Ngân hàng đề — AWS Certified Developer Associate

Tìm thấy 1356 câu.

Câu 991
A developer is testing an application that invokes an AWS Lambda function asynchronously. During the testing phase, the Lambda function fails to process after two retries.

How can the developer troubleshoot the failure?
  1. A Configure AWS CloudTrail logging to investigate the invocation failures.
  2. B Configure Dead Letter Queues by sending events to Amazon SQS for investigation.
  3. C Configure Amazon Simple Workflow Service to process any direct unprocessed events.
  4. D Configure AWS Config to process any direct unprocessed events.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào tình huống một lập trình viên đang kiểm thử ứng dụng gọi AWS Lambda function theo chế độ bất đồng bộ (asynchronously). Trong giai đoạn testing, Lambda function thất bại sau 2 lần thử lại (retries). Câu hỏi yêu cầu cách khắc phục sự cố (troubleshoot) thất bại này.

📘 Bối cảnh AWS Lambda (cập nhật đến 2026):

  • Với invocation bất đồng bộ (qua API Gateway, ALB, S3, SNS, v.v.), Lambda tự động retry tối đa 2 lần nếu function fail (timeout, lỗi code, out-of-memory, v.v.).
  • Sau 2 retries thất bại, event sẽ bị discard trừ khi cấu hình Dead Letter Queue (DLQ) để lưu trữ và phân tích sau.
  • Mục tiêu troubleshoot: Thu thập dữ liệu event thất bại để debug (log, payload, error details).

🛠️ Cách troubleshoot chuẩn: Sử dụng DLQ (SQS hoặc SNS) để queue các event thất bại, sau đó inspect qua CloudWatch Logs hoặc SQS console.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Configure Dead Letter Queues by sending events to Amazon SQS for investigation.

Lý do (🧩 Phân tích sâu):

  • AWS Lambda hỗ trợ DLQ chính thức cho asynchronous invocations từ năm 2016 và được tối ưu hóa đến 2026 (hỗ trợ SQS/SNS với enhanced retry policies).
  • Sau 2 retries fail, Lambda tự động gửi event gốc + metadata (error info) đến DLQ (SQS chuẩn cho queueing và investigation).
  • Developer có thể poll SQS để xem event fail, replay nếu cần, hoặc trigger Lambda khác để xử lý. Đây là best practice theo AWS Well-Architected Framework (Reliability pillar).
  • Không dùng DLQ thì event mất vĩnh viễn, khó troubleshoot.

📋 Giải thích tất cả các phương án (đúng/sai)

  • Configure AWS CloudTrail logging to investigate the invocation failures.
    ❌ Sai: CloudTrail ghi log API calls (management events như CreateFunction), không capture runtime errors hay payload của Lambda execution. Dùng CloudWatch Logs cho Lambda logs (execution logs, errors). CloudTrail chỉ troubleshoot invocation issues (permissions, throttling), không phải processing failures sau retries.

  • Configure Dead Letter Queues by sending events to Amazon SQS for investigation.
    ✅ Đúng: Như giải thích trên. DLQ với SQS là tính năng native của Lambda (async only), lưu event fail sau retries để inspect chi tiết (message body chứa input/error). Hỗ trợ visibility timeout, redrive policies (2026 updates).

  • Configure Amazon Simple Workflow Service to process any direct unprocessed events.
    ❌ Sai: Amazon SWF (Simple Workflow Service) là service orchestration cũ (legacy, ít dùng post-2020), dành cho long-running workflows phức tạp với deciders/workers. Không tích hợp trực tiếp với Lambda DLQ hay xử lý unprocessed events. Thay thế bằng Step Functions (serverless workflows).

  • Configure AWS Config to process any direct unprocessed events.
    ❌ Sai: AWS Config là service compliance & configuration monitoring (track resource changes, rules evaluation). Không xử lý events hay failures runtime. Dùng cho audit config drift, không troubleshoot Lambda processing errors.

📚 Tài liệu tham khảo (AWS cập nhật 2026)

Hy vọng phân tích này giúp bạn nắm vững! 🚀 Nếu cần ví dụ code Terraform/CLI config DLQ, hỏi thêm nhé!

Câu 992
A company is migrating its PostgreSQL database into the AWS Cloud. The company wants to use a database that will secure and regularly rotate database credentials. The company wants a solution that does not require additional programming overhead.

Which solution will meet these requirements?
  1. A Use Amazon Aurora PostgreSQL for the database. Store the database credentials in AWS Systems Manager Parameter Store. Turn on rotation.
  2. B Use Amazon Aurora PostgreSQL for the database. Store the database credentials in AWS Secrets Manager. Turn on rotation.
  3. C Use Amazon DynamoDB for the database. Store the database credentials in AWS Systems Manager Parameter Store. Turn on rotation.
  4. D Use Amazon DynamoDB for the database. Store the database credentials in AWS Secrets Manager. Turn on rotation.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc migrate cơ sở dữ liệu PostgreSQL (một loại relational database) lên AWS Cloud với các yêu cầu chính:

  • Bảo mật và tự động xoay vòng (rotate) credentials (tài khoản truy cập database như username/password) một cách định kỳ.
  • Không yêu cầu thêm overhead lập trình (không cần viết code tùy chỉnh, Lambda function hoặc logic phức tạp).

🛠️ Yêu cầu kỹ thuật cốt lõi:

  • Database phải tương thích với PostgreSQL (hỗ trợ SQL relational, không phải NoSQL).
  • Giải pháp phải tích hợp sẵn rotation credentials tự động, an toàn mà không cần can thiệp code.
  • Đây là chủ đề liên quan đến AWS RDS/Aurora và secrets management trong AWS, cập nhật đến phiên bản mới nhất năm 2026 (Aurora PostgreSQL v15+ và Secrets Manager với rotation tích hợp sẵn cho RDS family).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use Amazon Aurora PostgreSQL for the database. Store the database credentials in AWS Secrets Manager. Turn on rotation.

🧩 Lý do chi tiết:

  • Amazon Aurora PostgreSQL là dịch vụ managed PostgreSQL tương thích hoàn hảo (PostgreSQL-compatible), hỗ trợ migrate dễ dàng từ on-premise PostgreSQL.
  • AWS Secrets Manager lưu trữ credentials an toàn (encryption at rest/transit) và tự động rotate master user password cho Aurora PostgreSQL/RDS mà không cần code thêm (tích hợp sẵn, chỉ cần "Turn on rotation" trong console/API). Rotation xảy ra định kỳ (mặc định 30 ngày), test kết nối trước rotate để tránh downtime.
  • Giải pháp này meet 100% requirements: PostgreSQL-compatible, secure, auto-rotate, zero programming overhead.

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng lựa chọn, với ✅ đúng hoặc ❌ sai, giữ nguyên văn bản gốc tiếng Anh:

  • ❌ Use Amazon Aurora PostgreSQL for the database. Store the database credentials in AWS Systems Manager Parameter Store. Turn on rotation.
    Phương án này sai vì AWS Systems Manager Parameter Store (SSM Parameter Store) chỉ lưu trữ credentials (secure strings) nhưng không hỗ trợ rotation tự động cho database credentials như RDS/Aurora. "Turn on rotation" chỉ áp dụng cho SSM-managed secrets, nhưng với DB credentials cần custom Lambda hoặc manual process, vi phạm yêu cầu "no additional programming overhead". Aurora PostgreSQL đúng nhưng SSM không đủ.

  • ✅ Use Amazon Aurora PostgreSQL for the database. Store the database credentials in AWS Secrets Manager. Turn on rotation.
    Đúng hoàn toàn như đã giải thích ở trên: Aurora PostgreSQL + Secrets Manager với rotation tích hợp native, không code, secure và auto-rotate.

  • ❌ Use Amazon DynamoDB for the database. Store the database credentials in AWS Systems Manager Parameter Store. Turn on rotation.
    Phương án này sai kép:

    • DynamoDB là NoSQL key-value/document store, không tương thích PostgreSQL (không hỗ trợ SQL relational, migrate PostgreSQL sẽ thất bại). DynamoDB dùng IAM policies/IAM roles thay vì username/password credentials.
    • SSM Parameter Store không rotate DB credentials tự động như đã nêu, cần code thêm.
  • ❌ Use Amazon DynamoDB for the database. Store the database credentials in AWS Secrets Manager. Turn on rotation.
    Phương án này sai chính vì DynamoDB không sử dụng credentials kiểu username/password (nó dùng AWS IAM authentication), nên Secrets Manager rotation không áp dụng. Migrate PostgreSQL sang DynamoDB yêu cầu redesign schema lớn, không feasible. Secrets Manager đúng cho relational DB nhưng DynamoDB sai hoàn toàn.

📘 Tài liệu tham khảo (cập nhật AWS 2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm ví dụ thực hành, hãy hỏi nhé.

Câu 993
A developer is creating a mobile application that will not require users to log in.

What is the MOST efficient method to grant users access to AWS resources?
  1. A Use an identity provider to securely authenticate with the application.
  2. B Create an AWS Lambda function to create an IAM user when a user accesses the application.
  3. C Create credentials using AWS KMS and apply these credentials to users when using the application.
  4. D Use Amazon Cognito to associate unauthenticated users with an IAM role that has limited access to resources.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào một lập trình viên đang phát triển ứng dụng di động (mobile application) mà người dùng KHÔNG cần đăng nhập (no login required). Mục tiêu là tìm phương pháp hiệu quả NHẤT (MOST efficient) để cấp quyền truy cập vào tài nguyên AWS cho người dùng này.

🛠️ Bối cảnh chính:

  • Ứng dụng di động cần gọi AWS services (như S3, DynamoDB) mà không yêu cầu xác thực người dùng (unauthenticated/guest access).
  • Yêu cầu "hiệu quả nhất" nghĩa là phải an toàn, dễ scale, chi phí thấp, không phức tạp, tránh tạo user riêng lẻ hoặc credential vĩnh viễn.
  • Theo kiến thức AWS cập nhật đến 2026 (Cognito Identity Pools v2.0+ với hỗ trợ enhanced unauthenticated roles), giải pháp lý tưởng là sử dụng temporary credentials qua IAM roles, không dùng IAM users trực tiếp cho end-users.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use Amazon Cognito to associate unauthenticated users with an IAM role that has limited access to resources.

Lý do chi tiết:

  • Amazon Cognito Identity Pools cho phép unauthenticated identities (guest access) – lý tưởng cho app không login.
  • Cognito cấp temporary AWS credentials (qua STS) liên kết với IAM role có quyền hạn chế (least privilege), tự động hết hạn (1-12 giờ), dễ quản lý và scale.
  • Hiệu quả nhất: Không cần tạo user riêng, hỗ trợ hàng triệu users, tích hợp SDK mobile (iOS/Android), chi phí thấp (~$0.00005 per identity), tuân thủ security best practices (Zero Trust model).
  • Cập nhật 2026: Cognito hỗ trợ fine-grained access với tags và Cognito Sync cho device data.

📋 Phân tích tất cả các phương án

Dưới đây là phân tích từng phương án (giữ nguyên văn bản gốc bằng tiếng Anh), với lý do đúng/sai bằng tiếng Việt:

  • ❌ Use an identity provider to securely authenticate with the application.
    Sai vì: Identity Provider (IdP như SAML/OIDC) yêu cầu xác thực (authentication) qua login (username/password hoặc federated), không phù hợp với app "no login". Sử dụng sẽ làm phức tạp hóa và vi phạm yêu cầu "unauthenticated". Cognito IdP chỉ dùng cho authenticated users.

  • ❌ Create an AWS Lambda function to create an IAM user when a user accesses the application.
    Sai vì: Tạo IAM user động qua Lambda không hiệu quả, không an toàn. IAM users dành cho humans/services lâu dài, không scale cho mobile end-users (quota 5000 users/account, thủ công cleanup, rủi ro credential leak). Chi phí cao, vi phạm least privilege (users có quyền vĩnh viễn).

  • ❌ Create credentials using AWS KMS and apply these credentials to users when using the application.
    Sai vì: AWS KMS dùng để encrypt/decrypt data keys, KHÔNG tạo AWS access credentials cho gọi services. Credentials phải qua IAM/STF, KMS chỉ hỗ trợ CMK cho encryption. Phương án này sai cơ bản về chức năng, dẫn đến lỗi runtime và security hole.

  • ✅ Use Amazon Cognito to associate unauthenticated users with an IAM role that has limited access to resources.
    Đúng vì: Như giải thích trên, đây là best practice AWS cho guest access trong mobile apps. Sử dụng Identity Pools với unauthenticated role, cấp temp credentials tự động, tích hợp AWS SDK, đảm bảo efficiency và security.

📘 Tài liệu tham khảo

  • AWS Cognito Developer Guide (2026 update): Identity pools - Unauthenticated identities – Chi tiết guest access và IAM roles.
  • AWS Well-Architected Framework - Security Pillar: Khuyến nghị Cognito cho mobile unauth access (trang 45-50).
  • AWS re:Post & Best Practices: Mobile app guest access – Xác nhận Cognito là efficient nhất.
  • Exam DOP-C02 Guide: Topic "Identity & Access Management" nhấn mạnh Cognito cho non-login scenarios.

🛠️ Lời khuyên DevOps: Trong thực tế, attach policy cụ thể vào unauth role (e.g., S3:GetObject) và monitor qua CloudTrail. Test với Cognito SDK demo!

Câu 994
A company has developed a new serverless application using AWS Lambda functions that will be deployed using the AWS Serverless Application Model (AWS SAM) CLI.

Which step should the developer complete prior to deploying the application?
  1. A Compress the application to a .zip file and upload it into AWS Lambda.
  2. B Test the new AWS Lambda function by first tracing it in AWS X-Ray.
  3. C Bundle the serverless application using a SAM package.
  4. D Create the application environment using the eb create my-env command.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào quy trình triển khai ứng dụng serverless được phát triển bằng AWS Lambda và sử dụng AWS Serverless Application Model (AWS SAM) CLI để deploy. Cụ thể, công ty đã xây dựng ứng dụng mới và developer cần hoàn thành bước nào trước khi deploy ứng dụng.

🛠️ Quy trình chuẩn với AWS SAM CLI (cập nhật đến 2026):

  • AWS SAM CLI hỗ trợ build, package và deploy ứng dụng serverless một cách tự động hóa.
  • Trước khi chạy lệnh sam deploy, developer phải thực hiện sam package để bundle toàn bộ ứng dụng (bao gồm Lambda functions, layers, API Gateway, v.v.) thành artifacts và upload lên Amazon S3.
  • Điều này tạo ra một CloudFormation template đã được transform, sẵn sàng cho deployment mà không cần can thiệp thủ công vào từng resource.

📘 Tài liệu tham khảo:

✅ Đáp án đúng: Bundle the serverless application using a SAM package.

Lý do lựa chọn:

  • Đây là bước bắt buộc trước sam deploy trong quy trình SAM CLI. Lệnh sam package sẽ:
    • Bundle code và dependencies vào file ZIP (nếu cần).
    • Upload artifacts lên S3 bucket (tự động hoặc chỉ định).
    • Tạo template CloudFormation mới với tham chiếu S3 URL.
  • Nếu bỏ qua, sam deploy sẽ thất bại vì thiếu artifacts. Quy trình chuẩn: sam build → sam package → sam deploy.

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng lựa chọn một cách chi tiết, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá ✅ (đúng) hoặc ❌ (sai) kèm lý do bằng tiếng Việt.

  • Compress the application to a .zip file and upload it into AWS Lambda.
    ❌ Sai: Đây là cách triển khai thủ công cho Lambda đơn lẻ qua Console/CLI, không phù hợp với SAM CLI. SAM tự động hóa packaging (qua sam package), không yêu cầu zip thủ công toàn bộ app trước deploy. Làm vậy sẽ bỏ qua lợi ích của SAM như template transform và multi-resource handling.

  • Test the new AWS Lambda function by first tracing it in AWS X-Ray.
    ❌ Sai: Tracing với AWS X-Ray là bước kiểm tra/debug tùy chọn (enable qua SAM template), không phải bước prior bắt buộc trước deploy. Có thể test local bằng sam local invoke mà không cần X-Ray. Deploy vẫn thành công nếu skip tracing.

  • Bundle the serverless application using a SAM package.
    ✅ Đúng: Như đã giải thích ở trên, sam package là bước thiết yếu để chuẩn bị artifacts trên S3. Lệnh đầy đủ: sam package --template-file template.yaml --s3-bucket my-bucket --output-template-file packaged.yaml. Đây là best practice theo AWS SAM workflow mới nhất (2026).

  • Create the application environment using the eb create my-env command.
    ❌ Sai: Lệnh eb create thuộc AWS Elastic Beanstalk CLI (eb CLI), dùng cho ứng dụng containerized/EC2-based, không liên quan đến serverless Lambda/SAM. SAM deploy trực tiếp qua CloudFormation, không cần environment Beanstalk.

Câu 995
A company wants to automate part of its deployment process. A developer needs to automate the process of checking for and deleting unused resources that supported previously deployed stacks but that are no longer used.

The company has a central application that uses the AWS Cloud Development Kit (AWS CDK) to manage all deployment stacks. The stacks are spread out across multiple accounts. The developer’s solution must integrate as seamlessly as possible within the current deployment process.

Which solution will meet these requirements with the LEAST amount of configuration?
  1. A In the central AWS CDK application, write a handler function in the code that uses AWS SDK calls to check for and delete unused resources. Create an AWS CloudFormation template from a JSON file. Use the template to attach the function code to an AWS Lambda function and to invoke the Lambda function when the deployment stack runs.
  2. B In the central AWS CDK application, write a handler function in the code that uses AWS SDK calls to check for and delete unused resources. Create an AWS CDK custom resource. Use the custom resource to attach the function code to an AWS Lambda function and to invoke the Lambda function when the deployment stack runs.
  3. C In the central AWS CDK, write a handler function in the code that uses AWS SDK calls to check for and delete unused resources. Create an API in AWS Amplify. Use the API to attach the function code to an AWS Lambda function and to invoke the Lambda function when the deployment stack runs.
  4. D In the AWS Lambda console, write a handler function in the code that uses AWS SDK calls to check for and delete unused resources. Create an AWS CDK custom resource. Use the custom resource to import the Lambda function into the stack and to invoke the Lambda function when the deployment stack runs.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc tự động hóa quy trình triển khai trong môi trường AWS, cụ thể là kiểm tra và xóa các tài nguyên không sử dụng nữa (unused resources) từ các stack CloudFormation cũ đã được triển khai trước đó.

  • Bối cảnh: Công ty sử dụng AWS Cloud Development Kit (AWS CDK) làm ứng dụng trung tâm để quản lý tất cả các stack triển khai, phân bố qua nhiều tài khoản AWS (multi-account).
  • Yêu cầu chính: Giải pháp phải tích hợp mượt mà nhất (seamlessly) vào quy trình triển khai hiện tại (CDK-based), với ít cấu hình nhất (LEAST amount of configuration).
  • Mục tiêu: Developer viết code handler sử dụng AWS SDK để kiểm tra/xóa tài nguyên, và kích hoạt nó trong quá trình chạy stack deployment.

🔍 Vấn đề cốt lõi: Cần một cách native với CDK để nhúng logic tùy chỉnh (custom logic) vào stack, chạy Lambda tự động mà không cần quản lý riêng biệt hoặc công cụ ngoài.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
In the central AWS CDK application, write a handler function in the code that uses AWS SDK calls to check for and delete unused resources. Create an AWS CDK custom resource. Use the custom resource to attach the function code to an AWS Lambda function and to invoke the Lambda function when the deployment stack runs.

Lý do 🛠️:

  • AWS CDK Custom Resource là tính năng native và mạnh mẽ nhất của CDK (từ phiên bản CDK v1 và được cải tiến ở v2/v3 đến 2026), cho phép định nghĩa inline Lambda function trực tiếp trong code CDK.
  • Lambda sẽ tự động được tạo, attach code handler, và invoke khi stack được deploy/update (qua onCreate, onUpdate, hoặc onDelete).
  • Tích hợp seamless: Toàn bộ nằm trong central CDK app, hỗ trợ multi-account qua CDK constructs, không cần config ngoài (như IAM riêng, template JSON, hay console).
  • Least configuration: Chỉ cần vài dòng code CDK (ví dụ: new AwsCustomResource), tự động handle permissions và lifecycle.
  • Phù hợp best practice DevOps cho automation cleanup trong CI/CD pipeline CDK.

📋 Phân tích tất cả các phương án

  • ❌ Phương án SAI 1:
    In the central AWS CDK application, write a handler function in the code that uses AWS SDK calls to check for and delete unused resources. Create an AWS CloudFormation template from a JSON file. Use the template to attach the function code to an AWS Lambda function and to invoke the Lambda function when the deployment stack runs.
    Giải thích sai: Việc tạo CloudFormation template JSON thủ công để attach Lambda là cách hybrid không native, yêu cầu export/import giữa CDK và CFN. Điều này tạo overhead config cao (quản lý JSON riêng, sync code), không seamless với CDK app, dễ lỗi multi-account và vi phạm yêu cầu "least configuration".

  • ✅ Phương án ĐÚNG (như đã giải thích ở trên):
    In the central AWS CDK application, write a handler function in the code that uses AWS SDK calls to check for and delete unused resources. Create an AWS CDK custom resource. Use the custom resource to attach the function code to an AWS Lambda function and to invoke the Lambda function when the deployment stack runs.
    Giải thích đúng: Native CDK, inline Lambda, auto-invoke trong deployment – least config, seamless integration 📈.

  • ❌ Phương án SAI 3:
    In the central AWS CDK, write a handler function in the code that uses AWS SDK calls to check for and delete unused resources. Create an API in AWS Amplify. Use the API to attach the function code to an AWS Lambda function and to invoke the Lambda function when the deployment stack runs.
    Giải thích sai: AWS Amplify dành cho frontend/fullstack apps (React/Vue), không phải deployment stacks CDK/CloudFormation. Tạo API Amplify để attach/invoke Lambda là không liên quan, config phức tạp (auth, hosting), không tích hợp với CDK multi-account, vi phạm "least configuration" hoàn toàn 🚫.

  • ❌ Phương án SAI 4:
    In the AWS Lambda console, write a handler function in the code that uses AWS SDK calls to check for and delete unused resources. Create an AWS CDK custom resource. Use the custom resource to import the Lambda function into the stack and to invoke the Lambda function when the deployment stack runs.
    Giải thích sai: Viết code trong Lambda console là manual/outside CDK, sau đó import qua Custom Resource vẫn cần quản lý Lambda riêng (versioning, IAM). Không seamless (phụ thuộc console), khó scale multi-account, config nhiều hơn so với inline CDK native ❌.

📘 Tài liệu tham khảo (Cập nhật AWS 2026)

Giải pháp đúng giúp tối ưu DevOps pipeline, giảm chi phí unused resources! 🚀

Câu 996
A company built a new application in the AWS Cloud. The company automated the bootstrapping of new resources with an Auto Scaling group by using AWS CloudFormation templates. The bootstrap scripts contain sensitive data.

The company needs a solution that is integrated with CloudFormation to manage the sensitive data in the bootstrap scripts.

Which solution will meet these requirements in the MOST secure way?
  1. A Put the sensitive data into a CloudFormation parameter. Encrypt the CloudFormation templates by using an AWS Key Management Service (AWS KMS) key.
  2. B Put the sensitive data into an Amazon S3 bucket. Update the CloudFormation templates to download the object from Amazon S3 during bootstrap.
  3. C Put the sensitive data into AWS Systems Manager Parameter Store as a secure string parameter. Update the CloudFormation templates to use dynamic references to specify template values.
  4. D Put the sensitive data into Amazon Elastic File System (Amazon EFS). Enforce EFS encryption after file system creation. Update the CloudFormation templates to retrieve data from Amazon EFS.
Xem giải thích

🧩 Giải thích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào một tình huống thực tế trong AWS: Một công ty đã xây dựng ứng dụng mới trên AWS Cloud, sử dụng Auto Scaling group (ASG) kết hợp với AWS CloudFormation templates để tự động hóa việc bootstrapping (khởi tạo ban đầu) các tài nguyên mới. Các bootstrap scripts (kịch bản khởi tạo) chứa sensitive data (dữ liệu nhạy cảm như mật khẩu, API keys, v.v.).

Yêu cầu chính là tìm giải pháp TÍCH HỢP TRỰC TIẾP với CloudFormation để quản lý dữ liệu nhạy cảm này một cách AN TOÀN NHẤT (MOST secure way).

🛠️ Điểm mấu chốt:

  • Không lưu sensitive data trực tiếp trong template (vì template có thể bị expose qua CloudTrail hoặc stack events).
  • Cần cơ chế runtime resolution (giải quyết giá trị tại thời điểm triển khai) để tránh lưu trữ plaintext.
  • Giải pháp phải tích hợp native với CloudFormation, hỗ trợ Auto Scaling, và tuân thủ best practices bảo mật AWS (như encryption at rest/transit và IAM least privilege).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Put the sensitive data into AWS Systems Manager Parameter Store as a secure string parameter. Update the CloudFormation templates to use dynamic references to specify template values.

Lý do chọn đáp án này 🏆:

  • AWS Systems Manager Parameter Store (nay là SSM Parameter Store) hỗ trợ SecureString parameters được mã hóa tự động bằng KMS key mặc định hoặc custom, lưu trữ secrets an toàn với IAM controls.
  • Dynamic References trong CloudFormation (tính năng từ 2019, cập nhật liên tục đến 2026) cho phép sử dụng cú pháp {{resolve:ssm:parameter-name:X}} để inject giá trị secrets tại runtime vào resources như UserData của EC2/ASG. Giá trị KHÔNG được lưu plaintext trong template, stack events, hoặc CloudFormation console.
  • Tích hợp hoàn hảo với ASG bootstrapping (qua cfn-init hoặc UserData), scale tự động, và most secure vì tránh download từ external storage, giảm attack surface. Đây là AWS-recommended pattern cho secrets in CFN (Well-Architected Framework: Security Pillar).

📋 Phân tích tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá ✅ (đúng) hoặc ❌ (sai), kèm giải thích chi tiết bằng tiếng Việt.

  • Put the sensitive data into a CloudFormation parameter. Encrypt the CloudFormation templates by using an AWS Key Management Service (AWS KMS) key.
    ❌ Sai: CloudFormation parameters (NoEcho=true chỉ ẩn console) vẫn lưu plaintext trong stack events và CloudTrail logs, dễ bị expose. Encrypt template chỉ bảo vệ source code template, KHÔNG bảo vệ giá trị parameter khi resolve vào bootstrap scripts (như UserData). Không an toàn cho sensitive data, vi phạm principle of least exposure.

  • Put the sensitive data into an Amazon S3 bucket. Update the CloudFormation templates to download the object from Amazon S3 during bootstrap.
    ❌ Sai: S3 bucket yêu cầu IAM roles để download, nhưng objects dễ bị misconfigure (public ACL hoặc bucket policy lỏng lẻo), dẫn đến data leak. Không tích hợp native với CFN (chỉ custom script trong bootstrap), tăng complexity và attack surface (network calls). Không hỗ trợ dynamic resolution, kém secure hơn SSM (AWS khuyên dùng SSM/Secrets Manager thay S3 cho secrets từ 2020+).

  • Put the sensitive data into AWS Systems Manager Parameter Store as a secure string parameter. Update the CloudFormation templates to use dynamic references to specify template values.
    ✅ Đúng: Như đã giải thích ở trên. Đây là giải pháp native, serverless, encrypted, tích hợp trực tiếp với CFN dynamic refs ({{resolve:ssm:...}}), chỉ resolve cho resources cần thiết (như EC2 UserData trong ASG). Hỗ trợ versioning, auditing qua CloudTrail, và KMS integration – most secure và scalable theo AWS best practices 2026.

  • Put the sensitive data into Amazon Elastic File System (Amazon EFS). Enforce EFS encryption after file system creation. Update the CloudFormation templates to retrieve data from Amazon EFS.
    ❌ Sai: EFS là shared file system (NFS), KHÔNG dành cho secrets (dễ bị access bởi nhiều instances, khó control granularity). Encryption at rest/transit chỉ bảo vệ storage, nhưng retrieve qua mount point phức tạp, tăng latency, và yêu cầu VPC/security groups. Không tích hợp với CFN dynamic refs, kém secure và overkill so với SSM Parameter Store.

📘 Tài liệu tham khảo

  • AWS Documentation (cập nhật 2026):
  • AWS Well-Architected Framework (Security Pillar): Khuyến nghị Parameter Store/Secrets Manager cho CFN secrets.
  • Exam Prep: AWS DOP-C02 blueprint (DevOps Professional 2024+), topic "Infrastructure as Code".

Hy vọng phân tích này giúp bạn nắm vững! 🚀 Nếu cần ví dụ CloudFormation YAML, hãy hỏi thêm nhé!

Câu 997
A company needs to set up secure database credentials for all its AWS Cloud resources. The company’s resources include Amazon RDS DB instances, Amazon DocumentDB clusters, and Amazon Aurora DB instances. The company’s security policy mandates that database credentials be encrypted at rest and rotated at a regular interval.

Which solution will meet these requirements MOST securely?
  1. A Set up IAM database authentication for token-based access. Generate user tokens to provide centralized access to RDS DB instances, Amazon DocumentDB clusters, and Aurora DB instances.
  2. B Create parameters for the database credentials in AWS Systems Manager Parameter Store. Set the Type parameter to SecureString. Set up automatic rotation on the parameters.
  3. C Store the database access credentials as an encrypted Amazon S3 object in an S3 bucket. Block all public access on the S3 bucket. Use S3 server-side encryption to set up automatic rotation on the encryption key.
  4. D Create an AWS Lambda function by using the SecretsManagerRotationTemplate template in the AWS Secrets Manager console. Create secrets for the database credentials in Secrets Manager. Set up secrets rotation on a schedule.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc thiết lập thông tin xác thực (credentials) an toàn cho cơ sở dữ liệu trên AWS, cụ thể là các tài nguyên: Amazon RDS DB instances, Amazon DocumentDB clusters, và Amazon Aurora DB instances. Yêu cầu chính từ chính sách bảo mật của công ty bao gồm:

  • Mã hóa tại chỗ nghỉ (encrypted at rest): Credentials phải được lưu trữ an toàn, không thể đọc trực tiếp.
  • Xoay vòng định kỳ (rotated at a regular interval): Tự động thay đổi credentials theo lịch trình để giảm rủi ro lộ thông tin. Giải pháp phải an toàn nhất (MOST securely), nghĩa là ưu tiên tính năng native của AWS, tích hợp sâu với các dịch vụ DB, quản lý vòng đời secrets tự động, và tuân thủ best practices bảo mật (theo AWS Well-Architected Framework - Security Pillar, cập nhật 2024-2026).

📘 Tài liệu tham khảo chính:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create an AWS Lambda function by using the SecretsManagerRotationTemplate template in the AWS Secrets Manager console. Create secrets for the database credentials in Secrets Manager. Set up secrets rotation on a schedule.

Lý do 🛠️:

  • AWS Secrets Manager là dịch vụ chuyên dụng cho việc quản lý secrets, mã hóa at-rest tự động bằng AWS KMS (AES-256), và tích hợp rotation native cho RDS, Aurora, DocumentDB qua Lambda templates sẵn có (SecretsManagerRotationTemplate).
  • Hỗ trợ tất cả các DB types trong câu hỏi: Tự động generate, rotate credentials mà không downtime, cập nhật trực tiếp vào DB master user.
  • An toàn nhất: Least privilege (IAM roles scoped), audit logs qua CloudTrail, VPC integration, và chi phí tối ưu cho rotation (free rotations trong 2026 pricing).
  • Theo best practice AWS 2026: Secrets Manager > SSM cho DB secrets rotation vì tích hợp sâu hơn.

🔍 Phân tích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, với giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá dựa trên yêu cầu mã hóa at-rest + rotation định kỳ + hỗ trợ tất cả DB types + MOST secure.

  • ❌ Phương án SAI: Set up IAM database authentication for token-based access. Generate user tokens to provide centralized access to RDS DB instances, Amazon DocumentDB clusters, and Aurora DB instances.
    Giải thích: IAM DB authentication sử dụng token tạm thời (short-lived) thay vì lưu credentials lâu dài, nên không có credentials để mã hóa at-rest hoặc rotate. Chỉ hỗ trợ xác thực không mật khẩu, không đáp ứng "database credentials" và rotation. Không an toàn nhất vì thiếu quản lý vòng đời secrets. (Hỗ trợ RDS/Aurora/DocumentDB, nhưng không khớp yêu cầu).

  • ❌ Phương án SAI: Create parameters for the database credentials in AWS Systems Manager Parameter Store. Set the Type parameter to SecureString. Set up automatic rotation on the parameters.
    Giải thích: SSM Parameter Store hỗ trợ SecureString (mã hóa KMS) và rotation qua Lambda custom, nhưng không native cho RDS/Aurora/DocumentDB như Secrets Manager (cần code Lambda thủ công, dễ lỗi). Rotation kém tự động hơn, chi phí cao hơn cho nhiều secrets, và AWS recommend Secrets Manager cho DB credentials (theo 2026 docs). Không "MOST securely" vì thiếu integration sâu.

  • ❌ Phương án SAI: Store the database access credentials as an encrypted Amazon S3 object in an S3 bucket. Block all public access on the S3 bucket. Use S3 server-side encryption to set up automatic rotation on the encryption key.
    Giải thích: S3 SSE (KMS/SSE-S3) mã hóa object at-rest tốt, nhưng không hỗ trợ rotation credentials (chỉ rotate KMS key, không thay đổi nội dung credentials). Phải truy cập thủ công qua SDK, dễ lộ nếu IAM sai, không tự động cập nhật DB. Không phù hợp cho secrets động, vi phạm best practice (S3 cho static data, không phải secrets).

  • ✅ Phương án ĐÚNG: Create an AWS Lambda function by using the SecretsManagerRotationTemplate template in the AWS Secrets Manager console. Create secrets for the database credentials in Secrets Manager. Set up secrets rotation on a schedule.
    Giải thích chi tiết: Sử dụng template Lambda sẵn có để tự động rotate secrets cho RDS/Aurora/DocumentDB (hỗ trợ tất cả). Mã hóa at-rest mặc định, lịch rotation linh hoạt (e.g., 30 ngày), zero-downtime, và tích hợp IAM/DB engine. Đây là giải pháp secure nhất theo AWS 2026, với versioning secrets và history tracking.

🛡️ Kết luận: Secrets Manager là lựa chọn tối ưu, giúp tuân thủ Zero Trust và giảm bề mặt tấn công! Nếu triển khai, hãy dùng KMS customer-managed keys cho control cao hơn.

Câu 998
A developer has created an AWS Lambda function that makes queries to an Amazon Aurora MySQL DB instance. When the developer performs a test, the DB instance shows an error for too many connections.

Which solution will meet these requirements with the LEAST operational effort?
  1. A Create a read replica for the DB instance. Query the replica DB instance instead of the primary DB instance.
  2. B Migrate the data to an Amazon DynamoDB database.
  3. C Configure the Amazon Aurora MySQL DB instance for Multi-AZ deployment.
  4. D Create a proxy in Amazon RDS Proxy. Query the proxy instead of the DB instance.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi

Câu hỏi gốc (dịch sát nghĩa để hiểu): Một lập trình viên đã tạo một hàm AWS Lambda thực hiện các truy vấn đến một instance Amazon Aurora MySQL. Khi kiểm tra, instance DB báo lỗi "too many connections" (quá nhiều kết nối).
Yêu cầu: Tìm giải pháp đáp ứng với ít nỗ lực vận hành nhất (LEAST operational effort).

✅ Vấn đề cốt lõi: AWS Lambda là serverless, mỗi invocation (đặc biệt cold start) tạo kết nối mới đến DB, dẫn đến số lượng kết nối vượt quá giới hạn của Aurora MySQL (mặc định ~100-1000 tùy instance size). Giải pháp cần tối ưu hóa pooling kết nối mà không thay đổi lớn kiến trúc ứng dụng, ưu tiên managed service để giảm effort.
🛠️ Kiến thức cập nhật 2026: Amazon RDS Proxy (ra mắt 2020, hỗ trợ Aurora MySQL đầy đủ đến 2026) chính là giải pháp lý tưởng cho serverless workloads như Lambda với Aurora/RDS, theo AWS Well-Architected Framework (Serverless Lens).

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do chọn

Đáp án đúng: Create a proxy in Amazon RDS Proxy. Query the proxy instead of the DB instance.

Lý do chọn (chi tiết):
RDS Proxy là dịch vụ managed connection pooler của AWS, chuyên giải quyết vấn đề "too many connections" cho Lambda + RDS/Aurora. Nó reuse kết nối (multiplexing), giảm 60-90% số kết nối thực đến DB, hỗ trợ failover tự động và IAM authentication. Setup chỉ cần vài cú click trên console/CLI, tích hợp trực tiếp với Lambda (thay endpoint DB bằng proxy endpoint). Đây là least operational effort vì không cần code thay đổi lớn, không migrate data, fully managed (không lo scale/patch). Phù hợp Aurora MySQL (hỗ trợ đầy đủ đến 2026).

🛠️ Phân tích tất cả các phương án (đúng/sai)

  • Phương án 1: Create a read replica for the DB instance. Query the replica DB instance instead of the primary DB instance.
    ❌ Sai: Read replica chỉ scale read traffic (offload reads từ primary), nhưng không giải quyết connection pooling. Lambda vẫn tạo nhiều kết nối mới đến replica, dễ gây lỗi tương tự. Effort cao: Phải refactor code phân biệt read/write endpoint, monitor replication lag. Không phải giải pháp gốc cho vấn đề connections ở primary.

  • Phương án 2: Migrate the data to an Amazon DynamoDB database.
    ❌ Sai: DynamoDB là NoSQL serverless, phù hợp nếu redesign app (schema-less), nhưng effort cực lớn: Migrate data, rewrite Lambda queries (SQL → PartiQL/NoSQL), handle eventual consistency. Không giữ nguyên relational model của Aurora MySQL, vi phạm "least effort" và không giải quyết trực tiếp connections.

  • Phương án 3: Configure the Amazon Aurora MySQL DB instance for Multi-AZ deployment.
    ❌ Sai: Multi-AZ chỉ tăng high availability (failover automatic <60s), replicate data standby AZ. Không ảnh hưởng đến connection limits (vẫn giới hạn per instance). Effort trung bình (enable via console), nhưng không fix root cause Lambda connections.

  • Phương án 4 (ĐÚNG): Create a proxy in Amazon RDS Proxy. Query the proxy instead of the DB instance.
    ✅ Đúng: Như giải thích trên, giải pháp chính xác nhất với connection multiplexing, managed hoàn toàn, tích hợp seamless với Lambda VPC/security groups. Effort thấp: Tạo proxy → attach to Aurora → update Lambda env var endpoint. Metrics CloudWatch sẵn có để monitor.

Kết luận 💡: RDS Proxy là best practice AWS cho Lambda-DB integration (2026), giúp scale connections mà không tăng chi phí DB instance. Recommend test với proxy target group pinned nếu cần consistent connections!

Câu 999
A developer is creating a new REST API by using Amazon API Gateway and AWS Lambda. The development team tests the API and validates responses for the known use cases before deploying the API to the production environment.

The developer wants to make the REST API available for testing by using API Gateway locally.

Which AWS Serverless Application Model Command Line Interface (AWS SAM CLI) subcommand will meet these requirements?
  1. A Sam local invoke
  2. B Sam local generate-event
  3. C Sam local start-lambda
  4. D Sam local start-api
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc phát triển và kiểm thử local một REST API được xây dựng bằng Amazon API Gateway kết hợp AWS Lambda, sử dụng AWS Serverless Application Model (SAM) CLI.

  • Bối cảnh: Nhà phát triển đã tạo API, test các use case cơ bản, và giờ muốn triển khai local để test API trước khi đưa lên production. Yêu cầu cụ thể là làm cho REST API có thể truy cập để test local qua API Gateway.
  • Mục tiêu chính: Tìm subcommand của AWS SAM CLI giúp start một local HTTP server mô phỏng API Gateway, cho phép gọi API qua endpoint local (ví dụ: http://localhost:3000) mà không cần deploy lên AWS cloud.
  • Kiến thức liên quan (cập nhật 2026): AWS SAM CLI phiên bản mới nhất (v1.120.0+) hỗ trợ local testing cho serverless apps, đặc biệt với API Gateway REST APIs. Điều này giúp dev tiết kiệm thời gian, chi phí và debug nhanh chóng mà không phụ thuộc cloud resources. 🛠️

✅ Đáp án đúng: sam local start-api

Lý do lựa chọn:

  • Subcommand này khởi động một local API Gateway trên máy dev, bind với Lambda functions trong SAM template (template.yaml). Nó tạo endpoint local (thường port 3000) để test đầy đủ REST API với các method (GET, POST,...), integration và responses giống production.
  • Hoàn hảo cho yêu cầu "make the REST API available for testing by using API Gateway locally" vì hỗ trợ invoke qua HTTP requests thực tế (cURL, Postman), validate responses end-to-end.
  • Ví dụ sử dụng: sam local start-api – Sau khi chạy, truy cập http://127.0.0.1:3000/<path> để test. 📱

📋 Giải thích chi tiết tất cả các phương án

  • ❌ Sam local invoke
    Phương án này sai vì chỉ dùng để invoke trực tiếp một Lambda function cụ thể với event payload JSON, không start API Gateway local hay tạo HTTP endpoint. Nó phù hợp test isolated Lambda logic (không qua API Gateway), không đáp ứng yêu cầu test REST API full-stack. Ví dụ: sam local invoke FunctionName -e event.json.

  • ❌ Sam local generate-event
    Phương án này sai vì chỉ tạo mẫu event JSON cho các dịch vụ AWS (như API Gateway, S3,...), dùng để prepare input cho sam local invoke. Không start bất kỳ server local nào, chỉ generate file event – không test API qua HTTP endpoints.

  • ❌ Sam local start-lambda
    Phương án này sai (thực tế là sam local start-lambda, nhưng ít dùng cho API Gateway). Nó start Lambda container local để invoke qua Lambda Runtime API (port 3001), phù hợp test Lambda containerization riêng lẻ hoặc với custom runtime. Không mô phỏng API Gateway REST APIs hay HTTP endpoints đầy đủ.

  • ✅ Sam local start-api
    Đúng như giải thích ở trên: Start local HTTP server cho API Gateway, hỗ trợ test REST API thực tế với routes, methods, và Lambda proxy integrations. Lý tưởng cho dev workflow local-first.

📘 Tài liệu tham khảo (cập nhật 2026)

Hy vọng phân tích này giúp bạn nắm vững SAM CLI cho DevOps workflow! 🚀 Nếu cần ví dụ code hoặc lab, hỏi thêm nhé!

Câu 1000
A company has a serverless application on AWS that uses a fleet of AWS Lambda functions that have aliases. The company regularly publishes new Lambda function by using an in-house deployment solution. The company wants to improve the release process and to use traffic shifting. A newly published function version should initially make available only to a fixed percentage of production users.

Which solution will meet these requirements?
  1. A Configure routing on the alias of the new function by using a weighted alias.
  2. B Configure a canary deployment type for Lambda.
  3. C Configure routing on the new versions by using environment variables.
  4. D Configure a linear deployment type for Lambda.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm AWS

📘 Nội dung câu hỏi:
Câu hỏi xoay quanh một ứng dụng serverless trên AWS sử dụng nhiều hàm AWS Lambda với aliases (bí danh). Công ty thường xuyên phát hành phiên bản Lambda mới qua giải pháp triển khai nội bộ (in-house deployment). Họ muốn cải thiện quy trình phát hành (release process) bằng cách áp dụng traffic shifting (chuyển hướng lưu lượng), sao cho phiên bản Lambda mới chỉ tiếp cận được một tỷ lệ cố định (fixed percentage) của người dùng sản xuất (production users) ngay từ đầu.

🛠️ Yêu cầu chính:

  • Sử dụng aliases của Lambda để kiểm soát traffic.
  • Traffic shifting phải là fixed percentage (tỷ lệ cố định, không thay đổi dần dần theo thời gian).
  • Áp dụng cho fleet Lambda functions, phù hợp với quy trình publish thường xuyên.

✅ Đáp án đúng:
Configure routing on the alias of the new function by using a weighted alias.

Lý do lựa chọn (bằng kiến thức AWS cập nhật đến 2026):
Lambda hỗ trợ weighted aliases (bí danh có trọng số), cho phép cấu hình tỷ lệ traffic cố định giữa các phiên bản (versions) ngay lập tức. Ví dụ: Alias "prod" có thể route 10% traffic đến version mới ($LATEST hoặc version cụ thể) và 90% đến version cũ. Điều này đáp ứng hoàn hảo yêu cầu "fixed percentage" mà không cần công cụ bên ngoài như CodeDeploy. Quy trình: Publish version mới → Cập nhật weights trên alias → Traffic shifting ngay lập tức. Đây là tính năng native của Lambda, tối ưu cho serverless và in-house deployment.

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng lựa chọn giữ nguyên văn bản gốc bằng tiếng Anh, kèm đánh giá đúng/sai và lý do chi tiết bằng tiếng Việt:

✅ Configure routing on the alias of the new function by using a weighted alias.

  • Đúng vì: Tính năng weighted aliases cho phép set tỷ lệ traffic cố định (ví dụ: 20% version mới, 80% cũ) trên alias ngay khi publish. Không cần gradual shift, phù hợp chính xác với "fixed percentage of production users". Hỗ trợ nhiều hàm Lambda trong fleet.

❌ Configure a canary deployment type for Lambda.

  • Sai vì: Canary deployment (tích hợp Lambda với CodeDeploy) chỉ định tỷ lệ ban đầu (ví dụ 10%), nhưng tự động tăng dần theo thời gian (gradual shift) theo cấu hình deployment. Không phải fixed percentage cố định lâu dài mà là canary testing tạm thời. Không phù hợp với yêu cầu "initially make available only to a fixed percentage" mà không thay đổi.

❌ Configure routing on the new versions by using environment variables.

  • Sai vì: Environment variables chỉ dùng để truyền config runtime cho hàm Lambda, không hỗ trợ routing traffic giữa versions hay aliases. Không có cơ chế traffic shifting; đây là nhầm lẫn cơ bản về chức năng Lambda.

❌ Configure a linear deployment type for Lambda.

  • Sai vì: Linear deployment (qua CodeDeploy) chia traffic thành nhiều "segment" và tăng dần tuyến tính theo thời gian (ví dụ: 10% mỗi phút trong 10 phút). Không phải fixed percentage cố định từ đầu, mà là progressive rollout. Không đáp ứng yêu cầu traffic shifting ngay lập tức và cố định.

📚 Tài liệu tham khảo (AWS Documentation - cập nhật mới nhất 2026)

  • Weighted Aliases chính thức: AWS Lambda Aliases & Weights – Hướng dẫn cấu hình traffic shifting fixed ratio.
  • So sánh với Canary/Linear: Lambda Traffic Shifting with CodeDeploy – Giải thích sự khác biệt giữa weighted aliases (fixed) và deployments (gradual).
  • DevOps Best Practices: AWS Well-Architected Framework - Reliability Pillar (Serverless section, 2026 edition).

🛡️ Lời khuyên DevOps: Weighted aliases là giải pháp native, zero-cost, low-latency cho traffic shifting ở Lambda. Kết hợp với Lambda Provisioned Concurrency để ổn định performance! 🚀