Ngân hàng đề — AWS Certified Security Specialty

Tìm thấy 445 câu.

Câu 381
A company plans to create Amazon S3 buckets to store log data. All the S3 buckets will have versioning enabled and will use the S3 Standard storage class.

A security engineer needs to implement a solution that protects objects in the S3 buckets from deletion for 90 days. The solution must ensure that no object can be deleted during this time period, even by an administrator or the AWS account root user.

Which solution will meet these requirements?
  1. A Enable S3 Object Lock in governance mode. Set a legal hold of 90 days.
  2. B Enable S3 Object Lock in governance mode. Set a retention period of 90 days.
  3. C Enable S3 Object Lock in compliance mode. Set a retention period of 90 days.
  4. D Create an S3 Glacier Vault Lock policy that prevents deletion for 90 days.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc bảo vệ dữ liệu log trong các S3 bucket khỏi bị xóa trong 90 ngày, ngay cả bởi quản trị viên (administrator) hoặc AWS account root user. Các bucket đã bật versioning và sử dụng S3 Standard storage class.

Yêu cầu chính:

  • Phải ngăn chặn hoàn toàn việc xóa object (không có ngoại lệ).
  • Giải pháp phải không cho phép bypass bởi bất kỳ quyền cao nhất nào.
  • Đây là tình huống tuân thủ bảo mật nghiêm ngặt (compliance), thường dùng cho dữ liệu pháp lý hoặc kiểm toán.

🛠️ Công nghệ liên quan: S3 Object Lock là tính năng chính để "khóa" object, ngăn xóa hoặc ghi đè. Nó yêu cầu bucket phải có versioning enabled (đúng với mô tả). Object Lock có 2 chế độ: Governance (linh hoạt, có thể bypass) và Compliance (nghiêm ngặt, không bypass). Thời gian khóa dùng Retention period (có thời hạn cụ thể) hoặc Legal Hold (không thời hạn, phải thủ công gỡ).

✅ Đáp án đúng và lý do chọn

Đáp án đúng: Enable S3 Object Lock in compliance mode. Set a retention period of 90 days.

Lý do:

  • Compliance mode ✅: Đây là chế độ nghiêm ngặt nhất, khóa object vĩnh viễn không thể xóa hoặc sửa trong thời gian retention, kể cả root user hoặc admin có quyền đặc biệt. Không ai có thể bypass (trừ chờ hết hạn).
  • Retention period 90 days ✅: Đặt thời gian khóa chính xác 90 ngày, tự động hết hiệu lực sau đó.
  • Hoàn toàn phù hợp với S3 Standard + versioning. Đây là giải pháp chuẩn AWS cho yêu cầu "no object can be deleted... even by root user".
  • Cập nhật 2026: AWS vẫn giữ nguyên cơ chế này (không thay đổi lớn từ 2023-2026), hỗ trợ MFA Delete kết hợp nhưng Object Lock Compliance là tối ưu nhất.

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng lựa chọn một cách chi tiết, đánh dấu ✅/❌ rõ ràng:

  • ❌ Enable S3 Object Lock in governance mode. Set a legal hold of 90 days.
    Sai vì: Governance mode cho phép admin/root bypass bằng cách xóa policy hoặc dùng quyền đặc biệt (grant permissions to bypass governance). Legal Hold không hỗ trợ thời hạn 90 ngày cụ thể (nó là "hold vĩnh viễn" phải thủ công gỡ, không tự động hết hạn). Không đáp ứng "no deletion even by root".

  • ❌ Enable S3 Object Lock in governance mode. Set a retention period of 90 days.
    Sai vì: Governance mode vẫn cho phép bypass bởi admin/root (dùng s3:BypassGovernanceRetention permission). Dù retention 90 ngày đúng thời gian, nhưng không ngăn root user xóa ngay lập tức. Không đạt yêu cầu bảo vệ tuyệt đối.

  • ✅ Enable S3 Object Lock in compliance mode. Set a retention period of 90 days.
    Đúng vì: Compliance mode khóa tuyệt đối, không bypass được bởi bất kỳ ai (root/admin đều vô hiệu). Retention period đúng 90 ngày, tự động unlock sau. Bucket Standard + versioning hỗ trợ hoàn hảo. Giải pháp tối ưu và an toàn nhất.

  • ❌ Create an S3 Glacier Vault Lock policy that prevents deletion for 90 days.
    Sai vì: S3 Glacier Vault Lock chỉ áp dụng cho Amazon S3 Glacier (storage class Glacier), không phải S3 Standard. Vault Lock dùng cho vault toàn bộ, không phải object riêng lẻ. Bucket ở đây là Standard, không liên quan Glacier.

📘 Tài liệu tham khảo (AWS cập nhật mới nhất 2026)

💡 Lời khuyên DevOps: Trong thực tế, kết hợp với S3 Bucket Policies và MFA Delete để tăng lớp bảo vệ. Test bằng AWS CLI: aws s3api put-object-lock-configuration. Nếu cần script automation, dùng CDK/Terraform! 🚀

Câu 382
A company has used AWS Lambda functions to build an application on AWS. The company’s security engineer implemented Amazon Inspector and activated Lambda standard scanning and Lambda code scanning.

The security engineer reviews the Amazon Inspector console and learns that Amazon Inspector is not scanning some of the Lambda functions. The provided reason is that the scan eligibility expired.

What should the security engineer do to investigate the reason that the scans are failing?
  1. A Validate that the AmazonInspector2ServiceRolePolicy AWS managed policy grants permissions to access Lambda.
  2. B Increase the timeout value of the Lambda functions to complete the scans successfully while the code is running.
  3. C Build a custom runtime for the unscanned Lambda functions. Include the Amazon Inspector agent in the runtime.
  4. D Determine whether the unscanned Lambda functions have been invoked in the last 90 days.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh tình huống một công ty sử dụng AWS Lambda để xây dựng ứng dụng, và kỹ sư bảo mật đã triển khai Amazon Inspector với hai loại quét: Lambda standard scanning (quét tiêu chuẩn cho Lambda) và Lambda code scanning (quét mã nguồn Lambda). Khi kiểm tra console Amazon Inspector, kỹ sư phát hiện một số hàm Lambda không được quét, với lý do được cung cấp là "scan eligibility expired" (tính đủ điều kiện quét đã hết hạn).

📌 Vấn đề cốt lõi: Amazon Inspector yêu cầu các hàm Lambda phải đáp ứng điều kiện đủ điều kiện (eligibility) để được quét, đặc biệt với Lambda code scanning. Nếu không được invoke (gọi) trong một khoảng thời gian nhất định, hàm sẽ bị đánh dấu là hết hạn eligibility, dẫn đến không được quét. Câu hỏi yêu cầu hành động điều tra (investigate) lý do quét thất bại, dựa trên kiến thức AWS cập nhật đến năm 2026 (phiên bản Amazon Inspector hỗ trợ Lambda từ 2023, với quy tắc eligibility rõ ràng).

🛠️ Kiến thức liên quan: Theo tài liệu AWS mới nhất, Lambda code scanning chỉ áp dụng cho các hàm được invoke trong 90 ngày qua. Nếu hàm không hoạt động trong 90 ngày, nó sẽ ineligible và hiển thị lý do "scan eligibility expired". Standard scanning thì tự động hơn, nhưng code scanning có điều kiện này.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Determine whether the unscanned Lambda functions have been invoked in the last 90 days.

Lý do: Đây là bước điều tra đầu tiên và chính xác nhất để xác minh lý do "scan eligibility expired". Theo quy định của Amazon Inspector (cập nhật đến 2026), các hàm Lambda chỉ đủ điều kiện cho code scanning nếu chúng được invoke ít nhất một lần trong 90 ngày gần nhất. Nếu không, Inspector sẽ tự động loại trừ và hiển thị thông báo hết hạn. Kiểm tra lịch sử invoke qua CloudWatch Logs, Lambda console hoặc CloudTrail sẽ xác nhận vấn đề, giúp kỹ sư quyết định invoke thủ công hoặc loại bỏ hàm không dùng.

🔍 Giải thích tất cả các phương án (đúng/sai)

  • Validate that the AmazonInspector2ServiceRolePolicy AWS managed policy grants permissions to access Lambda.
    ❌ Sai: Phương án này tập trung vào quyền IAM (AmazonInspector2ServiceRolePolicy là policy managed cho Inspector), nhưng lý do "scan eligibility expired" không liên quan đến quyền truy cập. Nếu thiếu quyền, lỗi sẽ là "access denied" hoặc "permission error", không phải hết hạn eligibility. Inspector đã activate scanning, nên role đã đủ quyền cơ bản. Không cần validate ở đây vì không phải nguyên nhân gốc.

  • Increase the timeout value of the Lambda functions to complete the scans successfully while the code is running.
    ❌ Sai: Timeout của Lambda ảnh hưởng đến thời gian chạy hàm, không liên quan đến quá trình quét Inspector. Inspector quét mã nguồn và runtime độc lập, không chạy hàm để quét. Lý do hết hạn eligibility là do thiếu invoke 90 ngày, không phải timeout. Tăng timeout chỉ làm chậm chi phí, không giải quyết vấn đề.

  • Build a custom runtime for the unscanned Lambda functions. Include the Amazon Inspector agent in the runtime.
    ❌ Sai: Lambda không cần "Amazon Inspector agent" vì Inspector là dịch vụ serverless, quét tự động qua API mà không yêu cầu agent trong runtime. Custom runtime dùng cho ngôn ngữ đặc biệt, nhưng Inspector hỗ trợ tất cả runtime tiêu chuẩn (Node.js, Python, etc.) từ 2023. Đây là giải pháp thừa thãi, không điều tra mà cố fix sai lầm – không khớp với yêu cầu "investigate".

  • Determine whether the unscanned Lambda functions have been invoked in the last 90 days.
    ✅ Đúng: Như đã giải thích, đây chính là nguyên nhân trực tiếp của "scan eligibility expired". Kiểm tra qua Lambda metrics (Invocations trong CloudWatch), console Lambda > Monitoring, hoặc query CloudTrail sẽ xác nhận. Sau khi invoke (thủ công qua test event), hàm sẽ eligible lại trong lần quét tiếp theo (thường 24-48h). Hoàn hảo cho bước investigate!

🧩 Lời khuyên DevOps: Để tránh vấn đề, sử dụng CloudWatch Events/Scheduler để ping định kỳ các hàm idle, giữ eligibility. Theo best practice AWS 2026!

Câu 383
A security engineer received an Amazon GuardDuty alert indicating a finding involving the Amazon EC2 instance that hosts the company’s primary website. The GuardDuty finding received read:

UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration.

The security engineer confirmed that a malicious actor used API access keys intended for the EC2 instance from a country where the company does not operate. The security engineer needs to deny access to the malicious actor.

What is the first step the security engineer should take?
  1. A Open the EC2 console and remove any security groups that allow inbound traffic from 0.0.0.0/0.
  2. B Install the AWS Systems Manager Agent on the EC2 instance and run an inventory report.
  3. C Install the Amazon Inspector agent on the host and run an assessment with the CVE rules package.
  4. D Open the IAM console and revoke all IAM sessions that are associated with the instance profile.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh một tình huống bảo mật thực tế trên AWS: Một kỹ sư bảo mật nhận được cảnh báo từ Amazon GuardDuty với finding cụ thể là UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration. Finding này chỉ ra rằng có hành vi trích xuất trái phép credentials (API access keys) từ một EC2 instance đang host website chính của công ty. Kỹ sư xác nhận kẻ xấu đã sử dụng các API keys dành cho instance này từ một quốc gia mà công ty không hoạt động.
Mục tiêu chính: Kỹ sư cần ngăn chặn ngay lập tức truy cập của kẻ xấu (deny access to the malicious actor). Câu hỏi yêu cầu bước đầu tiên (first step) nên thực hiện.

🛠️ Bối cảnh kỹ thuật cập nhật (tính đến 2026): GuardDuty là dịch vụ giám sát liên tục, phát hiện các finding như exfiltration của IAM credentials từ instance profile (role gắn vào EC2). Credentials tạm thời (temporary credentials) từ instance metadata có thể bị đánh cắp và sử dụng qua API calls. Theo best practices AWS (AWS Security Best Practices và GuardDuty documentation), bước đầu tiên ưu tiên là invalidate ngay credentials bị compromise để giảm thiểu rủi ro lan rộng, trước khi điều tra sâu.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Open the IAM console and revoke all IAM sessions that are associated with the instance profile.

Lý do chi tiết:
Đây là bước đầu tiên ưu tiên nhất vì finding GuardDuty xác nhận credentials từ instance profile (IAM role gắn vào EC2) đã bị exfiltrated và sử dụng bởi kẻ xấu. Việc revoke all IAM sessions liên kết với instance profile sẽ invalidate ngay lập tức tất cả temporary security credentials đang active (bao gồm access keys bị đánh cắp). Điều này ngăn chặn kẻ xấu tiếp tục gọi API từ bất kỳ đâu, giảm thiểu thiệt hại nhanh chóng. AWS khuyến nghị hành động này đầu tiên trong remediation playbook cho finding này (theo GuardDuty console remediation actions, cập nhật 2025). Không cần chờ điều tra sâu, vì credentials instance profile tự động rotate sau ~6 giờ, nhưng revoke thủ công nhanh hơn và toàn diện.

📋 Phân tích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn một cách chi tiết, giữ nguyên nội dung văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá dựa trên tính phù hợp với first step để deny access ngay lập tức.

  • Open the EC2 console and remove any security groups that allow inbound traffic from 0.0.0.0/0.
    ❌ Sai: Phương án này chỉ xử lý network access (SSH/RDP inbound) qua Security Groups, không liên quan đến vấn đề API credentials exfiltration. Kẻ xấu đang sử dụng API keys qua HTTPS (port 443), không cần inbound traffic đến instance. Hành động này không invalidate credentials, nên kẻ xấu vẫn gọi API được. (Không phải remediation cho GuardDuty finding này).

  • Install the AWS Systems Manager Agent on the EC2 instance and run an inventory report.
    ❌ Sai: AWS Systems Manager (SSM) Agent dùng để quản lý inventory, patch, hoặc remote commands, nhưng không trực tiếp deny access credentials. Inventory report chỉ thu thập thông tin phần mềm/hardware sau sự việc, không phải first step để chặn kẻ xấu ngay. Điều này làm chậm quá trình response và không giải quyết exfiltration IAM.

  • Install the Amazon Inspector agent on the host and run an assessment with the CVE rules package.
    ❌ Sai: Amazon Inspector (nay là AWS Inspector, cập nhật 2025) dùng để scan vulnerabilities (CVE) trên instance, hữu ích cho điều tra sau nhưng không phải first step deny access. Nó không revoke credentials hay chặn API calls từ kẻ xấu. Remediation GuardDuty ưu tiên credential revocation trước vulnerability scanning.

  • Open the IAM console and revoke all IAM sessions that are associated with the instance profile.
    ✅ Đúng: Như đã giải thích ở trên, đây là hành động tức thì và hiệu quả nhất, trực tiếp vô hiệu hóa sessions/credentials từ instance profile. AWS IAM console hỗ trợ revoke sessions qua "IAM console > Roles > [Instance Role] > Sessions tab > Revoke". Giảm risk diffusion cao nhất theo Security Pillar.

🛡️ Khuyến nghị bổ sung: Sau first step, tiếp tục với: Rotate instance profile role, scan logs CloudTrail, block IP qua WAF/NACL nếu cần, và enable MFA/least privilege. Luôn test trong môi trường staging trước production!

Câu 384
A company is testing incident response procedures for destination containment. The company needs to contain a critical Amazon EC2 instance as quickly as possible while keeping the EC2 instance running. The EC2 instance is the only resource in a public subnet and has active connections to other resources.

Which solution will contain the EC2 instance IMMEDIATELY?
  1. A Create a new security group that has no inbound rules or outbound rules. Attach the new security group to the EC2 instance.
  2. B Configure the existing security group for the EC2 instance. Remove all existing inbound rules and outbound rules from the security group.
  3. C Create a new network ACL that has a single Deny rule for inbound traffic and outbound traffic. Associate the new network ACL with the subnet that contains the EC2 instance.
  4. D Create a new VPC for isolation. Stop the EC2 instance. Create a new AMI from the EC2 instance. Use the new AMI to launch a new EC2 instance in the new VPC.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào quy trình phản ứng sự cố (incident response) trong AWS, cụ thể là containment (ngăn chặn lan rộng) cho một Amazon EC2 instance critical. 🛡️️

  • Tình huống:

    • EC2 instance là tài nguyên duy nhất trong một public subnet.
    • Instance đang chạy và có active connections (kết nối đang hoạt động) đến các tài nguyên khác.
    • Mục tiêu: Contain (cách ly) instance NGAY LẬP TỨC (IMMEDIATELY), giữ instance tiếp tục chạy (không stop hoặc terminate), tránh ảnh hưởng đến các kết nối hiện tại nhưng chặn lan rộng rủi ro (ví dụ: malware hoặc tấn công).
  • Thách thức chính:

    • Cần giải pháp tác động ngay lập tức (không delay do propagation hoặc stateful behavior).
    • Phải block tất cả inbound/outbound traffic mà không làm gián đoạn việc instance chạy.
    • Public subnet ngụ ý có thể tiếp xúc internet qua Internet Gateway (IGW), cần chặn tại layer mạng thấp nhất.

Kiến thức AWS cập nhật đến 2026: Security Groups (SG) là stateful (duy trì trạng thái kết nối hiện tại, existing flows continue ngay cả khi rules thay đổi). Network ACLs (NACL) là stateless (kiểm tra mọi packet độc lập, block ngay lập tức kể cả existing connections). Đây là best practice cho immediate containment trong AWS Incident Response (theo AWS Security Incident Response Guide).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create a new network ACL that has a single Deny rule for inbound traffic and outbound traffic. Associate the new network ACL with the subnet that contains the EC2 instance.

Lý do chi tiết:

  • 🛡️ NACL hoạt động ngay lập tức: NACL là stateless firewall tại subnet level, áp dụng cho tất cả traffic (inbound/outbound) của instance. Tạo NACL mới với rule Deny all (lowest precedence, rule #*) sẽ block mọi packet ngay lập tức, kể cả existing connections (vì không track state).
  • 🏃‍♂️ Instance vẫn chạy: Không ảnh hưởng EBS, CPU, memory – chỉ chặn mạng.
  • 🎯 Phù hợp tình huống: Subnet chỉ có 1 instance → ảnh hưởng cục bộ. Associate NACL mới với subnet → thay thế NACL mặc định (allow all).
  • 🚀 Immediate: Changes propagate trong giây lát (stateless evaluation per packet).
  • Theo AWS best practice 2026: Sử dụng NACL cho zero-trust containment trong IR (không phụ thuộc SG stateful).

📋 Giải thích tất cả các phương án (đúng/sai)

  • ✅ [ĐÚNG] Create a new network ACL that has a single Deny rule for inbound traffic and outbound traffic. Associate the new network ACL with the subnet that contains the EC2 instance.
    Như đã giải thích ở trên: Stateless Deny all block ngay lập tức mọi traffic, instance chạy bình thường. Hoàn hảo cho containment mà không gián đoạn hoạt động.

  • ❌ [SAI] Create a new security group that has no inbound rules or outbound rules. Attach the new security group to the EC2 instance.
    Lý do sai: Security Group (SG) chỉ có implicit deny (không rules = deny new connections), nhưng stateful → existing connections tiếp tục hoạt động (return traffic được allow tự động). Không "immediate" block active connections. Attach SG mới vẫn không chặn ngay (state table của ENI giữ state cũ vài phút).

  • ❌ [SAI] Configure the existing security group for the EC2 instance. Remove all existing inbound rules and outbound rules from the security group.
    Lý do sai: Tương tự trên, SG stateful → remove rules chỉ chặn new connections, active connections vẫn flow (stateful inspection). Propagation SG ~60s+, không immediate. Không an toàn vì có thể để sót rules.

  • ❌ [SAI] Create a new VPC for isolation. Stop the EC2 instance. Create a new AMI from the EC2 instance. Use the new AMI to launch a new EC2 instance in the new VPC.
    Lý do sai: Không immediate (tạo VPC, stop instance, tạo AMI, launch new → mất phút đến giờ). Stop instance vi phạm yêu cầu "keep running". Phức tạp, rủi ro data loss, không phải containment (mà là recovery).

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm case study, hỏi nhé! 😊

Câu 385
A company needs to use HTTPS when connecting to its web applications to meet compliance requirements. These web applications run in Amazon VPC on Amazon EC2 instances behind an Application Load Balancer (ALB). A security engineer wants to ensure that the load balancer will only accept connections over port 443, even if the ALB is mistakenly configured with an HTTP listener.

Which configuration steps should the security engineer take to accomplish this task?
  1. A Create a security group with a rule that denies inbound connections from 0.0.0.0/0 on port 80. Attach this security group to the ALB to overwrite more permissive rules from the ALB’s default security group.
  2. B Create a network ACL that denies inbound connections from 0.0.0.0/0 on port 80. Associate the network ACL with the VPC’s internet gateway.
  3. C Create a network ACL that allows outbound connections to the VPC IP range on port 443 only. Associate the network ACL with the VPC’s internet gateway.
  4. D Create a security group with a single inbound rule that allows connections from 0.0.0.0/0 on port 443. Ensure this security group is the only one associated with the ALB.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh yêu cầu bảo mật trong AWS: Một công ty cần chỉ sử dụng HTTPS (port 443) để kết nối với các web application chạy trên EC2 instances trong Amazon VPC, phía sau Application Load Balancer (ALB). Kỹ sư bảo mật muốn ngăn chặn hoàn toàn các kết nối qua port 80 (HTTP) đến ALB, ngay cả khi ALB bị cấu hình sai (ví dụ: thêm HTTP listener trên port 80).

📌 Mục tiêu chính: Sử dụng Security Group (SG) hoặc Network ACL (NACL) để chặn traffic port 80 tại lớp mạng, đảm bảo chỉ port 443 được chấp nhận từ internet (0.0.0.0/0). Lưu ý:

  • ALB listeners chỉ xử lý traffic đã qua Security Group (lớp đầu tiên kiểm tra).
  • Security Groups là stateful (cho phép return traffic tự động), implicit deny (chỉ allow những gì chỉ định).
  • NACLs là stateless (phải allow cả inbound/outbound), hoạt động tại subnet level.
  • Kiến thức cập nhật đến 2026: ALB hỗ trợ TLS termination, SG vẫn là cách chính để kiểm soát traffic đến ENI của ALB (theo AWS Well-Architected Framework Security Pillar).

Thách thức: Nếu ALB có HTTP listener sai, traffic port 80 vẫn có thể đến nếu SG cho phép. Giải pháp phải block tại SG level trước listener.

✅ Đáp án đúng

Create a security group with a single inbound rule that allows connections from 0.0.0.0/0 on port 443. Ensure this security group is the only one associated with the ALB.

Lý do chọn đáp án này 🛡️:

  • Security Group của ALB kiểm tra traffic inbound đầu tiên trước khi đến listener.
  • Với quy tắc inbound duy nhất: allow 443 từ 0.0.0.0/0, mọi traffic port 80 sẽ bị implicit deny (SG không có quy tắc allow port 80).
  • Chỉ attach 1 SG này (không multiple SG), tránh union rules cho phép port 80 từ SG khác.
  • Ngay cả HTTP listener tồn tại, traffic port 80 không đến được listener vì SG block.
  • Hiệu quả cao, stateful nên response HTTPS tự động allow outbound.

❌ Giải thích tất cả các phương án

  • Phương án 1 (SAI):
    Create a security group with a rule that denies inbound connections from 0.0.0.0/0 on port 80. Attach this security group to the ALB to overwrite more permissive rules from the ALB’s default security group.
    Lý do sai ❌: Security Groups không hỗ trợ explicit deny rules (chỉ implicit deny). Multiple SG attach vào ALB là union (OR), không "overwrite" – nếu SG khác allow port 80, traffic vẫn qua. Không giải quyết được config sai listener.

  • Phương án 2 (SAI):
    Create a network ACL that denies inbound connections from 0.0.0.0/0 on port 80. Associate the network ACL with the VPC’s internet gateway.
    Lý do sai ❌: NACL associate với subnets, không phải Internet Gateway (IGW) trực tiếp. IGW chỉ route traffic, không có NACL riêng. NACL stateless cần rule outbound tương ứng, và không block hiệu quả bằng SG tại ALB ENI.

  • Phương án 3 (SAI):
    Create a network ACL that allows outbound connections to the VPC IP range on port 443 only. Associate the network ACL with the VPC’s internet gateway.
    Lý do sai ❌: Tập trung outbound (không liên quan đến inbound từ internet). "To VPC IP range" không chặn port 80 inbound. Associate với IGW không khả thi, và không ngăn traffic đến ALB port 80.

  • Phương án 4 (ĐÚNG):
    Create a security group with a single inbound rule that allows connections from 0.0.0.0/0 on port 443. Ensure this security group is the only one associated with the ALB.
    Lý do đúng ✅: Như giải thích ở trên – SG đơn giản, hiệu quả nhất để enforce HTTPS-only, block port 80 implicit dù listener sai.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Kết luận 🎯: Sử dụng SG chỉ allow 443 là best practice cho ALB HTTPS enforcement! Nếu cần lab, dùng AWS Console tạo SG và test với curl.

Câu 386
A consultant agency needs to perform a security audit for a company’s production AWS account. Several consultants need access to the account. The consultant agency already has its own AWS account.

The company requires multi-factor authentication (MFA) for all access to its production account. The company also forbids the use of long-term credentials.

Which solution will provide the consultant agency with access that meets these requirements?
  1. A Create an IAM group. Create an IAM user for each consultant. Add each user to the group. Turn on MFA for each consultant.
  2. B Configure Amazon Cognito on the company’s production account to authenticate against the consultant agency’s identity provider (IdP). Add MFA to a Cognito user pool.
  3. C Create an IAM role in the consultant agency’s AWS account. Define a trust policy that requires MFA. In the trust policy, specify the company’s production account as the principal. Attach the trust policy to the role.
  4. D Create an IAM role in the company’s production account. Define a trust policy that requires MFA. In the trust policy, specify the consultant agency’s AWS account as the principal. Attach the trust policy to the role.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh bảo mật truy cập AWS trong kịch bản thực tế: Một công ty có tài khoản AWS production cần agency tư vấn thực hiện audit bảo mật. Agency đã có tài khoản AWS riêng. Yêu cầu chính của công ty:

  • Tất cả truy cập vào production account phải dùng MFA (Multi-Factor Authentication).
  • Cấm sử dụng long-term credentials (như access keys lâu dài của IAM users, vì chúng không an toàn và dễ bị lộ).

Mục tiêu: Cung cấp quyền truy cập cho consultants của agency mà không vi phạm quy định, nghĩa là phải dùng short-term credentials (tạm thời, qua STS AssumeRole) và buộc MFA. Giải pháp lý tưởng là cross-account role assumption (agency account assume role từ production account), tận dụng IAM Roles để ủy quyền tạm thời.

Đây là kiến thức cốt lõi trong AWS IAM (Identity and Access Management) phiên bản mới nhất (2026), nhấn mạnh least privilege và zero trust với MFA serial (MFA-conditional access).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create an IAM role in the company’s production account. Define a trust policy that requires MFA. In the trust policy, specify the consultant agency’s AWS account as the principal. Attach the trust policy to the role.

Lý do 🛠️:

  • Tạo IAM Role trong production account (của công ty) – nơi cần bảo vệ.
  • Trust policy chỉ định principal là AWS account của agency (cross-account trust), cho phép users/roles từ agency assume role này.
  • Require MFA trong trust policy: Sử dụng điều kiện aws:MultiFactorAuthPresent hoặc aws:MultiFactorAuthAge, đảm bảo MFA bắt buộc khi assume role → tạo temporary credentials (qua STS AssumeRole, hết hạn sau 1 giờ mặc định).
  • Không cần tạo users/access keys lâu dài → Tuân thủ no long-term credentials.
  • Consultants chỉ cần login agency account (với MFA), rồi assume role → An toàn, kiểm soát được (công ty quản lý permissions trong role policy).

📋 Giải thích tất cả các phương án

  • Phương án 1 ❌: Create an IAM group. Create an IAM user for each consultant. Add each user to the group. Turn on MFA for each consultant.
    Sai vì: Tạo IAM users trực tiếp trong production account → Yêu cầu long-term credentials (access keys/secrets), vi phạm quy định cấm. MFA chỉ bảo vệ console login, nhưng vẫn lộ credentials lâu dài nếu consultants dùng CLI/SDK. Không tận dụng cross-account, agency mất kiểm soát users.

  • Phương án 2 ❌: Configure Amazon Cognito on the company’s production account to authenticate against the consultant agency’s identity provider (IdP). Add MFA to a Cognito user pool.
    Sai vì: Cognito dành cho app/web authentication (user pools với OIDC/SAML), không phù hợp cross-account AWS console/CLI access. Không hỗ trợ native STS AssumeRole cho IAM actions. Agency IdP chưa được xác nhận là SAML/OIDC chuẩn, và MFA Cognito không thay thế IAM MFA serial. Phức tạp, không meet yêu cầu AWS-native access.

  • Phương án 3 ❌: Create an IAM role in the consultant agency’s AWS account. Define a trust policy that requires MFA. In the trust policy, specify the company’s production account as the principal. Attach the trust policy to the role.
    Sai vì: Chiều trust ngược – Role trong agency account, principal là production account → Production account phải assume role của agency (không logic, agency không kiểm soát được). Không cấp quyền vào production account. MFA ở đây vô ích vì consultants không assume từ production.

  • Phương án 4 ✅: Create an IAM role in the company’s production account. Define a trust policy that requires MFA. In the trust policy, specify the consultant agency’s AWS account as the principal. Attach the trust policy to the role.
    Đúng vì (như giải thích ở trên): Hoàn hảo cho cross-account access với MFA-conditional, temporary creds. Consultants dùng lệnh aws sts assume-role từ agency account.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

  • IAM Roles cross-account: AWS IAM User Guide - Roles – Trust policy ví dụ với Principal: {"AWS": "arn:aws:iam::AGENCY-ACCOUNT:root"} và MFA condition.
  • Require MFA in trust policies: STS AssumeRole MFA – mfa_serial parameter.
  • Best practices no long-term creds: AWS Security Best Practices – Pillar 1: Implement strong identity foundation.
  • Exam tip DOP-C02: Chủ đề IAM Federation & MFA thường xuất hiện trong DevOps Professional.

Giải pháp này zero-trust compliant, dễ audit logs qua CloudTrail! 🚀

Câu 387 Chọn nhiều đáp án
A company uses AWS Lambda functions to implement application logic. The company uses an organization in AWS Organizations to manage hundreds of AWS accounts.

The company needs to implement a solution to continuously monitor the Lambda functions for vulnerabilities in all accounts. The solution must publish detected issues to a dashboard. Lambda functions that are being tested or are in development must not appear on the dashboard.

Which combination of steps will meet these requirements? (Choose two.)
  1. A Designate a delegated Amazon GuardDuty administrator account in the organization’s management account. Use the GuardDuty Summary dashboard to obtain an overview of Lambda functions that have vulnerabilities.
  2. B Designate a delegated Amazon Inspector administrator account in the organization’s management account. Use the Amazon Inspector dashboard to obtain an overview of Lambda functions that have vulnerabilities.
  3. C Apply tags of “test” or “development” to all Lambda functions that are in testing or development. Use a suppression filter that suppresses findings that contain these tags.
  4. D Enable AWS Shield Advanced in the organization’s management account. Use Amazon CloudWatch to build a dashboard for Lambda functions that have vulnerabilities.
  5. E Enable Lambda Protection in GuardDuty for all accounts. Auto-enable Lambda Protection for new accounts. Apply a tag to the Lambda functions that are in testing or development. Use GuardDutyExclusion as the tag key and LambdaStandardScanning as the tag value.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai giải pháp giám sát liên tục các hàm AWS Lambda để phát hiện lỗ hổng bảo mật (vulnerabilities) trong hàng trăm tài khoản AWS được quản lý bởi AWS Organizations. 🛡️️

  • Yêu cầu chính:

    • Giám sát tất cả Lambda functions trong toàn bộ tổ chức (organization-wide).
    • Publish kết quả phát hiện lên một dashboard để tổng quan.
    • Loại trừ (không hiển thị) các Lambda đang ở giai đoạn testing hoặc development trên dashboard.
  • Bối cảnh: Công ty sử dụng Lambda cho logic ứng dụng, cần giải pháp tự động, liên tục và tích hợp Organizations để tránh quản lý thủ công từng account. Giải pháp phải chọn 2 bước kết hợp (combination of steps).

  • Thách thức kỹ thuật:

    • Cần dịch vụ scanning vulnerabilities chuyên cho Lambda (không phải threats chung).
    • Hỗ trợ delegated admin cho multi-account.
    • Cơ chế filter/suppression dựa trên tags để loại trừ test/dev.

Dựa trên kiến thức AWS cập nhật đến 2026 (AWS Inspector v2 hỗ trợ Lambda scanning đầy đủ từ 2023, tích hợp Organizations delegated admin, suppression rules linh hoạt). 📘

✅ Đáp án đúng (Chọn 2)

Hai bước đúng là:

  1. Designate a delegated Amazon Inspector administrator account in the organization’s management account. Use the Amazon Inspector dashboard to obtain an overview of Lambda functions that have vulnerabilities.
  2. Apply tags of “test” or “development” to all Lambda functions that are in testing or development. Use a suppression filter that suppresses findings that contain these tags.

Lý do lựa chọn:

  • Amazon Inspector là dịch vụ chuẩn để scan software vulnerabilities và network issues cho Lambda functions (hỗ trợ runtime analysis, package vulnerabilities như CVEs). ✅
  • Delegated admin từ management account cho phép centralized scanning toàn Organizations, auto-enable cho new accounts. Dashboard Inspector cung cấp overview findings real-time, filterable. 🛠️
  • Tags + suppression filter (trong Inspector rules) loại trừ chính xác Lambda test/dev, tránh noise trên dashboard. Giải pháp này liên tục (continuous) và scale cho hundreds accounts. 🚀

Dẫn nguồn:

📋 Phân tích tất cả các phương án

Dưới đây là phân tích từng lựa chọn một, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá ✅ (đúng) hoặc ❌ (sai), kèm giải thích chi tiết bằng tiếng Việt.

  • Designate a delegated Amazon GuardDuty administrator account in the organization’s management account. Use the GuardDuty Summary dashboard to obtain an overview of Lambda functions that have vulnerabilities.
    ❌ Sai: GuardDuty không scan vulnerabilities (như CVEs trong packages/code) cho Lambda. GuardDuty Lambda Protection (ra mắt 2024) chỉ detect threats (malware, crypto-mining, reconnaissance) tại runtime, không phải vulnerabilities tĩnh. Summary dashboard GuardDuty không overview vulnerabilities Lambda. Không phù hợp yêu cầu. 🛑
    Nguồn: GuardDuty Lambda Protection Docs.

  • Designate a delegated Amazon Inspector administrator account in the organization’s management account. Use the Amazon Inspector dashboard to obtain an overview of Lambda functions that have vulnerabilities.
    ✅ Đúng: Inspector delegated admin cho phép management account quản lý scanning toàn Organizations. Dashboard Inspector hiển thị tổng quan findings (vulnerabilities Lambda, severity, affected functions). Hỗ trợ continuous scanning, perfect cho multi-account. 🏆
    Nguồn: Như trên.

  • Apply tags of “test” or “development” to all Lambda functions that are in testing or development. Use a suppression filter that suppresses findings that contain these tags.
    ✅ Đúng: Tags này dễ apply qua resource tagging policies. Inspector hỗ trợ suppression rules dựa trên tags (resource tags), tự động ẩn findings từ test/dev Lambda trên dashboard. Kết hợp với delegated admin để filter organization-wide. 🎯
    Nguồn: Inspector Suppression Docs.

  • Enable AWS Shield Advanced in the organization’s management account. Use Amazon CloudWatch to build a dashboard for Lambda functions that have vulnerabilities.
    ❌ Sai: AWS Shield Advanced chỉ bảo vệ DDoS attacks, không scan vulnerabilities Lambda. CloudWatch chỉ metrics/logs, phải build dashboard thủ công (không continuous scanning vulnerabilities). Không hỗ trợ Organizations delegated cho việc này. Hoàn toàn không liên quan. 🚫
    Nguồn: Shield Advanced Docs.

  • Enable Lambda Protection in GuardDuty for all accounts. Auto-enable Lambda Protection for new accounts. Apply a tag to the Lambda functions that are in testing or development. Use GuardDutyExclusion as the tag key and LambdaStandardScanning as the tag value.
    ❌ Sai: GuardDuty Lambda Protection detect threats, không phải vulnerabilities. Tag format "GuardDutyExclusion" không tồn tại chuẩn cho suppression Lambda vulnerabilities (GuardDuty suppression khác, không tag-based như vậy). Không có dashboard overview vulnerabilities. Sai cả kỹ thuật và format. 🔒
    Nguồn: GuardDuty Suppression Docs (không hỗ trợ tag LambdaStandardScanning).

Tóm tắt: Kết hợp Inspector delegated admin + tags suppression là giải pháp optimal, native AWS, scale cho Organizations lớn. Không cần custom tooling! 🌟

Câu 388
A company has an organization in AWS Organizations that includes dedicated accounts for each of its business units. The company is collecting all AWS CloudTrail logs from the accounts in a single Amazon S3 bucket in the top-level account. The company’s IT governance team has access to the top-level account. A security engineer needs to allow each business unit to access its own CloudTrail logs.

The security engineer creates an IAM role in the top-level account for each of the other accounts. For each role, the security engineer creates an IAM policy to allow read-only permissions to objects in the S3 bucket with the prefix of the respective logs.

Which action must the security engineer take in each business unit account to allow an IAM user in that account to read the logs?
  1. A Attach a policy to the IAM user to allow the user to assume the role that was created in the top-level account. Specify the role’s ARN in the policy.
  2. B Create an SCP that grants permissions to the top-level account.
  3. C Use the root account of the business unit account to assume the role that was created in the top-level account. Specify the role’s ARN in the policy.
  4. D Forward the credentials of the IAM role in the top-level account to the IAM user in the business unit account.
Xem giải thích

🧩 Giải thích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh việc quản lý quyền truy cập cross-account trong AWS Organizations 📘. Một công ty có tổ chức AWS Organizations với các tài khoản riêng cho từng business unit (BU). Tất cả CloudTrail logs từ các tài khoản được tập trung vào một S3 bucket duy nhất ở top-level account (tài khoản quản lý tổ chức). Đội ngũ IT governance có quyền truy cập top-level account.

Security engineer đã tạo IAM role ở top-level account cho từng BU account khác, và gắn IAM policy cho mỗi role chỉ cho phép read-only các object trong S3 bucket với prefix logs tương ứng của BU đó.

Mục tiêu: Cho phép IAM user ở mỗi BU account có thể đọc logs của chính BU mình (không đọc logs BU khác).

Vấn đề cần giải quyết: Làm gì trong từng BU account để IAM user đó có thể assume role cross-account từ top-level account và truy cập S3 logs? 🛠️

(Lưu ý: Để cross-account access hoạt động, IAM role ở top-level phải có trust policy cho phép principal từ BU account assume role – giả sử đã cấu hình đúng theo best practice AWS.)

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Attach a policy to the IAM user to allow the user to assume the role that was created in the top-level account. Specify the role’s ARN in the policy.

Lý do 🟢:

  • Đây là cách chuẩn cross-account role assumption trong AWS IAM. IAM user ở BU account cần một IAM policy cho phép action sts:AssumeRole với role ARN cụ thể ở top-level account.
  • Sau khi assume role (qua AWS CLI/SDK: aws sts assume-role), user nhận temporary credentials để read S3 objects theo prefix.
  • An toàn, tuân thủ least privilege, và hỗ trợ MFA/conditions nếu cần. Phù hợp với AWS Organizations delegated administration và CloudTrail aggregated trails (cập nhật đến 2026, không thay đổi cơ bản).

📋 Phân tích tất cả các phương án (đúng/sai)

  • Attach a policy to the IAM user to allow the user to assume the role that was created in the top-level account. Specify the role’s ARN in the policy.
    ✅ Đúng 🟢: Như giải thích trên, policy mẫu:

    {
      "Version": "2012-10-17",
      "Statement": [{
        "Effect": "Allow",
        "Action": "sts:AssumeRole",
        "Resource": "arn:aws:iam::TOP-ACCOUNT-ID:role/BU-Role-Name"
      }]
    }
    

    User assume role → temporary creds → read S3. Hoàn hảo cho scenario!

  • Create an SCP that grants permissions to the top-level account.
    ❌ Sai 🔴: SCP (Service Control Policy) ở AWS Organizations chỉ giới hạn permissions cho accounts con (không grant quyền mới). SCP không thể cho phép assume role cross-account từ BU lên top-level, và không áp dụng trực tiếp cho IAM user cụ thể. SCP chỉ ảnh hưởng Organizations level, không thay thế IAM policy.

  • Use the root account of the business unit account to assume the role that was created in the top-level account. Specify the role’s ARN in the policy.
    ❌ Sai 🔴: Root account không nên dùng cho operations hàng ngày (AWS best practice: bảo mật cao, chỉ dùng cho ít việc). Root không có policy gắn trực tiếp như IAM user, và "specify ARN in policy" không khả thi vì root không attach policy. Dẫn đến rủi ro bảo mật lớn!

  • Forward the credentials of the IAM role in the top-level account to the IAM user in the business unit account.
    ❌ Sai 🔴: Không an toàn và không phải cách AWS recommend! Forward long-term creds vi phạm nguyên tắc temporary credentials. Dễ bị leak, không hỗ trợ audit (CloudTrail), và trái với IAM best practices (luôn dùng AssumeRole cho cross-account).

📚 Tài liệu tham khảo (AWS cập nhật đến 2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần ví dụ code Terraform/CLI, hỏi thêm nhé!

Câu 389
A company has configured an organization in AWS Organizations for its AWS accounts. AWS CloudTrail is enabled in all AWS Regions.

A security engineer must implement a solution to prevent CloudTrail from being disabled.

Which solution will meet this requirement?
  1. A Enable CloudTrail log file integrity validation from the organization’s management account.
  2. B Enable server-side encryption with AWS KMS keys (SSE-KMS) for CloudTrail logs. Create a KMS key. Attach a policy to the key to prevent decryption of the logs.
  3. C Create an SCP that includes an explicit Deny rule for the StopLogging action and the DeleteTrail action. Attach the SCP to the root OU.
  4. D Create IAM policies for all the company’s users to prevent the users from performing the DescribeTrails action and the GetTrailStatus action.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh việc bảo vệ CloudTrail khỏi bị tắt (disabled) trong một tổ chức AWS Organizations. Cụ thể:

  • Công ty đã thiết lập AWS Organizations cho các tài khoản AWS.
  • CloudTrail đã được kích hoạt ở tất cả các Region.
  • Yêu cầu của security engineer: Implement giải pháp ngăn chặn việc tắt CloudTrail (prevent CloudTrail from being disabled).

📘 Mục tiêu chính: CloudTrail có thể bị tắt bằng các action như StopLogging (dừng ghi log) hoặc DeleteTrail (xóa trail). Giải pháp phải áp dụng ở mức tổ chức (organization-wide), không chỉ IAM user cụ thể, và sử dụng cơ chế phòng thủ mạnh mẽ nhất theo best practices AWS (cập nhật đến 2026: AWS Organizations SCP vẫn là công cụ chính để enforce policy ở level account/OU).

Tham khảo tài liệu AWS mới nhất:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create an SCP that includes an explicit Deny rule for the StopLogging action and the DeleteTrail action. Attach the SCP to the root OU.

Lý do chọn đáp án này 🛠️:

  • SCP (Service Control Policy) trong AWS Organizations là cơ chế deny-based mạnh mẽ nhất, áp dụng cho tất cả principal (users/roles) trong OU/account con, ngay cả management account (trừ root user ở một số trường hợp, nhưng deny explicit vẫn block).
  • Explicit Deny cho cloudtrail:StopLogging và cloudtrail:DeleteTrail hoàn toàn ngăn chặn việc tắt hoặc xóa trail ở tất cả accounts dưới root OU (áp dụng organization-wide).
  • Attach vào root OU đảm bảo phủ sóng toàn bộ tổ chức, phù hợp yêu cầu prevent disable ở tất cả regions/accounts.
  • Đây là best practice theo AWS (không có thay đổi đến 2026; SCP vẫn ưu tiên hơn IAM cho guardrails tổ chức).

📋 Phân tích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng phương án một cách chi tiết, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá ✅ (đúng) hoặc ❌ (sai), kèm giải thích rõ ràng tại sao:

  • ❌ Phương án SAI: Enable CloudTrail log file integrity validation from the organization’s management account.
    Giải thích: Tính năng log file integrity validation chỉ xác thực tính toàn vẹn của file log đã ghi (bằng hash/S3 digest), giúp phát hiện tamper sau khi ghi. Nó KHÔNG ngăn chặn việc tắt CloudTrail (StopLogging/DeleteTrail). Validation chỉ active sau khi log được tạo, không phải guardrail phòng thủ. (Tham khảo: CloudTrail User Guide - Log File Integrity).

  • ❌ Phương án SAI: Enable server-side encryption with AWS KMS keys (SSE-KMS) for CloudTrail logs. Create a KMS key. Attach a policy to the key to prevent decryption of the logs.
    Giải thích: SSE-KMS mã hóa log và policy deny decrypt chỉ ngăn đọc log, không ảnh hưởng đến việc tắt CloudTrail (StopLogging/DeleteTrail vẫn thực hiện được). CloudTrail có thể disable độc lập với encryption status. Đây chỉ bảo vệ confidentiality, không phải availability của logging service. (Tham khảo: CloudTrail Encryption docs).

  • ✅ Phương án ĐÚNG: Create an SCP that includes an explicit Deny rule for the StopLogging action and the DeleteTrail action. Attach the SCP to the root OU.
    Giải thích: Như đã nêu ở phần đáp án đúng. SCP explicit Deny là unique solution ở level tổ chức, block action gốc của CloudTrail API ở tất cả accounts/regions. Không IAM policy nào thay thế được vì IAM chỉ per-account/user.

  • ❌ Phương án SAI: Create IAM policies for all the company’s users to prevent the users from performing the DescribeTrails action and the GetTrailStatus action.
    Giải thích: IAM policies chỉ hạn chế user cụ thể (không organization-wide), và các action DescribeTrails/GetTrailStatus chỉ dùng để xem thông tin trail (read-only). Chúng KHÔNG liên quan đến việc tắt CloudTrail (StopLogging/DeleteTrail vẫn cho phép). Phải quản lý IAM cho mọi user/role là không scalable và bỏ sót service roles/system principals. (Tham khảo: IAM vs SCP comparison in Organizations docs).

Kết luận 🎯: Giải pháp SCP là duy nhất và hiệu quả nhất, align với AWS security best practices cho centralized governance. Nếu implement, test bằng AWS CLI: aws cloudtrail stop-logging sẽ bị deny!

Câu 390
A company runs its microservices architecture in Kubernetes containers on AWS by using Amazon Elastic Kubernetes Service (Amazon EKS) and Amazon Aurora The company has an organization in AWS Organizations to manage hundreds of AWS accounts that host different microservices.

The company needs to implement a monitoring solution for logs from all AWS resources across all accounts. The solution must include automatic detection of security-related issues.

Which solution will meet these requirements with the LEAST operational effort?
  1. A Designate an Amazon GuardDuty administrator account in the organization’s management account. Enable GuardDuty for all accounts. Enable EKS Protection and RDS Protection in the GuardDuty administrator account.
  2. B Designate a monitoring account. Share Amazon CloudWatch logs from all accounts with the monitoring account. Configure Aurora to publish all logs to CloudWatch. Use Amazon Inspector in the monitoring account to evaluate the CloudWatch logs.
  3. C Create a central Amazon S3 bucket in the organization’s management account. Configure AWS CloudTrail in all AWS accounts to deliver CloudTrail logs to the S3 bucket. Configure Aurora to publish all logs to CloudTrail. Use Amazon Athena to query the CloudTrail logs in the S3 bucket for security issues.
  4. D Designate a monitoring account. Share Amazon CloudWatch logs from all accounts with the monitoring account. Subscribe an Amazon Kinesis data stream to the CloudWatch logs. Create AWS Lambda functions to process log records in the data stream to detect security issues.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi xoay quanh một công ty đang triển khai kiến trúc microservices trên Amazon EKS (Elastic Kubernetes Service) kết hợp Amazon Aurora (cơ sở dữ liệu relational), quản lý hàng trăm AWS accounts thông qua AWS Organizations.
📊 Yêu cầu chính:

  • Triển khai giải pháp monitoring logs từ tất cả AWS resources trên tất cả accounts (cross-account).
  • Tự động phát hiện các vấn đề bảo mật (security-related issues).
  • Tiêu chí ưu tiên: LEAST operational effort (ít nỗ lực vận hành nhất), nghĩa là giải pháp phải dễ triển khai, tự động hóa cao, không cần can thiệp thủ công nhiều.

🛠️ Bối cảnh kỹ thuật: Logs bao gồm từ EKS (pods, clusters), Aurora (query logs, error logs), và các resources khác. Giải pháp phải hỗ trợ multi-account qua Organizations, tận dụng các dịch vụ AWS native để giảm effort (không build custom pipeline).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Designate an Amazon GuardDuty administrator account in the organization’s management account. Enable GuardDuty for all accounts. Enable EKS Protection and RDS Protection in the GuardDuty administrator account.

Lý do chọn (chi tiết):

  • Amazon GuardDuty là dịch vụ threat detection tự động (dựa trên ML), hỗ trợ multi-account qua Organizations (designate admin account ở management account, enable một lần cho tất cả member accounts).
  • EKS Protection (Auditing & Runtime Monitoring) tự động detect anomalies ở Kubernetes workloads (pods, network flows).
  • RDS Protection (bao gồm Aurora) detect threats như unauthorized access, unusual queries.
  • Least effort: Enable một lần ở admin account → tự động aggregate findings cross-account, không cần config từng account riêng lẻ, không custom code. Hoàn toàn serverless và managed bởi AWS.
  • ✅ Phù hợp 100%: Monitoring logs + auto security detection với effort thấp nhất (theo best practices AWS 2024-2026).

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn. Tôi giữ nguyên văn bản gốc bằng tiếng Anh, chỉ giải thích bằng tiếng Việt với lý do đúng/sai rõ ràng:

  • ✅ Phương án ĐÚNG (Designate an Amazon GuardDuty administrator account in the organization’s management account. Enable GuardDuty for all accounts. Enable EKS Protection and RDS Protection in the GuardDuty administrator account.):
    Như đã giải thích ở trên. Giải pháp native AWS, tự động hóa cao cho EKS/RDS/multi-account. Không cần build pipeline thủ công.

  • ❌ Phương án SAI (Designate a monitoring account. Share Amazon CloudWatch logs from all accounts with the monitoring account. Configure Aurora to publish all logs to CloudWatch. Use Amazon Inspector in the monitoring account to evaluate the CloudWatch logs.):
    ❌ Không phù hợp: Amazon Inspector chủ yếu scan vulnerabilities trên EC2/ECR/Lambda/AMIs, KHÔNG evaluate CloudWatch logs cho security threats (không phải công cụ log analysis). Share logs cross-account phức tạp (cần RAM subscriptions), Aurora publish logs đến CloudWatch có thể nhưng effort cao (config từng DB cluster). Không tự động detect, effort lớn hơn GuardDuty.

  • ❌ Phương án SAI (Create a central Amazon S3 bucket in the organization’s management account. Configure AWS CloudTrail in all AWS accounts to deliver CloudTrail logs to the S3 bucket. Configure Aurora to publish all logs to CloudTrail. Use Amazon Athena to query the CloudTrail logs in the S3 bucket for security issues.):
    ❌ Không phù hợp: CloudTrail chỉ log API calls, không bao gồm Aurora logs (Aurora publish đến CloudWatch/S3, KHÔNG phải CloudTrail). Athena là query tool thủ công, không tự động detect security issues (phải viết SQL rules). Effort cao: config bucket policy, event bridges cross-account, không cover EKS logs đầy đủ.

  • ❌ Phương án SAI (Designate a monitoring account. Share Amazon CloudWatch logs from all accounts with the monitoring account. Subscribe an Amazon Kinesis data stream to the CloudWatch logs. Create AWS Lambda functions to process log records in the data stream to detect security issues.):
    ❌ Không phù hợp: Đây là custom solution (Lambda rules tự viết), effort cao nhất (dev/maintain code, scale Kinesis/Lambda cross-account). Share CW logs cần subscriptions phức tạp (RAM + destinations). Không native cho security detection, dễ miss threats so với GuardDuty ML-based.

📘 Tài liệu tham khảo (cập nhật AWS 2024-2026)

🛡️ Kết luận: GuardDuty là lựa chọn optimal cho multi-account security monitoring trên EKS/Aurora! Nếu cần demo lab, tôi có thể hướng dẫn thêm. 🚀