Ngân hàng đề — AWS Certified Security Specialty

Tìm thấy 445 câu.

Câu 251 Chọn nhiều đáp án
A security engineer is creating an AWS Lambda function. The Lambda function needs to use a role that is named LambdaAuditRole to assume a role that is named AcmeAuditFactoryRole in a different AWS account.

When the code is processed, the following error message appears: "An error occurred (AccessDenied) when calling the AssumeRole operation."

Which combination of steps should the security engineer take to resolve this error? (Choose two.)
  1. A Ensure that LambdaAuditRole has the sts:AssumeRole permission for AcmeAuditFactoryRole.
  2. B Ensure that LambdaAuditRole has the AWSLambdaBasicExecutionRole managed policy attached.
  3. C Ensure that the trust policy for AcmeAuditFactoryRole allows the sts:AssumeRole action from LambdaAuditRole.
  4. D Ensure that the trust policy for LambdaAuditRole allows the sts:AssumeRole action from the lambda.amazonaws.com service.
  5. E Ensure that the sts:AssumeRole API call is being issued to the us-east-1 Region endpoint.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả tình huống một security engineer đang tạo một AWS Lambda function cần sử dụng execution role tên LambdaAuditRole (trong tài khoản hiện tại) để assume một role khác tên AcmeAuditFactoryRole (trong tài khoản AWS khác). Khi code chạy, xảy ra lỗi "An error occurred (AccessDenied) when calling the AssumeRole operation.".

🔍 Vấn đề cốt lõi: Lỗi AccessDenied trên API sts:AssumeRole xảy ra vì thiếu hai yếu tố chính trong cross-account role assumption:

  • Permissions policy trên role nguồn (LambdaAuditRole) phải cho phép thực hiện sts:AssumeRole trên ARN của role đích (AcmeAuditFactoryRole).
  • Trust policy trên role đích (AcmeAuditFactoryRole) phải tin tưởng (trust) principal là ARN của role nguồn (LambdaAuditRole).

Câu hỏi yêu cầu chọn TWO steps để khắc phục, dựa trên nguyên tắc IAM cross-account delegation (cập nhật theo AWS IAM best practices năm 2024-2026, hỗ trợ global STS endpoints và fine-grained permissions).

✅ Đáp án đúng (Chọn TWO)

Các bước cần thực hiện là:

  • Ensure that LambdaAuditRole has the sts:AssumeRole permission for AcmeAuditFactoryRole.
    (Đúng vì role nguồn cần policy cho phép assume role đích cụ thể).
  • Ensure that the trust policy for AcmeAuditFactoryRole allows the sts:AssumeRole action from LambdaAuditRole.
    (Đúng vì role đích phải trust role nguồn qua principal ARN).

Lý do chọn hai đáp án này 🛠️:
Đây là hai yêu cầu bắt buộc theo quy trình STS AssumeRole cross-account (AWS STS AssumeRole API). Lambda function chỉ có thể assume role khác nếu: (1) Execution role của Lambda có permission policy với sts:AssumeRole nhắm đến ARN role đích, và (2) Role đích có trust policy liệt kê principal là ARN của execution role nguồn. Thiếu một trong hai sẽ gây AccessDenied ngay lập tức. AWS không thay đổi cơ chế này đến 2026.

📋 Phân tích tất cả các phương án (Đúng/Sai)

Dưới đây là giải thích chi tiết từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh:

  • ✅ Ensure that LambdaAuditRole has the sts:AssumeRole permission for AcmeAuditFactoryRole.
    🟢 Đúng: Phần permissions policy (identity-based policy) gắn vào LambdaAuditRole phải có statement cho phép action sts:AssumeRole với resource là ARN của AcmeAuditFactoryRole (ví dụ: "Resource": "arn:aws:iam::TARGET-ACCOUNT-ID:role/AcmeAuditFactoryRole"). Không có permission này, STS từ chối ngay.

  • ❌ Ensure that LambdaAuditRole has the AWSLambdaBasicExecutionRole managed policy attached.
    🔴 Sai: AWSLambdaBasicExecutionRole chỉ cung cấp quyền ghi CloudWatch Logs (cho Lambda execution), không liên quan đến sts:AssumeRole hay cross-account. Lambda cần policy tùy chỉnh riêng cho AssumeRole.

  • ✅ Ensure that the trust policy for AcmeAuditFactoryRole allows the sts:AssumeRole action from LambdaAuditRole.
    🟢 Đúng: Trust policy (role trust relationship) của AcmeAuditFactoryRole phải có principal là ARN của LambdaAuditRole (ví dụ: "Principal": {"AWS": "arn:aws:iam::SOURCE-ACCOUNT-ID:role/LambdaAuditRole"} và action sts:AssumeRole). Đây là "chìa khóa tin cậy" cross-account.

  • ❌ Ensure that the trust policy for LambdaAuditRole allows the sts:AssumeRole action from the lambda.amazonaws.com service.
    🔴 Sai: Trust policy của LambdaAuditRole đã đúng (phải trust lambda.amazonaws.com để Lambda service assume nó). Vấn đề không phải ở đây, vì Lambda đã chạy và gọi AssumeRole được (chỉ fail AccessDenied ở target role).

  • ❌ Ensure that the sts:AssumeRole API call is being issued to the us-east-1 Region endpoint.
    🔴 Sai: sts:AssumeRole là global service (từ 2017, AWS hỗ trợ STS global endpoints ở mọi region). Không bắt buộc us-east-1; gọi từ region Lambda đang chạy là đủ (cập nhật AWS STS 2024+).

📘 Tài liệu tham khảo (Cập nhật mới nhất AWS 2026)

Hy vọng phân tích này giúp bạn nắm vững! 🚀 Nếu cần ví dụ code policy JSON, hãy hỏi thêm nhé!

Câu 252 Chọn nhiều đáp án
A company has AWS accounts in an organization in AWS Organizations. The organization includes a dedicated security account.

All AWS account activity across all member accounts must be logged and reported to the dedicated security account. The company must retain all the activity logs in a secure storage location within the dedicated security account for 2 years. No changes or deletions of the logs are allowed.

Which combination of steps will meet these requirements with the LEAST operational overhead? (Choose two.)
  1. A In the dedicated security account, create an Amazon S3 bucket. Configure S3 Object Lock in compliance mode and a retention period of 2 years on the S3 bucket. Set the bucket policy to allow the organization's management account to write to the S3 bucket.
  2. B In the dedicated security account, create an Amazon S3 bucket. Configure S3 Object Lock in compliance mode and a retention period of 2 years on the S3 bucket. Set the bucket policy to allow the organization's member accounts to write to the S3 bucket.
  3. C In the dedicated security account, create an Amazon S3 bucket that has an S3 Lifecycle configuration that expires objects after 2 years. Set the bucket policy to allow the organization's member accounts to write to the S3 bucket.
  4. D Create an AWS CloudTrail trail for the organization. Configure logs to be delivered to the logging Amazon S3 bucket in the dedicated security account.
  5. E Turn on AWS CloudTrail in each account. Configure logs to be delivered to an Amazon S3 bucket that is created in the organization's management account. Forward the logs to the S3 bucket in the dedicated security account by using AWS Lambda and Amazon Kinesis Data Firehose.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc thiết lập hệ thống ghi log (logging) toàn diện cho tất cả các tài khoản AWS trong một tổ chức AWS Organizations, với một tài khoản bảo mật riêng biệt (dedicated security account). Các yêu cầu chính bao gồm:

  • 📊 Ghi log tất cả hoạt động (AWS account activity) từ mọi tài khoản thành viên (member accounts) và báo cáo về tài khoản bảo mật.
  • 💾 Lưu trữ log an toàn trong tài khoản bảo mật ít nhất 2 năm, không cho phép thay đổi hoặc xóa bất kỳ log nào.
  • ⚡ Yêu cầu sử dụng giải pháp với ít overhead vận hành nhất (LEAST operational overhead), nghĩa là tự động hóa cao, dễ quản lý, tránh cấu hình thủ công ở từng tài khoản.
  • Chọn 2 bước kết hợp để đáp ứng.

Đây là chủ đề cốt lõi trong AWS CloudTrail kết hợp AWS Organizations và Amazon S3 Object Lock, giúp centralize logging cho multi-account environments. Giải pháp lý tưởng phải sử dụng Organization Trail để tự động log toàn org từ management account, và S3 với Object Lock in compliance mode để khóa immutable (không thể xóa/thay đổi) trong 2 năm. (Kiến thức cập nhật AWS 2024-2026: CloudTrail hỗ trợ organization trails với multi-region trails và integration S3 Object Lock).

✅ Đáp án đúng (Chọn 2)

Hai phương án đúng là:

  1. In the dedicated security account, create an Amazon S3 bucket. Configure S3 Object Lock in compliance mode and a retention period of 2 years on the S3 bucket. Set the bucket policy to allow the organization's management account to write to the S3 bucket.
  2. Create an AWS CloudTrail trail for the organization. Configure logs to be delivered to the logging Amazon S3 bucket in the dedicated security account.

Lý do lựa chọn:

  • 🛡️ S3 Object Lock (compliance mode) đảm bảo log immutable 2 năm (không xóa/thay đổi, ngay cả root user), phù hợp yêu cầu "no changes or deletions". Bucket policy chỉ cho management account write vì organization trail được tạo từ management account và deliver logs qua đó – giảm overhead, tránh cấp quyền trực tiếp cho member accounts (tuân thủ least privilege).
  • 🌐 Organization Trail tự động enable CloudTrail cho toàn bộ accounts trong org (bao gồm future accounts), deliver log centralized vào S3 của security account. Đây là cách least overhead vì chỉ cấu hình một lần từ management account, không cần bật CloudTrail riêng lẻ từng account.
  • Kết hợp: Overhead thấp nhất, scalable, secure. (Nguồn: AWS CloudTrail User Guide - Organization Trails, S3 Object Lock Docs).

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, với ✅ đúng hoặc ❌ sai:

  • ✅ In the dedicated security account, create an Amazon S3 bucket. Configure S3 Object Lock in compliance mode and a retention period of 2 years on the S3 bucket. Set the bucket policy to allow the organization's management account to write to the S3 bucket.
    🟢 Đúng: S3 Object Lock compliance mode khóa object immutable đúng 2 năm (legal hold-like), bucket policy chính xác cho management account (người deliver org trail logs). Least overhead vì chỉ config một bucket central. Hoàn hảo cho retention yêu cầu.

  • ❌ In the dedicated security account, create an Amazon S3 bucket. Configure S3 Object Lock in compliance mode and a retention period of 2 years on the S3 bucket. Set the bucket policy to allow the organization's member accounts to write to the S3 bucket.
    🔴 Sai: Object Lock đúng, nhưng bucket policy sai – cấp quyền write trực tiếp cho member accounts vi phạm least privilege, tăng rủi ro bảo mật (member có thể write junk data). Org trail không cần quyền này; management account handle delivery. Overhead cao hơn vì phải quản lý quyền cho nhiều accounts.

  • ❌ In the dedicated security account, create an Amazon S3 bucket that has an S3 Lifecycle configuration that expires objects after 2 years. Set the bucket policy to allow the organization's member accounts to write to the S3 bucket.
    🔴 Sai: S3 Lifecycle expire sau 2 năm trái ngược yêu cầu retain 2 năm không xóa. Không immutable (có thể delete thủ công). Policy cho member accounts cũng sai như trên. Không đáp ứng "no changes or deletions". (Nguồn: S3 Lifecycle vs Object Lock).

  • ✅ Create an AWS CloudTrail trail for the organization. Configure logs to be delivered to the logging Amazon S3 bucket in the dedicated security account.
    🟢 Đúng: Organization Trail tự động log tất cả activity từ mọi member accounts (data/management events), deliver central vào S3 security account. Chỉ config một lần từ management account → least overhead. Hỗ trợ cross-account delivery qua bucket policy. (Nguồn: CloudTrail Organization Features).

  • ❌ Turn on AWS CloudTrail in each account. Configure logs to be delivered to an Amazon S3 bucket that is created in the organization's management account. Forward the logs to the S3 bucket in the dedicated security account by using AWS Lambda and Amazon Kinesis Data Firehose.
    🔴 Sai: Phải bật CloudTrail thủ công từng account → high operational overhead (không scale với org lớn/future accounts). Forward qua Lambda + Kinesis: Phức tạp, tốn chi phí, không reliable bằng native org trail. Không least overhead.

🛠️ Khuyến nghị triển khai

  • Bước 1: Tạo S3 bucket với Object Lock ở security account, policy cho management ARN.
  • Bước 2: Từ management account, tạo org trail multi-region, deliver vào bucket đó.
  • Test: Kiểm tra logs ở security account sau 1-2 ngày activity. Enable CloudTrail Lake nếu cần query advanced (2024+ feature).

Tài liệu tham khảo chính:
📘 AWS Well-Architected Framework - Logging
📘 AWS Organizations + CloudTrail Best Practices.

Câu 253
A company is testing its incident response plan for compromised credentials. The company runs a database on an Amazon EC2 instance and stores the sensitive database credentials as a secret in AWS Secrets Manager. The secret has rotation configured with an AWS Lambda function that uses the generic rotation function template. The EC2 instance and the Lambda function are deployed in the same private subnet. The VPC has a Secrets Manager VPC endpoint.

A security engineer discovers that the secret cannot rotate. The security engineer determines that the VPC endpoint is working as intended. The Amazon CloudWatch logs contain the following error: "setSecret: Unable to log into database".

Which solution will resolve this error?
  1. A Use the AWS Management Console to edit the JSON structure of the secret in Secrets Manager so that the secret automatically conforms with the structure that the database requires.
  2. B Ensure that the security group that is attached to the Lambda function allows outbound connections to the EC2 instance. Ensure that the security group that is attached to the EC2 instance allows inbound connections from the security group that is attached to the Lambda function.
  3. C Use the Secrets Manager list-secrets command in the AWS CLI to list the secret. Identify the database credentials. Use the Secrets Manager rotate-secret command in the AWS CLI to force the immediate rotation of the secret.
  4. D Add an internet gateway to the VPC. Create a NAT gateway in a public subnet. Update the VPC route tables so that traffic from the Lambda function and traffic from the EC2 instance can reach the Secrets Manager public endpoint.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm AWS

📖 Nội dung câu hỏi:
Câu hỏi mô tả một tình huống thực tế trong AWS khi công ty đang kiểm tra kế hoạch phản ứng sự cố (incident response plan) liên quan đến credentials bị xâm phạm. Hệ thống bao gồm:

  • Một cơ sở dữ liệu (database) chạy trên Amazon EC2 instance.
  • Credentials nhạy cảm của database được lưu trữ dưới dạng secret trong AWS Secrets Manager.
  • Secret này được cấu hình rotation (xoay vòng tự động) sử dụng AWS Lambda function với generic rotation function template (mẫu hàm xoay vòng chung của AWS).
  • Cả EC2 instance và Lambda function đều nằm trong cùng một private subnet của VPC.
  • VPC có Secrets Manager VPC endpoint (điểm cuối VPC cho Secrets Manager), giúp truy cập dịch vụ mà không cần internet.

Vấn đề: Secret không thể rotate được. Kỹ sư bảo mật xác nhận VPC endpoint hoạt động bình thường. Trong Amazon CloudWatch logs của Lambda, lỗi cụ thể là "setSecret: Unable to log into database" – nghĩa là hàm Lambda không thể đăng nhập vào database để cập nhật secret mới (giai đoạn setSecret trong quy trình rotation).

🛠️ Nguyên nhân cốt lõi: Quy trình rotation của Secrets Manager với generic template bao gồm các bước: GenerateSecret (tạo secret mới), SetSecret (cập nhật secret vào database), TestSecret (kiểm tra), và FinishSecret (hoàn tất). Lỗi xảy ra ở SetSecret vì Lambda không kết nối được đến database trên EC2 (cùng private subnet), thường do vấn đề network connectivity nội bộ VPC, cụ thể là security groups chặn traffic giữa Lambda và EC2. VPC endpoint chỉ dùng cho truy cập Secrets Manager API, không ảnh hưởng đến kết nối Lambda → EC2.

✅ Đáp án đúng và lý do lựa chọn:
Đáp án đúng là:
Ensure that the security group that is attached to the Lambda function allows outbound connections to the EC2 instance. Ensure that the security group that is attached to the EC2 instance allows inbound connections from the security group that is attached to the Lambda function.

Lý do:

  • Lambda function cần outbound traffic đến EC2 instance trên port của database (ví dụ: 3306 cho MySQL, 5432 cho PostgreSQL) để thực hiện setSecret.
  • EC2 instance cần inbound traffic từ security group (SG) của Lambda để chấp nhận kết nối.
  • Vì cả hai cùng private subnet, traffic là internal VPC (không cần NAT/IGW), nhưng SG mặc định chặn hết nên phải cấu hình rõ ràng: SG Lambda outbound → SG EC2 inbound.
  • Điều này giải quyết trực tiếp lỗi "Unable to log into database" mà không ảnh hưởng VPC endpoint (đã ok). Kiến thức cập nhật AWS 2023-2026: Generic rotator vẫn yêu cầu network access đầy đủ giữa Lambda và DB (xem AWS Secrets Manager docs).

🔍 Giải thích tất cả các phương án (đúng/sai)

  • ❌ Phương án SAI: Use the AWS Management Console to edit the JSON structure of the secret in Secrets Manager so that the secret automatically conforms with the structure that the database requires.
    Giải thích: Việc chỉnh sửa JSON structure của secret qua Console chỉ thay đổi định dạng secret lưu trữ, không giải quyết vấn đề kết nối network. Lỗi là Lambda không log into database được (connectivity issue), không phải cấu trúc JSON sai. Generic template đã tự handle structure chuẩn; chỉnh tay có thể làm hỏng rotation tự động.

  • ✅ Phương án ĐÚNG: Ensure that the security group that is attached to the Lambda function allows outbound connections to the EC2 instance. Ensure that the security group that is attached to the EC2 instance allows inbound connections from the security group that is attached to the EC2 instance.
    Giải thích: Như đã nêu ở trên, đây là giải pháp chính xác vì traffic Lambda → EC2 bị chặn bởi SG. Cấu hình SG theo kiểu "self-referencing" (SG Lambda outbound to SG EC2, và ngược lại inbound) là best practice cho internal VPC communication trong rotation. Giải quyết ngay lỗi CloudWatch mà không cần thay đổi hạ tầng VPC.

  • ❌ Phương án SAI: Use the Secrets Manager list-secrets command in the AWS CLI to list the secret. Identify the database credentials. Use the Secrets Manager rotate-secret command in the AWS CLI to force the immediate rotation of the secret.
    Giải thích: Lệnh CLI list-secrets và rotate-secret chỉ force rotation thủ công, nhưng vẫn dùng Lambda function để thực hiện, nên lỗi connectivity không biến mất (Lambda vẫn fail setSecret). Đây chỉ là workaround tạm thời, không fix root cause; rotation tự động sẽ fail tiếp.

  • ❌ Phương án SAI: Add an internet gateway to the VPC. Create a NAT gateway in a public subnet. Update the VPC route tables so that traffic from the Lambda function and traffic from the EC2 instance can reach the Secrets Manager public endpoint.
    Giải thích: Không cần thiết vì VPC endpoint đã có và hoạt động (xác nhận trong câu hỏi), giúp truy cập Secrets Manager mà không qua internet. Vấn đề là kết nối internal giữa Lambda và EC2 (cùng private subnet), không liên quan public endpoint hay NAT/IGW. Thêm NAT chỉ làm phức tạp và tốn kém, vi phạm nguyên tắc least privilege.

📘 Tài liệu tham khảo (cập nhật AWS 2023-2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm ví dụ code Terraform/CloudFormation, hãy hỏi nhé!

Câu 254
A company needs to follow security best practices to deploy resources from an AWS CloudFormation template. The CloudFormation template must be able to configure sensitive database credentials.

The company already uses AWS Key Management Service (AWS KMS) and AWS Secrets Manager.

Which solution will meet the requirements?
  1. A Use a dynamic reference in the CloudFormation template to reference the database credentials in Secrets Manager.
  2. B Use a parameter in the CloudFormation template to reference the database credentials. Encrypt the CloudFormation template by using AWS KMS.
  3. C Use a SecureString parameter in the CloudFormation template to reference the database credentials in Secrets Manager.
  4. D Use a SecureString parameter in the CloudFormation template to reference an encrypted value in AWS KMS.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào best practices bảo mật khi triển khai tài nguyên AWS qua AWS CloudFormation template, cụ thể là cách cấu hình sensitive database credentials (như username/password cho database). Công ty đã sử dụng AWS KMS (dịch vụ quản lý khóa mã hóa) và AWS Secrets Manager (dịch vụ lưu trữ và quản lý bí mật an toàn).

Mục tiêu là chọn giải pháp an toàn nhất, tránh lộ thông tin nhạy cảm trong template, logs deploy, hoặc parameter inputs. CloudFormation hỗ trợ các cơ chế đặc biệt để xử lý dữ liệu nhạy cảm mà không cần hardcode hoặc truyền trực tiếp, tuân thủ nguyên tắc least privilege và zero-trust security theo tiêu chuẩn AWS mới nhất (cập nhật đến 2026, với hỗ trợ dynamic references nâng cao cho Secrets Manager).

✅ Đáp án đúng

Use a dynamic reference in the CloudFormation template to reference the database credentials in Secrets Manager.

Lý do lựa chọn:

  • Đây là best practice chính thức của AWS cho việc xử lý secrets trong CloudFormation. Dynamic reference (dạng {{resolve:secretsmanager:SecretId:SecretName:VersionStage}}) cho phép CloudFormation tự động retrieve giá trị secret từ Secrets Manager tại thời điểm runtime (khi stack tạo/update), mà không lưu giá trị thực tế vào template JSON/YAML, parameter store, hoặc CloudFormation logs/events.
  • Giá trị chỉ được giải mã tạm thời cho resource cần thiết (như RDS instance), sau đó bị xóa ngay, giảm rủi ro lộ thông tin.
  • Tích hợp hoàn hảo với KMS (Secrets Manager dùng KMS keys để mã hóa), hỗ trợ rotation tự động secrets. Điều này đáp ứng đầy đủ yêu cầu bảo mật mà không cần can thiệp thủ công. ✅

🛠️ Phân tích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá dựa trên tính an toàn, khả năng thực thi và tuân thủ best practices AWS (theo docs cập nhật 2026).

  • ✅ Use a dynamic reference in the CloudFormation template to reference the database credentials in Secrets Manager.
    Giải thích đúng: Như đã nêu ở trên, đây là phương pháp an toàn và hiệu quả nhất. Dynamic reference đảm bảo secrets không bao giờ lộ ra ngoài Secrets Manager, hỗ trợ versioning và ARNs đầy đủ. Ví dụ syntax: {{resolve:secretsmanager:arn:aws:secretsmanager:region:account:secret:MyDBSecret:AWSCURRENT}}. Hoàn toàn phù hợp với yêu cầu. 🏆

  • ❌ Use a parameter in the CloudFormation template to reference the database credentials. Encrypt the CloudFormation template by using AWS KMS.
    Giải thích sai: Parameter thông thường (String/NoEcho) yêu cầu truyền giá trị credentials trực tiếp khi deploy (qua CLI/console), dễ bị lộ trong command history, CloudTrail logs hoặc shared templates. Việc mã hóa toàn bộ template bằng KMS (qua CloudFormation template encryption feature) chỉ bảo vệ template file, không bảo vệ giá trị parameter nhạy cảm – creds vẫn plain text khi inject vào stack. Không phải best practice, rủi ro cao. 🚫

  • ❌ Use a SecureString parameter in the CloudFormation template to reference the database credentials in Secrets Manager.
    Giải thích sai: SecureString parameter chỉ mã hóa giá trị input khi lưu trong CloudFormation (sử dụng KMS default key), và ẩn trong console/logs (NoEcho=true). Tuy nhiên, nó không tự động reference hoặc retrieve từ Secrets Manager – người dùng vẫn phải copy-paste giá trị secret thủ công từ Secrets Manager vào parameter khi deploy, dẫn đến lộ thông tin tạm thời. Không hỗ trợ dynamic retrieval, vi phạm zero-trust. ❌

  • ❌ Use a SecureString parameter in the CloudFormation template to reference an encrypted value in AWS KMS.
    Giải thích sai: SecureString có thể mã hóa bằng custom KMS key, nhưng không trực tiếp reference giá trị đã mã hóa từ KMS như một blob. KMS chỉ cung cấp encrypt/decrypt APIs, không lưu trữ persistent data (dùng SSM hoặc Secrets Manager cho việc đó). Phương án này yêu cầu truyền ciphertext thủ công, vẫn lộ khi decrypt trong stack, và không tận dụng Secrets Manager cho DB creds (chỉ KMS thuần). Không an toàn bằng dynamic reference. 🔒🚫

📘 Tài liệu tham khảo

Phương pháp này giúp deploy an toàn, scalable! 🚀

Câu 255 Chọn nhiều đáp án
An international company wants to combine AWS Security Hub findings across all the company's AWS Regions and from multiple accounts. In addition, the company wants to create a centralized custom dashboard to correlate these findings with operational data for deeper analysis and insights. The company needs an analytics tool to search and visualize Security Hub findings.

Which combination of steps will meet these requirements? (Chose three.)
  1. A Designate an AWS account as a delegated administrator for Security Hub. Publish events to Amazon CloudWatch from the delegated administrator account, all member accounts, and required Regions that are enabled for Security Hub findings.
  2. B Designate an AWS account in an organization in AWS Organizations as a delegated administrator for Security Hub. Publish events to Amazon EventBridge from the delegated administrator account, all member accounts, and required Regions that are enabled for Security Hub findings.
  3. C In each Region, create an Amazon EventBridge rule to deliver findings to an Amazon Kinesis data stream. Configure the Kinesis data streams to output the logs to a single Amazon S3 bucket.
  4. D In each Region, create an Amazon EventBridge rule to deliver findings to an Amazon Kinesis Data Firehose delivery stream. Configure the Kinesis Data Firehose delivery streams to deliver the logs to a single Amazon S3 bucket.
  5. E Use AWS Glue DataBrew to crawl the Amazon S3 bucket and build the schema. Use AWS Glue Data Catalog to query the data and create views to flatten nested attributes. Build Amazon QuickSight dashboards by using Amazon Athena.
  6. F Partition the Amazon S3 data. Use AWS Glue to crawl the S3 bucket and build the schema. Use Amazon Athena to query the data and create views to flatten nested attributes. Build Amazon QuickSight dashboards that use the Athena views.
Xem giải thích

🧩 Phân tích câu hỏi trắc nghiệm AWS Security Hub

📘 Giải thích nội dung câu hỏi:
Câu hỏi mô tả một công ty quốc tế muốn tập trung hóa (centralize) các findings từ AWS Security Hub trên tất cả các AWS Regions và nhiều AWS accounts. Ngoài ra, họ cần tạo dashboard tùy chỉnh tập trung để tương quan (correlate) các findings này với dữ liệu hoạt động (operational data), nhằm phân tích sâu hơn và rút ra insights. Họ cũng yêu cầu một công cụ phân tích để tìm kiếm và trực quan hóa findings từ Security Hub.
Yêu cầu chọn ba bước kết hợp để đáp ứng đầy đủ, liên quan đến: thiết lập delegated admin, streaming events/findings, và phân tích dữ liệu trên S3 với dashboard. Đây là kịch bản phổ biến cho multi-account/multi-region Security Hub aggregation, sử dụng AWS Organizations, EventBridge, Kinesis, S3, Glue, Athena, và QuickSight (theo docs AWS cập nhật 2024-2026).

✅ Đáp án đúng (chọn 3):
Các lựa chọn đúng là:

  • Designate an AWS account in an organization in AWS Organizations as a delegated administrator for Security Hub. Publish events to Amazon EventBridge from the delegated administrator account, all member accounts, and required Regions that are enabled for Security Hub findings.
  • In each Region, create an Amazon EventBridge rule to deliver findings to an Amazon Kinesis Data Firehose delivery stream. Configure the Kinesis Data Firehose delivery streams to deliver the logs to a single Amazon S3 bucket.
  • Partition the Amazon S3 data. Use AWS Glue to crawl the S3 bucket and build the schema. Use Amazon Athena to query the data and create views to flatten nested attributes. Build Amazon QuickSight dashboards that use the Athena views.

🛠️ Lý do lựa chọn các đáp án đúng:
Kết hợp này hoàn hảo vì:

  • Delegated admin với EventBridge thiết lập aggregation từ multi-account/Region (Security Hub yêu cầu Organizations delegated admin để enable cross-account).
  • EventBridge → Kinesis Data Firehose → S3 stream findings hiệu quả vào bucket trung tâm (Firehose tự buffer và deliver batch).
  • Partition S3 + Glue Crawler + Athena + QuickSight cho phép query nhanh, flatten JSON nested (findings là JSON phức tạp), và dashboard tương quan dữ liệu. Điều này hỗ trợ phân tích sâu và visualization theo best practices AWS 2026.

🔍 Giải thích chi tiết từng phương án (đúng/sai):

  • ❌ SAI: Designate an AWS account as a delegated administrator for Security Hub. Publish events to Amazon CloudWatch from the delegated administrator account, all member accounts, and required Regions that are enabled for Security Hub findings.
    Phương án này không chính xác vì Security Hub tích hợp trực tiếp với Amazon EventBridge (trước là CloudWatch Events, nhưng hiện tại là EventBridge để publish findings/events). Sử dụng CloudWatch không phải cách chuẩn cho aggregation findings; nó thiếu tính năng rule-based routing linh hoạt cross-account/Region. Delegated admin cần chỉ định trong AWS Organizations, không chỉ "an AWS account" chung chung.

  • ✅ ĐÚNG: Designate an AWS account in an organization in AWS Organizations as a delegated administrator for Security Hub. Publish events to Amazon EventBridge from the delegated administrator account, all member accounts, and required Regions that are enabled for Security Hub findings.
    Đây là bước đầu tiên bắt buộc: Chỉ định delegated admin trong AWS Organizations để enable Security Hub multi-account (member accounts tự động join). Findings được publish tự động qua EventBridge từ delegated admin, members, và các Regions enabled – chuẩn theo AWS docs để centralize insights.

  • ❌ SAI: In each Region, create an Amazon EventBridge rule to deliver findings to an Amazon Kinesis data stream. Configure the Kinesis data streams to output the logs to a single Amazon S3 bucket.
    Không khả thi vì Kinesis Data Streams không hỗ trợ output trực tiếp đến S3 (nó cần consumer riêng như Lambda hoặc Kinesis Agent để pull data). Streams chỉ lưu tạm 24h-365d, không batch deliver tự động như Firehose, dẫn đến mất dữ liệu hoặc phức tạp hóa.

  • ✅ ĐÚNG: In each Region, create an Amazon EventBridge rule to deliver findings to an Amazon Kinesis Data Firehose delivery stream. Configure the Kinesis Data Firehose delivery streams to deliver the logs to a single Amazon S3 bucket.
    Hoàn hảo cho streaming: EventBridge rule target Kinesis Data Firehose (per Region) để buffer và deliver trực tiếp vào S3 bucket trung tâm (cross-Region via replication nếu cần). Firehose hỗ trợ transformation, compression, và error handling – lý tưởng cho log volume cao từ Security Hub.

  • ❌ SAI: Use AWS Glue DataBrew to crawl the Amazon S3 bucket and build the schema. Use AWS Glue Data Catalog to query the data and create views to flatten nested attributes. Build Amazon QuickSight dashboards by using Amazon Athena.
    Không phù hợp vì Glue DataBrew dùng cho data preparation/cleaning tương tác (không crawl schema tự động như Glue Crawler). Query trực tiếp Glue Catalog mà không qua Athena kém hiệu quả; thiếu partitioning S3 dẫn đến query chậm trên dữ liệu lớn/nested JSON findings.

  • ✅ ĐÚNG: Partition the Amazon S3 data. Use AWS Glue to crawl the S3 bucket and build the schema. Use Amazon Athena to query the data and create views to flatten nested attributes. Build Amazon QuickSight dashboards that use the Athena views.
    Best practice cho analytics: Partition S3 (ví dụ: by date/account/Region) tối ưu query cost/performance. Glue Crawler tự build schema vào Data Catalog. Athena query serverless, tạo views flatten nested fields (findings JSON phức tạp). QuickSight connect Athena views để dashboard tương quan operational data – hỗ trợ search/visualize đầy đủ.

📚 Tài liệu tham khảo (AWS cập nhật 2024-2026):

💡 Lời khuyên DevOps: Kết hợp này scalable, serverless, và cost-effective cho production! 🚀

Câu 256
An AWS account administrator created an IAM group and applied the following managed policy to require that each individual user authenticate using multi-factor authentication:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "ec2:*",
      "Resource": "*"
    },
    {
      "Sid": "BlockAnyAccessUnlessSignedInWithMFA",
      "Effect": "Deny",
      "Action": "ec2:*",
      "Resource": "*",
      "Condition": {
        "BoolIfExists": {
          "aws:MultiFactorAuthPresent": false
        }
      }
    }
  ]
}


After implementing the policy, the administrator receives reports that users are unable to perform Amazon EC2 commands using the AWS CLI.

What should the administrator do to resolve this problem while still enforcing multi-factor authentication?
  1. A Change the value of aws:MultiFactorAuthPresent to true.
  2. B Instruct users to run the aws sts get-session-token CLI command and pass the multi-factor authentication --serial-number and -token-code parameters. Use these resulting values to make API/CLI calls.
  3. C Implement federated API/CLI access using SAML 2.0, then configure the identity provider to enforce multi-factor authentication.
  4. D Create a role and enforce multi-factor authentication in the role trust policy. Instruct users to run the sts assume-role CLI command and pass --serial-number and --token-code parameters. Store the resulting values in environment variables. Add sts:AssumeRole to NotAction in the policy.
Xem giải thích

🧩 Giải thích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh một chính sách IAM (Identity and Access Management) được áp dụng cho một nhóm người dùng (IAM group) trong tài khoản AWS. Mục tiêu chính của policy là buộc người dùng phải xác thực bằng Multi-Factor Authentication (MFA) trước khi thực hiện bất kỳ hành động nào trên Amazon EC2 (như ec2:*).

📜 Nội dung policy cụ thể:

  • Statement 1: Cho phép (Allow) tất cả hành động EC2 trên mọi tài nguyên (ec2:* trên *).
  • Statement 2 (có Sid "BlockAnyAccessUnlessSignedInWithMFA"): Từ chối (Deny) tất cả hành động EC2 nếu điều kiện aws:MultiFactorAuthPresent không tồn tại hoặc là false (sử dụng BoolIfExists với giá trị false).
    • Nghĩa là: Policy chỉ cho phép EC2 nếu session hiện tại đã được xác thực MFA (aws:MultiFactorAuthPresent: true).

🛑 Vấn đề xảy ra: Sau khi áp dụng policy, quản trị viên nhận báo cáo rằng người dùng không thể thực hiện lệnh EC2 qua AWS CLI. Lý do: AWS CLI sử dụng access key/secret key dài hạn (long-term credentials) mặc định, không tự động bao gồm MFA. Do đó, aws:MultiFactorAuthPresent là false, kích hoạt rule Deny → block toàn bộ EC2 commands.

🎯 Yêu cầu giải quyết: Tìm cách khắc phục vấn đề (cho phép CLI hoạt động) nhưng vẫn enforce MFA (không bỏ yêu cầu MFA).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Instruct users to run the aws sts get-session-token CLI command and pass the multi-factor authentication --serial-number and -token-code parameters. Use these resulting values to make API/CLI calls.

Lý do chi tiết:

  • Lệnh aws sts get-session-token (Security Token Service) tạo temporary credentials (AccessKeyId, SecretAccessKey, SessionToken) với thời hạn ngắn (mặc định 12 giờ, tối đa 36 giờ).
  • Người dùng phải cung cấp ARN của MFA device (--serial-number) và MFA code tạm thời (--token-code) → session mới tự động set aws:MultiFactorAuthPresent: true.
  • Sau đó, export các giá trị này vào environment variables (như AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN) để AWS CLI sử dụng → CLI commands EC2 sẽ pass qua policy (bypass Deny vì MFA present).
  • 🛡️ Vẫn enforce MFA: Mỗi session hết hạn phải renew bằng MFA code mới, đảm bảo an ninh.
  • Đây là best practice cho CLI với MFA-conditional policies, theo docs AWS mới nhất (2026).

📋 Phân tích tất cả các phương án (đúng/sai)

  • ❌ SAI: Change the value of aws:MultiFactorAuthPresent to true.
    Giải thích: Thay đổi giá trị aws:MultiFactorAuthPresent thành true trong condition sẽ làm policy luôn Allow (vì Deny chỉ kích hoạt khi false), loại bỏ hoàn toàn enforce MFA. Điều này vi phạm yêu cầu "vẫn enforcing MFA". Hơn nữa, aws:MultiFactorAuthPresent là global condition key do AWS tự đánh giá, không phải giá trị do admin set thủ công.

  • ✅ ĐÚNG: Instruct users to run the aws sts get-session-token CLI command and pass the multi-factor authentication --serial-number and -token-code parameters. Use these resulting values to make API/CLI calls.
    Giải thích: Như đã phân tích ở trên. Phương án này trực tiếp giải quyết vấn đề CLI bằng temporary credentials có MFA, không thay đổi policy, và duy trì enforce MFA cho mọi session mới. Hoàn hảo cho AWS CLI/console.

  • ❌ SAI: Implement federated API/CLI access using SAML 2.0, then configure the identity provider to enforce multi-factor authentication.
    Giải thích: SAML 2.0 federation (với IdP như Okta/ADFS) có thể enforce MFA ở IdP, nhưng không giải quyết ngay vấn đề hiện tại (user vẫn dùng CLI với long-term keys bị block). Nó yêu cầu setup phức tạp mới (IAM roles, IdP config), không phải fix nhanh cho CLI EC2. Ngoài ra, CLI vẫn cần temporary creds từ STS sau federation, không đơn giản như get-session-token.

  • ❌ SAI: Create a role and enforce multi-factor authentication in the role trust policy. Instruct users to run the sts assume-role CLI command and pass --serial-number and --token-code parameters. Store the resulting values in environment variables. Add sts:AssumeRole to NotAction in the policy.
    Giải thích:

    • Trust policy của role không hỗ trợ condition MFA trực tiếp như aws:MultiFactorAuthPresent (trust policy chỉ check principal, không check MFA của user gốc). Phải dùng sts:AssumeRoleWithSAML hoặc workaround khác.
    • sts:AssumeRole KHÔNG hỗ trợ --serial-number/-token-code trực tiếp cho IAM users (chỉ cho root/STS GetSessionToken).
    • Add sts:AssumeRole to NotAction là sai syntax (policy dùng Action/NotAction, nhưng ở đây policy chỉ về EC2, không liên quan STS).
    • Tổng thể: Không khả thi và phức tạp hóa, không fix CLI EC2 trực tiếp.

📘 Tài liệu tham khảo (AWS docs cập nhật 2026)

🛠️ Lời khuyên: Luôn test policy với IAM Policy Simulator trước khi apply! Nếu cần scale, kết hợp với AWS SSO hoặc IAM Identity Center cho MFA tự động.

Câu 257
A company is developing a mechanism that will help data scientists use Amazon SageMaker to read, process, and output data to an Amazon S3 bucket. Data scientists will have access to a dedicated S3 prefix for each of their projects. The company will implement bucket policies that use the dedicated S3 prefixes to restrict access to the S3 objects. The projects can last up to 60 days.

The company's security team mandates that data cannot remain in the S3 bucket after the end of the projects that use the data.

Which solution will meet these requirements MOST cost-effectively?
  1. A Create an AWS Lambda function to identify and delete objects in the S3 bucket that have not been accessed for 60 days. Create an Amazon EventBridge scheduled rule that runs every day to invoke the Lambda function.
  2. B Create a new S3 bucket. Configure the new S3 bucket to use S3 Intelligent-Tiering. Copy the objects to the new S3 bucket.
  3. C Create an S3 Lifecycle configuration for each S3 bucket prefix for each project. Set the S3 Lifecycle configurations to expire objects after 60 days.
  4. D Create an AWS Lambda function to delete objects that have not been accessed for 60 days. Create an S3 event notification for S3 Intelligent-Tiering automatic archival events to invoke the Lambda function.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi xoay quanh việc xây dựng cơ chế tự động xóa dữ liệu trong Amazon S3 sau khi các dự án của data scientists kết thúc (tối đa 60 ngày). Các data scientists sử dụng Amazon SageMaker để đọc, xử lý và lưu dữ liệu vào một S3 bucket chung, nhưng mỗi dự án có prefix riêng (ví dụ: s3://bucket/project1/). Bucket policy đã được thiết lập để hạn chế truy cập chỉ vào prefix tương ứng. Yêu cầu bảo mật: Dữ liệu phải bị xóa hoàn toàn sau 60 ngày, tránh lưu trữ lâu dài. Giải pháp cần tiết kiệm chi phí nhất (MOST cost-effectively), tận dụng các tính năng AWS tự động, không tốn kém vận hành thủ công.

📘 Kiến thức AWS cập nhật (đến 2026): S3 hỗ trợ Lifecycle policies áp dụng cho prefix/folder cụ thể, tự động expire objects sau thời gian định sẵn (không cần Lambda). Đây là cách chuẩn theo AWS Well-Architected Framework (Pillar: Cost Optimization & Security).

🔗 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create an S3 Lifecycle configuration for each S3 bucket prefix for each project. Set the S3 Lifecycle configurations to expire objects after 60 days.

Lý do 🛠️:

  • Giải pháp này tự động hóa hoàn toàn việc xóa objects sau đúng 60 ngày (dựa trên tuổi của object - age), áp dụng riêng cho từng prefix dự án mà không ảnh hưởng bucket khác.
  • Tiết kiệm chi phí nhất vì S3 Lifecycle miễn phí (chỉ tính phí storage đến khi xóa), không cần Lambda invocations, EventBridge hay copy data.
  • Phù hợp yêu cầu: Data scientists upload vào prefix → Sau 60 ngày (kết thúc project) → Tự động permanent delete (expire rule chuyển sang Glacier Deep Archive rồi xóa, hoặc trực tiếp delete).
  • Dễ triển khai: Tạo rule Lifecycle qua Console/CLI cho prefix cụ thể (e.g., project1/*), hỗ trợ scale cho nhiều project.

📋 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, với emoji nổi bật và giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá dựa trên tính đúng/sai, hiệu quả chi phí và phù hợp yêu cầu (xóa sau 60 ngày, prefix-specific).

  • ❌ [SAI] Create an AWS Lambda function to identify and delete objects in the S3 bucket that have not been accessed for 60 days. Create an Amazon EventBridge scheduled rule that runs every day to invoke the Lambda function.

    • Giải thích sai: Phương án dùng Lambda scan toàn bucket hàng ngày dựa trên last access time (qua S3 Inventory hoặc GetObject), rồi xóa. ❌ Không cost-effective vì: Lambda chạy daily → Hàng nghìn invocations/tháng (chi phí ~$0.20/1M requests + execution time), cộng scan storage lớn (tốn GET requests). Không chính xác "sau 60 ngày project" (dùng access time thay vì creation time). Phức tạp scale cho nhiều prefix, vi phạm "MOST cost-effectively".
  • ❌ [SAI] Create a new S3 bucket. Configure the new S3 bucket to use S3 Intelligent-Tiering. Copy the objects to the new S3 bucket.

    • Giải thích sai: Tạo bucket mới với S3 Intelligent-Tiering (tự động tier IA/Glacier dựa trên access patterns) và copy data. ❌ Không đáp ứng yêu cầu xóa data sau 60 ngày (Intelligent-Tiering chỉ giảm chi phí storage, không expire/delete tự động). Copy tốn chi phí PUT/GET lớn, storage kép (old + new bucket), không prefix-specific. Không an toàn bảo mật (data vẫn tồn tại lâu dài ở tiers rẻ).
  • ✅ [ĐÚNG] Create an S3 Lifecycle configuration for each S3 bucket prefix for each project. Set the S3 Lifecycle configurations to expire objects after 60 days.

    • Giải thích đúng: Như đã nêu ở phần đáp án ✅. Hoàn hảo: Prefix-specific (rule filter Prefix: project1/), expire sau 60 ngày (creation date), zero operational cost ngoài storage ban đầu. Hỗ trợ SageMaker output trực tiếp vào prefix. Theo AWS re:Post 2025, đây là best practice cho temporary project data.
  • ❌ [SAI] Create an AWS Lambda function to delete objects that have not been accessed for 60 days. Create an S3 event notification for S3 Intelligent-Tiering automatic archival events to invoke the Lambda function.

    • Giải thích sai: Kết hợp Lambda delete dựa trên access + S3 Event cho Intelligent-Tiering archival (khi object vào Archive tier). ❌ Sai cơ bản: Intelligent-Tiering không trigger event cho archival tự động (events chỉ cho PUT/DELETE/Lifecycle expiry, không phải tiering nội bộ). Phụ thuộc access time (không phải project end), tốn Lambda chi phí, không prefix-specific, và không đảm bảo xóa sau 60 ngày fixed. Phức tạp, không reliable theo AWS docs 2026.

Kết luận 🚀: Sử dụng S3 Lifecycle là lựa pháp optimal theo DevOps best practices – automate, secure, low-cost! Nếu triển khai, dùng AWS CDK/Terraform để provision rules động cho từng project.

Câu 258
A company has AWS accounts that are in an organization in AWS Organizations. An Amazon S3 bucket in one of the accounts is publicly accessible.

A security engineer must change the configuration so that the S3 bucket is no longer publicly accessible. The security engineer also must ensure that the S3 bucket cannot be made publicly accessible in the future.

Which solution will meet these requirements?
  1. A Configure the S3 bucket to use an AWS Key Management Service (AWS KMS) key. Encrypt all objects in the S3 bucket by creating a bucket policy that enforces encryption. Configure an SCP to deny the s3:GetObject action for the OU that contains the AWS account.
  2. B Enable the PublicAccessBlock configuration on the S3 bucket. Configure an SCP to deny the s3:GetObject action for the OU that contains the AWS account.
  3. C Enable the PublicAccessBlock configuration on the S3 bucket. Configure an SCP to deny the s3:PutPublicAccessBlock action for the OU that contains the AWS account.
  4. D Configure the S3 bucket to use S3 Object Lock in governance mode. Configure an SCP to deny the s3:PutPublicAccessBlock action for the OU that contains the AWS account.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh tình huống một công ty sử dụng AWS Organizations với nhiều AWS accounts. Có một Amazon S3 bucket trong một account đang công khai (publicly accessible), nghĩa là bất kỳ ai trên internet có thể truy cập dữ liệu mà không cần xác thực. Nhiệm vụ của security engineer là:

  • Thay đổi cấu hình ngay lập tức để bucket không còn công khai.
  • Đảm bảo bucket không thể bị làm công khai trong tương lai, ngay cả bởi các admin trong account hoặc organization.

🔑 Yêu cầu cốt lõi:

  • Sử dụng S3 Block Public Access để chặn các ACL, bucket policies, hoặc IAM policies làm bucket public.
  • Kết hợp Service Control Policy (SCP) ở mức AWS Organizations (áp dụng cho Organizational Unit - OU chứa account) để ngăn chặn việc thay đổi cấu hình này vĩnh viễn.
  • Giải pháp phải toàn diện, không chỉ chặn đọc dữ liệu mà còn ngăn tạo public access từ gốc.

Đây là kiến thức chuẩn từ AWS Well-Architected Framework (Security Pillar) và cập nhật đến 2026 (S3 Block Public Access vẫn là tính năng chính thức, hỗ trợ 4 tùy chọn block: Block public ACLs, Block public bucket policies, Ignore public ACLs, Restrict public buckets).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Enable the PublicAccessBlock configuration on the S3 bucket. Configure an SCP to deny the s3:PutPublicAccessBlock action for the OU that contains the AWS account.

Lý do 🛠️:

  • Enable PublicAccessBlock: Ngay lập tức chặn bucket trở thành public bằng cách kích hoạt 4 tùy chọn block (Block Public Access). Bucket sẽ không còn accessible publicly (áp dụng cho cả bucket hiện tại và object mới).
  • SCP deny s3:PutPublicAccessBlock: Hành động s3:PutPublicAccessBlock dùng để tắt/modify Block Public Access. SCP ở mức OU ngăn toàn bộ account/OU thực hiện hành động này, đảm bảo không thể làm public trong tương lai (kể cả root user). SCP chỉ deny, không block các action khác cần thiết như GetObject với IAM.
  • Hoàn hảo match yêu cầu: Bucket-level block + Organization-level guardrail. Không ảnh hưởng performance, chi phí thấp.

📋 Giải thích tất cả các phương án (đúng/sai)

  • Phương án 1 ❌:
    Configure the S3 bucket to use an AWS Key Management Service (AWS KMS) key. Encrypt all objects in the S3 bucket by creating a bucket policy that enforces encryption. Configure an SCP to deny the s3:GetObject action for the OU that contains the AWS account.
    Phân tích sai 🚫: Encryption (KMS + bucket policy) chỉ bảo vệ dữ liệu tại rest, không chặn public access (vẫn có thể GetObject nếu public policy/ACL tồn tại). SCP deny s3:GetObject quá rộng, block tất cả đọc dữ liệu (kể cả authenticated users), gây downtime app. Không ngăn tạo public policy tương lai.

  • Phương án 2 ❌:
    Enable the PublicAccessBlock configuration on the S3 bucket. Configure an SCP to deny the s3:GetObject action for the OU that contains the AWS account.
    Phân tích sai 🚫: Phần enable Block đúng (chặn public ngay). Nhưng SCP deny s3:GetObject không liên quan, chỉ block đọc public/authorized, không ngăn tắt Block hoặc tạo public policy. Bucket vẫn có thể bị làm public nếu ai đó dùng s3:PutPublicAccessBlock để tắt.

  • Phương án 3 ✅ (Đúng - đã nêu ở trên):
    Enable the PublicAccessBlock configuration on the S3 bucket. Configure an SCP to deny the s3:PutPublicAccessBlock action for the OU that contains the AWS account.
    Phân tích đúng 🟢: Kết hợp hoàn hảo bucket-level fix + preventive SCP. SCP chính xác target action cần deny, không ảnh hưởng operations khác. Đảm bảo tuân thủ zero-trust ở Organizations.

  • Phương án 4 ❌:
    Configure the S3 bucket to use S3 Object Lock in governance mode. Configure an SCP to deny the s3:PutPublicAccessBlock action for the OU that contains the AWS account.
    Phân tích sai 🚫: S3 Object Lock (governance mode) chỉ khóa object không delete/modify trong retention period, không chặn public access (bucket vẫn public nếu ACL/policy cho phép). SCP phần đúng nhưng Object Lock không giải quyết yêu cầu chính (chỉ bảo vệ compliance, không phải security public).

📘 Tài liệu tham khảo (cập nhật 2026)

Giải pháp này an toàn, scalable cho enterprise! 🚀 Nếu cần demo Terraform/CLI, hỏi thêm nhé!

Câu 259 Chọn nhiều đáp án
A company is designing a new application stack. The design includes web servers and backend servers that are hosted on Amazon EC2 instances. The design also includes an Amazon Aurora MySQL DB cluster.

The EC2 instances are in an Auto Scaling group that uses launch templates. The EC2 instances for the web layer and the backend layer are backed by Amazon Elastic Block Store (Amazon EBS) volumes. No layers are encrypted at rest A security engineer needs to implement encryption at rest.

Which combination of steps will meet these requirements? (Choose two.)
  1. A Modify EBS default encryption settings in the target AWS Region to enable encryption. Use an Auto Scaling group instance refresh.
  2. B Modify the launch templates for the web layer and the backend layer to add AWS Certificate Manager (ACM) encryption for the attached EBS volumes. Use an Auto Scaling group instance refresh.
  3. C Create a new AWS Key Management Service (AWS KMS) encrypted DB cluster from a snapshot of the existing DB cluster.
  4. D Apply AWS Key Management Service (AWS KMS) encryption to the existing DB cluster.
  5. E Apply AWS Certificate Manager (ACM) encryption to the existing DB cluster.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai mã hóa dữ liệu tại chỗ (encryption at rest) cho một stack ứng dụng AWS mới. Cụ thể:

  • Web servers và backend servers chạy trên Amazon EC2 instances, nằm trong Auto Scaling Group (ASG) sử dụng launch templates.
  • Các EC2 này sử dụng Amazon EBS volumes làm lưu trữ, không được mã hóa tại chỗ.
  • Có Amazon Aurora MySQL DB cluster cũng không mã hóa tại chỗ.
  • Yêu cầu: Security engineer cần implement encryption at rest cho tất cả các layers (EC2/EBS và DB).
  • Loại câu hỏi: Multiple choice chọn TWO steps kết hợp để đáp ứng yêu cầu, đảm bảo tính khả thi, không downtime lớn, và tuân thủ best practices AWS.

Mục tiêu là mã hóa EBS volumes cho EC2/ASG và Aurora DB cluster, sử dụng các dịch vụ như KMS cho key management. AWS không cho phép bật mã hóa trực tiếp trên tài nguyên hiện có trong một số trường hợp, nên cần các bước gián tiếp như snapshot hoặc default settings.

✅ Đáp án đúng (Chọn TWO)

Hai phương án đúng là:

  1. Modify EBS default encryption settings in the target AWS Region to enable encryption. Use an Auto Scaling group instance refresh.
  2. Create a new AWS Key Management Service (AWS KMS) encrypted DB cluster from a snapshot of the existing DB cluster.

Lý do lựa chọn:

  • 🛠️ Phương án 1: Bật default EBS encryption ở Region sẽ tự động mã hóa tất cả EBS volumes mới (bao gồm khi ASG launch/replace instances). Kết hợp ASG instance refresh (tính năng AWS cho phép rolling update instances mà không downtime) để thay thế instances cũ bằng mới (encrypted EBS). Đây là cách scaleable và không cần modify launch templates ngay lập tức, phù hợp với thiết kế hiện tại.
  • 🛠️ Phương án 2: Aurora DB không hỗ trợ bật encryption sau khi tạo. Phải snapshot DB hiện tại, rồi restore snapshot thành DB cluster mới với KMS encryption enabled. Sau đó, cập nhật ứng dụng point đến cluster mới (minimal downtime với blue-green deployment).
  • Kết hợp hai bước này meet 100% requirements: Mã hóa EBS cho EC2/ASG và DB, sử dụng KMS, không vi phạm quy tắc "no layers encrypted at rest" ban đầu.

📝 Giải thích tất cả các phương án (Đúng/Sai)

Dưới đây là phân tích từng phương án một, giữ nguyên văn bản gốc tiếng Anh. Mỗi giải thích sử dụng kiến thức AWS cập nhật đến 2026 (EBS default encryption hỗ trợ KMS keys tùy chỉnh; Aurora v3+ vẫn yêu cầu snapshot cho encryption retroactive).

  • ✅ Modify EBS default encryption settings in the target AWS Region to enable encryption. Use an Auto Scaling group instance refresh.
    Đúng: Như giải thích trên, đây là best practice AWS cho EBS fleet-wide encryption. Instance refresh đảm bảo ASG rolling update (0-100% capacity), instances mới tự encrypt mà không cần edit launch templates. Hiệu quả cho production scale.

  • ❌ Modify the launch templates for the web layer and the backend layer to add AWS Certificate Manager (ACM) encryption for the attached EBS volumes. Use an Auto Scaling group instance refresh.
    Sai: ACM chỉ dùng cho SSL/TLS certificates (web traffic encryption in transit), KHÔNG hỗ trợ encryption at rest cho EBS. Modify launch templates cho EBS cần dùng Encrypted=true và KMS key ID, không phải ACM. Dù instance refresh đúng, nhưng ACM làm sai hoàn toàn.

  • ✅ Create a new AWS Key Management Service (AWS KMS) encrypted DB cluster from a snapshot of the existing DB cluster.
    Đúng: Theo docs AWS, Aurora không thể modify encryption trên existing cluster. Snapshot là cách chuẩn và an toàn để migrate sang cluster mới với StorageEncrypted=true và KMS key. Hỗ trợ multi-AZ, zero-ETL replication để minimize downtime.

  • ❌ Apply AWS Key Management Service (AWS KMS) encryption to the existing DB cluster.
    Sai: Aurora/MySQL không hỗ trợ bật KMS encryption sau khi cluster created (immutable property). Thử apply sẽ fail với error "encryption can't be enabled on existing cluster". Phải dùng snapshot method ở phương án đúng.

  • ❌ Apply AWS Certificate Manager (ACM) encryption to the existing DB cluster.
    Sai: ACM KHÔNG liên quan đến DB encryption at rest (chỉ certificates cho HTTPS/ELB). Aurora dùng RDS encryption với KMS/AWS-managed keys, không phải ACM. Đây là distractor rõ ràng, apply sẽ invalid.

📘 Tài liệu tham khảo (AWS Docs cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm ví dụ code Terraform/CLI, hãy hỏi nhé!

Câu 260 Chọn nhiều đáp án
A company uses SAML federation with AWS Identity and Access Management (IAM) to provide internal users with SSO for their AWS accounts. The company's identity provider certificate was rotated as part of its normal lifecycle Shortly after users started receiving the following error when attempting to log in:

“Error: Response Signature Invalid (Service: AWSSecurityTokenService; Status Code: 400; Error Code: InvalidIdentityToken)”

A security engineer needs to address the immediate issue and ensure that it will not occur again. Which combination of steps should the security engineer take to accomplish this? (Choose two.)
  1. A Download a new copy of the SAML metadata file from the identity provider. Create a new IAM identity provider entity. Upload the new metadata file to the new IAM identity provider entity.
  2. B During the next certificate rotation period and before the current certificate expires, add a new certificate as the secondary to the identity provider. Generate a new metadata file and upload it to the IAM identity provider entity. Perform automated or manual rotation of the certificate when required.
  3. C Download a new copy of the SAML metadata file from the identity provider. Upload the new metadata to the IAM identity provider entity configured for the SAML integration in question.
  4. D During the next certificate rotation period and before the current certificate expires, add a new certificate as the secondary to the identity provider. Generate a new copy of the metadata file and create a new IAM identity provider entity. Upload the metadata file to the new IAM identity provider entity. Perform automated or manual rotation of the certificate when required.
  5. E Download a new copy of the SAML metadata file from the identity provider. Create a new IAM identity provider entity. Upload the new metadata file to the new IAM identity provider entity. Update the identity provider configurations to pass a new IAM identity provider entity name in the SAML assertion.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm AWS

📘 Nội dung câu hỏi được giải thích rõ ràng:
Câu hỏi xoay quanh vấn đề SAML federation với AWS IAM để cung cấp Single Sign-On (SSO) cho người dùng nội bộ truy cập tài khoản AWS. Công ty đã rotate chứng chỉ (certificate) của Identity Provider (IdP) theo chu kỳ bảo mật thông thường. Sau đó, người dùng gặp lỗi:
“Error: Response Signature Invalid (Service: AWSSecurityTokenService; Status Code: 400; Error Code: InvalidIdentityToken)”.

Lý do lỗi: AWS IAM sử dụng chứng chỉ từ metadata của IdP để xác thực chữ ký SAML assertion. Khi chứng chỉ IdP thay đổi mà IAM chưa cập nhật metadata mới (chứa chứng chỉ mới), chữ ký bị coi là không hợp lệ, dẫn đến lỗi từ STS (Security Token Service).

Security engineer cần hai bước kết hợp:

  • Xử lý ngay lập tức (immediate fix): Cập nhật metadata mới vào IAM IdP entity hiện tại.
  • Ngăn ngừa lâu dài: Quản lý rotate chứng chỉ một cách graceful bằng cách thêm secondary cert trước khi primary expire, tránh gián đoạn SSO.

Chủ đề thuộc AWS IAM SAML 2.0 federation (cập nhật mới nhất AWS 2024-2026: Hỗ trợ multiple certificates trong metadata và best practices cho rotation không downtime).

✅ Đáp án đúng (chọn TWO):

  • Download a new copy of the SAML metadata file from the identity provider. Upload the new metadata to the IAM identity provider entity configured for the SAML integration in question.
    (Bước fix ngay: Tải metadata mới chứa cert mới và upload vào IAM IdP entity hiện tại. IAM sẽ tự động sử dụng cert mới để validate signature, giải quyết lỗi InvalidIdentityToken ngay lập tức. Không cần tạo entity mới, tránh thay đổi cấu hình bên IdP hoặc app.)

  • During the next certificate rotation period and before the current certificate expires, add a new certificate as the secondary to the identity provider. Generate a new metadata file and upload it to the IAM identity provider entity. Perform automated or manual rotation of the certificate when required.
    (Bước ngăn ngừa: Trước khi cert cũ expire, thêm cert mới làm secondary trong IdP. Metadata mới sẽ chứa cả hai cert, upload vào IAM entity hiện tại. IAM hỗ trợ multiple certs, validate bằng cert phù hợp. Sau đó rotate primary sang mới mà không downtime. Đây là best practice AWS cho zero-downtime rotation.)

Lý do chọn hai đáp án này:
🛠️ Chúng giải quyết immediate issue (upload metadata mới vào entity hiện tại) và prevent recurrence (graceful rotation với secondary cert). AWS khuyến nghị KHÔNG tạo IAM IdP entity mới vì yêu cầu cập nhật SAML assertion (thay đổi entity ID), gây phức tạp cho IdP và ứng dụng. Sử dụng entity hiện tại giữ tính nhất quán.

❌ Giải thích TẤT CẢ các phương án (đúng/sai)

  • ❌ Download a new copy of the SAML metadata file from the identity provider. Create a new IAM identity provider entity. Upload the new metadata file to the new IAM identity provider entity.
    Sai vì tạo IAM IdP entity mới không cần thiết và gây gián đoạn. Phải cập nhật entity ID trong SAML assertion từ IdP (thay đổi cấu hình IdP), dẫn đến downtime lớn hơn. Fix ngay chỉ cần update metadata vào entity hiện tại (AWS best practice).

  • ✅ During the next certificate rotation period and before the current certificate expires, add a new certificate as the secondary to the identity provider. Generate a new metadata file and upload it to the IAM identity provider entity. Perform automated or manual rotation of the certificate when required.
    Đúng (như giải thích trên): Hỗ trợ multiple certs trong metadata, upload vào entity hiện tại để IAM validate linh hoạt. Tránh downtime bằng secondary cert trước expire.

  • ✅ Download a new copy of the SAML metadata file from the identity provider. Upload the new metadata to the IAM identity provider entity configured for the SAML integration in question.
    Đúng (như giải thích trên): Immediate fix đơn giản nhất, IAM tự parse metadata mới và cập nhật certs. Không thay đổi entity ID hay cấu hình khác.

  • ❌ During the next certificate rotation period and before the current certificate expires, add a new certificate as the secondary to the identity provider. Generate a new copy of the metadata file and create a new IAM identity provider entity. Upload the metadata file to the new IAM identity provider entity. Perform automated or manual rotation of the certificate when required.
    Sai vì tạo entity mới làm phức tạp rotation tương lai: Cần switch traffic sang entity mới, cập nhật IdP config, và quản lý hai entity song song. AWS khuyên dùng entity hiện tại với metadata updates.

  • ❌ Download a new copy of the SAML metadata file from the identity provider. Create a new IAM identity provider entity. Upload the new metadata file to the new IAM identity provider entity. Update the identity provider configurations to pass a new IAM identity provider entity name in the SAML assertion.
    Sai vì yêu cầu cập nhật SAML assertion (thay đổi Audience/Entity ID từ IdP) gây thay đổi lớn ở IdP side, không phải immediate fix. Dẫn đến downtime và rủi ro config error.

📚 Tài liệu tham khảo (AWS cập nhật 2024-2026):

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm ví dụ CLI/SDK, hãy hỏi nhé!