Ngân hàng đề — AWS Certified Security Specialty

Tìm thấy 445 câu.

Câu 341
A company is using an Amazon CloudFront distribution to deliver content from two origins. One origin is a dynamic application that is hosted on Amazon EC2 instances. The other origin is an Amazon S3 bucket for static assets.

A security analysis shows that HTTPS responses from the application do not comply with a security requirement to provide an X-Frame-Options HTTP header to prevent frame-related cross-site scripting attacks. A security engineer must make the full stack compliant by adding the missing HTTP header to the responses.

Which solution will meet these requirements?
  1. A Create a Lambda@Edge function. Include code to add the X-Frame-Options header to the response. Configure the function to run in response to the CloudFront origin response event.
  2. B Create a Lambda@Edge function. Include code to add the X-Frame-Options header to the response. Configure the function to run in response to the CloudFront viewer request event.
  3. C Update the CloudFront distribution by adding X-Frame-Options to custom headers in the origin settings.
  4. D Customize the EC2 hosted application to add the X-Frame-Options header to the responses that are returned to CloudFront.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một công ty sử dụng Amazon CloudFront làm distribution để phân phối nội dung từ hai origins:

  • Origin 1: Ứng dụng dynamic chạy trên Amazon EC2 instances (nội dung động).
  • Origin 2: Amazon S3 bucket chứa static assets (tài nguyên tĩnh).

Phân tích bảo mật cho thấy HTTPS responses từ ứng dụng (EC2) thiếu header X-Frame-Options, dẫn đến không tuân thủ yêu cầu bảo mật chống frame-related cross-site scripting (XSS) attacks (tấn công XSS liên quan đến iframe/frames).

Yêu cầu: Security engineer phải thêm header này vào responses để làm full stack compliant (toàn bộ stack phân phối nội dung qua CloudFront tuân thủ). Giải pháp cần tận dụng tính năng CloudFront để xử lý tại edge, không thay đổi origin trực tiếp, đảm bảo áp dụng cho responses từ origin động (EC2) trước khi cache hoặc gửi về viewer.

Mục tiêu chính: Thêm header vào response từ origin (không phải request), xử lý ở edge locations của CloudFront để hiệu suất cao và nhất quán.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create a Lambda@Edge function. Include code to add the X-Frame-Options header to the response. Configure the function to run in response to the CloudFront origin response event.

Lý do 🛠️:

  • Lambda@Edge chạy tại edge locations của CloudFront, cho phép modify headers động mà không cần thay đổi origin.
  • Origin response event kích hoạt sau khi CloudFront nhận response từ origin (EC2) và trước khi cache/send về viewer. Đây là thời điểm lý tưởng để thêm header X-Frame-Options (ví dụ: DENY hoặc SAMEORIGIN) vào response headers, đảm bảo full stack compliant cho nội dung dynamic từ EC2.
  • Không ảnh hưởng đến S3 origin (static assets thường đã có headers cơ bản), và giải pháp scalable cho multi-origins.
  • Phù hợp best practice AWS (cập nhật 2024-2026): Lambda@Edge hỗ trợ event này đầy đủ cho header manipulation.

📋 Giải thích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá ✅ (đúng) hoặc ❌ (sai) kèm lý do bằng tiếng Việt:

  • ✅ Create a Lambda@Edge function. Include code to add the X-Frame-Options header to the response. Configure the function to run in response to the CloudFront origin response event.
    🧩 Đúng vì: Như giải thích trên, event "origin response" cho phép inspect và modify response headers từ origin trước khi propagate. Code Lambda có thể dùng response.headers['x-frame-options'] = [{value: 'DENY'}];. Áp dụng cho EC2 origin cụ thể qua CloudFront behaviors.

  • ❌ Create a Lambda@Edge function. Include code to add the X-Frame-Options header to the response. Configure the function to run in response to the CloudFront viewer request event.
    🚫 Sai vì: "Viewer request" kích hoạt trước khi request gửi đến origin, chỉ modify request (không phải response). Không thể thêm header vào response tại đây, dẫn đến không giải quyết vấn đề thiếu header từ EC2 response.

  • ❌ Update the CloudFront distribution by adding X-Frame-Options to custom headers in the origin settings.
    🚫 Sai vì: Custom headers trong origin settings chỉ forward headers từ viewer request đến origin (request phase), không thêm vào response từ origin về viewer. Không ảnh hưởng đến response headers từ EC2.

  • ❌ Customize the EC2 hosted application to add the X-Frame-Options header to the responses that are returned to CloudFront.
    🚫 Sai vì: Mặc dù khả thi, nhưng yêu cầu thay đổi code ứng dụng trên tất cả EC2 instances, không scalable (phải deploy/update thủ công), và không tận dụng CloudFront edge capabilities. Không đảm bảo "full stack compliant" qua CloudFront một cách tự động/centralized, đặc biệt với multi-origins.

📘 Tài liệu tham khảo (AWS cập nhật mới nhất 2026)

Giải pháp này tối ưu về performance (edge execution <1ms) và security! 🚀

Câu 342 Chọn nhiều đáp án
An application has been built with Amazon EC2 instances that retrieve messages from Amazon SQS. Recently, IAM changes were made and the instances can no longer retrieve messages.

What actions should be taken to troubleshoot the issue while maintaining least privilege? (Choose two.)
  1. A Configure and assign an MFA device to the role used by the instances.
  2. B Verify that the SQS resource policy does not explicitly deny access to the role used by the instances.
  3. C Verify that the access key attached to the role used by the instances is active.
  4. D Attach the AmazonSQSFullAccess managed policy to the role used by the instances.
  5. E Verify that the role attached to the instances contains policies that allow access to the queue.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi mô tả một ứng dụng sử dụng các EC2 instances để lấy (retrieve) tin nhắn từ Amazon SQS. Sau khi thay đổi IAM gần đây, các instance không còn lấy được tin nhắn nữa. Nhiệm vụ là xác định các hành động troubleshoot (khắc phục sự cố) phù hợp, đồng thời duy trì nguyên tắc least privilege (quyền hạn tối thiểu). Câu hỏi yêu cầu chọn hai hành động đúng từ các lựa chọn.

Vấn đề cốt lõi 🛠️:

  • EC2 instances thường sử dụng IAM Role (qua Instance Profile) để truy cập SQS, không dùng access keys trực tiếp.
  • Thay đổi IAM có thể ảnh hưởng đến identity-based policies (trên role) hoặc resource-based policies (trên SQS queue).
  • Troubleshoot phải an toàn, không cấp quyền thừa, tuân thủ best practices AWS (cập nhật đến 2026: IAM Access Analyzer, policy evaluation logic vẫn ưu tiên explicit deny).

✅ Đáp án đúng (Chọn TWO)

Hai hành động đúng là:

  • Verify that the SQS resource policy does not explicitly deny access to the role used by the instances.
    (Kiểm tra resource policy của SQS không explicitly deny quyền cho role của instances – đây là bước kiểm tra deny từ phía resource).
  • Verify that the role attached to the instances contains policies that allow access to the queue.
    (Kiểm tra role gắn với instances có policies cho phép truy cập queue – kiểm tra allow từ identity-based policy).

Lý do chọn 📈:

  • Đây là hai bước cơ bản và an toàn trong IAM troubleshooting (theo AWS policy evaluation: kiểm tra allow trước, deny sau). Chúng không thay đổi quyền, chỉ verify để duy trì least privilege. Phù hợp với DOP-C02 exam blueprint (Troubleshoot IAM issues).

🔍 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, với giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh dấu ✅ (đúng) hoặc ❌ (sai), kèm giải thích lý do bằng tiếng Việt.

  • Configure and assign an MFA device to the role used by the instances.
    ❌ Sai: MFA (Multi-Factor Authentication) chỉ áp dụng cho user/console access, không liên quan đến service roles trên EC2 (non-interactive). Gán MFA cho role không giải quyết vấn đề truy cập SQS và vi phạm best practices (roles không cần MFA). Không phải bước troubleshoot chuẩn.

  • Verify that the SQS resource policy does not explicitly deny access to the role used by the instances.
    ✅ Đúng: SQS hỗ trợ resource-based policies (SCP-like cho queue). Nếu policy này có explicit deny cho role ARN của EC2, sẽ block access dù identity policy allow. Bước verify này an toàn, không thay đổi quyền, và là phần của IAM debugger (AWS khuyến nghị kiểm tra Deny trước).

  • Verify that the access key attached to the role used by the instances is active.
    ❌ Sai: EC2 instances sử dụng IAM Role qua metadata service (IMDSv2 khuyến nghị từ 2023-2026), không attach access keys trực tiếp vào role. Access keys chỉ cho IAM users. Kiểm tra này vô ích và không tồn tại trong context EC2 roles.

  • Attach the AmazonSQSFullAccess managed policy to the role used by the instances.
    ❌ Sai: AmazonSQSFullAccess cấp quyền full access (bao gồm DeleteQueue, etc.), vi phạm least privilege (chỉ cần sqs:ReceiveMessage). Đây là "quick fix" không an toàn, không phải troubleshoot mà là thay đổi quyền vĩnh viễn. AWS khuyến nghị custom policies thay vì full access (IAM Best Practices 2026).

  • Verify that the role attached to the instances contains policies that allow access to the queue.
    ✅ Đúng: Role phải có identity-based policy với actions như sqs:ReceiveMessage, sqs:DeleteMessage cho ARN queue cụ thể. Thay đổi IAM có thể đã xóa/modify policy này. Verify qua IAM console/CLI (aws iam simulate-principal-policy) là bước đầu tiên và least intrusive.

📘 Tài liệu tham khảo (Cập nhật AWS 2026)

Lời khuyên thực hành 🚀: Sử dụng IAM Access Analyzer hoặc CloudTrail để audit thay đổi IAM gần đây!

Câu 343
A company has an AWS Key Management Service (AWS KMS) customer managed key with imported key material. Company policy requires all encryption keys to be rotated every year.

What should a security engineer do to meet this requirement for this customer managed key?
  1. A Enable automatic key rotation annually for the existing customer managed key.
  2. B Use the AWS CLI to create an AWS Lambda function to rotate the existing customer managed key annually.
  3. C Import new key material to the existing customer managed key. Manually rotate the key.
  4. D Create a new customer managed key. Import new key material to the new key. Point the key alias to the new key.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào AWS Key Management Service (AWS KMS), cụ thể là xử lý customer managed key (CMK) với imported key material (khóa vật liệu được import từ bên ngoài). Công ty có chính sách bắt buộc rotate (xoay vòng) tất cả encryption keys mỗi năm để đảm bảo an ninh.

🔍 Tình huống chính:

  • Key hiện tại là CMK do khách hàng quản lý, sử dụng key material được import thủ công (không phải do AWS tạo).
  • Yêu cầu: Security engineer phải thực hiện rotate key theo đúng chính sách, đảm bảo key material mới và an toàn.
  • Thách thức: Với imported key material, AWS KMS không hỗ trợ automatic rotation (tính năng chỉ áp dụng cho CMK do AWS tạo hoặc AWS managed keys). Phải xử lý thủ công nhưng hiệu quả, sử dụng alias để tránh downtime.

📘 Kiến thức nền tảng (cập nhật đến 2026): Theo tài liệu AWS KMS mới nhất (AWS Well-Architected Framework và KMS Developer Guide 2024-2026), imported keys yêu cầu tạo key mới để rotate, vì không thể thay thế key material trực tiếp trên key cũ. Alias giúp chuyển hướng seamless mà không cần thay đổi code ứng dụng.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create a new customer managed key. Import new key material to the new key. Point the key alias to the new key.

Lý do 🛠️:

  • Đây là cách chuẩn AWS khuyến nghị cho CMK với imported material. Tạo key mới, import key material mới (từ HSM hoặc nguồn ngoài), rồi cập nhật key alias trỏ đến key mới.
  • Ưu điểm: Không gián đoạn dịch vụ (ứng dụng dùng alias vẫn hoạt động), tuân thủ chính sách rotate hàng năm, và hỗ trợ lịch sử key cũ cho decryption dữ liệu cũ.
  • Hiệu quả cao, zero-downtime, phù hợp DevOps best practices.

📋 Giải thích tất cả các phương án (đúng/sai)

  • ❌ [SAI] Enable automatic key rotation annually for the existing customer managed key.
    Phương án này sai vì imported key material không hỗ trợ automatic rotation. Tính năng auto-rotate chỉ áp dụng cho CMK do AWS tạo key material (rotate mỗi năm tự động). Với imported keys, AWS không cho phép enable rotation để bảo vệ tính toàn vẹn của key material từ khách hàng.

  • ❌ [SAI] Use the AWS CLI to create an AWS Lambda function to rotate the existing customer managed key annually.
    Sai hoàn toàn vì không tồn tại API hoặc CLI command để rotate key material trên existing imported CMK. Lambda không thể thay thế key material trực tiếp (vi phạm thiết kế KMS). Cách này phức tạp, không an toàn và không được AWS hỗ trợ.

  • ❌ [SAI] Import new key material to the existing customer managed key. Manually rotate the key.
    Sai vì AWS KMS cấm import new key material vào existing CMK sau khi đã import lần đầu. Key material là immutable (không thay đổi được). Manual rotate trên key cũ sẽ thất bại, dẫn đến lỗi và không tuân thủ chính sách.

  • ✅ [ĐÚNG] Create a new customer managed key. Import new key material to the new key. Point the key alias to the new key.
    Đúng như giải thích ở trên: Tạo key mới (ScheduleKey hoặc Symmetric), import material mới, cập nhật alias (e.g., aws kms update-alias --alias-name alias/mykey --target-key-id new-key-arn). Đảm bảo rotate hàng năm dễ dàng qua automation (CloudFormation/EventBridge).

📘 Tài liệu tham khảo (AWS chính thức, cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần ví dụ code CloudFormation, hãy hỏi thêm.

Câu 344
A healthcare company has multiple AWS accounts in an organization in AWS Organizations. The company uses Amazon S3 buckets to store sensitive information of patients. The company needs to restrict users from deleting any S3 bucket across the organization.

What is the MOST scalable solution that meets these requirements?
  1. A Permissions boundaries in AWS Identity and Access Management (IAM)
  2. B S3 bucket policies
  3. C Tag policies
  4. D SCPs
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào một công ty y tế sử dụng AWS Organizations để quản lý nhiều AWS accounts (tài khoản AWS). Họ lưu trữ thông tin nhạy cảm của bệnh nhân trong Amazon S3 buckets. Yêu cầu chính là ngăn chặn users (người dùng) xóa bất kỳ S3 bucket nào trên toàn tổ chức (across the organization). Chúng ta cần tìm giải pháp scalable nhất (mở rộng tốt nhất), nghĩa là giải pháp phải áp dụng dễ dàng cho tất cả accounts mà không cần cấu hình thủ công từng cái một. Đây là tình huống thực tế trong DevOps, nhấn mạnh vào governance và security ở cấp tổ chức, đặc biệt với dữ liệu nhạy cảm như HIPAA-compliant storage trong S3. ✅ Mục tiêu cốt lõi: Deny action s3:DeleteBucket ở mức organization-wide.

✅ Đáp án đúng: SCPs

SCPs (Service Control Policies) là lựa chọn đúng và scalable nhất vì:

  • SCPs được áp dụng trực tiếp lên AWS Organizations (root OU hoặc account cụ thể), tự động kế thừa xuống tất cả child accounts mà không cần deploy IAM policy riêng lẻ.
  • Chúng deny các action cụ thể như s3:DeleteBucket cho mọi principal (IAM users/roles) trong organization.
  • Scalable cao: Với hàng trăm accounts, SCPs chỉ cần attach một lần tại root, không duplicate config. Hỗ trợ điều kiện phức tạp (conditions) như resource tags hoặc account ID.
  • Ví dụ SCP policy đơn giản:
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Deny",
          "Action": "s3:DeleteBucket",
          "Resource": "*"
        }
      ]
    }
    
  • Theo docs AWS 2024-2026, SCPs vẫn là best practice cho org-wide restrictions, đặc biệt với data sovereignty và compliance (như healthcare).

🔍 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, với lý do đúng/sai dựa trên tính năng AWS mới nhất:

  • ❌ Permissions boundaries in AWS Identity and Access Management (IAM):
    Sai vì permissions boundaries chỉ giới hạn quyền tối đa của IAM users/roles trong một account duy nhất, không áp dụng cross-account hay organization-wide. Phải set thủ công cho từng IAM entity → không scalable với multiple accounts. Không deny được action ở cấp bucket/resource trực tiếp mà chỉ là boundary cho policy attachment.

  • ❌ S3 bucket policies:
    Sai vì bucket policies chỉ attach trên từng S3 bucket cụ thể, phải config riêng cho mỗi bucket trong từng account → không scalable cho "any S3 bucket across the organization". Chúng là resource-based policies, không kế thừa tự động qua Organizations, và users với admin quyền vẫn có thể xóa bucket trước khi attach policy.

  • ❌ Tag policies:
    Sai vì tag policies chỉ enforce tagging rules (như required tags) trên resources, không deny actions như delete bucket. Chúng không kiểm soát permissions trực tiếp mà chỉ validate tags → không phù hợp để restrict delete action. Scalable ở org-level nhưng không giải quyết yêu cầu cốt lõi.

  • ✅ SCPs:
    Đúng (như đã giải thích ở trên). SCPs là blacklist policies ở mức organization, override tất cả IAM permissions, đảm bảo deny s3:DeleteBucket everywhere. Hoàn hảo cho compliance healthcare.

📘 Tài liệu tham khảo

Giải pháp này đảm bảo zero-trust cho sensitive data! 🚀

Câu 345
A company needs to detect unauthenticated access to its Amazon Elastic Kubernetes Service (Amazon EKS) clusters. The company needs a solution that requires no additional configuration of the existing EKS deployment.

Which solution will meet these requirements with the LEAST operational effort?
  1. A Install an Amazon EKS add-on from a security vendor.
  2. B Enable AWS Security Hub. Monitor the Kubernetes findings.
  3. C Monitor Amazon CloudWatch Container Insights metrics for Amazon EKS.
  4. D Enable Amazon GuardDuty. Use EKS Audit Log Monitoring.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc phát hiện truy cập không xác thực (unauthenticated access) vào các cụm Amazon Elastic Kubernetes Service (Amazon EKS). Công ty yêu cầu một giải pháp không cần cấu hình thêm cho deployment EKS hiện tại và phải có nỗ lực vận hành thấp nhất (LEAST operational effort).

📘 Bối cảnh chính:

  • Unauthenticated access là các truy cập ẩn danh hoặc không có token xác thực hợp lệ vào EKS cluster, có thể dẫn đến rủi ro bảo mật như khai thác lỗ hổng.
  • Giải pháp phải tự động, không yêu cầu thay đổi IAM roles, add-ons, hoặc chỉnh sửa cluster config (như enabling audit logs thủ công).
  • Theo tài liệu AWS mới nhất (2024-2026), GuardDuty EKS Protection là tính năng native hỗ trợ detect các threat như anonymous access mà không cần config EKS thêm, chỉ cần enable GuardDuty.

Nguồn tham khảo:

✅ Đáp án đúng: Enable Amazon GuardDuty. Use EKS Audit Log Monitoring

Lý do lựa chọn:

  • 🛡️ GuardDuty EKS Audit Log Monitoring là tính năng tự động của Amazon GuardDuty (từ 2022, cập nhật liên tục đến 2026), enable chỉ một lần ở tài khoản AWS mà không cần cấu hình EKS cluster thêm. Nó tự động thu thập và phân tích EKS control plane audit logs để detect unauthenticated access (như API calls ẩn danh).
  • Least operational effort: Không install add-on, không chỉnh kubeconfig, không setup CloudWatch logs thủ công. GuardDuty xử lý toàn bộ ingestion, analysis và alerting qua findings.
  • Phát hiện cụ thể: GuardDuty gen findings như Eks.UnauthAccess cho anonymous requests đến API server.
  • Hoàn hảo match yêu cầu: Zero config cho EKS deployment hiện tại.

🔍 Phân tích tất cả các phương án (đúng/sai)

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá dựa trên operational effort và khả năng detect unauthenticated access mà không config EKS thêm.

  • Install an Amazon EKS add-on from a security vendor.
    ❌ Sai: Yêu cầu install add-on vào EKS cluster (qua Helm hoặc kubectl), dẫn đến config thêm như IAM permissions, namespaces. Đây là operational effort cao, không "no additional configuration". Không phải giải pháp native AWS thuần.

  • Enable AWS Security Hub. Monitor the Kubernetes findings.
    ❌ Sai: Security Hub tổng hợp findings từ GuardDuty/others, nhưng không tự detect EKS unauthenticated access mà không enable GuardDuty trước. Cần config integrations (như enable CIS benchmarks), và monitor thủ công findings – effort cao hơn GuardDuty trực tiếp. Không zero-config cho EKS.

  • Monitor Amazon CloudWatch Container Insights metrics for Amazon EKS.
    ❌ Sai: Container Insights chỉ cung cấp metrics/performance (CPU, memory, pod metrics), không detect security events như unauthenticated access (không parse audit logs). Cần enable Insights trước (config EKS add-on), và vẫn phải build custom alarms – effort lớn, không phù hợp.

  • Enable Amazon GuardDuty. Use EKS Audit Log Monitoring.
    ✅ Đúng: Như giải thích trên, tự động 100%, detect chính xác unauthenticated access qua audit logs mà không động chạm EKS cluster. Least effort: Enable GuardDuty → Done! Alerting qua Console/CloudWatch/EventBridge.

🏆 Kết luận & Lời khuyên DevOps

Giải pháp này phù hợp best practice AWS Well-Architected Framework (Security Pillar, 2025 update). Để implement: Console > GuardDuty > Enable EKS Protection. Test bằng simulate anonymous kubectl get nodes. Nếu scale, integrate với Lambda auto-remediation! 🚀

Câu 346
A security engineer is investigating a malware infection that has spread across a set of Amazon EC2 instances. A key indicator of the compromise is outbound traffic on TCP port 2905 to a set of command and control hosts on the internet.

The security engineer creates a network ACL rule that denies the identified outbound traffic. The security engineer applies the network ACL rule to the subnet of the EC2 instances. The security engineer must identify any EC2 instances that are trying to communicate on TCP port 2905.

Which solution will identify the affected EC2 instances with the LEAST operational effort?
  1. A Create a Network Access Scope in Amazon VPC Network Access Analyzer. Use the Network Access Scope to identify EC2 instances that try to send traffic to TCP port 2905.
  2. B Enable VPC flow logs for the VPC where the affected EC2 instances are located. Configure the flow logs to capture rejected traffic. In the flow logs, search for REJECT records that have a destination TCP port of 2905.
  3. C Enable Amazon GuardDuty. Create a custom GuardDuty IP list to create a finding when an EC2 instance tries to communicate with one of the command and control hosts. Use Amazon Detective to identify the EC2 instances that initiate the communication.
  4. D Create a firewall in AWS Network Firewall. Attach the firewall to the subnet of the EC2 instances. Create a custom rule to identify and log traffic from the firewall on TCP port 2905. Create an Amazon CloudWatch Logs metric filter to identify firewall logs that reference traffic on TCP port 2905.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả tình huống một kỹ sư bảo mật đang điều tra nhiễm malware lan rộng trên các instance Amazon EC2. Dấu hiệu chính là outbound traffic trên TCP port 2905 đến các máy chủ command and control (C2) trên internet. 🛡️ Kỹ sư đã tạo rule Network ACL (NACL) để deny traffic outbound này và áp dụng vào subnet chứa các EC2 instances bị ảnh hưởng.

Mục tiêu: Xác định các EC2 instances đang cố gắng giao tiếp trên TCP port 2905 với ít nỗ lực vận hành nhất (LEAST operational effort). 📊

Tình huống nhấn mạnh nhu cầu phát hiện nhanh chóng các instance vẫn cố gửi traffic (dù bị block bởi NACL), dựa trên log rejected traffic mà không cần cấu hình phức tạp thêm.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Enable VPC flow logs for the VPC where the affected EC2 instances are located. Configure the flow logs to capture rejected traffic. In the flow logs, search for REJECT records that have a destination TCP port of 2905.

Lý do:

  • VPC Flow Logs là giải pháp tối ưu nhất để capture traffic bị reject bởi NACL ngay lập tức, với ít nỗ lực nhất. 🔍 Chỉ cần enable Flow Logs cho VPC/subnet, filter REJECT records với destination port 2905, và search log để thấy chính xác source IP (ENI của EC2) đang cố gửi traffic.
  • Không cần thay đổi architecture, chỉ publish log đến CloudWatch Logs/S3, query bằng CloudWatch Logs Insights hoặc Athena. Hoạt động real-time sau vài phút, phù hợp detect malware nhanh.
  • Theo AWS best practices (cập nhật 2024-2026), Flow Logs hỗ trợ REJECT/ACCEPT actions từ NACL/Security Groups. Least effort vì không cần custom rules hay services mới.

Tài liệu tham khảo:

📋 Giải thích chi tiết tất cả các phương án

  • ✅ Phương án đúng (như trên):
    Enable VPC flow logs for the VPC where the affected EC2 instances are located. Configure the flow logs to capture rejected traffic. In the flow logs, search for REJECT records that have a destination TCP port of 2905.
    Giải thích: Giải pháp đơn giản, nhanh chóng, chi phí thấp. Flow Logs tự động log ENI-level traffic bị NACL reject, dễ query port 2905 để map về EC2 instances. Không cần config thêm firewall hay detector phức tạp. 🚀

  • ❌ Phương án SAI:
    Create a Network Access Scope in Amazon VPC Network Access Analyzer. Use the Network Access Scope to identify EC2 instances that try to send traffic to TCP port 2905.
    Giải thích: Network Access Analyzer (nay là VPC Reachability Analyzer) dùng để analyze potential reachability giữa resources (asynchronous analysis), KHÔNG phải real-time monitoring traffic. Không capture actual attempted traffic hay rejected logs, chỉ check policy violations tĩnh. Không phù hợp detect attempts động từ malware, effort cao hơn vì cần define scopes thủ công. 📉

  • ❌ Phương án SAI:
    Enable Amazon GuardDuty. Create a custom GuardDuty IP list to create a finding when an EC2 instance tries to communicate with one of the command and control hosts. Use Amazon Detective to identify the EC2 instances that initiate the communication.
    Giải thích: GuardDuty giỏi detect threats qua threat intel, nhưng cần custom IP list cho C2 hosts và chờ findings (có thể delay). Amazon Detective chỉ graph analysis sau findings, KHÔNG least effort vì phải enable GuardDuty toàn VPC, config threat lists, và integrate Detective – phức tạp hơn Flow Logs đơn giản. Thời gian setup ~giờ, không instant như logs. ⏳

  • ❌ Phương án SAI:
    Create a firewall in AWS Network Firewall. Attach the firewall to the subnet of the EC2 instances. Create a custom rule to identify and log traffic from the firewall on TCP port 2905. Create an Amazon CloudWatch Logs metric filter to identify firewall logs that reference traffic on TCP port 2905.
    Giải thích: AWS Network Firewall là stateful firewall managed, mạnh nhưng overkill cho task này: Phải deploy firewall mới vào subnet (thay thế/overlay NACL), viết custom rules, log đến CloudWatch, rồi metric filter – effort cao, chi phí đắt (~$0.395/giờ/firewall). NACL đã block rồi, không cần firewall thứ 2. Không least effort. 💸

🛠️ Khuyến nghị bổ sung

  • Sau khi identify bằng Flow Logs, dùng EC2 Instance Connect hoặc SSM để remediate (quarantine/kill process). Kết hợp AWS Systems Manager Automation tự động.
  • Best practice: Enable Flow Logs proactive cho tất cả VPC critical. Theo AWS 2026 updates, Flow Logs hỗ trợ enhanced logging với ML insights qua CloudWatch. 🔄
Câu 347
A security engineer uses Amazon Macie to scan a company’s Amazon S3 buckets for sensitive data. The company has many S3 buckets and many objects stored in the S3 buckets. The security engineer must identify S3 buckets that contain sensitive data and must perform additional scanning on those S3 buckets.

Which solution will meet these requirements with the LEAST administrative overhead?
  1. A Configure S3 Cross-Region Replication (CRR) on the S3 buckets to replicate the objects to a second AWS Region. Configure Macie in the second Region to scan the replicated objects daily.
  2. B Create an AWS Lambda function as an S3 event destination for the S3 buckets. Configure the Lambda function to start a Macie scan of an object when the object is uploaded to an S3 bucket.
  3. C Configure Macie automated discovery to continuously sample data from the S3 buckets. Perform full scans of the S3 buckets where Macie discovers sensitive data.
  4. D Configure Macie scans to run on the S3 buckets. Aggregate the results of the scans in an Amazon DynamoDB table. Use the DynamoDB table for queries.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh việc một kỹ sư bảo mật sử dụng Amazon Macie để quét các Amazon S3 buckets nhằm phát hiện dữ liệu nhạy cảm (sensitive data) trong môi trường AWS của công ty. Công ty có nhiều S3 buckets và rất nhiều objects lưu trữ bên trong. Yêu cầu chính là:

  • Xác định (identify) các S3 buckets chứa dữ liệu nhạy cảm.
  • Thực hiện quét bổ sung (additional scanning) trên chính những buckets đó.
  • Giải pháp phải có ít overhead quản trị nhất (LEAST administrative overhead), nghĩa là tự động hóa cao, không cần can thiệp thủ công thường xuyên, tiết kiệm chi phí và công sức vận hành.

📘 Bối cảnh AWS mới nhất (cập nhật đến 2026): Amazon Macie là dịch vụ bảo mật sử dụng machine learning để tự động phát hiện, phân loại và bảo vệ dữ liệu nhạy cảm trong S3. Tính năng Automated Discovery (tự động khám phá) được nâng cấp mạnh mẽ từ năm 2023-2025, cho phép sampling liên tục dữ liệu từ toàn bộ S3 buckets, sau đó tự động kích hoạt full scans trên các buckets có phát hiện rủi ro, giảm thiểu overhead hoàn toàn.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Configure Macie automated discovery to continuously sample data from the S3 buckets. Perform full scans of the S3 buckets where Macie discovers sensitive data.

Lý do:

  • 🛠️ Giải pháp này tận dụng Macie Automated Discovery – một tính năng tự động hóa native của Macie (không cần code thêm), liên tục sampling (lấy mẫu) dữ liệu từ tất cả S3 buckets một cách ngẫu nhiên và hiệu quả.
  • Khi phát hiện sensitive data, Macie tự động trigger full scans chỉ trên những buckets cần thiết, tránh quét toàn bộ dữ liệu (giảm chi phí và overhead).
  • Least administrative overhead: Không cần thiết lập replication, Lambda, hay database thủ công. Chỉ cần enable Automated Discovery một lần trong Macie console hoặc qua API/CloudFormation, Macie sẽ xử lý continuous monitoring và alerting qua EventBridge/Security Hub.
  • Phù hợp với best practice AWS cho large-scale S3 environments (hàng triệu objects).

❌ Phân tích tất cả các phương án

  • Configure S3 Cross-Region Replication (CRR) on the S3 buckets to replicate the objects to a second AWS Region. Configure Macie in the second Region to scan the replicated objects daily.
    ❌ Sai vì: Giải pháp này tạo overhead cao do phải thiết lập CRR thủ công trên mọi bucket (tốn chi phí replication data transfer và storage gấp đôi). Macie ở region thứ hai quét daily replicated objects vẫn phải quản lý lịch scan thủ công, không tự động identify buckets cụ thể. Không hiệu quả cho many buckets/objects, vi phạm "least overhead". (CRR dùng cho DR/backup, không phải security scanning).

  • Create an AWS Lambda function as an S3 event destination for the S3 buckets. Configure the Lambda function to start a Macie scan of an object when the object is uploaded to an S3 bucket.
    ❌ Sai vì: Phải code và deploy Lambda custom làm S3 event trigger, kích hoạt Macie scan mỗi object upload – dẫn đến overhead khổng lồ (chi phí Lambda invocations cao với millions objects, throttling issues). Không identify buckets chứa existing data (chỉ new uploads), và không xử lý "additional scanning" trên toàn bucket. Quản trị phức tạp: maintain code, permissions, error handling.

  • Configure Macie automated discovery to continuously sample data from the S3 buckets. Perform full scans of the S3 buckets where Macie discovers sensitive data.
    ✅ Đúng như đã giải thích ở trên: Tự động, native, least overhead. Macie handling toàn bộ quy trình sampling → discovery → full scan prioritization.

  • Configure Macie scans to run on the S3 buckets. Aggregate the results of the scans in an Amazon DynamoDB table. Use the DynamoDB table for queries.
    ❌ Sai vì: Yêu cầu configure manual Macie jobs trên từng bucket (overhead lớn cho many buckets), rồi build pipeline aggregate results vào DynamoDB (provision tables, Lambda/Step Functions để ETL, queries). Không tự động identify và prioritize additional scans. Tốn công quản lý infra và data pipeline liên tục.

📘 Tài liệu tham khảo (AWS Docs cập nhật 2026)

Giải pháp này đảm bảo tuân thủ AWS best practices, tối ưu chi phí và bảo mật! 🚀

Câu 348
A security engineer for a large company is managing a data processing application used by 1,500 subsidiary companies. The parent and subsidiary companies all use AWS. The application uses TCP port 443 and runs on Amazon C2 behind a Network Load Balancer (NLB). For compliance reasons, the application should only be accessible to the subsidiaries and should not be available on the public internet. To meet the compliance requirements for restricted access, the engineer has received the public and private CIDR block ranges for each subsidiary.

What solution should the engineer use to implement the appropriate access restrictions for the application?
  1. A Create a NACL to allow access on TCP port 443 from the 1,500 subsidiary CIDR block ranges. Associate the NACL to both the NLB and EC2 instances.
  2. B Create an AWS security group to allow access on TCP port 443 from the 1,500 subsidiary CIDR block ranges. Associate the security group to the NLCreate a second security group for EC2 instances with access on TCP port 443 from the NLB security group.
  3. C Create an AWS PrivateLink endpoint service in the parent company account attached to the NLB. Create an AWS security group for the instances to allow access on TCP port 443 from the AWS PrivateLink endpoint. Use AWS PrivateLink interface endpoints in the 1,500 subsidiary AWS accounts to connect to the data processing application.
  4. D Create an AWS security group to allow access on TCP port 443 from the 1,500 subsidiary CIDR block ranges. Associate the security group with EC2 instances.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi mô tả một kỹ sư bảo mật quản lý ứng dụng xử lý dữ liệu cho 1.500 công ty con, tất cả đều sử dụng AWS (công ty mẹ và con). Ứng dụng chạy trên Amazon EC2 (có lẽ là lỗi đánh máy "C2" thay vì "EC2") đằng sau Network Load Balancer (NLB) sử dụng TCP port 443. Yêu cầu tuân thủ: ứng dụng chỉ accessible bởi các công ty con, không available trên public internet. Kỹ sư có CIDR public và private của từng công ty con để hạn chế truy cập.

🔍 Thách thức chính:

  • NLB thường dùng cho high-performance TCP traffic, có thể internet-facing hoặc internal.
  • Với 1.500 CIDR blocks (public/private), việc quản lý rule thủ công trên firewall sẽ phức tạp, dễ lỗi, và không scale tốt.
  • Cần giải pháp private, cross-account, không expose ra internet, tận dụng AWS native để đảm bảo compliance (ví dụ: HIPAA, PCI DSS yêu cầu private access).
  • Giải pháp phải hỗ trợ AWS multi-account (parent + subsidiaries).

🛠️ Mục tiêu: Implement access restrictions an toàn, scalable cho 1.500 entities mà không public-facing.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Create an AWS PrivateLink endpoint service in the parent company account attached to the NLB. Create an AWS security group for the instances to allow access on TCP port 443 from the AWS PrivateLink endpoint. Use AWS PrivateLink interface endpoints in the 1,500 subsidiary AWS accounts to connect to the data processing application.

Lý do chọn (theo AWS best practices 2026):
✅ AWS PrivateLink là giải pháp lý tưởng cho private connectivity cross-account/VPC mà không qua internet hay VPN.

  • Endpoint Service (trước là VPC Endpoint Service) attach trực tiếp vào NLB (hỗ trợ từ AWS 2018, cập nhật 2024 với Zone-specific endpoints cho resilience).
  • Các account con tạo Interface VPC Endpoints kết nối private tới service qua AWS backbone network.
  • Security Group (SG) trên EC2 chỉ allow từ PrivateLink endpoint (CIDR 192.0.2.0/30 hoặc prefix list), tránh expose CIDR public.
  • Scalable: Không cần quản lý 1.500 CIDR rules; mỗi subsidiary tự tạo endpoint. Hỗ trợ Resource Access Manager (RAM) để share service nếu cần.
  • Compliance: Traffic private, encrypted (TLS via port 443), audit qua VPC Flow Logs/CloudTrail. Không public DNS/IP.
    🛡️ Ưu điểm so với alternatives: Zero-trust model, no NAT/VPN overhead, tích hợp IAM policies cho fine-grained access.

📋 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá ✅ (đúng) hoặc ❌ (sai), kèm giải thích bằng tiếng Việt.

  • Create a NACL to allow access on TCP port 443 from the 1,500 subsidiary CIDR block ranges. Associate the NACL to both the NLB and EC2 instances.
    ❌ Sai.
    🛑 NACL (Network ACL) chỉ associate với subnet, không trực tiếp với NLB hay EC2 instances. NLB targets (EC2) chịu NACL của subnet, nhưng NLB node không có NACL riêng. Với 1.500 CIDR, rule limit (20 inbound/outbound mặc định, max 40) sẽ exceed → không scalable. Không giải quyết public exposure của NLB nếu internet-facing. NACL stateless, phức tạp quản lý so với stateful SG.

  • Create an AWS security group to allow access on TCP port 443 from the 1,500 subsidiary CIDR block ranges. Associate the security group to the NLCreate a second security group for EC2 instances with access on TCP port 443 from the NLB security group.
    ❌ Sai (lưu ý: văn bản có lỗi đánh máy "NLCreate", nhưng ý là SG cho NLB + EC2).
    🛑 NLB không hỗ trợ Security Groups trên listeners như ALB/ALB (từ AWS 2024, NLB chỉ hỗ trợ SG cho targets, không inbound rules cho load balancer nodes). Không thể attach SG để restrict source CIDR vào NLB. Với 1.500 CIDR, vượt SG rule limit (60 rules/group, max 5 groups/interface). Nếu NLB internal, vẫn cần private subnets, nhưng không cross-account native. Expose nếu NLB internet-facing.

  • Create an AWS PrivateLink endpoint service in the parent company account attached to the NLB. Create an AWS security group for the instances to allow access on TCP port 443 from the AWS PrivateLink endpoint. Use AWS PrivateLink interface endpoints in the 1,500 subsidiary AWS accounts to connect to the data processing application.
    ✅ Đúng.
    🟢 Như giải thích trên: PrivateLink + NLB là AWS-recommended architecture cho private SaaS-like services cross-account. Traffic stays in AWS network, no public IP/DNS. SG trên EC2 dùng endpoint ID hoặc prefix list (pl-xxx) để allow, tự động scale. Hỗ trợ TLS enforcement và VPC Endpoint Policies cho RBAC.

  • Create an AWS security group to allow access on TCP port 443 from the 1,500 subsidiary CIDR block ranges. Associate the security group with EC2 instances.
    ❌ Sai.
    🛑 Chỉ SG trên EC2 không protect NLB layer. Nếu NLB internet-facing (public subnets), traffic từ bất kỳ đâu có thể hit NLB trước khi đến EC2 → bypass restriction. Với 1.500 CIDR (public/private mix), vượt SG limits (60 rules), khó maintain. Không đảm bảo private access cross-account; subsidiaries ngoài VPC parent cần VPN/Direct Connect phức tạp.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

  • 🛤️ AWS PrivateLink Documentation: PrivateLink for NLB & Endpoint Services.
  • 🔒 Security Best Practices: AWS Well-Architected Framework - Security Pillar (2024 update): PrivateLink cho cross-account services.
  • 📊 NLB Limits: Elastic Load Balancing Quotas (SG/NACL rules).
  • 🎓 Exam Prep: AWS Certified DevOps Engineer - Professional (DOP-C02) Sample Questions & AWS re:Post threads về PrivateLink vs CIDR rules.

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ architecture, hãy hỏi nhé.

Câu 349
A company runs workloads on Amazon EC2 instances. The company needs to continually scan the EC2 instances for software vulnerabilities and unintended network exposure.

Which solution will meet these requirements?
  1. A Use Amazon Inspector. Set the scan mode to hybrid scanning.
  2. B Use Amazon GuardDuty. Enable the Malware Protection feature.
  3. C Use Amazon Inspector. Enable the Malware Protection feature.
  4. D Use Amazon GuardDuty. Enable the Runtime Monitoring feature.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào một công ty đang chạy workloads trên Amazon EC2 instances, và họ cần liên tục scan (continually scan) các instance này để phát hiện software vulnerabilities (lỗ hổng phần mềm, như CVE) và unintended network exposure (tiếp xúc mạng không mong muốn, ví dụ: port mở công khai hoặc cấu hình bảo mật sai).
✅ Yêu cầu chính: Giải pháp phải hỗ trợ scan liên tục, bao quát cả hai khía cạnh (lỗ hổng phần mềm + rủi ro mạng), phù hợp với EC2. Đây là chủ đề AWS Security scanning trong chứng chỉ DevOps Engineer Professional (DOP-C02), nhấn mạnh vào các dịch vụ tự động hóa bảo mật như Inspector và GuardDuty.
🛠️ Bối cảnh cập nhật 2026: Theo AWS re:Invent 2024 và docs mới nhất, Amazon Inspector đã nâng cấp với continuous scanning mặc định, hỗ trợ hybrid mode cho môi trường lai (cloud + on-prem), tích hợp Agentless Assessment cho network reachability.

✅ Đáp án đúng

Use Amazon Inspector. Set the scan mode to hybrid scanning.
Lý do lựa chọn: Amazon Inspector là dịch vụ chuyên scan software vulnerabilities (qua CVE database) và unintended network exposure (qua Network Reachability rules, kiểm tra CIS benchmarks). Chế độ hybrid scanning cho phép kết hợp agent-based (sâu cho vulns) và agentless (nhanh cho network), hỗ trợ continuous scanning tự động định kỳ (mỗi giờ/giờ). Điều này khớp hoàn hảo yêu cầu "continually scan" trên EC2. Không dịch vụ nào khác làm cả hai cùng lúc hiệu quả như vậy.
📘 Nguồn tham khảo: AWS Inspector User Guide (cập nhật 2025: Hybrid scanning cho EC2 hybrid workloads); Inspector Features.

❌ Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá dựa trên chức năng thực tế (không khớp yêu cầu = sai).

  • Use Amazon Inspector. Set the scan mode to hybrid scanning.
    ✅ Đúng: Như giải thích trên, Inspector xử lý chính xác software vulnerabilities + network exposure với hybrid mode (agentless + agent-based), continuous scanning tự động. Hoàn hảo cho EC2.

  • Use Amazon GuardDuty. Enable the Malware Protection feature.
    ❌ Sai: GuardDuty Malware Protection chỉ scan malware (tệp độc hại) trên EC2 và S3 qua EKS/EC2 Runtime, không scan software vulnerabilities (CVE) hay network exposure. Nó là threat detection thụ động, không continuous vulnerability scan. Không đáp ứng cả hai yêu cầu.

  • Use Amazon Inspector. Enable the Malware Protection feature.
    ❌ Sai: Inspector không có tính năng Malware Protection (đó là của GuardDuty từ 2022). Inspector tập trung vulnerability + network reachability, không scan malware. Kích hoạt sai feature này sẽ không hoạt động, dẫn đến không scan đúng.

  • Use Amazon GuardDuty. Enable the Runtime Monitoring feature.
    ❌ Sai: GuardDuty Runtime Monitoring phát hiện runtime behaviors đáng ngờ (shell commands, crypto mining) trên EC2 qua agentless, nhưng không scan software vulnerabilities hay network exposure. Nó chỉ monitor threats thời gian thực, không thay thế vulnerability scanner.

🛠️ Lời khuyên DevOps: Để implement, enable Inspector qua Console/CLI, tag EC2 instances, và set hybrid mode cho coverage tối ưu. Kết hợp với AWS Security Hub cho dashboard tổng hợp. Nếu hybrid cloud, tích hợp Outposts.
📘 Tài liệu bổ sung: GuardDuty Malware Protection Docs; DOP-C02 Exam Guide (Domain 5: Security).

Câu 350
A company has a requirement that no Amazon EC2 security group can allow SSH access from the CIDR block 0.0.0.0/0. The company wants to monitor compliance with this requirement at all times and wants to receive a near-real-time notification if any security group is noncompliant.

A security engineer has configured AWS Config and will use the restricted-ssh managed rule to monitor the security groups.

What should the security engineer do next to meet these requirements?
  1. A Configure AWS Config to send its configuration snapshots to an Amazon S3 bucket. Create an AWS Lambda function to run on a PutEvent to the S3 bucket. Configure the Lambda function to parse the snapshot for a compliance change to the restricted-ssh managed rule. Configure the Lambda function to send a notification to an Amazon Simple Notification Service (Amazon SNS) topic if a change is discovered.
  2. B Configure an Amazon EventBridge event rule that is invoked by a compliance change event from AWS Config for the restricted-ssh managed rule. Configure the event rule to target an Amazon Simple Notification Service (Amazon SNS) topic that will provide a notification.
  3. C Configure AWS Config to push all its compliance notifications to Amazon CloudWatch Logs. Configure a CloudWatch Logs metric filter on the AWS Config log group to look for a compliance notification change on the restricted-ssh managed rule. Create an Amazon CloudWatch alarm on the metric filter to send a notification to an Amazon Simple Notification Service (Amazon SNS) topic if the alarm is in the ALARM state.
  4. D Configure an Amazon CloudWatch alarm on the CloudWatch metric for the restricted-ssh managed rule. Configure the CloudWatch alarm to send a notification to an Amazon Simple Notification Service (Amazon SNS) topic if the alarm is in the ALARM state.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh việc giám sát tuân thủ (compliance monitoring) cho các Amazon EC2 Security Group trên AWS. Cụ thể:

  • Công ty yêu cầu không một Security Group nào được phép cho phép truy cập SSH (port 22) từ CIDR block 0.0.0.0/0 (tức là mở rộng toàn bộ internet, rất rủi ro bảo mật).
  • Họ muốn monitor liên tục (at all times) và nhận thông báo gần thời gian thực (near-real-time) nếu có Security Group vi phạm (noncompliant).
  • Security engineer đã cấu hình AWS Config và sử dụng managed rule "restricted-ssh" (một rule có sẵn của AWS Config để kiểm tra chính xác yêu cầu này: cấm inbound SSH từ 0.0.0.0/0).

Mục tiêu tiếp theo: Cấu hình cơ chế thông báo tự động khi compliance status thay đổi (ví dụ: từ COMPLIANT sang NON_COMPLIANT).
📘 Kiến thức cập nhật (AWS 2026): AWS Config tích hợp chặt chẽ với Amazon EventBridge để emit events real-time khi rule evaluation thay đổi (dựa trên config item changes). Rule "restricted-ssh" là managed rule chuẩn, evaluate periodic hoặc real-time qua triggers. Không cần custom rule vì AWS cung cấp sẵn (xem AWS Config Managed Rules docs).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Configure an Amazon EventBridge event rule that is invoked by a compliance change event from AWS Config for the restricted-ssh managed rule. Configure the event rule to target an Amazon Simple Notification Service (Amazon SNS) topic that will provide a notification.

Lý do chọn đáp án này 🛠️:

  • AWS Config tự động phát hiện thay đổi config item (như Security Group update) và evaluate rule "restricted-ssh", sau đó emit event "Compliance Change" đến EventBridge một cách near-real-time (gần tức thì khi evaluation hoàn tất, thường trong vài phút).
  • EventBridge rule match pattern event cụ thể (source: aws.config, detail-type: Config Rules Compliance Change, resourceType: AWS::EC2::SecurityGroup, rule name: restricted-ssh), rồi target trực tiếp SNS topic để notify (email/SMS).
  • Đây là cách tối ưu, serverless, real-time nhất, không phụ thuộc snapshot hay logs phức tạp. Hỗ trợ scale lớn và chi phí thấp.
    📘 Tài liệu tham khảo: AWS Config + EventBridge Integration (cập nhật 2025); restricted-ssh Rule Docs.

📋 Phân tích tất cả các phương án (đúng/sai)

  • ❌ Phương án SAI: Configure AWS Config to send its configuration snapshots to an Amazon S3 bucket. Create an AWS Lambda function to run on a PutEvent to the S3 bucket. Configure the Lambda function to parse the snapshot for a compliance change to the restricted-ssh managed rule. Configure the Lambda function to send a notification to an Amazon Simple Notification Service (Amazon SNS) topic if a change is discovered.
    Giải thích sai: Snapshot của AWS Config chỉ periodic (mặc định 24h hoặc thủ công), không near-real-time. Phải parse thủ công qua Lambda + S3 event (PutObject), phức tạp, dễ miss thay đổi nhanh và tốn chi phí (Lambda invocations). Không tận dụng native EventBridge của Config.

  • ✅ Phương án ĐÚNG (như đã phân tích ở trên): Configure an Amazon EventBridge event rule that is invoked by a compliance change event from AWS Config for the restricted-ssh managed rule. Configure the event rule to target an Amazon Simple Notification Service (Amazon SNS) topic that will provide a notification.
    Giải thích đúng: Native integration real-time, đơn giản, không code. Event pattern chính xác match compliance change của rule cụ thể.

  • ❌ Phương án SAI: Configure AWS Config to push all its compliance notifications to Amazon CloudWatch Logs. Configure a CloudWatch Logs metric filter on the AWS Config log group to look for a compliance notification change on the restricted-ssh managed rule. Create an Amazon CloudWatch alarm on the metric filter to send a notification to an Amazon Simple Notification Service (Amazon SNS) topic if the alarm is in the ALARM state.
    Giải thích sai: AWS Config không "push compliance notifications" trực tiếp đến CloudWatch Logs (chỉ logs aggregator nếu enable). Metric filter + alarm không real-time (delay parsing logs), phức tạp setup, và alarm chỉ trigger khi metric vượt ngưỡng (không ideal cho event-based change). EventBridge hiệu quả hơn nhiều.

  • ❌ Phương án SAI: Configure an Amazon CloudWatch alarm on the CloudWatch metric for the restricted-ssh managed rule. Configure the CloudWatch alarm to send a notification to an Amazon Simple Notification Service (Amazon SNS) topic if the alarm is in the ALARM state.
    Giải thích sai: AWS Config publish metric "NonCompliantRuleCount" tổng quát, không metric riêng cho từng rule cụ thể như restricted-ssh (chỉ aggregate). Alarm chỉ báo tổng số NON_COMPLIANT, không detect change real-time cho rule này, và không phân biệt Security Group cụ thể. Delay evaluation (periodic), không near-real-time.

💡 Lời khuyên DevOps: Trong thực tế DOP-C02 exam (2025+), ưu tiên EventBridge cho event-driven architecture. Test bằng AWS Console: Tạo SG vi phạm → Xem EventBridge events ngay lập tức! 🚀