Ngân hàng đề — AWS Certified DevOps Engineer Professional

Tìm thấy 681 câu.

Câu 31 Chọn nhiều đáp án Domain 2: Configuration Management and IaC

The DevOps team at a social media company has created a CodePipeline pipeline and the final step is to use CodeDeploy to update an AWS Lambda function. As a DevOps Engineering Lead at the company, you have decided that for every deployment, the new Lambda function must sustain a small amount of traffic for 10 minutes and then shift all the traffic to the new function. It has also been decided that safety must be put in place to automatically roll-back if the Lambda function experiences too many crashes.

Which of the following recommendations would you provide to address the given use-case? (Select two)

  1. A

    Choose a deployment configuration of LambdaLinear10PercentEvery10Minutes

  2. B

    Create a CloudWatch Event for the Lambda Deployment Monitoring and associate it with the CodeDeploy deployment

  3. C

    Create a CloudWatch Alarm on the Lambda CloudWatch metrics and associate it with the CodeDeploy deployment

  4. D

    Choose a deployment configuration of LambdaAllAtOnce

  5. E

    Choose a deployment configuration of LambdaCanary10Percent10Minutes

Xem giải thích

Đáp án

C và E — chọn deployment configuration LambdaCanary10Percent10Minutes, và tạo CloudWatch Alarm trên chỉ số của Lambda rồi gắn vào deployment của CodeDeploy

Vì sao đúng

  • E. LambdaCanary10Percent10Minutes — tên gọi mô tả chính xác điều đề yêu cầu: chuyển 10% lưu lượng sang phiên bản mới, giữ trong 10 phút, rồi chuyển toàn bộ phần còn lại một lần.

    Đây là chỗ phân biệt hai họ cấu hình của CodeDeploy cho Lambda:

    Canary Linear
    Cách chuyển Hai bước: một phần nhỏ, chờ, rồi chuyển hết Nhiều bước đều nhau cho tới 100%
    10Percent10Minutes 10% → chờ 10 phút → 100% 10% mỗi 10 phút → mất 90 phút
  • C. CloudWatch Alarm gắn vào deployment — đây là cơ chế tự quay lui. Bạn tạo cảnh báo trên chỉ số Errors hoặc Throttles của phiên bản mới; nếu nó kích hoạt trong giai đoạn canary, CodeDeploy tự chuyển toàn bộ lưu lượng về phiên bản cũ.

Vì sao các phương án khác sai

  • A. LambdaLinear10PercentEvery10Minutes — chuyển đều đặn 10% mỗi 10 phút, mất 90 phút mới xong; không khớp mô tả "giữ một lượng nhỏ trong 10 phút rồi chuyển hết". Đây là phương án nhiễu chính.
  • D. LambdaAllAtOnce — chuyển 100% ngay, không có giai đoạn quan sát nào.
  • B. Tạo "CloudWatch Event for Lambda Deployment Monitoring" — không tồn tại; cơ chế quay lui của CodeDeploy dựa trên CloudWatch Alarm, không phải CloudWatch Event.
Câu 32 Domain 1: SDLC Automation

The DevOps team at an e-commerce company is working with the in-house security team to improve the security workflow of the code release process. The DevOps team would like to initiate a 3rd party code vulnerability analysis tool for every push done to code in your CodeCommit repository. The code has to be sent via an external API.

As an AWS Certified DevOps Engineer, how would you implement this most efficiently?

  1. A

    Create a CloudWatch Event rule on your CodeCommit repository that reacts to pushes. As a target, choose an AWS Lambda function that will request the code from CodeCommit, zip it and send it to the 3rd party API

  2. B

    Create a CloudWatch Event rule on a schedule of 5 minutes that triggers a Lambda function that will check for new commits done on your CodeCommit repository. If new commits are detected, download and zip the code and then send it to the 3rd party API

  3. C

    Create a CodeCommit hook on an EC2 instance that streams changes from CodeCommit into the local filesystem. A cron job on the EC2 instance will zip the code and send it to the 3rd party API upon changes being detected

  4. D

    Create a CloudWatch Event rule on your CodeCommit repository that reacts to pushes. As a target, choose an S3 bucket so that the code will be automatically zipped into S3. Create an S3 Event rule to trigger a Lambda function that will retrieve the zipped code from S3 and send it to the 3rd party API

Xem giải thích

Đáp án

A — Tạo CloudWatch Events rule trên kho CodeCommit phản ứng với sự kiện push, nhắm tới một hàm Lambda lấy mã từ CodeCommit, nén lại và gửi tới API bên thứ ba

Vì sao đúng

Đề đòi hiệu quả nhất, và kiến trúc này là đường ngắn nhất có thể:

Push vào CodeCommit
   ▼  CloudWatch Events (hướng sự kiện, kích hoạt tức thì)
Lambda: lấy mã → nén → gọi API bên thứ ba

Ba lý do nó hiệu quả:

  • Hướng sự kiện — chạy đúng lúc có push, không có độ trễ và không lãng phí lần chạy nào.
  • Không có hạ tầng — Lambda tự co giãn, trả tiền theo lần chạy.
  • Ít mắt xích nhất — chỉ hai thành phần.

Vì sao các phương án khác sai

  • D. Cùng kiến trúc nhưng nhắm tới S3 để mã được tự nén vào đó, rồi S3 event gọi Lambda — không làm được: CloudWatch Events không có target nào tự lấy mã từ CodeCommit và nén vào S3. Đây là phương án nhiễu chính, và nó thêm một mắt xích không tồn tại.
  • B. Chạy Lambda mỗi 5 phút để kiểm tra commit mới — mô hình hỏi vòng (polling): có độ trễ tới 5 phút, và phần lớn lần chạy là vô ích vì không có commit nào. Kém hiệu quả hơn hẳn mô hình hướng sự kiện.
  • C. Dùng EC2 kèm cron job — máy chạy 24/7 cho một việc thỉnh thoảng mới xảy ra.
Câu 33 Domain 2: Configuration Management and IaC

A Big Data analytics company is operating a distributed Cassandra cluster on EC2. Each instance in the cluster must have a list of all the other instance's IP to function correctly, store in a configuration file. As a Devops Engineer at the company, you would like this solution to adapt automatically when newer EC2 instances join the cluster, or when some EC2 instances are terminated.

Which of the following solutions would you recommend for the given requirement?

  1. A

    Manage the EC2 instances using an Auto Scaling Group. Include a lifecycle hook for the instance pending and termination that will trigger an EC2 user-data script on the EC2 instances. The script issues an EC2 DescribeInstances API call and update the configuration file locally

  2. B

    Manage the EC2 instances using OpsWorks. Include a chef cookbook on the setup lifecycle event that will update the configuration file accordingly

  3. C

    Manage the EC2 instances using an Auto Scaling Group. Include a lifecycle hook for the instance pending and termination that will trigger an AWS Lambda function. The Lambda function will issue an EC2 DescribeInstances API call and update the configuration file through SSH

  4. D

    Manage the EC2 instances using OpsWorks. Include a chef cookbook on the configure lifecycle event that will update the configuration file accordingly

Xem giải thích

Đáp án

D — Quản lý các EC2 instance bằng OpsWorks, và đưa một Chef cookbook vào lifecycle event configure để cập nhật tệp cấu hình

Vì sao đúng

OpsWorks Stacks có năm lifecycle event, và configure có một tính chất riêng biệt:

Sự kiện configure được kích hoạt trên TẤT CẢ các instance trong stack mỗi khi có instance vào hoặc rời khỏi trạng thái online.

Đó chính xác là thứ bài toán Cassandra cần: mỗi node phải biết địa chỉ IP của mọi node khác, và danh sách đó thay đổi mỗi khi cụm co giãn.

Với configure, khi node thứ bảy tham gia, cả sáu node cũ đều chạy lại cookbook và cập nhật tệp cấu hình — tự động, không cần điều phối gì thêm.

Năm lifecycle event của OpsWorks:

setup      → khi instance vừa khởi động xong
configure  → TRÊN MỌI INSTANCE, khi có instance vào/ra
deploy     → khi triển khai ứng dụng
undeploy   → khi gỡ ứng dụng
shutdown   → trước khi instance dừng

Vì sao các phương án khác sai

  • *B. Dùng OpsWorks nhưng đặt cookbook ở lifecycle event setup — setup chỉ chạy trên chính instance vừa khởi động; các node cũ không biết gì về node mới. Đây là phương án nhiễu chính, và nó chỉ khác đáp án đúng ở tên sự kiện.
  • C. Dùng ASG lifecycle hook gọi Lambda cập nhật cấu hình — làm được, nhưng phải tự viết Lambda, tự xử lý việc ghi tệp lên các instance khác (qua SSM), và tự lo lỗi. Phức tạp hơn nhiều.
  • A. ASG lifecycle hook kích hoạt user-data script — user-data chỉ chạy lúc khởi động lần đầu, không chạy lại được theo lifecycle hook.
Câu 34 Domain 2: Configuration Management and IaC

An IT company is creating an online booking system for hotels. The booking workflow that the company has implemented can take over 3 hours to complete as a manual verification step is required by a 3rd party provider to ensure big transactions are not fraudulent.

As a DevOps Engineer, you need to expose this as a secure API for the end customers. The website must be able to sustain 5000 requests at the same time. How should you implement this in the simplest possible way?

  1. A

    Create the booking workflow in Step Functions. Create an API Gateway stage using a service integration with AWS Lambda, which will, in turn, invoke the Step Function workflow. Secure your API using Cognito

  2. B

    Create the booking workflow in AWS Lambda. Create an API Gateway stage using a service integration with AWS Lambda. The Lambda function will wait for the service provider response and then issue the status back to API Gateway. Secure your API using Cognito

  3. C

    Create the booking workflow in AWS Lambda. Enable public invocations of the Lambda functions so that clients can start the booking process. The Lambda function will wait for the service provider's response and then issue the status back to the client. Secure the calls using IAM

  4. D

    Create the booking workflow in Step Functions. Create an API Gateway stage using a service integration with Step Functions. Secure your API using Cognito

Xem giải thích

Đáp án

*D — Dựng luồng đặt phòng bằng Step Functions, tạo API Gateway stage dùng service integration trực tiếp với Step Functions, và bảo vệ API bằng Cognito

Vì sao đúng

Ràng buộc quyết định trong đề: quy trình mất hơn 3 giờ vì có bước xác minh thủ công của bên thứ ba.

Con số đó loại ngay Lambda: giới hạn tối đa của Lambda là 15 phút. Còn Step Functions hỗ trợ luồng chạy tới một năm, và có sẵn mẫu task token cho đúng tình huống chờ bên ngoài:

Step Functions dừng ở bước "chờ xác minh", trả về một task token
   ▼  (3 giờ sau)
Bên thứ ba gọi SendTaskSuccess kèm token  →  luồng chạy tiếp

Trong lúc chờ, không có tài nguyên nào chạy — bạn không trả tiền cho việc chờ đợi.

Chi tiết service integration trực tiếp là phần "đơn giản nhất": API Gateway gọi thẳng Step Functions, không cần Lambda ở giữa.

Cognito lo phần bảo mật API, và API Gateway chịu được 5.000 yêu cầu đồng thời.

Vì sao các phương án khác sai

  • A. Step Functions nhưng qua Lambda trung gian — hoạt động được nhưng thêm một mắt xích không cần thiết; đề đòi "đơn giản nhất có thể". Đây là phương án nhiễu chính.
  • B và C. Dựng luồng trong Lambda và để Lambda chờ phản hồi — bất khả thi: vượt giới hạn 15 phút, và giữ Lambda chạy để chờ là lãng phí. C còn đề xuất cho phép gọi Lambda công khai, bỏ luôn lớp bảo mật.
Câu 35 Domain 1: SDLC Automation

As part of the CICD pipeline, the DevOps team at a retail company wants to deploy the latest application code to a staging environment and the team also wants to ensure it can execute an automated functional test suite before deploying to production. The code is managed via CodeCommit. Usually, the functional test suite runs for over two hours. The company has hired you as an AWS Certified DevOps Engineer Professional to build a solution for this requirement.

How would you create the CICD pipeline to run your test suite in the most efficient way?

  1. A

    Create a CodePipeline pointing to the master branch of your CodeCommit repository and automatically deploy to a staging environment using CodeDeploy. After that stage, invoke a custom stage using a Lambda function that will run the test suite. If the stage doesn't fail, the last stage will deploy the application to production

  2. B

    Create a CodePipeline pointing to the master branch of your CodeCommit repository and as a first stage run a CodeBuild build that will run the test suite against the staging environment. Upon passing, deploy to staging using CodeDeploy and if it succeeds, deploy to production

  3. C

    Create a CodePipeline pointing to the master branch of your CodeCommit repository and automatically deploy to a staging environment using CodeDeploy. After that stage, invoke a CodeBuild build that will run the test suite. If the stage doesn't fail, the last stage will deploy the application to production

  4. D

    Create a CodePipeline pointing to the master branch of your CodeCommit repository and automatically deploy to a staging environment using CodeDeploy. After that stage, invoke a custom stage using a Lambda function that will invoke a Step Function execution. The Step Function will run the test suite. Create a CloudWatch Event Rule on the execution termination of your Step Function to invoke a Lambda function and signal CodePipeline the success or failure. If the stage doesn't fail, the last stage will deploy the application to production

Xem giải thích

Đáp án

C — CodePipeline triển khai sang môi trường staging bằng CodeDeploy, rồi gọi một CodeBuild build chạy bộ kiểm thử; đạt thì mới triển khai sản xuất

Vì sao đúng

Có hai quyết định trong phương án này, và cả hai đều đúng.

Thứ nhất — thứ tự: triển khai trước, kiểm thử sau. Đề nói rõ là kiểm thử chức năng, tức là kiểm thử ứng dụng đang chạy thật. Vì vậy phải có môi trường staging đã triển khai rồi mới chạy được.

Thứ hai — dùng CodeBuild, không dùng Lambda. Bộ kiểm thử chạy hơn hai giờ, mà Lambda giới hạn 15 phút. CodeBuild thì cho tới 8 giờ cho một build.

CodeCommit → CodeDeploy (staging) → CodeBuild (chạy test 2 giờ) → CodeDeploy (production)

CodeBuild cũng hợp lý về chi phí: nó chỉ chạy khi có việc và tính tiền theo phút.

Vì sao các phương án khác sai

  • B. Chạy CodeBuild ngay ở stage đầu tiên để kiểm thử đối với môi trường staging, rồi mới triển khai — mâu thuẫn logic: tại thời điểm đó staging vẫn đang chạy bản cũ, nên bộ kiểm thử đang kiểm bản sai. Đây là phương án nhiễu chính.
  • A và D. Dùng custom stage gọi Lambda để chạy bộ kiểm thử — vượt giới hạn 15 phút của Lambda; bộ kiểm thử sẽ bị cắt giữa chừng.
Câu 36 Chọn nhiều đáp án Domain 3: Resilient Cloud Solutions

The DevOps team at a multi-national financial services company manages hundreds of accounts through AWS Organizations. As part of the security compliance requirements, the team must enforce the use of a security-hardened AMI in each AWS account. When a new AMI is created, the team wants to make sure new EC2 instances cannot be instantiated from the old AMI. Additionally, the team also wants to track and audit compliance of AMI usage across all the accounts.

The company has hired you as an AWS Certified DevOps Engineer Professional to build a solution for this requirement. What do you recommend? (Select two)

  1. A

    Create an AWS Automation document to create that AMI and deploy it to all the accounts using AWS CloudFormation StackSets. Run the Automation in all the accounts to have the AMI created locally

  2. B

    Create an AWS Automation document to create that AMI in a master account and copy the AMI into the other accounts. When a new AMI is created, copy it as well

  3. C

    Create an AWS Config Custom Rule in all the accounts using CloudFormation StackSets. Report the rule's result using an AWS Config aggregation

  4. D

    Create an AWS Lambda function in all the accounts using CloudFormation StackSets, which will check the AMI id of all the EC2 instances in the account. Give it an IAM role that allows it to publish messages to an SNS topic in the master account

  5. E

    Create an AWS Automation document to create that AMI in a master account and share the AMI with the other accounts. When a new AMI is created, un-share the previous AMI and share the new one

Xem giải thích

Đáp án

C và E — dùng AWS Config Custom Rule triển khai bằng StackSets kèm Config aggregation để theo dõi tuân thủ, và tạo AMI ở tài khoản chính rồi chia sẻ (share) — khi có AMI mới thì bỏ chia sẻ AMI cũ

Vì sao đúng

Đề có hai yêu cầu tách bạch, và mỗi phương án đúng lo một cái:

  • E. Chia sẻ AMI, không sao chép — đây là chỗ quyết định. Khi bạn bỏ chia sẻ (un-share) AMI cũ, các tài khoản khác lập tức mất quyền khởi chạy từ nó. Nếu sao chép AMI sang từng tài khoản thì bản sao thuộc sở hữu của tài khoản đó, và bạn không gỡ được — họ vẫn dùng AMI cũ mãi.

  • C. Config Custom Rule kèm aggregation — Config Rule chạy ở mỗi tài khoản để kiểm tra AMI mà instance đang dùng, còn aggregator gom kết quả từ hàng trăm tài khoản về một bảng theo dõi duy nhất. Đó chính là phần "theo dõi và kiểm toán mức tuân thủ" mà đề yêu cầu.

Vì sao các phương án khác sai

  • B. Sao chép AMI sang các tài khoản khác — như đã nêu, bản sao thuộc về tài khoản đích và bạn không thu hồi được. Đây là phương án nhiễu chính.
  • A. Chạy Automation ở từng tài khoản để tạo AMI cục bộ — mỗi tài khoản tự tạo AMI riêng, nên không còn bảo đảm mọi nơi dùng cùng một AMI đã được cứng hoá.
  • D. Lambda ở mỗi tài khoản kiểm tra AMI rồi gửi SNS — làm được, nhưng bạn tự viết và bảo trì logic mà Config đã có sẵn, và mất luôn bảng theo dõi tuân thủ tập trung.
Câu 37 Domain 6: Security and Compliance

The DevOps team at a retail company has deployed its flagship application on EC2 instances using CodeDeploy and uses an RDS PostgreSQL database to store the data, while it uses DynamoDB to store the user sessions. As the Lead DevOps Engineer at the company, you would like the application to securely access RDS & DynamoDB.

How can you do this most securely?

  1. A

    Store the RDS credentials & DynamoDB credentials in Secrets Manager and create an IAM instance role for EC2 to access Secrets Manager

  2. B

    Store the RDS credentials in a DynamoDB table and create an IAM instance role for EC2 to access DynamoDB

  3. C

    Store the RDS credentials in Secrets Manager and create an IAM instance role for EC2 to access Secrets Manager and DynamoDB

  4. D

    Store IAM user credentials & RDS credentials in Secrets Manager and create an IAM instance role for EC2 to access Secrets Manager

Xem giải thích

Đáp án

*C — Lưu thông tin đăng nhập RDS trong Secrets Manager, và tạo IAM instance role cho EC2 để truy cập cả Secrets Manager lẫn DynamoDB

Vì sao đúng

Chìa khoá của câu này là nhận ra hai dịch vụ xác thực theo hai cách khác nhau:

RDS PostgreSQL DynamoDB
Xác thực bằng Tên đăng nhập và mật khẩu của cơ sở dữ liệu IAM — chữ ký SigV4
Có "credentials" để lưu không Có Không có gì để lưu

Vì vậy:

  • RDS cần mật khẩu, và nơi đúng để cất là Secrets Manager (mã hoá bằng KMS, kiểm toán qua CloudTrail, xoay vòng tự động).
  • DynamoDB thì không có thông tin đăng nhập nào — chỉ cần IAM role cho phép gọi API.

Một instance role duy nhất cấp cả hai quyền: đọc bí mật RDS từ Secrets Manager, và thao tác trên bảng DynamoDB.

Vì sao các phương án khác sai

  • A. Lưu "thông tin đăng nhập DynamoDB" vào Secrets Manager — không tồn tại thông tin đăng nhập nào cho DynamoDB. Đây là phương án nhiễu chính, và nó dựa trên hiểu lầm phổ biến rằng mọi dịch vụ đều có mật khẩu.
  • D. Lưu thông tin đăng nhập IAM user trong Secrets Manager — dùng khoá truy cập cố định trong khi instance role đã cho thông tin xác thực tạm thời; đây là bước lùi về bảo mật.
  • B. Lưu mật khẩu RDS trong một bảng DynamoDB — DynamoDB không phải kho bí mật: không có xoay vòng, không có kiểm toán chuyên biệt, và ai đọc được bảng là đọc được mật khẩu.
Câu 38 Domain 1: SDLC Automation

As part of your CodePipeline, you are running multiple test suites. Two are bundled as Docker containers and run directly on CodeBuild, while another one runs as a Lambda function executing Python code. All these test suites are based on HTTP requests and upon analyzing, these are found to be network bound, not CPU bound. Right now, the CodePipeline takes a long time to execute as these actions happen one after the other. They prevent the company from adding further tests. The whole pipeline is managed by CloudFormation.

As a DevOps Engineer, which of the following would you recommend improving the completion time of your pipeline?

  1. A

    Change the runOrder of your actions so that they have the same value

  2. B

    Increase the number of vCPU assigned to the CodeBuild builds and the RAM assigned to your Lambda function

  3. C

    Enable CloudFormation StackSets to run the actions in parallel

  4. D

    Migrate all the test suites to Jenkins and use the ECS plugin

Xem giải thích

Đáp án

*A — Đổi giá trị runOrder của các action thành giống nhau

Vì sao đúng

Trong CodePipeline, runOrder quyết định thứ tự thực thi các action trong cùng một stage:

runOrder: 1, 2, 3  →  chạy TUẦN TỰ, cái sau chờ cái trước
runOrder: 1, 1, 1  →  chạy SONG SONG cùng lúc

Đề nói rõ các bộ kiểm thử hiện chạy nối tiếp nhau, và chúng bị chặn bởi mạng chứ không phải bởi CPU. Nghĩa là chúng dành phần lớn thời gian chờ phản hồi HTTP, không giành tài nguyên của nhau — nên chạy song song là hoàn toàn an toàn và rút ngắn thời gian xuống bằng bộ test chậm nhất thay vì tổng ba bộ.

Đây cũng là thay đổi nhỏ nhất có thể: sửa một con số trong template CloudFormation.

Vì sao các phương án khác sai

  • B. Tăng vCPU cho CodeBuild và RAM cho Lambda — đề đã nói rõ workload bị chặn bởi mạng, không phải CPU. Thêm tài nguyên tính toán vào một tiến trình đang ngồi chờ mạng thì không nhanh lên chút nào, mà chi phí thì tăng. Đây là phương án nhiễu chính.
  • C. Bật CloudFormation StackSets để chạy song song — StackSets triển khai stack ra nhiều tài khoản và Region; nó không liên quan gì tới thứ tự action trong pipeline.
  • D. Chuyển toàn bộ sang Jenkins — thay cả hệ thống CI cho một vấn đề sửa được bằng một dòng cấu hình.
Câu 39 Domain 1: SDLC Automation

A healthcare technology company provides a Software as a Service (SaaS) solution to hospitals throughout the United States to use the company’s proprietary system to integrate their clinical documentation and coding workflows. The DevOps team at the company would like to enable a CICD pipeline that enables safe deployments to production and the ability to work on new features of the product roadmap.

As an AWS Certified DevOps Engineer, which solution would you recommend for the given use-case?

  1. A

    Create a CodeCommit repository and set the CICD pipeline to deploy the master branch. For each new feature being implemented, create a new branch and create pull requests to merge into master. Set a repository access policy on your repository to prevent direct pushes to master

  2. B

    Create a CodeCommit repository and create a branch for each feature. Create a CICD pipeline for each branch, and the last step of the CICD pipeline should be to merge into master. Set an IAM policy on your developer group to prevent direct pushes to master

  3. C

    Create the main CodeCommit repository and set the CICD pipeline to deploy the master branch. For each new feature being implemented, create a new CodeCommit repository and create pull requests to merge into the main repository. Set an IAM policy on your developer group to prevent direct pushes to the main repository

  4. D

    Create a CodeCommit repository and set the CICD pipeline to deploy the master branch. For each new feature being implemented, create a new branch and create pull requests to merge into master. Set an IAM policy on your developer group to prevent direct pushes to master

Xem giải thích

Đáp án

D — Một kho CodeCommit duy nhất, pipeline triển khai từ nhánh master; mỗi tính năng là một nhánh riêng và merge qua pull request; dùng IAM policy trên nhóm developer để chặn push thẳng vào master

Vì sao đúng

Đây là mô hình feature branch workflow chuẩn, và ba mảnh ghép đều cần thiết:

Mảnh Vai trò
Một kho duy nhất Mọi tính năng chia sẻ chung lịch sử; merge dễ
Nhánh cho mỗi tính năng Công việc đang dở không chạm vào mã sản xuất
Pull request Bắt buộc rà soát trước khi vào master
IAM policy chặn push thẳng Bảo đảm quy trình không bị đi tắt

Chi tiết quan trọng: chặn push vào master phải làm bằng IAM policy có điều kiện trên tham chiếu nhánh — đây là cơ chế duy nhất CodeCommit cung cấp cho việc bảo vệ nhánh.

Vì sao các phương án khác sai

  • A. Dùng repository access policy để chặn push — CodeCommit không có "repository policy" theo nghĩa như bucket policy của S3; kiểm soát truy cập làm qua IAM. Đây là phương án nhiễu chính, và nó chỉ khác đáp án đúng ở tên cơ chế.
  • *C. Mỗi tính năng một kho riêng — merge giữa các kho khác nhau rất rắc rối, và bạn mất lịch sử chung.
  • B. Mỗi nhánh một pipeline, bước cuối là merge vào master — đảo ngược quy trình: mã được triển khai trước khi được rà soát và merge.
Câu 40 Domain 2: Configuration Management and IaC

The DevOps team at a leading bitcoin wallet and exchange services company is trying to deploy a CloudFormation template that contains a Lambda Function, an S3 bucket, an IAM role, and a DynamoDB table from CodePipeline but the team is getting an InsufficientCapabilitiesException.

As an AWS Certified DevOps Engineer Professional, which of the following options would you suggest fixing this issue?

  1. A

    Enable the IAM Capability on the CodePipeline configuration for the Deploy CloudFormation stage action

  2. B

    Update the CodePipeline IAM Role so it has permissions to create all the resources mentioned in the CloudFormation template

  3. C

    Increase the service limits for your S3 bucket limits as you've reached it

  4. D

    Fix the CloudFormation template as there is circular dependency and CloudFormation does not have that capability

Xem giải thích

Đáp án

A — Bật IAM Capability trong cấu hình của stage action Deploy CloudFormation trong CodePipeline

Vì sao đúng

InsufficientCapabilitiesException là lỗi rất đặc trưng: nó xuất hiện khi template tạo hoặc sửa tài nguyên IAM mà bạn chưa xác nhận rõ ràng rằng mình biết điều đó.

Đây là cơ chế an toàn có chủ đích của CloudFormation: tài nguyên IAM có thể nâng quyền, nên CloudFormation buộc người triển khai phải thừa nhận trước.

Template trong đề có một IAM role, nên phải khai một trong hai capability:

Capability Dùng khi
CAPABILITY_IAM Template tạo tài nguyên IAM không đặt tên tường minh
CAPABILITY_NAMED_IAM Template có tài nguyên IAM được đặt tên cụ thể

Trong CodePipeline, đây là ô tích "IAM Capability" ngay trong cấu hình của deploy action.

Vì sao các phương án khác sai

  • B. Cập nhật IAM role của CodePipeline để có quyền tạo mọi tài nguyên trong template — nếu thiếu quyền thì lỗi sẽ là AccessDenied, không phải InsufficientCapabilities. Tên ngoại lệ chỉ đích danh vấn đề. Đây là phương án nhiễu chính.
  • C. Tăng hạn mức số bucket S3 — sẽ báo lỗi về service limit, không phải capability.
  • D. Sửa phụ thuộc vòng trong template — sẽ báo CircularDependency.