Ngân hàng đề — AWS Certified DevOps Engineer Professional

Tìm thấy 681 câu.

Câu 381
A DevOps engineer needs to configure a blue/green deployment for an existing three-tier application. The application runs on Amazon EC2 instances and uses an Amazon RDS database. The EC2 instances run behind an Application Load Balancer (ALB) and are in an Auto Scaling group.

The DevOps engineer has created a launch template and an Auto Scaling group for the blue environment. The DevOps engineer also has created a launch template and an Auto Scaling group for the green environment. Each Auto Scaling group deploys to a matching blue or green target group. The target group also specifies which software, blue or green, gets loaded on the EC2 instances. The ALB can be configured to send traffic to the blue environment’s target group or the green environment’s target group. An Amazon Route 53 record for www.example.com points to the ALB.

The deployment must move traffic all at once between the software on the blue environment’s EC2 instances to the newly deployed software on the green environment’s EC2 instances.

What should the DevOps engineer do to meet these requirements?
  1. A Start a rolling restart of the Auto Scaling group for the green environment to deploy the new software on the green environment’s EC2 instances. When the rolling restart is complete, use an AWS CLI command to update the ALB to send traffic to the green environment’s target group.
  2. B Use an AWS CLI command to update the ALB to send traffic to the green environment’s target group. Then start a rolling restart of the Auto Scaling group for the green environment to deploy the new software on the green environment’s EC2 instances.
  3. C Update the launch template to deploy the green environment’s software on the blue environment’s EC2 instances. Keep the target groups and Auto Scaling groups unchanged in both environments. Perform a rolling restart of the blue environment’s EC2 instances.
  4. D Start a rolling restart of the Auto Scaling group for the green environment to deploy the new software on the green environment’s EC2 instances. When the rolling restart is complete, update the Route 53 DNS to point to the green environment’s endpoint on the ALB.
Xem giải thích

🧩 Giải thích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai blue/green deployment cho một ứng dụng 3-tier (presentation, application, data) đang chạy trên Amazon EC2 instances, sử dụng Amazon RDS làm database, Application Load Balancer (ALB) để phân tải, và Auto Scaling Group (ASG) để quản lý instances.

  • Môi trường hiện tại (blue): ASG với launch template cũ, instances chạy phần mềm hiện tại, kết nối với target group blue.
  • Môi trường mới (green): Đã tạo launch template và ASG riêng, target group green tương ứng, launch template chỉ định phần mềm mới (green software).
  • ALB: Có thể cấu hình listener rule để gửi traffic đến target group blue hoặc green (switch all-at-once).
  • Route 53: Record www.example.com trỏ trực tiếp đến ALB (không phải endpoint riêng cho blue/green).
  • Yêu cầu chính: Di chuyển toàn bộ traffic (all at once) từ phần mềm cũ trên blue sang phần mềm mới trên green, đảm bảo zero-downtime và không ảnh hưởng RDS (vì RDS là shared).

Mục tiêu là deploy phần mềm mới lên green trước, test nếu cần, rồi switch traffic tại ALB listener để tránh downtime. Đây là best practice cho blue/green với ASG + ALB theo tài liệu AWS mới nhất (2024-2026), sử dụng rolling updates trên ASG để deploy mà không gián đoạn. 📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Start a rolling restart of the Auto Scaling group for the green environment to deploy the new software on the green environment’s EC2 instances. When the rolling restart is complete, use an AWS CLI command to update the ALB to send traffic to the green environment’s target group.

🛠️ Lý do đúng:

  • Bước 1: Thực hiện rolling restart trên ASG green (sử dụng aws autoscaling start-instance-refresh hoặc tương tự) để instances green load phần mềm mới từ launch template, đảm bảo green sẵn sàng hoàn toàn với software mới trước khi nhận traffic. Rolling restart tránh downtime ở green (terminate + launch instances dần dần).
  • Bước 2: Sau khi green ổn định (health checks pass trên target group green), dùng AWS CLI (aws elbv2 modify-rule hoặc update-listener) để switch listener rule của ALB từ target group blue sang green all at once → traffic chuyển ngay lập tức, zero-downtime.
  • Phù hợp yêu cầu "move traffic all at once" và giữ nguyên cấu trúc blue/green riêng biệt. Đây là quy trình chuẩn AWS cho blue/green manual deployment với ASG (không dùng CodeDeploy tự động).

📋 Giải thích tất cả các phương án (đúng/sai)

  • Start a rolling restart of the Auto Scaling group for the green environment to deploy the new software on the green environment’s EC2 instances. When the rolling restart is complete, use an AWS CLI command to update the ALB to send traffic to the green environment’s target group.
    ✅ Đúng (như đã giải thích ở trên). Quy trình an toàn: Deploy trước → Switch sau → All-at-once tại ALB. 🟢 Hoàn hảo cho zero-downtime!

  • Use an AWS CLI command to update the ALB to send traffic to the green environment’s target group. Then start a rolling restart of the Auto Scaling group for the green environment to deploy the new software on the green environment’s EC2 instances.
    ❌ Sai: Switch traffic trước khi deploy → green instances vẫn chạy phần mềm cũ (hoặc empty), gây downtime hoặc serve wrong version. Vi phạm nguyên tắc blue/green (deploy inactive environment trước). 🚫 Rủi ro cao!

  • Update the launch template to deploy the green environment’s software on the blue environment’s EC2 instances. Keep the target groups and Auto Scaling groups unchanged in both environments. Perform a rolling restart of the blue environment’s EC2 instances.
    ❌ Sai: Deploy green software lên blue ASG → Không còn blue/green thực sự (lẫn lộn environments), mất khả năng rollback nhanh bằng switch ALB. Phải recreate launch template và refresh ASG blue, gây phức tạp và rủi ro nếu fail. Không match "newly deployed software on the green environment". 🔄 Không phải blue/green chuẩn!

  • Start a rolling restart of the Auto Scaling group for the green environment to deploy the new software on the green environment’s EC2 instances. When the rolling restart is complete, update the Route 53 DNS to point to the green environment’s endpoint on the ALB.
    ❌ Sai: Route 53 không switch target group – nó chỉ trỏ ALB DNS (chung cho blue/green). Câu hỏi xác nhận ALB listener switch TG, không có "green endpoint riêng". Update R53 gây DNS propagation delay (phút đến giờ), không "all at once". Dùng ALB rule nhanh hơn (giây). 🌐 Sai vị trí switch!

🧠 Lưu ý pro tip: Trong thực tế 2026, có thể automate bằng AWS CodeDeploy blue/green hoặc Lambda + EventBridge, nhưng câu hỏi yêu cầu manual CLI → option đúng là optimal. Test bằng ALB health checks trước switch để đảm bảo! 🚀

Câu 382 Chọn nhiều đáp án
A company is building a new pipeline by using AWS CodePipeline and AWS CodeBuild in a build account. The pipeline consists of two stages. The first stage is a CodeBuild job to build and package an AWS Lambda function. The second stage consists of deployment actions that operate on two different AWS accounts: a development environment account and a production environment account. The deployment stages use the AWS CloudFormation action that CodePipeline invokes to deploy the infrastructure that the Lambda function requires.

A DevOps engineer creates the CodePipeline pipeline and configures the pipeline to encrypt build artifacts by using the AWS Key Management Service (AWS KMS) AWS managed key for Amazon S3 (the aws/s3 key). The artifacts are stored in an S3 bucket. When the pipeline runs, the CloudFormation actions fail with an access denied error.

Which combination of actions must the DevOps engineer perform to resolve this error? (Choose two.)
  1. A Create an S3 bucket in each AWS account for the artifacts. Allow the pipeline to write to the S3 buckets. Create a CodePipeline S3 action to copy the artifacts to the S3 bucket in each AWS account. Update the CloudFormation actions to reference the artifacts S3 bucket in the production account.
  2. B Create a customer managed KMS key. Configure the KMS key policy to allow the IAM roles used by the CloudFormation action to perform decrypt operations. Modify the pipeline to use the customer managed KMS key to encrypt artifacts.
  3. C Create an AWS managed KMS key. Configure the KMS key policy to allow the development account and the production account to perform decrypt operations. Modify the pipeline to use the KMS key to encrypt artifacts.
  4. D In the development account and in the production account, create an IAM role for CodePipeline. Configure the roles with permissions to perform CloudFormation operations and with permissions to retrieve and decrypt objects from the artifacts S3 bucket. In the CodePipeline account, configure the CodePipeline CloudFormation action to use the roles.
  5. E In the development account and in the production account, create an IAM role for CodePipeline. Configure the roles with permissions to perform CloudFormation operations and with permissions to retrieve and decrypt objects from the artifacts S3 bucket. In the CodePipeline account, modify the artifacts S3 bucket policy to allow the roles access. Configure the CodePipeline CloudFormation action to use the roles.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một pipeline AWS CodePipeline được xây dựng trong build account, sử dụng AWS CodeBuild để build và package một AWS Lambda function. Pipeline có hai stage chính:

  • Stage 1: CodeBuild job build và package Lambda.
  • Stage 2: Deployment qua AWS CloudFormation actions đến hai account khác: development account và production account. CloudFormation deploy infrastructure cần thiết cho Lambda.

DevOps engineer đã cấu hình pipeline encrypt artifacts bằng AWS KMS key managed bởi AWS cho S3 (aws/s3 key). Artifacts lưu trong S3 bucket ở build account. Khi chạy pipeline, CloudFormation actions fail với lỗi access denied.

Nguyên nhân gốc rễ ❌:

  • aws/s3 KMS key là AWS-managed key, không hỗ trợ cross-account decryption dễ dàng. Key policy của nó chỉ cho phép S3 service trong cùng account/region decrypt.
  • Cross-account deployment (dev/prod accounts) không thể truy cập/decrypt artifacts từ S3 bucket ở build account.
  • Cần giải quyết bằng cách: (1) Cho phép cross-account access vào S3 + decrypt KMS, hoặc (2) Sử dụng KMS key tùy chỉnh với policy phù hợp.

Yêu cầu chọn 2 actions để resolve lỗi này. Kiến thức dựa trên AWS docs cập nhật 2024-2026: CodePipeline cross-account artifacts yêu cầu explicit IAM roles + S3 bucket policy + KMS grants/policy (không thay đổi lớn từ re:Post và docs mới nhất).

✅ Đáp án đúng (Chọn 2)

Dựa trên best practices AWS cho cross-account CodePipeline artifacts:

  • Create a customer managed KMS key. Configure the KMS key policy to allow the IAM roles used by the CloudFormation action to perform decrypt operations. Modify the pipeline to use the customer managed KMS key to encrypt artifacts.
  • In the development account and in the production account, create an IAM role for CodePipeline. Configure the roles with permissions to perform CloudFormation operations and with permissions to retrieve and decrypt objects from the artifacts S3 bucket. In the CodePipeline account, modify the artifacts S3 bucket policy to allow the roles access. Configure the CodePipeline CloudFormation action to use the roles.

Lý do chọn 🛠️:

  • Customer managed KMS key thay thế aws/s3 key: Cho phép tùy chỉnh key policy grant kms:Decrypt cho IAM roles ở dev/prod accounts (cross-account). Pipeline update encryption → artifacts decrypt được.
  • IAM roles ở dev/prod + S3 bucket policy: Role có policy cho s3:GetObject, kms:Decrypt + CloudFormation perms. Bucket policy ở build account grant s3:GetObject cho roles cross-account. Cross-account role assumption qua CloudFormation action config → resolve access denied hoàn toàn.
  • Kết hợp 2 actions này fix cả S3 access lẫn KMS decrypt mà không cần copy artifacts (tiết kiệm, an toàn).

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng lựa chọn một, giữ nguyên văn bản gốc tiếng Anh. Sử dụng ✅ cho đúng, ❌ cho sai, kèm lý do chi tiết bằng tiếng Việt:

  • ❌ Create an S3 bucket in each AWS account for the artifacts. Allow the pipeline to write to the S3 buckets. Create a CodePipeline S3 action to copy the artifacts to the S3 bucket in each AWS account. Update the CloudFormation actions to reference the artifacts S3 bucket in the production account.

    • Sai vì: Tạo bucket riêng + copy artifacts phức tạp, không cần thiết (tăng cost, latency). Hơn nữa, chỉ reference production bucket mà bỏ qua dev account → không fix đầy đủ. Không giải quyết KMS decrypt nếu copy vẫn encrypt.
  • ✅ Create a customer managed KMS key. Configure the KMS key policy to allow the IAM roles used by the CloudFormation action to perform decrypt operations. Modify the pipeline to use the customer managed KMS key to encrypt artifacts.

    • Đúng vì: aws/s3 key không cross-account. Customer key + policy grant kms:Decrypt cho roles ở dev/prod → artifacts decrypt được từ build account. Update pipeline encryption đơn giản, hiệu quả cao.
  • ❌ Create an AWS managed KMS key. Configure the KMS key policy to allow the development account and the production account to perform decrypt operations. Modify the pipeline to use the KMS key to encrypt artifacts.

    • Sai vì: AWS managed keys (như aws/s3) không cho phép chỉnh key policy (read-only). Không thể grant cross-account decrypt → vô hiệu.
  • ❌ In the development account and in the production account, create an IAM role for CodePipeline. Configure the roles with permissions to perform CloudFormation operations and with permissions to retrieve and decrypt objects from the artifacts S3 bucket. In the CodePipeline account, configure the CodePipeline CloudFormation action to use the roles.

    • Sai vì: Tạo roles + perms đúng, nhưng thiếu S3 bucket policy ở build account để allow cross-account s3:GetObject. Role assume được nhưng S3 deny → vẫn access denied.
  • ✅ In the development account and in the production account, create an IAM role for CodePipeline. Configure the roles with permissions to perform CloudFormation operations and with permissions to retrieve and decrypt objects from the artifacts S3 bucket. In the CodePipeline account, modify the artifacts S3 bucket policy to allow the roles access. Configure the CodePipeline CloudFormation action to use the roles.

    • Đúng vì: Roles có đầy đủ perms (CF + S3/KMS). Bucket policy critical cho cross-account S3 access. Config action dùng role → pipeline assume role ở dev/prod, decrypt artifacts từ build account.

📘 Tài liệu tham khảo (Cập nhật AWS 2024-2026)

Hy vọng phân tích giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần demo CloudFormation template, hỏi thêm nhé!

Câu 383 Chọn nhiều đáp án
A company is using an organization in AWS Organizations to manage multiple AWS accounts. The company’s development team wants to use AWS Lambda functions to meet resiliency requirements and is rewriting all applications to work with Lambda functions that are deployed in a VPC. The development team is using Amazon Elastic File System (Amazon EFS) as shared storage in Account A in the organization.

The company wants to continue to use Amazon EFS with Lambda. Company policy requires all serverless projects to be deployed in Account B.

A DevOps engineer needs to reconfigure an existing EFS file system to allow Lambda functions to access the data through an existing EFS access point.

Which combination of steps should the DevOps engineer take to meet these requirements? (Choose three.)
  1. A Update the EFS file system policy to provide Account B with access to mount and write to the EFS file system in Account A.
  2. B Create SCPs to set permission guardrails with fine-grained control for Amazon EFS.
  3. C Create a new EFS file system in Account B. Use AWS Database Migration Service (AWS DMS) to keep data from Account A and Account B synchronized.
  4. D Update the Lambda execution roles with permission to access the VPC and the EFS file system.
  5. E Create a VPC peering connection to connect Account A to Account B.
  6. F Configure the Lambda functions in Account B to assume an existing IAM role in Account A.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh việc cấu hình lại hệ thống Amazon EFS hiện có ở Account A để cho phép AWS Lambda functions ở Account B (trong VPC) truy cập dữ liệu qua EFS access point hiện có, trong khi tuân thủ chính sách công ty yêu cầu deploy tất cả serverless projects (như Lambda) ở Account B.

  • Bối cảnh chính:
    • Công ty dùng AWS Organizations quản lý nhiều account.
    • Dev team đang rewrite app để chạy trên Lambda trong VPC, sử dụng Amazon EFS ở Account A làm shared storage.
    • Yêu cầu resiliency và tiếp tục dùng EFS hiện có (không tạo mới).
    • Lambda ở Account B cần mount và write vào EFS của Account A qua access point.
    • Mục tiêu: Chọn 3 steps để DevOps engineer thực hiện reconfiguration.

🛠️ Thách thức kỹ thuật (dựa trên kiến thức AWS mới nhất 2024-2026):

  • Cross-account EFS access: EFS hỗ trợ chia sẻ qua resource-based policy (EFS file system policy), không phải IAM role assume trực tiếp.
  • Network connectivity: Lambda trong VPC cần kết nối VPC của EFS (mount targets) → VPC peering hoặc Transit Gateway.
  • Lambda permissions: Execution role cần policy cho VPC (ENI), EFS (ClientMount, ClientWrite), và security groups.
  • Access point: Đã có sẵn ở Account A, dùng để POSIX permissions và path enforcement cho Lambda.
  • Không dùng DMS (file sync không phù hợp với EFS), không tạo EFS mới, SCP chỉ là guardrail không giải quyết access cụ thể.

📘 Dẫn nguồn tham khảo:

✅ Đáp án đúng (chọn 3)

Các bước đúng là:

  1. Update the EFS file system policy to provide Account B with access to mount and write to the EFS file system in Account A.
  2. Update the Lambda execution roles with permission to access the VPC and the EFS file system.
  3. Create a VPC peering connection to connect Account A to Account B.

Lý do lựa chọn 🏆:

  • Đây là bộ 3 steps tối ưu, trực tiếp và ít tốn kém nhất để enable cross-account EFS access cho Lambda trong VPC:
    • VPC peering giải quyết layer mạng (routing giữa VPC A và B).
    • EFS policy update cho phép principal từ Account B (Lambda service) mount/write.
    • Lambda role update cấp IAM permissions cho Lambda tạo ENI, mount EFS (efs:ClientMount, efs:ClientWrite, elasticfilesystem:ClientMount).
  • Đáp ứng "reconfigure existing EFS" mà không migrate data hay tạo mới, phù hợp resiliency và Organizations.

🔍 Giải thích chi tiết từng phương án (Giữ nguyên text gốc, phân tích bằng tiếng Việt)

  • ✅ Update the EFS file system policy to provide Account B with access to mount and write to the EFS file system in Account A.
    Đúng 🟢: Đây là bước cốt lõi cho cross-account access. EFS dùng resource policy (JSON policy trên file system) để allow Principal: {"AWS": "arn:aws:iam::AccountB:root"} với actions efs:MountFileSystem, efs:ClientMount, efs:ClientWrite. Lambda ở B sẽ dùng access point của A. Không cần IAM role cross-account.

  • ❌ Create SCPs to set permission guardrails with fine-grained control for Amazon EFS.
    Sai 🔴: SCP (Service Control Policies) ở AWS Organizations chỉ deny/block actions ở level organization/account, không allow/grant access cụ thể như mount EFS. SCP là guardrail tổng quát, không thay thế resource policy của EFS. Sử dụng SCP sẽ không giải quyết reconfiguration.

  • ❌ Create a new EFS file system in Account B. Use AWS Database Migration Service (AWS DMS) to keep data from Account A and Account B synchronized.
    Sai 🔴: Vi phạm yêu cầu "reconfigure existing EFS" ở A và "continue to use Amazon EFS with Lambda" (không tạo mới). DMS dành cho database replication, không phù hợp sync file system EFS (dùng AWS DataSync thay thế nếu cần). Tốn kém, phức tạp, không resilient.

  • ✅ Update the Lambda execution roles with permission to access the VPC and the EFS file system.
    Đúng 🟢: Lambda ở B cần execution role với:

    • VPC policy: ec2:CreateNetworkInterface, ec2:DescribeNetworkInterfaces (cho ENI).
    • EFS policy: elasticfilesystem:ClientMount, elasticfilesystem:ClientWrite, elasticfilesystem:ClientRootAccess.
    • Security group cho mount target. Bước này enable Lambda attach EFS volume qua access point.
  • ✅ Create a VPC peering connection to connect Account A to Account B.
    Đúng 🟢: Bắt buộc cho network layer vì Lambda/VPC ở B không thể reach mount targets của EFS ở VPC A. VPC peering (non-overlapping CIDR) cho phép routing private IP. Cập nhật route tables và security groups. (Lưu ý: Nếu multi-region, dùng Transit Gateway).

  • ❌ Configure the Lambda functions in Account B to assume an existing IAM role in Account A.
    Sai 🔴: EFS access dựa trên resource policy của EFS, không yêu cầu Lambda assume IAM role ở A. Assume role (STS) chỉ cho IAM actions, không giải quyết mount NFS (EFS protocol). Sẽ phức tạp hóa với OIDC provider hoặc external ID, không cần thiết khi có EFS policy.

Câu 384
A media company has several thousand Amazon EC2 instances in an AWS account. The company is using Slack and a shared email inbox for team communications and important updates. A DevOps engineer needs to send all AWS-scheduled EC2 maintenance notifications to the Slack channel and the shared inbox. The solution must include the instances’ Name and Owner tags.

Which solution will meet these requirements?
  1. A Integrate AWS Trusted Advisor with AWS Config. Configure a custom AWS Config rule to invoke an AWS Lambda function to publish notifications to an Amazon Simple Notification Service (Amazon SNS) topic. Subscribe a Slack channel endpoint and the shared inbox to the topic.
  2. B Use Amazon EventBridge to monitor for AWS Health events. Configure the maintenance events to target an Amazon Simple Notification Service (Amazon SNS) topic. Subscribe an AWS Lambda function to the SNS topic to send notifications to the Slack channel and the shared inbox.
  3. C Create an AWS Lambda function that sends EC2 maintenance notifications to the Slack channel and the shared inbox. Monitor EC2 health events by using Amazon CloudWatch metrics. Configure a CloudWatch alarm that invokes the Lambda function when a maintenance notification is received.
  4. D Configure AWS Support integration with AWS CloudTrail. Create a CloudTrail lookup event to invoke an AWS Lambda function to pass EC2 maintenance notifications to Amazon Simple Notification Service (Amazon SNS). Configure Amazon SNS to target the Slack channel and the shared inbox.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh một công ty truyền thông sở hữu hàng nghìn Amazon EC2 instances trong một tài khoản AWS. Họ sử dụng Slack channel và shared email inbox để giao tiếp nội bộ và cập nhật quan trọng. Nhiệm vụ của DevOps engineer là thiết lập giải pháp để gửi tất cả thông báo bảo trì EC2 theo lịch AWS (AWS-scheduled EC2 maintenance notifications) đến hai kênh này. Yêu cầu quan trọng: Giải pháp phải bao gồm tags Name và Owner của các instances trong thông báo.

🔑 Điểm cốt lõi:

  • Thông báo bảo trì EC2 được phát ra từ AWS Health (cụ thể là Personal Health Dashboard - PHD), bao gồm các sự kiện bảo trì theo lịch như thay thế hardware, cập nhật phần mềm.
  • Giải pháp cần tự động hóa, mở rộng quy mô cho hàng nghìn instances, và trích xuất tags (Name và Owner) từ event để cá nhân hóa thông báo.
  • Theo tài liệu AWS cập nhật 2024-2026 (EventBridge schema v2+), AWS Health events chứa resource ARN/ID, cho phép Lambda query tags qua EC2 API hoặc Config.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use Amazon EventBridge to monitor for AWS Health events. Configure the maintenance events to target an Amazon Simple Notification Service (Amazon SNS) topic. Subscribe an AWS Lambda function to the SNS topic to send notifications to the Slack channel and the shared inbox.

Lý do chọn đáp án này 🛠️:

  • Amazon EventBridge (trước là CloudWatch Events, cập nhật schema 2025) chuyên monitor AWS Health events, bao gồm EC2 scheduled maintenance (loại AWS_EC2_SYSTEM_MAINTENANCE_SCHEDULED).
  • Rule EventBridge target SNS topic, SNS subscribe Lambda để parse event (chứa instance ID/ARN), sau đó Lambda query EC2 DescribeTags API lấy Name và Owner tags, rồi gửi đến Slack webhook và email (qua SES hoặc trực tiếp).
  • Mở rộng tốt cho hàng nghìn instances, không miss event, và tuân thủ yêu cầu tags vì Lambda xử lý logic tùy chỉnh.
  • Đây là best practice AWS cho reactive notifications từ Health events.

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng lựa chọn một cách chi tiết. Tôi giữ nguyên văn bản gốc bằng tiếng Anh, sau đó giải thích lý do đúng/sai bằng tiếng Việt với emoji nổi bật.

  • Integrate AWS Trusted Advisor with AWS Config. Configure a custom AWS Config rule to invoke an AWS Lambda function to publish notifications to an Amazon Simple Notification Service (Amazon SNS) topic. Subscribe a Slack channel endpoint and the shared inbox to the topic.
    ❌ Sai hoàn toàn: AWS Trusted Advisor kiểm tra best practices và recommendations (như cost, security), không phát hiện maintenance events. AWS Config rule theo dõi configuration changes của resources, không phải real-time Health events. Không capture được scheduled maintenance từ AWS Health, và khó trích xuất tags realtime. Không phù hợp quy mô lớn.

  • Use Amazon EventBridge to monitor for AWS Health events. Configure the maintenance events to target an Amazon Simple Notification Service (Amazon SNS) topic. Subscribe an AWS Lambda function to the SNS topic to send notifications to the Slack channel and the shared inbox.
    ✅ Đúng: Như giải thích trên. EventBridge capture chính xác AWS Health events cho EC2 maintenance, SNS fan-out, Lambda tùy chỉnh gửi Slack/email với tags (query từ event detail). Hỗ trợ global events nếu enable PHD across accounts.

  • Create an AWS Lambda function that sends EC2 maintenance notifications to the Slack channel and the shared inbox. Monitor EC2 health events by using Amazon CloudWatch metrics. Configure a CloudWatch alarm that invokes the Lambda function when a maintenance notification is received.
    ❌ Sai: CloudWatch metrics theo dõi performance metrics (CPU, network), không phải Health events hay maintenance notifications (chỉ là status checks như System/Reachability). Không có metric cụ thể cho "maintenance notification", nên alarm không trigger đúng. Không lấy được tags dễ dàng từ metrics.

  • Configure AWS Support integration with AWS CloudTrail. Create a CloudTrail lookup event to invoke an AWS Lambda function to pass EC2 maintenance notifications to Amazon Simple Notification Service (Amazon SNS). Configure Amazon SNS to target the Slack channel and the shared inbox.
    ❌ Sai: AWS Support integration với CloudTrail logs API calls liên quan support cases, không phải scheduled maintenance từ Health. CloudTrail query lookup events là cho audit API, không real-time và không capture Health events (Health không phải API call). Không đảm bảo tags và miss nhiều events.

🏆 Kết luận và khuyến nghị

Giải pháp đúng sử dụng EventBridge + SNS + Lambda là tối ưu nhất về độ tin cậy, chi phí thấp (~$1/tháng cho rules), và dễ mở rộng. Để implement: Enable AWS Health PHD, tạo EventBridge rule với pattern {"source": ["aws.health"], "detail-type": ["AWS Health Event"]}, filter detail.service: "EC2", target SNS, Lambda code dùng boto3.ec2.describe_instances() lấy tags. Test qua EventBridge console! 🚀

Câu 385
An AWS CodePipeline pipeline has implemented a code release process. The pipeline is integrated with AWS CodeDeploy to deploy versions of an application to multiple Amazon EC2 instances for each CodePipeline stage.

During a recent deployment, the pipeline failed due to a CodeDeploy issue. The DevOps team wants to improve monitoring and notifications during deployment to decrease resolution times.

What should the DevOps engineer do to create notifications when issues are discovered?
  1. A Implement Amazon CloudWatch Logs for CodePipeline and CodeDeploy, create an AWS Config rule to evaluate code deployment issues, and create an Amazon Simple Notification Service (Amazon SNS) topic to notify stakeholders of deployment issues.
  2. B Implement Amazon EventBridge for CodePipeline and CodeDeploy, create an AWS Lambda function to evaluate code deployment issues, and create an Amazon Simple Notification Service (Amazon SNS) topic to notify stakeholders of deployment issues.
  3. C Implement AWS CloudTrail to record CodePipeline and CodeDeploy API call information, create an AWS Lambda function to evaluate code deployment issues, and create an Amazon Simple Notification Service (Amazon SNS) topic to notify stakeholders of deployment issues.
  4. D Implement Amazon EventBridge for CodePipeline and CodeDeploy, create an Amazon Inspector assessment target to evaluate code deployment issues, and create an Amazon Simple Notification Service (Amazon SNS) topic to notify stakeholders of deployment issues.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào quy trình triển khai ứng dụng sử dụng AWS CodePipeline tích hợp AWS CodeDeploy để deploy lên nhiều EC2 instances ở từng stage. 📦 Gần đây, pipeline thất bại do vấn đề từ CodeDeploy, và đội DevOps muốn cải thiện monitoring & notifications để phát hiện issue nhanh chóng, giảm thời gian resolution.

🎯 Mục tiêu chính: Tạo notifications tự động khi phát hiện vấn đề (như deployment failure). Điều này đòi hỏi một giải pháp real-time event-driven, capture events từ CodePipeline/CodeDeploy, evaluate issue, rồi notify qua SNS. AWS khuyến nghị sử dụng Amazon EventBridge (trước là CloudWatch Events) để monitor events từ các service này một cách hiệu quả nhất (cập nhật đến 2026: EventBridge hỗ trợ schema registry và partner events cho CI/CD). 🛠️

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Implement Amazon EventBridge for CodePipeline and CodeDeploy, create an AWS Lambda function to evaluate code deployment issues, and create an Amazon Simple Notification Service (Amazon SNS) topic to notify stakeholders of deployment issues.

Lý do chọn 📘:

  • EventBridge là dịch vụ event bus native của AWS, tự động nhận events real-time từ CodePipeline (như CodePipeline-PipelineExecutionSucceeded/Failed) và CodeDeploy (như CodeDeploy-DeploymentFailure). ✅ Nó cho phép tạo rules để filter events failure cụ thể.
  • Lambda function xử lý logic evaluate issue (ví dụ: parse event data, check deployment status), serverless và scale tự động.
  • SNS topic gửi notifications đến stakeholders (email/SMS/Slack). Toàn bộ flow event-driven, giảm MTTR (Mean Time To Resolution).
  • Đây là best practice theo AWS Well-Architected Framework cho DevOps (Pillar: Observability). Không cần polling, chi phí thấp.

📋 Giải thích tất cả các phương án (đúng/sai)

  • ✅ [ĐÚNG] Implement Amazon EventBridge for CodePipeline and CodeDeploy, create an AWS Lambda function to evaluate code deployment issues, and create an Amazon Simple Notification Service (Amazon SNS) topic to notify stakeholders of deployment issues.
    🟢 Đúng vì: EventBridge capture events real-time từ cả hai service (CodePipeline events: PipelineExecutionFailed; CodeDeploy: DeploymentFailed). Lambda evaluate chi tiết (custom logic), SNS notify ngay lập tức. Hoàn hảo cho monitoring deployment failures. 🚀

  • ❌ [SAI] Implement Amazon CloudWatch Logs for CodePipeline and CodeDeploy, create an AWS Config rule to evaluate code deployment issues, and create an Amazon Simple Notification Service (Amazon SNS) topic to notify stakeholders of deployment issues.
    🔴 Sai vì: CloudWatch Logs chỉ lưu log (không real-time events), cần Insights queries thủ công/polling. AWS Config rule dùng cho compliance config (như resource changes), KHÔNG evaluate deployment runtime issues (ví dụ: CodeDeploy failure logs). Không hiệu quả cho notifications nhanh. ⏳

  • ❌ [SAI] Implement AWS CloudTrail to record CodePipeline and CodeDeploy API call information, create an AWS Lambda function to evaluate code deployment issues, and create an Amazon Simple Notification Service (Amazon SNS) topic to notify stakeholders of deployment issues.
    🔴 Sai vì: CloudTrail ghi API calls (audit trail), nhưng events chỉ deliver qua EventBridge/S3 sau (không real-time như native events). Lambda evaluate API logs kém hiệu quả cho deployment status (quá noisy, delay). Không phải best practice cho CI/CD monitoring. 🕰️

  • ❌ [SAI] Implement Amazon EventBridge for CodePipeline and CodeDeploy, create an Amazon Inspector assessment target to evaluate code deployment issues, and create an Amazon Simple Notification Service (Amazon SNS) topic to notify stakeholders of deployment issues.
    🔴 Sai vì: EventBridge đúng, nhưng Amazon Inspector chỉ scan vulnerabilities/security (EC2/ECS assessments), KHÔNG evaluate deployment issues như failure stages hay rollback. Không liên quan đến CodeDeploy logic. 🛡️️

📚 Tài liệu tham khảo (cập nhật AWS 2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần ví dụ code Lambda/EventBridge rule, hỏi thêm nhé! 😊

Câu 386
A global company manages multiple AWS accounts by using AWS Control Tower. The company hosts internal applications and public applications.

Each application team in the company has its own AWS account for application hosting. The accounts are consolidated in an organization in AWS Organizations. One of the AWS Control Tower member accounts serves as a centralized DevOps account with CI/CD pipelines that application teams use to deploy applications to their respective target AWS accounts. An IAM role for deployment exists in the centralized DevOps account.

An application team is attempting to deploy its application to an Amazon Elastic Kubernetes Service (Amazon EKS) cluster in an application AWS account. An IAM role for deployment exists in the application AWS account. The deployment is through an AWS CodeBuild project that is set up in the centralized DevOps account. The CodeBuild project uses an IAM service role for CodeBuild. The deployment is failing with an Unauthorized error during attempts to connect to the cross-account EKS cluster from CodeBuild.

Which solution will resolve this error?
  1. A Configure the application account’s deployment IAM role to have a trust relationship with the centralized DevOps account. Configure the trust relationship to allow the sts:AssumeRole action. Configure the application account’s deployment IAM role to have the required access to the EKS cluster. Configure the EKS cluster aws-auth ConfigMap to map the role to the appropriate system permissions.
  2. B Configure the centralized DevOps account’s deployment IAM role to have a trust relationship with the application account. Configure the trust relationship to allow the sts:AssumeRole action. Configure the centralized DevOps account’s deployment IAM role to allow the required access to CodeBuild.
  3. C Configure the centralized DevOps account’s deployment IAM role to have a trust relationship with the application account. Configure the trust relationship to allow the sts:AssumeRoleWithSAML action. Configure the centralized DevOps account’s deployment IAM role to allow the required access to CodeBuild.
  4. D Configure the application account’s deployment IAM role to have a trust relationship with the AWS Control Tower management account. Configure the trust relationship to allow the sts:AssumeRole action. Configure the application account’s deployment IAM role to have the required access to the EKS cluster. Configure the EKS cluster aws-auth ConfigMap to map the role to the appropriate system permissions.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả một tình huống thực tế trong môi trường AWS Organizations sử dụng AWS Control Tower để quản lý nhiều tài khoản AWS. Công ty có:

  • Tài khoản centralized DevOps (một member account): Chứa các pipeline CI/CD (sử dụng AWS CodeBuild với IAM service role riêng), nơi các team ứng dụng deploy code đến tài khoản của họ. Có IAM role for deployment ở đây.
  • Tài khoản ứng dụng (application AWS account): Mỗi team có tài khoản riêng chứa Amazon EKS cluster và một IAM role for deployment dành cho deployment.

Vấn đề: Khi chạy deployment từ CodeBuild project ở centralized DevOps account đến EKS cluster ở application account (cross-account), gặp lỗi Unauthorized. Lý do gốc rễ là CodeBuild không thể assume IAM role ở application account để truy cập EKS, vì thiếu trust relationship đúng chiều và aws-auth ConfigMap trong EKS chưa map role vào RBAC (Role-Based Access Control).

Mục tiêu: Tìm giải pháp cross-account access an toàn, tuân thủ best practices AWS (cập nhật đến 2026: EKS hỗ trợ IAM Roles for Service Accounts - IRSA, nhưng ở đây tập trung vào IAM role assumption và aws-auth cho legacy/cross-account).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Configure the application account’s deployment IAM role to have a trust relationship with the centralized DevOps account. Configure the trust relationship to allow the sts:AssumeRole action. Configure the application account’s deployment IAM role to have the required access to the EKS cluster. Configure the EKS cluster aws-auth ConfigMap to map the role to the appropriate system permissions.

Lý do chọn 🛠️:

  • CodeBuild ở DevOps account cần assume IAM role ở application account (chiều từ DevOps → app account), nên trust policy của role ở app account phải trust DevOps account (Principal: ARN của DevOps account hoặc role ở đó). Action: sts:AssumeRole.
  • Role ở app account cần policy permissions cho EKS (ví dụ: eks:DescribeCluster, RBAC verbs).
  • EKS aws-auth ConfigMap (trong kube-system namespace) phải map role ARN vào system:masters hoặc RBAC cụ thể để kubectl/eksctl hoạt động cross-account.
  • Giải pháp này an toàn, least privilege, phù hợp multi-account với Organizations/Control Tower (không cần SCP rộng).

📋 Giải thích tất cả các phương án

  • ✅ Configure the application account’s deployment IAM role to have a trust relationship with the centralized DevOps account. Configure the trust relationship to allow the sts:AssumeRole action. Configure the application account’s deployment IAM role to have the required access to the EKS cluster. Configure the EKS cluster aws-auth ConfigMap to map the role to the appropriate system permissions.
    Phân tích đúng 🟢: Như trên, đây là flow chuẩn cross-account EKS access từ CodeBuild. CodeBuild service role (DevOps) assume role (app), sau đó dùng kubeconfig với assumed credentials. Aws-auth là bắt buộc cho auth vào EKS API server.

  • ❌ Configure the centralized DevOps account’s deployment IAM role to have a trust relationship with the application account. Configure the trust relationship to allow the sts:AssumeRole action. Configure the centralized DevOps account’s deployment IAM role to allow the required access to CodeBuild.
    Phân tích sai 🔴: Chiều trust ngược lại (DevOps role trust app account → app account assume DevOps role, không logic). CodeBuild cần access EKS ở app account, không phải ngược. "Access to CodeBuild" không giải quyết Unauthorized đến EKS.

  • ❌ Configure the centralized DevOps account’s deployment IAM role to have a trust relationship with the application account. Configure the trust relationship to allow the sts:AssumeRoleWithSAML action. Configure the centralized DevOps account’s deployment IAM role to allow the required access to CodeBuild.
    Phân tích sai 🔴: Chiều trust sai như trên. sts:AssumeRoleWithSAML dành cho federated identity (SAML provider), không áp dụng cho service-to-service cross-account (dùng AssumeRole). Vẫn không fix EKS auth.

  • ❌ Configure the application account’s deployment IAM role to have a trust relationship with the AWS Control Tower management account. Configure the trust relationship to allow the sts:AssumeRole action. Configure the application account’s deployment IAM role to have the required access to the EKS cluster. Configure the EKS cluster aws-auth ConfigMap to map the role to the appropriate system permissions.
    Phân tích sai 🔴: Trust với management account (Control Tower root) không liên quan – deployment từ DevOps member account, không phải management. SCP/OUs ở Organizations chặn cross-member nếu không đúng Principal. Aws-auth đúng nhưng trust sai → vẫn fail.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Giải pháp này đảm bảo zero-trust, auditable với CloudTrail! 🚀

Câu 387
A highly regulated company has a policy that DevOps engineers should not log in to their Amazon EC2 instances except in emergencies. If a DevOps engineer does log in, the security team must be notified within 15 minutes of the occurrence.

Which solution will meet these requirements?
  1. A Install the Amazon Inspector agent on each EC2 instance. Subscribe to Amazon EventBridge notifications. Invoke an AWS Lambda function to check if a message is about user logins. If it is, send a notification to the security team using Amazon SNS.
  2. B Install the Amazon CloudWatch agent on each EC2 instance. Configure the agent to push all logs to Amazon CloudWatch Logs and set up a CloudWatch metric filter that searches for user logins. If a login is found, send a notification to the security team using Amazon SNS.
  3. C Set up AWS CloudTrail with Amazon CloudWatch Logs. Subscribe CloudWatch Logs to Amazon Kinesis. Attach AWS Lambda to Kinesis to parse and determine if a log contains a user login. If it does, send a notification to the security team using Amazon SNS.
  4. D Set up a script on each Amazon EC2 instance to push all logs to Amazon S3. Set up an S3 event to invoke an AWS Lambda function, which invokes an Amazon Athena query to run. The Athena query checks for logins and sends the output to the security team using Amazon SNS.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một công ty có quy định nghiêm ngặt về an ninh: DevOps engineers không được đăng nhập (login) vào các instance Amazon EC2 trừ trường hợp khẩn cấp. Nếu có bất kỳ ai (bao gồm DevOps) thực hiện login, đội ngũ security phải được thông báo trong vòng 15 phút.

📌 Yêu cầu chính:

  • Phát hiện login: Tập trung vào các hoạt động đăng nhập người dùng vào EC2 instance (thường là SSH login qua /var/log/secure hoặc /var/log/auth.log trên Linux).
  • Thông báo nhanh chóng: Phải trigger notification (qua Amazon SNS) trong 15 phút, nghĩa là giải pháp phải real-time hoặc gần real-time, không dùng batch processing chậm.
  • Không cần login thủ công: Giải pháp phải tự động, không yêu cầu can thiệp thủ công vào instance.

🛠️ Kiến thức AWS liên quan (cập nhật đến 2026):

  • Login vào EC2 (SSH/RDP) được ghi log trong system logs của instance (không phải CloudTrail, vì CloudTrail chỉ ghi API calls như RunInstances, không ghi session login nội bộ).
  • CloudWatch agent là cách chuẩn để monitor và push logs real-time từ instance đến CloudWatch Logs.

✅ Đáp án đúng

Install the Amazon CloudWatch agent on each EC2 instance. Configure the agent to push all logs to Amazon CloudWatch Logs and set up a CloudWatch metric filter that searches for user logins. If a login is found, send a notification to the security team using Amazon SNS.

Lý do chọn đáp án này 🏆:

  • ✅ CloudWatch agent cài trên mỗi EC2, thu thập system logs (như /var/log/secure) real-time và push trực tiếp đến CloudWatch Logs (latency <1 phút).
  • ✅ Metric filter trên CloudWatch Logs có thể pattern-match chính xác các event login (ví dụ: "Accepted password" hoặc "Accepted publickey"), trigger alarm ngay lập tức.
  • ✅ Alarm → SNS gửi notification đến security team trong <15 phút (thường chỉ vài giây).
  • 🛡️ Hoàn hảo cho quy định: Không cần login thủ công, scale tốt cho nhiều instance, chi phí thấp.
  • 📈 Theo AWS best practices 2026: CloudWatch Logs Insights và metric filters hỗ trợ deep log analysis cho security monitoring.

📋 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai với lý do cụ thể:

  • ❌ [SAI] Install the Amazon Inspector agent on each EC2 instance. Subscribe to Amazon EventBridge notifications. Invoke an AWS Lambda function to check if a message is about user logins. If it is, send a notification to the security team using Amazon SNS.
    Lý do sai: Amazon Inspector agent chỉ dùng để scan vulnerability và compliance (như CIS benchmarks), không monitor hoặc ghi logins real-time. EventBridge chỉ forward findings (vulnerabilities), không detect SSH logins. Latency cao và không match yêu cầu 15 phút. (Không phù hợp theo AWS Inspector docs 2026).

  • ✅ [ĐÚNG] Install the Amazon CloudWatch agent on each EC2 instance. Configure the agent to push all logs to Amazon CloudWatch Logs and set up a CloudWatch metric filter that searches for user logins. If a login is found, send a notification to the security team using Amazon SNS.
    Lý do đúng: Như đã giải thích ở trên – real-time log monitoring từ system logs, metric filter chính xác, SNS notify nhanh chóng. Đây là giải pháp optimized và serverless nhất.

  • ❌ [SAI] Set up AWS CloudTrail with Amazon CloudWatch Logs. Subscribe CloudWatch Logs to Amazon Kinesis. Attach AWS Lambda to Kinesis to parse and determine if a log contains a user login. If it does, send a notification to the security team using Amazon SNS.
    Lý do sai: CloudTrail chỉ ghi API calls (như DescribeInstances), không ghi SSH logins nội bộ vào instance. Kinesis + Lambda thêm complexity và latency (streaming có thể >15 phút nếu backlog). Quá rườm rà cho vấn đề đơn giản (AWS CloudTrail docs 2026 xác nhận scope hạn chế).

  • ❌ [SAI] Set up a script on each Amazon EC2 instance to push all logs to Amazon S3. Set up an S3 event to invoke an AWS Lambda function, which invokes an Amazon Athena query to run. The Athena query checks for logins and sends the output to the security team using Amazon SNS.
    Lý do sai: Script push logs thủ công (phải maintain trên mỗi instance), S3 + Athena là batch querying (query có thể mất giờ để scan, không real-time). Không đáp ứng 15 phút, dễ lỗi scale, chi phí cao (Athena charge per query TB scanned). Không best practice cho monitoring.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Giải pháp này đảm bảo tuân thủ 100% và dễ implement! 🚀 Nếu cần demo code CloudWatch config, hãy hỏi thêm nhé! 😊

Câu 388 Chọn nhiều đáp án
A company updated the AWS CloudFormation template for a critical business application. The stack update process failed due to an error in the updated template, and AWS CloudFormation automatically began the stack rollback process. Later, a DevOps engineer discovered that the application was still unavailable and that the stack was in the UPDATE_ROLLBACK_FAILED state.

Which combination of actions should the DevOps engineer perform so that the stack rollback can complete successfully? (Choose two.)
  1. A Attach the AWSCloudFormationFullAccess IAM policy to the AWS CloudFormation role.
  2. B Automatically recover the stack resources by using AWS CloudFormation drift detection.
  3. C Issue a ContinueUpdateRollback command from the AWS CloudFormation console or the AWS CLI.
  4. D Manually adjust the resources to match the expectations of the stack.
  5. E Update the existing AWS CloudFormation stack by using the original template.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh tình huống AWS CloudFormation khi một công ty cập nhật template cho ứng dụng kinh doanh quan trọng. Quá trình cập nhật stack thất bại do lỗi trong template mới, dẫn đến CloudFormation tự động kích hoạt rollback (hoàn nguyên về trạng thái trước đó). Tuy nhiên, rollback cũng thất bại, khiến stack rơi vào trạng thái UPDATE_ROLLBACK_FAILED. Lúc này, ứng dụng vẫn không khả dụng.
Mục tiêu: DevOps engineer cần thực hiện kết hợp hai hành động để hoàn tất rollback thành công, khôi phục stack về trạng thái ổn định trước khi update.
📌 Bối cảnh quan trọng: Trạng thái UPDATE_ROLLBACK_FAILED xảy ra khi một số tài nguyên không thể rollback tự động (ví dụ: tài nguyên bị thay đổi thủ công, xóa ngoài CloudFormation, hoặc lỗi quyền hạn cục bộ). Không thể update/delete stack ngay, phải xử lý thủ công trước. (Kiến thức cập nhật AWS 2024-2026: CloudFormation hỗ trợ các API như ContinueUpdateRollback để xử lý trường hợp này).

✅ Đáp án đúng (Chọn TWO)

Hai lựa chọn đúng là:
Issue a ContinueUpdateRollback command from the AWS CloudFormation console or the AWS CLI.
Manually adjust the resources to match the expectations of the stack.

Lý do lựa chọn:

  • Khi stack ở UPDATE_ROLLBACK_FAILED, CloudFormation dừng rollback tại tài nguyên gây lỗi. DevOps engineer phải thủ công điều chỉnh tài nguyên để khớp với template cũ (previous known state), sau đó gọi ContinueUpdateRollback qua Console/CLI để tiếp tục và hoàn tất quá trình. Kết hợp này đảm bảo rollback thành công, khôi phục ứng dụng. Đây là quy trình chuẩn theo best practice AWS (không có thay đổi lớn đến 2026).
    🛠️ Thứ tự thực hiện: Fix thủ công trước → ContinueUpdateRollback sau.

🔍 Giải thích chi tiết từng phương án

Dưới đây là phân tích tất cả các lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá đúng/sai với lý do cụ thể:

  • ❌ [SAI] Attach the AWSCloudFormationFullAccess IAM policy to the AWS CloudFormation role.
    Việc gắn policy IAM này không giải quyết vấn đề UPDATE_ROLLBACK_FAILED. Trạng thái này thường do tài nguyên không khớp trạng thái (không phải thiếu quyền toàn cục), vì CloudFormation role đã có quyền cơ bản để bắt đầu rollback. Gắn policy chỉ hữu ích nếu lỗi quyền cụ thể, nhưng câu hỏi không đề cập và không phải giải pháp chuẩn.

  • ❌ [SAI] Automatically recover the stack resources by using AWS CloudFormation drift detection.
    Drift detection chỉ phát hiện sự khác biệt giữa tài nguyên thực tế và template (qua DetectStackDrift), không tự động recover hoặc fix rollback failed. Không có tính năng "automatically recover" cho trường hợp này đến 2026; drift chỉ hỗ trợ audit, không thay thế thủ công fix + ContinueUpdateRollback.

  • ✅ [ĐÚNG] Issue a ContinueUpdateRollback command from the AWS CloudFormation console or the AWS CLI.
    Đây là hành động trực tiếp để tiếp tục rollback sau khi fix thủ công. API/Console command này bỏ qua tài nguyên failed và hoàn tất rollback cho phần còn lại, đưa stack về trạng thái ổn định (UPDATE_COMPLETE). Bắt buộc kết hợp với fix thủ công để thành công.

  • ✅ [ĐÚNG] Manually adjust the resources to match the expectations of the stack.
    Bước cần thiết đầu tiên: Thủ công chỉnh sửa tài nguyên (qua Console/CLI/SDK) để khớp chính xác với template phiên bản trước (previous stable state). Chỉ sau đó ContinueUpdateRollback mới chạy được, vì CloudFormation kiểm tra consistency trước khi tiếp tục.

  • ❌ [SAI] Update the existing AWS CloudFormation stack by using the original template.
    Không thể update stack ở trạng thái UPDATE_ROLLBACK_FAILED (bị lock). Update với template gốc sẽ fail ngay, không giúp hoàn tất rollback. Phải fix rollback trước, sau đó mới update lại nếu cần.

📘 Tài liệu tham khảo (AWS Documentation mới nhất 2024-2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm ví dụ CLI, hãy hỏi nhé.

Câu 389 Chọn nhiều đáp án
A development team manually builds an artifact locally and then places it in an Amazon S3 bucket. The application has a local cache that must be cleared when a deployment occurs. The team runs a command to do this, downloads the artifact from Amazon S3, and unzips the artifact to complete the deployment.

A DevOps team wants to migrate to a CI/CD process and build in checks to stop and roll back the deployment when a failure occurs. This requires the team to track the progression of the deployment.

Which combination of actions will accomplish this? (Choose three.)
  1. A Allow developers to check the code into a code repository. Using Amazon EventBridge, on every pull into the main branch, invoke an AWS Lambda function to build the artifact and store it in Amazon S3.
  2. B Create a custom script to clear the cache. Specify the script in the BeforeInstall lifecycle hook in the AppSpec file.
  3. C Create user data for each Amazon EC2 instance that contains the clear cache script. Once deployed, test the application. If it is not successful, deploy it again.
  4. D Set up AWS CodePipeline to deploy the application. Allow developers to check the code into a code repository as a source for the pipeline.
  5. E Use AWS CodeBuild to build the artifact and place it in Amazon S3. Use AWS CodeDeploy to deploy the artifact to Amazon EC2 instances.
  6. F Use AWS Systems Manager to fetch the artifact from Amazon S3 and deploy it to all the instances.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả một quy trình triển khai ứng dụng thủ công hiện tại: Đội phát triển build artifact cục bộ, upload lên Amazon S3, sau đó chạy lệnh clear cache cục bộ, download artifact từ S3 và unzip để deploy lên EC2.

Mục tiêu của DevOps team: Chuyển sang quy trình CI/CD tự động (Continuous Integration/Continuous Deployment) với các kiểm tra (checks) để:

  • Dừng và rollback deployment nếu có lỗi (stop and roll back when failure occurs).
  • Theo dõi tiến trình deployment (track the progression).

Câu hỏi yêu cầu chọn TỔNG CỘNG 3 actions kết hợp để đạt được điều này. Giải pháp lý tưởng phải sử dụng các dịch vụ AWS CI/CD chuẩn như AWS CodePipeline (orchestrator pipeline), AWS CodeBuild (build artifact), AWS CodeDeploy (deploy với lifecycle hooks hỗ trợ before/after actions, rollback tự động, tracking qua CloudWatch/Events). Quy trình này đảm bảo tự động hóa từ source code → build → deploy, với monitoring và failure handling.

✅ Đáp án đúng (chọn 3 phương án sau):

  • Create a custom script to clear the cache. Specify the script in the BeforeInstall lifecycle hook in the AppSpec file.
    (Lý do: Xử lý clear cache tự động trong lifecycle của CodeDeploy, tích hợp hoàn hảo với pipeline để tránh manual steps và hỗ trợ rollback nếu fail sau hook này.)

  • Set up AWS CodePipeline to deploy the application. Allow developers to check the code into a code repository as a source for the pipeline.
    (Lý do: CodePipeline là trung tâm CI/CD, trigger từ code repo, orchestrate toàn bộ flow, track progression qua stages, tự động stop/rollback nếu stage fail.)

  • Use AWS CodeBuild to build the artifact and place it in Amazon S3. Use AWS CodeDeploy to deploy the artifact to Amazon EC2 instances.
    (Lý do: CodeBuild tự động build artifact từ source → S3; CodeDeploy deploy với checks, rollback (ví dụ: DeploymentAlarms, Canary/Linear strategies), tracking chi tiết qua console/CloudWatch.)

Kết hợp 3 actions này tạo pipeline hoàn chỉnh: Code repo → CodePipeline (source + orchestrate) → CodeBuild (build → S3) → CodeDeploy (deploy EC2 với BeforeInstall hook clear cache). Hỗ trợ full tracking, alarms, rollback tự động (cập nhật AWS 2024-2026: CodeDeploy hỗ trợ EC2/On-Prem, integration sâu với CodePipeline v2).

📋 Giải thích TẤT CẢ các phương án (đúng/sai)

🛠️ Phương án 1: Allow developers to check the code into a code repository. Using Amazon EventBridge, on every pull into the main branch, invoke an AWS Lambda function to build the artifact and store it in Amazon S3.
❌ SAI - Phương án này chỉ tự động hóa build qua EventBridge + Lambda (không phải CI/CD chuẩn), thiếu orchestration đầy đủ (không có deploy stage, tracking progression kém), không tích hợp rollback hay checks deployment. Lambda build không scalable như CodeBuild, không phù hợp migrate full CI/CD.

✅ Phương án 2: Create a custom script to clear the cache. Specify the script in the BeforeInstall lifecycle hook in the AppSpec file.
✅ ĐÚNG - CodeDeploy AppSpec file hỗ trợ lifecycle hooks (BeforeInstall chạy script clear cache trước unzip artifact), đảm bảo cache sạch tự động. Nếu hook fail → deployment dừng/rollback ngay. Tích hợp hoàn hảo với CodePipeline/CodeBuild, giải quyết manual cache clear. (Cập nhật: AppSpec v2 hỗ trợ EC2/ALB đến 2026).

🛠️ Phương án 3: Create user data for each Amazon EC2 instance that contains the clear cache script. Once deployed, test the application. If it is not successful, deploy it again.
❌ SAI - User data chỉ chạy lúc launch instance (không trigger per deployment), testing manual "deploy lại nếu fail" không tự động, thiếu tracking progression và rollback thực thụ. Không phù hợp CI/CD, vẫn thủ công cao.

✅ Phương án 4: Set up AWS CodePipeline to deploy the application. Allow developers to check the code into a code repository as a source for the pipeline.
✅ ĐÚNG - CodePipeline là "glue" CI/CD: Source (CodeCommit/GitHub), Build/Deploy stages, tự động trigger từ code check-in, track real-time qua dashboard/CloudWatch Events. Hỗ trợ failure handling (stop pipeline, manual approval, rollback via CodeDeploy). (Phiên bản mới: CodePipeline v2 hỗ trợ custom actions, S3 artifacts 2025+).

✅ Phương án 5: Use AWS CodeBuild to build the artifact and place it in Amazon S3. Use AWS CodeDeploy to deploy the artifact to Amazon EC2 instances.
✅ ĐÚNG - CodeBuild: Build tự động từ source → artifact S3 (batch/parallel). CodeDeploy: Deploy EC2 với appspec, strategies (AllAtOnce/Canary), alarms (CloudWatch), auto-rollback nếu fail (health checks/traffic). Track progression qua deployment groups/logs. Kết hợp với Pipeline → full CI/CD.

🛠️ Phương án 6: Use AWS Systems Manager to fetch the artifact from Amazon S3 and deploy it to all the instances.
❌ SAI - AWS Systems Manager (SSM) dùng cho automation/run commands/patching, không phải deployment artifact chuyên dụng (thiếu build stage, lifecycle hooks, rollback tự động, tracking CI/CD). Không thay thế CodeDeploy, chỉ hỗ trợ phụ (như State Manager), không đạt yêu cầu migrate CI/CD đầy đủ.

📘 Tài liệu tham khảo (AWS cập nhật mới nhất 2026)

Giải pháp này đạt best practice AWS Well-Architected Framework (Operational Excellence pillar)! 🚀

Câu 390 Chọn nhiều đáp án
A DevOps engineer is working on a project that is hosted on Amazon Linux and has failed a security review. The DevOps manager has been asked to review the company buildspec.yaml file for an AWS CodeBuild project and provide recommendations. The buildspec.yaml file is configured as follows:

env:
  variables:
    AWS_ACCESS_KEY_ID: AKIAJF7BRFWJBA4GHXNA
    AWS_SECRET_ACCESS_KEY: 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
    AWS_DEFAULT_REGION: us-east-1
    DB_PASSWORD: cuj5RptFa3va
phases:
  build:
    commands:
      - aws s3 cp s3://db-deploy-bucket/my.cnf.template /tmp/my.cnf
      - sed -i "s/DB_PW/${DB_PASSWORD}/g" /tmp/my.cnf
      - aws s3 cp s3://db-deploy-bucket/instance.key /tmp/instance.key
      - chmod 600 /tmp/instance.key
      - scp -i /tmp/instance.key /tmp/my.cnf root@10.25.15.23:/etc/my.cnf
      - ssh -i /tmp/instance.key root@10.25.15.23 /etc/init.d/mysqld restart


What changes should be recommended to comply with AWS security best practices? (Choose three.)
  1. A Add a post-build command to remove the temporary files from the container before termination to ensure they cannot be seen by other CodeBuild users.
  2. B Update the CodeBuild project role with the necessary permissions and then remove the AWS credentials from the environment variable.
  3. C Store the DB_PASSWORD as a SecureString value in AWS Systems Manager Parameter Store and then remove the DB_PASSWORD from the environment variables.
  4. D Move the environment variables to the ‘db-deploy-bucket’ Amazon S3 bucket, add a prebuild stage to download, then export the variables.
  5. E Use AWS Systems Manager run command versus scp and ssh commands directly to the instance.
  6. F Scramble the environment variables using XOR followed by Base64, add a section to install, and then run XOR and Base64 to the build phase.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào việc phân tích file buildspec.yaml của một dự án AWS CodeBuild chạy trên Amazon Linux, đã thất bại trong đánh giá bảo mật. 🛡️ File này có nhiều vấn đề nghiêm trọng vi phạm AWS security best practices (cập nhật đến năm 2026, theo AWS Well-Architected Framework - Security Pillar):

  • Hardcode AWS credentials: AWS_ACCESS_KEY_ID và AWS_SECRET_ACCESS_KEY được lưu trực tiếp trong biến môi trường (env: variables), dễ bị lộ nếu build log bị truy cập hoặc container bị hack. ❌
  • Lưu mật khẩu database plaintext: DB_PASSWORD nằm plaintext trong env vars, có thể bị log hoặc truy cập bởi người dùng khác.
  • Tải private key từ S3 và sử dụng SCP/SSH: Tải instance.key từ S3, chmod, rồi dùng SCP/SSH kết nối trực tiếp đến IP 10.25.15.23 (có thể là private IP) để cập nhật file MySQL config và restart service. Điều này lộ private key tạm thời, không mã hóa kết nối đúng cách, và phụ thuộc vào SSH root – rủi ro cao nếu key bị lộ. 🔓
  • Thiếu cleanup: Không xóa file tạm (/tmp/my.cnf, /tmp/instance.key), có thể tồn tại trong container CodeBuild (dù ephemeral nhưng vẫn rủi ro).
  • Quy trình build: Copy template từ S3, thay thế password bằng sed, rồi deploy qua SSH.

Mục tiêu: Đề xuất 3 thay đổi để tuân thủ best practices như sử dụng IAM roles, AWS Systems Manager (SSM) Parameter Store cho secrets, và SSM Run Command thay SSH. Câu hỏi yêu cầu chọn ba lựa chọn đúng từ sáu phương án. 📝

✅ Đáp án đúng và lý do lựa chọn

Các đáp án đúng là ba phương án sau (chọn THREE theo yêu cầu câu hỏi). Chúng trực tiếp khắc phục các lỗ hổng lớn nhất: loại bỏ credentials plaintext, quản lý secrets an toàn, và thay thế SSH bằng dịch vụ managed của AWS.

  1. Update the CodeBuild project role with the necessary permissions and then remove the AWS credentials from the environment variable.
    ✅ Lý do: CodeBuild nên dùng IAM service role (attach policy như AmazonS3ReadOnlyAccess, AmazonSSMFullAccess) để truy cập S3/SSM mà không cần access keys. Hardcode keys vi phạm nguyên tắc "least privilege" và dễ bị lộ (AWS khuyến cáo từ 2015, cập nhật 2026 với IAM Roles Anywhere). Xóa env vars này ngay lập tức.

  2. Store the DB_PASSWORD as a SecureString value in AWS Systems Manager Parameter Store and then remove the DB_PASSWORD from the environment variables.
    ✅ Lý do: SSM Parameter Store SecureString mã hóa KMS-managed, truy cập qua IAM role (command: aws ssm get-parameter --name /db/password --with-decryption). Xóa env var plaintext để tránh log/exposure. Đây là best practice cho secrets (ưu tiên hơn Secrets Manager cho simple params, theo AWS 2026).

  3. Use AWS Systems Manager run command versus scp and ssh commands directly to the instance.
    ✅ Lý do: SSM Run Command (hoặc Session Manager) cho phép chạy script trên EC2 mà không cần SSH keys, qua IAM role (EC2 cần AmazonSSMManagedInstanceCore policy). An toàn hơn: không tải key, audit trail đầy đủ, không mở port 22. Thay thế SCP/SSH hoàn toàn (AWS deprecated SSH khuyến khích SSM từ 2020+).

🔍 Phân tích tất cả các phương án (đúng/sai)

Dưới đây là phân tích chi tiết từng phương án, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi cái được đánh giá dựa trên AWS security best practices 2026 (không chỉ fix triệu chứng mà giải quyết gốc rễ).

  • ❌ Add a post-build command to remove the temporary files from the container before termination to ensure they cannot be seen by other CodeBuild users.
    Phân tích sai: Việc thêm rm -rf /tmp/* ở post_build là tốt để cleanup (CodeBuild containers ephemeral, reset sau build), nhưng không phải ưu tiên cao. Không giải quyết hardcode creds/passwords/SSH – chỉ fix triệu chứng temp files. AWS docs khuyến cáo nhưng không phải thay đổi chính để pass security review. Multi-tenant CodeBuild đã isolate tốt.

  • ✅ Update the CodeBuild project role with the necessary permissions and then remove the AWS credentials from the environment variable.
    Phân tích đúng: Như trên, dùng IAM role cho CodeBuild (edit project → Service role) với policies cần thiết (S3, SSM). Xóa keys plaintext tuân thủ credential rotation và zero-standing-access. Best practice #1 cho CodeBuild security.

  • ✅ Store the DB_PASSWORD as a SecureString value in AWS Systems Manager Parameter Store and then remove the DB_PASSWORD from the environment variables.
    Phân tích đúng: Trong build phase: DB_PASSWORD=$(aws ssm get-parameter --name "/path/db-pw" --with-decryption --query Parameter.Value --output text). SecureString encrypt at-rest/transit, tích hợp KMS. Xóa env var tránh log exposure (CodeBuild logs env vars nếu debug mode).

  • ❌ Move the environment variables to the ‘db-deploy-bucket’ Amazon S3 bucket, add a prebuild stage to download, then export the variables.
    Phân tích sai: Di chuyển sang S3 (ví dụ JSON file) vẫn plaintext hoặc bucket public/default ACL, dễ leak nếu bucket misconfig. Pre-build download/export không an toàn hơn env vars gốc (vẫn log/export). AWS không recommend; dùng SSM/Secrets Manager thay thế.

  • ✅ Use AWS Systems Manager run command versus scp and ssh commands directly to the instance.
    Phân tích đúng: Thay bằng aws ssm send-command --instance-ids i-xxx --document-name AWS-RunShellScript --parameters commands=.... EC2 cần SSM agent + IAM role. Không cần key, firewall port 22, zero-trust model (audit via CloudTrail).

  • ❌ Scramble the environment variables using XOR followed by Base64, add a section to install, and then run XOR and Base64 to the build phase.
    Phân tích sai: XOR + Base64 chỉ obfuscate, không encrypt – dễ reverse (script decode trong 5s). Vi phạm compliance (không FIPS-approved), AWS cấm recommend custom crypto. Thêm install tool (base64 có sẵn) vô ích và rủi ro supply-chain.

📘 Tài liệu tham khảo

Hy vọng phân tích này giúp bạn chuẩn bị DOP-C02! 🚀 Nếu cần ví dụ code fix buildspec, hỏi thêm nhé.