Ngân hàng đề — AWS Certified Security Specialty

Tìm thấy 445 câu.

Câu 391 Chọn nhiều đáp án
A security engineer has been asked to troubleshoot inbound connectivity to a web server. This single web server is not receiving inbound connections from the internet, whereas all other web servers are functioning properly.

The architecture includes network ACLs, security groups, and a virtual security appliance. In addition, the development team has implemented Application Load Balancers (ALBs) to distribute the load across all web servers. It is a requirement that traffic between the web servers and the internet flow through the virtual security appliance.

The security engineer has verified the following:

1.The rule set in the security groups is correct.
2.The rule set in the network ACLs is correct.
3.The rule set in the virtual appliance is correct.

Which of the following are other valid items to troubleshoot in this scenario? (Choose two.)
  1. A Verify that the 0.0.0.0/0 route in the route table for the web server subnet points to a NAT gateway.
  2. B Verify which security group is applied to the particular web server’s elastic network interface (ENI).
  3. C Verify that the 0.0.0.0/0 route in the route table for the web server subnet points to the virtual security appliance.
  4. D Verify the registered targets in the ALB.
  5. E Verify that the 0.0.0.0/0 route in the public subnet points to a NAT gateway.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả tình huống một security engineer đang troubleshoot vấn đề kết nối inbound từ internet vào một web server duy nhất, trong khi các web server khác hoạt động bình thường. Kiến trúc hệ thống bao gồm:

  • Network ACLs (NACLs), Security Groups (SGs), và virtual security appliance (VSA) – một thiết bị bảo mật ảo (như firewall third-party).
  • Application Load Balancers (ALBs) phân phối tải đến tất cả web servers.
  • Yêu cầu bắt buộc: Tất cả traffic giữa web servers và internet phải đi qua VSA (không dùng NAT Gateway trực tiếp).

Engineer đã xác nhận ✅:

  1. Rule set trong Security Groups đúng.
  2. Rule set trong Network ACLs đúng.
  3. Rule set trong virtual appliance đúng.

Vấn đề tập trung vào inbound connectivity (kết nối từ internet vào web server), nhưng vì là TCP connection, cần cả chiều inbound và outbound hoạt động (ví dụ: response từ server ra internet phải route đúng). Traffic flow điển hình:

  • Inbound: Internet → ALB (public subnet?) → Target Groups → Web servers (private subnet?).
  • Outbound/Response: Web servers → VSA → Internet.

Câu hỏi yêu cầu chọn TWO items khác để troubleshoot, dựa trên kiến trúc yêu cầu traffic qua VSA (không NAT).

✅ Đáp án đúng (Chọn TWO)

  • Verify that the 0.0.0.0/0 route in the route table for the web server subnet points to the virtual security appliance.
  • Verify the registered targets in the ALB.

Lý do chọn:

  • Với một server cụ thể bị lỗi (các server khác OK), cần kiểm tra route table của subnet web server để đảm bảo outbound traffic (response) đi qua VSA – nếu route 0.0.0.0/0 sai (ví dụ point IGW hoặc NAT), connection sẽ fail dù inbound OK.
  • ALB targets: Server có thể không registered đúng trong Target Group của ALB, dẫn đến ALB không forward traffic đến server đó (health check fail hoặc không đăng ký).

🛠️ Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn giữ nguyên văn bản gốc tiếng Anh, đánh dấu ✅ đúng hoặc ❌ sai, kèm giải thích bằng tiếng Việt dựa trên kiến trúc VPC/ALB mới nhất (AWS 2026: Không thay đổi cơ bản route tables, ALB target registration, VSA integration qua ENI routing).

  • Verify that the 0.0.0.0/0 route in the route table for the web server subnet points to a NAT gateway.
    ❌ Sai. Kiến trúc yêu cầu traffic web servers ↔ internet qua VSA, không dùng NAT Gateway. Route 0.0.0.0/0 phải point đến ENI của VSA (appliance mode). NAT chỉ dùng cho private subnets outbound không cần inspect, nhưng ở đây contradict yêu cầu VSA → không troubleshoot theo hướng này.

  • Verify which security group is applied to the particular web server’s elastic network interface (ENI).
    ❌ Sai. Đã verify rule set trong security groups đúng, vấn đề là server cụ thể nhưng SG rules chung OK. Kiểm tra SG applied chỉ hữu ích nếu nghi apply sai group, nhưng câu hỏi ngụ ý rules đã đúng → ưu tiên các yếu tố khác như route hoặc ALB targets (server-specific).

  • Verify that the 0.0.0.0 route in the route table for the web server subnet points to the virtual security appliance.
    ✅ Đúng. Đây là item quan trọng vì outbound route từ web server subnet phải point đến VSA (traffic appliance mode). Nếu route sai (ví dụ local hoặc IGW), response không qua VSA → inbound connection fail (TCP handshake broken). Phù hợp yêu cầu "traffic flow through VSA", và giải thích tại sao chỉ một subnet/server ảnh hưởng (route table per subnet).

  • Verify the registered targets in the ALB.
    ✅ Đúng. ALB forward inbound traffic dựa trên Target Groups. Server cụ thể có thể không registered, deregistered, hoặc unhealthy (health check fail từ ALB subnet). Đây là nguyên nhân phổ biến cho một instance fail inbound, trong khi others OK. AWS ALB (2026) yêu cầu targets phải "healthy" và registered để nhận traffic.

  • Verify that the 0.0.0.0/0 route in the public subnet points to a NAT gateway.
    ❌ Sai. Public subnet (ALB thường ở đây) route 0.0.0.0/0 phải point Internet Gateway (IGW) để inbound từ internet vào ALB. NAT dùng cho private outbound, không áp dụng public subnet → không liên quan troubleshoot inbound web server.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Hy vọng phân tích này giúp bạn nắm vững! 🚀 Nếu cần demo CloudFormation, comment nhé!

Câu 392
A company has a strict policy against using root credentials. The company’s security team wants to be alerted as soon as possible when root credentials are used to sign in to the AWS Management Console.

How should the security team achieve this goal?
  1. A Use AWS Lambda to periodically query AWS CloudTrail for console login events and send alerts using Amazon Simple Notification Service (Amazon SNS).
  2. B Use Amazon EventBridge to monitor console logins and direct them to Amazon Simple Notification Service (Amazon SNS).
  3. C Use Amazon Athena to query AWS IAM Identity Center logs and send alerts using Amazon Simple Notification Service (Amazon SNS) for root login events.
  4. D Configure AWS Resource Access Manager to review the access logs and send alerts using Amazon Simple Notification Service (Amazon SNS).
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào chính sách bảo mật nghiêm ngặt của công ty, cấm sử dụng root credentials (tài khoản gốc AWS) và yêu cầu security team được cảnh báo ngay lập tức khi có ai đó sử dụng root credentials để đăng nhập vào AWS Management Console.

✅ Mục tiêu chính: Phát hiện và thông báo real-time (gần thời gian thực) cho sự kiện đăng nhập console bằng root user.
🛠️ Bối cảnh AWS: AWS CloudTrail ghi nhận tất cả các sự kiện đăng nhập console (bao gồm root) dưới dạng event "ConsoleLogin". Để alert nhanh chóng, cần sử dụng dịch vụ event-driven hỗ trợ near real-time monitoring mà không cần polling thủ công. Đây là yêu cầu phổ biến trong kỳ thi AWS Certified DevOps Engineer Professional (DOP-C02), nhấn mạnh vào event-based architecture và least privilege principle (tránh root usage).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use Amazon EventBridge to monitor console logins and direct them to Amazon Simple Notification Service (Amazon SNS).

Lý do chi tiết:

  • Amazon EventBridge (trước đây là CloudWatch Events) là dịch vụ serverless event bus hỗ trợ real-time monitoring các sự kiện từ AWS services như CloudTrail.
  • EventBridge có thể filter chính xác sự kiện "ConsoleLogin" với điều kiện userIdentity.type = "Root" từ CloudTrail logs, sau đó route trực tiếp đến Amazon SNS để gửi alert (email, SMS, etc.).
  • Thời gian xử lý: Gần real-time (thường dưới 1 phút), phù hợp với yêu cầu "as soon as possible". Không cần code custom, dễ cấu hình qua console hoặc CDK/Terraform.
  • 📘 Kiến thức cập nhật 2026: EventBridge hỗ trợ EventBridge Pipes và Schema Registry cho advanced filtering, vẫn là best practice theo AWS Well-Architected Framework (Security Pillar).

❌ Phân tích tất cả các phương án

Dưới đây là giải thích từng lựa chọn một cách chi tiết, với nội dung phương án giữ nguyên bằng tiếng Anh gốc. Mỗi phương án được đánh giá đúng/sai dựa trên tính khả thi, real-time và liên quan đến root console login.

  • [SAI] Use AWS Lambda to periodically query AWS CloudTrail for console login events and send alerts using Amazon Simple Notification Service (Amazon SNS).
    ❌ Lý do sai: Phương án này sử dụng Lambda polling định kỳ (ví dụ: mỗi 5-15 phút qua CloudWatch Events), dẫn đến độ trễ cao (không "as soon as possible"). Query CloudTrail qua API tốn kém và không hiệu quả cho real-time. CloudTrail phù hợp làm nguồn dữ liệu, nhưng cần event-driven thay vì polling. Không phải best practice theo AWS (Well-Architected: Operational Excellence).

  • [ĐÚNG] Use Amazon EventBridge to monitor console logins and direct them to Amazon Simple Notification Service (Amazon SNS).
    ✅ Lý do đúng: Như đã giải thích ở trên. EventBridge tích hợp native với CloudTrail, filter event "ConsoleLogin" với responseElements.ConsoleLogin = "Success" và userIdentity.arn chứa root, rồi forward đến SNS. Real-time, scalable, no custom code. Hoàn hảo cho use case này!

  • [SAI] Use Amazon Athena to query AWS IAM Identity Center logs and send alerts using Amazon Simple Notification Service (Amazon SNS) for root login events.
    ❌ Lý do sai: Amazon Athena là công cụ query batch trên S3 (không real-time, độ trễ hàng giờ/ngày). IAM Identity Center (trước là SSO) chỉ log cho federated users/roles, KHÔNG ghi root console logins (root là IAM user gốc, không qua Identity Center). CloudTrail mới là nguồn đúng cho console logins.

  • [SAI] Configure AWS Resource Access Manager to review the access logs and send alerts using Amazon Simple Notification Service (Amazon SNS).
    ❌ Lý do sai: AWS Resource Access Manager (RAM) dùng để chia sẻ resources cross-account (như VPC, Transit Gateway), KHÔNG liên quan đến login/access logs. Không có tính năng monitor console logins hay gửi SNS alerts. Sai hoàn toàn về service purpose.

📘 Tài liệu tham khảo (AWS cập nhật mới nhất 2026)

🛠️ Lời khuyên thực hành: Để implement nhanh, tạo EventBridge Rule với pattern: {"detail-type": ["AWS Console Sign In via CloudTrail"], "detail": {"eventSource": ["signin.amazonaws.com"], "userIdentity": {"type": ["Root"]}}} → Target SNS Topic. Test bằng root login thử nghiệm! 🚀

Câu 393
A company wants to store all objects that contain sensitive data in an Amazon S3 bucket. The company will use server-side encryption to encrypt the S3 bucket. The company’s operations team manages access to the company’s S3 buckets. The company’s security team manages access to encryption keys.

The company wants to separate the duties of the two teams to ensure that configuration errors by only one of these teams will not compromise the data by granting unauthorized access to plaintext data.

Which solution will meet this requirement?
  1. A Ensure that the operations team configures default bucket encryption on the S3 bucket to use server-side encryption with Amazon S3 managed encryption keys (SSE-S3). Ensure that the security team creates an IAM policy that controls access to use the encryption keys.
  2. B Ensure that the operations team creates a bucket policy that requires requests to use server-side encryption with AWS KMS keys (SSE-KMS) that are customer managed. Ensure that the security team creates a key policy that controls access to the encryption keys.
  3. C Ensure that the operations team creates a bucket policy that requires requests to use server-side encryption with Amazon S3 managed keys (SSE-S3). Ensure that the security team creates an IAM policy that controls access to the encryption keys.
  4. D Ensure that the operations team creates a bucket policy that requires requests to use server-side encryption with customer-provided encryption keys (SSE-C). Ensure that the security team stores the customer-provided keys in AWS Key Management Service (AWS KMS). Ensure that the security team creates a key policy that controls access to the encryption keys.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc bảo mật dữ liệu nhạy cảm trong Amazon S3 bucket bằng cách sử dụng server-side encryption (SSE), đồng thời tách biệt trách nhiệm (separation of duties) giữa hai đội ngũ:

  • Operations team: Quản lý truy cập vào S3 buckets (bucket policies, default encryption).
  • Security team: Quản lý khóa mã hóa (encryption keys).

🎯 Yêu cầu cốt lõi: Đảm bảo rằng nếu một đội mắc lỗi cấu hình (ví dụ: cấp quyền sai), thì không thể truy cập dữ liệu plaintext (dữ liệu chưa mã hóa). Nghĩa là:

  • Ops team chỉ config S3 để buộc sử dụng encryption, nhưng không kiểm soát keys.
  • Security team kiểm soát keys, nên họ có thể chặn truy cập bằng cách từ chối quyền sử dụng keys.

🔍 Các loại SSE liên quan (cập nhật AWS 2026):

  • SSE-S3: S3 managed keys (AWS tự quản lý, không tách biệt duties).
  • SSE-KMS: Sử dụng AWS KMS keys (có customer managed keys - CMK). Ops config bucket policy yêu cầu SSE-KMS, security quản lý key policy trên CMK.
  • SSE-C: Client cung cấp keys (không lưu trong KMS, không phù hợp server-side).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Ensure that the operations team creates a bucket policy that requires requests to use server-side encryption with AWS KMS keys (SSE-KMS) that are customer managed. Ensure that the security team creates a key policy that controls access to the encryption keys.

🛠️ Lý do chi tiết:

  • Operations team tạo bucket policy để buộc tất cả requests phải dùng SSE-KMS với CMK cụ thể (customer managed KMS key). Họ không tạo hay quản lý key, chỉ config S3 yêu cầu encryption.
  • Security team tạo key policy trên CMK trong KMS để kiểm soát ai được dùng key (grant/decrypt).
  • Separation of duties hoàn hảo: Nếu ops cấp quyền đọc bucket sai → không decrypt được vì thiếu quyền key từ security. Nếu security cấp quyền key sai → vẫn bị chặn bởi bucket policy yêu cầu SSE-KMS. Không ai có thể truy cập plaintext.
  • Đây là best practice AWS cho enterprise security (SSE-KMS với CMK hỗ trợ dual-control).

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng lựa chọn một cách chi tiết. Tôi giữ nguyên văn bản gốc bằng tiếng Anh, chỉ giải thích bằng tiếng Việt với emoji đánh dấu đúng/sai.

  • ❌ Phương án 1 (SAI):
    Ensure that the operations team configures default bucket encryption on the S3 bucket to use server-side encryption with Amazon S3 managed encryption keys (SSE-S3). Ensure that the security team creates an IAM policy that controls access to use the encryption keys.
    Giải thích sai: SSE-S3 dùng keys do AWS quản lý hoàn toàn, ops team config default bucket encryption là đủ để encrypt/decrypt → security team không kiểm soát keys (không có "encryption keys" để IAM policy control). Không tách biệt duties, ops có thể cấp quyền đọc plaintext gián tiếp.

  • ✅ Phương án 2 (ĐÚNG):
    Ensure that the operations team creates a bucket policy that requires requests to use server-side encryption with AWS KMS keys (SSE-KMS) that are customer managed. Ensure that the security team creates a key policy that controls access to the encryption keys.
    Giải thích đúng: Như đã phân tích ở trên. Bucket policy (ops) buộc SSE-KMS CMK, key policy (security) kiểm soát quyền sử dụng key → lỗi một bên không compromise data. Hoàn hảo cho separation of duties.

  • ❌ Phương án 3 (SAI):
    Ensure that the operations team creates a bucket policy that requires requests to use server-side encryption with Amazon S3 managed keys (SSE-S3). Ensure that the security team creates an IAM policy that controls access to the encryption keys.
    Giải thích sai: SSE-S3 không có "encryption keys" riêng để IAM policy control (AWS managed). Bucket policy chỉ buộc SSE-S3, nhưng ops vẫn kiểm soát toàn bộ → security không có quyền chặn decrypt, vi phạm separation.

  • ❌ Phương án 4 (SAI):
    Ensure that the operations team creates a bucket policy that requires requests to use server-side encryption with customer-provided encryption keys (SSE-C). Ensure that the security team stores the customer-provided keys in AWS Key Management Service (AWS KMS). Ensure that the security team creates a key policy that controls access to the encryption keys.
    Giải thích sai: SSE-C là client-side encryption (client cung cấp keys trong request), không phải server-side thực thụ (S3 encrypt sau khi nhận object). KMS không lưu trữ SSE-C keys (SSE-C keys phải do client generate/manage). Bucket policy không hỗ trợ yêu cầu SSE-C hiệu quả → không tách biệt đúng, dễ lộ plaintext nếu client gửi sai.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần ví dụ code policy, hỏi thêm nhé!

Câu 394
A security engineer is designing security controls for a fleet of Amazon EC2 instances that run sensitive workloads in a VPC. The security engineer needs to implement a solution to detect and mitigate software vulnerabilities on the EC2 instances.

Which solution will meet this requirement?
  1. A Scan the EC2 instances by using Amazon Inspector. Apply security patches and updates by using AWS Systems Manager Patch Manager.
  2. B Install host-based firewall and antivirus software on each EC2 instance. Use AWS Systems Manager Run Command to update the firewall and antivirus software.
  3. C Install the Amazon CloudWatch agent on the EC2 instances. Enable detailed logging. Use Amazon EventBridge to review the software logs for anomalies.
  4. D Scan the EC2 instances by using Amazon GuardDuty Malware Protection. Apply security patches and updates by using AWS Systems Manager Patch Manager.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào việc một security engineer đang thiết kế các security controls cho một fleet Amazon EC2 instances chạy sensitive workloads (các workload nhạy cảm) trong một VPC. Yêu cầu chính là triển khai giải pháp để detect (phát hiện) và mitigate (giảm thiểu) software vulnerabilities (lỗ hổng phần mềm) trên các EC2 instances.

📌 Phân tích yêu cầu chi tiết:

  • Detect: Cần công cụ scan (quét) tự động các lỗ hổng phần mềm (như CVEs - Common Vulnerabilities and Exposures) trên hệ điều hành, ứng dụng, thư viện.
  • Mitigate: Áp dụng security patches (bản vá bảo mật) và updates (cập nhật) để khắc phục lỗ hổng.
  • Ngữ cảnh: Giải pháp phải phù hợp với EC2 trong VPC, dễ scale cho fleet lớn, tích hợp native AWS, và tuân thủ best practices bảo mật (theo AWS Well-Architected Framework - Security Pillar, cập nhật 2024-2026).
  • Mục tiêu: Giải pháp toàn diện, tự động hóa cao, không yêu cầu agent tùy chỉnh phức tạp.

🛠️ Kiến thức AWS liên quan (cập nhật đến 2026): AWS khuyến nghị sử dụng Amazon Inspector cho vulnerability scanning trên EC2 (hỗ trợ agent-based và agentless từ 2023), kết hợp AWS Systems Manager (SSM) Patch Manager cho patching tự động, không downtime.

✅ Đáp án đúng và lý do lựa chọn

Scan the EC2 instances by using Amazon Inspector. Apply security patches and updates by using AWS Systems Manager Patch Manager.

Lý do chi tiết:

  • Amazon Inspector là dịch vụ chuyên dụng để phát hiện software vulnerabilities (CVEs, misconfigurations) trên EC2 instances, Lambda, ECS/EKS, với hỗ trợ agentless scanning (EC2 Instance Connect Endpoint) và CIS benchmarks. Nó tự động đánh giá và tạo findings trong console hoặc tích hợp EventBridge/SNS.
  • AWS Systems Manager Patch Manager (phần của SSM) quản lý patching cho Windows/Linux EC2, tự động scan compliance, approve patches, và apply mà không cần reboot thủ công (sử dụng Maintenance Windows).
  • Kết hợp hoàn hảo: Inspector detect → SSM mitigate, scale cho fleet lớn, zero-trust model, tuân thủ PCI-DSS, HIPAA. Đây là recommended solution trong AWS Security Best Practices (2026).

📋 Phân tích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá dựa trên khả năng detect/mitigate software vulnerabilities cụ thể trên EC2.

  • ✅ Scan the EC2 instances by using Amazon Inspector. Apply security patches and updates by using AWS Systems Manager Patch Manager.
    Đúng hoàn toàn 🏆: Như giải thích ở trên, đây là giải pháp native AWS tối ưu, tự động hóa end-to-end cho vulnerability management. Inspector quét CVEs real-time (hàng triệu signatures cập nhật hàng ngày), SSM Patch Manager xử lý patching baseline/compliance với approval rules.

  • ❌ Install host-based firewall and antivirus software on each EC2 instance. Use AWS Systems Manager Run Command to update the firewall and antivirus software.
    Sai 🚫: Firewall (như iptables/ufw) và antivirus (như ClamAV/Endpoint Protection) chỉ bảo vệ chống network threats/malware, không detect software vulnerabilities (CVEs trên apps/OS). SSM Run Command chỉ update software này, không mitigate vulns gốc. Phải install thủ công/agent-heavy, không scale tốt cho fleet.

  • ❌ Install the Amazon CloudWatch agent on the EC2 instances. Enable detailed logging. Use Amazon EventBridge to review the software logs for anomalies.
    Sai 🚫: CloudWatch Agent thu thập metrics/logs, EventBridge route events để monitor anomalies (như unusual behavior). Đây là log-based detection, không scan vulnerabilities (không biết CVEs cụ thể). Phù hợp threat detection nhưng không mitigate patches, dễ false positives.

  • ❌ Scan the EC2 instances by using Amazon GuardDuty Malware Protection. Apply security patches and updates by using AWS Systems Manager Patch Manager.
    Sai 🚫: GuardDuty Malware Protection (ra mắt 2022, cập nhật 2025 cho EC2 agentless via SSM/S3) chuyên malware/threat scanning (file hashes, EICAR, ransomware), không phải software vulnerabilities (CVEs trên OS/apps - đó là nhiệm vụ của Inspector). SSM Patch Manager đúng nhưng kết hợp sai tool detect.

📘 Tài liệu tham khảo (AWS Docs cập nhật 2026)

Giải pháp này đảm bảo compliance cao, cost-effective và zero-downtime cho production workloads! 🚀

Câu 395
A company stores sensitive data in AWS Secrets Manager. A security engineer needs to design a solution to generate a notification email when anomalous GetSecretValue API calls occur. The security engineer has configured an Amazon EventBridge rule for all Secrets Manager events that AWS CloudTrail delivers.

Which solution will meet these requirements?
  1. A Configure CloudTrail as the target of the EventBridge rule. Set up an attribute filter on the IncomingBytes attribute and enable anomaly detection. Create an Amazon Simple Notification Service (Amazon SNS) topic. Configure a CloudTrail alarm that uses the SNS topic to send the notification.
  2. B Configure CloudTrail as the target of the EventBridge rule. Set up an attribute filter on the IncomingBytes attribute and enable anomaly detection. Create an Amazon Simple Queue Service (Amazon SQS) queue. Configure a CloudTrail alarm that uses the SQS queue to send the notification.
  3. C Configure Amazon CloudWatch Logs as the target of the EventBridge rule. Set up a metric filter on the IncomingBytes metric and enable anomaly detection. Create an Amazon Simple Notification Service (Amazon SNS) topic. Configure a CloudWatch alarm that uses the SNS topic to send the notification.
  4. D Configure Amazon CloudWatch Logs as the target of the EventBridge rule. Use CloudWatch Logs Insights query syntax to search for anomalous GetSecretValue API calls. Create an Amazon Simple Queue Service (Amazon SQS) queue. Configure a CloudWatch alarm that uses the SQS queue to send the notification.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi xoay quanh việc thiết kế giải pháp bảo mật trên AWS để phát hiện và thông báo bất thường (anomalous) các cuộc gọi API GetSecretValue đối với dữ liệu nhạy cảm lưu trữ trong AWS Secrets Manager.

  • Bối cảnh: Công ty đã cấu hình Amazon EventBridge rule để nhận tất cả các sự kiện (events) từ AWS CloudTrail liên quan đến Secrets Manager. CloudTrail ghi lại chi tiết các API calls như GetSecretValue (lấy giá trị secret).
  • Yêu cầu chính: Gửi email thông báo khi phát hiện hành vi bất thường (ví dụ: số lượng calls đột biến, không hợp lý so với baseline).
  • Thách thức: Cần route events từ EventBridge đến nơi xử lý, trích xuất metric từ logs, áp dụng anomaly detection (phát hiện bất thường dựa trên ML của CloudWatch), và thiết lập alarm gửi thông báo qua email (thường dùng SNS).
  • Kiến thức liên quan (cập nhật AWS 2026):
    • CloudTrail → EventBridge (source: aws.cloudtrail) → Target (như CloudWatch Logs).
    • CloudWatch Logs metric filters trích xuất metric từ logs (ví dụ: đếm số calls GetSecretValue).
    • Anomaly detection trên CloudWatch metrics (tính năng ML tự động detect outliers).
    • CloudWatch Alarms → SNS topic → Email subscription cho notifications.

📘 Tài liệu tham khảo:

✅ Đáp án đúng: Phương án thứ 3

Configure Amazon CloudWatch Logs as the target of the EventBridge rule. Set up a metric filter on the IncomingBytes metric and enable anomaly detection. Create an Amazon Simple Notification Service (Amazon SNS) topic. Configure a CloudWatch alarm that uses the SNS topic to send the notification.

Lý do lựa chọn:

  • 🛠️ EventBridge target là CloudWatch Logs: Hoàn hảo để lưu trữ và phân tích CloudTrail events (bao gồm GetSecretValue calls) dưới dạng logs.
  • 📊 Metric filter trên IncomingBytes metric + anomaly detection: IncomingBytes là metric mặc định của CloudWatch Logs đại diện cho lượng dữ liệu logs ingested (liên quan đến volume events Secrets Manager). Metric filter có thể customize để filter pattern cụ thể (như eventName=GetSecretValue), tạo metric count/bytes, rồi enable anomaly detection (ML model detect spikes bất thường).
  • 🔔 SNS topic + CloudWatch alarm: Alarm trên metric anomaly → Trigger SNS → Subscribe email → Gửi notification ngay lập tức. Đây là best practice cho alerting.
  • ✅ Đầy đủ, scalable, không sai quy trình AWS (cập nhật 2026: Tích hợp EventBridge-CloudWatch seamless).

🔍 Giải thích chi tiết tất cả các phương án

  • Phương án 1 ❌: Configure CloudTrail as the target of the EventBridge rule. Set up an attribute filter on the IncomingBytes attribute and enable anomaly detection. Create an Amazon Simple Notification Service (Amazon SNS) topic. Configure a CloudTrail alarm that uses the SNS topic to send the notification.
    Sai vì: CloudTrail là source (nguồn sự kiện), không thể là target của EventBridge rule (rule chỉ route đến services như Logs/SNS/SQS). Không có "CloudTrail alarm" native; CloudTrail dùng CloudWatch cho alerting. Attribute filter không phù hợp cho anomaly trên logs.

  • Phương án 2 ❌: Configure CloudTrail as the target of the EventBridge rule. Set up an attribute filter on the IncomingBytes attribute and enable anomaly detection. Create an Amazon Simple Queue Service (Amazon SQS) queue. Configure a CloudTrail alarm that uses the SQS queue to send the notification.
    Sai vì: Tương tự phương án 1, CloudTrail không phải target. SQS dùng cho queuing, không trực tiếp gửi email (cần Lambda/SNS trung gian phức tạp). "CloudTrail alarm" không tồn tại; và SQS không ideal cho notification email thời gian thực.

  • Phương án 3 ✅: Configure Amazon CloudWatch Logs as the target of the EventBridge rule. Set up a metric filter on the IncomingBytes metric and enable anomaly detection. Create an Amazon Simple Notification Service (Amazon SNS) topic. Configure a CloudWatch alarm that uses the SNS topic to send the notification.
    Đúng vì: Như giải thích trên – Quy trình chuẩn: EventBridge → Logs → Metric filter/anomaly → Alarm → SNS/email. Hỗ trợ phát hiện anomalous GetSecretValue qua volume logs/metric.

  • Phương án 4 ❌: Configure Amazon CloudWatch Logs as the target of the EventBridge rule. Use CloudWatch Logs Insights query syntax to search for anomalous GetSecretValue API calls. Create an Amazon Simple Queue Service (Amazon SQS) queue. Configure a CloudWatch alarm that uses the SQS queue to send the notification.
    Sai vì: CloudWatch Logs Insights chỉ dùng cho query ad-hoc (không liên tục/alarm realtime). Không integrate trực tiếp với anomaly detection/alarm như metric filters. SQS queue không gửi email trực tiếp (phải process thêm), kém hiệu quả so với SNS.

🛠️ Lời khuyên triển khai: Test bằng cách simulate GetSecretValue calls qua AWS CLI, monitor metric trong CloudWatch console. Chi phí thấp, tích hợp GuardDuty nếu cần threat detection nâng cao! 🚀

Câu 396
A company is using AWS Organizations with the default SCP. The company needs to restrict AWS usage for all AWS accounts that are in a specific OU.

Except for some desired global services, the AWS usage must occur only in the eu-west-1 Region for all accounts in the OU. A security engineer must create an SCP that applies the restriction to existing accounts and any new accounts in the OU.

Which SCP will meet these requirements?
  1. A
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "DenyNonDefaultRegions",
          "Effect": "Deny",
          "NotAction": [
            ""
          ],
          "Resource": "*",
          "Condition": {
            "StringEquals": {
              "aws:RequestedRegion": [
                "eu-west-1"
              ]
            }
          }
        }
      ]
    }

  2. B
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "DenyNonDefaultRegions",
          "Effect": "Allow",
          "Action": [
            ""
          ],
          "Resource": "*",
          "Condition": {
            "StringEquals": {
              "aws:RequestedRegion": [
                "eu-west-1"
              ]
            }
          }
        }
      ]
    }

  3. C
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "DenyNonDefaultRegions",
          "Effect": "Deny",
          "NotAction": [
            ""
          ],
          "Resource": "*",
          "Condition": {
            "StringNotEquals": {
              "aws:RequestedRegion": [
                "eu-west-1"
              ]
            }
          }
        }
      ]
    }

  4. D
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "DenyNonDefaultRegions",
          "Effect": "Allow",
          "NotAction": [
            ""
          ],
          "Resource": "*",
          "Condition": {
            "StringNotEquals": {
              "aws:RequestedRegion": [
                "eu-west-1"
              ]
            }
          }
        }
      ]
    }
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào AWS Organizations và Service Control Policies (SCP), một tính năng quan trọng để quản lý quyền hạn ở cấp tổ chức. Công ty đang sử dụng default SCP (cho phép tất cả các hành động một cách mặc định). Yêu cầu là hạn chế sử dụng AWS chỉ trong OU (Organizational Unit) cụ thể, áp dụng cho tất cả tài khoản hiện có và mới:

  • Cho phép một số dịch vụ toàn cầu (global services) như IAM, AWS Organizations (không bị ràng buộc region).
  • Tất cả sử dụng AWS khác chỉ được phép ở region eu-west-1.

SCP hoạt động theo nguyên tắc deny explicit overrides allow implicit (từ chối rõ ràng sẽ ghi đè cho phép ngầm định). SCP không cấp quyền mà chỉ hạn chế (giống như guardrail). Để đạt yêu cầu, SCP phải deny các hành động không phải global services ở region khác eu-west-1, tận dụng condition key aws:RequestedRegion (áp dụng cho các API call yêu cầu region cụ thể).

🛠️ Mục tiêu SCP lý tưởng:

  • Effect: Deny các hành động không phải <Desired Global Services> (sử dụng NotAction).
  • Condition: Chỉ deny khi aws:RequestedRegion KHÔNG bằng eu-west-1 (sử dụng StringNotEquals).

✅ Đáp án đúng: Lựa chọn thứ 3

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "DenyNonDefaultRegions",
      "Effect": "Deny",
      "NotAction": [
        "<Desired Global Services>"
      ],
      "Resource": "*",
      "Condition": {
        "StringNotEquals": {
          "aws:RequestedRegion": [
            "eu-west-1"
          ]
        }
      }
    }
  ]
}

Lý do chọn đáp án này 🏆:

  • Effect: Deny kết hợp NotAction → Deny tất cả hành động TRỪ global services.
  • Condition StringNotEquals "eu-west-1" → Chỉ kích hoạt deny khi region yêu cầu KHÔNG phải eu-west-1.
  • Kết quả:
    • ✅ Global services: Luôn cho phép (vì NotAction loại trừ chúng khỏi deny).
    • ✅ Non-global ở eu-west-1: Không match condition → Không deny.
    • ❌ Non-global ở region khác: Match condition → Deny.
  • Áp dụng hoàn hảo cho default SCP (allow all), và tự động cho tài khoản mới trong OU. Phù hợp kiến thức AWS mới nhất (2026), SCP vẫn giữ nguyên logic này.

📋 Phân tích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên code gốc tiếng Anh. Mỗi phương án được đánh giá dựa trên logic SCP và yêu cầu câu hỏi:

  • ❌ Phương án 1 (SAI):

    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "DenyNonDefaultRegions",
          "Effect": "Deny",
          "NotAction": [
            "<Desired Global Services>"
          ],
          "Resource": "*",
          "Condition": {
            "StringEquals": {
              "aws:RequestedRegion": [
                "eu-west-1"
              ]
            }
          }
        }
      ]
    }
    

    Giải thích sai: Condition StringEquals "eu-west-1" khiến deny kích hoạt CHÍNH XÁC ở eu-west-1 cho non-global services → Cấm sử dụng ở region mong muốn, trái ngược yêu cầu. Global services vẫn ok (NotAction), nhưng fail tổng thể.

  • ❌ Phương án 2 (SAI):

    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "DenyNonDefaultRegions",
          "Effect": "Allow",
          "Action": [
            "<Desired Global Services>"
          ],
          "Resource": "*",
          "Condition": {
            "StringEquals": {
              "aws:RequestedRegion": [
                "eu-west-1"
              ]
            }
          }
        }
      ]
    }
    

    Giải thích sai: Effect: Allow chỉ cho phép global services ở eu-west-1, nhưng SCP không dùng để cấp quyền (chỉ restrict). Default SCP đã allow all, nên cái này không deny gì cả ở region khác → Không hạn chế được non-global ở region ngoài eu-west-1.

  • ✅ Phương án 3 (ĐÚNG): (Đã giải thích chi tiết ở trên). Hoàn hảo match yêu cầu! 🚀

  • ❌ Phương án 4 (SAI):

    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "DenyNonDefaultRegions",
          "Effect": "Allow",
          "NotAction": [
            "<Desired Global Services>"
          ],
          "Resource": "*",
          "Condition": {
            "StringNotEquals": {
              "aws:RequestedRegion": [
                "eu-west-1"
              ]
            }
          }
        }
      ]
    }
    

    Giải thích sai: Effect: Allow với NotAction → Cho phép non-global ở region KHÔNG phải eu-west-1, trái ngược hoàn toàn (nên deny ở đó). Không đạt restrict, chỉ "cho phép thừa" trên default SCP.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

  • AWS Organizations User Guide: Service control policies (SCPs) – Chi tiết về SCP deny logic và aws:RequestedRegion.
  • IAM Policy Elements Reference: StringNotEquals & aws:RequestedRegion.
  • Exam Topic DOP-C02: SCP trong AWS Organizations (phiên bản exam 2024-2026 không thay đổi core logic).
  • Best Practice: AWS Well-Architected Framework – Security Pillar: Sử dụng SCP cho multi-account strategy.

Hy vọng phân tích này giúp bạn nắm vững! Nếu cần demo SCP thực tế qua AWS CLI, hãy hỏi nhé! 😊

Câu 397 Chọn nhiều đáp án
A company is planning to migrate its applications to AWS in a single AWS Region. The company’s applications will use a combination of Amazon EC2 instances, Elastic Load Balancing (ELB) load balancers, and Amazon S3 buckets. The company wants to complete the migration as quickly as possible. All the applications must meet the following requirements:

•Data must be encrypted at rest.
•Data must be encrypted in transit.
•Endpoints must be monitored for anomalous network traffic.

Which combination of steps should a security engineer take to meet these requirements with the LEAST effort? (Choose three.)
  1. A Install the Amazon Inspector agent on EC2 instances by using AWS Systems Manager Automation.
  2. B Enable Amazon GuardDuty in all AWS accounts.
  3. C Create VPC endpoints for Amazon EC2 and Amazon S3. Update VPC route tables to use only the secure VPC endpoints.
  4. D Configure AWS Certificate Manager (ACM). Configure the load balancers to use certificates from ACM.
  5. E Use AWS Key Management Service (AWS KMS) for key management. Create an S3 bucket policy to deny any PutObject command with a condition for x-amz-meta-side-encryption.
  6. F Use AWS Key Management Service (AWS KMS) for key management. Create an S3 bucket policy to deny any PutObject command with a condition for x-amz-server-side-encryption.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc di chuyển ứng dụng sang AWS một Region duy nhất, sử dụng EC2 instances, Elastic Load Balancing (ELB) load balancers và S3 buckets. Mục tiêu là hoàn thành nhanh chóng với ít nỗ lực nhất (LEAST effort), đồng thời đáp ứng 3 yêu cầu bảo mật chính:

  • Dữ liệu mã hóa tại chỗ (encrypted at rest): Áp dụng cho S3 (server-side encryption) và EC2 (EBS encryption mặc định).
  • Dữ liệu mã hóa khi truyền (encrypted in transit): Sử dụng TLS/HTTPS cho ELB và S3.
  • Giám sát endpoints cho lưu lượng mạng bất thường (monitored for anomalous network traffic): Phát hiện threat qua dịch vụ managed.

Câu hỏi yêu cầu chọn 3 bước kết hợp từ security engineer, ưu tiên giải pháp managed services tự động để giảm công sức (không cần agent thủ công hay config phức tạp). Dựa trên kiến thức AWS cập nhật 2026 (AWS Well-Architected Framework Security Pillar, GuardDuty v2.0+ với Malware Protection, S3 Object Lock enhancements).

✅ Đáp án đúng (Chọn 3)

Các đáp án đúng là:

  • Enable Amazon GuardDuty in all AWS accounts. (Giám sát anomalous traffic toàn diện).
  • Configure AWS Certificate Manager (ACM). Configure the load balancers to use certificates from ACM. (Mã hóa in transit cho ELB).
  • Use AWS Key Management Service (AWS KMS) for key management. Create an S3 bucket policy to deny any PutObject command with a condition for x-amz-server-side-encryption. (Enforce mã hóa at rest cho S3).

Lý do chọn: Bộ 3 này bao quát đầy đủ 3 yêu cầu với least effort – tất cả là managed services (GuardDuty tự động scan logs VPC Flow Logs/CloudTrail/S3 Data Events mà không cần agent; ACM tự provision cert miễn phí cho ELB; KMS + bucket policy enforce SSE-KMS tự động). Không cần install agent, VPC config phức tạp hay header sai. Tổng effort thấp, scale nhanh cho migration.

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng phương án (giữ nguyên văn bản gốc tiếng Anh), đánh dấu ✅ đúng hoặc ❌ sai, kèm lý do cụ thể bằng tiếng Việt:

  • Install the Amazon Inspector agent on EC2 instances by using AWS Systems Manager Automation.
    ❌ Sai: Amazon Inspector (nay là Inspector v2+) dùng để scan vulnerability và compliance trên EC2, không phải monitor anomalous network traffic (nó tập trung vào software misconfig/host threats). Cần install agent thủ công qua SSM, tăng effort không cần thiết. Không address encryption.

  • Enable Amazon GuardDuty in all AWS accounts.
    ✅ Đúng: GuardDuty là dịch vụ managed threat detection tự động phân tích VPC Flow Logs, CloudTrail, DNS logs để phát hiện anomalous network traffic (e.g., reconnaissance, crypto-mining). Enable one-click, cover EC2/ELB/S3 endpoints mà không cần agent/config. Least effort cao, tích hợp S3 protection từ 2023+.

  • Create VPC endpoints for Amazon EC2 and Amazon S3. Update VPC route tables to use only the secure VPC endpoints.
    ❌ Sai: VPC Endpoints (Gateway cho S3, Interface cho services khác) giúp private access, giảm public traffic nhưng không trực tiếp encrypt data (vẫn cần TLS riêng) và không monitor anomalous traffic. EC2 không cần endpoint (nó native trong VPC). Config route tables tốn effort, không cover ELB fully. Không optimal cho least effort.

  • Configure AWS Certificate Manager (ACM). Configure the load balancers to use certificates from ACM.
    ✅ Đúng: ACM provision free TLS certs tự động renew, attach vào ELB (ALB/NLB) để enforce HTTPS (encryption in transit). Cover traffic đến EC2 qua ELB. Least effort: Integrate trực tiếp với ELB listener rules, không cần self-managed certs.

  • Use AWS Key Management Service (AWS KMS) for key management. Create an S3 bucket policy to deny any PutObject command with a condition for x-amz-meta-side-encryption.
    ❌ Sai: Bucket policy đúng syntax nhưng header sai: x-amz-meta-side-encryption không tồn tại (user metadata). Header chuẩn là x-amz-server-side-encryption: aws:kms để enforce SSE-KMS (at rest). Sai này làm policy vô hiệu, không protect data.

  • Use AWS Key Management Service (AWS KMS) for key management. Create an S3 bucket policy to deny any PutObject command with a condition for x-amz-server-side-encryption.
    ✅ Đúng: KMS manage keys, policy deny PutObject nếu thiếu header x-amz-server-side-encryption: aws:kms – enforce SSE-KMS tự động cho S3 at rest. Least effort: Bucket policy one-time config, cover tất cả uploads. S3 mặc định SSE-S3 từ 2023, nhưng KMS mạnh hơn cho compliance.

🛠️ Lời khuyên triển khai & Tài liệu tham khảo 📘

Bộ đáp án này đảm bảo compliance zero-trust với migration nhanh! 🚀

Câu 398
A security engineer is working with a development team to design a supply chain application that stores sensitive inventory data in an Amazon S3 bucket. The application will use an AWS Key Management Service (AWS KMS) customer managed key to encrypt the data in Amazon S3.

The inventory data in Amazon S3 will be shared with hundreds of vendors. All vendors will use AWS principals from their own AWS accounts to access the data in Amazon S3. The vendor list might change weekly. The security engineer needs to find a solution that supports cross-account access.

Which solution is the MOST operationally efficient way to manage access control for the customer managed key?
  1. A Use KMS grants to manage key access. Programmatically create and revoke grants to manage vendor access.
  2. B Use am IAM role to manage key access. Programmatically update the IAM role policies to manage vendor access.
  3. C Use KMS key policies to manage key access. Programmatically update the KMS key policies to manage vendor access.
  4. D Use delegated access across AWS accounts by using IAM roles to manage key access. Programmatically update the IAM trust policy to manage cross-account vendor access.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc thiết kế một ứng dụng quản lý chuỗi cung ứng (supply chain application) lưu trữ dữ liệu hàng tồn kho nhạy cảm trong Amazon S3 bucket, sử dụng AWS KMS customer managed key để mã hóa dữ liệu. Dữ liệu này cần được chia sẻ với hàng trăm nhà cung cấp (vendors) từ các AWS account riêng biệt của họ. Các vendor sử dụng AWS principals (như IAM users/roles) từ account của mình để truy cập S3. Danh sách vendor có thể thay đổi hàng tuần, đòi hỏi giải pháp hỗ trợ cross-account access một cách hiệu quả về mặt vận hành (MOST operationally efficient) cho quyền truy cập vào KMS key (vì S3 encryption yêu cầu KMS key permissions để decrypt).

🛠️ Vấn đề cốt lõi: Quản lý quyền truy cập động (dynamic), scale lớn (hàng trăm vendors), thay đổi thường xuyên, cross-account, mà không làm gián đoạn hoạt động hoặc tăng chi phí quản lý thủ công. Giải pháp phải tận dụng tính năng KMS tốt nhất để programmatic (tự động hóa qua code/API).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use KMS grants to manage key access. Programmatically create and revoke grants to manage vendor access.

Lý do chi tiết:

  • KMS Grants là tính năng được thiết kế đặc biệt cho việc cấp quyền tạm thời, granular, và có thể thu hồi nhanh chóng cho các AWS principals cross-account mà không cần chỉnh sửa key policy (chỉ giới hạn 10,000 policy bytes).
  • ✅ Với hàng trăm vendors thay đổi hàng tuần, việc programmatically create/revoke grants qua API (như CreateGrant và RetireGrant) là hiệu quả nhất về vận hành: Tự động hóa dễ dàng, không giới hạn số lượng grants (lên đến 10,000 active grants/key theo docs 2024-2026), không yêu cầu update policy lớn, và hỗ trợ delegation cross-account trực tiếp.
  • 🛠️ Quy trình: Vendor account principal được grant quyền kms:Decrypt hoặc tương ứng → Vendor truy cập S3 object → Auto revoke khi vendor list thay đổi. Giảm thiểu lỗi con người và scale tốt.

📋 Phân tích tất cả các phương án (đúng/sai)

  • Phương án 1: Use KMS grants to manage key access. Programmatically create and revoke grants to manage vendor access.
    ✅ Đúng - Như giải thích trên, đây là best practice của AWS cho dynamic cross-account access. Grants linh hoạt, programmatic, không ảnh hưởng key policy chính, scale lớn (hàng trăm vendors), và là lựa chọn MOST operationally efficient theo AWS Well-Architected Framework (Security Pillar, 2026 update).

  • Phương án 2: Use an IAM role to manage key access. Programmatically update the IAM role policies to manage vendor access.
    ❌ Sai - IAM role policies chỉ kiểm soát quyền trong account (không trực tiếp cho cross-account KMS). Để cross-account, cần assume role, nhưng programmatically update IAM role policies cho hàng trăm vendors sẽ vi phạm quota (policy size limit 10,240 chars), khó scale, và không efficient (phải redeploy/update liên tục).

  • Phương án 3: Use KMS key policies to manage key access. Programmatically update the KMS key policies to manage vendor access.
    ❌ Sai - KMS key policies hỗ trợ cross-account, nhưng update policy programmatically cho hàng trăm vendors sẽ nhanh chóng vượt giới hạn 10,000 bytes/policy (theo KMS limits 2026), gây lỗi quota. Không efficient cho thay đổi hàng tuần (mỗi update là versioning policy mới, tốn thời gian propagate).

  • Phương án 4: Use delegated access across AWS accounts by using IAM roles to manage key access. Programmatically update the IAM trust policy to manage cross-account vendor access.
    ❌ Sai - IAM trust policy chỉ cho phép assume role từ principals cụ thể, nhưng update trust policy programmatically cho hàng trăm vendors cross-account sẽ gặp vấn đề tương tự: policy size limit, service quotas, và phức tạp (phải quản lý role riêng + key policy cho phép role). Không trực tiếp/efficient như grants, tăng overhead vận hành.

📘 Tài liệu tham khảo (AWS docs cập nhật 2026)

🛠️ Lời khuyên thực tế: Kết hợp với S3 bucket policies cho object access + CloudTrail audit grants. Test với AWS CLI: aws kms create-grant --key-id <key> --grantee-principal arn:aws:iam::VENDOR-ACCT:root --operations Decrypt.

Câu 399
A company runs an application on a fleet of Amazon EC2 instances behind an Application Load Balancer (ALB). A security engineer needs to provide secure access to the application without requiring the use of a VPN. Users should be able to access the application only when they meet specific security conditions, including a defined device posture.

Which solution will meet these requirements?
  1. A Create an AWS WAF web ACL. Configure a custom response to block traffic that does not align with the defined device posture.
  2. B Configure AWS Verified Access. Add the application by creating an endpoint for the ALB.
  3. C Configure Amazon Verified Permissions. Use a policy-based access control (PBAC) policy to perform authorization.
  4. D Configure Amazon Verified Permissions. Add the application by creating an endpoint for the ALB.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả một tình huống thực tế trong môi trường AWS:
Một công ty đang chạy ứng dụng trên fleet Amazon EC2 instances đứng sau Application Load Balancer (ALB). Kỹ sư bảo mật cần cung cấp truy cập an toàn vào ứng dụng mà không yêu cầu sử dụng VPN. Người dùng chỉ được phép truy cập khi đáp ứng các điều kiện bảo mật cụ thể, bao gồm device posture (tư thế thiết bị - ví dụ: thiết bị có cập nhật phần mềm bảo mật, antivirus đang chạy, hoặc tuân thủ các tiêu chuẩn bảo mật định sẵn).

Mục tiêu là triển khai giải pháp zero-trust access (không tin tưởng mặc định), kiểm tra posture trước khi cho phép truy cập, tích hợp trực tiếp với ALB mà không cần VPN. Đây là yêu cầu điển hình cho AWS Verified Access - dịch vụ mới hỗ trợ kiểm tra device posture qua các đối tác như CrowdStrike, Zscalr, giúp đảm bảo truy cập an toàn từ xa. (Kiến thức cập nhật đến 2026: AWS Verified Access đã GA từ 2023 và được khuyến nghị cho các use case zero-trust không VPN).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Configure AWS Verified Access. Add the application by creating an endpoint for the ALB.

Lý do:
🛡️ AWS Verified Access là giải pháp lý tưởng cho yêu cầu này. Nó cung cấp truy cập xác thực và ủy quyền dựa trên zero-trust mà không cần VPN, hỗ trợ kiểm tra device posture thông qua integration với các công cụ như CrowdStrike Falcon, BeyondCorp, giúp đánh giá thiết bị trước khi cấp quyền truy cập. Bạn có thể tạo endpoint cho ALB để bảo vệ ứng dụng trực tiếp, với các policy kiểm tra điều kiện bảo mật cụ thể. Giải pháp này tích hợp liền mạch với ALB, hỗ trợ HTTP/HTTPS và các giao thức khác, đảm bảo an toàn cao nhất mà không thay đổi kiến trúc hiện tại.

📋 Phân tích tất cả các phương án (đúng/sai)

Dưới đây là phân tích chi tiết từng lựa chọn. Tôi giữ nguyên nội dung văn bản gốc bằng tiếng Anh cho các phương án, và giải thích hoàn toàn bằng tiếng Việt với lý do đúng/sai:

  • ❌ [SAI] Create an AWS WAF web ACL. Configure a custom response to block traffic that does not align with the defined device posture.
    🛑 Sai vì: AWS WAF (Web Application Firewall) chủ yếu dùng để bảo vệ web app khỏi các tấn công như SQL injection, XSS, hoặc rate limiting dựa trên IP/Geo. Nó không hỗ trợ kiểm tra device posture (như trạng thái antivirus, OS patch) vì WAF hoạt động ở layer 7 và chỉ kiểm tra request headers/body, không tích hợp sâu với agent trên thiết bị. Custom response chỉ block traffic đơn giản, không đáp ứng zero-trust với posture check. (Không phù hợp cho non-VPN access với device conditions).

  • ✅ [ĐÚNG] Configure AWS Verified Access. Add the application by creating an endpoint for the ALB.
    🟢 Đúng vì: Như đã giải thích ở trên, Verified Access được thiết kế chính xác cho use case này: tạo endpoint enforcer cho ALB, hỗ trợ device posture signals từ các provider (CrowdStrike, etc.), và cho phép truy cập an toàn không VPN. Policy engine linh hoạt kiểm tra multiple conditions trước khi route traffic đến ALB.

  • ❌ [SAI] Configure Amazon Verified Permissions. Use a policy-based access control (PBAC) policy to perform authorization.
    🛑 Sai vì: Amazon Verified Permissions dùng Cedar policy language cho fine-grained authorization trong apps (như kiểm tra role/user attributes), nhưng không phải giải pháp access proxy và không hỗ trợ device posture check. Nó tập trung vào PBAC sau khi đã authenticate, không tạo endpoint cho ALB hay thay thế VPN. Không đáp ứng yêu cầu kiểm tra security conditions trước access.

  • ❌ [SAI] Configure Amazon Verified Permissions. Add the application by creating an endpoint for the ALB.
    🛑 Sai vì: Verified Permissions không hỗ trợ tạo endpoint cho ALB (nó là dịch vụ policy management, không phải access gateway). Không có tính năng device posture hay zero-trust proxy như Verified Access. Sử dụng sai dịch vụ dẫn đến không giải quyết được vấn đề non-VPN secure access.

📘 Tài liệu tham khảo (cập nhật mới nhất đến 2026)

Giải pháp này giúp đạt DevOps Engineer Professional best practices: secure, scalable, và không downtime! 🚀 Nếu cần demo CDK/Terraform, hãy hỏi thêm!

Câu 400
A company needs to retain data that is stored in Amazon CloudWatch Logs log groups. The company must retain this data for 90 days. The company must receive notification in AWS Security Hub when log group retention is not compliant with this requirement.

Which solution will provide the appropriate notification?
  1. A Create a Security Hub custom action to assess the log group retention period.
  2. B Create a data protection policy in CloudWatch Logs to assess the log group retention period.
  3. C Create a Security Hub automation rule. Configure the automation rule to assess the log group retention period.
  4. D Use the AWS Config managed rule that assesses the log group retention period. Ensure that AWS Config integration is enabled in Security Hub.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc quản lý và giám sát thời gian lưu trữ (retention period) dữ liệu trong Amazon CloudWatch Logs log groups. Cụ thể:

  • Công ty yêu cầu giữ dữ liệu ít nhất 90 ngày (retention period ≥ 90 ngày).
  • Khi bất kỳ log group nào không tuân thủ (retention < 90 ngày), hệ thống phải gửi thông báo (notification) qua AWS Security Hub.
  • Mục tiêu là tìm giải pháp tích hợp tự động giữa CloudWatch Logs, AWS Config và Security Hub để phát hiện và cảnh báo vi phạm chính sách lưu trữ, đảm bảo tuân thủ (compliance) mà không cần can thiệp thủ công.

Đây là tình huống thực tế trong DevOps, liên quan đến governance, compliance và monitoring trên AWS, sử dụng các dịch vụ native để tự động hóa kiểm tra và tích hợp với Security Hub (dịch vụ trung tâm hóa bảo mật và tuân thủ).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use the AWS Config managed rule that assesses the log group retention period. Ensure that AWS Config integration is enabled in Security Hub.

Lý do 🛠️:

  • AWS Config cung cấp managed rule có sẵn tên cloudwatch-log-group-retention-period-check, tự động kiểm tra retention period của tất cả CloudWatch Log Groups và đánh dấu NON_COMPLIANT nếu < 90 ngày (có thể tùy chỉnh thông số).
  • Khi bật tích hợp AWS Config với Security Hub (qua Security Hub console > Integrations > AWS Config), các findings từ rule này sẽ tự động xuất hiện trong Security Hub dưới dạng security findings, kích hoạt notification (email/SNS/EventBridge).
  • Giải pháp này đơn giản, chi phí thấp, scalable và tuân thủ best practices AWS đến năm 2026 (không thay đổi lớn trong AWS Config/Security Hub integration).
  • ✅ Hoàn hảo khớp yêu cầu: Assess retention → Tạo finding → Notification qua Security Hub.

📋 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, với nội dung gốc giữ nguyên tiếng Anh:

  • ❌ Create a Security Hub custom action to assess the log group retention period.
    Sai vì: Security Hub custom actions chỉ dùng để thực hiện hành động tự động (như Lambda invocation) khi đã có finding tồn tại, không phải để tạo hoặc assess kiểm tra mới như retention period. Không có cơ chế assess log groups trực tiếp từ custom action. 🧩 Điều này sẽ không phát hiện vi phạm từ đầu.

  • ❌ Create a data protection policy in CloudWatch Logs to assess the log group retention period.
    Sai vì: CloudWatch Logs không hỗ trợ "data protection policy" như mô tả (tính năng này không tồn tại đến 2026). CloudWatch Logs chỉ có retention settings thủ công/API, không tích hợp policy để assess và gửi đến Security Hub. 🛠️ Có thể nhầm lẫn với Amazon Macie (data protection cho S3) hoặc GuardDuty, nhưng không áp dụng cho Logs.

  • ❌ Create a Security Hub automation rule. Configure the automation rule to assess the log group retention period.
    Sai vì: Security Hub automation rules chỉ xử lý findings đã có (filter/tag/suppress/update), không dùng để assess hoặc tạo kiểm tra mới như retention period của log groups. Không kết nối trực tiếp với CloudWatch Logs để đánh giá compliance. 📘 Rules này dành cho remediation, không phải discovery.

  • ✅ Use the AWS Config managed rule that assesses the log group retention period. Ensure that AWS Config integration is enabled in Security Hub.
    Đúng vì: Như giải thích ở trên, rule managed cloudwatch-log-group-retention-period-check của AWS Config tự động đánh giá tất cả log groups, tích hợp liền mạch với Security Hub để gửi notification. Hỗ trợ tùy chỉnh retention (ví dụ: 90 ngày) qua config rule parameters.

📘 Tài liệu tham khảo (cập nhật đến 2026)

Giải pháp này đảm bảo zero-touch compliance! 🚀 Nếu cần triển khai thực tế, tôi có thể hướng dẫn CDK/Terraform code.