Ngân hàng đề — AWS Certified DevOps Engineer Professional
Tìm thấy 681 câu.
Which solution will meet these requirements with the LEAST operational overhead?
- A Create an AWS CodeBuild project. Set the public repository as the source. Use a webhook to rebuild when the company pushes a code change. Configure the artifacts section of the project to use the S3 bucket as the destination. Set up an appropriate path to store build outputs in the bucket. Disable artifact encryption.
- B Create an AWS CodeBuild project. Set the public repository as the source. Configure the artifacts section of the project to use the S3 bucket as the destination. Ensure that artifact encryption is enabled in the artifacts configuration. Configure an Amazon EventBridge rule to initiate the CodeBuild project on a daily schedule.
- C Add a new stage to the end of the pipeline. Configure the stage to include an action to publish artifacts to the S3 bucket. Update the pipeline to run in response to pull requests to the public repository.
- D Add a new stage to the end of the pipeline. Configure the stage to include an action to publish artifacts to the S3 bucket. Create an Amazon EventBridge rule to initiate the pipeline on a daily schedule.
Xem giải thích
🧩 Phân tích nội dung câu hỏi
Câu hỏi mô tả một công ty đang sản xuất build artifacts hàng ngày cho dự án open source được lưu trữ trên public code repository (kho mã công khai mà công ty hỗ trợ). Hiện tại, họ thủ công kích hoạt (manually invoke) một pipeline trong AWS CodePipeline để build artifacts. Yêu cầu là làm cho các build artifacts trở nên công khai (publicly available) trên website được host trên Amazon S3 bucket. Giải pháp phải đáp ứng với operational overhead thấp nhất (LEAST operational overhead), nghĩa là tận dụng tối đa hạ tầng hiện có, tránh tạo mới các thành phần phức tạp, và tự động hóa quy trình hàng ngày (every day).
Mục tiêu chính:
- Tự động build và publish artifacts daily (không phải on-push hay pull request).
- Artifacts public trên S3 (cần stage/action để upload và set public).
- Ưu tiên least overhead: Không tạo mới project/pipeline, chỉ chỉnh sửa existing pipeline và thêm trigger đơn giản.
📘 Tài liệu tham khảo:
- AWS CodePipeline User Guide (2024-2026): docs.aws.amazon.com/codepipeline/latest/userguide.
- Amazon EventBridge (Scheduler): docs.aws.amazon.com/eventbridge/latest/userguide/eb-create-rule-schedule.html.
- AWS CodeBuild Artifacts & S3: docs.aws.amazon.com/codebuild/latest/userguide.
✅ Đáp án đúng và lý do lựa chọn
Đáp án đúng:
Add a new stage to the end of the pipeline. Configure the stage to include an action to publish artifacts to the S3 bucket. Create an Amazon EventBridge rule to initiate the pipeline on a daily schedule.
Lý do 🛠️:
- Tận dụng pipeline hiện có (đã tồn tại trong CodePipeline), chỉ cần thêm stage cuối với S3 deploy action (S3Deploy provider) để publish artifacts trực tiếp vào S3 bucket và set public (qua bucket policy hoặc object ACL). Điều này least overhead vì không tạo mới project hay thay đổi source.
- EventBridge rule daily schedule trigger pipeline tự động hàng ngày (cron expression như
rate(1 day)), khớp yêu cầu "every day" mà không phụ thuộc vào code changes. - Theo best practices AWS 2026, CodePipeline hỗ trợ cross-account/region S3 actions và EventBridge integration native, giảm quản lý thủ công.
❌ Giải thích tất cả các phương án
-
Create an AWS CodeBuild project. Set the public repository as the source. Use a webhook to rebuild when the company pushes a code change. Configure the artifacts section of the project to use the S3 bucket as the destination. Set up an appropriate path to store build outputs in the bucket. Disable artifact encryption.
❌ Sai vì: Tạo mới CodeBuild project thay vì dùng pipeline existing → overhead cao (cần config source, buildspec, IAM roles mới). Webhook on push chỉ trigger khi "company pushes code change", không khớp yêu cầu daily builds (có thể không push hàng ngày). Disable encryption vi phạm security best practices AWS (S3 default encryption bắt buộc từ 2023), và không cần thiết cho public artifacts. -
Create an AWS CodeBuild project. Set the public repository as the source. Configure the artifacts section of the project to use the S3 bucket as the destination. Ensure that artifact encryption is enabled in the artifacts configuration. Configure an Amazon EventBridge rule to initiate the CodeBuild project on a daily schedule.
❌ Sai vì: Vẫn tạo mới CodeBuild project độc lập → overhead lớn (duplicate effort so với existing pipeline, cần migrate build logic). Tuy EventBridge daily đúng trigger, nhưng bỏ qua pipeline hiện có làm tăng quản lý (riêng biệt CodeBuild vs. CodePipeline). AWS khuyến nghị dùng CodePipeline cho multi-stage workflows để least overhead. -
Add a new stage to the end of the pipeline. Configure the stage to include an action to publish artifacts to the S3 bucket. Update the pipeline to run in response to pull requests to the public repository.
❌ Sai vì: Thêm stage publish S3 đúng (tận dụng pipeline), nhưng trigger on pull requests không đảm bảo daily (pull requests phụ thuộc contributor, repo open source có thể không có PR hàng ngày). Yêu cầu là every day builds, không liên quan PR → không tự động hóa đúng.
Giải pháp đúng là tối ưu nhất với 0 thay đổi lớn, chỉ 2 bước đơn giản! 🚀