Ngân hàng đề — AWS Certified Security Specialty

Tìm thấy 445 câu.

Câu 351 Chọn nhiều đáp án
A security engineer discovers that a company’s user passwords have no required minimum length. The company is using the following two identity providers (IdPs):
•AWS Identity and Access Management (IAM) federated with on-premises Active Directory
•Amazon Cognito user pools that contain the user database for an AWS Cloud application that the company developed

Which combination of actions should the security engineer take to implement a required minimum length for the passwords? (Choose two.)
  1. A Update the password length policy in the IAM configuration.
  2. B Update the password length policy in the Cognito configuration.
  3. C Update the password length policy in the on-premises Active Directory configuration
  4. D Create an SCP in AWS Organizations. Configure the SCP to enforce a minimum password length for IAM and Cognito.
  5. E Create an IAM policy that includes a condition for minimum password length. Enforce the policy for IAM and Cognito.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả tình huống một security engineer phát hiện rằng password của người dùng công ty không có yêu cầu độ dài tối thiểu. Công ty đang sử dụng hai Identity Providers (IdPs) chính:

  • AWS IAM federated với on-premises Active Directory: Người dùng xác thực qua Active Directory (AD) tại chỗ, IAM chỉ cấp quyền truy cập qua federation (không quản lý password trực tiếp).
  • Amazon Cognito user pools: Lưu trữ cơ sở dữ liệu người dùng cho ứng dụng AWS Cloud do công ty phát triển, nơi Cognito quản lý trực tiếp password của người dùng.

Mục tiêu: Chọn hai hành động kết hợp để thực thi yêu cầu độ dài password tối thiểu. Đây là câu hỏi kiểu chọn nhiều đáp án (Choose TWO), tập trung vào cách cấu hình chính sách password đúng nơi quản lý credentials. Kiến thức AWS mới nhất (đến 2026) nhấn mạnh rằng password policy phải được áp dụng tại nguồn IdP quản lý password thực tế, không phải qua IAM policies hoặc SCP (vì chúng chỉ kiểm soát quyền truy cập, không phải quy tắc password).

✅ Đáp án đúng và lý do lựa chọn

Hai đáp án đúng là:

  • Update the password length policy in the Cognito configuration.
  • Update the password length policy in the on-premises Active Directory configuration.

Lý do:

  • Với Cognito user pools, password được quản lý trực tiếp bởi Cognito. Bạn có thể cấu hình Password Policy trong User Pool settings (qua Console, CLI hoặc CDK/Terraform), đặt MinimumLength từ 6-99 ký tự (mặc định 8). Điều này áp dụng ngay lập tức cho tất cả users trong pool. 🛠️
  • Với IAM federated qua on-premises AD, password được quản lý bởi Active Directory (không phải IAM). Phải cập nhật Password Policy trong AD Domain Controller (qua Group Policy hoặc Fine-Grained Password Policy) để enforce minimum length. IAM chỉ federate SAML/JWT, không override password từ IdP ngoài. ✅

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn giữ nguyên văn bản gốc bằng tiếng Anh, với giải thích đúng/sai bằng tiếng Việt dựa trên tài liệu AWS mới nhất:

  • ❌ Update the password length policy in the IAM configuration.
    Sai: IAM Password Policy chỉ áp dụng cho IAM users sử dụng console password (root hoặc IAM user login trực tiếp). Trong trường hợp federated với AD, người dùng không có IAM password; họ dùng AD credentials qua SAML/OIDC federation. IAM không kiểm soát password từ external IdP. Cập nhật IAM policy sẽ không ảnh hưởng đến federated users hoặc Cognito.

  • ✅ Update the password length policy in the Cognito configuration.
    Đúng: Cognito User Pools có Sign-up attributes và Password Policy riêng (trong Pool settings > Policies). Bạn đặt minLength trực tiếp, áp dụng cho tất cả users tự đăng ký hoặc migrated. Hỗ trợ MFA, temporary passwords. Đây là cách chuẩn cho app-based authentication.

  • ✅ Update the password length policy in the on-premises Active Directory configuration.
    Đúng: AD là nguồn gốc password cho IAM federation. Cấu hình qua Default Domain Policy hoặc Password Settings Object (PSO) trong AD DS. IAM AssumeRoleWithSAML chỉ kiểm tra valid token từ AD, không enforce password rules riêng.

  • ❌ Create an SCP in AWS Organizations. Configure the SCP to enforce a minimum password length for IAM and Cognito.
    Sai: Service Control Policies (SCP) chỉ deny/allow AWS API actions ở mức organization/account, không kiểm soát password policies. SCP không thể enforce minimum password length vì đây là quy tắc authn (authentication), không phải authz (authorization).

  • ❌ Create an IAM policy that includes a condition for minimum password length. Enforce the policy for IAM and Cognito.
    Sai: IAM policies định nghĩa quyền truy cập (actions/resources/conditions như IP, MFA), không phải password requirements. Không có condition nào cho "password length" vì password managed bởi IdP, không qua IAM. Cognito và AD không bị ràng buộc bởi IAM policy cho password rules.

📘 Tài liệu tham khảo (AWS cập nhật đến 2026)

Kết luận: 🏆 Câu hỏi kiểm tra hiểu biết sâu về IdP delegation trong AWS security. Luôn enforce policy tại nguồn quản lý password để tránh lỗ hổng! Nếu cần lab thực hành, dùng AWS Free Tier với Cognito và AD Connector. 🚀

Câu 352
A company uses AWS Key Management Service (AWS KMS). During an attempt to attach an encrypted Amazon Elastic Block Store (Amazon EBS) volume to an Amazon EC2 instance, the attachment fails. The company discovers that a customer managed key has become unusable because the key material for the key was deleted. The company needs the data that is on the EBS volume.

A security engineer must recommend a solution to decrypt the EBS volume’s encrypted data key. The solution must also attach the volume to the EC2 instance.

Which solution will meet these requirements?
  1. A Import new key material into the key. Attach the EBS volume.
  2. B Restore the EBS volume from a snapshot that was taken before the deletion of the key material.
  3. C Reimport the same key material that originally was imported into the key. Attach the EBS volume.
  4. D Create a new key. Import new key material. Attach the EBS volume.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi xoay quanh tình huống khẩn cấp trong AWS: Một công ty sử dụng AWS Key Management Service (AWS KMS) để mã hóa Amazon Elastic Block Store (EBS) volume. Khi cố gắng gắn (attach) volume mã hóa này vào Amazon EC2 instance, quá trình thất bại. Nguyên nhân là customer managed key (khóa do khách hàng quản lý) trở nên unusable vì key material (vật liệu khóa) của nó đã bị xóa (deleted). Công ty cần truy xuất dữ liệu trên volume EBS đó.
📌 Yêu cầu giải pháp:

  • Giải mã (decrypt) encrypted data key của EBS volume (data key là khóa mã hóa dữ liệu thực tế trên volume, được bảo vệ bởi KMS key).
  • Gắn volume vào EC2 instance thành công.
    🛠️ Bối cảnh kỹ thuật: Với KMS imported keys (khóa nhập vật liệu từ bên ngoài), nếu key material bị xóa, key không thể decrypt nữa. Giải pháp phải tuân thủ cơ chế imported key material của AWS KMS (hỗ trợ reimport để khôi phục tính tương thích với dữ liệu cũ). Không áp dụng cho AWS-managed keys. Dữ liệu cập nhật AWS đến 2026 vẫn giữ nguyên quy trình này (xem AWS KMS docs).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Reimport the same key material that originally was imported into the key. Attach the EBS volume.
Lý do:

  • Với customer managed KMS key sử dụng imported key material, AWS cho phép reimport chính xác cùng key material gốc để khôi phục khả năng decrypt. Key material phải giống hệt (byte-for-byte) để data encryption key (DEK) trên EBS volume khớp và decrypt được. Sau reimport, key trở lại trạng thái active, cho phép attach EBS vào EC2.
  • Đây là giải pháp chính thức từ AWS, tránh mất dữ liệu vĩnh viễn. ✅ Hoạt động ngay lập tức mà không cần tạo key mới hay snapshot.

📋 Giải thích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh dấu ✅ (đúng) hoặc ❌ (sai), kèm lý do dựa trên tài liệu AWS KMS mới nhất (2026).

  • ❌ [SAI] Import new key material into the key. Attach the EBS volume.
    Phương án này không khả thi vì AWS KMS không cho phép import key material mới vào một imported key hiện có. Key material phải giống hệt gốc; nếu import khác, DEK trên EBS không decrypt được (gây lỗi "InvalidCiphertext" hoặc key mismatch). Key vẫn unusable với dữ liệu cũ. 🧨 Rủi ro mất dữ liệu.

  • ❌ [SAI] Restore the EBS volume from a snapshot that was taken before the deletion of the key material.
    Snapshot EBS cũng được mã hóa bằng cùng KMS key và DEK, nên nếu key material bị xóa, snapshot vẫn không decrypt được. Restore chỉ tạo volume mới với cùng vấn đề, không giải quyết gốc rễ. 📸 Không hiệu quả, cần khôi phục key trước.

  • ✅ [ĐÚNG] Reimport the same key material that originally was imported into the key. Attach the EBS volume.
    Như đã giải thích ở phần đáp án đúng: Reimport cùng key material gốc khôi phục key hoàn toàn, decrypt DEK thành công, attach EBS vào EC2 mượt mà. 🛡️ Giải pháp chuẩn AWS cho imported keys.

  • ❌ [SAI] Create a new key. Import new key material. Attach the EBS volume.
    Tạo key mới với material mới không decrypt được DEK cũ trên EBS (DEK chỉ tương thích với key gốc). Phải re-encrypt toàn bộ dữ liệu (copy volume, decrypt/encrypt lại) – tốn kém, phức tạp, và không đáp ứng yêu cầu "decrypt EBS volume’s encrypted data key" trực tiếp. 🔄 Không phù hợp.

📘 Tài liệu tham khảo

Câu 353
A company needs to analyze access logs for an Application Load Balancer (ALB). The ALB directs traffic to the company’s online login portal. The company needs to use visualizations to identify login attempts by bots from a list of known IP sources.

Which solution will meet these requirements?
  1. A Configure the ALB to send logs directly to Amazon CloudWatch Logs. Analyze and visualize the logs by using CloudWatch Logs Insights.
  2. B Configure the ALB to send logs directly to Amazon Redshift. Analyze the logs by using SQL queries. Visualize the logs by using custom reports.
  3. C Configure the ALB to send logs directly to Amazon OpenSearch Service. Analyze the logs by using OpenSearch dashboards. Visualize the logs by using custom OpenSearch dashboards.
  4. D Configure the ALB to send logs directly to an Amazon S3 bucket. Analyze the logs by using Amazon Athena. Visualize the logs by using Amazon QuickSight.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc phân tích access logs của Application Load Balancer (ALB) để phát hiện các nỗ lực đăng nhập từ bot dựa trên danh sách IP đã biết. ALB đang hướng traffic đến cổng login trực tuyến của công ty. Yêu cầu chính là:

  • Thu thập logs từ ALB một cách trực tiếp và hiệu quả.
  • Sử dụng visualizations (biểu đồ, dashboard) để phân tích và xác định hành vi bot.
  • Giải pháp phải tuân thủ tính năng native của AWS, đặc biệt là khả năng gửi logs trực tiếp từ ALB (không qua trung gian phức tạp), kết hợp với công cụ phân tích dữ liệu lớn (big data analytics) và visualization.

🛠️ Lưu ý kỹ thuật: Access logs của ALB là định dạng chuẩn (ELB/ALB log format), chứa thông tin như client IP, timestamp, request path, v.v. AWS ALB chỉ hỗ trợ gửi logs trực tiếp đến Amazon S3 (tính năng built-in từ lâu, cập nhật đến 2026 vẫn giữ nguyên). Không hỗ trợ gửi trực tiếp đến các dịch vụ khác như CloudWatch Logs, Redshift hay OpenSearch Service. Sau khi lưu vào S3, có thể dùng Athena để query serverless và QuickSight để visualize.

✅ Đáp án đúng

Configure the ALB to send logs directly to an Amazon S3 bucket. Analyze the logs by using Amazon Athena. Visualize the logs by using Amazon QuickSight.

Lý do lựa chọn:

  • ALB hỗ trợ gửi logs trực tiếp đến S3 (enable access logs trong ALB attributes, chỉ định S3 bucket), đây là cách tiết kiệm chi phí, scalable và serverless nhất cho volume logs lớn từ traffic login.
  • Amazon Athena là query engine serverless trên S3, hỗ trợ SQL queries trên logs định dạng CSV/JSON mà không cần ETL, lý tưởng để filter IP từ list known bots (ví dụ: SELECT * FROM logs WHERE client_ip IN ('x.x.x.x', ...)).
  • Amazon QuickSight tích hợp trực tiếp với Athena/S3 để tạo visualizations động (charts, dashboards) như heatmaps IP sources, trends login attempts – phù hợp hoàn hảo với yêu cầu.
  • Giải pháp này cost-effective (pay-per-query cho Athena, pay-per-session cho QuickSight), không cần quản lý infrastructure, và scale theo traffic cao của login portal (cập nhật AWS 2026: Athena hỗ trợ ML insights qua Athena Data Lake).

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá dựa trên tính khả thi trực tiếp từ ALB và phù hợp với visualization cho bot detection.

  • Configure the ALB to send logs directly to Amazon CloudWatch Logs. Analyze and visualize the logs by using CloudWatch Logs Insights.
    ❌ Sai: ALB không hỗ trợ gửi logs trực tiếp đến CloudWatch Logs (phải lưu S3 trước, rồi dùng Lambda/CloudWatch Logs Agent để forward – phức tạp và tốn kém). CloudWatch Logs Insights chỉ phù hợp logs nhỏ, không scale tốt cho access logs volume cao từ ALB. Không phải giải pháp native.

  • Configure the ALB to send logs directly to Amazon Redshift. Analyze the logs by using SQL queries. Visualize the logs by using custom reports.
    ❌ Sai: ALB không gửi trực tiếp đến Redshift (Redshift là data warehouse managed, cần ETL pipeline như Kinesis Firehose hoặc Lambda để load từ S3). Custom reports không phải visualization mạnh mẽ, và Redshift đắt đỏ cho logs real-time (provisioned clusters), không phù hợp bot detection nhanh.

  • Configure the ALB to send logs directly to Amazon OpenSearch Service. Analyze the logs by using OpenSearch dashboards. Visualize the logs by using custom OpenSearch dashboards.
    ❌ Sai: ALB không hỗ trợ gửi trực tiếp đến OpenSearch Service (trước là Elasticsearch; cần S3 → Kinesis → OpenSearch hoặc Fluentd). OpenSearch tốt cho search logs nhưng overkill và tốn kém cho ALB logs (domain management), không phải lựa chọn đầu tay cho visualization đơn giản từ IP lists.

  • Configure the ALB to send logs directly to an Amazon S3 bucket. Analyze the logs by using Amazon Athena. Visualize the logs by using Amazon QuickSight.
    ✅ Đúng: Như giải thích trên, đây là best practice AWS cho ALB logs: trực tiếp → S3 (zero config ngoài bucket policy), Athena query petabyte-scale, QuickSight BI dashboards pro (ML-powered anomalies detection cho bots).

📘 Tài liệu tham khảo (cập nhật AWS 2026)

💡 Mẹo DevOps: Để tối ưu, enable S3 versioning + Athena table partitioning by date/IP cho query nhanh! 🚀

Câu 354
A company runs a cron job on an Amazon EC2 instance on a predefined schedule. The cron job calls a bash script that encrypts a 2 KB file. A security engineer creates an AWS Key Management Service (AWS KMS) customer managed key with a key policy. The key policy and the EC2 instance role have the necessary configuration for this job.

Which process should the bash script use to encrypt the file?
  1. A Use the aws kms encrypt command to encrypt the file by using the existing KMS key.
  2. B Use the aws kms create-grant command to generate a grant for the existing KMS key.
  3. C Use the aws kms encrypt command to generate a data key. Use the plaintext data key to encrypt the file.
  4. D Use the aws kms generate-data-key command to generate a data key. Use the encrypted data key to encrypt the file.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh một tình huống thực tế trong AWS: Một công ty chạy cron job trên Amazon EC2 instance theo lịch cố định. Cron job này gọi một bash script để mã hóa một file nhỏ chỉ 2 KB. Đã có AWS Key Management Service (KMS) với customer managed key (CMK), kèm theo key policy và EC2 instance role đã được cấu hình đầy đủ quyền hạn cần thiết cho job này.

Mục tiêu chính: Bash script cần sử dụng quy trình nào để mã hóa file một cách an toàn, hiệu quả bằng KMS key hiện có?
✅ Lưu ý quan trọng: File chỉ 2 KB (rất nhỏ), nên phù hợp với các phương pháp mã hóa trực tiếp. EC2 role đã có quyền truy cập KMS (kms:Encrypt), không cần thêm grant hay cấu hình phức tạp. Kiến thức dựa trên phiên bản AWS KMS mới nhất (2024-2026), hỗ trợ CLI v2 với giới hạn encrypt trực tiếp lên đến 4 KB dữ liệu plaintext/ciphertext.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use the aws kms encrypt command to encrypt the file by using the existing KMS key.

Lý do chi tiết:

  • Với file nhỏ (2 KB < 4 KB giới hạn), lệnh aws kms encrypt là cách đơn giản, trực tiếp và hiệu quả nhất để mã hóa toàn bộ file bằng KMS key hiện có.
  • Script bash trên EC2 chỉ cần gọi CLI: aws kms encrypt --key-id <key-arn> --plaintext file://input.txt --output text --query CiphertextBlob | base64 --decode > encrypted.bin.
  • Không cần envelope encryption (cho file lớn), vì overhead thấp và EC2 role đã có quyền kms:Encrypt.
  • 🛠️ Ưu điểm: Nhanh chóng, ít bước, phù hợp cron job tự động. Đây là best practice cho dữ liệu nhỏ theo AWS Well-Architected Framework (Security Pillar).

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn một cách chi tiết. Tôi giữ nguyên văn bản gốc bằng tiếng Anh, chỉ dịch và giải thích lý do bằng tiếng Việt. Sử dụng ✅ cho đúng, ❌ cho sai.

  • ✅ Use the aws kms encrypt command to encrypt the file by using the existing KMS key.
    Giải thích đúng: Như trên, đây là phương pháp chuẩn cho file nhỏ. KMS encrypt trực tiếp dữ liệu với key hiện có, trả về ciphertext ngay lập tức. Không cần data key riêng vì file < 4 KB. Hoàn hảo cho bash script đơn giản.

  • ❌ Use the aws kms create-grant command to generate a grant for the existing KMS key.
    Giải thích sai: Lệnh aws kms create-grant chỉ tạo grant (quyền tạm thời) cho principal khác sử dụng key, không mã hóa file. EC2 role đã có quyền sẵn (qua key policy), nên không cần grant. Sử dụng lệnh này sẽ thất bại vì không liên quan đến encrypt, chỉ thêm overhead không cần thiết.

  • ❌ Use the aws kms encrypt command to generate a data key. Use the plaintext data key to encrypt the file.
    Giải thích sai: aws kms encrypt không generate data key; nó chỉ encrypt trực tiếp dữ liệu với KMS key. Lệnh generate data key là generate-data-key hoặc generate-data-key-pair. Nếu dùng plaintext data key (từ generate-data-key), phải encrypt file local bằng công cụ như OpenSSL, nhưng lựa chọn này nhầm lẫn API và không phải quy trình chuẩn cho trường hợp đơn giản.

  • ❌ Use the aws kms generate-data-key command to generate a data key. Use the encrypted data key to encrypt the file.
    Giải thích sai: aws kms generate-data-key tạo plaintext data key (để encrypt file local) và encrypted data key (bằng KMS key để lưu trữ). Encrypted data key không dùng để encrypt file; chỉ plaintext data key mới encrypt local. Sử dụng sai cách này sẽ làm script lỗi, vì envelope encryption dành cho file lớn (>4 KB), không cần thiết ở đây và phức tạp hơn cho cron job.

📘 Tài liệu tham khảo (AWS Official - Cập nhật 2024-2026)

  • AWS KMS Developer Guide: Encrypting data directly with KMS – Xác nhận giới hạn 4 KB cho Encrypt.
  • AWS CLI Reference: aws kms encrypt và generate-data-key.
  • Exam Prep DOP-C02: Topic "KMS Encryption Strategies" – Nhấn mạnh direct encrypt cho small payloads.
  • AWS Well-Architected: Security Pillar – Best practice cho EC2 + KMS integration.

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần ví dụ code bash đầy đủ, hãy hỏi thêm.

Câu 355
A security engineer needs to analyze Apache web server access logs that are stored in an Amazon S3 bucket. Amazon EC2 instance web servers generated the logs. The EC2 instances have the Amazon CloudWatch agent installed and configured to report their access logs.

The security engineer needs to use a query in Amazon Athena to analyze the logs. The query must identify IP addresses that have attempted and failed to access restricted web server content held at the /admin URL path. The query also must identify the URLs that the IP addresses attempted to access.

Which query will meet these requirements?
  1. A SELECT client_ip, client_request FROM logs WHERE client_request LIKE '%/admin%!’ AND server_status = '403’
  2. B SELECT client_ip FROM logs WHERE client_request CONTAINS '%/admin%’ AND server_status = '401' GROUP BY client_ip
  3. C SELECT DISTINCT (client_ip), client_request, client_id FROM logs WHERE server status = ‘403’ LIMIT 1000
  4. D SELECT DISTINCT (client_ip), client_request FROM logs WHERE user_id <> ‘admin’ AND server_status = ‘401!’
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi này thuộc chủ đề Amazon Athena (dịch vụ query serverless trên dữ liệu S3), liên quan đến việc phân tích Apache web server access logs được lưu trữ trong Amazon S3 bucket. Các log được tạo từ Amazon EC2 instances có cài đặt Amazon CloudWatch agent để báo cáo logs.

Yêu cầu cụ thể của query Athena:

  • Xác định IP addresses (client_ip) đã thử truy cập thất bại nội dung hạn chế tại đường dẫn /admin (thất bại thường là mã trạng thái 403 Forbidden – từ chối truy cập).
  • Đồng thời liệt kê các URLs mà IP đó đã thử truy cập (thường là trường client_request trong log Apache).
  • Query phải sử dụng cú pháp SQL chuẩn của Athena (dựa trên Presto/Trino engine, phiên bản mới nhất 2026 hỗ trợ partition, federated queries, và regex nâng cao).

Bối cảnh logs Apache tiêu chuẩn (theo định dạng Common Log Format hoặc Combined):

  • Các trường liên quan: client_ip (IP client), client_request (request line như GET /admin HTTP/1.1), server_status (mã HTTP status như 403).
  • Logs được CloudWatch agent push vào S3, sau đó partitioned/glued trong Athena để query hiệu quả. 📘

Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: SELECT client_ip, client_request FROM logs WHERE client_request LIKE '%/admin%!’ AND server_status = '403’

Lý do chi tiết 🛠️:

  • Query chọn đúng client_ip và client_request (IPs và URLs attempted).
  • LIKE '%/admin%!’ khớp request chứa /admin (dấu ! có thể là phần của regex hoặc lỗi log, nhưng khớp yêu cầu "/admin URL path").
  • server_status = '403’ chính xác xác định failed access (403 Forbidden cho restricted content).
  • Không dùng GROUP BY/DISTINCT/LIMIT thừa, tránh sai lệch kết quả. Hoàn hảo cho yêu cầu! 🚀

📋 Giải thích tất cả các phương án (đúng/sai)

  • ✅ Phương án ĐÚNG:
    SELECT client_ip, client_request FROM logs WHERE client_request LIKE '%/admin%!’ AND server_status = '403’
    Giải thích: Hoàn toàn khớp yêu cầu. Sử dụng LIKE với pattern %/admin%!’ để tìm request chứa /admin, kết hợp server_status = '403’ lọc failed attempts. Trả về chính xác IP và URLs cần thiết. Syntax chuẩn Athena/Presto. 👌

  • ❌ Phương án SAI 1:
    SELECT client_ip FROM logs WHERE client_request CONTAINS '%/admin%’ AND server_status = '401' GROUP BY client_ip
    Giải thích: Sai syntax CONTAINS (Athena dùng LIKE hoặc RLIKE, không hỗ trợ CONTAINS như Spark SQL). server_status = '401' là Unauthorized (yêu cầu auth), không phải failed restricted access (403). GROUP BY chỉ IP mà thiếu URLs requested. Không đáp ứng đầy đủ. ❌

  • ❌ Phương án SAI 2:
    SELECT DISTINCT (client_ip), client_request, client_id FROM logs WHERE server status = ‘403’ LIMIT 1000
    Giải thích: Tên cột sai server status (có space, phải là server_status). Thêm client_id không tồn tại trong Apache logs (không liên quan). LIMIT 1000 giới hạn kết quả tùy ý, không filter /admin. DISTINCT thừa vì thiếu WHERE chính xác cho /admin. Không tìm failed /admin access. 🚫

  • ❌ Phương án SAI 3:
    SELECT DISTINCT (client_ip), client_request FROM logs WHERE user_id &lt;&gt; ‘admin’ AND server_status = ‘401!’
    Giải thích: Không có trường user_id trong Apache access logs (chỉ có trong auth logs). Toán tử &lt;&gt; (≠) không logic với yêu cầu (phải filter request path, không phải user). server_status = ‘401!’ sai mã (401 + '!' vô nghĩa, phải 403). Không khớp /admin path. Hoàn toàn lệch! 🔴

Câu 356
A company uses Amazon Cognito as an OAuth 2.0 identity platform for its web and mobile applications. The company needs to capture successful and unsuccessful login attempts. The company also needs to query the data about the login attempts.

Which solution will meet these requirements?
  1. A Configure Cognito to send logs of user activity to Amazon CloudWatch. Configure Amazon EventBridge to invoke an AWS Lambda function to export the logs to an Amazon S3 bucket. Use Amazon Athena to query the logs for event names of SignUp with event sources of cognito-idp.amazonaws.com.
  2. B Enable AWS CloudTrail to deliver logs to an Amazon S3 bucket. Use Amazon Athena to query the logs for event names of InitiateAuth with event sources of cognito-idp.amazonaws.com.
  3. C Configure AWS CloudTrail to send Cognito CloudTrail events to Amazon CloudWatch for monitoring. Query the event logs for event names of SignUp with event sources of cognito-idp.amazonaws.com.
  4. D Configure Amazon CloudWatch metrics to monitor and report Cognito events. Create a CloudWatch dashboard for the provided metrics. Display the Cognito user pools for event names of InitiateAuth with event sources of cognito-idp.amazonaws.com.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc ghi nhận (capture) các lần đăng nhập thành công và thất bại từ Amazon Cognito (dùng làm nền tảng OAuth 2.0 cho ứng dụng web và mobile), đồng thời truy vấn (query) dữ liệu về các lần đăng nhập này.

📌 Yêu cầu chính:

  • Cognito xử lý xác thực người dùng (login attempts), bao gồm cả thành công (successful) và thất bại (unsuccessful).
  • Cần giải pháp lưu trữ logs và truy vấn dễ dàng, phù hợp với quy mô lớn.
  • Không phải chỉ đăng ký (SignUp), mà là đăng nhập (InitiateAuth) – đây là API call chính cho authentication trong Cognito User Pools.

🛠️ Kiến thức AWS liên quan (cập nhật đến 2026):

  • Amazon Cognito ghi logs hoạt động người dùng qua AWS CloudTrail (management events tự động, data events cần enable).
  • Event InitiateAuth (eventName) từ source cognito-idp.amazonaws.com capture login attempts (thành công/thất bại dựa trên response).
  • Lưu vào S3, query bằng Athena là chuẩn best practice cho phân tích logs lớn.
  • Cognito không gửi logs trực tiếp đến CloudWatch; metrics CloudWatch chỉ tổng hợp (không chi tiết từng attempt).

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Enable AWS CloudTrail to deliver logs to an Amazon S3 bucket. Use Amazon Athena to query the logs for event names of InitiateAuth with event sources of cognito-idp.amazonaws.com.

Lý do 🏆:

  • CloudTrail capture tất cả API calls đến Cognito User Pools (bao gồm InitiateAuth cho login attempts – cả success/error).
  • Logs lưu trữ lâu dài trong S3 (immutable, scalable).
  • Athena query SQL trực tiếp trên S3 logs, lọc chính xác eventName=InitiateAuth và eventSource=cognito-idp.amazonaws.com → hoàn hảo cho query login data.
  • Đây là giải pháp native, cost-effective, serverless theo AWS Well-Architected Framework (Operational Excellence pillar).

📋 Giải thích chi tiết từng phương án

Dưới đây là phân tích tất cả 4 lựa chọn (giữ nguyên văn bản gốc tiếng Anh). Mỗi cái có ✅ (đúng) hoặc ❌ (sai), kèm giải thích đầy đủ bằng tiếng Việt.

  • Phương án 1: Configure Cognito to send logs of user activity to Amazon CloudWatch. Configure Amazon EventBridge to invoke an AWS Lambda function to export the logs to an Amazon S3 bucket. Use Amazon Athena to query the logs for event names of SignUp with event sources of cognito-idp.amazonaws.com.
    ❌ Sai vì:

    • Cognito không hỗ trợ gửi logs user activity trực tiếp đến CloudWatch (chỉ metrics tổng hợp, không chi tiết logs).
    • Phức tạp không cần thiết (EventBridge + Lambda để export → overhead cao).
    • SignUp là event đăng ký user, không phải login attempts (InitiateAuth mới đúng).
  • Phương án 2: Enable AWS CloudTrail to deliver logs to an Amazon S3 bucket. Use Amazon Athena to query the logs for event names of InitiateAuth with event sources of cognito-idp.amazonaws.com.
    ✅ Đúng hoàn toàn (như đã giải thích ở trên). Giải pháp đơn giản, chính xác, scalable cho capture và query login events.

  • Phương án 3: Configure AWS CloudTrail to send Cognito CloudTrail events to Amazon CloudWatch for monitoring. Query the event logs for event names of SignUp with event sources of cognito-idp.amazonaws.com.
    ❌ Sai vì:

    • CloudTrail có thể forward sang CloudWatch Logs, nhưng query logs trong CloudWatch kém hiệu quả cho dữ liệu lớn (chi phí cao, retention ngắn).
    • Lại dùng SignUp thay vì InitiateAuth → không capture login attempts.
    • Không đề cập Athena hoặc S3 → thiếu khả năng query linh hoạt lâu dài.
  • Phương án 4: Configure Amazon CloudWatch metrics to monitor and report Cognito events. Create a CloudWatch dashboard for the provided metrics. Display the Cognito user pools for event names of InitiateAuth with event sources of cognito-idp.amazonaws.com.
    ❌ Sai vì:

    • CloudWatch metrics cho Cognito chỉ tổng hợp (như "SignIn.Success", "SignIn.Failure") → không capture chi tiết từng attempt (không có event names/sources).
    • Dashboard chỉ visualize metrics, không query logs chi tiết (không hỗ trợ eventSource).
    • Không lưu trữ/query như yêu cầu (metrics ephemeral, không drill-down).

🔥 Kết luận: Chọn phương án 2 để meet requirements tối ưu – tuân thủ AWS best practices cho auditing và analytics! Nếu thi DOP-C02, đây là pattern kinh điển về CloudTrail + Athena. 🚀

Câu 357
A security engineer is setting up an AWS CloudTrail trail for all regions in an AWS account. For added security, the logs are stored using server-side encryption with AWS KMS-managed keys (SSE-KMS) and have log integrity validation enabled.

While testing the solution, the security engineer discovers that the digest files are readable, but the log files are not. What is the MOST likely cause?
  1. A The log files fail integrity validation and automatically are marked as unavailable.
  2. B The KMS key policy does not grant the security engineer’s IAM user or role permissions to decrypt with it.
  3. C The bucket is set up to use server-side encryption with Amazon S3-managed keys (SSE-S3) as the default and does not allow SSE-KMS-encrypted files.
  4. D An IAM policy applicable to the security engineer’s IAM user or role denies access to the “CloudTrail/” prefix in the Amazon S3 bucket.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh việc thiết lập AWS CloudTrail trail cho tất cả các region trong một AWS account. Security engineer đã cấu hình thêm lớp bảo mật bằng cách:

  • Lưu trữ logs vào Amazon S3 bucket sử dụng server-side encryption với AWS KMS-managed keys (SSE-KMS).
  • Bật log integrity validation (xác thực tính toàn vẹn logs qua digest files).

Khi testing, phát hiện:

  • Digest files (file tóm tắt hash để validate integrity, bao gồm daily và annual digest) có thể đọc được.
  • Log files (file logs thực tế) không thể đọc được.

MOST likely cause (nguyên nhân có khả năng nhất)?
🛠️ Vấn đề cốt lõi: CloudTrail với SSE-KMS encrypt chỉ log files bằng KMS key, trong khi digest files KHÔNG được encrypt (chúng chỉ là các file hash plain text để validate). Do đó, digest luôn readable, nhưng log files cần quyền decrypt từ KMS key để đọc. Đây là hành vi chuẩn theo tài liệu AWS (cập nhật đến 2024-2026, không thay đổi lớn ở phiên bản mới nhất).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: The KMS key policy does not grant the security engineer’s IAM user or role permissions to decrypt with it.

Lý do:

  • Log files được encrypt bằng SSE-KMS, yêu cầu quyền kms:Decrypt trên KMS key để đọc.
  • KMS key policy (chính sách khóa KMS) kiểm soát ai được decrypt. Nếu policy không grant quyền cho IAM user/role của security engineer, họ không thể decrypt → log files "không readable".
  • Digest files không encrypt, nên readable bình thường, khớp triệu chứng.
  • Đây là MOST likely vì SSE-KMS + integrity validation thường gặp issue quyền KMS khi test.

📋 Giải thích tất cả các phương án (đúng/sai)

  • ❌ The log files fail integrity validation and automatically are marked as unavailable.
    Sai vì: Nếu log files fail integrity validation (không match hash trong digest), CloudTrail sẽ báo lỗi validation khi check, nhưng không tự động mark unavailable hoặc làm chúng không readable. Digest vẫn readable, và log files vẫn có thể tải về (chỉ fail validate). Triệu chứng không khớp (digest readable chứng tỏ validation setup OK).

  • ✅ The KMS key policy does not grant the security engineer’s IAM user or role permissions to decrypt with it.
    Đúng vì: Như giải thích trên. KMS key policy là yếu tố quyết định quyền decrypt cho SSE-KMS objects. IAM user/role cần explicit kms:Decrypt trong key policy hoặc resource-based policy. Đây là nguyên nhân phổ biến nhất khi digest readable nhưng log không (xác nhận từ AWS best practices).

  • ❌ The bucket is set up to use server-side encryption with Amazon S3-managed keys (SSE-S3) as the default and does not allow SSE-KMS-encrypted files.
    Sai vì: CloudTrail override bucket default encryption khi specify SSE-KMS trong trail config → logs vẫn encrypt bằng KMS dù bucket default SSE-S3. S3 hỗ trợ cả SSE-S3 và SSE-KMS cùng lúc (không "không allow"). Nếu conflict, CloudTrail sẽ fail deliver logs hoàn toàn, không phải chỉ log files.

  • ❌ An IAM policy applicable to the security engineer’s IAM user or role denies access to the “CloudTrail/” prefix in the Amazon S3 bucket.
    Sai vì: Nếu IAM deny prefix "CloudTrail/", cả digest và log files (cùng prefix) đều không readable. Nhưng digest readable → chứng tỏ quyền S3 access OK (s3:GetObject). Vấn đề chỉ ở decrypt layer của KMS.

📘 Tài liệu tham khảo (AWS cập nhật mới nhất đến 2026)

🧑‍💻 Lời khuyên DevOps: Luôn attach kms:Decrypt cho CloudTrail service + IAM principals trong KMS key policy khi dùng SSE-KMS! Test bằng CLI: aws s3 cp s3://bucket/AWSLogs/... . --sse aws:kms --cli-read-timeout 0.

Câu 358
A company needs to securely deploy resources and workloads across AWS accounts. The accounts are in an organization in AWS Organizations.

The company needs to use AWS CloudFormation for infrastructure as code (IaC) management of approved architectural patterns. The company also must enforce tagging requirements and specific guidelines for resource and workload configuration and creation.

Which solution will meet these requirements?
  1. A Use CloudFormation stack policies to prevent the creation of resources that do not meet the tagging or configuration requirements. Use Amazon EventBridge rules to detect API calls that attempt to create resources outside of CloudFormation.
  2. B Use an AWS CodePipeline pipeline to test and deploy IaC defined workloads through CloudFormation into the accounts. Use AWS Config rules to enforce the tagging requirements. Apply an SCP to prevent the creation of misconfigured resources in all OUs.
  3. C Create an IAM permissions boundary to prevent the creation of misconfigured resources through CloudFormation and to enforce the tagging requirements. Apply the permissions boundary to all account roles. Use AWS Config rules to identify existing resources that are in a misconfigured state.
  4. D Use AWS Service Catalog with CloudFormation to manage access to approved architecture configurations. Provision Service Catalog portfolios to the accounts across the organization. Use AWS Config rules to enforce the tagging requirements and other resource configuration policies across accounts.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai an toàn tài nguyên và workload qua các AWS accounts trong AWS Organizations 📊. Công ty yêu cầu:

  • Sử dụng AWS CloudFormation cho Infrastructure as Code (IaC) để quản lý các architectural patterns đã được phê duyệt (approved patterns).
  • Buộc thực thi (enforce) các yêu cầu tagging (gắn thẻ tài nguyên) và hướng dẫn cụ thể về cấu hình/tạo tài nguyên/workload.
  • Giải pháp phải an toàn, tập trung và áp dụng cho toàn tổ chức (organization-wide), đảm bảo chỉ deploy những gì đã approve, đồng thời kiểm soát tagging/config liên tục.

Mục tiêu chính: Kết hợp IaC với governance để tránh tạo tài nguyên không chuẩn, sử dụng công cụ AWS phù hợp với best practices DevOps trong multi-account setup (cập nhật đến 2026: AWS Organizations hỗ trợ delegated admin cho Service Catalog, CloudFormation StackSets cho org-wide deployment). 🛡️

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use AWS Service Catalog with CloudFormation to manage access to approved architecture configurations. Provision Service Catalog portfolios to the accounts across the organization. Use AWS Config rules to enforce the tagging requirements and other resource configuration policies across accounts.

Lý do chọn đáp án này (dựa trên AWS best practices 2026):

  • AWS Service Catalog là dịch vụ lý tưởng để quản lý và phân phối portfolios chứa CloudFormation templates đã phê duyệt (approved IaC patterns), cho phép user chỉ deploy những kiến trúc chuẩn qua Products và Portfolios. Hỗ trợ provision cross-account/org qua delegated administration trong Organizations, đảm bảo governance tập trung. 🏗️
  • Provisioning portfolios đến các accounts tự động enforce access control (IAM roles, launch constraints cho tagging bắt buộc).
  • AWS Config rules bổ sung để enforce tagging và config policies (reactive + proactive), detect non-compliant resources và remediate tự động (qua Config Aggregator cho org-wide).
  • Giải pháp toàn diện, native AWS, không cần custom code, phù hợp DevOps Professional level. ✅

Tài liệu tham khảo:

📋 Phân tích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá đúng/sai với lý do cụ thể dựa trên tính khả thi, coverage và AWS limitations (2026 updates). ❌ cho sai, ✅ cho đúng.

  • Phương án 1: Use CloudFormation stack policies to prevent the creation of resources that do not meet the tagging or configuration requirements. Use Amazon EventBridge rules to detect API calls that attempt to create resources outside of CloudFormation.

    • ❌ Sai: CloudFormation stack policies chỉ protect stacks khỏi delete/update (không prevent creation hoặc enforce tagging/config trong template). EventBridge có thể detect API calls ngoài CFn, nhưng không prevent creation (chỉ notify/remediate sau), và không quản lý approved IaC patterns centrally. Không cover org-wide IaC governance. 🛑
  • Phương án 2: Use an AWS CodePipeline pipeline to test and deploy IaC defined workloads through CloudFormation into the accounts. Use AWS Config rules to enforce the tagging requirements. Apply an SCP to prevent the creation of misconfigured resources in all OUs.

    • ❌ Sai: CodePipeline tốt cho CI/CD, nhưng không quản lý access đến approved patterns (user vẫn tạo CFn stacks thủ công ngoài pipeline). AWS Config rules enforce tagging (tốt), nhưng SCP (Service Control Policies) chỉ deny actions ở mức coarse-grained (không granular cho config/tagging cụ thể, ví dụ không check resource props). Không prevent non-approved IaC. 🔧
  • Phương án 3: Create an IAM permissions boundary to prevent the creation of misconfigured resources through CloudFormation and to enforce the tagging requirements. Apply the permissions boundary to all account roles. Use AWS Config rules to identify existing resources that are in a misconfigured state.

    • ❌ Sai: IAM Permissions Boundary giới hạn max permissions cho roles/users, nhưng không enforce tagging hoặc config trong CFn templates (boundary chỉ control API calls, không validate template content). Config rules chỉ identify existing issues (reactive, không prevent). Không cover approved architectures hoặc org-wide IaC catalog. 👥
  • Phương án 4 (Đúng, như trên): Use AWS Service Catalog with CloudFormation to manage access to approved architecture configurations. Provision Service Catalog portfolios to the accounts across the organization. Use AWS Config rules to enforce the tagging requirements and other resource configuration policies across accounts.

    • ✅ Đúng: Hoàn hảo cover approved IaC via Service Catalog + CFn, provision org-wide, kết hợp Config cho continuous enforcement. Best practice cho multi-account governance! 🌟

Kết luận: Giải pháp đúng tận dụng Service Catalog làm "cửa hàng IaC approved" + Config cho compliance, đảm bảo secure deployment toàn tổ chức. Nếu deploy thực tế, dùng CloudFormation StackSets để scale portfolios. 🚀

Câu 359
A company is migrating its Amazon EC2 based applications to use Instance Metadata Service Version 2 (IMDSv2). A security engineer needs to determine whether any of the EC2 instances are still using Instance Metadata Service Version 1 (IMDSv1).

What should the security engineer do to confirm that the IMDSv1 endpoint is no longer being used?
  1. A Configure logging on the Amazon CloudWatch agent for IMDSv1 as part of EC2 instance startup. Create a metric filter and a CloudWatch dashboard. Track the metric in the dashboard.
  2. B Create an Amazon CloudWatch dashboard. Verify that the EC2:MetadataNoToken metric is zero across all EC2 instances. Monitor the dashboard.
  3. C Create a security group that blocks access to HTTP for the IMDSv1 endpoint. Attach the security group to all EC2 instances.
  4. D Configure user data scripts for all EC2 instances to send logging information to AWS CloudTrail when IMDSV1 is used. Create a metric filter and an Amazon CloudWatch dashboard. Track the metric in the dashboard.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào chủ đề bảo mật trên Amazon EC2, cụ thể là việc chuyển đổi từ Instance Metadata Service Version 1 (IMDSv1) sang Version 2 (IMDSv2). IMDSv1 sử dụng endpoint http://169.254.169.254/ mà không yêu cầu token, dễ bị tấn công SSRF (Server-Side Request Forgery). IMDSv2 yêu cầu token tạm thời, an toàn hơn. Công ty đang migrate ứng dụng EC2 sang IMDSv2, và security engineer cần xác nhận (confirm) rằng không còn instance nào sử dụng endpoint IMDSv1. Phương pháp phải chủ động giám sát mà không làm gián đoạn hoạt động, phù hợp với best practice AWS năm 2026 (IMDSv2 là mặc định cho instance mới từ 2022, và AWS khuyến nghị enforce qua Instance Metadata Options).

🛠️ Mục tiêu chính: Tìm cách kiểm tra và monitor việc sử dụng IMDSv1 một cách chính xác, không can thiệp trực tiếp vào instance.

✅ Đáp án đúng

Create an Amazon CloudWatch dashboard. Verify that the EC2:MetadataNoToken metric is zero across all EC2 instances. Monitor the dashboard.

Lý do chọn đáp án này (🧩 Phân tích chi tiết):
Metric EC2:MetadataNoToken là metric CloudWatch tích hợp sẵn của EC2 (có từ 2021, cập nhật 2026 vẫn hỗ trợ), đếm số lần truy cập IMDS không có token (tức IMDSv1). Nếu metric = 0 trên tất cả instance, chứng tỏ không còn sử dụng IMDSv1. Security engineer chỉ cần tạo CloudWatch dashboard để visualize và monitor metric này theo thời gian thực, dễ dàng xác nhận migrate thành công mà không cần agent hay script bổ sung. Đây là cách scaleable, non-intrusive nhất, phù hợp DevOps Professional.

📋 Phân tích tất cả các phương án

Dưới đây là phân tích từng lựa chọn một cách chi tiết. Tôi giữ nguyên văn bản gốc bằng tiếng Anh, đánh dấu ✅/❌, và giải thích hoàn toàn bằng tiếng Việt dựa trên tài liệu AWS mới nhất (2026).

  • ❌ Configure logging on the Amazon CloudWatch agent for IMDSv1 as part of EC2 instance startup. Create a metric filter and a CloudWatch dashboard. Track the metric in the dashboard.
    Sai vì: CloudWatch agent không hỗ trợ logging trực tiếp IMDSv1 một cách chuẩn (agent chủ yếu log file/system metrics, không capture metadata access tự động). Cần script custom phức tạp để log, nhưng không scaleable cho tất cả instance và có thể miss traffic. Metric filter chỉ hoạt động trên log group, không phải metric native như MetadataNoToken. Không phải best practice, tốn công config trên từng instance.

  • ✅ Create an Amazon CloudWatch dashboard. Verify that the EC2:MetadataNoToken metric is zero across all EC2 instances. Monitor the dashboard.
    Đúng vì: Như đã giải thích ở trên. Metric EC2:MetadataNoToken (Namespace: AWS/EC2, Dimension: InstanceId) là chuẩn AWS, tự động thu thập mà không cần agent. Dashboard cho phép aggregate cross-instance, alert nếu >0. Hoàn hảo để confirm migrate toàn bộ fleet.

  • ❌ Create a security group that blocks access to HTTP for the IMDSv1 endpoint. Attach the security group to all EC2 instances.
    Sai vì: Security group không block được IMDS vì IMDS là link-local (169.254.169.254), traffic internal hypervisor, không qua network interface. Block HTTP (port 80) chỉ ảnh hưởng external traffic. Phương pháp đúng để enforce là Instance Metadata Options (Hop Limit=1, Require IMDSv2) qua AWS Console/CLI/API, không phải SG. Có thể gây downtime nếu app chưa migrate.

  • ❌ Configure user data scripts for all EC2 instances to send logging information to AWS CloudTrail when IMDSV1 is used. Create a metric filter and an Amazon CloudWatch dashboard. Track the metric in the dashboard.
    Sai vì: CloudTrail log management/API calls, không capture IMDS access (IMDS là instance-local, không phải API call). User data script chỉ chạy lúc launch, không monitor runtime. Không thể detect IMDSv1 real-time, và gửi log giả định đến CloudTrail cần IAM role phức tạp + custom code, dễ lỗi và không scale. CloudTrail không phải tool cho metadata traffic.

📘 Tài liệu tham khảo (AWS Official Docs - Cập nhật 2026)

🛠️ Lời khuyên DevOps Pro: Để enforce vĩnh viễn, dùng AWS Organizations SCP hoặc Config Rule kiểm tra Instance Metadata Options = HttpTokens=required. Monitor dashboard + set alarm nếu metric >0! 🚀

Câu 360
A company is planning to create an organization by using AWS Organizations. The company needs to integrate user management with the company’s external identity provider (IdP). The company also needs to centrally manage access to all of its AWS accounts and applications from the organization’s management account.

Which solution will meet these requirements?
  1. A Configure AWS Directory Service with the external IdP. Create IAM policies and associate them with users from the external IdP.
  2. B Enable AWS IAM Identity Center and use the external IdP as the identity source. Create permission sets and account assignments by using IAM Identity Center.
  3. C Configure AWS Identity and Access Management (IAM) to use the external IdP as an IdP. Create IAM policies and associate them with users from the external IdP.
  4. D Enable Amazon Cognito in the organization’s management account. Create an identity pool and associate it with the external IdP. Create IAM roles and associate them with the identity pool.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc thiết lập AWS Organizations để quản lý tập trung nhiều tài khoản AWS. Công ty cần:

  • Tích hợp quản lý người dùng với external Identity Provider (IdP) bên ngoài (như Okta, Azure AD hoặc SAML/OIDC providers).
  • Quản lý truy cập tập trung vào tất cả các tài khoản AWS và ứng dụng từ management account (tài khoản gốc của organization).

Mục tiêu là giải pháp tập trung, đa tài khoản (multi-account), hỗ trợ federation từ external IdP, sử dụng permission sets và assignments để cấp quyền linh hoạt. Đây là yêu cầu điển hình cho zero-trust identity management trong AWS Organizations (cập nhật đến 2026, AWS khuyến nghị IAM Identity Center làm core solution).

📘 Tài liệu tham khảo:

✅ Đáp án đúng

Enable AWS IAM Identity Center and use the external IdP as the identity source. Create permission sets and account assignments by using IAM Identity Center.

Lý do chọn:

  • IAM Identity Center (tên mới của AWS SSO) là dịch vụ tập trung identity và access dành riêng cho AWS Organizations, cho phép kết nối external IdP (SAML 2.0/OIDC) làm identity source.
  • Từ management account, bạn tạo permission sets (bộ quyền IAM-like) và account assignments (gán quyền cho user/group vào account cụ thể), hỗ trợ quản lý hàng nghìn user/account mà không cần IAM user per account.
  • Hoàn hảo cho multi-account, scalable, tích hợp SCIM provisioning (cập nhật 2025-2026 hỗ trợ AI-driven access insights). Không cần tạo IAM user/role thủ công ở từng account.
    🛠️ Ưu điểm: Zero-effort federation, audit qua CloudTrail, tích hợp với AWS Access Analyzer.

📋 Phân tích tất cả các phương án

Dưới đây là giải thích chi tiết từng lựa chọn (giữ nguyên văn bản gốc). Tôi đánh dấu ✅/❌ và lý do dựa trên tính phù hợp với yêu cầu tập trung multi-account + external IdP.

  • Configure AWS Directory Service with the external IdP. Create IAM policies and associate them with users from the external IdP.
    ❌ Sai: AWS Directory Service (như Managed Microsoft AD) dùng cho on-premises directory sync, không hỗ trợ tập trung access multi-account trong Organizations. Nó không tích hợp trực tiếp external IdP cho AWS services, và việc tạo IAM policies thủ công per user không scalable/centralized từ management account. Phù hợp hơn cho EC2 domain join, không phải Organizations identity.

  • Enable AWS IAM Identity Center and use the external IdP as the identity source. Create permission sets and account assignments by using IAM Identity Center.
    ✅ Đúng: Như giải thích trên, đây là giải pháp chuẩn AWS (recommended best practice 2026). Hỗ trợ external IdP làm source, permission sets thay thế IAM policies, assignments cho multi-account từ management account.

  • Configure AWS Identity and Access Management (IAM) to use the external IdP as an IdP. Create IAM policies and associate them with users from the external IdP.
    ❌ Sai: IAM Identity Provider chỉ hỗ trợ federation vào MỘT account duy nhất (qua SAML/OIDC), không phải tập trung cho toàn Organizations. Bạn phải config IdP riêng ở từng account, không manage từ management account. IAM policies attach thủ công kém scalable cho multi-account.

  • Enable Amazon Cognito in the organization’s management account. Create an identity pool and associate it with the external IdP. Create IAM roles and associate them with the identity pool.
    ❌ Sai: Amazon Cognito dùng cho app/web/mobile authentication (user pools/identity pools), cấp temporary creds qua IAM roles cho AWS services từ apps, không phải quản lý truy cập AWS console/CLI tập trung multi-account. Không hỗ trợ permission sets hay Organizations-level assignments; chỉ phù hợp developer-facing apps.