Ngân hàng đề — AWS Certified DevOps Engineer Professional
Tìm thấy 681 câu.
A DevOps engineer is creating a pipeline in AWS CodePipeline for automation of a testing process. The engineer wants to be notified when the execution state fails and used the following custom event pattern in Amazon EventBridge:
Which type of events will match this event pattern?
-
A
Failed deploy and build actions across all the pipelines.
-
B
All abandoned or cancelled approval actions across all pipelines.
-
C
Failed stage execution events for the executed stage.
-
D
All rejected or failed approval actions across all the pipelines.
Xem giải thích
Đáp án
*D — Tất cả các hành động phê duyệt bị từ chối hoặc thất bại, trên mọi pipeline
Vì sao đúng
Đọc từng dòng của event pattern trong đề:
{
"source": ["aws.codepipeline"],
"detail-type": ["CodePipeline Action Execution State Change"],
"detail": {
"state": ["FAILED"],
"type": { "category": ["Approval"] }
}
}
| Dòng | Nghĩa là |
|---|---|
detail-type: Action Execution State Change |
Bắt sự kiện ở mức hành động (action), không phải mức stage hay pipeline |
category: Approval |
Chỉ hành động thuộc loại phê duyệt |
state: FAILED |
Chỉ trạng thái thất bại |
Không có trường resources |
Áp cho mọi pipeline trong tài khoản |
Điểm cần biết về CodePipeline: khi ai đó từ chối (reject) một yêu cầu phê duyệt, hành động đó được ghi nhận với trạng thái FAILED — không có trạng thái REJECTED riêng. Vì vậy mẫu này bắt được cả từ chối lẫn thất bại, đúng như phương án D mô tả.
Vì sao các phương án khác sai
- *C. Sự kiện thất bại ở mức stage — sai
detail-type: mẫu này dùng Action Execution State Change, không phải Stage Execution State Change. Đây là phương án nhiễu chính. - A. Hành động deploy và build thất bại — bị loại bởi bộ lọc
category: Approval. - *B. Các phê duyệt bị huỷ hoặc bỏ dở — những trạng thái đó không phải
FAILED; chúng được ghi nhận làCANCELEDhoặcABANDONED.
The buildspec.yml file contains the following:
The DevOps engineer has noticed that anybody with an AWS account is able to download the artifacts.
What steps should the DevOps engineer take to stop this?
- A Modify the post_build command to use --acl public-read and configure a bucket policy that grants read access to the relevant AWS accounts only.
- B Configure a default ACL for the S3 bucket that defines the set of authenticated users as the relevant AWS accounts only and grants read-only access.
- C Create an S3 bucket policy that grants read access to the relevant AWS accounts and denies read access to the principal “*”.
- D Modify the post_build command to remove --acl authenticated-read and configure a bucket policy that allows read access to the relevant AWS accounts only.
Xem giải thích
Đáp án
D — Bỏ --acl authenticated-read khỏi lệnh post_build và dùng bucket policy
Vì sao đúng
authenticated-read nghe như "chỉ người đã xác thực" nhưng trong S3 nó nghĩa là bất kỳ ai có tài khoản AWS — tức là gần như công khai. Cách đúng là bỏ ACL đi và dùng bucket policy liệt kê đích danh những tài khoản được phép đọc. Bucket policy còn có ưu điểm là khai ở một chỗ, đọc được toàn cảnh, và AWS cũng khuyến nghị dừng dùng ACL.
Vì sao các phương án khác sai
- A. Đổi sang
public-read— mở rộng ra cho cả Internet, tệ hơn hẳn. - B. Đặt ACL mặc định cho "authenticated users" — vẫn là nhóm mọi tài khoản AWS, đúng vấn đề ban đầu.
- C. Tạo bucket policy nhưng giữ nguyên ACL — ACL quá rộng vẫn còn đó, nên lỗ hổng chưa đóng.
Which type of events will match this event pattern?
- A Failed deploy and build actions across all the pipelines
- B All rejected or failed approval actions across all the pipelines
- C All the events across all pipelines
- D Approval actions across all the pipelines
Xem giải thích
Đáp án
B — Mọi hành động phê duyệt bị từ chối hoặc thất bại, trên tất cả pipeline
Vì sao đúng
Sự kiện của CodePipeline trong EventBridge có ba mức: Pipeline Execution State Change, Stage Execution State Change, và Action Execution State Change. Ở mức action, phần detail mang cả loại hành động (type.category nhận giá trị Approval, Build, Deploy...) và trạng thái (FAILED, SUCCEEDED, CANCELED). Một mẫu chỉ lọc theo category là Approval cùng trạng thái hỏng, mà không khai resources, sẽ khớp đúng như phương án B mô tả: chỉ hành động phê duyệt, chỉ khi hỏng, và trên mọi pipeline.
Vì sao các phương án khác sai
- A. Hành động deploy và build — sẽ đúng nếu mẫu khai hai category đó, không phải
Approval. - C. Mọi sự kiện của mọi pipeline — chỉ đúng khi mẫu không lọc gì ngoài nguồn
aws.codepipeline. - D. Mọi hành động phê duyệt — thiếu vế trạng thái, sẽ khớp cả những lần phê duyệt thành công.
Ghi chú về chất lượng câu hỏi
Bản đề trong ngân hàng này thiếu mất khối JSON mẫu sự kiện mà câu hỏi nhắc tới, nên không đối chiếu trực tiếp được. Phần giải thích trên dựa vào cấu trúc sự kiện của CodePipeline; hãy xem nó như bài học về cách đọc một event pattern hơn là lời giải cho đúng mẫu bị thiếu.
A development team is building a new project in an account that is in an organization in AWS Organizations. The development team wants to use a Python library that has already been stored in the CodeArtifact repository in the organization. The development team uses AWS CodePipeline and AWS CodeBuild to build the new application. The CodeBuild job that the development team uses to build the application is configured to run in a VPC. Because of compliance requirements, the VPC has no internet connectivity.
The development team creates the VPC endpoints for CodeArtifact and updates the CodeBuild buildspec.yaml file. However, the development team cannot download the Python library from the repository.
Which combination of steps should a DevOps engineer take so that the development team can use CodeArtifact? (Choose two.)
- A Create an Amazon S3 gateway endpoint. Update the route tables for the subnets that are running the CodeBuild job.
- B Update the repository policy’s Principal statement to include the ARN of the role that the CodeBuild project uses.
- C Share the CodeArtifact repository with the organization by using AWS Resource Access Manager (AWS RAM).
- D Update the role that the CodeBuild project uses so that the role has sufficient permissions to use the CodeArtifact repository.
- E Specify the account that hosts the repository as the delegated administrator for CodeArtifact in the organization.
Xem giải thích
Đáp án
A và D — tạo S3 gateway endpoint, và cấp đủ quyền cho vai của CodeBuild
Vì sao đúng
Kéo gói từ CodeArtifact cần hai thứ đi cùng nhau, và thiếu một trong hai là hỏng:
- D. Quyền cho vai CodeBuild — cần
codeartifact:GetAuthorizationToken,codeartifact:ReadFromRepository, cùngsts:GetServiceBearerToken. Đây là phần cho phép build lấy được gói. - A. S3 gateway endpoint — CodeArtifact lưu nội dung gói thật trên S3. Khi CodeBuild chạy trong subnet riêng của VPC, không có endpoint này thì nó xác thực xong nhưng vẫn không tải nổi tệp gói. Đây đúng là chỗ hay bị bỏ sót.
Vì sao các phương án khác sai
- B. Thêm ARN vào Principal của repository policy — có thể cần khi khác tài khoản, nhưng không thay được quyền phía vai và không giải quyết phần đường mạng.
- C. Chia sẻ qua AWS RAM — RAM không phải cơ chế chia sẻ của CodeArtifact.
- E. Chỉ định tài khoản quản trị được uỷ quyền — khái niệm của các dịch vụ cấp tổ chức, CodeArtifact không dùng.
What changes should be recommended to comply with AWS security best practices? (Choose three.)
- A Add a post-build command to remove the temporary files from the container before termination to ensure they cannot be seen by other CodeBuild users.
- B Update the CodeBuild project role with the necessary permissions and then remove the AWS credentials from the environment variable.
- C Store the DB_PASSWORD as a SecureString value in AWS Systems Manager Parameter Store and then remove the DB_PASSWORD from the environment variables.
- D Move the environment variables to the ‘db-deploy-bucket’ Amazon S3 bucket, add a prebuild stage to download, then export the variables.
- E Use AWS Systems Manager run command versus scp and ssh commands directly to the instance.
- F Scramble the environment variables using XOR followed by Base64, add a section to install, and then run XOR and Base64 to the build phase.
Xem giải thích
Đáp án
B, C và E
Vì sao đúng
Cả ba đều gỡ bí mật nằm thẳng trong tệp build hoặc thay cách truy cập máy chủ bằng cơ chế an toàn hơn:
- B. Cấp quyền cho vai của CodeBuild rồi bỏ khoá truy cập đi — thông tin đăng nhập tĩnh trong buildspec là lỗi nặng nhất; vai IAM cho khoá tạm thời, tự xoay vòng, không bao giờ nằm trong mã.
- C. Cất
DB_PASSWORDdưới dạng SecureString trong Parameter Store — mật khẩu được mã hoá bằng KMS và chỉ giải mã lúc chạy, không lộ trong nhật ký build. - E. Dùng Systems Manager Run Command thay cho
scpvàsshthẳng — bỏ hẳn khoá SSH và cổng 22, mọi lệnh chạy qua IAM và được ghi lại trong CloudTrail.
Vì sao các phương án khác sai
- A. Xoá tệp tạm trước khi container kết thúc — container build vốn đã bị huỷ sau mỗi lần chạy; bí mật đã lộ trong nhật ký từ trước đó rồi.
- D. Chuyển biến môi trường sang một bucket S3 — chỉ dời chỗ cất bí mật, vẫn là văn bản thuần và giờ lại thêm một bucket phải bảo vệ.
- F. Xáo bằng XOR rồi Base64 — che mắt chứ không phải mã hoá; ai đọc được cũng giải ra trong vài giây.
A working appspec.yml file exists in the code repository and contains the following text:
A DevOps engineer needs to ensure that a script downloads and installs a license file onto the instances before the replacement instances start to handle request traffic. The DevOps engineer adds a hooks section to the appspec.yml file.
Which hook should the DevOps engineer use to run the script that downloads and installs the license file?
- A AfterBlockTraffic
- B BeforeBlockTraffic
- C BeforeInstall
- D DownloadBundle
Xem giải thích
Đáp án
C — BeforeInstall
Vì sao đúng
Trong triển khai xanh–lam của CodeDeploy, các máy của nhóm thay thế được tạo mới từ ảnh nền, nên phần mềm phụ thuộc chưa có sẵn. Vòng đời triển khai chạy theo thứ tự ApplicationStop → DownloadBundle → BeforeInstall → Install → AfterInstall → ... BeforeInstall là hook đầu tiên bạn viết được sau khi bundle đã tải về nhưng trước khi tệp ứng dụng được chép vào chỗ — đúng chỗ để cài gói phụ thuộc.
Vì sao các phương án khác sai
- A. AfterBlockTraffic và B. BeforeBlockTraffic — chạy quanh lúc gỡ máy khỏi bộ cân bằng tải, tức là thuộc nhóm máy cũ, quá muộn cho việc cài đặt.
- D. DownloadBundle — là bước do CodeDeploy tự làm, không phải hook bạn gắn script vào.
The company applies the following policy to the API Gateway interface VPC endpoint:
The company also updates the API Gateway resource policies to deny invocations that do not come through the interface VPC endpoint. After the updates, the following error message appears during attempts to use the interface VPC endpoint URL to invoke an API: "User: anonymous is not authorized."
Which combination of steps will solve this problem? (Choose two.)
- A Enable IAM authentication on all API methods by setting AWS JAM as the authorization method.
- B Create a token-based AWS Lambda authorizer that passes the caller's identity in a bearer token.
- C Create a request parameter-based AWS Lambda authorizer that passes the caller's identity in a combination of headers, query string parameters, stage variables, and $cortext variables.
- D Use Amazon Cognito user pools as the authorizer to control access to the API.
- E Verify the identity of the requester by using Signature Version 4 to sign client requests by using AWS credentials.
Xem giải thích
Đáp án
A và E — bật xác thực IAM cho các phương thức của API, và ký yêu cầu bằng Signature Version 4
Vì sao đúng
Đây là hai nửa của cùng một cơ chế. A đặt kiểu uỷ quyền là AWS_IAM ở phía API Gateway, nhờ đó quyền gọi API được kiểm soát bằng chính sách IAM — rất hợp khi bên gọi là các tài khoản khác trong cùng tổ chức. E là việc phía máy khách phải làm: ký yêu cầu bằng SigV4 để API Gateway xác minh được danh tính. Không có chữ ký thì bật AWS_IAM chỉ khiến mọi lời gọi bị từ chối.
Vì sao các phương án khác sai
- B và C. Lambda authorizer — dùng khi danh tính đến từ hệ thống bên ngoài qua token hoặc tham số; ở đây bên gọi đã có danh tính IAM sẵn nên tự viết authorizer là thừa.
- D. Cognito user pool — dành cho người dùng cuối của ứng dụng, không phải cho các tài khoản AWS trong tổ chức.
The team uses a developer IAM role to access the environment. The role is configured with the AdministratorAccess managed IAM policy. The company has created a new CloudFormationDeployment IAM role that has the following policy attached:
The company wants to ensure that only CloudFormation can use the new role. The development team cannot make any manual changes to the deployed resources.
Which combination of steps will meet these requirements? (Choose three.)
- A Remove the AdministratorAccess policy. Assign the ReadOnlyAccess managed IAM policy to the developer role. Instruct the developers to use the CloudFormationDeployment role as a CloudFormation service role when the developers deploy new stacks.
- B Update the trust policy of the CloudFormationDeployment role to allow the developer IAM role to assume the CloudFormationDeployment role.
- C Configure the developer IAM role to be able to get and pass the CloudFormationDeployment role if iam:PassedToService equals . Configure the CloudFormationDeployment role to allow all cloudformation actions for all resources.
- D Update the trust policy of the CloudFormationDeployment role to allow the cloudformation.amazonaws.com AWS principal to perform the iam:AssumeRole action.
- E Remove the AdministratorAccess policy. Assign the ReadOnlyAccess managed IAM policy to the developer role. Instruct the developers to assume the CloudFormationDeployment role when the developers deploy new stacks.
- F Add an IAM policy to the CloudFormationDeployment role to allow cloudformation:* on all resources. Add a policy that allows the iam:PassRole action for the ARN of the CloudFormationDeployment role if iam:PassedToService equals cloudformation.amazonaws.com.
Xem giải thích
Đáp án
A, D và F
Vì sao đúng
Yêu cầu là lập trình viên chỉ được thay đổi hạ tầng thông qua CloudFormation. Ba việc dưới đây ghép lại thành đúng mô hình đó:
- A. Gỡ
AdministratorAccess, gánReadOnlyAccesscho vai của lập trình viên — cắt đường sửa tài nguyên trực tiếp; họ vẫn xem được mọi thứ. - D. Cho
cloudformation.amazonaws.comđóng vaiCloudFormationDeployment— để chính dịch vụ CloudFormation dùng vai đó, chứ không phải con người dùng. - F. Cấp cho vai triển khai quyền
cloudformation:*— vai đó mới là thứ thực sự tạo và sửa tài nguyên.
Kết quả: mọi thay đổi đều phải đi qua một stack, nên có lịch sử và có thể hoàn tác.
Vì sao các phương án khác sai
- B. Cho vai lập trình viên đóng vai triển khai — mở lại đúng cửa vừa đóng: họ sẽ thao tác trực tiếp bằng quyền của vai đó.
- C. Cho phép
iam:PassRolevai triển khai — cần khi người dùng tự truyền vai, nhưng ở mô hình này chính dịch vụ mới là bên đảm nhiệm vai. - E — trùng ý với A nhưng gán sai phạm vi.
The following policy is attached to the S3 bucket:
What should the DevOps engineer do to resolve this access issue?
- A Modify the S3 bucket policy. Turn off the S3 Block Public Access setting on the S3 bucket. In the S3 policy, add the aws:SourceAccount condition. Add the AWS account IDs of all developers who are experiencing the issue.
- B Verify that no IAM permissions boundaries are denying developers access to the S3 bucket. Make the necessary changes to IAM permissions boundaries. Use an AWS Config recorder in the individual developer accounts that are experiencing the issue to revert any changes that are blocking access. Commit the fix back into the CodeCommit repository. Invoke deployment through CloudFormation to apply the changes.
- C Configure an SCP that stops anyone from modifying IAM resources in developer OUs. In the S3 policy, add the aws:SourceAccount condition. Add the AWS account IDs of all developers who are experiencing the issue. Commit the fix back into the CodeCommit repository. Invoke deployment through CloudFormation to apply the changes.
- D Ensure that no SCP is blocking access for developers to the S3 bucket. Ensure that no IAM policy permissions boundaries are denying access to developer IAM users. Make the necessary changes to the SCP and IAM policy permissions boundaries in the CodeCommit repository. Invoke deployment through CloudFormation to apply the changes.
Xem giải thích
Đáp án
D — Kiểm tra không có SCP nào chặn lập trình viên truy cập bucket, và không có ranh giới quyền nào chặn
Vì sao đúng
Khi truy cập bị từ chối trong môi trường nhiều tài khoản, thứ tự soát lỗi phải đi từ lớp ngoài cùng vào trong, vì mọi lớp đều có quyền phủ quyết:
- SCP ở AWS Organizations đặt trần quyền cho cả OU — dù chính sách IAM có cho phép, SCP từ chối là hết.
- Ranh giới quyền (permissions boundary) giới hạn quyền tối đa của một vai.
- Sau đó mới tới chính sách IAM và bucket policy.
Phương án D đúng vì nó kiểm cả hai lớp phủ quyết đó.
Vì sao các phương án khác sai
- A. Tắt Block Public Access — mở bucket ra công khai để chữa một vấn đề phân quyền nội bộ; vừa không đúng nguyên nhân vừa nguy hiểm.
- B. Chỉ kiểm ranh giới quyền — bỏ sót SCP, là lớp nằm trên và hay là thủ phạm thật.
- C. Đặt SCP chặn sửa IAM — siết thêm quyền trong khi vấn đề là đang bị từ chối.
The appspec.yml file has the following contents in the files section:
What will the result be for the deployment of the config.txt file?
- A The config.txt file will be deployed to only /var/www/html/config/config.txt.
- B The config.txt file will be deployed to /usr/local/src/config.txt and to /var/www/html/config/config.txt.
- C The config.txt file will be deployed to only /usr/local/src/config.txt.
- D The config.txt file will be deployed to /usr/local/src/config.txt and to /var/www/html/application/web/config.txt.
Xem giải thích
Đáp án
B — Tệp config.txt được triển khai tới cả hai đích
Vì sao đúng
Mục files trong appspec.yml là một danh sách các cặp source–destination, và CodeDeploy xử lý từng mục một cách độc lập. Nếu cùng một tệp nguồn xuất hiện ở hai mục với hai đích khác nhau, nó được chép sang cả hai — không có chuyện mục sau ghi đè mục trước, cũng không có chuyện chỉ mục đầu tiên có hiệu lực.
Một điểm hay nhầm nữa: khi source là một thư mục, CodeDeploy chép nội dung bên trong thư mục đó sang destination, chứ không chép cả thư mục thành một cấp con.
Vì sao các phương án khác sai
- A và C — đều giả định chỉ một mục có hiệu lực; không đúng với cách
fileshoạt động. - D — đúng ý "hai đích" nhưng sai đường dẫn đích thứ hai.
Ghi chú về chất lượng câu hỏi
Bản đề trong ngân hàng này thiếu cây thư mục và phần files của appspec.yml mà câu hỏi nhắc tới. Phần giải thích trên dựa vào quy tắc chung của CodeDeploy; hãy xem nó như bài học về cách files hoạt động hơn là lời giải cho đúng tệp bị thiếu.