Ngân hàng đề — AWS Certified DevOps Engineer Professional

Tìm thấy 681 câu.

Câu 341
An application running on a set of Amazon EC2 instances in an Auto Scaling group requires a configuration file to operate. The instances are created and maintained with AWS CloudFormation. A DevOps engineer wants the instances to have the latest configuration file when launched, and wants changes to the configuration file to be reflected on all the instances with a minimal delay when the CloudFormation template is updated. Company policy requires that application configuration files be maintained along with AWS infrastructure configuration files in source control.

Which solution will accomplish this?
  1. A In the CloudFormation template, add an AWS Config rule. Place the configuration file content in the rule’s InputParameters property, and set the Scope property to the EC2 Auto Scaling group. Add an AWS Systems Manager Resource Data Sync resource to the template to poll for updates to the configuration.
  2. B In the CloudFormation template, add an EC2 launch template resource. Place the configuration file content in the launch template. Configure the cfn-init script to run when the instance is launched, and configure the cfn-hup script to poll for updates to the configuration.
  3. C In the CloudFormation template, add an EC2 launch template resource. Place the configuration file content in the launch template. Add an AWS Systems Manager Resource Data Sync resource to the template to poll for updates to the configuration.
  4. D In the CloudFormation template, add CloudFormation init metadata. Place the configuration file content in the metadata. Configure the cfn-init script to run when the instance is launched, and configure the cfn-hup script to poll for updates to the configuration.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc quản lý file cấu hình (configuration file) cho ứng dụng chạy trên các instance Amazon EC2 thuộc Auto Scaling Group (ASG), được tạo và duy trì bởi AWS CloudFormation.

📌 Yêu cầu chính:

  • Instance mới launch phải có file config mới nhất ngay lập tức.
  • Khi update CloudFormation template, thay đổi config phải phản ánh trên tất cả instances với delay tối thiểu (không cần restart ASG hay thay thế instances).
  • Chính sách công ty: File config phải lưu trữ cùng infrastructure config trong source control (như Git), nghĩa là file config nên được nhúng trực tiếp vào CloudFormation template (YAML/JSON) để version control thống nhất.

🛠️ Thách thức: Cần cơ chế tự động pull config từ CloudFormation metadata khi launch và poll định kỳ để cập nhật mà không vi phạm policy (không dùng S3 riêng hay external storage).

Kiến thức cập nhật (AWS 2026): CloudFormation hỗ trợ Init Metadata và cfn-hup (daemon monitor stack changes) để xử lý dynamic config trên running instances mà không cần Lambda hay SSM riêng lẻ.


✅ Đáp án đúng

Đáp án đúng là lựa chọn cuối cùng:

In the CloudFormation template, add CloudFormation init metadata. Place the configuration file content in the metadata. Configure the cfn-init script to run when the instance is launched, and configure the cfn-hup script to poll for updates to the configuration.

Lý do chọn:

  • CloudFormation Init Metadata (phần Metadata: AWS::CloudFormation::Init) cho phép nhúng nội dung file config trực tiếp vào template, lưu trong source control cùng infra code. ✅
  • cfn-init script chạy lúc launch instance (qua UserData), tải và áp dụng config từ stack metadata → instance mới có config mới nhất ngay. 🆕
  • cfn-hup script (daemon) poll metadata mỗi 5 phút mặc định, detect thay đổi khi update stack → tự động chạy cfn-init để update config trên tất cả instances hiện tại với delay tối thiểu (không cần replace instances). 🔄
  • Hoàn hảo cho ASG vì metadata theo stack, update template sẽ propagate tự động. Không vi phạm policy!

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn một cách chi tiết, giữ nguyên văn bản gốc tiếng Anh. Mỗi phân tích dùng ✅ (đúng hoàn toàn) hoặc ❌ (sai, với lý do cụ thể).

  • ❌ Phương án 1 (SAI):

    In the CloudFormation template, add an AWS Config rule. Place the configuration file content in the rule’s InputParameters property, and set the Scope property to the EC2 Auto Scaling group. Add an AWS Systems Manager Resource Data Sync resource to the template to poll for updates to the configuration.
    Giải thích sai: AWS Config rules dùng để compliance checking (kiểm tra quy tắc), không phải lưu trữ/push file config. InputParameters không hỗ trợ nội dung file lớn, Scope chỉ tag resources chứ không trigger update. SSM Resource Data Sync sync inventory data (như software list), không poll config files. Không đảm bảo update nhanh trên ASG, vi phạm policy vì không nhúng trực tiếp vào template. 🚫

  • ❌ Phương án 2 (SAI):

    In the CloudFormation template, add an EC2 launch template resource. Place the configuration file content in the launch template. Configure the cfn-init script to run when the instance is launched, and configure the cfn-hup script to poll for updates to the configuration.
    Giải thích sai: Launch Template (LT) lưu config static trong AMI/UserData, chỉ áp dụng cho instance mới launch. cfn-hup không poll LT changes (LT không phải stack metadata), nên instances cũ không update khi CF template thay đổi. ASG dùng LT sẽ không roll instances tự động → delay lớn, không update "all instances". Phù hợp partial nhưng miss poll mechanism. 🔄❌

  • ❌ Phương án 3 (SAI):

    In the CloudFormation template, add an EC2 launch template resource. Place the configuration file content in the launch template. Add an AWS Systems Manager Resource Data Sync resource to the template to poll for updates to the configuration.
    Giải thích sai: Tương tự phương án 2, LT chỉ cho instance mới. SSM Resource Data Sync không poll config files mà sync metadata như patch status/software inventory về S3. Không có cơ chế push config realtime đến instances, không update khi CF update. Delay cao và không nhúng config vào LT metadata đúng cách. 📊❌

  • ✅ Phương án 4 (ĐÚNG):

    In the CloudFormation template, add CloudFormation init metadata. Place the configuration file content in the metadata. Configure the cfn-init script to run when the instance is launched, and configure the cfn-hup script to poll for updates to the configuration.
    Giải thích đúng: Như phần ✅ trên. Đây là best practice AWS cho dynamic config trên EC2/ASG với CFN: Nhúng config vào metadata, init lúc launch, hup poll update. Hoàn thành tất cả yêu cầu với delay ~5 phút. 🎯


📘 Tài liệu tham khảo (AWS Docs cập nhật 2026)

  • CloudFormation Init & cfn-hup: AWS::CloudFormation::Init & cfn-hup guide – Best practice cho config management.
  • ASG với CFN: Auto Scaling Groups in CloudFormation.
  • Exam Tips (DOP-C02): Chủ đề "Infrastructure as Code" & "Configuration Management" thường dùng cfn-init/hup cho ASG updates.
  • Whitepaper: AWS Well-Architected Framework – Reliability Pillar: Dynamic config via CFN metadata.

🛠️ Lời khuyên: Trong thực tế, test với cfn-init -v và cron cho cfn-hup để đảm bảo poll interval phù hợp! Nếu cần scale, kết hợp SSM Parameter Store cho secrets. 😊

Câu 342 Chọn nhiều đáp án
A company manages an application that stores logs in Amazon CloudWatch Logs. The company wants to archive the logs to an Amazon S3 bucket. Logs are rarely accessed after 90 days and must be retained for 10 years.

Which combination of steps should a DevOps engineer take to meet these requirements? (Choose two.)
  1. A Configure a CloudWatch Logs subscription filter to use AWS Glue to transfer all logs to an S3 bucket.
  2. B Configure a CloudWatch Logs subscription filter to use Amazon Kinesis Data Firehose to stream all logs to an S3 bucket.
  3. C Configure a CloudWatch Logs subscription filter to stream all logs to an S3 bucket.
  4. D Configure the S3 bucket lifecycle policy to transition logs to S3 Glacier after 90 days and to expire logs after 3.650 days.
  5. E Configure the S3 bucket lifecycle policy to transition logs to Reduced Redundancy after 90 days and to expire logs after 3.650 days.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi yêu cầu một DevOps engineer thực hiện kết hợp hai bước (Choose two) để đáp ứng yêu cầu sau:

  • Ứng dụng lưu trữ logs trong Amazon CloudWatch Logs.
  • Archive logs vào Amazon S3 bucket (lưu trữ lâu dài).
  • Logs hiếm khi được truy cập sau 90 ngày, nhưng phải giữ nguyên (retain) trong 10 năm (khoảng 3.650 ngày).

Mục tiêu chính:

  • Chuyển logs từ CloudWatch Logs sang S3 một cách hiệu quả (streaming hoặc batch).
  • Áp dụng S3 Lifecycle policy để tối ưu chi phí: chuyển sang lớp lưu trữ rẻ hơn sau 90 ngày (phù hợp với ít truy cập), và xóa (expire) sau đúng 10 năm để tuân thủ retention policy.

🛠️ Cách tiếp cận chuẩn AWS (cập nhật đến 2024-2026): Sử dụng CloudWatch Logs subscription filter kết hợp Amazon Kinesis Data Firehose để stream logs realtime/batch vào S3 (hỗ trợ buffer, compression, encryption). Sau đó, dùng S3 Lifecycle để transition sang S3 Glacier (lưu trữ archive rẻ, truy xuất chậm phù hợp logs cũ) sau 90 ngày, và expire sau 3.650 ngày. Điều này đảm bảo tuân thủ, tối ưu chi phí và scalability.

📘 Tài liệu tham khảo:

✅ Đáp án đúng (Chọn TWO) và lý do lựa chọn

Dựa trên best practices AWS DOP-C02 (DevOps Professional 2024), hai bước đúng là:

  1. Configure a CloudWatch Logs subscription filter to use Amazon Kinesis Data Firehose to stream all logs to an S3 bucket.
    🧩 Lý do: Kinesis Data Firehose là dịch vụ managed để stream logs từ CloudWatch trực tiếp vào S3, hỗ trợ buffering (1-24h), compression (GZIP), encryption, và error handling. Hoàn hảo cho volume logs lớn, realtime archiving. Không có lựa chọn nào khác stream trực tiếp hiệu quả như vậy.

  2. Configure the S3 bucket lifecycle policy to transition logs to S3 Glacier after 90 days and to expire logs after 3.650 days.
    🧩 Lý do: S3 Glacier (nay là S3 Glacier Flexible Retrieval) lý tưởng cho dữ liệu ít truy cập, chi phí thấp (~$0.004/GB/tháng). Transition sau 90 ngày khớp yêu cầu "rarely accessed", expire sau 3.650 ngày (10 năm) đảm bảo retention chính xác. Tối ưu chi phí theo S3 Intelligent-Tiering principles.

🛠️ Giải thích TẤT CẢ các phương án (Đúng/Sai)

  • Configure a CloudWatch Logs subscription filter to use AWS Glue to transfer all logs to an S3 bucket.
    ❌ Sai. AWS Glue là dịch vụ ETL cho data lake/batch processing (crawl, catalog, transform), không hỗ trợ subscription filter trực tiếp từ CloudWatch Logs để stream realtime. Glue Jobs cần trigger riêng (Lambda/EventBridge), phức tạp và không hiệu quả cho logs streaming. Không phải best practice cho archiving logs (dùng Firehose thay thế).

  • Configure a CloudWatch Logs subscription filter to use Amazon Kinesis Data Firehose to stream all logs to an S3 bucket.
    ✅ Đúng. Như giải thích trên: Firehose là lựa chọn tối ưu cho streaming logs từ CloudWatch sang S3, hỗ trợ tất cả features cần thiết (buffer, transform via Lambda, delivery to S3/Glacier trực tiếp). Đã được AWS khuyến nghị trong DOP-C02 exam.

  • Configure a CloudWatch Logs subscription filter to stream all logs to an S3 bucket.
    ❌ Sai. Subscription filter chỉ hỗ trợ đích đến như Lambda, Kinesis Streams/Firehose, hoặc Elasticsearch – KHÔNG hỗ trợ S3 trực tiếp. Cần trung gian như Firehose để convert và deliver vào S3.

  • Configure the S3 bucket lifecycle policy to transition logs to S3 Glacier after 90 days and to expire logs after 3.650 days.
    ✅ Đúng. Như giải thích trên: Glacier phù hợp archive dài hạn (retrieval 1-5 phút hoặc Deep Archive cho rẻ hơn), expire chính xác 10 năm. Hỗ trợ noncurrent versions nếu cần.

  • Configure the S3 bucket lifecycle policy to transition logs to Reduced Redundancy after 90 days and to expire logs after 3.650 days.
    ❌ Sai. Reduced Redundancy Storage (RRS) đã deprecated từ 2021, AWS khuyến nghị dùng S3 Standard-IA hoặc One Zone-IA thay thế. RRS chỉ giảm durability (4000:1 thay vì 11 9's), không phù hợp cho logs cần retain 10 năm (rủi ro mất dữ liệu cao). Glacier mới là lựa chọn archive chuẩn.

Câu 343 Chọn nhiều đáp án
A company is developing a new application. The application uses AWS Lambda functions for its compute tier. The company must use a canary deployment for any changes to the Lambda functions. Automated rollback must occur if any failures are reported.

The company’s DevOps team needs to create the infrastructure as code (IaC) and the CI/CD pipeline for this solution.

Which combination of steps will meet these requirements? (Choose three.)
  1. A Create an AWS CloudFormation template for the application. Define each Lambda function in the template by using the AWS::Lambda::Function resource type. In the template, include a version for the Lambda function by using the AWS::Lambda::Version resource type. Declare the CodeSha256 property. Configure an AWS::Lambda::Alias resource that references the latest version of the Lambda function.
  2. B Create an AWS Serverless Application Model (AWS SAM) template for the application. Define each Lambda function in the template by using the AWS::Serverless::Function resource type. For each function, include configurations for the AutoPublishAlias property and the DeploymentPreference property. Configure the deployment configuration type to LambdaCanary10Percent10Minutes.
  3. C Create an AWS CodeCommit repository. Create an AWS CodePipeline pipeline. Use the CodeCommit repository in a new source stage that starts the pipeline. Create an AWS CodeBuild project to deploy the AWS Serverless Application Model (AWS SAM) template. Upload the template and source code to the CodeCommit repository. In the CodeCommit repository, create a buildspec.yml file that includes the commands to build and deploy the SAM application.
  4. D Create an AWS CodeCommit repository. Create an AWS CodePipeline pipeline. Use the CodeCommit repository in a new source stage that starts the pipeline. Create an AWS CodeDeploy deployment group that is configured for canary deployments with a DeploymentPreference type of Canary10Percent10Minutes. Upload the AWS CloudFormation template and source code to the CodeCommit repository. In the CodeCommit repository, create an appspec.yml file that includes the commands to deploy the CloudFormation template.
  5. E Create an Amazon CloudWatch composite alarm for all the Lambda functions. Configure an evaluation period and dimensions for Lambda. Configure the alarm to enter the ALARM state if any errors are detected or if there is insufficient data.
  6. F Create an Amazon CloudWatch alarm for each Lambda function. Configure the alarms to enter the ALARM state if any errors are detected. Configure an evaluation period, dimensions for each Lambda function and version, and the namespace as AWS/Lambda on the Errors metric.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi

Câu hỏi này thuộc chủ đề DevOps trên AWS, tập trung vào việc triển khai ứng dụng sử dụng AWS Lambda với yêu cầu cụ thể:

  • Sử dụng canary deployment (triển khai canary) cho mọi thay đổi Lambda functions.
  • Automated rollback (tự động rollback) nếu phát hiện failures (lỗi).
  • DevOps team cần tạo IaC (Infrastructure as Code) và CI/CD pipeline để đáp ứng.

Yêu cầu chọn 3 bước kết hợp để xây dựng giải pháp hoàn chỉnh:
✅ IaC: Sử dụng template định nghĩa Lambda với hỗ trợ canary deployment và versioning/alias.
✅ CI/CD: Pipeline tự động build/deploy từ source code.
✅ Monitoring/Rollback: Alarms theo dõi errors để trigger rollback tự động.

Giải pháp phải tận dụng các dịch vụ AWS mới nhất (tính đến 2026): AWS SAM (Serverless Application Model) là lựa chọn tối ưu cho Lambda IaC với canary built-in, kết hợp CodePipeline/CodeBuild cho CI/CD, và CloudWatch alarms trên metric Errors để enable auto-rollback.

📘 Tài liệu tham khảo:

✅ Đáp án đúng (Chọn 3)

Các bước đúng là:

  1. Tạo AWS SAM template với AWS::Serverless::Function, AutoPublishAlias, và DeploymentPreference type LambdaCanary10Percent10Minutes 🛠️ (Hỗ trợ canary deployment và alias tự động cho traffic shifting + rollback).
  2. Tạo CodeCommit repo + CodePipeline + CodeBuild với buildspec.yml để deploy SAM template 🚀 (Xây dựng CI/CD pipeline hoàn chỉnh cho SAM app).
  3. Tạo CloudWatch alarm cho mỗi Lambda trên metric Errors (namespace AWS/Lambda), với evaluation period và dimensions cho function/version 🎯 (Trigger ALARM nếu errors, kích hoạt rollback tự động trong SAM).

Lý do chọn: Kết hợp này tạo IaC (SAM template) hỗ trợ canary/alias/rollback built-in, CI/CD tự động qua CodePipeline/CodeBuild, và monitoring chính xác trên Errors metric (metric chuẩn cho Lambda failures). Không dùng CloudFormation thuần vì thiếu hỗ trợ canary native; SAM simplify và integrate tốt hơn (cập nhật SAM CLI v1.XX+ đến 2026).

🔍 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn. Tôi giữ nguyên nội dung phương án gốc bằng tiếng Anh, đánh dấu ✅ (đúng) hoặc ❌ (sai), và giải thích bằng tiếng Việt.

  • ❌ Create an AWS CloudFormation template for the application. Define each Lambda function in the template by using the AWS::Lambda::Function resource type. In the template, include a version for the Lambda function by using the AWS::Lambda::Version resource type. Declare the CodeSha256 property. Configure an AWS::Lambda::Alias resource that references the latest version of the Lambda function.
    ❌ Sai: CloudFormation thuần không hỗ trợ canary deployment native cho Lambda (chỉ versioning/alias cơ bản). Không có cơ chế DeploymentPreference hay auto-rollback tự động. Phải dùng SAM để simplify và enable canary/traffic shifting.

  • ✅ Create an AWS Serverless Application Model (AWS SAM) template for the application. Define each Lambda function in the template by using the AWS::Serverless::Function resource type. For each function, include configurations for the AutoPublishAlias property and the DeploymentPreference property. Configure the deployment configuration type to LambdaCanary10Percent10Minutes.
    ✅ Đúng: SAM AWS::Serverless::Function hỗ trợ AutoPublishAlias (tạo alias tự động) và DeploymentPreference: LambdaCanary10Percent10Minutes (canary: 10% traffic 10 phút đầu, sau full rollout). Tích hợp auto-rollback nếu alarms trigger (yêu cầu câu hỏi). Hoàn hảo cho IaC Lambda canary (SAM transform thành CloudFormation).

  • ✅ Create an AWS CodeCommit repository. Create an AWS CodePipeline pipeline. Use the CodeCommit repository in a new source stage that starts the pipeline. Create an AWS CodeBuild project to deploy the AWS Serverless Application Model (AWS SAM) template. Upload the template and source code to the CodeCommit repository. In the CodeCommit repository, create a buildspec.yml file that includes the commands to build and deploy the SAM application.
    ✅ Đúng: Xây dựng CI/CD pipeline chuẩn với CodeCommit (source), CodePipeline (orchestrator), CodeBuild (build/deploy SAM via sam build/deploy). buildspec.yml chạy lệnh SAM CLI, tự động trigger từ commit. Lý tưởng cho SAM app (hỗ trợ canary qua template).

  • ❌ Create an AWS CodeCommit repository. Create an AWS CodePipeline pipeline. Use the CodeCommit repository in a new source stage that starts the pipeline. Create an AWS CodeDeploy deployment group that is configured for canary deployments with a DeploymentPreference type of Canary10Percent10Minutes. Upload the AWS CloudFormation template and source code to the CodeCommit repository. In the CodeCommit repository, create an appspec.yml file that includes the commands to deploy the CloudFormation template.
    ❌ Sai: CodeDeploy không hỗ trợ Lambda trực tiếp cho canary như vậy (DeploymentPreference: Canary10Percent10Minutes là cho EC2/ALB, không phải Lambda). Với Lambda, dùng SAM/CodeDeploy Lambda compute chỉ cơ bản, thiếu alias/canary native. appspec.yml không phù hợp deploy CloudFormation (dùng cho app deployments, không IaC).

  • ❌ Create an Amazon CloudWatch composite alarm for all the Lambda functions. Configure an evaluation period and dimensions for Lambda. Configure the alarm to enter the ALARM state if any errors are detected or if there is insufficient data.
    ❌ Sai: Composite alarm (kết hợp nhiều alarms) không phù hợp cho per-function/version monitoring cần thiết rollback SAM canary. Thiếu chỉ định Errors metric cụ thể (namespace AWS/Lambda), dimensions cho từng function/version. "Insufficient data" không trigger rollback chính xác; cần alarm riêng trên Errors >0.

  • ✅ Create an Amazon CloudWatch alarm for each Lambda function. Configure the alarms to enter the ALARM state if any errors are detected. Configure an evaluation period, dimensions for each Lambda function and version, and the namespace as AWS/Lambda on the Errors metric.
    ✅ Đúng: Alarm riêng cho mỗi Lambda trên Errors metric (AWS/Lambda namespace, dimensions: FunctionName + Version/Alias) là chuẩn để detect failures. Khi ALARM, SAM auto-rollback traffic về version cũ (tích hợp DeploymentPreference). Evaluation period đảm bảo độ tin cậy.

Kết luận 🎉: Kết hợp 3 bước ✅ tạo giải pháp full IaC + CI/CD + monitoring với canary & rollback tự động, tuân thủ best practices AWS DevOps Professional (2026). Nếu cần lab thực hành, dùng SAM CLI local! 🛠️

Câu 344 Chọn nhiều đáp án
A DevOps engineer is deploying a new version of a company’s application in an AWS CodeDeploy deployment group associated with its Amazon EC2 instances. After some time, the deployment fails. The engineer realizes that all the events associated with the specific deployment ID are in a Skipped status, and code was not deployed in the instances associated with the deployment group.

What are valid reasons for this failure? (Choose two.)
  1. A The networking configuration does not allow the EC2 instances to reach the internet via a NAT gateway or internet gateway, and the CodeDeploy endpoint cannot be reached.
  2. B The IAM user who triggered the application deployment does not have permission to interact with the CodeDeploy endpoint.
  3. C The target EC2 instances were not properly registered with the CodeDeploy endpoint.
  4. D An instance profile with proper permissions was not attached to the target EC2 instances.
  5. E The appspec.yml file was not included in the application revision.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả tình huống một DevOps engineer đang triển khai phiên bản mới của ứng dụng công ty lên Amazon EC2 instances thông qua AWS CodeDeploy deployment group. Sau một thời gian, deployment thất bại với tất cả các events liên quan đến deployment ID cụ thể đều ở trạng thái Skipped (bị bỏ qua), và mã nguồn không được triển khai lên các instances trong deployment group.

📘 Ngữ cảnh kỹ thuật chính (dựa trên AWS CodeDeploy mới nhất năm 2026):

  • CodeDeploy sử dụng agent trên EC2 để poll (kiểm tra định kỳ) các deployment từ service endpoint của AWS CodeDeploy (như codedeploy.<region>.amazonaws.com).
  • Trạng thái SkippedLifeCycleState xảy ra khi CodeDeploy agent không thể kết nối hoặc thực thi deployment do vấn đề mạng, quyền truy cập, hoặc cấu hình instance. Agent sẽ skip event mà không báo lỗi rõ ràng, dẫn đến code không deploy.
  • Đây là lỗi phổ biến trong troubleshooting deployments (xem AWS docs: CodeDeploy User Guide - Deployment lifecycle events).

Câu hỏi yêu cầu chọn TWO valid reasons (hai lý do hợp lệ) gây ra tình trạng này. Chúng ta cần phân tích dựa trên mechanism của CodeDeploy agent polling model.

✅ Đáp án đúng (Chọn TWO)

Hai lựa chọn đúng là:

  1. The networking configuration does not allow the EC2 instances to reach the internet via a NAT gateway or internet gateway, and the CodeDeploy endpoint cannot be reached.
  2. An instance profile with proper permissions was not attached to the target EC2 instances.

Lý do lựa chọn:

  • 🛠️ Những lý do này trực tiếp gây ra Skipped status vì CodeDeploy agent trên EC2 cần kết nối outbound đến CodeDeploy API endpoint (HTTPS port 443) và IAM permissions để download artifacts từ S3 và thực thi lifecycle hooks. Nếu thiếu mạng hoặc instance profile (chứa IAM role như CodeDeployDemoRole), agent sẽ poll thành công deployment nhưng skip tất cả events do không thể proceed. Đây là nguyên nhân phổ biến nhất theo AWS best practices (xác nhận qua CloudWatch Logs của agent).

📋 Phân tích tất cả các phương án (Đúng/Sai)

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phân tích giải thích tại sao đúng/sai dựa trên hành vi của CodeDeploy (kiến thức cập nhật 2026, không thay đổi lớn từ 2023).

  • ✅ The networking configuration does not allow the EC2 instances to reach the internet via a NAT gateway or internet gateway, and the CodeDeploy endpoint cannot be reached.
    Đúng: CodeDeploy agent yêu cầu outbound internet access đến regional endpoint (codedeploy.region.amazonaws.com) qua NAT Gateway (private subnet) hoặc Internet Gateway (public subnet). Nếu VPC thiếu route, Security Group/NACL block port 443, hoặc không dùng VPC Endpoint, agent không poll/reach được deployment, dẫn đến tất cả events Skipped. Kiểm tra logs: /var/log/amazon/codedeploy-agent/codedeploy-agent.log sẽ báo connection timeout. (Tham khảo: AWS Docs - CodeDeploy prerequisites for EC2).

  • ❌ The IAM user who triggered the application deployment does not have permission to interact with the CodeDeploy endpoint.
    Sai: IAM user (hoặc role) chỉ cần quyền create deployment (codedeploy:CreateDeployment). Nếu thiếu, deployment sẽ fail ngay lúc tạo (status Failed/CreatedFailed), không đến mức events Skipped trên instances. Skipped là vấn đề side của instances/agent, không phải initiator. (Tham khảo: AWS IAM policies for CodeDeploy).

  • ❌ The target EC2 instances were not properly registered with the CodeDeploy endpoint.
    Sai: "Registered" nghĩa là tag instances đúng với deployment group (ec2tagset). Nếu không match, instances không được chọn (deployment status InProgress nhưng 0/0 succeeded). Events không tồn tại cho deployment ID đó trên instances, không phải Skipped. CodeDeploy không yêu cầu "register endpoint" thủ công. (Tham khảo: AWS Docs - Create deployment group).

  • ✅ An instance profile with proper permissions was not attached to the target EC2 instances.
    Đúng: EC2 cần IAM Instance Profile gắn role có policy AWSCodeDeployRoleForEC2 hoặc custom (codedeploy:*, s3:GetObject cho bundle). Không có profile/role, agent không authorize được để download appspec.yml hoặc artifacts từ S3, dẫn đến skip toàn bộ lifecycle events (DownloadBundle, BeforeInstall,...). Logs agent báo AccessDenied. (Tham khảo: AWS Docs - Instance profile for CodeDeploy).

  • ❌ The appspec.yml file was not included in the application revision.
    Sai: Nếu thiếu appspec.yml trong revision (zip/tar từ S3/GitHub), deployment fail ở DownloadBundle với lỗi cụ thể (INVALID appspec), status Failed chứ không Skipped. Agent vẫn poll được nhưng reject bundle. (Tham khảo: AWS Docs - appspec.yml reference).

📘 Tài liệu tham khảo (AWS Official - Cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần ví dụ code hoặc lab, hỏi thêm nhé.

Câu 345
A company has a guideline that every Amazon EC2 instance must be launched from an AMI that the company’s security team produces. Every month, the security team sends an email message with the latest approved AMIs to all the development teams.

The development teams use AWS CloudFormation to deploy their applications. When developers launch a new service, they have to search their email for the latest AMIs that the security department sent. A DevOps engineer wants to automate the process that the security team uses to provide the AMI IDs to the development teams.

What is the MOST scalable solution that meets these requirements?
  1. A Direct the security team to use CloudFormation to create new versions of the AMIs and to list the AMI ARNs in an encrypted Amazon S3 object as part of the stack’s Outputs section. Instruct the developers to use a cross-stack reference to load the encrypted S3 object and obtain the most recent AMI ARNs.
  2. B Direct the security team to use a CloudFormation stack to create an AWS CodePipeline pipeline that builds new AMIs and places the latest AMI ARNs in an encrypted Amazon S3 object as part of the pipeline output. Instruct the developers to use a cross-stack reference within their own CloudFormation template to obtain the S3 object location and the most recent AMI ARNs.
  3. C Direct the security team to use Amazon EC2 Image Builder to create new AMIs and to place the AMI ARNs as parameters in AWS Systems Manager Parameter Store. Instruct the developers to specify a parameter of type SSM in their CloudFormation stack to obtain the most recent AMI ARNs from Parameter Store.
  4. D Direct the security team to use Amazon EC2 Image Builder to create new AMIs and to create an Amazon Simple Notification Service (Amazon SNS) topic so that every development team can receive notifications. When the development teams receive a notification, instruct them to write an AWS Lambda function that will update their CloudFormation stack with the most recent AMI ARNs.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một công ty có quy định mọi EC2 instance phải được launch từ AMI do security team sản xuất. Mỗi tháng, security team gửi email chứa danh sách AMI IDs mới nhất cho các development teams. Các dev teams sử dụng AWS CloudFormation để deploy ứng dụng, nhưng họ phải tìm kiếm email thủ công để lấy AMI IDs – điều này không hiệu quả. Một DevOps engineer muốn tự động hóa quy trình để security team cung cấp AMI IDs cho dev teams một cách scalable nhất (có khả năng mở rộng cao, không phụ thuộc thủ công, dễ quản lý hàng tháng).

Mục tiêu chính:

  • Tự động hóa việc tạo và chia sẻ AMI mới.
  • Dev teams dễ dàng lấy AMI IDs mới nhất trong CloudFormation mà không cần email.
  • Giải pháp phải scalable, tích hợp tốt với CloudFormation, và tuân thủ best practices AWS (cập nhật đến 2026, với EC2 Image Builder là công cụ chuẩn cho golden AMIs).

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Direct the security team to use Amazon EC2 Image Builder to create new AMIs and to place the AMI ARNs as parameters in AWS Systems Manager Parameter Store. Instruct the developers to specify a parameter of type SSM in their CloudFormation stack to obtain the most recent AMI ARNs from Parameter Store.

Lý do chọn đáp án này 🛠️:

  • Scalable cao nhất: EC2 Image Builder (ra mắt 2020, cập nhật 2026 với pipeline tự động, testing, distribution) cho phép security team tự động build AMI mới hàng tháng qua pipeline (recipe + infrastructure config), không cần thủ công.
  • AMI ARNs được lưu vào SSM Parameter Store dưới dạng parameter versioned (Standard/SecureString), hỗ trợ versioning để lấy "latest" dễ dàng (e.g., /security/latest-ami-us-east-1).
  • Dev teams chỉ cần khai báo SSM parameter type trong CloudFormation (sử dụng AWS::SSM::Parameter::Value<String> hoặc dynamic reference {{resolve:ssm:parameter-name}}), CloudFormation tự động fetch giá trị mới nhất lúc stack update – không cần code thêm, cross-stack tự động.
  • Best practices: An toàn (Parameter Store mã hóa mặc định), chi phí thấp, global (multi-region), không phụ thuộc email/S3/SNS. Hoàn hảo cho DevOps automation.

📋 Phân tích chi tiết tất cả các phương án

  • Phương án 1 [SAI]: Direct the security team to use CloudFormation to create new versions of the AMIs and to list the AMI ARNs in an encrypted Amazon S3 object as part of the stack’s Outputs section. Instruct the developers to use a cross-stack reference to load the encrypted S3 object and obtain the most recent AMI ARNs.
    ❌ Sai vì: CloudFormation không tạo "versions của AMIs" (AMI là resource độc lập, không phải stack output như vậy – CFN chỉ launch/copy AMI). Phải upload AMI ARNs vào S3 object encrypted, rồi dùng cross-stack reference để load object – phức tạp, không scalable (dev phải parse S3 object thủ công trong CFN, không tự động version). Không dùng Image Builder, vi phạm quy trình build AMI chuẩn. Rủi ro bảo mật cao khi load S3 động.

  • Phương án 2 [SAI]: Direct the security team to use a CloudFormation stack to create an AWS CodePipeline pipeline that builds new AMIs and places the latest AMI ARNs in an encrypted Amazon S3 object as part of the pipeline output. Instruct the developers to use a cross-stack reference within their own CloudFormation template to obtain the S3 object location and the most recent AMI ARNs.
    ❌ Sai vì: CodePipeline có thể build AMI nhưng quá phức tạp (cần custom actions để build AMI thay vì dùng Image Builder chuyên dụng). Lại lưu vào S3 object, dùng cross-stack reference để lấy location – không scalable (dev phải parse output, không version tự động, phụ thuộc stack security). Overhead cao (pipeline + S3 + CFN), không phải giải pháp "MOST scalable" so với SSM đơn giản.

  • Phương án 3 [ĐÚNG]: Direct the security team to use Amazon EC2 Image Builder to create new AMIs and to place the AMI ARNs as parameters in AWS Systems Manager Parameter Store. Instruct the developers to specify a parameter of type SSM in their CloudFormation stack to obtain the most recent AMI ARNs from Parameter Store.
    ✅ Đúng vì: Như giải thích ở trên – tối ưu, scalable, tự động hoàn toàn. Image Builder + SSM + CFN SSM type là stack AWS-native, hỗ trợ lifecycle policy (2026 updates cho Image Builder). Dev chỉ update stack là lấy AMI mới ngay!

  • Phương án 4 [SAI]: Direct the security team to use Amazon EC2 Image Builder to create new AMIs and to create an Amazon Simple Notification Service (Amazon SNS) topic so that every development team can receive notifications. When the development teams receive a notification, instruct them to write an AWS Lambda function that will update their CloudFormation stack with the most recent AMI ARNs.
    ❌ Sai vì: Image Builder tốt nhưng SNS + Lambda update stack thủ công – không scalable (mỗi team phải subscribe SNS, viết Lambda custom để update CFN stack via API – rủi ro lỗi, delay, multi-team coordination). Phụ thuộc human intervention khi nhận notify, quay về vấn đề "manual" tương tự email. Không tự động như SSM reference.

Kết luận 🚀: Giải pháp đúng tận dụng tích hợp native AWS (Image Builder → SSM → CFN), đảm bảo zero-touch cho dev teams, scalable toàn cầu!

Câu 346
An application runs on Amazon EC2 instances behind an Application Load Balancer (ALB). A DevOps engineer is using AWS CodeDeploy to release a new version. The deployment fails during the AllowTraffic lifecycle event, but a cause for the failure is not indicated in the deployment logs.

What would cause this?
  1. A The appspec.yml file contains an invalid script that runs in the AllowTraffic lifecycle hook.
  2. B The user who initiated the deployment does not have the necessary permissions to interact with the ALB.
  3. C The health checks specified for the ALB target group are misconfigured.
  4. D The CodeDeploy agent was not installed in the EC2 instances that are part of the ALB target group.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào quy trình triển khai blue/green deployment sử dụng AWS CodeDeploy kết hợp với Application Load Balancer (ALB) trên các instance Amazon EC2. Ứng dụng đang chạy ổn định, nhưng khi DevOps engineer triển khai phiên bản mới, quá trình thất bại cụ thể ở lifecycle event "AllowTraffic" – giai đoạn mà CodeDeploy cho phép ALB bắt đầu route traffic từ target group xanh (sản xuất hiện tại) sang target group mới (xanh mới).

Điểm quan trọng: Logs deployment của CodeDeploy không ghi nhận nguyên nhân thất bại cụ thể. Điều này gợi ý vấn đề nằm ở lớp ALB health checks hoặc tương tác với load balancer, chứ không phải lỗi script nội bộ CodeDeploy (vì lỗi script sẽ được log rõ ràng). Đây là tình huống phổ biến trong CodeDeploy với ALB integration (cập nhật đến AWS 2026, hỗ trợ EC2/On-Prem với ALB qua CodeDeploy agent v1.0+).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: The health checks specified for the ALB target group are misconfigured.

🛠️ Lý do chi tiết:

  • Trong blue/green deployment với ALB, lifecycle event AllowTraffic kích hoạt ALB route traffic đến target group mới. ALB sẽ kiểm tra health checks (như HTTP status code, path endpoint) trên các EC2 instance mới.
  • Nếu health checks bị cấu hình sai (ví dụ: path /health không tồn tại, timeout quá ngắn, hoặc threshold unhealthy cao), ALB sẽ đánh dấu instances là unhealthy, dẫn đến traffic không route được và deployment fail ở AllowTraffic.
  • Logs CodeDeploy không ghi chi tiết health check failure vì đây là lỗi bên ALB (kiểm tra qua CloudWatch metrics hoặc ALB console), không phải lỗi CodeDeploy agent. Đây là hành vi chuẩn theo tài liệu AWS mới nhất (2026), nơi ALB target group health checks là yếu tố quyết định thành bại ở giai đoạn này.

📋 Phân tích tất cả các phương án

Dưới đây là phân tích từng phương án một cách chi tiết, giữ nguyên văn bản gốc bằng tiếng Anh:

  • The appspec.yml file contains an invalid script that runs in the AllowTraffic lifecycle hook.
    ❌ Sai: appspec.yml chỉ hỗ trợ scripts cho các hook như BeforeInstall, AfterInstall, ApplicationStop... nhưng AllowTraffic không chạy script nào (nó chỉ notify ALB route traffic). Lỗi script ở hook khác sẽ được log rõ ràng trong CloudWatch/CodeDeploy logs, không khớp với mô tả "không indicated in the deployment logs". AWS CodeDeploy docs xác nhận AllowTraffic là lifecycle event "no-op" cho scripts.

  • The user who initiated the deployment does not have the necessary permissions to interact with the ALB.
    ❌ Sai: Quyền IAM cho deployment được kiểm tra ở BeforeBlockTraffic hoặc initiation phase. Nếu thiếu quyền ALB (như elasticloadbalancing:ModifyTargetGroup), deployment sẽ fail sớm hơn (trước AllowTraffic) và logs sẽ báo lỗi IAM cụ thể (e.g., AccessDenied). Không ảnh hưởng đến AllowTraffic sau khi traffic routing bắt đầu.

  • The health checks specified for the ALB target group are misconfigured.
    ✅ Đúng: Như giải thích ở trên, đây là nguyên nhân chính xác. Health checks fail dẫn đến ALB không approve traffic, gây failure silent ở logs CodeDeploy. Kiểm tra bằng ALB console (Targets tab) hoặc CloudWatch alarms TargetResponseTime, UnHealthyHostCount.

  • The CodeDeploy agent was not installed in the EC2 instances that are part of the ALB target group.
    ❌ Sai: Thiếu CodeDeploy agent gây fail ở DownloadBundle/Install phase (không deploy được artifacts), logs sẽ báo rõ "agent not found" hoặc "connection timeout". AllowTraffic chỉ chạy sau khi appspec hooks thành công và instances đã sẵn sàng, nên agent phải có mặt trước đó.

📘 Tài liệu tham khảo

Câu 347
A company has 20 service teams. Each service team is responsible for its own microservice. Each service team uses a separate AWS account for its microservice and a VPC with the 192.168.0.0/22 CIDR block. The company manages the AWS accounts with AWS Organizations.

Each service team hosts its microservice on multiple Amazon EC2 instances behind an Application Load Balancer. The microservices communicate with each other across the public internet. The company’s security team has issued a new guideline that all communication between microservices must use HTTPS over private network connections and cannot traverse the public internet.

A DevOps engineer must implement a solution that fulfills these obligations and minimizes the number of changes for each service team.

Which solution will meet these requirements?
  1. A Create a new AWS account in AWS Organizations. Create a VPC in this account, and use AWS Resource Access Manager to share the private subnets of this VPC with the organization. Instruct the service teams to launch a new Network Load Balancer (NLB) and EC2 instances that use the shared private subnets. Use the NLB DNS names for communication between microservices.
  2. B Create a Network Load Balancer (NLB) in each of the microservice VPCs. Use AWS PrivateLink to create VPC endpoints in each AWS account for the NLBs. Create subscriptions to each VPC endpoint in each of the other AWS accounts. Use the VPC endpoint DNS names for communication between microservices.
  3. C Create a Network Load Balancer (NLB) in each of the microservice VPCs. Create VPC peering connections between each of the microservice VPCs. Update the route tables for each VPC to use the peering links. Use the NLB DNS names for communication between microservices.
  4. D Create a new AWS account in AWS Organizations. Create a transit gateway in this account, and use AWS Resource Access Manager to share the transit gateway with the organization. In each of the microservice VPCs, create a transit gateway attachment to the shared transit gateway. Update the route tables of each VPC to use the transit gateway. Create a Network Load Balancer (NLB) in each of the microservice VPCs. Use the NLB DNS names for communication between microservices.
Xem giải thích

🧩 Giải thích chi tiết nội dung câu hỏi

Câu hỏi mô tả một công ty có 20 đội ngũ dịch vụ (service teams), mỗi đội quản lý một microservice riêng biệt trong AWS account riêng và VPC với CIDR block 192.168.0.0/22. Tất cả accounts được quản lý qua AWS Organizations. Hiện tại, các microservice chạy trên nhiều EC2 instances phía sau Application Load Balancer (ALB), và chúng giao tiếp lẫn nhau qua public internet (không an toàn).

🛡️ Yêu cầu mới từ security team: Tất cả giao tiếp giữa microservices phải dùng HTTPS qua private network connections, không được đi qua public internet.

DevOps engineer cần implement giải pháp đáp ứng yêu cầu này, đồng thời tối thiểu hóa thay đổi (minimize changes) cho từng service team (nghĩa là tránh phải refactor lớn code, cấu hình route phức tạp, hoặc migrate resources nhiều).

🔑 Thách thức chính:

  • 20 VPCs/accounts riêng biệt, cùng CIDR block → Không thể dùng các giải pháp yêu cầu CIDR non-overlapping (như VPC Peering).
  • Cần private connectivity cho HTTPS (app layer), không expose public.
  • Scalable với multi-account, dễ quản lý qua Organizations.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Create a Network Load Balancer (NLB) in each of the microservice VPCs. Use AWS PrivateLink to create VPC endpoints in each AWS account for the NLBs. Create subscriptions to each VPC endpoint in each of the other AWS accounts. Use the VPC endpoint DNS names for communication between microservices.

Lý do chọn ✅:

  • AWS PrivateLink là giải pháp lý tưởng cho service-to-service private access qua AWS backbone network, không qua public internet, hỗ trợ HTTPS (TLS termination tại LB hoặc app).
  • Mỗi team chỉ cần: Tạo NLB (private/internal) trong VPC của mình để expose microservice, sau đó tạo VPC Endpoint Service (cho NLB). Các team khác tạo VPC Endpoint (Interface) kết nối đến service đó và subscribe (accept connection).
  • Sử dụng VPC Endpoint DNS names (private-powered DNS) để giao tiếp → Clients resolve DNS private, traffic giữ trong AWS network.
  • Minimize changes: Không cần thay đổi route tables, CIDR overlap không vấn đề (PrivateLink dùng regional endpoints). Teams chỉ thêm NLB + endpoints, giữ EC2/ALB hiện tại (NLB proxy đến ALB nếu cần).
  • Scalable với 20 accounts: Organizations + RAM không cần, chỉ cần endpoint cross-account.

📋 Phân tích tất cả các phương án

  • Phương án 1 [SAI] ❌
    Create a new AWS account in AWS Organizations. Create a VPC in this account, and use AWS Resource Access Manager to share the private subnets of this VPC with the organization. Instruct the service teams to launch a new Network Load Balancer (NLB) and EC2 instances that use the shared private subnets. Use the NLB DNS names for communication between microservices.
    Giải thích sai ❌: Giải pháp dùng RAM để share subnets từ VPC trung tâm, yêu cầu teams migrate EC2 và NLB vào shared subnets (cross-account launch phức tạp, cần IAM roles đặc biệt, security groups riêng). Thay đổi lớn cho teams (relocate instances), không minimize. NLB DNS chỉ accessible trong shared VPC, nhưng với 20 teams, traffic vẫn cần routing phức tạp. Không tận dụng PrivateLink thực sự, và CIDR overlap với spokes có thể gây issue khi share.

  • Phương án 2 [ĐÚNG] ✅
    Create a Network Load Balancer (NLB) in each of the microservice VPCs. Use AWS PrivateLink to create VPC endpoints in each AWS account for the NLBs. Create subscriptions to each VPC endpoint in each of the other AWS accounts. Use the VPC endpoint DNS names for communication between microservices.
    Giải thích đúng ✅: Như phần trên, PrivateLink enable private HTTPS connectivity cross-VPC/account mà không expose public, dùng NLB làm endpoint service (hỗ trợ L4 TLS passthrough cho HTTPS). DNS resolution private, zero-trust model. Tối ưu minimize changes: Teams giữ VPC/EC2 hiện tại, chỉ thêm NLB + endpoints (~few clicks). Hỗ trợ multi-account qua Organizations, scalable đến hàng nghìn endpoints (cập nhật 2024+).

  • Phương án 3 [SAI] ❌
    Create a Network Load Balancer (NLB) in each of the microservice VPCs. Create VPC peering connections between each of the microservice VPCs. Update the route tables for each VPC to use the peering links. Use the NLB DNS names for communication between microservices.
    Giải thích sai ❌: VPC Peering yêu cầu CIDR non-overlapping (tất cả VPC dùng 192.168.0.0/22 → overlap, peering thất bại!). Cần full-mesh 190+ peerings (không scalable với 20 VPCs), update route tables thủ công ở mọi VPC (thay đổi lớn). NLB DNS cần private DNS resolution qua peering, nhưng vẫn expose nếu NLB public. Không private-by-default như PrivateLink.

  • Phương án 4 [SAI] ❌
    Create a new AWS account in AWS Organizations. Create a transit gateway in this account, and use AWS Resource Access Manager to share the transit gateway with the organization. In each of the microservice VPCs, create a transit gateway attachment to the shared transit gateway. Update the route tables of each VPC to use the transit gateway. Create a Network Load Balancer (NLB) in each of the microservice VPCs. Use the NLB DNS names for communication between microservices.
    Giải thích sai ❌: Transit Gateway (TGW) tốt cho hub-spoke connectivity private (RAM share ok), nhưng yêu cầu tạo attachments + update route tables ở mọi VPC (thay đổi lớn, O(n) config). NLB DNS accessible qua TGW, nhưng nếu NLB public thì vẫn rủi ro (cần internal NLB). Phức tạp hơn PrivateLink (TGW cho network layer, không service-specific), chi phí cao hơn, không minimize changes. CIDR overlap ok với TGW (dùng segmentations), nhưng không phải giải pháp tối ưu.

📘 Tài liệu tham khảo (AWS Docs cập nhật 2024-2026)

🛠️ Khuyến nghị thực tế: Test với AWS VPC Reachability Analyzer để verify private paths sau implement!

Câu 348 Chọn nhiều đáp án
An Amazon EC2 instance is running in a VPC and needs to download an object from a restricted Amazon S3 bucket. When the DevOps engineer tries to download the object, an AccessDenied error is received.

What are the possible causes for this error? (Choose two.)
  1. A The S3 bucket default encryption is enabled.
  2. B There is an error in the S3 bucket policy.
  3. C The object has been moved to S3 Glacier.
  4. D There is an error in the IAM role configuration.
  5. E S3 Versioning is enabled.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm AWS

📘 Giải thích nội dung câu hỏi:
Câu hỏi mô tả tình huống một instance Amazon EC2 đang chạy trong VPC (Virtual Private Cloud) cần tải xuống một object từ một S3 bucket bị hạn chế (restricted Amazon S3 bucket). Khi DevOps engineer thử tải, nhận lỗi AccessDenied. Câu hỏi yêu cầu chọn hai nguyên nhân có thể gây ra lỗi này.

🛠️ Bối cảnh kỹ thuật:

  • EC2 instance thường sử dụng IAM role (thông qua instance profile) để truy cập S3 mà không cần hardcode credentials.
  • S3 bucket "restricted" nghĩa là có bucket policy hoặc ACL giới hạn quyền truy cập.
  • Lỗi AccessDenied (HTTP 403) xảy ra khi AWS từ chối quyền thực hiện hành động s3:GetObject, có thể do vấn đề ở IAM policy, bucket policy, VPC endpoint policy (nếu dùng VPC endpoint cho S3), hoặc các yếu tố khác.
  • Không liên quan đến kết nối mạng (vì không phải lỗi timeout hay DNS), mà thuần túy quyền truy cập.
    (Kiến thức cập nhật AWS 2024-2026: Không thay đổi lớn ở S3 IAM/bucket policy; tham khảo AWS S3 Troubleshooting Access Denied: https://docs.aws.amazon.com/AmazonS3/latest/userguide/troubleshoot-403-errors.html)

✅ Đáp án đúng (Chọn TWO):

  • There is an error in the S3 bucket policy.
  • There is an error in the IAM role configuration.

🧠 Lý do chọn đáp án đúng:
Bucket policy và IAM role là hai yếu tố chính quyết định quyền truy cập S3 từ EC2. Nếu bucket policy sai (ví dụ: Deny explicit hoặc Condition không khớp VPC/Principal), hoặc IAM role thiếu policy s3:GetObject cho bucket/object cụ thể, sẽ dẫn đến AccessDenied ngay lập tức. Đây là hai nguyên nhân phổ biến nhất trong kịch bản VPC + restricted bucket.

🔍 Giải thích tất cả các phương án (Đúng/Sai):

  • ❌ The S3 bucket default encryption is enabled.
    Phương án này SAI. Bucket default encryption (SSE-S3 hoặc SSE-KMS) chỉ yêu cầu quyền kms:Decrypt nếu dùng KMS, nhưng không gây AccessDenied nếu IAM/bucket policy cho phép đọc object. Lỗi sẽ là KMSAccessDeniedException riêng biệt nếu thiếu quyền KMS, không phải AccessDenied chung. (Tham khảo: AWS S3 Encryption docs - https://docs.aws.amazon.com/AmazonS3/latest/userguide/bucket-encryption.html)

  • ✅ There is an error in the S3 bucket policy.
    Phương án này ĐÚNG. Bucket policy kiểm soát quyền truy cập từ Principal (như IAM role của EC2). Nếu policy có lỗi (ví dụ: Deny VPC source, sai ARN, hoặc Condition không khớp), EC2 sẽ bị chặn dù IAM role đúng. Đây là nguyên nhân phổ biến với "restricted bucket". (Tham khảo: AWS Bucket Policy Troubleshooting - https://docs.aws.amazon.com/AmazonS3/latest/userguide/example-bucket-policies.html)

  • ❌ The object has been moved to S3 Glacier.
    Phương án này SAI. Nếu object ở storage class Glacier (hoặc Deep Archive), lỗi sẽ là RestoreObjectInProgress hoặc NoSuchKey sau khi restore, KHÔNG PHẢI AccessDenied. AccessDenied chỉ xảy ra khi quyền bị từ chối trước khi kiểm tra storage class. (Tham khảo: AWS S3 Storage Classes - https://docs.aws.amazon.com/AmazonS3/latest/userguide/storage-class-intro.html)

  • ✅ There is an error in the IAM role configuration.
    Phương án này ĐÚNG. EC2 dùng IAM role (qua Instance Profile) để generate temporary credentials. Nếu role thiếu policy s3:GetObject (Resource: arn:aws:s3:::bucket/object), hoặc sai Trust Policy (không trust EC2 service), STS sẽ không cấp token hợp lệ → AccessDenied. Phổ biến nhất ở setup VPC. (Tham khảo: IAM Roles for EC2 - https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-roles-for-amazon-ec2.html)

  • ❌ S3 Versioning is enabled.
    Phương án này SAI. Versioning chỉ tạo nhiều version object khi PUT, không ảnh hưởng đến quyền GET. AccessDenied vẫn do policy, không liên quan versioning. Lỗi versioning thường là NoSuchVersion nếu chỉ định version sai. (Tham khảo: AWS S3 Versioning - https://docs.aws.amazon.com/AmazonS3/latest/userguide/Versioning.html)

💡 Lời khuyên DevOps:
Để debug, dùng AWS IAM Policy Simulator 🧪 kiểm tra IAM role + bucket policy kết hợp, hoặc S3 Access Analyzer 🔍 để phát hiện misconfigs. Nếu dùng VPC Endpoint, kiểm tra endpoint policy nữa! (Nguồn: AWS Well-Architected Framework - Reliability Pillar, 2024)

Câu 349
A company wants to use a grid system for a proprietary enterprise in-memory data store on top of AWS. This system can run in multiple server nodes in any Linux-based distribution. The system must be able to reconfigure the entire cluster every time a node is added or removed. When adding or removing nodes, an /etc/cluster/nodes.config file must be updated, listing the IP addresses of the current node members of that cluster.

The company wants to automate the task of adding new nodes to a cluster.

What can a DevOps engineer do to meet these requirements?
  1. A Use AWS OpsWorks Stacks to layer the server nodes of that cluster. Create a Chef recipe that populates the content of the /etc/cluster/nodes.config file and restarts the service by using the current members of the layer. Assign that recipe to the Configure lifecycle event.
  2. B Put the file nodes.config in version control. Create an AWS CodeDeploy deployment configuration and deployment group based on an Amazon EC2 tag value for the cluster nodes. When adding a new node to the cluster, update the file with all tagged instances, and make a commit in version control. Deploy the new file and restart the services.
  3. C Create an Amazon S3 bucket and upload a version of the /etc/cluster/nodes.config file. Create a crontab script that will poll for that S3 file and download it frequently. Use a process manager, such as Monit or systemd, to restart the cluster services when it detects that the new file was modified. When adding a node to the cluster, edit the file’s most recent members. Upload the new file to the S3 bucket.
  4. D Create a user data script that lists all members of the current security group of the cluster and automatically updates the /etc/cluster/nodes.config file whenever a new instance is added to the cluster.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một hệ thống grid system cho enterprise in-memory data store độc quyền chạy trên các node server Linux trên AWS. Hệ thống yêu cầu tái cấu hình toàn bộ cluster mỗi khi thêm hoặc xóa node, bằng cách cập nhật file /etc/cluster/nodes.config chứa danh sách IP addresses của các node hiện tại trong cluster.
Mục tiêu chính: Tự động hóa việc thêm node mới vào cluster một cách hiệu quả, đảm bảo file config luôn được cập nhật động và dịch vụ được restart kịp thời.
🛠️ Yêu cầu DevOps: Cần giải pháp tự động, scalable, tích hợp tốt với AWS để xử lý thay đổi cluster động mà không cần can thiệp thủ công nhiều.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Use AWS OpsWorks Stacks to layer the server nodes of that cluster. Create a Chef recipe that populates the content of the /etc/cluster/nodes.config file and restarts the service by using the current members of the layer. Assign that recipe to the Configure lifecycle event.

Lý do chọn đáp án này (dựa trên AWS best practices cập nhật đến 2026):

  • AWS OpsWorks Stacks (nay tích hợp sâu với Chef/AWS Systems Manager) lý tưởng cho quản lý configuration của các layer server nodes trong cluster.
  • Chef recipe trong Configure lifecycle event tự động chạy mỗi khi instance được thêm/xóa vào layer, lấy danh sách current members (IPs) từ OpsWorks API và cập nhật file /etc/cluster/nodes.config, sau đó restart service.
  • Giải pháp tự động hoàn toàn, idempotent (chạy nhiều lần an toàn), và scale theo cluster mà không cần polling hay manual trigger.
    📘 Tài liệu tham khảo: AWS OpsWorks Stacks Documentation - Lifecycle Events & Chef Recipes in OpsWorks (cập nhật 2025).

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng phương án một cách rõ ràng. Tôi giữ nguyên nội dung văn bản gốc bằng tiếng Anh, nhưng giải thích đúng/sai hoàn toàn bằng tiếng Việt với lý do kỹ thuật cụ thể:

  • ✅ Phương án ĐÚNG (như trên):
    Use AWS OpsWorks Stacks to layer the server nodes of that cluster. Create a Chef recipe that populates the content of the /etc/cluster/nodes.config file and restarts the service by using the current members of the layer. Assign that recipe to the Configure lifecycle event.
    🟢 Tại sao đúng? OpsWorks tự động detect thay đổi layer (add/remove node), trigger Configure event để Chef recipe query danh sách IPs hiện tại từ metadata layer, cập nhật file config và restart service. Hoàn hảo cho cluster động, không lag, không phụ thuộc external polling.

  • ❌ Phương án SAI 1:
    Put the file nodes.config in version control. Create an AWS CodeDeploy deployment configuration and deployment group based on an Amazon EC2 tag value for the cluster nodes. When adding a new node to the cluster, update the file with all tagged instances, and make a commit in version control. Deploy the new file and restart the services.
    🔴 Tại sao sai? Yêu cầu manual steps (update file, commit version control, trigger deploy) mỗi khi add node – không tự động hóa hoàn toàn. CodeDeploy phù hợp deploy app, không phải config động cluster. Dễ race condition nếu nhiều node thay đổi cùng lúc, và không scale tốt cho reconfigure realtime.

  • ❌ Phương án SAI 2:
    Create an Amazon S3 bucket and upload a version of the /etc/cluster/nodes.config file. Create a crontab script that will poll for that S3 file and download it frequently. Use a process manager, such as Monit or systemd, to restart the cluster services when it detects that the new file was modified. When adding a node to the cluster, edit the file’s most recent members. Upload the new file to the S3 bucket.
    🔴 Tại sao sai? Polling crontab (kiểm tra S3 định kỳ) gây lag (có thể vài phút), tốn resource (network/CPU), và vẫn cần manual edit/upload file khi add node. Không idempotent, dễ lỗi nếu S3 versioning conflict. Không phải best practice cho cluster config động (AWS khuyến nghị event-driven hơn polling).

  • ❌ Phương án SAI 3:
    Create a user data script that lists all members of the current security group of the cluster and automatically updates the /etc/cluster/nodes.config file whenever a new instance is added to the cluster.
    🔴 Tại sao sai? User data script chỉ chạy một lần lúc launch instance, không trigger lại khi cluster thay đổi (add/remove node khác). Security Group không expose IP list dễ dàng qua API đơn giản, và script không tự động update existing nodes. Không xử lý remove node hoặc reconfigure toàn cluster.

🏆 Kết luận & Best Practice

Giải pháp OpsWorks là optimal vì tận dụng lifecycle events native AWS cho automation cluster config. Trong thực tế DevOps (2026), kết hợp với AWS Systems Manager (SSM) hoặc EC2 Fleet để scale cluster.
🔗 Nguồn bổ sung: AWS DevOps Best Practices - Configuration Management & OpsWorks for Cluster Management.

Câu 350 Chọn nhiều đáp án
A DevOps engineer is working on a data archival project that requires the migration of on-premises data to an Amazon S3 bucket. The DevOps engineer develops a script that incrementally archives on-premises data that is older than 1 month to Amazon S3. Data that is transferred to Amazon S3 is deleted from the on-premises location. The script uses the S3 PutObject operation.

During a code review, the DevOps engineer notices that the script does not verify whether the data was successfully copied to Amazon S3. The DevOps engineer must update the script to ensure that data is not corrupted during transmission. The script must use MD5 checksums to verify data integrity before the on-premises data is deleted.

Which solutions for the script will meet these requirements? (Choose two.)
  1. A Check the returned response for the VersionId. Compare the returned VersionId against the MD5 checksum.
  2. B Include the MD5 checksum within the Content-MD5 parameter. Check the operation call’s return status to find out if an error was returned.
  3. C Include the checksum digest within the tagging parameter as a URL query parameter.
  4. D Check the returned response for the ETag. Compare the returned ETag against the MD5 checksum.
  5. E Include the checksum digest within the Metadata parameter as a name-value pair. After upload, use the S3 HeadObject operation to retrieve metadata from the object.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi xoay quanh một dự án lưu trữ dữ liệu (data archival) trên AWS, nơi DevOps engineer cần di chuyển dữ liệu on-premises cũ hơn 1 tháng lên Amazon S3 bucket bằng script sử dụng S3 PutObject operation. Script hiện tại chỉ upload và xóa dữ liệu on-premises mà không verify tính toàn vẹn dữ liệu (data integrity) trong quá trình truyền, dẫn đến rủi ro dữ liệu bị corrupt.

📌 Yêu cầu cụ thể: Cập nhật script để sử dụng MD5 checksums nhằm xác nhận dữ liệu đã được copy thành công lên S3 trước khi xóa dữ liệu on-premises. Cần chọn TWO giải pháp phù hợp nhất từ các lựa chọn.

🛠️ Bối cảnh AWS cập nhật đến 2026: S3 hỗ trợ MD5 checksum qua header Content-MD5 (S3 tự verify payload) và ETag (thường là MD5 hex cho single-part upload). Không có thay đổi lớn trong PutObject API liên quan đến integrity check này (xem AWS S3 API Reference 2024-2026).

✅ Đáp án đúng (Chọn TWO)

Hai giải pháp đúng là:

  • Include the MD5 checksum within the Content-MD5 parameter. Check the operation call’s return status to find out if an error was returned.
  • Check the returned response for the ETag. Compare the returned ETag against the MD5 checksum.

Lý do lựa chọn 📘:

  • Những phương án này trực tiếp sử dụng MD5 để verify integrity trong quá trình upload PutObject, đảm bảo dữ liệu không bị corrupt trước khi delete. Content-MD5 cho phép S3 server-side validation ngay lập tức (HTTP 200 OK nếu match, 400 Bad Digest nếu không). ETag trả về từ response thường chính là MD5 hex của object (cho non-multipart upload), dễ so sánh client-side. Đây là best practice theo AWS Well-Architected Framework (Reliability Pillar).

🔍 Giải thích chi tiết từng phương án

Dưới đây là phân tích từng lựa chọn (giữ nguyên văn bản gốc tiếng Anh), với lý do đúng/sai dựa trên AWS S3 API:

  • ❌ [SAI] Check the returned response for the VersionId. Compare the returned VersionId against the MD5 checksum.
    Giải thích: VersionId chỉ dùng cho S3 versioning (xác định phiên bản object khi bucket enable versioning), không liên quan đến checksum hoặc integrity check. So sánh VersionId với MD5 là vô nghĩa, vì VersionId là UUID-like string, không phải hash digest. Không verify được dữ liệu corrupt.

  • ✅ [ĐÚNG] Include the MD5 checksum within the Content-MD5 parameter. Check the operation call’s return status to find out if an error was returned.
    Giải thích: Đây là cách chuẩn và hiệu quả nhất. Tính MD5 của file on-premises, gửi qua header Content-MD5 (Base64-encoded). S3 sẽ verify payload server-side: nếu match → trả HTTP 200 OK; nếu không → 400 Bad Digest error. Script check return status (error hay không) để confirm trước khi delete. Hỗ trợ full cho PutObject, kể cả large objects (multipart cần xử lý riêng).

  • ❌ [SAI] Include the checksum digest within the tagging parameter as a URL query parameter.
    Giải thích: S3 tagging dùng cho metadata management và cost allocation (key-value pairs), không phải để verify integrity. Không có cơ chế server-side validation checksum qua tagging. Query parameter cũng không áp dụng cho PutObject tagging (tagging dùng x-amz-tagging header). Cách này không đảm bảo dữ liệu không corrupt.

  • ✅ [ĐÚNG] Check the returned response for the ETag. Compare the returned ETag against the MD5 checksum.
    Giải thích: PutObject response luôn trả ETag header, thường là MD5 hex (double-quoted, ví dụ: "d41d8cd98f00b204e9800998ecf8427e") cho single-part upload. Script tính MD5 local, so sánh trực tiếp với ETag → verify integrity client-side. Rất đáng tin cậy cho non-multipart (multipart ETag khác format). Nếu không match, dữ liệu corrupt → không delete.

  • ❌ [SAI] Include the checksum digest within the Metadata parameter as a name-value pair. After upload, use the S3 HeadObject operation to retrieve metadata from the object.
    Giải thích: Metadata (user-defined via x-amz-meta-*) chỉ lưu thông tin kèm object, không verify nội dung payload. Bạn put MD5 vào metadata rồi HeadObject để đọc lại, nhưng điều này chỉ confirm metadata được lưu (không check dữ liệu corrupt trong transmission). Thêm API call (HeadObject) làm chậm script, không phải giải pháp trực tiếp cho integrity check theo yêu cầu.

📚 Tài liệu tham khảo (AWS Official - Cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần code sample, hỏi thêm nhé!