Ngân hàng đề — AWS Certified DevOps Engineer Professional

Tìm thấy 681 câu.

Câu 471 Chọn nhiều đáp án
A DevOps engineer is building an application that uses an AWS Lambda function to query an Amazon Aurora MySQL DB cluster. The Lambda function performs only read queries. Amazon EventBridge events invoke the Lambda function.

As more events invoke the Lambda function each second, the database's latency increases and the database's throughput decreases. The DevOps engineer needs to improve the performance of the application.

Which combination of steps will meet these requirements? (Choose three.)
  1. A Use Amazon RDS Proxy to create a proxy. Connect the proxy to the Aurora cluster reader endpoint. Set a maximum connections percentage on the proxy.
  2. B Implement database connection pooling inside the Lambda code. Set a maximum number of connections on the database connection pool.
  3. C Implement the database connection opening outside the Lambda event handler code.
  4. D Implement the database connection opening and closing inside the Lambda event handler code.
  5. E Connect to the proxy endpoint from the Lambda function.
  6. F Connect to the Aurora cluster endpoint from the Lambda function.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả một tình huống thực tế trong AWS: Một DevOps engineer đang xây dựng ứng dụng sử dụng AWS Lambda function để thực hiện chỉ các truy vấn đọc (read queries) trên Amazon Aurora MySQL DB cluster. Lambda được kích hoạt bởi Amazon EventBridge events.

📈 Vấn đề chính: Khi số lượng events tăng lên mỗi giây (tăng tải), latency của database tăng (thời gian phản hồi chậm hơn) và throughput của database giảm (số lượng truy vấn xử lý/giây thấp hơn). Nguyên nhân gốc rễ là:

  • Lambda là serverless, mỗi invocation có thể tạo container mới (cold start), dẫn đến việc mở/đóng kết nối DB lặp lại gây connection overhead.
  • Aurora MySQL cluster có reader endpoint cho reads, nhưng kết nối trực tiếp từ Lambda dễ bị giới hạn connections và scaling issues.
  • Không có cơ chế pooling hoặc proxy, DB bị quá tải bởi hàng nghìn connections ngắn hạn từ Lambda.

🎯 Yêu cầu: Chọn kết hợp 3 bước để cải thiện performance (giảm latency, tăng throughput). Giải pháp tập trung vào RDS Proxy (quản lý connections serverless), reuse connections trong Lambda, và reader endpoint cho reads only.

✅ Đáp án đúng (Chọn 3 phương án sau)

Các đáp án đúng là sự kết hợp hoàn hảo theo best practices AWS mới nhất (2024-2026): Sử dụng RDS Proxy để proxy connections đến Aurora reader endpoint (tối ưu reads), giới hạn connections, và Lambda kết nối qua proxy với connection reuse (mở ngoài handler).

  1. Use Amazon RDS Proxy to create a proxy. Connect the proxy to the Aurora cluster reader endpoint. Set a maximum connections percentage on the proxy.
    🛠️ Lý do: RDS Proxy là dịch vụ serverless quản lý connection pooling cho Lambda/RDS, giảm overhead bằng cách multiplex connections. Kết nối proxy với reader endpoint tận dụng Aurora replicas cho reads (scale reads). Set max connections % (ví dụ 80%) tránh DB quá tải. Giảm latency >50% theo AWS benchmarks.

  2. Implement the database connection opening outside the Lambda event handler code.
    🛠️ Lý do: Mở connection ở global scope (ngoài handler) cho phép Lambda reuse container và connection giữa invocations, giảm cold starts và connection churn. Đây là best practice cốt lõi cho Lambda + DB.

  3. Connect to the proxy endpoint from the Lambda function.
    🛠️ Lý do: Lambda kết nối proxy endpoint thay vì DB trực tiếp, tận dụng pooling/multiplexing của Proxy, đảm bảo scalability và security (IAM auth).

Kết quả tổng thể: Giảm connections từ hàng nghìn xuống hàng trăm, latency giảm 70-90%, throughput tăng theo scale events (EventBridge).

📘 Giải thích tất cả các phương án (Đúng/Sai)

Dưới đây là phân tích từng phương án một, giữ nguyên văn bản gốc tiếng Anh. Mỗi sai sẽ chỉ ra lý do không phù hợp và best practice thay thế.

✅ Use Amazon RDS Proxy to create a proxy. Connect the proxy to the Aurora cluster reader endpoint. Set a maximum connections percentage on the proxy.
🛠️ Phương án ĐÚNG. RDS Proxy (ra mắt 2020, cập nhật 2025 hỗ trợ Aurora Serverless v2) là giải pháp lý tưởng cho Lambda reads: Proxy kết nối reader endpoint (tự động scale reads sang replicas), set max connections % (throttle nếu vượt) bảo vệ DB. Theo AWS Well-Architected Framework (DevOps Pillar), giảm connection storms 90%.
📚 Nguồn: AWS RDS Proxy Docs.

❌ Implement database connection pooling inside the Lambda code. Set a maximum number of connections on the database connection pool.
🚫 SAI. Pooling trong Lambda code (ví dụ dùng SQLAlchemy pool) không hiệu quả vì Lambda stateless, container reuse không đảm bảo, dẫn đến stale connections và memory leaks. RDS Proxy xử lý pooling tốt hơn, không cần code thủ công. Best practice: Dùng Proxy thay vì custom pooling.

✅ Implement the database connection opening outside the Lambda event handler code.
🛠️ Phương án ĐÚNG. Theo Lambda runtime model (Node.js/Python/Java 2025+), mở connection ở module/global level (init phase) cho phép reuse giữa invocations (warm containers ~70% cases), giảm latency 50-80ms/connection. Không làm trong handler để tránh mở/đóng mỗi event.
📚 Nguồn: AWS Lambda Best Practices.

❌ Implement the database connection opening and closing inside the Lambda event handler code.
🚫 SAI. Đây là anti-pattern phổ biến gây vấn đề chính: Mỗi EventBridge event mở/đóng connection → thousands connections/sec → DB throttle (max_connections Aurora ~4000+). Tăng latency và giảm throughput, chính xác tình huống câu hỏi.

✅ Connect to the proxy endpoint from the Lambda function.
🛠️ Phương án ĐÚNG. Lambda dùng proxy endpoint (ví dụ proxy-abc123.us-east-1.rds.amazonaws.com:3306) với IAM/secrets auth, Proxy handle multiplexing đến reader endpoint. Scale tự động theo Lambda concurrency.

❌ Connect to the Aurora cluster endpoint from the Lambda function.
🚫 SAI. Kết nối trực tiếp cluster endpoint (primary writable) không tận dụng readers, gây overload primary instance (reads + writes nếu có). Reader endpoint tốt hơn, nhưng vẫn cần Proxy cho Lambda scaling. Dẫn đến connection exhaustion nhanh.

🔗 Tài liệu tham khảo chính (Cập nhật 2026)

Hy vọng phân tích giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần ví dụ code Lambda, hỏi thêm nhé!

Câu 472
A company has an AWS CloudFormation stack that is deployed in a single AWS account. The company has configured the stack to send event notifications to an Amazon Simple Notification Service (Amazon SNS) topic.

A DevOps engineer must implement an automated solution that applies a tag to the specific CloudFormation stack instance only after a successful stack update occurs. The DevOps engineer has created an AWS Lambda function that applies and updates this tag for the specific stack instance.

Which solution will meet these requirements?
  1. A Run the AWS-UpdateCloudFormationStack AWS Systems ManagerAutomation runbook when Systems Manager detects an UPDATE_COMPLETE event for the instance status of the CloudFormation stack. Configure the runbook to invoke the Lambda function.
  2. B Create a custom AWS Config rule that produces a compliance change event if the CloudFormation stack has an UPDATE_COMPLETE instance status. Configure AWS Config to directly invoke the Lambda function to automatically remediate the change event.
  3. C Create an Amazon EventBridge rule that matches the UPDATE_COMPLETE event pattern for the instance status of the CloudFormation stack. Configure the rule to invoke the Lambda function.
  4. D Adjust the configuration of the CloudFormation stack to send notifications for only an UPDATE_COMPLETE instance status event to the SNS topic. Subscribe the Lambda function to the SNS topic.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi mô tả một tình huống thực tế trong AWS: Một công ty đang quản lý một CloudFormation stack được triển khai trong một tài khoản AWS duy nhất. Stack này đã được cấu hình để gửi event notifications (các thông báo sự kiện) đến một Amazon SNS topic (chủ yếu là các sự kiện về trạng thái stack như CREATE_IN_PROGRESS, UPDATE_COMPLETE, v.v.).

📋 Yêu cầu chính của DevOps engineer:

  • Triển khai giải pháp tự động hóa để áp dụng một tag cụ thể lên chính instance stack CloudFormation đó (không phải toàn bộ tài nguyên).
  • Tag chỉ được áp dụng sau khi stack update thành công, tức là khi trạng thái stack đạt UPDATE_COMPLETE (xác nhận update hoàn tất mà không lỗi).
  • Đã có sẵn một AWS Lambda function để thực hiện việc thêm/cập nhật tag cho stack instance cụ thể.

🛠️ Mục tiêu: Tìm giải pháp tối ưu, tự động, chính xác chỉ trigger Lambda khi sự kiện UPDATE_COMPLETE xảy ra cho stack cụ thể, sử dụng kiến thức AWS cập nhật đến 2026 (EventBridge là dịch vụ chính thức hỗ trợ CloudFormation events native từ năm 2019, với các cải tiến filter pattern mạnh mẽ hơn).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Create an Amazon EventBridge rule that matches the UPDATE_COMPLETE event pattern for the instance status of the CloudFormation stack. Configure the rule to invoke the Lambda function.

Lý do chi tiết 🏆:

  • Amazon EventBridge (trước đây là CloudWatch Events) là dịch vụ native của AWS để capture và route CloudFormation events một cách real-time, serverless, và không phụ thuộc SNS. Từ năm 2023-2026, EventBridge hỗ trợ event patterns chi tiết cho CloudFormation (source: "aws.cloudformation"), detail-type: "CloudFormation Stack Action", với filter trên "detail.status" == "UPDATE_COMPLETE" và "detail.stackName" match tên stack cụ thể.
  • Rule EventBridge có thể trực tiếp invoke Lambda mà không cần trung gian, đảm bảo low latency (dưới 1 giây), cost-effective (chỉ charge per event), và chính xác (filter event pattern chỉ trigger cho stack instance đúng).
  • Giải pháp này meet 100% requirements: Tự động, chỉ sau UPDATE_COMPLETE, target specific stack, không ảnh hưởng stack hiện tại (vì SNS đã config nhưng không dùng ở đây).
  • So với các option khác, đây là best practice theo AWS Well-Architected Framework (DevOps pillar) cho event-driven architecture.

📋 Phân tích tất cả các phương án

Dưới đây là phân tích từng lựa chọn một cách chi tiết, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phân tích giải thích đúng/sai dựa trên cơ chế AWS mới nhất (2026), với lý do kỹ thuật cụ thể:

  • ❌ Phương án SAI:
    Run the AWS-UpdateCloudFormationStack AWS Systems ManagerAutomation runbook when Systems Manager detects an UPDATE_COMPLETE event for the instance status of the CloudFormation stack. Configure the runbook to invoke the Lambda function.
    Giải thích sai: Systems Manager (SSM) Automation không hỗ trợ detect CloudFormation events real-time như UPDATE_COMPLETE một cách native. Runbook AWS-UpdateCloudFormationStack (nếu tồn tại) chỉ dùng để update stack, không phải apply tag. SSM cần State Manager hoặc Session Manager để detect, nhưng không event-driven, phải poll thủ công, không tự động và overkill (chi phí cao, latency lớn). Không meet yêu cầu real-time cho specific event.

  • ❌ Phương án SAI:
    Create a custom AWS Config rule that produces a compliance change event if the CloudFormation stack has an UPDATE_COMPLETE instance status. Configure AWS Config to directly invoke the Lambda function to automatically remediate the change event.
    Giải thích sai: AWS Config dùng cho compliance monitoring và configuration changes của resources (như stack drift), KHÔNG phải real-time events như CloudFormation stack status (UPDATE_COMPLETE là transient event, không lưu trong Config snapshot). Config rules không trigger trực tiếp từ stack events, chỉ từ configuration recorder (poll-based, delay 1-15 phút). Remediation via Lambda chỉ cho non-compliant states, không phù hợp và không chính xác cho UPDATE_COMPLETE trigger.

  • ✅ Phương án ĐÚNG (như đã phân tích ở trên):
    Create an Amazon EventBridge rule that matches the UPDATE_COMPLETE event pattern for the instance status of the CloudFormation stack. Configure the rule to invoke the Lambda function.
    Giải thích đúng: EventBridge native capture tất cả CFN events (bao gồm UPDATE_COMPLETE) từ source "aws.cloudformation". Filter pattern mẫu: {"source": ["aws.cloudformation"], "detail-type": ["CloudFormation Stack Action"], "detail": {"stackName": ["specific-stack"], "status": ["UPDATE_COMPLETE"]}}. Invoke Lambda trực tiếp qua target, zero config thêm, scalable đến 2026 với Partner Event Sources.

  • ❌ Phương án SAI:
    Adjust the configuration of the CloudFormation stack to send notifications for only an UPDATE_COMPLETE instance status event to the SNS topic. Subscribe the Lambda function to the SNS topic.
    Giải thích sai: CloudFormation notifications có thể filter events (qua NotificationARN trong template), nhưng stack hiện tại đã config gửi TẤT CẢ events đến SNS chung → adjust yêu cầu update template và redeploy stack (circular dependency, rủi ro). SNS subscription broad-cast đến tất cả subscribers, không filter specific stack instance dễ dàng (cần thêm filter policy phức tạp). Latency cao hơn EventBridge (SNS + Lambda ~3-5s), không optimal so với EventBridge native (AWS khuyến nghị migrate SNS sang EventBridge từ 2024).

📘 Tài liệu tham khảo (AWS Docs cập nhật 2026)

  • EventBridge + CloudFormation: Using EventBridge with CloudFormation – Chi tiết event patterns.
  • CloudFormation Notifications: CloudFormation SNS Notifications.
  • Best Practices: AWS Well-Architected DevOps Lens (2025): Event-driven tagging với EventBridge.
  • Exam Tip 🎓: DOP-C02 (DevOps Pro) thường test EventBridge vs. legacy SNS/CloudWatch cho automation.

Giải pháp này đảm bảo zero-downtime, cost-optimized! Nếu cần demo code filter pattern, hãy hỏi thêm. 🚀

Câu 473
A company deploys an application to two AWS Regions. The application creates and stores objects in an Amazon S3 bucket that is in the same Region as the application. Both deployments of the application need to have access to all the objects and their metadata from both Regions. The company has configured two-way replication between the S3 buckets and has enabled S3 Replication metrics on each S3 bucket.

A DevOps engineer needs to implement a solution that retries the replication process if an object fails to replicate.

Which solution will meet these requirements?
  1. A Create an Amazon EventBridge rule that listens to S3 event notifications for failed replication events. Create an AWS Lambda function that downloads the failed replication object and then runs a PutObject command for the object to the destination bucket. Configure the EventBridge rule to invoke the Lambda function to handle the object that failed to replicate.
  2. B Create an Amazon Simple Queue Service (Amazon SQS) queue. Configure S3 event notifications to send failed replication notifications to the SQS queue. Create an AWS Lambda function that downloads the failed replication object and then runs a PutObject command for the object to the destination bucket. Configure the Lambda function to poll the queue for notifications to process.
  3. C Create an Amazon EventBridge rule that listens to S3 event notifications for failed replications. Create an AWS Lambda function that downloads the failed replication object and then runs a PutObject command for the object to the destination bucket.
  4. D Create an AWS Lambda function that will use S3 batch operations to retry the replication on the existing object for a failed replication. Configure S3 event notifications to send failed replication notifications to the Lambda function.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi này xoay quanh Amazon S3 Cross-Region Replication (CRR) trong môi trường AWS đa vùng (multi-Region). Một công ty triển khai ứng dụng tại hai AWS Regions, với ứng dụng tạo và lưu trữ objects trong bucket S3 cùng Region. Yêu cầu là cả hai deployments cần truy cập đầy đủ objects và metadata từ cả hai bên. Họ đã cấu hình two-way replication (replication hai chiều) giữa hai buckets và kích hoạt S3 Replication metrics trên mỗi bucket.

📌 Vấn đề cốt lõi: DevOps engineer cần giải pháp tự động retry (thử lại) quá trình replication nếu một object fail replicate.

  • S3 Replication tự động sao chép objects, metadata, tags, ACLs, versioning... nhưng có thể fail do quota, permissions, hoặc lỗi tạm thời.
  • S3 Replication metrics và events (như s3:Replication:OperationFailedReplication) giúp theo dõi và notify failures.
  • Giải pháp phải hiệu quả, scalable, không can thiệp thủ công, và retry replication thực thụ (không phải copy thủ công) để giữ nguyên tính toàn vẹn metadata.

Mục tiêu: Đảm bảo replication đáng tin cậy mà không làm gián đoạn ứng dụng. Kiến thức dựa trên AWS S3 cập nhật 2024-2026, nơi S3 hỗ trợ Batch Operations cho retry replication và event notifications chi tiết hơn.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Create an AWS Lambda function that will use S3 batch operations to retry the replication on the existing object for a failed replication. Configure S3 event notifications to send failed replication notifications to the Lambda function.

🛠️ Lý do chi tiết:

  • S3 Event Notifications capture sự kiện failed replication (event type: s3:Replication:OperationFailedReplication) và gửi trực tiếp đến Lambda, giúp trigger ngay lập tức mà không cần polling.
  • Lambda sử dụng S3 Batch Operations (job type: Copy với S3 Replication) để retry replication trên objects failed. Điều này giữ nguyên toàn bộ metadata, tags, versioning, encryption – giống hệt replication gốc, không phải copy thủ công.
  • Scalable và best practice: Batch Operations xử lý hàng triệu objects hiệu quả, hỗ trợ manifest từ replication metrics, và retry idempotent (an toàn lặp lại).
  • Two-way replication được hỗ trợ đầy đủ, tránh loop vô tận nhờ metrics tracking.
  • Cập nhật AWS 2026: S3 Batch hỗ trợ enhanced replication retry với metrics chi tiết hơn (docs AWS xác nhận).

📘 Tài liệu tham khảo:

🔍 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng phương án một cách chi tiết, giữ nguyên văn bản gốc tiếng Anh. Tôi sử dụng ✅ cho đúng và ❌ cho sai, kèm lý do dựa trên best practices AWS.

  • ❌ Phương án 1 (SAI):
    Create an Amazon EventBridge rule that listens to S3 event notifications for failed replication events. Create an AWS Lambda function that downloads the failed replication object and then runs a PutObject command for the object to the destination bucket. Configure the EventBridge rule to invoke the Lambda function to handle the object that failed to replicate.
    Lý do sai: EventBridge đúng hướng (capture events), nhưng Lambda download rồi PutObject thủ công không phải replication thực thụ. ❌ Mất metadata đầy đủ (tags, versioning, ACLs, Object Lock), không scalable cho large objects (chi phí GetObject + PutObject cao), và có thể trigger replication loop. Không dùng cơ chế retry native của S3.

  • ❌ Phương án 2 (SAI):
    Create an Amazon Simple Queue Service (Amazon SQS) queue. Configure S3 event notifications to send failed replication notifications to the SQS queue. Create an AWS Lambda function that downloads the failed replication object and then runs a PutObject command for the object to the destination bucket. Configure the Lambda function to poll the queue for notifications to process.
    Lý do sai: SQS + polling Lambda ổn định nhưng vẫn dùng download/PutObject thủ công – cùng vấn đề như phương án 1. ❌ Polling tốn tài nguyên (không real-time như direct invoke), chi phí cao hơn, và không đảm bảo tính toàn vẹn replication (không replicate metadata đúng cách). Không phải giải pháp AWS recommend cho retry replication.

  • ❌ Phương án 3 (SAI):
    Create an Amazon EventBridge rule that listens to S3 event notifications for failed replications. Create an AWS Lambda function that downloads the failed replication object and then runs a PutObject command for the object to the destination bucket.
    Lý do sai: Tương tự phương án 1, thiếu config invoke chi tiết nhưng core issue là download/PutObject. ❌ Không hiệu quả, không giữ metadata, rủi ro timeout với large objects, và không tận dụng S3 Batch (best tool cho bulk retry). EventBridge dư thừa nếu không kết hợp replication native.

  • ✅ Phương án 4 (ĐÚNG):
    Create an AWS Lambda function that will use S3 batch operations to retry the replication on the existing object for a failed replication. Configure S3 event notifications to send failed replication notifications to the Lambda function.
    Lý do đúng: Kết hợp hoàn hảo S3 Events direct-to-Lambda (real-time, no polling) và S3 Batch Operations để retry replication chính xác. ✅ Scalable, chi phí thấp, giữ nguyên mọi thuộc tính object, hỗ trợ two-way mà không loop. Đây là official AWS solution cho failed replications.

Kết luận 💡: Giải pháp đúng tận dụng native S3 features (Events + Batch), tránh custom code phức tạp. Nếu implement, cần IAM roles phù hợp (s3:CreateJob, replication rules). Recommend test với Replication Time Control (RTC) cho SLA 99.99%! 🚀

Câu 474
A company needs to implement failover for its application. The application includes an Amazon CloudFront distribution and a public Application Load Balancer (ALB) in an AWS Region. The company has configured the ALB as the default origin for the distribution.

After some recent application outages, the company wants a zero-second RTO. The company deploys the application to a secondary Region in a warm standby configuration. A DevOps engineer needs to automate the failover of the application to the secondary Region so that HTTP GET requests meet the desired RTO.

Which solution will meet these requirements?
  1. A Create a second CloudFront distribution that has the secondary ALB as the default origin. Create Amazon Route 53 alias records that have a failover policy and Evaluate Target Health set to Yes for both CloudFront distributions. Update the application to use the new record set.
  2. B Create a new origin on the distribution for the secondary ALCreate a new origin group. Set the original ALB as the primary origin. Configure the origin group to fail over for HTTP 5xx status codes. Update the default behavior to use the origin group.
  3. C Create Amazon Route 53 alias records that have a failover policy and Evaluate Target Health set to Yes for both ALBs. Set the TTL of both records to 0. Update the distribution's origin to use the new record set.
  4. D Create a CloudFront function that detects HTTP 5xx status codes. Configure the function to return a 307 Temporary Redirect error response to the secondary ALB if the function detects 5xx status codes. Update the distribution's default behavior to send origin responses to the function.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai failover cho ứng dụng sử dụng Amazon CloudFront làm CDN và Application Load Balancer (ALB) công khai ở một AWS Region chính. ALB hiện là origin mặc định cho CloudFront. Sau các sự cố gián đoạn gần đây, công ty yêu cầu zero-second RTO (Recovery Time Objective), nghĩa là thời gian khôi phục phải bằng 0 giây (không gián đoạn). Họ đã triển khai ứng dụng ở secondary Region theo mô hình warm standby (sẵn sàng ấm, có thể scale nhanh). Nhiệm vụ của DevOps engineer là tự động hóa failover để các yêu cầu HTTP GET đạt RTO mong muốn.

🔑 Yêu cầu cốt lõi:

  • Failover phải tự động, dựa trên lỗi (như 5xx từ origin chính).
  • Zero-second RTO: Không phụ thuộc vào DNS propagation (có thể mất vài giây/phút), TTL=0 vẫn không đảm bảo 0s.
  • Giải pháp phải tận dụng CloudFront để failover immediate tại edge locations.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create a new origin on the distribution for the secondary ALB. Create a new origin group. Set the original ALB as the primary origin. Configure the origin group to fail over for HTTP 5xx status codes. Update the default behavior to use the origin group.

Lý do chọn đáp án này 🛠️:

  • CloudFront Origin Groups (tính năng từ 2021, cập nhật đến 2026) cho phép failover tự động tức thì (zero-second RTO) giữa primary và secondary origin mà không cần thay đổi DNS hay Route 53.
  • Thêm origin mới cho secondary ALB, tạo origin group với ALB chính làm primary, secondary làm backup.
  • Cấu hình failover khi nhận HTTP 5xx (server errors) từ primary → CloudFront tự động route traffic sang secondary ngay lập tức tại edge locations, không gián đoạn người dùng.
  • Cập nhật default behavior dùng origin group → Áp dụng toàn bộ distribution.
  • Hoàn hảo cho warm standby, vì secondary Region đã sẵn sàng scale.

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Tôi đánh dấu ✅ đúng hoặc ❌ sai, kèm giải thích bằng tiếng Việt:

  • ❌ Phương án A: Create a second CloudFront distribution that has the secondary ALB as the default origin. Create Amazon Route 53 alias records that have a failover policy and Evaluate Target Health set to Yes for both CloudFront distributions. Update the application to use the new record set.
    Giải thích sai: Phương án dùng hai CloudFront distributions riêng biệt + Route 53 failover policy với health check. Tuy có Evaluate Target Health = Yes, nhưng RTO không zero-second vì phụ thuộc DNS propagation (dù TTL thấp vẫn mất 1-60s toàn cầu). Phải update DNS record của app → Không tự động hoàn toàn, phức tạp và tốn kém (2 distributions).

  • ✅ Phương án B (đúng, như đã giải thích ở trên): Create a new origin on the distribution for the secondary ALB. Create a new origin group. Set the original ALB as the primary origin. Configure the origin group to fail over for HTTP 5xx status codes. Update the default behavior to use the origin group.
    Giải thích đúng: Xem phần ✅ ở trên. Đây là giải pháp tối ưu, native của CloudFront, hỗ trợ failover immediate cho 5xx errors, zero-downtime.

  • ❌ Phương án C: Create Amazon Route 53 alias records that have a failover policy and Evaluate Target Health set to Yes for both ALBs. Set the TTL of both records to 0. Update the distribution's origin to use the new record set.
    Giải thích sai: Dùng Route 53 failover trực tiếp cho hai ALB, TTL=0, health check Yes. Vẫn không zero-second RTO vì DNS caching/propagation tại resolver của client/edge (CloudFront phải resolve DNS mới, mất vài giây). Update origin của CloudFront dùng record set → CloudFront cache origin lâu, failover chậm.

  • ❌ Phương án D: Create a CloudFront function that detects HTTP 5xx status codes. Configure the function to return a 307 Temporary Redirect error response to the secondary ALB if the function detects 5xx status codes. Update the distribution's default behavior to send origin responses to the function.
    Giải thích sai: Dùng CloudFront Functions (viewer/request/response) để detect 5xx và redirect 307 sang secondary ALB. Không phải failover thật: Redirect gây thêm latency (extra request), không transparent (client thấy 307, có thể cache sai), và không zero-second (chỉ sau khi nhận 5xx mới redirect). Phức tạp, không scalable cho warm standby.

📘 Tài liệu tham khảo (cập nhật đến 2026)

Giải pháp này đảm bảo high availability toàn cầu! 🚀 Nếu cần demo CDK/Terraform, hãy hỏi thêm.

Câu 475
A cloud team uses AWS Organizations and AWS IAM Identity Center (AWS Single Sign-On) to manage a company's AWS accounts. The company recently established a research team. The research team requires the ability to fully manage the resources in its account. The research team must not be able to create IAM users.

The cloud team creates a Research Administrator permission set in IAM Identity Center for the research team. The permission set has the AdministratorAccess AWS managed policy attached. The cloud team must ensure that no one on the research team can create IAM users.

Which solution will meet these requirements?
  1. A Create an IAM policy that denies the iam:CreateUser action. Attach the IAM policy to the Research Administrator permission set.
  2. B Create an IAM policy that allows all actions except the iam:CreateUser action. Use the IAM policy to set the permissions boundary for the Research Administrator permission set.
  3. C Create an SCP that denies the iam:CreateUser action. Attach the SCP to the research team's AWS account.
  4. D Create an AWS Lambda function that deletes IAM users. Create an Amazon EventBridge rule that detects the IAM CreateUser event. Configure the rule to invoke the Lambda function.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm AWS

📘 Nội dung câu hỏi được giải thích rõ ràng:
Câu hỏi xoay quanh việc sử dụng AWS Organizations và AWS IAM Identity Center (trước đây là AWS SSO) để quản lý tài khoản AWS của công ty. Một nhóm nghiên cứu (research team) mới được thành lập với tài khoản riêng, cần quyền quản lý đầy đủ (fully manage) tất cả tài nguyên trong tài khoản đó, nhưng KHÔNG được phép tạo IAM users. Nhóm cloud đã tạo permission set tên Research Administrator trong IAM Identity Center, gắn policy AdministratorAccess (AWS managed policy cho phép tất cả hành động *). Yêu cầu là đảm bảo không ai trong research team có thể tạo IAM users, ngay cả khi họ có quyền admin cao.

Đây là tình huống điển hình trong multi-account strategy của AWS Organizations (cập nhật đến 2026), nơi cần phân tách quyền delegation qua permission sets (dựa trên IAM roles được assume qua SSO) nhưng vẫn kiểm soát chặt chẽ qua Service Control Policies (SCP) để tránh bypass. SCP có precedence cao nhất, chặn hành động ngay cả với IAM policies allow.

✅ Đáp án đúng:
Create an SCP that denies the iam:CreateUser action. Attach the SCP to the research team's AWS account.

Lý do lựa chọn (chi tiết):
🛠️ SCP là Service Control Policy trong AWS Organizations, áp dụng ở mức OU (Organizational Unit) hoặc account, chặn hành động cụ thể trên toàn tài khoản, bất kể IAM role/user có allow hay không (explicit deny trong SCP override mọi IAM policy).

  • Research team assume permission set với AdministratorAccess (cho phép iam:CreateUser), nhưng SCP deny iam:CreateUser sẽ ngăn chặn hoàn toàn, kể cả admin không thể bypass bằng cách chỉnh sửa role/policy.
  • Đáp ứng yêu cầu: Fully manage resources (trừ create IAM users), an toàn ở Organizations level.
  • Cập nhật 2026: SCP hỗ trợ full IAM actions control, khuyến nghị cho guardrails trong landing zone (AWS Control Tower).

📘 Tài liệu tham khảo:

🔍 Phân tích tất cả các phương án (đúng/sai)

  • Create an IAM policy that denies the iam:CreateUser action. Attach the IAM policy to the Research Administrator permission set.
    ❌ Sai. Policy deny này attach vào permission set (tạo IAM role) sẽ chặn iam:CreateUser cho research team khi assume role. Tuy nhiên, AdministratorAccess cho phép iam:UpdateRole, iam:DetachRolePolicy, nên research team (admin) có thể tự detach policy deny này và tạo IAM users, bypass dễ dàng. Không đảm bảo "no one can create".

  • Create an IAM policy that allows all actions except the iam:CreateUser action. Use the IAM policy to set the permissions boundary for the Research Administrator permission set.
    ❌ Sai. Permissions boundary (giới hạn max quyền cho role) là allow-based, policy "* except iam:CreateUser" sẽ intersect với AdministratorAccess → chặn CreateUser. Nhưng: (1) Research admin có thể chỉnh sửa boundary (iam:SetRolePermissionsBoundaryToPolicy); (2) Boundary không phải deny explicit, dễ bypass; (3) Không phù hợp cho Organizations delegation. Cập nhật 2026: Boundary hỗ trợ deny nhưng không thay thế SCP cho account-wide control.

  • Create an SCP that denies the iam:CreateUser action. Attach the SCP to the research team's AWS account.
    ✅ Đúng (như đã giải thích ở trên). SCP enforce ở Organizations level, không thể bypass bởi IAM admins, lý tưởng cho research account dedicated.

  • Create an AWS Lambda function that deletes IAM users. Create an Amazon EventBridge rule that detects the IAM CreateUser event. Configure the rule to invoke the Lambda function.
    ❌ Sai. Đây là giải pháp reactive (phát hiện và xóa sau khi tạo), không ngăn "must not be able to create" (họ vẫn tạo được tạm thời). Phức tạp, tốn kém, không best practice; có race condition (user tồn tại ngắn). EventBridge + Lambda dùng cho audit/compliance, không thay SCP. Cập nhật 2026: CloudTrail + EventBridge cải tiến nhưng vẫn không preventive.

Câu 476
A company releases a new application in a new AWS account. The application includes an AWS Lambda function that processes messages from an Amazon Simple Queue Service (Amazon SQS) standard queue. The Lambda function stores the results in an Amazon S3 bucket for further downstream processing. The Lambda function needs to process the messages within a specific period of time after the messages are published. The Lambda function has a batch size of 10 messages and takes a few seconds to process a batch of messages.

As load increases on the application's first day of service, messages in the queue accumulate at a greater rate than the Lambda function can process the messages. Some messages miss the required processing timelines. The logs show that many messages in the queue have data that is not valid. The company needs to meet the timeline requirements for messages that have valid data.

Which solution will meet these requirements?
  1. A Increase the Lambda function's batch size. Change the SQS standard queue to an SQS FIFO queue. Request a Lambda concurrency increase in the AWS Region.
  2. B Reduce the Lambda function's batch size. Increase the SQS message throughput quota. Request a Lambda concurrency increase in the AWS Region.
  3. C Increase the Lambda function's batch size. Configure S3 Transfer Acceleration on the S3 bucket. Configure an SQS dead-letter queue.
  4. D Keep the Lambda function's batch size the same. Configure the Lambda function to report failed batch items. Configure an SQS dead-letter queue.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một ứng dụng mới được triển khai trên tài khoản AWS mới, bao gồm một hàm AWS Lambda xử lý tin nhắn từ Amazon SQS standard queue. Hàm Lambda này nhận tin nhắn theo batch kích thước 10, xử lý trong vài giây, rồi lưu kết quả vào Amazon S3 bucket để xử lý tiếp theo. Yêu cầu quan trọng: Tin nhắn phải được xử lý trong một khoảng thời gian cụ thể sau khi được publish vào queue.

🔥 Vấn đề gặp phải:

  • Ngày đầu tiên, tải tăng cao → Tin nhắn tích tụ nhanh hơn tốc độ Lambda xử lý.
  • Một số tin nhắn miss timeline (không xử lý kịp).
  • Logs cho thấy nhiều tin nhắn có dữ liệu không hợp lệ (invalid data).
  • Mục tiêu: Đảm bảo timeline cho tin nhắn có dữ liệu hợp lệ (valid data), loại bỏ hoặc xử lý riêng invalid ones để tránh ảnh hưởng toàn bộ queue.

🛠️ Ngữ cảnh kỹ thuật (cập nhật AWS 2024-2026):

  • SQS standard queue: Không đảm bảo thứ tự, hỗ trợ high throughput, nhưng khi Lambda poll batch, nếu một item fail (do invalid data), toàn batch có thể bị retry → Tích tụ, chậm processing valid messages.
  • Lambda với SQS trigger: Mặc định retry toàn batch nếu partial fail → Không hiệu quả với invalid data.
  • Giải pháp cần: Isolate failed messages để valid ones xử lý nhanh, meet deadline.

✅ Đáp án đúng

Keep the Lambda function's batch size the same. Configure the Lambda function to report failed batch items. Configure an SQS dead-letter queue.

Lý do lựa chọn:

  • Giữ nguyên batch size (10) vì nó đã phù hợp (xử lý nhanh vài giây), tránh rủi ro timeout hoặc memory nếu tăng/giảm.
  • Report failed batch items (feature Lambda từ 2021, cập nhật 2024): Lambda chỉ retry các item fail cụ thể (invalid data), thành công items được process ngay → Valid messages không bị delay, meet timeline.
  • SQS Dead-Letter Queue (DLQ): Failed messages (sau maxReceiveCount) tự động move sang DLQ → Queue chính sạch, Lambda tập trung valid data, giảm tích tụ.
  • Kết hợp: Giải quyết gốc rễ (invalid data gây chậm), hiệu quả nhất mà không cần scale lớn hoặc thay đổi queue type. Phù hợp AWS best practice cho event-driven architecture.

📋 Phân tích tất cả các phương án

  • ❌ [SAI] Increase the Lambda function's batch size. Change the SQS standard queue to an SQS FIFO queue. Request a Lambda concurrency increase in the AWS Region.
    Giải thích sai: Tăng batch size có thể làm timeout (vì invalid data làm chậm toàn batch). Chuyển sang FIFO queue thêm overhead (exactly-once, ordering) không cần thiết (câu hỏi không yêu cầu order). Tăng concurrency giúp scale nhưng không giải quyết invalid data → Vẫn miss timeline cho valid messages. Quá phức tạp, không target vấn đề gốc.

  • ❌ [SAI] Reduce the Lambda function's batch size. Increase the SQS message throughput quota. Request a Lambda concurrency increase in the AWS Region.
    Giải thích sai: Giảm batch size làm tăng polling frequency → Thêm overhead, chậm hơn với high load. Tăng SQS quota và concurrency scale throughput nhưng bỏ qua invalid data → Batch vẫn fail partial, retry toàn bộ, tích tụ tiếp. Không hiệu quả cho timeline strict.

  • ❌ [SAI] Increase the Lambda function's batch size. Configure S3 Transfer Acceleration on the S3 bucket. Configure an SQS dead-letter queue.
    Giải thích sai: Tăng batch size rủi ro timeout như trên. S3 Transfer Acceleration chỉ tối ưu upload/download large files/global (không liên quan, vì Lambda-S3 local Region nhanh). DLQ tốt nhưng thiếu report failed items → Batch fail vẫn retry toàn bộ, invalid data vẫn ảnh hưởng valid ones. Không giải quyết triệt để.

  • ✅ [ĐÚNG] Keep the Lambda function's batch size the same. Configure the Lambda function to report failed batch items. Configure an SQS dead-letter queue.
    Giải thích đúng: Như phần trên – Isolate failed items ngay trong Lambda (reportBatchItemFailures), DLQ catch persistent fails → Queue chính chỉ valid data, Lambda process nhanh, meet timeline. Optimal, low-cost, no infra change lớn.

📘 Tài liệu tham khảo (AWS cập nhật 2024-2026)

  • Lambda ReportBatchItemFailures: AWS Docs - Lambda SQS Integration – "Use ReportBatchItemFailures to return successful items."
  • SQS DLQ: AWS Docs - Dead-Letter Queues – Config via redrive policy.
  • Best Practices: AWS Well-Architected Framework - Reliability Pillar (2024): Handle partial failures in event sources.
  • Exam Topic: DOP-C02 (DevOps Pro) – Serverless event processing, error handling.

Hy vọng phân tích giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm chi tiết, hỏi nhé!

Câu 477 Chọn nhiều đáp án
A company has an application that runs on AWS Lambda and sends logs to Amazon CloudWatch Logs. An Amazon Kinesis data stream is subscribed to the log groups in CloudWatch Logs. A single consumer Lambda function processes the logs from the data stream and stores the logs in an Amazon S3 bucket.

The company’s DevOps team has noticed high latency during the processing and ingestion of some logs.

Which combination of steps will reduce the latency? (Choose three.)
  1. A Create a data stream consumer with enhanced fan-out. Set the Lambda function that processes the logs as the consumer.
  2. B Increase the ParallelizationFactor setting in the Lambda event source mapping.
  3. C Configure reserved concurrency for the Lambda function that processes the logs.
  4. D Increase the batch size in the Kinesis data stream.
  5. E Turn off the ReportBatchItemFailures setting in the Lambda event source mapping.
  6. F Increase the number of shards in the Kinesis data stream.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một kiến trúc AWS nơi ứng dụng chạy trên AWS Lambda gửi logs đến Amazon CloudWatch Logs. Một Amazon Kinesis Data Stream được subscribe trực tiếp vào các log groups của CloudWatch Logs (qua subscription filter). Một Lambda function duy nhất đóng vai trò consumer, đọc logs từ Kinesis stream qua event source mapping (ESM) và lưu trữ chúng vào Amazon S3 bucket.

🚨 Vấn đề chính: Đội DevOps nhận thấy high latency (độ trễ cao) trong quá trình processing (xử lý) và ingestion (tiếp nhận) logs. Nguyên nhân tiềm năng bao gồm:

  • Kinesis stream có throughput hạn chế nếu số shards ít.
  • Lambda consumer xử lý sequential hoặc batch lớn, gây backlog.
  • Mô hình fan-out chuẩn (shared throughput) có latency cao hơn so với enhanced fan-out.

🎯 Yêu cầu: Chọn TAM 3 bước kết hợp để giảm latency, dựa trên best practices AWS cho Kinesis + Lambda (cập nhật đến 2026, theo AWS re:Invent 2025 và docs mới nhất).

✅ Đáp án đúng (Chọn 3)

Các đáp án đúng là:

  • Create a data stream consumer with enhanced fan-out. Set the Lambda function that processes the logs as the consumer.
  • Increase the ParallelizationFactor setting in the Lambda event source mapping.
  • Increase the number of shards in the Kinesis data stream.

Lý do chọn:
🛠️ Kết hợp 3 bước này tối ưu hóa throughput ingestion (tăng shards), đọc dữ liệu nhanh hơn (enhanced fan-out), và xử lý parallel cao (ParallelizationFactor), giảm backlog và latency xuống mức thấp nhất (thường <1s theo benchmarks AWS). Đây là giải pháp chuẩn cho high-volume logs từ CloudWatch → Kinesis → Lambda → S3.

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng phương án, với ✅ Đúng hoặc ❌ Sai, kèm lý do dựa trên docs AWS mới nhất (2026):

  • ✅ Create a data stream consumer with enhanced fan-out. Set the Lambda function that processes the logs as the consumer.
    🧩 Giải thích đúng: Enhanced fan-out (từ 2019, cập nhật 2025) cho phép mỗi consumer đọc trực tiếp 2MB/s/shard mà không chia sẻ throughput với consumer khác, giảm latency từ ~200ms (standard) xuống ~70ms. Đăng ký Lambda làm subscriber qua RegisterStreamConsumer API. Lý tưởng cho logs real-time từ CloudWatch subscription.
    📘 Nguồn: AWS Kinesis Enhanced Fan-Out.

  • ✅ Increase the ParallelizationFactor setting in the Lambda event source mapping.
    🧩 Giải thích đúng: ESM cho Kinesis/Lambda có ParallelizationFactor (mặc định 1, max 10 từ 2020, vẫn valid 2026). Tăng giá trị này cho phép Lambda poll nhiều shards parallel (ví dụ: 10 shards → xử lý nhanh gấp 10 lần), giảm thời gian chờ batch và backlog. Hoàn hảo cho consumer đơn lẻ như ở đây.
    📘 Nguồn: AWS Lambda Kinesis ESM.

  • ❌ Configure reserved concurrency for the Lambda function that processes the logs.
    🧩 Giải thích sai: Reserved concurrency giới hạn số instances Lambda đồng thời (ví dụ: 100), có thể gây throttling nếu traffic cao, tăng latency/backlog thay vì giảm. Không giải quyết gốc rễ ingestion từ Kinesis. Chỉ dùng khi tránh noisy neighbor, không phải scale.
    📘 Nguồn: AWS Lambda Concurrency.

  • ❌ Increase the batch size in the Kinesis data stream.
    🧩 Giải thích sai: Batch size ở đây ám chỉ BatchSize trong ESM (mặc định 100 records), tăng sẽ làm batch lớn hơn → xử lý lâu hơn mỗi invocation, tăng end-to-end latency (có thể lên 15-30s). Kinesis producer batching (PutRecords) không ảnh hưởng consumer latency trực tiếp.
    📘 Nguồn: AWS Lambda Batch Config.

  • ❌ Turn off the ReportBatchItemFailures setting in the Lambda event source mapping.
    🧩 Giải thích sai: ReportBatchItemFailures=true (mặc định) cho phép partial success (chỉ retry item fail, không retry toàn batch), giảm retry loop và latency. Tắt nó → toàn batch fail → retry toàn bộ, tăng latency đáng kể (đặc biệt với logs noisy). Luôn giữ ON.
    📘 Nguồn: AWS Lambda ESM Batch Failures.

🏆 Kết luận & Best Practices

🔥 Kết hợp 3 đúng là optimal: Bắt đầu bằng tăng shards (scale horizontally), enable enhanced fan-out (low-latency read), rồi tăng ParallelizationFactor (parallel processing). Monitor bằng CloudWatch Metrics (IteratorAge, GetRecords.Latency).
⚠️ Test với Provisioned Concurrency nếu cần burst.
📘 Tài liệu tham khảo chính:

Câu 478
A company operates sensitive workloads across the AWS accounts that are in the company's organization in AWS Organizations. The company uses an IP address range to delegate IP addresses for Amazon VPC CIDR blocks and all non-cloud hardware.

The company needs a solution that prevents principals that are outside the company’s IP address range from performing AWS actions in the organization's accounts.

Which solution will meet these requirements?
  1. A Configure AWS Firewall Manager for the organization. Create an AWS Network Firewall policy that allows only source traffic from the company's IP address range. Set the policy scope to all accounts in the organization.
  2. B In Organizations, create an SCP that denies source IP addresses that are outside of the company’s IP address range. Attach the SCP to the organization's root.
  3. C Configure Amazon GuardDuty for the organization. Create a GuardDuty trusted IP address list for the company's IP range. Activate the trusted IP list for the organization.
  4. D In Organizations, create an SCP that allows source IP addresses that are inside of the company’s IP address range. Attach the SCP to the organization's root.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào bảo mật truy cập AWS trong môi trường AWS Organizations. Công ty đang vận hành các workload nhạy cảm trên nhiều AWS accounts thuộc organization. Họ sử dụng một dải IP cụ thể để phân bổ cho Amazon VPC CIDR blocks và hardware ngoài cloud (non-cloud hardware).

Yêu cầu chính: Cần một giải pháp ngăn chặn principals (như IAM users, roles, hoặc external identities) từ bên ngoài dải IP của công ty thực hiện bất kỳ AWS actions nào trong các accounts của organization.

📌 Điểm mấu chốt:

  • Không phải bảo vệ network traffic (như inbound/outbound), mà là kiểm soát quyền thực hiện AWS API calls dựa trên source IP của principals gọi API.
  • Giải pháp phải áp dụng tổ chức-wide (toàn organization), không chỉ một account.
  • Điều này liên quan đến Service Control Policies (SCP) trong AWS Organizations, hỗ trợ điều kiện aws:SourceIp để kiểm soát dựa trên IP (cập nhật mới nhất AWS 2024-2026 vẫn giữ nguyên cơ chế này).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: In Organizations, create an SCP that denies source IP addresses that are outside of the company’s IP address range. Attach the SCP to the organization's root.

Lý do 🛠️:

  • SCP là chính sách kiểm soát dịch vụ trong AWS Organizations, áp dụng deny-by-default cho toàn organization khi attach vào root.
  • Sử dụng điều kiện "Deny" với aws:SourceIp NOT trong dải IP công ty sẽ chặn hoàn toàn các principals ngoài IP range thực hiện tất cả AWS actions (trừ những action không hỗ trợ IP condition).
  • Đây là cách hiệu quả, native và least privilege, không ảnh hưởng đến principals inside IP range. SCP propagate xuống tất cả accounts con.
  • ✅ Hoàn hảo cho yêu cầu "prevents principals outside... from performing AWS actions".

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn. Tôi giữ nguyên văn bản gốc bằng tiếng Anh, chỉ giải thích bằng tiếng Việt với lý do đúng/sai dựa trên kiến thức AWS mới nhất (2026).

  • ❌ Configure AWS Firewall Manager for the organization. Create an AWS Network Firewall policy that allows only source traffic from the company's IP address range. Set the policy scope to all accounts in the organization.
    Sai vì: AWS Firewall Manager + Network Firewall chỉ kiểm soát network traffic (Layer 3/4/7) qua VPC endpoints hoặc internet gateways, không kiểm soát AWS API calls từ principals (như console, CLI). Nó không ngăn "principals outside IP" gọi AWS actions (ví dụ: từ IP lạ gọi ec2:RunInstances qua API). Phù hợp cho firewall rules, không phải IAM-level control.

  • ✅ In Organizations, create an SCP that denies source IP addresses that are outside of the company’s IP address range. Attach the SCP to the organization's root.
    Đúng vì: Như giải thích trên. SCP với Deny + condition !StringEquals hoặc NotIpAddress cho aws:SourceIp chặn principals ngoài IP range tại mức API permission. Attach root đảm bảo áp dụng toàn organization. Hỗ trợ full IPv4/IPv6 (AWS docs 2024+).

  • ❌ Configure Amazon GuardDuty for the organization. Create a GuardDuty trusted IP address list for the company's IP range. Activate the trusted IP list for the organization.
    Sai vì: GuardDuty là threat detection service, trusted IP lists chỉ dùng để giảm false positives trong findings (không tạo findings cho traffic từ IP trusted). Nó không prevent actions mà chỉ phát hiện và alert sau khi action xảy ra. Không chặn principals ngoài IP thực hiện AWS actions.

  • ❌ In Organizations, create an SCP that allows source IP addresses that are inside of the company’s IP address range. Attach the SCP to the organization's root.
    Sai vì: SCP "Allow" chỉ cho phép inside IP, nhưng không deny outside IP (permissions khác vẫn có thể allow outside nếu không explicit deny). SCP hoạt động additive với IAM policies; outside IP vẫn inherit permissions từ root/OU policies khác. Phải dùng "Deny" explicit cho outside để block chắc chắn (principle of explicit deny).

📘 Tài liệu tham khảo (AWS chính thức, cập nhật 2024-2026)

Hy vọng phân tích này giúp bạn nắm vững! 🚀 Nếu cần demo SCP JSON, hãy hỏi thêm nhé!

Câu 479 Chọn nhiều đáp án
A company deploys an application in two AWS Regions. The application currently uses an Amazon S3 bucket in the primary Region to store data.

A DevOps engineer needs to ensure that the application is highly available in both Regions. The DevOps engineer has created a new S3 bucket in the secondary Region. All existing and new objects must be in both S3 buckets. The application must fail over between the Regions with no data loss.

Which combination of steps will meet these requirements with the MOST operational efficiency? (Choose three.)
  1. A Create a new IAM role that allows the Amazon S3 and S3 Batch Operations service principals to assume the role that has the necessary permissions for S3 replication.
  2. B Create a new IAM role that allows the AWS Batch service principal to assume the role that has the necessary permissions for S3 replication.
  3. C Create an S3 Cross-Region Replication (CRR) rule on the source S3 bucket. Configure the rule to use the IAM role for Amazon S3 to replicate to the target S3 bucket.
  4. D Create a two-way replication rule on the source S3 bucket. Configure the rule to use the IAM role for Amazon S3 to replicate to the target S3 bucket.
  5. E Create an AWS Batch job that has an AWS Fargate orchestration type. Configure the job to use the IAM role for AWS Batch. Specify a Bash command to use the AWS CLI to synchronize the contents of the source S3 bucket and the target S3 bucket
  6. F Create an operation in S3 Batch Operations to replicate the contents of the source S3 bucket to the target S3 bucket. Configure the operation to use the IAM role for Amazon S3.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc đảm bảo high availability (HA) cho ứng dụng AWS được triển khai ở hai Regions (chính và phụ), sử dụng Amazon S3 làm nơi lưu trữ dữ liệu. Ứng dụng hiện chỉ dùng bucket S3 ở primary Region. DevOps engineer đã tạo bucket mới ở secondary Region.

Yêu cầu chính:

  • ✅ Tất cả existing objects (dữ liệu hiện có) và new objects (dữ liệu mới) phải được lưu ở cả hai buckets.
  • ✅ Ứng dụng phải failover giữa hai Regions không mất dữ liệu (zero data loss).
  • 📌 Chọn kết hợp 3 bước đạt MOST operational efficiency (hiệu quả vận hành cao nhất, tự động hóa tối đa, ít can thiệp thủ công).

Giải pháp cốt lõi (dựa trên AWS best practices cập nhật 2024-2026):

  • Sử dụng S3 Cross-Region Replication (CRR) cho dữ liệu mới (ongoing replication, tự động, low latency).
  • Sử dụng S3 Batch Operations cho dữ liệu existing (backfill một lần).
  • Cần IAM role chuyên dụng cho S3 service và S3 Batch để ủy quyền replication.
  • Để hai chiều (bi-directional) hỗ trợ failover seamless, cần CRR rule ở cả hai buckets, đảm bảo zero-RPO (Recovery Point Objective).

🛠️ Kiến thức cập nhật: S3 CRR hỗ trợ bi-directional replication (configure rules ở cả hai bên), S3 Batch Operations tích hợp trực tiếp với CRR cho existing objects (không cần AWS Batch hay script thủ công). Điều này tối ưu chi phí và effort so với các tool khác như AWS Batch.

📘 Tài liệu tham khảo:

✅ Đáp án đúng (Chọn 3)

Các bước đúng tạo quy trình tự động, efficient nhất: Tạo IAM role hỗ trợ S3 & Batch Ops, dùng two-way CRR rule cho dữ liệu mới (bi-directional để failover zero-loss), và S3 Batch Operations cho existing objects.

  • Create a new IAM role that allows the Amazon S3 and S3 Batch Operations service principals to assume the role that has the necessary permissions for S3 replication.
    Lý do: IAM role này là prerequisite bắt buộc cho cả CRR (S3 service principal) và S3 Batch (Batch Ops principal), đảm bảo replication an toàn, least privilege. Không dùng AWS Batch (inefficient).

  • Create a two-way replication rule on the source S3 bucket. Configure the rule to use the IAM role for Amazon S3 to replicate to the target S3 bucket.
    Lý do: Two-way CRR (bi-directional) replicate new objects liên tục hai chiều, hỗ trợ failover HA với zero data loss (RPO=0). Efficient hơn one-way vì app đọc local bucket ở mỗi Region.

  • Create an operation in S3 Batch Operations to replicate the contents of the source S3 bucket to the target S3 bucket. Configure the operation to use the IAM role for Amazon S3.
    Lý do: S3 Batch Ops chuyên replicate existing objects hàng loạt (one-time job), tự động scale, chi phí thấp. Kết hợp CRR cho new objects → full coverage.

📋 Giải thích chi tiết TẤT CẢ các phương án

Dưới đây là phân tích từng lựa chọn giữ nguyên văn bản gốc tiếng Anh, đánh dấu ✅ (đúng, chọn) hoặc ❌ (sai, loại bỏ), kèm lý do bằng tiếng Việt:

  • Create a new IAM role that allows the Amazon S3 and S3 Batch Operations service principals to assume the role that has the necessary permissions for S3 replication.
    ✅ ĐÚNG. Đây là bước nền tảng, cho phép S3 service principal (cho CRR) và S3 Batch Operations principal (arn:aws:iam:::s3:) assume role để replicate. Tuân thủ least privilege, hỗ trợ MOST efficiency. Không cần thêm service khác.

  • Create a new IAM role that allows the AWS Batch service principal to assume the role that has the necessary permissions for S3 replication.
    ❌ SAI. AWS Batch không phải tool native cho S3 replication; dùng nó kém efficient (cần Fargate/EC2, script CLI, monitoring thủ công). S3 Batch Operations mới là lựa chọn tối ưu cho AWS-native.

  • Create an S3 Cross-Region Replication (CRR) rule on the source S3 bucket. Configure the rule to use the IAM role for Amazon S3 to replicate to the target S3 bucket.
    ❌ SAI. Đây chỉ là one-way CRR (từ source → target), không replicate ngược chiều → không đảm bảo "both buckets" full sync cho failover zero-loss. Cần two-way để HA thực sự.

  • Create a two-way replication rule on the source S3 bucket. Configure the rule to use the IAM role for Amazon S3 to replicate to the target S3 bucket.
    ✅ ĐÚNG. Two-way CRR (bi-directional rule) replicate new objects hai chiều tự động, low-latency, hỗ trợ app failover đọc local bucket mà không mất data. Efficient nhất cho ongoing replication (theo AWS docs 2024).

  • Create an AWS Batch job that has an AWS Fargate orchestration type. Configure the job to use the IAM role for AWS Batch. Specify a Bash command to use the AWS CLI to synchronize the contents of the source S3 bucket and the target S3 bucket.
    ❌ SAI. AWS Batch + Fargate + CLI sync là cách thủ công, kém efficient (periodic job, error-prone, chi phí cao hơn S3 Batch Ops). Không scale tốt cho large datasets, vi phạm "MOST operational efficiency".

  • Create an operation in S3 Batch Operations to replicate the contents of the source S3 bucket to the target S3 bucket. Configure the operation to use the IAM role for Amazon S3.
    ✅ ĐÚNG. S3 Batch Operations replicate existing objects serverless, one-time job, tích hợp IAM role trực tiếp. Hoàn hảo kết hợp CRR cho new objects → zero data loss, ultra-efficient (no infra management).

Tóm tắt lợi ích combo 3 bước đúng 🏆: Tự động hóa 100%, zero downtime failover, chi phí tối ưu (S3-native tools). Test trong AWS Console để verify! 🚀

Câu 480 Chọn nhiều đáp án
A company uses an organization in AWS Organizations to manage multiple AWS accounts. The company needs an automated process across all AWS accounts to isolate any compromised Amazon EC2 instances when the instances receive a specific tag.

Which combination of steps will meet these requirements? (Choose two.)
  1. A Use AWS CloudFormation StackSets to deploy the CloudFormation stacks in all AWS accounts.
  2. B Create an SCP that has a Deny statement for the ec2:* action with a condition of "aws:RequestTag/isolation": false.
  3. C Attach the SCP to the root of the organization.
  4. D Create an AWS CloudFormation template that creates an EC2 instance role that has no IAM policies attached. Configure the template to have a security group that has an explicit Deny rule on all traffic. Use the CloudFormation template to create an AWS Lambda function that attaches the IAM role to instances. Configure the Lambda function to add a network ACL. Set up an Amazon EventBridge rule to invoke the Lambda function when a specific tag is applied to a compromised EC2 instance.
  5. E Create an AWS CloudFormation template that creates an EC2 instance role that has no IAM policies attached. Configure the template to have a security group that has no inbound rules or outbound rules. Use the CloudFormation template to create an AWS Lambda function that attaches the IAM role to instances. Configure the Lambda function to replace any existing security groups with the new security group. Set up an Amazon EventBridge rule to invoke the Lambda function when a specific tag is applied to a compromised EC2 instance.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc xây dựng quy trình tự động hóa để cô lập (isolate) các Amazon EC2 instance bị compromised trong môi trường AWS Organizations quản lý nhiều tài khoản AWS. Khi một EC2 instance nhận tag cụ thể (ví dụ: tag báo hiệu compromised), hệ thống phải tự động thực hiện các hành động cô lập như ngắt kết nối mạng, hạn chế quyền IAM, v.v., và áp dụng trên tất cả các tài khoản một cách nhất quán.

Yêu cầu chính:

  • Tự động hóa đa tài khoản: Sử dụng cơ chế deploy nhất quán qua AWS Organizations.
  • Kích hoạt bởi tag: Sử dụng Amazon EventBridge để phát hiện tag và trigger Lambda.
  • Cơ chế cô lập:
    • Thay thế IAM role bằng role rỗng (no policies) để khóa quyền truy cập.
    • Thay thế Security Group (SG) bằng SG "khóa chặt" (no inbound/outbound rules) để chặn traffic.
  • Chọn TWO steps: Kết hợp deploy toàn tổ chức + template thực hiện cô lập.

Đây là kịch bản DevOps thực tế cho incident response (phản ứng sự cố bảo mật), tuân thủ best practices AWS như least privilege và automation at scale (tính đến 2026, AWS vẫn khuyến nghị StackSets + EventBridge + Lambda cho multi-account security automation). 📘

✅ Đáp án đúng và lý do lựa chọn

Hai đáp án đúng (chọn TWO):

  1. Use AWS CloudFormation StackSets to deploy the CloudFormation stacks in all AWS accounts.
  2. Create an AWS CloudFormation template that creates an EC2 instance role that has no IAM policies attached. Configure the template to have a security group that has no inbound rules or outbound rules. Use the CloudFormation template to create an AWS Lambda function that attaches the IAM role to instances. Configure the Lambda function to replace any existing security groups with the new security group. Set up an Amazon EventBridge rule to invoke the Lambda function when a specific tag is applied to a compromised EC2 instance.

Lý do lựa chọn 🛠️:

  • Kết hợp hoàn hảo cho multi-account: StackSets deploy template (chứa Lambda + EventBridge + Role/SG) tự động đến tất cả accounts trong Organizations, đảm bảo consistency mà không cần manual intervention.
  • Cơ chế cô lập chính xác:
    • IAM Role rỗng: Ngăn instance thực hiện API calls (no policies attached).
    • Security Group "zero rules": Không có inbound/outbound rules → chặn toàn bộ traffic (AWS default deny implicit, không cần explicit Deny).
    • Lambda actions: Attach role mới + replace existing SGs (hiệu quả hơn modify/add).
    • EventBridge trigger: Phát hiện tag (event source: EC2 tag update) → invoke Lambda ngay lập tức.
  • Scalable & Secure: Không ảnh hưởng instances lành mạnh, chỉ trigger khi tag cụ thể. Tuân thủ AWS Well-Architected Framework (Security Pillar). 🚀

📋 Giải thích tất cả các phương án (Đúng/Sai)

Dưới đây là phân tích từng phương án một cách chi tiết, giữ nguyên text gốc tiếng Anh. Mỗi cái được đánh dấu ✅ (Đúng) hoặc ❌ (Sai), kèm lý do bằng tiếng Việt rõ ràng:

  • ✅ Use AWS CloudFormation StackSets to deploy the CloudFormation stacks in all AWS accounts.
    Đúng vì: StackSets là công cụ chính thức của AWS để deploy CloudFormation stacks multi-account/multi-region trong Organizations. Nó tự động replicate stack đến tất cả accounts (target OUs/roots), giải quyết yêu cầu "across all AWS accounts". Không có cách nào hiệu quả hơn cho automation at scale (cập nhật 2026: StackSets hỗ trợ StackSetCollections cho delegation). 🛤️

  • ❌ Create an SCP that has a Deny statement for the ec2: action with a condition of "aws:RequestTag/isolation": false.*
    Sai vì: SCP (Service Control Policy) chỉ deny/prevent actions dựa trên request time (khi gọi API), không trigger reactive isolation dựa trên existing tag của instance. Condition "aws:RequestTag/isolation": false chỉ áp dụng cho tag mới khi tạo/modify resource, không detect tag đã apply trên running instance. SCP không thể "isolate" (như chặn network) mà chỉ limit permissions tổ chức-wide. Không phù hợp cho event-driven response. 🔒

  • ❌ Attach the SCP to the root of the organization.
    Sai vì: Dù attach SCP to root sẽ áp dụng toàn tổ chức, nhưng SCP không giải quyết vấn đề cô lập instance (chỉ control permissions, không chặn network/attach role). Kết hợp với option trước vẫn fail vì logic condition sai. SCP là preventive, không phải reactive như yêu cầu. Thêm nữa, SCP quá rộng có thể break operations hợp pháp. 🛑

  • ❌ Create an AWS CloudFormation template that creates an EC2 instance role that has no IAM policies attached. Configure the template to have a security group that has an explicit Deny rule on all traffic. Use the CloudFormation template to create an AWS Lambda function that attaches the IAM role to instances. Configure the Lambda function to add a network ACL. Set up an Amazon EventBridge rule to invoke the Lambda function when a specific tag is applied to a compromised EC2 instance.
    Sai vì:

    • SG với explicit Deny rule không cần thiết (AWS SG default implicit deny all), và explicit Deny có thể conflict hoặc không hiệu quả hơn "no rules".
    • Lambda add network ACL sai: NACL là subnet-level, không attach trực tiếp instance; thay vào đó phải modify subnet NACL → phức tạp, rủi ro ảnh hưởng instances khác cùng subnet.
    • Không replace existing SGs → instance vẫn giữ SG cũ, traffic không bị chặn hoàn toàn. Logic gần đúng nhưng thiếu precision, không phải best practice. ❌
  • ✅ Create an AWS CloudFormation template that creates an EC2 instance role that has no IAM policies attached. Configure the template to have a security group that has no inbound rules or outbound rules. Use the CloudFormation template to create an AWS Lambda function that attaches the IAM role to instances. Configure the Lambda function to replace any existing security groups with the new security group. Set up an Amazon EventBridge rule to invoke the Lambda function when a specific tag is applied to a compromised EC2 instance.
    Đúng vì: Template tạo đầy đủ components (Role rỗng + SG zero-rules + Lambda + EventBridge). Lambda attach role + replace SGs → cô lập tức thì (IAM locked + network blocked). EventBridge pattern chuẩn cho EC2 tag events. Kết hợp StackSets → deploy everywhere. Hoàn hảo! 🌟

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Hy vọng phân tích giúp bạn ôn thi hiệu quả! 💪 Nếu cần demo code, hỏi thêm nhé!