Ngân hàng đề — AWS Certified DevOps Engineer Professional

Tìm thấy 681 câu.

Câu 451 Chọn nhiều đáp án
A company's application teams use AWS CodeCommit repositories for their applications. The application teams have repositories in multiple AWS accounts. All accounts are in an organization in AWS Organizations.

Each application team uses AWS IAM Identity Center (AWS Single Sign-On) configured with an external IdP to assume a developer IAM role. The developer role allows the application teams to use Git to work with the code in the repositories.

A security audit reveals that the application teams can modify the main branch in any repository. A DevOps engineer must implement a solution that allows the application teams to modify the main branch of only the repositories that they manage.

Which combination of steps will meet these requirements? (Choose three.)
  1. A Update the SAML assertion to pass the user's team name. Update the IAM role's trust policy to add an access-team session tag that has the team name.
  2. B Create an approval rule template for each team in the Organizations management account. Associate the template with all the repositories. Add the developer role ARN as an approver.
  3. C Create an approval rule template for each account. Associate the template with all repositories. Add the "aws:ResourceTag/access-team": "$ ;{aws:PrincipalTag/access-team}" condition to the approval rule template.
  4. D For each CodeCommit repository, add an access-team tag that has the value set to the name of the associated team.
  5. E Attach an SCP to the accounts. Include the following statement:
    {
      "Effect": "Deny",
      "Action": [
        "codecommit:GitPush",
        "codecommit:PutFile",
        "codecommit:Merge*"
      ],
      "Resource": "*",
      "Condition": {
        "StringEqualsIfExists": {
          "codecommit:References": ["refs/heads/main"]
        },
        "StringNotEquals": {
          "aws:ResourceTag/access-team": "${aws:PrincipalTag/access-team}"
        },
        "Null": {
          "codecommit:References": "false"
        }
      }
    }
  6. F Create an IAM permissions boundary in each account. Include the following statement:
    {
      "Effect": "Allow",
      "Action": [
        "codecommit:GitPush",
        "codecommit:PutFile",
        "codecommit:Merge*"
      ],
      "Resource": "*",
      "Condition": {
        "StringEqualsIfExists": {
          "codecommit:References": ["refs/heads/main"]
        },
        "StringNotEquals": {
          "aws:ResourceTag/access-team": "${aws:PrincipalTag/access-team}"
        },
        "Null": {
          "codecommit:References": "false"
        }
      }
    }
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi xoay quanh việc bảo mật truy cập CodeCommit repositories trong môi trường AWS Organizations đa tài khoản (multiple AWS accounts). Các team ứng dụng sử dụng AWS CodeCommit để lưu code, và họ assume developer IAM role qua AWS IAM Identity Center (SSO) kết nối với external IdP (như SAML). Hiện tại, audit phát hiện lỗ hổng: các team có thể modify main branch (push trực tiếp lên nhánh refs/heads/main) ở bất kỳ repository nào, thay vì chỉ repo họ quản lý.

Yêu cầu giải pháp: Implement 3 steps để chỉ cho phép team modify main branch của repo họ manage, sử dụng cơ chế tag-based access control (tag trên resource và principal). Giải pháp phải enforce cross-account qua Organizations, tận dụng session tags từ SSO/SAML và SCP (Service Control Policy) để deny push không hợp lệ.

Mục tiêu cốt lõi:

  • Tag repo với access-team = tên team.
  • Principal (dev role) có session tag access-team từ SAML.
  • Deny push/merge lên main nếu tag repo ≠ tag principal.

📘 Tài liệu tham khảo (AWS cập nhật 2024-2026):

✅ Đáp án đúng (Chọn 3)

Các đáp án đúng là:

  1. Update the SAML assertion to pass the user's team name. Update the IAM role's trust policy to add an access-team session tag that has the team name.
  2. For each CodeCommit repository, add an access-team tag that has the value set to the name of the associated team.
  3. Attach an SCP to the accounts. Include the following statement: (với policy Deny push/merge lên main nếu tag mismatch).

Lý do lựa chọn 🛠️:

  • Kết hợp hoàn hảo: Bước 1 truyền access-team từ SAML vào session tag của principal (dev role), giúp IAM conditions kiểm tra ${aws:PrincipalTag/access-team}.
  • Bước 2 tag repo với access-team, khớp với ABAC (Attribute-Based Access Control).
  • Bước 3 dùng SCP Deny (cross-account enforcement) chặn GitPush, PutFile, Merge* lên main nếu aws:ResourceTag/access-team ≠ ${aws:PrincipalTag/access-team}. Condition StringEqualsIfExists + Null đảm bảo chỉ áp dụng khi push lên refs/heads/main.
  • Giải pháp zero-trust, không cần approval rules (vì direct push), và hiệu quả đến 2026 (AWS khuyến nghị ABAC + SCP cho multi-account).

🔍 Phân tích chi tiết từng phương án

Dưới đây là phân tích tất cả 6 phương án, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá ✅ (Đúng - chọn) hoặc ❌ (Sai - không chọn), kèm giải thích bằng tiếng Việt.

  1. Update the SAML assertion to pass the user's team name. Update the IAM role's trust policy to add an access-team session tag that has the team name.
    ✅ Đúng. Cập nhật SAML assertion từ external IdP để truyền team name như attribute. Trust policy của dev role cho phép TransitiveTagKeys: ['access-team'] và AttributeMappings map vào session tag. Điều này inject tag vào principal session, cho phép IAM/SCP kiểm tra ${aws:PrincipalTag/access-team} khớp với repo tag. Bắt buộc cho ABAC.

  2. Create an approval rule template for each team in the Organizations management account. Associate the template with all the repositories. Add the developer role ARN as an approver.
    ❌ Sai. Approval rule templates (CodeCommit feature) dùng cho pull requests yêu cầu approve trước merge, không chặn direct Git push lên main. Tạo template ở management account không enforce per-repo/team, và thêm dev role ARN làm approver không restrict theo team (ai assume role cũng approve được). Không giải quyết vấn đề audit (direct modify main).

  3. Create an approval rule template for each account. Associate the template with all repositories. Add the "aws:ResourceTag/access-team": "${aws:PrincipalTag/access-team}" condition to the approval rule template.
    ❌ Sai. Approval rules không hỗ trợ IAM conditions như aws:ResourceTag hay ${aws:PrincipalTag} trong template (chỉ định approvers ARN hoặc groups). Đây là feature pull request, không chặn push trực tiếp. Tạo per-account/template không scalable và không match yêu cầu deny push main.

  4. For each CodeCommit repository, add an access-team tag that has the value set to the name of the associated team.
    ✅ Đúng. Tag repo với access-team: <team-name> (qua Console/CLI/API) tạo resource attribute cho IAM conditions kiểm tra ${aws:ResourceTag/access-team}. Bắt buộc để SCP/policy so sánh với principal tag, enforce "team owns repo".

  5. Attach an SCP to the accounts. Include the following statement:

    {
      "Effect": "Deny",
      "Action": [
        "codecommit:GitPush",
        "codecommit:PutFile",
        "codecommit:Merge*"
      ],
      "Resource": "*",
      "Condition": {
        "StringEqualsIfExists": {
          "codecommit:References": ["refs/heads/main"]
        },
        "StringNotEquals": {
          "aws:ResourceTag/access-team": "${aws:PrincipalTag/access-team}"
        },
        "Null": {
          "codecommit:References": "false"
        }
      }
    }
    

    ✅ Đúng. SCP attach OU/accounts deny các action push/merge lên main branch nếu tag repo ≠ principal tag. Conditions tinh tế: StringEqualsIfExists + Null: false chỉ trigger khi references = main; StringNotEquals deny mismatch. SCP enforce tất cả principals cross-account, lý tưởng cho Organizations.

  6. Create an IAM permissions boundary in each account. Include the following statement:

    {
      "Effect": "Allow",
      "Action": [
        "codecommit:GitPush",
        "codecommit:PutFile",
        "codecommit:Merge*"
      ],
      "Resource": "*",
      "Condition": {
        "StringEqualsIfExists": {
          "codecommit:References": ["refs/heads/main"]
        },
        "StringNotEquals": {
          "aws:ResourceTag/access-team": "${aws:PrincipalTag/access-team}"
        },
        "Null": {
          "codecommit:References": "false"
        }
      }
    }
    

    ❌ Sai. Permissions Boundary (PB) là allow policy giới hạn max permissions của role/user (role policy phải subset PB). Policy này "Allow" chỉ khi tag match (do StringNotEquals ngược), nhưng PB không deny (chỉ cap allow), và không enforce cross-account/team (phải set per-role). Không chặn push invalid như SCP Deny; dev role có thể có allow rộng hơn bypass PB nếu không match condition.

Tóm tắt 🎯: Giải pháp 1+4+5 tạo ABAC full-stack (SAML tag → Repo tag → SCP deny), an toàn và scalable cho multi-account DevOps! 🚀

Câu 452
A company uses AWS WAF to protect its cloud infrastructure. A DevOps engineer needs to give an operations team the ability to analyze log messages from AWS WAF. The operations team needs to be able to create alarms for specific patterns in the log output.

Which solution will meet these requirements with the LEAST operational overhead?
  1. A Create an Amazon CloudWatch Logs log group. Configure the appropriate AWS WAF web ACL to send log messages to the log group. Instruct the operations team to create CloudWatch metric filters.
  2. B Create an Amazon OpenSearch Service cluster and appropriate indexes. Configure an Amazon Kinesis Data Firehose delivery stream to stream log data to the indexes. Use OpenSearch Dashboards to create filters and widgets.
  3. C Create an Amazon S3 bucket for the log output. Configure AWS WAF to send log outputs to the S3 bucket. Instruct the operations team to create AWS Lambda functions that detect each desired log message pattern. Configure the Lambda functions to publish to an Amazon Simple Notification Service (Amazon SNS) topic.
  4. D Create an Amazon S3 bucket for the log output. Configure AWS WAF to send log outputs to the S3 bucket. Use Amazon Athena to create an external table definition that fits the log message pattern. Instruct the operations team to write SQL queries and to create Amazon CloudWatch metric filters for the Athena queries.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc bảo vệ cơ sở hạ tầng đám mây bằng AWS WAF (AWS Web Application Firewall). Một kỹ sư DevOps cần cấp quyền cho nhóm vận hành (operations team) để phân tích log messages từ AWS WAF và tạo alarms cho các pattern cụ thể trong log. Yêu cầu chính là giải pháp có ít overhead vận hành nhất (LEAST operational overhead).

🛠️ Chi tiết yêu cầu:

  • AWS WAF tạo ra log chứa thông tin về các request web (như blocked requests, patterns tấn công).
  • Nhóm vận hành cần: analyze logs và tạo alarms dựa trên pattern (ví dụ: số lượng request từ IP lạ).
  • Giải pháp phải tích hợp sẵn, dễ quản lý, không cần setup phức tạp như cluster, stream, hay code custom để giảm thiểu công sức vận hành.

📘 Kiến thức cập nhật (tính đến 2026): AWS WAF hỗ trợ logging trực tiếp đến CloudWatch Logs (từ 2019, ổn định và tích hợp sâu hơn ở phiên bản mới). Metric filters cho phép extract metrics từ logs và tạo alarms mà không cần tool ngoài.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create an Amazon CloudWatch Logs log group. Configure the appropriate AWS WAF web ACL to send log messages to the log group. Instruct the operations team to create CloudWatch metric filters.

Lý do chọn 🏆:

  • Đây là giải pháp native và đơn giản nhất của AWS: AWS WAF web ACL gửi logs trực tiếp đến CloudWatch Logs log group chỉ với vài cú click (enable logging trong WAF console).
  • Nhóm vận hành chỉ cần tạo CloudWatch metric filters trên log group để match pattern (ví dụ: regex cho "blocked" requests), sau đó tạo alarms tự động – zero code, zero infra thêm.
  • LEAST overhead: Không cần quản lý cluster, stream, hay function; tích hợp IAM policy để grant quyền analyze/alarms cho team. Hỗ trợ real-time analysis và alarms ngay lập tức.

📋 Giải thích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá ✅ (đúng) hoặc ❌ (sai) dựa trên overhead và tính phù hợp.

  • Create an Amazon CloudWatch Logs log group. Configure the appropriate AWS WAF web ACL to send log messages to the log group. Instruct the operations team to create CloudWatch metric filters.
    ✅ Đúng hoàn toàn 🥇: Như đã giải thích ở trên, đây là tích hợp trực tiếp (WAF → CloudWatch Logs), metric filters hỗ trợ pattern matching (JSON logs của WAF) để tạo metrics/alarms. Overhead thấp nhất: chỉ config ACL và IAM. Phù hợp DevOps best practice.

  • Create an Amazon OpenSearch Service cluster and appropriate indexes. Configure an Amazon Kinesis Data Firehose delivery stream to stream log data to the indexes. Use OpenSearch Dashboards to create filters and widgets.
    ❌ Sai 🚫: Giải pháp phức tạp với high overhead – cần tạo OpenSearch cluster (quản lý nodes, scaling, cost cao ~$100+/tháng), Kinesis Firehose (config stream, transformation), và indexes. OpenSearch Dashboards chỉ visualize, không native alarms cho patterns như CloudWatch. Không phải "LEAST overhead".

  • Create an Amazon S3 bucket for the log output. Configure AWS WAF to send log outputs to the S3 bucket. Instruct the operations team to create AWS Lambda functions that detect each desired log message pattern. Configure the Lambda functions to publish to an Amazon Simple Notification Service (Amazon SNS) topic.
    ❌ Sai 🚫: Overhead rất cao – WAF gửi đến S3 (batch logs), nhưng team phải viết Lambda custom (parse logs, detect patterns bằng code), trigger S3 events, publish SNS. Cần dev/test/deploy Lambda cho mỗi pattern, quản lý permissions, error handling. Không scalable và không real-time.

  • Create an Amazon S3 bucket for the log output. Configure AWS WAF to send log outputs to the S3 bucket. Use Amazon Athena to create an external table definition that fits the log message pattern. Instruct the operations team to create Amazon CloudWatch metric filters for the Athena queries.
    ❌ Sai 🚫: Phức tạp và không chính xác – S3 + Athena query logs (ad-hoc SQL), nhưng CloudWatch metric filters không hỗ trợ trực tiếp Athena queries (metric filters chỉ cho CloudWatch Logs/Events). Cần Glue crawler cho table, query delay (batch S3), và custom để convert query thành metrics. Overhead cao hơn CloudWatch native.

📘 Tài liệu tham khảo (AWS Docs mới nhất 2026)

Giải pháp này giúp team analyze & alarm nhanh chóng mà không lo quản lý infra thừa! 🚀

Câu 453
A software team is using AWS CodePipeline to automate its Java application release pipeline. The pipeline consists of a source stage, then a build stage, and then a deploy stage. Each stage contains a single action that has a runOrder value of 1.

The team wants to integrate unit tests into the existing release pipeline. The team needs a solution that deploys only the code changes that pass all unit tests.

Which solution will meet these requirements?
  1. A Modify the build stage. Add a test action that has a runOrder value of 1. Use AWS CodeDeploy as the action provider to run unit tests.
  2. B Modify the build stage. Add a test action that has a runOrder value of 2. Use AWS CodeBuild as the action provider to run unit tests.
  3. C Modify the deploy stage. Add a test action that has a runOrder value of 1. Use AWS CodeDeploy as the action provider to run unit tests.
  4. D Modify the deploy stage. Add a test action that has a runOrder value of 2. Use AWS CodeBuild as the action provider to run unit tests.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh việc tích hợp unit tests vào pipeline AWS CodePipeline cho ứng dụng Java. Pipeline hiện tại có cấu trúc đơn giản:

  • Source stage: Lấy mã nguồn (action duy nhất với runOrder = 1).
  • Build stage: Build ứng dụng (action duy nhất với runOrder = 1).
  • Deploy stage: Triển khai (action duy nhất với runOrder = 1).

Yêu cầu chính: Chỉ triển khai code nếu tất cả unit tests pass. Điều này có nghĩa là unit tests phải chạy trước deploy stage, và nếu test fail thì pipeline dừng lại (stage fail).
🛠️ runOrder trong CodePipeline quyết định thứ tự thực thi actions trong cùng một stage: Giá trị nhỏ hơn chạy trước (sequential nếu khác runOrder; parallel nếu cùng).
📘 Kiến thức cập nhật AWS 2024-2026: CodePipeline hỗ trợ Test actions chủ yếu qua AWS CodeBuild (tích hợp buildspec.yml cho unit tests như Maven/Gradle). CodeDeploy chỉ dùng cho deploy, không phải test. (Xem AWS docs mới nhất tại CodePipeline Actions).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Modify the build stage. Add a test action that has a runOrder value of 2. Use AWS CodeBuild as the action provider to run unit tests.

Lý do:

  • 🧩 Thêm Test action vào Build stage (sau action build hiện tại runOrder=1), với runOrder=2 để chạy sau build (sequential).
  • AWS CodeBuild là action provider lý tưởng cho unit tests (hỗ trợ Java: Maven test phase, báo cáo JUnit, fail pipeline nếu test fail).
  • Nếu test fail → Build stage fail → Không chuyển sang Deploy stage → Đáp ứng "chỉ deploy code pass unit tests".
  • ✅ Hoàn hảo cho CI/CD best practices AWS DevOps (tách build + test trong Build stage).

❌ Phân tích tất cả các phương án (đúng/sai)

Dưới đây là giải thích chi tiết từng lựa chọn, giữ nguyên văn bản gốc:

  • Modify the build stage. Add a test action that has a runOrder value of 1. Use AWS CodeDeploy as the action provider to run unit tests.
    ❌ Sai: runOrder=1 sẽ chạy song song với build action hiện tại (cùng runOrder), không đảm bảo build hoàn tất trước test. CodeDeploy không hỗ trợ Test action (chỉ dùng cho Deploy stage, không chạy unit tests). Sẽ fail validation pipeline.

  • Modify the build stage. Add a test action that has a runOrder value of 2. Use AWS CodeBuild as the action provider to run unit tests.
    ✅ Đúng: Như giải thích ở trên. CodeBuild lý tưởng (buildspec: phases: build: commands: - mvn test), runOrder=2 đảm bảo thứ tự đúng, fail sớm trước deploy.

  • Modify the deploy stage. Add a test action that has a runOrder value of 1. Use AWS CodeDeploy as the action provider to run unit tests.
    ❌ Sai: Thêm vào Deploy stage → Test chạy trong/song song deploy, code đã deploy trước/song song test → Không ngăn deploy nếu test fail. CodeDeploy không phải Test provider (dùng cho deployment hooks như SmokeTests, không unit tests).

  • Modify the deploy stage. Add a test action that has a runOrder value of 2. Use AWS CodeBuild as the action provider to run unit tests.
    ❌ Sai: Vẫn trong Deploy stage → Test chạy sau deploy (runOrder=2), code đã triển khai rồi mới test → Vi phạm yêu cầu "chỉ deploy nếu pass tests". Dù CodeBuild đúng provider, vị trí stage sai.

📘 Tài liệu tham khảo AWS (cập nhật 2026)

🛠️ Khuyến nghị: Sử dụng CodeBuild project với reports để lưu JUnit results, tích hợp Lambda cho notifications nếu test fail!

Câu 454
A company uses an organization in AWS Organizations to manage several AWS accounts that the company's developers use. The company requires all data to be encrypted in transit.

Multiple Amazon S3 buckets that were created in developer accounts allow unencrypted connections. A DevOps engineer must enforce encryption of data in transit for all existing S3 buckets that are created in accounts in the organization.

Which solution will meet these requirements?
  1. A Use AWS CloudFormation StackSets to deploy an AWS Network Firewall firewall to each account. Route all outbound requests from the AWS environment through the firewall. Deploy a policy to block access to all outbound requests on port 80.
  2. B Use AWS CloudFormation StackSets to deploy an AWS Network Firewall firewall to each account. Route all inbound requests to the AWS environment through the firewall. Deploy a policy to block access to all inbound requests on port 80.
  3. C Turn on AWS Config for the organization. Deploy a conformance pack that uses the s3-bucket-ssl-requests-only managed rule and an AWS Systems Manager Automation runbook. Use a runbook that adds a bucket policy statement to deny access to an S3 bucket when the value of the aws:SecureTransport condition key is false.
  4. D Turn on AWS Config for the organization. Deploy a conformance pack that uses the s3-bucket-ssl-requests-only managed rule and an AWS Systems Manager Automation runbook. Use a runbook that adds a bucket policy statement to deny access to an S3 bucket when the value of the s3:x-amz-server-side-encryption-aws-kms-key-id condition key is null.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào việc enforce encryption of data in transit (mã hóa dữ liệu khi truyền tải) cho tất cả các S3 buckets hiện có trong các AWS accounts thuộc AWS Organizations. 🎯

  • Bối cảnh: Công ty quản lý nhiều account developer qua AWS Organizations. Các S3 buckets trong đó cho phép kết nối không mã hóa (HTTP/port 80), vi phạm yêu cầu mã hóa transit (phải dùng HTTPS/SSL).
  • Yêu cầu cụ thể: DevOps engineer cần giải pháp áp dụng cho tất cả existing buckets (không chỉ mới), tự động hóa và enforce qua organization-wide. Không đề cập server-side encryption (at rest), chỉ transit.
  • Thách thức: Phải dùng cơ chế organization-level (như Config, Organizations), remediation tự động, và chính xác với S3 policy để block non-SSL access.
    📘 Kiến thức AWS cập nhật 2026: S3 hỗ trợ HTTPS mặc định, nhưng để enforce, dùng bucket policy với condition aws:SecureTransport = "false" → deny. AWS Config rule s3-bucket-ssl-requests-only kiểm tra và remediate qua SSM Automation. (Nguồn: AWS S3 Security Best Practices, AWS Config Rules).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Turn on AWS Config for the organization. Deploy a conformance pack that uses the s3-bucket-ssl-requests-only managed rule and an AWS Systems Manager Automation runbook. Use a runbook that adds a bucket policy statement to deny access to an S3 bucket when the value of the aws:SecureTransport condition key is false.

Lý do:
🛠️ Giải pháp này hoàn hảo cho organization-wide enforcement:

  • AWS Config bật organization-wide → monitor tất cả accounts.
  • Conformance pack deploy rule s3-bucket-ssl-requests-only → kiểm tra bucket policy có deny non-SSL (HTTP) không. Nếu NON_COMPLIANT, trigger SSM Automation runbook.
  • Runbook thêm bucket policy chính xác: Deny nếu aws:SecureTransport = false (tức HTTP). Đây là standard way enforce transit encryption cho existing buckets (remediate tự động).
    ✅ Ưu điểm: Áp dụng ngay cho existing buckets, scalable qua Organizations, không ảnh hưởng performance. Tuân thủ AWS Well-Architected Security Pillar (2026 update).
    (Nguồn: AWS Config Conformance Packs, SSM Remediation Examples).

📋 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn (giữ nguyên văn bản gốc), đánh dấu ✅ đúng hoặc ❌ sai, kèm giải thích bằng tiếng Việt:

  • Phương án 1 ❌: Use AWS CloudFormation StackSets to deploy an AWS Network Firewall firewall to each account. Route all outbound requests from the AWS environment through the firewall. Deploy a policy to block access to all outbound requests on port 80.
    Giải thích sai: Network Firewall block port 80 outbound không enforce encryption cho S3 buckets cụ thể (S3 dùng virtual endpoints, bypass firewall dễ dàng qua VPC endpoints hoặc direct HTTPS). Không remediate existing buckets (chỉ block traffic, không sửa policy). Phức tạp, tốn kém, không target S3 transit chính xác. Không phải best practice AWS cho S3 SSL enforcement.

  • Phương án 2 ❌: Use AWS CloudFormation StackSets to deploy an AWS Network Firewall firewall to each account. Route all inbound requests to the AWS environment through the firewall. Deploy a policy to block access to all inbound requests on port 80.
    Giải thích sai: Block inbound port 80 vô ích vì vấn đề là S3 buckets cho phép client kết nối HTTP đến S3 (outbound từ client, inbound đến S3 service). Firewall không kiểm soát S3 service endpoints. Không áp dụng cho existing buckets, không scalable cho Organizations, và không liên quan đến encryption transit policy của S3.

  • Phương án 3 ✅: Turn on AWS Config for the organization. Deploy a conformance pack that uses the s3-bucket-ssl-requests-only managed rule and an AWS Systems Manager Automation runbook. Use a runbook that adds a bucket policy statement to deny access to an S3 bucket when the value of the aws:SecureTransport condition key is false.
    Giải thích đúng: Như phần trên – rule s3-bucket-ssl-requests-only detect NON_COMPLIANT nếu thiếu policy deny non-SSL. SSM runbook remediate bằng aws:SecureTransport = false → deny (chính xác cho transit encryption). Hoạt động organization-wide, auto-fix existing buckets. Best practice 2026!

  • Phương án 4 ❌: Turn on AWS Config for the organization. Deploy a conformance pack that uses the s3-bucket-ssl-requests-only managed rule and an AWS Systems Manager Automation runbook. Use a runbook that adds a bucket policy statement to deny access to an S3 bucket when the value of the s3:x-amz-server-side-encryption-aws-kms-key-id condition key is null.
    Giải thích sai: Condition key s3:x-amz-server-side-encryption-aws-kms-key-id null dùng cho server-side encryption (at rest) với KMS, không phải transit (SSL). Sai hoàn toàn mục tiêu câu hỏi (encryption in transit). Rule s3-bucket-ssl-requests-only không match condition này, dẫn đến remediation thất bại.

🛡️ Kết luận: Giải pháp đúng tận dụng AWS native services (Config + SSM) để enforce policy-level, an toàn và hiệu quả nhất cho DevOps Professional level! Nếu cần lab thực hành, dùng AWS Free Tier với Organizations. 📘

Câu 455 Chọn nhiều đáp án
A company is developing an application that will generate log events. The log events consist of five distinct metrics every one tenth of a second and produce a large amount of data.

The company needs to configure the application to write the logs to Amazon Timestream. The company will configure a daily query against the Timestream table.

Which combination of steps will meet these requirements with the FASTEST query performance? (Choose three.)
  1. A Use batch writes to write multiple log events in a single write operation.
  2. B Write each log event as a single write operation.
  3. C Treat each log as a single-measure record.
  4. D Treat each log as a multi-measure record.
  5. E Configure the memory store retention period to be longer than the magnetic store retention period.
  6. F Configure the memory store retention period to be shorter than the magnetic store retention period.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào việc tối ưu hóa hiệu suất ghi và truy vấn dữ liệu trên Amazon Timestream – một dịch vụ cơ sở dữ liệu thời gian (time-series database) của AWS, được thiết kế để xử lý lượng dữ liệu lớn với độ trễ thấp.

Ứng dụng tạo ra log events chứa 5 metrics riêng biệt mỗi 0.1 giây, dẫn đến lượng dữ liệu khổng lồ (high-velocity data). Công ty cần:

  • Ghi logs vào Timestream table.
  • Thực hiện query hàng ngày (daily query).

Mục tiêu: Chọn 3 bước kết hợp để đạt hiệu suất truy vấn NHANH NHẤT (FASTEST query performance).

Các yếu tố ảnh hưởng đến hiệu suất truy vấn trên Timestream bao gồm:

  • Cách ghi dữ liệu (single vs batch, single vs multi-measure).
  • Cấu hình memory store (lưu trữ tạm thời, query siêu nhanh) và magnetic store (lưu trữ lâu dài, chậm hơn nhưng rẻ).

Dựa trên tài liệu AWS Timestream mới nhất (cập nhật đến 2026), Timestream khuyến nghị sử dụng batch writes, multi-measure records cho dữ liệu có nhiều metrics cùng timestamp, và memory store retention ngắn hơn magnetic store để ưu tiên query dữ liệu gần đây từ memory store. 📘

✅ Đáp án đúng (Chọn 3 phương án sau)

Các phương án đúng là:

  1. Use batch writes to write multiple log events in a single write operation.
  2. Treat each log as a multi-measure record.
  3. Configure the memory store retention period to be shorter than the magnetic store retention period.

Lý do lựa chọn (tóm tắt ngắn gọn):

  • Những bước này giảm số lượng records, tối ưu hóa ghi dữ liệu hàng loạt, và ưu tiên query từ memory store nhanh chóng cho daily query, giúp đạt hiệu suất cao nhất. Theo best practices AWS DOP-C02 (2024-2026), kết hợp chúng giảm latency query lên đến 10x so với cấu hình mặc định. 🛠️

📝 Phân tích chi tiết tất cả các phương án

Dưới đây là giải thích từng phương án một cách rõ ràng, dựa trên nguyên lý hoạt động của Timestream:

  • ✅ Use batch writes to write multiple log events in a single write operation.
    Đúng: Ghi dữ liệu theo batch (tối đa 100 records/lần) giảm số lượng API calls, throughput cao hơn (lên đến 1.000 writes/giây/table), và giảm overhead. Với dữ liệu high-velocity (0.1s/log), batch giúp tối ưu hóa ghi và query nhanh hơn vì dữ liệu được tổ chức hiệu quả. Trái lại, single write chậm và tốn kém hơn.

  • ❌ Write each log event as a single write operation.
    Sai: Ghi từng log riêng lẻ tạo ra hàng triệu API calls, dẫn đến throttling, latency cao khi ghi, và query chậm vì dữ liệu phân mảnh. Timestream giới hạn 200 writes/giây cho single, không phù hợp với dữ liệu lớn – vi phạm nguyên tắc batching của AWS.

  • ❌ Treat each log as a single-measure record.
    Sai: Với 5 metrics/log cùng timestamp, single-measure tạo 5 records riêng biệt → tăng số lượng records lên 5x, làm query scan nhiều dữ liệu hơn, chậm hơn. Multi-measure hiệu quả hơn cho trường hợp này.

  • ✅ Treat each log as a multi-measure record.
    Đúng: Mỗi log là 1 record chứa 5 measures (dimensions chung), giảm số records đáng kể (từ 5 xuống 1/log), query nhanh hơn vì ít dữ liệu scan. Hỗ trợ tối đa 128 measures/record (cập nhật 2025), lý tưởng cho daily query trên dữ liệu metrics-dense. 🏆

  • ❌ Configure the memory store retention period to be longer than the magnetic store retention period.
    Sai: Memory store dành cho dữ liệu recent (query <1ms), magnetic cho dữ liệu cũ. Nếu memory dài hơn magnetic, dữ liệu cũ bị xóa sớm khỏi magnetic và không migrate đúng, gây query thất bại hoặc chậm. Best practice: Memory ngắn (ví dụ 1-3 ngày), magnetic dài (hàng tháng/năm).

  • ✅ Configure the memory store retention period to be shorter than the magnetic store retention period.
    Đúng: Daily query chủ yếu truy cập dữ liệu recent → ưu tiên memory store (nhanh nhất). Ví dụ: Memory 1 ngày < Magnetic 365 ngày → query gần như 100% từ memory, giảm latency từ giây xuống ms. Đây là cấu hình chuẩn cho workload real-time/high-velocity (AWS docs 2026). ⚡

📚 Tài liệu tham khảo

  • AWS Timestream Developer Guide (2026): Best practices for writing data – Nhấn mạnh batch/multi-measure/memory retention.
  • DOP-C02 Exam Guide (AWS 2024-2026): Domain 4 – Optimization, ví dụ Timestream performance tuning.
  • Timestream Limits: Quotas – Batch 100 records, multi-measure tối ưu query.
  • Blog AWS: "Optimizing Timestream for High-Throughput Workloads" (2025).

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm ví dụ code hoặc query sample, hãy hỏi nhé! 😊

Câu 456 Chọn nhiều đáp án
A DevOps engineer has created an AWS CloudFormation template that deploys an application on Amazon EC2 instances. The EC2 instances run Amazon Linux. The application is deployed to the EC2 instances by using shell scripts that contain user data. The EC2 instances have an IAM instance profile that has an IAM role with the AmazonSSMManagedinstanceCore managed policy attached.

The DevOps engineer has modified the user data in the CloudFormation template to install a new version of the application. The engineer has also applied the stack update. However, the application was not updated on the running EC2 instances. The engineer needs to ensure that the changes to the application are installed on the running EC2 instances.

Which combination of steps will meet these requirements? (Choose two.)
  1. A Configure the user data content to use the Multipurpose Internet Mail Extensions (MIME) multipart format. Set the scripts-user parameter to always in the text/cloud-config section.
  2. B Refactor the user data commands to use the cfn-init helper script. Update the user data to install and configure the cfn-hup and cfn-init helper scripts to monitor and apply the metadata changes.
  3. C Configure an EC2 launch template for the EC2 instances. Create a new EC2 Auto Scaling group. Associate the Auto Scaling group with the EC2 launch template. Use the AutoScalingScheduledAction update policy for the Auto Scaling group.
  4. D Refactor the user data commands to use an AWS Systems Manager document (SSM document). Add an AWS CLI command in the user data to use Systems Manager Run Command to apply the SSM document to the EC2 instances.
  5. E Refactor the user data command to use an AWS Systems Manager document (SSM document). Use Systems Manager State Manager to create an association between the SSM document and the EC2 instances.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào tình huống một DevOps Engineer đã tạo AWS CloudFormation template để triển khai ứng dụng trên Amazon EC2 instances chạy Amazon Linux. Ứng dụng được deploy qua shell scripts trong user data. Các EC2 có IAM instance profile gắn IAM role với policy AmazonSSMManagedInstanceCore (cho phép sử dụng AWS Systems Manager - SSM).

🔄 Vấn đề chính: Engineer đã sửa user data trong template để cài phiên bản ứng dụng mới, sau đó update stack CloudFormation. Tuy nhiên, ứng dụng không được cập nhật trên các EC2 đang chạy (running instances). Lý do: User data chỉ chạy một lần lúc instance khởi động (launch), không tự động rerun khi update metadata từ CloudFormation.

🎯 Yêu cầu: Chọn TWO bước kết hợp để đảm bảo thay đổi ứng dụng được áp dụng lên running EC2 instances mà không cần thay thế instance. Giải pháp phải tận dụng CloudFormation metadata hoặc SSM (vì đã có policy SSM sẵn).

📘 Kiến thức cập nhật (AWS 2026): User data không rerun tự động sau stack update (xem AWS CloudFormation User Guide). Cần dùng helper như cfn-hup hoặc SSM State Manager để monitor và apply changes. Không dùng rolling update mặc định vì không hỗ trợ user data rerun.

✅ Đáp án đúng (Chọn TWO)

Hai phương án đúng là:
B: Refactor the user data commands to use the cfn-init helper script. Update the user data to install and configure the cfn-hup and cfn-init helper scripts to monitor and apply the metadata changes.
E: Refactor the user data command to use an AWS Systems Manager document (SSM document). Use Systems Manager State Manager to create an association between the SSM document and the EC2 instances.

Lý do chọn:
🛠️ Phương án B tận dụng cfn-init (helper script của CloudFormation) để parse metadata và chạy commands từ template. cfn-hup (helper daemon) monitor thay đổi metadata mỗi 15 phút (mặc định) và tự động rerun cfn-init, áp dụng update lên running instances mà không downtime. Phù hợp nhất cho CloudFormation updates.
🛠️ Phương án E refactor commands vào SSM document (YAML/JSON định nghĩa actions), rồi dùng SSM State Manager tạo association với EC2 (target bằng tag hoặc instance ID). State Manager liên tục enforce state (periodic/check), update document sẽ apply ngay lên running instances nhờ IAM role SSM sẵn có. Hỗ trợ compliance và idempotent.

📋 Giải thích chi tiết tất cả các phương án

  • ❌ Phương án A (SAI):
    Configure the user data content to use the Multipurpose Internet Mail Extensions (MIME) multipart format. Set the scripts-user parameter to always in the text/cloud-config section.
    Giải thích sai: MIME multipart cho phép chạy nhiều scripts/types trong user data (cloud-init trên Amazon Linux 2+). scripts-user: always chỉ đảm bảo script chạy lúc boot, không monitor/update metadata từ CloudFormation stack update. User data vẫn chỉ execute once lúc launch, không rerun trên running instances. Không giải quyết vấn đề core.

  • ✅ Phương án B (ĐÚNG):
    Refactor the user data commands to use the cfn-init helper script. Update the user data to install and configure the cfn-hup and cfn-init helper scripts to monitor and apply the metadata changes.
    Giải thích đúng: cfn-init đọc config từ CloudFormation metadata (AWS::CloudFormation::Init section) và chạy commands. cfn-hup chạy như daemon, poll metadata changes (mặc định 15 phút) và trigger cfn-init lại. Khi stack update, metadata thay đổi → cfn-hup detect → apply app mới lên running EC2. Idempotent, zero-downtime. Hoàn hảo cho scenario này.

  • ❌ Phương án C (SAI):
    Configure an EC2 launch template for the EC2 instances. Create a new EC2 Auto Scaling group. Associate the Auto Scaling group with the EC2 launch template. Use the AutoScalingScheduledAction update policy for the Auto Scaling group.
    Giải thích sai: Tạo launch template + new ASG + ScheduledAction sẽ thay thế (replace) instances cũ bằng instances mới (rolling update theo lịch). Không update running instances hiện tại, mà terminate và launch mới → gây downtime ngắn và không giữ nguyên instances đang chạy. Không phù hợp yêu cầu "install on running EC2".

  • ❌ Phương án D (SAI):
    Refactor the user data commands to use an AWS Systems Manager document (SSM document). Add an AWS CLI command in the user data to use Systems Manager Run Command to apply the SSM document to the EC2 instances.
    Giải thích sai: SSM Run Command chạy one-time trên target instances tốt, nhưng thêm AWS CLI vào user data chỉ execute lúc launch lần đầu, không rerun sau stack update. Running instances không được trigger lại, và cần manual invoke Run Command sau. Không tự động/monitor changes như State Manager.

  • ✅ Phương án E (ĐÚNG):
    Refactor the user data command to use an AWS Systems Manager document (SSM document). Use Systems Manager State Manager to create an association between the SSM document and the EC2 instances.
    Giải thích đúng: SSM document chứa commands idempotent (install app). State Manager association liên kết document với EC2 (qua tag/InstanceIds), chạy periodic (mặc định 1 ngày) hoặc on-change. Update document/association → State Manager enforce ngay trên running instances (nhờ SSM agent + IAM policy). Scale tốt, audit trail đầy đủ.

📚 Tài liệu tham khảo (AWS Docs mới nhất 2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần ví dụ code, hỏi thêm nhé!

Câu 457 Chọn nhiều đáp án
A company is refactoring applications to use AWS. The company identifies an internal web application that needs to make Amazon S3 API calls in a specific AWS account.

The company wants to use its existing identity provider (IdP) auth.company.com for authentication. The IdP supports only OpenID Connect (OIDC). A DevOps engineer needs to secure the web application's access to the AWS account.

Which combination of steps will meet these requirements? (Choose three.)
  1. A Configure AWS IAM Identity Center (AWS Single Sign-On). Configure an IdP. Upload the IdP metadata from the existing IdP.
  2. B Create an IAM IdP by using the provider URL, audience, and signature from the existing IP.
  3. C Create an IAM role that has a policy that allows the necessary S3 actions. Configure the role's trust policy to allow the OIDC IP to assume the role if the sts.amazon.com:aud context key is appid_from_idp.
  4. D Create an IAM role that has a policy that allows the necessary S3 actions. Configure the role's trust policy to allow the OIDC IP to assume the role if the auth.company.com:aud context key is appid_from_idp.
  5. E Configure the web application to use the AssumeRoleWithWebIdentity API operation to retrieve temporary credentials. Use the temporary credentials to make the S3 API calls.
  6. F Configure the web application to use the GetFederationToken API operation to retrieve temporary credentials. Use the temporary credentials to make the S3 API calls.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc secure hóa quyền truy cập của một web application nội bộ vào Amazon S3 API trong một AWS account cụ thể, khi công ty đang refactor ứng dụng lên AWS.

  • Yêu cầu chính: Web app cần gọi S3 API, sử dụng IdP hiện có (auth.company.com) chỉ hỗ trợ OpenID Connect (OIDC) cho authentication. Không dùng IAM user/password, mà phải dùng federation để cấp temporary credentials an toàn.
  • Mục tiêu: DevOps engineer cần thiết kế quy trình OIDC federation với IAM để web app assume role và gọi S3. Chọn 3 steps đúng từ các lựa chọn.
  • Kiến thức cốt lõi (cập nhật AWS 2024-2026): AWS hỗ trợ OIDC qua IAM OIDC Identity Provider (IdP), kết hợp IAM Role với trust policy sử dụng context keys (như {ProviderURL}:aud), và API AssumeRoleWithWebIdentity để lấy temporary creds từ ID token của OIDC.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Các đáp án đúng (chọn 3):

  • Create an IAM IdP by using the provider URL, audience, and signature from the existing IP.
  • Create an IAM role that has a policy that allows the necessary S3 actions. Configure the role's trust policy to allow the OIDC IP to assume the role if the auth.company.com:aud context key is appid_from_idp.
  • Configure the web application to use the AssumeRoleWithWebIdentity API operation to retrieve temporary credentials. Use the temporary credentials to make the S3 API calls.

Lý do chọn 🛠️:

  • Đây là quy trình chuẩn OIDC federation cho web apps (như JavaScript/SAML/OIDC clients). Bước 1 tạo IAM OIDC IdP từ metadata IdP. Bước 2 tạo IAM Role với permissions S3 + trust policy dùng context key chính xác (auth.company.com:aud) để validate audience trong ID token. Bước 3 dùng AssumeRoleWithWebIdentity (dành riêng cho OIDC/SAML web identity) để lấy creds tạm thời, đảm bảo least privilege và không cần long-term keys. Quy trình này tuân thủ AWS best practices cho cross-account access với external IdP.

📋 Giải thích chi tiết từng phương án

Dưới đây là phân tích từng lựa chọn (giữ nguyên text gốc tiếng Anh). Sử dụng ✅ cho đúng, ❌ cho sai:

  • ❌ Configure AWS IAM Identity Center (AWS Single Sign-On). Configure an IdP. Upload the IdP metadata from the existing IdP.
    Phương án này sai vì IAM Identity Center (SSO, nay là IAM Identity Center) dành cho human users/groups qua SSO portal (như phép users login console/apps). Không phù hợp cho machine-to-machine hoặc web app gọi API trực tiếp như S3. OIDC federation cần IAM OIDC IdP riêng, không qua Identity Center.

  • ✅ Create an IAM IdP by using the provider URL, audience, and signature from the existing IP.
    Phương án này đúng vì đây là bước đầu tiên chuẩn: Tạo IAM OIDC Identity Provider với URL (auth.company.com), Audience (appid_from_idp), và thumbprint/signature từ metadata IdP. AWS verify JWT token từ IdP này trước khi allow assume role.

  • ❌ Create an IAM role that has a policy that allows the necessary S3 actions. Configure the role's trust policy to allow the OIDC IP to assume the role if the sts.amazon.com:aud context key is appid_from_idp.
    Phương án này sai vì context key sai: Với OIDC, phải dùng {ProviderURL}:aud (ví dụ: auth.company.com:aud), không phải sts.amazon.com:aud (dành cho STS service contexts khác). Sử dụng sai sẽ làm trust policy fail validation ID token.

  • ✅ Create an IAM role that has a policy that allows the necessary S3 actions. Configure the role's trust policy to allow the OIDC IP to assume the role if the auth.company.com:aud context key is appid_from_idp.
    Phương án này đúng vì context key chính xác: auth.company.com:aud match Provider URL + audience từ ID token OIDC. Role policy cấp S3 actions (như s3:GetObject), trust policy chỉ allow IdP assume nếu aud=appid_from_idp, đảm bảo security chặt chẽ.

  • ✅ Configure the web application to use the AssumeRoleWithWebIdentity API operation to retrieve temporary credentials. Use the temporary credentials to make the S3 API calls.
    Phương án này đúng vì AssumeRoleWithWebIdentity là API chuẩn cho OIDC/SAML web federation. Web app dùng ID token từ IdP (auth.company.com) để gọi API này, nhận AccessKey/Secret/STS token tạm thời (1h), rồi dùng gọi S3. An toàn, không lưu long-term creds.

  • ❌ Configure the web application to use the GetFederationToken API operation to retrieve temporary credentials. Use the temporary credentials to make the S3 API calls.
    Phương án này sai vì GetFederationToken yêu cầu long-term IAM creds (AccessKey) để gọi, không hỗ trợ OIDC token trực tiếp. Nó dùng cho internal federation (như STS session), không phù hợp với external IdP OIDC. Sẽ vi phạm yêu cầu "no long-term creds" và kém secure.

🧠 Lưu ý cuối: Quy trình này có thể mở rộng với Condition keys thêm (như token expiry, sub claim) để tăng security. Test qua AWS CLI: aws iam create-open-id-connect-provider.

Câu 458
A company uses Amazon RDS for all databases in its AWS accounts. The company uses AWS Control Tower to build a landing zone that has an audit and logging account. All databases must be encrypted at rest for compliance reasons. The company's security engineer needs to receive notification about any noncompliant databases that are in the company’s accounts.

Which solution will meet these requirements with the MOST operational efficiency?
  1. A Use AWS Control Tower to activate the optional detective control (guardrail) to determine whether the RDS storage is encrypted. Create an Amazon Simple Notification Service (Amazon SNS) topic in the company's audit account. Create an Amazon EventBridge rule to filter noncompliant events from the AWS Control Tower control (guardrail) to notify the SNS topic. Subscribe the security engineer's email address to the SNS topic.
  2. B Use AWS CloudFormation StackSets to deploy AWS Lambda functions to every account. Write the Lambda function code to determine whether the RDS storage is encrypted in the account the function is deployed to. Send the findings as an Amazon CloudWatch metric to the management account. Create an Amazon Simple Notification Service (Amazon SNS) topic. Create a CloudWatch alarm that notifies the SNS topic when metric thresholds are met. Subscribe the security engineer's email address to the SNS topic.
  3. C Create a custom AWS Config rule in every account to determine whether the RDS storage is encrypted. Create an Amazon Simple Notification Service (Amazon SNS) topic in the audit account. Create an Amazon EventBidge rule to filter noncompliant events from the AWS Control Tower control (guardrail) to notify the SNS topic. Subscribe the security engineer's email address to the SNS topic.
  4. D Launch an Amazon C2 instance. Run an hourly cron job by using the AWS CLI to determine whether the RDS storage is encrypted in each AWS account. Store the results in an RDS database. Notify the security engineer by sending email messages from the EC2 instance when noncompliance is detected
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc đảm bảo tuân thủ mã hóa tại chỗ (encryption at rest) cho tất cả cơ sở dữ liệu Amazon RDS trong các AWS accounts của công ty. Công ty sử dụng AWS Control Tower để thiết lập landing zone với một audit and logging account riêng biệt. Yêu cầu chính là security engineer phải nhận thông báo (notification) về bất kỳ RDS instance nào không tuân thủ (noncompliant). Giải pháp cần đạt hiệu quả vận hành cao nhất (MOST operational efficiency), nghĩa là ưu tiên các tính năng tự động, native của AWS, giảm thiểu code tùy chỉnh, quản lý thủ công hoặc triển khai phức tạp trên nhiều account.
📘 Bối cảnh cập nhật đến 2026: AWS Control Tower (phiên bản mới nhất) hỗ trợ detective guardrails tùy chọn để kiểm tra mã hóa RDS storage. Các guardrail này tích hợp trực tiếp với Amazon EventBridge để phát hiện và thông báo sự kiện noncompliant mà không cần code thêm.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng là phương án đầu tiên.
🛠️ Lý do: Phương án này tận dụng tính năng native của AWS Control Tower bằng cách kích hoạt optional detective guardrail chuyên kiểm tra mã hóa RDS storage. Guardrail tự động giám sát tất cả accounts trong landing zone, gửi sự kiện noncompliant qua EventBridge đến SNS topic ở audit account. Security engineer chỉ cần subscribe email – hoàn toàn không code, không triển khai thủ công, đạt hiệu quả vận hành tối ưu (zero-touch management). Đây là best practice theo AWS Well-Architected Framework cho multi-account governance.

📋 Giải thích chi tiết từng phương án

Dưới đây là phân tích tất cả 4 phương án, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá ✅ (đúng) hoặc ❌ (sai), kèm giải thích rõ ràng về lý do phù hợp/không phù hợp với yêu cầu MOST operational efficiency.

  • Use AWS Control Tower to activate the optional detective control (guardrail) to determine whether the RDS storage is encrypted. Create an Amazon Simple Notification Service (Amazon SNS) topic in the company's audit account. Create an Amazon EventBridge rule to filter noncompliant events from the AWS Control Tower control (guardrail) to notify the SNS topic. Subscribe the security engineer's email address to the SNS topic.
    ✅ Đúng và hiệu quả nhất: Guardrail native của Control Tower (cập nhật 2024-2026) tự động kiểm tra RDS encryption trên toàn landing zone. EventBridge + SNS chỉ là routing đơn giản, không cần code hay deploy per-account. Hoàn hảo cho multi-account, audit account centralized.

  • Use AWS CloudFormation StackSets to deploy AWS Lambda functions to every account. Write the Lambda function code to determine whether the RDS storage is encrypted in the account the function is deployed to. Send the findings as an Amazon CloudWatch metric to the management account. Create an Amazon Simple Notification Service (Amazon SNS) topic. Create a CloudWatch alarm that notifies the SNS topic when metric thresholds are met. Subscribe the security engineer's email address to the SNS topic.
    ❌ Sai: Yêu cầu viết code Lambda tùy chỉnh, deploy StackSets qua mọi account (phức tạp quản lý, scale kém). Gửi metrics qua CloudWatch rồi alarm – operational overhead cao, không native như guardrail. Không tận dụng Control Tower, vi phạm "MOST operational efficiency".

  • Create a custom AWS Config rule in every account to determine whether the RDS storage is encrypted. Create an Amazon Simple Notification Service (Amazon SNS) topic in the audit account. Create an Amazon EventBidge rule to filter noncompliant events from the AWS Control Tower control (guardrail) to notify the SNS topic. Subscribe the security engineer's email address to the SNS topic.
    ❌ Sai: Phải tạo custom AWS Config rule ở mọi account (deploy thủ công/per-account, tốn kém maintain). Phần EventBridge đề cập "Control Tower guardrail" nhưng không kích hoạt guardrail thật sự – mâu thuẫn logic, thiếu tính native. AWS Config advanced nhưng kém efficient hơn guardrail built-in cho RDS encryption.

  • Launch an Amazon C2 instance. Run an hourly cron job by using the AWS CLI to determine whether the RDS storage is encrypted in each AWS account. Store the results in an RDS database. Notify the security engineer by sending email messages from the EC2 instance when noncompliance is detected
    ❌ Sai hoàn toàn: Sử dụng EC2 (lưu ý: có lẽ typo "C2", ý là EC2) với cron job CLI – thủ công, không scalable, tốn chi phí idle instance. Cross-account polling kém an toàn, lưu kết quả vào RDS riêng (overkill). Không tự động hóa, vi phạm mọi nguyên tắc DevOps efficiency.

📘 Tài liệu tham khảo (AWS docs cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm ví dụ thực hành, hãy hỏi nhé!

Câu 459 Chọn nhiều đáp án
A company is migrating from its on-premises data center to AWS. The company currently uses a custom on-premises Cl/CD pipeline solution to build and package software.

The company wants its software packages and dependent public repositories to be available in AWS CodeArtifact to facilitate the creation of application-specific pipelines.

Which combination of steps should the company take to update the CI/CD pipeline solution and to configure CodeArtifact with the LEAST operational overhead? (Choose two.)
  1. A Update the C1ICD pipeline to create a VM image that contains newly packaged software. Use AWS Import/Export to make the VM image available as an Amazon EC2 AMI. Launch the AMI with an attached IAM instance profile that allows CodeArtifact actions. Use AWS CLI commands to publish the packages to a CodeArtifact repository.
  2. B Create an AWS Identity and Access Management Roles Anywhere trust anchor. Create an IAM role that allows CodeArtifact actions and that has a trust relationship on the trust anchor. Update the on-premises CI/CD pipeline to assume the new IAM role and to publish the packages to CodeArtifact.
  3. C Create a new Amazon S3 bucket. Generate a presigned URL that allows the PutObject request. Update the on-premises CI/CD pipeline to use the presigned URL to publish the packages from the on-premises location to the S3 bucket. Create an AWS Lambda function that runs when packages are created in the bucket through a put command. Configure the Lambda function to publish the packages to CodeArtifact.
  4. D For each public repository, create a CodeArutact repository that is configured with an external connection. Configure the dependent repositories as upstream public repositories.
  5. E Create a Codeartitact repository that is configured with a set of external connections to the public repositories. Configure the external connections to be downstream of the repository.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc migrate CI/CD pipeline tùy chỉnh từ on-premises sang AWS, cụ thể là làm cho software packages (gói phần mềm tự build) và dependent public repositories (các kho lưu trữ công khai phụ thuộc, như npm, Maven public) có sẵn trong AWS CodeArtifact. Mục tiêu là cập nhật pipeline CI/CD và cấu hình CodeArtifact với LEAST operational overhead (ít nỗ lực vận hành nhất), chọn TWO steps kết hợp.

  • Bối cảnh: Công ty dùng pipeline on-prem để build/package software. Họ muốn dùng CodeArtifact làm private repository manager để dễ dàng tạo pipelines riêng cho từng ứng dụng (application-specific pipelines).
  • Yêu cầu chính:
    • Publish packages tự build từ on-prem vào CodeArtifact (cần auth an toàn, ít overhead).
    • Kết nối với public repos để pull dependencies (không copy thủ công).
  • Phiên bản AWS mới nhất (2026): CodeArtifact hỗ trợ external connections làm upstream (kéo packages từ public repos như npmjs.com). IAM Roles Anywhere (ra mắt 2021, cập nhật liên tục) cho phép on-prem servers assume IAM roles qua certificate-based auth, lý tưởng cho hybrid workloads mà không cần VPN/Direct Connect đầy đủ.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng là hai lựa chọn sau (kết hợp để đạt LEAST overhead):

  • Lựa chọn thứ 2: Sử dụng IAM Roles Anywhere để on-prem CI/CD assume IAM role và publish trực tiếp vào CodeArtifact – an toàn, không cần infra thêm, auth zero-trust.
  • Lựa chọn thứ 4: Tạo CodeArtifact repository với external connection upstream cho từng public repo – tự động proxy/pull dependencies từ public sources.

Lý do chọn:

  • Kết hợp này trực tiếp, serverless-native, không cần VM/S3/Lambda trung gian. On-prem publish thẳng (qua Roles Anywhere), dependencies tự động available (qua upstream connections). Overhead thấp: chỉ config IAM + repository (mất vài phút), scale tự động, tích hợp sẵn với CodeBuild/CodePipeline.

🛠️ Giải thích chi tiết từng phương án

  • ❌ Phương án SAI:
    Update the C1ICD pipeline to create a VM image that contains newly packaged software. Use AWS Import/Export to make the VM image available as an Amazon EC2 AMI. Launch the AMI with an attached IAM instance profile that allows CodeArtifact actions. Use AWS CLI commands to publish the packages to a CodeArtifact repository.
    Giải thích sai: Overhead cao vì tạo VM image + Import/Export (Snowball/AWS DataSync chậm, tốn kém cho dữ liệu thường xuyên). Phải launch EC2 AMI mới mỗi lần – không scale, không "least overhead". Không phù hợp on-prem direct publish.

  • ✅ Phương án ĐÚNG:
    Create an AWS Identity and Access Management Roles Anywhere trust anchor. Create an IAM role that allows CodeArtifact actions and that has a trust relationship on the trust anchor. Update the on-premises CI/CD pipeline to assume the new IAM role and to publish the packages to CodeArtifact.
    Giải thích đúng: IAM Roles Anywhere dùng trust anchor (certificate CA) để on-prem CI/CD servers assume IAM role tạm thời, gọi aws codeartifact put-package trực tiếp. Least overhead: Không cần VPC peering/VPN/EC2, auth mTLS an toàn, tích hợp CLI/SDK. Cập nhật 2026: Hỗ trợ EKS/ECS on-prem hybrid.

  • ❌ Phương án SAI:
    Create a new Amazon S3 bucket. Generate a presigned URL that allows the PutObject request. Update the on-premises CI/CD pipeline to use the presigned URL to publish the packages from the on-premises location to the S3 bucket. Create an AWS Lambda function that runs when packages are created in the bucket through a put command. Configure the Lambda function to publish the packages to CodeArtifact.
    Giải thích sai: Gián tiếp (on-prem → S3 → Lambda → CodeArtifact), thêm EventBridge/S3 trigger + Lambda polling – overhead vận hành cao (quản lý Lambda code, error handling, cold starts). Không hiệu quả cho CI/CD real-time, vi phạm "least overhead".

  • ✅ Phương án ĐÚNG:
    For each public repository, create a CodeArutact repository that is configured with an external connection. Configure the dependent repositories as upstream public repositories.
    Giải thích đúng: CodeArtifact external connection làm upstream (proxy/pull từ public repos như PyPI/Maven Central). Tạo repo riêng cho từng public repo → dependencies available ngay trong CodeArtifact cho pipelines. Least overhead: Config 1-click qua Console/CLI, cache tự động, không copy thủ công. (Lưu ý typo "CodeArutact" → CodeArtifact).

  • ❌ Phương án SAI:
    Create a Codeartitact repository that is configured with a set of external connections to the public repositories. Configure the external connections to be downstream of the repository.
    Giải thích sai: External connections chỉ hỗ trợ upstream (CodeArtifact pull từ public), không có "downstream" (push ra ngoài). Sai khái niệm AWS (docs xác nhận: upstream only). Tạo 1 repo với multi-connections cũng không hiệu quả bằng per-repo cho isolation.

📘 Tài liệu tham khảo (AWS mới nhất 2026)

Hy vọng phân tích giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ CLI, hỏi nhé!

Câu 460
A DevOps team uses AWS CodePipeline, AWS CodeBuild, and AWS CodeDeploy to deploy an application. The application is a REST API that uses AWS Lambda functions and Amazon API Gateway. Recent deployments have introduced errors that have affected many customers.

The DevOps team needs a solution that reverts to the most recent stable version of the application when an error is detected. The solution must affect the fewest customers possible.

Which solution will meet these requirements with the MOST operational efficiency?
  1. A Set the deployment configuration in CodeDeploy to LambdaAllAtOnce. Configure automatic rollbacks on the deployment group. Create an Amazon CloudWatch alarm that detects HTTP Bad Gateway errors on API Gateway. Configure the deployment group to roll back when the number of alarms meets the alarm threshold.
  2. B Set the deployment configuration in CodeDeploy to LambdaCanary10Percent10Minutes. Configure automatic rollbacks on the deployment group. Create an Amazon CloudWatch alarm that detects HTTP Bad Gateway errors on API Gateway. Configure the deployment group to roll back when the number of alarms meets the alarm threshold.
  3. C Set the deployment configuration in CodeDeploy to LambdaAllAtOnce. Configure manual rollbacks on the deployment group. Create an Amazon Simple Notification Service (Amazon SNS) topic to send notifications every time a deployment fails. Configure the SNS topic to invoke a new Lambda function that stops the current deployment and starts the most recent successful deployment.
  4. D Set the deployment configuration in CodeDeploy to LambdaCanary10Percent10Minutes. Configure manual rollbacks on the deployment group. Create a metric filter on an Amazon CloudWatch log group for API Gateway to monitor HTTP Bad Gateway errors. Configure the metric filter to invoke a new Lambda function that stops the current deployment and starts the most recent successful deployment.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi

Câu hỏi xoay quanh một đội DevOps đang sử dụng AWS CodePipeline, AWS CodeBuild và AWS CodeDeploy để triển khai ứng dụng REST API dựa trên AWS Lambda và Amazon API Gateway. Gần đây, các lần deploy mới đã gây lỗi ảnh hưởng đến nhiều khách hàng.

Yêu cầu chính của giải pháp:

  • ✅ Tự động revert (rollback) về phiên bản ổn định gần nhất khi phát hiện lỗi.
  • ✅ Ảnh hưởng đến ít khách hàng nhất có thể (minimize blast radius).
  • ✅ Đạt operational efficiency cao nhất (tự động hóa tối đa, ít can thiệp thủ công).

🛠️ Bối cảnh kỹ thuật: Với Lambda + API Gateway, CodeDeploy hỗ trợ các deployment config đặc thù như Canary (triển khai dần dần theo % traffic) hoặc AllAtOnce (toàn bộ ngay lập tức). Lỗi thường là HTTP Bad Gateway (503 - từ API Gateway khi Lambda lỗi). Giải pháp cần kết hợp deployment strategy an toàn, automatic rollback và monitoring qua CloudWatch để detect lỗi sớm.

📘 Kiến thức cập nhật (AWS 2026): CodeDeploy for Lambda hỗ trợ Canary10Percent10Minutes (10% traffic trong 10 phút, sau đó 100%), automatic rollbacks dựa trên CloudWatch alarms (metric: 5xx errors từ API Gateway). Đây là best practice cho serverless, giảm rủi ro theo AWS Well-Architected Framework (Reliability pillar).

Nguồn tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Set the deployment configuration in CodeDeploy to LambdaCanary10Percent10Minutes. Configure automatic rollbacks on the deployment group. Create an Amazon CloudWatch alarm that detects HTTP Bad Gateway errors on API Gateway. Configure the deployment group to roll back when the number of alarms meets the alarm threshold.

Lý do:

  • 🛡️ Canary deployment (LambdaCanary10Percent10Minutes): Chỉ triển khai 10% traffic trong 10 phút đầu, giúp detect lỗi sớm mà ảnh hưởng ít khách hàng nhất (chỉ 10% thay vì 100%).
  • 🔄 Automatic rollbacks: CodeDeploy tự động revert về phiên bản trước khi alarm threshold đạt (ví dụ: số lượng Bad Gateway errors > ngưỡng). Không cần thủ công.
  • 📊 CloudWatch alarm trên HTTP Bad Gateway: Metric chính xác từ API Gateway (5xx errors), tích hợp native với CodeDeploy.
  • 🚀 Operational efficiency cao nhất: Toàn bộ tự động, không custom code/Lambda, tuân thủ zero-touch operations.

🧪 Phân tích tất cả các phương án

  • Phương án 1 ❌ [SAI] Set the deployment configuration in CodeDeploy to LambdaAllAtOnce. Configure automatic rollbacks on the deployment group. Create an Amazon CloudWatch alarm that detects HTTP Bad Gateway errors on API Gateway. Configure the deployment group to roll back when the number of alarms meets the alarm threshold.
    Giải thích sai: LambdaAllAtOnce triển khai toàn bộ 100% traffic ngay lập tức, gây ảnh hưởng lớn đến tất cả khách hàng nếu lỗi xảy ra (không minimize blast radius). Dù có auto rollback và alarm tốt, nhưng strategy deploy không an toàn, vi phạm yêu cầu "fewest customers possible".

  • Phương án 2 ✅ [ĐÚNG] Set the deployment configuration in CodeDeploy to LambdaCanary10Percent10Minutes. Configure automatic rollbacks on the deployment group. Create an Amazon CloudWatch alarm that detects HTTP Bad Gateway errors on API Gateway. Configure the deployment group to roll back when the number of alarms meets the alarm threshold.
    Giải thích đúng: Như phần trên, kết hợp Canary 10% (ít ảnh hưởng), auto rollback native và alarm chuẩn, đạt efficiency cao nhất mà không cần custom logic.

  • Phương án 3 ❌ [SAI] Set the deployment configuration in CodeDeploy to LambdaAllAtOnce. Configure manual rollbacks on the deployment group. Create an Amazon Simple Notification Service (Amazon SNS) topic to send notifications every time a deployment fails. Configure the SNS topic to invoke a new Lambda function that stops the current deployment and starts the most recent successful deployment.
    Giải thích sai: AllAtOnce ảnh hưởng lớn; manual rollbacks yêu cầu can thiệp tay (không efficient); dùng SNS + custom Lambda để stop/start deploy phức tạp, tốn kém maintain, không tự động native như CodeDeploy alarms. Không đáp ứng "MOST operational efficiency".

  • Phương án 4 ❌ [SAI] Set the deployment configuration in CodeDeploy to LambdaCanary10Percent10Minutes. Configure manual rollbacks on the deployment group. Create a metric filter on an Amazon CloudWatch log group for API Gateway to monitor HTTP Bad Gateway errors. Configure the metric filter to invoke a new Lambda function that stops the current deployment and starts the most recent successful deployment.
    Giải thích sai: Dù Canary tốt (ít ảnh hưởng), nhưng manual rollbacks và custom Lambda từ metric filter (trên CloudWatch Logs) làm giải pháp không tự động, phức tạp hơn native alarms. Metric filter chỉ parse logs (chậm hơn metrics), kém efficiency so với auto rollback trực tiếp từ CodeDeploy.