Ngân hàng đề — AWS Certified Security Specialty

Tìm thấy 445 câu.

Câu 291
A company wants to implement host-based security for Amazon EC2 instances and containers in Amazon Elastic Container Registry (Amazon ECR). The company has deployed AWS Systems Manager Agent (SSM Agent) on the EC2 instances. All the company's AWS accounts are in one organization in AWS Organizations. The company will analyze the workloads for software vulnerabilities and unintended network exposure. The company will push any findings to AWS Security Hub, which the company has configured for the organization.

The company must deploy the solution to all member accounts, including new accounts, automatically. When new workloads come online, the solution must scan the workloads.

Which solution will meet these requirements?
  1. A Use SCPs to configure scanning of EC2 instances and ECR containers for all accounts in the organization.
  2. B Configure a delegated administrator for Amazon GuardDuty for the organization. Create an Amazon EventBridge rule to initiate analysis of ECR containers
  3. C Configure a delegated administrator for Amazon Inspector for the organization. Configure automatic scanning for new member accounts.
  4. D Configure a delegated administrator for Amazon Inspector for the organization. Create an AWS Config rule to initiate analysis of ECR containers.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai bảo mật dựa trên host (host-based security) cho các Amazon EC2 instances và containers trong Amazon ECR. Công ty đã cài đặt AWS Systems Manager Agent (SSM Agent) trên EC2, tất cả tài khoản AWS nằm trong một AWS Organizations. Yêu cầu chính là:

  • Phân tích workloads để phát hiện software vulnerabilities (lỗ hổng phần mềm) và unintended network exposure (tiếp xúc mạng không mong muốn).
  • Đẩy kết quả phân tích vào AWS Security Hub (đã cấu hình cho toàn organization).
  • Triển khai tự động cho tất cả member accounts, bao gồm tài khoản mới, và tự động scan khi có workloads mới online.

Giải pháp phải tích hợp sâu với Organizations, sử dụng delegated administrator để quản lý tập trung, và hỗ trợ scanning tự động cho cả EC2 (qua SSM Agent) và ECR containers. Đây là yêu cầu điển hình cho Amazon Inspector – dịch vụ chuyên scan vulnerabilities và network reachability (cập nhật đến 2026, Inspector hỗ trợ full integration với Security Hub và auto-scanning cho ECR/EC2 trong orgs).

📘 Tài liệu tham khảo:

✅ Đáp án đúng

Configure a delegated administrator for Amazon Inspector for the organization. Configure automatic scanning for new member accounts.

Lý do lựa chọn:

  • 🛠️ Amazon Inspector chính là dịch vụ lý tưởng cho host-based scanning trên EC2 (sử dụng SSM Agent để scan vulnerabilities và network exposure) và ECR container images (tự động scan khi push hoặc new images).
  • Delegated administrator trong Organizations cho phép management account enable Inspector cho toàn org, tự động áp dụng cho new member accounts (không cần manual setup).
  • Automatic scanning được cấu hình để scan ngay khi workloads mới online (EC2 instances hoặc ECR images mới), và findings tự động push vào Security Hub.
  • Hoàn toàn khớp yêu cầu zero-touch deployment và continuous scanning (theo best practices DevOps 2026).

❌ Phân tích tất cả các phương án

  • Use SCPs to configure scanning of EC2 instances and ECR containers for all accounts in the organization.
    ❌ Sai: SCPs (Service Control Policies) chỉ dùng để restrict/deny actions (như prevent disable scanning), không configure hay initiate scanning cho EC2/ECR. SCPs không hỗ trợ auto-scanning workloads mới hoặc integrate với Security Hub. Đây là misuse của SCPs – chỉ là guardrail, không phải tool deployment.

  • Configure a delegated administrator for Amazon GuardDuty for the organization. Create an Amazon EventBridge rule to initiate analysis of ECR containers
    ❌ Sai: Amazon GuardDuty chuyên threat detection (malware, crypto-mining, recon), không scan software vulnerabilities hay host-based analysis trên EC2/ECR như yêu cầu. Delegated admin cho GuardDuty không cover Inspector features. EventBridge có thể trigger, nhưng GuardDuty không hỗ trợ ECR container vuln scanning sâu (chỉ runtime threats), và không tự động cho new accounts như Inspector.

  • Configure a delegated administrator for Amazon Inspector for the organization. Configure automatic scanning for new member accounts.
    ✅ Đúng (như đã giải thích ở trên). Đây là giải pháp chuẩn AWS, full automation cho orgs, EC2/ECR, và Security Hub integration.

  • Configure a delegated administrator for Amazon Inspector for the organization. Create an AWS Config rule to initiate analysis of ECR containers.
    ❌ Sai: AWS Config dùng cho compliance monitoring và resource inventory, không initiate scanning vulnerabilities trên EC2/ECR. Inspector đã có built-in automatic scanning (không cần Config rule), và Config rule chỉ evaluate config drift chứ không trigger deep vuln scans hay network exposure analysis. Thêm Config làm phức tạp hóa không cần thiết.

🛠️ Khuyến nghị DevOps: Sử dụng AWS Organizations + Inspector delegated admin để scale security across multi-accounts. Test bằng SSM Quick Setup cho EC2 và ECR image scanning rules cho containers! 🚀

Câu 292
A company uses AWS Organizations to manage several AWS accounts. The company processes a large volume of sensitive data. The company uses a serverless approach to microservices. The company stores all the data in either Amazon S3 or Amazon DynamoDB. The company reads the data by using either AWS Lambda functions or container-based services that the company hosts on Amazon Elastic Kubernetes Service (Amazon EKS) on AWS Fargate.

The company must implement a solution to encrypt all the data at rest and enforce least privilege data access controls. The company creates an AWS Key Management Service (AWS KMS) customer managed key.

What should the company do next to meet these requirements?
  1. A Create a key policy that allows the kms:Decrypt action only for Amazon S3 and DynamoDB. Create an SCP that denies the creation of S3 buckets and DynamoDB tables that are not encrypted with the key.
  2. B Create an IAM policy that denies the kms:Decrypt action for the key. Create a Lambda function than runs on a schedule to attach the policy to any new roles. Create an AWS Config rule to send alerts for resources that are not encrypted with the key.
  3. C Create a key policy that allows the kms:Decrypt action only for Amazon S3, DynamoDB, Lambda, and Amazon EKS. Create an SCP that denies the creation of S3 buckets and DynamoDB tables that are not encrypted with the key.
  4. D Create a key policy that allows the kms:Decrypt action only for Amazon S3, DynamoDB, Lambda, and Amazon EKS. Create an AWS Config rule to send alerts for resources that are not encrypted with the key.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai mã hóa dữ liệu tại chỗ (encryption at rest) và kiểm soát truy cập dữ liệu theo nguyên tắc least privilege trong môi trường AWS Organizations với nhiều tài khoản. Công ty xử lý lượng lớn dữ liệu nhạy cảm bằng kiến trúc serverless/microservices, lưu trữ trên Amazon S3 hoặc Amazon DynamoDB, và truy cập dữ liệu qua AWS Lambda hoặc container trên Amazon EKS chạy Fargate. Họ đã tạo một AWS KMS customer managed key (CMK).

Yêu cầu chính:

  • Mã hóa tất cả dữ liệu tại chỗ (S3/DynamoDB).
  • Enforce least privilege: Chỉ cho phép decrypt dữ liệu bởi các dịch vụ cần thiết (S3, DynamoDB để lưu, Lambda/EKS để đọc).
  • Sử dụng Organizations nên cần cơ chế tập trung như SCP (Service Control Policy) để ngăn chặn tạo resource không mã hóa.

Bước tiếp theo sau khi tạo KMS CMK phải đảm bảo:

  • Key policy kiểm soát chặt chẽ ai/services được dùng key (kms:Decrypt).
  • Enforce encryption khi tạo S3 bucket/DynamoDB table (không chỉ alert).

Kiến thức cập nhật AWS 2026: KMS key policy là cách chính để grant quyền cho services (như S3, DynamoDB, Lambda, EKS service roles). SCP trong Organizations deny creation resource không dùng KMS key cụ thể. AWS Config chỉ monitor/alert, không block.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create a key policy that allows the kms:Decrypt action only for Amazon S3, DynamoDB, Lambda, and Amazon EKS. Create an SCP that denies the creation of S3 buckets and DynamoDB tables that are not encrypted with the key.

Lý do 🛠️:

  • Key policy cho phép kms:Decrypt chỉ cho các services cần: S3/DynamoDB (lưu data), Lambda/EKS (đọc data qua roles). Điều này enforce least privilege – không ai khác decrypt được.
  • SCP deny tạo S3 bucket/DynamoDB table nếu không dùng đúng KMS key, đảm bảo enforce encryption at rest tập trung qua Organizations (áp dụng multi-account).
  • Hoàn hảo kết hợp: Kiểm soát access (key policy) + Enforce creation (SCP). Không cần Config vì SCP block proactive.

📋 Giải thích tất cả các phương án

  • ❌ Phương án SAI: Create a key policy that allows the kms:Decrypt action only for Amazon S3 and DynamoDB. Create an SCP that denies the creation of S3 buckets and DynamoDB tables that are not encrypted with the key.
    Giải thích: Key policy thiếu Lambda/EKS – các services đọc data sẽ không decrypt được (vi phạm least privilege ngược lại, block access hợp lệ). SCP đúng nhưng key policy hỏng toàn bộ.

  • ❌ Phương án SAI: Create an IAM policy that denies the kms:Decrypt action for the key. Create a Lambda function than runs on a schedule to attach the policy to any new roles. Create an AWS Config rule to send alerts for resources that are not encrypted with the key.
    Giải thích: IAM policy deny kms:Decrypt là sai lầm – block tất cả decrypt, kể cả services cần. Lambda attach policy tự động phức tạp/rủi ro (không scale, không enforce). Config chỉ alert, không block tạo resource → Không meet enforce encryption.

  • ✅ Phương án ĐÚNG (như đã giải thích ở trên): Create a key policy that allows the kms:Decrypt action only for Amazon S3, DynamoDB, Lambda, and Amazon EKS. Create an SCP that denies the creation of S3 buckets and DynamoDB tables that are not encrypted with the key.
    Giải thích bổ sung: Least privilege hoàn hảo (chỉ services liên quan), SCP proactive block → Tuân thủ AWS best practices DevOps 2026.

  • ❌ Phương án SAI: Create a key policy that allows the kms:Decrypt action only for Amazon S3, DynamoDB, Lambda, and Amazon EKS. Create an AWS Config rule to send alerts for resources that are not encrypted with the key.
    Giải thích: Key policy đúng nhưng Config chỉ monitor/alert (reactive), không deny tạo resource → Không enforce encryption at rest, vi phạm yêu cầu "implement a solution to encrypt all the data".

📘 Tài liệu tham khảo (AWS Docs cập nhật 2026)

Hy vọng phân tích giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm case tương tự, hỏi nhé!

Câu 293
An AWS Lambda function was misused to alter data, and a security engineer must identify who invoked the function and what output was produced. The engineer cannot find any logs created by the Lambda function in Amazon CloudWatch Logs.

Which of the following explains why the logs are not available?
  1. A The execution role for the Lambda function did not grant permissions to write log data to CloudWatch Logs.
  2. B The Lambda function was invoked by using Amazon API Gateway, so the logs are not stored in CloudWatch Logs.
  3. C The execution role for the Lambda function did not grant permissions to write to the Amazon S3 bucket where CloudWatch Logs stores the logs.
  4. D The version of the Lambda function that was invoked was not current.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh tình huống một AWS Lambda function bị lạm dụng (misused) để thay đổi dữ liệu, và kỹ sư bảo mật cần điều tra bằng cách xác định ai đã invoke (gọi) function và output (kết quả đầu ra) của nó. Tuy nhiên, không tìm thấy bất kỳ logs nào được tạo bởi Lambda function trong Amazon CloudWatch Logs.

📌 Bối cảnh quan trọng:

  • AWS Lambda tự động gửi logs (bao gồm thông tin về invoker, input, output, và execution details) đến CloudWatch Logs mặc định nếu function được cấu hình đúng.
  • Logs này rất cần thiết để audit và forensics, đặc biệt trong sự cố bảo mật.
  • Vấn đề cốt lõi: Logs không tồn tại, không phải logs bị mất hay không hiển thị – nghĩa là chúng chưa được tạo ra từ đầu.
  • Theo tài liệu AWS mới nhất (cập nhật đến 2026, Lambda runtime hỗ trợ lên đến Node.js 22.x, Python 3.12, và các tính năng như Lambda SnapStart), logging là tính năng tích hợp sẵn, nhưng phụ thuộc vào IAM execution role của Lambda.

🛠️ Mục tiêu: Xác định lý do chính xác khiến logs không có sẵn, dựa trên các nguyên tắc bảo mật và vận hành AWS Lambda.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: The execution role for the Lambda function did not grant permissions to write log data to CloudWatch Logs.

Lý do 🧐:

  • Lambda function luôn cố gắng ghi logs vào CloudWatch Logs (log group /aws/lambda/<function-name>), nhưng điều này yêu cầu IAM execution role của function phải có các policy permissions cụ thể như logs:CreateLogGroup, logs:CreateLogStream, và logs:PutLogEvents (thường được cung cấp qua managed policy AWSLambdaBasicExecutionRole).
  • Nếu role thiếu quyền này, Lambda sẽ không tạo logs (silent failure), ngay cả khi function chạy thành công. Đây là lý do phổ biến nhất khiến logs "không tồn tại" trong CloudWatch.
  • Trong ngữ cảnh bảo mật (misuse để alter data), việc thiếu quyền logs có thể là do cấu hình sai hoặc bị cố tình loại bỏ để tránh audit trail.
  • Xác nhận từ AWS (2026): Logging là opt-out (không thể tắt hoàn toàn), nhưng phụ thuộc 100% vào IAM role.

📋 Giải thích tất cả các phương án (đúng/sai)

  • ✅ The execution role for the Lambda function did not grant permissions to write log data to CloudWatch Logs.
    Đúng vì: Đây là điều kiện tiên quyết. Lambda sử dụng execution role để gọi CloudWatch Logs API. Thiếu quyền → Không logs được tạo. Đây là nguyên nhân trực tiếp và phổ biến nhất trong troubleshooting (xem AWS Well-Architected Framework: Reliability Pillar).

  • ❌ The Lambda function was invoked by using Amazon API Gateway, so the logs are not stored in CloudWatch Logs.
    Sai vì: API Gateway chỉ là integration source để invoke Lambda (qua proxy hoặc direct), nhưng logs của Lambda function vẫn được ghi độc lập vào CloudWatch Logs của Lambda service. API Gateway có logs riêng (CloudWatch Logs hoặc CloudWatch Logs Insights), không ảnh hưởng đến Lambda logs.

  • ❌ The execution role for the Lambda function did not grant permissions to write to the Amazon S3 bucket where CloudWatch Logs stores the logs.
    Sai vì: CloudWatch Logs không lưu trữ dữ liệu trên S3 bucket công khai mà sử dụng internal storage của service (export to S3 là optional và thủ công). Execution role của Lambda không cần quyền S3 cho logging cơ bản – chỉ cần CloudWatch Logs permissions. Đây là hiểu lầm phổ biến về architecture.

  • ❌ The version of the Lambda function that was invoked was not current.
    Sai vì: Tất cả versions/aliases của Lambda (kể cả $LATEST hay published versions) đều log vào cùng một log group, chỉ khác log stream theo version. Việc invoke version cũ không ngăn cản logging nếu role đúng. Lambda hỗ trợ versions từ lâu (không thay đổi đến 2026).

📘 Tài liệu tham khảo (AWS Official - cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm ví dụ thực hành, hãy hỏi nhé.

Câu 294
A company is worried about potential DDoS attacks. The company has a web application that runs on Amazon EC2 instances. The application uses Amazon S3 to serve static content such as images and videos.

A security engineer must create a resilient architecture that can withstand DDoS attacks.

Which solution will meet these requirements MOST cost-effectively?
  1. A Create an Amazon CloudWatch alarm that invokes an AWS Lambda function when an EC2 instance’s CPU utilization reaches 90%. Program the Lambda function to update security groups that are attached to the EC2 instance to deny inbound ports 80 and 443.
  2. B Put the EC2 instances into an Auto Scaling group behind an Elastic Load Balancing (ELB) load balancer. Use Amazon CioudFront with Amazon S3 as an origin.
  3. C Set up a warm standby disaster recovery (DR) environment. Fail over to the warm standby DR environment if a DDoS attack is detected on the application.
  4. D Subscribe to AWS Shield Advanced. Configure permissions to allow the Shield Response Team to manage resources on the company's behalf during a DDoS event.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc xây dựng một kiến trúc resilient (bền vững) cho ứng dụng web chạy trên Amazon EC2 instances, kết hợp với Amazon S3 để phục vụ nội dung tĩnh như hình ảnh và video. Công ty lo ngại về tấn công DDoS (Distributed Denial of Service), và kỹ sư bảo mật cần thiết kế giải pháp chống chịu DDoS tốt nhất đồng thời tiết kiệm chi phí nhất (MOST cost-effectively).

🛠️ Yêu cầu chính: Giải pháp phải phân tán traffic, tự động scale, giảm tải cho EC2, và tận dụng các dịch vụ AWS có bảo vệ DDoS tích hợp sẵn (như AWS Shield Standard - miễn phí). Không chỉ dừng ở bảo vệ thủ công mà cần kiến trúc tổng thể resilient từ đầu, theo best practices AWS năm 2026 (với CloudFront và ELB được tối ưu hóa chống DDoS qua edge network toàn cầu).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Put the EC2 instances into an Auto Scaling group behind an Elastic Load Balancing (ELB) load balancer. Use Amazon CloudFront with Amazon S3 as an origin.

Lý do (🧩 Phân tích chi tiết):

  • Giải pháp này cost-effective nhất vì tận dụng AWS Shield Standard (miễn phí, tự động bảo vệ ELB, CloudFront, và EC2) mà không cần trả phí Shield Advanced.
  • EC2 trong Auto Scaling Group (ASG) + ELB: Phân tán traffic, tự động scale instances để chịu tải DDoS, ELB có DDoS mitigation tích hợp.
  • CloudFront với S3 origin: Offload toàn bộ static content (images/videos) ra edge locations toàn cầu (hàng trăm PoP), giảm tải EC2 >90%, cache content để chống volumetric DDoS. CloudFront có layer 3/4/7 protection mạnh mẽ.
  • Theo AWS Well-Architected Framework (2026), đây là blueprint chuẩn cho web apps chống DDoS, tiết kiệm hơn so với DR hoặc Shield Advanced (chi phí cao hơn 3.000 USD/tháng + phí mitigation).

📋 Phân tích tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá ✅ (đúng) hoặc ❌ (sai), kèm giải thích chi tiết bằng tiếng Việt.

  • ❌ Create an Amazon CloudWatch alarm that invokes an AWS Lambda function when an EC2 instance’s CPU utilization reaches 90%. Program the Lambda function to update security groups that are attached to the EC2 instance to deny inbound ports 80 and 443.
    Giải thích sai: Phương án này chỉ là phản ứng thủ công muộn màng (reactive), chặn port 80/443 khi CPU cao sẽ làm app ngừng hoạt động hoàn toàn (không resilient). Không scale, không offload static, và không chống DDoS thực sự (DDoS thường volumetric, không chỉ CPU). Chi phí Lambda thấp nhưng kém hiệu quả, không phải best practice AWS.

  • ✅ Put the EC2 instances into an Auto Scaling group behind an Elastic Load Balancing (ELB) load balancer. Use Amazon CloudFront with Amazon S3 as an origin.
    Giải thích đúng: Như phần trên, đây là giải pháp toàn diện, proactive và cost-effective. Kết hợp scale (ASG+ELB) + CDN (CloudFront+S3) tận dụng Shield Standard miễn phí, giảm tải EC2, phân tán DDoS qua global edge. Hoàn hảo cho web app hybrid (dynamic EC2 + static S3).

  • ❌ Set up a warm standby disaster recovery (DR) environment. Fail over to the warm standby DR environment if a DDoS attack is detected on the application.
    Giải thích sai: Warm standby DR (như EC2 replicated) không chống DDoS trực tiếp, chỉ failover sau khi phát hiện (RTO/RPO cao, downtime vài phút). Chi phí gấp đôi (2 environments chạy song song), không scale real-time, và DDoS có thể tấn công cả primary + DR nếu cùng region. Không cost-effective cho DDoS mitigation.

  • ❌ Subscribe to AWS Shield Advanced. Configure permissions to allow the Shield Response Team to manage resources on the company's behalf during a DDoS event.
    Giải thích sai: Shield Advanced cung cấp DDoS protection nâng cao (proactive monitoring, SRT support), nhưng chi phí cao (3.000-8.000 USD/tháng + traffic fees), không "MOST cost-effectively". Không giải quyết kiến trúc gốc (EC2+S3 chưa optimize), chỉ là "bảo hiểm" bổ sung. Shield Standard đã đủ cho hầu hết cases với ELB/CloudFront.

📘 Tài liệu tham khảo (Cập nhật AWS 2026)

  • AWS Shield Documentation: AWS Shield Overview - Shield Standard miễn phí cho CloudFront/ELB.
  • AWS Well-Architected Framework - Reliability Pillar: Reliability Pillar - Khuyến nghị ASG + ELB + CloudFront chống DDoS.
  • CloudFront DDoS Protection: CloudFront Security - Edge protection layer 3/7.
  • Exam Guide DOP-C02: AWS Certified DevOps Engineer Professional (2026) - Topic: High Availability & DDoS Resilience.
  • AWS Blog: "Mitigating DDoS Attacks Using AWS Best Practices" (2025 update).

🛠️ Kết luận: Giải pháp đúng không chỉ bảo vệ mà còn tối ưu chi phí và performance theo nguyên tắc AWS! Nếu cần thiết kế chi tiết hơn, hãy cung cấp thêm info. 🚀

Câu 295
A company uses an organization in AWS Organizations to manage hundreds of AWS accounts. Some of the accounts provide access to external AWS principals through cross-account IAM roles and Amazon S3 bucket policies.

The company needs to identify which external principals have access to which accounts.

Which solution will provide this information?
  1. A Enable AWS Identity and Access Management Access Analyzer for the organization. Configure the organization as a zone of trust. Filter findings by AWS account ID.
  2. B Create a custom AWS Config rule to monitor IAM roles in each account. Deploy an AWS Config aggregator to a central account. Filter findings by AWS account ID.
  3. C Activate Amazon Inspector. Integrate Amazon Inspector with AWS Security Hub. Filter findings by AWS account ID for the IAM role resource type and the S3 bucket policy resource type.
  4. D Configure the organization to use Amazon GuardDuty. Filter findings by AWS account ID for the Discovery:IAMUser/AnomalousBehavior finding type.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào AWS Organizations quản lý hàng trăm tài khoản AWS (hundreds of AWS accounts). Một số tài khoản cho phép external AWS principals (các thực thể AWS từ bên ngoài, như tài khoản khác hoặc principals khác) truy cập qua cross-account IAM roles (vai trò IAM cross-account) và Amazon S3 bucket policies (chính sách bucket S3).

Mục tiêu: Xác định external principals nào có quyền truy cập vào tài khoản nào (which external principals have access to which accounts).

🛠️ Đây là vấn đề phân tích quyền truy cập bên ngoài (external access analysis) ở quy mô lớn, cần giải pháp tự động, toàn tổ chức, hỗ trợ lọc theo AWS account ID. AWS cung cấp các công cụ bảo mật chuyên biệt cho việc này, cập nhật đến năm 2026 với IAM Access Analyzer hỗ trợ zone of trust nâng cao cho Organizations (theo AWS re:Invent 2025 updates).

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Enable AWS Identity and Access Management Access Analyzer for the organization. Configure the organization as a zone of trust. Filter findings by AWS account ID.

Lý do:

  • AWS IAM Access Analyzer chính xác được thiết kế để phân tích và xác định quyền truy cập bên ngoài không mong muốn từ external principals vào resources như IAM roles và S3 buckets cross-account.
  • Khi enable cho organization và configure organization as zone of trust, nó quét toàn bộ accounts, tạo findings liệt kê external principals cụ thể (account IDs, roles, users) có quyền truy cập vào từng account/resource.
  • Filter by AWS account ID cho phép xem chi tiết per account, phù hợp quy mô lớn.
  • ✅ Hoàn hảo, tự động, không cần custom code, hỗ trợ S3 policies và IAM roles cross-account (cập nhật 2026: tích hợp sâu hơn với Organizations SCPs).

📋 Giải thích tất cả các phương án

  • Enable AWS Identity and Access Management Access Analyzer for the organization. Configure the organization as a zone of trust. Filter findings by AWS account ID.
    ✅ Đúng (như đã giải thích ở trên). Đây là giải pháp chuẩn AWS, hiệu quả nhất cho external access visibility.

  • Create a custom AWS Config rule to monitor IAM roles in each account. Deploy an AWS Config aggregator to a central account. Filter findings by AWS account ID.
    ❌ Sai. AWS Config chỉ ghi nhận trạng thái cấu hình (compliance) của IAM roles, không phân tích external principals hoặc mô phỏng quyền truy cập thực tế từ bên ngoài. Custom rule tốn công phát triển, không hỗ trợ S3 policies sâu, và aggregator chỉ tổng hợp config – không phải access analysis. 🛠️ Không phù hợp mục tiêu.

  • Activate Amazon Inspector. Integrate Amazon Inspector with AWS Security Hub. Filter findings by AWS account ID for the IAM role resource type and the S3 bucket policy resource type.
    ❌ Sai. Amazon Inspector chuyên quét lỗ hổng phần mềm/cấu hình (vulnerability scanning), không phân tích external access principals. Security Hub tổng hợp findings nhưng Inspector không detect cross-account access qua roles/policies. Cập nhật 2026 vẫn tập trung CIS benchmarks, không phải identity analysis. 🧩 Sai hướng hoàn toàn.

  • Configure the organization to use Amazon GuardDuty. Filter findings by AWS account ID for the Discovery:IAMUser/AnomalousBehavior finding type.
    ❌ Sai. GuardDuty phát hiện threat intelligence và anomalous behavior (hành vi bất thường), không liệt kê external principals có quyền truy cập hợp lệ. Finding "Discovery:IAMUser/AnomalousBehavior" chỉ alert user reconnaissance, không map principals-to-accounts cho IAM roles/S3. 2026 updates thêm ML models nhưng vẫn là threat detection, không phải access auditing. 🚫 Không liên quan.

🛡️ Kết luận: Sử dụng IAM Access Analyzer là best practice cho DevOps Engineer Professional, đảm bảo least privilege và compliance ở multi-account environments!

Câu 296
A company has AWS accounts in an organization in AWS Organizations. The company needs to install a corporate software package on all Amazon EC2 instances for all the accounts in the organization.

A central account provides base AMIs for the EC2 instances. The company uses AWS Systems Manager for software inventory and patching operations.

A security engineer must implement a solution that detects EC2 instances that do not have the required software. The solution also must automatically install the software if the software is not present.

Which solution will meet these requirements?
  1. A Provide new AMIs that have the required software pre-installed. Apply a tag to the AMIs to indicate that the AMIs have the required software. Configure an SCP that allows new EC2 instances to be launched only if the instances have the tagged AMIs. Tag all existing EC2 instances.
  2. B Configure a custom patch baseline in Systems Manager Patch Manager. Add the package name for the required software to the approved packages list. Associate the new patch baseline with all EC2 instances. Set up a maintenance window for software deployment.
  3. C Centrally enable AWS Config. Set up the ec2-managedinstance-applications-required AWS Config rule for all accounts. Create an Amazon EventBridge rule that reacts to AWS Config events. Configure the EventBridge rule to invoke an AWS Lambda function that uses Systems Manager Run Command to install the required software.
  4. D Create a new Systems Manager Distributor package for the required software. Specify the download location. Select all EC2 instances in the different accounts. Install the software by using Systems Manager Run Command.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh một công ty sử dụng AWS Organizations với nhiều tài khoản AWS, cần triển khai một gói phần mềm doanh nghiệp (corporate software package) lên tất cả Amazon EC2 instances trong toàn bộ tổ chức.

  • 📍 Bối cảnh chính:

    • Có một tài khoản trung tâm (central account) cung cấp các base AMIs cho EC2.
    • Công ty đang sử dụng AWS Systems Manager (SSM) để quản lý inventory phần mềm và vá lỗi (patching).
    • Yêu cầu của security engineer:
      • Phát hiện (detect) các EC2 instances không có phần mềm yêu cầu.
      • Tự động cài đặt (automatically install) phần mềm nếu thiếu.
  • 🎯 Thách thức: Giải pháp phải hoạt động cross-account (toàn tổ chức), tự động, phát hiện liên tục (không chỉ one-time), và tích hợp với SSM. Không chỉ install ban đầu mà còn đảm bảo compliance lâu dài cho cả instances mới và hiện có.

Giải pháp lý tưởng cần sử dụng các dịch vụ serverless, event-driven để giám sát và remediate tự động, phù hợp với best practices DevOps trên AWS (multi-account management với Organizations).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Centrally enable AWS Config. Set up the ec2-managedinstance-applications-required AWS Config rule for all accounts. Create an Amazon EventBridge rule that reacts to AWS Config events. Configure the EventBridge rule to invoke an AWS Lambda function that uses Systems Manager Run Command to install the required software.

🛠️ Lý do chọn đáp án này (phù hợp nhất với yêu cầu):

  • AWS Config được kích hoạt centrally qua Organizations (sử dụng Aggregate Configuration Recorder), áp dụng rule ec2-managedinstance-applications-required (một managed rule chuẩn của AWS Config, cập nhật đến 2026) để liên tục kiểm tra các SSM-managed instances có chứa phần mềm yêu cầu không. Rule này detect chính xác instances thiếu software dựa trên SSM inventory.
  • Amazon EventBridge rule capture sự kiện non-compliant từ Config (events như CONFIG_RULE_COMPLIANCE_CHANGE), trigger AWS Lambda function.
  • Lambda sử dụng SSM Run Command (hoặc SSM Automation) để tự động install software trên instance vi phạm – hoàn toàn serverless, event-driven, và cross-account (qua Organizations delegated admin).
  • ✅ Đầy đủ yêu cầu: Detect + Auto-remediate, scale toàn tổ chức, không can thiệp thủ công, tích hợp SSM inventory/patching.
  • Best practice: Tuân thủ AWS Well-Architected Framework (Operations Pillar) cho continuous compliance.

📘 Tài liệu tham khảo:

❌ Phân tích tất cả các phương án (đúng/sai)

  • Phương án A (SAI):
    Provide new AMIs that have the required software pre-installed. Apply a tag to the AMIs to indicate that the AMIs have the required software. Configure an SCP that allows new EC2 instances to be launched only if the instances have the tagged AMIs. Tag all existing EC2 instances.
    🧨 Tại sao SAI?: Phương án chỉ pre-install trên AMIs mới và dùng SCP (Service Control Policy) để restrict launch instances mới (nhưng SCP không enforce tags trên instances, chỉ trên AMIs – và không block nếu dùng AMI khác). Không detect tự động instances hiện có thiếu software, cũng không auto-install. Việc "tag existing instances" chỉ đánh dấu, không install. Không scale cho remediation liên tục.

  • Phương án B (SAI):
    Configure a custom patch baseline in Systems Manager Patch Manager. Add the package name for the required software to the approved patches list. Associate the new patch baseline with all EC2 instances. Set up a maintenance window for software deployment.
    🧨 Tại sao SAI?: SSM Patch Manager chỉ dành cho OS patches và security updates (như kernel, apps hệ thống), không hỗ trợ arbitrary corporate software packages (không phải patch chuẩn). "Approved packages" chỉ apply cho patching, không detect/install custom software. Maintenance window là scheduled, không event-driven hay detect real-time. Không phù hợp cross-account tự động.

  • Phương án C (ĐÚNG):
    Centrally enable AWS Config. Set up the ec2-managedinstance-applications-required AWS Config rule for all accounts. Create an Amazon EventBridge rule that reacts to AWS Config events. Configure the EventBridge rule to invoke an AWS Lambda function that uses Systems Manager Run Command to install the required software.
    ✅ Tại sao ĐÚNG?: Như phân tích ở phần đáp án đúng. Hoàn hảo cho compliance-as-code, detect qua SSM inventory, remediate tự động via Lambda + Run Command. Hỗ trợ Organizations đầy đủ (delegated administrator cho Config).

  • Phương án D (SAI):
    Create a new Systems Manager Distributor package for the required software. Specify the download location. Select all EC2 instances in the different accounts. Install the software by using Systems Manager Run Command.
    🧨 Tại sao SAI?: SSM Distributor đã deprecated từ 2023 (thay bằng SSM Quick Setup hoặc State Manager), không khuyến khích dùng mới (cập nhật 2026). Yêu cầu select thủ công tất cả instances (không auto-detect thiếu software). Không liên tục monitor, chỉ one-time install. Khó scale cross-account mà không tự động hóa thêm.

🔍 Kết luận: Giải pháp C là optimal cho môi trường Organizations lớn, đảm bảo zero-touch compliance với chi phí thấp, theo phiên bản AWS mới nhất (re:Post và Well-Architected 2025). Nếu triển khai, test rule Config trước trên dev account! 🚀

Câu 297 Chọn nhiều đáp án
A development team is creating an open source toolset to manage a company's software as a service (SaaS) application. The company stores the code in a public repository so that anyone can view and download the toolset's code.

The company discovers that the code contains an IAM access key and secret key that provide access to internal resources in the company’s AWS environment

A security engineer must implement a solution to identify whether unauthorized usage of the exposed credentials has occurred. The solution also must prevent any additional usage of the exposed credentials.

Which combination of steps will meet these requirements? (Choose two.)
  1. A Use AWS Identity and Access Management Access Analyzer to determine which resources the exposed credentials accessed and who used them.
  2. B Deactivate the exposed IAM access key from the user’s IAM account.
  3. C Create a rule in Amazon GuardDuty to block the access key in the source code from being used.
  4. D Create a new IAM access key and secret key for the user whose credentials were exposed.
  5. E Generate an IAM credential report. Check the report to determine when the user that owns the access key last logged in.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh tình huống một đội ngũ phát triển đã vô tình commit IAM access key và secret key vào kho mã nguồn public repository (mở cho mọi người xem và tải về). Những credentials này có quyền truy cập vào tài nguyên nội bộ AWS của công ty.

📌 Yêu cầu chính của giải pháp (phải chọn TWO bước):

  • Xác định xem credentials bị lộ đã được sử dụng không được phép (unauthorized usage) như thế nào (tức là kiểm tra tài nguyên nào đã truy cập và ai đã dùng).
  • Ngăn chặn mọi sử dụng thêm của credentials bị lộ.

🛠️ Bối cảnh AWS liên quan:

  • Đây là vấn đề bảo mật phổ biến với leaked credentials trong code public (như GitHub).
  • Giải pháp cần sử dụng các dịch vụ AWS như IAM, Access Analyzer, GuardDuty... để phát hiện (detect) và khóa (revoke/prevent).
  • Theo kiến thức AWS cập nhật đến 2026 (IAM Access Analyzer phiên bản mới nhất hỗ trợ external access findings cho leaked keys từ public repos, tích hợp CloudTrail/S3/others để audit access).

✅ Đáp án đúng (Chọn TWO)

Hai phương án đúng là:

  1. Use AWS Identity and Access Management Access Analyzer to determine which resources the exposed credentials accessed and who used them.
  2. Deactivate the exposed IAM access key from the user’s IAM account.

Lý do lựa chọn:

  • ✅ Access Analyzer là công cụ lý tưởng để phân tích lịch sử truy cập (qua tích hợp CloudTrail, S3, etc.), xác định chính xác tài nguyên nào bị truy cập bởi credentials bị lộ và ai đã dùng (external principals). Nó tạo policy findings và external access findings cho leaked keys, giúp detect unauthorized usage ngay lập tức.
  • ✅ Deactivate IAM key ngay lập tức ngăn chặn sử dụng thêm bằng cách vô hiệu hóa key mà không cần xóa (để giữ audit trail). Đây là bước best practice từ AWS IAM docs để revoke credentials bị lộ.

📋 Giải thích tất cả các phương án (Đúng/Sai)

  • Use AWS Identity and Access Management Access Analyzer to determine which resources the exposed credentials accessed and who used them.
    ✅ ĐÚNG 🏆: IAM Access Analyzer (cập nhật 2026) hỗ trợ finding leaked credentials từ public repos (như GitHub/CodeCommit public). Nó phân tích access logs để liệt kê tài nguyên bị ảnh hưởng (S3, EC2, etc.) và principal (user/IP) đã dùng, đáp ứng yêu cầu "identify unauthorized usage". Không chỉ detect mà còn visualize access paths.

  • Deactivate the exposed IAM access key from the user’s IAM account.
    ✅ ĐÚNG 🛡️: Đây là hành động tức thì để prevent additional usage. Trong IAM console/CLI/API, dùng UpdateAccessKey status="Inactive" để khóa key. AWS khuyến nghị deactivate trước khi xóa để audit.

  • Create a rule in Amazon GuardDuty to block the access key in the source code from being used.
    ❌ SAI 🚫: GuardDuty là dịch vụ threat detection (phát hiện unusual behavior như crypto mining, reconnaissance), không phải để block specific access key từ source code. Nó có IAM findings cho anomalous API calls nhưng không "block" key, chỉ alert. Không match yêu cầu "prevent usage".

  • Create a new IAM access key and secret key for the user whose credentials were exposed.
    ❌ SAI 🔄: Tạo key mới chỉ giúp user tiếp tục làm việc, nhưng không prevent old key bị lộ (vẫn active và có thể bị abuse). Phải deactivate old key trước, theo AWS security best practices.

  • Generate an IAM credential report. Check the report to determine when the user that owns the access key last logged in.
    ❌ SAI ⏰: IAM Credential Report chỉ cung cấp snapshot về status keys/users (last used date, login time), không chi tiết tài nguyên accessed hay unauthorized usage từ external. Không đủ để "identify which resources and who used", chỉ hỗ trợ audit cơ bản.

📘 Tài liệu tham khảo (AWS Official - Cập nhật 2026)

🛡️ Khuyến nghị DevOps: Sử dụng AWS Secrets Manager hoặc SSM Parameter Store thay commit keys vào code, kết hợp pre-commit hooks + GuardDuty để tránh tương lai!

Câu 298
A company needs to create a centralized solution to analyze log files. The company uses an organization in AWS Organizations to manage its AWS accounts.

The solution must aggregate and normalize events from the following sources:

•The entire organization in Organizations
•All AWS Marketplace offerings that run in the company’s AWS accounts
•The company's on-premises systems

Which solution will meet these requirements?
  1. A Configure a centralized Amazon S3 bucket for the logs. Enable VPC Flow Logs, AWS CloudTrail. and Amazon Route 53 logs in all accounts. Configure all accounts to use the centralized S3 bucket. Configure AWS Glue crawlers to parse the log files. Use Amazon Athena to query the log data.
  2. B Configure log streams in Amazon CloudWatch Logs for the sources that need monitoring Create log subscription filters for each log stream. Forward the messages to Amazon OpenSearch Service for analysis.
  3. C Set up a delegated Amazon Security Lake administrator account in Organizations. Enable and configure Security Lake for the organization. Add the accounts that need monitoring. Use Amazon Athena to query the log data.
  4. D Apply an SCP to configure all member accounts and services to deliver log files to a centralized Amazon S3 bucket. Use Amazon OpenSearch Service to query the centralized S3 bucket for log entries.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi yêu cầu xây dựng một giải pháp tập trung (centralized solution) để phân tích log files, với các yêu cầu chính:

  • Tổng hợp (aggregate) và chuẩn hóa (normalize) events từ nhiều nguồn đa dạng:
    • Toàn bộ AWS Organizations (bao gồm tất cả accounts trong organization).
    • Tất cả AWS Marketplace offerings chạy trong các AWS accounts của công ty (các dịch vụ bên thứ ba từ Marketplace).
    • Hệ thống on-premises (máy chủ tại chỗ ngoài AWS).
  • Giải pháp phải tích hợp sâu với AWS Organizations, hỗ trợ quy mô lớn, tự động hóa và chuẩn hóa dữ liệu log theo định dạng thống nhất (như OCSF - Open Cybersecurity Schema Framework) để dễ phân tích.
  • Kiến thức cập nhật 2026: Amazon Security Lake (ra mắt 2022, cập nhật liên tục) là dịch vụ lý tưởng nhất, hỗ trợ chính xác các nguồn này mà không cần cấu hình thủ công phức tạp cho từng account/service. Nó tự động thu thập, chuẩn hóa logs từ Organizations, AWS services, third-party/SaaS (Marketplace), và on-premises qua agent hoặc API.

✅ Đáp án đúng

Set up a delegated Amazon Security Lake administrator account in Organizations. Enable and configure Security Lake for the organization. Add the accounts that need monitoring. Use Amazon Athena to query the log data.

Lý do lựa chọn:

  • 🛠️ Amazon Security Lake là giải pháp tập trung, tự động dành riêng cho security logging trong AWS Organizations. Nó chỉ định một delegated administrator account để quản lý toàn organization.
  • ✅ Hỗ trợ đầy đủ các nguồn: | Nguồn | Hỗ trợ | |-------|--------| | Organizations | Tự động enable cho toàn bộ accounts. | | AWS Marketplace | Thu thập logs từ third-party/SaaS qua integrations sẵn (hỗ trợ rộng rãi đến 2026). | | On-premises | Hỗ trợ qua OCSF schema, agent-based hoặc API để forward logs. |
  • 📊 Tổng hợp & chuẩn hóa: Logs được lưu trữ ở S3 object storage dạng Parquet (optimized), normalize theo OCSF, query dễ dàng bằng Amazon Athena (serverless).
  • ⚡ Ưu điểm: Không cần SCP thủ công, VPC Flow Logs riêng lẻ; tích hợp Organizations native; scale tự động, chi phí pay-per-query.
  • Đây là best practice theo AWS Well-Architected Framework (Security Pillar, 2026 edition).

📝 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Tôi đánh dấu ✅ (đúng) hoặc ❌ (sai) và giải thích rõ lý do bằng tiếng Việt:

  • ❌ Configure a centralized Amazon S3 bucket for the logs. Enable VPC Flow Logs, AWS CloudTrail. and Amazon Route 53 logs in all accounts. Configure all accounts to use the centralized S3 bucket. Configure AWS Glue crawlers to parse the log files. Use Amazon Athena to query the log data.
    Sai vì: Giải pháp chỉ tập trung vào logs AWS native cơ bản (VPC Flow Logs, CloudTrail, Route 53), phải enable thủ công từng account – không scale tốt cho Organizations lớn. ❌ Không hỗ trợ AWS Marketplace (third-party logs không tự động forward vào S3) và on-premises (cần agent riêng, không normalize). Glue + Athena tốn kém cho parsing thủ công, không chuẩn hóa OCSF. Không phải giải pháp centralized native.

  • ❌ Configure log streams in Amazon CloudWatch Logs for the sources that need monitoring Create log subscription filters for each log stream. Forward the messages to Amazon OpenSearch Service for analysis.
    Sai vì: CloudWatch Logs phù hợp monitoring cơ bản, nhưng ❌ không centralized cho Organizations (phải config subscription filters thủ công từng log stream/account). ❌ Không hỗ trợ tốt Marketplace (third-party không integrate dễ) và on-premises (cần agent phức tạp, chi phí cao). OpenSearch chỉ phân tích search, không aggregate/normalize toàn diện như Security Lake. Scale kém cho multi-account.

  • ✅ Set up a delegated Amazon Security Lake administrator account in Organizations. Enable and configure Security Lake for the organization. Add the accounts that need monitoring. Use Amazon Athena to query the log data.
    Đúng vì: Như đã giải thích ở phần đáp án đúng. Hoàn hảo match requirements, tự động hóa cao, hỗ trợ tất cả nguồn với normalization OCSF. Query Athena native trên S3 Parquet siêu hiệu quả.

  • ❌ Apply an SCP to configure all member accounts and services to deliver log files to a centralized Amazon S3 bucket. Use Amazon OpenSearch Service to query the centralized S3 bucket for log entries.
    Sai vì: SCP (Service Control Policy) chỉ deny/enforce policies, không thể config services deliver logs (ví dụ: không force CloudTrail/VPC Logs vào S3 cụ thể). ❌ Không cover Marketplace/on-premises (không có cơ chế forward tự động). OpenSearch query S3 kém hiệu quả (cần Lambda trigger), không normalize, tốn kém so với Athena. Không phải best practice cho Organizations logging.

📘 Tài liệu tham khảo (cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ thực hành, hãy hỏi nhé!

Câu 299
A company uses AWS Organizations. The company has more than 100 AWS accounts and will increase the number of accounts. The company also uses an external corporate identity provider (IdP).

The company needs to provide users with role-based access to the accounts. The solution must maximize scalability and operational efficiency.

Which solution will meet these requirements?
  1. A In each account, create a set of dedicated IAM users. Ensure that all users assume these IAM users through federation with the existing IdP.
  2. B Deploy an IAM role in a central identity account. Allow users to assume the role through federation with the existing IdP. In each account, deploy a set of IAM roles that match the desired access patterns. Include a trust policy that allows access from the central identity account. Edit the permissions policy for the role in each account to match user access requirements.
  3. C Enable AWS IAM Identity Center. Integrate IAM Identity Center with the company's existing IdP. Create permission sets that match the desired access patterns. Assign permissions to match user access requirements.
  4. D In each account, deploy a set of IAM roles that match the desired access patterns. Create a trust policy with the existing IdP. Update each role's permissions policy to use SAML-based IAM condition keys that are based on user access requirements.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào một công ty sử dụng AWS Organizations với hơn 100 tài khoản AWS (và sẽ tăng thêm), đồng thời đang dùng external corporate identity provider (IdP) bên ngoài (như SAML hoặc OIDC).
Yêu cầu chính: Cung cấp role-based access (truy cập dựa trên vai trò) cho người dùng đến các tài khoản này, đồng thời tối đa hóa scalability (khả năng mở rộng) và operational efficiency (hiệu quả vận hành).
🛠️ Thách thức cốt lõi: Với số lượng tài khoản lớn và tăng dần, giải pháp phải centralized (tập trung), dễ quản lý permission (quyền hạn), hỗ trợ federation với IdP hiện có, tránh phải cấu hình lặp lại ở từng account để giảm công sức bảo trì. Đây là best practice cho môi trường multi-account trong AWS Organizations (cập nhật đến 2026, AWS khuyến nghị sử dụng IAM Identity Center cho identity management).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Enable AWS IAM Identity Center. Integrate IAM Identity Center with the company's existing IdP. Create permission sets that match the desired access patterns. Assign permissions to match user access requirements.

Lý do chọn đáp án này 🏆:

  • AWS IAM Identity Center (trước đây gọi là AWS SSO, cập nhật tên từ 2022) là dịch vụ centralized identity management được thiết kế dành riêng cho AWS Organizations multi-account environments. Nó hỗ trợ tích hợp trực tiếp với external IdP (SAML 2.0 hoặc OIDC), cho phép người dùng federate một lần và truy cập role-based qua permission sets (bộ quyền hạn có thể tái sử dụng).
  • Scalability cao: Quản lý tập trung một nơi, dễ assign permission sets đến hàng nghìn accounts/groups/users mà không cần cấu hình từng account. Hỗ trợ auto-provisioning và SCIM cho enterprise IdP.
  • Operational efficiency: Giảm workload admin bằng cách sử dụng permission sets predefined (như PowerUser, ReadOnly), dễ scale khi thêm accounts mới chỉ cần assign. Không cần trust policy phức tạp ở từng account.
  • Phù hợp với AWS Well-Architected Framework (Pillar: Security & Operational Excellence).

📘 Tài liệu tham khảo:

❌ Phân tích tất cả các phương án

Dưới đây là giải thích chi tiết từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá dựa trên scalability và efficiency cho >100 accounts.

  • Phương án A: In each account, create a set of dedicated IAM users. Ensure that all users assume these IAM users through federation with the existing IdP.
    ❌ Sai vì: Phải tạo IAM users riêng biệt ở từng account (hàng nghìn users cho 100+ accounts), vi phạm nguyên tắc least privilege và no IAM users for federation (AWS khuyến cáo dùng roles). Không scalable: Mỗi account cần quản lý users riêng, khó đồng bộ khi thêm accounts/users. Federation qua IAM users kém efficient, dễ lỗi và tốn chi phí (users tính phí riêng). Không phải best practice.

  • Phương án B: Deploy an IAM role in a central identity account. Allow users to assume the role through federation with the existing IdP. In each account, deploy a set of IAM roles that match the desired access patterns. Include a trust policy that allows access from the central identity account. Edit the permissions policy for the role in each account to match user access requirements.
    ❌ Sai vì: Sử dụng central role làm proxy rồi cross-account assume (qua trust policy từ central account). Với 100+ accounts, phải deploy và edit policy thủ công ở từng account, rất tốn kém vận hành khi scale (thêm account mới cần repeat). Không centralized permission management, dễ lỗi trust policy và kém secure (session chaining). Không efficient so với IAM Identity Center.

  • Phương án C (Đúng): Enable AWS IAM Identity Center. Integrate IAM Identity Center with the company's existing IdP. Create permission sets that match the desired access patterns. Assign permissions to match user access requirements.
    ✅ Đúng vì: Như đã giải thích ở phần đáp án đúng. Đây là giải pháp native, scalable nhất của AWS cho multi-account + external IdP, hỗ trợ zero-touch provisioning qua permission sets và assignments tại organizational level.

  • Phương án D: In each account, deploy a set of IAM roles that match the desired access patterns. Create a trust policy with the existing IdP. Update each role's permissions policy to use SAML-based IAM condition keys that are based on user access requirements.
    ❌ Sai vì: Phải deploy roles và trust policy trực tiếp với IdP ở từng account, sau đó dùng SAML condition keys (như ${aws:PrincipalTag/...}) để fine-tune. Với 100+ accounts, việc update policy lặp lại ở mọi nơi không scalable, dễ sai sót khi thay đổi IdP attributes hoặc thêm accounts. Quản lý tập trung kém, tốn operational overhead cao hơn IAM Identity Center (phải dùng AWS SSO Permission Sets thay vì manual roles).

🛠️ Kết luận: Chọn IAM Identity Center để đạt zero-effort scaling trong AWS Organizations! Nếu triển khai thực tế, bắt đầu bằng enable trong management account. 🚀

Câu 300
A company has a web-based application that runs behind an Application Load Balancer (ALB). The application is experiencing a credential stuffing attack that is producing many failed login attempts. The attack is coming from many IP addresses. The login attempts are using a user agent string of a known mobile device emulator.

A security engineer needs to implement a solution to mitigate the credential stuffing attack. The solution must still allow legitimate logins to the application.

Which solution will meet these requirements?
  1. A Create an Amazon CloudWatch alarm that reacts to login attempts that contain the specified user agent string Add an Amazon Simple Notification Service (Amazon SNS) topic to the alarm.
  2. B Modify the inbound security group on the ALB to deny traffic from the IP addresses that are involved in the attack.
  3. C Create an AWS WAF web ACL for the ALB Create a custom rule that blocks requests that contain the user agent string of the device emulator.
  4. D Create an AWS WAF web ACL for the ALB. Create a custom rule that allows requests from legitimate user agent strings.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh một ứng dụng web chạy sau Application Load Balancer (ALB) đang bị tấn công credential stuffing – một loại tấn công brute-force đăng nhập bằng cách thử nhiều tài khoản/mật khẩu từ các nguồn khác nhau. Đặc điểm tấn công:

  • Đến từ nhiều địa chỉ IP (không thể block bằng IP cố định).
  • Sử dụng user agent string của một mobile device emulator đã biết (chuỗi nhận dạng trình duyệt giả lập thiết bị di động).

Yêu cầu giải pháp:

  • Mitigate (giảm thiểu) tấn công một cách hiệu quả.
  • Vẫn cho phép đăng nhập hợp pháp (legitimate logins) từ người dùng thật.

🛠️ Bối cảnh AWS: ALB hỗ trợ tích hợp AWS WAF (Web Application Firewall) để kiểm soát traffic dựa trên rules như user agent, IP, string matching... Đây là giải pháp layer 7 phù hợp cho web apps. Kiến thức cập nhật đến 2026: AWS WAF v2 (phiên bản mới nhất) hỗ trợ custom rules linh hoạt với rate-based rules, regex patterns, và geo-matching.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create an AWS WAF web ACL for the ALB. Create a custom rule that blocks requests that contain the user agent string of the device emulator.

Lý do:

  • AWS WAF tích hợp trực tiếp với ALB, cho phép tạo web ACL với custom rule dựa trên string matching cho user agent.
  • Rule này block chính xác requests chứa user agent của emulator (signature của attack), mà không ảnh hưởng đến legitimate users (họ dùng user agent thật từ browser/mobile thật).
  • Hiệu quả với tấn công từ nhiều IP, vì WAF inspect HTTP headers (User-Agent) ở layer 7.
  • Tuân thủ best practice: Least privilege – chỉ block pattern xấu, allow traffic tốt. Hỗ trợ rate limiting nếu cần scale.

📋 Giải thích tất cả các phương án (đúng/sai)

  • Create an Amazon CloudWatch alarm that reacts to login attempts that contain the specified user agent string. Add an Amazon Simple Notification Service (Amazon SNS) topic to the alarm.
    ❌ Sai: CloudWatch chỉ giám sát và thông báo (notify) qua SNS khi phát hiện pattern (dựa trên logs ALB/CloudWatch Logs). Không block traffic trực tiếp. Giải pháp này chỉ phản ứng sau (reactive), không ngăn chặn real-time, dẫn đến app vẫn bị flood failed logins. Không đáp ứng "mitigate attack".

  • Modify the inbound security group on the ALB to deny traffic from the IP addresses that are involved in the attack.
    ❌ Sai: Security Group (SG) của ALB chỉ hỗ trợ allow/deny theo IP/CIDR ở layer 4 (TCP/UDP). Tấn công từ nhiều IP thay đổi (distributed), việc cập nhật SG thủ công không khả thi (scale kém, dễ miss IP mới). Ngoài ra, SG không inspect user agent (HTTP header), nên không block chính xác attack.

  • Create an AWS WAF web ACL for the ALB. Create a custom rule that blocks requests that contain the user agent string of the device emulator.
    ✅ Đúng: Như đã giải thích ở trên. WAF rule sử dụng string match hoặc regex trên User-Agent header để block ngay lập tức (drop/challenge). Legitimate traffic (user agent khác) pass qua bình thường. Có thể kết hợp managed rules (SQLi/XSS) để bảo vệ toàn diện.

  • Create an AWS WAF web ACL for the ALB. Create a custom rule that allows requests from legitimate user agent strings.
    ❌ Sai: Đây là whitelist (allow list) dựa trên user agent hợp pháp. Vấn đề:

    • Attacker có thể fake user agent hợp pháp (dễ dàng thay đổi).
    • Block tất cả user agent không trong list, ảnh hưởng legitimate users (họ dùng đa dạng UA từ browser khác nhau, mobile thật, etc.).
    • Vi phạm yêu cầu "allow legitimate logins" vì quá restrictive. Best practice WAF dùng block bad patterns thay vì allow good ones.

🛡️ Khuyến nghị bổ sung: Kết hợp AWS Shield Advanced cho DDoS, rate-based rules trong WAF (limit login attempts/IP), và Amazon GuardDuty để detect credential stuffing tự động. Test rule với WAF logging (CloudWatch/S3) trước deploy!