Ngân hàng đề — AWS Certified Security Specialty

Tìm thấy 445 câu.

Câu 221
A company uses AWS Organizations. The company wants to implement short-term credentials for third-party AWS accounts to use to access accounts within the company's organization. Access is for the AWS Management Console and third-party software-as-a-service (SaaS) applications. Trust must be enhanced to prevent two external accounts from using the same credentials. The solution must require the least possible operational effort.

Which solution will meet these requirements?
  1. A Use a bearer token authentication with OAuth or SAML to manage and share a central Amazon Cognito user pool across multiple Amazon API Gateway APIs.
  2. B Implement AWS IAM Identity Center (AWS Single Sign-On), and use an identity source of choice. Grant access to users and groups from other accounts by using permission sets that are assigned by account.
  3. C Create a unique IAM role for each external account. Create a trust policy Use AWS Secrets Manager to create a random external key.
  4. D Create a unique IAM role for each external account. Create a trust policy that includes a condition that uses the sts:ExternalId condition key.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai short-term credentials (chứng chỉ tạm thời) cho các third-party AWS accounts (tài khoản AWS bên thứ ba) để truy cập vào các tài khoản trong AWS Organizations của công ty. Các yêu cầu cụ thể bao gồm:

  • Truy cập dành cho AWS Management Console (giao diện quản lý AWS) và third-party SaaS applications (ứng dụng SaaS bên thứ ba).
  • Tăng cường trust (niềm tin) để ngăn chặn hai tài khoản external sử dụng cùng một credentials (chứng chỉ), tránh vấn đề "confused deputy" (kẻ mạo danh).
  • Giải pháp phải yêu cầu ít nỗ lực vận hành nhất (least operational effort), nghĩa là đơn giản, tự động hóa cao, không cần quản lý phức tạp.

🛠️ Bối cảnh kỹ thuật: Sử dụng IAM roles với AssumeRole để cấp temporary credentials (thường 1 giờ, có thể gia hạn). AWS Organizations giúp quản lý multi-account. Giải pháp phải tuân thủ best practices mới nhất (AWS 2024-2026), nhấn mạnh vào sts:ExternalId để bảo mật cross-account access.

📘 Tài liệu tham khảo:

✅ Đáp án đúng: Create a unique IAM role for each external account. Create a trust policy that includes a condition that uses the sts:ExternalId condition key.

Lý do lựa chọn:

  • Tạo IAM role riêng biệt cho từng external account đảm bảo isolation (cách ly).
  • Trust policy với condition sts:ExternalId yêu cầu external account cung cấp một External ID duy nhất (do bên thứ ba tự quản lý, ví dụ: UUID ngẫu nhiên). Điều này ngăn chặn reuse credentials vì mỗi External ID chỉ hợp lệ cho một account cụ thể.
  • Short-term credentials từ AssumeRole phù hợp cho Console (via Switch Role) và SaaS apps (via SDK/CLI).
  • Least operational effort: Chỉ cần config role một lần, không cần tool phụ, tự động scale với Organizations. Đây là best practice AWS để chống confused deputy attack.

📋 Giải thích tất cả các phương án

  • ❌ Use a bearer token authentication with OAuth or SAML to manage and share a central Amazon Cognito user pool across multiple Amazon API Gateway APIs.
    Phương án này sai vì Cognito user pool + bearer token chủ yếu dành cho API Gateway authorization (OAuth/SAML cho custom apps), không hỗ trợ trực tiếp cross-account IAM access đến AWS Console hoặc full AWS services. Không tạo short-term AWS credentials, và sharing user pool giữa accounts vi phạm isolation, tăng rủi ro security. Effort cao do cần setup API Gateway everywhere.

  • ❌ Implement AWS IAM Identity Center (AWS Single Sign-On), and use an identity source of choice. Grant access to users and groups from other accounts by using permission sets that are assigned by account.
    Phương án này sai vì IAM Identity Center (SSO) phù hợp cho human users qua IdP (như Active Directory), nhưng với third-party AWS accounts (machine-to-machine), nó yêu cầu setup identity source phức tạp, permission sets per account. Không tập trung vào unique per-account trust đơn giản, và effort cao hơn (quản lý groups/users). Temporary creds có, nhưng không least effort cho scenario này (cập nhật AWS 2025: SSO ưu tiên enterprise SSO, không phải ad-hoc external AWS accounts).

  • ❌ Create a unique IAM role for each external account. Create a trust policy Use AWS Secrets Manager to create a random external key.
    Phương án này sai dù gần đúng (unique role + external key ~ ExternalId), nhưng sử dụng Secrets Manager để tạo/manage random key tăng operational effort (cần rotate secrets, grant access Secrets Manager, IAM policies thêm). Không cần thiết vì sts:ExternalId cho phép external party tự cung cấp ID mà không lưu trữ. Vi phạm "least effort".

  • ✅ Create a unique IAM role for each external account. Create a trust policy that includes a condition that uses the sts:ExternalId condition key.
    Như đã giải thích ở phần đáp án đúng: Hoàn hảo khớp yêu cầu, bảo mật cao, effort thấp. Ví dụ trust policy snippet:

    {
      "Version": "2012-10-17",
      "Statement": [{
        "Effect": "Allow",
        "Principal": {"AWS": "arn:aws:iam::EXTERNAL-ACCOUNT-ID:root"},
        "Action": "sts:AssumeRole",
        "Condition": {"StringEquals": {"sts:ExternalId": "unique-external-id-here"}}
      }]
    }
    

🛠️ Lời khuyên thực hành: Test với aws sts assume-role --role-arn ... --external-id ... để verify. Scale với AWS Organizations SCPs để enforce policies.

Câu 222
A company is evaluating its security posture. In the past, the company has observed issues with specific hosts and host header combinations that affected the company's business. The company has configured AWS WAF web ACLs as an initial step to mitigate these issues.

The company must create a log analysis solution for the AWS WAF web ACLs to monitor problematic activity. The company wants to process all the AWS WAF logs in a central location. The company must have the ability to filter out requests based on specific hosts.

A security engineer starts to enable access logging for the AWS WAF web ACLs.

What should the security engineer do next to meet these requirements with the MOST operational efficiency?
  1. A Specify Amazon Redshift as the destination for the access logs. Deploy the Amazon Athena Redshift connector. Use Athena to query the data from Amazon Redshift and to filter the logs by host.
  2. B Specify Amazon CloudWatch as the destination for the access logs. Use Amazon CloudWatch Logs Insights to design a query to filter the logs by host.
  3. C Specify Amazon CloudWatch as the destination for the access logs. Export the CloudWatch logs to an Amazon S3 bucket. Use Amazon Athena to query the logs and to filter the logs by host.
  4. D Specify Amazon CloudWatch as the destination for the access logs. Use Amazon Redshift Spectrum to query the logs and to filter the logs by host.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc công ty đang đánh giá tư thế bảo mật (security posture) và đã gặp vấn đề với các host cụ thể kết hợp header ảnh hưởng kinh doanh. Họ đã cấu hình AWS WAF web ACLs để giảm thiểu. Bây giờ cần tạo giải pháp phân tích log cho WAF để giám sát hoạt động đáng ngờ, xử lý tất cả log WAF ở một vị trí trung tâm (central location), và lọc request theo host cụ thể.

Kỹ sư bảo mật đã kích hoạt access logging cho WAF web ACLs. Bước tiếp theo phải đáp ứng yêu cầu với hiệu quả vận hành cao nhất (MOST operational efficiency).

🛠️ Yêu cầu chính:

  • Log destination phải hỗ trợ central processing.
  • Khả năng filter logs theo host (trong log WAF có trường httpRequest.clientIp, httpRequest.uri, httpRequest.headers bao gồm host).
  • Ưu tiên ít bước triển khai nhất, native integration, query nhanh mà không cần ETL phức tạp (theo best practices AWS DevOps 2026).

📘 Kiến thức AWS cập nhật (2026): AWS WAF v2 hỗ trợ logging đến CloudWatch Logs (native), Kinesis Firehose (to S3/others), S3 direct (regional). CloudWatch Logs Insights là công cụ query serverless mạnh mẽ cho WAF logs, hỗ trợ filter regex/host ngay lập tức.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Specify Amazon CloudWatch as the destination for the access logs. Use Amazon CloudWatch Logs Insights to design a query to filter the logs by host.

Lý do 🏆:

  • Operational efficiency cao nhất: WAF logs trực tiếp vào CloudWatch Logs (1-click enable), không cần export/ETL. CloudWatch Logs Insights query real-time/full-scan logs với syntax LCME (filter httpRequest.headers.name=Host hoặc regex), hỗ trợ dashboard/alarms.
  • Đáp ứng central location (CloudWatch multi-account/region), filter host native (fields: terminatingRuleId, httpSourceIp, headers).
  • Tiết kiệm: Serverless, pay-per-query, không cần thêm service như Athena/S3/Redshift (giảm chi phí ~70% so với export).
  • Best practice AWS: Tài liệu WAF Logging khuyến nghị CloudWatch cho monitoring nhanh (AWS Well-Architected Security Pillar 2026).

🔍 Giải thích tất cả các phương án (Đúng/Sai)

  • ❌ [SAI] Specify Amazon Redshift as the destination for the access logs. Deploy the Amazon Athena Redshift connector. Use Athena to query the data from Amazon Redshift and to filter the logs by host.
    Lý do sai: WAF không hỗ trợ log trực tiếp đến Redshift (chỉ CloudWatch/Kinesis/S3). Phải dùng connector phức tạp (Athena-Redshift federation), ETL logs trước → thấp efficiency (multi-step, quản lý cluster Redshift tốn kém). Không central native, query chậm với volume lớn WAF logs (TB/ngày).

  • ✅ [ĐÚNG] Specify Amazon CloudWatch as the destination for the access logs. Use Amazon CloudWatch Logs Insights to design a query to filter the logs by host.
    Lý do đúng: Như phân tích trên – native, 1-step, query filter host tức thì (ví dụ: fields @timestamp, httpRequest.headers.name | filter httpRequest.headers.value = "example.com"). Hỗ trợ Live Tail, Insights ML anomaly detection (mới 2025+).

  • ❌ [SAI] Specify Amazon CloudWatch as the destination for the access logs. Export the CloudWatch logs to an Amazon S3 bucket. Use Amazon Athena to query the logs and to filter the logs by host.
    Lý do sai: Hoạt động nhưng không efficient nhất – cần export subscription filter (thêm bước cron/export), rồi Athena trên S3 (partitioning schema thủ công). Latency cao (minutes-hours), tốn storage/export cost, phức tạp hơn Logs Insights (AWS re:Invent 2025 ưu tiên Insights cho WAF).

  • ❌ [SAI] Specify Amazon CloudWatch as the destination for the access logs. Use Amazon Redshift Spectrum to query the logs and to filter the logs by host.
    Lý do sai: Redshift Spectrum query S3, không trực tiếp CloudWatch. Phải export logs sang S3 trước → multi-hop phức tạp, cluster Redshift required (không serverless), chi phí cao cho ad-hoc query. Không phù hợp WAF logs semi-structured.

📚 Tài liệu tham khảo (AWS cập nhật 2026)

Hy vọng phân tích giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần ví dụ query cụ thể, hỏi thêm nhé!

Câu 223 Chọn nhiều đáp án
A security engineer is trying to use Amazon EC2 Image Builder to create an image of an EC2 instance. The security engineer has configured the pipeline to send logs to an Amazon S3 bucket. When the security engineer runs the pipeline, the build fails with the following error: "AccessDenied: Access Denied status code: 403".

The security engineer must resolve the error by implementing a solution that complies with best practices for least privilege access.

Which combination of steps will meet these requirements? (Choose two.)
  1. A Ensure that the following policies are attached to the IAM role that the security engineer is using·EC2InstanceProfileForImageBuilder, EC2InstanceProfileForImageBuilderECRContainerBuilds, and AmazonSSMManagedInstanceCore.
  2. B Ensure that the following policies are attached to the instance profile for the EC2 instance: EC2InstanceProfileForImageBuilder, EC2InstanceProfileForImageBuilderECRContainerBuilds, and AmazonSSMManagedInstanceCore.
  3. C Ensure that the AWSImageBuilderFullAccess policy is attached to the instance profile for the EC2 instance.
  4. D Ensure that the security engineer's IAM role has the s3:PutObject permission for the S3 bucket.
  5. E Ensure that the instance profile for the EC2 instance has the s3:PutObject permission for the S3 bucket.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh việc sử dụng Amazon EC2 Image Builder để tạo image từ một EC2 instance. Kỹ sư bảo mật đã cấu hình pipeline để gửi logs (nhật ký) đến một Amazon S3 bucket, nhưng khi chạy pipeline, build thất bại với lỗi "AccessDenied: Access Denied status code: 403".

🔍 Nguyên nhân lỗi chính: Lỗi 403 Access Denied xảy ra vì thiếu quyền truy cập khi Image Builder cố gắng gửi logs đến S3. Trong quy trình Image Builder (theo tài liệu AWS cập nhật đến 2026):

  • Image Builder sẽ tự động khởi chạy một EC2 instance tạm thời (build instance) để thực hiện build image.
  • Instance này cần instance profile (IAM role gắn với instance) có quyền thực hiện các hành động build, bao gồm gửi logs đến S3 nếu được config.
  • Best practices cho least privilege: Chỉ cấp quyền tối thiểu cần thiết, tránh dùng policy full access. Không phải IAM role của kỹ sư console mà là instance profile của build instance chịu trách nhiệm gửi logs.

Yêu cầu chọn 2 steps để khắc phục, tuân thủ least privilege access (quyền hạn nhỏ nhất).

📘 Tài liệu tham khảo:

✅ Đáp án đúng (Chọn 2)

Hai phương án sau là đúng vì chúng tập trung vào instance profile của EC2 build instance – nơi thực sự cần quyền để build image và gửi logs đến S3, đồng thời sử dụng managed policies chuẩn của AWS để đảm bảo least privilege:

  1. Ensure that the following policies are attached to the instance profile for the EC2 instance: EC2InstanceProfileForImageBuilder, EC2InstanceProfileForImageBuilderECRContainerBuilds, and AmazonSSMManagedInstanceCore.
    🛠️ Lý do: Đây là bộ policies managed policy chính thức của AWS dành riêng cho instance profile của build instance trong Image Builder. Chúng cấp quyền tối thiểu để instance có thể build image, hỗ trợ ECR container builds (nếu cần), và SSM để quản lý instance – tránh quyền thừa.

  2. Ensure that the instance profile for the EC2 instance has the s3:PutObject permission for the S3 bucket.
    🛠️ Lý do: Lỗi 403 trực tiếp từ việc gửi logs đến S3, nên instance profile cần quyền s3:PutObject cụ thể cho bucket đó (least privilege). Không cấp cho role khác vì build instance mới là bên thực hiện PutObject.

📋 Giải thích tất cả các phương án (Đúng/Sai)

  • ❌ Ensure that the following policies are attached to the IAM role that the security engineer is using·EC2InstanceProfileForImageBuilder, EC2InstanceProfileForImageBuilderECRContainerBuilds, and AmazonSSMManagedInstanceCore.
    Sai: Các policies này dành cho instance profile của EC2 build instance, không phải IAM role của kỹ sư (console/user role). Role của kỹ sư chỉ cần quyền quản lý Image Builder pipeline (như imagebuilder:StartImagePipeline), không liên quan trực tiếp đến việc gửi logs từ build instance. Gắn nhầm sẽ không giải quyết lỗi 403.

  • ✅ Ensure that the following policies are attached to the instance profile for the EC2 instance: EC2InstanceProfileForImageBuilder, EC2InstanceProfileForImageBuilderECRContainerBuilds, and AmazonSSMManagedInstanceCore.
    Đúng: Như giải thích ở trên, đây là yêu cầu bắt buộc từ AWS docs để instance profile hỗ trợ toàn bộ lifecycle build (bao gồm SSM và ECR). Least privilege vì dùng managed policies tinh gọn.

  • ❌ Ensure that the AWSImageBuilderFullAccess policy is attached to the instance profile for the EC2 instance.
    Sai: Policy AWSImageBuilderFullAccess cấp quyền quá rộng (full access Image Builder), vi phạm nguyên tắc least privilege. AWS khuyến nghị chỉ dùng policies cụ thể như EC2InstanceProfileForImageBuilder thay vì full access.

  • ❌ Ensure that the security engineer's IAM role has the s3:PutObject permission for the S3 bucket.
    Sai: IAM role của kỹ sư không gửi logs; chính build instance (qua instance profile) mới thực hiện s3:PutObject đến bucket. Cấp quyền này cho role kỹ sư không ảnh hưởng đến lỗi và vi phạm least privilege.

  • ✅ Ensure that the instance profile for the EC2 instance has the s3:PutObject permission for the S3 bucket.
    Đúng: Trực tiếp khắc phục lỗi 403 bằng quyền cụ thể, chỉ cho bucket logs. Kết hợp với policies build ở trên để pipeline chạy mượt mà.

🆕 Lưu ý cập nhật 2026: Từ phiên bản Image Builder 2025+, AWS nhấn mạnh instance profile với s3:PutObject cho logging và tích hợp SSM Session Manager để debug an toàn hơn, tránh mở port SSH. Kiểm tra bằng AWS IAM Policy Simulator để verify least privilege! 🚀

Câu 224
A security engineer must use AWS Key Management Service (AWS KMS) to design a key management solution for a set of Amazon Elastic Block Store (Amazon EBS) volumes that contain sensitive data. The solution needs to ensure that the key material automatically expires in 90 days.

Which solution meets these criteria?
  1. A A customer managed key that uses customer provided key material
  2. B A customer managed key that uses AWS provided key material
  3. C An AWS managed key
  4. D Operating system encryption that uses GnuPG
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc thiết kế giải pháp quản lý khóa mã hóa (key management) sử dụng AWS Key Management Service (AWS KMS) cho một tập hợp các volume Amazon Elastic Block Store (Amazon EBS) chứa dữ liệu nhạy cảm. Yêu cầu chính là key material phải tự động hết hạn (expire) sau 90 ngày.

📝 Giải thích rõ ràng:

  • EBS volumes cần được mã hóa bằng KMS để bảo vệ dữ liệu nhạy cảm (sensitive data).
  • Giải pháp phải đảm bảo key material (vật liệu khóa, tức là nội dung thực tế của khóa mã hóa) tự động bị xóa hoặc vô hiệu hóa sau đúng 90 ngày, giúp kiểm soát vòng đời khóa chặt chẽ, giảm rủi ro lộ khóa lâu dài.
  • Đây là tình huống thực tế trong DevOps và Security, nơi cần tuân thủ các tiêu chuẩn như PCI DSS hoặc HIPAA, với tính năng tự động expire chỉ có ở một loại key cụ thể trong KMS (dựa trên phiên bản AWS cập nhật đến 2026, không có thay đổi lớn về tính năng này).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: A customer managed key that uses customer provided key material

Lý do chi tiết 🛠️:

  • Đây là Customer Managed Key (CMK) với customer-provided key material (khóa do khách hàng tự import vào KMS).
  • Khi import key material vào CMK, bạn có thể chỉ định expiration time chính xác (ví dụ: 90 ngày). Sau thời gian này, KMS tự động xóa key material, đưa CMK vào trạng thái Inactive, và không thể sử dụng để mã hóa/giải mã nữa.
  • Hoàn hảo cho EBS volumes vì EBS hỗ trợ mã hóa trực tiếp bằng KMS keys, và tính năng này đảm bảo tuân thủ yêu cầu tự động expire.
  • Không có giải pháp nào khác trong KMS hỗ trợ tự động expire key material một cách linh hoạt như vậy.

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh, kèm giải thích bằng tiếng Việt:

  • A customer managed key that uses customer provided key material
    ✅ Đúng 🏆: Như đã giải thích ở trên, chỉ loại CMK này mới cho phép import key material với tùy chọn expiration date cụ thể (90 ngày). KMS sẽ tự động xóa material sau thời hạn, phù hợp hoàn hảo cho EBS encryption. Đây là best practice cho key rotation và compliance.

  • A customer managed key that uses AWS provided key material
    ❌ Sai 🚫: CMK với key material do AWS cung cấp (AWS-generated) không hỗ trợ tự động expire. Key material tồn tại vĩnh viễn cho đến khi bạn xóa thủ công hoặc rotate key (nhưng rotate chỉ tạo key mới, không expire material cũ tự động). Không đáp ứng yêu cầu 90 ngày.

  • An AWS managed key
    ❌ Sai 🔒: AWS managed keys được AWS quản lý hoàn toàn (dùng cho services như RDS, EBS mặc định), bạn không thể tùy chỉnh expiration hoặc import material. Chúng không expire tự động và thiếu quyền kiểm soát cần thiết cho sensitive data.

  • Operating system encryption that uses GnuPG
    ❌ Sai 💥: GnuPG (GNU Privacy Guard) là công cụ mã hóa cấp file/OS (như dm-crypt/LUKS trên Linux), không liên quan đến AWS KMS hay EBS native encryption. Không hỗ trợ key management tự động expire qua KMS, và không phải giải pháp AWS-native cho EBS volumes.

📘 Tài liệu tham khảo (AWS cập nhật đến 2026)

  • AWS KMS Developer Guide: Importing key material – Chi tiết về expiration cho customer-provided material (xác nhận tự động delete sau expire time).
  • EBS Encryption Docs: Encrypting Amazon EBS volumes with KMS – Hỗ trợ CMK cho volumes.
  • KMS Key Types: AWS managed vs Customer managed keys – Phân biệt rõ ràng các loại key.
  • Exam Topic DOP-C02: Phần Security & Encryption trong AWS Certified DevOps Engineer - Professional (phiên bản 2023+, không thay đổi đến 2026).

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ code Terraform/CLI, hãy hỏi nhé!

Câu 225 Chọn nhiều đáp án
A security engineer is building a Java application that is running on Amazon EC2. The application communicates with an Amazon RDS instance and authenticates with a user name and password.

Which combination of steps can the engineer take to protect the credentials and minimize downtime when the credentials are rotated? (Choose two.)
  1. A Have a database administrator encrypt the credentials and store the ciphertext in Amazon S3. Grant permission to the instance role associated with the EC2 instance to read the object and decrypt the ciphertext.
  2. B Configure a scheduled job that updates the credential in AWS Systems Manager Parameter Store and notifies the engineer that the application needs to be restarted.
  3. C Configure automatic rotation of credentials in AWS Secrets Manager.
  4. D Store the credential in an encrypted string parameter in AWS Systems Manager Parameter Store. Grant permission to the instance role associated with the EC2 instance to access the parameter and the AWS KMS key that is used to encrypt it.
  5. E Configure the Java application to catch a connection failure and make a call to AWS Secrets Manager to retrieve updated credentials when the password is rotated. Grant permission to the instance role associated with the EC2 instance to access Secrets Manager.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm AWS

📖 Nội dung câu hỏi được giải thích rõ ràng:
Câu hỏi tập trung vào một kỹ sư bảo mật (security engineer) đang phát triển ứng dụng Java chạy trên Amazon EC2. Ứng dụng này kết nối với cơ sở dữ liệu Amazon RDS bằng cách sử dụng tên người dùng và mật khẩu (username và password). Yêu cầu chính là tìm kết hợp 2 bước (choose TWO) để:

  • Bảo vệ credentials (tên đăng nhập/mật khẩu) một cách an toàn, tránh lưu trữ plain-text.
  • Giảm thiểu thời gian gián đoạn (minimize downtime) khi thực hiện xoay vòng credentials (rotation) – tức là thay đổi mật khẩu định kỳ mà không làm ứng dụng ngừng hoạt động lâu.

Đây là tình huống thực tế trong DevOps và bảo mật AWS, nơi AWS Secrets Manager là giải pháp lý tưởng cho việc quản lý và xoay vòng bí mật (secrets) động, đặc biệt với RDS (hỗ trợ rotation tự động từ năm 2018 và cập nhật liên tục đến 2026 với tích hợp IAM và KMS nâng cao). Câu hỏi kiểm tra kiến thức về best practices cho credential management, tránh các phương pháp thủ công gây downtime.

✅ Đáp án đúng (chọn 2):

  • Configure automatic rotation of credentials in AWS Secrets Manager.
  • Configure the Java application to catch a connection failure and make a call to AWS Secrets Manager to retrieve updated credentials when the password is rotated. Grant permission to the instance role associated with the EC2 instance to access Secrets Manager.

🛠️ Lý do chọn đáp án đúng:
Kết hợp này sử dụng AWS Secrets Manager – dịch vụ chuyên quản lý secrets với rotation tự động cho RDS (hỗ trợ MySQL, PostgreSQL, v.v.). Bước 1 kích hoạt rotation lambda tự động thay đổi password RDS mà không cần can thiệp thủ công. Bước 2 làm ứng dụng Java thông minh: bắt lỗi kết nối (connection failure), gọi API Secrets Manager lấy credentials mới ngay lập tức qua IAM role của EC2, đảm bảo zero-downtime (ứng dụng reconnect mà không restart). Điều này tuân thủ AWS Well-Architected Framework (Security Pillar) đến năm 2026, giảm rủi ro lộ credentials và tuân thủ compliance như PCI-DSS.

🔍 Giải thích TẤT CẢ các phương án (đúng/sai)

  • ❌ Have a database administrator encrypt the credentials and store the ciphertext in Amazon S3. Grant permission to the instance role associated with the EC2 instance to read the object and decrypt the ciphertext.
    Phương án này sai vì chỉ lưu trữ encrypted trong S3 (sử dụng KMS hoặc SSE), nhưng không hỗ trợ rotation tự động. DBA phải thủ công encrypt/update object mỗi lần rotate, dẫn đến downtime khi app phải reload credentials (cần restart hoặc re-read S3). Không minimize downtime và tăng rủi ro quản lý thủ công.

  • ❌ Configure a scheduled job that updates the credential in AWS Systems Manager Parameter Store and notifies the engineer that the application needs to be restarted.
    Phương án này sai vì sử dụng SSM Parameter Store để lưu/update credentials theo lịch, nhưng yêu cầu restart ứng dụng sau thông báo – trực tiếp vi phạm "minimize downtime". SSM không có rotation tự động cho RDS như Secrets Manager, chỉ là lưu trữ parameter, dễ gây gián đoạn cao.

  • ✅ Configure automatic rotation of credentials in AWS Secrets Manager.
    Phương án này đúng vì Secrets Manager cung cấp rotation tự động qua Lambda functions tích hợp sẵn cho RDS (cấu hình 30 ngày/lần hoặc tùy chỉnh). Nó generate password mới, update RDS, và lưu secrets mới – hoàn toàn tự động, bảo mật cao với KMS encryption, phù hợp minimize downtime khi kết hợp retrieve động.

  • ❌ Store the credential in an encrypted string parameter in AWS Systems Manager Parameter Store. Grant permission to the instance role associated with the EC2 instance to access the parameter and the AWS KMS key that is used to encrypt it.
    Phương án này sai dù an toàn (encrypted với KMS, IAM access), nhưng SSM Parameter Store không hỗ trợ rotation tự động cho RDS. App phải polling hoặc restart để lấy giá trị mới sau rotate thủ công, gây downtime. Secrets Manager vượt trội hơn cho use case này (SSM phù hợp config hơn secrets động).

  • ✅ Configure the Java application to catch a connection failure and make a call to AWS Secrets Manager to retrieve updated credentials when the password is rotated. Grant permission to the instance role associated with the EC2 instance to access Secrets Manager.
    Phương án này đúng vì làm app resilient: Sử dụng AWS SDK for Java (GetSecretValue API) để fetch credentials realtime khi connection fail (do rotation). IAM role EC2 cấp quyền secretsmanager:GetSecretValue, tránh hardcode. Kết hợp với rotation tự động → seamless reconnect, zero-downtime thực tế (best practice từ AWS re:Invent 2023-2026).

📘 Tài liệu tham khảo (cập nhật đến 2026):

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm ví dụ code Java, hãy hỏi nhé!

Câu 226 Chọn nhiều đáp án
A company uses SAML federation to grant users access to AWS accounts. A company workload that is in an isolated AWS account runs on immutable infrastructure with no human access to Amazon EC2. The company requires a specialized user known as a break glass user to have access to the workload AWS account and instances in the case of SAML errors. A recent audit discovered that the company did not create the break glass user for the AWS account that contains the workload.

The company must create the break glass user. The company must log any activities of the break glass user and send the logs to a security team.

Which combination of solutions will meet these requirements? (Choose two.)
  1. A Create a local individual break glass IAM user for the security team. Create a trail in AWS CloudTrail that has Amazon CloudWatch Logs turned on. Use Amazon EventBridge to monitor local user activities.
  2. B Create a break glass EC2 key pair for the AWS account. Provide the key pair to the security team. Use AWS CloudTrail to monitor key pair activity. Send notifications to the security team by using Amazon Simple Notification Service (Amazon SNS).
  3. C Create a break glass IAM role for the account. Allow security team members to perform the AssumeRoleWithSAML operation. Create an AWS CloudTrail trail that has Amazon CloudWatch Logs turned on. Use Amazon EventBridge to monitor security team activities.
  4. D Create a local individual break glass IAM user on the operating system level of each workload instance. Configure unrestricted security groups on the instances to grant access to the break glass IAM users.
  5. E Configure AWS Systems Manager Session Manager for Amazon EC2. Configure an AWS CloudTrail filter based on Session Manager. Send the results to an Amazon Simple Notification Service (Amazon SNS) topic.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào tình huống một công ty sử dụng SAML federation để cấp quyền truy cập vào các tài khoản AWS. Workload chạy trên immutable infrastructure (cơ sở hạ tầng không thay đổi, không có quyền truy cập con người trực tiếp vào Amazon EC2) trong một tài khoản AWS cô lập. Công ty cần một break glass user chuyên biệt để truy cập tài khoản workload và các instance EC2 khi xảy ra lỗi SAML. Kết quả audit cho thấy chưa tạo break glass user cho tài khoản này.

Yêu cầu chính:

  • Tạo break glass user.
  • Log mọi hoạt động của break glass user và gửi log đến security team.

Câu hỏi yêu cầu chọn TWO giải pháp kết hợp để đáp ứng (chọn hai phương án đúng). Đây là best practice trong AWS để xử lý tình huống khẩn cấp (break glass) khi federation thất bại, đảm bảo truy cập khẩn cấp mà vẫn audit đầy đủ qua AWS CloudTrail, Amazon CloudWatch, EventBridge, hoặc SNS. Kiến thức dựa trên AWS cập nhật 2024-2026: IAM best practices khuyến nghị local IAM users cho break glass, kết hợp SSM Session Manager cho access EC2 không cần SSH keys (immutable infra).

📘 Tài liệu tham khảo:

✅ Đáp án đúng (chọn TWO)

Các phương án đúng là phương án 1 và phương án 5, vì chúng tạo break glass user local IAM (không phụ thuộc SAML), hỗ trợ truy cập EC2 immutable qua SSM (không cần SSH), và log/notify đầy đủ qua CloudTrail + EventBridge/SNS. Điều này đảm bảo tính sẵn sàng cao khi SAML lỗi, tuân thủ least privilege và auditing.

Lý do chọn:

  • 🛠️ Phương án 1: Tạo IAM user local cá nhân (không federated), CloudTrail trail với CloudWatch Logs để ghi log, EventBridge monitor hoạt động local user → Hoàn hảo cho break glass account-level access.
  • 🛠️ Phương án 5: SSM Session Manager cho EC2 access (không key/SSH, phù hợp immutable), CloudTrail filter SSM events gửi SNS → Log và notify security team instance-level.

📋 Phân tích chi tiết tất cả các phương án

  • Create a local individual break glass IAM user for the security team. Create a trail in AWS CloudTrail that has Amazon CloudWatch Logs turned on. Use Amazon EventBridge to monitor local user activities.
    ✅ Đúng. Đây là giải pháp chuẩn cho break glass: IAM user local (không dùng SAML, tránh lỗi federation). CloudTrail trail lưu log vào CloudWatch Logs, EventBridge filter/monitor events của local users (ví dụ: ConsoleLogin, IAM actions) để alert security team real-time. Phù hợp account-level access, auditing đầy đủ theo AWS best practices 2026.

  • Create a break glass EC2 key pair for the AWS account. Provide the key pair to the security team. Use AWS CloudTrail to monitor key pair activity. Send notifications to the security team by using Amazon Simple Notification Service (Amazon SNS).
    ❌ Sai. Key pair chỉ dùng SSH/RDP EC2, không phải "user" AWS account-level (không access IAM/Console). Immutable infra tránh SSH keys (security risk). CloudTrail không monitor "key pair activity" chi tiết (chỉ CreateKeyPair events), không đủ log toàn diện. Không đáp ứng break glass user yêu cầu.

  • Create a break glass IAM role for the account. Allow security team members to perform the AssumeRoleWithSAML operation. Create an AWS CloudTrail trail that has Amazon CloudWatch Logs turned on. Use Amazon EventBridge to monitor security team activities.
    ❌ Sai. IAM role dùng AssumeRoleWithSAML vẫn phụ thuộc SAML → Khi SAML lỗi, không assume được (mâu thuẫn yêu cầu). Break glass phải độc lập federation. CloudTrail/EventBridge tốt nhưng không giải quyết vấn đề core.

  • Create a local individual break glass IAM user on the operating system level of each workload instance. Configure unrestricted security groups on the instances to grant access to the break glass IAM users.
    ❌ Sai. "Local user on OS level" là OS user (không IAM AWS), phải tạo thủ công mỗi instance → Vi phạm immutable infra (không thay đổi). Unrestricted SG (open ports) tăng risk attack surface, không liên quan IAM users (IAM không grant OS access trực tiếp). Không log AWS-level, không scalable.

  • Configure AWS Systems Manager Session Manager for Amazon EC2. Configure an AWS CloudTrail filter based on Session Manager. Send the results to an Amazon Simple Notification Service (Amazon SNS) topic.
    ✅ Đúng. SSM Session Manager cho phép access EC2 qua browser/IAM không cần key/SSH (hoàn hảo immutable, no human access). CloudTrail capture SSM events (SessionStart/Stop), filter gửi SNS notify security team real-time. Kết hợp IAM user (từ phương án 1) để authorize SSM, đáp ứng instance access + logging. AWS khuyến nghị 2026 cho secure bastionless access.

Câu 227 Chọn nhiều đáp án
A security engineer is working with a product team building a web application on AWS. The application uses Amazon S3 to host the static content, Amazon API Gateway to provide RESTful services, and Amazon DynamoDB as the backend data store. The users already exist in a directory that is exposed through a SAML identity provider.

Which combination of the following actions should the engineer take to allow users to be authenticated into the web application and call APIs? (Choose three.)
  1. A Create a custom authorization service using AWS Lambda.
  2. B Configure a SAML identity provider in Amazon Cognito to map attributes to the Amazon Cognito user pool attributes.
  3. C Configure the SAML identity provider to add the Amazon Cognito user pool as a relying party.
  4. D Configure an Amazon Cognito identity pool to integrate with social login providers.
  5. E Update DynamoDB to store the user email addresses and passwords.
  6. F Update API Gateway to use a COGNITO_USER_POOLS authorizer.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc tích hợp xác thực (authentication) và ủy quyền (authorization) cho một ứng dụng web trên AWS. Ứng dụng sử dụng:

  • Amazon S3 để host nội dung tĩnh (static content).
  • Amazon API Gateway để cung cấp các RESTful API.
  • Amazon DynamoDB làm cơ sở dữ liệu backend.
  • Người dùng (users) đã tồn tại trong một directory được expose qua SAML Identity Provider (IdP) (như Active Directory Federation Services - ADFS hoặc Okta).

Mục tiêu: Cho phép người dùng đăng nhập vào web app và gọi API một cách an toàn. Cần chọn 3 hành động kết hợp để thực hiện điều này.

Giải pháp chính dựa trên Amazon Cognito – dịch vụ quản lý danh tính người dùng trên AWS (cập nhật đến năm 2026, Cognito hỗ trợ SAML 2.0 đầy đủ với user pools và identity pools). Quy trình chuẩn:

  1. Sử dụng Cognito User Pool làm trung gian để federate với SAML IdP.
  2. Ánh xạ thuộc tính (attributes) từ SAML IdP sang Cognito.
  3. Cấu hình API Gateway sử dụng Cognito User Pool authorizer để bảo vệ API. ✅ Không cần lưu mật khẩu trong DynamoDB (vi phạm best practices bảo mật) và không dùng identity pools cho social login vì đây là SAML enterprise.

✅ Đáp án đúng (Chọn 3)

Các đáp án đúng là:

  • Configure a SAML identity provider in Amazon Cognito to map attributes to the Amazon Cognito user pool attributes.
  • Configure the SAML identity provider to add the Amazon Cognito user pool as a relying party.
  • Update API Gateway to use a COGNITO_USER_POOLS authorizer.

Lý do lựa chọn: 🛠️ Kết hợp này tạo luồng xác thực SAML federation hoàn chỉnh:

  • Cognito User Pool đóng vai trò Identity Provider (IdP) trung gian hoặc Service Provider (SP) nhận token từ SAML IdP.
  • Người dùng đăng nhập qua SAML IdP → Nhận JWT token từ Cognito → Sử dụng token này gọi API Gateway (qua authorizer).
  • Đảm bảo zero-trust security, không lưu credentials trong app, hỗ trợ MFA/attributes mapping. Đây là cách best practice theo AWS Well-Architected Framework (Security Pillar, cập nhật 2026).

📋 Phân tích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai dựa trên tính phù hợp với yêu cầu (SAML integration cho web app + API calls).

  • ❌ Create a custom authorization service using AWS Lambda.
    Sai vì: Không cần thiết và phức tạp hóa kiến trúc. Cognito đã hỗ trợ sẵn authorizers cho API Gateway (như COGNITO_USER_POOLS hoặc Lambda authorizer built-in). Tạo custom Lambda chỉ dùng khi có yêu cầu đặc biệt (custom logic), nhưng ở đây SAML + Cognito đủ. Vi phạm nguyên tắc least privilege và tăng chi phí vận hành. 🛑

  • ✅ Configure a SAML identity provider in Amazon Cognito to map attributes to the Amazon Cognito user pool attributes.
    Đúng vì: Trong Cognito User Pool console, bạn thêm SAML provider (IdP metadata XML), rồi map attributes (ví dụ: SAML email → Cognito email). Điều này cho phép Cognito nhận và chuẩn hóa claims từ SAML IdP, tạo JWT token cho user. Bắt buộc cho federation. 🛠️ (Cập nhật 2026: Hỗ trợ OIDC/SAML với attribute mapping động).

  • ✅ Configure the SAML identity provider to add the Amazon Cognito user pool as a relying party.
    Đúng vì: SAML IdP (như ADFS/Okta) cần config Cognito User Pool làm Relying Party (RP/SP) bằng cách upload Cognito metadata XML (từ User Pool > Federated Identities). Điều này thiết lập trust relationship hai chiều, cho phép SAML assertions được gửi đến Cognito. Thiếu bước này, federation thất bại. 🔗

  • ❌ Configure an Amazon Cognito identity pool to integrate with social login providers.
    Sai vì: Identity Pool dùng để trao đổi token lấy AWS credentials tạm thời (cho truy cập S3/DynamoDB), không phải authenticate user vào web app hoặc API Gateway. Hơn nữa, social login (Google/Facebook) không liên quan đến SAML enterprise directory. Dùng identity pool ở đây chỉ phù hợp nếu cần AWS IAM roles, nhưng câu hỏi tập trung vào API calls qua authorizer. 🚫

  • ❌ Update DynamoDB to store the user email addresses and passwords.
    Sai vì: Vi phạm nghiêm trọng AWS security best practices (Shared Responsibility Model). Không bao giờ lưu passwords plaintext/hashed trong DynamoDB – dễ bị breach, không hỗ trợ MFA/federation. Cognito xử lý toàn bộ user directory và hashing (bcrypt/PBKDF2). Điều này làm app kém scalable và không compliant (GDPR/SOC2). ⚠️

  • ✅ Update API Gateway to use a COGNITO_USER_POOLS authorizer.
    Đúng vì: Sau khi user authenticate qua Cognito (từ SAML), họ nhận ID/access token. Config authorizer loại COGNITO_USER_POOLS trên API Gateway để validate JWT token tự động, kiểm tra scopes/claims trước khi proxy đến backend (DynamoDB). Hỗ trợ caching, rate limiting. Hoàn hảo cho RESTful APIs bảo mật. 🚀 (Cập nhật 2026: Tích hợp Lambda@Edge cho global auth).

📘 Tài liệu tham khảo

  • AWS Cognito Developer Guide: Federation with SAML (Attribute mapping & Relying Party).
  • API Gateway Docs: Cognito User Pool Authorizer.
  • AWS Well-Architected Framework (2026): Security Pillar – Identity Federation chapter.
  • Sample Architecture: AWS blog "Secure API Gateway with Cognito SAML" (tìm kiếm AWS re:Post).

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 💪 Nếu cần lab thực hành, dùng AWS Free Tier với CloudFormation template Cognito-SAML.

Câu 228 Chọn nhiều đáp án
A company needs to improve its ability to identify and prevent IAM policies that grant public access or cross-account access to resources. The company has implemented AWS Organizations and has started using AWS Identity and Access Management Access Analyzer to refine overly broad access to accounts in the organization.

A security engineer must automate a response in the company's organization for any newly created policies that are overly permissive. The automation must remediate external access and must notify the company's security team.

Which combination of steps should the security engineer take to meet these requirements? (Choose three.)
  1. A Create an AWS Step Functions state machine that checks the resource type in the finding and adds an explicit Deny statement in the trust policy for the IAM role. Configure the state machine to publish a notification to an Amazon Simple Notification Service (Amazon SNS) topic.
  2. B Create an AWS Batch job that forwards any resource type findings to an AWS Lambda function. Configure the Lambda function to add an explicit Deny statement in the trust policy for the IAM role. Configure the AWS Batch job to publish a notification to an Amazon Simple Notification Service (Amazon SNS) topic.
  3. C In Amazon EventBridge, create an event rule that matches active IAM Access Analyzer findings and invokes AWS Step Functions for resolution.
  4. D In Amazon CloudWatch, create a metric filter that matches active IAM Access Analyzer findings and invokes AWS Batch for resolution.
  5. E Create an Amazon Simple Queue Service (Amazon SQS) queue. Configure the queue to forward a notification to the security team that an external principal has been granted access to the specific IAM role and has been blocked.
  6. F Create an Amazon Simple Notification Service (Amazon SNS) topic for external or cross-account access notices. Subscribe the security team's email addresses to the topic.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào việc tự động hóa phản hồi cho các chính sách IAM quá permissive (quá rộng rãi), đặc biệt là những chính sách cấp quyền truy cập công khai (public access) hoặc chéo tài khoản (cross-account access) trong tổ chức AWS Organizations. Công ty đã triển khai AWS Organizations và IAM Access Analyzer để phát hiện và tinh chỉnh quyền truy cập rộng.

Yêu cầu chính của security engineer:

  • Tự động phát hiện các policy mới tạo ra findings "active" từ Access Analyzer (tức là các vấn đề external access chưa được giải quyết).
  • Remediate (khắc phục) bằng cách chặn external access (ví dụ: thêm explicit Deny vào trust policy của IAM role).
  • Notify đội ngũ security.
  • Chọn BAI bước kết hợp (choose three) để đạt yêu cầu này.

Mục tiêu tổng thể: Xây dựng workflow event-driven, sử dụng dịch vụ serverless để phát hiện sự kiện → xử lý tự động → thông báo, đảm bảo an ninh IAM mà không cần can thiệp thủ công. Kiến thức dựa trên phiên bản AWS mới nhất (2024-2026), nơi IAM Access Analyzer tích hợp sâu với EventBridge để emit events cho findings active/high-risk.

✅ Đáp án đúng và lý do lựa chọn

Các đáp án đúng là 3 phương án sau (phù hợp với yêu cầu chọn THREE):

  • In Amazon EventBridge, create an event rule that matches active IAM Access Analyzer findings and invokes AWS Step Functions for resolution.
  • Create an AWS Step Functions state machine that checks the resource type in the finding and adds an explicit Deny statement in the trust policy for the IAM role. Configure the state machine to publish a notification to an Amazon Simple Notification Service (Amazon SNS) topic.
  • Create an Amazon Simple Notification Service (Amazon SNS) topic for external or cross-account access notices. Subscribe the security team's email addresses to the topic.

Lý do chọn 🛠️:

  • Kết hợp này tạo workflow hoàn chỉnh: EventBridge trigger từ findings active của Access Analyzer → Step Functions orchestrate remediation (kiểm tra resource, update trust policy với Deny, notify SNS) → SNS gửi email thông báo. Đây là giải pháp serverless, scalable, event-driven chuẩn AWS best practice cho automation security (theo AWS Well-Architected Framework - Security Pillar, cập nhật 2024).

📋 Phân tích từng phương án

Dưới đây là phân tích TẤT CẢ 6 phương án, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá ✅ (đúng, phù hợp yêu cầu) hoặc ❌ (sai, không phù hợp), kèm giải thích chi tiết bằng tiếng Việt.

  • ✅ In Amazon EventBridge, create an event rule that matches active IAM Access Analyzer findings and invokes AWS Step Functions for resolution.
    Giải thích: Đây là bước trigger chính xác! IAM Access Analyzer (phiên bản mới nhất 2024+) emit CloudTrail events cho findings active (external/public access). EventBridge rule match pattern này (ví dụ: detail.type: "ExternalAccess" hoặc status: "Active") và invoke Step Functions để resolve. Không dùng CloudWatch vì findings không phải log/metrics. Hoàn hảo cho event-driven automation. 🧩

  • ❌ In Amazon CloudWatch, create a metric filter that matches active IAM Access Analyzer findings and invokes AWS Batch for resolution.
    Giải thích: Sai hoàn toàn về dịch vụ! CloudWatch metric filter dùng cho CloudWatch Logs (ví dụ: lọc log patterns), không phải findings từ Access Analyzer (là event-based qua EventBridge/CloudTrail). AWS Batch là batch computing (chạy job lớn), không phù hợp remediation real-time IAM. Không scalable cho security response. 🚫

  • ❌ Create an AWS Batch job that forwards any resource type findings to an AWS Lambda function. Configure the Lambda function to add an explicit Deny statement in the trust policy for the IAM role. Configure the AWS Batch job to publish a notification to an Amazon Simple Notification Service (Amazon SNS) topic.
    Giải thích: Không hiệu quả và thừa thãi! AWS Batch dành cho compute-intensive batch jobs (như ML training), không phải event-driven remediation IAM. Forward sang Lambda là rối rắm, tốn chi phí; Step Functions tốt hơn cho orchestration. Không match best practice cho Access Analyzer findings. 💥

  • ✅ Create an AWS Step Functions state machine that matches active IAM Access Analyzer findings and invokes AWS Step Functions for resolution. (Lưu ý: Đây là phương án gốc, nhưng trong câu hỏi là "Create an AWS Step Functions state machine that checks the resource type in the finding and adds an explicit Deny statement in the trust policy for the IAM role. Configure the state machine to publish a notification to an Amazon Simple Notification Service (Amazon SNS) topic.")
    Giải thích: Bước remediation cốt lõi! Step Functions orchestrate workflow: Parse finding (từ EventBridge), check resource (IAM role/policy), dùng Lambda/SSM để update trust policy thêm Deny external principals (ví dụ: "Principal": {"AWS": "*"}), rồi publish SNS. Durable, retryable, visual – lý tưởng cho DevOps automation IAM (Express Workflows cho low-latency). 🔥

  • ❌ Create an Amazon Simple Queue Service (Amazon SQS) queue. Configure the queue to forward a notification to the security team that an external principal has been granted access to the specific IAM role and has been blocked.
    Giải thích: Không phù hợp cho notification! SQS là message queue (pull-based, cho app-to-app), không hỗ trợ native email subscription như SNS. Notify team cần push (email/SMS), SQS yêu cầu polling Lambda/consumer – phức tạp thừa. SNS là lựa chọn chuẩn cho alerting security. 📧❌

  • ✅ Create an Amazon Simple Notification Service (Amazon SNS) topic for external or cross-account access notices. Subscribe the security team's email addresses to the topic.
    Giải thích: Bước notify hoàn hảo! SNS topic nhận message từ Step Functions/Lambda, subscribe email trực tiếp (raw/JSON format), hỗ trợ fan-out đến nhiều endpoint. Tích hợp IAM policy cho secure publishing. Đáp ứng "notify the company's security team" một cách đơn giản, cost-effective. 📱

📘 Tài liệu tham khảo

Giải pháp này 100% production-ready, đảm bảo zero-trust cho IAM! 🚀 Nếu cần code sample, hỏi thêm nhé!

Câu 229
A security engineer is configuring a mechanism to send an alert when three or more failed sign-in attempts to the AWS Management Console occur during a 5-minute period. The security engineer creates a trail in AWS CloudTrail to assist in this work.

Which solution will meet these requirements?
  1. A In CloudTrail, turn on Insights events on the trail. Configure an alarm on the insight with eventName matching ConsoleLogin and errorMessage matching "Failed authentication''. Configure a threshold of 3 and a period of 5 minutes.
  2. B Configure CloudTrail to send events to Amazon CloudWatch Logs. Create a metric filter for the relevant log group. Create a filter pattern with eventName matching ConsoleLogin and errorMessage matching "Failed authentication". Create a CloudWatch alarm with a threshold of 3 and a period of 5 minutes.
  3. C Create an Amazon Athena table from the CloudTrail events. Run a query for eventName matching ConsoleLogin and for errorMessage matching "Failed authentication". Create a notification action from the query to send an Amazon Simple Notification Service (Amazon SNS) notification when the count equals 3 within a period of 5 minutes.
  4. D In AWS Identity and Access Management Access Analyzer, create a new analyzer. Configure the analyzer to send an Amazon Simple Notification Service (Amazon SNS) notification when a failed sign-in event occurs 3 times for any IAM user within a period of 5 minutes.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một security engineer đang thiết lập cơ chế gửi cảnh báo (alert) khi có ít nhất 3 lần đăng nhập thất bại (failed sign-in attempts) vào AWS Management Console xảy ra trong khoảng thời gian 5 phút. Họ đã tạo một trail trong AWS CloudTrail để hỗ trợ công việc này.
Mục tiêu chính: Tìm giải pháp thời gian thực (near real-time), sử dụng CloudTrail để phát hiện sự kiện ConsoleLogin với lỗi "Failed authentication", và kích hoạt alarm dựa trên ngưỡng 3 lần/5 phút.
🛠️ Yêu cầu kỹ thuật: Giải pháp phải tận dụng dữ liệu log từ CloudTrail, xử lý metric hoặc pattern matching, và tích hợp với alarm/notification để đáp ứng yêu cầu bảo mật brute-force attack detection trên Management Console (cập nhật AWS 2023-2026: CloudTrail hỗ trợ real-time delivery qua CloudWatch Logs cho các trường hợp này).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Configure CloudTrail to send events to Amazon CloudWatch Logs. Create a metric filter for the relevant log group. Create a filter pattern with eventName matching ConsoleLogin and errorMessage matching "Failed authentication". Create a CloudWatch alarm with a threshold of 3 and a period of 5 minutes.

Lý do chọn đáp án này (🛠️ Giải pháp chuẩn AWS):

  • CloudTrail trail gửi log trực tiếp đến CloudWatch Logs (hỗ trợ near real-time delivery, latency ~5-15 phút).
  • Metric filter trên log group lọc chính xác pattern: eventName = "ConsoleLogin" và errorMessage = "Failed authentication" (xem AWS docs: failed ConsoleLogin logs có trường này).
  • CloudWatch Alarm đặt threshold 3 occurrences trong period 5 phút, kích hoạt SNS/email khi vượt ngưỡng → hoàn hảo cho yêu cầu real-time alerting.
  • Đây là best practice cho security monitoring (AWS Well-Architected Security Pillar).
    📘 Tài liệu tham khảo:
  • AWS CloudTrail User Guide: Sending CloudTrail Events to CloudWatch Logs (cập nhật 2024).
  • CloudWatch Logs Metric Filters for CloudTrail (ví dụ pattern cho failed logins).
  • CloudWatch Alarms.

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn (giữ nguyên văn bản gốc tiếng Anh). Tôi đánh dấu ✅ đúng hoặc ❌ sai, kèm lý do bằng tiếng Việt rõ ràng:

  • In CloudTrail, turn on Insights events on the trail. Configure an alarm on the insight with eventName matching ConsoleLogin and errorMessage matching "Failed authentication''. Configure a threshold of 3 and a period of 5 minutes.
    ❌ Sai: CloudTrail Insights chỉ phát hiện unusual API activity (như spikes bất thường), không hỗ trợ filter cụ thể eventName hoặc errorMessage cho failed logins, và không có alarm trực tiếp trên insight (Insights tạo events riêng, phải dùng CloudWatch Events/Lambda để xử lý). Không đáp ứng threshold chính xác 3/5 phút cho ConsoleLogin failures.
    🧩 Vấn đề: Insights dành cho anomaly detection, không phải pattern matching chi tiết (AWS docs 2024 xác nhận).

  • Configure CloudTrail to send events to Amazon CloudWatch Logs. Create a metric filter for the relevant log group. Create a filter pattern with eventName matching ConsoleLogin and errorMessage matching "Failed authentication". Create a CloudWatch alarm with a threshold of 3 and a period of 5 minutes.
    ✅ Đúng: Như giải thích ở phần trên, đây là giải pháp hoàn chỉnh, real-time, tận dụng metric filter để đếm occurrences và alarm threshold chính xác.

  • Create an Amazon Athena table from the CloudTrail events. Run a query for eventName matching ConsoleLogin and for errorMessage matching "Failed authentication". Create a notification action from the query to send an Amazon Simple Notification Service (Amazon SNS) notification when the count equals 3 within a period of 5 minutes.
    ❌ Sai: Athena là công cụ query batch trên S3 (không real-time, delay hàng giờ/ngày), không hỗ trợ notification action tự động từ query cho threshold thời gian thực (5 phút). Phải dùng scheduled queries (AWS Glue/QuickSight), không phù hợp cho alerting kịp thời.
    🧩 Vấn đề: Athena cho phân tích lịch sử, không phải monitoring live (docs Athena 2025: no built-in alarms).

  • In AWS Identity and Access Management Access Analyzer, create a new analyzer. Configure the analyzer to send an Amazon Simple Notification Service (Amazon SNS) notification when a failed sign-in event occurs 3 times for any IAM user within a period of 5 minutes.
    ❌ Sai: IAM Access Analyzer phân tích policy permissions và external access findings (như S3 buckets public), không theo dõi failed sign-ins hoặc ConsoleLogin events từ CloudTrail. Không hỗ trợ threshold cho login failures.
    🧩 Vấn đề: Sai công cụ hoàn toàn (docs IAM Access Analyzer 2024: focus on policy validation, không phải login monitoring).

Kết luận 💡: Giải pháp đúng nhấn mạnh tích hợp CloudTrail + CloudWatch Logs + Metric Filter + Alarm – chuẩn AWS DevOps/Security cho brute-force detection trên Console (DOPE exam topic). Nếu triển khai thực tế, test pattern filter trước! 🚀

Câu 230 Chọn nhiều đáp án
A company's security engineer is developing an incident response plan to detect suspicious activity in an AWS account for VPC hosted resources. The security engineer needs to provide visibility for as many AWS Regions as possible.

Which combination of steps will meet these requirements MOST cost-effectively? (Choose two.)
  1. A Turn on VPC Flow Logs for all VPCs in the account.
  2. B Activate Amazon GuardDuty across all AWS Regions.
  3. C Activate Amazon Detective across all AWS Regions.
  4. D Create an Amazon Simple Notification Service (Amazon SNS) topic. Create an Amazon EventBridge rule that responds to findings and publishes the findings to the SNS topic.
  5. E Create an AWS Lambda function. Create an Amazon EventBridge rule that invokes the Lambda function to publish findings to Amazon Simple Email Service (Amazon SES).
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào việc xây dựng kế hoạch phản ứng sự cố (incident response plan) để phát hiện hoạt động đáng ngờ (suspicious activity) trong tài khoản AWS, đặc biệt dành cho tài nguyên được lưu trữ trong VPC (VPC hosted resources). Kỹ sư bảo mật cần cung cấp khả năng quan sát (visibility) cho nhiều AWS Region nhất có thể, đồng thời phải tiết kiệm chi phí nhất (MOST cost-effectively). Đây là câu hỏi chọn hai bước kết hợp (Choose two).

Mục tiêu chính:

  • Phát hiện threat tự động, đa Region.
  • Tối ưu chi phí: Tránh các giải pháp tốn kém như log chi tiết hoặc dịch vụ phân tích sâu.
  • Phù hợp với GuardDuty (dịch vụ phát hiện threat hàng đầu của AWS, hỗ trợ multi-Region tự động).

✅ Đáp án đúng và lý do lựa chọn

Hai đáp án đúng là:

  1. Activate Amazon GuardDuty across all AWS Regions.
  2. Create an Amazon Simple Notification Service (Amazon SNS) topic. Create an Amazon EventBridge rule that responds to findings and publishes the findings to the SNS topic.

Lý do lựa chọn:

  • 🛡️ GuardDuty là dịch vụ threat detection tự động, phân tích hàng triệu điểm dữ liệu từ CloudTrail, VPC Flow Logs, DNS logs... mà không cần cấu hình thủ công nhiều. Khi kích hoạt ở một Region, nó có thể giám sát đa Region (multi-Region findings), bao gồm VPC resources, với chi phí dựa trên volume phân tích (rẻ hơn so với log thủ công). Đây là cách cost-effective nhất để có visibility rộng.
  • 📨 SNS + EventBridge là cách tiếp nhận thông báo findings (từ GuardDuty) một cách tự động và rẻ tiền. EventBridge (trước là CloudWatch Events) route findings trực tiếp đến SNS topic, chi phí thấp (dựa trên số events), dễ scale đa Region, hỗ trợ incident response nhanh chóng.
  • Kết hợp này toàn diện, tiết kiệm: GuardDuty detect → EventBridge route → SNS notify (email/SMS/team). Không cần Lambda hay SES phức tạp hơn.

📋 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Tôi đánh dấu ✅ cho đúng, ❌ cho sai, kèm giải thích rõ ràng dựa trên kiến thức AWS mới nhất (2026: GuardDuty hỗ trợ Malware Protection, S3 Protection đa Region; EventBridge tích hợp sâu hơn với Bedrock).

  • ❌ Turn on VPC Flow Logs for all VPCs in the account.
    ❌ Sai: VPC Flow Logs chỉ ghi lại traffic network chi tiết per VPC/per Region, phải enable thủ công cho tất cả VPC → chi phí cao (dựa trên GB dữ liệu log, lưu trữ CloudWatch Logs/S3). Không phải threat detection tự động, chỉ cung cấp raw data cần phân tích thêm. Không cost-effective cho multi-Region visibility rộng.

  • ✅ Activate Amazon GuardDuty across all AWS Regions.
    ✅ Đúng: GuardDuty tự động detect suspicious activity (malware, recon, crypto-mining) từ VPC/DNS/CloudTrail multi-Region chỉ với một lần enable (sau đó enable findings multi-Region). Chi phí thấp (pay-per-analysis, free trial 30 ngày), lý tưởng cho incident response mà không cần quản lý log thủ công. Phù hợp nhất cho VPC resources.

  • ❌ Activate Amazon Detective across all AWS Regions.
    ❌ Sai: Detective là dịch vụ investigation graph-based (xây dựng biểu đồ hoạt động từ log), không phải primary detection. Phải enable trên Graph (data source) per Region, chi phí cao (dựa trên GB ingested + queries), dùng sau khi có findings (từ GuardDuty). Không cost-effective cho bước detect ban đầu.

  • ✅ Create an Amazon Simple Notification Service (Amazon SNS) topic. Create an Amazon EventBridge rule that responds to findings and publishes the findings to the SNS topic.
    ✅ Đúng: EventBridge tự động capture GuardDuty findings (event source) và push đến SNS topic với chi phí gần như zero cho low-volume (pay-per-event, <$1/million). SNS hỗ trợ notify đa kênh (email, SMS, Lambda). Cost-effective nhất cho alerting multi-Region, không cần code.

  • ❌ Create an AWS Lambda function. Create an Amazon EventBridge rule that invokes the Lambda function to publish findings to Amazon Simple Email Service (Amazon SES).
    ❌ Sai: Cách này phức tạp và đắt hơn: EventBridge invoke Lambda (chi phí invocation + duration), Lambda gửi qua SES (có quota/email cost). Dễ error (cold start), không scale tốt bằng SNS trực tiếp. SES chỉ gửi email, kém linh hoạt cho incident response.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ thực hành, hãy hỏi nhé!