Ngân hàng đề — AWS Certified Security Specialty

Tìm thấy 445 câu.

Câu 421
A security engineer has noticed an unusually high amount of traffic coming from a single IP address. This was discovered by analyzing the Application Load Balancer’s access logs.

How can the security engineer limit the number of requests from a specific IP address without blocking the IP address?
  1. A Add a rule to the Application Load Balancer to route the traffic originating from the IP address in question and show a static webpage.
  2. B Implement a rate-based rule with AWS WAF.
  3. C Use AWS Shield to limit the originating traffic hit rate.
  4. D Implement the GeoLocation feature in Amazon Route 53.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào tình huống bảo mật trên AWS, cụ thể là một kỹ sư bảo mật phát hiện lượng traffic bất thường cao từ một địa chỉ IP duy nhất thông qua việc phân tích access logs của Application Load Balancer (ALB). Mục tiêu là giới hạn số lượng requests từ IP cụ thể này mà KHÔNG chặn hoàn toàn IP đó (tức là không block tuyệt đối, mà chỉ throttle hoặc rate limit).

🛠️ Bối cảnh kỹ thuật:

  • ALB access logs ghi lại thông tin chi tiết về requests, giúp phát hiện nguồn traffic đáng ngờ (như DDoS nhẹ hoặc scraping).
  • Yêu cầu nhấn mạnh rate limiting theo IP (ví dụ: giới hạn 100 requests/phút từ IP đó), phù hợp với các tính năng bảo mật AWS hiện đại (cập nhật đến 2026, AWS WAF v2 hỗ trợ rate-based rules linh hoạt hơn với integration sâu vào ALB/CloudFront).
  • Không muốn block IP để tránh ảnh hưởng legitimate traffic, chỉ limit để giảm tải.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Implement a rate-based rule with AWS WAF.

🧩 Lý do chi tiết:

  • AWS WAF (Web Application Firewall) hỗ trợ rate-based rules chính xác để giới hạn số requests từ một IP cụ thể (ví dụ: block tạm thời nếu vượt quá 2000 requests/5 phút từ IP đó).
  • Rule này KHÔNG block vĩnh viễn mà chỉ throttle (giới hạn tốc độ), cho phép traffic hợp lệ tiếp tục sau khi giảm tốc độ – hoàn hảo khớp yêu cầu.
  • WAF tích hợp trực tiếp với ALB, tự động áp dụng rule dựa trên IP nguồn từ access logs hoặc real-time metrics.
  • Cập nhật 2026: WAF v2 hỗ trợ IP sets động và rate limiting dựa trên custom keys (như IP + URI), scalable với Managed Rules từ AWS Marketplace.

❌ Phân tích tất cả các phương án (đúng/sai)

  • [SAI] Add a rule to the Application Load Balancer to route the traffic originating from the IP address in question and show a static webpage.
    ❌ Sai vì: ALB listener rules chỉ hỗ trợ host/path-based routing, header matching, hoặc fixed responses (như static page), nhưng KHÔNG có rate limiting theo IP. Bạn có thể redirect traffic từ IP cụ thể đến static page (giống CAPTCHA), nhưng điều này tương đương block gián tiếp (không phục vụ nội dung thật), vi phạm yêu cầu "không blocking". ALB không theo dõi rate theo IP native.

  • [ĐÚNG] Implement a rate-based rule with AWS WAF.
    ✅ Đúng vì: Như giải thích trên, đây là giải pháp chuẩn AWS cho rate limiting IP-specific trên ALB. WAF rule monitor requests real-time, throttle mà không block hoàn toàn (action: Count/Challenge/Block tạm thời). Dễ deploy via Console/CLI/Terraform.

  • [SAI] Use AWS Shield to limit the originating traffic hit rate.
    ❌ Sai vì: AWS Shield (Standard/Advanced) chuyên bảo vệ DDoS layer 3/4/7, tự động mitigate volumetric attacks nhưng KHÔNG hỗ trợ rate limiting thủ công theo IP đơn lẻ. Shield không cho phép config rule cụ thể như "limit X requests/IP" trên ALB; nó chỉ trigger global protection. Phù hợp DDoS lớn, không phải suspicious single IP.

  • [SAI] Implement the GeoLocation feature in Amazon Route 53.
    ❌ Sai vì: Route 53 Geolocation routing dùng để chuyển hướng traffic dựa trên vị trí địa lý quốc gia/thành phố, không phải rate limit theo IP cụ thể. Nó block/route toàn bộ vùng địa lý, không granular đến single IP, và không integrate trực tiếp với ALB logs để limit requests. Không giải quyết vấn đề traffic cao từ 1 IP.

🛠️ Khuyến nghị thực tế: Sau khi implement WAF rate rule, monitor qua CloudWatch Metrics (WAFBlockedRequests, RateExceeded) và Athena query ALB logs để tinh chỉnh threshold. Kết hợp AWS GuardDuty cho threat detection tự động! 🚀

Câu 422
A company runs workloads that are spread across hundreds of Amazon EC2 instances. During a recent security incident, an EC2 instance was compromised and ran malware code until the company manually terminated the instance.

The company is now using Amazon GuardDuty to detect malware on EC2 instances. A security engineer needs to implement a solution that automates a response when GuardDuty determines that an instance is infected. The solution must mitigate the incident and must comply with the AWS Well-Architected Framework guidance for incident response.

Which solution will meet these requirements?
  1. A Configure AWS Systems Manager Run Command to run when a GuardDuty scan determines that an instance is infected. Use Run Command to remove all network adapters from the operating system of the infected instance. Use Run Command to also add a tag of “Infected” to the instance.
  2. B Create an AWS Lambda function that runs when a GuardDuty scan determines that an instance is infected. Program the Lambda function to delete all elastic network interfaces that are associated with the instance. Program the Lambda function to also add a tag of “Infected” to the instance.
  3. C Create an AWS Lambda function that runs when a GuardDuty scan determines that an instance is infected. Program the Lambda function to detach all Amazon Elastic Block Store (Amazon EBS) volumes from the instance. Program the Lambda function to also add a tag of “Infected” to the EBS volumes and to terminate the instance afterward.
  4. D Define a separate VPC to isolate EC2 instances. Define a security group that does not allow any network traffic. Create an AWS Lambda function that runs when a GuardDuty scan determines that an instance is infected. Program the Lambda function to move the instance into the separate VPC and to assign the security group to the instance.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi này tập trung vào chủ đề bảo mật và phản ứng sự cố (Incident Response) trên AWS, cụ thể là xử lý tự động khi Amazon GuardDuty phát hiện một Amazon EC2 instance bị nhiễm malware.

  • Bối cảnh: Công ty có hàng trăm EC2 instances chạy workload. Gần đây, một instance bị hack chạy mã độc cho đến khi bị terminate thủ công. Bây giờ, họ dùng GuardDuty (dịch vụ phát hiện mối đe dọa sử dụng ML) để quét malware trên EC2 (qua Malware Protection for EC2, scan EBS volumes ngay cả khi instance tắt).
  • Yêu cầu giải pháp:
    • Tự động hóa phản ứng khi GuardDuty xác định instance bị nhiễm (thường qua Amazon EventBridge trigger).
    • Giảm thiểu sự cố (mitigate): Ngăn chặn malware lan rộng, bảo toàn bằng chứng (evidence).
    • Tuân thủ AWS Well-Architected Framework (WAF), đặc biệt Security Pillar về Incident Response:
      • Contain (cách ly): Ngăn malware hoạt động/lan rộng.
      • Eradicate (xóa sổ): Loại bỏ threat.
      • Recover (khôi phục): Phục hồi an toàn.
      • Tránh xóa dữ liệu vội (preserve forensics), ưu tiên immutable evidence như tag EBS volumes.

Giải pháp phải dùng AWS Lambda hoặc tương tự để tự động, không thủ công, và an toàn theo best practices AWS (cập nhật 2024-2026).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create an AWS Lambda function that runs when a GuardDuty scan determines that an instance is infected. Program the Lambda function to detach all Amazon Elastic Block Store (Amazon EBS) volumes from the instance. Program the Lambda function to also add a tag of “Infected” to the EBS volumes and to terminate the instance afterward.

Lý do chọn đáp án này 🛠️:

  • Cách ly hoàn hảo: Detach EBS volumes (lưu trữ dữ liệu/malware) ngay lập tức, ngăn instance truy cập dữ liệu độc hại, malware không lan rộng (contain).
  • Bảo toàn bằng chứng: Tag "Infected" trên EBS volumes (không xóa/detach vĩnh viễn), cho phép forensics sau (attach vào forensic workstation).
  • Kết thúc an toàn: Terminate instance sau detach (eradicate), tránh malware chạy tiếp.
  • Tuân thủ WAF Security Pillar: Chính xác theo hướng dẫn AWS cho EC2 Malware Response – detach EBS trước terminate để preserve evidence. Sử dụng EventBridge rule từ GuardDuty findings trigger Lambda (zero-downtime, scalable).
  • Cập nhật mới nhất (2024-2026): GuardDuty Malware Protection scan EBS snapshots/volumes real-time; Lambda hỗ trợ IAM roles để detach/terminate/tag qua EC2/EBS APIs.

📋 Phân tích tất cả các phương án

Dưới đây là phân tích từng lựa chọn một cách chi tiết. Tôi giữ nguyên văn bản gốc tiếng Anh của phương án, chỉ đánh dấu ✅/❌ và giải thích bằng tiếng Việt:

  • ❌ Phương án 1:
    Configure AWS Systems Manager Run Command to run when a GuardDuty scan determines that an instance is infected. Use Run Command to remove all network adapters from the operating system of the infected instance. Use Run Command to also add a tag of “Infected” to the instance.
    Giải thích sai: ❌ SSM Run Command yêu cầu SSM Agent chạy trên instance và instance phải alive/responsive. Malware có thể block/kháng cự lệnh (disable agent), dẫn đến thất bại. Remove network adapters OS-level (như ip link delete) không isolate hoàn toàn (malware vẫn chạy, có thể dùng loopback/other vectors). Không tuân thủ WAF: Không preserve EBS evidence, rủi ro cao (instance vẫn live).

  • ❌ Phương án 2:
    Create an AWS Lambda function that runs when a GuardDuty scan determines that an instance is infected. Program the Lambda function to delete all elastic network interfaces that are associated with the instance. Program the Lambda function to also add a tag of “Infected” to the instance.
    Giải thích sai: ❌ Không thể delete ENI đang attached trực tiếp (API error: phải detach trước, nhưng Lambda cần quyền và timing chính xác). Chỉ isolate network (malware vẫn chạy trên CPU/RAM/EBS), không eradicate (instance live, có thể rebuild ENI). Tag instance vô ích vì terminate không đề cập. Vi phạm WAF: Không preserve EBS (malware persist trên disk), không full mitigation.

  • ✅ Phương án 3 (Đáp án đúng – đã giải thích chi tiết ở trên):
    Create an AWS Lambda function that runs when a GuardDuty scan determines that an instance is infected. Program the Lambda function to detach all Amazon Elastic Block Store (Amazon EBS) volumes from the instance. Program the Lambda function to also add a tag of “Infected” to the EBS volumes and to terminate the instance afterward.
    Giải thích đúng: ✅ Hoàn hảo theo best practices (xem lý do trên). Lambda dùng EC2 APIs (DetachVolume, CreateTags, TerminateInstances) – nhanh, atomic, no agent needed.

  • ❌ Phương án 4:
    Define a separate VPC to isolate EC2 instances. Define a security group that does not allow any network traffic. Create an AWS Lambda function that runs when a GuardDuty scan determines that an instance is infected. Program the Lambda function to move the instance into the separate VPC and to assign the security group to the instance.
    Giải thích sai: ❌ EC2 instance KHÔNG THỂ move VPC (immutable sau launch – phải tạo instance mới từ AMI). Lambda không hỗ trợ "move VPC" (API không tồn tại). Security Group zero-traffic chỉ block inbound/outbound, nhưng malware vẫn chạy local (không detach EBS). Phức tạp, không scalable (separate VPC overhead), vi phạm WAF Reliability (downtime cao, không eradicate).

📘 Tài liệu tham khảo (Cập nhật AWS 2024-2026)

Hy vọng phân tích này giúp bạn ôn thi AWS Certified DevOps Engineer Professional hiệu quả! 🚀 Nếu cần thêm ví dụ code Lambda, hãy hỏi nhé!

Câu 423
A public subnet contains two Amazon EC2 instances. The subnet has a custom network ACL. A security engineer is designing a solution to improve the subnet security.

The solution must allow outbound traffic to an internet service that uses TLS through port 443. The solution also must deny inbound traffic that is destined for MySQL port 3306.

Which network ACL rule set meets these requirements?
  1. A Use inbound rule 100 to allow traffic on TCP port 443. Use inbound rule 200 to deny traffic on TCP port 3306. Use outbound rule 100 to allow traffic on TCP port 443.
  2. B Use inbound rule 100 to deny traffic on TCP port 3306. Use inbound rule 200 to allow traffic on TCP port range 1024-65535. Use outbound rule 100 to allow traffic on TCP port 443.
  3. C Use inbound rule 100 to allow traffic on TCP port range 1024-65535. Use inbound rule 200 to deny traffic on TCP port 3306. Use outbound rule 100 to allow traffic on TCP port 443.
  4. D Use inbound rule 100 to deny traffic on TCP port 3306. Use inbound rule 200 to allow traffic on TCP port 443. Use outbound rule 100 to allow traffic on TCP port 443.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi xoay quanh việc thiết kế quy tắc Network ACL (NACL) tùy chỉnh cho một public subnet chứa 2 instance Amazon EC2. Public subnet có route table dẫn đến Internet Gateway (IGW), cho phép giao tiếp ra internet. NACL là stateless firewall ở mức subnet (khác với stateful Security Group ở mức instance), nghĩa là mọi hướng traffic (inbound/outbound) phải được explicit allow, không tự động cho phép response.

Yêu cầu cụ thể của solution:

  • ✅ Allow outbound traffic từ EC2 đến internet service sử dụng TLS port 443 (HTTPS): EC2 khởi tạo kết nối → source port là ephemeral (1024-65535), destination port 443. Response từ internet → inbound với source port 443, destination port ephemeral (1024-65535).
  • ❌ Deny inbound traffic destined for MySQL port 3306 (destination port 3306 từ ngoài vào EC2).

Quy tắc NACL được đánh số thứ tự (thấp nhất ưu tiên trước), kết thúc bằng implicit deny. Phiên bản AWS mới nhất (2026): Không thay đổi cơ bản về NACL, vẫn yêu cầu explicit ephemeral ports cho response (xem AWS VPC User Guide).

📘 Tài liệu tham khảo:

  • AWS Documentation: Network ACLs (cập nhật 2025-2026).
  • AWS Exam Content Outline DOP-C02 (DevOps Engineer Pro): VPC Networking & Security.

✅ Đáp án đúng

Use inbound rule 100 to deny traffic on TCP port 3306. Use inbound rule 200 to allow traffic on TCP port range 1024-65535. Use outbound rule 100 to allow traffic on TCP port 443.

Lý do chọn 🛠️:

  • Inbound rule 100 (deny TCP 3306): Ưu tiên đầu tiên, chặn traffic inbound nhắm đến port 3306 (MySQL) trước khi kiểm tra các rule khác.
  • Inbound rule 200 (allow TCP 1024-65535): Cho phép response từ HTTPS (destination port ephemeral của EC2). Port 3306 nằm trong range này nhưng đã bị deny ở rule 100.
  • Outbound rule 100 (allow TCP 443): Cho phép EC2 gửi request HTTPS ra internet (destination port 443).
  • Hoàn hảo vì NACL stateless → phải explicit allow ephemeral inbound cho response. Không rule thừa, thứ tự đúng.

❌ Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn giữ nguyên văn bản gốc (bằng tiếng Anh). Mỗi phương án được đánh giá dựa trên yêu cầu allow HTTPS outbound + deny MySQL inbound.

  • Use inbound rule 100 to allow traffic on TCP port 443. Use inbound rule 200 to deny traffic on TCP port 3306. Use outbound rule 100 to allow traffic on TCP port 443.
    ❌ Sai: Inbound rule 100 allow port 443 (không cần thiết cho response HTTPS, vì response cần destination ephemeral 1024-65535, không phải 443). Rule 200 deny 3306 quá muộn nếu có traffic khác; thiếu allow ephemeral inbound → HTTPS response bị chặn. Outbound đúng nhưng tổng thể không đủ.

  • Use inbound rule 100 to deny traffic on TCP port 3306. Use inbound rule 200 to allow traffic on TCP port range 1024-65535. Use outbound rule 100 to allow traffic on TCP port 443.
    ✅ Đúng: Như giải thích ở trên. Thứ tự inbound hoàn hảo (deny cụ thể trước allow range), outbound chính xác cho HTTPS. Đáp ứng stateless nature của NACL.

  • Use inbound rule 100 to allow traffic on TCP port range 1024-65535. Use inbound rule 200 to deny traffic on TCP port 3306. Use outbound rule 100 to allow traffic on TCP port 443.
    ❌ Sai: Inbound rule 100 allow 1024-65535 trước tiên → traffic đến port 3306 (nằm trong range) bị allow trước khi đến rule 200 deny → không chặn được MySQL. Outbound đúng nhưng inbound fail yêu cầu deny 3306.

  • Use inbound rule 100 to deny traffic on TCP port 3306. Use inbound rule 200 to allow traffic on TCP port 443. Use outbound rule 100 to allow traffic on TCP port 443.
    ❌ Sai: Inbound rule 200 allow port 443 (sai port cho response; response cần ephemeral destination, không phải 443). Thiếu allow 1024-65535 → HTTPS response inbound bị chặn dù outbound OK. Deny 3306 đúng nhưng tổng thể thiếu ephemeral.

Kết luận 🎯: Chỉ phương án thứ 2 mới cân bằng stateless rules, thứ tự ưu tiên đúng, và chính xác port mapping cho HTTPS + deny MySQL!

Câu 424
A company is investigating actions that an IAM role performed. The company must find out when the role last accessed AWS Security Hub and when the role last used the DeleteInsight action in Security Hub.

Which solution will provide this information?
  1. A Use the checks for the security category in AWS Trusted Advisor. Search for the role and examine the actions taken.
  2. B Use the Access Advisor tab in AWS Identity and Access Management (IAM). Search for Security Hub and the actions taken.
  3. C Use AWS Identity and Access Management (IAM) to generate a credential report. Search the report for Security Hub activity.
  4. D Create an analyzer in AWS Identity and Access Management Access Analyzer. Examine the findings for the role’s actions in Security Hub.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc điều tra lịch sử truy cập của một IAM role trong AWS, cụ thể là:

  • Thời điểm cuối cùng IAM role truy cập AWS Security Hub (dịch vụ bảo mật tổng hợp dữ liệu từ nhiều nguồn).
  • Thời điểm cuối cùng IAM role sử dụng action DeleteInsight (hành động xóa Insight - một tính năng phát hiện vấn đề bảo mật trong Security Hub).

Mục tiêu là tìm giải pháp chính xác để lấy thông tin này một cách hiệu quả và trực tiếp. Đây là chủ đề thuộc IAM (Identity and Access Management), liên quan đến tính năng theo dõi truy cập dịch vụ (service last accessed) và hành động cụ thể (actions last accessed), cập nhật theo phiên bản AWS mới nhất đến năm 2026 (IAM Access Analyzer và Access Advisor được cải tiến mạnh mẽ với dữ liệu real-time hơn).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use the Access Advisor tab in AWS Identity and Access Management (IAM). Search for Security Hub and the actions taken.

Lý do:

  • IAM Access Advisor (truy cập qua tab "Access Advisor" trong IAM console cho role/user) cung cấp dữ liệu lịch sử truy cập chi tiết nhất, bao gồm:
    • Service last accessed: Thời gian cuối cùng role truy cập Security Hub.
    • Actions last accessed: Danh sách các action cụ thể (như securityhub:DeleteInsight) và thời gian cuối cùng sử dụng.
  • Tính năng này miễn phí, dữ liệu cập nhật liên tục (lên đến 400 ngày lịch sử theo AWS 2026), và dễ tìm kiếm bằng cách chọn role → tab Access Advisor → lọc Security Hub → xem actions.
  • Đây là cách chính thức AWS khuyến nghị cho việc audit truy cập IAM mà không cần CloudTrail log phức tạp. 🛠️

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng lựa chọn một cách chi tiết, đánh dấu ✅ (đúng) hoặc ❌ (sai), với lý do dựa trên chức năng thực tế của AWS:

  • ❌ [SAI] Use the checks for the security category in AWS Trusted Advisor. Search for the role and examine the actions taken.
    Giải thích: AWS Trusted Advisor chỉ cung cấp kiểm tra best practices tổng quát (như security checks), không theo dõi lịch sử truy cập cụ thể của role hay thời gian action như DeleteInsight. Nó không tìm kiếm role ARN hay actions chi tiết, chỉ đưa ra khuyến nghị chung (ví dụ: unused permissions). Không phù hợp cho audit lịch sử. 🛑

  • ✅ [ĐÚNG] Use the Access Advisor tab in AWS Identity and Access Management (IAM). Search for Security Hub and the actions taken.
    Giải thích: Như đã nêu ở phần đáp án đúng, đây là tính năng chuyên biệt của IAM để xem "last accessed time" cho service (Security Hub) và actions (DeleteInsight). Dữ liệu trực quan, dễ lọc, và chính xác 100% cho yêu cầu. Hoàn hảo! 🎯

  • ❌ [SAI] Use AWS Identity and Access Management (IAM) to generate a credential report. Search the report for Security Hub activity.
    Giải thích: IAM Credential Report chỉ báo cáo trạng thái credentials (access keys active/inactive, password last used, MFA status), không chứa thông tin truy cập service hay actions như Security Hub/DeleteInsight. Nó là file CSV tĩnh, không dùng để audit lịch sử hành động. Sai hoàn toàn! 🚫

  • ❌ [SAI] Create an analyzer in AWS Identity and Access Management Access Analyzer. Examine the findings for the role’s actions in Security Hub.
    Giải thích: IAM Access Analyzer phân tích policy hiện tại để tìm external access risks (ví dụ: policy cho phép truy cập cross-account), không cung cấp lịch sử thời gian truy cập/action. Findings tập trung vào "what if" chứ không phải "when last accessed". Không đáp ứng yêu cầu lịch sử cụ thể. ❌

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Hy vọng phân tích này giúp bạn nắm vững! Nếu cần thực hành lab, hãy dùng IAM console trực tiếp. 🚀

Câu 425
A company hosts its microservices application on Amazon Elastic Kubernetes Service (Amazon EKS). The company has set up continuous deployments to update the application on demand.

A security engineer must implement a solution to provide automatic detection of anomalies in application logs in near real time. The solution also must send notifications about these anomalies to the security team.

Which solution will meet these requirements?
  1. A Configure Amazon CloudWatch Container Insights to collect and aggregate EKS application logs. Create a CloudWatch alarm to monitor for anomalies. Configure the alarm to launch an AWS Lambda function to alert the security team when anomalies are detected.
  2. B Configure Amazon EKS to send application logs to Amazon CloudWatch. Create a CloudWatch alarm based on a log group metric filter. Specify anomaly detection as the threshold type. Configure the alarm to use Amazon Simple Notification Service (Amazon SNS) to alert the security team.
  3. C Configure Amazon EKS to export logs to Amazon S3. Use Amazon Athena queries to analyze the logs for anomalies. Use Amazon QuickSight to visualize and monitor user access requests for anomalies. Configure Amazon Simple Notification Service (Amazon SNS) notifications to alert the security team.
  4. D Configure AWS App Mesh to monitor the traffic to the microservices in Amazon EKS. Integrate App Mesh with AWS CloudTrail for logging. Use Amazon Detective to analyze the logs for anomalies and to alert the security team when anomalies are detected.
Xem giải thích

🧩 Phân tích câu hỏi trắc nghiệm AWS

📘 Nội dung câu hỏi được giải thích chi tiết:
Câu hỏi mô tả một công ty đang triển khai ứng dụng microservices trên Amazon Elastic Kubernetes Service (Amazon EKS), với quy trình continuous deployments để cập nhật ứng dụng theo nhu cầu. Một security engineer cần triển khai giải pháp tự động phát hiện các bất thường (anomalies) trong application logs một cách gần real-time (near real-time). Giải pháp còn phải gửi thông báo cho đội ngũ security khi phát hiện anomalies.
🛠️ Yêu cầu chính:

  • Phát hiện anomalies từ logs ứng dụng EKS.
  • Xử lý nhanh chóng (near real-time).
  • Tích hợp thông báo tự động (notifications).
    Đây là tình huống điển hình trong DevSecOps, tập trung vào logging và monitoring trên EKS với công cụ AWS native, đảm bảo scalability và low-latency.

✅ Đáp án đúng:
Configure Amazon EKS to send application logs to Amazon CloudWatch. Create a CloudWatch alarm based on a log group metric filter. Specify anomaly detection as the threshold type. Configure the alarm to use Amazon Simple Notification Service (Amazon SNS) to alert the security team.

Lý do chọn đáp án đúng (chi tiết):

  • EKS gửi logs trực tiếp đến CloudWatch Logs qua Fluent Bit hoặc Fluentd (tích hợp native từ EKS 1.18+), hỗ trợ near real-time ingestion.
  • Metric filter trên log group trích xuất metrics từ logs (ví dụ: số lượng errors, latencies).
  • Anomaly detection là tính năng ML-native của CloudWatch Alarms (ra mắt 2021, cập nhật liên tục đến 2026), tự động học bandwidth anomalies dựa trên lịch sử dữ liệu, threshold type "Anomaly Detection" cho phép phát hiện outliers mà không cần set static threshold.
  • SNS integration gửi notify tức thì qua email/SMS/Slack/Teams.
    Giải pháp này fully managed, cost-effective, và near real-time (logs ingest trong giây).

📚 Tài liệu tham khảo:

🔍 Phân tích tất cả các phương án (đúng/sai)

  • ✅ Phương án ĐÚNG (như đã giải thích ở trên):
    Configure Amazon EKS to send application logs to Amazon CloudWatch. Create a CloudWatch alarm based on a log group metric filter. Specify anomaly detection as the threshold type. Configure the alarm to use Amazon Simple Notification Service (Amazon SNS) to alert the security team.
    🟢 Hoàn hảo khớp yêu cầu: native integration, ML-based anomaly detection real-time, SNS notify.

  • ❌ Phương án SAI:
    Configure Amazon CloudWatch Container Insights to collect and aggregate EKS application logs. Create a CloudWatch alarm to monitor for anomalies. Configure the alarm to launch an AWS Lambda function to alert the security team when anomalies are detected.
    ❌ Lý do sai: Container Insights chủ yếu thu thập metrics và performance data (CPU, memory, network) từ EKS pods/nodes, không tập trung vào application logs chi tiết để anomaly detection. Alarms chỉ hỗ trợ static/breach thresholds, không có anomaly detection native trên logs từ Insights. Lambda notify thêm latency, không optimal cho near real-time logs.

  • ❌ Phương án SAI:
    Configure Amazon EKS to export logs to Amazon S3. Use Amazon Athena queries to analyze the logs for anomalies. Use Amazon QuickSight to visualize and monitor user access requests for anomalies. Configure Amazon Simple Notification Service (Amazon SNS) notifications to alert the security team.
    ❌ Lý do sai: Export logs sang S3 là batch process (không near real-time, delay minutes/giờ). Athena là query engine cho dữ liệu stored, QuickSight dành cho visualization/dashboard (không tự động detect anomalies real-time). Tập trung "user access requests" lệch khỏi application logs, SNS notify nhưng toàn bộ pipeline quá chậm.

  • ❌ Phương án SAI:
    Configure AWS App Mesh to monitor the traffic to the microservices in Amazon EKS. Integrate App Mesh with AWS CloudTrail for logging. Use Amazon Detective để analyze the logs for anomalies and to alert the security team when anomalies are detected.
    ❌ Lý do sai: App Mesh monitor service mesh traffic (metrics như latency, errors HTTP), không phải application logs nội bộ. CloudTrail log API calls (không phải app logs). Amazon Detective phân tích security findings từ CloudTrail/VPC flow logs, không hỗ trợ anomaly detection trên EKS app logs real-time, chủ yếu cho investigation post-event.

🎯 Kết luận: Giải pháp đúng tận dụng CloudWatch Logs + Anomaly Detection – best practice cho EKS monitoring theo AWS Well-Architected Framework (Security Pillar, 2024 update). Các phương án sai thiếu real-time hoặc không khớp logs source! 🚀

Câu 426
A company is migrating container workloads from a data center to Amazon Elastic Container Service (Amazon ECS) clusters. The company must implement a solution to detect potential threats in the workloads and to improve the security posture of the container clusters.

Which solution will meet these requirements?
  1. A Configure Amazon Inspector on the VPC that is running the ECS clusters.
  2. B Enable Amazon GuardDuty Runtime Monitoring on the ECS clusters.
  3. C Audit Amazon ECS API access by using Amazon CloudWatch logs to identify unauthorized access.
  4. D Create container clusters in the same VPC. Use VPC flow logs to centrally monitor network traffic.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc di chuyển workload container từ data center sang Amazon ECS clusters (dịch vụ quản lý container serverless hoặc trên EC2 của AWS). Yêu cầu chính là triển khai giải pháp để:

  • Phát hiện các mối đe dọa tiềm năng (potential threats) trong workload (như mã độc, hoạt động đáng ngờ tại runtime).
  • Cải thiện security posture (tư thế bảo mật) của các ECS clusters.
    🛡️ Đây là vấn đề bảo mật runtime cho container, cần công cụ chuyên biệt theo dõi hành vi thời gian thực trong container, không chỉ scan tĩnh hoặc network.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Enable Amazon GuardDuty Runtime Monitoring on the ECS clusters.
🧠 Lý do: Amazon GuardDuty Runtime Monitoring (ra mắt năm 2022 và cập nhật liên tục đến 2026) là tính năng chuyên dụng cho ECS (bao gồm Fargate và EC2 launch type). Nó phát hiện threats runtime như crypto mining, privilege escalation, suspicious processes trong container mà không cần agent. Giải pháp này trực tiếp detect threats in workloads và cải thiện security posture bằng cách cung cấp insights, alerts tự động qua EventBridge/CloudWatch. Hoàn hảo khớp yêu cầu!

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá dựa trên tài liệu AWS mới nhất (2026): GuardDuty hỗ trợ runtime monitoring ECS/EKS/Fargate đầy đủ; Inspector tập trung vulnerability scanning.

  • ❌ [SAI] Configure Amazon Inspector on the VPC that is running the ECS clusters.
    🛑 Giải thích sai: Amazon Inspector (cập nhật 2026 với coverage cho container images và EC2) scan vulnerabilities tĩnh (như CVE trong image/OS), không phải runtime threats trong workload đang chạy. Áp dụng trên VPC không hợp lý vì Inspector không monitor VPC mà target instances/containers trực tiếp. Không detect threats động như malicious behavior.

  • ✅ [ĐÚNG] Enable Amazon GuardDuty Runtime Monitoring on the ECS clusters.
    🎯 Giải thích đúng: Như đã nêu, GuardDuty Runtime Monitoring phân tích behavior tại runtime (process, file, network connections) trong ECS tasks/containers. Hỗ trợ agentless trên Fargate/EC2, tích hợp Malware Protection (2023+). Trực tiếp meet yêu cầu detect threats và boost security posture với ML-based detection. (Nguồn: AWS GuardDuty docs - Runtime Monitoring for ECS).

  • ❌ [SAI] Audit Amazon ECS API access by using Amazon CloudWatch logs to identify unauthorized access.
    🔒 Giải thích sai: Đây chỉ audit API calls (như ECS DescribeClusters) qua CloudTrail + CloudWatch Logs, phát hiện unauthorized access từ người dùng/API. Không liên quan đến threats trong workload container (như malware chạy bên trong task), chỉ bảo vệ control plane chứ không phải data plane/runtime.

  • ❌ [SAI] Create container clusters in the same VPC. Use VPC flow logs to centrally monitor network traffic.
    🌐 Giải thích sai: VPC Flow Logs ghi network traffic (IP, ports) giữa clusters/VPC, hữu ích cho network monitoring nhưng không detect threats trong container workload (như process độc hại không liên quan network). Không cải thiện security posture runtime; chỉ là basic traffic visibility.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

🛠️ Lời khuyên DevOps: Kết hợp GuardDuty với ECS IAM roles, Image Scanning (Inspector/ECR), và X-Ray cho full observability!

Câu 427
A security engineer needs to implement a solution to determine whether a company’s Amazon EC2 instances are being used to mine cryptocurrency. The solution must provide notifications of cryptocurrency-related activity to an Amazon Simple Notification Service (Amazon SNS) topic.

Which solution will meet these requirements?
  1. A Create AWS Config custom rules by using Guard custom policy. Configure the AWS Config rules to detect when an EC2 instance queries a DNS domain name that is associated with cryptocurrency-related activity. Configure AWS Config to initiate alerts to the SNS topic.
  2. B Enable Amazon GuardDuty. Create an Amazon EventBridge rule to send alerts to the SNS topic when GuardDuty creates a finding that is associated with cryptocurrency-related activity.
  3. C Enable Amazon Inspector. Create an Amazon EventBridge rule to send alerts to the SNS topic when Amazon Inspector creates a finding that is associated with cryRtocurrency-related activity.
  4. D Enable VPC flow logs. Send the flow logs to an Amazon S3 bucket. Set up a query in Amazon Athena to detect when an EC2 instance queries a DNS domain name that is associated with cryptocurrency-related activity. Configure the Athena query to initiate alerts to the SNS topic.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai một giải pháp bảo mật trên AWS để phát hiện các instance Amazon EC2 đang bị sử dụng cho hoạt động khai thác tiền mã hóa (cryptocurrency mining). Yêu cầu chính là:

  • Giải pháp phải tự động phát hiện hoạt động liên quan đến cryptocurrency (như truy vấn DNS đến domain mining, hoặc các pattern mining cụ thể).
  • Khi phát hiện, gửi thông báo ngay lập tức đến Amazon SNS topic để cảnh báo.

Đây là tình huống thực tế trong bảo mật AWS, nơi cần threat detection (phát hiện mối đe dọa) mà không yêu cầu can thiệp thủ công phức tạp. Giải pháp phải tích hợp sẵn, thời gian thực (near real-time), và dễ mở rộng cho nhiều EC2 instances. Sử dụng kiến thức AWS cập nhật đến năm 2026, Amazon GuardDuty là dịch vụ threat detection hàng đầu hỗ trợ phát hiện cryptocurrency mining qua các finding cụ thể như CryptoCurrency:EC2/BitcoinTool hoặc CryptoCurrency:EC2/Mining.

✅ Đáp án đúng

Enable Amazon GuardDuty. Create an Amazon EventBridge rule to send alerts to the SNS topic when GuardDuty creates a finding that is associated with cryptocurrency-related activity.

Lý do lựa chọn:

  • Amazon GuardDuty là dịch vụ threat detection ML-based (machine learning) được thiết kế chuyên biệt để phát hiện các mối đe dọa như cryptocurrency mining trên EC2, thông qua phân tích CloudTrail, VPC Flow Logs, DNS logs mà không cần cấu hình thủ công.
  • GuardDuty tự động tạo findings (báo cáo) cho các hoạt động mining cụ thể (ví dụ: kết nối đến mining pools hoặc chạy mining software).
  • Sử dụng Amazon EventBridge (trước đây là CloudWatch Events) để route events từ GuardDuty findings đến SNS topic một cách near real-time, đảm bảo thông báo tức thì và dễ tích hợp.
  • Đây là best practice theo AWS Well-Architected Framework (Security Pillar), tiết kiệm chi phí và không yêu cầu quản lý log thủ công. Đến năm 2026, GuardDuty vẫn hỗ trợ đầy đủ các crypto threats với coverage mở rộng.

❌ Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá dựa trên tính khả thi, hiệu quả và phù hợp với yêu cầu (phát hiện mining + notify SNS).

  • Create AWS Config custom rules by using Guard custom policy. Configure the AWS Config rules to detect when an EC2 instance queries a DNS domain name that is associated with cryptocurrency-related activity. Configure AWS Config to initiate alerts to the SNS topic.
    ❌ Sai vì: AWS Config dùng để kiểm tra compliance cấu hình tài nguyên (configuration drift), không phải threat detection thời gian thực. Guard (policy language của Config) chỉ kiểm tra trạng thái snapshot định kỳ (không phải log realtime như DNS queries). Phát hiện DNS mining cần log liên tục, Config không hỗ trợ hiệu quả → chậm trễ, không scalable. Không phải giải pháp native cho crypto threats.

  • Enable Amazon GuardDuty. Create an Amazon EventBridge rule to send alerts to the SNS topic when GuardDuty creates a finding that is associated with cryptocurrency-related activity.
    ✅ Đúng (như đã giải thích ở trên). Giải pháp managed, automated, và chính xác cao với GuardDuty's crypto-specific findings.

  • Enable Amazon Inspector. Create an Amazon EventBridge rule to send alerts to the SNS topic when Amazon Inspector creates a finding that is associated cryRtocurrency-related activity.
    ❌ Sai vì: Amazon Inspector là dịch vụ vulnerability scanning (quét lỗ hổng phần mềm/CVEs trên EC2), không phát hiện runtime behaviors như mining (chạy process, network connections). Inspector không có findings cho cryptocurrency → sẽ không trigger alerts. Đến 2026, Inspector tập trung vào CIS benchmarks và package vulnerabilities, không phải threat hunting.

  • Enable VPC flow logs. Send the flow logs to an Amazon S3 bucket. Set up a query in Amazon Athena to detect when an EC2 instance queries a DNS domain name that is associated with cryptocurrency-related activity. Configure the Athena query to initiate alerts to the SNS topic.
    ❌ Sai vì: VPC Flow Logs ghi network traffic nhưng không bao gồm DNS queries chi tiết (chỉ IP/port). Phân tích bằng Athena/S3 là batch processing (chậm, hàng giờ/ngày), không realtime. Cần maintain danh sách domain mining thủ công → phức tạp, tốn kém, dễ miss threats. GuardDuty đã làm việc này tự động từ Flow Logs mà không cần query thủ công.

📘 Tài liệu tham khảo

  • AWS GuardDuty Documentation: GuardDuty CryptoCurrency Findings (xác nhận detections như EC2/Mining, cập nhật 2025-2026).
  • EventBridge Integration: GuardDuty EventBridge.
  • AWS Well-Architected Security Pillar: Threat Detection – Khuyến nghị GuardDuty cho crypto mining.
  • Exam Topic DOP-C02: Phần Security & Compliance (AWS Certified DevOps Engineer Professional, phiên bản 2026).

🛠️ Lời khuyên: Trong thực tế, kích hoạt GuardDuty ở chế độ multi-account qua Organizations và test findings qua AWS Console để verify!

Câu 428
A company controls user access by using IAM users and groups in AWS accounts across an organization in AWS Organizations. The company uses an external identity provider (IdP) for workforce single sign-on (SSO).

The company needs to implement a solution to provide a single management portal to access accounts within the organization. The solution must support the external IdP as a federation source.

Which solution will meet these requirements?
  1. A Enable AWS IAM Identity Center. Specify the external IdP as the identity source.
  2. B Enable federation with AWS Identity and Access Management (IAM). Specify the external IdP as the identity source.
  3. C Migrate to Amazon Verified Permissions. Implement fine-grained access to AWS by using policy-based access control (PBAC).
  4. D Migrate users to AWS Directory Service. Use AWS Control Tower to centralize security across the organization.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một công ty đang quản lý truy cập người dùng thông qua IAM users và groups trong các tài khoản AWS thuộc AWS Organizations. Họ đã sử dụng external Identity Provider (IdP) bên ngoài để hỗ trợ workforce single sign-on (SSO).
Yêu cầu chính: Triển khai giải pháp cung cấp một cổng quản lý duy nhất (single management portal) để truy cập vào các tài khoản trong organization. Giải pháp phải hỗ trợ external IdP làm nguồn federation.
🔍 Điểm mấu chốt: Cần một console trung tâm hóa, tích hợp SSO từ external IdP (như SAML 2.0 hoặc OIDC), phù hợp với mô hình multi-account trong AWS Organizations. Đây là kịch bản điển hình cho việc centralize access management mà không cần migrate users nội bộ (vẫn giữ IAM users/groups hiện tại).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Enable AWS IAM Identity Center. Specify the external IdP as the identity source.

Lý do chi tiết 🛠️:

  • AWS IAM Identity Center (tên mới của AWS SSO từ năm 2022, cập nhật đến 2026) chính là giải pháp chính thức của AWS cung cấp single management portal (portal truy cập duy nhất qua trình duyệt) để quản lý permission sets và truy cập multi-account trong Organizations.
  • Nó hỗ trợ trực tiếp external IdP như nguồn identity source (SAML 2.0, OIDC), cho phép federation SSO mà không cần thay đổi IAM users/groups hiện tại.
  • Người dùng đăng nhập qua IdP → portal trung tâm → assign permission sets cho các accounts. Hoàn hảo khớp yêu cầu!
    📘 Tài liệu tham khảo: AWS IAM Identity Center Documentation và Integrate with external IdP (cập nhật 2024-2026).

📋 Phân tích tất cả các phương án

Dưới đây là phân tích từng phương án một cách chi tiết, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá ✅ (đúng) hoặc ❌ (sai), kèm giải thích rõ ràng dựa trên tính năng AWS mới nhất (2026).

  • Enable AWS IAM Identity Center. Specify the external IdP as the identity source.
    ✅ Đúng hoàn toàn 🏆: Như đã giải thích ở trên, đây là giải pháp native và tối ưu cho single portal với federation external IdP. Hỗ trợ Organizations đầy đủ, không cần migrate gì thêm. Triển khai nhanh qua console Organizations.

  • Enable federation with AWS Identity and Access Management (IAM). Specify the external IdP as the identity source.
    ❌ Sai 🚫: IAM federation (qua SAML/OIDC roles) chỉ hỗ trợ truy cập ứng dụng cụ thể (app-level federation), không cung cấp single management portal trung tâm cho toàn Organizations. Nó yêu cầu setup riêng từng account/role, không scale cho multi-account và thiếu console thống nhất. Không phù hợp cho workforce SSO organization-wide.

  • Migrate to Amazon Verified Permissions. Implement fine-grained access to AWS by using policy-based access control (PBAC).
    ❌ Sai 🚫: Amazon Verified Permissions (ra mắt 2023, cập nhật 2026) là dịch vụ authorization fine-grained sử dụng Cedar policy language cho apps/custom resources, không phải SSO portal hay identity federation. Nó tập trung PBAC (policy-based access control) cho non-AWS resources, yêu cầu migrate lớn và không hỗ trợ external IdP làm nguồn truy cập accounts. Không giải quyết single portal.

  • Migrate users to AWS Directory Service. Use AWS Control Tower to centralize security across the organization.
    ❌ Sai 🚫: AWS Directory Service (Managed Microsoft AD) là dịch vụ directory nội bộ, yêu cầu migrate users từ external IdP – trái với yêu cầu giữ nguyên. AWS Control Tower (cập nhật 2026) dùng cho landing zone/governance baselines, không phải single management portal hỗ trợ external IdP federation. Kết hợp này chỉ centralize security, không cung cấp SSO portal trực tiếp.

Kết luận 🎯: Chỉ AWS IAM Identity Center đáp ứng đầy đủ single portal + external IdP support mà không cần migrate. Đây là best practice cho AWS Organizations theo AWS Well-Architected Framework (Security Pillar). Nếu triển khai, enable qua AWS Organizations console → Identity → Identity source → External IdP!

Câu 429
A company must create annual snapshots of Amazon Elastic Block Store (Amazon EBS) volumes. The company must retain the snapshots for 10 years. The company will use AWS Key Management Service (AWS KMS) to encrypt the EBS volumes and snapshots.

The encryption keys must be rotated automatically every year. Snapshots that were created in previous years must be readable after rotation of the encryption keys.

Which type of KMS keys should the company use for encryption to meet these requirements?
  1. A Asymmetric AWS managed KMS keys with key material created by AWS KMS
  2. B Symmetric customer managed KMS keys with key material created by AWS KMS
  3. C Symmetric customer managed KMS keys with custom imported key material
  4. D Asymmetric AWS managed KMS keys with custom imported key material
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc công ty cần tạo snapshot hàng năm cho Amazon EBS volumes, lưu trữ trong 10 năm, sử dụng AWS KMS để mã hóa EBS volumes và snapshots. Các yêu cầu chính bao gồm:

  • Khóa mã hóa (KMS keys) phải được xoay vòng (rotated) tự động hàng năm (automatic rotation every year).
  • Snapshots từ các năm trước vẫn có thể đọc được (readable) sau khi xoay vòng khóa, nghĩa là dữ liệu cũ không bị mất khả năng giải mã.

🛠️ Bối cảnh kỹ thuật: EBS snapshots được mã hóa bằng KMS keys. Khi rotate key, KMS phải đảm bảo tính tương thích ngược (backward compatibility) để decrypt dữ liệu cũ. Điều này đòi hỏi loại key cụ thể hỗ trợ automatic key rotation mà vẫn giữ lịch sử phiên bản key material để giải mã dữ liệu lịch sử. AWS KMS (cập nhật đến 2026) chỉ hỗ trợ automatic rotation cho một số loại symmetric CMK nhất định.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Symmetric customer managed KMS keys with key material created by AWS KMS

Lý do chi tiết (dựa trên tài liệu AWS KMS mới nhất 2026):

  • Đây là Customer Managed Key (CMK) symmetric với key material do AWS KMS tạo (không phải imported).
  • Loại key này hỗ trợ automatic rotation hàng năm (enable qua AWS Console/CLI/API, AWS tạo new cryptographic material hàng năm nhưng giữ lịch sử versions cũ).
  • Snapshots cũ vẫn readable: KMS tự động quản lý lịch sử key versions, cho phép decrypt dữ liệu được mã hóa bằng key versions trước đó.
  • Phù hợp hoàn hảo cho EBS snapshots dài hạn (10 năm), vì rotation không làm gián đoạn truy cập dữ liệu lịch sử. ✅

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng lựa chọn một cách chi tiết, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá dựa trên khả năng đáp ứng automatic yearly rotation và readability của snapshots cũ.

  • Asymmetric AWS managed KMS keys with key material created by AWS KMS
    ❌ Sai:

    • Asymmetric keys không hỗ trợ automatic rotation (AWS KMS chỉ rotate symmetric keys).
    • AWS managed keys (do AWS quản lý hoàn toàn) không cho phép customer enable yearly rotation; AWS chỉ rotate khi cần thiết, không theo lịch customer.
    • Snapshots cũ có thể readable, nhưng không đáp ứng yêu cầu rotation tự động hàng năm.
  • Symmetric customer managed KMS keys with key material created by AWS KMS
    ✅ Đúng (như đã giải thích ở phần trên):

    • Symmetric CMK với key material từ AWS hỗ trợ enable automatic rotation hàng năm (AWS tạo new material, giữ lịch sử để decrypt dữ liệu cũ).
    • Hoàn toàn phù hợp cho EBS snapshots dài hạn mà không gián đoạn readability.
  • Symmetric customer managed KMS keys with custom imported key material
    ❌ Sai:

    • Imported key material (customer tự tạo và import) không hỗ trợ automatic rotation; customer phải manually rotate bằng cách tạo key mới và re-encrypt (rất phức tạp cho snapshots 10 năm).
    • Sau rotation, snapshots cũ không readable trừ khi customer quản lý thủ công lịch sử material, vi phạm yêu cầu tự động và dễ gây lỗi.
  • Asymmetric AWS managed KMS keys with custom imported key material
    ❌ Sai:

    • Kết hợp asymmetric + AWS managed + imported: Không hỗ trợ automatic rotation (asymmetric không rotate tự động, AWS managed không cho customer control, imported càng không).
    • Readability snapshots cũ không đảm bảo vì thiếu lịch sử versions tự động; phải manual re-key, không phù hợp cho quy trình hàng năm dài hạn.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

  • AWS KMS Developer Guide: Rotating KMS keys – Chi tiết automatic rotation chỉ cho symmetric CMKs với AWS-generated material.
  • Amazon EBS Encryption: EBS Snapshots và KMS – Xác nhận snapshots giữ readability sau CMK rotation.
  • AWS Well-Architected Framework - Security Pillar: Khuyến nghị CMKs cho compliance dài hạn như 10 năm retention.
  • Exam Prep DOP-C02: Chủ đề KMS key types trong DevOps Professional (verified qua AWS re:Post và A Cloud Guru 2026 updates).

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ code CLI/SDK, hãy hỏi nhé!

Câu 430
A company has hundreds of AWS accounts and uses AWS Organizations. The company plans to create many different IAM roles and policies for its product team, security team, and platform team. Some IAM policies will be shared across teams.

A security engineer needs to implement a solution to logically group together the IAM roles of each team. The solution must allow only the platform team to delegate IAM permissions to AWS services.

Which solution will meet these requirements?
  1. A Set up an IAM path with the IAM roles for each team. Deploy an SCP that denies the iam:PassRole permission to all entities except the IAM path of the platform team.
  2. B Apply different tags for each team to the IAM roles. Deploy an SCP that denies the sts:AssumeRole permission to all entities except the roles of the platform team.
  3. C Apply different tags for each team to the IAM policies. Deploy an SCP that denies the iam:PassRole permission to all entities except the policies of the platform team.
  4. D Set up an IAM path with the IAM roles for each team. Use IAM permissions boundaries to deny the sts:AssumeRole permission to the IAM roles for the product team and the security team.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi này xoay quanh việc quản lý IAM roles và permissions trong môi trường AWS Organizations lớn (hàng trăm accounts). Công ty cần:

  • Logically group IAM roles theo từng team: product team, security team, platform team (vì có nhiều roles/policies, một số shared).
  • Chỉ cho phép platform team delegate IAM permissions đến AWS services – điều này ám chỉ quyền iam:PassRole (action cho phép pass một IAM role đến service như Lambda, ECS để service assume role đó). Các team khác không được phép này để tránh rủi ro security.

Yêu cầu giải pháp:

  • Sử dụng AWS Organizations (với SCP - Service Control Policies) để enforce tại organizational level.
  • Group roles một cách logic, không phải tạo OUs riêng (vì hundreds accounts, cần granular hơn).
  • Đảm bảo chỉ platform team được passrole, các team khác bị deny.

🛠️ Kiến thức cốt lõi AWS (cập nhật 2026):

  • IAM paths dùng để group roles/users theo hierarchy (e.g., /team/platform/*).
  • SCPs deny actions với conditions (như path, tags) tại org/account/OU level, không ảnh hưởng existing permissions.
  • iam:PassRole là key action cần control để prevent unauthorized service delegation.

📘 Tài liệu tham khảo:

✅ Đáp án đúng: Set up an IAM path with the IAM roles for each team. Deploy an SCP that denies the iam:PassRole permission to all entities except the IAM path of the platform team.

Lý do lựa chọn:

  • ✅ Group logically: IAM paths cho phép phân loại roles theo đường dẫn như /product/*, /security/*, /platform/* – dễ quản lý, không cần tags phức tạp.
  • ✅ Control chính xác iam:PassRole: SCP với condition Deny iam:PassRole trừ khi iam:PassedToService và role path thuộc /platform/*. Điều này chỉ cho platform team delegate permissions (pass role đến services), các team khác bị block tại org level.
  • ✅ Phù hợp multi-account: SCP propagate qua Organizations, hiệu quả cho hundreds accounts.
  • 🛡️ Best practice: AWS recommend paths/SCPs cho cross-team isolation trong large orgs (không ảnh hưởng assume role thông thường).

📋 Giải thích tất cả các phương án

  • Set up an IAM path with the IAM roles for each team. Deploy an SCP that denies the iam:PassRole permission to all entities except the IAM path of the platform team.
    ✅ Đúng (như phân tích trên). Hoàn hảo vì paths hỗ trợ SCP conditions trực tiếp (e.g., "StringLike": {"iam:RolePath": "/platform/*"}), enforce deny iam:PassRole selective.

  • Apply different tags for each team to the IAM roles. Deploy an SCP that denies the sts:AssumeRole permission to all entities except the roles of the platform team.
    ❌ Sai. Tags có thể dùng cho conditions, nhưng sts:AssumeRole chỉ control ai assume role (không phải delegate/passrole đến services). Yêu cầu là control iam:PassRole (delegate permissions), không phải assume. SCP deny sts:AssumeRole sẽ block assume roles platform team, vi phạm yêu cầu.

  • Apply different tags for each team to the IAM policies. Deploy an SCP that denies the iam:PassRole permission to all entities except the policies of the platform team.
    ❌ Sai. iam:PassRole condition trên roles (không phải policies). Tags trên policies không trực tiếp control PassRole (PassRole kiểm tra role ARN cụ thể). SCP không thể condition chính xác "policies of team" cho PassRole, dẫn đến không enforce đúng.

  • Set up an IAM path with the IAM roles for each team. Use IAM permissions boundaries to deny the sts:AssumeRole permission to the IAM roles for the product team and the security team.
    ❌ Sai. Permissions boundaries limit max permissions của role/user (không deny actions như sts:AssumeRole). Boundaries không control ai gọi PassRole, và sts:AssumeRole không phải focus (lại sai action). Boundaries là per-role, không scalable cho hundreds accounts/Organizations.

🧠 Tóm tắt key takeaway: Giải pháp đúng tận dụng IAM paths + SCP conditions để granular control iam:PassRole – chuẩn DevOps Professional cho large-scale security! 🚀