Ngân hàng đề — AWS Certified DevOps Engineer Professional

Tìm thấy 681 câu.

Câu 61 Domain 3: Resilient Cloud Solutions

An e-commerce company has deployed its flagship application in two Auto Scaling groups (ASGs) and two Application Load Balancers (ALBs). You have a Route 53 record that points to the ALB+ASG group where the application has been the most recently deployed. Deployments are alternating between the two groups, and every time a deployment happens it is done on the non-active ALB+ASG group. Finally, the Route53 record is updated. It turns out that some of your clients are not behaving correctly towards the DNS record and thus making requests to the inactive ALB+ASG group.

The company would like to improve this behavior at a minimal cost and also reduce the complexity of the solution. The company has hired you as an AWS Certified DevOps Engineer Professional to build a solution for this requirement. What of the following would you suggest?

  1. A

    Change the TTL of the Route53 to 1 minute before doing a deployment. Do the deployment and then increase the TTL back to the old value

  2. B

    Deploy the application to Elastic Beanstalk under two environments. To do a deployment, deploy to the older environment, then perform a CNAME swap

  3. C

    Deploy a set of NGINX proxy onto each application instance so that if requests are made through the inactive ALB, they are proxied onto the correct ALB

  4. D

    Remove one ALB and keep the two ASG. When new deployments happen, deploy to the older ASG, and then swap the target group in the ALB rule. Keep the Route53 record pointing to the ALB

Xem giải thích

Đáp án

D — Bỏ bớt một ALB, giữ hai ASG; mỗi lần triển khai thì đưa mã lên ASG cũ rồi hoán đổi target group trong luật của ALB, và giữ nguyên bản ghi Route 53 trỏ tới ALB đó

Vì sao đúng

Vấn đề gốc: chuyển đổi bằng Route 53 phụ thuộc vào việc client tôn trọng TTL của DNS — và nhiều client (đặc biệt là ứng dụng Java và một số thư viện HTTP) cache DNS vô thời hạn, bất kể TTL. Đó chính là lý do một số client vẫn gọi vào nhóm đã ngừng hoạt động.

Cách chữa triệt để là bỏ hẳn DNS khỏi đường chuyển đổi:

Route 53  →  MỘT ALB (không bao giờ đổi)
                 │  luật listener trỏ tới target group nào?
                 ├── Target Group Blue  (ASG 1)
                 └── Target Group Green (ASG 2)

Chuyển đổi giờ là đổi target group trong luật của ALB — có hiệu lực tức thì với mọi client, vì tên DNS và địa chỉ không đổi. Client có cache DNS bao lâu cũng không ảnh hưởng.

Nó cũng rẻ hơn: bỏ được một ALB.

Vì sao các phương án khác sai

  • A. Giảm TTL xuống 1 phút trước khi triển khai rồi tăng lại — giảm vấn đề nhưng không xoá bỏ nó: client cache DNS bất chấp TTL vẫn hỏng như cũ. Đây là phương án nhiễu chính.
  • B. Chuyển sang Elastic Beanstalk và hoán đổi CNAME — vẫn dựa vào DNS, nên vướng đúng vấn đề cũ; và còn đòi di trú cả nền tảng.
  • C. Dựng NGINX proxy trên mỗi instance để chuyển tiếp sang ALB đúng — thêm một tầng phải bảo trì, thêm độ trễ, và chỉ che giấu vấn đề.
Câu 62 Domain 6: Security and Compliance

The technology team at a leading bank is using software that has a license type that gets billed based on the number of CPU sockets that are being used. The team would like to ensure that they are using the most appropriate EC2 launch mode and create a compliance dashboard that highlights any violation of that decision. The company has hired you as an AWS Certified DevOps Engineer Professional to build a solution for this requirement.

Which of the following solutions would you recommend as the best fit?

  1. A

    Launch the EC2 instances on Reserved Instances and create a tag for the application. Deploy an AWS Config custom rule backed by a Lambda function that will check the application tag and ensure the instance is launched on the correct launch mode

  2. B

    Launch the EC2 instances on Reserved Instance and create a tag for the application. Deploy an AWS Service Catalog rule backed by a Lambda function to track that the application is always launched on an EC2 instance with the correct mode

  3. C

    Launch the EC2 instances on Dedicated Hosts and create a tag for the application. Deploy an AWS Config custom rule backed by a Lambda function that will check the application tag and ensure the instance is launched on the correct launch mode

  4. D

    Launch the EC2 instances on Dedicated Hosts and create a tag for the application. Deploy an AWS Service Catalog rule backed by a Lambda function to track that the application is always launched on an EC2 instance with the correct mode

Xem giải thích

Đáp án

C — Khởi chạy EC2 trên Dedicated Hosts, gắn thẻ cho ứng dụng, và triển khai một AWS Config custom rule dùng Lambda kiểm tra rằng instance mang thẻ đó luôn chạy trên Dedicated Host

Vì sao đúng

Có hai quyết định, và cả hai đều đúng.

Thứ nhất — Dedicated Host là mô hình duy nhất phù hợp với giấy phép tính theo socket. Chỉ Dedicated Host cho bạn nhìn thấy và kiểm soát máy chủ vật lý: bạn biết nó có bao nhiêu socket và bao nhiêu nhân, và kiểm soát được instance nào chạy ở đâu. Đó là điều kiện để tuân thủ và chứng minh được khi bị kiểm tra giấy phép.

Thứ hai — AWS Config là công cụ đúng cho bảng theo dõi tuân thủ. Config đánh giá liên tục, có sẵn bảng tổng hợp mức tuân thủ, và chỉ ra chính xác tài nguyên nào vi phạm — đúng cả hai yêu cầu của đề.

Vì sao các phương án khác sai

  • A. Dùng Reserved Instance kèm Config custom rule — sai ở mô hình khởi chạy: Reserved Instance là mô hình GIÁ, không phải mô hình cách ly phần cứng; nó vẫn chạy trên phần cứng dùng chung. Đây là phương án nhiễu chính.
  • B và D. Dùng AWS Service Catalog để theo dõi tuân thủ — Service Catalog quản lý danh mục sản phẩm được duyệt để người dùng tự triển khai; nó không đánh giá tuân thủ của tài nguyên đã tồn tại, và không có bảng theo dõi vi phạm.

Ghi nhớ

Dedicated Instance cũng chạy trên phần cứng không chia sẻ, nhưng không cho thấy cấu hình socket và nhân — nên không dùng được cho giấy phép tính theo socket. Đây là cặp rất dễ lẫn.

Câu 63 Domain 2: Configuration Management and IaC

A 3D modeling company would like to deploy applications on Elastic Beanstalk with support for various programming languages with predictable and standardized deployment strategies. Some of these languages are supported (such as Node.js, Java, Golang) but others such as Rust are not supported. The company has hired you as an AWS Certified DevOps Engineer Professional to build a solution for this requirement.

Which of the following options would you recommend as the MOST efficient solution for this use-case?

  1. A

    Package each application as a standalone AMI that contains the OS, the application runtime and the application itself. To update a Beanstalk environment, provide a new AMI

  2. B

    Create a custom platform for each language that is not supported. Package each application in S3 before deploying to Elastic Beanstalk

  3. C

    Run Opsworks on top of Elastic Beanstalk to bring the missing compatibility layer

  4. D

    Deploy to Elastic Beanstalk using a Multi-Docker container configuration. Package each application as a Docker container in ECR

Xem giải thích

Đáp án

D — Triển khai lên Elastic Beanstalk bằng cấu hình Multi-Docker container, đóng gói mỗi ứng dụng thành Docker image trong ECR

Vì sao đúng

Vấn đề: Beanstalk hỗ trợ sẵn nhiều ngôn ngữ nhưng không có Rust. Câu hỏi là làm sao hỗ trợ ngôn ngữ bất kỳ mà vẫn giữ được chiến lược triển khai chuẩn hoá và đoán trước được.

Docker giải đúng chỗ đó: nền tảng Docker của Beanstalk không quan tâm ngôn ngữ nào chạy bên trong — nó chỉ chạy container. Nghĩa là:

  • Một cách đóng gói duy nhất cho mọi ngôn ngữ, kể cả những ngôn ngữ Beanstalk chưa từng hỗ trợ.
  • Vẫn giữ nguyên mọi tính năng của Beanstalk: rolling update, immutable, blue/green, health monitoring.
  • Ứng dụng chạy giống hệt trên máy lập trình viên và trên sản xuất.

Vì sao các phương án khác sai

  • B. Tạo custom platform cho từng ngôn ngữ không được hỗ trợ — làm được (Beanstalk có tính năng custom platform dựng bằng Packer), nhưng bạn phải xây và bảo trì một nền tảng riêng cho mỗi ngôn ngữ: vá lỗi, cập nhật, kiểm thử. Tốn hơn Docker rất nhiều. Đây là phương án nhiễu chính.
  • A. Đóng gói mỗi ứng dụng thành một AMI riêng — dựng và cập nhật AMI cho từng ứng dụng còn tốn công hơn, và mất tính di động.
  • C. Chạy OpsWorks trên nền Elastic Beanstalk — không có mô hình như vậy; hai dịch vụ không xếp chồng lên nhau được.
Câu 64 Chọn nhiều đáp án Domain 4: Monitoring and Logging

A social media company has multiple EC2 instances that are behind an Auto Scaling group (ASG) and you would like to retrieve all the log files within the instances before they are terminated. You would like to also build a metadata index of all the log files so you can efficiently find them by instance id and date range.

As a DevOps Engineer, which of the following options would you recommend to address the given requirements? (Select three)

  1. A

    Create a Lambda function that is triggered by S3 events for PUT. Write to the DynamoDB table

  2. B

    Create a Lambda function that is triggered by CloudWatch Events for PUT. Write to the DynamoDB table

  3. C

    Create a termination hook for your ASG and create a CloudWatch Events rule to trigger an AWS Lambda function. The Lambda function should invoke an SSM Run Command to send the log files from the EC2 instance to CloudWatch Logs. Create a log subscription to send it to Firehose and then S3

  4. D

    Create a DynamoDB table with a primary key of instance-id and a sort key of datetime

  5. E

    Create a termination hook for your ASG and create a CloudWatch Events rule to trigger an AWS Lambda function. The Lambda function should invoke an SSM Run Command to send the log files from the EC2 instance to S3

  6. F

    Create a DynamoDB table with a primary key of datetime and a sort key of instance-id

Xem giải thích

Đáp án

A, D và E — dùng lifecycle hook khi kết thúc gọi Lambda chạy SSM Run Command đẩy log lên S3, tạo bảng DynamoDB với khoá chính instance-id và khoá sắp xếp datetime, và dùng Lambda kích hoạt bởi sự kiện S3 PUT để ghi vào bảng đó

Vì sao đúng

Ba phương án ghép thành một luồng hoàn chỉnh:

Instance sắp bị huỷ
   ▼  E: lifecycle hook giữ ở Terminating:Wait → Lambda → SSM Run Command → đẩy log lên S3
S3 nhận tệp
   ▼  A: sự kiện s3:ObjectCreated:Put kích hoạt Lambda
DynamoDB  ← D: ghi bản ghi chỉ mục

Thiết kế khoá của DynamoDB là chỗ quyết định. Đề nói cần tìm theo instance id và theo khoảng thời gian, và DynamoDB chỉ hỗ trợ truy vấn theo dải trên khoá sắp xếp:

Partition key: instance-id   →  chọn đúng một máy
Sort key:      datetime      →  lọc theo dải: BETWEEN ngày A AND ngày B

Đảo ngược thứ tự là hỏng: datetime làm partition key thì mỗi mốc thời gian là một phân vùng riêng, và không lọc theo dải được.

Vì sao các phương án khác sai

  • F. Bảng có khoá chính datetime và khoá sắp xếp instance-id — đảo ngược, như vừa nêu. Đây là phương án nhiễu chính, và nó chỉ khác đáp án đúng ở thứ tự hai cột.
  • C. Đẩy log sang CloudWatch thay vì S3 — đắt hơn cho lưu trữ lâu dài, và sự kiện PUT trong phương án A là sự kiện của S3, nên hai mảnh không khớp nhau.
  • B. Lambda kích hoạt bởi "CloudWatch Events cho PUT" — sự kiện tải tệp lên S3 đến từ S3 event notification hoặc EventBridge với nguồn aws.s3, không phải "CloudWatch Events for PUT".
Câu 65 Domain 6: Security and Compliance

A financial services company is using security-hardened AMI due to strong regulatory compliance requirements. The company must be able to check every day for AMI vulnerabilities based on the newly disclosed ones through the common vulnerabilities and exposures (CVEs) program. Currently, all the instances are launched through an Auto Scaling group (ASG) leveraging the latest security-hardened AMI.

As a DevOps Engineer, how can you implement this while minimizing cost and application disruption?

  1. A

    Create a CloudWatch Event with a daily schedule. Invoke a Lambda Function that will start an AWS Inspector Run directly from the AMI reference in the API call. AWS Inspector will automatically launch an instance and terminate it upon assessment completion

  2. B

    Create a CloudWatch Event with a daily schedule, the target being a Lambda Function. Tag all the instances in your ASG with CheckVulnerabilities: True. The Lambda function should start an assessment in AWS Inspector targeting all instances having the tag

  3. C

    Create a CloudWatch Event with a daily schedule, the target being a Step Function. The Step Function should launch an EC2 instance from the AMI and tag it with CheckVulnerabilities: True. The Step Function then starts an AMI assessment template using AWS Inspector and the above tag. Terminate the instance afterward

  4. D

    Create a CloudWatch Event with a daily schedule. Make the target of the rule being AWS Inspector and pass some extra data in the rule using the AMI ID to inspect. AWS Inspector will automatically launch an instance and terminate it upon assessment completion

Xem giải thích

Đáp án

C — CloudWatch Event chạy hằng ngày, target là một Step Functions workflow: khởi chạy một EC2 instance từ AMI, gắn thẻ CheckVulnerabilities: True, rồi chạy đánh giá Inspector

Vì sao đúng

Ràng buộc quyết định: AWS Inspector quét instance đang chạy, không quét AMI. Nó cần một agent chạy bên trong hệ điều hành để đọc danh sách gói đã cài.

Vì vậy quy trình bắt buộc phải có nhiều bước:

1. Khởi chạy MỘT instance tạm từ AMI cần kiểm tra
2. Gắn thẻ để Inspector biết nhắm vào đâu
3. Chạy assessment và CHỜ kết quả (mất khoảng 15 phút tới 1 giờ)
4. Đọc kết quả
5. Huỷ instance tạm

Chuỗi này cần chờ giữa các bước và xử lý lỗi — đúng thứ Step Functions làm tốt và một hàm Lambda đơn lẻ không làm được (giới hạn 15 phút).

Về hai tiêu chí của đề: chi phí tối thiểu vì instance chỉ sống trong lúc quét, và không gián đoạn ứng dụng vì quét trên máy tạm chứ không đụng tới instance đang phục vụ.

Vì sao các phương án khác sai

  • B. Gắn thẻ mọi instance trong ASG rồi chạy Inspector trên chúng — quét máy đang phục vụ lưu lượng; agent Inspector tiêu tốn tài nguyên và có thể ảnh hưởng hiệu năng. Vi phạm yêu cầu "không gián đoạn". Đây là phương án nhiễu chính.
  • A và D. Inspector tự khởi chạy và huỷ instance từ tham chiếu AMI trong lời gọi API — không có tính năng này; Inspector không tự cấp phát instance.
Câu 66 Domain 6: Security and Compliance

A data analytics company would like to create an automated solution to be alerted in case of EC2 instances being under-utilized for over 24 hours in order to save some costs. The solution should require a manual intervention of an operator validating the assessment before proceeding for instance termination.

As a DevOps Engineer, how would you implement a solution with the LEAST development effort?

  1. A

    Enable Trusted Advisor and ensure the check for low-utilized EC2 instances are on. Create a CloudWatch Event that tracks the events created by Trusted Advisor and use a Lambda Function as a target for that event. The Lambda function should trigger an SSM Automation document with a manual approval step. Upon approval, the SSM document proceeds with the instance termination

  2. B

    Create a CloudWatch Event rule that triggers every 5 minutes and use a Lambda function as a target. The Lambda function should issue API calls to AWS CloudWatch Metrics and store the information in DynamoDB. Use a DynamoDB Stream to detect a stream of the low-utilized event for a period of 24 hours and trigger a Lambda function. The Lambda function should trigger an SSM Automation document with a manual approval step. Upon approval, the SSM document proceeds with the instance termination

  3. C

    Create a CloudWatch Alarm tracking the minimal CPU utilization across all your EC2 instances. Connect the CloudWatch Alarm to an SNS topic and use the Lambda Function as a subscriber to the SNS topic. The Lambda function should trigger an SSM Automation document with a manual approval step. Upon approval, the SSM document proceeds with the instance termination

  4. D

    Enable Trusted Advisor and ensure the check for low-utilized EC2 instances are on. Connect Trusted Advisor to an SNS topic for that check and use a Lambda Function as a subscriber to the SNS topic. The Lambda function should trigger an SSM Automation document with a manual approval step. Upon approval, the SSM document proceeds with the instance termination

Xem giải thích

Đáp án

A — Bật Trusted Advisor và bảo đảm kiểm tra "low-utilized EC2 instances" đang hoạt động; tạo CloudWatch Event theo dõi sự kiện do Trusted Advisor phát ra, với target là một Lambda function

Vì sao đúng

Chữ khoá của đề là "ít công phát triển nhất", và Trusted Advisor đã có sẵn kiểm tra cần thiết: nó theo dõi mức sử dụng CPU và lưu lượng mạng trong 14 ngày và đánh dấu instance sử dụng thấp. Bạn không phải viết logic phân tích nào.

Phần còn lại chỉ là nối dây: Trusted Advisor phát sự kiện qua CloudWatch Events khi trạng thái một kiểm tra thay đổi, và Lambda nhận sự kiện đó rồi khởi động quy trình cần phê duyệt của người vận hành.

Vì sao các phương án khác sai

  • D. Nối Trusted Advisor trực tiếp với một SNS topic cho kiểm tra đó — Trusted Advisor không phát trực tiếp ra SNS; nó phát qua CloudWatch Events, và từ đó mới đi tiếp. Đây là phương án nhiễu chính, và nó chỉ khác đáp án đúng ở một mắt xích.
  • B. Lambda chạy mỗi 5 phút gọi API CloudWatch Metrics rồi lưu vào DynamoDB — tự xây lại toàn bộ logic mà Trusted Advisor đã có: thu thập, tính trung bình theo 24 giờ, so ngưỡng, lưu trạng thái. Nhiều công nhất trong bốn phương án.
  • C. Dùng CloudWatch Alarm theo dõi CPU tối thiểu trên tất cả instance — alarm hoạt động trên một chỉ số của một tài nguyên, không đánh giá được từng instance riêng lẻ trong cả đội máy.

Lưu ý về gói hỗ trợ

Kiểm tra tối ưu chi phí của Trusted Advisor chỉ có từ gói Business trở lên.

Câu 67 Domain 3: Resilient Cloud Solutions

As a DevOps Engineer at a social media company, you have deployed your application in an Auto Scaling group (ASG) using CloudFormation. You would like to update the Auto Scaling Group to have all the instances reference the newly created launch configuration, which upgrades the instance type. Your ASG currently contains 6 instances and you need at least 4 instances to be up at all times.

Which configuration should you use in the CloudFormation template?

  1. A

    AutoScalingLaunchTemplateUpdate

  2. B

    AutoScalingReplacingUpdate

  3. C

    AutoScalingRollingUpdate

  4. D

    AutoScalingLaunchConfigurationUpdate

Xem giải thích

Đáp án

C — AutoScalingRollingUpdate

Vì sao đúng

CloudFormation có ba UpdatePolicy cho Auto Scaling group, và câu này kiểm tra việc chọn đúng cái:

Policy Cách hoạt động
AutoScalingRollingUpdate Thay thế từng lô instance trong chính ASG hiện có
AutoScalingReplacingUpdate Tạo một ASG hoàn toàn mới, rồi xoá ASG cũ
AutoScalingScheduledAction Bảo vệ scheduled action khỏi bị ghi đè khi cập nhật

Ràng buộc trong đề — luôn phải có ít nhất 4 trong 6 instance hoạt động — được diễn đạt trực tiếp bằng thuộc tính của rolling update:

UpdatePolicy:
  AutoScalingRollingUpdate:
    MinInstancesInService: 4
    MaxBatchSize: 2
    PauseTime: PT5M
    WaitOnResourceSignals: true

MinInstancesInService: 4 bảo đảm CloudFormation không bao giờ gỡ quá 2 máy cùng lúc.

Vì sao các phương án khác sai

  • B. AutoScalingReplacingUpdate — tạo ASG mới song song rồi chuyển sang. An toàn hơn về mặt quay lui, nhưng tạo tài nguyên mới và không có tham số MinInstancesInService để bảo đảm ràng buộc của đề. Đây là phương án nhiễu chính.
  • A. AutoScalingLaunchTemplateUpdate và D. AutoScalingLaunchConfigurationUpdate — không tồn tại; đây là hai tên bịa nghe rất hợp lý.
Câu 68 Domain 4: Monitoring and Logging

A financial services company has a solution in place to track all the API calls made by users, applications, and SDK within the AWS account. Recently, it has experienced a hack and could find a user amongst the logs that did some compromising API calls. The company wants to know with 100% certainty that the log files represent the correct sequence of events and have not been altered. The company has hired you as an AWS Certified DevOps Engineer Professional to build a solution for this requirement.

Which of the following would you suggest as the most effective solution?

  1. A

    Turn on API calls logging using AWS CloudTrail. Deliver the logs in an S3 bucket, and use the log verification integrity API call to verify the log file

  2. B

    Turn on AWS account configuration tracking using AWS Config. Deliver the configuration logs into S3 and use the log verification integrity API to verify the log files

  3. C

    Turn on API calls logging using AWS CloudTrail. Deliver the logs in an S3 bucket and choose a lifecycle policy that archives file right away in Glacier. Implement a Glacier Vault Lock policy

  4. D

    Turn on AWS account configuration tracking using AWS Config. Deliver the logs in an S3 bucket and choose a lifecycle policy that archives the files right away in Glacier. Implement a Glacier Vault Lock policy

Xem giải thích

Đáp án

A — Bật ghi nhật ký lời gọi API bằng CloudTrail, giao log vào bucket S3, và dùng log file integrity validation để xác minh tệp log

Vì sao đúng

Đề đòi chắc chắn 100% rằng tệp log đúng trình tự và chưa bị sửa đổi — và CloudTrail có tính năng dựng riêng cho điều đó.

Log file integrity validation hoạt động bằng mật mã học:

Mỗi giờ, CloudTrail tạo một tệp DIGEST chứa:
  • Mã băm SHA-256 của từng tệp log trong giờ đó
  • Tham chiếu tới tệp digest của GIỜ TRƯỚC   ← tạo thành chuỗi liên kết
  • Chữ ký số bằng khoá riêng của AWS

Hai tính chất quan trọng:

  • Phát hiện sửa đổi — đổi một byte trong log là mã băm không khớp.
  • Phát hiện xoá — vì các digest liên kết thành chuỗi, xoá một tệp làm đứt chuỗi và lộ ra ngay. Đây chính là phần "đúng trình tự sự kiện" mà đề yêu cầu.

Xác minh bằng lệnh aws cloudtrail validate-logs.

Vì sao các phương án khác sai

  • C. CloudTrail kèm lifecycle chuyển vào Glacier và Vault Lock — Vault Lock ngăn việc xoá về sau, nhưng nó không chứng minh được rằng tệp chưa bị sửa trước khi vào Glacier. Đây là phương án nhiễu chính.
  • B và D. Dùng AWS Config để theo dõi — Config ghi thay đổi cấu hình tài nguyên, nó không ghi lời gọi API của người dùng; đề nói rõ là "API calls". Và Config không có tính năng xác minh toàn vẹn log như CloudTrail.
Câu 69 Domain 3: Resilient Cloud Solutions

A multi-national retail company is planning for disaster recovery and needs the data to be stored in Amazon S3 in two different regions that are in different continents. The data is written at a high rate of 10000 objects per second. For regulatory reasons, the data also needs to be encrypted in transit and at rest. The company has hired you as an AWS Certified DevOps Engineer Professional to build a solution for this requirement.

Which of the following solutions would you recommend?

  1. A

    Create a bucket policy to create a condition for Denying any request that is "aws:SecureTransport": "true". Encrypt the objects at rest using SSE-KMS. Setup Cross-Region Replication

  2. B

    Create a bucket policy to create a condition for Denying any request that is "aws:SecureTransport": "true". Encrypt the objects at rest using SSE-S3. Setup Cross-Region Replication

  3. C

    Create a bucket policy to create a condition for Denying any request that is "aws:SecureTransport": "false". Encrypt the objects at rest using SSE-KMS. Setup Cross-Region Replication

  4. D

    Create a bucket policy to create a condition for Denying any request that is "aws:SecureTransport": "false". Encrypt the objects at rest using SSE-S3. Setup Cross-Region Replication

Xem giải thích

Đáp án

D — Bucket policy từ chối yêu cầu có "aws:SecureTransport": "false", mã hoá khi lưu bằng SSE-S3, và bật Cross-Region Replication

Vì sao đúng

Có hai quyết định, và cả hai đều phải đúng.

Thứ nhất — chiều của điều kiện aws:SecureTransport. Khoá này trả về true khi yêu cầu dùng HTTPS. Muốn bắt buộc HTTPS, bạn phải từ chối khi nó bằng false:

{ "Effect": "Deny", "Condition": { "Bool": { "aws:SecureTransport": "false" } } }

Viết ngược (Deny khi true) sẽ chặn đúng những yêu cầu an toàn và cho qua yêu cầu HTTP — thảm hoạ về bảo mật.

Thứ hai — SSE-S3 thay vì SSE-KMS, vì tốc độ ghi. Đề nói 10.000 đối tượng mỗi giây. Mỗi thao tác SSE-KMS sinh ra một lời gọi tới KMS, mà KMS có hạn mức số yêu cầu mỗi giây — ở tốc độ này bạn sẽ bị throttle và chi phí KMS cũng rất lớn. SSE-S3 không có hạn mức đó và miễn phí.

Cross-Region Replication lo phần nhân bản sang châu lục khác, và nó mã hoá dữ liệu khi truyền theo mặc định.

Vì sao các phương án khác sai

  • *C. Đúng chiều điều kiện nhưng dùng SSE-KMS — vướng hạn mức KMS ở tốc độ 10.000 đối tượng mỗi giây. Đây là phương án nhiễu chính, và chi tiết phân biệt nằm ở con số tốc độ ghi.
  • A và *B. Từ chối khi aws:SecureTransport bằng true — đảo ngược logic, chặn nhầm HTTPS.
Câu 70 Domain 1: SDLC Automation

Your company has adopted CodeCommit and forces developers to create new branches and create pull requests before merging the code to master. The development team lead reviewing the pull request needs high confidence in the quality of the code and therefore would like the CICD system to automatically build a Pull Request to provide a testing badge with a pass/fail status.

How can you implement the validation of Pull Requests by CodeBuild efficiently?

  1. A

    Create a CloudWatch Event Rule with a scheduled rate of 5 minutes that invokes a Lambda function. This function checks for the creation and updates done to Pull Requests in the source repository, and invokes CodeBuild when needed. The function waits for CodeBuild to be done and then updates the Pull Request with a message with the build outcome

  2. B

    Create a CloudWatch Event Rule with a scheduled rate of 5 minutes that invokes a Lambda function. This function checks for the creation and updates done to Pull Requests in the source repository, and invokes CodeBuild when needed. Create a CloudWatch Event rule to watch for CodeBuild build success or failure event and as a target invoke a Lambda function that will update the pull request with the Build outcome

  3. C

    Create a CloudWatch Event Rule that reacts to the creation and updates done to Pull Requests in the source repository. The target of that rule should be AWS Lambda. This function invokes CodeBuild and waits for CodeBuild to be done and then updates the Pull Request with a message with the build outcome

  4. D

    Create a CloudWatch Event Rule that reacts to the creation and updates done to Pull Requests in the source repository. The target of that rule should be CodeBuild. Create a second CloudWatch Event rule to watch for CodeBuild build success or failure event and as a target invoke a Lambda function that will update the pull request with the Build outcome

Xem giải thích

Đáp án

D — CloudWatch Event rule phản ứng với việc tạo và cập nhật pull request, target là CodeBuild; và một rule thứ hai theo dõi trạng thái build của CodeBuild để cập nhật lại pull request

Vì sao đúng

Chữ khoá là "hiệu quả", và điểm mấu chốt là: CodeBuild là target hợp lệ của EventBridge — bạn khởi động build trực tiếp, không cần Lambda ở giữa.

Kiến trúc hai chiều:

Tạo/cập nhật pull request
   ▼  Rule 1: target trực tiếp là CodeBuild
CodeBuild chạy bộ kiểm thử
   ▼  phát sự kiện trạng thái build
   ▼  Rule 2: target là Lambda
Gọi PostCommentForPullRequest để gắn nhãn pass/fail lên pull request

Vì sao cần hai rule thay vì một: CodeBuild chạy bất đồng bộ và có thể mất nhiều phút. Nếu dùng một Lambda chờ kết quả, bạn phải giữ nó chạy suốt thời gian đó — tốn tiền và vướng giới hạn 15 phút. Mô hình hướng sự kiện thì không có ai phải chờ.

Vì sao các phương án khác sai

  • *C. Target của rule là Lambda, và Lambda gọi CodeBuild rồi chờ — chính là mô hình chờ vừa nêu; thêm một mắt xích và tốn tiền cho thời gian ngồi không. Đây là phương án nhiễu chính.
  • A và B. Dùng rule chạy theo lịch mỗi 5 phút để kiểm tra pull request mới — mô hình hỏi vòng: có độ trễ tới 5 phút, và phần lớn lần chạy là vô ích. Kém hiệu quả hơn hẳn mô hình hướng sự kiện.