Ngân hàng đề — AWS Certified Solutions Architect Associate

Tìm thấy 2194 câu.

Câu 1231
A company has registered its domain name with Amazon Route 53. The company uses Amazon API Gateway in the ca-central-1 Region as a public interface for its backend microservice APIs. Third-party services consume the APIs securely. The company wants to design its API Gateway URL with the company's domain name and corresponding certificate so that the third-party services can use HTTPS.
Which solution will meet these requirements?
  1. A Create stage variables in API Gateway with Name="Endpoint-URL" and Value="Company Domain Name" to overwrite the default URL. Import the public certificate associated with the company's domain name into AWS Certificate Manager (ACM).
  2. B Create Route 53 DNS records with the company's domain name. Point the alias record to the Regional API Gateway stage endpoint. Import the public certificate associated with the company's domain name into AWS Certificate Manager (ACM) in the us-east-1 Region.
  3. C Create a Regional API Gateway endpoint. Associate the API Gateway endpoint with the company's domain name. Import the public certificate associated with the company's domain name into AWS Certificate Manager (ACM) in the same Region. Attach the certificate to the API Gateway endpoint. Configure Route 53 to route traffic to the API Gateway endpoint.
  4. D Create a Regional API Gateway endpoint. Associate the API Gateway endpoint with the company's domain name. Import the public certificate associated with the company's domain name into AWS Certificate Manager (ACM) in the us-east-1 Region. Attach the certificate to the API Gateway APIs. Create Route 53 DNS records with the company's domain name. Point an A record to the company's domain name.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi xoay quanh việc thiết kế URL tùy chỉnh cho Amazon API Gateway sử dụng domain name của công ty (đã đăng ký với Amazon Route 53) và chứng chỉ SSL/TLS để hỗ trợ HTTPS an toàn cho các third-party services.

  • Bối cảnh: API Gateway nằm ở Region ca-central-1, hoạt động như public interface cho backend microservices. Yêu cầu chính là tùy chỉnh URL thành domain của công ty (ví dụ: api.company.com) thay vì URL mặc định của AWS, đồng thời đảm bảo HTTPS với chứng chỉ công khai.
  • Thách thức chính (theo docs AWS mới nhất 2024-2026):
    • API Gateway hỗ trợ Regional endpoint (phù hợp cho regional traffic như ở ca-central-1).
    • Custom domain yêu cầu: Tạo Custom Domain Name trong API Gateway, attach ACM certificate (phải ở cùng Region với endpoint cho Regional type), và cấu hình Route 53 để route traffic (thường dùng CNAME hoặc alias).
    • Không hỗ trợ A record trực tiếp hoặc stage variables để overwrite URL.
  • Mục tiêu: Đảm bảo third-party gọi HTTPS qua domain tùy chỉnh mà không lộ URL gốc AWS.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do chọn

Đáp án đúng: Phương án thứ 3 (Create a Regional API Gateway endpoint. Associate the API Gateway endpoint with the company's domain name. Import the public certificate associated with the company's domain name into AWS Certificate Manager (ACM) in the same Region. Attach the certificate to the API Gateway endpoint. Configure Route 53 to route traffic to the API Gateway endpoint.)

Lý do chi tiết 🛠️:

  • ✅ Tạo Regional endpoint phù hợp cho API ở ca-central-1 (không dùng Edge-optimized vì cần regional control).
  • ✅ Import ACM cert ở cùng Region (ca-central-1): Bắt buộc cho Regional custom domain (Edge mới dùng us-east-1).
  • ✅ Associate domain và attach cert trực tiếp vào Custom Domain Name trong API Gateway → Tự động generate target domain (ví dụ: d-abc123.execute-api.ca-central-1.amazonaws.com).
  • ✅ Route 53 route traffic (CNAME hoặc alias) đến target domain → Traffic HTTPS an toàn qua domain tùy chỉnh.
  • Hoàn hảo khớp yêu cầu, theo best practice AWS 2024+ (hỗ trợ TLS 1.3 mặc định).

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng phương án một cách chi tiết, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá dựa trên docs AWS mới nhất.

  • Phương án 1 ❌ SAI:
    Create stage variables in API Gateway with Name="Endpoint-URL" and Value="Company Domain Name" to overwrite the default URL. Import the public certificate associated with the company's domain name into AWS Certificate Manager (ACM).
    Giải thích sai: Stage variables chỉ dùng để dynamic config backend integration (như URL động), KHÔNG overwrite public-facing URL của API Gateway. Không tạo custom domain/HTTPS thực sự. Cert import OK nhưng thiếu associate & Route 53 → Third-party vẫn thấy URL gốc AWS.

  • Phương án 2 ❌ SAI:
    Create Route 53 DNS records with the company's domain name. Point the alias record to the Regional API Gateway stage endpoint. Import the public certificate associated with the company's domain name into AWS Certificate Manager (ACM) in the us-east-1 Region.
    Giải thích sai: Route 53 alias KHÔNG hỗ trợ trực tiếp cho Regional stage endpoint (chỉ alias OK cho Edge-optimized hoặc CloudFront). Cert ở us-east-1 SAI cho Regional ở ca-central-1 (gây lỗi attach). Thiếu Custom Domain Name trong API Gateway → Không có HTTPS custom.

  • Phương án 3 ✅ ĐÚNG (như đã giải thích ở trên).
    Create a Regional API Gateway endpoint. Associate the API Gateway endpoint with the company's domain name. Import the public certificate associated with the company's domain name into AWS Certificate Manager (ACM) in the same Region. Attach the certificate to the API Gateway endpoint. Configure Route 53 to route traffic to the API Gateway endpoint.
    Tóm tắt: Quy trình chuẩn 100%, end-to-end từ docs AWS.

  • Phương án 4 ❌ SAI:
    Create a Regional API Gateway endpoint. Associate the API Gateway endpoint with the company's domain name. Import the public certificate associated with the company's domain name into AWS Certificate Manager (ACM) in the us-east-1 Region. Attach the certificate to the API Gateway APIs. Create Route 53 DNS records with the company's domain name. Point an A record to the company's domain name.
    Giải thích sai: Cert ở us-east-1 KHÔNG dùng được cho Regional endpoint ca-central-1 (lỗi validation/attach). A record SAI hoàn toàn (API Gateway không có IP tĩnh; phải dùng CNAME/alias đến target domain). "Attach to APIs" mơ hồ, không chính xác (phải attach Custom Domain).

Kết luận 🎯: Phương án 3 là optimal, scalable cho production. Nếu deploy thực tế, dùng AWS Console/CLI với --endpoint-configuration cho Regional!

Câu 1232
A company is running a popular social media website. The website gives users the ability to upload images to share with other users. The company wants to make sure that the images do not contain inappropriate content. The company needs a solution that minimizes development effort.
What should a solutions architect do to meet these requirements?
  1. A Use Amazon Comprehend to detect inappropriate content. Use human review for low-confidence predictions.
  2. B Use Amazon Rekognition to detect inappropriate content. Use human review for low-confidence predictions.
  3. C Use Amazon SageMaker to detect inappropriate content. Use ground truth to label low-confidence predictions.
  4. D Use AWS Fargate to deploy a custom machine learning model to detect inappropriate content. Use ground truth to label low-confidence predictions.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một công ty đang vận hành trang web mạng xã hội phổ biến, nơi người dùng có thể upload hình ảnh để chia sẻ. Công ty muốn đảm bảo hình ảnh không chứa nội dung không phù hợp (như nội dung khiêu dâm, bạo lực, v.v.), và giải pháp phải tối thiểu hóa nỗ lực phát triển (minimize development effort).
🛠️ Yêu cầu chính: Cần một dịch vụ AWS sẵn có, dễ tích hợp, không đòi hỏi xây dựng mô hình ML từ đầu, hỗ trợ xử lý low-confidence bằng human review. Đây là bài toán content moderation cho hình ảnh, thuộc lĩnh vực Solutions Architect Professional (SAP-C01 hoặc DOP-C02).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use Amazon Rekognition to detect inappropriate content. Use human review for low-confidence predictions.
Lý do:
Amazon Rekognition là dịch vụ nhận diện hình ảnh và video chuyên dụng của AWS, có sẵn API DetectModerationLabels để phát hiện nội dung không phù hợp (như explicit nudity, suggestive, violence, weapons). Nó trả về confidence score, cho phép human review cho low-confidence (dưới ngưỡng như 80-90%). Giải pháp này plug-and-play, không cần train model, tích hợp dễ dàng với S3/Lambda, tối thiểu hóa development effort. Phù hợp với best practice AWS đến 2026 (Rekognition v7+ hỗ trợ multi-language moderation).
📘 Tài liệu tham khảo:

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá dựa trên tính phù hợp, effort và tính năng AWS mới nhất (2026).

  • ❌ [SAI] Use Amazon Comprehend to detect inappropriate content. Use human review for low-confidence predictions.
    Amazon Comprehend là dịch vụ NLP cho text (phân tích sentiment, entities, toxicity trong văn bản), KHÔNG hỗ trợ hình ảnh. Không thể detect inappropriate content trong images. Sử dụng sẽ yêu cầu custom pipeline (OCR + text moderation), tăng effort cao, không minimize development.

  • ✅ [ĐÚNG] Use Amazon Rekognition to detect inappropriate content. Use human review for low-confidence predictions.
    Như đã giải thích ở trên: Hoàn hảo phù hợp với image moderation, confidence-based filtering, zero-code training. Tích hợp nhanh với API calls từ Lambda/S3 events.

  • ❌ [SAI] Use Amazon SageMaker to detect inappropriate content. Use ground truth to label low-confidence predictions.
    Amazon SageMaker là nền tảng build/train/deploy custom ML models, đòi hỏi data labeling, training, tuning (ground truth cho low-confidence). Effort rất cao (dev + data scientists), KHÔNG minimize development. Rekognition đã pre-trained cho moderation, SageMaker chỉ dùng nếu cần custom.

  • ❌ [SAI] Use AWS Fargate to deploy a custom machine learning model to detect inappropriate content. Use ground truth to label low-confidence predictions.
    AWS Fargate là container orchestration serverless, chỉ dùng để deploy model đã train (từ SageMaker hoặc custom). Vẫn cần build/train model riêng + ground truth labeling, effort cực cao (infra management + ML ops). Không phải giải pháp managed, vi phạm yêu cầu minimize effort.

🏆 Kết luận & Best Practice

Giải pháp Rekognition + human review (qua Amazon A2I hoặc custom queue) là serverless, scalable, cost-effective (~$0.001/image). Triển khai mẫu: S3 trigger → Rekognition → SNS/SQS cho low-confidence → Human queue.
🔄 Cập nhật 2026: Rekognition hỗ trợ Custom Moderation Labels (train trên dataset riêng nếu cần), nhưng base version đã đủ cho hầu hết cases. Luôn test với AWS Free Tier!

Câu 1233
A company wants to run its critical applications in containers to meet requirements for scalability and availability. The company prefers to focus on maintenance of the critical applications. The company does not want to be responsible for provisioning and managing the underlying infrastructure that runs the containerized workload.
What should a solutions architect do to meet these requirements?
  1. A Use Amazon EC2 instances, and install Docker on the instances.
  2. B Use Amazon Elastic Container Service (Amazon ECS) on Amazon EC2 worker nodes.
  3. C Use Amazon Elastic Container Service (Amazon ECS) on AWS Fargate.
  4. D Use Amazon EC2 instances from an Amazon Elastic Container Service (Amazon ECS)-optimized Amazon Machine Image (AMI).
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi mô tả một công ty muốn triển khai các ứng dụng quan trọng (critical applications) dưới dạng container để đảm bảo khả năng mở rộng (scalability) và khả dụng cao (availability). Họ ưu tiên tập trung vào việc bảo trì ứng dụng thay vì phải lo lắng về việc cung cấp và quản lý hạ tầng cơ sở (provisioning and managing the underlying infrastructure) chạy workload containerized.

🛠️ Yêu cầu chính: Giải pháp phải serverless hoặc không cần quản lý server, giúp công ty chỉ tập trung vào code ứng dụng, trong khi AWS xử lý phần hạ tầng (như EC2 instances, networking, scaling). Đây là kịch bản điển hình cho container orchestration trên AWS, nhấn mạnh vào AWS Fargate – dịch vụ compute serverless cho containers (cập nhật đến 2026, Fargate hỗ trợ ECS và EKS với các tính năng mới như Fargate Spot, ARM64 Graviton processors, và tích hợp sâu với AWS VPC).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use Amazon Elastic Container Service (Amazon ECS) on AWS Fargate.

Lý do:

  • AWS Fargate là mô hình serverless cho Amazon ECS, cho phép chạy containers mà không cần quản lý EC2 instances hay bất kỳ hạ tầng nào. AWS tự động xử lý provisioning, scaling, patching, và availability của underlying infrastructure.
  • Đáp ứng hoàn hảo yêu cầu: Scalability (auto-scaling tasks/services), Availability (multi-AZ), và focus vào app maintenance (chỉ định nghĩa task definitions, không lo server).
  • Theo tài liệu AWS mới nhất (2026), Fargate hỗ trợ ECR integration, IAM roles for tasks, và platform version 1.4+ với enhanced networking, lý tưởng cho critical apps.

📋 Phân tích tất cả các phương án

  • ❌ Use Amazon EC2 instances, and install Docker on the instances.
    Phương án này yêu cầu công ty tự cài đặt và quản lý Docker trên EC2, bao gồm provisioning instances, OS patching, scaling thủ công, và high availability (như Auto Scaling Groups). Sai vì vi phạm yêu cầu "không chịu trách nhiệm quản lý underlying infrastructure" – công ty phải lo toàn bộ server management.

  • ❌ Use Amazon Elastic Container Service (Amazon ECS) on Amazon EC2 worker nodes.
    ECS trên EC2 vẫn cần quản lý worker nodes EC2 (chọn instance types, capacity providers, ASG). AWS chỉ orchestrate containers, nhưng infra vẫn do công ty chịu trách nhiệm. Sai vì không serverless, dẫn đến overhead maintenance cao cho critical apps.

  • ✅ Use Amazon Elastic Container Service (Amazon ECS) on AWS Fargate.
    Đúng như đã giải thích ở trên: Serverless compute, AWS handle toàn bộ infra (provisioning, scaling, security). Hỗ trợ full ECS features như blue/green deployments qua CodeDeploy, phù hợp scalability/availability mà không cần quản lý server.

  • ❌ Use Amazon EC2 instances from an Amazon Elastic Container Service (Amazon ECS)-optimized Amazon Machine Image (AMI).
    AMI này chỉ tối ưu hóa cho ECS (pre-installed Docker/agent), nhưng vẫn phải quản lý EC2 instances (launch, monitor, patch). Sai vì không loại bỏ trách nhiệm infra, chỉ tiện lợi hơn so với install thủ công.

📘 Tài liệu tham khảo

  • AWS Documentation (ECS with Fargate): Amazon ECS on AWS Fargate – Mô tả serverless model (cập nhật 2026 với Fargate 1.4+).
  • AWS Well-Architected Framework (Serverless Lens): Containers Pillar – Khuyến nghị Fargate cho no-infra management.
  • AWS re:Post & Blogs: Tìm "ECS Fargate vs EC2" trên re:Post cho case studies critical workloads.

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm ví dụ thực tế, hỏi nhé!

Câu 1234
A company hosts more than 300 global websites and applications. The company requires a platform to analyze more than 30 TB of clickstream data each day.
What should a solutions architect do to transmit and process the clickstream data?
  1. A Design an AWS Data Pipeline to archive the data to an Amazon S3 bucket and run an Amazon EMR cluster with the data to generate analytics.
  2. B Create an Auto Scaling group of Amazon EC2 instances to process the data and send it to an Amazon S3 data lake for Amazon Redshift to use for analysis.
  3. C Cache the data to Amazon CloudFront. Store the data in an Amazon S3 bucket. When an object is added to the S3 bucket. run an AWS Lambda function to process the data for analysis.
  4. D Collect the data from Amazon Kinesis Data Streams. Use Amazon Kinesis Data Firehose to transmit the data to an Amazon S3 data lake. Load the data in Amazon Redshift for analysis.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc xây dựng một nền tảng xử lý dữ liệu clickstream (dữ liệu theo dõi hành vi người dùng như click, view trang) từ hơn 300 website và ứng dụng toàn cầu, với khối lượng khổng lồ hơn 30 TB mỗi ngày. 🛡️️ Yêu cầu chính là truyền tải (transmit) và xử lý (process) dữ liệu này một cách hiệu quả, scalable, và chi phí thấp trên AWS.

  • Thách thức chính: Dữ liệu real-time, volume cao (30TB/ngày ≈ 347 GB/giờ), phân tán toàn cầu → cần giải pháp streaming ingestion, lưu trữ data lake, và phân tích OLAP.
  • Mục tiêu: Solutions Architect phải chọn kiến trúc tối ưu cho ingestion → storage → analytics, tận dụng serverless và managed services để tránh quản lý hạ tầng thủ công. 📈
  • Kiến thức cập nhật 2026: AWS ưu tiên Kinesis family (Data Streams/Firehose), S3 Data Lake, Redshift Spectrum cho petabyte-scale analytics (theo AWS Well-Architected Framework for Data Analytics, phiên bản mới nhất).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Collect the data from Amazon Kinesis Data Streams. Use Amazon Kinesis Data Firehose to transmit the data to an Amazon S3 data lake. Load the data in Amazon Redshift for analysis.

Lý do chọn:

  • 🏆 Hoàn hảo cho streaming high-volume: Kinesis Data Streams thu thập real-time từ hàng nghìn nguồn (300+ sites), hỗ trợ shards tự scale lên hàng TB/giờ. Firehose (fully managed) tự động batch, compress, encrypt và deliver đến S3 mà không cần code phức tạp.
  • 📊 Data lake + Analytics: S3 làm data lake scalable, Redshift (với Spectrum) query trực tiếp trên S3 mà không cần load full dataset → tiết kiệm chi phí, hỗ trợ ML/ BI tools.
  • 💰 Serverless & Global: Tích hợp CloudFront/Kinesis Agent cho edge collection, auto-scale, pay-per-use. Phù hợp Well-Architected pillars: Reliability, Performance Efficiency (AWS 2026 updates: Firehose hỗ trợ direct-to-Redshift).

🔍 Phân tích tất cả các phương án (đúng/sai)

  • ❌ Phương án SAI: Design an AWS Data Pipeline to archive the data to an Amazon S3 bucket and run an Amazon EMR cluster with the data to generate analytics.
    Giải thích: AWS Data Pipeline đã deprecated từ 2019 và không còn hỗ trợ mới (xác nhận AWS docs 2026). Không phù hợp real-time streaming (batch-oriented), EMR tốn kém khởi động cluster thủ công cho 30TB/ngày, thiếu scalability tự động. 🛑

  • ❌ Phương án SAI: Create an Auto Scaling group of Amazon EC2 instances to process the data and send it to an Amazon S3 data lake for Amazon Redshift to use for analysis.
    Giải thích: EC2 ASG yêu cầu quản lý OS/patching/code deployment thủ công, khó scale real-time toàn cầu (latency cao, chi phí idle instances). Không serverless, vi phạm Operational Excellence pillar; 30TB/ngày dễ overload CPU/network. 🚫

  • ❌ Phương án SAI: Cache the data to Amazon CloudFront. Store the data in an Amazon S3 bucket. When an object is added to the S3 bucket. run an AWS Lambda function to process the data for analysis.
    Giải thích: CloudFront là CDN cache static content, không thiết kế cho ingest clickstream (không persistent storage). Lambda trigger S3 có timeout 15 phút, memory limit (10GB), không xử lý 30TB batch lớn → throttling/error. Không real-time. ⛔

  • ✅ Phương án ĐÚNG: Collect the data from Amazon Kinesis Data Streams. Use Amazon Kinesis Data Firehose to transmit the data to an Amazon S3 data lake. Load the data in Amazon Redshift for analysis.
    Giải thích: Kinesis Streams ingest real-time đa nguồn, Firehose transform/deliver seamless đến S3 (partitioning tự động), Redshift query federated trên data lake. Scalable ∞ shards, VPC endpoints global, tích hợp Athena/SageMaker. Hoàn hảo cho volume cao! 🎯

📘 Tài liệu tham khảo

Kiến trúc này là best practice cho clickstream analytics như Netflix/Amazon dùng! 🚀

Câu 1235
A company has a website hosted on AWS. The website is behind an Application Load Balancer (ALB) that is configured to handle HTTP and HTTPS separately. The company wants to forward all requests to the website so that the requests will use HTTPS.
What should a solutions architect do to meet this requirement?
  1. A Update the ALB's network ACL to accept only HTTPS traffic.
  2. B Create a rule that replaces the HTTP in the URL with HTTPS.
  3. C Create a listener rule on the ALB to redirect HTTP traffic to HTTPS.
  4. D Replace the ALB with a Network Load Balancer configured to use Server Name Indication (SNI).
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc cấu hình Application Load Balancer (ALB) trên AWS để chuyển hướng tất cả các yêu cầu (requests) từ HTTP sang HTTPS.

  • Bối cảnh: Website được lưu trữ trên AWS, phía sau một ALB đã được thiết lập riêng biệt để xử lý lưu lượng HTTP (thường trên cổng 80) và HTTPS (thường trên cổng 443).
  • Yêu cầu: Đảm bảo tất cả requests đều sử dụng HTTPS, nghĩa là các request HTTP phải được redirect (chuyển hướng) tự động sang HTTPS mà không làm mất dữ liệu hoặc trải nghiệm người dùng.
  • Mục tiêu chính: Đây là best practice bảo mật trên AWS để enforce HTTPS everywhere, tránh lưu lượng không mã hóa và tuân thủ các tiêu chuẩn như PCI DSS hoặc GDPR. ALB hỗ trợ điều này qua listener rules với redirect actions (301 hoặc 302 status code).

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create a listener rule on the ALB to redirect HTTP traffic to HTTPS.

🛠️ Lý do chi tiết:

  • ALB hỗ trợ listener trên cổng 80 (HTTP) với rule action là redirect đến HTTPS (cổng 443), sử dụng HTTP status code 301 (permanent redirect) hoặc 302 (temporary).
  • Quy trình: Tạo listener HTTP → Thêm rule → Chọn action "Redirect" → Chỉ định protocol HTTPS, port 443, và giữ nguyên host/path/query.
  • Điều này đơn giản, không tốn kém, và tích hợp sẵn trong ALB mà không cần thay đổi infrastructure. Đáp ứng chính xác yêu cầu "forward all requests to HTTPS".
  • Cập nhật mới nhất (2026): ALB vẫn là lựa chọn hàng đầu cho L7 (HTTP/HTTPS) với redirect rules; hỗ trợ gRPC và HTTP/3.

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn một cách chi tiết:

  • Update the ALB's network ACL to accept only HTTPS traffic.
    ❌ Sai: Network ACL (NACL) là lớp bảo mật Layer 3/4 cho subnet VPC, không phải thuộc tính của ALB và không thể "chấp nhận chỉ HTTPS" (HTTPS là Layer 7). NACL chỉ lọc theo IP/port/protocol (ví dụ: block port 80), nhưng không redirect traffic – nó chỉ drop packets, dẫn đến lỗi 503/timeout cho client HTTP. Không giải quyết yêu cầu "forward to HTTPS".

  • Create a rule that replaces the HTTP in the URL with HTTPS.
    ❌ Sai: ALB không có rule thay thế "HTTP" trong URL như vậy. Listener rules chỉ hỗ trợ path-based routing, host-based, hoặc redirect actions, không phải string replacement trong URL scheme. Cách này không tồn tại và có thể gây lỗi; phải dùng redirect rule chuẩn thay vì "thay thế".

  • Create a listener rule on the ALB to redirect HTTP traffic to HTTPS.
    ✅ Đúng: Như đã giải thích ở trên. Đây là phương pháp chính thức và hiệu quả nhất của AWS cho ALB. Listener rule trên HTTP listener với redirect action sẽ tự động chuyển hướng client browser sang HTTPS mà không cần code thay đổi ở backend.

  • Replace the ALB with a Network Load Balancer configured to use Server Name Indication (SNI).
    ❌ Sai: Network Load Balancer (NLB) là Layer 4 (TCP/UDP/TLS), không hỗ trợ HTTP redirect vì không inspect HTTP headers. SNI chỉ dùng cho TLS handshake (chọn certificate), không redirect HTTP sang HTTPS. Thay NLB sẽ phức tạp hóa (cần target group riêng), tốn kém hơn ALB cho L7, và không đáp ứng yêu cầu.

🧠 Kết luận: Phương pháp đúng tận dụng native feature của ALB để enforce HTTPS một cách mượt mà, scalable. Nếu triển khai thực tế, dùng AWS Console/CLI/Terraform với rule như: aws elbv2 create-rule --listener-arn <http-listener> --priority 1 --actions Type=redirect,RedirectConfig={Protocol=HTTPS,Port=443,StatusCode=HTTP_301}.

Câu 1236
A company is developing a two-tier web application on AWS. The company's developers have deployed the application on an Amazon EC2 instance that connects directly to a backend Amazon RDS database. The company must not hardcode database credentials in the application. The company must also implement a solution to automatically rotate the database credentials on a regular basis.
Which solution will meet these requirements with the LEAST operational overhead?
  1. A Store the database credentials in the instance metadata. Use Amazon EventBridge (Amazon CloudWatch Events) rules to run a scheduled AWS Lambda function that updates the RDS credentials and instance metadata at the same time.
  2. B Store the database credentials in a configuration file in an encrypted Amazon S3 bucket. Use Amazon EventBridge (Amazon CloudWatch Events) rules to run a scheduled AWS Lambda function that updates the RDS credentials and the credentials in the configuration file at the same time. Use S3 Versioning to ensure the ability to fall back to previous values.
  3. C Store the database credentials as a secret in AWS Secrets Manager. Turn on automatic rotation for the secret. Attach the required permission to the EC2 role to grant access to the secret.
  4. D Store the database credentials as encrypted parameters in AWS Systems Manager Parameter Store. Turn on automatic rotation for the encrypted parameters. Attach the required permission to the EC2 role to grant access to the encrypted parameters.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai một ứng dụng web hai tầng (two-tier web application) trên AWS, với frontend chạy trên Amazon EC2 instance và backend là Amazon RDS database. Yêu cầu chính là:

  • Không hardcode database credentials (tên người dùng/mật khẩu) trực tiếp trong code ứng dụng để tránh rủi ro bảo mật.
  • Tự động rotate (xoay vòng) credentials định kỳ để tăng cường an ninh.
  • Giải pháp phải có LEAST operational overhead (ít công sức vận hành nhất), nghĩa là ưu tiên các dịch vụ AWS managed, tự động hóa cao, không cần code custom hay quản lý thủ công nhiều.

Mục tiêu là bảo mật credentials (secrets) cho EC2 kết nối RDS, sử dụng IAM role để truy cập an toàn, và rotation tự động mà không cần can thiệp thường xuyên. Đây là tình huống điển hình trong DevOps trên AWS, nhấn mạnh zero-trust security và least privilege theo best practices cập nhật 2024-2026.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Store the database credentials as a secret in AWS Secrets Manager. Turn on automatic rotation for the secret. Attach the required permission to the EC2 role to grant access to the secret.

Lý do:

  • AWS Secrets Manager là dịch vụ chuyên quản lý secrets (như DB credentials) với tự động rotation built-in cho RDS (hỗ trợ MySQL, PostgreSQL, SQL Server, Oracle, Aurora). Chỉ cần bật automatic rotation qua console/API, Secrets Manager sẽ tự tạo Lambda function managed để rotate credentials mà không cần code custom.
  • EC2 sử dụng IAM role attach policy secretsmanager:GetSecretValue để retrieve secret động (qua SDK như boto3), không lưu trữ local.
  • Least overhead: Toàn bộ quá trình managed bởi AWS, không cần EventBridge/Lambda custom, versioning thủ công hay quản lý file. Giảm rủi ro và chi phí vận hành.
  • Cập nhật 2026: Secrets Manager hỗ trợ rotation multi-account, caching cải tiến, và tích hợp chặt chẽ hơn với RDS Proxy cho scalability.

🛠️ Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, với giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai dựa trên tính khả thi, bảo mật và operational overhead:

  • ❌ Phương án SAI: Store the database credentials in the instance metadata. Use Amazon EventBridge (Amazon CloudWatch Events) rules to run a scheduled AWS Lambda function that updates the RDS credentials and instance metadata at the same time.
    Giải thích: Instance metadata (IMDSv2) không dành cho lưu trữ secrets lâu dài vì dễ bị truy cập nếu instance bị compromise (IMDS public). Không có rotation tự động native; phải custom Lambda + EventBridge để update đồng bộ RDS và metadata, dẫn đến overhead cao (code Lambda, handle failure, sync issues). Không best practice, vi phạm nguyên tắc "secrets không lưu trên instance".

  • ❌ Phương án SAI: Store the database credentials in a configuration file in an encrypted Amazon S3 bucket. Use Amazon EventBridge (Amazon CloudWatch Events) rules to run a scheduled AWS Lambda function that updates the RDS credentials and the credentials in the configuration file at the same time. Use S3 Versioning to ensure the ability to fall back to previous values.
    Giải thích: S3 tốt cho static files nhưng không phải secrets store. Phải custom Lambda + EventBridge để rotate RDS và update file S3 (encrypt bằng SSE-KMS), versioning chỉ hỗ trợ rollback nhưng không tự động hóa retrieve cho app. Overhead lớn: Quản lý file sync, polling S3 từ EC2 (IAM access), rủi ro exposure nếu bucket misconfig. Không managed như Secrets Manager.

  • ✅ Phương án ĐÚNG: Store the database credentials as a secret in AWS Secrets Manager. Turn on automatic rotation for the secret. Attach the required permission to the EC2 role to grant access to the secret.
    Giải thích: Như đã nêu ở phần đáp án đúng. Hoàn hảo khớp yêu cầu: Rotation tự động (AWS-managed Lambda), EC2 IAM role truy cập an toàn (GetSecretValue), không hardcode, zero custom code. Overhead thấp nhất nhờ fully managed service.

  • ❌ Phương án SAI: Store the database credentials as encrypted parameters in AWS Systems Manager Parameter Store. Turn on automatic rotation for the encrypted parameters. Attach the required permission to the EC2 role to grant access to the encrypted parameters.
    Giải thích: Parameter Store (SecureString với KMS) lưu trữ tốt nhưng KHÔNG hỗ trợ automatic rotation built-in cho DB credentials (chỉ có TTL cho expiration, không rotate RDS). Phải custom Lambda để rotate, không "turn on" đơn giản như Secrets Manager. Overhead cao hơn: EC2 cần SSM agent hoặc API calls thường xuyên, kém hiệu quả cho high-frequency access so với Secrets Manager caching.

📘 Tài liệu tham khảo (AWS Docs cập nhật 2024-2026)

Giải pháp này đảm bảo compliance PCI-DSS, HIPAA và scalability! 🚀

Câu 1237
A company is deploying a new public web application to AWS. The application will run behind an Application Load Balancer (ALB). The application needs to be encrypted at the edge with an SSL/TLS certificate that is issued by an external certificate authority (CA). The certificate must be rotated each year before the certificate expires.
What should a solutions architect do to meet these requirements?
  1. A Use AWS Certificate Manager (ACM) to issue an SSL/TLS certificate. Apply the certificate to the ALB. Use the managed renewal feature to automatically rotate the certificate.
  2. B Use AWS Certificate Manager (ACM) to issue an SSL/TLS certificate. Import the key material from the certificate. Apply the certificate to the ALUse the managed renewal feature to automatically rotate the certificate.
  3. C Use AWS Certificate Manager (ACM) Private Certificate Authority to issue an SSL/TLS certificate from the root CA. Apply the certificate to the ALB. Use the managed renewal feature to automatically rotate the certificate.
  4. D Use AWS Certificate Manager (ACM) to import an SSL/TLS certificate. Apply the certificate to the ALB. Use Amazon EventBridge (Amazon CloudWatch Events) to send a notification when the certificate is nearing expiration. Rotate the certificate manually.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai một ứng dụng web công khai mới trên AWS, chạy phía sau Application Load Balancer (ALB). Yêu cầu chính là mã hóa SSL/TLS tại edge (tức là ngay tại ALB để xử lý traffic HTTPS từ client). Chứng chỉ SSL/TLS phải được cấp bởi một Certificate Authority (CA) bên ngoài AWS (external CA, không phải ACM tự issue). Ngoài ra, chứng chỉ cần được rotate (xoay vòng/thay mới) hàng năm trước khi hết hạn để đảm bảo an ninh liên tục.

🛠️ Các yếu tố kỹ thuật cần lưu ý:

  • ALB hỗ trợ gắn chứng chỉ SSL/TLS từ AWS Certificate Manager (ACM).
  • External CA có nghĩa là chứng chỉ từ nhà cung cấp bên thứ ba (như DigiCert, Let's Encrypt), không phải ACM public CA hoặc private CA.
  • Rotation phải tự động hoặc có cơ chế cảnh báo, nhưng với external CA, ACM không hỗ trợ auto-renewal (chỉ hỗ trợ cho cert do ACM tự issue).

Mục tiêu: Tìm giải pháp tuân thủ yêu cầu external CA và xử lý rotation hiệu quả.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng là lựa chọn cuối cùng:
Use AWS Certificate Manager (ACM) to import an SSL/TLS certificate. Apply the certificate to the ALB. Use Amazon EventBridge (Amazon CloudWatch Events) to send a notification when the certificate is nearing expiration. Rotate the certificate manually.

Lý do chọn đáp án này 🏆:

  • ACM cho phép import chứng chỉ từ external CA (bao gồm private key), sau đó gắn trực tiếp vào ALB để mã hóa tại edge.
  • Với imported cert, ACM không auto-renew, nên dùng Amazon EventBridge (trước là CloudWatch Events) để theo dõi sự kiện "nearing expiration" (gần hết hạn, thường 30/45 ngày trước), gửi thông báo qua SNS/Email/Lambda để admin rotate thủ công (tải cert mới từ external CA và import lại).
  • Giải pháp này đúng yêu cầu 100%: External CA, mã hóa ALB, rotation hàng năm (manual nhưng có alert tự động). Đây là best practice theo AWS đến năm 2026.

📋 Giải thích tất cả các phương án (đúng/sai)

  • Phương án 1: Use AWS Certificate Manager (ACM) to issue an SSL/TLS certificate. Apply the certificate to the ALB. Use the managed renewal feature to automatically rotate the certificate.
    ❌ Sai vì: ACM chỉ issue cert từ public CA của AWS (không phải external CA như yêu cầu). Managed renewal chỉ hoạt động với cert do ACM tự issue, không phù hợp với external CA.

  • Phương án 2: Use AWS Certificate Manager (ACM) to issue an SSL/TLS certificate. Import the key material from the certificate. Apply the certificate to the ALUse the managed renewal feature to automatically rotate the certificate.
    ❌ Sai vì: Vẫn dùng ACM issue cert (không phải external CA). "Import key material" chỉ là bổ sung key cho cert ACM issue, không thay đổi nguồn gốc cert. Managed renewal vẫn không áp dụng cho external CA. Lưu ý: Text có lỗi đánh máy ("ALU" thay vì "ALB"), nhưng không ảnh hưởng phân tích.

  • Phương án 3: Use AWS Certificate Manager (ACM) Private Certificate Authority to issue an SSL/TLS certificate from the root CA. Apply the certificate to the ALB. Use the managed renewal feature to automatically rotate the certificate.
    ❌ Sai vì: ACM Private CA dùng cho internal/private cert (không public-facing như web app công khai). Không phải "external CA" (external nghĩa là bên ngoài AWS). Managed renewal cho private cert phức tạp và không tự động như public ACM cert.

  • Phương án 4 (Đúng): Use AWS Certificate Manager (ACM) to import an SSL/TLS certificate. Apply the certificate to the ALB. Use Amazon EventBridge (Amazon CloudWatch Events) to send a notification when the certificate is nearing expiration. Rotate the certificate manually.
    ✅ Đúng vì: Import cert từ external CA vào ACM → Gắn ALB dễ dàng. EventBridge theo dõi expiration event → Alert tự động → Rotate manual (phù hợp cert external). Hoàn hảo cho public web app!

📘 Tài liệu tham khảo (kiến thức cập nhật đến 2026)

Giải pháp này đảm bảo tuân thủ AWS best practices, an toàn và scalable! 🚀 Nếu cần demo code CloudFormation/EventBridge rule, hãy hỏi thêm nhé!

Câu 1238
A company runs its infrastructure on AWS and has a registered base of 700,000 users for its document management application. The company intends to create a product that converts large .pdf files to .jpg image files. The .pdf files average 5 MB in size. The company needs to store the original files and the converted files. A solutions architect must design a scalable solution to accommodate demand that will grow rapidly over time.
Which solution meets these requirements MOST cost-effectively?
  1. A Save the .pdf files to Amazon S3. Configure an S3 PUT event to invoke an AWS Lambda function to convert the files to .jpg format and store them back in Amazon S3.
  2. B Save the .pdf files to Amazon DynamoDUse the DynamoDB Streams feature to invoke an AWS Lambda function to convert the files to .jpg format and store them back in DynamoDB.
  3. C Upload the .pdf files to an AWS Elastic Beanstalk application that includes Amazon EC2 instances, Amazon Elastic Block Store (Amazon EBS) storage, and an Auto Scaling group. Use a program in the EC2 instances to convert the files to .jpg format. Save the .pdf files and the .jpg files in the EBS store.
  4. D Upload the .pdf files to an AWS Elastic Beanstalk application that includes Amazon EC2 instances, Amazon Elastic File System (Amazon EFS) storage, and an Auto Scaling group. Use a program in the EC2 instances to convert the file to .jpg format. Save the .pdf files and the .jpg files in the EBS store.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc thiết kế một giải pháp có khả năng mở rộng (scalable) và tiết kiệm chi phí nhất (most cost-effectively) cho ứng dụng quản lý tài liệu của công ty có 700.000 người dùng trên AWS.

  • Yêu cầu chính: Xử lý file PDF lớn (trung bình 5 MB), chuyển đổi sang định dạng JPG, lưu trữ cả file gốc (PDF) và file đã chuyển đổi (JPG).
  • Thách thức: Nhu cầu tăng trưởng nhanh chóng, cần giải pháp tự động, không cần quản lý server, tối ưu chi phí lưu trữ và xử lý.
  • Mục tiêu: Sử dụng dịch vụ AWS phù hợp cho object storage (lưu file lớn), event-driven processing (xử lý khi có sự kiện upload), và serverless để scale tự động mà không tốn phí idle.
    📘 Tài liệu tham khảo: AWS Well-Architected Framework (Pillar: Cost Optimization & Operational Excellence), S3 Event Notifications docs (cập nhật 2024-2026), Lambda với S3 integration (AWS re:Invent 2025 updates vẫn giữ nguyên mô hình serverless).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Save the .pdf files to Amazon S3. Configure an S3 PUT event to invoke an AWS Lambda function to convert the files to .jpg format and store them back in Amazon S3.

Lý do:
🛠️ Giải pháp này serverless hoàn toàn, sử dụng Amazon S3 làm object storage lý tưởng cho file lớn (5 MB, scale vô hạn, chi phí thấp ~$0.023/GB/tháng).

  • S3 PUT event kích hoạt AWS Lambda tự động convert file (xử lý song song, scale theo demand, chỉ trả phí execution time).
  • Lưu cả PDF và JPG vào S3, không cần server luôn chạy, cost-effective nhất vì chỉ tính phí storage + Lambda invocations (rẻ hơn EC2/EBS).
  • Phù hợp tăng trưởng nhanh: S3 + Lambda scale elastic, xử lý hàng triệu file/ngày mà không downtime.
    📘 Nguồn: AWS S3 User Guide (Event Notifications), Lambda Best Practices (2026 edition: hỗ trợ PDF processing với layers như ImageMagick/Poppler).

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn (giữ nguyên văn bản gốc), đánh dấu ✅ đúng hoặc ❌ sai, kèm lý do bằng tiếng Việt:

  • Save the .pdf files to Amazon S3. Configure an S3 PUT event to invoke an AWS Lambda function to convert the files to .jpg format and store them back in Amazon S3.
    ✅ Đúng - Như đã giải thích ở trên: Serverless, scalable, cost-effective tối ưu. S3 xử lý storage lớn, Lambda convert on-demand, không phí idle. Hoàn hảo cho workload tăng trưởng nhanh.

  • Save the .pdf files to Amazon DynamoDUse the DynamoDB Streams feature to invoke an AWS Lambda function to convert the files to .jpg format and store them back in DynamoDB.
    ❌ Sai - DynamoDB là NoSQL database cho dữ liệu structured/small (giới hạn item 400KB), không phù hợp lưu file binary lớn 5MB (vi phạm best practice, tốn kém ~$1.25/GB). DynamoDB Streams chỉ trigger cho changes, không optimize cho file processing. Cost cao và không scalable cho storage file.

  • Upload the .pdf files to an AWS Elastic Beanstalk application that includes Amazon EC2 instances, Amazon Elastic Block Store (Amazon EBS) storage, and an Auto Scaling group. Use a program in the EC2 instances to convert the files to .jpg format. Save the .pdf files and the .jpg files in the EBS store.
    ❌ Sai - Elastic Beanstalk + EC2 + EBS yêu cầu server luôn chạy (Auto Scaling giúp nhưng vẫn tốn phí instance idle ~$0.1/giờ). EBS là block storage gắn với EC2 (không shared giữa instances), không phù hợp lưu trữ lớn scale nhanh (giới hạn volume, snapshot đắt). Convert trên EC2 kém cost-effective so với Lambda.

  • Upload the .pdf files to an AWS Elastic Beanstalk application that includes Amazon EC2 instances, Amazon Elastic File System (Amazon EFS) storage, and an Auto Scaling group. Use a program in the EC2 instances to convert the file to .jpg format. Save the .pdf files and the .jpg files in the EBS store.
    ❌ Sai - Tương tự phương án trước: EC2 luôn chạy tốn kém. EFS shared filesystem tốt hơn EBS cho multi-instance, nhưng vẫn cần EC2 quản lý, phí cao (~$0.30/GB/tháng + throughput). Lưu ý mâu thuẫn: Đề cập EFS nhưng lưu vào "EBS store" (lỗi logic). Không serverless, kém scalable/cost-effective so với S3+Lambda.

🧩 Kết luận: Giải pháp S3 + Lambda là best practice cho file processing pipeline, tuân thủ AWS Well-Architected (Reliability & Cost pillars). Nếu implement, thêm S3 Lifecycle policies để optimize storage costs! 🚀

Câu 1239
A company has more than 5 TB of file data on Windows file servers that run on premises. Users and applications interact with the data each day.
The company is moving its Windows workloads to AWS. As the company continues this process, the company requires access to AWS and on-premises file storage with minimum latency. The company needs a solution that minimizes operational overhead and requires no significant changes to the existing file access patterns. The company uses an AWS Site-to-Site VPN connection for connectivity to AWS.
What should a solutions architect do to meet these requirements?
  1. A Deploy and configure Amazon FSx for Windows File Server on AWS. Move the on-premises file data to FSx for Windows File Server. Reconfigure the workloads to use FSx for Windows File Server on AWS.
  2. B Deploy and configure an Amazon S3 File Gateway on premises. Move the on-premises file data to the S3 File Gateway. Reconfigure the on-premises workloads and the cloud workloads to use the S3 File Gateway.
  3. C Deploy and configure an Amazon S3 File Gateway on premises. Move the on-premises file data to Amazon S3. Reconfigure the workloads to use either Amazon S3 directly or the S3 File Gateway. depending on each workload's location.
  4. D Deploy and configure Amazon FSx for Windows File Server on AWS. Deploy and configure an Amazon FSx File Gateway on premises. Move the on-premises file data to the FSx File Gateway. Configure the cloud workloads to use FSx for Windows File Server on AWS. Configure the on-premises workloads to use the FSx File Gateway.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh một công ty đang sở hữu hơn 5 TB dữ liệu file trên các Windows file servers on-premises. Người dùng và ứng dụng tương tác với dữ liệu này hàng ngày. Công ty đang di chuyển dần các workload Windows sang AWS, nhưng cần đảm bảo truy cập file storage từ cả AWS và on-premises với độ trễ (latency) tối thiểu. Giải pháp phải giảm thiểu overhead vận hành, không thay đổi lớn file access patterns hiện tại, và họ đang sử dụng AWS Site-to-Site VPN để kết nối.

🛠️ Yêu cầu chính cần giải quyết:

  • Hỗ trợ hybrid access (on-prem và cloud) với latency thấp.
  • Tương thích Windows SMB protocol (vì là Windows file servers).
  • Không làm gián đoạn workflow hiện tại (không reconfigure lớn).
  • Dữ liệu lớn (>5TB), cần hiệu suất cao cho daily interactions.

Giải pháp lý tưởng phải sử dụng hybrid file storage để cache dữ liệu local on-prem, đồng bộ với AWS, tận dụng VPN hiện có.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Deploy and configure Amazon FSx for Windows File Server on AWS. Deploy and configure an Amazon FSx File Gateway on premises. Move the on-premises file data to the FSx File Gateway. Configure the cloud workloads to use FSx for Windows File Server on AWS. Configure the on-premises workloads to use the FSx File Gateway.

Lý do chọn đáp án này 🏆:

  • Amazon FSx for Windows File Server (trên AWS) là dịch vụ fully managed Windows file system hỗ trợ SMB protocol, tích hợp AD, phù hợp migrate Windows workloads.
  • Amazon FSx File Gateway (on-premises) là hybrid appliance (phần của AWS Storage Gateway) kết nối trực tiếp với FSx on AWS, cache dữ liệu hot local để latency thấp cho on-prem access. Dữ liệu được sync tự động qua VPN.
  • Move data to Gateway rồi để Gateway quản lý cache/sync với FSx AWS → không thay đổi access patterns (on-prem workloads dùng SMB đến Gateway như file server local).
  • Cloud workloads truy cập trực tiếp FSx AWS → seamless hybrid.
  • Minimize overhead: Managed service, auto-scale, no hardware on-prem lớn.
  • Phù hợp dữ liệu >5TB với multi-AZ FSx và cache Gateway.

📋 Phân tích tất cả các phương án (đúng/sai)

  • Phương án 1: Deploy and configure Amazon FSx for Windows File Server on AWS. Move the on-premises file data to FSx for Windows File Server. Reconfigure the workloads to use FSx for Windows File Server on AWS.
    ❌ Sai vì chỉ di chuyển toàn bộ dữ liệu lên FSx AWS và reconfigure tất cả workloads (bao gồm on-prem) để dùng FSx qua VPN. Điều này gây latency cao cho on-prem daily access (dữ liệu >5TB qua VPN chậm), thay đổi lớn access patterns, và tăng overhead (không hybrid cache).

  • Phương án 2: Deploy and configure an Amazon S3 File Gateway on premises. Move the on-premises file data to the S3 File Gateway. Reconfigure the on-premises workloads and the cloud workloads to use the S3 File Gateway.
    ❌ Sai vì S3 File Gateway dùng cho object storage S3 (NFS/SMB proxy), không phải native Windows file server (SMB multi-user locking kém). Reconfigure tất cả workloads dùng Gateway → thay đổi access patterns, latency không tối ưu cho Windows apps, và S3 không hỗ trợ Windows-specific features như AD integration.

  • Phương án 3: Deploy and configure an Amazon S3 File Gateway on premises. Move the on-premises file data to Amazon S3. Reconfigure the workloads to use either Amazon S3 directly or the S3 File Gateway. depending on each workload's location.
    ❌ Sai tương tự phương án 2: S3 không phù hợp Windows file sharing (object storage, không SMB native, file locking issues). Move trực tiếp sang S3 → mất file system semantics, reconfigure lớn, và latency cao cho on-prem qua Gateway (không cache FSx-like).

  • Phương án 4 (Đúng): Deploy and configure Amazon FSx for Windows File Server on AWS. Deploy and configure an Amazon FSx File Gateway on premises. Move the on-premises file data to the FSx File Gateway. Configure the cloud workloads to use FSx for Windows File Server on AWS. Configure the on-premises workloads to use the FSx File Gateway.
    ✅ Đúng như giải thích ở trên: Hybrid FSx + Gateway cung cấp low-latency cache, no changes to patterns, Windows-native, scale cho >5TB. Hoàn hảo cho migrate dần.

📘 Tài liệu tham khảo (cập nhật AWS 2026)

💡 Lưu ý: Giải pháp này tận dụng AWS Shared Responsibility Model – AWS quản lý FSx, bạn chỉ deploy Gateway VM on-prem (EC2-compatible). Test với AWS Free Tier cho POC! 🚀

Câu 1240
A hospital recently deployed a RESTful API with Amazon API Gateway and AWS Lambda. The hospital uses API Gateway and Lambda to upload reports that are in PDF format and JPEG format. The hospital needs to modify the Lambda code to identify protected health information (PHI) in the reports.
Which solution will meet these requirements with the LEAST operational overhead?
  1. A Use existing Python libraries to extract the text from the reports and to identify the PHI from the extracted text.
  2. B Use Amazon Textract to extract the text from the reports. Use Amazon SageMaker to identify the PHI from the extracted text.
  3. C Use Amazon Textract to extract the text from the reports. Use Amazon Comprehend Medical to identify the PHI from the extracted text.
  4. D Use Amazon Rekognition to extract the text from the reports. Use Amazon Comprehend Medical to identify the PHI from the extracted text.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh một bệnh viện đã triển khai RESTful API sử dụng Amazon API Gateway kết hợp AWS Lambda để upload các báo cáo dưới định dạng PDF và JPEG. Yêu cầu chính là sửa đổi code Lambda nhằm xác định thông tin sức khỏe được bảo vệ (PHI - Protected Health Information) trong các báo cáo này. PHI là dữ liệu nhạy cảm trong y tế theo quy định HIPAA, bao gồm tên bệnh nhân, ngày sinh, chẩn đoán, v.v.

Mục tiêu là chọn giải pháp có chi phí vận hành thấp nhất (LEAST operational overhead), nghĩa là ưu tiên các dịch vụ managed serverless của AWS, không cần tự code phức tạp, train model hay maintain infrastructure. Các file đầu vào là PDF (documents có cấu trúc) và JPEG (hình ảnh), nên cần dịch vụ OCR (Optical Character Recognition) chuyên biệt để trích xuất text trước khi phân tích PHI.

🛠️ Yêu cầu kỹ thuật chính:

  • Trích xuất text từ PDF/JPEG một cách chính xác.
  • Phân tích text để detect PHI (như ICD-10 codes, medications, symptoms).
  • Tích hợp dễ dàng vào Lambda (invoke API từ code).

📘 Kiến thức AWS cập nhật 2026: Amazon Textract hỗ trợ PDF/JPEG với độ chính xác cao cho documents y tế. Amazon Comprehend Medical là dịch vụ chuyên biệt cho PHI, tích hợp HIPAA-eligible. Không có thay đổi lớn từ AWS re:Invent 2025.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use Amazon Textract to extract the text from the reports. Use Amazon Comprehend Medical to identify the PHI from the extracted text.

Lý do chọn (bằng tiếng Việt):
✅ Giải pháp này có operational overhead thấp nhất vì sử dụng hai dịch vụ managed serverless của AWS:

  • Textract chuyên trích xuất text từ PDF/JPEG (hỗ trợ tables/forms trong reports y tế).
  • Comprehend Medical tự động detect PHI (entities như MEDICAL_CONDITION, MEDICATION, PROTECTED_HEALTH_INFORMATION) mà không cần train model.
    Lambda chỉ cần invoke API calls đơn giản (boto3 SDK), không code phức tạp. Tích hợp HIPAA-compliant, scalable tự động. Đây là best practice AWS cho PII/PHI extraction.

🧩 Phân tích tất cả các phương án

Dưới đây là phân tích từng lựa chọn một cách chi tiết. Tôi giữ nguyên văn bản gốc tiếng Anh của phương án, chỉ đánh dấu đúng/sai và giải thích hoàn toàn bằng tiếng Việt.

  • Use existing Python libraries to extract the text from the reports and to identify the PHI from the extracted text.
    ❌ Sai. Phương án này yêu cầu tự code sử dụng thư viện Python như Tesseract/PyMuPDF cho OCR và regex/NLP libs (spaCy) cho PHI detection. Operational overhead cao: Phải maintain code, handle errors (accuracy thấp với handwritten text), scale thủ công, và không HIPAA-eligible tự động. Không phù hợp Lambda vì CPU-intensive.

  • Use Amazon Textract to extract the text from the reports. Use Amazon SageMaker to identify the PHI from the extracted text.
    ❌ Sai. Textract đúng cho extraction, nhưng SageMaker cần build/deploy custom ML model (training data y tế nhạy cảm), endpoint management, và monitoring. Overhead cao: Provision instances, tune hyperparameters, cost cao hơn Comprehend Medical. Không phải giải pháp least-effort cho PHI.

  • Use Amazon Textract to extract the text from the reports. Use Amazon Comprehend Medical to identify the PHI from the extracted text.
    ✅ Đúng. Như đã giải thích ở phần đáp án. Least overhead: Fully managed, pay-per-use, accuracy cao cho medical text (entities >95%), tích hợp boto3 invoke trực tiếp từ Lambda. Best practice AWS.

  • Use Amazon Rekognition to extract the text from the reports. Use Amazon Comprehend Medical to identify the PHI from the extracted text.
    ❌ Sai. Rekognition chủ yếu cho general images/videos (OCR cơ bản), không tối ưu cho PDF/documents phức tạp như reports y tế (accuracy thấp với tables/multi-page PDF). Phải convert PDF sang images thủ công, tăng complexity. Comprehend Medical đúng nhưng upstream fail → không least overhead.

📘 Tài liệu tham khảo (AWS Docs cập nhật 2026)

Giải pháp này đảm bảo tuân thủ DevOps best practices: IaC, serverless, zero-maintenance! 🚀