Ngân hàng đề — AWS Certified DevOps Engineer Professional

Tìm thấy 681 câu.

Câu 71 Domain 4: Monitoring and Logging

You are working as a DevOps Engineer at an e-commerce company and have a deployed a Node.js application on Elastic Beanstalk. You would like to track error rates and specifically, you need to ensure by looking at the application log, that you do not have more than 100 errors in a 5 minutes interval. In case you are getting too many errors, you would like to be alerted via email.

Which of the following options represents the most efficient solution in your opinion?

  1. A

    Implement custom logic in your Node.js application to track the number of errors it has received in the last 5 minutes. In case the number exceeds the threshold, use the SetAlarmState API to trigger a CloudWatch alarm. Make the CloudWatch Alarm use SNS as a target. Create an email subscription on SNS

  2. B

    Use the Elastic Beanstalk Health Metrics to monitor the application health and track the error rates. Create a CloudWatch alarm on top of the metric and use SNS as a target. Create an email subscription on SNS

  3. C

    Create a CloudWatch Logs Metric Filter and assign a CloudWatch Metric. Create a CloudWatch Alarm linked to the metric and use SNS as a target. Create an email subscription on SNS

  4. D

    Create a CloudWatch Logs Metric Filter with a target being a CloudWatch Alarm. Make the CloudWatch Alarm use SNS as a target. Create an email subscription on SNS

Xem giải thích

Đáp án

C — Tạo CloudWatch Logs Metric Filter gắn với một CloudWatch Metric, tạo CloudWatch Alarm trên metric đó, và dùng SNS làm target với một email subscription

Vì sao đúng

Đề cần đếm số lỗi trong log ứng dụng và cảnh báo khi vượt 100 lỗi trong 5 phút. Chuỗi công cụ đúng gồm bốn mắt xích, và thứ tự rất quan trọng:

Log ứng dụng trong CloudWatch Logs
   ▼  Metric Filter: khớp mẫu "ERROR", đếm số lần khớp
CloudWatch Metric (chỉ số tuỳ chỉnh)
   ▼  Alarm: > 100 trong khoảng 5 phút
CloudWatch Alarm
   ▼
SNS  →  email

Metric filter là mắt xích then chốt: nó biến văn bản log thành chỉ số dạng số mà alarm đánh giá được. Không có nó thì không có gì để đặt ngưỡng lên.

Toàn bộ giải pháp không cần sửa mã ứng dụng, và Elastic Beanstalk đã cấu hình sẵn việc đẩy log lên CloudWatch Logs.

Vì sao các phương án khác sai

  • *D. Metric Filter với target trực tiếp là CloudWatch Alarm — không làm được: metric filter chỉ tạo ra metric; alarm là một tài nguyên riêng đặt trên metric đó. Đây là phương án nhiễu chính, và nó thiếu đúng một mắt xích.
  • A. Tự viết logic đếm lỗi trong ứng dụng rồi gọi SetAlarmState — đòi sửa mã, và SetAlarmState chỉ dùng để kiểm thử alarm chứ không phải cơ chế vận hành.
  • B. Dùng Elastic Beanstalk Health Metrics — cho biết tình trạng chung của môi trường; nó không đếm được lỗi trong log ứng dụng theo mẫu bạn định nghĩa.
Câu 72 Domain 1: SDLC Automation

The DevOps team at your company is using CodeDeploy to deploy new versions of a Lambda function after it has passed a CodeBuild check via your CodePipeline. Before deploying, the CodePipeline has a step in which it optionally kickstarts a restructuring of files on an S3 bucket that is forward compatible. That restructuring is done using a Step Function execution which invokes a Fargate task. The new Lambda function cannot work until the restructuring task has fully completed.

As a DevOps Engineer, how can you ensure traffic isn't served to your new Lambda function until the task is completed?

  1. A

    In your appspec.yml file, include a BeforeAllowTraffic hook that checks on the completion of the Step Function execution

  2. B

    In your appspec.yml file, include an AfterAllowTraffic hook that checks on the completion of the Step Function execution

  3. C

    Enable Canary Deployment in CodeDeploy so that only a fraction of the service is served by the new Lambda function while the restructuring is happening

  4. D

    Include an extra step in the Step Function to signal to CodeDeploy the completion of the restructuring and serve new traffic to the new Lambda function

Xem giải thích

Đáp án

A — Trong appspec.yml, thêm hook BeforeAllowTraffic kiểm tra xem quá trình thực thi Step Functions đã hoàn tất chưa

Vì sao đúng

CodeDeploy cho Lambda có hai hook, và tên của chúng nói đúng thời điểm:

Triển khai phiên bản Lambda mới
   ▼
BeforeAllowTraffic   ←  chạy TRƯỚC khi bất kỳ lưu lượng nào tới hàm mới
   ▼
Chuyển lưu lượng sang hàm mới
   ▼
AfterAllowTraffic    ←  chạy SAU khi lưu lượng đã chuyển

Đề nói rõ: hàm mới không hoạt động được cho tới khi việc tái cấu trúc tệp hoàn tất. Nghĩa là kiểm tra phải diễn ra trước khi có bất kỳ người dùng nào chạm tới hàm — tức là BeforeAllowTraffic.

Hook này là một hàm Lambda riêng; nó kiểm tra trạng thái của Step Functions execution rồi báo kết quả về CodeDeploy. Nếu chưa xong hoặc lỗi, CodeDeploy dừng triển khai và không chuyển lưu lượng nào.

Vì sao các phương án khác sai

  • B. Dùng hook AfterAllowTraffic — quá muộn: lưu lượng đã được chuyển sang hàm mới, và người dùng đã gặp lỗi rồi. Đây là phương án nhiễu chính, và nó chỉ khác đáp án đúng ở một từ.
  • C. Bật canary deployment để chỉ một phần lưu lượng vào hàm mới trong lúc tái cấu trúc — vẫn có một phần người dùng thật gặp lỗi; đề nói hàm không hoạt động được, không phải "hoạt động kém".
  • D. Thêm một bước trong Step Functions để báo cho CodeDeploy — đảo ngược quan hệ điều khiển: CodeDeploy là bên điều phối triển khai, nó phải là bên hỏi, không phải bên chờ được gọi.
Câu 73 Domain 1: SDLC Automation

A retail company is implementing a CodePipeline pipeline in which every push to the CodeCommit master branch gets deployed to development, staging, and production environment consisting of EC2 instances. When deploying to production, traffic should be deployed on a few instances so that metrics can be gathered before a manual approval step is done to deploy to all the instances.

The company has hired you as an AWS Certified DevOps Engineer Professional to build a solution to address this use-case. How would you implement this?

  1. A

    In CodeDeploy, create three deployment groups - one for development, one for staging, and one for the entire production instances. Create one CodePipeline and chain up these together. For the deployment to production, enable the Canary deployment setting for CodeDeploy, and introduce a manual step after the canary deployment that will pause the rest of the deployment. Upon approval, the rest of the instances in production will have a deployment made to them

  2. B

    In CodeDeploy, create four deployment groups - one for development, one for staging, one for the canary testing instances in production and one for the entire production instances. Create separate CodePipeline for each deployment group all having the same source being your code repository. Introducing a manual approval step in the pipeline that deploys to production

  3. C

    In CodeDeploy, create four deployment groups - one for development, one for staging, one for the canary testing instances in production and one for the entire production instances. Create one CodePipeline and chain up these stages together, introducing a manual approval step after the deployment to the canary instances

  4. D

    In CodeDeploy, create three deployment groups - one for development, one for staging, and one for the entire production instances. Create three separate CodePipeline for each deployment group having all the same sources being your code repository. For the deployment to production, enable the Canary deployment setting for CodeDeploy, and introduce a manual step after the canary deployment that will pause the rest of the deployment. Upon approval, the rest of the instances in production will have a deployment made to them

Xem giải thích

Đáp án

*C — Tạo bốn deployment group trong CodeDeploy (development, staging, nhóm canary trong production, và toàn bộ production), rồi nối chúng trong một CodePipeline duy nhất

Vì sao đúng

Đề mô tả một luồng có bốn bước triển khai và một bước phê duyệt thủ công ở giữa:

CodeCommit master
   ▼
Deploy → development
   ▼
Deploy → staging
   ▼
Deploy → canary (vài instance trong production)
   ▼
[ Phê duyệt thủ công sau khi xem chỉ số ]
   ▼
Deploy → toàn bộ production

Bốn deployment group là cần thiết vì nhóm canary và nhóm production đầy đủ là hai tập instance khác nhau; CodeDeploy nhắm mục tiêu theo deployment group, nên phải tách chúng ra.

Một pipeline duy nhất là cần thiết vì đây là một luồng liên tục với bước phê duyệt ở giữa — chia thành nhiều pipeline thì mất tính liên tục và không truy vết được một bản mã đã đi tới đâu.

Vì sao các phương án khác sai

  • A. Chỉ ba deployment group, dùng cấu hình triển khai theo tỷ lệ cho production — thiếu nhóm canary riêng, nên không giữ được lưu lượng ở một tập nhỏ trong lúc chờ người phê duyệt; triển khai theo tỷ lệ sẽ tự chạy tiếp. Đây là phương án nhiễu chính.
  • B và D. Tạo pipeline riêng cho từng deployment group — mất tính liên tục, và bước phê duyệt không nối được hai pipeline lại với nhau.
Câu 74 Domain 5: Incident and Event Response

As a DevOps Engineer at an e-commerce company, you have deployed a web application in an Auto Scaling group (ASG) that is being distributed by an Application Load Balancer (ALB). The web application is using RDS Multi-AZ as a back-end and has been experiencing some issues to connect to the database. The health check implemented in the application currently returns an un-healthy status if the application cannot connect to the database. The ALB / ASG health check integration has been enabled, and therefore the ASG keeps on terminating instances right after they're done booting up.

You need to be able to isolate one instance for troubleshooting for an undetermined amount of time, how should you proceed?

  1. A

    Create an autoscaling hook for instance termination. Troubleshoot the instance while it is in the Terminating:Wait state

  2. B

    Set an instance in Standby right after it has launched

  3. C

    Enable termination protection for EC2

  4. D

    Suspend the Launch process

Xem giải thích

Đáp án

B — Đặt instance vào trạng thái Standby ngay sau khi nó vừa khởi chạy

Vì sao đúng

Vấn đề trong đề: instance vừa boot xong là fail health check (vì không kết nối được cơ sở dữ liệu), nên ASG huỷ nó ngay — bạn không kịp đăng nhập để chẩn đoán.

Trạng thái Standby giải đúng chỗ đó:

Instance ở trạng thái Standby Kết quả
Vẫn thuộc ASG Không bị coi là mất máy
ASG ngừng kiểm tra sức khoẻ nó Không bị huỷ
Bị gỡ khỏi target group của ALB Không nhận lưu lượng thật
Vẫn chạy, vẫn SSH vào được Chẩn đoán thoải mái

Xong việc thì đưa nó trở lại trạng thái InService, hoặc huỷ đi.

Vì sao các phương án khác sai

  • A. Dùng lifecycle hook cho hành động kết thúc rồi chẩn đoán ở trạng thái Terminating:Wait — làm được nhưng có hai nhược điểm: thời gian chờ giới hạn tối đa 2 giờ, và instance đã ở trên đường bị huỷ nên chắc chắn mất sau đó. Đây là phương án nhiễu chính.
  • C. Bật termination protection cho EC2 — thuộc tính này chỉ chặn lệnh TerminateInstances do người dùng gọi; nó không ngăn được Auto Scaling huỷ instance.
  • D. Tạm dừng tiến trình Launch — chặn việc tạo máy mới, không chặn việc huỷ máy hiện có. (Muốn chặn huỷ thì phải tạm dừng Terminate và HealthCheck — nhưng khi đó cả ASG mất khả năng tự phục hồi.)
Câu 75 Domain 5: Incident and Event Response

As the Lead DevOps Engineer at an e-commerce company, you would like to upgrade the major version of your MySQL database, which is managed by CloudFormation with AWS::RDS::DBInstance and setup using Multi-AZ.

You have a requirement to minimize the downtime as much as possible, what steps should you take to achieve this?

  1. A

    Upgrade the RDS database by updating the DBEngineVersion to the next major version, then run an UpdateStack Operation

  2. B

    Create an RDS Read Replica in a CloudFormation template by specifying SourceDBInstanceIdentifier and wait for it to be created. Afterward, upgrade the RDS Read Replica DBEngineVersion to the next major version. Then promote the Read Replica and use it as your new master database

  3. C

    Upgrade the RDS database by updating the EngineVersion to the next major version, then run an UpdateStack Operation

  4. D

    Create an RDS Read Replica in a CloudFormation template by specifying SourceDBInstanceIdentifier and wait for it to be created. Afterward, upgrade the RDS Read Replica EngineVersion to the next major version. Then promote the Read Replica and use it as your new master database

Xem giải thích

Đáp án

D — Tạo RDS Read Replica trong template bằng cách khai SourceDBInstanceIdentifier, nâng cấp EngineVersion của replica lên phiên bản chính mới, rồi promote nó thành instance độc lập

Vì sao đúng

Có hai quyết định, và cả hai đều phải đúng.

Thứ nhất — tên thuộc tính là EngineVersion. Trong AWS::RDS::DBInstance, thuộc tính khai phiên bản engine là EngineVersion, không phải "DBEngineVersion". Sai tên thì template không hợp lệ.

Thứ hai — dùng read replica để giảm thời gian ngừng. Nâng cấp phiên bản chính (major version) tại chỗ gây ngừng dịch vụ hàng chục phút, và Multi-AZ không cứu được — vì bản chờ được nâng cấp cùng lúc chứ không luân phiên.

Quy trình qua replica giữ cơ sở dữ liệu chính phục vụ suốt quá trình:

1. Tạo read replica từ instance chính           (chính vẫn chạy)
2. Nâng cấp phiên bản trên REPLICA              (chính vẫn chạy)
3. Chờ replica bắt kịp                          (chính vẫn chạy)
4. Promote replica thành instance độc lập       ← chỉ đây mới cần chuyển đổi
5. Trỏ ứng dụng sang instance mới

Thời gian ngừng thu về đúng bước 5.

Vì sao các phương án khác sai

  • *B. Cùng quy trình nhưng dùng tên thuộc tính DBEngineVersion — sai tên thuộc tính. Đây là phương án nhiễu chính, và nó chỉ khác đáp án đúng ở hai chữ cái.
  • C. Nâng cấp thẳng bằng cách sửa EngineVersion rồi chạy UpdateStack — tên thuộc tính đúng nhưng đây là nâng cấp tại chỗ, gây ngừng dịch vụ lâu.
  • A. Nâng cấp tại chỗ với tên thuộc tính sai — sai cả hai.
Câu 76 Domain 6: Security and Compliance

An e-commerce company would like to automate the patching of their hybrid fleet and distribute some patches through their internal patch repositories every week. As a DevOps Engineer at the company, you have been tasked to implement this most efficiently.

Which of the following options represents the BEST solution to meet this requirement?

  1. A

    Using SSM Parameter Store, configure the custom repositories in the OS' internal configuration files. Use the Default Patch Baseline. Define a Maintenance window and include the Run Command RunPatchBaseline. Schedule the maintenance window with a weekly recurrence

  2. B

    Manage your instances with AWS OpsWorks. Define a maintenance window and define custom chef cookbooks for the 'configure' lifecycle hook that will patch the instances from the internal patch repositories. Schedule the window with a weekly recurrence

  3. C

    Using SSM, do a RunCommand to install the custom repositories in the OS' internal configuration files. Use the Default Patch Baseline. Define a Maintenance window and include the Run Command RunPatchBaseline. Schedule the maintenance window with a weekly recurrence

  4. D

    Using SSM, implement a Custom Patch Baseline. Define a Maintenance window and include the Run Command RunPatchBaseline. Schedule the maintenance window with a weekly recurrence

Xem giải thích

Đáp án

D — Dùng SSM tạo một Custom Patch Baseline, định nghĩa Maintenance Window có chạy Run Command AWS-RunPatchBaseline, và đặt lịch lặp lại hằng tuần

Vì sao đúng

Chi tiết quyết định trong đề: cần phân phối bản vá từ kho nội bộ của công ty.

Custom Patch Baseline là cơ chế duy nhất hỗ trợ điều đó — nó có tuỳ chọn alternate patch source repositories: bạn khai kho nội bộ ngay trong baseline, theo từng hệ điều hành.

Ba mảnh của giải pháp đều là tính năng có sẵn của Systems Manager:

  • Custom Patch Baseline — quy định bản vá nào được duyệt, từ kho nào.
  • Maintenance Window — khung thời gian được phép vá, đặt lịch lặp hằng tuần.
  • AWS-RunPatchBaseline — document dựng sẵn thực hiện việc quét và cài đặt.

Nó cũng phủ được đội máy lai: máy chủ tại chỗ đăng ký qua hybrid activation được quản lý y hệt EC2.

Vì sao các phương án khác sai

  • *C. Dùng Run Command để cài kho nội bộ vào tệp cấu hình của hệ điều hành, rồi dùng Default Patch Baseline — hoạt động được nhưng mong manh: bạn sửa tệp cấu hình bên ngoài cơ chế của SSM, nên không có gì bảo đảm nó còn nguyên, và Default Patch Baseline vẫn trỏ tới kho công cộng. Đây là phương án nhiễu chính.
  • A. Dùng SSM Parameter Store để cấu hình kho trong tệp cấu hình hệ điều hành — Parameter Store lưu giá trị, nó không tự sửa tệp trên máy nào.
  • B. Quản lý bằng OpsWorks với cookbook Chef — làm được nhưng đòi vận hành cả một hệ thống quản lý cấu hình cho việc mà SSM đã có sẵn.
Câu 77 Domain 1: SDLC Automation

An online coding platform wants to fully customize the build tasks and automatically run builds concurrently to take the pain out of managing the build environments. The DevOps team at the company wants to use CodeBuild for all build-tasks and would like the artifacts created by CodeBuild to be named based on the branch being tested. The team wants this solution to be scalable to newer branches with a minimal amount of rework.

As a DevOps Engineer, how would you go about implementing the simplest possible solution to address the given use-case?

  1. A

    Create a buildspec.yml file that will look for the environment variable BRANCH_NAME at runtime. For each existing branch and new branch, create a separate CodeBuild and set the BRANCH_NAME variable accordingly. Use the variable in the artifacts section of your buildspec.yml file

  2. B

    Create a unique buildspec.yml file that will be the same for each branch and will name the artifacts the same way. When the artifact is uploaded into S3, create an S3 Event that will trigger a Lambda function that will issue an API call against CodeBuild, extract the branch name from it and rename the file on S3

  3. C

    Create a buildspec.yml file that will be different for every single branch. Create a new CodeBuild for each branch. Upon adding a new branch, ensure to edit the buildspec.yml file

  4. D

    Create a buildspec.yml file that will look for the environment variable CODEBUILD_SOURCE_VERSION at runtime. Use the variable in the artifacts section of your buildspec.yml file

Xem giải thích

Đáp án

D — Viết một tệp buildspec.yml dùng biến môi trường CODEBUILD_SOURCE_VERSION tại thời điểm chạy, và dùng biến đó trong phần artifacts

Vì sao đúng

Chữ khoá của đề là "đơn giản nhất" và "mở rộng sang nhánh mới với ít công sửa nhất".

CodeBuild cung cấp sẵn nhiều biến môi trường tự động, trong đó có CODEBUILD_SOURCE_VERSION — nó chứa thông tin về nhánh hoặc commit đang được dựng. Bạn dùng nó thẳng trong buildspec:

artifacts:
  name: my-app-$CODEBUILD_SOURCE_VERSION.zip

Kết quả: một tệp buildspec duy nhất, một CodeBuild project duy nhất, và nhánh mới thêm vào không phải sửa gì cả — biến tự mang giá trị đúng.

Vì sao các phương án khác sai

  • *A. Dùng biến BRANCH_NAME và tạo một CodeBuild project cho mỗi nhánh — hoạt động được nhưng mỗi nhánh mới lại phải tạo project mới và đặt biến bằng tay; ngược hẳn tiêu chí "mở rộng với ít công". Đây là phương án nhiễu chính.
  • C. Mỗi nhánh một tệp buildspec riêng — tệ hơn nữa: nhân bản cấu hình ra khắp các nhánh, và sửa một thứ phải sửa ở mọi nơi.
  • B. Đặt tên artefact giống nhau rồi dùng S3 event gọi Lambda để đổi tên — thêm một dịch vụ và một hàm phải bảo trì, cho việc mà một biến có sẵn đã giải quyết.
Câu 78 Domain 4: Monitoring and Logging

A cyber forensics company would like to ensure that CloudTrail is always enabled in its AWS account. It also needs to have an audit trail of the status for CloudTrail. In the case of compliance breaches, the company would like to automatically resolve them.

As a DevOps Engineer, how can you implement a solution for this requirement?

  1. A

    Create an AWS Config rule to track if CloudTrail is enabled. Create a CloudWatch Event rule to get alerted in case of breaches, and trigger a Lambda function that will re-enable CloudTrail

  2. B

    Place all your AWS IAM users under an IAM group named 'everyone'. Create an IAM deny policy on that group to prevent users from using the DeleteTrail API. Create a CloudWatch Event rule that will trigger a Lambda function every 5 minutes. That Lambda function will check if CloudTrail is enabled using an API call and enable it back if necessary

  3. C

    Create a CloudWatch Event rule that will trigger a Lambda function every 5 minutes. That Lambda function will check if CloudTrail is enabled using an API call and enable it back if necessary

  4. D

    Place all your AWS IAM users under an IAM group named 'everyone'. Create an IAM deny policy on that group to prevent users from using the DeleteTrail API. Create an AWS Config rule that tracks if every user is in that IAM group. Create a CloudWatch Event rule to get alerted in case of breaches, and trigger a Lambda function that will add users to the 'everyone' group automatically

Xem giải thích

Đáp án

*A — Tạo AWS Config rule theo dõi xem CloudTrail có được bật không, tạo CloudWatch Event rule để nhận cảnh báo khi vi phạm, và gọi một Lambda function bật lại CloudTrail

Vì sao đúng

Đề có ba yêu cầu, và giải pháp phủ cả ba:

Yêu cầu Mảnh ghép
Bảo đảm CloudTrail luôn bật Config rule cloudtrail-enabled — kiểm tra liên tục
Có lịch sử kiểm toán về trạng thái Config lưu lịch sử tuân thủ theo thời gian
Tự động khắc phục vi phạm Lambda gọi API bật lại CloudTrail

Điểm mạnh của Config so với việc tự kiểm tra: nó đánh giá theo sự kiện — khi cấu hình thay đổi là nó chạy ngay, không phải chờ tới chu kỳ kiểm tra tiếp theo.

(Config còn có Auto Remediation dựng sẵn qua SSM Automation, làm được việc khắc phục mà không cần Lambda — nhưng phương án A vẫn là kiến trúc đúng.)

Vì sao các phương án khác sai

  • C. Lambda chạy mỗi 5 phút gọi API kiểm tra rồi bật lại nếu cần — mô hình hỏi vòng: có cửa sổ tối đa 5 phút mà CloudTrail bị tắt và không có gì được ghi lại; và bạn cũng không có lịch sử tuân thủ. Đây là phương án nhiễu chính.
  • B và D. Đưa mọi IAM user vào một nhóm và chặn DeleteTrail — không đủ: CloudTrail bị vô hiệu bằng StopLogging chứ không nhất thiết phải xoá, và biện pháp này không chạm tới vai trò hay tài khoản nằm ngoài nhóm đó.
Câu 79 Domain 1: SDLC Automation

A data intelligence and analytics company enables publishers to measure, analyze, and improve the impact of the advertising across their range of online deliverables. The DevOps team at the company wants to use CodePipeline to deploy code from CodeCommit with CodeDeploy. The company has hired you as an AWS Certified DevOps Engineer Professional to build a solution for this requirement.

How would you configure the EC2 instances to facilitate the deployment?

  1. A

    Create an EC2 instance with an IAM role giving access to the S3 bucket where CodeDeploy is deploying from. Ensure that the EC2 instance also has the CodeDeploy agent installed. Tag the instance to have it part of a deployment group

  2. B

    Create an EC2 instance with an IAM user access credentials giving access to the CodeCommit repository where CodeDeploy is deploying from. Ensure that the EC2 instance also has the CodeDeploy agent installed. Tag the instance to have it part of a deployment group

  3. C

    Create an EC2 instance with an IAM role giving access to the CodeCommit repository where CodeDeploy is deploying from. CodeDeploy will install the agent on the EC2 instance

  4. D

    Create an EC2 instance with an IAM user access credentials giving access to the S3 bucket where CodeDeploy is deploying from. Ensure that the EC2 instance also has the CodeDeploy agent installed. Tag the instance to have it part of a deployment group

Xem giải thích

Đáp án

A — Tạo EC2 instance với IAM role cấp quyền đọc bucket S3 nơi CodeDeploy lấy mã, cài CodeDeploy agent, và gắn thẻ để instance thuộc về một deployment group

Vì sao đúng

Ba điều kiện để một EC2 instance nhận được triển khai từ CodeDeploy, và phương án này nêu đủ cả ba:

Thứ nhất — quyền đọc S3, không phải quyền đọc CodeCommit. Đây là chi tiết quyết định. Trong CodePipeline, mã không đi thẳng từ CodeCommit tới instance:

CodeCommit  →  CodePipeline đóng gói artefact  →  S3 (artifact bucket)  →  CodeDeploy agent tải về

Nên instance cần quyền với bucket artefact của pipeline, và không cần biết gì về CodeCommit.

Thứ hai — phải tự cài agent. CodeDeploy không tự cài agent lên instance; bạn cài qua user-data, qua AMI dựng sẵn, hoặc qua SSM Distributor.

Thứ ba — dùng IAM role, không dùng khoá của IAM user. Role cấp thông tin xác thực tạm thời tự xoay vòng.

Vì sao các phương án khác sai

  • C. Cấp quyền truy cập CodeCommit và cho rằng CodeDeploy sẽ tự cài agent — sai ở cả hai vế. Đây là phương án nhiễu chính.
  • *D. Đúng bucket S3 nhưng dùng khoá truy cập của IAM user — khoá cố định nằm trên instance; bước lùi về bảo mật khi instance role đã sẵn có.
  • B. Dùng khoá IAM user và cấp quyền CodeCommit — sai cả hai.
Câu 80 Domain 4: Monitoring and Logging

A gaming company would like to be able to receive near real-time notifications when the API call DeleteTable is invoked in DynamoDB.

As a DevOps Engineer at the company, how would you implement this at a minimal cost?

  1. A

    Create a CloudTrail event filter and hook it up to a Lambda function. Use the Lambda function to send an SNS notification

  2. B

    Send CloudTrail Logs to CloudWatch Logs and use an AWS Lambda function to be triggered on a CloudWatch Logs metrics filter. Use the Lambda function to send an SNS notification

  3. C

    Enable DynamoDB Streams, and have a Lambda function consuming that stream. Send alerts to SNS whenever a record is being deleted

  4. D

    Enable CloudTrail. Create a CloudWatch Event rule to track an AWS API call via CloudTrail and use SNS as a target

Xem giải thích

Đáp án

*D — Bật CloudTrail, tạo CloudWatch Event rule theo dõi lời gọi API qua CloudTrail, với SNS làm target

Vì sao đúng

Chữ khoá của đề là "chi phí tối thiểu", và phương án này là đường ngắn nhất có thể:

DeleteTable được gọi
   ▼  CloudTrail ghi lại
EventBridge rule (khớp eventName = DeleteTable, eventSource = dynamodb.amazonaws.com)
   ▼  target TRỰC TIẾP
SNS  →  thông báo

Ba lý do nó rẻ nhất:

  • Không có Lambda — SNS là target hợp lệ của EventBridge, gọi thẳng được.
  • CloudTrail management event miễn phí cho bản ghi đầu tiên.
  • EventBridge không tính phí cho sự kiện do dịch vụ AWS phát ra.

Nó cũng gần thời gian thực — sự kiện tới trong vài phút.

Vì sao các phương án khác sai

  • B. Đẩy CloudTrail log sang CloudWatch Logs rồi dùng metric filter gọi Lambda gửi SNS — hoạt động được nhưng thêm hai khoản phí (nhập log vào CloudWatch Logs, và Lambda) cho việc mà EventBridge làm trực tiếp. Đây là phương án nhiễu chính.
  • C. Bật DynamoDB Streams để bắt sự kiện xoá — hiểu sai phạm vi: DynamoDB Streams ghi lại thay đổi của các mục dữ liệu trong bảng, nó không ghi thao tác xoá bảng. Đây là bẫy đáng chú ý vì cả hai đều có chữ "delete".
  • A. Tạo "CloudTrail event filter" nối với Lambda — CloudTrail không có tính năng lọc và kích hoạt như vậy; việc đó do EventBridge làm.