Ngân hàng đề — AWS Certified DevOps Engineer Professional

Tìm thấy 681 câu.

Câu 91 Domain 4: Monitoring and Logging

A video-sharing application stores its files on an Amazon S3 bucket. During the last year, the user traffic has multiplied by thousands and the company is planning on introducing subscription services for its video sharing application. The company needs the access pattern of the video files to identify the most viewed and downloaded videos.

Which of the following would you identify as the MOST cost-effective solution that can be implemented at the earliest?

  1. A

    Leverage Amazon S3 request metrics from CloudWatch for analysis via an AWS Lambda function. The AWS/S3 namespace includes the request metrics GetRequests and BytesDownloaded that can be passed to the Lambda function for analyzing the access pattern of the S3 bucket. The output of the Lambda function can be stored in an S3 bucket and visually analyzed using Amazon QuickSight

  2. B

    Enable server access logging on the S3 bucket. Use Amazon Redshift Spectrum to efficiently query large datasets leveraging the massive parallelism offered by dedicated Amazon Redshift servers

  3. C

    Enable server access logging on the S3 bucket. Configure Amazon Athena to create an external table with the log files. Use SQL query to analyze the access patterns from Athena

  4. D

    Enable server access logging on the S3 bucket. Configure file create event notification on Access log S3 bucket to trigger an AWS Lambda function. Configure Lambda to write the data to Kinesis Firehose which then writes the log data to Amazon OpenSearch Service. Use Elasticsearch search and analytics engine for analyzing usage patterns of the S3 access logs

Xem giải thích

Đáp án

C — Bật server access logging trên bucket, tạo external table trong Athena trỏ vào log, rồi truy vấn bằng SQL.

Vì sao đúng

Đề đòi ba thứ cùng lúc: biết từng object nào được xem/tải nhiều nhất, rẻ nhất, và triển khai nhanh nhất.

S3 server access logging ghi mỗi request một dòng, có key, operation, bytes_sent, remote_ip, requester… và không mất phí cho bản thân việc ghi log — chỉ trả tiền lưu trữ log trên S3. Athena thì serverless, tính tiền theo dữ liệu quét (khoảng 5 USD/TB), không có gì phải dựng.

Toàn bộ việc "triển khai" gói trong một câu DDL:

CREATE EXTERNAL TABLE s3_access_logs (
  bucketowner STRING, bucket_name STRING, requestdatetime STRING,
  remoteip STRING, requester STRING, requestid STRING, operation STRING,
  key STRING, ..., bytessent BIGINT, ...
)
ROW FORMAT SERDE 'org.apache.hadoop.hive.serde2.RegexSerDe'
LOCATION 's3://bucket-log/prefix/';

SELECT key, COUNT(*) AS luot_tai, SUM(bytessent) AS tong_byte
FROM s3_access_logs
WHERE operation = 'REST.GET.OBJECT'
GROUP BY key ORDER BY luot_tai DESC LIMIT 20;

Vì sao các phương án khác sai

  • A. S3 request metrics của CloudWatch — GetRequests và BytesDownloaded là metric theo bucket hoặc theo prefix/filter, không theo từng object. Muốn biết video nào thì metric này không trả lời được. Ngoài ra request metrics là tính năng có phí theo từng metric.
  • B. Redshift Spectrum — truy vấn được đúng dữ liệu đó, nhưng Spectrum đòi một cluster Redshift đang chạy để làm điểm vào. Dựng cluster chỉ để chạy vài câu thống kê là đắt hơn hẳn và chậm hơn hẳn — trượt cả hai tiêu chí của đề. (Redshift Serverless có thể rẻ hơn, nhưng phương án nói rõ "dedicated Amazon Redshift servers".)
  • D. Lambda → Kinesis → … — đường ống tự viết, phải nuôi mãi, để đạt cùng kết quả mà Athena cho bằng một câu SQL.

Ghi nhớ

Câu hỏi kiểu "phân tích log đã có, rẻ nhất, nhanh nhất" trong đề AWS gần như luôn ra Athena. Còn khi đề hỏi theo từng object, hãy loại ngay CloudWatch metric — chúng tổng hợp theo bucket/prefix.

Câu 92 Domain 4: Monitoring and Logging

A company wants to enforce regulations to prevent frequent logins by DevOps engineers to the Amazon EC2 instances, with the added condition that immediate notification must be sent to the security team if any login occurs.

What solution would you suggest to meet these requirements?

  1. A

    Configure AWS CloudTrail to track AWS API calls and log them to Amazon CloudWatch Logs. Subscribe CloudWatch Logs to Amazon Kinesis. Set up an AWS Lambda function as a consumer for the Kinesis stream to process the logs and detect any user logins. Use Amazon SNS to send notifications to the security team upon detecting a login event

  2. B

    Set up the Amazon Inspector Agent on each Amazon EC2 instance with the configuration to push all logs to Amazon CloudWatch Logs. Create a CloudWatch metric filter to detect user logins. Use Amazon SNS to notify the security team when a login is detected

  3. C

    Set up the Amazon CloudWatch Agent on each Amazon EC2 instance with the configuration to push all logs to Amazon CloudWatch Logs. Create a CloudWatch metric filter to detect user logins. Use Amazon SNS to notify the security team when a login is detected

  4. D

    Set up the Amazon CloudWatch Agent on each Amazon EC2 instance with the configuration to push all logs to Amazon CloudWatch Logs. Create a CloudWatch subscription filter to detect user logins. Use Amazon SNS to notify the security team when a login is detected

Xem giải thích

Đáp án

C — CloudWatch Agent đẩy log lên CloudWatch Logs, tạo metric filter bắt sự kiện đăng nhập, cảnh báo qua SNS.

Vì sao đúng

Sự kiện cần bắt là đăng nhập vào hệ điều hành của EC2 — /var/log/secure hay /var/log/auth.log trên Linux, Security event log trên Windows. Đây là log bên trong instance, không phải lời gọi API AWS, nên chỉ có agent cài trên máy mới thấy.

Đường đi: CloudWatch Agent → CloudWatch Logs → metric filter biến dòng log khớp mẫu thành metric số → CloudWatch alarm khi metric > 0 → SNS.

Metric filter là mắt xích đúng vì nó chuyển từ văn bản sang số đếm, và alarm chỉ làm việc được với số.

Vì sao các phương án khác sai

  • A. CloudTrail — CloudTrail ghi lời gọi API tới AWS, không ghi phiên SSH/RDP vào instance. Người ta đăng nhập bằng SSH thì CloudTrail không thấy gì cả. (Nếu vào bằng SSM Session Manager thì có StartSession trong CloudTrail — nhưng đề không nói vậy, và nếu chỉ chặn được lối SSM thì lối SSH vẫn hở.)
  • B. Amazon Inspector Agent — Inspector quét lỗ hổng phần mềm và phơi nhiễm mạng; nó không phải tác nhân thu thập log tuỳ ý. Bản Inspector hiện nay còn không dùng agent riêng nữa mà dùng SSM Agent.
  • D. Subscription filter — cũng bắt được mẫu log, nhưng nó đẩy log thô sang Lambda / Kinesis / OpenSearch, tức là bạn phải tự viết hàm rồi tự gọi SNS. Chỉ để gửi một thông báo thì metric filter + alarm là con đường có sẵn, không cần code.

Ghi nhớ

Cần gì Dùng gì
Đếm/alarm theo mẫu trong log metric filter + alarm
Đưa log thô sang nơi khác xử lý subscription filter
Lời gọi API AWS CloudTrail
Sự kiện trong hệ điều hành CloudWatch Agent
Câu 93 Domain 2: Configuration Management and IaC

In a multinational company, various AWS accounts are efficiently managed using AWS Control Tower. The company operates both internal and public applications across its infrastructure. To streamline operations, each application team is assigned a dedicated AWS account responsible for hosting their respective applications. These accounts are consolidated under an organization in AWS Organizations. Additionally, a specific AWS Control Tower member account acts as a centralized DevOps hub, offering Continuous Integration/Continuous Deployment (CI/CD) pipelines that application teams utilize to deploy applications to their designated AWS accounts. A specialized IAM role for deployment is available within this central DevOps account.

Currently, a particular application team is facing challenges while attempting to deploy its application to an Amazon Elastic Kubernetes Service (Amazon EKS) cluster situated in their application-specific AWS account. They have an existing IAM role for deployment within the application AWS account. The deployment process relies on an AWS CodeBuild project, configured within the centralized DevOps account, and utilizes an IAM service role for CodeBuild. However, the deployment process is encountering an Unauthorized error when trying to establish connections to the cross-account EKS cluster from the CodeBuild environment.

To resolve this error and facilitate a successful deployment, what solution would you recommend?

  1. A

    Establish a trust relationship in the application account's deployment IAM role for the centralized DevOps account, allowing the sts:AssumeRoleWithSAML action. Also, grant the centralized DevOps account's deployment IAM role the required access to CodeBuild and the EKS cluster

  2. B

    Establish a trust relationship in the application account's deployment IAM role for the centralized DevOps account, allowing the sts:AssumeRole action. Also, grant the application account's deployment IAM role the necessary access to the EKS cluster. Additionally, configure the EKS cluster aws-auth ConfigMap to map the role to the appropriate system permissions

  3. C

    Establish a trust relationship in the centralized DevOps account for the application account's deployment IAM role, allowing the sts:AssumeRole action. Also, grant the application account's deployment IAM role the necessary access to the EKS cluster. Additionally, configure the EKS cluster aws-auth ConfigMap to map the role to the appropriate system permissions

  4. D

    Establish a trust relationship in the centralized DevOps account's deployment IAM role for the application account, allowing the sts:AssumeRoleWithSAML action. Also, grant the centralized DevOps account's deployment IAM role the required access to CodeBuild

Xem giải thích

Đáp án

B — Thiết lập trust relationship trong deployment role của tài khoản ứng dụng cho tài khoản DevOps trung tâm với sts:AssumeRole; đồng thời cấp cho pipeline ở tài khoản DevOps quyền sts:AssumeRole lên role đó.

Vì sao đúng

Truy cập chéo tài khoản trong IAM luôn cần hai vế, và đây là chỗ dễ lẫn nhất:

Vế Nằm ở đâu Nội dung
Trust policy (ai được vào) trên role đích — tài khoản ứng dụng Principal: arn:aws:iam::<DevOps>:root, action sts:AssumeRole
Identity policy (được phép xin vào) trên principal nguồn — role của pipeline ở tài khoản DevOps Action: sts:AssumeRole, Resource: <ARN role bên tài khoản ứng dụng>

Chiều đi là: pipeline ở tài khoản DevOps đi vào tài khoản ứng dụng để deploy. Vậy role được assume phải nằm ở tài khoản ứng dụng, và trust policy của nó phải nêu tên tài khoản DevOps.

Vì sao các phương án khác sai

  • A và D. sts:AssumeRoleWithSAML — dành cho liên kết danh tính từ IdP bên ngoài (Active Directory, Okta) qua SAML 2.0. Ở đây bên gọi là một role AWS đã có sẵn danh tính, phải dùng sts:AssumeRole thuần.
  • C và D. Đặt trust ở tài khoản DevOps — ngược chiều. Làm vậy nghĩa là tài khoản ứng dụng được phép vào tài khoản DevOps, đúng ngược với việc cần làm.

Ghi nhớ

Câu thần chú: trust policy nằm ở nơi bạn muốn ĐẾN, permission policy nằm ở nơi bạn ĐI TỪ. Thiếu vế nào cũng ra AccessDenied, và thông báo lỗi không nói thiếu vế nào.

Câu 94 Domain 2: Configuration Management and IaC

A social media company has its web application hosted on Amazon EC2 instances that are deployed in a single AWS Region. The company has now expanded its operations into new geographies and the company wants to offer low-latency access for the application to its customers. To comply with different financial regulations of each geography, the application needs to operate in silos and the underlying instances in one region should not interact with instances running in other regions.

Which of the following represents the most optimal solution to automate the application deployment to different AWS regions?

  1. A

    Create a CloudFormation template describing the application infrastructure in the Resources section. Create a CloudFormation stack from the template by using the AWS CLI, specify multiple regions using the --regions parameter to deploy the application

  2. B

    Create a CloudFormation template describing the application infrastructure in the Resources section. Use CloudFormation change set from an administrator account to launch stack instances that deploy the application to various other regions

  3. C

    Create a CloudFormation template describing the application infrastructure in the Resources section. Use CloudFormation stack set from an administrator account to launch stack instances that deploy the application to various other regions

  4. D

    Create a shell script that uses the AWS CLI to query the current state in one region and output an AWS CloudFormation template. Create a CloudFormation stack from the template by using the AWS CLI, specifying the --region parameter to deploy the application to other regions

Xem giải thích

Đáp án

C — Dùng CloudFormation StackSets từ một tài khoản quản trị để triển khai stack instance sang nhiều Region.

Vì sao đúng

Đề cần triển khai cùng một hạ tầng ra nhiều Region, và mỗi Region phải độc lập hoàn toàn (không được gọi qua lại vì lý do pháp lý).

StackSets là cơ chế duy nhất trong CloudFormation làm được việc "một template, nhiều tài khoản và/hoặc nhiều Region, quản lý tập trung":

aws cloudformation create-stack-set --stack-set-name web-app --template-body file://app.yaml
aws cloudformation create-stack-instances --stack-set-name web-app \
    --accounts 111122223333 \
    --regions ap-southeast-1 eu-west-1 us-east-1

Mỗi stack instance là một stack riêng, tài nguyên riêng, không có liên kết mạng nào giữa chúng — đúng yêu cầu chạy silo. Sửa template một lần thì đẩy được xuống tất cả.

Vì sao các phương án khác sai

  • A. "create-stack chỉ định nhiều Region" — aws cloudformation create-stack không có tham số nhận nhiều Region. Một lệnh, một Region.
  • B. Change set — change set là cơ chế xem trước thay đổi trước khi cập nhật một stack đã có. Nó không tạo được stack instance ở Region khác.
  • D. Shell script sinh template từ trạng thái hiện tại — vừa mong manh (không API nào xuất được template đầy đủ từ tài nguyên đang chạy), vừa vẫn phải lặp thủ công cho từng Region, và mỗi lần cập nhật lại phải làm lại từ đầu.

Ghi nhớ

Cùng một template, nhiều tài khoản hoặc nhiều Region → StackSets. Đó gần như là dấu hiệu nhận dạng cố định trong đề thi.

Câu 95 Chọn nhiều đáp án Domain 3: Resilient Cloud Solutions

A DevOps engineer is currently involved in a data archival project where the task is to migrate on-premises data to an Amazon S3 bucket. The engineer has created a script that handles the incremental archiving of on-premises data, specifically transferring data older than 6 months to Amazon S3. As part of the process, the data is removed from the on-premises location after being successfully transferred using the S3 PutObject operation.

During a thorough code review, the DevOps engineer identified a crucial issue in the script. The script does not include any validation to confirm whether the data is copied to Amazon S3 without any corruption. To ensure data integrity throughout the transmission, the DevOps engineer needs to update the script accordingly. The new solution must use MD5 checksums to verify the data integrity before allowing the deletion of the on-premises data.

Considering these requirements, what modifications or solutions should the DevOps engineer implement in the script to ensure successful data transfer and integrity validation? (Select two)

  1. A

    Examine the returned response for the version ID. Compare the version ID value of the object with a calculated or previously stored Content-MD5 digest

  2. B

    Examine the returned response for the ETag. Compare the ETag value of the object with a calculated or previously stored Content-MD5 digest

  3. C

    Provide the MD5 digest within the Content-MD5 parameter of the PUT command. Examine the Amazon S3's call return status to check for an error

  4. D

    Provide the MD5 digest as a custom name-value pair in the metadata of the object. Examine the Amazon S3's call return status to check for an error

  5. E

    Provide the MD5 digest as a trailing checksum of the object. Examine the Amazon S3's call return status to check for an error

Xem giải thích

Đáp án

B và C.

  • B — Đọc ETag trong phản hồi và so với digest Content-MD5 đã tính/lưu.
  • C — Truyền digest MD5 vào tham số Content-MD5 của lệnh PUT rồi kiểm tra trạng thái trả về.

Vì sao đúng

Kịch bản rất đáng sợ: xoá dữ liệu on-premises sau khi PutObject. Nếu object lên S3 mà hỏng dọc đường, dữ liệu gốc đã không còn. Nên phải kiểm tra tính toàn vẹn trước khi xoá, và có hai cách chính thống — cả hai đều được liệt kê:

Cách chủ động (C). Gửi kèm header Content-MD5:

MD5=$(openssl md5 -binary file.dat | base64)
aws s3api put-object --bucket kho --key file.dat --body file.dat --content-md5 "$MD5"

S3 tự tính lại MD5 khi nhận. Lệch là nó từ chối lưu và trả BadDigest. Đây là cách tốt hơn vì object hỏng không bao giờ tồn tại.

Cách kiểm tra sau (B). Với single-part upload, ETag chính là MD5 hex của nội dung object. So nó với digest đã lưu là biết ngay.

Vì sao các phương án khác sai

  • A. So version ID với Content-MD5 — version ID là chuỗi định danh phiên bản do S3 sinh ngẫu nhiên, chẳng liên quan gì tới nội dung. Không bao giờ khớp.
  • D. MD5 để trong metadata tuỳ ý — S3 không kiểm metadata do người dùng đặt, nó chỉ lưu nguyên xi. Object hỏng vẫn được nhận, kèm theo metadata nói rằng nó không hỏng.
  • E. Trailing checksum — S3 có hỗ trợ trailing checksum, nhưng chỉ với các thuật toán bổ sung (CRC32, CRC32C, SHA-1, SHA-256) qua header x-amz-trailer, không dùng cho MD5. MD5 phải đi ở Content-MD5.

Ghi nhớ

ETag = MD5 chỉ khi upload một phần và không mã hoá bằng SSE-KMS/SSE-C. Với multipart, ETag có dạng <hash>-<số phần> và không phải MD5 của cả file — xem thêm câu về checksum sau khi copy object.

Câu 96 Chọn nhiều đáp án Domain 2: Configuration Management and IaC

For deployments across AWS accounts, an e-commerce company has decided to use AWS CodePipeline to deploy an AWS CloudFormation stack in an AWS account (account A) to a different AWS account (account B).

What combination of steps will you take to configure this requirement? (Select three)

  1. A

    In account B, create a cross-account IAM role. In account A, add the AssumeRole permission to account A's CodePipeline service role to allow it to assume the cross-account role in account B

  2. B

    In account A, create a customer-managed AWS KMS key that grants usage permissions to account A's CodePipeline service role and account B. Also, create an Amazon Simple Storage Service (Amazon S3) bucket with a bucket policy that grants account B access to the bucket

  3. C

    In account B, add the AssumeRole permission to account A's CodePipeline service role to allow it to assume the cross-account role in account A

  4. D

    In account A, create a customer-managed AWS KMS key that grants usage permissions to account A's CodePipeline service role and account B. In account B, create an Amazon Simple Storage Service (Amazon S3) bucket with a bucket policy that grants account A access to the bucket

  5. E

    In account A, create a service role for the CloudFormation stack that includes the required permissions for the services deployed by the stack. In account B, update the CodePipeline configuration to include the resources associated with account A

  6. F

    In account B, create a service role for the CloudFormation stack that includes the required permissions for the services deployed by the stack. In account A, update the CodePipeline configuration to include the resources associated with account B

Xem giải thích

Đáp án

A, B và F.

  • A — Ở account B tạo cross-account role; ở account A cấp AssumeRole cho CodePipeline service role.
  • B — Ở account A tạo customer-managed KMS key và bucket artifact, cấp quyền dùng cho service role của A và cho account B.
  • F — Ở account B tạo service role cho CloudFormation stack; ở account A cấu hình pipeline dùng role đó.

Vì sao đúng

Pipeline nằm ở account A, stack được deploy sang account B. Ba mảnh ghép phải đúng chỗ:

Mảnh Đặt ở đâu Lý do
Artifact bucket + KMS key A Pipeline sống ở A nên artifact store cũng ở A. Account B phải được cấp quyền đọc bucket và dùng key để lấy artifact về.
Cross-account role B Đích đến. Trust policy nêu tên account A.
CloudFormation service role B Stack được tạo ở B, nên role mà CloudFormation dùng để tạo tài nguyên phải ở B.

Điểm mấu chốt hay bị bỏ sót: artifact store bắt buộc dùng customer-managed key, không dùng được key mặc định aws/s3. Lý do là key mặc định của AWS không cho sửa key policy, mà không sửa key policy thì không có cách nào cấp quyền giải mã cho account B. Đây là câu chuyện dễ nhớ nhất về vì sao CMK tồn tại.

Vì sao các phương án khác sai

  • C. "Ở account B cấp AssumeRole cho service role của A để assume role trong account A" — câu này tự mâu thuẫn: cấp ở B nhưng để vào A. Permission sts:AssumeRole phải nằm trên principal ở A.
  • D. Bucket artifact ở account B — CodePipeline lưu artifact ở artifact store của chính nó, tức ở A. Đặt bucket ở B thì pipeline không dùng được nó làm artifact store.
  • E. CloudFormation service role ở account A — role dùng để dựng tài nguyên ở B thì phải là role của B. Role của A không tạo được tài nguyên trong B.

Ghi nhớ

Deploy chéo tài khoản bằng CodePipeline luôn cần đủ ba thứ: cross-account role ở tài khoản đích, service role cho dịch vụ deploy ở tài khoản đích, và CMK dùng chung cho artifact bucket. Quên CMK là lỗi phổ biến nhất — biểu hiện là artifact tải về được nhưng giải mã thất bại.

Câu 97 Domain 1: SDLC Automation

A production support team manages a web application running on a fleet of Amazon EC2 instances configured with an Application Load balancer (ALB). The instances run in an EC2 Auto Scaling group across multiple Availability Zones. A critical bug fix has to be deployed to the production application. The team needs a deployment strategy that can:

a) Create another fleet of instances with the same capacity and configuration as the original one. b) Continue access to the original application without a downtime c) Transition the traffic to the new fleet when the deployment is fully done. The production test team has requested a two-hour window to complete thorough testing on the new fleet of instances. d) Terminate the original fleet automatically once the test window expires.

As a DevOps engineer, which deployment solution will you choose to cater to all the given requirements?

  1. A

    Use AWS CodeDeploy with a deployment type configured to Blue/Green deployment configuration. To terminate the original fleet after two hours, change the deployment settings of the Blue/Green deployment. Set Original instances value to 'Terminate the original instances in the deployment group' and choose a waiting period of two hours. Choose OneAtATime Deployment configuration setting to deregister the original fleet of instances one at a time to provide increased test time for the production team

  2. B

    Configure AWS Elastic Beanstalk to use rolling deployment policy. Elastic Beanstalk splits the environment's Amazon EC2 instances into batches and deploys the new version of the application to one batch at a time. Production traffic is served unaffected. Use rolling restarts to restart the proxy and application servers running on your environment's instances without downtime

  3. C

    Use AWS CodeDeploy with a deployment type configured to Blue/Green deployment configuration. To terminate the original fleet after two hours, change the deployment settings of the Blue/Green deployment. Set Original instances value to Terminate the original instances in the deployment group and choose a waiting period of two hours

  4. D

    Configure AWS Elastic Beanstalk to perform a Blue/Green deployment. This will create a new environment different from the original environment to continue serving the production traffic. Terminate the original environment after two hours and confirm the DNS changes of the new environment have propagated correctly

Xem giải thích

Đáp án

C — CodeDeploy với deployment type Blue/Green, đặt thiết lập "Original instances" thành huỷ sau hai giờ.

Vì sao đúng

Đọc lại đúng ba yêu cầu của đề và soi vào Blue/Green của CodeDeploy trên nền EC2/ASG:

Yêu cầu Blue/Green làm gì
Tạo fleet mới cùng dung lượng và cấu hình CodeDeploy tự sao chép Auto Scaling group hiện có
Vẫn truy cập được bản gốc trong khi deploy Fleet cũ vẫn nhận traffic cho tới lúc chuyển
Huỷ fleet gốc sau hai giờ Thiết lập Original instances → Terminate, chọn thời gian chờ

Hai giờ chờ đó chính là cửa sổ rollback: có sự cố thì trỏ ALB về fleet cũ trong vài giây, không cần deploy lại.

Cả A và C mô tả gần như y hệt nhau — điểm khác nằm ở nửa sau của câu chữ (một bên nói giữ, một bên nói huỷ theo đúng thời hạn). Đây là kiểu câu bắt đọc kỹ tới chữ cuối.

Vì sao các phương án khác sai

  • A. Cùng hướng đi nhưng phần thiết lập không khớp yêu cầu huỷ sau hai giờ.
  • B. Elastic Beanstalk rolling — rolling cập nhật tại chỗ theo từng lô trên chính instance cũ. Không có fleet thứ hai, năng lực bị giảm trong lúc deploy, và rollback đồng nghĩa với deploy ngược lại một lượt nữa. Trượt cả ba yêu cầu.
  • D. Elastic Beanstalk Blue/Green — về nguyên tắc đúng mô hình, nhưng ứng dụng đang chạy trên EC2 + ASG + ALB tự quản, không chạy trên Beanstalk. Chọn phương án này là bắt công ty di trú cả nền tảng chỉ để vá một lỗi.

Ghi nhớ

Trong CodeDeploy Blue/Green trên EC2, sau khi chuyển traffic bạn có ba lựa chọn cho fleet cũ: giữ nguyên, huỷ ngay, hoặc huỷ sau N phút/giờ. Lựa chọn thứ ba là cách rẻ nhất để có cửa sổ rollback tức thời.

Câu 98 Chọn nhiều đáp án Domain 3: Resilient Cloud Solutions

A DevOps Engineer is working on multiple applications that need to be configured for Application Auto scaling, however, there are some application constraints to be addressed:

a) A serverless application is built on AWS Lambda with the following traffic pattern - The traffic for the application starts to increase on Wednesday, remains high on Thursday, and starts to decrease on Friday. b) Another flagship application runs on Spot Fleet. The CPU utilization of the fleet has to stay at around 50 percent when the load on the application changes.

Which of the following solutions can address these requirements? (Select two)

  1. A

    Create an Amazon CloudWatch metric to track the utilization of the AWS Lambda function. Setup step scaling policy by configuring the upper bound, lower bound, and breach threshold values for the Lambda function

  2. B

    Use Scheduled scaling Auto Scaling policy, and create a scheduled action with AWS Lambda function as a scalable target. Specify the minimum and maximum capacity based on the requirements. AWS CLI, SDKs, or CloudFormation can be used for configuring the schedule scaling

  3. C

    Create an Amazon CloudWatch metric to track average CPU utilization of 50 percent for the Spot Fleet. Create a target tracking auto-scaling policy CloudWatch alarm against the CloudWatch metric created from the AWS console

  4. D

    Use Scheduled scaling Auto Scaling policy, and create a scheduled action with Spot instances as a scalable target. Specify the minimum and maximum capacity based on the requirements

  5. E

    Create a target tracking auto-scaling policy that targets an average CPU utilization of 50 percent for an application that runs on Spot Fleet. You can create and manage target tracking using the AWS CLI, SDKs, or CloudFormation

Xem giải thích

Đáp án

B và E.

  • B — Ứng dụng Lambda: dùng scheduled scaling của Application Auto Scaling, đặt Lambda làm scalable target.
  • E — Ứng dụng trên Spot Fleet: dùng target tracking nhắm CPU trung bình 50%.

Vì sao đúng

Hai bài toán, hai loại chính sách — và đề cố tình cho hai tình huống kinh điển:

(a) Lambda, tải lên vào thứ Tư, cao thứ Năm, giảm thứ Sáu. Đây là mẫu tải biết trước theo lịch. Scheduled scaling điều chỉnh provisioned concurrency theo giờ, nên năng lực đã sẵn sàng trước khi traffic tới, không phải sau. Application Auto Scaling hỗ trợ Lambda provisioned concurrency làm scalable target chính thức.

aws application-autoscaling put-scheduled-action \
  --service-namespace lambda \
  --resource-id function:xu-ly-don:prod \
  --scalable-dimension lambda:function:ProvisionedConcurrency \
  --scheduled-action-name tang-thu-tu \
  --schedule "cron(0 0 ? * WED *)" \
  --scalable-target-action MinCapacity=100,MaxCapacity=500

(b) Spot Fleet giữ CPU quanh 50%. "Giữ một chỉ số quanh một giá trị" chính là định nghĩa của target tracking. Bạn khai giá trị mục tiêu, Application Auto Scaling tự tạo và quản lý các alarm cần thiết.

Vì sao các phương án khác sai

  • A. Step scaling cho Lambda — step scaling phản ứng sau khi metric vượt ngưỡng, tức là đợt tải sáng thứ Tư vẫn ăn nguyên cold start rồi mới được thêm năng lực. Với tải đã biết trước theo lịch, phản ứng là lựa chọn kém hơn dự phòng.
  • C. Tự tạo metric và alarm cho target tracking — sai ở chỗ hiểu cách target tracking hoạt động: bạn không tự tạo alarm. Chính sách tự sinh và tự xoá alarm; tự tạo tay là vừa thừa vừa dễ xung đột. Ngoài ra CPUUtilization của Spot Fleet đã là metric có sẵn, không phải metric tuỳ chỉnh.
  • D. Scheduled scaling cho Spot Fleet — Spot Fleet đây cần giữ CPU ở một mức, không có lịch nào cả.

Ghi nhớ

Mẫu tải Chính sách
Biết trước theo giờ/ngày Scheduled scaling
Giữ một chỉ số quanh giá trị mục tiêu Target tracking
Phản ứng theo nhiều nấc độ lệch Step scaling
Không đoán được, cần đơn giản Simple scaling (đã cũ)
Câu 99 Domain 6: Security and Compliance

Consider a multi-account setup within AWS Organizations where a company is running a data ingestion application on Amazon EC2 instances through several Auto Scaling groups. These instances lack internet access due to sensitive data handling, and VPC endpoints have been deployed accordingly. The application operates on a custom AMI designed specifically for its needs.

To effectively manage and troubleshoot the application, system administrators require automated and centralized login access to the EC2 instances. Additionally, the company's security team needs to be notified whenever such instances are accessed.

As an AWS Certified DevOps Engineer - Professional, what solution will you suggest to satisfy these requirements?

  1. A

    Set up a NAT gateway and a bastion host with internet access. Configure a security group that permits incoming traffic from the bastion host to all EC2 instances. Set up AWS Systems Manager Agent on the EC2 instances for monitoring and troubleshooting. Leverage Auto Scaling group lifecycle hooks for monitoring access. Utilize Systems Manager Session Manager for centralized login. Direct EC2 instance logs to an Amazon CloudWatch Logs log group. For auditing purposes, export data to Amazon S3 and notify the security team through S3 event notifications

  2. B

    Utilize EC2 Image Builder to rebuild the custom AMI that includes the latest AWS Systems Manager Agent version. Set up the Auto Scaling group to attach the AmazonSSMManagedInstanceCore role to EC2 instances. Leverage EC2 Instance Connect for centralized access and automated login. Configure logging of session details to Amazon S3. Set up an S3 event notification for new file uploads to notify the security team via an Amazon Simple Notification Service (Amazon SNS) topic

  3. C

    Utilize AWS Systems Manager Automation to rebuild the custom AMI that includes the latest AWS Systems Manager Agent version. Configure AWS Config to attach an SCP to the root organization account to allow the EC2 instances to connect to Systems Manager and grant access to centralized and automated login. Configure logging of session details to Amazon S3. Set up an S3 event notification for new file uploads to notify the security team via an Amazon Simple Notification Service (Amazon SNS) topic

  4. D

    Utilize EC2 Image Builder to rebuild the custom AMI that includes the latest AWS Systems Manager Agent version. Set up the Auto Scaling group to attach the AmazonSSMManagedInstanceCore role to EC2 instances. Leverage Systems Manager Session Manager for centralized and automated login. Configure logging of session details to Amazon S3. Set up an S3 event notification for new file uploads to notify the security team via an Amazon Simple Notification Service (Amazon SNS) topic

Xem giải thích

Đáp án

D — EC2 Image Builder dựng lại AMI kèm SSM Agent mới nhất; ASG gắn role AmazonSSMManagedInstanceCore; dùng Session Manager, và EventBridge bắt sự kiện StartSession để báo cho đội bảo mật.

Vì sao đúng

Ba ràng buộc của đề: instance không có Internet, đã có VPC endpoint, và cần đăng nhập tập trung, tự động kèm thông báo cho bảo mật.

Session Manager là câu trả lời cho vế đăng nhập: không cần cổng 22 mở, không cần bastion, không cần khoá SSH, và chạy được hoàn toàn trong VPC riêng nhờ các interface endpoint ssm, ssmmessages, ec2messages. Đề đã nói VPC endpoint được triển khai sẵn.

Ba mảnh phải có đủ:

  1. SSM Agent trong AMI — AMI tuỳ chỉnh nên phải tự đưa agent vào. EC2 Image Builder sinh ra đúng để dựng lại AMI theo pipeline có phiên bản, có kiểm thử.
  2. Instance profile AmazonSSMManagedInstanceCore — không có role này thì agent không đăng ký được với Systems Manager.
  3. Thông báo — mỗi phiên tạo ra sự kiện CloudTrail StartSession; EventBridge bắt sự kiện đó rồi đẩy sang SNS.

Vì sao các phương án khác sai

  • A. NAT gateway + bastion host — đi ngược yêu cầu. Đề nói rõ instance không được có Internet vì xử lý dữ liệu nhạy cảm; dựng NAT và bastion là mở lại đúng lối vào mà kiến trúc đang cố tránh, lại thêm khoá SSH phải quản lý.
  • B. Đúng ba bước đầu nhưng sai ở cơ chế thông báo (không dùng đường CloudTrail → EventBridge cho StartSession).
  • C. "AWS Config gắn SCP vào root account" — sai ở nhiều tầng: Config không gắn SCP, SCP là công cụ của Organizations, và SCP giới hạn quyền chứ không cấp quyền — không bao giờ dùng SCP để cho EC2 quyền gọi SSM.

Ghi nhớ

Đăng nhập EC2 trong subnet riêng, không Internet: SSM Session Manager + ba VPC interface endpoint (ssm, ssmmessages, ec2messages). Thiếu ssmmessages là lỗi hay gặp nhất — instance hiện "Managed" nhưng mở phiên thì treo.

Câu 100 Domain 6: Security and Compliance

A company hosts all its web applications on Amazon EC2 instances. The company is looking for a security solution that will proactively detect software vulnerabilities and unintended network exposure of the instances. The solution should also include an audit trail of all login activities on the instances.

Which solution will meet these requirements?

  1. A

    Configure Amazon Inspector to detect vulnerabilities on the EC2 instances. Install the Amazon CloudWatch Agent to capture system logs and record them via Amazon CloudWatch Logs. Configure your trail to send log events to CloudWatch Logs

  2. B

    Configure Amazon ECR image scanning to scan for vulnerabilities on the EC2 instances. Amazon ECR sends an event to Amazon EventBridge when an image scan is completed. Configure CloudTrail to send its trail data to Amazon EventBridge for further processing/notification

  3. C

    Configure Amazon GuardDuty to detect vulnerabilities and threats on the EC2 instances. Integrate with a workflow system to review the findings and trigger an AWS Lambda function to automate the remediation process

  4. D

    Configure AWS Systems Manager's Systems Manager (SSM) agent to collect software vulnerabilities of the Amazon EC2 instances. Configure a Systems Manager Automation runbook to automatically patch the vulnerabilities identified by the SSM agent

Xem giải thích

Đáp án

A — Amazon Inspector dò lỗ hổng; CloudWatch Agent thu system log vào CloudWatch Logs; CloudTrail ghi vết.

Vì sao đúng

Đề đòi ba thứ tách bạch, và mỗi thứ có đúng một dịch vụ:

Yêu cầu Dịch vụ
Dò lỗ hổng phần mềm trên EC2 Amazon Inspector
Phát hiện phơi nhiễm mạng ngoài ý muốn Amazon Inspector (network reachability)
Vết đăng nhập vào instance CloudWatch Agent đẩy /var/log/secure lên CloudWatch Logs

Inspector là dịch vụ duy nhất trong danh sách vừa quét CVE của gói phần mềm vừa phân tích khả năng tiếp cận từ Internet (đọc security group, NACL, route table, ENI để kết luận cổng nào thực sự với tới được). Vế "audit trail of all login activities" thì bắt buộc phải có agent, vì đăng nhập hệ điều hành không xuất hiện trong bất kỳ log nào của AWS.

Vì sao các phương án khác sai

  • B. ECR image scanning — quét image container trong registry, không quét EC2 instance. Sai đối tượng hoàn toàn.
  • C. GuardDuty — GuardDuty phát hiện hành vi đe doạ (gọi API bất thường, liên lạc với IP xấu, dò quét), không dò lỗ hổng phần mềm. Đây là cặp hay bị lẫn nhất: Inspector = lỗ hổng, GuardDuty = mối đe doạ.
  • D. SSM Agent thu thập lỗ hổng — SSM Inventory liệt kê gói đã cài, còn Patch Manager biết bản vá nào thiếu; nhưng cả hai không phải công cụ đánh giá lỗ hổng, và không có phần nào của phương án đáp ứng vế "phơi nhiễm mạng".

Ghi nhớ

Inspector — lỗ hổng và phơi nhiễm. GuardDuty — mối đe doạ và hành vi bất thường. Macie — dữ liệu nhạy cảm trong S3. Detective — điều tra sau sự cố.