Ngân hàng đề — AWS Certified Solutions Architect Professional

Tìm thấy 1221 câu.

Câu 1021
A financial services company runs a complex, multi-tier application on Amazon EC2 instances and AWS Lambda functions. The application stores temporary data in Amazon S3. The S3 objects are valid for only 45 minutes and are deleted after 24 hours.

The company deploys each version of the application by launching an AWS CloudFormation stack. The stack creates all resources that are required to run the application. When the company deploys and validates a new application version, the company deletes the CloudFormation stack of the old version.

The company recently tried to delete the CloudFormation stack of an old application version, but the operation failed. An analysis shows that CloudFormation failed to delete an existing S3 bucket. A solutions architect needs to resolve this issue without making major changes to the application's architecture.

Which solution meets these requirements?
  1. A Implement a Lambda function that deletes all files from a given S3 bucket. Integrate this Lambda function as a custom resource into the CloudFormation stack. Ensure that the custom resource has a DependsOn attribute that points to the S3 bucket's resource.
  2. B Modify the CloudFormation template to provision an Amazon Elastic File System (Amazon EFS) file system to store the temporary files there instead of in Amazon S3. Configure the Lambda functions to run in the same VPC as the file system. Mount the file system to the EC2 instances and Lambda functions.
  3. C Modify the CloudF ormation stack to create an S3 Lifecycle rule that expires all objects 45 minutes after creation. Add a DependsOn attribute that points to the S3 bucket’s resource.
  4. D Modify the CloudFormation stack to attach a DeletionPolicy attribute with a value of Delete to the S3 bucket.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả một ứng dụng tài chính phức tạp chạy trên Amazon EC2 và AWS Lambda, lưu trữ dữ liệu tạm thời trong Amazon S3. Các object S3 chỉ hợp lệ trong 45 phút và bị xóa sau 24 giờ.

Công ty triển khai từng phiên bản ứng dụng bằng AWS CloudFormation stack, tạo tất cả tài nguyên cần thiết. Khi triển khai phiên bản mới, họ xóa stack cũ. Vấn đề: Gần đây, việc xóa stack cũ thất bại vì CloudFormation không xóa được S3 bucket (do bucket chứa objects chưa được xóa hết).

Yêu cầu giải pháp: Giải quyết mà không thay đổi lớn kiến trúc ứng dụng (giữ nguyên S3 cho dữ liệu tạm). 🛠️

Nguyên nhân gốc rễ (theo docs AWS cập nhật 2024-2026): S3 bucket không thể xóa nếu còn objects (kể cả empty objects hoặc versions). CloudFormation delete stack sẽ fail nếu resource con (như S3 bucket) không delete được. Cần cơ chế cleanup objects trước khi delete bucket. 📘

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Implement a Lambda function that deletes all files from a given S3 bucket. Integrate this Lambda function as a custom resource into the CloudFormation stack. Ensure that the custom resource has a DependsOn attribute that points to the S3 bucket's resource.

Lý do chọn ✅:

  • Custom Resource trong CloudFormation (hỗ trợ đầy đủ đến 2026) cho phép tích hợp Lambda function để thực hiện hành động tùy chỉnh trước khi delete resource.
  • Lambda nhận event "Delete" từ CloudFormation khi xóa stack: Nó liệt kê và xóa tất cả objects trong bucket (sử dụng ListObjectsV2 + DeleteObjects).
  • DependsOn đảm bảo: Bucket được tạo trước custom resource (CREATE phase), và custom resource delete trước bucket (DELETE phase) → Bucket empty → Delete thành công.
  • Không thay đổi architecture: Giữ nguyên S3, chỉ thêm Lambda cleanup tự động. Hoàn hảo cho multi-tier app với dữ liệu tạm 24h. 🧩
  • Cập nhật AWS: Custom Resources với Lambda là best practice cho cleanup S3 trong CFN (AWS Well-Architected Framework - Operational Excellence pillar).

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn một, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá ✅ hoặc ❌ với lý do chi tiết bằng tiếng Việt:

  • Implement a Lambda function that deletes all files from a given S3 bucket. Integrate this Lambda function as a custom resource into the CloudFormation stack. Ensure that the custom resource has a DependsOn attribute that points to the S3 bucket's resource.
    ❌ Đúng (như giải thích trên): Lambda cleanup objects qua custom resource + DependsOn đảm bảo thứ tự delete chính xác, giải quyết fail delete bucket mà không thay đổi lớn. Best practice AWS. ✅🛠️

  • Modify the CloudFormation template to provision an Amazon Elastic File System (Amazon EFS) file system to store the temporary files there instead of in Amazon S3. Configure the Lambda functions to run in the same VPC as the file system. Mount the file system to the EC2 instances and Lambda functions.
    ❌ Sai: Thay S3 bằng EFS là thay đổi lớn architecture (yêu cầu cấm), vì EFS là file system persistent (không phù hợp dữ liệu tạm 45 phút/24h), cần VPC config phức tạp cho EC2/Lambda, tăng chi phí/latency. EFS không tự xóa như S3 Lifecycle, và không giải quyết vấn đề CloudFormation delete hiện tại. 🚫

  • Modify the CloudF ormation stack to create an S3 Lifecycle rule that expires all objects 45 minutes after creation. Add a DependsOn attribute that points to the S3 bucket’s resource.
    ❌ Sai: S3 Lifecycle rule expire objects sau 45 phút không đảm bảo bucket empty ngay lập tức khi delete stack (có thể còn objects valid đến 24h). Lifecycle chạy asynchronous (có delay), không block delete. DependsOn chỉ kiểm soát thứ tự tạo resource, không ảnh hưởng delete phase hoặc force cleanup. Vẫn fail delete bucket. ⏳❌

  • Modify the CloudFormation stack to attach a DeletionPolicy attribute with a value of Delete to the S3 bucket.
    ❌ Sai: DeletionPolicy: Delete là mặc định cho S3 bucket trong CloudFormation (không cần thêm). Nó chỉ thử delete, nhưng fail nếu bucket không empty (vấn đề gốc). Không có cơ chế cleanup objects → Không giải quyết gì. (Lưu ý: Retain/Snapshot mới hữu ích giữ data). 🔄❌

📘 Tài liệu tham khảo (cập nhật AWS 2024-2026)

Giải pháp này 100% production-ready cho DevOps Pro! 🚀 Nếu cần sample code Lambda, hỏi thêm nhé. 😊

Câu 1022
A company has developed a mobile game. The backend for the game runs on several virtual machines located in an on-premises data center. The business logic is exposed using a REST API with multiple functions. Player session data is stored in central file storage. Backend services use different API keys for throttling and to distinguish between live and test traffic.

The load on the game backend varies throughout the day. During peak hours, the server capacity is not sufficient. There are also latency issues when fetching player session data. Management has asked a solutions architect to present a cloud architecture that can handle the game’s varying load and provide low-latency data access. The API model should not be changed.

Which solution meets these requirements?
  1. A Implement the REST API using a Network Load Balancer (NLB). Run the business logic on an Amazon EC2 instance behind the NLB. Store player session data in Amazon Aurora Serverless.
  2. B Implement the REST API using an Application Load Balancer (ALB). Run the business logic in AWS Lambda. Store player session data in Amazon DynamoDB with on-demand capacity.
  3. C Implement the REST API using Amazon API Gateway. Run the business logic in AWS Lambda. Store player session data in Amazon DynamoDB with on-demand capacity.
  4. D Implement the REST API using AWS AppSync. Run the business logic in AWS Lambda. Store player session data in Amazon Aurora Serverless.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả một công ty phát triển game mobile với backend chạy trên các máy ảo (VM) tại data center on-premises. Logic kinh doanh được expose qua REST API với nhiều functions, dữ liệu session của người chơi lưu trữ trong file storage tập trung. Các backend services sử dụng API keys để throttling (giới hạn rate) và phân biệt traffic live/test.

Vấn đề chính:

  • Load backend biến động theo giờ cao điểm (peak hours), capacity server không đủ.
  • Latency cao khi fetch dữ liệu session người chơi từ file storage.
  • Yêu cầu: Kiến trúc cloud phải handle varying load (scale tự động theo tải), low-latency data access, KHÔNG thay đổi API model (vẫn giữ nguyên REST API).

📘 Mục tiêu: Đề xuất giải pháp AWS phù hợp, tận dụng serverless để scale linh hoạt, database low-latency cho session data (thường là key-value, read/write cao), và hỗ trợ API keys/throttling mà không thay đổi REST API.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Implement the REST API using Amazon API Gateway. Run the business logic in AWS Lambda. Store player session data in Amazon DynamoDB with on-demand capacity.

Lý do chi tiết 🛠️:

  • Amazon API Gateway: Hỗ trợ đầy đủ REST API (không thay đổi model), tích hợp API keys cho authentication/throttling, phân biệt live/test traffic. Tự động scale theo load, hỗ trợ caching để giảm latency.
  • AWS Lambda: Serverless compute, auto-scale theo varying load (peak hours), không cần quản lý server, pay-per-use, integrate trực tiếp với API Gateway.
  • Amazon DynamoDB on-demand: NoSQL key-value store lý tưởng cho session data (low-latency reads/writes <10ms), on-demand capacity auto-scale vô hạn mà không provision trước, xử lý burst traffic game tốt.
  • Toàn bộ giải pháp serverless, handle varying load hoàn hảo, low-latency, phù hợp cập nhật AWS 2026 (DynamoDB hỗ trợ global tables, Lambda Graviton3 cho performance cao).

📋 Phân tích tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai với lý do cụ thể dựa trên yêu cầu (varying load, low-latency, giữ REST API).

  • ❌ [SAI] Implement the REST API using a Network Load Balancer (NLB). Run the business logic on an Amazon EC2 instance behind the NLB. Store player session data in Amazon Aurora Serverless.

    • Lý do sai: NLB hoạt động ở Layer 4 (TCP/UDP), không phù hợp optimize REST API HTTP/HTTPS (thiếu features như path-based routing, API keys/throttling). EC2 cần manual/auto scaling group (ASG), không handle varying load mượt mà như serverless, vẫn có overhead quản lý. Aurora Serverless (relational DB) không low-latency cho session data key-value (query phức tạp hơn DynamoDB), scale chậm hơn cho burst traffic game.
  • ❌ [SAI] Implement the REST API using an Application Load Balancer (ALB). Run the business logic in AWS Lambda. Store player session data in Amazon DynamoDB with on-demand capacity.

    • Lý do sai: ALB (Layer 7) hỗ trợ HTTP nhưng không integrate native tốt với Lambda cho REST API phức tạp (cần target group đặc biệt, thiếu API keys/throttling/caching built-in như API Gateway). ALB phù hợp hơn EC2/Fargate, không phải serverless API endpoint lý tưởng. DynamoDB đúng nhưng tổng thể không tối ưu cho REST API với API keys phân biệt traffic.
  • ✅ [ĐÚNG] Implement the REST API using Amazon API Gateway. Run the business logic in AWS Lambda. Store player session data in Amazon DynamoDB with on-demand capacity.

    • Lý do đúng: Như phân tích trên, full serverless, giữ nguyên REST API, API Gateway xử lý throttling/API keys hoàn hảo, Lambda scale varying load, DynamoDB low-latency/on-demand cho session data. Giải pháp best practice cho game backend.
  • ❌ [SAI] Implement the REST API using AWS AppSync. Run the business logic in AWS Lambda. Store player session data in Amazon Aurora Serverless.

    • Lý do sai: AWS AppSync dành cho GraphQL API, không phải REST API (thay đổi hoàn toàn API model, vi phạm yêu cầu). Aurora Serverless (SQL) không low-latency/efficient cho session data như DynamoDB, scale kém hơn cho high-throughput game.

📚 Tài liệu tham khảo (AWS cập nhật 2026)

Giải pháp này đảm bảo cost-effective, scalable, low-latency cho game mobile! 🎮✨

Câu 1023
A company is migrating an application to the AWS Cloud. The application runs in an on-premises data center and writes thousands of images into a mounted NFS file system each night. After the company migrates the application, the company will host the application on an Amazon EC2 instance with a mounted Amazon Elastic File System (Amazon EFS) file system.

The company has established an AWS Direct Connect connection to AWS. Before the migration cutover, a solutions architect must build a process that will replicate the newly created on-premises images to the EFS file system.

What is the MOST operationally efficient way to replicate the images?
  1. A Configure a periodic process to run the aws s3 sync command from the on-premises file system to Amazon S3. Configure an AWS Lambda function to process event notifications from Amazon S3 and copy the images from Amazon S3 to the EFS file system.
  2. B Deploy an AWS Storage Gateway file gateway with an NFS mount point. Mount the file gateway file system on the on-premises server. Configure a process to periodically copy the images to the mount point.
  3. C Deploy an AWS DataSync agent to an on-premises server that has access to the NFS file system. Send data over the Direct Connect connection to an S3 bucket by using a public VIF. Configure an AWS Lambda function to process event notifications from Amazon S3 and copy the images from Amazon S3 to the EFS file system.
  4. D Deploy an AWS DataSync agent to an on-premises server that has access to the NFS file system. Send data over the Direct Connect connection to an AWS PrivateLink interface VPC endpoint for Amazon EFS by using a private VIF. Configure a DataSync scheduled task to send the images to the EFS file system every 24 hours.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi xoay quanh việc di chuyển ứng dụng (migration) từ trung tâm dữ liệu on-premises sang AWS Cloud. Ứng dụng hiện đang chạy on-premises và ghi hàng ngàn ảnh mới vào hệ thống file NFS được mount mỗi đêm. Sau khi migrate, ứng dụng sẽ chạy trên EC2 instance với Amazon EFS được mount. Công ty đã thiết lập AWS Direct Connect để kết nối trực tiếp. Trước thời điểm cutover migration (chuyển đổi chính thức), cần xây dựng quy trình replicate (sao chép đồng bộ) các ảnh mới tạo trên on-premises sang EFS một cách hiệu quả vận hành nhất (MOST operationally efficient).

🔑 Yêu cầu chính: Quy trình phải tự động, đáng tin cậy, tận dụng Direct Connect (tránh public internet để đảm bảo bảo mật và hiệu suất), tập trung vào việc sync file từ NFS on-prem sang EFS AWS, với tần suất hàng đêm (khoảng 24 giờ/lần).

📘 Kiến thức AWS cập nhật đến 2026: AWS DataSync (phiên bản mới nhất hỗ trợ NFS 4.1, EFS IA/Standard, PrivateLink endpoints), Direct Connect với private VIF cho PrivateLink, EFS replication qua DataSync là best practice cho file sync lớn (theo AWS Well-Architected Framework - Storage Pillar).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Deploy an AWS DataSync agent to an on-premises server that has access to the NFS file system. Send data over the Direct Connect connection to an AWS PrivateLink interface VPC endpoint for Amazon EFS by using a private VIF. Configure a DataSync scheduled task to send the images to the EFS file system every 24 hours.

Lý do chọn đáp án này 🛠️:

  • Hiệu quả vận hành cao nhất: DataSync agent cài trực tiếp trên server on-prem truy cập NFS, sync trực tiếp sang EFS qua PrivateLink VPC endpoint (không qua public internet, tận dụng Direct Connect private VIF cho traffic private, an toàn, low-latency, high-throughput lên đến 10 Gbps+).
  • Tự động hóa hoàn hảo: Hỗ trợ scheduled task mỗi 24 giờ, chỉ sync delta (thay đổi), hỗ trợ hàng ngàn file lớn mà không cần script thủ công.
  • Tối ưu chi phí & hiệu suất: Không trung gian (như S3), hỗ trợ NFS-to-EFS native (EFS Access Points, IAM auth), phù hợp migration lớn theo AWS re:Invent 2025 updates.
  • Best practice: Khuyến nghị chính thức cho hybrid file replication (AWS Storage Gateway vs DataSync: DataSync ưu tiên cho EFS direct sync).

Tài liệu tham khảo 📖:

❌ Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá ✅ (đúng) hoặc ❌ (sai), kèm giải thích lý do bằng tiếng Việt.

  • Phương án 1: Configure a periodic process to run the aws s3 sync command from the on-premises file system to Amazon S3. Configure an AWS Lambda function to process event notifications from Amazon S3 and copy the images from Amazon S3 to the EFS file system.
    ❌ Sai vì: Không hiệu quả vận hành - phải qua S3 trung gian (sync NFS → S3 → Lambda → EFS), tăng độ trễ, chi phí lưu trữ/transfer kép, phức tạp (cần cron job + Lambda event), không tận dụng Direct Connect tối ưu cho EFS direct. Không phải MOST efficient cho file system replication.

  • Phương án 2: Deploy an AWS Storage Gateway file gateway with an NFS mount point. Mount the file gateway file system on the on-premises server. Configure a process to periodically copy the images to the mount point.
    ❌ Sai vì: Storage Gateway File Gateway chỉ sync NFS/SMB sang S3 (không trực tiếp EFS), dữ liệu lưu local cache rồi upload S3, không hỗ trợ EFS native. Cần process thủ công copy thêm, không tự động delta sync, kém efficient cho hàng ngàn ảnh nightly, và không leverage Direct Connect cho EFS.

  • Phương án 3: Deploy an AWS DataSync agent to an on-premises server that has access to the NFS file system. Send data over the Direct Connect connection to an S3 bucket by using a public VIF. Configure an AWS Lambda function to process event notifications from Amazon S3 and copy the images from Amazon S3 to the EFS file system.
    ❌ Sai vì: Dù dùng DataSync agent tốt, nhưng sync sang S3 qua public VIF (không private, kém bảo mật), rồi Lambda copy S3 → EFS - vẫn trung gian S3, phức tạp 2 bước, tăng chi phí/latency. Không direct EFS, vi phạm "MOST operationally efficient".

  • Phương án 4 (Đúng): Deploy an AWS DataSync agent to an on-premises server that has access to the NFS file system. Send data over the Direct Connect connection to an AWS PrivateLink interface VPC endpoint for Amazon EFS by using a private VIF. Configure a DataSync scheduled task to send the images to the EFS file system every 24 hours.
    ✅ Đúng vì: Như đã giải thích ở trên - direct NFS → EFS, private secure qua Direct Connect private VIF + PrivateLink, scheduled tự động, zero trung gian, scalable cho large-scale migration. Hoàn hảo theo AWS best practices 2026.

🧠 Kết luận: Lựa chọn này đảm bảo zero-downtime replication trước cutover, dễ scale post-migration! Nếu cần lab thực hành, dùng AWS Free Tier DataSync.

Câu 1024
A company recently migrated a web application from an on-premises data center to the AWS Cloud. The web application infrastructure consists of an Amazon CloudFront distribution that routes to an Application Load Balancer (ALB), with Amazon Elastic Container Service (Amazon ECS) to process requests. A recent security audit revealed that the web application is accessible by using both CloudFront and ALB endpoints. However, the company requires that the web application must be accessible only by using the CloudFront endpoint.

Which solution will meet this requirement with the LEAST amount of effort?
  1. A Create a new security group and attach it to the CloudFront distribution. Update the ALB security group ingress to allow access only from the CloudFront security group.
  2. B Update ALB security group ingress to allow access only from the com.amazonaws.global.cloudfront.origin-facing CloudFront managed prefix list.
  3. C Create a com.amazonaws.region.elasticloadbalancing VPC interface endpoint for Elastic Load Balancing. Update the ALB scheme from internet-facing to internal.
  4. D Extract CloudFront IPs from the AWS provided ip-ranges.json document. Update ALB security group ingress to allow access only from CloudFront IPs.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một ứng dụng web đã được di chuyển từ data center on-premises lên AWS Cloud, với kiến trúc bao gồm:
Amazon CloudFront (CDN phân phối nội dung) làm điểm truy cập đầu tiên, sau đó route traffic đến Application Load Balancer (ALB), và ALB xử lý request đến Amazon Elastic Container Service (ECS).

🔍 Vấn đề phát hiện từ security audit: Ứng dụng web có thể truy cập trực tiếp qua cả endpoint của CloudFront (đúng yêu cầu) và ALB (không mong muốn). Công ty yêu cầu chỉ cho phép truy cập qua CloudFront endpoint, nghĩa là phải chặn traffic trực tiếp đến ALB từ internet, nhưng vẫn cho CloudFront truy cập ALB.

🎯 Yêu cầu giải pháp: Implement với LEAST amount of effort (ít công sức nhất), tức ưu tiên giải pháp đơn giản, tự động hóa cao, không cần can thiệp thủ công thường xuyên.

📘 Kiến thức liên quan (cập nhật AWS 2026): CloudFront hỗ trợ Managed Prefix Lists (danh sách tiền tố IP được AWS quản lý) để restrict origin (như ALB) chỉ chấp nhận traffic từ CloudFront. Prefix list này dynamic, tự update khi AWS thay đổi IP ranges của CloudFront.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Update ALB security group ingress to allow access only from the com.amazonaws.global.cloudfront.origin-facing CloudFront managed prefix list.

Lý do:

  • 🛠️ Giải pháp này least effort vì sử dụng CloudFront managed prefix list (tên: com.amazonaws.global.cloudfront.origin-facing), được AWS tự động quản lý và cập nhật IP ranges của CloudFront origin-facing traffic. Chỉ cần update Security Group (SG) ingress của ALB để allow traffic từ prefix list này (port 80/443), chặn tất cả traffic khác từ internet.
  • Không cần hardcode IP, không tạo resource mới, và hoạt động ngay lập tức với CloudFront -> ALB.
  • ✅ Hoàn hảo cho yêu cầu: ALB chỉ accessible từ CloudFront, traffic trực tiếp bị block.

Tài liệu tham khảo:

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, với giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai kèm lý do bằng tiếng Việt:

  • ❌ [SAI] Create a new security group and attach it to the CloudFront distribution. Update the ALB security group ingress to allow access only from the CloudFront security group.
    Lý do sai: CloudFront là service global, không hỗ trợ attach Security Group (SG chỉ dùng cho VPC resources như EC2/ALB). Không thể tạo SG cho CloudFront distribution, dẫn đến giải pháp không khả thi. Phức tạp và sai từ gốc.

  • ✅ [ĐÚNG] Update ALB security group ingress to allow access only from the com.amazonaws.global.cloudfront.origin-facing CloudFront managed prefix list.
    Lý do đúng: Như đã giải thích ở phần đáp án. Giải pháp đơn giản nhất (least effort), chỉ update SG rule một lần, AWS tự quản lý prefix list. Hiệu quả cao, không downtime.

  • ❌ [SAI] Create a com.amazonaws.region.elasticloadbalancing VPC interface endpoint for Elastic Load Balancing. Update the ALB scheme from internet-facing to internal.
    Lý do sai: Chuyển ALB thành internal scheme sẽ làm ALB chỉ accessible trong VPC, yêu cầu VPC Interface Endpoint cho ELB (nhưng ELB không cần endpoint để access internal ALB). CloudFront cần origin public hoặc private riêng (qua VPC endpoint policy phức tạp). Thay đổi lớn (reconfigure ALB, DNS, CloudFront origin), không least effort, và có thể gây downtime.

  • ❌ [SAI] Extract CloudFront IPs from the AWS provided ip-ranges.json document. Update ALB security group ingress to allow access only from CloudFront IPs.
    Lý do sai: File ip-ranges.json liệt kê IP của CloudFront, nhưng IP ranges thay đổi thường xuyên (AWS publish weekly updates). Phải extract thủ công, update SG liên tục (Lambda/script), dễ lỗi và không scalable/least effort. Prefix list tốt hơn vì tự động.

🛡️ Khuyến nghị thực tế: Sau implement, test bằng curl trực tiếp ALB (nên fail) và qua CloudFront (nên success). Monitor bằng AWS WAF/CloudWatch Logs để verify. Giải pháp này tuân thủ AWS Well-Architected Framework (Security Pillar).

Câu 1025
A company hosts a community forum site using an Application Load Balancer (ALB) and a Docker application hosted in an Amazon ECS cluster. The site data is stored in Amazon RDS for MySQL and the container image is stored in ECR. The company needs to provide their customers with a disaster recovery SLA with an RTO of no more than 24 hours and RPO of no more than 8 hours.

Which of the following solutions is the MOST cost-effective way to meet the requirements?
  1. A Use AWS CloudFormation to deploy identical ALB, EC2, ECS and RDS resources in two regions. Schedule RDS snapshots every 8 hours. Use RDS multi-region replication to update the secondary region's copy of the database. In the event of a failure, restore from the latest snapshot, and use an Amazon Route 53 DNS failover policy to automatically redirect customers to the ALB in the secondary region.
  2. B Store the Docker image in ECR in two regions. Schedule RDS snapshots every 8 hours with snapshots copied to the secondary region. In the event of a failure, use AWS CloudFormation to deploy the ALB, EC2, ECS and RDS resources in the secondary region, restore from the latest snapshot, and update the DNS record to point to the ALB in the secondary region.
  3. C Use AWS CloudFormation to deploy identical ALB, EC2, ECS, and RDS resources in a secondary region. Schedule hourly RDS MySQL backups to Amazon S3 and use cross-region replication to replicate data to a bucket in the secondary region. In the event of a failure, import the latest Docker image to Amazon ECR in the secondary region, deploy to the EC2 instance, restore the latest MySQL backup, and update the DNS record to point to the ALB in the secondary region.
  4. D Deploy a pilot light environment in a secondary region with an ALB and a minimal resource EC2 deployment for Docker in an AWS Auto Scaling group with a scaling policy to increase instance size and number of nodes. Create a cross-region read replica of the RDS data. In the event of a failure, promote the replica to primary, and update the DNS record to point to the ALB in the secondary region.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh việc thiết kế giải pháp Disaster Recovery (DR) cho một trang web diễn đàn cộng đồng được host trên AWS. Kiến trúc hiện tại bao gồm:

  • Application Load Balancer (ALB) phân tải lưu lượng.
  • Amazon ECS cluster chạy ứng dụng Docker (container image lưu trong Amazon ECR).
  • Amazon RDS for MySQL lưu trữ dữ liệu site.

Yêu cầu DR phải đáp ứng SLA:

  • RTO (Recovery Time Objective) ≤ 24 giờ: Thời gian khôi phục hệ thống sau sự cố không quá 24 giờ.
  • RPO (Recovery Point Objective) ≤ 8 giờ: Mất dữ liệu tối đa không quá 8 giờ (tức là dữ liệu phải được sao lưu ít nhất mỗi 8 giờ).

Giải pháp phải là cách tiết kiệm chi phí nhất (MOST cost-effective). 🛠️ Thách thức chính: Cân bằng giữa tính sẵn sàng (backup dữ liệu và image), thời gian khôi phục nhanh (deploy tự động), và chi phí thấp (tránh chạy tài nguyên dư thừa ở vùng secondary region liên tục). AWS khuyến nghị các mô hình DR như Backup & Restore (rẻ nhất cho RTO/RPO lớn), Pilot Light, Warm Standby – phù hợp với kiến thức cập nhật đến 2026 (AWS Well-Architected Framework: Reliability Pillar).

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng là lựa chọn thứ 2:

Store the Docker image in ECR in two regions. Schedule RDS snapshots every 8 hours with snapshots copied to the secondary region. In the event of a failure, use AWS CloudFormation to deploy the ALB, EC2, ECS and RDS resources in the secondary region, restore from the latest snapshot, and update the DNS record to point to the ALB in the secondary region.

Lý do 🏆:

  • Đáp ứng RPO ≤8h: Snapshot RDS mỗi 8 giờ và copy cross-region (tính năng native của RDS, retention tự động).
  • Đáp ứng RTO ≤24h: Sử dụng AWS CloudFormation deploy toàn bộ stack (ALB, ECS cluster trên EC2, RDS) ở secondary region chỉ khi fail – thời gian deploy thường < vài giờ với template sẵn.
  • Tiết kiệm chi phí nhất 💰: Không chạy tài nguyên ở secondary region thường xuyên (chỉ ECR replication cho image – chi phí thấp), tránh phí idle cho EC2/ECS/RDS. Đây là mô hình Backup & Restore tối ưu cho RTO/RPO lớn.
  • Hoàn hảo cho ECS/ECR: ECR hỗ trợ cross-region replication tự động (cập nhật 2023+), Docker image sẵn sàng ngay.

📋 Giải thích tất cả các phương án (đúng/sai)

  • Phương án 1 ❌ SAI:

    Use AWS CloudFormation to deploy identical ALB, EC2, ECS and RDS resources in two regions. Schedule RDS snapshots every 8 hours. Use RDS multi-region replication to update the secondary region's copy of the database. In the event of a failure, restore from the latest snapshot, and use an Amazon Route 53 DNS failover policy to automatically redirect customers to the ALB in the secondary region.

    Lý do sai:

    • RDS không hỗ trợ "multi-region replication" tự động cho MySQL (chỉ có multi-AZ trong region hoặc read replicas cross-region, nhưng không phải replication real-time hai chiều như mô tả). Phải dùng snapshot copy – mâu thuẫn.
    • Deploy identical resources ở hai regions → chi phí cao gấp đôi (không cost-effective). Route 53 failover nhanh nhưng phí idle lớn.
  • Phương án 2 ✅ ĐÚNG (như đã giải thích ở trên – tối ưu chi phí và SLA).

  • Phương án 3 ❌ SAI:

    Use AWS CloudFormation to deploy identical ALB, EC2, ECS, and RDS resources in a secondary region. Schedule hourly RDS MySQL backups to Amazon S3 and use cross-region replication to replicate data to a bucket in the secondary region. In the event of a failure, import the latest Docker image to Amazon ECR in the secondary region, deploy to the EC2 instance, restore the latest MySQL backup, and update the DNS record to point to the ALB in the secondary region.

    Lý do sai:

    • Deploy identical resources ở secondary → tốn kém phí idle (EC2/ECS/RDS chạy song song).
    • RDS không backup trực tiếp hourly to S3 (native là automated snapshots to S3 nội bộ; export to S3 là manual/expensive cho MySQL). "Deploy to EC2 instance" không khớp với ECS cluster.
    • Import Docker thủ công → chậm, không tự động. Hourly backup vượt RPO nhưng chi phí cao hơn cần thiết.
  • Phương án 4 ❌ SAI:

    Deploy a pilot light environment in a secondary region with an ALB and a minimal resource EC2 deployment for Docker in an AWS Auto Scaling group with a scaling policy to increase instance size and number of nodes. Create a cross-region read replica of the RDS data. In the event of a failure, promote the replica to primary, and update the DNS record to point to the ALB in the secondary region.

    Lý do sai:

    • Pilot light vẫn yêu cầu tài nguyên minimal chạy liên tục (ALB + EC2 ASG) → chi phí cao hơn Backup & Restore.
    • Cross-region read replica RDS MySQL có lag replication (có thể >8h tùy workload, không đảm bảo RPO). Promote replica nhanh nhưng setup phức tạp và phí replica.
    • ECS không được đề cập rõ (chỉ EC2), scale ASG cần thời gian >24h nếu từ minimal.

Kết luận 🎯: Phương án 2 là cost-effective nhất vì chỉ "pay-as-you-go" khi disaster, tận dụng native AWS services như CFN, RDS snapshot copy, ECR replication – phù hợp DevOps best practices 2026!

Câu 1026
A company is migrating its infrastructure to the AWS Cloud. The company must comply with a variety of regulatory standards for different projects. The company needs a multi-account environment.

A solutions architect needs to prepare the baseline infrastructure. The solution must provide a consistent baseline of management and security, but it must allow flexibility for different compliance requirements within various AWS accounts. The solution also needs to integrate with the existing on-premises Active Directory Federation Services (AD FS) server.

Which solution meets these requirements with the LEAST amount of operational overhead?
  1. A Create an organization in AWS Organizations. Create a single SCP for least privilege access across all accounts. Create a single OU for all accounts. Configure an IAM identity provider for federation with the on-premises AD FS server. Configure a central logging account with a defined process for log generating services to send log events to the central account. Enable AWS Config in the central account with conformance packs for all accounts.
  2. B Create an organization in AWS Organizations. Enable AWS Control Tower on the organization. Review included controls (guardrails) for SCPs. Check AWS Config for areas that require additions. Add OUs as necessary. Connect AWS IAM Identity Center (AWS Single Sign-On) to the on-premises AD FS server.
  3. C Create an organization in AWS Organizations. Create SCPs for least privilege access. Create an OU structure, and use it to group AWS accounts. Connect AWS IAM Identity Center (AWS Single Sign-On) to the on-premises AD FS server. Configure a central logging account with a defined process for log generating services to send log events to the central account. Enable AWS Config in the central account with aggregators and conformance packs.
  4. D Create an organization in AWS Organizations. Enable AWS Control Tower on the organization. Review included controls (guardrails) for SCPs. Check AWS Config for areas that require additions. Configure an IAM identity provider for federation with the on-premises AD FS server.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào việc thiết lập cơ sở hạ tầng baseline cho môi trường multi-account trên AWS trong quá trình di chuyển (migration) từ on-premises lên AWS Cloud. 🏢 Công ty phải tuân thủ nhiều tiêu chuẩn quy định (regulatory standards) khác nhau cho các dự án riêng biệt, nên cần môi trường multi-account để cô lập và quản lý linh hoạt.

Yêu cầu chính của giải pháp:

  • Cung cấp baseline nhất quán về quản lý và bảo mật (management and security).
  • Linh hoạt cho các yêu cầu compliance khác nhau ở từng AWS account.
  • Tích hợp với on-premises Active Directory Federation Services (AD FS) để hỗ trợ federation (xác thực liên kết).
  • Ít overhead vận hành nhất (LEAST amount of operational overhead) – nghĩa là giải pháp tự động hóa cao, dễ triển khai, giảm công sức quản lý thủ công.

Bối cảnh AWS: Sử dụng AWS Organizations làm nền tảng cho multi-account. Giải pháp cần bao gồm SCPs (Service Control Policies) cho least privilege, OUs (Organizational Units) cho phân nhóm, AWS Config cho compliance checks, và tích hợp identity federation. Theo tài liệu AWS mới nhất (2024-2026), AWS Control Tower là dịch vụ được khuyến nghị để thiết lập nhanh baseline multi-account với guardrails tự động, tích hợp AWS IAM Identity Center (trước là AWS SSO, nay là chuẩn) cho federation với AD FS. 📘 Tài liệu tham khảo: AWS Control Tower User Guide, AWS Organizations Best Practices, IAM Identity Center Federation.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create an organization in AWS Organizations. Enable AWS Control Tower on the organization. Review included controls (guardrails) for SCPs. Check AWS Config for areas that require additions. Add OUs as necessary. Connect AWS IAM Identity Center (AWS Single Sign-On) to the on-premises AD FS server.

Lý do chọn đáp án này 🛠️:

  • AWS Control Tower tự động hóa việc thiết lập baseline infrastructure với guardrails (controls) dựa trên SCPs và AWS Config, đảm bảo nhất quán quản lý/bảo mật mà ít overhead (chỉ cần enable và review/add tùy chỉnh).
  • Review guardrails cho SCPs và check AWS Config cho phép linh hoạt compliance bằng cách thêm controls phù hợp từng OU/account.
  • Add OUs as necessary hỗ trợ phân nhóm linh hoạt cho các dự án khác nhau.
  • Connect AWS IAM Identity Center (chuẩn mới nhất từ 2023+) là cách tích hợp AD FS hiệu quả nhất, hỗ trợ SSO/federation toàn tổ chức, thay thế IAM IdP thủ công (deprecated dần).
  • Least overhead: Control Tower landing zone tự động hóa 80-90% setup (theo AWS Well-Architected), giảm manual config so với các option khác. ✅ Hoàn hảo khớp yêu cầu!

📋 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn. Tôi giữ nguyên văn bản gốc tiếng Anh của phương án, đánh dấu ✅ Đúng hoặc ❌ Sai, và giải thích bằng tiếng Việt với lý do cụ thể dựa trên best practices AWS 2026. 🧐

  • Phương án 1: Create an organization in AWS Organizations. Create a single SCP for least privilege access across all accounts. Create a single OU for all accounts. Configure an IAM identity provider for federation with the on-premises AD FS server. Configure a central logging account with a defined process for log generating services to send log events to the central account. Enable AWS Config in the central account with conformance packs for all accounts.
    ❌ Sai vì:

    • Single SCP và single OU thiếu linh hoạt cho "different compliance requirements" (không phân nhóm account theo dự án).
    • IAM identity provider là cách cũ, thủ công cao overhead; không scale tốt cho multi-account so với IAM Identity Center.
    • Central logging + Config thủ công tăng operational overhead lớn (phải define process, setup conformance packs manual). Không dùng Control Tower nên không tự động hóa baseline. 🛠️ Overhead cao!
  • Phương án 2 (Đúng - đã giải thích ở trên): ✅ Hoàn chỉnh, tự động hóa cao với Control Tower + IAM Identity Center. Ít overhead nhất!

  • Phương án 3: Create an organization in AWS Organizations. Create SCPs for least privilege access. Create an OU structure, and use it to group AWS accounts. Connect AWS IAM Identity Center (AWS Single Sign-On) to the on-premises AD FS server. Configure a central logging account with a defined process for log generating services to send log events to the central account. Enable AWS Config in the central account with aggregators and conformance packs.
    ❌ Sai vì:

    • Create SCPs và OU structure thủ công + central logging/Config aggregators/conformance packs đòi hỏi overhead vận hành cao (setup process, monitoring manual).
    • Mặc dù dùng IAM Identity Center tốt cho federation, nhưng thiếu AWS Control Tower nên không có guardrails tự động, baseline không nhất quán. AWS khuyến nghị Control Tower cho multi-account compliance để giảm 50% effort. 📘 Không phải "LEAST overhead".
  • Phương án 4: Create an organization in AWS Organizations. Enable AWS Control Tower on the organization. Review included controls (guardrails) for SCPs. Check AWS Config for areas that require additions. Configure an IAM identity provider for federation with the on-premises AD FS server.
    ❌ Sai vì:

    • Control Tower tốt cho baseline/guardrails linh hoạt, nhưng IAM identity provider thay vì IAM Identity Center là sai lầm lớn: IAM IdP chỉ per-account/role, không centralized cho toàn tổ chức; overhead cao khi scale multi-account và không tích hợp mượt với Control Tower.
    • Thiếu đề cập OUs rõ ràng (dù Control Tower hỗ trợ), nhưng federation sai làm giải pháp không hoàn chỉnh. AWS docs 2026 ưu tiên IAM Identity Center cho AD FS in Control Tower setups. 🔒 Không khớp yêu cầu tích hợp!

Kết luận 🎯: AWS Control Tower + IAM Identity Center là best practice cho multi-account với compliance linh hoạt và federation, giảm overhead tối đa. Nếu triển khai thực tế, bắt đầu từ AWS Landing Zone Accelerator! 🚀

Câu 1027 Chọn nhiều đáp án
An online magazine will launch its latest edition this month. This edition will be the first to be distributed globally. The magazine's dynamic website currently uses an Application Load Balancer in front of the web tier, a fleet of Amazon EC2 instances for web and application servers, and Amazon Aurora MySQL. Portions of the website include static content and almost all traffic is read-only.

The magazine is expecting a significant spike in internet traffic when the new edition is launched. Optimal performance is a top priority for the week following the launch.

Which combination of steps should a solutions architect take to reduce system response times for a global audience? (Choose two.)
  1. A Use logical cross-Region replication to replicate the Aurora MySQL database to a secondary Region. Replace the web servers with Amazon S3. Deploy S3 buckets in cross-Region replication mode.
  2. B Ensure the web and application tiers are each in Auto Scaling groups. Introduce an AWS Direct Connect connection. Deploy the web and application tiers in Regions across the world.
  3. C Migrate the database from Amazon Aurora to Amazon RDS for MySQL. Ensure all three of the application tiers – web, application, and database – are in private subnets.
  4. D Use an Aurora global database for physical cross-Region replication. Use Amazon S3 with cross-Region replication for static content and resources. Deploy the web and application tiers in Regions across the world.
  5. E Introduce Amazon Route 53 with latency-based routing and Amazon CloudFront distributions. Ensure the web and application tiers are each in Auto Scaling groups.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một trang web tạp chí trực tuyến sắp ra mắt phiên bản mới phân phối toàn cầu, với lưu lượng truy cập dự kiến tăng đột biến (spike traffic) trong tuần đầu tiên sau launch. Hệ thống hiện tại bao gồm:

  • Application Load Balancer (ALB) trước lớp web tier.
  • Fleet Amazon EC2 cho web servers và application servers.
  • Amazon Aurora MySQL làm database.
  • Phần lớn nội dung là static content (tĩnh), và gần như toàn bộ traffic là read-only (chỉ đọc).

Mục tiêu chính: Giảm thời gian phản hồi hệ thống (response times) cho khán giả toàn cầu, ưu tiên hiệu suất tối ưu trong giai đoạn cao điểm. Cần chọn TWO bước kết hợp từ solutions architect để đạt được điều này, tận dụng kiến trúc AWS mới nhất (tính đến 2026, với Aurora Global Database hỗ trợ physical replication tốc độ cao, CloudFront với global edge locations, và Route 53 latency-based routing nâng cao).

🛠️ Yêu cầu cốt lõi: Giải pháp phải xử lý global latency thấp (độ trễ thấp toàn cầu), scale tự động, tách static/dynamic content, và read-heavy workload mà không làm gián đoạn hệ thống hiện tại.

✅ Đáp án đúng (Chọn TWO)

Các đáp án đúng là:

  • Use an Aurora global database for physical cross-Region replication. Use Amazon S3 with cross-Region replication for static content and resources. Deploy the web and application tiers in Regions across the world.
  • Introduce Amazon Route 53 with latency-based routing and Amazon CloudFront distributions. Ensure the web and application tiers are each in Auto Scaling groups.

Lý do lựa chọn: 🧩 Hai bước này kết hợp hoàn hảo để giảm latency toàn cầu: Aurora Global DB cung cấp physical replication nhanh (sub-second lag) cho read traffic từ secondary regions; S3 CRR + multi-region EC2 xử lý static/dynamic content phân tán; Route 53 latency routing + CloudFront (caching tại 400+ edge locations toàn cầu) route traffic đến nearest endpoint; ASG đảm bảo scale auto cho spike. Tổng thể tối ưu performance read-only, static-heavy workload mà không cần thay đổi lớn.

📋 Phân tích chi tiết từng phương án

Dưới đây là phân tích tất cả 5 phương án, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá ✅ (đúng) hoặc ❌ (sai), với giải thích đầy đủ bằng tiếng Việt dựa trên best practices AWS 2026.

  • Use logical cross-Region replication to replicate the Aurora MySQL database to a secondary Region. Replace the web servers with Amazon S3. Deploy S3 buckets in cross-Region replication mode.
    ❌ Sai vì: Logical replication (dựa binlog) của Aurora chậm hơn physical replication (lag cao hơn, không phù hợp read-heavy spike). Web servers xử lý dynamic content (không chỉ static), thay bằng S3 sẽ phá vỡ app logic. S3 CRR chỉ tốt cho static, nhưng không giải quyết full global dynamic traffic. Không scale web/app tier đúng cách.

  • Ensure the web and application tiers are each in Auto Scaling groups. Introduce an AWS Direct Connect connection. Deploy the web and application tiers in Regions across the world.
    ❌ Sai vì: ASG tốt cho auto-scale, multi-region deploy hợp lý, nhưng Direct Connect là kết nối dedicated private (dành enterprise internal), không giúp public internet traffic của website toàn cầu (tăng latency cho end-users). Thiếu routing thông minh (như Route 53) và CDN để giảm global latency.

  • Migrate the database from Amazon Aurora to Amazon RDS for MySQL. Ensure all three of the application tiers – web, application, and database – are in private subnets.
    ❌ Sai vì: Migrate sang RDS kém hơn Aurora về performance/scale (Aurora nhanh hơn 5x cho read replicas, serverless options tốt hơn đến 2026). Private subnets chỉ tăng security (không expose public), không giảm latency toàn cầu hay xử lý spike traffic. Không liên quan trực tiếp đến global audience.

  • Use an Aurora global database for physical cross-Region replication. Use Amazon S3 with cross-Region replication for static content and resources. Deploy the web and application tiers in Regions across the world.
    ✅ Đúng vì: Aurora Global Database (ra mắt 2018, cập nhật 2026 hỗ trợ multi-Region clusters với physical replication <1s lag) lý tưởng cho read-only traffic. S3 CRR sync static content nhanh toàn cầu. Multi-region EC2 phân tán workload dynamic, giảm latency cho audience quốc tế – phù hợp spike performance.

  • Introduce Amazon Route 53 with latency-based routing and Amazon CloudFront distributions. Ensure the web and application tiers are each in Auto Scaling groups.
    ✅ Đúng vì: Route 53 latency-based routing tự động hướng traffic đến Region gần nhất (dựa real-time latency). CloudFront (400+ POPs toàn cầu, caching static/dynamic) giảm response time 50-70% cho static/read-heavy. ASG scale EC2 theo demand – combo hoàn hảo cho global spike mà không cần multi-region phức tạp ngay.

📘 Tài liệu tham khảo (AWS Docs cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm ví dụ thực tế, hãy hỏi nhé.

Câu 1028
An online gaming company needs to optimize the cost of its workloads on AWS. The company uses a dedicated account to host the production environment for its online gaming application and an analytics application.

Amazon EC2 instances host the gaming application and must always be available. The EC2 instances run all year. The analytics application uses data that is stored in Amazon S3. The analytics application can be interrupted and resumed without issue.

Which solution will meet these requirements MOST cost-effectively?
  1. A Purchase an EC2 Instance Savings Plan for the online gaming application instances. Use On-Demand Instances for the analytics application.
  2. B Purchase an EC2 Instance Savings Plan for the online gaming application instances. Use Spot Instances for the analytics application.
  3. C Use Spot Instances for the online gaming application and the analytics application. Set up a catalog in AWS Service Catalog to provision services at a discount.
  4. D Use On-Demand Instances for the online gaming application. Use Spot Instances for the analytics application. Set up a catalog in AWS Service Catalog to provision services at a discount.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm AWS

✅ Giải thích nội dung câu hỏi:
Câu hỏi xoay quanh việc tối ưu hóa chi phí (cost optimization) cho workload của một công ty game online trên AWS. Họ sử dụng tài khoản riêng cho môi trường production, bao gồm:

  • Ứng dụng gaming: Chạy trên Amazon EC2 instances, luôn phải sẵn sàng (always available) và chạy suốt năm (baseline ổn định, không gián đoạn được).
  • Ứng dụng analytics: Sử dụng dữ liệu từ Amazon S3, có thể bị gián đoạn và resume lại mà không ảnh hưởng lớn (fault-tolerant, workload không critical real-time).

Mục tiêu: Chọn giải pháp tiết kiệm chi phí nhất (MOST cost-effectively), tận dụng các mô hình giá AWS như Savings Plans, Spot Instances, On-Demand để phù hợp với đặc tính từng workload. Đây là chủ đề cốt lõi trong AWS Well-Architected Framework - Pillar Cost Optimization (cập nhật 2024-2026), nhấn mạnh việc phân loại workload steady-state vs. flexible để áp dụng discount phù hợp.

🎯 Đáp án đúng: Phương án thứ 2
Purchase an EC2 Instance Savings Plan for the online gaming application instances. Use Spot Instances for the analytics application.

Lý do lựa chọn (chi tiết):
🛠️ Giải pháp này tối ưu nhất vì:

  • Gaming app (steady, always-on): EC2 Instance Savings Plan cam kết giờ sử dụng cố định (1-3 năm), tiết kiệm lên đến 72% so với On-Demand, linh hoạt chuyển instance family/type/region/OS (Compute Savings Plans còn linh hoạt hơn nhưng Instance Savings Plan phù hợp EC2 cụ thể). Phù hợp workload chạy 100% năm.
  • Analytics app (interruptible): Spot Instances tiết kiệm đến 90% so On-Demand, lý tưởng cho batch processing từ S3 (dùng Spot Fleet hoặc EC2 Auto Scaling với Spot để handle interruptions).
    Kết hợp hai mô hình này đạt discount tối đa mà vẫn đảm bảo HA cho gaming. Không cần tool thừa như Service Catalog.

📘 Tài liệu tham khảo:

  • AWS Savings Plans (cập nhật 2025: Instance Savings Plans hỗ trợ Graviton4).
  • Amazon EC2 Spot Instances (2026: Tích hợp tốt hơn với ECS/EKS).
  • AWS Well-Architected: Cost Optimization Pillar (v2.1, 2024).

🔍 Phân tích tất cả các phương án (đúng/sai)

  • Phương án 1 (SAI):
    Purchase an EC2 Instance Savings Plan for the online gaming application instances. Use On-Demand Instances for the analytics application.
    ❌ Sai vì: Tuy gaming dùng Savings Plan tốt (tiết kiệm 72%), nhưng analytics dùng On-Demand là đắt đỏ nhất (không tận dụng interruptible nature). Analytics có thể dùng Spot để tiết kiệm thêm 90%, nên giải pháp này chưa MOST cost-effective.

  • Phương án 2 (ĐÚNG):
    Purchase an EC2 Instance Savings Plan for the online gaming application instances. Use Spot Instances for the analytics application.
    ✅ Đúng vì: Như giải thích ở trên, kết hợp hoàn hảo steady workload (Savings Plan) + flexible workload (Spot), đạt chi phí thấp nhất mà đáp ứng yêu cầu always-available cho gaming và fault-tolerant cho analytics. Linh hoạt, scalable.

  • Phương án 3 (SAI):
    Use Spot Instances for the online gaming application and the analytics application. Set up a catalog in AWS Service Catalog to provision services at a discount.
    ❌ Sai vì: Spot Instances không phù hợp gaming (có thể bị interrupt bất cứ lúc nào, vi phạm "always available"). AWS Service Catalog chỉ quản lý provisioning template (không tạo discount trực tiếp, chỉ gián tiếp qua governance). Giải pháp rủi ro cao và không tiết kiệm thực sự cho gaming.

  • Phương án 4 (SAI):
    Use On-Demand Instances for the online gaming application. Use Spot Instances for the analytics application. Set up a catalog in AWS Service Catalog to provision services at a discount.
    ❌ Sai vì: Analytics dùng Spot tốt (90% off), nhưng gaming dùng On-Demand là chi phí cao nhất (không commitment discount như Savings Plan). Service Catalog thừa thãi, không mang discount trực tiếp (chỉ standardize provisioning). Không tối ưu cho gaming chạy cả năm.

💡 Lời khuyên DevOps: Để implement, dùng AWS Cost Explorer dự báo savings, Compute Optimizer recommend instance, và Spot Advisor cho coverage. Theo dõi qua AWS Budgets! 🚀

Câu 1029 Chọn nhiều đáp án
A company runs applications in hundreds of production AWS accounts. The company uses AWS Organizations with all features enabled and has a centralized backup operation that uses AWS Backup.

The company is concerned about ransomware attacks. To address this concern, the company has created a new policy that all backups must be resilient to breaches of privileged-user credentials in any production account.

Which combination of steps will meet this new requirement? (Choose three.)
  1. A Implement cross-account backup with AWS Backup vaults in designated non-production accounts.
  2. B Add an SCP that restricts the modification of AWS Backup vaults.
  3. C Implement AWS Backup Vault Lock in compliance mode.
    C. Implement least privilege access for the IAM service role that is assigned to AWS Backup.
  4. D Configure the backup frequency, lifecycle, and retention period to ensure that at least one backup always exists in the cold tier.
  5. E Configure AWS Backup to write all backups to an Amazon S3 bucket in a designated non-production account. Ensure that the S3 bucket has S3 Object Lock enabled.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

📖 Tóm tắt câu hỏi:
Một công ty đang vận hành ứng dụng trên hàng trăm tài khoản AWS production (sản xuất). Họ sử dụng AWS Organizations với all features enabled (bao gồm cả delegated administration và SCP - Service Control Policies), và có hoạt động sao lưu tập trung sử dụng AWS Backup.

Công ty lo ngại về tấn công ransomware (mã độc tống tiền), dẫn đến chính sách mới: Tất cả các bản sao lưu (backups) phải kiên cường (resilient) trước các vụ breach (xâm phạm) thông tin xác thực của người dùng privileged (quyền cao) trong bất kỳ tài khoản production nào.

Nghĩa là: Ngay cả khi tài khoản production bị hack bởi admin privileged (có quyền cao nhất), kẻ tấn công KHÔNG THỂ xóa, sửa đổi hoặc làm hỏng backups. Yêu cầu chọn 3 bước kết hợp để đáp ứng.

🎯 Mục tiêu chính: Bảo vệ backups khỏi rủi ro nội bộ/ngoại bộ ở production accounts bằng cách sử dụng các tính năng AWS như cross-account, SCP, và Vault Lock (kiến thức cập nhật đến 2026: AWS Backup hỗ trợ Vault Lock ở compliance mode với WORM - Write Once Read Many, và cross-account đầy đủ qua Organizations).

✅ Đáp án đúng (Chọn 3):

Các bước đúng là:

  1. Implement cross-account backup with AWS Backup vaults in designated non-production accounts.
  2. Add an SCP that restricts the modification of AWS Backup vaults.
  3. Implement AWS Backup Vault Lock in compliance mode.

Lý do lựa chọn (kết hợp 3 bước này):
🛡️ Bước 1 di chuyển vaults ra ngoài production accounts (vào non-production), ngăn privileged users ở production truy cập/xóa.
🔒 Bước 2 dùng SCP (từ Organizations) chặn toàn bộ member accounts sửa vaults ở mức org-wide.
⚙️ Bước 3 kích hoạt Vault Lock ở compliance mode (không thể xóa khóa ngay cả owner, chỉ đọc sau lock period).
Kết hợp: Tạo lớp bảo vệ đa tầng, resilient hoàn toàn với breach privileged credentials. Không bước nào đơn lẻ đủ, nhưng 3 này meet yêu cầu chính xác (theo best practices AWS 2026).

📋 Giải thích tất cả các phương án

  • Implement cross-account backup with AWS Backup vaults in designated non-production accounts.
    ✅ Đúng. Di chuyển vaults sang non-production accounts (qua AWS Backup cross-account sharing trong Organizations). Privileged users ở production không thể truy cập vaults này, ngăn xóa backups dù breach. (Cập nhật 2026: Hỗ trợ delegated admin cho Backup plans cross-OU).

  • Add an SCP that restricts the modification of AWS Backup vaults.
    ✅ Đúng. SCP (Service Control Policy) ở root OU chặn actions như backup:DeleteBackupVault, backup:UpdateBackupVault cho tất cả member accounts. Ngăn modify từ production dù privileged creds bị breach. (SCP deny rules áp dụng org-wide, không override bởi IAM).

  • Implement AWS Backup Vault Lock in compliance mode.
    ✅ Đúng. Vault Lock ở compliance mode áp dụng chính sách WORM (không xóa/sửa trong retention period, cần chờ unlock sau). Ngay cả root user không bypass được, lý tưởng chống ransomware. (Governance mode yếu hơn, chỉ compliance mới resilient tuyệt đối - AWS update 2023+).

  • C. Implement least privilege access for the IAM service role that is assigned to AWS Backup.
    ❌ Sai. Least privilege IAM role chỉ giảm rủi ro access thông thường, nhưng không resilient với breach privileged creds (root/admin có thể assume/edit role). Không ngăn xóa vaults trực tiếp từ console/CLI.

  • Configure the backup frequency, lifecycle, and retention period to ensure that at least one backup always exists in the cold tier.
    ❌ Sai. Lifecycle/move to cold tier (S3 Glacier) chỉ tối ưu chi phí/phục hồi, không ngăn delete/modify vaults. Ransomware vẫn xóa tất cả nếu có quyền.

  • Configure AWS Backup to write all backups to an Amazon S3 bucket in a designated non-production account. Ensure that the S3 bucket has S3 Object Lock enabled.
    ❌ Sai. AWS Backup KHÔNG write trực tiếp vào S3 buckets thông thường; backups lưu trong Backup Vaults (logical containers). S3 Object Lock chỉ áp dụng S3 objects, không tương thích trực tiếp với Backup workflows cross-account. Dùng Vault Lock thay thế.

📘 Tài liệu tham khảo (AWS cập nhật mới nhất 2026)

Hy vọng phân tích giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ code SCP, hỏi nhé!

Câu 1030 Chọn nhiều đáp án
A company needs to aggregate Amazon CloudWatch logs from its AWS accounts into one central logging account. The collected logs must remain in the AWS Region of creation. The central logging account will then process the logs, normalize the logs into standard output format, and stream the output logs to a security tool for more processing.

A solutions architect must design a solution that can handle a large volume of logging data that needs to be ingested. Less logging will occur outside normal business hours than during normal business hours. The logging solution must scale with the anticipated load. The solutions architect has decided to use an AWS Control Tower design to handle the multi-account logging process.

Which combination of steps should the solutions architect take to meet the requirements? (Choose three.)
  1. A Create a destination Amazon Kinesis data stream in the central logging account.
  2. B Create a destination Amazon Simple Queue Service (Amazon SQS) queue in the central logging account.
  3. C Create an IAM role that grants Amazon CloudWatch Logs the permission to add data to the Amazon Kinesis data stream. Create a trust policy. Specify the trust policy in the IAM role. In each member account, create a subscription filter for each log group to send data to the Kinesis data stream.
  4. D Create an IAM role that grants Amazon CloudWatch Logs the permission to add data to the Amazon Simple Queue Service (Amazon SQS) queue. Create a trust policy. Specify the trust policy in the IAM role. In each member account, create a single subscription filter for all log groups to send data to the SQS queue.
  5. E Create an AWS Lambda function. Program the Lambda function to normalize the logs in the central logging account and to write the logs to the security tool.
  6. F Create an AWS Lambda function. Program the Lambda function to normalize the logs in the member accounts and to write the logs to the security tool.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi này thuộc chủ đề AWS multi-account logging với Amazon CloudWatch Logs, tập trung vào việc thiết kế giải pháp tổng hợp logs từ nhiều AWS accounts (member accounts) vào một central logging account bằng AWS Control Tower.

🔍 Yêu cầu chính:

  • Logs phải giữ nguyên AWS Region nơi được tạo (không cross-region).
  • Xử lý logs lớn: ingest volume cao (đỉnh vào giờ làm việc, thấp hơn ngoài giờ), cần scale tự động.
  • Central account sẽ normalize logs thành format chuẩn và stream đến security tool.
  • Sử dụng AWS Control Tower để quản lý multi-account (landing zone, guardrails).

🛠️ Giải pháp cốt lõi: Sử dụng CloudWatch Logs subscription filters để stream logs real-time từ member accounts đến destination ở central account. Destination phù hợp là Amazon Kinesis Data Stream (scale tốt cho high-throughput, fan-out). IAM role cross-account cho phép push data. Lambda ở central để process.

📊 Tại sao cần chọn 3 steps? Đây là câu hỏi chọn 3 (combination of steps), dựa trên best practice AWS cho centralized logging với Control Tower (Log Archive blueprint hỗ trợ tương tự).

✅ Đáp án đúng (Chọn 3 phương án sau)

Các đáp án đúng là sự kết hợp hoàn hảo để xây dựng pipeline logging cross-account, scale với volume lớn:

  1. Create a destination Amazon Kinesis data stream in the central logging account.
  2. Create an IAM role that grants Amazon CloudWatch Logs the permission to add data to the Amazon Kinesis data stream. Create a trust policy. Specify the trust policy in the IAM role. In each member account, create a subscription filter for each log group to send data to the Kinesis data stream.
  3. Create an AWS Lambda function. Program the Lambda function to normalize the logs in the central logging account and to write the logs to the security tool.

Lý do lựa chọn 📘:

  • Kinesis Data Stream là destination lý tưởng cho high-volume streaming (scale shards tự động, handle peaks giờ làm việc).
  • IAM role + trust policy + subscription filter per log group đảm bảo cross-account delivery an toàn (CloudWatch Logs service principal trust).
  • Lambda ở central account consume từ Kinesis, normalize và forward – tận dụng aggregation point, scale theo concurrent executions.
  • Toàn bộ giữ nguyên region, phù hợp Control Tower (2024-2026 updates vẫn giữ pattern này, với enhanced fan-out cho Kinesis).

🔍 Giải thích tất cả các phương án (Đúng/Sai)

✅ Create a destination Amazon Kinesis data stream in the central logging account.
🟢 Đúng: Đây là destination chính cho CloudWatch Logs subscription filters trong multi-account setup. Kinesis scale shard-based (auto-scale với volume peaks), hỗ trợ fan-out đến nhiều consumer (như Lambda). Phù hợp "large volume" và "scale with load". (Không dùng SQS vì không hỗ trợ streaming logs hiệu quả).

❌ Create a destination Amazon Simple Queue Service (Amazon SQS) queue in the central logging account.
🔴 Sai: CloudWatch Logs subscription filters không hỗ trợ SQS trực tiếp làm destination (chỉ Kinesis Stream/Data Firehose/Lambda/partner). SQS là queue-based, không optimize cho streaming high-throughput logs real-time như Kinesis. Sẽ fail ingestion lớn.

✅ Create an IAM role that grants Amazon CloudWatch Logs the permission to add data to the Amazon Kinesis data stream. Create a trust policy. Specify the trust policy in the IAM role. In each member account, create a subscription filter for each log group to send data to the Kinesis data stream.
🟢 Đúng: IAM role ở central account với policy PutRecord/PutRecords trên Kinesis, trust policy cho principal "logs.region.amazonaws.com" (cross-account từ member). Subscription filter per log group ở member accounts stream filtered logs đến ARN của destination + role. Best practice cho Control Tower multi-account logging (per-group để granular control).

❌ Create an IAM role that grants Amazon CloudWatch Logs the permission to add data to the Amazon Simple Queue Service (Amazon SQS) queue. Create a trust policy. Specify the trust policy in the IAM role. In each member account, create a single subscription filter for all log groups to send data to the SQS queue.
🔴 Sai:

  • Subscription không hỗ trợ SQS.
  • Single filter cho all log groups không khả thi (mỗi log group cần filter riêng để stream).
  • SQS không phù hợp scale streaming logs (FIFO/DLQ issues với volume lớn).

✅ Create an AWS Lambda function. Program the Lambda function to normalize the logs in the central logging account and to write the logs to the security tool.
🟢 Đúng: Lambda event source từ Kinesis (central account), scale auto với concurrent (provisioned/increased limits 2025+), process/normalize batch logs rồi stream đến security tool (API/another stream). Giữ aggregation ở central, tránh duplicate work ở member accounts.

❌ Create an AWS Lambda function. Program the Lambda function to normalize the logs in the member accounts and to write the logs to the security tool.
🔴 Sai: Normalize ở member accounts vi phạm yêu cầu "central logging account will process" và aggregate logs trước. Tạo duplicate Lambda (không scale multi-account), tăng cost/complexity. Lambda subscription trực tiếp chỉ cho single-account, không centralize.

📘 Tài liệu tham khảo (Cập nhật AWS 2026)

💡 Lưu ý: Giải pháp này cost-effective (pay-per-use Kinesis/Lambda), secure (least-privilege IAM), và resilient (Kinesis retries). Nếu volume cực lớn, cân nhắc Kinesis Data Firehose thay stream (2026 preview).