aws dynamodb get-item --table-name demoman-table --key '{"id": {"N":"1993"}}'

The command returned errors and no rows were returned.

What is the MOST likely cause of these issues?
  1. A The command is incorrect; it should be rewritten to use put-item with a string argument.
  2. B The developer needs to log a ticket with AWS Support to enable access to the demoman-table.
  3. C Amazon DynamoDB cannot be accessed from the AWS CLI and needs to be called via the REST API.
  4. D The IAM user needs an associated policy with read access to demoman-table.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi mô tả tình huống một lập trình viên đang cố gắng lấy dữ liệu từ bảng Amazon DynamoDB có tên demoman-table bằng lệnh AWS CLI sau:
aws dynamodb get-item --table-name demoman-table --key '{"id": {"N":"1993"}}'

Lệnh này sử dụng credentials của một IAM user cụ thể, nhưng kết quả trả về lỗi và không có dữ liệu nào được trả về.
Vấn đề cốt lõi: Lệnh AWS CLI truy vấn một item có khóa chính id với giá trị số 1993 (định dạng "N" cho Number trong DynamoDB). Đây là cú pháp chuẩn cho DynamoDB API qua CLI (theo tài liệu AWS CLI v2 mới nhất năm 2026). Tuy nhiên, lỗi xảy ra chủ yếu do thiếu quyền truy cập, không phải lỗi cú pháp lệnh hay hạn chế dịch vụ. Câu hỏi yêu cầu tìm nguyên nhân MOST likely (nguyên nhân có khả năng cao nhất) gây ra vấn đề này.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: The IAM user needs an associated policy with read access to demoman-table.

Lý do:
🛠️ Trong AWS, mọi truy cập vào DynamoDB đều yêu cầu IAM policy phù hợp gắn với IAM user/role. Lệnh get-item cần quyền dynamodb:GetItem (hoặc policy rộng hơn như dynamodb:Read) trên bảng demoman-table. Nếu thiếu policy này, AWS CLI sẽ báo lỗi AccessDeniedException ngay lập tức, dẫn đến không trả về dữ liệu. Đây là nguyên nhân phổ biến nhất (MOST likely) vì developer đã config credentials đúng, lệnh syntax chuẩn, nhưng thiếu quyền IAM. Theo best practices AWS (2026), luôn kiểm tra IAM permissions đầu tiên khi gặp lỗi truy cập DynamoDB.

📝 Giải thích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Tôi đánh dấu ✅ cho đúng, ❌ cho sai và giải thích rõ ràng:

  • ❌ The command is incorrect; it should be rewritten to use put-item with a string argument.
    Phương án này sai hoàn toàn. Lệnh get-item dùng để lấy dữ liệu (read), không phải put-item (ghi dữ liệu). Khóa chính {"id": {"N":"1993"}} đúng cú pháp JSON cho DynamoDB (N = Number), không cần string (S). Nếu sửa thành put-item sẽ gây lỗi khác vì đây là lệnh GET, không phải PUT. AWS CLI DynamoDB hỗ trợ đầy đủ get-item từ phiên bản đầu.

  • ❌ The developer needs to log a ticket with AWS Support to enable access to the demoman-table.
    Phương án này sai. DynamoDB là dịch vụ public (không cần ticket Support để enable access). Bảng demoman-table là user-created, chỉ cần IAM policy đúng là truy cập được ngay. AWS Support chỉ can thiệp cho vấn đề billing/quota cao cấp, không phải permission cơ bản (theo AWS Well-Architected Framework 2026).

  • ❌ Amazon DynamoDB cannot be accessed from the AWS CLI and needs to be called via the REST API.
    Phương án này sai 100%. AWS CLI hỗ trợ đầy đủ DynamoDB qua các lệnh như get-item, scan, query (dựa trên DynamoDB API). CLI chính là wrapper cho REST API AWS, không cần gọi trực tiếp REST. Tài liệu AWS CLI v2 (2026) liệt kê rõ DynamoDB commands.

  • ✅ The IAM user needs an associated policy with read access to demoman-table.
    Như đã giải thích ở phần đáp án đúng: Đây là nguyên nhân chính xác và MOST likely. Policy mẫu:

    {
      "Version": "2012-10-17",
      "Statement": [{
        "Effect": "Allow",
        "Action": "dynamodb:GetItem",
        "Resource": "arn:aws:dynamodb:region:account:table/demoman-table"
      }]
    }
    

📘 Tài liệu tham khảo

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm ví dụ policy IAM, hãy hỏi nhé!

Câu 949 Chọn nhiều đáp án
An organization is using Amazon CloudFront to ensure that its users experience low-latency access to its web application. The organization has identified a need to encrypt all traffic between users and CloudFront, and all traffic between CloudFront and the web application.

How can these requirements be met? (Choose two.)
  1. A Use AWS KMS to encrypt traffic between CloudFront and the web application.
  2. B Set the Origin Protocol Policy to “HTTPS Only”.
  3. C Set the Origin’s HTTP Port to 443.
  4. D Set the Viewer Protocol Policy to “HTTPS Only” or “Redirect HTTP to HTTPS”.
  5. E Enable the CloudFront option Restrict Viewer Access.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào Amazon CloudFront, một dịch vụ CDN (Content Delivery Network) của AWS giúp giảm độ trễ (low-latency) cho người dùng truy cập ứng dụng web. Tổ chức cần mã hóa toàn bộ lưu lượng (traffic) theo hai chiều:

  • Giữa người dùng (users/viewers) và CloudFront (viewer-to-edge).
  • Giữa CloudFront và ứng dụng web gốc (origin) (edge-to-origin).

Mục tiêu là đảm bảo HTTPS everywhere để mã hóa end-to-end, tránh sử dụng HTTP không an toàn. Đây là câu hỏi chọn TWO đáp án đúng, dựa trên các thiết lập protocol policy trong CloudFront distribution (cập nhật đến AWS re:Invent 2025 và docs 2026).
📘 Tài liệu tham khảo:

✅ Đáp án đúng (Chọn TWO)

Hai đáp án đúng là:

  • Set the Origin Protocol Policy to “HTTPS Only” 🛡️: Thiết lập này buộc CloudFront chỉ sử dụng HTTPS khi kết nối đến origin (web app), đảm bảo mã hóa traffic giữa CloudFront và origin. Không cho phép HTTP fallback.
  • Set the Viewer Protocol Policy to “HTTPS Only” or “Redirect HTTP to HTTPS” 🔒: Thiết lập này đảm bảo traffic từ người dùng đến CloudFront luôn là HTTPS – "HTTPS Only" chặn HTTP hoàn toàn, "Redirect HTTP to HTTPS" tự động chuyển hướng HTTP sang HTTPS.

Lý do chọn: Đây là các policy chuẩn của CloudFront để enforce HTTPS end-to-end, hỗ trợ certificate từ ACM hoặc custom, tuân thủ best practices bảo mật (zero-trust model). Không cần config thêm port hay KMS cho network encryption.

📋 Giải thích tất cả các phương án (Đúng/Sai)

Dưới đây là phân tích từng lựa chọn một cách chi tiết:

  • ❌ SAI: Use AWS KMS to encrypt traffic between CloudFront and the web application.
    AWS KMS dùng để mã hóa dữ liệu tại chỗ (data at rest) hoặc API keys, không hỗ trợ mã hóa network traffic thời gian thực như HTTPS/TLS. Traffic encryption phải dùng TLS/HTTPS protocol, không liên quan KMS.

  • ✅ ĐÚNG: Set the Origin Protocol Policy to “HTTPS Only”.
    Policy này buộc CloudFront kết nối origin qua HTTPS port 443, mã hóa toàn bộ traffic edge-to-origin. Nếu origin hỗ trợ HTTP, policy sẽ reject và fallback không xảy ra, đảm bảo yêu cầu "all traffic encrypted".

  • ❌ SAI: Set the Origin’s HTTP Port to 443.
    Port 443 dành cho HTTPS, không phải HTTP. Set HTTP port thành 443 sẽ gây lỗi kết nối vì origin expect TLS handshake, nhưng CloudFront gửi plain HTTP. Phải dùng HTTPS protocol + port 443 qua Origin Protocol Policy, không phải set HTTP port.

  • ✅ ĐÚNG: Set the Viewer Protocol Policy to “HTTPS Only” or “Redirect HTTP to HTTPS”.
    Viewer Policy kiểm soát protocol từ user đến CloudFront edge: "HTTPS Only" chặn HTTP (reject 403), "Redirect" tự động 301/302 sang HTTPS. Đảm bảo "all traffic between users and CloudFront" được mã hóa, hỗ trợ HSTS preload.

  • ❌ SAI: Enable the CloudFront option Restrict Viewer Access.
    Tùy chọn này dùng cho signed URLs/cookies (token-based access control), không liên quan đến mã hóa traffic. Nó chỉ restrict ai truy cập được nội dung, không enforce HTTPS hay TLS.

🛠️ Lời khuyên thực hành: Khi config CloudFront, kết hợp với ACM certificates cho custom domain, enable HTTP/2+3 và security headers (ví dụ: Strict-Transport-Security). Test bằng curl hoặc CloudFront tools để verify TLS handshake. Nếu origin là ALB/EC2, đảm bảo listener HTTPS enabled!

Câu 950
A developer is planning to migrate on-premises company data to Amazon S3. The data must be encrypted, and the encryption keys must support automatic annual rotation. The company must use AWS Key Management Service (AWS KMS) to encrypt the data.

Which type of keys should the developer use to meet these requirements?
  1. A Amazon S3 managed keys
  2. B Symmetric customer managed keys with key material that is generated by AWS
  3. C Asymmetric customer managed keys with key material that is generated by AWS
  4. D Symmetric customer managed keys with imported key material
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi này thuộc chủ đề mật mã hóa dữ liệu (Encryption) trên Amazon S3 sử dụng AWS Key Management Service (AWS KMS), một phần quan trọng trong kỳ thi AWS Certified DevOps Engineer Professional.

Tình huống cụ thể:

  • Một lập trình viên (developer) đang lập kế hoạch di chuyển dữ liệu từ on-premises (hệ thống nội bộ công ty) sang Amazon S3.
  • Yêu cầu bắt buộc:
    • Dữ liệu phải được mã hóa (encrypted).
    • Khóa mã hóa (encryption keys) phải hỗ trợ xoay vòng tự động hàng năm (automatic annual rotation).
    • Bắt buộc sử dụng AWS KMS để mã hóa dữ liệu.

Mục tiêu: Chọn loại khóa (key type) phù hợp nhất trong AWS KMS để đáp ứng đầy đủ các yêu cầu trên. AWS KMS cung cấp nhiều loại khóa như AWS managed keys, customer managed keys (CMK), symmetric/asymmetric, và imported/generated key material. Tuy nhiên, chỉ một số loại hỗ trợ tự động xoay vòng (automatic rotation) hàng năm mà không cần can thiệp thủ công.

📘 Kiến thức cốt lõi từ AWS (cập nhật đến 2026): Theo tài liệu AWS KMS mới nhất, automatic key rotation chỉ áp dụng cho symmetric customer managed keys (CMKs) do AWS tạo key material. Điều này giúp bảo mật cao mà không cần quản lý thủ công, phù hợp cho dữ liệu S3 với SSE-KMS.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Symmetric customer managed keys with key material that is generated by AWS

Lý do chi tiết 🛠️:

  • Đây là loại Customer Managed Key (CMK) đối xứng (symmetric) mà AWS tự động tạo key material (không phải import từ bên ngoài).
  • Hỗ trợ automatic annual rotation: AWS tự động tạo phiên bản khóa mới hàng năm, giữ nguyên khóa cũ để giải mã dữ liệu legacy. Tính năng này bật mặc định khi tạo CMK symmetric qua AWS Console/CLI/API.
  • Phù hợp với S3: Sử dụng SSE-KMS với CMK này để mã hóa dữ liệu di chuyển, đảm bảo tuân thủ yêu cầu "must use AWS KMS".
  • Lợi ích: Developer kiểm soát đầy đủ quyền truy cập (IAM policies), và rotation không làm gián đoạn dịch vụ S3.

🧩 Giải thích tất cả các phương án (Đúng/Sai)

  • ❌ Amazon S3 managed keys
    Phương án này SAI vì đây là khóa do S3 quản lý (SSE-S3), KHÔNG sử dụng AWS KMS. SSE-S3 chỉ hỗ trợ mã hóa AES-256 với khóa tự xoay hàng năm, nhưng không đáp ứng yêu cầu "must use AWS KMS". Developer không kiểm soát khóa, và không phải CMK thực thụ trong KMS.

  • ✅ Symmetric customer managed keys with key material that is generated by AWS
    Phương án này ĐÚNG như đã giải thích ở trên. Symmetric CMK do AWS generate key material là lựa chọn duy nhất hỗ trợ automatic rotation hàng năm, mã hóa S3 qua SSE-KMS, và tuân thủ đầy đủ yêu cầu.

  • ❌ Asymmetric customer managed keys with key material that is generated by AWS
    Phương án này SAI vì khóa bất đối xứng (asymmetric CMK) trong AWS KMS KHÔNG hỗ trợ automatic rotation. Asymmetric chỉ dùng cho ký/mã hóa (sign/verify), không phù hợp mã hóa dữ liệu khối như S3 (chỉ symmetric mới dùng cho SSE-KMS). Rotation phải thủ công nếu cần.

  • ❌ Symmetric customer managed keys with imported key material
    Phương án này SAI vì symmetric CMK với key material import từ bên ngoài KHÔNG hỗ trợ automatic rotation. AWS không xoay vòng khóa import để tránh mất kiểm soát key gốc. Developer phải quản lý thủ công, vi phạm yêu cầu "automatic annual rotation".

📘 Tài liệu tham khảo chính thức từ AWS (cập nhật 2026)

  • AWS KMS Key Rotation ✅: Chi tiết automatic rotation chỉ cho symmetric AWS-generated CMKs.
  • S3 Server-Side Encryption with KMS 🛠️: Hướng dẫn SSE-KMS với CMKs.
  • KMS Key Types 🧩: Phân biệt symmetric/asymmetric và imported keys.
  • Whitepaper AWS Well-Architected Framework - Security Pillar (2025 update): Khuyến nghị CMKs cho DevOps migration với rotation tự động.

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ code CLI tạo CMK, hãy hỏi nhé!