Ngân hàng đề — AWS Certified DevOps Engineer Professional

Tìm thấy 681 câu.

Câu 591
A company has deployed a new REST API by using Amazon API Gateway. The company uses the API to access confidential data. The API must be accessed from only specific VPCs in the company.

Which solution will meet these requirements?
  1. A Create and attach a resource policy to the API Gateway API. Configure the resource policy to allow only the specific VPC IDs.
  2. B Add a security group to the API Gateway API. Configure the inbound rules to allow only the specific VPC IP address ranges.
  3. C Create and attach an IAM role to the API Gateway API. Configure the IAM role to allow only the specific VPC IDs.
  4. D Add an ACL to the API Gateway API. Configure the outbound rules to allow only the specific VPC IP address ranges.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi xoay quanh việc bảo mật Amazon API Gateway cho một REST API mới được triển khai để truy cập dữ liệu bí mật. Yêu cầu chính là chỉ cho phép truy cập từ các VPC cụ thể của công ty, không cho phép từ các nguồn khác (như internet hoặc VPC khác).

  • Bối cảnh: API Gateway là dịch vụ managed của AWS, không nằm trong VPC mà hoạt động ở edge locations. Do đó, không thể sử dụng các công cụ VPC thông thường như security groups hay ACL trực tiếp.
  • Mục tiêu: Cần một cơ chế kiểm soát truy cập từ cấp độ VPC (source VPC), đảm bảo tính bảo mật cao cho dữ liệu nhạy cảm. Giải pháp phải tuân thủ best practices của AWS đến năm 2026, nơi API Gateway hỗ trợ resource policies để kiểm soát chính xác nguồn truy cập dựa trên VPC ID hoặc VPC Endpoint (VPCE).

✅ Đáp án đúng

Create and attach a resource policy to the API Gateway API. Configure the resource policy to allow only the specific VPC IDs.

Lý do lựa chọn:

  • Resource policy của API Gateway là cơ chế chính thức và được khuyến nghị để restrict truy cập dựa trên aws:SourceVpc hoặc aws:SourceVpce. Bạn có thể attach policy trực tiếp vào API, chỉ định VPC IDs cụ thể (ví dụ: "vpc-12345") và sử dụng điều kiện Allow cho các VPC đó, đồng thời Deny tất cả các nguồn khác.
  • Điều này hoạt động ngay cả với public APIs, private APIs, hoặc khi sử dụng VPC Endpoint. Policy được đánh giá trước khi request đến integration backend, đảm bảo bảo mật tối ưu.
  • Cập nhật 2026: AWS tiếp tục hỗ trợ và mở rộng resource policies trong API Gateway v2 (HTTP APIs), với tích hợp tốt hơn IAM và VPC Lattice cho hybrid networking.

📋 Giải thích chi tiết từng phương án

Dưới đây là phân tích tất cả 4 phương án, với đánh giá đúng/sai dựa trên tài liệu AWS mới nhất. Mỗi phương án giữ nguyên văn bản gốc tiếng Anh.

  • ✅ Create and attach a resource policy to the API Gateway API. Configure the resource policy to allow only the specific VPC IDs.
    Đúng 🛠️: Như đã giải thích ở trên, đây là giải pháp chuẩn. Policy JSON ví dụ:

    {
      "Statement": [{
        "Effect": "Allow",
        "Principal": "*",
        "Action": "execute-api:Invoke",
        "Resource": "arn:aws:execute-api:*:*:*/",
        "Condition": {
          "StringEquals": {"aws:SourceVpc": ["vpc-abc123", "vpc-def456"]}
        }
      }]
    }
    

    Hoàn hảo cho yêu cầu restrict theo VPC IDs.

  • ❌ Add a security group to the API Gateway API. Configure the inbound rules to allow only the specific VPC IP address ranges.
    Sai 🚫: API Gateway là managed service toàn cầu, không hỗ trợ security groups (chỉ dành cho EC2, RDS, ELB trong VPC). Không thể attach SG vào API Gateway. Hơn nữa, dùng IP ranges của VPC không chính xác vì VPC có CIDR động và private, dễ bypass qua NAT/Internet Gateway.

  • ❌ Create and attach an IAM role to the API Gateway API. Configure the IAM role to allow only the specific VPC IDs.
    Sai 🚫: IAM roles dùng để API Gateway assume quyền gọi backend (như Lambda, DynamoDB), không kiểm soát nguồn truy cập từ client (VPC). Không có thuộc tính "VPC ID" trong IAM role để restrict source. IAM chỉ kiểm soát identity-based access, không phải network-based như VPC.

  • ❌ Add an ACL to the API Gateway API. Configure the outbound rules to allow only the specific VPC IP address ranges.
    Sai 🚫: Network ACLs (NACLs) chỉ áp dụng cho subnets trong VPC, không attach được vào API Gateway (dịch vụ ngoài VPC). Outbound rules cũng không liên quan vì ACL kiểm soát traffic vào/ra subnet, không phải source VPC cho API calls. Sử dụng IP ranges kém hiệu quả và không an toàn.

📘 Tài liệu tham khảo (AWS cập nhật đến 2026)

Giải pháp này đảm bảo zero-trust access từ VPC cụ thể, phù hợp DevOps Professional! 🚀

Câu 592
A company runs a website by using an Amazon Elastic Container Service (Amazon ECS) service that is connected to an Application Load Balancer (ALB). The service was in a steady state with tasks responding to requests successfully.

A DevOps engineer updated the task definition with a new container image and deployed the new task definition to the service. The DevOps engineer noticed that the service is frequently stopping and starting new tasks because the ALB healtth checks are failing.

What should the DevOps engineer do to troubleshoot the failed deployment?
  1. A Ensure that a security group associated with the service allows traffic from the ALB.
  2. B Increase the ALB health check grace period for the service.
  3. C Increase the service minimum healthy percent setting.
  4. D Decrease the ALB health check interval.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một tình huống thực tế trong AWS ECS:
Một công ty đang chạy website trên Amazon ECS service kết nối với Application Load Balancer (ALB). Service trước đó ở trạng thái ổn định (steady state), các task xử lý request thành công.
Sau khi DevOps engineer cập nhật task definition với container image mới và deploy lên service, xảy ra vấn đề: Service liên tục stop và start new tasks vì ALB health checks thất bại.

🔍 Nguyên nhân tiềm ẩn: Khi deploy task definition mới, ECS sẽ dần thay thế old tasks bằng new tasks (theo deployment strategy mặc định). Tuy nhiên, new container image có thể cần thời gian warmup (khởi tạo, load dữ liệu, connect database...), dẫn đến health checks từ ALB fail tạm thời. ECS nhận tín hiệu unhealthy từ ALB nên terminate task cũ và start task mới, tạo vòng lặp draining liên tục.
Mục tiêu: Troubleshoot failed deployment bằng cách xác định hành động phù hợp nhất để khắc phục mà không thay đổi code/image.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Increase the ALB health check grace period for the service.

Lý do:
🛠️ Trong ECS service, health check grace period (healthCheckGracePeriodSeconds) là khoảng thời gian (tính bằng giây) sau khi task start mà ECS bỏ qua các health check failures từ ALB. Mặc định là 0 giây.
Khi deploy image mới cần warmup (ví dụ: app boot chậm), tăng grace period (ví dụ: 300 giây) sẽ cho task thời gian ổn định trước khi ALB/ECS đánh giá unhealthy. Điều này ngăn chặn việc frequently stopping/starting tasks, giúp deployment thành công.
Đây là giải pháp trực tiếp troubleshoot vấn đề grace period quá ngắn, phù hợp với kiến thức AWS ECS mới nhất (2024-2026, không thay đổi cơ bản).

📋 Giải thích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc:

  • Ensure that a security group associated with the service allows traffic from the ALB.
    ❌ Sai: Security group (SG) cho ECS tasks phải allow traffic từ ALB (thường port 80/443 inbound từ ALB SG) để health checks hoạt động. Tuy nhiên, service đang steady state trước deploy (tasks healthy), và chỉ update container image (không động chạm SG). Nếu SG sai, vấn đề đã xảy ra từ trước. Không phải nguyên nhân deploy fail mới.

  • Increase the ALB health check grace period for the service.
    ✅ Đúng: Như giải thích ở trên. Đây là best practice cho trường hợp new tasks fail health check tạm thời do warmup. AWS khuyến nghị tăng grace period lên 1-5 phút cho app cần init chậm.

  • Increase the service minimum healthy percent setting.
    ❌ Sai: Minimum healthy percent (trong ECS service deployment) quy định tỷ lệ tối thiểu tasks phải healthy (RUNNING và healthy theo ALB) trong quá trình rollout (default 100%). Tăng giá trị này (ví dụ: từ 50% lên 100%) làm nghiêm ngặt hơn, yêu cầu nhiều tasks healthy hơn, dẫn đến deployment fail/stuck nhanh hơn nếu health checks fail. Không giúp troubleshoot, mà làm tệ hơn.

  • Decrease the ALB health check interval.
    ❌ Sai: Health check interval của ALB target group là thời gian giữa các checks (default 30 giây). Giảm interval (ví dụ: 10 giây) làm check thường xuyên hơn, detect unhealthy nhanh hơn, tăng tần suất stop/start tasks. Điều này làm vấn đề nghiêm trọng hơn, không troubleshoot được.

📘 Tài liệu tham khảo (AWS cập nhật mới nhất 2024-2026)

Hy vọng phân tích này giúp bạn nắm vững! 🚀 Nếu cần ví dụ CloudFormation/Terraform, hãy hỏi thêm nhé!

Câu 593
A company that uses electronic patient health records runs a fleet of Amazon EC2 instances with an Amazon Linux operating system. The company must continuously ensure that the EC2 instances are running operating system patches and application patches that are in compliance with current privacy regulations. The company uses a custom repository to store application patches.

A DevOps engineer needs to automate the deployment of operating system patches and application patches. The DevOps engineer wants to use both the default operating system patch repository and the custom patch repository.

Which solution will meet these requirements with the LEAST effort?
  1. A Use AWS Systems Manager to create a new custom patch baseline that includes the default operating system repository and the custom repository. Run the AWS-RunPatchBaseline document by using the Run command to verify and install patches. Use the BaselineOverride API to configure the new custom patch baseline.
  2. B Use AWS Direct Connect to integrate the custom repository with the EC2 instances. Use Amazon EventBridge events to deploy the patches.
  3. C Use the yum-config-manager command to add the custom repository to the /etc/yum.repos.d configuration. Run the yum-config-manager-enable command to activate the new repository.
  4. D Use AWS Systems Manager to create a patch baseline for the default operating system repository and a second patch baseline for the custom repository. Run the AWS-RunPatchBaseline document by using the Run command to verify and install patches. Use the BaselineOverride API to configure the default patch baseline and the custom patch baseline.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh một công ty sử dụng hồ sơ sức khỏe bệnh nhân điện tử, chạy fleet EC2 instances trên Amazon Linux OS. Họ cần liên tục đảm bảo các instance luôn cập nhật OS patches (bản vá hệ điều hành) và application patches (bản vá ứng dụng) tuân thủ quy định bảo mật. Công ty dùng custom repository để lưu trữ application patches.

📋 Yêu cầu cụ thể của DevOps engineer:

  • Tự động hóa việc triển khai patches từ default OS patch repository (kho mặc định của Amazon Linux) và custom repository.
  • Giải pháp phải có LEAST effort (ít công sức nhất), nghĩa là tận dụng dịch vụ AWS managed, scalable cho toàn fleet, không can thiệp thủ công từng instance.

🛠️ Bối cảnh kỹ thuật (dựa trên AWS cập nhật 2026):

  • Amazon Linux 2/2023 hỗ trợ yum/dnf cho packages.
  • AWS Systems Manager (SSM) Patch Manager là giải pháp chuẩn cho patching tự động trên EC2, hỗ trợ patch baselines (tiêu chí phê duyệt patches), Run Command, State Manager, và Maintenance Windows.
  • Patch baselines có thể kết hợp default sources (như Amazon Linux repo) và custom sources (repo tùy chỉnh) chỉ với một baseline duy nhất.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Use AWS Systems Manager to create a new custom patch baseline that includes the default operating system repository and the custom repository. Run the AWS-RunPatchBaseline document by using the Run command to verify and install patches. Use the BaselineOverride API to configure the new custom patch baseline.

Lý do chọn đáp án này (ít effort nhất):
✅ SSM Patch Manager cho phép tạo một custom patch baseline duy nhất kết hợp cả default OS repo (tự động từ AWS) và custom repo (thêm source URL).
✅ Chạy AWS-RunPatchBaseline SSM document qua Run Command để scan/install patches trên fleet – tự động, không agent thủ công.
✅ BaselineOverride API (trong State Manager hoặc Maintenance Windows) override baseline mặc định, áp dụng cho toàn fleet chỉ với một lệnh/config.
🧩 Điều này fully managed, scalable, least effort vì không cần script custom, hỗ trợ Amazon Linux (yum-based), và tuân thủ compliance (scan/install theo lịch). Không cần chỉnh config từng instance.

📘 Giải thích tất cả các phương án

  • Use AWS Systems Manager to create a new custom patch baseline that includes the default operating system repository and the custom repository. Run the AWS-RunPatchBaseline document by using the Run command to verify and install patches. Use the BaselineOverride API to configure the new custom patch baseline.
    ✅ Đúng vì: Đây là cách chuẩn và least effort của AWS SSM Patch Manager (2026). Một baseline duy nhất hỗ trợ multiple sources (default + custom), Run Command tự động hóa scan/install, BaselineOverride linh hoạt override cho associations. Hoàn hảo cho fleet lớn, compliance cao.

  • Use AWS Direct Connect to integrate the custom repository with the EC2 instances. Use Amazon EventBridge events to deploy the patches.
    ❌ Sai vì: AWS Direct Connect dùng cho kết nối private high-bandwidth (on-prem to AWS), không liên quan đến patch repo integration (repo chỉ cần HTTP/HTTPS accessible). EventBridge trigger events, nhưng không deploy patches – thiếu cơ chế scan/install. Effort cao, phức tạp, không managed.

  • Use the yum-config-manager command to add the custom repository to the /etc/yum.repos.d configuration. Run the yum-config-manager-enable command to activate the new repository.
    ❌ Sai vì: Đây là cách thủ công trên từng instance (UserData hoặc SSM Run Command lặp lại), không tự động hóa fleet patching (chỉ add repo, không scan/compliance). Phải cronjob yum update riêng, effort cao, không dùng default SSM baseline, dễ lỗi scale/privacy regs.

  • Use AWS Systems Manager to create a patch baseline for the default operating system repository and a second patch baseline for the custom repository. Run the AWS-RunPatchBaseline document by using the Run command to verify and install patches. Use the BaselineOverride API to configure the default patch baseline and the custom patch baseline.
    ❌ Sai vì: Tạo hai baselines riêng biệt phức tạp hơn (phải run Run Command hai lần hoặc multi-associations), không least effort. SSM hỗ trợ một baseline multi-source hiệu quả hơn, tránh override chồng chéo, dễ quản lý compliance.

📚 Tài liệu tham khảo (AWS cập nhật 2026)

🛡️ Giải pháp này đảm bảo compliance cao cho health records (HIPAA-eligible via SSM). Nếu cần implement, bắt đầu từ Console SSM > Patch Baselines > Create!

Câu 594 Chọn nhiều đáp án
A company use an organization in AWS Organizations to manage multiple AWS accounts. The company has enabled all features enabled for the organization. The company configured the organization as a hierarchy of OUs under the root OU. The company recently registered all its OUs and enrolled all its AWS accounts in AWS Control Tower.

The company needs to customize the AWS Control Tower managed AWS Config configuration recorder in each of the company's AWS accounts. The company needs to apply the customizations to both the existing AWS accounts and to any new AWS accounts that the company enrolls in AWS Control Tower in the future.

Which combination of steps will meet these requirements? (Choose three.)
  1. A Create a new AWS account. Create an AWS Lambda function in the new account to apply the customizations to the AWS Config configuration recorder in each AWS account in the organization.
  2. B Create a new AWS account as an AWS Config delegated administrator. Create an AWS Lambda function in the delegated administrator account to apply the customizations to the AWS Config configuration recorder in the delegated administrator account.
  3. C Configure an Amazon EventBridge rule in the AWS Control Tower management account to invoke an AWS Lambda function when the Organizations OU is registered or reregistered. Re-register the root Organizations OU.
  4. D Configure the AWSControlTowerExecution IAM role in each AWS account in the organization to be assumable by an AWS Lambda function. Configure the Lambda function to assume the AWSControlTowerExecution IAM role.
  5. E Create an IAM role in the AWS Control Tower management account that an AWS Lambda function can assume. Grant the IAM role permission to assume the AWSControlTowerExecution IAM role in any account in the organization. Configure the Lambda function to use the new IAM role.
  6. F Configure an Amazon EventBridge rule in the AWS Control Tower management account to invoke an AWS Lambda function when an AWS account is updated or enrolled in AWS Control Tower or when the landing zone is updated. Re-register each Organizations OU in the organization.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào AWS Control Tower trong môi trường AWS Organizations với all features enabled. Công ty đã thiết lập hierarchy OUs dưới root, đăng ký tất cả OUs và enroll tất cả AWS accounts vào Control Tower.

Yêu cầu chính: Tùy chỉnh (customize) AWS Config configuration recorder do Control Tower quản lý (managed) trong tất cả AWS accounts hiện tại và tương lai khi enroll mới. Điều này cần áp dụng tự động, scalable cho toàn organization.

Bối cảnh kỹ thuật (dựa trên AWS docs cập nhật 2024-2026):

  • AWS Control Tower tạo landing zone chuẩn, quản lý AWS Config recorder để hỗ trợ controls và guardrails.
  • Để customize recorder (ví dụ: thêm resource types, thay đổi settings), không thể chỉnh trực tiếp vì managed bởi Control Tower.
  • Giải pháp chuẩn: Sử dụng Customizations for AWS Control Tower (CfCT) với Amazon EventBridge trigger AWS Lambda trên lifecycle events (account enroll/update, OU register, landing zone update). Lambda assume role AWSControlTowerExecution (role mặc định của Control Tower trong member accounts) để apply thay đổi.
  • Cần management account của Control Tower làm trung tâm trigger.
  • Để tránh clutter management account, thường tạo new dedicated account cho Lambda.
  • Áp dụng cho existing accounts: Re-register OUs để trigger events.
  • ✅ Chọn 3 bước kết hợp để tự động hóa cho hiện tại & tương lai.

✅ Đáp án đúng (Chọn 3)

Các lựa chọn đúng là: Lựa chọn 1, Lựa chọn 5, và Lựa chọn 6.

Lý do lựa chọn:

  • Kết hợp hoàn hảo: Tạo new account chứa Lambda (1) để deploy custom logic an toàn, isolated. Role ở management account (5) cho phép Lambda cross-account assume AWSControlTowerExecution trong mọi member account. EventBridge rule ở management account (6) trigger Lambda trên events enroll/update, và re-register OUs để apply ngay cho existing accounts + tự động future.
  • Đảm bảo idempotent, scalable, secure theo best practices AWS (không chỉnh role ở từng account, tránh manual).
  • Áp dụng cho Config recorder managed: Lambda dùng role để put-configuration-recorder với custom settings (e.g., resourceTypes).

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn. Giữ nguyên văn bản gốc tiếng Anh, giải thích bằng tiếng Việt với lý do đúng/sai dựa trên docs AWS Control Tower 2026 (CfCT & lifecycle events).

  • Create a new AWS account. Create an AWS Lambda function in the new account to apply the customizations to the AWS Config configuration recorder in each AWS account in the organization.
    ✅ Đúng. Tạo dedicated "customizations account" (enroll vào Control Tower), deploy Lambda ở đây để cross-modify Config recorder toàn org qua assume role. Isolated, dễ manage, tránh overload management account. Phù hợp CfCT pattern. (Nguồn: AWS Control Tower User Guide - Customizations).

  • Create a new AWS account as an AWS Config delegated administrator. Create an AWS Lambda function in the delegated administrator account to apply the customizations to the AWS Config configuration recorder in the delegated administrator account.
    ❌ Sai. Delegated admin cho AWS Config chỉ cho phép manage Config ở org level, nhưng Lambda chỉ customize riêng delegated account (không cross to others). Không cover existing/future accounts. (Nguồn: AWS Config Delegated Administrator docs).

  • Configure an Amazon EventBridge rule in the AWS Control Tower management account to invoke an AWS Lambda function when the Organizations OU is registered or reregistered. Re-register the root Organizations OU.
    ❌ Sai. Event chỉ trigger khi OU registered/reregistered, không cover account enroll/update hoặc landing zone update. Re-register chỉ root OU không propagate xuống child OUs/accounts. Không full coverage future accounts. (Nguồn: Control Tower EventBridge events).

  • Configure the AWSControlTowerExecution IAM role in each AWS account in the organization to be assumable by an AWS Lambda function. Configure the Lambda function to assume the AWSControlTowerExecution IAM role.
    ❌ Sai. Phải chỉnh mỗi account (không scalable cho large org/future accounts). AWSControlTowerExecution là managed role, không nên modify trực tiếp (vi phạm least privilege & Control Tower integrity). (Nguồn: IAM roles in Control Tower).

  • Create an IAM role in the AWS Control Tower management account that an AWS Lambda function can assume. Grant the IAM role permission to assume the AWSControlTowerExecution IAM role in any account in the organization. Configure the Lambda function to use the new IAM role.
    ✅ Đúng. Role trung tâm ở management account (e.g., "CfctCrossAccountRole") với sts:AssumeRole policy cho AWSControlTowerExecution (arn:aws:iam::*:role/AWSControlTowerExecution). Lambda assume role này để modify Config recorder cross-account. Secure & org-wide. (Nguồn: CfCT Cross-account permissions).

  • Configure an Amazon EventBridge rule in the AWS Control Tower management account to invoke an AWS Lambda function when an AWS account is updated or enrolled in AWS Control Tower or when the landing zone is updated. Re-register each Organizations OU in the organization.
    ✅ Đúng. EventBridge target events chính xác: control-tower:AccountFactoryEvent (enroll/update), control-tower:LandingZoneUpdateEvent. Trigger Lambda apply custom. Re-register each OU emit events cho existing accounts (propagate xuống). Tự động future. (Nguồn: AWS Blogs - Customize Control Tower Lifecycle Events).

🛠️ Khuyến nghị triển khai & Tài liệu tham khảo

Câu 595
A company runs an application in an Auto Scaling group of Amazon EC2 instances behind an Application Load Balancer (ALB). The EC2 instances run Docker containers that make requests to a MySQL database that runs on separate EC2 instances.

A DevOps engineer needs to update the application to use a serverless architecture.

Which solution will meet this requirement with the FEWEST changes?
  1. A Replace the containers that run on EC2 instances and the ALB with AWS Lambda functions. Replace the MySQL database with an Amazon Aurora Serverless v2 database that is compatible with MySQL.
  2. B Replace the containers that run on EC2 instances with AWS Fargate. Replace the MySQL database with an Amazon Aurora Serverless v2 database that is compatible with MySQL.
  3. C Replace the containers that run on EC2 instances and the ALB with AWS Lambda functions. Replace the MySQL database with Amazon DynamoDB tables.
  4. D Replace the containers that run on EC2 instances with AWS Fargate. Replace the MySQL database with Amazon DynamoDB tables.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một kiến trúc hiện tại:

  • Ứng dụng chạy trong Auto Scaling group (ASG) của các instance Amazon EC2, trên đó là các Docker containers.
  • Các containers này được đặt sau một Application Load Balancer (ALB) để phân tải.
  • Containers gửi yêu cầu đến một MySQL database chạy trên các EC2 instances riêng biệt.

Yêu cầu của DevOps engineer: Chuyển đổi sang kiến trúc serverless (không cần quản lý server cơ sở hạ tầng) với FEWEST changes (ít thay đổi nhất có thể).
✅ Mục tiêu chính: Giữ nguyên logic ứng dụng (containers Docker và truy vấn MySQL), chỉ thay thế phần compute và database để đạt serverless, giảm thiểu việc viết lại code.
🛠️ Serverless ở đây nghĩa là sử dụng dịch vụ AWS tự động scale và quản lý server như Fargate (cho containers), Lambda (cho functions), hoặc Aurora Serverless (cho DB). Kiến thức cập nhật đến 2026: AWS ưu tiên ECS on Fargate cho serverless containers và Aurora Serverless v2 (ra mắt 2022, cải tiến scale zero và performance cao hơn v1).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Replace the containers that run on EC2 instances with AWS Fargate. Replace the MySQL database with an Amazon Aurora Serverless v2 database that is compatible with MySQL.

Lý do:

  • Đây là giải pháp ít thay đổi nhất vì:
    • AWS Fargate cho phép chạy Docker containers trực tiếp mà không cần quản lý EC2 (serverless compute engine cho ECS). Chỉ cần migrate containers từ EC2 sang ECS on Fargate, giữ nguyên ALB (ALB tích hợp sẵn với Fargate). Không cần viết lại code ứng dụng.
    • Amazon Aurora Serverless v2 (MySQL-compatible) thay thế MySQL trên EC2: Tự động scale từ 0.5 ACU đến hàng nghìn ACU, tương thích 100% với MySQL (hỗ trợ JDBC/ODBC drivers), chỉ thay connection string là dùng được. Không cần thay đổi schema SQL hay code truy vấn.
  • Tổng thay đổi: Loại bỏ ASG EC2 và EC2 DB, giữ nguyên containers/Docker image và logic app → FEWEST changes.

📋 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh:

  • ❌ Phương án SAI: Replace the containers that run on EC2 instances and the ALB with AWS Lambda functions. Replace the MySQL database with an Amazon Aurora Serverless v2 database that is compatible with MySQL.
    Giải thích sai: Thay containers và ALB bằng Lambda yêu cầu viết lại toàn bộ ứng dụng thành serverless functions (Lambda không chạy Docker containers trực tiếp, phải refactor code từ containerized app sang event-driven functions). ALB không tương thích trực tiếp với Lambda (cần dùng API Gateway hoặc Lambda URL, phức tạp hơn). DB thay OK nhưng phần compute thay đổi lớn → KHÔNG phải FEWEST changes.

  • ✅ Phương án ĐÚNG: Replace the containers that run on EC2 instances with AWS Fargate. Replace the MySQL database with an Amazon Aurora Serverless v2 database that is compatible with MySQL.
    Giải thích đúng: Như phần trên, Fargate giữ nguyên Docker containers (chỉ deploy lên ECS cluster serverless), ALB vẫn dùng, DB tương thích MySQL → Thay đổi tối thiểu, đạt serverless full-stack.

  • ❌ Phương án SAI: Replace the containers that run on EC2 instances and the ALB with AWS Lambda functions. Replace the MySQL database with Amazon DynamoDB tables.
    Giải thích sai: Tương tự phương án 1, Lambda yêu cầu refactor lớn (containers → functions). DynamoDB là NoSQL key-value, không tương thích MySQL (phải viết lại schema, queries từ SQL sang PartiQL/NoSQL API) → Thay đổi cực lớn, không phù hợp FEWEST.

  • ❌ Phương án SAI: Replace the containers that run on EC2 instances with AWS Fargate. Replace the MySQL database with Amazon DynamoDB tables.
    Giải thích sai: Fargate tốt (ít thay đổi cho compute), nhưng DynamoDB buộc phải refactor app từ relational SQL sang NoSQL (thay đổi models, queries, migrations) → Vẫn nhiều thay đổi ở DB layer, không tối ưu bằng Aurora Serverless v2.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

🛠️ Lời khuyên: Trong thực tế, test migration với ECS Exec và Aurora Data API để zero-downtime!

Câu 596
A company uses an organization in AWS Organizations to manage 10 AWS accounts. All features are enabled, and trusted access for AWS CloudFormation is enabled.

A DevOps engineer needs to use CloudFormation to deploy an IAM role to the Organizations management account and all member accounts in the organization.

Which solution will meet these requirements with the LEAST operational overhead?
  1. A Create a CloudFormation StackSet that has service-managed permissions. Set the root OU as a deployment target.
  2. B Create a CloudFormation StackSet that has service-managed permissions. Set the root OU as a deployment target. Deploy a separate CloudFormation stack in the Organizations management account.
  3. C Create a CloudFormation StackSet that has self-managed permissions. Set the root OU as a deployment target.
  4. D Create a CloudFormation StackSet that has self-managed permissions. Set the root OU as a deployment target. Deploy a separate CloudFormation stack in the Organizations management account.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm AWS

📘 Nội dung câu hỏi được giải thích rõ ràng:
Câu hỏi xoay quanh việc sử dụng AWS Organizations (với 10 tài khoản AWS, tất cả tính năng được kích hoạt - all features enabled) và trusted access cho AWS CloudFormation đã được bật. Một DevOps engineer cần triển khai một IAM role bằng CloudFormation đến tài khoản management account (tài khoản gốc của tổ chức) VÀ tất cả member accounts (các tài khoản thành viên) trong tổ chức.
Yêu cầu chính là giải pháp có LEAST operational overhead (ít công sức vận hành nhất), nghĩa là ưu tiên tự động hóa cao, giảm thiểu việc quản lý thủ công IAM roles ở từng tài khoản.
🛠️ Bối cảnh kỹ thuật cập nhật 2026: Với CloudFormation StackSets tích hợp Organizations (từ phiên bản mới nhất), có hai loại permissions: service-managed (CloudFormation tự quản lý IAM roles qua delegated administrator) và self-managed (phải tạo roles thủ công). Targeting root OU sẽ deploy đến tất cả member accounts dưới root, nhưng management account KHÔNG được bao gồm tự động trong StackSet (phải deploy riêng).

✅ Đáp án đúng:
Create a CloudFormation StackSet that has service-managed permissions. Set the root OU as a deployment target. Deploy a separate CloudFormation stack in the Organizations management account.

Lý do chọn đáp án này (chi tiết):

  • Service-managed permissions tận dụng trusted access của Organizations để CloudFormation tự động tạo và quản lý IAM roles (delegated admin model), deploy stack đến tất cả member accounts qua root OU mà KHÔNG cần can thiệp thủ công ở từng account → least overhead.
  • StackSet chỉ cover member accounts, nên cần separate stack (stack thông thường) ở management account để deploy IAM role → Hoàn chỉnh yêu cầu.
  • Đây là best practice từ AWS (updated 2026), giảm thiểu rủi ro và effort so với self-managed.
    🛡️ Lợi ích: Tự động hóa 100% cho members, chỉ 1 stack thủ công cho management.

🔍 Giải thích tất cả các phương án (đúng/sai)

  • ❌ Phương án SAI: Create a CloudFormation StackSet that has service-managed permissions. Set the root OU as a deployment target.
    Lý do sai: Service-managed StackSet targeting root OU chỉ deploy đến member accounts (dưới root), bỏ sót management account (management không thuộc OU nào để StackSet target). Không đáp ứng yêu cầu deploy đến TẤT CẢ accounts, dẫn đến IAM role thiếu ở management → Không hoàn chỉnh.

  • ✅ Phương án ĐÚNG: Create a CloudFormation StackSet that has service-managed permissions. Set the root OU as a deployment target. Deploy a separate CloudFormation stack in the Organizations management account.
    (Đã giải thích chi tiết ở phần trên). Đây là giải pháp tối ưu, least overhead nhờ tự động hóa qua service-managed + 1 bước đơn giản cho management.

  • ❌ Phương án SAI: Create a CloudFormation StackSet that has self-managed permissions. Set the root OU as a deployment target.
    Lý do sai: Self-managed permissions yêu cầu tạo IAM roles thủ công ở MỖI member account trước khi deploy (execution/admin roles), tăng operational overhead cao (phải scale thủ công cho 10 accounts). Không tận dụng trusted access Organizations, kém hiệu quả hơn service-managed.

  • ❌ Phương án SAI: Create a CloudFormation StackSet that has self-managed permissions. Set the root OU as a deployment target. Deploy a separate CloudFormation stack in the Organizations management account.
    Lý do sai: Dù cover management bằng separate stack, nhưng self-managed vẫn yêu cầu quản lý roles thủ công ở tất cả members → Overhead lớn hơn service-managed (phải duplicate effort tạo roles). Không phải least overhead.

📚 Tài liệu tham khảo (AWS docs cập nhật mới nhất 2026)

Hy vọng phân tích này giúp bạn nắm vững! 🚀 Nếu cần demo code CloudFormation template, hãy hỏi thêm.

Câu 597 Chọn nhiều đáp án
A company runs an application that stores artifacts in an Amazon S3 bucket. The application has a large user base. The application writes a high volume of objects to the S3 bucket. The company has enabled event notifications for the S3 bucket.

When the application writes an object to the S3 bucket, several processing tasks need to be performed simultaneously. The company's DevOps team needs to create an AWS Step Functions workflow to orchestrate the processing tasks.

Which combination of steps should the DevOps team take to meet these requirements with the LEAST operational overhead? (Choose two.)
  1. A Create a Standard workflow that contains a parallel state that defines the processing tasks. Create an Asynchronous Express workflow that contains a parallel state that defines the processing tasks.
  2. B Create a Synchronous Express workflow that contains a map state that defines the processing tasks.
  3. C Create an Amazon EventBridge rule to match when a new S3 object is created. Configure the EventBridge rule to invoke an AWS Lambda function. Configure the Lambda function to start the processing workflow.
  4. D Create an Amazon EventBridge rule to match when a new S3 object is created. Configure the EventBridge rule to start the processing workflow.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc tối ưu hóa quy trình xử lý sự kiện từ Amazon S3 trong một ứng dụng có lượng người dùng lớn, ghi high volume objects vào S3 bucket đã kích hoạt event notifications. Khi một object mới được tạo (write), cần thực hiện nhiều processing tasks đồng thời (simultaneously). Nhiệm vụ của DevOps team là xây dựng AWS Step Functions workflow để orchestrate (điều phối) các tasks này với LEAST operational overhead (ít chi phí vận hành nhất).

📌 Yêu cầu chính:

  • Xử lý high volume → Cần scalable, không blocking.
  • Simultaneously → Sử dụng cơ chế chạy song song.
  • Least overhead → Tránh các thành phần trung gian thừa (như Lambda), tận dụng tích hợp native giữa S3 → EventBridge → Step Functions.
  • Choose TWO → Kết hợp hai bước.

Kiến thức AWS cập nhật đến 2026: S3 Event Notifications hỗ trợ gửi trực tiếp đến EventBridge (từ 2020, cải tiến 2023+). Step Functions Express Workflows (ra mắt 2022, tối ưu 2024-2026) lý tưởng cho high-throughput, short-duration tasks với parallel states. EventBridge có thể invoke Step Functions trực tiếp (Standard hoặc Express), không cần Lambda.

✅ Đáp án đúng (Choose TWO)

Hai lựa chọn đúng là:

  1. Create a Standard workflow that contains a parallel state that defines the processing tasks. Create an Asynchronous Express workflow that contains a parallel state that defines the processing tasks.
  2. Create an Amazon EventBridge rule to match when a new S3 object is created. Configure the EventBridge rule to start the processing workflow.

Lý do chọn 🛠️:

  • Kết hợp EventBridge rule trực tiếp trigger workflow từ S3 event (không Lambda → least overhead, scalable cho high volume).
  • Workflow sử dụng parallel state để chạy several tasks đồng thời (native hỗ trợ branching song song). Standard workflow cho long-running/complex logic; Asynchronous Express workflow lý tưởng high-volume/short tasks (hàng triệu executions/giây, auto-scaling, giá rẻ hơn 2026 pricing). Đây là best practice AWS cho orchestration S3 events.

📋 Giải thích tất cả các phương án

  • ✅ Create a Standard workflow that contains a parallel state that defines the processing tasks. Create an Asynchronous Express workflow that contains a parallel state that defines the processing tasks.
    🟢 Đúng vì: Parallel state cho phép định nghĩa và chạy nhiều tasks đồng thời (như Lambda invokes song song), khớp yêu cầu "several processing tasks simultaneously". Standard workflow hỗ trợ durable execution dài hạn; Asynchronous Express workflow (Express v2 2024+) tối ưu high-volume S3 events (thousands/sec, không polling). Least overhead: Native state machine, không code custom.

  • ❌ Create a Synchronous Express workflow that contains a map state that defines the processing tasks.
    🔴 Sai vì: Map state dùng để iterate (lặp) qua array inputs (fan-out sequential/parallel), không phải cho "several fixed tasks simultaneously" (không khớp). Synchronous Express blocking và kém scalable cho high-volume (chỉ ~1s timeout), gây overhead throttling. Không least overhead so với parallel state đơn giản.

  • ❌ Create an Amazon EventBridge rule to match when a new S3 object is created. Configure the EventBridge rule to invoke an AWS Lambda function. Configure the Lambda function to start the processing workflow.
    🔴 Sai vì: Thêm Lambda trung gian tạo operational overhead (provisioning, cold starts, error handling, scaling code), không least. EventBridge + Lambda kém hiệu quả cho high-volume S3 events (throttling Lambda concurrency). Best practice: EventBridge direct start Step Functions.

  • ✅ Create an Amazon EventBridge rule to match when a new S3 object is created. Configure the EventBridge rule to start the processing workflow.
    🟢 Đúng vì: S3 Event Notifications → EventBridge rule filter objectCreated events → direct start Step Functions (native integration từ 2021, Express async 2023+). Scalable vô hạn, least overhead (no code, pay-per-use), lý tưởng high-volume. Tránh Lambda proxy hoàn toàn.

📘 Tài liệu tham khảo (AWS Docs cập nhật 2026)

Hy vọng phân tích giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần ví dụ ASL code, hỏi thêm nhé.

Câu 598 Chọn nhiều đáp án
A DevOps team supports an application that runs in an Amazon Elastic Container Service (Amazon ECS) cluster behind an Application Load Balancer (ALB). Currently, the DevOps team uses AWS CodeDeploy to deploy the application by using a blue/green all-at-once strategy. Recently, the DevOps team had to roll back a deployment when a new version of the application dramatically increased response times for requests.

The DevOps team needs use to a deployment strategy that will allow the team to monitor a new version of the application before the team shifts all traffic to the new version. If a new version of the application increases response times, the deployment should be rolled back as quickly as possible.

Which combination of steps will meet these requirements? (Choose two.)
  1. A Modify the CodeDeploy deployment to use the CodeDeployDefault.ECSCanary10Percent5Minutes configuration.
  2. B Modify the CodeDeploy deployment to use the CodeDeployDefault.ECSLinear10PercentEvery3Minutes configuration.
  3. C Create an Amazon CloudWatch alarm to monitor the UnHealthyHostCount metric for the ALB. Set the alarm to activate if the metric is higher than the desired value. Associate the alarm with the CodeDeploy deployment group. Modify the deployment group to roll back when a deployment fails.
  4. D Create an Amazon CloudWatch alarm to monitor the TargetResponseTime metric for the ALB. Set the alarm to activate if the metric is higher than the desired value. Associate the alarm with the CodeDeploy deployment group. Modify the deployment group to roll back when alarm thresholds are met.
  5. E Create an Amazon CloudWatch alarm to monitor the TargetConnectionErrorCount metric for the ALB. Set the alarm to activate if the metric is higher than the desired value. Associate the alarm with the CodeDeploy deployment group. Modify the deployment group to roll back when alarm thresholds are met.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi xoay quanh một đội DevOps quản lý ứng dụng chạy trên Amazon ECS cluster phía sau Application Load Balancer (ALB). Hiện tại, họ sử dụng AWS CodeDeploy với chiến lược blue/green all-at-once (chuyển toàn bộ traffic sang phiên bản mới ngay lập tức). Vấn đề gần đây: Một deployment mới làm tăng đáng kể response times, buộc phải rollback thủ công.

Yêu cầu chính:

  • Chuyển sang chiến lược deployment cho phép monitor phiên bản mới trước khi chuyển toàn bộ traffic sang nó.
  • Nếu response times tăng, rollback nhanh chóng tự động.

Câu hỏi yêu cầu chọn 2 bước kết hợp (combination of steps) để đáp ứng. Đây là tình huống điển hình trong DevOps trên AWS ECS blue/green deployments (cập nhật đến 2026, CodeDeploy hỗ trợ ECS với Fargate/EC2, tích hợp ALB tightly).

✅ Đáp án đúng (chọn 2)

  • Modify the CodeDeploy deployment to use the CodeDeployDefault.ECSCanary10Percent5Minutes configuration.
  • Create an Amazon CloudWatch alarm to monitor the TargetResponseTime metric for the ALB. Set the alarm to activate if the metric is higher than the desired value. Associate the alarm with the CodeDeploy deployment group. Modify the deployment group to roll back when alarm thresholds are met.

Lý do chọn:

  • Canary configuration (10% traffic trong 5 phút) cho phép test phiên bản mới với traffic nhỏ, monitor trước khi shift 100% – phù hợp "monitor before shifting all traffic".
  • Alarm trên TargetResponseTime trực tiếp theo dõi response times (metric của ALB target groups), trigger rollback tự động nếu vượt ngưỡng – giải quyết vấn đề cụ thể "increased response times" và "rollback as quickly as possible". Kết hợp 2 bước này tạo deployment an toàn, canary + alarm-based rollback (tính năng CodeDeploy ECS blue/green từ 2018, ổn định đến 2026).

📋 Giải thích chi tiết từng phương án

Dưới đây là phân tích tất cả 5 lựa chọn, với ✅ đúng và ❌ sai. Giữ nguyên text gốc tiếng Anh, giải thích bằng tiếng Việt rõ ràng:

  • ✅ Modify the CodeDeploy deployment to use the CodeDeployDefault.ECSCanary10Percent5Minutes configuration.
    🛠️ Đúng: Đây là Canary deployment config chuẩn của CodeDeploy cho ECS blue/green. Nó route 10% traffic sang target group xanh (new version) trong 5 phút, sau đó bake time rồi shift 100%. Cho phép monitor metrics (như response time) trên phần traffic nhỏ trước khi commit full – chính xác đáp ứng "monitor new version before shifting all traffic". So với all-at-once hiện tại, giảm rủi ro lớn. (Cập nhật: Vẫn là config mặc định tốt nhất cho canary đến 2026).

  • ❌ Modify the CodeDeploy deployment to use the CodeDeployDefault.ECSLinear10PercentEvery3Minutes configuration.
    🧩 Sai: Đây là Linear config, tăng dần 10% traffic mỗi 3 phút đến 100%. Tuy cũng monitor dần dần, nhưng chậm hơn canary (khoảng 30 phút full shift), không ưu tiên "rollback as quickly as possible" vì traffic đã phân tán nhiều. Canary nhanh test/small blast radius hơn, phù hợp yêu cầu chính.

  • ❌ Create an Amazon CloudWatch alarm to monitor the UnHealthyHostCount metric for the ALB. Set the alarm to activate if the metric is higher than the desired value. Associate the alarm with the CodeDeploy deployment group. Modify the deployment group to roll back when a deployment fails.
    🚫 Sai: UnHealthyHostCount chỉ đếm target hosts unhealthy (dựa health checks như HTTP 200), không liên quan trực tiếp đến response times tăng. Alarm này trigger trên failure health check, nhưng vấn đề là response chậm (không fail health check ngay). Phần "roll back when a deployment fails" chỉ rollback on deployment failure, không phải alarm threshold – không match yêu cầu monitor response time.

  • ✅ Create an Amazon CloudWatch alarm to monitor the TargetResponseTime metric for the ALB. Set the alarm to activate if the metric is higher than the desired value. Associate the alarm with the CodeDeploy deployment group. Modify the deployment group to roll back when alarm thresholds are met.
    🛠️ Đúng: TargetResponseTime là metric p99 response time của targets sau ALB (bao gồm app processing time). Alarm associate trực tiếp với CodeDeploy deployment group (tính năng ECS blue/green), set auto-rollback khi vượt threshold (ví dụ >500ms). Hoàn hảo cho "increased response times" và rollback nhanh (seconds sau alarm). Kết hợp với canary = best practice.

  • ❌ Create an Amazon CloudWatch alarm to monitor the TargetConnectionErrorCount metric for the ALB. Set the alarm to activate if the metric is higher than the desired value. Associate the alarm with the CodeDeploy deployment group. Modify the deployment group to roll back when alarm thresholds are met.
    🚫 Sai: TargetConnectionErrorCount đếm lỗi kết nối TCP/SSL đến targets (như port closed, timeout connect), không phải response times (đã connect nhưng app chậm). Không giải quyết vấn đề cụ thể "response times increased" – chỉ hữu ích cho connection issues.

📘 Tài liệu tham khảo (AWS docs cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm ví dụ thực hành, hỏi nhé!

Câu 599
A security team must record the configuration of AWS resources, detect issues, and send notifications for findings. The main workload in the AWS account consists of an Amazon EC2 Auto Scaling group that scales in and out several times during the day.

The team wants to be notified within 2 days if any Amazon EC2 security group allows traffic on port 22 for 0.0.0.0/0. The team also needs a snapshot of the configuration of the AWS resources to be taken routinely.

The security team has already created and subscribed to an Amazon Simple Notification Service (Amazon SNS) topic.

Which solution meets these requirements?
  1. A Configure AWS Config to use periodic recording for the AWS account. Deploy the vpc-sg-port-restriction-check AWS Config managed rule. Configure AWS Config to use the SNS topic as the target for notifications.
  2. B Configure AWS Config to use configuration change recording for the AWS account. Deploy the vpc-sg-open-only-to-authorized-ports AWS Config managed rule. Configure AWS Config to use the SNS topic as the target for notifications.
  3. C Configure AWS Config to use configuration change recording for the AWS account. Deploy the ssh-restricted AWS Config managed rule. Configure AWS Config to use the SNS topic as the target for notifications.
  4. D Create an AWS Lambda function to evaluate security groups and publish a message to the SNS topic. Use an Amazon EventBridge rule to schedule the Lambda function to run once a day.
Xem giải thích

🧩 Giải thích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc thiết lập hệ thống giám sát và thông báo bảo mật cho tài nguyên AWS, đặc biệt là Amazon EC2 security groups trong môi trường có Auto Scaling group (ASG) scale in/out thường xuyên (nhiều lần trong ngày). Các yêu cầu chính bao gồm:

  • 📝 Ghi lại cấu hình tài nguyên AWS (recording configuration) và chụp snapshot định kỳ (routine snapshots).
  • 🔍 Phát hiện vấn đề: Thông báo trong vòng 2 ngày nếu bất kỳ security group nào cho phép traffic inbound trên port 22 (SSH) từ 0.0.0.0/0 (nghĩa là mở cửa cho toàn bộ internet – rủi ro bảo mật cao).
  • 🔔 Gửi thông báo qua Amazon SNS topic đã được tạo sẵn và subscribe.

🛠️ Thách thức chính: Với ASG scale động, cấu hình thay đổi liên tục (instances mới/old được thay thế), nên cần cơ chế ghi nhận thay đổi realtime thay vì chỉ snapshot định kỳ. AWS Config là dịch vụ lý tưởng để ghi config, đánh giá rules, và tích hợp SNS cho alerts. Kiến thức cập nhật đến 2026: AWS Config hỗ trợ managed rules chuyên biệt cho security groups, với continuous evaluation trên config changes (theo AWS Well-Architected Framework Security Pillar).

✅ Đáp án đúng và lý do lựa chọn

Configure AWS Config to use configuration change recording for the AWS account. Deploy the ssh-restricted AWS Config managed rule. Configure AWS Config to use the SNS topic as the target for notifications.

Lý do chi tiết:

  • Configuration change recording 🧩: Phù hợp hoàn hảo với ASG scale thường xuyên, ghi nhận mọi thay đổi config realtime (không miss updates từ scaling). Đồng thời hỗ trợ routine snapshots tự động (mặc định hàng ngày).
  • ssh-restricted rule 🔒: Managed rule chuyên kiểm tra security groups có mở port 22 (SSH) inbound từ 0.0.0.0/0 hay không – khớp chính xác yêu cầu. Rule evaluate liên tục trên changes, đảm bảo notify trong 2 ngày (thực tế nhanh hơn, thường minutes).
  • SNS integration 🔔: Config gửi NON_COMPLIANT findings trực tiếp đến SNS topic.
    Giải pháp toàn diện, chi phí thấp, serverless.

📘 Tài liệu tham khảo:

🔍 Phân tích tất cả các phương án (đúng/sai)

  • ❌ Configure AWS Config to use periodic recording for the AWS account. Deploy the vpc-sg-port-restriction-check AWS Config managed rule. Configure AWS Config to use the SNS topic as the target for notifications.
    Sai vì: Periodic recording chỉ chụp snapshot theo lịch cố định (ví dụ: hàng ngày/giờ), miss các thay đổi realtime từ ASG scaling (scale nhiều lần/ngày). Rule vpc-sg-port-restriction-check kiểm tra tất cả port 1-65535 mở từ 0.0.0.0/0, không cụ thể port 22 SSH – không khớp yêu cầu chính xác. Không hiệu quả cho môi trường động.

  • ❌ Configure AWS Config to use configuration change recording for the AWS account. Deploy the vpc-sg-open-only-to-authorized-ports AWS Config managed rule. Configure AWS Config to use the SNS topic as the target for notifications.
    Sai vì: Change recording đúng, nhưng rule vpc-sg-open-only-to-authorized-ports yêu cầu tự định nghĩa authorized ports (ví dụ: chỉ cho phép port 80/443), không mặc định kiểm tra port 22 từ 0.0.0.0/0. Phải customize parameters, phức tạp và không khớp straight-forward với yêu cầu SSH-specific.

  • ✅ Configure AWS Config to use configuration change recording for the AWS account. Deploy the ssh-restricted AWS Config managed rule. Configure AWS Config to use the SNS topic as the target for notifications.
    Đúng vì: Như giải thích ở trên – change recording capture scaling changes, ssh-restricted rule chính xác cho port 22/0.0.0.0/0, SNS notify kịp thời. Hoàn hảo, native AWS solution.

  • ❌ Create an AWS Lambda function to evaluate security groups and publish a message to the SNS topic. Use an Amazon EventBridge rule to schedule the Lambda function to run once a day.
    Sai vì: Chỉ chạy daily (EventBridge schedule), không đảm bảo notify trong 2 ngày nếu issue xảy ra ngay sau run (và với ASG, changes liên tục). Không hỗ trợ routine snapshots config toàn diện (Lambda chỉ check SGs thủ công). Custom code tốn công maintain, kém scalable so với AWS Config managed rules. Vi phạm best practice serverless.

Câu 600
A company has proprietary data available by using an Amazon CloudFront distribution. The company needs to ensure that the distribution is accessible by only users from the corporate office that have a known set of IP address ranges. An AWS WAF web ACL is associated with the distribution and has a default action set to Count.

Which solution will meet these requirements with the LEAST operational overhead?
  1. A Create a new regex pattern set. Add the regex pattern set to a new rule group. Create a new web ACL that has a default action set to Block. Associate the web ACL with the CloudFront distribution. Add a rule that allows traffic based on the new rule group.
  2. B Create an AWS WAF IP address set that matches the corporate office IP address range. Create a new web ACL that has a default action set to Allow. Associate the web ACL with the CloudFront distribution. Add a rule that allows traffic from the IP address set.
  3. C Create a new regex pattern set. Add the regex pattern set to a new rule group. Set the default action on the existing web ACL to Allow. Add a rule that has priority 0 that allows traffic based on the regex pattern set.
  4. D Create a WAF IP address set that matches the corporate office IP address range. Set the default action on the existing web ACL to Block. Add a rule that has priority 0 that allows traffic from the IP address set.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc bảo mật Amazon CloudFront distribution chứa dữ liệu độc quyền của công ty. Yêu cầu là chỉ cho phép truy cập từ một tập hợp IP address ranges cụ thể của văn phòng công ty, đồng thời sử dụng AWS WAF web ACL đã tồn tại (đang gắn với distribution và có default action là Count). Giải pháp phải đạt LEAST operational overhead (ít công sức vận hành nhất), nghĩa là ưu tiên tái sử dụng tài nguyên hiện có, tránh tạo mới nhiều thành phần.

Bối cảnh kỹ thuật chính (dựa trên AWS WAF v2 - phiên bản mới nhất đến 2026):

  • AWS WAF hoạt động theo quy tắc ưu tiên (priority số thấp hơn chạy trước).
  • Default action áp dụng cho traffic không khớp rule nào.
  • Hiện tại default là Count (chỉ đếm, không block/allow).
  • Để chặn tất cả ngoại trừ IP cụ thể: Cần default Block + rule priority 0 allow IP (chạy đầu tiên).
  • CloudFront hỗ trợ WAF để kiểm soát truy cập dựa trên IP set (hiệu quả hơn regex cho IP ranges).

Mục tiêu: Chuyển ACL hiện có thành allow chỉ IP văn phòng, block còn lại, với overhead thấp nhất.

✅ Đáp án đúng

Create a WAF IP address set that matches the corporate office IP address range. Set the default action on the existing web ACL to Block. Add a rule that has priority 0 that allows traffic from the IP address set.

Lý do lựa chọn:

  • 🛠️ Tái sử dụng existing web ACL: Chỉ chỉnh sửa (set default to Block + thêm 1 rule priority 0), không tạo ACL mới → least overhead.
  • 📍 IP set phù hợp nhất cho IP ranges (regex không cần thiết, IP set đơn giản và hiệu suất cao).
  • 🔒 Logic đúng: Rule priority 0 allow IP chạy trước → cho phép IP văn phòng; default Block chặn tất cả còn lại.
  • ⚡ Hiệu quả: Không cần rule group/regex phức tạp, phù hợp best practice AWS WAF cho IP restriction trên CloudFront (cập nhật 2024-2026).

📋 Giải thích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc:

  • Create a new regex pattern set. Add the regex pattern set to a new rule group. Create a new web ACL that has a default action set to Block. Associate the web ACL with the CloudFront distribution. Add a rule that allows traffic based on the new rule group.
    ❌ Sai: Tạo quá nhiều tài nguyên mới (regex set, rule group, web ACL mới, associate lại) → overhead cao. Regex không tối ưu cho IP ranges (IP set đơn giản hơn). Không tận dụng existing ACL.

  • Create an AWS WAF IP address set that matches the corporate office IP address range. Create a new web ACL that has a default action set to Allow. Associate the web ACL with the distribution. Add a rule that allows traffic from the IP address set.
    ❌ Sai: Tạo web ACL mới → overhead không cần thiết. Default Allow cho phép tất cả traffic (rule allow IP chỉ dư thừa, không block ngoài IP) → không đáp ứng yêu cầu bảo mật.

  • Create a new regex pattern set. Add the regex pattern set to a new rule group. Set the default action on the existing web ACL to Allow. Add a rule that has priority 0 that allows traffic based on the regex pattern set.
    ❌ Sai: Regex và rule group mới không cần (IP set hiệu quả hơn). Default Allow vẫn cho phép tất cả (priority 0 chỉ allow IP, nhưng default allow phần còn lại) → không block traffic ngoài IP.

  • Create a WAF IP address set that matches the corporate office IP address range. Set the default action on the existing web ACL to Block. Add a rule that has priority 0 that allows traffic from the IP address set.
    ✅ Đúng: Như giải thích trên, overhead thấp nhất, logic bảo mật hoàn hảo.

📘 Tài liệu tham khảo

Giải pháp này đảm bảo tuân thủ zero-trust với overhead tối thiểu! 🚀