Ngân hàng đề — AWS Certified Security Specialty

Tìm thấy 445 câu.

Câu 311
A company suspects that an attacker has exploited an overly permissive role to export credentials from Amazon EC2 instance metadata. The company uses Amazon GuardDuty and AWS Audit Manager. The company has enabled AWS CloudTrail logging and Amazon CloudWatch logging for all of its AWS accounts.

A security engineer must determine if the credentials were used to access the company's resources from an external account.

Which solution will provide this information?
  1. A Review GuardDuty findings to find InstanceCredentialExfiltration events.
  2. B Review assessment reports in the Audit Manager console to find InstanceCredentialExfiltration events.
  3. C Review CloudTrail logs for GetSessionToken API calls to AWS Security Token Service (AWS STS) that come from an account ID from outside the company.
  4. D Review CloudWatch logs for GetSessionToken API calls to AWS Security Token Service (AWS STS) that come from an account ID from outside the company.
Xem giải thích

🧩 Giải thích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh tình huống bảo mật AWS nơi một công ty nghi ngờ kẻ tấn công đã khai thác IAM role quá permissive (quyền hạn quá rộng) để trích xuất credentials (tài khoản xác thực) từ Amazon EC2 Instance Metadata Service (IMDS). Công ty đã kích hoạt các dịch vụ sau:

  • Amazon GuardDuty: Dịch vụ phát hiện mối đe dọa tự động.
  • AWS Audit Manager: Công cụ đánh giá tuân thủ (compliance).
  • AWS CloudTrail: Ghi log tất cả API calls.
  • Amazon CloudWatch Logs: Lưu trữ logs từ CloudTrail và các nguồn khác.

Nhiệm vụ của security engineer là xác định xem credentials bị đánh cắp có được sử dụng để truy cập tài nguyên của công ty từ một tài khoản AWS bên ngoài (external account) hay không. 🛡️

Câu hỏi yêu cầu giải pháp tốt nhất để thu thập thông tin này một cách hiệu quả và chính xác nhất, dựa trên các dịch vụ đã enabled.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Review GuardDuty findings to find InstanceCredentialExfiltration events.

Lý do:

  • Amazon GuardDuty (cập nhật đến 2026) có finding cụ thể tên "InstanceCredentialExfiltration" (hoặc các biến thể như InstanceCredentialExfiltration.S3DataExfil), được thiết kế để phát hiện chính xác khi IAM credentials từ EC2 instance metadata bị exfiltration (trích xuất và sử dụng bất thường).
  • GuardDuty sử dụng machine learning và threat intelligence để phân tích logs từ CloudTrail, VPC Flow Logs, DNS logs, v.v., và tự động detect nếu credentials bị dùng từ IP lạ, external account, hoặc outside expected network (ví dụ: từ tài khoản AWS khác không thuộc công ty).
  • Finding này cung cấp chi tiết rõ ràng: source IP, account ID nguồn, tài nguyên bị truy cập, giúp xác nhận external account usage mà không cần manually parse logs. Đây là giải pháp tự động, real-time và chính xác nhất. 🚀

📋 Phân tích tất cả các phương án (đúng/sai)

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá ✅ (đúng) hoặc ❌ (sai), kèm giải thích bằng tiếng Việt dựa trên kiến thức AWS mới nhất 2026.

  • ✅ Review GuardDuty findings to find InstanceCredentialExfiltration events.
    Đúng hoàn toàn: Như đã giải thích ở trên, GuardDuty cung cấp finding chuyên biệt cho trường hợp này. Nó detect suspicious usage của instance credentials từ external sources, bao gồm account ID lạ. Đây là best practice theo AWS Security best practices. 🏆

  • ❌ Review assessment reports in the Audit Manager console to find InstanceCredentialExfiltration events.
    Sai: AWS Audit Manager dùng để tạo báo cáo tuân thủ định kỳ (compliance assessments) dựa trên frameworks như NIST, PCI DSS. Nó không có real-time findings như InstanceCredentialExfiltration, và không detect specific threats từ GuardDuty. Audit Manager chỉ aggregate evidence từ CloudTrail/GuardDuty, nhưng không phải nguồn chính để check external usage ngay lập tức. 📊

  • ❌ Review CloudTrail logs for GetSessionToken API calls to AWS Security Token Service (AWS STS) that come from an account ID from outside the company.
    Sai:

    • GetSessionToken là API STS để tạo temp credentials từ long-term access keys, không liên quan đến credentials từ EC2 IMDS (là temp creds từ instance role, không cần GetSessionToken).
    • CloudTrail log tất cả API calls, nhưng để detect external account, phải manually filter source IP, userAgent, principal account – rất tốn thời gian và không specific cho InstanceCredentialExfiltration.
    • Attacker dùng stolen creds trực tiếp (không qua STS mới), nên GetSessionToken không phải indicator đúng. Thủ công parse logs kém hiệu quả so với GuardDuty. 🔍
  • ❌ Review CloudWatch logs for GetSessionToken API calls to AWS Security Token Service (AWS STS) that come from an account ID from outside the company.
    Sai tương tự phương án trước: CloudWatch Logs chỉ lưu trữ CloudTrail logs (nếu enabled), nên cùng vấn đề về GetSessionToken không liên quan và thiếu automation. Không có insight threat detection như GuardDuty. CloudWatch tốt cho monitoring metrics/logs, nhưng không phải tool security forensics chính. ☁️

📘 Tài liệu tham khảo (AWS Documentation - Cập nhật 2026)

Giải pháp này đảm bảo tuân thủ AWS Well-Architected Framework - Security Pillar! 🔒

Câu 312
A security engineer needs to run an AWS CloudFormation script. The CloudFormation script builds AWS infrastructure to support a stack that includes web servers and a MySQL database. The stack has been deployed in pre-production environments and is ready for production.

The production script must comply with the principle of least privilege. Additionally, separation of duties must exist between the security engineer’s IAM account and CloudFormation.

Which solution will meet these requirements?
  1. A Use IAM Access Analyzer policy generation to generate a policy that allows the CloudFormation script to run and manage the stack. Attach the policy to a new IAM role. Modify the security engineer's IAM permissions to be able to pass the new role to CloudFormation.
  2. B Create an IAM policy that allows ec2:* and rds:* permissions. Attach the policy to a new IAM role. Modify the security engineer's IAM permissions to be able to assume the new role.
  3. C Use IAM Access Analyzer policy generation to generate a policy that allows the CloudFormation script to run and manage the stack. Modify the security engineer's IAM permissions to be able to run the CloudFormation script.
  4. D Create an IAM policy that allows ec2:* and rds:* permissions. Attach the policy to a new IAM role. Use the IAM policy simulator to confirm that the policy allows the AWS API calls that are necessary to build the stack. Modify the security engineer's IAM permissions to be able to pass the new role to CloudFormation.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai một script AWS CloudFormation để xây dựng stack hạ tầng bao gồm web servers (EC2) và MySQL database (RDS) trong môi trường production. Stack này đã được kiểm tra ở pre-production và sẵn sàng.

Yêu cầu chính cần đáp ứng:

  • Principle of least privilege 🛡️: IAM policy chỉ cấp quyền tối thiểu cần thiết để script CloudFormation chạy và quản lý stack (không cấp quyền rộng như ec2:* hay rds:*).
  • Separation of duties 🔄: Phải tách biệt quyền giữa IAM account của security engineer và CloudFormation service. Nghĩa là engineer không trực tiếp có quyền deploy stack (như cloudformation:*), mà chỉ có quyền pass IAM role cho CloudFormation để service này tự thực hiện các hành động thay thế.

Bối cảnh thực tế trên AWS (cập nhật đến 2026): CloudFormation hỗ trợ service role (IAM role dành riêng cho CloudFormation) để thực hiện các API calls thay mặt user. Security engineer chỉ cần quyền iam:PassRole cho role đó. IAM Access Analyzer (feature từ 2021, cập nhật liên tục) giúp generate policy fine-grained dựa trên access patterns thực tế, đảm bảo least privilege tự động.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Use IAM Access Analyzer policy generation to generate a policy that allows the CloudFormation script to run and manage the stack. Attach the policy to a new IAM role. Modify the security engineer's IAM permissions to be able to pass the new role to CloudFormation.

Lý do chi tiết 🛠️:

  • Sử dụng IAM Access Analyzer policy generation để tạo policy least privilege chính xác dựa trên script CloudFormation đã chạy ở pre-production (phân tích access logs để chỉ cấp quyền cần thiết như ec2:RunInstances, rds:CreateDBInstance thay vì *).
  • Attach policy vào IAM role mới dành riêng cho CloudFormation service role.
  • Security engineer chỉ cần quyền iam:PassRole để "chuyền" role này cho CloudFormation khi tạo/update stack (qua --role-arn trong CLI hoặc template).
  • Đảm bảo separation of duties hoàn hảo: Engineer không có quyền trực tiếp trên EC2/RDS/CloudFormation, chỉ "ủy quyền" cho service.

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn, giữ nguyên nội dung gốc tiếng Anh. Tôi đánh dấu ✅/❌ và giải thích rõ lý do bằng tiếng Việt.

  • ✅ [ĐÚNG] Use IAM Access Analyzer policy generation to generate a policy that allows the CloudFormation script to run and manage the stack. Attach the policy to a new IAM role. Modify the security engineer's IAM permissions to be able to pass the new role to CloudFormation.
    🛡️ Hoàn hảo tuân thủ least privilege (policy từ Access Analyzer fine-grained) và separation of duties (engineer chỉ pass role, CloudFormation tự hành động).

  • ❌ [SAI] Create an IAM policy that allows ec2: and rds: permissions. Attach the policy to a new IAM role. Modify the security engineer's IAM permissions to be able to assume the new role.**
    ❌ Vi phạm least privilege nặng: ec2:* và rds:* cấp quyền rộng rãi (hàng trăm actions, bao gồm delete/destroy), không an toàn cho production. Ngoài ra, engineer assume role nghĩa là họ có thể tự thực hiện ec2/rds actions trực tiếp, phá vỡ separation of duties với CloudFormation.

  • ❌ [SAI] Use IAM Access Analyzer policy generation to generate a policy that allows the CloudFormation script to run and manage the stack. Modify the security engineer's IAM permissions to be able to run the CloudFormation script.
    ❌ Tuy dùng Access Analyzer tốt cho least privilege, nhưng attach policy trực tiếp vào IAM của engineer làm họ có quyền cloudformation:* đầy đủ. Không có separation of duties: Engineer có thể deploy/run stack trực tiếp mà không cần role riêng cho CloudFormation.

  • ❌ [SAI] Create an IAM policy that allows ec2: and rds: permissions. Attach the policy to a new IAM role. Use the IAM policy simulator to confirm that the policy allows the AWS API calls that are necessary to build the stack. Modify the security engineer's IAM permissions to be able to pass the new role to CloudFormation.**
    ❌ Dù dùng simulator kiểm tra và pass role (tốt cho separation), nhưng policy ec2:*/rds:* vẫn quá rộng, vi phạm least privilege. Access Analyzer hoặc CloudTrail insights mới là cách generate policy chính xác hơn simulator thủ công.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm ví dụ thực hành, hãy hỏi nhé.

Câu 313 Chọn nhiều đáp án
A company that uses AWS Organizations is migrating workloads to AWS. The company's application team determines that the workloads will use Amazon EC2 instances, Amazon S3 buckets, Amazon DynamoDB tables, and Application Load Balancers. For each resource type, the company mandates that deployments must comply with the following requirements:

•All EC2 instances must be launched from approved AWS accounts.
•All DynamoDB tables must be provisioned with a standardized naming convention.
•All infrastructure that is provisioned in any accounts in the organization must be deployed by AWS CloudFormation templates.

Which combination of steps should the application team take to meet these requirements? (Choose two.)
  1. A Create CloudFormation templates in an administrator AWS account. Share the stack sets with an application AWS account. Restrict the template to be used specifically by the application AWS account.
  2. B Create CloudFormation templates in an application AWS account. Share the output with an administrator AWS account ta review compliant resources. Restrict output to only the administrator AWS account.
  3. C Use permissions boundaries to prevent the application AWS account from provisioning specific resources unless conditions for the internal compliance requirements are met.
  4. D Use SCPs to prevent the application AWS account from provisioning specific resources unless conditions for the internal compliance requirements are met.
  5. E Activate AWS Config managed rules for each service in the application AWS account.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi này thuộc chủ đề AWS Organizations và quản lý tuân thủ (compliance) trong môi trường đa tài khoản AWS, tập trung vào việc migrate workloads sử dụng các dịch vụ như Amazon EC2, S3, DynamoDB, và Application Load Balancers (ALB). Công ty yêu cầu 3 điều kiện bắt buộc cho mọi deployment:

  • ✅ Tất cả EC2 instances phải được launch từ các AWS accounts được phê duyệt (approved AWS accounts): Đảm bảo chỉ deploy từ tài khoản đáng tin cậy, tránh tạo instance từ tài khoản không được phép.
  • ✅ Tất cả DynamoDB tables phải sử dụng naming convention chuẩn hóa: Buộc đặt tên theo quy tắc thống nhất để dễ quản lý và kiểm soát.
  • ✅ Toàn bộ infrastructure trong bất kỳ account nào thuộc organization phải deploy bằng AWS CloudFormation templates: Không cho phép tạo tài nguyên thủ công, chỉ qua template CloudFormation để đảm bảo tính nhất quán và tự động hóa.

Mục tiêu là chọn 2 bước kết hợp (combination of steps) để đáp ứng tất cả yêu cầu trên một cách hiệu quả, tận dụng các tính năng của AWS Organizations như Service Control Policies (SCPs) và CloudFormation StackSets để enforce cross-account.

🛠️ Phân tích ngữ cảnh: Đây là kịch bản DevOps điển hình cho enterprise, nơi tài khoản quản trị (administrator account) kiểm soát tài khoản ứng dụng (application account). Cần cơ chế prevent (ngăn chặn) provisioning không hợp lệ trước khi xảy ra, thay vì chỉ monitor sau (như AWS Config).

✅ Đáp án đúng (Chọn 2)

Hai lựa chọn đúng là:

  1. Create CloudFormation templates in an administrator AWS account. Share the stack sets with an application AWS account. Restrict the template to be used specifically by the application AWS account.
  2. Use SCPs to prevent the application AWS account from provisioning specific resources unless conditions for the internal compliance requirements are met.

Lý do lựa chọn:

  • 🛠️ Lựa chọn 1: Sử dụng CloudFormation StackSets từ administrator account (delegated administrator) để chia sẻ và deploy template cross-account vào application account. Điều này enforce deploy chỉ qua CloudFormation, đảm bảo EC2 chỉ launch từ approved accounts (admin), và DynamoDB có naming chuẩn (define trong template). StackSets hỗ trợ permissions boundaries và restrictions để chỉ application account cụ thể được dùng.
  • 🛠️ Lựa chọn 2: SCPs (Service Control Policies) trong AWS Organizations là policy cấp organization để deny actions (như ec2:RunInstances, dynamodb:CreateTable) trừ khi conditions met (ví dụ: aws:PrincipalAccount phải là approved account, hoặc dynamodb:TableName match pattern naming convention). SCPs prevent provisioning ngay lập tức, bổ sung hoàn hảo cho StackSets.
  • Kết hợp hai bước này cover 100% yêu cầu: StackSets enforce CloudFormation + approved accounts/naming, SCPs là lớp bảo vệ cuối cùng deny mọi hành động ngoài luồng.

📋 Giải thích chi tiết tất cả các phương án

  • ✅ Create CloudFormation templates in an administrator AWS account. Share the stack sets with an application AWS account. Restrict the template to be used specifically by the application AWS account.
    Đúng 🟢: StackSets (tính năng CloudFormation cross-account) cho phép admin account tạo và deploy stack vào target accounts, enforce chỉ dùng template approved. Hỗ trợ self-managed permissions để restrict chỉ application account cụ thể. Đáp ứng toàn bộ EC2 approved + DynamoDB naming + CloudFormation mandatory (từ phiên bản CloudFormation 2023+, StackSets hỗ trợ Org-wide deployment với guardrails).

  • ❌ Create CloudFormation templates in an application AWS account. Share the output with an administrator AWS account ta review compliant resources. Restrict output to only the administrator AWS account.
    Sai 🔴: Tạo template trong application account không enforce approved accounts cho EC2 (vẫn có thể launch thủ công từ app account). "Share output" chỉ review sau khi deploy, không prevent, và SCP/guardrails không cần thiết cho output. Không cover CloudFormation mandatory org-wide.

  • ❌ Use permissions boundaries to prevent the application AWS account from provisioning specific resources unless conditions for the internal compliance requirements are met.
    Sai 🔴: Permissions boundaries chỉ áp dụng cho IAM users/roles trong cùng account, không cross-account hoặc org-wide như Organizations. Không enforce approved accounts hoặc naming convention ở mức organization, chỉ giới hạn power của principal cá nhân (không phù hợp cho workload migration quy mô lớn).

  • ✅ Use SCPs to prevent the application AWS account from provisioning specific resources unless conditions for the internal compliance requirements are met.
    Đúng 🟢: SCPs là preventive guardrails mạnh mẽ nhất trong Organizations (cập nhật 2024+ với condition keys như aws:ResourceTag/Compliance, dynamodb:TableName). Ví dụ: Deny ec2:RunInstances trừ khi aws:PrincipalAccount là approved, hoặc DynamoDB naming match regex. Bổ sung StackSets để full compliance.

  • ❌ Activate AWS Config managed rules for each service in the application AWS account.
    Sai 🔴: AWS Config chỉ detect và record non-compliance sau provisioning (ví dụ: rules như ec2-instance-no-public-ip-check), không prevent tạo tài nguyên (reactive, không proactive). Không enforce CloudFormation mandatory hoặc approved accounts, chỉ dùng cho audit/remediation (cần AWS Config Aggregator cho org-wide).

📘 Tài liệu tham khảo (Cập nhật AWS 2026)

  • AWS Organizations User Guide: Service Control Policies (SCPs) – Condition keys cho deny unless compliant.
  • CloudFormation StackSets: Cross-account deployments – Delegated admin & restrictions (phiên bản 2024+ hỗ trợ StackSetCollections).
  • Exam DOP-C02 Guide: AWS re:Post & A Cloud Guru (topics: Governance with SCPs/StackSets).
  • Best Practices: AWS Well-Architected Framework – Reliability Pillar (Control Tower cho org compliance).

Hy vọng phân tích này giúp bạn ôn thi AWS Certified DevOps Engineer Professional hiệu quả! 🚀 Nếu cần thêm ví dụ JSON policy, hãy hỏi nhé!

Câu 314 Chọn nhiều đáp án
A company has a batch-processing system that uses Amazon S3, Amazon EC2, and AWS Key Management Service (AWS KMS). The system uses two AWS accounts: Account A and Account B.

Account A hosts an S3 bucket that stores the objects that will be processed. The S3 bucket also stores the results of the processing. All the S3 bucket objects are encrypted by a KMS key that is managed in Account A.

Account B hosts a VPC that has a fleet of EC2 instances that access the S3 bucket in Account A by using statements in the bucket policy. The VPC was created with DNS hostnames enabled and DNS resolution enabled.

A security engineer needs to update the design of the system without changing any of the system's code. No AWS API calls from the batch-processing EC2 instances can travel over the internet.

Which combination of steps will meet these requirements? (Choose two.)
  1. A In the Account B VPC, create a gateway VPC endpoint for Amazon S3. For the gateway VPC endpoint, create a resource policy that allows the s3:GetObject, s3:ListBucket, s3:PutObject, and s3:PutObjectAcl actions for the S3 bucket.
  2. B In the Account B VPC, create an interface VPC endpoint for Amazon S3. For the interface VPC endpoint, create a resource policy that allows the s3:GetObject, s3:ListBucket, s3:PutObject, and s3:PutObjectAcl actions for the S3 bucket.
  3. C In the Account B VPC, create an interface VPC endpoint for AWS KMS. For the interface VPC endpoint, create a resource policy that allows the kms:Encrypt, kms:Decrypt, and kms:GenerateDataKey actions for the KMS key. Ensure that private DNS is turned on for the endpoint.
  4. D In the Account B VPC, create an interface VPC endpoint for AWS KMS. For the interface VPC endpoint, create a resource policy that allows the kms:Encrypt, kms:Decrypt, and kms:GenerateDataKey actions for the KMS key. Ensure that private DNS is turned off for the endpoint.
  5. E In the Account B VPC, verify that the S3 bucket policy allows the s3:PutObjectAcl action for cross-account use. In the Account B VPC, create a gateway VPC endpoint for Amazon S3. For the gateway VPC endpoint, create a resource policy that allows the s3:GetObject, s3:ListBucket, and s3:PutObject actions for the S3 bucket.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một hệ thống batch-processing sử dụng Amazon S3 (lưu trữ dữ liệu đầu vào và kết quả xử lý, được mã hóa bằng KMS key thuộc Account A), Amazon EC2 (chạy trong VPC của Account B), và AWS KMS. EC2 instances trong Account B truy cập S3 bucket cross-account qua bucket policy. VPC đã bật DNS hostnames và DNS resolution.

Yêu cầu chính (theo phiên bản AWS mới nhất 2024-2026):

  • Cập nhật thiết kế mà không thay đổi code (tức chỉ cấu hình network/security).
  • Không cho phép bất kỳ AWS API calls từ EC2 đi qua internet (phải dùng VPC Endpoints để giữ traffic private trong AWS network).
  • Chọn TWO steps phù hợp.

Vấn đề cốt lõi: EC2 cần GetObject/ListBucket/PutObject/PutObjectAcl trên S3 (đọc/ghi dữ liệu mã hóa), và Encrypt/Decrypt/GenerateDataKey trên KMS key (để xử lý dữ liệu mã hóa cross-account). Phải dùng Gateway Endpoint cho S3 (hiệu suất cao, miễn phí) và Interface Endpoint cho KMS (hỗ trợ private connectivity cross-account).

✅ Đáp án đúng (chọn TWO)

Hai phương án đúng là:

  1. In the Account B VPC, create a gateway VPC endpoint for Amazon S3. For the gateway VPC endpoint, create a resource policy that allows the s3:GetObject, s3:ListBucket, s3:PutObject, and s3:PutObjectAcl actions for the S3 bucket.
  2. In the Account B VPC, create an interface VPC endpoint for AWS KMS. For the interface VPC endpoint, create a resource policy that allows the kms:Encrypt, kms:Decrypt, and kms:GenerateDataKey actions for the KMS key. Ensure that private DNS is turned on for the endpoint.

Lý do chọn 🛠️:

  • Gateway Endpoint cho S3 giữ traffic S3 private (không qua internet), hỗ trợ cross-account qua endpoint policy (full access actions cần thiết). Bucket policy hiện tại vẫn hỗ trợ, nhưng endpoint policy bổ sung để enforce private access.
  • Interface Endpoint cho KMS cần thiết vì KMS không hỗ trợ gateway endpoint (chỉ interface cho private DNS và cross-account key access). Private DNS ON (bật theo mặc định mới nhất) cho phép EC2 resolve KMS endpoints qua private IP (không public DNS/internet), phù hợp VPC đã bật DNS. Không thay đổi code vì dùng hostname chuẩn (kms.*.amazonaws.com).
  • Kết hợp hai cái này đảm bảo zero internet traffic cho S3/KMS APIs, tuân thủ security best practices (AWS Well-Architected Framework - Security Pillar).

📋 Giải thích chi tiết từng phương án

Dưới đây là phân tích tất cả 5 phương án, với ✅ cho đúng và ❌ cho sai. Giữ nguyên văn bản gốc tiếng Anh, chỉ giải thích bằng tiếng Việt.

  • ✅ In the Account B VPC, create a gateway VPC endpoint for Amazon S3. For the gateway VPC endpoint, create a resource policy that allows the s3:GetObject, s3:ListBucket, s3:PutObject, and s3:PutObjectAcl actions for the S3 bucket.
    Đúng 🟢: Đây là cách chuẩn cho S3 (gateway endpoint, không phí data transfer). Endpoint policy cho phép full actions cross-account (bao gồm PutObjectAcl cho ACL trên objects). Traffic S3 private, không internet. Phù hợp không thay đổi code (EC2 dùng S3 endpoints tự động route).

  • ❌ In the Account B VPC, create an interface VPC endpoint for Amazon S3. For the interface VPC endpoint, create a resource policy that allows the s3:GetObject, s3:ListBucket, s3:PutObject, and s3:PutObjectAcl actions for the S3 bucket.
    Sai 🔴: S3 không hỗ trợ interface endpoint (chỉ gateway endpoint cho S3). Interface dùng cho dịch vụ như KMS/ECR. Nếu tạo sẽ fail hoặc không route đúng, vi phạm yêu cầu private access hiệu quả.

  • ✅ In the Account B VPC, create an interface VPC endpoint for AWS KMS. For the interface VPC endpoint, create a resource policy that allows the kms:Encrypt, kms:Decrypt, and kms:GenerateDataKey actions for the KMS key. Ensure that private DNS is turned on for the endpoint.
    Đúng 🟢: KMS yêu cầu interface endpoint (PrivateLink). Endpoint policy cho phép actions cần thiết trên KMS key cross-account. Private DNS ON (enable private hosted zone) resolve kms.region.amazonaws.com qua ENI private IP, tránh internet/public DNS. VPC đã bật DNS nên seamless, không thay đổi code.

  • ❌ In the Account B VPC, create an interface VPC endpoint for AWS KMS. For the interface VPC endpoint, create a resource policy that allows the kms:Encrypt, kms:Decrypt, and kms:GenerateDataKey actions for the KMS key. Ensure that private DNS is turned off for the endpoint.
    Sai 🔴: Private DNS OFF sẽ buộc EC2 dùng public DNS (traffic ra internet qua NAT/IGW), vi phạm yêu cầu "No AWS API calls... over the internet". Theo AWS docs mới (2024+), private DNS nên ON cho interface endpoints để full private resolution.

  • ❌ In the Account B VPC, verify that the S3 bucket policy allows the s3:PutObjectAcl action for cross-account use. In the Account B VPC, create a gateway VPC endpoint for Amazon S3. For the gateway VPC endpoint, create a resource policy that allows the s3:GetObject, s3:ListBucket, and s3:PutObject actions for the S3 bucket.
    Sai 🔴: Endpoint policy thiếu s3:PutObjectAcl (cần cho ACL trên objects kết quả), nên EC2 fail khi put objects với ACL. Verify bucket policy không đủ (vì yêu cầu endpoint để private traffic), và thiếu action làm policy incomplete.

📘 Tài liệu tham khảo (AWS Docs cập nhật 2024-2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần demo CloudFormation, hỏi thêm nhé.

Câu 315
A security engineer is designing an IAM policy for a script that will use the AWS CLI. The script currently assumes an IAM role that is attached to three AWS managed IAM policies: AmazonEC2FullAccess, AmazonDynamoDBFullAccess, and AmazonVPCFullAccess.

The security engineer needs to construct a least privilege IAM policy that will replace the AWS managed IAM policies that are attached to this role.

Which solution will meet these requirements in the MOST operationally efficient way?
  1. A In AWS CloudTrail, create a trail for management events. Run the script with the existing AWS managed IAM policies. Use IAM Access Analyzer to generate a new IAM policy that is based on access activity in the trail. Replace the existing AWS managed IAM policies with the generated IAM policy for the role.
  2. B Remove the existing AWS managed IAM policies from the role. Attach the IAM Access Analyzer Role Policy Generator to the role. Run the script. Return to IAM Access Analyzer and generate a least privilege IAM policy. Attach the new IAM policy to the role.
  3. C Create an account analyzer in IAM Access Analyzer. Create an archive rule that has a filter that checks whether the PrincipalArn value matches the ARN of the role. Run the script. Remove the existing AWS managed IAM policies from the role.
  4. D In AWS CloudTrail, create a trail for management events. Remove the existing AWS managed IAM policies from the role. Run the script. Find the authorization failure in the trail event that is associated with the script. Create a new IAM policy that includes the action and resource that caused the authorization failure. Repeat the process until the script succeeds. Attach the new IAM policy to the role.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi xoay quanh việc một kỹ sư bảo mật cần thiết kế IAM policy theo nguyên tắc least privilege (quyền hạn tối thiểu) cho một script sử dụng AWS CLI. Script hiện tại assume một IAM role được gắn 3 AWS managed policies rộng rãi: AmazonEC2FullAccess, AmazonDynamoDBFullAccess, và AmazonVPCFullAccess. Những policy này cấp quyền full access cho EC2, DynamoDB và VPC, dẫn đến rủi ro bảo mật cao.

Yêu cầu là xây dựng policy mới thay thế hoàn toàn các policy cũ, đồng thời phải là cách MOST operationally efficient (hiệu quả vận hành nhất) – nghĩa là tự động hóa cao, ít thủ công, giảm thời gian và lỗi con người. Giải pháp phải dựa trên hoạt động thực tế của script để chỉ cấp đúng quyền cần thiết, tránh over-permission.

Bối cảnh cập nhật AWS (đến 2026): IAM Access Analyzer (từ 2020 và cải tiến liên tục) tích hợp với CloudTrail để tự động generate policy dựa trên access activity thực tế từ management events, giúp đạt least privilege mà không cần thử nghiệm thủ công nhiều lần. 🛠️

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
In AWS CloudTrail, create a trail for management events. Run the script with the existing AWS managed IAM policies. Use IAM Access Analyzer to generate a new IAM policy that is based on access activity in the trail. Replace the existing AWS managed IAM policies with the generated IAM policy for the role.

Lý do chọn đáp án này (hiệu quả vận hành nhất ✅):

  • Phương pháp này tự động hóa hoàn toàn việc phân tích hoạt động thực tế: Tạo CloudTrail trail cho management events (ghi log API calls), chạy script với quyền hiện tại (không gián đoạn), rồi IAM Access Analyzer generate policy chính xác dựa trên access activity trong trail (chỉ bao gồm actions/resources thực sự dùng). Sau đó replace policy cũ.
  • Ưu điểm: Không cần remove policy trước (tránh script fail), không thử nghiệm lặp lại, scale tốt cho production. Đây là best practice AWS khuyến nghị cho least privilege (IAM Access Analyzer policy generation feature, cập nhật 2023-2026).
  • Hiệu quả cao: Một lần chạy script + generate = policy tối ưu, giảm thời gian từ giờ xuống phút. 🏆

📋 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn. Tôi giữ nguyên nội dung phương án gốc bằng tiếng Anh, chỉ giải thích đúng/sai bằng tiếng Việt với lý do rõ ràng dựa trên tính năng AWS mới nhất.

✅ Phương án A (ĐÚNG):
In AWS CloudTrail, create a trail for management events. Run the script with the existing AWS managed IAM policies. Use IAM Access Analyzer to generate a new IAM policy that is based on access activity in the trail. Replace the existing AWS managed IAM policies with the generated IAM policy for the role.
Giải thích: Như trên, đây là quy trình chuẩn của IAM Access Analyzer (tích hợp CloudTrail từ 2021, cải tiến 2024). Nó capture chính xác API calls thực tế, generate customer-managed policy least privilege, và thay thế seamless. Hoàn hảo cho operational efficiency! 🚀

❌ Phương án B (SAI):
Remove the existing AWS managed IAM policies from the role. Attach the IAM Access Analyzer Role Policy Generator to the role. Run the script. Return to IAM Access Analyzer and generate a least privilege IAM policy. Attach the new IAM policy to the role.
Giải thích: IAM Access Analyzer không có tính năng "Role Policy Generator" như mô tả (tính năng generate policy chỉ từ CloudTrail activity hoặc unused access analysis, không phải attach trực tiếp vào role rồi run). Remove policy trước sẽ làm script fail ngay lập tức (authorization errors), buộc phải debug thủ công – không efficient và rủi ro cao. Sai về workflow AWS thực tế. 😵

❌ Phương án C (SAI):
Create an account analyzer in IAM Access Analyzer. Create an archive rule that has a filter that checks whether the PrincipalArn value matches the ARN of the role. Run the script. Remove the existing AWS managed IAM policies from the role.
Giải thích: "Account analyzer" trong IAM Access Analyzer dùng để phát hiện external access (public/inactive policies), không generate least privilege policy từ hoạt động script. Archive rule (CloudWatch Logs?) không liên quan đến policy generation. Remove policy cuối cùng làm script fail vĩnh viễn nếu không attach policy mới – thiếu bước generate policy, không đạt yêu cầu thay thế least privilege. Workflow sai hoàn toàn! 🚫

❌ Phương án D (SAI):
In AWS CloudTrail, create a trail for management events. Remove the existing AWS managed IAM policies from the role. Run the script. Find the authorization failure in the trail event that is associated with the script. Create a new IAM policy that includes the action and resource that caused the authorization failure. Repeat the process until the script succeeds. Attach the new IAM policy to the role.
Giải thích: Đây là cách thủ công lặp lại (trial-and-error): Remove policy → script fail → check CloudTrail → add quyền từng cái → repeat. Rất không efficient (có thể hàng chục lần nếu script phức tạp), tốn thời gian, dễ miss quyền, và gián đoạn script. IAM Access Analyzer tồn tại để tránh cách này! Không phải "MOST operationally efficient". ⏳

📘 Tài liệu tham khảo

  • AWS Docs IAM Access Analyzer - Generate policies from CloudTrail: IAM Access Analyzer policy generation (cập nhật 2025: Hỗ trợ management events tự động).
  • CloudTrail integration: CloudTrail for IAM analysis.
  • Best Practices Least Privilege: AWS Well-Architected Framework - Security Pillar (2026 edition).
  • Exam Reference: AWS Certified DevOps Engineer Professional DOP-C02 (phần IAM & Access Analyzer).

Nếu cần ví dụ code hoặc demo thực tế, hãy cho tôi biết nhé! 💡

Câu 316
A security engineer is designing a cloud architecture to support an application. The application runs on Amazon EC2 instances and processes sensitive information, including credit card numbers.

The application will send the credit card numbers to a component that is running in an isolated environment. The component will encrypt, store, and decrypt the numbers. The component then will issue tokens to replace the numbers in other parts of the application.

The component of the application that manages the tokenization process will be deployed on a separate set of EC2 instances. Other components of the application must not be able to store or access the credit card numbers.

Which solution will meet these requirements?
  1. A Use EC2 Dedicated Instances for the tokenization component of the application.
  2. B Place the EC2 instances that manage the tokenization process into a partition placement group.
  3. C Create a separate VPDeploy new EC2 instances into the separate VPC to support the data tokenization.
  4. D Deploy the tokenization code onto AWS Nitro Enclaves that are hosted on EC2 instances.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả một kỹ sư bảo mật đang thiết kế kiến trúc đám mây cho ứng dụng chạy trên Amazon EC2 instances, xử lý thông tin nhạy cảm như số thẻ tín dụng. Ứng dụng sẽ gửi số thẻ tín dụng đến một component riêng biệt chạy trong môi trường cô lập. Component này chịu trách nhiệm mã hóa (encrypt), lưu trữ (store), giải mã (decrypt) số thẻ, sau đó phát hành token để thay thế số thẻ ở các phần khác của ứng dụng.

Component quản lý quá trình tokenization được triển khai trên tập EC2 instances riêng biệt. Yêu cầu cốt lõi: Các component khác của ứng dụng KHÔNG được phép lưu trữ hoặc truy cập số thẻ tín dụng gốc.

Mục tiêu là tìm giải pháp cô lập hoàn toàn dữ liệu nhạy cảm, đảm bảo ngay cả trên cùng instance hoặc môi trường, dữ liệu không bị lộ ra ngoài component tokenization. Đây là vấn đề bảo mật cao cấp, liên quan đến zero-trust architecture và memory-encrypted enclaves trên AWS (cập nhật đến 2026, Nitro Enclaves vẫn là giải pháp chuẩn cho use case này).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Deploy the tokenization code onto AWS Nitro Enclaves that are hosted on EC2 instances.

Lý do:

  • AWS Nitro Enclaves cung cấp môi trường thực thi cô lập (isolated execution environment) trên EC2 instances (hỗ trợ các loại như m5, r5, c5, i3 với Nitro hypervisor). Mã chạy trong Enclave không thể bị truy cập từ hệ điều hành host, hypervisor, hoặc bất kỳ process nào bên ngoài, kể cả root/admin trên instance cha.
  • Dữ liệu nhạy cảm (số thẻ tín dụng) chỉ tồn tại trong bộ nhớ được mã hóa (encrypted memory) của Enclave, không lưu trên EBS/disk mặc định, và không có cách nào dump memory hoặc truy cập từ host.
  • Hoàn hảo cho tokenization: Nhận dữ liệu gốc → encrypt/store/decrypt trong Enclave → trả token ra ngoài. Các phần ứng dụng khác chỉ nhận token, không bao giờ thấy dữ liệu gốc.
  • Tuân thủ PCI-DSS cho dữ liệu thẻ tín dụng (cập nhật AWS 2026: Enclaves hỗ trợ attestation để chứng minh tính toàn vẹn).

🛠️ Phân tích tất cả các phương án (đúng/sai)

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh:

  • Use EC2 Dedicated Instances for the tokenization component of the application.
    ❌ Sai: EC2 Dedicated Instances chỉ cô lập phần cứng vật lý (không chia sẻ host vật lý với tenant khác), nhưng không cô lập dữ liệu ở mức process/memory. Dữ liệu thẻ tín dụng vẫn có thể bị truy cập qua OS host, EBS volumes, hoặc admin privileges. Không đáp ứng yêu cầu "other components must not store or access" vì vẫn chạy trên cùng instance/OS thông thường.

  • Place the EC2 instances that manage the tokenization process into a partition placement group.
    ❌ Sai: Partition Placement Group dùng để tối ưu hiệu suất mạng thấp độ trễ giữa các instances trong cùng partition (dùng cho HPC/ML workloads). Nó không cung cấp cô lập bảo mật dữ liệu; instances vẫn chia sẻ mạng VPC và có thể bị truy cập qua IAM/Security Groups. Không liên quan đến bảo vệ dữ liệu nhạy cảm trong memory.

  • Create a separate VPDeploy new EC2 instances into the separate VPC to support the data tokenization.
    ❌ Sai (lưu ý: văn bản gốc có lỗi đánh máy "VPDeploy", có lẽ là "VPC. Deploy"): Tạo VPC riêng chỉ cô lập mạng layer (traffic isolation qua NACL/SG/VPC peering), nhưng dữ liệu vẫn lưu trên EBS/S3 có thể truy cập qua IAM cross-account. Không ngăn chặn lưu trữ/truy cập dữ liệu gốc trên instance; admin hoặc malware trên instance vẫn đọc được. Không đủ cho yêu cầu cô lập "isolated environment" ở mức CPU/memory.

  • Deploy the tokenization code onto AWS Nitro Enclaves that are hosted on EC2 instances.
    ✅ Đúng: Như giải thích ở trên, đây là giải pháp chuẩn AWS cho isolated compute với dữ liệu nhạy cảm (confidential computing). Đáp ứng đầy đủ yêu cầu mà không cần thay đổi hạ tầng lớn.

📘 Tài liệu tham khảo (cập nhật AWS 2026)

Giải pháp này đảm bảo tuân thủ zero-trust và scalable! 🚀 Nếu cần demo code hoặc thiết kế sâu hơn, hãy hỏi nhé!

Câu 317
A company has two AWS accounts: Account A and Account B. Account A has an IAM role that IAM users in Account B assume when they need to upload sensitive documents to Amazon S3 buckets in Account A.

A new requirement mandates that users can assume the role only if they are authenticated with multi-factor authentication (MFA). A security engineer must recommend a solution that meets this requirement with minimum risk and effort.

Which solution should the security engineer recommend?
  1. A Add an aws:MultiFactorAuthPresent condition to the role's permissions policy.
  2. B Add an aws MultiFactorAuthPresent condition to the role’s trust policy.
  3. C Add an aws:MultiFactorAuthPresent condition to the session policy.
  4. D Add an aws:MultiFactorAuthPresent condition to the S3 bucket policies.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi xoay quanh chính sách bảo mật IAM trong môi trường multi-account AWS, cụ thể là cơ chế cross-account role assumption giữa Account A và Account B.

  • Tình huống: Account A sở hữu các S3 bucket chứa tài liệu nhạy cảm. IAM users từ Account B cần assume một IAM role trong Account A để upload dữ liệu lên S3. Đây là mô hình trust relationship điển hình, nơi trust policy của role ở Account A cho phép principals (users) từ Account B assume role.
  • Yêu cầu mới: Chỉ cho phép assume role nếu user đã authenticated với MFA (Multi-Factor Authentication). Giải pháp phải có rủi ro thấp nhất và nỗ lực triển khai tối thiểu (minimum risk and effort).
  • Thách thức chính: Kiểm soát điều kiện MFA phải được áp dụng tại thời điểm assume role, không phải sau khi role đã được assume hoặc tại resource level (như S3). Điều này liên quan đến trust policy của IAM role, vì trust policy định nghĩa "ai" (principals) và "dưới điều kiện nào" (conditions) có thể assume role.

Mục tiêu là enforce MFA trong quá trình STS AssumeRole, sử dụng condition key aws:MultiFactorAuthPresent để kiểm tra sự hiện diện của MFA token.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Add an aws MultiFactorAuthPresent condition to the role’s trust policy.

Lý do chi tiết 🛠️:

  • Trust policy của IAM role chính là nơi kiểm soát assume role action (sts:AssumeRole). Thêm condition aws:MultiFactorAuthPresent: "true" vào trust policy sẽ yêu cầu user phải cung cấp MFA token khi gọi AssumeRole API từ Account B.
  • Ví dụ cấu hình (JSON snippet trong trust policy):
    {
      "Condition": {
        "Bool": {
          "aws:MultiFactorAuthPresent": "true"
        }
      }
    }
    
  • Lợi ích: Giải pháp đơn giản nhất (chỉ chỉnh sửa 1 policy), rủi ro thấp (không ảnh hưởng permissions sau assume, không cần thay đổi user-side nhiều), và hiệu quả cao vì AWS STS tự động validate MFA. Đây là best practice cho cross-account access với MFA enforcement.
  • Áp dụng phiên bản AWS mới nhất (2026): IAM conditions vẫn hỗ trợ aws:MultiFactorAuthPresent đầy đủ, không có thay đổi lớn (IAM Access Analyzer khuyến khích audit trust policies).

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai với lý do cụ thể:

  • ❌ [SAI] Add an aws:MultiFactorAuthPresent condition to the role's permissions policy.
    Giải thích: Permissions policy chỉ kiểm soát actions mà role có thể thực hiện SAU KHI đã assume (như s3:PutObject). Không ảnh hưởng đến quá trình assume role ban đầu. Nếu thêm condition MFA ở đây, user vẫn assume role mà không cần MFA, dẫn đến lỗ hổng bảo mật. Không đáp ứng yêu cầu "chỉ assume nếu có MFA".

  • ✅ [ĐÚNG] Add an aws MultiFactorAuthPresent condition to the role’s trust policy.
    Giải thích: Như đã nêu ở phần đáp án đúng. Đây là vị trí chính xác và tối ưu để enforce MFA tại assume time, tuân thủ nguyên tắc least privilege trong IAM trust relationships.

  • ❌ [SAI] Add an aws:MultiFactorAuthPresent condition to the session policy.
    Giải thích: Session policy chỉ áp dụng khi sử dụng STS AssumeRoleWithSAML hoặc external IdP, và nó giới hạn permissions tạm thời của session. Không kiểm soát điều kiện assume role cơ bản từ IAM user cross-account. Session policy không phải là policy cố định của role, mà là tham số động khi gọi API → nỗ lực cao hơn, không minimum effort.

  • ❌ [SAI] Add an aws:MultiFactorAuthPresent condition to the S3 bucket policies.
    Giải thích: S3 bucket policy chỉ kiểm soát access đến bucket (như PutObject), không kiểm soát assume role. User có thể assume role mà không MFA, rồi bị chặn tại S3 → không ngăn chặn assume role, vi phạm yêu cầu. Ngoài ra, điều kiện MFA ở resource policy không liên quan trực tiếp đến STS AssumeRole.

📘 Tài liệu tham khảo

Giải pháp này đảm bảo zero-trust model với MFA enforcement hiệu quả! 🚀

Câu 318
A company wants to receive automated email notifications when AWS access keys from developer AWS accounts are detected on code repository sites.

Which solution will provide the required email notifications?
  1. A Create an Amazon EventBridge rule to send Amazon Simple Notification Service (Amazon SNS) email notifications for Amazon GuardDuty UnauthorizedAccess:IAMUser/lnstanceCredentialExfiltration.OutsideAWS findings.
  2. B Change the AWS account contact information for the Operations type to a separate email address. Periodically poll this email address for notifications.
  3. C Create an Amazon EventBridge rule that reacts to AWS Health events that have a value of Risk for the service category. Configure email notifications by using Amazon Simple Notification Service (Amazon SNS).
  4. D Implement new anomaly detection software. Ingest AWS CloudTrail logs. Configure monitoring for ConsoleLogin events in the AWS Management Console. Configure email notifications from the anomaly detection software.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc công ty muốn nhận thông báo email tự động khi phát hiện AWS access keys từ các tài khoản developer bị lộ trên các site lưu trữ code (code repository sites) như GitHub công khai.
✅ Mục tiêu chính: Cần một giải pháp tự động hóa hoàn toàn, sử dụng dịch vụ AWS native để phát hiện rò rỉ credentials trên các nền tảng bên ngoài AWS và gửi email notifications.
🛠️ Bối cảnh AWS: Đây liên quan đến Amazon GuardDuty – dịch vụ threat detection có khả năng quét public GitHub repositories để tìm AWS IAM access keys bị lộ công khai (tính năng được cập nhật từ năm 2022 và vẫn là chuẩn đến 2026). GuardDuty tạo findings cụ thể cho trường hợp này, và có thể tích hợp với Amazon EventBridge để trigger Amazon SNS gửi email ngay lập tức. Không cần can thiệp thủ công.

✅ Đáp án đúng

Create an Amazon EventBridge rule to send Amazon Simple Notification Service (Amazon SNS) email notifications for Amazon GuardDuty UnauthorizedAccess:IAMUser/lnstanceCredentialExfiltration.OutsideAWS findings.

Lý do chọn đáp án này (dựa trên AWS best practices 2026):
🛡️ Amazon GuardDuty tự động phát hiện AWS access keys bị lộ trên public code repos (như GitHub) thông qua GitHub scan và S3 data source. Finding type UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration.OutsideAWS (lưu ý: "lnstance" là lỗi chính tả chuẩn AWS là "Instance") chính xác chỉ trường hợp IAM user credentials bị exfiltrate ra ngoài AWS, bao gồm lộ trên code sites.
📡 EventBridge rule capture findings này làm event source, trigger SNS topic với email subscription để gửi thông báo tự động. Giải pháp này serverless, scalable, real-time và không cần code custom. Hoàn hảo cho DevOps automation!

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai với lý do cụ thể:

  • ✅ [ĐÚNG] Create an Amazon EventBridge rule to send Amazon Simple Notification Service (Amazon SNS) email notifications for Amazon GuardDuty UnauthorizedAccess:IAMUser/lnstanceCredentialExfiltration.OutsideAWS findings.
    🧠 Tại sao đúng? Như đã giải thích, GuardDuty chuyên detect exposed IAM keys trên GitHub/public repos với finding này. EventBridge + SNS đảm bảo email tự động tức thì, tích hợp native AWS (zero false positives cao nhờ ML của GuardDuty). Phù hợp DOP-C02 exam blueprint về monitoring/security.

  • ❌ [SAI] Change the AWS account contact information for the Operations type to a separate email address. Periodically poll this email address for notifications.
    🛑 Tại sao sai? Chỉ thay đổi AWS account contact (qua Support Center) gửi thông báo chung về billing/operations, không detect access keys trên code repos. "Periodically poll" là thủ công, không tự động, vi phạm yêu cầu automated notifications. Không liên quan GuardDuty hay real-time detection.

  • ❌ [SAI] Create an Amazon EventBridge rule that reacts to AWS Health events that have a value of Risk for the service category. Configure email notifications by using Amazon Simple Notification Service (Amazon SNS).
    🚫 Tại sao sai? AWS Health (Personal Health Dashboard) chỉ theo dõi service disruptions/outages với status "Risk/Impaired", không scan code repos hay detect leaked credentials. EventBridge có thể react Health events, nhưng không match yêu cầu về access keys developer accounts.

  • ❌ [SAI] Implement new anomaly detection software. Ingest AWS CloudTrail logs. Configure monitoring for ConsoleLogin events in the AWS Management Console. Configure email notifications from the anomaly detection software.
    🔍 Tại sao sai? CloudTrail log ConsoleLogin chỉ track login vào Console, không detect keys lộ trên external code sites (GitHub). "New anomaly detection software" là custom/third-party, phức tạp, tốn kém, không native AWS. Không tự động cho public repos scanning như GuardDuty.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

  • Amazon GuardDuty Findings: GuardDuty Finding Types – Xem "UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration.OutsideAWS" và GitHub Exposed Credentials (ra mắt 2022, enhanced 2024).
  • EventBridge + GuardDuty Integration: Automate GuardDuty Response.
  • SNS Email Subscriptions: SNS Notifications.
  • DOP-C02 Exam Guide: AWS Certified DevOps Engineer Professional – Domain 5: Security & Compliance (GuardDuty là key service).
    🔗 Tất cả từ AWS Documentation chính thức (kiểm tra re:Post hoặc console GuardDuty để demo).

Giải pháp này cost-effective (~$1/100k findings) và zero-config sau enable GuardDuty GitHub protection! 🚀

Câu 319
A company deployed an Amazon EC2 instance to a VPC on AWS. A recent alert indicates that the EC2 instance is receiving a suspicious number of requests over an open TCP port from an external source. The TCP port remains open for long periods of time.

The company's security team needs to stop all activity to this port from the external source to ensure that the EC2 instance is not being compromised. The application must remain available to other users.

Which solution will meet these requirements?
  1. A Update the network ACL that is attached to the subnet that is associated with the EC2 instance. Add a Deny statement for the port and the source IP addresses.
  2. B Update the elastic network interface security group that is attached to the EC2 instance to remove the port from the inbound rule list.
  3. C Update the elastic network interface security group that is attached to the EC2 instance by adding a Deny entry in the inbound list for the port and the source IP addresses.
  4. D Create a new network ACL for the subnet. Deny all traffic from the EC2 instance to prevent data from being removed.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả một tình huống bảo mật trên AWS: Một công ty đã triển khai một instance Amazon EC2 trong VPC. Gần đây, có cảnh báo về số lượng yêu cầu đáng ngờ (suspicious requests) qua một TCP port mở từ nguồn bên ngoài (external source). Port này vẫn mở trong thời gian dài. Đội ngũ bảo mật cần chặn HOÀN TOÀN hoạt động từ nguồn bên ngoài này đến port đó để tránh EC2 bị compromise, nhưng ứng dụng vẫn phải khả dụng cho các users khác.

Yêu cầu chính:

  • ✅ Chặn cụ thể traffic từ nguồn IP đáng ngờ đến TCP port mở.
  • ✅ Giữ nguyên khả năng truy cập từ các users khác (tức không block toàn bộ port).
  • 🛡️ Giải pháp phải nhanh chóng, hiệu quả, không ảnh hưởng ứng dụng đang chạy.

Ngữ cảnh AWS VPC Security (cập nhật đến 2026):

  • Security Groups (SG): Stateful firewall, chỉ hỗ trợ ALLOW rules (không có explicit DENY), mặc định deny tất cả traffic không được allow.
  • Network ACLs (NACL): Stateless firewall, hỗ trợ cả ALLOW và DENY rules, đánh giá theo thứ tự số (rule number), áp dụng cho toàn subnet.
  • Để block specific source IPs mà không ảnh hưởng others, NACL là lựa chọn lý tưởng vì có DENY rule chính xác.

📘 Tài liệu tham khảo:

✅ Đáp án ĐÚNG và lý do lựa chọn

Đáp án đúng: Update the network ACL that is attached to the subnet that is associated with the EC2 instance. Add a Deny statement for the port and the source IP addresses.

Lý do:

  • 🛡️ NACL cho phép thêm DENY rule cụ thể cho port và source IP addresses (ví dụ: rule #100: DENY TCP port 1234 from IP 203.0.113.0/24).
  • 📡 Áp dụng cho toàn subnet chứa EC2, chặn traffic inbound từ external source mà không ảnh hưởng users khác (vì chỉ deny specific IPs).
  • 🔄 Stateless nên chặn ngay lập tức, hiệu quả cao cho threat isolation.
  • Không làm gián đoạn ứng dụng (app vẫn nhận traffic từ IPs khác).
  • Theo best practices AWS 2026: Sử dụng NACL cho micro-segmentation và explicit deny suspicious traffic.

📋 Giải thích TẤT CẢ các phương án (Đúng/Sai)

  • ✅ [ĐÚNG] Update the network ACL that is attached to the subnet that is associated with the EC2 instance. Add a Deny statement for the port and the source IP addresses.
    🟢 Đúng vì: Như phân tích trên, NACL hỗ trợ DENY rule chính xác cho source IPs/port, block chỉ suspicious traffic, giữ app available. Hoàn hảo cho yêu cầu.

  • ❌ [SAI] Update the elastic network interface security group that is attached to the EC2 instance to remove the port from the inbound rule list.
    🔴 Sai vì: Việc xóa port khỏi inbound rules của SG sẽ block TẤT CẢ inbound traffic đến port đó (bao gồm users hợp lệ), vi phạm "application must remain available to other users". SG chỉ allow cụ thể, không granular block per IP.

  • ❌ [SAI] Update the elastic network interface security group that is attached to the EC2 instance by adding a Deny entry in the inbound list for the port and the source IP addresses.
    🔴 Sai vì: SG KHÔNG hỗ trợ explicit DENY rules (chỉ ALLOW, implicit deny all else). Thêm "Deny entry" sẽ không hoạt động theo docs AWS. Không chặn được specific source mà không ảnh hưởng others.

  • ❌ [SAI] Create a new network ACL for the subnet. Deny all traffic from the EC2 instance to prevent data from being removed.
    🔴 Sai vì:

    • Hướng sai: Deny FROM EC2 (outbound) thay vì TO EC2 (inbound suspicious), không giải quyết vấn đề requests đến port.
    • Quá rộng: "Deny all traffic" block TOÀN BỘ outbound, ngăn app giao tiếp ra ngoài (data exfiltration prevention sai ngữ cảnh).
    • Tạo new NACL không cần thiết (có thể update existing), và làm app unavailable.

Kết luận 🏆: Giải pháp NACL Deny là tối ưu nhất theo AWS best practices cho VPC security hardening! 🚀

Câu 320 Chọn nhiều đáp án
A company has secured the AWS account root user for its AWS account by following AWS best practices. The company also has enabled AWS CloudTrail, which is sending its logs to Amazon S3. A security engineer wants to receive notification in near-real time if a user uses the AWS account root user credentials to sign in to the AWS Management Console

Which solutions will provide this notification? (Choose two.)
  1. A Use AWS Trusted Advisor and its security evaluations for the root account. Configure an Amazon EventBridge event rule that is invoked by the Trusted Advisor API. Configure the rule to target an Amazon Simple Notification Service (Amazon SNS) topic. Subscribe any required endpoints to the SNS topic so that these endpoints can receive notification.
  2. B Use AWS IAM Access Analyzer. Create an Amazon Cloud Watch Logs metric filter to evaluate log entries from Access Analyzer that detect a successful root account login. Create an Amazon CloudWatch alarm that monitors whether a root login has occurred. Configure the CloudWatch alarm to notify an Amazon Simple Notification Service (Amazon SNS) topic when the alarm enters the ALARM state. Subscribe any required endpoints to this SNS topic so that these endpoints can receive notification.
  3. C Configure AWS CloudTrail to send its logs to Amazon CloudWatch Logs. Configure a metric filter on the CloudWatch Logs log group used by CloudTrail to evaluate log entries for successful root account logins. Create an Amazon CloudWatch alarm that monitors whether a root login has occurred. Configure the CloudWatch alarm to notify an Amazon Simple Notification Service (Amazon SNS) topic when the alarm enters the ALARM state. Subscribe any required endpoints to this SNS topic so that these endpoints can receive notification.
  4. D Configure AWS CloudTrail to send log notifications to an Amazon Simple Notification Service (Amazon SNS) topic. Create an AWS Lambda function that parses the CloudTrail notification for root login activity and notifies a separate SNS topic that contains the endpoints that should receive notification. Subscribe the Lambda function to the SNS topic that is receiving log notifications from CloudTrail.
  5. E Configure an Amazon EventBridge event rule that runs when Amazon CloudWatch API calls are recorded for a successful root login. Configure the rule to target an Amazon Simple Notification Service (Amazon SNS) topic. Subscribe any required endpoints to the SNS topic so that these endpoints can receive notification.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào việc phát hiện và thông báo gần thời gian thực (near-real time) khi người dùng sử dụng tài khoản root user để đăng nhập vào AWS Management Console.

  • Bối cảnh: Công ty đã bảo mật root user theo best practices AWS (như kích hoạt MFA, không dùng root hàng ngày), và đã kích hoạt AWS CloudTrail gửi logs đến Amazon S3.
  • Yêu cầu: Security engineer cần hai giải pháp để nhận thông báo ngay lập tức qua Amazon SNS (ví dụ: email, SMS cho endpoints).
  • Kiến thức cốt lõi (cập nhật 2026): Root user login tạo event ConsoleLogin trong CloudTrail (event source: console.amazonaws.com, với responseElements.ConsoleLogin: Success và userIdentity.type: Root). CloudTrail logs mặc định lưu S3 (không real-time), cần tích hợp CloudWatch Logs hoặc EventBridge để xử lý near-real time (latency ~1-5 phút).
    📘 Tài liệu tham khảo:
  • AWS CloudTrail User Guide - Console Login Events
  • Monitoring Root Activity with CloudWatch & EventBridge (cập nhật 2024-2026).

✅ Đáp án đúng (Chọn TWO)

Hai giải pháp chính xác là:

  1. Phương án 3: Sử dụng CloudTrail gửi logs đến CloudWatch Logs + metric filter phát hiện root login + CloudWatch alarm + SNS.
    🛠️ Lý do: Đây là cách chuẩn, đáng tin cậy nhất cho near-real time (CloudTrail stream trực tiếp đến CloudWatch Logs, metric filter match pattern ConsoleLogin root success → alarm trigger SNS ngay). Hỗ trợ full log analysis.

  2. Phương án 5: Sử dụng Amazon EventBridge event rule match trên CloudWatch API calls (thực tế là CloudTrail events ghi nhận ConsoleLogin) → target SNS.
    🛠️ Lý do: EventBridge natively hỗ trợ CloudTrail events near-real time (không cần S3/CloudWatch Logs), rule pattern match chính xác detail.eventName: "ConsoleLogin", detail.userIdentity.type: "Root", detail.responseElements.ConsoleLogin: "Success". Latency thấp, serverless.

📋 Phân tích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn (giữ nguyên văn bản gốc tiếng Anh), với lý do đúng/sai dựa trên tính khả thi, near-real time và best practices AWS 2026:

  • Use AWS Trusted Advisor and its security evaluations for the root account. Configure an Amazon EventBridge event rule that is invoked by the Trusted Advisor API. Configure the rule to target an Amazon Simple Notification Service (Amazon SNS) topic. Subscribe any required endpoints to the SNS topic so that these endpoints can receive notification.
    ❌ SAI: Trusted Advisor chỉ kiểm tra check định kỳ (hàng giờ/ngày) về security root (như thiếu MFA), không monitor real-time login events. Không có API real-time cho ConsoleLogin; EventBridge không hỗ trợ trigger từ Trusted Advisor cho login. Không near-real time.
    📘 Nguồn: Trusted Advisor Docs - Không có login monitoring.

  • Use AWS IAM Access Analyzer. Create an Amazon Cloud Watch Logs metric filter to evaluate log entries from Access Analyzer that detect a successful root account login. Create an Amazon CloudWatch alarm that monitors whether a root login has occurred. Configure the CloudWatch alarm to notify an Amazon Simple Notification Service (Amazon SNS) topic when the alarm enters the ALARM state. Subscribe any required endpoints to this SNS topic so that these endpoints can receive notification.
    ❌ SAI: IAM Access Analyzer phân tích policy permissions và external access (S3 buckets, IAM roles), không ghi log login events như ConsoleLogin. Không có CloudWatch Logs từ Access Analyzer cho root login; metric filter sẽ không match được.
    📘 Nguồn: IAM Access Analyzer Docs - Chỉ focus policy findings, không login.

  • Configure AWS CloudTrail to send its logs to Amazon CloudWatch Logs. Configure a metric filter on the CloudWatch Logs log group used by CloudTrail to evaluate log entries for successful root account logins. Create an Amazon CloudWatch alarm that monitors whether a root login has occurred. Configure the CloudWatch alarm to notify an Amazon Simple Notification Service (Amazon SNS) topic when the alarm enters the ALARM state. Subscribe any required endpoints to this SNS topic so that these endpoints can receive notification.
    ✅ ĐÚNG: Hoàn hảo cho near-real time. CloudTrail stream logs → CloudWatch Logs → metric filter pattern "ConsoleLogin" "Success" Root → alarm → SNS. Đã enable CloudTrail (chỉ cần thêm CloudWatch Logs integration). Best practice AWS.
    📘 Nguồn: CloudTrail + CloudWatch Integration.

  • Configure AWS CloudTrail to send log notifications to an Amazon Simple Notification Service (Amazon SNS) topic. Create an AWS Lambda function that parses the CloudTrail notification for root login activity and notifies a separate SNS topic that contains the endpoints that should receive notification. Subscribe the Lambda function to the SNS topic that is receiving log notifications from CloudTrail.
    ❌ SAI: CloudTrail không gửi "log notifications" trực tiếp đến SNS cho từng event; chỉ gửi SNS notification khi new log file delivered to S3 (batch, không real-time, delay 5-15 phút). Lambda parse file S3 phức tạp, không near-real time cho single login.
    📘 Nguồn: CloudTrail SNS Notifications - Chỉ cho delivery, không event-level.

  • Configure an Amazon EventBridge event rule that runs when Amazon CloudWatch API calls are recorded for a successful root login. Configure the rule to target an Amazon Simple Notification Service (Amazon SNS) topic. Subscribe any required endpoints to the SNS topic so that these endpoints can receive notification.
    ✅ ĐÚNG: EventBridge rule match CloudTrail events (ConsoleLogin success root) near-real time (event source cloudtrail.amazonaws.com). Mặc dù đề cập "CloudWatch API calls" (có thể ám chỉ CloudTrail qua CloudWatch Events cũ), nhưng pattern hỗ trợ chính xác login. Serverless, đơn giản.
    📘 Nguồn: EventBridge + CloudTrail Patterns - Ví dụ rule cho root ConsoleLogin.

🛡️ Lời khuyên DevOps Pro: Luôn test rule pattern với CloudTrail Lake (new 2024) cho query nhanh hơn. Kết hợp GuardDuty cho threat detection bổ sung!