Ngân hàng đề — AWS Certified DevOps Engineer Professional

Tìm thấy 681 câu.

Câu 481
A company manages multiple AWS accounts by using AWS Organizations with OUs for the different business divisions. The company is updating their corporate network to use new IP address ranges. The company has 10 Amazon S3 buckets in different AWS accounts. The S3 buckets store reports for the different divisions. The S3 bucket configurations allow only private corporate network IP addresses to access the S3 buckets.

A DevOps engineer needs to change the range of IP addresses that have permission to access the contents of the S3 buckets. The DevOps engineer also needs to revoke the permissions of two OUs in the company.

Which solution will meet these requirements?
  1. A Create a new SCP that has two statements, one that allows access to the new range of IP addresses for all the S3 buckets and one that denies access to the old range of IP addresses for all the S3 buckets. Set a permissions boundary for the OrganizationAccountAccessRole role in the two OUs to deny access to the S3 buckets.
  2. B Create a new SCP that has a statement that allows only the new range of IP addresses to access the S3 buckets. Create another SCP that denies access to the S3 buckets. Attach the second SCP to the two OUs.
  3. C On all the S3 buckets, configure resource-based policies that allow only the new range of IP addresses to access the S3 buckets. Create a new SCP that denies access to the S3 buckets. Attach the SCP to the two OUs.
  4. D On all the S3 buckets, configure resource-based policies that allow only the new range of IP addresses to access the S3 buckets. Set a permissions boundary for the OrganizationAccountAccessRole role in the two OUs to deny access to the S3 buckets.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi xoay quanh việc quản lý truy cập vào 10 Amazon S3 buckets nằm ở các AWS accounts khác nhau trong AWS Organizations (sử dụng OUs cho các bộ phận kinh doanh). Các S3 buckets hiện chỉ cho phép truy cập từ dải IP mạng nội bộ công ty cũ (private corporate network IP addresses) thông qua bucket policies (resource-based policies).

Yêu cầu chính của DevOps engineer:

  • Cập nhật dải IP mới: Thay đổi để chỉ dải IP mạng nội bộ mới được phép truy cập nội dung S3 buckets.
  • Thu hồi quyền của 2 OUs: Ngăn chặn hoàn toàn quyền truy cập vào S3 buckets đối với các accounts thuộc hai Organizational Units (OUs) cụ thể.

Thách thức:

  • S3 buckets rải rác ở nhiều accounts → Cần giải pháp áp dụng cross-account.
  • Truy cập IP-based là condition trong S3 bucket policies (không phải IAM policies).
  • Thu hồi quyền OU-level → Sử dụng Service Control Policies (SCPs) trong AWS Organizations để deny actions ở mức tổ chức (SCPs chỉ restrict, không grant permissions).
  • Không ảnh hưởng đến các accounts/OUs khác.

Giải pháp phải kết hợp cập nhật resource-based policies trên S3 (cho IP) và SCPs (cho deny OU).

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: On all the S3 buckets, configure resource-based policies that allow only the new range of IP addresses to access the S3 buckets. Create a new SCP that denies access to the S3 buckets. Attach the SCP to the two OUs.

Lý do 🛠️:

  • Cập nhật IP: S3 bucket policies (resource-based) hỗ trợ condition IpAddress để chỉ định chính xác dải IP mới ("IpAddress": {"aws:SourceIp": ["new-range"]}), áp dụng trực tiếp cho tất cả 10 buckets cross-account. Điều này thay thế IP cũ một cách chính xác mà không ảnh hưởng IAM roles.
  • Thu hồi OU: SCP mới với Deny statement cho actions như s3:* (hoặc cụ thể hơn s3:GetObject), attach vào 2 OUs → Áp dụng deny cho tất cả principals (users/roles) trong accounts thuộc OUs đó, bất kể IAM policies. SCPs là công cụ chuẩn cho Organizations (effective ngay lập tức, không cần update từng account).
  • Toàn diện: Không ảnh hưởng accounts ngoài OUs; IP mới chỉ áp dụng global cho buckets.
  • Phù hợp best practice AWS Organizations (2026): SCPs cho guardrails, bucket policies cho resource control.

📋 Giải thích chi tiết tất cả các phương án

  • Phương án 1 ❌: Create a new SCP that has two statements, one that allows access to the new range of IP addresses for all the S3 buckets and one that denies access to the old range of IP addresses for all the S3 buckets. Set a permissions boundary for the OrganizationAccountAccessRole role in the two OUs to deny access to the S3 buckets.
    Phân tích sai ❌: SCPs không hỗ trợ "Allow" cụ thể cho IP (SCPs chỉ Deny hoặc implicit Allow all; không control conditions như IpAddress cho S3 access). IpAddress chỉ dùng trong bucket policies, không phải SCP. Permissions boundary trên OrganizationAccountAccessRole chỉ giới hạn khi assume role từ management account, không deny toàn bộ access S3 trong accounts OU (các IAM roles khác vẫn access được). Không giải quyết IP cross-buckets.

  • Phương án 2 ❌: Create a new SCP that has a statement that allows only the new range of IP addresses to access the S3 buckets. Create another SCP that denies access to the S3 buckets. Attach the second SCP to the two OUs.
    Phân tích sai ❌: Tương tự phương án 1, SCP không thể "Allow only new IP" vì thiếu cơ chế resource/resource-condition như bucket policy. SCP chỉ kiểm soát actions (s3:GetObject), không filter IP nguồn. Attach SCP deny thứ hai đúng cho OU nhưng không fix IP global → Vẫn cho IP cũ access từ accounts ngoài OU.

  • Phương án 3 ✅: On all the S3 buckets, configure resource-based policies that allow only the new range of IP addresses to access the S3 buckets. Create a new SCP that denies access to the S3 buckets. Attach the SCP to the two OUs.
    Phân tích đúng ✅: Như giải thích ở phần đáp án đúng. Bucket policies handle IP perfectly (aws:SourceIp condition). SCP Deny attach OU → Block toàn bộ S3 access cho accounts trong 2 OUs (ví dụ: {"Effect": "Deny", "Action": "s3:*", "Resource": "*"}). Hiệu quả, scalable cho multiple accounts.

  • Phương án 4 ❌: On all the S3 buckets, configure resource-based policies that allow only the new range of IP addresses to access the S3 buckets. Set a permissions boundary for the OrganizationAccountAccessRole role in the two OUs to deny access to the S3 buckets.
    Phân tích sai ❌: Bucket policies đúng cho IP, nhưng permissions boundary chỉ áp dụng cho IAM principals cụ thể (như OrganizationAccountAccessRole), không deny toàn bộ access S3 trong OU/accounts (các local IAM roles/users vẫn access). Phải set boundary từng account thủ công (không scalable cho OUs), và không block non-assume-role access. SCP hiệu quả hơn cho Organizations.

Kết luận 🚀: Giải pháp đúng tận dụng resource-based (S3) + organization-level (SCP), tuân thủ least privilege và zero-trust AWS 2026. Test bằng AWS Policy Simulator để verify!

Câu 482
A company has started using AWS across several teams. Each team has multiple accounts and unique security profiles. The company manages the accounts in an organization in AWS Organizations. Each account has its own configuration and security controls.

The company's DevOps team wants to use preventive and detective controls to govern all accounts. The DevOps team needs to ensure the security of accounts now and in the future as the company creates new accounts in the organization.

Which solution will meet these requirements?
  1. A Use Organizations to create OUs that have appropriate SCPs attached for each team. Place team accounts in the appropriate OUs to apply security controls. Create any new team accounts in the appropriate OUs.
  2. B Create an AWS Control Tower landing zone. Configure OUs and appropriate controls in AWS Control Tower for the existing teams. Configure trusted access for AWS Control Tower. Enroll the existing accounts in the appropriate OUs that match the appropriate security policies for each team. Use AWS Control Tower to provision any new accounts.
  3. C Create AWS CloudFormation stack sets in the organization's management account. Configure a stack set that deploys AWS Config with configuration rules and remediation actions for all controls to each account in the organization. Update the stack sets to deploy to new accounts as the accounts are created.
  4. D Configure AWS Config to manage the AWS Config rules across all AWS accounts in the organization. Deploy conformance packs that provide AWS Config rules and remediation actions across the organization.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai preventive controls (các biện pháp ngăn chặn trước khi sự cố xảy ra, như SCPs) và detective controls (các biện pháp phát hiện sau khi sự cố xảy ra, như AWS Config rules với remediation). Công ty đang sử dụng AWS Organizations để quản lý nhiều tài khoản AWS thuộc các team khác nhau, mỗi team có profile bảo mật riêng. DevOps team cần một giải pháp govern toàn bộ accounts hiện tại và tương lai (khi tạo account mới), đảm bảo tính tự động hóa, dễ mở rộng và tuân thủ security trong môi trường multi-account.
📘 Yêu cầu chính: Giải pháp phải hỗ trợ cả preventive/detective controls, áp dụng cho existing accounts và tự động cho new accounts mà không cần can thiệp thủ công nhiều. Đây là chủ đề cốt lõi trong AWS multi-account strategy và governance (theo AWS Well-Architected Framework - Governance Pillar, cập nhật 2024-2026).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Create an AWS Control Tower landing zone. Configure OUs and appropriate controls in AWS Control Tower for the existing teams. Configure trusted access for AWS Control Tower. Enroll the existing accounts in the appropriate OUs that match the appropriate security policies for each team. Use AWS Control Tower to provision any new accounts.

Lý do chọn đáp án này 🛠️:
AWS Control Tower là giải pháp tích hợp toàn diện nhất (best practice theo AWS đến 2026) để thiết lập landing zone multi-account với preventive guards (dựa trên SCPs, OUs) và detective guards (AWS Config rules, remediation tự động). Nó hỗ trợ:

  • Enroll existing accounts vào OUs phù hợp qua Account Factory và trusted access.
  • Tự động provision new accounts với controls sẵn có, đảm bảo consistency cho tương lai.
  • Guardrails (controls) bao quát security profiles cho từng team.
    Điều này đáp ứng yêu cầu govern now & future mà không cần quản lý thủ công.
    📘 Tài liệu tham khảo:
  • AWS Control Tower User Guide (cập nhật 2026: Hỗ trợ hybrid enrollment và advanced guardrails).
  • AWS Well-Architected: Multi-Account Strategies.

📋 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, với giữ nguyên văn bản gốc và giải thích đúng/sai bằng tiếng Việt:

  • Use Organizations to create OUs that have appropriate SCPs attached for each team. Place team accounts in the appropriate OUs to apply security controls. Create any new team accounts in the appropriate OUs.
    ❌ Sai: Phương án này chỉ cung cấp preventive controls qua SCPs và OUs (tốt cho existing accounts), nhưng thiếu detective controls (như Config rules/remediation). Việc tạo new accounts phải thủ công (không tự động), không đảm bảo govern tương lai scalable. SCPs chỉ deny actions, không detect/remediate.

  • Create an AWS Control Tower landing zone. Configure OUs and appropriate controls in AWS Control Tower for the existing teams. Configure trusted access for AWS Control Tower. Enroll the existing accounts in the appropriate OUs that match the appropriate security policies for each team. Use AWS Control Tower to provision any new accounts.
    ✅ Đúng: Như đã giải thích ở trên, đây là giải pháp toàn diện với preventive + detective controls qua Guardrails, hỗ trợ enroll existing accounts và auto-provision new accounts qua Account Factory. Đảm bảo security profiles cho từng team và mở rộng dễ dàng.

  • Create AWS CloudFormation stack sets in the organization's management account. Configure a stack set that deploys AWS Config with configuration rules and remediation actions for all controls to each account in the organization. Update the stack sets to deploy to new accounts as the accounts are created.
    ❌ Sai: Stack sets có thể deploy AWS Config rules/remediation (detective controls) cho existing accounts, nhưng phải update thủ công cho new accounts (không tự động). Thiếu preventive controls mạnh mẽ như SCPs/OUs, và quản lý phức tạp ở quy mô lớn. Không phải best practice cho governance multi-account.

  • Configure AWS Config to manage the AWS Config rules across all AWS accounts in the organization. Deploy conformance packs that provide AWS Config rules and remediation actions across the organization.
    ❌ Sai: Conformance packs tốt cho detective controls (rules + remediation), nhưng thiếu preventive controls (SCPs), và không tự động enroll new accounts (phải deploy thủ công). AWS Config không thay thế được full governance framework như Control Tower.

🛠️ Kết luận: AWS Control Tower là lựa chọn tối ưu theo AWS best practices 2026 cho DevOps governance, giúp giảm toil và tăng compliance! 🚀

Câu 483
A company uses an AWS CodeCommit repository to store its source code and corresponding unit tests. The company has configured an AWS CodePipeline pipeline that includes an AWS CodeBuild project that runs when code is merged to the main branch of the repository.

The company wants the CodeBuild project to run the unit tests. If the unit tests pass, the CodeBuild project must tag the most recent commit.

How should the company configure the CodeBuild project to meet these requirements?
  1. A Configure the CodeBuild project to use native Git to done the CodeCommit repository. Configure the project to run the unit tests. Configure the project to use native Git to create a tag and to push the Git tag to the repository if the code passes the unit tests.
  2. B Configure the CodeBuild projed to use native Git to done the CodeCommit repository. Configure the project to run the unit tests. Configure the project to use AWS CLI commands to create a new repository tag in the repository if the code passes the unit tests.
  3. C Configure the CodeBuild project to use AWS CLI commands to copy the code from the CodeCommit repository. Configure the project to run the unit tests. Configure the project to use AWS CLI commands to create a new Git tag in the repository if the code passes the unit tests.
  4. D Configure the CodeBuild project to use AWS CLI commands to copy the code from the CodeCommit repository. Configure the project to run the unit tests. Configure the project to use AWS CLI commands to create a new repository tag in the repository if the code passes the unit tests.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc cấu hình AWS CodeBuild project trong pipeline AWS CodePipeline, kết nối với AWS CodeCommit repository. Cụ thể:

  • CodeCommit lưu trữ source code và unit tests.
  • Pipeline kích hoạt CodeBuild khi code được merge vào main branch.
  • Yêu cầu: CodeBuild phải chạy unit tests. Nếu tests pass, thì tag commit mới nhất (tạo Git tag cho commit gần nhất).
  • Mục tiêu: Đảm bảo CodeBuild có thể truy cập code, chạy tests, và push Git tag trở lại repo một cách an toàn, hiệu quả.
  • Bối cảnh DevOps: Đây là quy trình CI/CD tiêu chuẩn, nơi CodeBuild cần quyền Git đầy đủ để tương tác với CodeCommit (clone, test, push tags). Kiến thức cập nhật đến 2026: AWS CodeBuild hỗ trợ native Git integration với CodeCommit qua IAM roles (như codebuild.amazonaws.com với policy AWSCodeCommitPowerUser hoặc custom cho codecommit:GitPush).

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Configure the CodeBuild project to use native Git to done the CodeCommit repository. Configure the project to run the unit tests. Configure the project to use native Git to create a tag and to push the Git tag to the repository if the code passes the unit tests.

Lý do 🛠️:

  • Native Git là cách chuẩn và được AWS khuyến nghị để CodeBuild clone repo từ CodeCommit (sử dụng git clone trong buildspec.yaml). Điều này đảm bảo repo đầy đủ lịch sử Git, cần thiết để tag commit mới nhất (git tag <tagname> <commit-hash> và git push origin <tagname>).
  • Nếu tests pass (kiểm tra exit code 0), buildspec dùng phases (pre_build/install, build cho tests, post_build cho tagging/push).
  • Service role của CodeBuild cần quyền codecommit:GitPull (clone) và codecommit:GitPush (push tag). Native Git hoạt động mượt mà mà không cần AWS CLI phức tạp.
  • Ưu điểm: An toàn, nhanh, hỗ trợ full Git workflow. Không cần credential thủ công (AWS tự handle qua IAM).

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng phương án một cách rõ ràng. Tôi giữ nguyên văn bản gốc tiếng Anh, đánh dấu ✅/❌, và giải thích bằng tiếng Việt dựa trên cơ chế AWS mới nhất.

  • Phương án 1 ✅:
    Configure the CodeBuild project to use native Git to done the CodeCommit repository. Configure the project to run the unit tests. Configure the project to use native Git to create a tag and to push the Git tag to the repository if the code passes the unit tests.
    Đúng vì: Như giải thích trên, native Git clone/push tag là cách tối ưu, native hỗ trợ. Buildspec ví dụ:

    version: 0.2
    phases:
      install: { runtime-versions: {nodejs: latest} }
      build:
        commands:
          - npm test  # Chạy unit tests
      post_build:
        commands:
          - git config --global user.email "build@aws.com"
          - git tag -a v1.0 -m "Tests passed"
          - git push origin v1.0  # Push tag nếu tests pass
    

    (Lưu ý: "done" là lỗi đánh máy của "clone").

  • Phương án 2 ❌:
    Configure the CodeBuild projed to use native Git to done the CodeCommit repository. Configure the project to run the unit tests. Configure the project to use AWS CLI commands to create a new repository tag in the repository if the code passes the unit tests.
    Sai vì: Native Git clone và tests OK, nhưng AWS CLI không hỗ trợ tạo Git tag trực tiếp. CodeCommit CLI chỉ có aws codecommit create-branch hoặc create-commit, không có lệnh tạo/push Git tag (tags là Git refs cục bộ, cần git push). Sử dụng CLI sẽ fail với lỗi permission hoặc syntax. (Lỗi chính tả: "projed" -> project, "done" -> clone).

  • Phương án 3 ❌:
    Configure the CodeBuild project to use AWS CLI commands to copy the code from the CodeCommit repository. Configure the project to run the unit tests. Configure the project to use AWS CLI commands to create a new Git tag in the repository if the code passes the unit tests.
    Sai vì: Không có AWS CLI command để "copy code" từ CodeCommit (không phải get-file hay get-folder cho toàn repo; chỉ lấy file riêng lẻ). Phải dùng git clone. Hơn nữa, AWS CLI không tạo Git tag (như phương án 2), dẫn đến fail hoàn toàn.

  • Phương án 4 ❌:
    Configure the CodeBuild project to use AWS CLI commands to copy the code from the CodeCommit repository. Configure the project to run the unit tests. Configure the project to use AWS CLI commands to create a new repository tag in the repository if the code passes the unit tests.
    Sai vì: Tương tự phương án 3, AWS CLI không copy toàn bộ code (thiếu lệnh tương đương git clone). "Repository tag" ám chỉ Git tag, nhưng CLI chỉ quản lý repo metadata (branch/commit), không tạo Git tag thực thụ. CodeBuild cần Git binary để xử lý tags đúng cách.

🏆 Kết luận & Best Practice

✅ Chọn phương án 1 để đạt zero-downtime CI/CD với tagging tự động. Test trong môi trường thực tế qua AWS Console hoặc CDK/Terraform. Luôn attach IAM policy đầy đủ cho CodeBuild role! 🚀

Câu 484
A DevOps engineer manages a company's Amazon Elastic Container Service (Amazon ECS) cluster. The cluster runs on several Amazon EC2 instances that are in an Auto Scaling group. The DevOps engineer must implement a solution that logs and reviews all stopped tasks for errors.

Which solution will meet these requirements?
  1. A Create an Amazon EventBridge rule to capture task state changes. Send the event to Amazon CloudWatch Logs. Use CloudWatch Logs Insights to investigate stopped tasks.
  2. B Configure tasks to write log data in the embedded metric format. Store the logs in Amazon CloudWatch Logs. Monitor the ContainerInstanceCount metric for changes.
  3. C Configure the EC2 instances to store logs in Amazon CloudWatch Logs. Create a CloudWatch Contributor Insights rule that uses the EC2 instance log data. Use the Contributor Insights rule to investigate stopped tasks.
  4. D Configure an EC2 Auto Scaling lifecycle hook for the EC2_INSTANCE_TERMINATING scale-in event. Write the SystemEventLog file to Amazon S3. Use Amazon Athena to query the log file for errors.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc quản lý và giám sát các task bị dừng (stopped tasks) trong Amazon Elastic Container Service (Amazon ECS) cluster. Cụ thể:

  • Cluster ECS chạy trên các Amazon EC2 instances thuộc Auto Scaling Group (ASG).
  • Yêu cầu: Triển khai giải pháp để ghi log (logs) và xem xét (review) tất cả các stopped tasks nhằm tìm lỗi (errors).
  • Mục tiêu chính là bắt sự kiện stopped tasks một cách tự động, lưu trữ logs và phân tích dễ dàng, phù hợp với best practices của AWS cho ECS monitoring (cập nhật đến 2026, ECS vẫn hỗ trợ EventBridge cho task state changes).

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create an Amazon EventBridge rule to capture task state changes. Send the event to Amazon CloudWatch Logs. Use CloudWatch Logs Insights to investigate stopped tasks.

Lý do chọn 🛠️:

  • ECS tự động phát ra events qua Amazon EventBridge khi task thay đổi trạng thái (như STOPPED), bao gồm chi tiết lỗi (reason, exit code).
  • Rule EventBridge filter chính xác event ECS Task State Change với detail-type: "ECS Task State Change" và stateChange: "STOPPED".
  • Gửi event đến CloudWatch Logs để lưu trữ, sau dùng CloudWatch Logs Insights query logs (ví dụ: filter stoppedReason hoặc containers.exitCode).
  • Giải pháp serverless, scalable, chi phí thấp, không phụ thuộc EC2 instance lifecycle, phù hợp ASG.

📋 Giải thích chi tiết tất cả các phương án

  • Create an Amazon EventBridge rule to capture task state changes. Send the event to Amazon CloudWatch Logs. Use CloudWatch Logs Insights to investigate stopped tasks.
    ✅ Đúng 🏆: Như giải thích trên, đây là phương pháp chuẩn của AWS để capture task state changes (bao gồm stopped tasks với error details). EventBridge rule target CloudWatch Logs, Insights hỗ trợ query mạnh mẽ (queries như fields @timestamp, stoppedReason | filter detail.taskARN | sort @timestamp desc). Hoàn hảo cho yêu cầu log & review errors.

  • Configure tasks to write log data in the embedded metric format. Store the logs in Amazon CloudWatch Logs. Monitor the ContainerInstanceCount metric for changes.
    ❌ Sai 🚫: Embedded metric format dùng để extract metrics từ logs (không phải log events). ContainerInstanceCount metric theo dõi số lượng EC2 instances trong cluster, không liên quan đến stopped tasks (tasks stop không ảnh hưởng trực tiếp metric này). Không capture error details của tasks.

  • Configure the EC2 instances to store logs in Amazon CloudWatch Logs. Create a CloudWatch Contributor Insights rule that uses the EC2 instance log data. Use the Contributor Insights rule to investigate stopped tasks.
    ❌ Sai 🚫: Logs từ EC2 instances (qua CloudWatch Agent) chỉ ghi hệ thống instance, không capture task-level events như stopped reasons trong ECS. Contributor Insights dùng phân tích top contributors trong logs/metrics (ví dụ: top errors), nhưng thiếu dữ liệu task-specific, không hiệu quả cho review stopped tasks.

  • Configure an EC2 Auto Scaling lifecycle hook for the EC2_INSTANCE_TERMINATING scale-in event. Write the SystemEventLog file to Amazon S3. Use Amazon Athena to query the log file for errors.
    ❌ Sai 🚫: ASG lifecycle hook chỉ trigger khi EC2 instance terminate (scale-in), không phải khi task stop (tasks có thể stop độc lập với instance). SystemEventLog không phải log chuẩn cho ECS tasks (có thể nhầm với Docker daemon logs), query Athena trên S3 tốn kém và chậm, không real-time như EventBridge.

🧠 Kết luận: Giải pháp đúng tận dụng native ECS events qua EventBridge – best practice DevOps cho monitoring, dễ scale với ASG! Nếu triển khai, test rule pattern: { "source": ["aws.ecs"], "detail-type": ["ECS Task State Change"], "detail": { "stoppedReason": [{ "anything-but": "Essential container in task exited" }] } }.

Câu 485 Chọn nhiều đáp án
A company wants to deploy a workload on several hundred Amazon EC2 instances. The company will provision the EC2 instances in an Auto Scaling group by using a launch template.

The workload will pull files from an Amazon S3 bucket, process the data, and put the results into a different S3 bucket. The EC2 instances must have least-privilege permissions and must use temporary security credentials.

Which combination of steps will meet these requirements? (Choose two.)
  1. A Create an IAM role that has the appropriate permissions for S3 buckets Add the IAM role to an instance profile.
  2. B Update the launch template to include the IAM instance profile.
  3. C Create an IAM user that has the appropriate permissions for Amazon S3 Generate a secret key and token.
  4. D Create a trust anchor and profile Attach the IAM role to the profile.
  5. E Update the launch template Modify the user data to use the new secret key and token.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi này thuộc chủ đề IAM (Identity and Access Management) và EC2 Auto Scaling trên AWS, tập trung vào việc cấp quyền least-privilege (quyền hạn tối thiểu) cho các instance EC2 trong Auto Scaling group sử dụng launch template.

  • Yêu cầu chính:

    • Deploy workload trên hàng trăm EC2 instances (sử dụng Auto Scaling group + launch template).
    • Workload: Pull file từ S3 bucket nguồn, xử lý dữ liệu, push kết quả vào S3 bucket đích.
    • Yêu cầu bảo mật: EC2 chỉ có quyền hạn cần thiết (least-privilege) và sử dụng temporary security credentials (chứng chỉ tạm thời, tự động rotate, không dùng long-term keys).
  • Mục tiêu: Chọn TWO steps (hai bước) kết hợp để đáp ứng. Giải pháp chuẩn AWS là sử dụng IAM Role gắn với Instance Profile, associate vào Launch Template để EC2 tự động nhận temporary creds qua metadata service (IMDS/IMDSv2). Điều này đảm bảo bảo mật cao, scale tự động, không hardcode keys.

✅ Kiến thức cập nhật AWS 2024-2026: Không thay đổi cơ bản (theo AWS Well-Architected Framework - Security Pillar). Launch Templates hỗ trợ IAM Instance Profile ARN trực tiếp (từ 2019), khuyến khích dùng IMDSv2 để tránh SSRF attacks.

✅ Đáp án đúng (Chọn TWO)

Hai phương án đúng là:

  1. Create an IAM role that has the appropriate permissions for S3 buckets Add the IAM role to an instance profile.
  2. Update the launch template to include the IAM instance profile.

Lý do lựa chọn:

  • Kết hợp hai bước này tạo ra quy trình chuẩn AWS: IAM Role định nghĩa quyền S3 (GetObject/PutObject cho buckets cụ thể → least-privilege), gắn vào Instance Profile (container cho role), rồi link vào Launch Template. Khi ASG launch instances, chúng tự nhận temporary creds (Access Key, Secret Key, Session Token) qua http://169.254.169.254 (IMDS).
  • Ưu điểm: Scale tự động cho hàng trăm instances, creds rotate hàng giờ, zero manual key management. ❌ Tránh static keys (IAM User).

📋 Phân tích tất cả các phương án (Đúng/Sai)

🛠️ Phương án 1:
Create an IAM role that has the appropriate permissions for S3 buckets Add the IAM role to an instance profile.
✅ ĐÚNG. Đây là bước đầu tiên chuẩn AWS: Tạo IAM Role với policy JSON chỉ định quyền S3 (ví dụ: s3:GetObject cho bucket nguồn, s3:PutObject cho bucket đích). Gắn role vào Instance Profile (AWS tự tạo nếu dùng CLI: aws ec2 create-instance-profile). Instance Profile là "wrapper" để EC2 attach role an toàn. Nguồn: IAM Roles for EC2 Docs.

🛠️ Phương án 2:
Update the launch template to include the IAM instance profile.
✅ ĐÚNG. Bước thứ hai: Trong Launch Template (EC2 Console/CLI), chỉ định IAM instance profile (ARN hoặc name). Khi ASG dùng template này launch instances, EC2 tự động assume role → temporary creds. Hỗ trợ scale lớn (hàng trăm instances). Nguồn: Launch Templates IAM Role.

🛠️ Phương án 3:
Create an IAM user that has the appropriate permissions for Amazon S3 Generate a secret key and token.
❌ SAI. IAM User dùng long-term static credentials (Access Key/Secret Key), không phải temporary. Không scale cho Auto Scaling (phải hardcode keys → rủi ro leak), vi phạm least-privilege (user có quyền rộng), và không an toàn cho EC2 fleet. AWS khuyến cáo KHÔNG dùng cho instances.

🛠️ Phương án 4:
Create a trust anchor and profile Attach the IAM role to the profile.
❌ SAI. "Trust anchor" thuộc IAM Identity Center hoặc OIDC provider (cho EKS/K8s external ID), không áp dụng cho EC2. EC2 dùng trust policy đơn giản (principal: ec2.amazonaws.com), không cần "trust anchor". Sai ngữ cảnh hoàn toàn, không cung cấp temporary creds cho S3 workload.

🛠️ Phương án 5:
Update the launch template Modify the user data to use the new secret key and token.
❌ SAI. User data chỉ chạy script bootstrap, nhưng dùng secret key/token static → không temporary, dễ leak (log/userdata public nếu config sai), không scale (phải generate keys thủ công). Vi phạm nguyên tắc zero trust AWS, rủi ro cao cho hàng trăm instances.

📘 Tài liệu tham khảo chính thức AWS (Cập nhật 2026)

Kết luận: Giải pháp ✅1 + ✅2 là best practice cho DevOps, đảm bảo bảo mật + scale! 🚀 Nếu cần demo code Terraform/CloudFormation, hỏi thêm nhé!

Câu 486
A company is using AWS CodeDeploy to automate software deployment. The deployment must meet these requirements:

• A number of instances must be available to serve traffic during the deployment. Traffic must be balanced across those instances, and the instances must automatically heal in the event of failure. • A new fleet of instances must be launched for deploying a new revision automatically, with no manual provisioning.
• Traffic must be rerouted to the new environment to half of the new instances at a time. The deployment should succeed if traffic is rerouted to at least half of the instances: otherwise, it should fail.
• Before routing traffic to the new fleet of instances, the temporary files generated during the deployment process must be deleted.
• At the end of a successful deployment, the original instances in the deployment group must be deleted immediately to reduce costs.

How can a DevOps engineer meet these requirements?
  1. A Use an Application Load Balancer and an in-place deployment. Associate the Auto Scaling group with the deployment group. Use the Automatically copy Auto Scaling group option, and use CodeDeployDefault.OneAtAtime as the deployment configuration. Instruct AWS CodeDeploy to terminate the original instances in the deployment group, and use the AllowTraffic hook within appspec.yml to delete the temporary files.
  2. B Use an Application Load Balancer and a blue/green deployment. Associate the Auto Scaling group and Application Load Balancer target group with the deployment group. Use the Automatically copy Auto Scaling group option, create a custom deployment configuration with minimum healthy hosts defined as 50%, and assign the configuration to the deployment group. Instruct AWS CodeDeploy to terminate the original instances in the deployment group, and use the BeforeBlockTraffic hook within appspec.yml to delete the temporary files.
  3. C Use an Application Load Balancer and a blue/green deployment. Associate the Auto Scaling group and the Application Load Balancer target group with the deployment group. Use the Automatically copy Auto Scaling group option, and use CodeDeployDefault.HalfAtAtime as the deployment configuration. Instruct AWS CodeDeploy to terminate the original instances in the deployment group, and use the BeforeAllowTraffic hook within appspec.yml to delete the temporary files.
  4. D Use an Application Load Balancer and an in-place deployment. Associate the Auto Scaling group and Application Load Balancer target group with the deployment group. Use the Automatically copy Auto Scaling group option, and use CodeDeployDefault.AllatOnce as a deployment configuration. Instruct AWS CodeDeploy to terminate the original instances in the deployment group, and use the BlockTraffic hook within appspec.yml to delete the temporary files.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai phần mềm tự động sử dụng AWS CodeDeploy với các yêu cầu cụ thể sau:
✅ Giữ tính sẵn sàng cao: Phải có một số lượng instances luôn sẵn sàng phục vụ traffic, cân bằng tải qua chúng, và tự động phục hồi nếu hỏng (sử dụng Auto Scaling Group - ASG kết hợp Application Load Balancer - ALB).
🛠️ Triển khai fleet mới tự động: Tạo fleet instances mới cho revision mới mà không cần provision thủ công (gợi ý blue/green deployment với tùy chọn Automatically copy Auto Scaling group).
📊 Chuyển traffic dần dần: Chuyển traffic sang môi trường mới với một nửa instances mới mỗi lần, và deployment thành công chỉ nếu ít nhất 50% instances mới nhận traffic thành công (phù hợp deployment configuration HalfAtATime).
🧹 Xóa file tạm trước khi chuyển traffic: Xóa các file tạm sinh ra trong quá trình deploy trước khi route traffic sang fleet mới (sử dụng hook BeforeAllowTraffic trong appspec.yml).
💰 Xóa instances cũ ngay lập tức: Sau khi deploy thành công, terminate ngay instances gốc trong deployment group để tiết kiệm chi phí (tính năng của blue/green).

Tóm lại, đây là kịch bản blue/green deployment trên EC2 với ASG và ALB, đảm bảo zero-downtime, canary-like rollout (half at a time), cleanup trước shift traffic, và auto-terminate blue environment. Kiến thức dựa trên phiên bản AWS CodeDeploy mới nhất (2024-2026), hỗ trợ ALB target groups cho blue/green.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Use an Application Load Balancer and a blue/green deployment. Associate the Auto Scaling group and the Application Load Balancer target group with the deployment group. Use the Automatically copy Auto Scaling group option, and use CodeDeployDefault.HalfAtAtime as the deployment configuration. Instruct AWS CodeDeploy to terminate the original instances in the deployment group, and use the BeforeAllowTraffic hook within appspec.yml to delete the temporary files.

Lý do chọn đáp án này 🏆:

  • ✅ Blue/green deployment + Automatically copy ASG: Tự động launch fleet xanh (new) từ ASG gốc, không manual provision.
  • ✅ CodeDeployDefault.HalfAtATime: Chuyển traffic sang một nửa instances mới mỗi lần, fail nếu không đạt ít nhất 50% healthy (đúng yêu cầu "half of the new instances at a time" và "succeed if at least half").
  • ✅ BeforeAllowTraffic hook: Chạy trên instances xanh ngay trước khi ALB route traffic sang chúng, lý tưởng để xóa temp files trước khi routing traffic.
  • ✅ Terminate original instances: CodeDeploy tự động xóa blue fleet (original) ngay sau success, tiết kiệm chi phí.
  • ✅ Hoàn hảo khớp tất cả yêu cầu, đảm bảo high availability qua ASG + ALB target group.

📋 Giải thích tất cả các phương án

  • ❌ Phương án 1 (SAI):
    Use an Application Load Balancer and an in-place deployment. Associate the Auto Scaling group with the deployment group. Use the Automatically copy Auto Scaling group option, and use CodeDeployDefault.OneAtAtime as the deployment configuration. Instruct AWS CodeDeploy to terminate the original instances in the deployment group, and use the AllowTraffic hook within appspec.yml to delete the temporary files.
    Lý do sai: In-place deployment không launch fleet mới (deploy trực tiếp trên instances hiện tại, vi phạm "new fleet automatically"). OneAtATime quá chậm (1 instance/lần, không phải half). AllowTraffic hook chạy sau khi traffic routed, không xóa temp trước routing. Terminate original không phù hợp in-place (gây downtime).

  • ❌ Phương án 2 (SAI):
    Use an Application Load Balancer and a blue/green deployment. Associate the Auto Scaling group and Application Load Balancer target group with the deployment group. Use the Automatically copy Auto Scaling group option, create a custom deployment configuration with minimum healthy hosts defined as 50%, and assign the configuration to the deployment group. Instruct AWS CodeDeploy to terminate the original instances in the deployment group, and use the BeforeBlockTraffic hook within appspec.yml to delete the temporary files.
    Lý do sai: Custom config 50% healthy không khớp chính xác "half at a time" (HalfAtATime là standard, custom có thể khác). BeforeBlockTraffic chạy trên blue instances trước khi block traffic từ blue, không phải trên green trước routing (temp files ở green mới cần xóa).

  • ✅ Phương án 3 (ĐÚNG):
    (Như đã giải thích ở phần đáp án đúng, khớp 100% tất cả yêu cầu).

  • ❌ Phương án 4 (SAI):
    Use an Application Load Balancer and an in-place deployment. Associate the Auto Scaling group and Application Load Balancer target group with the deployment group. Use the Automatically copy Auto Scaling group option, and use CodeDeployDefault.AllatOnce as a deployment configuration. Instruct AWS CodeDeploy to terminate the original instances in the deployment group, and use the BlockTraffic hook within appspec.yml to delete the temporary files.
    Lý do sai: In-place không tạo new fleet (deploy trên existing, vi phạm yêu cầu). AllAtOnce deploy toàn bộ cùng lúc, không "half at a time" và rủi ro cao (không fail nếu chỉ half success). BlockTraffic chạy trên original instances khi block traffic, không xóa temp trên new fleet trước routing. Terminate original gây vấn đề in-place.

Câu 487
A company needs to adopt a multi-account strategy to deploy its applications and the associated CI/CD infrastructure. The company has created an organization in AWS Organizations that has all features enabled. The company has configured AWS Control Tower and has set up a landing zone.

The company needs to use AWS Control Tower controls (guardrails) in all AWS accounts in the organization. The company must create the accounts for a multi-environment application and must ensure that all accounts are configured to an initial baseline.

Which solution will meet these requirements with the LEAST operational overhead?
  1. A Create an AWS Control Tower Account Factory Customization (AFC) blueprint that uses the baseline configuration. Use AWS Control Tower Account Factory to provision a dedicated AWS account for each environment and a CI/CD account by using the blueprint.
  2. B Use AWS Control Tower Account Factory to provision a dedicated AWS account for each environment and a CI/CD account. Use AWS CloudFormation StackSets to apply the baseline configuration to the new accounts.
  3. C Use Organizations to provision a multi-environment AWS account and a CI/CD account. In the Organizations management account, create an AWS Lambda function that assumes the Organizations access role to apply the baseline configuration to the new accounts.
  4. D Use Organizations to provision a dedicated AWS account for each environment, an audit account, and a CI/CD account. Use AWS CloudFormation StackSets to apply the baseline configuration to the new accounts.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai chiến lược multi-account trên AWS sử dụng AWS Organizations (đã kích hoạt tất cả tính năng), AWS Control Tower và landing zone đã được thiết lập. Công ty cần:

  • Áp dụng AWS Control Tower controls (guardrails) cho tất cả các AWS accounts trong organization để đảm bảo tuân thủ và bảo mật.
  • Tạo các accounts dành riêng cho multi-environment application (như dev, test, prod) và một CI/CD account.
  • Đảm bảo tất cả accounts mới được cấu hình initial baseline (cấu hình cơ bản chuẩn hóa, bao gồm IAM roles, security baselines, networking, v.v.).
  • Giải pháp phải có LEAST operational overhead (ít công sức vận hành nhất, tự động hóa cao, tránh manual intervention).

🛠️ Mục tiêu chính: Tối ưu hóa việc provision accounts mới với baseline tự động, tích hợp guardrails từ Control Tower, giảm thiểu công việc thủ công như deploy StackSets hay Lambda custom. Đây là best practice trong AWS Well-Architected Framework cho multi-account strategy (multi-account & multi-environment).

📘 Tài liệu tham khảo:

  • AWS Control Tower User Guide: Account Factory (cập nhật 2024-2026).
  • AWS Organizations & Control Tower best practices: Landing Zone Accelerator.
  • AWS re:Post & Exam topics DOP-C02 (DevOps Professional 2024+).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create an AWS Control Tower Account Factory Customization (AFC) blueprint that uses the baseline configuration. Use AWS Control Tower Account Factory để provision a dedicated AWS account for each environment and a CI/CD account by using the blueprint.

Lý do 🏆:

  • AWS Control Tower Account Factory Customization (AFC) là tính năng mới nhất (ra mắt 2023, cập nhật 2024-2026) cho phép tạo blueprint tùy chỉnh dựa trên baseline chuẩn (enroll accounts vào OUs, áp dụng guardrails tự động).
  • Provision accounts qua Account Factory sẽ tự động inherit landing zone config, guardrails, và baseline (như CloudTrail, Config, GuardDuty).
  • Least overhead: Không cần StackSets/Lambda custom; chỉ thiết kế blueprint một lần, sau đó provision tự động cho multi-env + CI/CD account. Hoàn toàn managed bởi Control Tower.

📋 Phân tích tất cả các phương án (đúng/sai)

  • Create an AWS Control Tower Account Factory Customization (AFC) blueprint that uses the baseline configuration. Use AWS Control Tower Account Factory to provision a dedicated AWS account for each environment and a CI/CD account by using the blueprint.
    ✅ Đúng 🏅: Như giải thích trên, AFC blueprint tự động hóa toàn bộ baseline + guardrails khi provision accounts. Ít overhead nhất, native integration với Control Tower landing zone. Best practice cho multi-account scaling.

  • Use AWS Control Tower Account Factory to provision a dedicated AWS account for each environment and a CI/CD account. Use AWS CloudFormation StackSets to apply the baseline configuration to the new accounts.
    ❌ Sai 🚫: Account Factory provision accounts cơ bản, nhưng thiếu AFC blueprint nên phải dùng CloudFormation StackSets riêng để apply baseline → tăng overhead (quản lý StackSets cross-account, IAM permissions, drift detection). Không tự động guardrails đầy đủ.

  • Use Organizations to provision a multi-environment AWS account and a CI/CD account. In the Organizations management account, create an AWS Lambda function that assumes the Organizations access role to apply the baseline configuration to the new accounts.
    ❌ Sai ⚠️: Chỉ dùng Organizations API provision accounts thô (không qua Control Tower) → mất lợi ích landing zone/guardrails tự động. Lambda custom assume role để apply baseline → high overhead (code, error handling, scaling, maintenance). Không khuyến khích, vi phạm least effort.

  • Use Organizations to provision a dedicated AWS account for each environment, an audit account, and a CI/CD account. Use AWS CloudFormation StackSets to apply the baseline configuration to the new accounts.
    ❌ Sai 🔧: Tương tự option B, provision qua Organizations thiếu Control Tower integration (không enroll OUs tự động, guardrails). StackSets apply baseline → overhead cao (multi-account deployment, admin account setup). Thêm "audit account" thừa, không khớp yêu cầu chính xác.

Kết luận 🎯: Chọn AFC blueprint để tối ưu tự động hóa trong Control Tower ecosystem – phù hợp DOP-C02 exam blueprint 2024+. Nếu implement, bắt đầu từ Control Tower console > Account Factory > Customize!

Câu 488
A DevOps team has created a Custom Lambda rule in AWS Config. The rule monitors Amazon Elastic Container Repository (Amazon ECR) policy statements for ecr:* actions. When a noncompliant repository is detected, Amazon EventBridge uses Amazon Simple Notification Service (Amazon SNS) to route the notification to a security team.

When the custom AWS Config rule is evaluated, the AWS Lambda function fails to run.

Which solution will resolve the issue?
  1. A Modify the Lambda function's resource policy to grant AWS Config permission to invoke the function.
  2. B Modify the SNS topic policy to include configuration changes for EventBridge to publish to the SNS topic.
  3. C Modify the Lambda function's execution role to include configuration changes for custom AWS Config rules.
  4. D Modify all the ECR repository policies to grant AWS Config access to the necessary ECR API actions.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả một tình huống thực tế trong môi trường AWS DevOps:
Một team DevOps đã tạo Custom Lambda rule trong AWS Config để giám sát các policy statements của Amazon Elastic Container Repository (Amazon ECR), cụ thể kiểm tra các hành động *ecr: ** (tất cả các API actions liên quan đến ECR).
Khi phát hiện repository không tuân thủ (noncompliant), Amazon EventBridge sẽ sử dụng Amazon Simple Notification Service (Amazon SNS) để gửi thông báo đến team bảo mật.

Vấn đề chính (Issue): Khi AWS Config thực hiện đánh giá (evaluate) custom rule này, AWS Lambda function (được dùng làm rule) thất bại trong việc chạy (fails to run).

Mục tiêu: Tìm giải pháp resolve issue này một cách chính xác, dựa trên kiến thức AWS mới nhất (tính đến 2026, AWS Config vẫn yêu cầu permission đặc biệt cho service invocation với custom Lambda rules theo mô hình resource-based policy).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Modify the Lambda function's resource policy to grant AWS Config permission to invoke the function.

Lý do chi tiết 🛠️:

  • Với Custom Lambda rules trong AWS Config, dịch vụ AWS Config (principal: config.amazonaws.com) cần quyền Invoke Lambda function để thực thi rule evaluation.
  • Quyền này KHÔNG được tự động cấp; phải cấu hình thủ công qua resource-based policy (Lambda Resource Policy) trên function, cho phép lambda:InvokeFunction từ AWS Config.
  • Đây là yêu cầu bắt buộc theo best practice AWS (không thay đổi đến 2026). Nếu thiếu, Lambda sẽ fail invoke ngay từ đầu, khớp với issue mô tả.
  • Sau khi fix, flow sẽ hoạt động: Config invoke Lambda → Lambda check ECR policies → Noncompliant → EventBridge → SNS notify.

📋 Giải thích tất cả các phương án (Đúng/Sai)

Dưới đây là phân tích từng phương án một cách chi tiết, giữ nguyên văn bản gốc bằng tiếng Anh. Tôi sử dụng ✅ cho đúng và ❌ cho sai, kèm lý do dựa trên kiến thức AWS Config & Lambda mới nhất.

  • Modify the Lambda function's resource policy to grant AWS Config permission to invoke the function.
    ✅ Đúng 🛠️: Như giải thích ở trên, đây là solution chính xác. AWS Config cần explicit permission qua Lambda resource policy để invoke function (ARN: arn:aws:lambda:region:account:function:name). Nếu thiếu, invocation fail với lỗi "AccessDenied". Fix này resolve ngay issue mà không ảnh hưởng flow khác.

  • Modify the SNS topic policy to include configuration changes for EventBridge to publish to the SNS topic.
    ❌ Sai 🚫: SNS topic policy chỉ kiểm soát quyền publish/subscribe của EventBridge đến SNS (sau khi rule evaluate). Issue xảy ra ở bước Lambda fail run (trước khi trigger EventBridge/SNS), nên chỉnh SNS policy không liên quan và không fix được vấn đề gốc.

  • Modify the Lambda function's execution role to include configuration changes for custom AWS Config rules.
    ❌ Sai 🚫: Execution role (IAM role của Lambda) dùng để Lambda access resources khác khi chạy (ví dụ: đọc ECR policies). Nó KHÔNG cấp quyền cho AWS Config invoke Lambda. Permission invoke phải từ resource policy của Lambda, không phải execution role.

  • Modify all the ECR repository policies to grant AWS Config access to the necessary ECR API actions.
    ❌ Sai 🚫: ECR repository policies kiểm soát access đến ECR resources (như pull/push images). Issue là Lambda fail invoke, không phải Lambda không đọc được ECR. Hơn nữa, chỉnh tất cả ECR policies là không cần thiết và rủi ro bảo mật cao, vì Lambda (qua execution role) mới cần quyền đọc ECR, không phải AWS Config trực tiếp.

📘 Tài liệu tham khảo (AWS Official Docs - Cập nhật 2026)

Kết luận 🎯: Fix resource policy là giải pháp nhanh, an toàn và đúng chuẩn AWS DevOps. Nếu implement, test bằng AWS Config console hoặc CLI: aws configservice start-config-rules-evaluation.

Câu 489
A developer is creating a proof of concept for a new software as a service (SaaS) application. The application is in a shared development AWS account that is part of an organization in AWS Organizations.

The developer needs to create service-linked IAM roles for the AWS services that are being considered for the proof of concept. The solution needs to give the developer the ability to create and configure the service-linked roles only.

Which solution will meet these requirements?
  1. A Create an IAM user for the developer in the organization's management account. Configure a cross-account role in the development account for the developer to use. Limit the scope of the cross-account role to common services.
  2. B Add the developer to an IAM group. Attach the PowerUserAccess managed policy to the IAM group. Enforce multi-factor authentication (MFA) on the user account.
  3. C Add an SCP to the development account in Organizations. Configure the SCP with a Deny rule for iam:* to limit the developer's access.
  4. D Create an IAM role that has the necessary IAM access to allow the developer to create policies and roles. Create and attach a permissions boundary to the role. Grant the developer access to assume the role.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi xoay quanh một lập trình viên (developer) đang xây dựng proof of concept (POC) cho ứng dụng SaaS mới trong tài khoản AWS development chia sẻ, thuộc một organization trong AWS Organizations.

📌 Yêu cầu chính:

  • Developer cần tạo service-linked IAM roles cho các dịch vụ AWS đang thử nghiệm trong POC.
  • Giải pháp phải giới hạn chặt chẽ: Chỉ cho phép developer tạo và cấu hình service-linked roles thôi, không cấp quyền rộng hơn (least privilege principle theo AWS Well-Architected Framework).

🛠️ Service-linked IAM roles là các role đặc biệt được AWS quản lý, liên kết trực tiếp với dịch vụ (như Elastic Load Balancing, Lambda). Chúng thường được tạo tự động, nhưng để tạo thủ công hoặc tùy chỉnh, cần quyền IAM cụ thể như iam:CreateServiceLinkedRole, iam:PutRolePolicy, iam:DeleteServiceLinkedRole, v.v. (theo tài liệu AWS IAM mới nhất 2026).

Mục tiêu: Đảm bảo an toàn trong môi trường shared account, tránh developer lạm dụng quyền IAM.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Create an IAM role that has the necessary IAM access to allow the developer to create policies and roles. Create and attach a permissions boundary to the role. Grant the developer access to assume the role.

Lý do chi tiết 🧩:

  • Tạo IAM role với quyền IAM cần thiết (như iam:CreateRole, iam:CreatePolicy, iam:PutRolePolicy, iam:CreateServiceLinkedRole) để developer assume role và tạo service-linked roles.
  • Permissions boundary (giới hạn quyền) được attach vào role, chỉ cho phép các action cụ thể liên quan đến service-linked roles (ví dụ: Deny các IAM action khác như iam:CreateUser, iam:AttachRolePolicy rộng rãi). Điều này đảm bảo least privilege: Developer chỉ làm được đúng việc cần, ngay cả khi role có quyền cao hơn.
  • Phù hợp với shared development account trong Organizations, không ảnh hưởng SCP hoặc cross-account.
  • Cập nhật 2026: Permissions boundaries hỗ trợ tinh chỉnh cho service-linked roles qua AWS IAM Access Analyzer (tích hợp AI để verify boundaries).

📘 Tài liệu tham khảo:

📋 Phân tích tất cả các phương án

Dưới đây là phân tích từng lựa chọn (giữ nguyên văn bản gốc tiếng Anh). Tôi đánh dấu ✅ đúng hoặc ❌ sai, kèm giải thích chi tiết bằng tiếng Việt.

  • Phương án 1:
    Create an IAM user for the developer in the organization's management account. Configure a cross-account role in the development account for the developer to use. Limit the scope of the cross-account role to common services.
    ❌ Sai: Tạo IAM user ở management account rồi dùng cross-account role ở dev account chỉ giới hạn "common services" (quá mơ hồ, không cụ thể cho service-linked roles). Không đảm bảo chỉ tạo/config roles, dễ cấp quyền rộng (như EC2, S3). Phức tạp không cần thiết cho shared dev account, vi phạm least privilege.

  • Phương án 2:
    Add the developer to an IAM group. Attach the PowerUserAccess managed policy to the IAM group. Enforce multi-factor authentication (MFA) on the user account.
    ❌ Sai: PowerUserAccess cho phép hầu hết AWS actions trừ IAM đầy đủ (vẫn quá rộng: EC2, RDS, Lambda,...). Không giới hạn chỉ service-linked roles, developer có thể tạo resources khác. MFA tốt nhưng không giải quyết vấn đề chính. Không phù hợp POC shared account.

  • Phương án 3:
    Add an SCP to the development account in Organizations. Configure the SCP with a Deny rule for iam: to limit the developer's access.*
    ❌ Sai: SCP (Service Control Policy) ở Organizations là *Deny rule cho iam: **sẽ block toàn bộ IAM actions (bao gồm CreateServiceLinkedRole). Developer không thể tạo role nào, trái yêu cầu. SCP ảnh hưởng toàn account/group OU, không granular cho 1 user/dev.

  • Phương án 4 (Đúng, như đã phân tích ở trên):
    Create an IAM role that has the necessary IAM access to allow the developer to create policies and roles. Create and attach a permissions boundary to the role. Grant the developer access to assume the role.
    ✅ Đúng: Như giải thích ✅, sử dụng permissions boundary để giới hạn chính xác quyền chỉ cho service-linked roles, an toàn và tuân thủ best practices AWS IAM 2026.

💡 Lời khuyên DevOps: Trong Organizations, kết hợp SCP (broad deny) + IAM policies + boundaries cho multi-account security. Test bằng IAM Access Analyzer trước deploy! 🚀

Câu 490 Chọn nhiều đáp án
A company uses AWS Organizations to manage its AWS accounts. The company wants its monitoring system to receive an alert when a root user logs in. The company also needs a dashboard to display any log activity that the root user generates.

Which combination of steps will meet these requirements? (Choose three.)
  1. A Enable AWS Config with a multi-account aggregator. Configure log forwarding to Amazon CloudWatch Logs.
  2. B Create an Amazon QuickSight dashboard that uses an Amazon CloudWatch Logs query.
  3. C Create an Amazon CloudWatch Logs metric filter to match root user login events. Configure a CloudWatch alarm and an Amazon Simple Notification Service (Amazon SNS) topic to send alerts to the company's monitoring system.
  4. D Create an Amazon CloudWatch Logs subscription filter to match root user login events. Configure the filter to forward events to an Amazon Simple Notification Service (Amazon SNS) topic. Configure the SNS topic to send alerts to the company's monitoring system.
  5. E Create an AWS CloudTrail organization trail. Configure the organization trail to send events to Amazon CloudWatch Logs.
  6. F Create an Amazon CloudWatch dashboard that uses a CloudWatch Logs Insights query.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc thiết lập giám sát và cảnh báo cho hoạt động của root user trong môi trường AWS Organizations (quản lý nhiều tài khoản AWS). Cụ thể:

  • Yêu cầu 1: Hệ thống giám sát của công ty phải nhận cảnh báo (alert) ngay khi root user đăng nhập (login).
  • Yêu cầu 2: Cần một dashboard để hiển thị hoạt động log (log activity) mà root user tạo ra.
  • Bối cảnh: Sử dụng AWS Organizations, nên cần giải pháp multi-account (áp dụng cho tất cả tài khoản con).
  • Hình thức: Chọn 3 bước kết hợp để đáp ứng đầy đủ, dựa trên các dịch vụ như AWS CloudTrail (ghi log hoạt động), Amazon CloudWatch Logs (lưu trữ và phân tích log), CloudWatch Alarms (cảnh báo), và dashboard.
    🛠️ Giải pháp cốt lõi: Phải ghi log toàn tổ chức qua CloudTrail organization trail (để capture root login events từ tất cả accounts), lưu vào CloudWatch Logs, sau đó dùng metric filter + alarm cho alert, và dashboard cho visualization.

✅ Đáp án đúng và lý do lựa chọn

Các đáp án đúng (chọn 3):

  • Create an Amazon CloudWatch Logs metric filter to match root user login events. Configure a CloudWatch alarm and an Amazon Simple Notification Service (Amazon SNS) topic to send alerts to the company's monitoring system.
  • Create an AWS CloudTrail organization trail. Configure the organization trail to send events to Amazon CloudWatch Logs.
  • Create an Amazon CloudWatch dashboard that uses a CloudWatch Logs Insights query.

Lý do chọn:
✅ Kết hợp này đáp ứng đầy đủ 2 yêu cầu:

  • Organization trail (CloudTrail) capture log root login từ tất cả accounts trong Organizations và forward đến CloudWatch Logs (bắt buộc cho multi-account).
  • Metric filter + Alarm + SNS match pattern root login (ví dụ: eventName="ConsoleLogin" và userIdentity.type="Root") để gửi alert chính xác đến hệ thống giám sát.
  • CloudWatch dashboard với Logs Insights query visualize log activity của root user (query như fields @timestamp, @message | filter userIdentity.type = "Root").
    🛠️ Đây là best practice theo AWS Well-Architected Framework (2023-2026), hỗ trợ real-time monitoring và scalability.

📋 Phân tích chi tiết tất cả các phương án

Dưới đây là phân tích từng phương án một, giữ nguyên nội dung gốc tiếng Anh. Mỗi phương án được đánh giá đúng/sai với lý do cụ thể bằng tiếng Việt:

  • Enable AWS Config with a multi-account aggregator. Configure log forwarding to Amazon CloudWatch Logs.
    ❌ SAI. AWS Config dùng để ghi nhận thay đổi cấu hình tài nguyên (configuration changes), không phải log hoạt động người dùng như root login (đó là nhiệm vụ của CloudTrail). Multi-account aggregator chỉ aggregate config data, không capture login events. Forwarding đến CloudWatch Logs cũng không giúp match root login.

  • Create an Amazon QuickSight dashboard that uses an Amazon CloudWatch Logs query.
    ❌ SAI. QuickSight phù hợp cho business analytics từ dữ liệu structured (như S3/ Athena), nhưng không tối ưu cho log activity real-time từ CloudWatch Logs. Nó yêu cầu export dữ liệu thủ công, phức tạp hơn so với CloudWatch dashboard native (hỗ trợ Logs Insights trực tiếp, nhanh và rẻ hơn).

  • Create an Amazon CloudWatch Logs metric filter to match root user login events. Configure a CloudWatch alarm and an Amazon Simple Notification Service (Amazon SNS) topic to send alerts to the company's monitoring system.
    ✅ ĐÚNG. Metric filter trên CloudWatch Logs match chính xác pattern root login (JSON filter như {"userIdentity":{"type":"Root"}}), tạo metric → trigger CloudWatch Alarm → SNS gửi alert đến hệ thống giám sát. Hoàn hảo cho real-time alerting, tích hợp Organizations qua CloudTrail logs.

  • Create an Amazon CloudWatch Logs subscription filter to match root user login events. Configure the filter to forward events to an Amazon Simple Notification Service (Amazon SNS) topic. Configure the SNS topic to send alerts to the company's monitoring system.
    ❌ SAI. Subscription filter forward log stream đến Lambda/Kinesis/Firehose/HTTP, KHÔNG hỗ trợ trực tiếp SNS (theo docs AWS 2026). Để alert, phải dùng metric filter + alarm (như phương án đúng), không phải subscription filter (dành cho streaming processing).

  • Create an AWS CloudTrail organization trail. Configure the organization trail to send events to Amazon CloudWatch Logs.
    ✅ ĐÚNG. Với AWS Organizations, organization trail là bắt buộc để delegate quản lý trail từ management account, capture management/management events (bao gồm root login) từ tất cả member accounts. Forward đến CloudWatch Logs để enable Logs Insights và metric filters. Không dùng single-account trail vì không cover multi-account.

  • Create an Amazon CloudWatch dashboard that uses a CloudWatch Logs Insights query.
    ✅ ĐÚNG. CloudWatch dashboard native hỗ trợ Logs Insights query để visualize log root user (filter bằng userIdentity.type="Root"), real-time và interactive. Tích hợp trực tiếp với CloudWatch Logs từ CloudTrail, đáp ứng yêu cầu dashboard log activity một cách đơn giản, cost-effective.

📘 Tài liệu tham khảo (cập nhật AWS 2026)