Ngân hàng đề — AWS Certified Solutions Architect Professional

Tìm thấy 1221 câu.

Câu 771
Example Corp. has an on-premises data center and a VPC named VPC A in the Example Corp. AWS account. The on-premises network connects to VPC A through an AWS Site-To-Site VPN. The on-premises servers can properly access VPC A. Example Corp. just acquired AnyCompany, which has a VPC named VPC B. There is no IP address overlap among these networks. Example Corp. has peered VPC A and VPC B.

Example Corp. wants to connect from its on-premise servers to VPC B. Example Corp. has properly set up the network ACL and security groups.

Which solution will meet this requirement with the LEAST operational effort?
  1. A Create a transit gateway. Attach the Site-to-Site VPN, VPC A, and VPC B to the transit gateway. Update the transit gateway route tables for all networks to add IP range routes for all other networks.
  2. B Create a transit gateway. Create a Site-to-Site VPN connection between the on-premises network and VPC B, and connect the VPN connection to the transit gateway. Add a route to direct traffic to the peered VPCs, and add an authorization rule to give clients access to the VPCs A and B.
  3. C Update the route tables for the Site-to-Site VPN and both VPCs for all three networks. Configure BGP propagation for all three networks. Wait for up to 5 minutes for BGP propagation to finish.
  4. D Modify the Site-to-Site VPN’s virtual private gateway definition to include VPC A and VPC B. Split the two routers of the virtual private getaway between the two VPCs.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả tình huống thực tế của Example Corp.:

  • Họ có data center on-premises kết nối với VPC A (trong tài khoản AWS của Example Corp.) qua AWS Site-to-Site VPN. Kết nối này hoạt động tốt (on-premises servers truy cập được VPC A).
  • Example Corp. vừa mua lại AnyCompany, sở hữu VPC B. Không có overlap IP giữa on-premises, VPC A và VPC B.
  • VPC A và VPC B đã được peering (VPC Peering).
  • Mục tiêu: Cho phép on-premises servers truy cập VPC B, với các Network ACL và Security Groups đã được cấu hình đúng.
  • Yêu cầu chính: Giải pháp với LEAST operational effort (ít nỗ lực vận hành nhất), nghĩa là đơn giản, dễ scale, ít config thủ công và quản lý lâu dài.

🛠️ Vấn đề cốt lõi: VPC Peering không transitive (không tự động lan tỏa route qua nhiều hop). On-premises chỉ route đến VPC A qua VPN, chưa tự động đến VPC B dù đã peering A-B. Cần giải pháp kết nối hub-and-spoke hiệu quả cho on-premises + nhiều VPCs.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create a transit gateway. Attach the Site-to-Site VPN, VPC A, and VPC B to the transit gateway. Update the transit gateway route tables for all networks to add IP range routes for all other networks.

Lý do:

  • Transit Gateway (TGW) là giải pháp hub-and-spoke native của AWS, lý tưởng cho kết nối on-premises + multiple VPCs với least effort. Chỉ cần attach VPN attachment, VPC A và VPC B vào TGW (1 lệnh attach/VPC), sau đó update route tables TGW (một nơi tập trung, hỗ trợ static/propagation).
  • Không cần thay đổi peering hiện có, tận dụng VPN sẵn. Scale tự động, dễ quản lý (up to 1M routes/TGW RT), tránh config thủ công từng route table VPC/VPN.
  • Least effort: Ít bước nhất (3 attachments + vài route entries), giảm operational overhead so với peering thủ công hoặc multi-VPN. Phù hợp kiến trúc enterprise 2026 với TGW Policy Tables mới.

📋 Giải thích tất cả các phương án (đúng/sai)

  • ✅ Create a transit gateway. Attach the Site-to-Site VPN, VPC A, and VPC B to the transit gateway. Update the transit gateway route tables for all networks to add IP range routes for all other networks.
    Đúng vì: Như phân tích trên, TGW đơn giản hóa routing transitive cho tất cả (on-prem ↔ VPC A ↔ VPC B). Chỉ config một TGW route table thay vì nhiều nơi. Effort thấp, scale cao (hỗ trợ BGP auto-propagation nếu cần).

  • ❌ Create a transit gateway. Create a Site-to-Site VPN connection between the on-premises network and VPC B, and connect the VPN connection to the transit gateway. Add a route to direct traffic to the peered VPCs, and add an authorization rule to give clients access to the VPCs A and B.
    Sai vì: Tạo VPN thứ 2 đến VPC B là thừa thãi, tăng effort (config thêm VPN, customer gateway, BGP peering). TGW không yêu cầu VPN riêng cho VPC B (chỉ cần VPC attachment). "Authorization rule" không tồn tại trong TGW context (có lẽ nhầm với RAM sharing). Phức tạp hơn đáp án đúng.

  • ❌ Update the route tables for the Site-to-Site VPN and both VPCs for all three networks. Configure BGP propagation for all three networks. Wait for up to 5 minutes for BGP propagation to finish.
    Sai vì: VPC Peering không transitive, nên update route table VPN/VPC A để point CIDR VPC B qua peering connection là có thể, nhưng phải thủ công từng route table (VPN VGW RT + VPC A RT + VPC B RT). BGP chỉ dynamic cho VPN, không áp dụng peering (peering dùng static routes). Effort cao, khó scale nếu thêm VPCs, không "least effort". Thời gian BGP 5 phút không liên quan peering.

  • ❌ Modify the Site-to-Site VPN’s virtual private gateway definition to include VPC A and VPC B. Split the two routers of the virtual private getaway between the two VPCs.
    Sai vì: Virtual Private Gateway (VGW) gắn chỉ 1 VPC (không modify để include multiple VPCs). Không có khái niệm "split routers" (VGW có 2 tunnels cho HA, không chia VPC). Sai kiến trúc cơ bản, không khả thi theo AWS (2026 vẫn vậy). Effort vô ích vì phá cấu hình hiện có.

Câu 772
A company recently completed the migration from an on-premises data center to the AWS Cloud by using a replatforming strategy. One of the migrated servers is running a legacy Simple Mail Transfer Protocol (SMTP) service that a critical application relies upon. The application sends outbound email messages to the company’s customers. The legacy SMTP server does not support TLS encryption and uses TCP port 25. The application can use SMTP only.

The company decides to use Amazon Simple Email Service (Amazon SES) and to decommission the legacy SMTP server. The company has created and validated the SES domain. The company has lifted the SES limits.

What should the company do to modify the application to send email messages from Amazon SES?
  1. A Configure the application to connect to Amazon SES by using TLS Wrapper. Create an IAM role that has ses:SendEmail and ses:SendRawEmail permissions. Attach the IAM role to an Amazon EC2 instance.
  2. B Configure the application to connect to Amazon SES by using STARTTLS. Obtain Amazon SES SMTP credentials. Use the credentials to authenticate with Amazon SES.
  3. C Configure the application to use the SES API to send email messages. Create an IAM role that has ses:SendEmail and ses:SendRawEmail permissions. Use the IAM role as a service role for Amazon SES.
  4. D Configure the application to use AWS SDKs to send email messages. Create an IAM user for Amazon SES. Generate API access keys. Use the access keys to authenticate with Amazon SES.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi này xoay quanh tình huống một công ty đã migrate máy chủ từ on-premises sang AWS bằng chiến lược replatforming (tái nền tảng hóa, tức là di chuyển và điều chỉnh nhẹ ứng dụng để chạy trên cloud). Trong số các máy chủ được migrate, có một máy chủ legacy SMTP (giao thức Simple Mail Transfer Protocol cũ kỹ) mà một ứng dụng quan trọng phụ thuộc vào để gửi email outbound đến khách hàng. Đặc điểm của máy chủ này:

  • Không hỗ trợ TLS encryption (không mã hóa TLS).
  • Sử dụng TCP port 25.
  • Ứng dụng chỉ có thể sử dụng SMTP (không hỗ trợ API hoặc SDK khác).

Công ty quyết định chuyển sang Amazon Simple Email Service (Amazon SES) để gửi email, đã verify domain SES và lift limits (nâng giới hạn gửi email). Nhiệm vụ là modify ứng dụng để kết nối với SES qua SMTP, đồng thời decommission (tháo dỡ) máy chủ legacy.

🛠️ Thách thức chính: Ứng dụng legacy chỉ dùng SMTP cơ bản (port 25, không TLS), nhưng SES yêu cầu xác thực an toàn qua SMTP với STARTTLS (port 587 khuyến nghị) hoặc TLS (port 465). Không thể dùng port 25 trực tiếp vì AWS chặn port 25 outbound từ EC2 để chống spam (trừ khi request EC2 Port 25 Throttle). Giải pháp phải tương thích với ứng dụng chỉ dùng SMTP.

📘 Kiến thức AWS SES cập nhật 2026: SES hỗ trợ SMTP interface với credentials riêng (username/password từ SES console), sử dụng STARTTLS để nâng cấp kết nối an toàn. Không cần IAM role/user cho SMTP thuần (chỉ cho API). Tài liệu chính: AWS SES SMTP Documentation và SES SMTP Credentials.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Configure the application to connect to Amazon SES by using STARTTLS. Obtain Amazon SES SMTP credentials. Use the credentials to authenticate with Amazon SES.

Lý do:

  • Ứng dụng chỉ dùng SMTP, nên SES cung cấp SMTP interface chính thức với STARTTLS (port 587) để mã hóa sau khi kết nối ban đầu – phù hợp hoàn hảo với legacy app không hỗ trợ TLS native nhưng có thể nâng cấp qua STARTTLS.
  • SMTP credentials (tạo từ SES console: username là email verified, password là key 57 ký tự) dùng để authenticate trực tiếp, không cần IAM.
  • Điều này cho phép decommission legacy server ngay lập tức, vì app chỉ cần thay endpoint SES SMTP (smtp.email..amazonaws.com:587).
  • ✅ Tối ưu, an toàn và tuân thủ best practice AWS (không dùng port 25, tránh throttle).

🔍 Giải thích tất cả các phương án (A, B, C, D)

Dưới đây là phân tích chi tiết từng lựa chọn. Tôi giữ nguyên văn bản gốc tiếng Anh của phương án, đánh dấu ✅ (đúng) hoặc ❌ (sai), và giải thích hoàn toàn bằng tiếng Việt.

  • Phương án A: Configure the application to connect to Amazon SES by using TLS Wrapper. Create an IAM role that has ses:SendEmail and ses:SendRawEmail permissions. Attach the IAM role to an Amazon EC2 instance.
    ❌ Sai vì: TLS Wrapper (như stunnel) là workaround không chính thức, phức tạp hóa việc config cho app legacy chỉ dùng SMTP plain. IAM role với ses:SendEmail/ses:SendRawEmail chỉ dùng cho API calls (không phải SMTP), nên attach vào EC2 vô ích cho SMTP auth. Không phải cách AWS recommend cho SMTP thuần.

  • Phương án B: Configure the application to connect to Amazon SES by using STARTTLS. Obtain Amazon SES SMTP credentials. Use the credentials to authenticate with Amazon SES.
    ✅ Đúng như đã giải thích ở trên. Đây là phương pháp chuẩn, đơn giản nhất cho app SMTP legacy, hỗ trợ STARTTLS để mã hóa mà không yêu cầu thay đổi lớn.

  • Phương án C: Configure the application to use the SES API to send email messages. Create an IAM role that has ses:SendEmail and ses:SendRawEmail permissions. Use the IAM role as a service role for Amazon SES.
    ❌ Sai vì: Ứng dụng chỉ dùng SMTP, không thể chuyển sang SES API (yêu cầu HTTP/HTTPS calls). SES không có "service role" như vậy – IAM role chỉ dùng cho app gọi API qua SDK/CLI, không phải service role cho SES. Vi phạm ràng buộc "application can use SMTP only".

  • Phương án D: Configure the application to use AWS SDKs to send email messages. Create an IAM user for Amazon SES. Generate API access keys. Use the access keys to authenticate with Amazon SES.
    ❌ Sai vì: AWS SDKs yêu cầu code thay đổi lớn (gọi SendEmail/SendRawEmail API), nhưng app chỉ dùng SMTP (không hỗ trợ SDK). IAM user/access keys chỉ cho API auth, không dùng cho SMTP. Không khả thi với legacy app.

🛠️ Khuyến nghị thực tế: Sau khi config, test gửi email qua SES SMTP với tools như telnet/swaks, monitor quota qua CloudWatch. Nếu cần scale, tích hợp SES với VPC endpoints để private connectivity! 🚀

Câu 773
A company recently acquired several other companies. Each company has a separate AWS account with a different billing and reporting method. The acquiring company has consolidated all the accounts into one organization in AWS Organizations. However, the acquiring company has found it difficult to generate a cost report that contains meaningful groups for all the teams.

The acquiring company’s finance team needs a solution to report on costs for all the companies through a self-managed application.

Which solution will meet these requirements?
  1. A Create an AWS Cost and Usage Report for the organization. Define tags and cost categories in the report. Create a table in Amazon Athena. Create an Amazon QuickSight dataset based on the Athena table. Share the dataset with the finance team.
  2. B Create an AWS Cost and Usage Report for the organization. Define tags and cost categories in the report. Create a specialized template in AWS Cost Explorer that the finance department will use to build reports.
  3. C Create an Amazon QuickSight dataset that receives spending information from the AWS Price List Query API. Share the dataset with the finance team.
  4. D Use the AWS Price List Query API to collect account spending information. Create a specialized template in AWS Cost Explorer that the finance department will use to build reports.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả tình huống một công ty lớn mua lại nhiều công ty nhỏ, mỗi công ty có AWS account riêng với phương thức billing và reporting khác nhau. Sau khi hợp nhất tất cả vào một AWS Organization, công ty mẹ gặp khó khăn trong việc tạo báo cáo chi phí (cost report) có các nhóm dữ liệu ý nghĩa (meaningful groups) cho tất cả các team. Đội ngũ tài chính (finance team) cần một giải pháp để báo cáo chi phí cho toàn bộ các công ty thông qua một ứng dụng tự quản lý (self-managed application).

🛠️ Yêu cầu chính:

  • Hỗ trợ báo cáo chi phí ở cấp độ Organization (bao gồm nhiều accounts).
  • Cho phép tùy chỉnh nhóm dữ liệu (như tags, cost categories) để dễ phân tích.
  • Phải là giải pháp self-managed (tự xây dựng và quản lý dashboard/report qua app), không phụ thuộc hoàn toàn vào công cụ AWS UI sẵn có.
  • Áp dụng kiến thức AWS mới nhất (2024-2026): AWS Cost and Usage Reports (CUR) hỗ trợ đầy đủ Organizations với tagging và cost allocation tags; tích hợp seamless với Athena và QuickSight cho phân tích tự động hóa.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create an AWS Cost and Usage Report for the organization. Define tags and cost categories in the report. Create a table in Amazon Athena. Create an Amazon QuickSight dataset based on the Athena table. Share the dataset with the finance team.

Lý do chọn 🏆:

  • Giải pháp này hoàn toàn đáp ứng self-managed application vì CUR cung cấp dữ liệu chi phí thô (raw data) ở S3 cho toàn Organization, hỗ trợ tags và cost categories để nhóm dữ liệu ý nghĩa (ví dụ: theo team, company con).
  • Athena query dữ liệu CUR nhanh chóng, tạo table schema tự động → QuickSight build dataset và dashboard tùy chỉnh, share cho finance team quản lý độc lập.
  • Đây là best practice AWS cho cost analytics quy mô lớn, scalable đến 2026 với CURv2 (hỗ trợ hourly granularity, better performance).

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai với lý do cụ thể:

  • Create an AWS Cost and Usage Report for the organization. Define tags and cost categories in the report. Create a table in Amazon Athena. Create an Amazon QuickSight dataset based on the Athena table. Share the dataset with the finance team.
    ✅ Đúng 🥇: CUR lý tưởng cho Organization, export dữ liệu tagged vào S3. Athena partition và query hiệu quả (serverless SQL). QuickSight tạo viz tự động, share dataset cho self-managed dashboard. Không cần code phức tạp, finance team tự build report ý nghĩa.

  • Create an AWS Cost and Usage Report for the organization. Define tags and cost categories in the report. Create a specialized template in AWS Cost Explorer that the finance department will use to build reports.
    ❌ Sai 🚫: CUR + tags tốt, nhưng Cost Explorer chỉ là UI tool với template giới hạn (shared/grouped by tags, nhưng không export raw data cho app tự quản). Không phải "self-managed application" thực thụ, finance team vẫn phụ thuộc AWS console, khó customize sâu cho nhiều teams.

  • Create an Amazon QuickSight dataset that receives spending information from the AWS Price List Query API. Share the dataset with the finance team.
    ❌ Sai ⚠️: AWS Price List Query API chỉ cung cấp giá list (on-demand/spot prices), KHÔNG phải dữ liệu spending thực tế (usage/costs đã consume). Không hỗ trợ historical data, tags, hay Organization-level reports. QuickSight dataset sẽ thiếu chính xác, không meet yêu cầu báo cáo chi phí thực.

  • Use the AWS Price List Query API to collect account spending information. Create a specialized template in AWS Cost Explorer that the finance department will use to build reports.
    ❌ Sai 🔒: Tương tự trên, Price List API không collect spending info (chỉ giá, không usage/cost). Cost Explorer template hữu ích cho quick views nhưng KHÔNG tự động hóa self-managed app, và thiếu raw data cho custom grouping ở Organization multi-account.

🧠 Kết luận: Giải pháp đúng tận dụng CUR → Athena → QuickSight là stack mạnh mẽ, cost-effective cho enterprise cost governance theo AWS Well-Architected Framework (Operations Pillar, 2024 update).

Câu 774 Chọn nhiều đáp án
A company runs an IoT platform on AWS. IoT sensors in various locations send data to the company’s Node.js API servers on Amazon EC2 instances running behind an Application Load Balancer. The data is stored in an Amazon RDS MySQL DB instance that uses a 4 TB General Purpose SSD volume.

The number of sensors the company has deployed in the field has increased over time, and is expected to grow significantly. The API servers are consistently overloaded and RDS metrics show high write latency.

Which of the following steps together will resolve the issues permanently and enable growth as new sensors are provisioned, while keeping this platform cost-efficient? (Choose two.)
  1. A Resize the MySQL General Purpose SSD storage to 6 TB to improve the volume’s IOPS.
  2. B Re-architect the database tier to use Amazon Aurora instead of an RDS MySQL DB instance and add read replicas.
  3. C Leverage Amazon Kinesis Data Streams and AWS Lambda to ingest and process the raw data.
  4. D Use AWS X-Ray to analyze and debug application issues and add more API servers to match the load.
  5. E Re-architect the database tier to use Amazon DynamoDB instead of an RDS MySQL DB instance.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một nền tảng IoT trên AWS gặp vấn đề hiệu suất do số lượng sensors tăng mạnh:
📡 Dữ liệu từ sensors được gửi đến Node.js API servers chạy trên Amazon EC2 phía sau Application Load Balancer (ALB).
💾 Dữ liệu được lưu trữ vào Amazon RDS MySQL với volume General Purpose SSD (gp3/gp2) dung lượng 4 TB.
🚨 Vấn đề chính:

  • API servers liên tục overload (quá tải).
  • RDS high write latency (độ trễ ghi cao).
  • Số sensors tăng đáng kể trong tương lai, cần giải pháp vĩnh viễn (permanently resolve), hỗ trợ scale (enable growth) và tiết kiệm chi phí (cost-efficient).

Câu hỏi yêu cầu chọn 2 bước kết hợp để giải quyết gốc rễ: overload ingestion và bottleneck writes trên RDS relational. Giải pháp cần decouple (tách rời) luồng dữ liệu, chuyển sang kiến trúc serverless/noSQL scale tự động, phù hợp IoT high-volume writes (dữ liệu sensor thường là time-series, append-only).

✅ Đáp án đúng (Chọn 2)

Hai lựa chọn đúng là:

  1. Leverage Amazon Kinesis Data Streams and AWS Lambda to ingest and process the raw data.
    🛠️ Lý do: Sử dụng Kinesis Data Streams để thu thập dữ liệu raw từ sensors với throughput cao (hàng triệu events/giây), Lambda xử lý async (serverless), giảm tải ngay lập tức cho API/EC2 và RDS. Hỗ trợ scale tự động, cost-efficient (pay-per-use), lý tưởng cho IoT growth. Kết hợp này decouple ingestion, tránh overload sync writes.

  2. Re-architect the database tier to use Amazon DynamoDB instead of an RDS MySQL DB instance.
    🛠️ Lý do: DynamoDB là NoSQL fully managed, tối ưu high writes (hàng tỷ requests/ngày, auto-scale partitions), phù hợp dữ liệu IoT (key-value/JSON sensor data). Thay thế RDS MySQL relational (kém scale writes lớn), giảm latency vĩnh viễn, cost-efficient với on-demand capacity, hỗ trợ growth không giới hạn mà không cần resize thủ công.

Kết hợp 2 bước: Kinesis+Lambda ingest/process → lưu vào DynamoDB → scale toàn diện, loại bỏ bottleneck.

📝 Giải thích chi tiết từng phương án

Dưới đây là phân tích tất cả 5 lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá ✅ (đúng) hoặc ❌ (sai), kèm lý do dựa trên kiến trúc AWS mới nhất (2024-2026: DynamoDB on-demand v2, Kinesis enhanced fan-out, gp3 volumes).

  • Resize the MySQL General Purpose SSD storage to 6 TB to improve the volume’s IOPS.
    ❌ Sai: Tăng size gp3 từ 4TB lên 6TB tăng baseline IOPS (3 IOPS/GB, max 16k IOPS), nhưng chỉ cải thiện tạm thời, không scale vĩnh viễn với growth lớn (vẫn giới hạn burst credits). RDS MySQL relational không phù hợp high writes IoT (transaction overhead), chi phí cao hơn mà không giải quyết overload API gốc.

  • Re-architect the database tier to use Amazon Aurora instead of an RDS MySQL DB instance and add read replicas.
    ❌ Sai: Aurora MySQL tốt hơn RDS (storage scale đến 128TB, I/O cao gấp 5x), read replicas giúp reads nhưng không giải quyết write latency (writes vẫn tập trung primary, replicas async). Không cost-efficient dài hạn cho IoT append-only, vẫn cần provisioned IOPS và không auto-scale writes như NoSQL.

  • Leverage Amazon Kinesis Data Streams and AWS Lambda to ingest and process the raw data.
    ✅ Đúng: Như giải thích trên. Kinesis (2026: hỗ trợ MSK integration, enhanced monitoring) + Lambda (concurrency auto-scale) decouple hoàn hảo, xử lý millions TPS, tích hợp IoT Core nếu cần. Giảm 90% load API/RDS ngay lập tức, pay-per-throughput siêu tiết kiệm.

  • Use AWS X-Ray to analyze and debug application issues and add more API servers to match the load.
    ❌ Sai: X-Ray chỉ debug tracing (trace requests), không giải quyết gốc (RDS writes). Thêm EC2/API servers scale horizontal nhưng vẫn bottleneck RDS, tăng chi phí (EC2 + ALB), không vĩnh viễn vì writes sync vẫn overload DB khi sensors grow.

  • Re-architect the database tier to use Amazon DynamoDB instead of an RDS MySQL DB instance.
    ✅ Đúng: Như giải thích trên. DynamoDB (2026: Global Tables v2, PartiQL queries) hoàn hảo IoT với DAX caching, TTL auto-delete old sensor data, zero-downtime migration via DMS. Scale writes vô hạn, cost 50-70% rẻ hơn RDS cho workloads tương tự.

📘 Tài liệu tham khảo (AWS mới nhất 2024-2026)

  • AWS Well-Architected Framework - IoT Lens: Khuyến nghị Kinesis+Lambda+DynamoDB cho high-ingest (aws.amazon.com/architecture/iot).
  • DynamoDB Best Practices: IoT workloads (docs.aws.amazon.com/amazondynamodb/latest/developerguide/bp-use-cases.html).
  • Kinesis Data Streams: Scaling for IoT (aws.amazon.com/kinesis/data-streams/features/#:~:text=millions%20records/second).
  • RDS vs DynamoDB Comparison: aws.amazon.com/compare/the-difference-between-dynamodb-and-rds/.
  • Exam DOP-C02 Guide: Phần Database Services & Ingestion (aws.amazon.com/certification/certified-devops-engineer-professional/).

Giải pháp này đảm bảo 99.99% availability, serverless-first theo AWS 2026 best practices! 🚀

Câu 775 Chọn nhiều đáp án
A company is building an electronic document management system in which users upload their documents. The application stack is entirely serverless and runs on AWS in the eu-central-1 Region. The system includes a web application that uses an Amazon CloudFront distribution for delivery with Amazon S3 as the origin. The web application communicates with Amazon API Gateway Regional endpoints. The API Gateway APIs call AWS Lambda functions that store metadata in an Amazon Aurora Serverless database and put the documents into an S3 bucket.
The company is growing steadily and has completed a proof of concept with its largest customer. The company must improve latency outside of Europe.

Which combination of actions will meet these requirements? (Choose two.)
  1. A Enable S3 Transfer Acceleration on the S3 bucket. Ensure that the web application uses the Transfer Acceleration signed URLs.
  2. B Create an accelerator in AWS Global Accelerator. Attach the accelerator to the CloudFront distribution.
  3. C Change the API Gateway Regional endpoints to edge-optimized endpoints.
  4. D Provision the entire stack in two other locations that are spread across the world. Use global databases on the Aurora Serverless cluster.
  5. E Add an Amazon RDS proxy between the Lambda functions and the Aurora Serverless database.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một hệ thống quản lý tài liệu điện tử hoàn toàn serverless trên AWS tại vùng eu-central-1 (Frankfurt, châu Âu). Kiến trúc bao gồm:

  • Web application: Phân phối qua Amazon CloudFront với Amazon S3 làm origin (lưu trữ tài liệu).
  • API Gateway Regional endpoints: Giao tiếp với AWS Lambda functions.
  • Lambda: Lưu metadata vào Amazon Aurora Serverless và upload tài liệu vào S3 bucket.

Công ty đang phát triển, cần cải thiện độ trễ (latency) cho người dùng ngoài châu Âu sau proof-of-concept thành công. Yêu cầu chọn hai hành động kết hợp để đáp ứng, tập trung vào tối ưu hóa global mà không thay đổi lớn kiến trúc serverless.

Mục tiêu chính: Giảm thời gian phản hồi cho upload tài liệu và gọi API từ xa (Mỹ, Á, v.v.), tận dụng edge locations toàn cầu của AWS.

✅ Đáp án đúng (Chọn hai phương án sau)

Hai đáp án đúng là:

  • Enable S3 Transfer Acceleration on the S3 bucket. Ensure that the web application uses the Transfer Acceleration signed URLs.
  • Change the API Gateway Regional endpoints to edge-optimized endpoints.

Lý do lựa chọn:

  • Hệ thống hiện tại dùng API Gateway Regional (chỉ tối ưu trong region eu-central-1), gây latency cao cho client xa châu Âu khi gọi API → Chuyển sang edge-optimized tự động tạo CloudFront distribution, route request đến edge location gần nhất, cache responses, giảm RTT (round-trip time) lên đến 50-70% cho global traffic.
  • Upload tài liệu vào S3 từ xa chậm do đường truyền dài → S3 Transfer Acceleration sử dụng AWS edge network (CloudFront backbone) để tăng tốc upload/download, đặc biệt hiệu quả với signed URLs (an toàn cho presigned uploads từ web app). Kết hợp hai hành động này giữ nguyên serverless, chi phí thấp, triển khai nhanh, cải thiện latency toàn cầu mà không cần multi-region phức tạp. Đây là best practice cho serverless global apps theo AWS Well-Architected Framework (2023-2026 updates).

🔍 Phân tích chi tiết tất cả các phương án

  • ✅ Enable S3 Transfer Acceleration on the S3 bucket. Ensure that the web application uses the Transfer Acceleration signed URLs.
    Đúng: Phương án này kích hoạt Transfer Acceleration trên S3 bucket, route traffic upload qua edge locations gần người dùng (hơn 100 edge toàn cầu), giảm latency upload lớn (tăng tốc 50-500% tùy khoảng cách). Web app dùng signed URLs (với endpoint bucketname.s3-accelerate.amazonaws.com) đảm bảo bảo mật và tận dụng tối đa. Hoàn hảo cho user ngoài châu Âu upload tài liệu lớn. (Không ảnh hưởng API Gateway).

  • ❌ Create an accelerator in AWS Global Accelerator. Attach the accelerator to the CloudFront distribution.
    Sai: AWS Global Accelerator tối ưu TCP/UDP traffic đến static IP anycast, phù hợp ALB/NLB/EC2/Elastic IP, không hỗ trợ trực tiếp attach vào CloudFront (CloudFront đã dùng global edge network riêng, anycast DNS). Attach sẽ không cải thiện mà còn thêm overhead không cần thiết. Global Accelerator dành cho non-HTTP(S), không phải trường hợp này.

  • ✅ Change the API Gateway Regional endpoints to edge-optimized endpoints.
    Đúng: Regional endpoints chỉ tối ưu intra-region (eu-central-1), latency cao từ xa. Edge-optimized tự động provision CloudFront distribution + custom domain, route API calls đến edge gần nhất, hỗ trợ caching (TTL tùy chỉnh), giảm latency global. Lambda/Aurora vẫn ở eu-central-1, nhưng response nhanh hơn. Hỗ trợ đầy đủ serverless stack, theo AWS updates 2024-2026 (vẫn recommend cho global APIs).

  • ❌ Provision the entire stack in two other locations that are spread across the world. Use global databases on the Aurora Serverless cluster.
    Sai: Yêu cầu serverless thuần (không provision infra), phương án này cần deploy multi-region full stack (CloudFront/S3/API/Lambda/Aurora), tốn kém cao (data transfer fees), phức tạp quản lý (cross-region sync), vi phạm "serverless entirely". Aurora Global Database hỗ trợ read replicas multi-region nhưng write vẫn primary region, không giải quyết latency upload/API chính.

  • ❌ Add an Amazon RDS proxy between the Lambda functions và the Aurora Serverless database.
    Sai: Amazon RDS Proxy (nay là Aurora Serverless v2 Proxy) chỉ pool connections, giảm cold starts Lambda và manage connections (max_prepared_statements), không cải thiện network latency địa lý (vẫn route từ Lambda ở eu-central-1 đến DB cùng region). Không liên quan đến client ngoài châu Âu gọi API/upload S3.

📘 Tài liệu tham khảo (AWS cập nhật mới nhất 2024-2026)

🛠️ Khuyến nghị triển khai: Test với CloudWatch Insights theo dõi P99 latency post-change. Scale Lambda concurrency nếu cần!

Câu 776
An adventure company has launched a new feature on its mobile app. Users can use the feature to upload their hiking and rafting photos and videos anytime. The photos and videos are stored in Amazon S3 Standard storage in an S3 bucket and are served through Amazon CloudFront.

The company needs to optimize the cost of the storage. A solutions architect discovers that most of the uploaded photos and videos are accessed infrequently after 30 days. However, some of the uploaded photos and videos are accessed frequently after 30 days. The solutions architect needs to implement a solution that maintains millisecond retrieval availability of the photos and videos at the lowest possible cost.

Which solution will meet these requirements?
  1. A Configure S3 Intelligent-Tiering on the S3 bucket.
  2. B Configure an S3 Lifecycle policy to transition image objects and video objects from S3 Standard to S3 Glacier Deep Archive after 30 days.
  3. C Replace Amazon S3 with an Amazon Elastic File System (Amazon EFS) file system that is mounted on Amazon EC2 instances.
  4. D Add a Cache-Control: max-age header to the S3 image objects and S3 video objects. Set the header to 30 days.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi mô tả một công ty phiêu lưu đã triển khai tính năng mới trên app di động, cho phép người dùng upload ảnh và video hiking/rafting bất kỳ lúc nào. Các file này được lưu trữ ở Amazon S3 Standard trong một bucket S3 và phục vụ qua Amazon CloudFront.

📊 Vấn đề chính:

  • Cần tối ưu chi phí lưu trữ (optimize storage cost).
  • Đặc điểm truy cập: Hầu hết ảnh/video ít được truy cập sau 30 ngày (infrequently accessed), nhưng một số vẫn truy cập thường xuyên (frequently accessed).
  • Yêu cầu: Giữ millisecond retrieval availability (truy xuất trong mili giây) với chi phí thấp nhất (lowest possible cost).

🛠️ Phân tích ngữ cảnh: S3 Standard phù hợp cho truy cập thường xuyên ban đầu, nhưng không tối ưu cho dữ liệu ít truy cập lâu dài. Giải pháp phải tự động hóa việc chuyển tier lưu trữ dựa trên pattern truy cập thực tế, đảm bảo tốc độ nhanh và chi phí thấp, đồng thời tương thích với CloudFront (CDN).

✅ Đáp án đúng: Configure S3 Intelligent-Tiering on the S3 bucket.

Lý do lựa chọn:
S3 Intelligent-Tiering là giải pháp tự động tối ưu nhất cho tình huống này. Nó giám sát pattern truy cập và tự động di chuyển objects giữa các access tier (Frequent Access, Infrequent Access, Archive Instant Access, Archive Access, Deep Archive) không cần cấu hình thủ công.

  • Millisecond retrieval: Tất cả tier đều hỗ trợ truy xuất mili giây (ngay cả Archive Instant chỉ mất vài mili giây).
  • Chi phí thấp: Chỉ tính phí monitoring nhỏ (~$0.0025/1.000 objects/tháng), tiết kiệm 40-95% so với Standard cho dữ liệu ít truy cập, mà không phạt nếu access thay đổi đột ngột (như một số file vẫn hot sau 30 ngày).
  • Cập nhật 2026: Từ 2023, Intelligent-Tiering hỗ trợ thêm Deep Archive Access tier với retrieval <12 giờ, nhưng vẫn giữ millisecond cho Instant tiers. Hoàn hảo cho media files với CloudFront.

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn giữ nguyên văn bản gốc bằng tiếng Anh, kèm giải thích sai/đúng bằng tiếng Việt:

  • Configure S3 Intelligent-Tiering on the S3 bucket.
    ✅ Đúng hoàn toàn (như đã giải thích ở trên). Giải pháp thông minh, tự động, phù hợp với pattern truy cập hỗn hợp (phần lớn ít access sau 30d, nhưng linh hoạt cho exceptions). Không downtime, seamless với CloudFront.

  • Configure an S3 Lifecycle policy to transition image objects and video objects from S3 Standard to S3 Glacier Deep Archive after 30 days.
    ❌ Sai: S3 Lifecycle policy có thể chuyển objects sau 30 ngày, nhưng S3 Glacier Deep Archive có thời gian retrieval rất chậm (12 giờ đầu tiên, bulk 48 giờ), không đáp ứng millisecond retrieval. Dù rẻ nhất (~$0.00099/GB/tháng), nhưng vi phạm yêu cầu availability cho các file vẫn access thường xuyên sau 30d. Không linh hoạt nếu pattern thay đổi.

  • Replace Amazon S3 with an Amazon Elastic File System (Amazon EFS) file system that is mounted on Amazon EC2 instances.
    ❌ Sai: EFS là file system chia sẻ (NFS), không phải object storage như S3. Chi phí cao hơn nhiều (Standard ~$0.30/GB/tháng vs S3 ~$0.023/GB), không scale tốt cho media upload lớn, và không tích hợp native với CloudFront (phải mount trên EC2 phức tạp, tăng latency). Không tối ưu cost hay performance cho use case này.

  • Add a Cache-Control: max-age header to the S3 image objects and S3 video objects. Set the header to 30 days.
    ❌ Sai: Cache-Control chỉ tăng thời gian cache ở CloudFront/browser (giảm requests đến S3), không giảm chi phí lưu trữ S3 (storage cost vẫn tính trên Standard). Sau 30d cache expire, vẫn tốn kém cho dữ liệu ít access. Không giải quyết vấn đề storage tiering, chỉ là optimization edge caching.

📘 Tài liệu tham khảo (AWS cập nhật đến 2026)

🛠️ Khuyến nghị bổ sung: Kết hợp Intelligent-Tiering với S3 Inventory reports để monitor, và CloudFront Field-Level Encryption cho media bảo mật. Nếu scale lớn, xem xét S3 Object Lambda cho transformations!

Câu 777
A company uses Amazon S3 to store files and images in a variety of storage classes. The company's S3 costs have increased substantially during the past year.

A solutions architect needs to review data trends for the past 12 months and identity the appropriate storage class for the objects.

Which solution will meet these requirements?
  1. A Download AWS Cost and Usage Reports for the last 12 months of S3 usage. Review AWS Trusted Advisor recommendations for cost savings.
  2. B Use S3 storage class analysis. Import data trends into an Amazon QuickSight dashboard to analyze storage trends.
  3. C Use Amazon S3 Storage Lens. Upgrade the default dashboard to include advanced metrics for storage trends.
  4. D Use Access Analyzer for S3. Download the Access Analyzer for S3 report for the last 12 months. Import the .csv file to an Amazon QuickSight dashboard.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào vấn đề tối ưu hóa chi phí Amazon S3 khi công ty sử dụng nhiều storage class khác nhau (như Standard, Intelligent-Tiering, Glacier, v.v.) để lưu trữ files và images, dẫn đến chi phí tăng mạnh trong năm qua.
Yêu cầu chính của solutions architect:

  • Xem xét xu hướng dữ liệu (data trends) trong 12 tháng qua.
  • Xác định storage class phù hợp cho các objects dựa trên patterns truy cập (access patterns).

🔍 Mục tiêu: Tìm giải pháp tích hợp sẵn trong AWS, cung cấp phân tích trends chi tiết, metrics về storage usage, và recommendations tự động cho storage class mà không cần export dữ liệu thủ công hoặc công cụ bên ngoài. Giải pháp phải hỗ trợ dashboard để visualize trends (phiên bản AWS mới nhất đến 2026 nhấn mạnh S3 Storage Lens với advanced metrics và ML-based recommendations).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use Amazon S3 Storage Lens. Upgrade the default dashboard to include advanced metrics for storage trends.

Lý do chi tiết:
🛠️ S3 Storage Lens là tính năng miễn phí, serverless của Amazon S3 (ra mắt 2020, cập nhật liên tục đến 2026 với ML insights nâng cao), cho phép phân tích toàn diện trends storage cross-account/cross-region.

  • Cung cấp metrics mặc định và advanced (như object age, access frequency, replication rules, encryption status) cho 15-365 ngày (bao phủ 12 tháng).
  • Dashboard mặc định có thể upgrade để thêm advanced metrics, visualize trends, và tự động recommend storage class dựa trên access patterns (ví dụ: di chuyển sang S3 Glacier nếu ít truy cập).
  • Không cần import dữ liệu thủ công, hỗ trợ export CSV/Parquet cho QuickSight nếu cần.
    📘 Nguồn tham khảo: AWS S3 Storage Lens Documentation (cập nhật 2025-2026 với advanced metrics và organization-level views).

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn một cách chi tiết, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá dựa trên khả năng đáp ứng review trends 12 tháng và identify storage class.

  • ❌ [SAI] Download AWS Cost and Usage Reports for the last 12 months of S3 usage. Review AWS Trusted Advisor recommendations for cost savings.
    Lý do sai: Cost and Usage Reports (CUR) chỉ cung cấp dữ liệu chi phí tổng quát (billing-focused), không có trends chi tiết về access patterns hay recommend storage class cụ thể cho objects. Trusted Advisor có check S3 cost (như "S3 Bucket with Incomplete Multipart Uploads") nhưng không phân tích trends 12 tháng hay storage class analysis sâu. Phải download thủ công và analyze thủ công, không hiệu quả cho yêu cầu.

  • ❌ [SAI] Use S3 storage class analysis. Import data trends into an Amazon QuickSight dashboard to analyze storage trends.
    Lý do sai: S3 Storage Class Analysis (trong Intelligent-Tiering) chỉ áp dụng cho objects cụ thể (per-object/prefix), phân tích access patterns trong 30 ngày gần nhất (không phải 12 tháng), và recommend class cho object đó. Không hỗ trợ toàn bộ bucket trends, phải import thủ công vào QuickSight (phức tạp, không native). Không phù hợp cho review toàn diện.

  • ✅ [ĐÚNG] Use Amazon S3 Storage Lens. Upgrade the default dashboard to include advanced metrics for storage trends.
    Lý do đúng (tóm tắt lại): Hoàn hảo khớp yêu cầu với native dashboard, advanced metrics (prefixed, non-prefixed, object locks), trends 12 tháng, và recommendations tự động cho storage class. Hỗ trợ free tier và scale lớn (multi-account).
    📘 Nguồn: S3 Storage Lens Getting Started.

  • ❌ [SAI] Use Access Analyzer for S3. Download the Access Analyzer for S3 report for the last 12 months. Import the .csv file to an Amazon QuickSight dashboard.
    Lý do sai: Access Analyzer for S3 chỉ tập trung vào policy analysis (find unintended access via IAM/S3 policies), không phân tích storage trends hay access frequency/storage class. Report không có dữ liệu 12 tháng về usage patterns, chỉ về findings (external access risks). Phải download CSV và import QuickSight – không native và không liên quan đến cost/storage optimization.

🏆 Kết luận & Lời khuyên DevOps

Giải pháp S3 Storage Lens là best practice theo AWS Well-Architected Framework (Cost Optimization pillar, cập nhật 2026). DevOps Engineer nên automate setup Storage Lens via CloudFormation/ CDK và integrate với S3 Lifecycle policies dựa trên recommendations.
🔗 Tài liệu bổ sung:

Nếu cần demo code hoặc lab thực hành, hãy cho tôi biết! 🚀

Câu 778
A company has its cloud infrastructure on AWS. A solutions architect needs to define the infrastructure as code. The infrastructure is currently deployed in one AWS Region. The company’s business expansion plan includes deployments in multiple Regions across multiple AWS accounts.

What should the solutions architect do to meet these requirements?
  1. A Use AWS CloudFormation templates. Add IAM policies to control the various accounts, Deploy the templates across the multiple Regions.
  2. B Use AWS Organizations. Deploy AWS CloudFormation templates from the management account Use AWS Control Tower to manage deployments across accounts.
  3. C Use AWS Organizations and AWS CloudFormation StackSets. Deploy a Cloud Formation template from an account that has the necessary IAM permissions.
  4. D Use nested stacks with AWS CloudFormation templates. Change the Region by using nested stacks.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai Infrastructure as Code (IaC) trên AWS cho một công ty đang mở rộng hạ tầng đám mây. Hiện tại, hạ tầng được triển khai ở một AWS Region duy nhất và một AWS account. Kế hoạch kinh doanh yêu cầu mở rộng sang nhiều Region và nhiều AWS account (multi-account, multi-Region). Solutions Architect cần chọn giải pháp phù hợp để định nghĩa và triển khai hạ tầng một cách tự động, nhất quán, tuân thủ nguyên tắc IaC.

Vấn đề cốt lõi: AWS CloudFormation là công cụ IaC chính, nhưng cần cơ chế hỗ trợ cross-account và cross-Region deployment mà không phải deploy thủ công từng nơi. Giải pháp phải tận dụng các dịch vụ AWS quản lý multi-account như AWS Organizations và công cụ deploy stack quy mô lớn. ✅ Yêu cầu chính: Tự động hóa deployment IaC qua nhiều account/Region một cách an toàn và hiệu quả.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use AWS Organizations and AWS CloudFormation StackSets. Deploy a Cloud Formation template from an account that has the necessary IAM permissions.

Lý do chọn đáp án này 🛠️:

  • AWS Organizations giúp quản lý tập trung nhiều AWS accounts (management account và member accounts).
  • AWS CloudFormation StackSets (cập nhật mới nhất 2024-2026) là dịch vụ chuyên dụng để deploy CloudFormation templates qua nhiều Regions và nhiều accounts trong Organizations. StackSets admin account (thường là management account) với IAM permissions phù hợp (như AWSCloudFormationFullAccess và StackSets permissions) có thể tự động tạo stack instances ở các target accounts/Regions.
  • Giải pháp này đảm bảo nhất quán IaC, hỗ trợ self-managed hoặc service-managed permissions, và tích hợp với AWS Organizations delegated administration cho bảo mật cao. Đây là best practice theo AWS Well-Architected Framework (Pillar: Operational Excellence & Security).

📋 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá ✅ đúng hoặc ❌ sai với lý do cụ thể:

  • Use AWS CloudFormation templates. Add IAM policies to control the various accounts, Deploy the templates across the multiple Regions.
    ❌ Sai: CloudFormation templates thông thường chỉ deploy trong cùng một account và Region (hoặc cross-Region thủ công qua console/CLI). Việc thêm IAM policies chỉ kiểm soát quyền truy cập, không tự động hóa deployment cross-account/multi-Region. Phải deploy thủ công từng account → Không scale, dễ lỗi, vi phạm IaC best practice.

  • Use AWS Organizations. Deploy AWS CloudFormation templates from the management account Use AWS Control Tower to manage deployments across accounts.
    ❌ Sai: AWS Organizations chỉ quản lý accounts, không deploy templates tự động. AWS Control Tower dùng để thiết lập landing zone (governance, guardrails) chứ không phải deploy CloudFormation templates trực tiếp cross-account. Deploy từ management account vẫn cần thủ công hoặc StackSets → Không đáp ứng yêu cầu IaC multi-Region/account đầy đủ.

  • Use AWS Organizations and AWS CloudFormation StackSets. Deploy a Cloud Formation template from an account that has the necessary IAM permissions.
    ✅ Đúng: Như đã giải thích ở phần đáp án. StackSets + Organizations là giải pháp chuẩn (hỗ trợ delegated admin từ 2023+, cập nhật 2026 vẫn giữ nguyên), deploy từ admin account với IAM roles phù hợp → Tự động, nhất quán, an toàn cho multi-account/multi-Region.

  • Use nested stacks with AWS CloudFormation templates. Change the Region by using nested stacks.
    ❌ Sai: Nested stacks chỉ giúp modular hóa templates trong cùng account (có thể cross-Region qua parameters, nhưng thủ công). Không hỗ trợ cross-account deployment tự động → Không giải quyết multi-account, chỉ phù hợp single-account scenarios.

📘 Tài liệu tham khảo (kiến thức cập nhật đến 2026)

🛡️ Lưu ý: Giải pháp này tuân thủ Security best practices với least privilege IAM và guardrails từ Organizations/Control Tower bổ sung. Nếu cần lab thực hành, dùng AWS Free Tier với Organizations sandbox!

Câu 779
A company plans to refactor a monolithic application into a modern application design deployed on AWS. The CI/CD pipeline needs to be upgraded to support the modern design for the application with the following requirements:

•It should allow changes to be released several times every hour.
•It should be able to roll back the changes as quickly as possible.

Which design will meet these requirements?
  1. A Deploy a CI/CD pipeline that incorporates AMIs to contain the application and their configurations. Deploy the application by replacing Amazon EC2 instances.
  2. B Specify AWS Elastic Beanstalk to stage in a secondary environment as the deployment target for the CI/CD pipeline of the application. To deploy, swap the staging and production environment URLs.
  3. C Use AWS Systems Manager to re-provision the infrastructure for each deployment. Update the Amazon EC2 user data to pull the latest code artifact from Amazon S3 and use Amazon Route 53 weighted routing to point to the new environment.
  4. D Roll out the application updates as part of an Auto Scaling event using prebuilt AMIs. Use new versions of the AMIs to add instances. and phase out all instances that use the previous AMI version with the configured termination policy during a deployment event.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm AWS

📘 Nội dung câu hỏi được giải thích rõ ràng:
Câu hỏi xoay quanh việc nâng cấp CI/CD pipeline cho một ứng dụng monolithic được refactor thành thiết kế hiện đại (modern application design) triển khai trên AWS. Yêu cầu chính là:

  • ✅ Cho phép phát hành thay đổi (release changes) nhiều lần mỗi giờ (several times every hour) → Cần pipeline nhanh, tự động hóa cao, hỗ trợ deployment liên tục (high-frequency deployments).
  • ✅ Rollback thay đổi nhanh nhất có thể (roll back as quickly as possible) → Ưu tiên phương pháp deployment không downtime, dễ đảo ngược mà không cần rebuild/re-provision tài nguyên (như blue-green deployment hoặc immutable deployments).
    Chủ đề liên quan đến DevOps best practices trên AWS, đặc biệt là các dịch vụ hỗ trợ containerization, serverless hoặc PaaS để refactor monolithic app, đảm bảo tính linh hoạt và độ tin cậy cao theo AWS Well-Architected Framework (Pillar: Operational Excellence). Kiến thức cập nhật đến 2026 vẫn giữ nguyên các tính năng cốt lõi của AWS services như Elastic Beanstalk blue-green deployment (từ EB platform version 2024+).

✅ Đáp án ĐÚNG và lý do lựa chọn:
Đáp án đúng là: Specify AWS Elastic Beanstalk to stage in a secondary environment as the deployment target for the CI/CD pipeline of the application. To deploy, swap the staging and production environment URLs.

🛠️ Lý do chi tiết (bằng tiếng Việt):

  • AWS Elastic Beanstalk hỗ trợ blue-green deployment bằng cách sử dụng secondary environment (staging) song song với production. Pipeline CI/CD (ví dụ: CodePipeline) deploy code mới vào staging, test, sau đó swap URLs (chỉ mất vài giây) để traffic chuyển sang staging → production.
  • Điều này đáp ứng hoàn hảo: Release several times/hour (deploy nhanh qua EB CLI hoặc API) và rollback cực nhanh (swap ngược URL lại staging cũ, zero-downtime). Không cần rebuild AMI hay re-provision instances.
  • Phù hợp refactor monolithic → microservices hoặc containerized apps trên EB (hỗ trợ Docker/ECS). Theo AWS 2026, EB tích hợp sâu hơn với CodePipeline và Graviton processors cho performance cao.

🔍 Giải thích TẤT CẢ các phương án (Đúng/Sai)

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá ✅/❌ với lý do bằng tiếng Việt:

  • ❌ [SAI] Deploy a CI/CD pipeline that incorporates AMIs to contain the application and their configurations. Deploy the application by replacing Amazon EC2 instances.
    🧩 Lý do sai: Phương án dùng AMI (Amazon Machine Images) để chứa app và config, sau đó replace EC2 instances → Chậm và không rollback nhanh. Build AMI mới mỗi lần deploy mất 10-30 phút (bake process), không phù hợp "several times/hour". Rollback cần launch AMI cũ → downtime cao. Không hiện đại cho refactor app (immutable nhưng overhead lớn).

  • ✅ [ĐÚNG] Specify AWS Elastic Beanstalk to stage in a secondary environment as the deployment target for the CI/CD pipeline of the application. To deploy, swap the staging and production environment URLs.
    🛠️ Lý do đúng: Như đã giải thích ở trên. Đây là blue-green deployment chuẩn AWS, zero-downtime, swap URL chỉ <1 phút. Hỗ trợ CI/CD nhanh (CodePipeline + EB), lý tưởng cho high-frequency releases và instant rollback.

  • ❌ [SAI] Use AWS Systems Manager to re-provision the infrastructure for each deployment. Update the Amazon EC2 user data to pull the latest code artifact from Amazon S3 and use Amazon Route 53 weighted routing to point to the new environment.
    🧩 Lý do sai: Systems Manager (SSM) dùng để re-provision infra + user data pull code từ S3, kết hợp Route 53 weighted routing → Quá phức tạp và chậm. Re-provision EC2 mỗi deploy mất thời gian (provisioning + bootstrap), không đạt "several times/hour". Rollback cần weighted routing shift lại (có thể gây inconsistency). Không scalable cho modern design.

  • ❌ [SAI] Roll out the application updates as part of an Auto Scaling event using prebuilt AMIs. Use new versions of the AMIs to add instances. and phase out all instances that use the previous AMI version with the configured termination policy during a deployment event.
    🧩 Lý do sai: Dùng Auto Scaling với prebuilt AMI mới, add instances mới và phase out cũ qua termination policy → Gần blue-green nhưng chậm rollback. Phase out instances mất 5-15 phút (drain connections), build AMI mới overhead cao. Không hỗ trợ "several times/hour" vì ASG events không đủ nhanh cho frequent deploys. Phù hợp legacy hơn modern refactor.

📚 Tài liệu tham khảo (AWS cập nhật 2026):

🎯 Kết luận: Phương án Elastic Beanstalk là optimal choice cho yêu cầu high-frequency + fast rollback trong modern AWS architecture! 🚀

Câu 780 Chọn nhiều đáp án
A company has an application that runs on Amazon EC2 instances. A solutions architect is designing VPC infrastructure in an AWS Region where the application needs to access an Amazon Aurora DB Cluster. The EC2 instances are all associated with the same security group. The DB cluster is associated with its own security group.

The solutions architect needs to add rules to the security groups to provide the application with least privilege access to the DB Cluster.

Which combination of steps will meet these requirements? (Choose two.)
  1. A Add an inbound rule to the EC2 instances' security group. Specify the DB cluster's security group as the source over the default Aurora port.
  2. B Add an outbound rule to the EC2 instances' security group. Specify the DB cluster's security group as the destination over the default Aurora port.
  3. C Add an inbound rule to the DB cluster's security group. Specify the EC2 instances' security group as the source over the default Aurora port.
  4. D Add an outbound rule to the DB cluster's security group. Specify the EC2 instances' security group as the destination over the default Aurora port.
  5. E Add an outbound rule to the DB cluster's security group. Specify the EC2 instances' security group as the destination over the ephemeral ports.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc thiết kế VPC infrastructure trong một Region AWS, nơi ứng dụng chạy trên Amazon EC2 instances cần truy cập Amazon Aurora DB Cluster với nguyên tắc least privilege access (quyền hạn tối thiểu). Các EC2 instances đều thuộc một security group chung (SG_EC2), còn DB cluster thuộc security group riêng (SG_DB).

📌 Yêu cầu chính: Thêm rules vào security groups để EC2 có thể kết nối đến DB mà không mở rộng quyền không cần thiết. Security Groups (SG) trong VPC là stateful firewalls, nghĩa là traffic outbound được phép tự động cho phép inbound response (và ngược lại). Để EC2 (client) kết nối DB (server):

  • EC2 cần outbound rule đến SG_DB trên default Aurora port (ví dụ: 3306 cho MySQL, 5432 cho PostgreSQL).
  • DB cần inbound rule từ SG_EC2 trên cùng port đó.
  • Sử dụng reference SG thay vì CIDR để đảm bảo least privilege, chỉ cho phép traffic giữa các SG cụ thể.

Câu hỏi yêu cầu chọn TWO steps đúng. Kiến thức dựa trên AWS VPC Security Groups phiên bản mới nhất (2024-2026), không thay đổi cơ bản từ các bản trước.

✅ Đáp án đúng và lý do lựa chọn

Hai đáp án đúng là (phải chọn cả hai để hoàn thiện kết nối):

  • Add an outbound rule to the EC2 instances' security group. Specify the DB cluster's security group as the destination over the default Aurora port.
  • Add an inbound rule to the DB cluster's security group. Specify the EC2 instances' security group as the source over the default Aurora port.

Lý do:

  • Đây là cách chuẩn AWS để cho phép EC2 initiate kết nối đến DB với least privilege. Outbound từ SG_EC2 (client → server port), inbound vào SG_DB (server chấp nhận từ client SG). SG reference động, tự động cập nhật nếu instances thay đổi. Không cần rules ngược vì SG stateful.

🛠️ Phân tích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phân tích giải thích đúng/sai dựa trên luồng traffic (EC2 là client, DB là server).

  • ❌ Add an inbound rule to the EC2 instances' security group. Specify the DB cluster's security group as the source over the default Aurora port.
    Sai vì: Inbound rule vào SG_EC2 chỉ cho phép traffic vào EC2 từ nguồn (source) SG_DB. Nhưng DB không initiate kết nối ra ngoài (chỉ listen), traffic là từ EC2 → DB. Rule này vô ích và vi phạm least privilege (mở inbound không cần).

  • ✅ Add an outbound rule to the EC2 instances' security group. Specify the DB cluster's security group as the destination over the default Aurora port.
    Đúng vì: EC2 cần gửi traffic ra ngoài (outbound) đến SG_DB trên port DB (default Aurora port). Rule này cho phép kết nối initiate từ client, kết hợp inbound ở DB sẽ hoàn thiện. Least privilege nhờ reference SG cụ thể.

  • ✅ Add an inbound rule to the DB cluster's security group. Specify the EC2 instances' security group as the source over the default Aurora port.
    Đúng vì: DB cần chấp nhận traffic vào (inbound) từ SG_EC2 trên port listen (default Aurora port). Đây là rule cốt lõi cho server-side, stateful nên response tự động quay về EC2 mà không cần thêm outbound ở DB.

  • ❌ Add an outbound rule to the DB cluster's security group. Specify the EC2 instances' security group as the destination over the default Aurora port.
    Sai vì: Outbound từ SG_DB chỉ áp dụng nếu DB initiate kết nối ra ngoài đến SG_EC2 trên port DB – nhưng DB không làm vậy (chỉ listen inbound). Rule này không liên quan đến luồng EC2 → DB.

  • ❌ Add an outbound rule to the DB cluster's security group. Specify the EC2 instances' security group as the destination over the ephemeral ports.
    Sai vì: Tương tự trên, outbound từ DB không cần. "Ephemeral ports" (thường 1024-65535) dùng cho client response, nhưng DB không initiate. Rule này thừa và có thể mở rộng quyền không cần thiết.

📘 Tài liệu tham khảo

  • AWS Documentation: Amazon VPC Security Groups (cập nhật 2024): Giải thích SG rules cho DB access, ví dụ EC2-to-RDS/Aurora.
  • Aurora Best Practices: Amazon Aurora Security – Khuyến nghị dùng SG reference cho least privilege.
  • Exam Topic DOP-C02: Security Groups in VPC (AWS Certified DevOps Engineer Professional, phiên bản 2024).

Hy vọng phân tích này giúp bạn nắm vững! 🚀 Nếu cần thêm ví dụ thực hành với AWS Console/CLI, hãy hỏi nhé!