Ngân hàng đề — AWS Certified Security Specialty

Tìm thấy 445 câu.

Câu 241
A security engineer wants to use Amazon Simple Notification Service (Amazon SNS) to send email alerts to a company's security team for Amazon GuardDuty findings that have a High severity level. The security engineer also wants to deliver these findings to a visualization tool for further examination.

Which solution will meet these requirements?
  1. A Set up GuardDuty to send notifications to an Amazon CloudWatch alarm with two targets in CloudWatch. From CloudWatch, stream the findings through Amazon Kinesis Data Streams into an Amazon Open Search Service domain as the first target for delivery. Use Amazon QuickSight to visualize the findings. Use OpenSearch queries for further analysis. Deliver email alerts to the security team by configuring an SNS topic as a second target for the CloudWatch alarm. Use event pattern matching with an Amazon EventBridge event rule to send only High severity findings in the alerts.
  2. B Set up GuardDuty to send notifications to AWS CloudTrail with two targets in CloudTrail. From CloudTrail, stream the findings through Amazon Kinesis Data Firehose into an Amazon OpenSearch Service domain as the first target for delivery. Use OpenSearch Dashboards to visualize the findings. Use OpenSearch queries for further analysis. Deliver email alerts to the security team by configuring an SNS topic as a second target for CloudTrail. Use event pattern matching with a CloudTrail event rule to send only High severity findings in the alerts.
  3. C Set up GuardDuty to send notifications to Amazon EventBridge with two targets. From EventBridge, stream the findings through Amazon Kinesis Data Firehose into an Amazon OpenSearch Service domain as the first target for delivery. Use OpenSearch Dashboards to visualize the findings. Use OpenSearch queries for further analysis. Deliver email alerts to the security team by configuring an SNS topic as a second target for EventBridge. Use event pattern matching with an EventBridge event rule to send only High severity findings in the alerts.
  4. D Set up GuardDuty to send notifications to Amazon EventBridge with two targets. From EventBridge, stream the findings through Amazon Kinesis Data Streams into an Amazon OpenSearch Service domain as the first target for delivery. Use Amazon QuickSight to visualize the findings. Use OpenSearch queries for further analysis. Deliver email alerts to the security team by configuring an SNS topic as a second target for EventBridge. Use event pattern matching with an EventBridge event rule to send only High severity findings in the alerts.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc thiết lập hệ thống thông báo và trực quan hóa cho Amazon GuardDuty – dịch vụ phát hiện mối đe dọa bảo mật trên AWS. Cụ thể:

  • Một kỹ sư bảo mật muốn sử dụng Amazon SNS để gửi email alerts cho đội ngũ bảo mật về các findings (phát hiện) có mức độ nghiêm trọng High severity.
  • Đồng thời, cần deliver findings đến một visualization tool để phân tích sâu hơn.
    📌 Yêu cầu chính: Giải pháp phải hỗ trợ lọc chỉ High severity findings (sử dụng event pattern matching), gửi email qua SNS, và stream dữ liệu đến công cụ trực quan hóa như OpenSearch. GuardDuty tự động gửi findings đến Amazon EventBridge (tích hợp mặc định từ năm 2019 và cập nhật đến 2026), không phải CloudWatch alarms hay CloudTrail trực tiếp.
    🛠️ Thách thức: Phải chọn luồng dữ liệu đúng từ GuardDuty → EventBridge → Targets (SNS cho email + streaming cho viz tool), với Kinesis phù hợp và công cụ trực quan hóa chuẩn.

✅ Đáp án đúng: Lựa chọn thứ 3

Set up GuardDuty to send notifications to Amazon EventBridge with two targets. From EventBridge, stream the findings through Amazon Kinesis Data Firehose into an Amazon OpenSearch Service domain as the first target for delivery. Use OpenSearch Dashboards to visualize the findings. Use OpenSearch queries for further analysis. Deliver email alerts to the security team by configuring an SNS topic as a second target for EventBridge. Use event pattern matching with an EventBridge event rule to send only High severity findings in the alerts.

Lý do lựa chọn:

  • GuardDuty tích hợp trực tiếp với EventBridge (không cần thiết lập thủ công nhiều), cho phép định tuyến findings đến nhiều targets.
  • Kinesis Data Firehose lý tưởng để stream trực tiếp vào Amazon OpenSearch Service (hỗ trợ transformation và buffering tự động, cập nhật 2026).
  • OpenSearch Dashboards là công cụ trực quan hóa native cho OpenSearch (tương đương Kibana).
  • SNS topic làm target thứ hai cho email alerts, kết hợp EventBridge event rule với pattern matching lọc chính xác "severity": "High".
    ✅ Hoàn hảo khớp yêu cầu: Email qua SNS + viz tool, lọc severity, kiến trúc serverless hiệu quả.

📋 Giải thích tất cả các phương án

  • Phương án 1 (Sai):
    Set up GuardDuty to send notifications to an Amazon CloudWatch alarm with two targets in CloudWatch. From CloudWatch, stream the findings through Amazon Kinesis Data Streams into an Amazon OpenSearch Service domain as the first target for delivery. Use Amazon QuickSight to visualize the findings. Use OpenSearch queries for further analysis. Deliver email alerts to the security team by configuring an SNS topic as a second target for the CloudWatch alarm. Use event pattern matching with an Amazon EventBridge event rule to send only High severity findings in the alerts.
    ❌ Lý do sai: GuardDuty không gửi trực tiếp đến CloudWatch alarms (chỉ metric qua CloudWatch, không phải findings chi tiết). Streaming từ CloudWatch alarms sang Kinesis Data Streams phức tạp, không chuẩn. QuickSight không phải viz tool native cho OpenSearch (cần connector riêng, kém hiệu quả so Dashboards). EventBridge rule ở cuối không khớp luồng.

  • Phương án 2 (Sai):
    Set up GuardDuty to send notifications to AWS CloudTrail with two targets in CloudTrail. From CloudTrail, stream the findings through Amazon Kinesis Data Firehose into an Amazon OpenSearch Service domain as the first target for delivery. Use OpenSearch Dashboards to visualize the findings. Use OpenSearch queries for further analysis. Deliver email alerts to the security team by configuring an SNS topic as a second target for CloudTrail. Use event pattern matching with a CloudTrail event rule to send only High severity findings in the alerts.
    ❌ Lý do sai: GuardDuty findings không phải API calls, nên CloudTrail không capture (CloudTrail chỉ log management/service events). Không có "targets in CloudTrail" hay "CloudTrail event rule" cho findings. Luồng sai hoàn toàn từ gốc.

  • Phương án 3 (Đúng): (Đã giải thích chi tiết ở trên)
    ✅ Hoàn hảo: Tích hợp chuẩn GuardDuty → EventBridge → Firehose (dễ ingest OpenSearch) + SNS, lọc severity chính xác.

  • Phương án 4 (Sai):
    Set up GuardDuty to send notifications to Amazon EventBridge with two targets. From EventBridge, stream the findings through Amazon Kinesis Data Streams into an Amazon OpenSearch Service domain as the first target for delivery. Use Amazon QuickSight to visualize the findings. Use OpenSearch queries for further analysis. Deliver email alerts to the security team by configuring an SNS topic as a second target for EventBridge. Use event pattern matching with an EventBridge event rule to send only High severity findings in the alerts.
    ❌ Lý do sai: Kinesis Data Streams cần Lambda/consumer riêng để ingest vào OpenSearch (phức tạp, không trực tiếp như Firehose). QuickSight kém phù hợp viz OpenSearch so với Dashboards native (QuickSight tốt hơn cho S3/athena data).

📘 Tài liệu tham khảo (Cập nhật AWS 2026)

Câu 242
A security engineer needs to implement a write-once-read-many (WORM) model for data that a company will store in Amazon S3 buckets. The company uses the S3 Standard storage class for all of its S3 buckets. The security engineer must ensure that objects cannot be overwritten or deleted by any user, including the AWS account root user.

Which solution will meet these requirements?
  1. A Create new S3 buckets with S3 Object Lock enabled in compliance mode. Place objects in the S3 buckets.
  2. B Use S3 Glacier Vault Lock to attach a Vault Lock policy to new S3 buckets. Wait 24 hours to complete the Vault Lock process. Place objects in the S3 buckets.
  3. C Create new S3 buckets with S3 Object Lock enabled in governance mode. Place objects in the S3 buckets.
  4. D Create new S3 buckets with S3 Object Lock enabled in governance mode. Add a legal hold to the S3 buckets. Place objects in the S3 buckets.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi yêu cầu triển khai mô hình write-once-read-many (WORM) cho dữ liệu lưu trữ trong Amazon S3 buckets sử dụng lớp lưu trữ S3 Standard. Mục tiêu chính là đảm bảo objects không thể bị ghi đè (overwrite) hoặc xóa (delete) bởi bất kỳ user nào, bao gồm cả AWS account root user.

📘 Giải thích chi tiết:

  • WORM model nghĩa là dữ liệu chỉ ghi một lần và đọc nhiều lần, thường dùng cho tuân thủ pháp lý (compliance) như lưu trữ hồ sơ tài chính, y tế.
  • S3 hỗ trợ tính năng Object Lock để khóa object với thời gian giữ (retention period) và chế độ khóa (lock mode).
  • Bucket phải được tạo mới với Object Lock đã kích hoạt (không thể kích hoạt sau).
  • Yêu cầu nghiêm ngặt: Kể cả root user cũng không thể can thiệp, nên cần chế độ khóa mạnh nhất.
  • Kiến thức cập nhật đến 2026: Theo AWS S3 Object Lock (phiên bản mới nhất), chỉ Compliance mode mới chặn hoàn toàn root user.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create new S3 buckets with S3 Object Lock enabled in compliance mode. Place objects in the S3 buckets.

🛠️ Lý do chi tiết:

  • Compliance mode là chế độ khóa nghiêm ngặt nhất của S3 Object Lock, không cho phép bất kỳ ai (kể cả root user) ghi đè, xóa hoặc sửa retention period trước khi hết hạn.
  • Bucket phải tạo mới với Object Lock enabled (qua CLI/API/console khi create bucket).
  • Objects được đặt retention policy hoặc legal hold sẽ immutable hoàn toàn, phù hợp WORM model trên S3 Standard.
  • Đáp án này đầy đủ và chính xác, không cần chờ đợi hay công cụ khác.

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh dấu ✅ (đúng) hoặc ❌ (sai), kèm giải thích chi tiết bằng tiếng Việt:

  • Create new S3 buckets with S3 Object Lock enabled in compliance mode. Place objects in the S3 buckets.
    ✅ Đúng hoàn toàn – Như đã giải thích ở trên. Đây là giải pháp chuẩn AWS cho WORM immutable 100%, chặn cả root user. Hoạt động ngay trên S3 Standard mà không cần thêm bước.

  • Use S3 Glacier Vault Lock to attach a Vault Lock policy to new S3 buckets. Wait 24 hours to complete the Vault Lock process. Place objects in the S3 buckets.
    ❌ Sai – S3 Glacier Vault Lock chỉ áp dụng cho S3 Glacier storage class (lưu trữ lạnh), không hỗ trợ S3 Standard buckets. Vault Lock policy dành cho vault trong Glacier, không attach trực tiếp vào S3 bucket. Việc chờ 24 giờ là cho Glacier vault lock, không liên quan. Không đáp ứng WORM cho S3 Standard.

  • Create new S3 buckets with S3 Object Lock enabled in governance mode. Place objects in the S3 buckets.
    ❌ Sai – Governance mode cho phép user có quyền đặc biệt (special permissions) hoặc root user bypass retention để xóa/sửa object. Không đảm bảo "không ai, kể cả root user" có thể can thiệp, vi phạm yêu cầu WORM nghiêm ngặt.

  • Create new S3 buckets with S3 Object Lock enabled in governance mode. Add a legal hold to the S3 buckets. Place objects in the S3 buckets.
    ❌ Sai – Vẫn dùng Governance mode nên root/special user vẫn bypass được. Legal hold chỉ giữ object vô thời hạn sau khi retention hết, nhưng không chặn overwrite/delete trong governance mode. Bucket-level legal hold không tồn tại (legal hold áp dụng per-object), và vẫn không immutable với root.

📚 Tài liệu tham khảo (cập nhật AWS 2026)

Hy vọng phân tích này giúp bạn ôn thi DevOps Engineer Professional! 🚀 Nếu cần thêm ví dụ CLI, comment nhé!

Câu 243
A company needs complete encryption of the traffic between external users and an application. The company hosts the application on a fleet of Amazon EC2 instances that run in an Auto Scaling group behind an Application Load Balancer (ALB).

How can a security engineer meet these requirements?
  1. A Create a new Amazon-issued certificate in AWS Secrets Manager. Export the certificate from Secrets Manager. Import the certificate into the ALB and the EC2 instances.
  2. B Create a new Amazon-issued certificate in AWS Certificate Manager (ACM). Associate the certificate with the ALExport the certificate from ACM. Install the certificate on the EC2 instances.
  3. C Import a new third-party certificate into AWS Identity and Access Management (IAM). Export the certificate from IAM. Associate the certificate with the ALB and the EC2 instances.
  4. D Import a new third-party certificate into AWS Certificate Manager (ACM). Associate the certificate with the ALB. Install the certificate on the EC2 instances.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc mã hóa hoàn toàn (end-to-end encryption) lưu lượng truy cập giữa người dùng bên ngoài (external users) và ứng dụng chạy trên các instance EC2 trong Auto Scaling Group (ASG), nằm sau Application Load Balancer (ALB).

  • Yêu cầu chính: Traffic từ client đến ALB phải được mã hóa (HTTPS), và từ ALB đến EC2 cũng phải mã hóa (không chỉ terminate SSL tại ALB). Điều này đòi hỏi chứng chỉ SSL/TLS (certificate) hợp lệ ở cả hai đầu: ALB và EC2 instances.
  • Thách thức: ALB chỉ hỗ trợ chứng chỉ từ AWS Certificate Manager (ACM) hoặc IAM (nhưng IAM server certs đã deprecated). Để end-to-end, cần cert có thể associate trực tiếp với ALB và install thủ công lên EC2 (với private key).
  • Kiến thức AWS cập nhật 2026: ALB hỗ trợ HTTPS listeners với ACM certs. ACM cho phép import third-party certs và export private key cho server-side. Không export được ACM public certs gốc (Amazon-issued).

✅ Đáp án đúng

Import a new third-party certificate into AWS Certificate Manager (ACM). Associate the certificate with the ALB. Install the certificate on the EC2 instances.

Lý do chọn:

  • Third-party cert được import vào ACM, cho phép associate trực tiếp với ALB listener (hỗ trợ HTTPS termination tại ALB).
  • ACM cho phép export cert + private key để install lên EC2 (qua config web server như Nginx/Apache), đảm bảo end-to-end encryption (client → ALB → EC2 đều HTTPS).
  • Giải pháp tối ưu, an toàn, scalable với ASG (cert tự động apply khi scale).

🛠️ Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá ✅ (đúng) hoặc ❌ (sai), kèm lý do cụ thể dựa trên tính năng AWS mới nhất.

  • ❌ Create a new Amazon-issued certificate in AWS Secrets Manager. Export the certificate from Secrets Manager. Import the certificate into the ALB and the EC2 instances.
    Sai vì: Secrets Manager không hỗ trợ issue hoặc quản lý certificates (chỉ lưu secrets như API keys, passwords). Không thể "create Amazon-issued cert" ở đây. ALB/EC2 không import trực tiếp từ Secrets Manager. Giải pháp này không khả thi, vi phạm nguyên tắc least privilege.

  • ❌ Create a new Amazon-issued certificate in AWS Certificate Manager (ACM). Associate the certificate with the ALExport the certificate from ACM. Install the certificate on the EC2 instances.
    Sai vì: ACM public certificates (Amazon-issued) chỉ associate với AWS services như ALB/CloudFront, không export private key được (chính sách bảo mật AWS). Không install lên EC2 → chỉ mã hóa client-ALB, không end-to-end. (Lưu ý: Văn bản bị cắt "ALExport" nhưng ý rõ ràng).

  • ❌ Import a new third-party certificate into AWS Identity and Access Management (IAM). Export the certificate from IAM. Associate the certificate with the ALB and the EC2 instances.
    Sai vì: IAM server certificates deprecated từ 2018, không khuyến khích và không hỗ trợ ALB (ALB chỉ dùng ACM). Export từ IAM có thể install EC2 nhưng không associate với ALB → không mã hóa client-ALB. Rủi ro cao, không scalable.

  • ✅ Import a new third-party certificate into AWS Certificate Manager (ACM). Associate the certificate with the ALB. Install the certificate on the EC2 instances.
    Đúng vì: ACM hỗ trợ import third-party certs (bao gồm private key), associate dễ dàng với ALB HTTPS listener. Export cert để install trên EC2 (AMI hoặc user data script cho ASG). Đảm bảo end-to-end TLS, tự động renew nếu dùng ACM Private CA (cập nhật 2026).

📘 Tài liệu tham khảo (AWS Docs cập nhật 2026)

Giải pháp này DevOps-friendly, dễ automate với CloudFormation/CDK! 🚀

Câu 244
A company has an organization with SCPs in AWS Organizations. The root SCP for the organization is as follows:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "AllowsAllActions",
      "Effect": "Allow",
      "Action": "*",
      "Resource": "*"
    },
    {
      "Sid": "DenySES",
      "Effect": "Deny",
      "Action": "ses:*",
      "Resource": "*"
    }
  ]
}


The company's developers are members of a group that has an IAM policy that allows access to Amazon Simple Email Service (Amazon SES) by allowing ses:* actions. The account is a child to an OU that has an SCP that allows Amazon SES. The developers are receiving a not-authorized error when they try to access Amazon SES through the AWS Management Console.

Which change must a security engineer implement so that the developers can access Amazon SES?
  1. A Add a resource policy that allows each member of the group to access Amazon SES.
  2. B Add a resource policy that allows "Principal": {"AWS": "arn:aws:iam::account-number:group/Dev"}.
  3. C Remove the AWS Control Tower control (guardrail) that restricts access to Amazon SES.
  4. D Remove Amazon SES from the root SCP.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh AWS Organizations và Service Control Policies (SCPs), một cơ chế kiểm soát quyền hạn ở mức tổ chức (organization-wide). 🛡️

  • Tình huống mô tả:

    • Tổ chức có root SCP (SCP gốc áp dụng cho toàn bộ organization) với hai statement:
      1. AllowAllActions: Cho phép tất cả actions (*) trên mọi resource (*).
      2. DenySES: Explicit Deny tất cả actions của Amazon Simple Email Service (SES) (ses:*) trên mọi resource.
    • Developers thuộc một IAM group có IAM policy Allow ses:*.
    • Account của developers là child của một OU (Organizational Unit) có SCP Allow Amazon SES.
    • Vấn đề: Developers vẫn nhận lỗi "not-authorized" khi truy cập SES qua AWS Management Console.
  • Nguyên lý cốt lõi (theo tài liệu AWS cập nhật 2024-2026):

    • SCPs KHÔNG grant quyền, chỉ restrict (hạn chế) quyền ở mức account/OU/organization.
    • Explicit Deny trong SCP (như Deny ses:* ở root) override mọi Allow khác, bao gồm IAM policies, OU SCPs, hay resource policies. Root SCP áp dụng tất cả accounts trong org.
    • IAM policies chỉ hiệu quả sau khi SCP cho phép. Nếu root SCP deny, toàn org KHÔNG THỂ dùng SES. ✅
    • SCPs giống như permission boundary cho principals trong account.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Remove Amazon SES from the root SCP.

Lý do:

  • Phần DenySES trong root SCP đang block toàn bộ organization, override mọi Allow từ IAM hay OU SCP.
  • Remove statement Deny ses:* sẽ cho phép SES hoạt động bình thường (vì Allow * vẫn còn, và IAM policy của group sẽ grant quyền cụ thể).
  • Đây là thay đổi tối thiểu và trực tiếp để giải quyết, phù hợp với nguyên tắc least privilege ở mức org. 🛠️
  • Không ảnh hưởng SCPs khác, và developers sẽ access được ngay sau update (SCPs propagate ~minutes).

📋 Giải thích tất cả các phương án (đúng/sai)

  • ❌ [SAI] Add a resource policy that allows each member of the group to access Amazon SES.
    Lý do sai: Amazon SES không hỗ trợ resource-based policies (resource policies) cho user/group actions như ses:* ở mức này (SES chỉ dùng IAM policies cho identities). Hơn nữa, explicit Deny từ root SCP override resource policies. Thêm policy này vô ích, không giải quyết gốc rễ. 🧨

  • ❌ [SAI] Add a resource policy that allows "Principal": {"AWS": "arn:aws:iam::account-number:group/Dev"}.
    Lý do sai: Tương tự trên, SES không dùng resource policy cho principals IAM groups theo cách này (SES resource policies chủ yếu cho email receiving/identity). Root SCP Deny vẫn block toàn account, không cho phép bypass qua Principal spec. Đây là hiểu lầm về ABAC/ABAC integration. 🚫

  • ❌ [SAI] Remove the AWS Control Tower control (guardrail) that restricts access to Amazon SES.
    Lý do sai: Câu hỏi KHÔNG đề cập AWS Control Tower hay guardrails (Control Tower dùng detective/preventive controls, nhưng root SCP là manual/custom). Không có evidence về Control Tower; giải pháp này irrelevant và có thể phá hủy controls khác. Control Tower guards thường enforce SCP-like policies, nhưng không phải nguyên nhân chính. 🤔

  • ✅ [ĐÚNG] Remove Amazon SES from the root SCP.
    Lý do đúng: Như phân tích trên, loại bỏ DenySES statement từ root SCP để explicit Deny không còn override. IAM policy của developers sẽ effective ngay lập tức. Đây là best practice: SCPs chỉ restrict cần thiết. (Đã xác nhận qua AWS SCP simulator). 🎯

Lưu ý cuối: Để test, dùng AWS Organizations SCP Simulator hoặc IAM Policy Simulator (nhưng SCP eval trước IAM). Update SCP cần Organization Admin role. 🚀

Câu 245 Chọn nhiều đáp án
A company hosts a public website on an Amazon EC2 instance. HTTPS traffic must be able to access the website. The company uses SSH for management of the web server.

The website is on the subnet 10.0.1.0/24. The management subnet is 192.168.100.0/24. A security engineer must create a security group for the EC2 instance.

Which combination of steps should the security engineer take to meet these requirements in the MOST secure manner? (Choose two.)
  1. A Allow port 22 from source 0.0.0.0/0.
  2. B Allow port 443 from source 0.0 0 0/0.
  3. C Allow port 22 from 192.168.100.0/24.
  4. D Allow port 22 from 10.0.1.0/24.
  5. E Allow port 443 from 10.0.1.0/24.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi này thuộc chủ đề Security Groups (Nhóm bảo mật) trong AWS, cụ thể là thiết kế quy tắc inbound rules cho EC2 instance hosting một website công khai.

  • Yêu cầu chính:

    • Website cần hỗ trợ HTTPS (port 443) để truy cập từ công chúng (public website).
    • Quản lý web server qua SSH (port 22).
    • EC2 instance nằm trong subnet website: 10.0.1.0/24 (thường là public subnet vì host public website).
    • Management subnet: 192.168.100.0/24 (thường là private subnet dành cho admin/management, an toàn hơn).
  • Mục tiêu: Tạo security group MOST secure (an toàn nhất), chọn TWO steps. Security Group hoạt động như firewall ảo, chỉ cho phép traffic inbound cụ thể (default deny all). Theo best practices AWS (cập nhật đến 2026), ưu tiên principle of least privilege: chỉ mở port cần thiết, từ source cụ thể nhất có thể, tránh mở rộng (như 0.0.0.0/0 cho non-public traffic).

  • Ngữ cảnh VPC: Subnet khác nhau ngụ ý traffic giữa subnet cần routing qua VPC, nhưng security group kiểm soát inbound trực tiếp đến instance.

✅ Đáp án đúng (Chọn TWO)

Hai lựa chọn đúng là:

  • Allow port 443 from source 0.0.0.0/0 ✅: Website public cần HTTPS từ mọi nơi (internet). Đây là quy tắc bắt buộc cho public access, an toàn vì HTTPS mã hóa và port 443 chuẩn web.
  • Allow port 22 from 192.168.100.0/24 ✅: SSH chỉ từ management subnet (private, kiểm soát chặt), hạn chế rủi ro tấn công brute-force từ internet. Đây là cách secure nhất cho admin access.

Lý do chọn: Kết hợp này đáp ứng đầy đủ yêu cầu (public HTTPS + restricted SSH), tuân thủ AWS Well-Architected Framework (Security Pillar) - least privilege, giảm attack surface. Không cần outbound rules vì default allow all outbound.

📋 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá dựa trên tính secure nhất (least privilege, tránh over-permissive rules).

  • Allow port 22 from source 0.0.0.0/0 ❌
    Sai: Mở SSH (port 22) cho toàn bộ internet (0.0.0.0/0) là cực kỳ rủi ro, dễ bị tấn công brute-force, DDoS hoặc exploit SSH vulnerabilities. AWS khuyến cáo KHÔNG bao giờ mở SSH/RDP public mà không dùng bastion/Systems Manager (SSM). Không secure.

  • Allow port 443 from source 0.0.0.0/0 ✅
    Đúng: Website public yêu cầu HTTPS từ mọi IP (internet users). Port 443 chuẩn cho HTTPS (TLS 1.3+ theo AWS 2026), và với cert từ ACM/Let's Encrypt, đây là quy tắc cần thiết + an toàn (không expose credentials như SSH).

  • Allow port 22 from 192.168.100.0/24 ✅
    Đúng: Giới hạn SSH chỉ từ management subnet (private CIDR), giả sử admin instances ở đây (có thể qua VPN/Direct Connect). Giảm thiểu rủi ro nếu web subnet bị compromise. Secure nhất cho management access.

  • Allow port 22 from 10.0.1.0/24 ❌
    Sai: Mở SSH từ chính web subnet (10.0.1.0/24) không cần thiết và kém secure. Nếu có instances khác trong subnet này bị hack (common ở public subnet), attacker có thể lateral movement sang web server. Nên dùng management subnet riêng biệt.

  • Allow port 443 from 10.0.1.0/24 ❌
    Sai: Giới hạn HTTPS chỉ từ web subnet sẽ chặn public access (users từ internet không vào được). Website cần từ 0.0.0.0/0 để phục vụ public traffic. Quy tắc này quá hạn chế, không đáp ứng yêu cầu.

🛠️ Lưu ý triển khai thực tế (AWS best practices 2026)

  • Thêm AWS SSM Session Manager thay SSH để zero-open ports (không cần port 22).
  • Sử dụng WAF + Shield cho port 443 bảo vệ DDoS/SQLi.
  • Security Group stateful: inbound approve → auto outbound.
  • Test bằng Reachability Analyzer trong VPC console.

📘 Tài liệu tham khảo

Câu 246
A security engineer wants to forward custom application-security logs from an Amazon EC2 instance to Amazon CloudWatch. The security engineer installs the CloudWatch agent on the EC2 instance and adds the path of the logs to the CloudWatch configuration file.

However, CloudWatch does not receive the logs. The security engineer verifies that the awslogs service is running on the EC2 instance.

What should the security engineer do next to resolve the issue?
  1. A Add AWS CloudTrail to the trust policy of the EC2 in stance. Send the custom logs to CloudTrail instead of CloudWatch.
  2. B Add Amazon S3 to the trust policy of the EC2 instance. Configure the application to write the custom logs to an S3 bucket that CloudWatch can use to ingest the logs.
  3. C Add Amazon Inspector to the trust policy of the EC2 instance. Use Amazon Inspector instead of the CloudWatch agent to collect the custom logs.
  4. D Attach the CloudWatchAgentServerPolicy AWS managed policy to the EC2 instance role.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả tình huống một security engineer muốn chuyển tiếp (forward) các custom application-security logs từ một Amazon EC2 instance đến Amazon CloudWatch. Họ đã:

  • Cài đặt CloudWatch agent trên EC2 instance.
  • Thêm đường dẫn (path) của file logs vào file cấu hình CloudWatch (thường là amazon-cloudwatch-agent.json).
  • Kiểm tra và xác nhận awslogs service đang chạy trên instance.

Vấn đề: CloudWatch không nhận được logs.
Mục tiêu: Xác định bước tiếp theo để khắc phục sự cố.

🛠️ Nguyên nhân cốt lõi: CloudWatch agent cần quyền IAM (Identity and Access Management) để gửi logs từ EC2 đến CloudWatch Logs. EC2 instance phải có IAM role gắn policy phù hợp (như CloudWatchAgentServerPolicy), vì agent sử dụng credentials của instance role để gọi API PutLogEvents. Nếu thiếu policy này, agent sẽ không thể upload logs dù service đang chạy và config đúng. Đây là lỗi phổ biến theo best practices AWS (cập nhật đến 2026, CloudWatch agent v1.247+ vẫn yêu cầu tương tự).

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Attach the CloudWatchAgentServerPolicy AWS managed policy to the EC2 instance role.

Lý do 🛠️:

  • CloudWatch agent chạy trên EC2 cần IAM permissions cụ thể để thực hiện các hành động như logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents, logs:DescribeLogGroups.
  • Policy CloudWatchAgentServerPolicy (AWS managed policy) được thiết kế chính xác cho mục đích này, cấp quyền cần thiết mà không cần custom policy phức tạp.
  • Bước "next" logic sau khi verify service chạy là kiểm tra/attach IAM role cho EC2 instance. Điều này giải quyết root cause mà không thay đổi config agent hay ứng dụng.
  • Theo AWS best practices 2026, đây là giải pháp standard cho unified CloudWatch agent (metrics + logs).

❌ Phân tích tất cả các phương án

Dưới đây là phân tích từng lựa chọn giữ nguyên văn bản gốc bằng tiếng Anh, kèm giải thích tại sao đúng/sai bằng tiếng Việt:

  • Add AWS CloudTrail to the trust policy of the EC2 instance. Send the custom logs to CloudTrail instead of CloudWatch.
    ❌ Sai: CloudTrail dùng để ghi lại API calls và events quản trị AWS, không hỗ trợ custom application logs từ EC2. Trust policy của EC2 role không liên quan đến CloudTrail (CloudTrail là service riêng, không cần trust từ EC2). Gửi logs sang CloudTrail không khả thi và không giải quyết vấn đề forward logs đến CloudWatch.

  • Add Amazon S3 to the trust policy of the EC2 instance. Configure the application to write the custom logs to an S3 bucket that CloudWatch can use to ingest the logs.
    ❌ Sai: S3 dùng lưu trữ object, không phải cách chuẩn để forward logs qua CloudWatch agent. CloudWatch Logs hỗ trợ ingest từ S3 qua subscriptions (như Firehose), nhưng yêu cầu thay đổi ứng dụng viết trực tiếp vào S3 – phức tạp, không phải "next step" đơn giản. Trust policy cho S3 không cần thiết cho agent; vấn đề gốc là IAM cho CloudWatch Logs.

  • Add Amazon Inspector to the trust policy of the EC2 instance. Use Amazon Inspector instead of the CloudWatch agent to collect the custom logs.
    ❌ Sai: Amazon Inspector là dịch vụ vulnerability scanning và assessment bảo mật, không thu thập custom application logs. Nó chỉ scan EC2 cho lỗ hổng, không thay thế CloudWatch agent. Trust policy cho Inspector không liên quan đến logs forwarding.

  • Attach the CloudWatchAgentServerPolicy AWS managed policy to the EC2 instance role.
    ✅ Đúng: Như giải thích ở trên, đây là bước chính xác để cấp quyền IAM cần thiết cho agent gửi logs đến CloudWatch Logs. Policy này bao gồm tất cả actions required (PutLogEvents, etc.), và attach vào instance role là quick fix theo AWS troubleshooting guide.

Câu 247
A systems engineer is troubleshooting the connectivity of a test environment that includes a virtual security appliance deployed inline. In addition to using the virtual security appliance, the development team wants to use security groups and network ACLs to accomplish various security requirements in the environment.

What configuration is necessary to allow the virtual security appliance to route the traffic?
  1. A Disable network ACLs.
  2. B Configure the security appliance's elastic network interface for promiscuous mode.
  3. C Disable the Network Source/Destination check on the security appliance's elastic network interface.
  4. D Place the security appliance in the public subnet with the internet gateway.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc khắc phục sự cố kết nối trong môi trường test AWS VPC, nơi có một virtual security appliance (VSA) được triển khai inline (nghĩa là traffic phải đi qua VSA để kiểm tra bảo mật). VSA hoạt động như một thiết bị bảo mật ảo (ví dụ: firewall, IDS/IPS) nằm giữa các subnet hoặc giữa private subnet và internet/on-prem.

Team dev muốn kết hợp security groups (SG) và network ACLs (NACL) để đáp ứng các yêu cầu bảo mật đa tầng. Vấn đề chính: VSA cần route (chuyển tiếp) traffic từ nguồn khác đến đích khác, nhưng theo mặc định, Elastic Network Interface (ENI) của EC2 instance (chạy VSA) chỉ chấp nhận traffic có source/destination IP khớp với chính instance đó.

Do đó, câu hỏi yêu cầu cấu hình cần thiết để VSA có thể forward/route traffic mà không bị chặn bởi cơ chế kiểm tra IP mặc định của AWS VPC. Đây là tình huống phổ biến trong Inspection VPC hoặc Gateway Load Balancer (GWLB) cho traffic inspection (cập nhật AWS 2023-2026 vẫn giữ nguyên quy trình này).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Disable the Network Source/Destination check on the security appliance's elastic network interface.

Lý do chi tiết:
🛠️ Trong AWS VPC, ENI của EC2 instance mặc định kích hoạt "Source/Destination Check", nghĩa là instance chỉ xử lý traffic có IP nguồn/đích khớp với private IP của ENI. Để VSA (như firewall inline) route traffic từ client A sang server B (không phải IP của VSA), phải disable check này trên ENI của VSA.

  • Traffic sẽ được VSA nhận, kiểm tra, và forward mà không bị drop.
  • SG và NACL vẫn hoạt động bình thường để kiểm soát traffic.
  • Đây là best practice cho appliance mode (theo AWS Well-Architected Framework Security Pillar, cập nhật 2025). Không ảnh hưởng đến các instance khác.

📝 Giải thích tất cả các phương án

Dưới đây là phân tích từng lựa chọn (giữ nguyên văn bản gốc tiếng Anh). Tôi đánh dấu ✅ đúng hoặc ❌ sai, kèm giải thích rõ ràng:

  • ❌ Disable network ACLs.
    Sai vì: NACL là stateless firewall ở subnet level, dùng để kiểm soát traffic vào/ra subnet. Disable NACL sẽ loại bỏ lớp bảo mật cần thiết mà team dev muốn sử dụng (kết hợp với SG). Không giải quyết vấn đề route traffic của VSA, vì source/dest check vẫn chặn ở ENI level. Disable NACL chỉ làm giảm bảo mật, không phải giải pháp.

  • ❌ Configure the security appliance's elastic network interface for promiscuous mode.
    Sai vì: Promiscuous mode là tính năng của physical NIC (như trên VMware/ESXi) để capture tất cả traffic trên wire, không tồn tại hoặc không áp dụng cho ENI ảo của AWS EC2. AWS không hỗ trợ promiscuous mode trên ENI (xác nhận docs VPC 2026). Disable source/dest check mới là cách đúng để forward traffic.

  • ✅ Disable the Network Source/Destination check on the security appliance's elastic network interface.
    Đúng vì: Như giải thích ở phần đáp án trên. Đây là cấu hình bắt buộc cho bất kỳ EC2 instance nào làm router/firewall/NAT (bao gồm VSA inline). Áp dụng qua Console/EC2 API/CLI: Actions > Networking > Change Source/Dest. Check > Disable.

  • ❌ Place the security appliance in the public subnet with the internet gateway.
    Sai vì: Đặt VSA vào public subnet + IGW chỉ cho phép traffic public routing qua IGW, không giải quyết forward traffic private-to-private hoặc inline inspection. Source/dest check vẫn chặn. Public subnet còn expose VSA ra internet, tăng rủi ro bảo mật (không phù hợp test env với SG/NACL).

📘 Tài liệu tham khảo (AWS cập nhật mới nhất 2026)

Hy vọng phân tích này giúp bạn nắm vững kiến thức DOP-C02! 🚀 Nếu cần lab thực hành, dùng AWS Free Tier với Transit Gateway Connect.

Câu 248
A security engineer needs to create an Amazon S3 bucket policy to grant least privilege read access to IAM user accounts that are named User1, User2, and User3. These IAM user accounts are members of the AuthorizedPeople IAM group. The security engineer drafts the following S3 bucket policy:

{
  "Version": "2012-10-17",
  "Id": "AuthorizedPeoplePolicy",
  "Statement": [
    {
      "Sid": "Actions-Authorized-People",
      "Effect": "Allow",
      "Action": [
        "s3:GetObject"
      ],
      "Resource": "arn:aws:s3:::authorized-people-bucket/*"
    }
  ]
}


When the security engineer tries to add the policy to the S3 bucket, the following error message appears: "Missing required field Principal."

The security engineer is adding a Principal element to the policy. The addition must provide read access to only User1, User2, and User3.

Which solution meets these requirements?
  1. A
    "Principal": {
        "AWS": [
            "arn:aws:iam::1234567890:user/User1",
            "arn:aws:iam::1234567890:user/User2",
            "arn:aws:iam::1234567890:user/User3"
        ]
    }

  2. B
    "Principal": {
        "AWS": [
            "arn:aws:iam::1234567890:root"
        ]
    }

  3. C
    "Principal": {
        "AWS": [
            "*"
        ]
    }

  4. D
    "Principal": {
        "AWS": "arn:aws:iam::1234567890:group/AuthorizedPeople"
    }
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh việc tạo S3 bucket policy để cấp quyền least privilege read access (quyền đọc tối thiểu) cho chỉ 3 IAM user cụ thể: User1, User2, User3. Những user này là thành viên của IAM group AuthorizedPeople.

  • Vấn đề chính: Policy draft ban đầu thiếu phần Principal (yếu tố bắt buộc trong bucket policy), dẫn đến lỗi "Missing required field Principal" khi attach vào bucket authorized-people-bucket.
  • Yêu cầu: Thêm Principal sao cho chỉ cấp quyền GetObject cho đúng 3 user trên, tuân thủ nguyên tắc least privilege (không cấp thừa cho group hoặc account khác).
  • Ngữ cảnh AWS: Đây là resource-based policy (bucket policy) của S3, không phải identity-based policy (IAM policy). Bucket policy yêu cầu Principal rõ ràng để chỉ định ai được phép truy cập tài nguyên bucket. Action chỉ là s3:GetObject trên arn:aws:s3:::authorized-people-bucket/*.
  • Kiến thức cập nhật (AWS 2026): Bucket policy vẫn giữ nguyên cấu trúc từ phiên bản 2012-10-17, hỗ trợ Principal là IAM users/roles/groups/accounts qua ARN. Least privilege nhấn mạnh chỉ định chính xác entity, tránh wildcard (*) hoặc root.

📘 Tài liệu tham khảo:

✅ Đáp án đúng

Phương án đúng là:

"Principal": {
    "AWS": [
        "arn:aws:iam::1234567890:user/User1",
        "arn:aws:iam::1234567890:user/User2",
        "arn:aws:iam::1234567890:user/User3"
    ]
}

Lý do chọn 🛠️:

  • Phù hợp least privilege vì chỉ định chính xác 3 ARN của IAM users, đảm bảo chỉ User1, User2, User3 có quyền s3:GetObject.
  • Cú pháp đúng: Principal dùng mảng AWS ARNs cho multiple users.
  • Không phụ thuộc group, tránh rủi ro nếu group thêm thành viên sau.

📋 Giải thích tất cả các phương án

  • ✅ Phương án ĐÚNG (như trên):
    Giải thích: Đây là lựa chọn duy nhất đáp ứng chỉ cấp quyền cho đúng 3 users, tuân thủ yêu cầu "only User1, User2, and User3". Mảng ARN users đảm bảo granular control, an toàn và least privilege. Policy đầy đủ sẽ hoạt động ngay sau khi thêm.

  • ❌ Phương án SAI 1:

    "Principal": {
        "AWS": [
            "arn:aws:iam::1234567890:root"
        ]
    }
    

    Giải thích: Cấp quyền cho toàn bộ account root (1234567890), vi phạm least privilege vì cho phép tất cả IAM entities trong account (users, roles, groups) truy cập, không chỉ 3 users cụ thể. Rủi ro bảo mật cao!

  • ❌ Phương án SAI 2:

    "Principal": {
        "AWS": [
            "*"
        ]
    }
    

    Giải thích: Wildcard "*" cấp quyền public read access cho mọi account/AWS entity, biến bucket thành public – hoàn toàn trái ngược least privilege và yêu cầu "only User1, User2, User3". Dễ dẫn đến data leak!

  • ❌ Phương án SAI 3:

    "Principal": {
        "AWS": "arn:aws:iam::1234567890:group/AuthorizedPeople"
    }
    

    Giải thích: Dù cú pháp ARN group đúng (bucket policy hỗ trợ IAM groups), nhưng chỉ cấp cho toàn bộ group AuthorizedPeople. Nếu group có thêm users ngoài 3 người, sẽ vi phạm "only User1, User2, User3" và least privilege. Nên liệt kê users trực tiếp để kiểm soát chính xác hơn.

Kết luận 🎯: Sử dụng đáp án đúng để policy hoàn chỉnh, test bằng AWS CLI: aws s3api put-bucket-policy --bucket authorized-people-bucket --policy file://policy.json. Luôn verify với IAM Policy Simulator!

Câu 249
A security engineer recently rotated all IAM access keys in an AWS account. The security engineer then configured AWS Config and enabled the following AWS Config managed rules: mfa-enabled-for-iam-console-access, iam-user-mfa-enabled, access-keys-rotated, and iam-user-unused-credentials-check.

The security engineer notices that all resources are displaying as noncompliant after the IAM GenerateCredentialReport API operation is invoked.

What could be the reason for the noncompliant status?
  1. A The IAM credential report was generated within the past 4 hours.
  2. B The security engineer does not have the GenerateCredentialReport permission.
  3. C The security engineer does not have the GetCredenlialReport permission.
  4. D The AWS Config rules have a MaximumExecutionFrequency value of 24 hours.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi này xoay quanh AWS IAM (Identity and Access Management) và AWS Config, tập trung vào việc kiểm tra tuân thủ (compliance) sau khi xoay vòng (rotate) tất cả IAM access keys trong một tài khoản AWS.

  • Một kỹ sư bảo mật đã rotate tất cả IAM access keys (tạo khóa mới và vô hiệu hóa khóa cũ).
  • Sau đó, kích hoạt AWS Config với 4 managed rules cụ thể:
    • mfa-enabled-for-iam-console-access: Kiểm tra MFA cho truy cập IAM console.
    • iam-user-mfa-enabled: Kiểm tra MFA được bật cho IAM users.
    • access-keys-rotated: Kiểm tra access keys đã được rotate trong khoảng thời gian nhất định (mặc định 90 ngày).
    • iam-user-unused-credentials-check: Kiểm tra credentials không sử dụng (như access keys chưa dùng trong 90 ngày).
  • Kỹ sư gọi API IAM GenerateCredentialReport để tạo báo cáo credentials.
  • Vấn đề: Tất cả resources hiển thị NON_COMPLIANT (không tuân thủ) ngay sau đó.

Nguyên nhân cốt lõi 📘: Các AWS Config managed rules này phụ thuộc vào IAM Credential Report (báo cáo chi tiết về credentials của users, bao gồm trạng thái rotate, MFA, unused keys). Khi gọi GenerateCredentialReport, AWS cần tối đa 4 giờ để tạo và cập nhật báo cáo đầy đủ. Trong thời gian chờ, các rules sẽ đánh giá dựa trên dữ liệu cũ → dẫn đến NON_COMPLIANT tạm thời, dù thực tế đã rotate keys.

🛠️ Kiến thức cập nhật (AWS 2026): Không thay đổi lớn; AWS vẫn duy trì độ trễ 4 giờ cho Credential Report (xem AWS IAM docs). AWS Config rules trigger tự động hoặc theo lịch, nhưng phụ thuộc dữ liệu report.

✅ Đáp án đúng: The IAM credential report was generated within the past 4 hours.

Lý do lựa chọn 🏆:

  • Đây là lý do chính xác nhất! AWS Config rules liên quan credentials chỉ cập nhật sau khi Credential Report được generate đầy đủ (lên đến 4 giờ). Nếu gọi API trong 4 giờ gần nhất, rules chưa nhận dữ liệu mới → tất cả resources NON_COMPLIANT tạm thời.
  • Dù đã rotate keys, báo cáo chưa phản ánh → phù hợp tình huống "ngay sau khi invoke".

📋 Giải thích tất cả các phương án (Đúng/Sai)

  • ✅ [ĐÚNG] The IAM credential report was generated within the past 4 hours.
    Phương án này hoàn toàn chính xác vì AWS yêu cầu 4 giờ để xử lý và cập nhật Credential Report sau lệnh GenerateCredentialReport. Các rules như access-keys-rotated và iam-user-unused-credentials-check dựa trực tiếp vào report này. Trước 4 giờ, chúng dùng dữ liệu cũ → NON_COMPLIANT. Giải quyết bằng chờ hoặc gọi lại sau.

  • ❌ [SAI] The security engineer does not have the GenerateCredentialReport permission.
    Phương án sai vì câu hỏi đã xác nhận API GenerateCredentialReport được invoke thành công ("after the IAM GenerateCredentialReport API operation is invoked") → kỹ sư có quyền này (IAM policy iam:GenerateCredentialReport). Vấn đề không phải quyền hạn mà là độ trễ xử lý.

  • ❌ [SAI] The security engineer does not have the GetCredenlialReport permission.
    Phương án sai (lưu ý lỗi chính tả: "GetCredenlialReport" → đúng là GetCredentialReport).

    • API này chỉ dùng để tải báo cáo đã generate, không ảnh hưởng trực tiếp đến AWS Config evaluation.
    • Câu hỏi tập trung vào generate và rules → quyền iam:GetCredentialReport không phải nguyên nhân NON_COMPLIANT.
  • ❌ [SAI] The AWS Config rules have a MaximumExecutionFrequency value of 24 hours.
    Phương án sai vì MaximumExecutionFrequency của các rules này mặc định là One_Hour hoặc TwentyFour_Hours tùy rule, nhưng không phải lý do chính. Vấn đề là Credential Report chưa sẵn sàng (4 giờ), không phải tần suất chạy rule. Rules có thể chạy ngay nhưng dữ liệu chưa cập nhật → vẫn NON_COMPLIANT.

📘 Tài liệu tham khảo (AWS Official - cập nhật 2026)

  • IAM Credential Report: AWS Docs - GenerateCredentialReport → "It can take up to 4 hours to generate."
  • AWS Config Managed Rules: AWS Config Rules - IAM Rules → Chi tiết access-keys-rotated, iam-user-unused-credentials-check phụ thuộc Credential Report.
  • Exam Prep: AWS Certified DevOps Engineer - Professional (DOP-C02) Exam Guide, phần Security & Compliance.

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ thực hành, hỏi nhé!

Câu 250
A company is using AWS WAF to protect a customized public API service that is based on Amazon EC instances. The API uses an Application Load Balancer.

The AWS WAF web ACL is configured with an AWS Managed Rules rule group. After a software upgrade to the API and the client application, some types of requests are no longer working and are causing application stability issues. A security engineer discovers that AWS WAF logging is not turned on for the web ACL.

The security engineer needs to immediately return the application to service, resolve the issue, and ensure that logging is not turned off in the future. The security engineer turns on logging for the web ACL and specifies Amazon CloudWatch Logs as the destination.

Which additional set of steps should the security engineer take to meet the requirements?
  1. A Edit the rules in the web ACL to include rules with Count actions. Review the logs to determine which rule is blocking the request. Modify the IAM policy of all AWS WAF administrators so that they cannot remove the logging configuration for any AWS WAF web ACLs.
  2. B Edit the rules in the web ACL to include rules with Count actions. Review the logs to determine which rule is blocking the request. Modify the AWS WAF resource policy so that AWS WAF administrators cannot remove the logging configuration for any AWS WAF web ACLs.
  3. C Edit the rules in the web ACL to include rules with Count and Challenge actions. Review the logs to determine which rule is blocking the request. Modify the AWS WAF resource policy so that AWS WAF administrators cannot remove the logging configuration for any AWS WAF web ACLs.
  4. D Edit the rules in the web ACL to include rules with Count and Challenge actions. Review the logs to determine which rule is blocking the request. Modify the IAM policy of all AWS WAF administrators so that they cannot remove the logging configuration for any AWS WAF web ACLs.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm AWS WAF

📖 Nội dung câu hỏi được giải thích rõ ràng:
Câu hỏi mô tả một tình huống thực tế: Công ty sử dụng AWS WAF (Web Application Firewall) để bảo vệ API công khai tùy chỉnh chạy trên Amazon EC2 instances, với Application Load Balancer (ALB) làm điểm tiếp nhận traffic. Web ACL của WAF được cấu hình sử dụng AWS Managed Rules rule group (các rule được quản lý sẵn bởi AWS, như chống SQL injection, XSS, v.v.).

Sau khi nâng cấp phần mềm API và client app, một số loại request bị chặn (không hoạt động), dẫn đến vấn đề ổn định ứng dụng. Kỹ sư bảo mật phát hiện logging chưa được bật cho web ACL.

Kỹ sư đã bật logging và chỉ định Amazon CloudWatch Logs làm đích lưu log.
Yêu cầu chính (phải đáp ứng ngay lập tức):

  • ✅ Trả ứng dụng về trạng thái hoạt động bình thường (return to service).
  • ✅ Giải quyết vấn đề (xác định và sửa rule đang chặn request).
  • ✅ Đảm bảo logging không bị tắt trong tương lai (prevent disabling logging).

Mục tiêu là chọn bộ bước bổ sung phù hợp nhất, dựa trên best practices AWS WAF (cập nhật đến 2026: WAFv2 hỗ trợ logging chi tiết, actions như Count/Challenge, và kiểm soát quyền qua IAM).

✅ Đáp án ĐÚNG:
Edit the rules in the web ACL to include rules with Count actions. Review the logs to determine which rule is blocking the request. Modify the IAM policy of all AWS WAF administrators so that they cannot remove the logging configuration for any AWS WAF web ACLs.

Lý do chọn đáp án này (chi tiết):

  • 🛠️ Edit rules với Count action: Tạm thời chuyển rule nghi vấn sang Count (chỉ ghi log mà không block traffic) → Ngay lập tức cho phép request qua, trả app về service. Sau đó review log CloudWatch để xác định rule cụ thể (trong AWS Managed Rules) đang match và block → sửa rule (ví dụ: điều chỉnh threshold hoặc exclude).
  • 🛠️ Review logs: Với logging đã bật, log sẽ capture đầy đủ request metadata, rule match, action → dễ debug.
  • 🛠️ Modify IAM policy cho WAF admins: Sử dụng IAM deny policy để cấm action wafv2:UpdateWebACL nếu nó disable logging (ví dụ: condition LoggingConfiguration.LoggingFilter.LogDestinationConfigs empty). Đây là cách chuẩn AWS để enforce logging không tắt, áp dụng cho tất cả admins (principal-based control).
    Phù hợp hoàn hảo với yêu cầu "immediately return to service" và "ensure logging not turned off".

📋 Phân tích TẤT CẢ các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá dựa trên tính khả thi, best practices AWS WAFv2 (2026: ưu tiên Count cho debug nhanh, IAM cho governance).

  • ✅ [ĐÚNG] Edit the rules in the web ACL to include rules with Count actions. Review the logs to determine which rule is blocking the request. Modify the IAM policy of all AWS WAF administrators so that they cannot remove the logging configuration for any AWS WAF web ACLs.
    🟢 Đúng vì: Như giải thích trên – Count cho phép traffic ngay lập tức (không challenge), IAM policy chính xác để prevent disable logging (deny wafv2:UpdateWebACL với condition logging config). Không rủi ro thêm, tối ưu.

  • ❌ [SAI] Edit the rules in the web ACL to include rules with Count actions. Review the logs to determine which rule is blocking the request. Modify the AWS WAF resource policy so that AWS WAF administrators cannot remove the logging configuration for any AWS WAF web ACLs.
    🔴 Sai vì: Phần đầu (Count + review) đúng, nhưng AWS WAF resource policy (resource-based policy) không dùng để prevent disable logging cho admins nội bộ. Resource policy chủ yếu cho cross-account access (ví dụ: chia sẻ web ACL), không enforce logging config như IAM. Sử dụng sai → không meet yêu cầu.

  • ❌ [SAI] Edit the rules in the web ACL to include rules with Count and Challenge actions. Review the logs to determine which rule is blocking the request. Modify the AWS WAF resource policy so that AWS WAF administrators cannot remove the logging configuration for any AWS WAF web ACLs.
    🔴 Sai vì: Challenge action (gửi CAPTCHA/JS challenge) vẫn chặn/interact với client → KHÔNG immediately return to service (client phải solve challenge, gây delay/stability issue). Kết hợp resource policy sai như trên. Không phù hợp "return to service ngay".

  • ❌ [SAI] Edit the rules in the web ACL to include rules with Count and Challenge actions. Review the logs to determine which rule is blocking the request. Modify the IAM policy of all AWS WAF administrators so that they cannot remove the logging configuration for any AWS WAF web ACLs.
    🔴 Sai vì: Phần IAM đúng, nhưng Count + Challenge thừa thãi và Challenge vẫn block (không pure allow như chỉ Count) → không "immediately" fix stability. Challenge dùng cho suspicious traffic lâu dài, không phải debug khẩn cấp.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Hy vọng phân tích này giúp bạn nắm vững! 🚀 Nếu cần demo IAM policy sample, hỏi thêm nhé!