Ngân hàng đề — AWS Certified Solutions Architect Associate

Tìm thấy 2194 câu.

Câu 1271
An Amazon EC2 administrator created the following policy associated with an IAM group containing several users:
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "ec2:TerminateInstances",
      "Resource": "*",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": "10.100.100.0/24"
        }
      }
    },
    {
      "Effect": "Deny",
      "Action": "ec2:*",
      "Resource": "*",
      "Condition": {
        "StringNotEquals": {
          "ec2:Region": "us-east-1"
        }
      }
    }
  ]
}

What is the effect of this policy?
  1. A Users can terminate an EC2 instance in any AWS Region except us-east-1.
  2. B Users can terminate an EC2 instance with the IP address 10.100.100.1 in the us-east-1 Region.
  3. C Users can terminate an EC2 instance in the us-east-1 Region when the user's source IP is 10.100.100.254.
  4. D Users cannot terminate an EC2 instance in the us-east-1 Region when the user's source IP is 10.100.100.254.
Xem giải thích

📘 Phân tích câu hỏi

Câu hỏi liên quan đến chính sách IAM (Identity and Access Management) trên Amazon Web Services (AWS). Một chính sách IAM được tạo và gắn với một nhóm người dùng IAM, nhóm người dùng này có thể thực hiện các hành động trên các tài nguyên AWS dựa trên các quy tắc được định nghĩa trong chính sách.

Chính sách bao gồm hai câu lệnh (Statement):

  1. Allow - Cho phép người dùng thực hiện hành động ec2:TerminateInstances trên tất cả các tài nguyên EC2 (Resource: "*") với điều kiện địa chỉ IP nguồn (aws:SourceIp) phải nằm trong dải 10.100.100.0/24.
  2. Deny - Từ chối người dùng thực hiện bất kỳ hành động nào trên EC2 (ec2:*) trên tất cả các tài nguyên (Resource: "*") nếu hành động không diễn ra trong vùng us-east-1 (ec2:Region không bằng us-east-1).

✅ Giải thích các lựa chọn

  • [SAI] Users can terminate an EC2 instance in any AWS Region except us-east-1.

❌ Sai vì chính sách cho phép (Allow) thực hiện hành động ec2:TerminateInstances không bị giới hạn bởi vùng AWS, nhưng điều kiện IP nguồn phải được đáp ứng. Tuy nhiên, chính sách từ chối (Deny) áp dụng cho tất cả các vùng ngoại trừ us-east-1, nhưng nó không đặc biệt từ chối việc terminate instance ở các vùng khác nếu điều kiện IP được đáp ứng.

  • [SAI] Users can terminate an EC2 instance with the IP address 10.100.100.1 in the us-east-1 Region.

❌ Sai vì dải IP được chỉ định là 10.100.100.0/24, địa chỉ IP 10.100.100.1 nằm trong dải này nên có thể thực hiện việc terminate instance. Tuy nhiên, không có thông tin cụ thể về việc IP của người dùng phải khớp với địa chỉ IP của EC2 instance. Chính sách chỉ quan tâm đến IP nguồn của người dùng thực hiện hành động.

  • [ĐÚNG] Users can terminate an EC2 instance in the us-east-1 Region when the user's source IP is 10.100.100.254.

✅ Đúng vì địa chỉ IP 10.100.100.254 nằm trong dải IP được cho phép (10.100.100.0/24), và không có điều kiện từ chối (Deny) nào áp dụng cho việc terminate instance trong vùng us-east-1.

  • [SAI] Users cannot terminate an EC2 instance in the us-east-1 Region when the user's source IP is 10.100.100.254.

❌ Sai vì như đã giải thích ở trên, với địa chỉ IP 10.100.100.254, người dùng hoàn toàn có thể thực hiện việc terminate instance trong vùng us-east-1 miễn là đáp ứng điều kiện về IP nguồn.

📘 Tài liệu tham khảo

🔍 Kết luận

Hiểu rõ cách chính sách IAM được áp dụng và cách các điều kiện trong chính sách tương tác với các hành động người dùng trên AWS là rất quan trọng đối với vai trò của một AWS Certified DevOps Engineer Professional. Điều này giúp đảm bảo rằng các chính sách được thiết kế và áp dụng một cách chính xác để đạt được các mục tiêu bảo mật và quản lý truy cập trên AWS.

Câu 1272
A company has a large Microsoft SharePoint deployment running on-premises that requires Microsoft Windows shared file storage. The company wants to migrate this workload to the AWS Cloud and is considering various storage options. The storage solution must be highly available and integrated with Active Directory for access control.
Which solution will satisfy these requirements?
  1. A Configure Amazon EFS storage and set the Active Directory domain for authentication.
  2. B Create an SMB file share on an AWS Storage Gateway file gateway in two Availability Zones.
  3. C Create an Amazon S3 bucket and configure Microsoft Windows Server to mount it as a volume.
  4. D Create an Amazon FSx for Windows File Server file system on AWS and set the Active Directory domain for authentication.
Xem giải thích

🔍 Giải thích nội dung câu hỏi
🧩 Câu hỏi mô tả một công ty có hệ thống Microsoft SharePoint lớn đang chạy on-premises (trên máy chủ tại chỗ), yêu cầu sử dụng lưu trữ file chia sẻ kiểu Microsoft Windows (SMB protocol). Công ty muốn di chuyển toàn bộ workload này lên AWS Cloud. Các yêu cầu chính của giải pháp lưu trữ bao gồm:

  • Highly available (có tính sẵn sàng cao, thường ngụ ý Multi-AZ deployment để tránh downtime).
  • Tích hợp với Active Directory (AD) cho việc kiểm soát truy cập (authentication và authorization theo chuẩn Windows).
    Mục tiêu là chọn giải pháp lưu trữ phù hợp nhất trên AWS để thay thế shared file storage Windows, đảm bảo tương thích với SharePoint (yêu cầu SMB shares và AD integration). Đây là tình huống điển hình trong việc migrate Windows workloads sang AWS, tập trung vào file systems managed services. (Kiến thức cập nhật AWS 2024-2026: FSx family vẫn là lựa chọn hàng đầu cho Windows file sharing).

✅ Đáp án đúng
Create an Amazon FSx for Windows File Server file system on AWS and set the Active Directory domain for authentication.

Lý do lựa chọn:
🛠️ Amazon FSx for Windows File Server là dịch vụ fully managed Windows file system trên AWS, hỗ trợ SMB protocol (SMB 2.0, 3.0, 3.1.1) hoàn hảo cho SharePoint và Windows apps. Nó tích hợp trực tiếp với Microsoft Active Directory (AD) qua AWS Managed Microsoft AD hoặc self-managed AD, cho phép authentication/authorization theo chuẩn Windows (NTFS permissions, ACLs). Hơn nữa, FSx hỗ trợ Multi-AZ deployment để đạt high availability (99.99% SLA), với automatic failover dưới 60 giây. Giải pháp này native cho Windows, scalable, và được khuyến nghị chính thức cho migrate SharePoint file shares lên AWS. Không cần quản lý hạ tầng dưới, hoàn toàn chạy trên cloud.

🛠️ Phân tích chi tiết từng phương án
📋 Dưới đây là phân tích tất cả các phương án, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai dựa trên yêu cầu highly available + AD integration cho Windows SMB shares.

  • Configure Amazon EFS storage and set the Active Directory domain for authentication.
    ❌ Sai: Amazon EFS là file system NFS-based (Linux/Unix), không hỗ trợ SMB protocol native cho Windows/SharePoint. Mặc dù EFS có IAM/AD integration qua Access Points (từ 2021), nhưng đây là Linux-style auth (NFSv4/ Kerberos), không tương thích với Windows NTFS permissions hay SMB shares. Không highly available theo chuẩn Windows Multi-AZ, và mounting trên Windows yêu cầu phần mềm third-party (không ổn định cho production SharePoint).

  • Create an SMB file share on an AWS Storage Gateway file gateway in two Availability Zones.
    ❌ Sai: AWS Storage Gateway File Gateway hỗ trợ SMB shares và AD integration, nhưng đây là giải pháp hybrid (gateway appliance chạy on-premises hoặc EC2, cache local, dữ liệu chính trên S3). Không fully on AWS cloud như yêu cầu migrate workload, và việc deploy ở hai AZ chỉ là regional setup chứ không phải true Multi-AZ file system failover. Phù hợp cho hybrid migration, nhưng không lý tưởng cho full cloud migration của SharePoint lớn (latency cao, không managed hoàn toàn).

  • Create an Amazon S3 bucket and configure Microsoft Windows Server to mount it as a volume.
    ❌ Sai: Amazon S3 là object storage, không phải file system SMB. Mounting S3 như volume trên Windows (qua S3 File Gateway hoặc tools như Riofs/s3fs) chỉ là emulation, không hỗ trợ native AD authentication hay Windows file locking/sharing cho SharePoint. Không highly available như file system (S3 durable nhưng mount không failover real-time), và performance kém cho random I/O của SharePoint. AWS không khuyến nghị cho Windows file shares production.

  • Create an Amazon FSx for Windows File Server file system on AWS and set the Active Directory domain for authentication.
    ✅ Đúng: Như đã giải thích ở trên, đây là giải pháp hoàn hảo khớp yêu cầu: SMB native, AD integration đầy đủ (join domain trực tiếp), Multi-AZ high availability, và optimized cho Windows workloads như SharePoint. Scalable lên petabytes, backup tự động qua AWS Backup.

📘 Tài liệu tham khảo (Cập nhật AWS 2024-2026):

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm ví dụ thực tế, hãy hỏi nhé!

Câu 1273
An image-processing company has a web application that users use to upload images. The application uploads the images into an Amazon S3 bucket. The company has set up S3 event notifications to publish the object creation events to an Amazon Simple Queue Service (Amazon SQS) standard queue. The SQS queue serves as the event source for an AWS Lambda function that processes the images and sends the results to users through email.
Users report that they are receiving multiple email messages for every uploaded image. A solutions architect determines that SQS messages are invoking the Lambda function more than once, resulting in multiple email messages.
What should the solutions architect do to resolve this issue with the LEAST operational overhead?
  1. A Set up long polling in the SQS queue by increasing the ReceiveMessage wait time to 30 seconds.
  2. B Change the SQS standard queue to an SQS FIFO queue. Use the message deduplication ID to discard duplicate messages.
  3. C Increase the visibility timeout in the SQS queue to a value that is greater than the total of the function timeout and the batch window timeout.
  4. D Modify the Lambda function to delete each message from the SQS queue immediately after the message is read before processing.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả một ứng dụng web xử lý hình ảnh của công ty, nơi người dùng upload ảnh lên Amazon S3 bucket. S3 được cấu hình event notifications để gửi sự kiện tạo object (object creation events) đến một Amazon SQS standard queue. Queue SQS này làm event source cho một AWS Lambda function, Lambda sẽ xử lý ảnh và gửi kết quả qua email cho người dùng.

Vấn đề chính (user reports): Người dùng nhận nhiều email cho mỗi ảnh upload, do SQS messages invoke Lambda nhiều lần (multiple invocations), dẫn đến xử lý lặp lại.

Nguyên nhân gốc rễ: SQS standard queue có tính chất at-least-once delivery (giao ít nhất một lần, có thể duplicate). Khi Lambda function (hoặc consumer) poll message từ SQS, message được "ẩn" tạm thời trong visibility timeout. Nếu thời gian xử lý Lambda vượt quá visibility timeout, message sẽ visible lại và bị poll bởi Lambda instance khác, gây duplicate processing và nhiều email.

Yêu cầu giải quyết: Solutions architect cần giải pháp với LEAST operational overhead (ít overhead vận hành nhất), tức ưu tiên thay đổi cấu hình đơn giản, không refactor code hay thay đổi architecture lớn.

Kiến thức AWS cập nhật đến 2026: SQS standard queue hỗ trợ batch processing cho Lambda (batch window), và visibility timeout cần lớn hơn tổng function timeout + batch window timeout để tránh duplicate invokes (theo AWS best practices cho event source mapping).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Increase the visibility timeout in the SQS queue to a value that is greater than the total of the function timeout and the batch window timeout.

Lý do 🛠️:

  • Đây là giải pháp chuẩn AWS và least overhead vì chỉ cần chỉnh visibility timeout trên SQS queue (qua console/CLI/API, không cần code change).
  • Visibility timeout phải > (Lambda function timeout + batch window timeout) để đảm bảo Lambda hoàn tất xử lý batch trước khi message visible lại, tránh duplicate poll.
  • Theo tài liệu AWS (2024-2026), với Lambda event source mapping từ SQS, AWS khuyến nghị set visibility timeout ít nhất 6x function timeout, nhưng cụ thể > tổng timeout để xử lý idempotent hoặc tránh re-processing.
  • Giải quyết tận gốc duplicate do race condition giữa poll và processing.

📋 Phân tích tất cả các phương án (đúng/sai)

  • ❌ [SAI] Set up long polling in the SQS queue by increasing the ReceiveMessage wait time to 30 seconds.
    Giải thích sai: Long polling (tăng ReceiveMessage WaitTimeSeconds lên 20-30s) chỉ giúp giảm số lần empty receives (poll không message), tối ưu chi phí và throughput. Nó không giải quyết duplicate invokes do visibility timeout quá ngắn. Overhead thấp nhưng không fix vấn đề gốc.

  • ❌ [SAI] Change the SQS standard queue to an SQS FIFO queue. Use the message deduplication ID to discard duplicate messages.
    Giải thích sai: SQS FIFO hỗ trợ exactly-once delivery với message deduplication ID và content-based dedup, nhưng overhead cao hơn: Phải refactor S3 event notification để set message group ID/dedup ID, queue FIFO có throughput giới hạn (300 msg/s/shard), và không tương thích trực tiếp nếu app không thiết kế cho FIFO. Không phải "least overhead" so với chỉnh visibility timeout.

  • ✅ [ĐÚNG] Increase the visibility timeout in the SQS queue to a value that is greater than the total of the function timeout and the batch window timeout.
    Giải thích đúng (như phần trên): Fix trực tiếp race condition với thay đổi cấu hình đơn giản nhất, không code change, hỗ trợ batch processing Lambda-SQS.

  • ❌ [SAI] Modify the Lambda function to delete each message from the SQS queue immediately after the message is read before processing.
    Giải thích sai: Với Lambda event source mapping, AWS tự động delete message sau successful processing (không cần code delete). Delete ngay sau "read" (trước process) sẽ mất message nếu Lambda fail/crash giữa chừng, dẫn đến data loss. Phải refactor code (thêm SQS delete API), tăng overhead và rủi ro (không idempotent).

📘 Tài liệu tham khảo (AWS cập nhật 2024-2026)

Giải pháp này đảm bảo high availability và fault-tolerant mà không phức tạp hóa hệ thống! 🚀

Câu 1274
A company is implementing a shared storage solution for a gaming application that is hosted in an on-premises data center. The company needs the ability to use Lustre clients to access data. The solution must be fully managed.
Which solution meets these requirements?
  1. A Create an AWS Storage Gateway file gateway. Create a file share that uses the required client protocol. Connect the application server to the file share.
  2. B Create an Amazon EC2 Windows instance. Install and configure a Windows file share role on the instance. Connect the application server to the file share.
  3. C Create an Amazon Elastic File System (Amazon EFS) file system, and configure it to support Lustre. Attach the file system to the origin server. Connect the application server to the file system.
  4. D Create an Amazon FSx for Lustre file system. Attach the file system to the origin server. Connect the application server to the file system.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một công ty đang triển khai giải pháp lưu trữ chia sẻ (shared storage) cho ứng dụng game được host tại data center on-premises (trên máy chủ cục bộ, không phải AWS cloud). Yêu cầu chính bao gồm:

  • Hỗ trợ Lustre clients (các client sử dụng giao thức Lustre để truy cập dữ liệu) – Lustre là file system parallel cao hiệu suất, thường dùng cho HPC và gaming/big data.
  • Giải pháp phải fully managed (AWS quản lý hoàn toàn, không cần tự quản lý hạ tầng).
  • Cần kết nối origin server (máy chủ gốc on-premises) và application server (máy chủ ứng dụng) với storage.

Mục tiêu: Tìm giải pháp AWS fully managed hỗ trợ Lustre, accessible từ on-premises qua kết nối mạng (như VPN/Direct Connect). Kiến thức cập nhật 2026: Amazon FSx for Lustre là dịch vụ managed Lustre hàng đầu, tích hợp tốt với on-premises qua VPC peering/VPN/Direct Connect, hỗ trợ gaming workloads cao IOPS.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create an Amazon FSx for Lustre file system. Attach the file system to the origin server. Connect the application server to the file system.

Lý do:

  • 🛠️ Amazon FSx for Lustre là dịch vụ fully managed duy nhất của AWS cung cấp file system Lustre native, hỗ trợ Lustre clients trực tiếp (mount qua NFSv4.1 hoặc s3fs cho S3 data repository).
  • 📈 Phù hợp gaming: Hiệu suất cao (hàng triệu IOPS), scale đến PB, lazy loading từ S3 cho dữ liệu lớn.
  • 🔗 On-premises access: Mount FSx từ origin/application server qua VPC (kết nối VPN/Direct Connect/PrivateLink). "Attach" ở đây nghĩa là mount filesystem đến server.
  • ✅ Đầy đủ yêu cầu: Fully managed, Lustre support, shared storage.

📋 Phân tích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai với lý do cụ thể dựa trên tài liệu AWS mới nhất (2026).

  • Phương án A (❌ SAI):
    Create an AWS Storage Gateway file gateway. Create a file share that uses the required client protocol. Connect the application server to the file share.
    Giải thích: AWS Storage Gateway File Gateway chỉ hỗ trợ NFS/SMB, không hỗ trợ Lustre clients. Nó là hybrid storage cho on-premises cache data lên S3, nhưng không phải Lustre file system. Không đáp ứng "Lustre clients" và không fully managed cho Lustre workload gaming.

  • Phương án B (❌ SAI):
    Create an Amazon EC2 Windows instance. Install and configure a Windows file share role on the instance. Connect the application server to the file share.
    Giải thích: EC2 Windows với file share role (SMB) không hỗ trợ Lustre (Lustre là Linux-based, không Windows native). EC2 không fully managed (phải tự install/config/maintain), không phù hợp shared storage Lustre cho gaming on-premises. Chi phí cao, phức tạp.

  • Phương án C (❌ SAI):
    Create an Amazon Elastic File System (Amazon EFS) file system, and configure it to support Lustre. Attach the file system to the origin server. Connect the application server to the file system.
    Giải thích: Amazon EFS không hỗ trợ Lustre – EFS dùng NFSv4.1, không có config Lustre (dù có Elastic File Cache nhưng không fully managed Lustre). EFS dành regional shared file storage, nhưng không mount Lustre clients. Không đáp ứng yêu cầu chính xác.

  • Phương án D (✅ ĐÚNG):
    Create an Amazon FSx for Lustre file system. Attach the file system to the origin server. Connect the application server to the file system.
    Giải thích: Hoàn hảo như đã nêu ở phần đáp án đúng. FSx for Lustre fully managed, native Lustre, hỗ trợ on-premises mount qua network connectivity. Cập nhật 2026: Hỗ trợ Persistent/Scratch deployment, S3 integration cho gaming data pipelines.

📘 Tài liệu tham khảo

  • AWS FSx for Lustre Documentation: Amazon FSx for Lustre – Xác nhận fully managed Lustre, on-premises access via VPC.
  • AWS Storage Gateway: File Gateway Protocols – Chỉ NFS/SMB.
  • AWS EFS: EFS Features – Không Lustre.
  • Exam Topic DOP-C02: Shared storage for HPC/gaming thường chỉ FSx Lustre.
  • AWS Well-Architected Framework (2026): Gaming workloads recommend FSx Lustre for high-throughput.

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ thực hành, hãy hỏi nhé!

Câu 1275
A company's containerized application runs on an Amazon EC2 instance. The application needs to download security certificates before it can communicate with other business applications. The company wants a highly secure solution to encrypt and decrypt the certificates in near real time. The solution also needs to store data in highly available storage after the data is encrypted.
Which solution will meet these requirements with the LEAST operational overhead?
  1. A Create AWS Secrets Manager secrets for encrypted certificates. Manually update the certificates as needed. Control access to the data by using fine-grained IAM access.
  2. B Create an AWS Lambda function that uses the Python cryptography library to receive and perform encryption operations. Store the function in an Amazon S3 bucket.
  3. C Create an AWS Key Management Service (AWS KMS) customer managed key. Allow the EC2 role to use the KMS key for encryption operations. Store the encrypted data on Amazon S3.
  4. D Create an AWS Key Management Service (AWS KMS) customer managed key. Allow the EC2 role to use the KMS key for encryption operations. Store the encrypted data on Amazon Elastic Block Store (Amazon EBS) volumes.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một ứng dụng containerized đang chạy trên Amazon EC2 instance. Ứng dụng này cần tải xuống (download) các security certificates trước khi có thể giao tiếp (communicate) với các ứng dụng kinh doanh khác. Yêu cầu chính là một giải pháp highly secure để encrypt và decrypt certificates gần như thời gian thực (near real time), đồng thời lưu trữ dữ liệu đã mã hóa vào highly available storage sau khi mã hóa. Giải pháp phải có operational overhead thấp nhất (LEAST operational overhead).

🔑 Các yếu tố cốt lõi cần đáp ứng:

  • Bảo mật cao: Sử dụng dịch vụ AWS managed để quản lý khóa mã hóa (keys) và mã hóa/giải mã.
  • Near real-time: Hỗ trợ API calls nhanh chóng cho encrypt/decrypt.
  • Highly available storage: Lưu trữ dữ liệu mã hóa phải có tính sẵn sàng cao, multi-AZ, durable (không phụ thuộc vào một instance duy nhất).
  • Least overhead: Tối ưu hóa, sử dụng dịch vụ serverless/managed, tránh tự quản lý code hoặc manual intervention.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create an AWS Key Management Service (AWS KMS) customer managed key. Allow the EC2 role to use the KMS key for encryption operations. Store the encrypted data on Amazon S3.

🛠️ Lý do chi tiết:

  • AWS KMS customer managed key (CMK): Cho phép mã hóa/giải mã near real-time qua API calls (Encrypt/Decrypt APIs), highly secure với HSM-backed keys, AWS quản lý toàn bộ lifecycle (rotation tự động tùy chọn).
  • EC2 IAM role: Gán quyền sử dụng KMS key (kms:Encrypt, kms:Decrypt) mà không cần hardcode credentials, tuân thủ least privilege.
  • Amazon S3: Lưu trữ encrypted data với highly available (multi-AZ, 11 9's durability), serverless, không cần quản lý volume hay instance. Ứng dụng trên EC2 có thể gọi KMS để encrypt trước khi upload S3.
  • Least overhead: Toàn bộ là managed services, không code custom, không manual update, scale tự động. Phù hợp DevOps best practices.

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng phương án một cách chi tiết, đánh dấu ✅ đúng hoặc ❌ sai, với lý do dựa trên yêu cầu câu hỏi:

  • ❌ [SAI] Create AWS Secrets Manager secrets for encrypted certificates. Manually update the certificates as needed. Control access to the data by using fine-grained IAM access.
    Phương án này sử dụng AWS Secrets Manager để lưu secrets đã mã hóa, nhưng yêu cầu manually update certificates gây overhead cao (không tự động). Secrets Manager chủ yếu retrieve secrets đã decrypt sẵn, không hỗ trợ encrypt/decrypt arbitrary data near real-time như certificates tải về. Không lưu encrypted data vào HA storage riêng (Secrets Manager là managed secrets store, không phải general storage). Overhead cao do manual intervention, vi phạm "least overhead".

  • ❌ [SAI] Create an AWS Lambda function that uses the Python cryptography library to receive and perform encryption operations. Store the function in an Amazon S3 bucket.
    Phương án dùng Lambda với thư viện cryptography Python để mã hóa, nhưng tự implement crypto lib không secure bằng KMS (dễ lỗi key management, compliance issues). Lambda code được upload như ZIP vào S3, nhưng "store function in S3" không chính xác (Lambda là service riêng). Overhead cao: Phát triển/maintain code custom, xử lý errors, scaling, không near real-time như KMS API. Không đề cập HA storage cho encrypted data.

  • ✅ [ĐÚNG] Create an AWS Key Management Service (AWS KMS) customer managed key. Allow the EC2 role to use the KMS key for encryption operations. Store the encrypted data on Amazon S3.
    Như đã giải thích ở trên: Hoàn hảo khớp tất cả yêu cầu với KMS cho secure near real-time encrypt/decrypt, IAM role cho access, S3 cho HA storage. Zero custom code, fully managed.

  • ❌ [SAI] Create an AWS Key Management Service (AWS KMS) customer managed key. Allow the EC2 role to use the KMS key for encryption operations. Store the encrypted data on Amazon Elastic Block Store (Amazon EBS) volumes.
    KMS và EC2 role tốt, nhưng Amazon EBS không phải highly available storage: EBS là block storage gắn với EC2 instance (single AZ, nếu instance fail thì mất data trừ khi snapshot). Phải quản lý volume attach/detach/snapshot thủ công, overhead cao hơn S3 (object storage multi-AZ). Không phù hợp cho certificates cần HA.

🔥 Kết luận: Giải pháp đúng tận dụng AWS managed services tối ưu cho DevOps, đảm bảo security, availability và low ops theo AWS best practices 2026! 🚀

Câu 1276
A solutions architect is designing a VPC with public and private subnets. The VPC and subnets use IPv4 CIDR blocks. There is one public subnet and one private subnet in each of three Availability Zones (AZs) for high availability. An internet gateway is used to provide internet access for the public subnets. The private subnets require access to the internet to allow Amazon EC2 instances to download software updates.
What should the solutions architect do to enable Internet access for the private subnets?
  1. A Create three NAT gateways, one for each public subnet in each AZ. Create a private route table for each AZ that forwards non-VPC traffic to the NAT gateway in its AZ.
  2. B Create three NAT instances, one for each private subnet in each AZ. Create a private route table for each AZ that forwards non-VPC traffic to the NAT instance in its AZ.
  3. C Create a second internet gateway on one of the private subnets. Update the route table for the private subnets that forward non-VPC traffic to the private internet gateway.
  4. D Create an egress-only internet gateway on one of the public subnets. Update the route table for the private subnets that forward non-VPC traffic to the egress-only Internet gateway.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi này xoay quanh việc thiết kế một VPC (Virtual Private Cloud) trên AWS với cấu hình high availability (HA) sử dụng 3 Availability Zones (AZs). Cụ thể:

  • VPC và các subnet sử dụng IPv4 CIDR blocks.
  • Mỗi AZ có 1 public subnet và 1 private subnet.
  • Internet Gateway (IGW) đã được gắn vào VPC để cung cấp internet access cho các public subnets (cho phép inbound/outbound traffic).
  • Private subnets cần truy cập internet outbound only (chỉ đi ra ngoài) để các EC2 instances trong private subnets có thể download software updates (như patch bảo mật), nhưng không expose inbound traffic từ internet để đảm bảo bảo mật.
  • Vấn đề cốt lõi: Làm thế nào để enable internet access cho private subnets mà không làm chúng public?

📘 Mục tiêu thiết kế: Đảm bảo high availability (multi-AZ), fault-tolerant (không single point of failure), và tuân thủ best practices AWS VPC networking (cập nhật đến 2024-2026, theo AWS Well-Architected Framework).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create three NAT gateways, one for each public subnet in each AZ. Create a private route table for each AZ that forwards non-VPC traffic to the NAT gateway in its AZ.

Lý do 🛠️:

  • NAT Gateway (NAT GW) là dịch vụ fully managed của AWS, hỗ trợ outbound internet access từ private subnets mà không cho phép inbound traffic (hoàn hảo cho use case download updates).
  • Để đạt HA và fault tolerance, cần 1 NAT GW mỗi public subnet (tức 3 NAT GW cho 3 AZs). Mỗi NAT GW được deploy trong public subnet của AZ tương ứng, với Elastic IP (EIP).
  • Private route table riêng cho mỗi AZ: Route 0.0.0.0/0 (non-VPC traffic) trỏ đến NAT GW trong AZ đó. Điều này đảm bảo traffic không cross-AZ (giảm latency, tránh failure nếu AZ khác down).
  • Đây là best practice AWS cho multi-AZ setups (theo VPC User Guide mới nhất).

📋 Giải thích chi tiết từng phương án

  • Phương án đúng ✅:
    Create three NAT gateways, one for each public subnet in each AZ. Create a private route table for each AZ that forwards non-VPC traffic to the NAT gateway in its AZ.
    🧩 Giải thích: Như đã nêu ở trên, đây là giải pháp chuẩn AWS cho private subnet outbound access với HA multi-AZ. NAT GW managed, auto-scale, và hỗ trợ up to 100 Gbps throughput (cập nhật 2024). Không cần quản lý instance thủ công.

  • Phương án sai ❌:
    Create three NAT instances, one for each private subnet in each AZ. Create a private route table for each AZ that forwards non-VPC traffic to the NAT instance in its AZ.
    🧩 Giải thích sai: NAT Instance là EC2 self-managed (không phải managed service như NAT GW), đặt trong private subnet sẽ không có internet access outbound (vì private subnet chưa có route ra ngoài). Phải đặt NAT Instance ở public subnet. Hơn nữa, NAT Instance không HA tự động (cần Auto Scaling Group, monitoring thủ công), dễ single point of failure, vi phạm best practices (AWS khuyến nghị migrate sang NAT GW).

  • Phương án sai ❌:
    Create a second internet gateway on one of the private subnets. Update the route table for the private subnets that forward non-VPC traffic to the private internet gateway.
    🧩 Giải thích sai: Internet Gateway (IGW) chỉ attach vào VPC level, không attach trực tiếp vào subnet (private hay public). IGW luôn bidirectional (inbound/outbound), sẽ expose private subnets ra internet (rủi ro bảo mật cao). Không có khái niệm "private IGW". AWS không hỗ trợ "second IGW" kiểu này.

  • Phương án sai ❌:
    Create an egress-only internet gateway on one of the public subnets. Update the route table for the private subnets that forward non-VPC traffic to the egress-only Internet gateway.
    🧩 Giải thích sai: Egress-only Internet Gateway chỉ dành cho IPv6 (không phải IPv4 CIDR blocks ở đây). Nó chỉ cho outbound IPv6 traffic, không hỗ trợ IPv4. Hơn nữa, chỉ 1 cái cho toàn VPC (không per subnet/AZ), và không giải quyết IPv4 use case (download updates thường IPv4).

📘 Tài liệu tham khảo (AWS Docs cập nhật 2024-2026)

Hy vọng phân tích này giúp bạn nắm vững! 🚀 Nếu cần lab thực hành, dùng AWS Free Tier VPC.

Câu 1277 Chọn nhiều đáp án
A company wants to migrate an on-premises data center to AWS. The data center hosts an SFTP server that stores its data on an NFS-based file system. The server holds 200 GB of data that needs to be transferred. The server must be hosted on an Amazon EC2 instance that uses an Amazon Elastic File System (Amazon EFS) file system.
Which combination of steps should a solutions architect take to automate this task? (Choose two.)
  1. A Launch the EC2 instance into the same Availability Zone as the EFS file system.
  2. B Install an AWS DataSync agent in the on-premises data center.
  3. C Create a secondary Amazon Elastic Block Store (Amazon EBS) volume on the EC2 instance for the data.
  4. D Manually use an operating system copy command to push the data to the EC2 instance.
  5. E Use AWS DataSync to create a suitable location configuration for the on-premises SFTP server.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một công ty muốn migrate (di chuyển) data center on-premises sang AWS. Cụ thể:

  • On-premises có SFTP server lưu trữ dữ liệu trên NFS-based file system, tổng dung lượng 200 GB cần transfer.
  • Trên AWS, server mới phải chạy trên Amazon EC2 instance sử dụng Amazon EFS làm file system (EFS là dịch vụ file storage chia sẻ, hỗ trợ multi-AZ, scalable).
  • Yêu cầu: Solutions Architect cần chọn kết hợp 2 bước để automate (tự động hóa) quá trình này. Mục tiêu chính là transfer dữ liệu từ NFS on-premises sang EFS trên EC2 một cách tự động, hiệu quả, tránh manual, tận dụng công cụ AWS chuyên dụng cho data migration như AWS DataSync (dịch vụ sync file giữa on-premises và AWS, hỗ trợ NFS, SFTP, EFS, tốc độ cao lên đến 10 Gbps, cập nhật mới nhất 2024-2026 với hỗ trợ SFTP locations không cần agent cho network-accessible servers).

📘 Nguồn tham khảo:

✅ Đáp án đúng (Chọn TWO)

Hai bước đúng là:

  • Install an AWS DataSync agent in the on-premises data center.
  • Use AWS DataSync to create a suitable location configuration for the on-premises SFTP server.

Lý do lựa chọn 🛠️:

  • AWS DataSync là giải pháp tự động hóa tối ưu cho việc transfer file từ on-premises (NFS/SFTP) sang EFS.
    • Bước 1: Cài agent trên on-premises (VM có access NFS/SFTP server) để DataSync kết nối source an toàn, hỗ trợ incremental sync, compression, verification (giảm thời gian transfer 200 GB xuống hàng giờ).
    • Bước 2: Tạo location cho SFTP server (source) và EFS (destination), sau đó tạo task để automate sync. EC2 mount EFS sau khi data sẵn sàng để host SFTP server mới.
  • Kết hợp này automate hoàn toàn, scalable, không downtime lớn. Phiên bản DataSync mới nhất (2026) hỗ trợ SFTP trực tiếp với agent cho hybrid setups.

📋 Giải thích chi tiết TẤT CẢ các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh:

  • ❌ Launch the EC2 instance into the same Availability Zone as the EFS file system.
    Sai vì Amazon EFS là multi-AZ bằng default (Regional service), EC2 có thể mount EFS từ bất kỳ AZ nào trong cùng Region qua DNS name (Mount target cross-AZ). Không cần same AZ, tránh single point of failure. Nếu force same AZ, giảm tính available/high availability. 🛑

  • ✅ Install an AWS DataSync agent in the on-premises data center.
    Đúng vì DataSync yêu cầu agent (VM appliance) cài trên on-premises để access NFS/SFTP backend an toàn (firewall/VPN), scan metadata, hỗ trợ protocol conversion NFS → EFS. Agent chạy trên VM Linux (4 vCPU, 16 GB RAM), deploy OVA, kết nối STS endpoint AWS. Automate transfer 200 GB nhanh chóng với scheduling. 🚀

  • ❌ Create a secondary Amazon Elastic Block Store (Amazon EBS) volume on the EC2 instance for the data.
    Sai vì câu hỏi yêu cầu EFS file system (shared, POSIX-compliant, multi-instance access cho SFTP server). EBS là block storage single-AZ/single-instance, không phù hợp NFS-like sharing, kém scalable/costly cho 200 GB shared data. Phải dùng EFS làm chính. 🔒

  • ❌ Manually use an operating system copy command to push the data to the EC2 instance.
    Sai vì không automate (manual scp/rsync qua internet/VPN chậm, error-prone, không incremental/compression). Với 200 GB, mất ngày, không scalable, vi phạm yêu cầu "automate this task". DataSync tốt hơn gấp 10x tốc độ. ⏰

  • ✅ Use AWS DataSync to create a suitable location configuration for the on-premises SFTP server.
    Đúng vì DataSync hỗ trợ SFTP location trực tiếp (server IP/port/user/key, private/public key auth). Tạo source location cho SFTP server (access data on NFS backend), destination EFS (EC2 mount sau). Task chạy automate, filter/sync chỉ changed files, verify integrity. Hoàn hảo cho migration SFTP → EFS. 🔄

🧠 Lưu ý bổ sung: Sau hai bước trên, tạo DataSync Task + Location cho EFS (EFS access point cho security), chạy once/many, rồi launch EC2 mount EFS với SFTP software (OpenSSH). Tổng thời gian: <1 ngày cho 200 GB. Test trước production với small subset!

Câu 1278
A company has an AWS Glue extract, transform, and load (ETL) job that runs every day at the same time. The job processes XML data that is in an Amazon S3 bucket. New data is added to the S3 bucket every day. A solutions architect notices that AWS Glue is processing all the data during each run.
What should the solutions architect do to prevent AWS Glue from reprocessing old data?
  1. A Edit the job to use job bookmarks.
  2. B Edit the job to delete data after the data is processed.
  3. C Edit the job by setting the NumberOfWorkers field to 1.
  4. D Use a FindMatches machine learning (ML) transform.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi mô tả một tình huống thực tế trong AWS: Một công ty đang sử dụng AWS Glue ETL job chạy hàng ngày vào cùng một thời điểm để xử lý dữ liệu XML lưu trữ trong Amazon S3 bucket. Mỗi ngày, dữ liệu mới được thêm vào bucket, nhưng vấn đề là AWS Glue đang xử lý lại toàn bộ dữ liệu cũ (reprocessing) trong mỗi lần chạy, dẫn đến lãng phí tài nguyên, thời gian và chi phí.
Mục tiêu: Solutions Architect cần tìm cách ngăn chặn việc xử lý lại dữ liệu cũ, chỉ xử lý dữ liệu mới thôi. Đây là vấn đề phổ biến với các job Glue xử lý dữ liệu incremental từ S3, nơi Glue mặc định quét toàn bộ dataset trừ khi cấu hình cơ chế theo dõi tiến độ.

✅ Đáp án đúng: Edit the job to use job bookmarks

Lý do lựa chọn:
AWS Glue Job Bookmarks là tính năng chuyên dụng để theo dõi tiến độ xử lý dữ liệu từ nguồn như S3. Khi kích hoạt, Glue sẽ ghi nhớ vị trí cuối cùng đã xử lý (dựa trên key/path của file hoặc partition), giúp job chỉ xử lý dữ liệu mới thêm vào mà không reprocess dữ liệu cũ. Điều này hoàn hảo cho job chạy định kỳ với dữ liệu incremental như XML trong S3.
Theo tài liệu AWS mới nhất (2024-2026), Job Bookmarks hỗ trợ các định dạng như XML và có các chế độ như job.bookmark (mặc định cho S3), đảm bảo hiệu suất tối ưu mà không cần thay đổi logic code. ✅ Giải pháp hiệu quả, an toàn và native!

📋 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên nội dung gốc bằng tiếng Anh. Tôi đánh dấu ✅ cho đúng và ❌ cho sai, kèm giải thích rõ ràng:

  • Edit the job to use job bookmarks.
    ✅ Đúng. Như đã giải thích ở trên, Job Bookmarks là cơ chế built-in của AWS Glue để tránh reprocessing bằng cách lưu trạng thái xử lý (source và target). Với S3 XML data, nó tự động detect file mới dựa trên key hoặc partition. Không ảnh hưởng đến dữ liệu gốc, dễ enable qua Glue console/CLI ( --job-bookmark-option job-bookmark-enable). Hoàn hảo cho job daily! 🛠️

  • Edit the job to delete data after the data is processed.
    ❌ Sai. Việc xóa dữ liệu sau xử lý sẽ mất dữ liệu gốc vĩnh viễn, vi phạm nguyên tắc lưu trữ dữ liệu bền vững trong S3 (immutable storage). Không giải quyết vấn đề reprocessing mà còn tạo rủi ro data loss, không phù hợp với best practice AWS (S3 lifecycle cho retention). Rất nguy hiểm cho production! 🚫

  • Edit the job by setting the NumberOfWorkers field to 1.
    ❌ Sai. Tham số NumberOfWorkers chỉ kiểm soát số lượng worker nodes (G.1X/G.2X/DPU) để scale job, không liên quan đến việc filter dữ liệu cũ/mới. Nó có thể làm job chậm hơn (single worker), nhưng vẫn reprocess toàn bộ data, lãng phí hơn. Không giải quyết root cause! ⚠️

  • Use a FindMatches machine learning (ML) transform.
    ❌ Sai. FindMatches là ML transform trong Glue để entity resolution (tìm match dữ liệu duplicate), không dùng để theo dõi tiến độ xử lý incremental hay tránh reprocessing S3 data. Nó dành cho data cleaning/ML tasks, không liên quan đến vấn đề này. Sử dụng sai sẽ phức tạp hóa job vô ích! 🤖

📘 Tài liệu tham khảo (cập nhật AWS 2024-2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm ví dụ code Glue script, cứ hỏi nhé!

Câu 1279 Chọn nhiều đáp án
A solutions architect must design a highly available infrastructure for a website. The website is powered by Windows web servers that run on Amazon EC2 instances. The solutions architect must implement a solution that can mitigate a large-scale DDoS attack that originates from thousands of IP addresses. Downtime is not acceptable for the website.
Which actions should the solutions architect take to protect the website from such an attack? (Choose two.)
  1. A Use AWS Shield Advanced to stop the DDoS attack.
  2. B Configure Amazon GuardDuty to automatically block the attackers.
  3. C Configure the website to use Amazon CloudFront for both static and dynamic content.
  4. D Use an AWS Lambda function to automatically add attacker IP addresses to VPC network ACLs.
  5. E Use EC2 Spot Instances in an Auto Scaling group with a target tracking scaling policy that is set to 80% CPU utilization.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi yêu cầu một Solutions Architect thiết kế hạ tầng highly available (có tính sẵn sàng cao) cho một website chạy trên Windows web servers đặt trên Amazon EC2 instances. Thách thức chính là phải chống lại các cuộc tấn công DDoS quy mô lớn (phát sinh từ hàng ngàn IP addresses), đồng thời không chấp nhận downtime (nghĩa là website phải luôn hoạt động liên tục).

🔑 Yêu cầu chọn TWO actions (hai hành động) phù hợp nhất để bảo vệ website. Đây là tình huống thực tế trong AWS, nơi DDoS attack có thể làm quá tải EC2 trực tiếp, nên cần các dịch vụ phân tán traffic và bảo vệ chuyên dụng. Kiến thức dựa trên AWS Well-Architected Framework (2023-2026 updates), nhấn mạnh Reliability Pillar và Security Pillar, với Shield Advanced được nâng cấp hỗ trợ AI-driven mitigation cho volumetric attacks lớn hơn.

✅ Đáp án đúng (Chọn TWO)

Hai lựa chọn đúng là:

  1. Use AWS Shield Advanced to stop the DDoS attack.
    Lý do: AWS Shield Advanced là dịch vụ chuyên chống DDoS Layer 3/4/7 quy mô lớn (volumetric, protocol, application), tự động mitigate từ hàng ngàn IP mà không cần can thiệp thủ công. Nó tích hợp với EC2, cung cấp DDoS Response Team (DRT) 24/7, cost protection (hoàn tiền nếu attack gây chi phí tăng), và visibility qua dashboards. Phù hợp hoàn hảo cho no-downtime.

  2. Configure the website to use Amazon CloudFront for both static and dynamic content.
    Lý do: CloudFront là CDN toàn cầu, phân tán traffic đến edge locations (hàng trăm PoP), hấp thụ DDoS trước khi chạm EC2 origin. Hỗ trợ dynamic content qua origin shielding và Lambda@Edge. Kết hợp Shield Standard (miễn phí) hoặc Advanced, giúp scale globally mà không downtime. Đây là best practice cho web apps trên EC2.

📋 Giải thích tất cả các phương án (Đúng/Sai)

Dưới đây là phân tích từng lựa chọn một cách chi tiết, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi giải thích dựa trên tính khả thi, scalability cho DDoS lớn, và no-downtime requirement (cập nhật AWS 2026: Shield Advanced nay có ML-based auto-mitigation nhanh hơn 50%).

  • ✅ Use AWS Shield Advanced to stop the DDoS attack.
    Giải thích đúng: Đây là lựa chọn hàng đầu cho DDoS lớn từ thousands IPs. Shield Advanced cung cấp proactive engagement, inline mitigation, và tích hợp trực tiếp với EC2/ELB. Không chỉ block mà còn monitor real-time qua Shield metrics in CloudWatch. Hoàn hảo cho highly available infra mà không gây downtime (mitigate at edge). 🛡️

  • ❌ Configure Amazon GuardDuty to automatically block the attackers.
    Giải thích sai: GuardDuty là dịch vụ threat detection (phát hiện unusual behavior qua ML trên logs VPC Flow, CloudTrail), không phải công cụ block tự động. Nó chỉ generate findings/alerts, cần tích hợp Lambda/Firewall Manager để block – quá chậm và không scale cho DDoS volumetric lớn (hàng ngàn IPs). Không phù hợp no-downtime vì detection chỉ sau attack. 👎

  • ✅ Configure the website to use Amazon CloudFront for both static and dynamic content.
    Giải thích đúng: CloudFront offload traffic đến edge, giảm tải EC2 trực tiếp. Với AWS Shield integration, tự động scrub DDoS Layer 7. Hỗ trợ dynamic content (API Gateway, ALB origin), cache static assets, và origin failover cho HA. Best practice từ AWS DDoS Whitepaper: giảm attack surface 99%. 🌐

  • ❌ Use an AWS Lambda function to automatically add attacker IP addresses to VPC network ACLs.
    Giải thích sai: Lambda có thể parse logs để add IPs vào NACLs, nhưng không scale cho thousands IPs (NACL limits: 20 rules/entry mỗi direction, đánh số sequential). Quá trình reactive, gây latency/block legit traffic (false positives), và downtime khi update ACLs (propagation ~60s). Không phải giải pháp enterprise cho DDoS lớn. ⚠️

  • ❌ Use EC2 Spot Instances in an Auto Scaling group with a target tracking scaling policy that is set to 80% CPU utilization.
    Giải thích sai: Spot Instances rẻ nhưng không reliable (có thể interrupt bất kỳ lúc nào), vi phạm highly available + no-downtime. Scaling policy dựa CPU không chống DDoS (attack volumetric không phải CPU spike nhất quán), và Spot dễ bị terminate trong high demand. Chỉ dùng cho fault-tolerant workloads, không phải web critical. 🚫

📘 Tài liệu tham khảo (AWS Official - Cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm case studies, hỏi nhé!

Câu 1280
A company is preparing to deploy a new serverless workload. A solutions architect must use the principle of least privilege to configure permissions that will be used to run an AWS Lambda function. An Amazon EventBridge (Amazon CloudWatch Events) rule will invoke the function.
Which solution meets these requirements?
  1. A Add an execution role to the function with lambda:InvokeFunction as the action and * as the principal.
  2. B Add an execution role to the function with lambda:InvokeFunction as the action and Service: lambda.amazonaws.com as the principal.
  3. C Add a resource-based policy to the function with lambda:* as the action and Service: events.amazonaws.com as the principal.
  4. D Add a resource-based policy to the function with lambda:InvokeFunction as the action and Service: events.amazonaws.com as the principal.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai một workload serverless mới trên AWS, cụ thể là cấu hình quyền hạn (permissions) cho hàm AWS Lambda theo nguyên tắc least privilege (quyền hạn tối thiểu cần thiết). Một rule của Amazon EventBridge (trước đây gọi là Amazon CloudWatch Events) sẽ kích hoạt (invoke) hàm Lambda này.
📌 Yêu cầu chính: Solutions Architect phải chọn giải pháp đảm bảo quyền hạn an toàn nhất, chỉ cho phép EventBridge invoke Lambda mà không cấp quyền thừa. Điều này liên quan đến hai loại policy chính trên Lambda:

  • Execution role (IAM role mà Lambda assume để truy cập các dịch vụ AWS khác).
  • Resource-based policy (policy gắn trực tiếp vào Lambda function để cho phép các service bên ngoài invoke nó).
    Kiến thức cập nhật đến 2026: AWS vẫn yêu cầu resource-based policy cho EventBridge invoke Lambda (theo AWS Lambda và EventBridge docs phiên bản mới nhất, hỗ trợ cross-account và least privilege qua điều kiện cụ thể).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Add a resource-based policy to the function with lambda:InvokeFunction as the action and Service: events.amazonaws.com as the principal.

🛠️ Lý do chi tiết:

  • Đây là cách chuẩn và an toàn nhất theo best practice AWS. Resource-based policy trên Lambda function cho phép Service: events.amazonaws.com (EventBridge) thực hiện action lambda:InvokeFunction cụ thể, tuân thủ least privilege (không cấp quyền thừa như lambda:*).
  • EventBridge cần quyền này để invoke Lambda (không phải qua execution role). AWS tự động tạo policy mẫu khi tạo rule, nhưng cần tùy chỉnh để least privilege.
  • ✅ Hoàn hảo cho serverless: Không ảnh hưởng execution role (dùng cho Lambda access DynamoDB/S3...), tránh rủi ro bảo mật.

📋 Phân tích tất cả các phương án

Dưới đây là phân tích từng lựa chọn một cách chi tiết. Tôi giữ nguyên văn bản gốc bằng tiếng Anh, đánh dấu ✅/❌ và giải thích bằng tiếng Việt:

  • ❌ Add an execution role to the function with lambda:InvokeFunction as the action and * as the principal.
    🧩 Sai vì: Execution role dùng cho Lambda service (lambda.amazonaws.com) assume để function truy cập tài nguyên khác (như S3), không dùng để invoke function. Principal "*" quá rộng, vi phạm least privilege (cho phép bất kỳ ai invoke). Không hoạt động cho EventBridge.

  • ❌ Add an execution role to the function with lambda:InvokeFunction as the action and Service: lambda.amazonaws.com as the principal.
    🧩 Sai vì: Vẫn dùng execution role sai vị trí – nó chỉ cho Lambda service thực hiện action trên behalf của function (như GetObject trên S3), không cấp quyền cho EventBridge invoke. Principal lambda.amazonaws.com chỉ tự invoke chính nó, vô ích ở đây.

  • ❌ Add a resource-based policy to the function with lambda: as the action and Service: events.amazonaws.com as the principal.*
    🧩 Sai vì: Resource-based policy và principal (events.amazonaws.com) đúng hướng, nhưng action lambda: quá rộng* (cho phép tất cả action Lambda như UpdateFunctionCode, DeleteFunction...). Vi phạm least privilege nghiêm trọng, có thể dẫn đến privilege escalation. AWS khuyến cáo chỉ dùng InvokeFunction.

  • ✅ Add a resource-based policy to the function with lambda:InvokeFunction as the action and Service: events.amazonaws.com as the principal.
    🛠️ Đúng vì: Kết hợp hoàn hảo: Resource-based policy cho phép chính xác EventBridge (events.amazonaws.com) invoke với action cụ thể lambda:InvokeFunction. An toàn, tuân thủ least privilege, và được AWS hỗ trợ đầy đủ (có thể thêm điều kiện như SourceArn cho rule cụ thể).

📘 Tài liệu tham khảo

  • AWS Lambda Developer Guide: Resource-based policy examples for Lambda (cập nhật 2025-2026, ví dụ EventBridge invoke).
  • Amazon EventBridge User Guide: Permissions for invoking Lambda (yêu cầu resource policy với InvokeFunction).
  • AWS Well-Architected Framework - Security Pillar: Nhấn mạnh least privilege cho serverless (phiên bản 2026).
    🔍 Kiểm tra thực tế qua AWS Console: Tạo EventBridge rule → Lambda → Xem policy tự sinh với chính format này!