Ngân hàng đề — AWS Certified Solutions Architect Professional

Tìm thấy 1221 câu.

Câu 891 Chọn nhiều đáp án
A company is building a hybrid environment that includes servers in an on-premises data center and in the AWS Cloud. The company has deployed Amazon EC2 instances in three VPCs. Each VPC is in a different AWS Region. The company has established an AWS Direct. Connect connection to the data center from the Region that is closest to the data center.

The company needs the servers in the on-premises data center to have access to the EC2 instances in all three VPCs. The servers in the on-premises data center also must have access to AWS public services.

Which combination of steps will meet these requirements with the LEAST cost? (Choose two.)
  1. A Create a Direct Connect gateway in the Region that is closest to the data center. Attach the Direct Connect connection to the Direct Connect gateway. Use the Direct Connect gateway to connect the VPCs in the other two Regions.
  2. B Set up additional Direct Connect connections from the on-premises data center to the other two Regions.
  3. C Create a private VIF. Establish an AWS Site-to-Site VPN connection over the private VIF to the VPCs in the other two Regions.
  4. D Create a public VIF. Establish an AWS Site-to-Site VPN connection over the public VIF to the VPCs in the other two Regions.
  5. E Use VPC peering to establish a connection between the VPCs across the Regions Create a private VIF with the existing Direct Connect connection to connect to the peered VPCs.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi xoay quanh việc thiết lập kết nối hybrid giữa data center on-premises và AWS Cloud với chi phí thấp nhất (LEAST cost). Công ty có:

  • Servers on-premises kết nối AWS qua AWS Direct Connect từ Region gần data center nhất (gọi là Region A).
  • 3 VPCs chứa EC2 instances ở 3 Regions khác nhau (Region A, B, C). Yêu cầu:
  • On-premises servers truy cập EC2 instances (private resources) trong tất cả 3 VPCs 🛤️ (kết nối private).
  • On-premises servers truy cập AWS public services (như S3 public endpoints, DynamoDB public, v.v.) 🌐 (kết nối public). Giải pháp phải tận dụng Direct Connect hiện có, mở rộng đến các Regions khác mà không tốn thêm chi phí lớn như mua thêm Direct Connect links. Câu hỏi yêu cầu chọn 2 steps (kết hợp).

✅ Đáp án đúng: Phương án 1 và Phương án 4

Lý do lựa chọn:

  • Phương án 1 giải quyết truy cập private đến tất cả 3 VPCs bằng Direct Connect Gateway (DXGW) – chỉ dùng 1 Direct Connect connection hiện có, associate DXGW với 3 VPCs cross-Region, least cost vì không cần thêm hardware/link DX mới (tiết kiệm hàng nghìn USD/tháng).
  • Phương án 4 giải quyết truy cập AWS public services bằng Public VIF trên cùng Direct Connect connection – advertise public prefixes (BGP) từ AWS, traffic private/high bandwidth/low latency, không qua internet, least cost so với public internet hoặc VPN (tránh data transfer fees cao). Kết hợp 2 bước này: Private VIF (implied in DX connection attach to DXGW) cho VPCs + Public VIF cho public services → tận dụng 1 DX link duy nhất, mở rộng multi-Region/global, phù hợp kiến thức AWS cập nhật 2026 (DXGW hỗ trợ lên đến 20 VPCs/10 Regions, public prefixes dynamic).

🔍 Phân tích tất cả các phương án

  • Phương án 1: Create a Direct Connect gateway in the Region that is closest to the data center. Attach the Direct Connect connection to the Direct Connect gateway. Use the Direct Connect gateway to connect the VPCs in the other two Regions.
    ✅ Đúng. DXGW cho phép 1 private VIF (từ DX connection) propagate routes đến VPCs ở Region khác (B và C) qua associations. Không cần thêm DX links, least cost (~0.02$/GB ingress/egress + port-hour fees cố định). Hoàn hảo cho private access đến EC2 cross-Region.

  • Phương án 2: Set up additional Direct Connect connections from the on-premises data center to the other two Regions.
    ❌ Sai. Yêu cầu 3 DX connections riêng (1 cho mỗi Region), chi phí cao (dedicated port 1/10Gbps ~$0.03/GB + setup fees/hardware). Không least cost, vi phạm yêu cầu.

  • Phương án 3: Create a private VIF. Establish an AWS Site-to-Site VPN connection over the private VIF to the VPCs in the other two Regions.
    ❌ Sai. Private VIF chỉ route VPC CIDRs (private), không hỗ trợ IPsec VPN overlay trực tiếp đến VPCs khác Region (VPN cần Virtual Private Gateway + internet/DX underlay riêng). Phức tạp, latency cao, không mở rộng cross-Region hiệu quả, cost cao hơn DXGW.

  • Phương án 4: Create a public VIF. Establish an AWS Site-to-Site VPN connection over the public VIF to the VPCs in the other two Regions.
    ✅ Đúng (phần cốt lõi). Public VIF trên DX connection advertise AWS public IP prefixes (S3, EC2 public endpoints, v.v.) qua BGP → on-premises access public services private path, low jitter/cost (không data out fees như internet). Phần VPN không chuẩn (public VIF không dùng VPN cho VPC private), nhưng overall enable public access với least cost trên DX existing. Lưu ý: Không cần VPN vì public VIF route trực tiếp.

  • Phương án 5: Use VPC peering to establish a connection between the VPCs across the Regions Create a private VIF with the existing Direct Connect connection to connect to the peered VPCs.
    ❌ Sai. VPC peering không hỗ trợ cross-Region trực tiếp (chỉ same Region hoặc dùng Transit Gateway). Thêm Transit Gateway (~$0.02/hour/VPC + data fees) phức tạp/cost cao. Private VIF chỉ connect 1 VPC (Region A), không propagate qua peering cross-Region.

📘 Tài liệu tham khảo (AWS Docs cập nhật 2026)

Giải pháp này optimized, scalable cho hybrid multi-Region! 🚀 Nếu cần lab thực hành, dùng AWS Console DX section.

Câu 892 Chọn nhiều đáp án
A company is using an organization in AWS Organizations to manage hundreds of AWS accounts. A solutions architect is working on a solution to provide baseline protection for the Open Web Application Security Project (OWASP) top 10 web application vulnerabilities. The solutions architect is using AWS WAF for all existing and new Amazon CloudFront distributions that are deployed within the organization.

Which combination of steps should the solutions architect take to provide the baseline protection? (Choose three.)
  1. A Enable AWS Config in all accounts
  2. B Enable Amazon GuardDuty in all accounts
  3. C Enable all features for the organization
  4. D Use AWS Firewall Manager to deploy AWS WAF rules in all accounts for all CloudFront distributions
  5. E Use AWS Shield Advanced to deploy AWS WAF rules in all accounts for all CloudFront distributions
  6. F Use AWS Security Hub to deploy AWS WAF rules in all accounts for all CloudFront distributions
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai bảo vệ cơ bản (baseline protection) cho các lỗ hổng web ứng dụng hàng đầu theo OWASP Top 10 (các mối đe dọa phổ biến như SQL injection, XSS, CSRF, v.v.) trong một tổ chức AWS Organizations quản lý hàng trăm tài khoản AWS. Giải pháp sử dụng AWS WAF (Web Application Firewall) cho tất cả Amazon CloudFront distributions hiện có và mới được triển khai.

📌 Mục tiêu chính: Solutions Architect cần chọn kết hợp 3 bước để triển khai AWS WAF một cách tập trung, tự động và nhất quán trên toàn tổ chức, đảm bảo bảo vệ baseline cho OWASP Top 10 (AWS WAF hỗ trợ managed rule groups dành riêng cho OWASP Top 10 từ phiên bản mới nhất 2024-2026).

🛠️ Bối cảnh kỹ thuật:

  • AWS Organizations giúp quản lý đa tài khoản.
  • AWS WAF tích hợp với CloudFront để chặn traffic độc hại.
  • Cần công cụ tập trung để áp dụng rules WAF cho tất cả accounts và distributions mà không cần cấu hình thủ công từng nơi.
  • Kiến thức cập nhật đến 2026: AWS Firewall Manager (FMS) là dịch vụ chính để quản lý WAF centrally trong Organizations, hỗ trợ OWASP rulesets mới nhất (ví dụ: Core Rule Set - CRS v4.0 với OWASP coverage).

✅ Đáp án đúng (Chọn 3)

Các đáp án đúng là:

  • Enable AWS Config in all accounts
  • Enable all features for the organization
  • Use AWS Firewall Manager to deploy AWS WAF rules in all accounts for all CloudFront distributions

Lý do lựa chọn:

  • Kết hợp này đảm bảo triển khai tự động, giám sát và tuân thủ AWS WAF trên toàn tổ chức:
    • Enable all features kích hoạt chế độ đầy đủ cho Organizations (bao gồm delegated administrator cho FMS).
    • AWS Firewall Manager deploy rules WAF (bao gồm OWASP Top 10 managed rules) cho tất cả CloudFront distributions.
    • AWS Config ghi nhận và kiểm tra compliance của configurations WAF trên mọi accounts, đảm bảo baseline protection lâu dài.
  • Đây là best practice theo AWS Well-Architected Framework (Security Pillar, 2026 edition), hỗ trợ scale cho hàng trăm accounts mà không cần scripting thủ công.

📋 Giải thích chi tiết tất cả các phương án

  • ✅ Enable AWS Config in all accounts
    Đúng. AWS Config (cập nhật 2026 với advanced compliance rules) được kích hoạt trên tất cả accounts để ghi nhận thay đổi cấu hình CloudFront/WAF, kiểm tra rules có được áp dụng đúng (ví dụ: conformance packs cho WAF-OWASP). Nó cung cấp baseline monitoring, phát hiện drift và báo cáo compliance trung tâm qua Organizations. Không có nó, khó đảm bảo rules được enforce liên tục.

  • ❌ Enable Amazon GuardDuty in all accounts
    Sai. Amazon GuardDuty (phiên bản Malware Protection 2026) là dịch vụ phát hiện threat intelligence (malware, reconnaissance, crypto mining) từ logs CloudTrail/VPC Flow Logs/DNS. Nó không liên quan đến việc deploy hoặc quản lý WAF rules cho OWASP Top 10 trên CloudFront, chỉ là detection chứ không phải prevention baseline.

  • ✅ Enable all features for the organization
    Đúng. Trong AWS Organizations, phải enable all features (chế độ đầy đủ, không chỉ consolidated billing) để kích hoạt delegated administrator cho các dịch vụ như Firewall Manager. Không có bước này, FMS không thể quản lý WAF cross-account (tài liệu AWS 2026 xác nhận yêu cầu bắt buộc cho FMS policies).

  • ✅ Use AWS Firewall Manager to deploy AWS WAF rules in all accounts for all CloudFront distributions
    Đúng. AWS Firewall Manager (FMS, hỗ trợ WAF v2.0+ năm 2026) là dịch vụ trung tâm để tạo security policies áp dụng WAF rules (OWASP Top 10 managed rulesets) tự động cho tất cả CloudFront distributions hiện có/mới trong Organizations. Hoàn hảo cho scale lớn, hỗ trợ auto-remediation.

  • ❌ Use AWS Shield Advanced to deploy AWS WAF rules in all accounts for all CloudFront distributions
    Sai. AWS Shield Advanced (2026 với proactive engagement) bảo vệ DDoS và tích hợp WAF, nhưng không deploy WAF rules centrally như FMS. Nó yêu cầu subscription riêng/account và tập trung vào mitigation DDoS, không phải baseline OWASP cho tất cả distributions.

  • ❌ Use AWS Security Hub to deploy AWS WAF rules in all accounts for all CloudFront distributions
    Sai. AWS Security Hub (2026 với ASFF v2 và custom insights) tổng hợp findings từ GuardDuty/Config/WAF, hỗ trợ compliance checks, nhưng không deploy rules WAF. Nó chỉ monitor/aggregate, không phải công cụ quản lý/deploy policies cross-account.

📘 Tài liệu tham khảo (Cập nhật AWS 2026)

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ code Terraform/CloudFormation, hãy hỏi nhé!

Câu 893 Chọn nhiều đáp án
A solutions architect has implemented a SAML 2.0 federated identity solution with their company's on-premises identity provider (IdP) to authenticate users' access to the AWS environment. When the solutions architect tests authentication through the federated identity web portal, access to the AWS environment is granted. However, when test users attempt to authenticate through the federated identity web portal, they are not able to access the AWS environment.

Which items should the solutions architect check to ensure identity federation is properly configured? (Choose three.)
  1. A The IAM user's permissions policy has allowed the use of SAML federation for that user.
  2. B The IAM roles created for the federated users' or federated groups' trust policy have set the SAML provider as the principal.
    B. Test users are not in the AWSFederatedUsers group in the company's IdP.
  3. C The web portal calls the AWS STS AssumeRoleWithSAML API with the ARN of the SAML provider, the ARN of the IAM role, and the SAML assertion from IdP.
  4. D The on-premises IdP's DNS hostname is reachable from the AWS environment VPCs.
  5. E The company's IdP defines SAML assertions that properly map users or groups. In the company to IAM roles with appropriate permissions.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi này xoay quanh vấn đề xác thực liên kết danh tính SAML 2.0 giữa IdP (Identity Provider) on-premises của công ty và môi trường AWS. Một solutions architect đã triển khai giải pháp này thành công khi test cá nhân qua cổng web liên kết danh tính (federated identity web portal), nhưng các test users khác lại không thể truy cập AWS.

📌 Tình huống chính:

  • Auth thành công cho architect (có lẽ architect có quyền hoặc mapping đặc biệt).
  • Test users thất bại → Cần kiểm tra cấu hình federation để đảm bảo tất cả users đều hoạt động đúng.
  • Yêu cầu chọn 3 items cần kiểm tra, tập trung vào các yếu tố liên quan đến trust policy của IAM role, SAML assertion từ IdP, và cách gọi API STS.

🛠️ Kiến thức cốt lõi (cập nhật AWS 2026): SAML federation với AWS sử dụng IAM roles (không phải IAM users), nơi IdP gửi SAML assertion chứa role ARN để STS AssumeRoleWithSAML cấp temporary credentials. Lỗi thường gặp: mapping attributes sai, trust policy không đúng principal, hoặc gọi API sai params. (Không liên quan đến IAM user policy hay network từ VPC đến IdP).

✅ Đáp án đúng (Chọn 3)

Dựa trên best practices AWS IAM Federation (phiên bản mới nhất 2026), các items cần kiểm tra là:

  • The IAM roles created for the federated users' or federated groups' trust policy have set the SAML provider as the principal. ✅ (Trust policy phải chỉ định SAML provider ARN làm trusted entity).
  • The web portal calls the AWS STS AssumeRoleWithSAML API with the ARN of the SAML provider, the ARN of the IAM role, and the SAML assertion from IdP. ✅ (API call phải đúng params để exchange assertion lấy credentials).
  • The company's IdP defines SAML assertions that properly map users or groups in the company to IAM roles with appropriate permissions. ✅ (IdP phải encode role ARN vào assertion attributes để match IAM role).

Lý do chọn: Architect test OK → Cấu hình cơ bản đúng, nhưng test users fail → Vấn đề ở mapping user/group đến role (assertion), trust policy principal, và API call params (có thể web portal xử lý khác cho users). Những cái này là root cause phổ biến theo AWS troubleshooting guide.

📋 Giải thích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Tôi đánh dấu ✅ (đúng - cần kiểm tra) hoặc ❌ (sai - không liên quan), kèm giải thích bằng tiếng Việt:

  • The IAM user's permissions policy has allowed the use of SAML federation for that user.
    ❌ Sai: SAML federation sử dụng IAM roles để assume, không phải IAM users trực tiếp. Không có IAM user permissions policy nào cho phép "SAML federation" – đây là nhầm lẫn cơ bản. Architect test OK chứng tỏ không phải vấn đề này.

  • The IAM roles created for the federated users' or federated groups' trust policy have set the SAML provider as the principal.
    ✅ Đúng: Trust policy của IAM role bắt buộc phải set Principal là ARN của SAML provider (e.g., arn:aws:iam::account:saml-provider/MyIdP). Nếu sai, STS từ chối assume role cho tất cả users, nhưng architect OK → Có thể principal đúng nhưng mapping cụ thể fail.

  • Test users are not in the AWSFederatedUsers group in the company's IdP.
    ❌ Sai: AWS không yêu cầu group cụ thể như "AWSFederatedUsers" trong IdP. Federation dựa vào SAML attributes mapping (e.g., https://aws.amazon.com/SAML/Attributes/Role), không phụ thuộc group name. Đây là lựa chọn đánh lừa.

  • The web portal calls the AWS STS AssumeRoleWithSAML API with the ARN of the SAML provider, the ARN of the IAM role, and the SAML assertion from IdP.
    ✅ Đúng: Web portal (SP - Service Provider) phải gọi AssumeRoleWithSAML với đúng 3 params: SAMLProviderArn, RoleArn (từ assertion), và SAMLAssertion (Base64 encoded từ IdP). Nếu portal lấy RoleArn sai (dựa trên user), test users fail.

  • The on-premises IdP's DNS hostname is reachable from the AWS environment VPCs.
    ❌ Sai: Flow SAML là browser-based (user → IdP → AWS STS qua web portal), không yêu cầu AWS VPC connect trực tiếp đến IdP DNS. IdP on-premises chỉ cần reachable từ user browser, không từ VPC.

  • The company's IdP defines SAML assertions that properly map users or groups in the company to IAM roles with appropriate permissions.
    ✅ Đúng: IdP phải inject Role attribute vào SAML assertion (e.g., https://aws.amazon.com/SAML/Attributes/Role: arn:aws:iam::account:role/MyRole). Nếu mapping user/group sai, assertion không match role → Test users (khác architect) fail access.

📘 Tài liệu tham khảo

Hy vọng phân tích này giúp bạn nắm vững! 🚀 Nếu cần demo code Terraform/CloudFormation cho SAML setup, hỏi nhé!

Câu 894
A solutions architect needs to improve an application that is hosted in the AWS Cloud. The application uses an Amazon Aurora MySQL DB instance that is experiencing overloaded connections. Most of the application’s operations insert records into the database. The application currently stores credentials in a text-based configuration file.

The solutions architect needs to implement a solution so that the application can handle the current connection load. The solution must keep the credentials secure and must provide the ability to rotate the credentials automatically on a regular basis.

Which solution will meet these requirements?
  1. A Deploy an Amazon RDS Proxy layer. In front of the DB instance. Store the connection credentials as a secret in AWS Secrets Manager.
  2. B Deploy an Amazon RDS Proxy layer in front of the DB instance. Store the connection credentials in AWS Systems Manager Parameter Store
  3. C Create an Aurora Replica. Store the connection credentials as a secret in AWS Secrets Manager
  4. D Create an Aurora Replica. Store the connection credentials in AWS Systems Manager Parameter Store.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một ứng dụng chạy trên AWS Cloud sử dụng Amazon Aurora MySQL DB instance đang gặp vấn đề overloaded connections (quá tải kết nối). Hầu hết hoạt động của ứng dụng là insert records (chèn dữ liệu), và hiện tại credentials (tài khoản truy cập DB) được lưu trong file cấu hình text đơn giản, không an toàn.

Yêu cầu giải pháp chính (phải đáp ứng TẤT CẢ):

  • Xử lý được tải kết nối hiện tại (giảm overload connections).
  • Giữ credentials an toàn (secure).
  • Tự động rotate credentials định kỳ (xoay vòng mật khẩu tự động).

🛠️ Vấn đề cốt lõi: Cần connection pooling để tái sử dụng kết nối (phù hợp với workload insert-heavy), kết hợp lưu trữ credentials an toàn với tính năng rotate tự động. Giải pháp phải áp dụng kiến thức AWS mới nhất (tính đến 2026), nơi Amazon RDS Proxy hỗ trợ Aurora MySQL với tích hợp sâu Secrets Manager cho rotation.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Deploy an Amazon RDS Proxy layer. In front of the DB instance. Store the connection credentials as a secret in AWS Secrets Manager.

Lý do chi tiết:

  • RDS Proxy là lớp proxy chuyên dụng cho RDS/Aurora, cung cấp connection pooling (m pooling kết nối), multiplexing (tái sử dụng kết nối nhanh), giảm overload connections hiệu quả cho workload insert-heavy (viết dữ liệu). Proxy đặt in front of DB instance để ứng dụng kết nối qua proxy thay vì trực tiếp.
  • AWS Secrets Manager lưu credentials dưới dạng secret, mã hóa an toàn (KMS), và tự động rotate định kỳ (hỗ trợ Aurora MySQL với Lambda rotator tích hợp sẵn). RDS Proxy tích hợp native với Secrets Manager để fetch và rotate credentials mà không downtime.
  • Giải pháp này đáp ứng 100% yêu cầu: Xử lý load, secure, auto-rotate. ✅ Hoàn hảo theo best practice AWS 2026.

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá dựa trên khả năng đáp ứng connection load, secure credentials, và auto-rotate.

  • Deploy an Amazon RDS Proxy layer. In front of the DB instance. Store the connection credentials as a secret in AWS Secrets Manager.
    ✅ ĐÚNG (như đã giải thích ở trên). RDS Proxy giải quyết overload connections hoàn hảo 🛠️, Secrets Manager đảm bảo secure + auto-rotate (hỗ trợ rotation cho Aurora MySQL mà không cần code custom). Best practice AWS!

  • Deploy an Amazon RDS Proxy layer in front of the DB instance. Store the connection credentials in AWS Systems Manager Parameter Store.
    ❌ SAI. RDS Proxy đúng giúp connection pooling, nhưng AWS Systems Manager Parameter Store (SSM Parameter Store) chỉ lưu SecureString mã hóa cơ bản, KHÔNG hỗ trợ auto-rotate tự động cho DB credentials (phải custom Lambda thủ công, phức tạp và không native). Không đáp ứng yêu cầu rotate định kỳ! 🚫

  • Create an Aurora Replica. Store the connection credentials as a secret in AWS Secrets Manager.
    ❌ SAI. Aurora Replica là read replica (chỉ scale read queries), KHÔNG giúp overload connections cho insert-heavy workload (viết dữ liệu vẫn đổ dồn vào primary). Secrets Manager đúng cho secure + rotate, nhưng không giải quyết vấn đề chính (connection pooling). Sai hướng! 🔄

  • Create an Aurora Replica. Store the connection credentials in AWS Systems Manager Parameter Store.
    ❌ SAI toàn diện. Aurora Replica không xử lý connection overload cho writes ❌, SSM Parameter Store thiếu auto-rotate 🚫. Kết hợp hai điểm yếu, hoàn toàn không đáp ứng yêu cầu. Tránh xa!

🧩 Kết luận: Chỉ phương án đầu tiên kết hợp RDS Proxy (pooling) + Secrets Manager (secure + rotate) mới là giải pháp tối ưu, scalable theo AWS Well-Architected Framework. Nếu implement, cấu hình RDS Proxy target group với Secrets Manager ARN để auto-rotate seamless! 🚀

Câu 895
A company needs to build a disaster recovery (DR) solution for its ecommerce website. The web application is hosted on a fleet of t3.large Amazon EC2 instances and uses an Amazon RDS for MySQL DB instance. The EC2 instances are in an Auto Scaling group that extends across multiple Availability Zones.

In the event of a disaster, the web application must fail over to the secondary environment with an RPO of 30 seconds and an RTO of 10 minutes.

Which solution will meet these requirements MOST cost-effectively?
  1. A Use infrastructure as code (IaC) to provision the new infrastructure in the DR Region. Create a cross-Region read replica for the DB instance. Set up a backup plan in AWS Backup to create cross-Region backups for the EC2 instances and the DB instance. Create a cron expression to back up the EC2 instances and the DB instance every 30 seconds to the DR Region. Recover the EC2 instances from the latest EC2 backup. Use an Amazon Route 53 geolocation routing policy to automatically fail over to the DR Region in the event of a disaster.
  2. B Use infrastructure as code (IaC) to provision the new infrastructure in the DR Region. Create a cross-Region read replica for the DB instance. Set up AWS Elastic Disaster Recovery to continuously replicate the EC2 instances to the DR Region. Run the EC2 instances at the minimum capacity in the DR Region. Use an Amazon Route 53 failover routing policy to automatically fail over to the DR Region in the event of a disaster. Increase the desired capacity of the Auto Scaling group.
  3. C Set up a backup plan in AWS Backup to create cross-Region backups for the EC2 instances and the DB instance. Create a cron expression to back up the EC2 instances and the DB instance every 30 seconds to the DR Region. Use infrastructure as code (IaC) to provision the new infrastructure in the DR Region. Manually restore the backed-up data on new instances. Use an Amazon Route 53 simple routing policy to automatically fail over to the DR Region in the event of a disaster.
  4. D Use infrastructure as code (IaC) to provision the new infrastructure in the DR Region. Create an Amazon Aurora global database. Set up AWS Elastic Disaster Recovery to continuously replicate the EC2 instances to the DR Region. Run the Auto Scaling group of EC2 instances at full capacity in the DR Region. Use an Amazon Route 53 failover routing policy to automatically fail over to the DR Region in the event of a disaster.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi trắc nghiệm AWS Disaster Recovery (DR)

✅ Nội dung câu hỏi được giải thích rõ ràng:
Câu hỏi yêu cầu xây dựng giải pháp phục hồi sau thảm họa (Disaster Recovery - DR) cho một website thương mại điện tử (ecommerce). Ứng dụng web chạy trên nhóm EC2 t3.large trong Auto Scaling Group (ASG) trải rộng nhiều Availability Zones (AZ), và cơ sở dữ liệu là Amazon RDS for MySQL.
Yêu cầu chính:

  • Trong trường hợp thảm họa, ứng dụng phải chuyển đổi (failover) sang môi trường phụ (DR Region) với:
    • RPO (Recovery Point Objective) = 30 giây: Mất dữ liệu tối đa chỉ 30 giây (nghĩa là dữ liệu phải được sao chép liên tục gần như real-time).
    • RTO (Recovery Time Objective) = 10 phút: Thời gian khôi phục toàn bộ hệ thống không quá 10 phút.
  • Giải pháp phải tiết kiệm chi phí nhất (MOST cost-effectively).
    🛠️ Thách thức chính: Cần sao chép dữ liệu EC2 và RDS cross-Region với RPO thấp, failover tự động nhanh chóng, nhưng tránh chi phí cao như chạy full capacity ở DR Region (ví dụ: warm standby hoặc pilot light thay vì hot standby).

🎯 Đáp án đúng: Phương án thứ 2 (B)
Use infrastructure as code (IaC) to provision the new infrastructure in the DR Region. Create a cross-Region read replica for the DB instance. Set up AWS Elastic Disaster Recovery to continuously replicate the EC2 instances to the DR Region. Run the EC2 instances at the minimum capacity in the DR Region. Use an Amazon Route 53 failover routing policy to automatically fail over to the DR Region in the event of a disaster. Increase the desired capacity of the Auto Scaling group.

📈 Lý do chọn đáp án này (tiết kiệm chi phí nhất, đạt RPO/RTO):

  • IaC (như CloudFormation hoặc Terraform): Tự động provision infra DR nhanh chóng, giảm thời gian setup thủ công (hỗ trợ RTO).
  • Cross-Region read replica cho RDS MySQL: Sao chép dữ liệu DB liên tục với lag thấp (<30 giây, thường ~1 giây), dễ promote thành primary khi failover.
  • AWS Elastic Disaster Recovery (DRS - trước là CloudEndure): Sao chép block-level liên tục EC2 cross-Region với RPO ~giây, hỗ trợ launch nhanh ở DR (RTO <10 phút).
  • Chạy EC2 ở minimum capacity (pilot light): Tiết kiệm chi phí (chỉ chạy ASG nhỏ ở DR, scale up khi cần bằng tăng desired capacity).
  • Route 53 failover routing: Tự động detect healthy check và switch DNS sang DR trong vài phút.
    ✅ Tổng hợp: Đạt RPO 30s (DRS + replica), RTO 10 phút (tăng capacity ASG + promote replica ~2-5 phút), cost-effective nhất nhờ minimum capacity thay vì full/hot.

📋 Phân tích TẤT CẢ các phương án (đúng/sai)

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Tôi đánh dấu ✅ Đúng hoặc ❌ Sai dựa trên yêu cầu RPO/RTO và cost-effectiveness (dữ liệu AWS cập nhật 2026: DRS hỗ trợ EC2 replication real-time, RDS MySQL cross-region replica lag thấp).

  • ❌ Phương án 1 (Sai - Không đạt RPO/RTO, không khả thi):
    Use infrastructure as code (IaC) to provision the new infrastructure in the DR Region. Create a cross-Region read replica for the DB instance. Set up a backup plan in AWS Backup to create cross-Region backups for the EC2 instances and the DB instance. Create a cron expression to back up the EC2 instances and the DB instance every 30 seconds to the DR Region. Recover the EC2 instances from the latest EC2 backup. Use an Amazon Route 53 geolocation routing policy to automatically fail over to the DR Region in the event of a disaster.
    🧨 Lý do sai: Backup AWS Backup (EBS snapshots hoặc DB) không hỗ trợ cron every 30 giây (tối thiểu hàng giờ, và snapshot EC2 mất ~15-30 phút), dẫn đến RPO >30s. Recovery từ backup thủ công chậm (RTO >10 phút). Route 53 geolocation không phải failover tự động (dựa vị trí user, không detect disaster). Cross-replica DB tốt nhưng EC2 kém.

  • ✅ Phương án 2 (Đúng - Tối ưu nhất):
    Use infrastructure as code (IaC) to provision the new infrastructure in the DR Region. Create a cross-Region read replica for the DB instance. Set up AWS Elastic Disaster Recovery to continuously replicate the EC2 instances to the DR Region. Run the EC2 instances at the minimum capacity in the DR Region. Use an Amazon Route 53 failover routing policy to automatically fail over to the DR Region in the event of a disaster. Increase the desired capacity of the Auto Scaling group.
    🛠️ Lý do đúng: Như đã giải thích ở trên, continuous replication của DRS đảm bảo RPO thấp, minimum capacity tiết kiệm (pilot light model), failover tự động nhanh.

  • ❌ Phương án 3 (Sai - Không tự động, RTO cao):
    Set up a backup plan in AWS Backup to create cross-Region backups for the EC2 instances and the DB instance. Create a cron expression to back up the EC2 instances and the DB instance every 30 seconds to the DR Region. Use infrastructure as code (IaC) to provision the new infrastructure in the DR Region. Manually restore the backed-up data on new instances. Use an Amazon Route 53 simple routing policy to automatically fail over to the DR Region in the event of a disaster.
    🧨 Lý do sai: Backup every 30s không khả thi (AWS Backup không hỗ trợ tần suất cao như vậy cho EC2/RDS). Manually restore làm RTO >10 phút (snapshot restore mất hàng giờ). Route 53 simple routing không tự động failover (chỉ static DNS).

  • ❌ Phương án 4 (Sai - Không tương thích DB, chi phí cao):
    Use infrastructure as code (IaC) to provision the new infrastructure in the DR Region. Create an Amazon Aurora global database. Set up AWS Elastic Disaster Recovery to continuously replicate the EC2 instances to the DR Region. Run the Auto Scaling group of EC2 instances at full capacity in the DR Region. Use an Amazon Route 53 failover routing policy to automatically fail over to the DR Region in the event of a disaster.
    🧨 Lý do sai: DB gốc là RDS MySQL, không phải Aurora → Aurora Global Database không áp dụng (chỉ cho Aurora MySQL/PostgreSQL, cần migrate phức tạp). Full capacity ASG ở DR tốn kém (hot standby model, chi phí gấp đôi primary), không "MOST cost-effectively". DRS và Route 53 tốt nhưng các điểm trên làm sai.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm ví dụ thực hành, hãy hỏi nhé!

Câu 896
A company is planning a one-time migration of an on-premises MySQL database to Amazon Aurora MySQL in the us-east-1 Region. The company's current internet connection has limited bandwidth. The on-premises MySQL database is 60 TB in size. The company estimates that it will take a month to transfer the data to AWS over the current internet connection. The company needs a migration solution that will migrate the database more quickly.

Which solution will migrate the database in the LEAST amount of time?
  1. A Request a 1 Gbps AWS Direct Connect connection between the on-premises data center and AWS. Use AWS Database Migration Service (AWS DMS) to migrate the on-premises MySQL database to Aurora MySQL.
  2. B Use AWS DataSync with the current internet connection to accelerate the data transfer between the on-premises data center and AWS. Use AWS Application Migration Service to migrate the on-premises MySQL database to Aurora MySQL.
  3. C Order an AWS Snowball Edge device. Load the data into an Amazon S3 bucket by using the S3 interface. Use AWS Database Migration Service (AWS DMS) to migrate the data from Amazon S3 to Aurora MySQL.
  4. D Order an AWS Snowball device. Load the data into an Amazon S3 bucket by using the S3 Adapter for Snowball. Use AWS Application Migration Service to migrate the data from Amazon S3 to Aurora MySQL.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả tình huống một công ty cần migrate một lần (one-time migration) cơ sở dữ liệu MySQL on-premises dung lượng 60 TB sang Amazon Aurora MySQL tại region us-east-1. Kết nối internet hiện tại có băng thông hạn chế, ước tính mất 1 tháng để chuyển dữ liệu qua internet thông thường. Yêu cầu là tìm giải pháp migrate nhanh nhất (LEAST amount of time), tận dụng các dịch vụ AWS để vượt qua hạn chế băng thông mạng.

Điểm chính cần lưu ý:

  • Dung lượng lớn (60 TB) → Không phù hợp với chuyển trực tiếp qua internet hoặc kết nối tốc độ thấp.
  • One-time migration → Không cần CDC (change data capture) liên tục, ưu tiên bulk transfer nhanh.
  • Mục tiêu: Aurora MySQL → Cần công cụ hỗ trợ DB migration như DMS, không phải VM migration.
  • Giải pháp lý tưởng: Sử dụng thiết bị vật lý ship dữ liệu (như Snow family) để tránh bottleneck mạng.

✅ Đáp án đúng

Order an AWS Snowball Edge device. Load the data into an Amazon S3 bucket by using the S3 interface. Use AWS Database Migration Service (AWS DMS) to migrate the data from Amazon S3 to Aurora MySQL.

Lý do lựa chọn:

  • 🛠️ AWS Snowball Edge là thiết bị di động có dung lượng lưu trữ lớn (lên đến 210 TB với model Storage Optimized mới nhất 2024-2026), phù hợp hoàn hảo cho 60 TB dữ liệu. Nó có S3 interface onboard cho phép load dữ liệu trực tiếp như S3 local, không cần adapter phức tạp.
  • 📦 Quy trình: Export DB dump từ MySQL on-premises → Load vào Snowball Edge qua S3 interface → Ship về AWS → Tự động upload vào S3 bucket.
  • 🔄 AWS DMS hỗ trợ S3 làm source (từ AWS 2018+, cập nhật 2026 vẫn giữ), migrate full-load từ file S3 (như MySQL dump) sang Aurora MySQL. Thời gian migrate chỉ vài giờ sau khi data đến AWS, tổng thời gian ~1 tuần (ship đi/về).
  • ⏱️ Nhanh nhất: Tránh hoàn toàn internet upload/download lớn, chỉ ship vật lý (2-5 ngày mỗi chiều).

❌ Giải thích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai với lý do cụ thể dựa trên tính khả thi, tốc độ và tính tương thích (kiến thức AWS 2026).

  • [SAI] Request a 1 Gbps AWS Direct Connect connection between the on-premises data center and AWS. Use AWS Database Migration Service (AWS DMS) to migrate the on-premises MySQL database to Aurora MySQL.
    ❌ Sai vì vẫn chậm: Direct Connect 1 Gbps (125 MB/s) mất ~20 ngày cho 60 TB (tính toán: 60 TB / 125 MB/s ≈ 500 giờ). DMS hỗ trợ MySQL → Aurora nhưng bottleneck là transfer qua Direct Connect hosted (cần setup 1-2 tuần). Không phải "LEAST time" so với ship vật lý.

  • [SAI] Use AWS DataSync with the current internet connection to accelerate the data transfer between the on-premises data center and AWS. Use AWS Application Migration Service to migrate the on-premises MySQL database to Aurora MySQL.
    ❌ Sai vì không tương thích và vẫn chậm: DataSync accelerate transfer (parallel + compression) nhưng vẫn phụ thuộc internet hạn chế (ước tính vẫn ~1 tháng). Application Migration Service (MGN) dành cho VM/app lift-and-shift, KHÔNG hỗ trợ DB migration như MySQL → Aurora (chỉ block-level replication cho servers).

  • [ĐÚNG] Order an AWS Snowball Edge device. Load the data into an Amazon S3 bucket by using the S3 interface. Use AWS Database Migration Service (AWS DMS) to migrate the data from Amazon S3 to Aurora MySQL.
    ✅ Đúng như phân tích trên: Snowball Edge + S3 interface + DMS là combo tối ưu cho large-scale, one-time DB migration. DMS từ S3 hỗ trợ MySQL-compatible format (dump files).

  • [SAI] Order an AWS Snowball device. Load the data into an Amazon S3 bucket by using the S3 Adapter for Snowball. Use AWS Application Migration Service to migrate the data from Amazon S3 to Aurora MySQL.
    ❌ Sai vì thiết bị và công cụ không phù hợp: Snowball (classic) dung lượng max 50 TB (không đủ 60 TB, cần multiple jobs phức tạp). S3 Adapter đúng nhưng Application Migration Service (MGN) không migrate từ S3 sang DB (chỉ VM/block storage, không hỗ trợ DB restore từ S3).

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Giải pháp này đảm bảo DevOps best practices: Minimize downtime, scalable, cost-effective cho large data! 🚀

Câu 897
A company has an application in the AWS Cloud. The application runs on a fleet of 20 Amazon EC2 instances. The EC2 instances are persistent and store data on multiple attached Amazon Elastic Block Store (Amazon EBS) volumes.

The company must maintain backups in a separate AWS Region. The company must be able to recover the EC2 instances and their configuration within 1 business day, with loss of no more than 1 day's worth of data. The company has limited staff and needs a backup solution that optimizes operational efficiency and cost. The company already has created an AWS CloudFormation template that can deploy the required network configuration in a secondary Region.

Which solution will meet these requirements?
  1. A Create a second CloudFormation template that can recreate the EC2 instances in the secondary Region. Run daily multivolume snapshots by using AWS Systems Manager Automation runbooks. Copy the snapshots to the secondary Region. In the event of a failure launch the CloudFormation templates, restore the EBS volumes from snapshots, and transfer usage to the secondary Region.
  2. B Use Amazon Data Lifecycle Manager (Amazon DLM) to create daily multivolume snapshots of the EBS volumes. In the event of a failure, launch the CloudFormation template and use Amazon DLM to restore the EBS volumes and transfer usage to the secondary Region.
  3. C Use AWS Backup to create a scheduled daily backup plan for the EC2 instances. Configure the backup task to copy the backups to a vault in the secondary Region. In the event of a failure, launch the CloudFormation template, restore the instance volumes and configurations from the backup vault, and transfer usage to the secondary Region.
  4. D Deploy EC2 instances of the same size and configuration to the secondary Region. Configure AWS DataSync daily to copy data from the primary Region to the secondary Region. In the event of a failure, launch the CloudFormation template and transfer usage to the secondary Region.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một ứng dụng chạy trên 20 instance Amazon EC2 persistent (không phải Spot hay tạm thời), lưu trữ dữ liệu trên nhiều EBS volumes. Công ty cần:

  • Backup lưu trữ ở Region riêng biệt (cross-Region).
  • Thời gian khôi phục (RTO): Trong vòng 1 ngày làm việc (1 business day).
  • Mức mất dữ liệu tối đa (RPO): Không quá 1 ngày dữ liệu → Yêu cầu backup hàng ngày.
  • Yêu cầu khác: Nhân sự hạn chế → Giải pháp phải tối ưu hiệu quả vận hành (ít can thiệp thủ công). Tối ưu chi phí. Đã có AWS CloudFormation template để deploy network config ở secondary Region.

Mục tiêu: Giải pháp backup toàn diện (bao gồm EC2 config + EBS data), tự động, cross-Region, dễ restore, phù hợp DevOps với automation cao. ✅ Phiên bản AWS mới nhất (2026): AWS Backup hỗ trợ backup EC2 full (instance config + EBS), cross-Region copy vault, lifecycle policies tối ưu cost.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use AWS Backup to create a scheduled daily backup plan for the EC2 instances. Configure the backup task to copy the backups to a vault in the secondary Region. In the event of a failure, launch the CloudFormation template, restore the instance volumes and configurations from the backup vault, and transfer usage to the secondary Region.

Lý do 🛠️:

  • AWS Backup là dịch vụ centralized backup (từ 2019, cập nhật 2026 hỗ trợ EC2 full-fidelity: AMI + EBS snapshots + metadata config).
  • Tự động daily backup → Đáp ứng RPO 1 ngày.
  • Cross-Region copy trực tiếp vào backup vault ở secondary Region (tích hợp KMS encryption).
  • Restore dễ dàng: Khôi phục volumes/config từ vault, kết hợp CloudFormation cho network → RTO trong 1 ngày.
  • Tối ưu ops & cost: Automation cao (ít staff), lifecycle policies (delete old backups), pay-per-use, không cần instances warm standby.
  • Hoàn hảo cho limited staff với single pane of glass management.

❌ Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá dựa trên yêu cầu RTO/RPO, cross-Region, efficiency, cost.

  • Phương án 1: Create a second CloudFormation template that can recreate the EC2 instances in the secondary Region. Run daily multivolume snapshots by using AWS Systems Manager Automation runbooks. Copy the snapshots to the secondary Region. In the event of a failure launch the CloudFormation templates, restore the EBS volumes from snapshots, and transfer usage to the secondary Region.
    ❌ Sai vì: AWS Systems Manager (SSM) Automation không phải công cụ chính cho daily multi-volume snapshots tự động (chỉ dùng cho ad-hoc tasks, không scale tốt cho 20 instances). Phải tự build runbooks phức tạp → Không tối ưu ops efficiency (staff phải maintain). Copy snapshots thủ công qua API → Lỗi-prone, tốn công. Không backup EC2 config đầy đủ (chỉ EBS data). Cost cao do custom scripting. 🛠️ SSM tốt cho remediation, không phải backup scheduler.

  • Phương án 2: Use Amazon Data Lifecycle Manager (Amazon DLM) to create daily multivolume snapshots of the EBS volumes. In the event of a failure, launch the CloudFormation template and use Amazon DLM to restore the EBS volumes and transfer usage to the secondary Region.
    ❌ Sai vì: DLM chỉ snapshot EBS volumes (không backup EC2 instance config như AMI, security groups, user data). Không hỗ trợ cross-Region copy tự động tốt (phải dùng Lambda/CLI bổ sung). Restore cần thủ công attach volumes vào new EC2 → Không đạt RTO 1 ngày, phức tạp cho limited staff. Thiếu toàn diện so với AWS Backup. 📘 DLM docs: Chỉ EBS-focused, không EC2 metadata.

  • Phương án 3 (Đúng): Use AWS Backup to create a scheduled daily backup plan for the EC2 instances. Configure the backup task to copy the backups to a vault in the secondary Region. In the event of a failure, launch the CloudFormation template, restore the instance volumes and configurations from the backup vault, and transfer usage to the secondary Region.
    ✅ Đúng hoàn hảo như giải thích ở trên. Full-stack backup (EC2 + EBS), cross-Region native, automation 100%, cost-effective với retention policies. 🧩 Kết hợp CloudFormation → Pilot light strategy tối ưu.

  • Phương án 4: Deploy EC2 instances of the same size and configuration to the secondary Region. Configure AWS DataSync daily to copy data from the primary Region to the secondary Region. In the event of a failure, launch the CloudFormation template and transfer usage to the secondary Region.
    ❌ Sai vì: DataSync chỉ sync data (EBS → EFS/NFS, không backup snapshots/config EC2). Deploy warm standby instances ở secondary Region → Tốn kém chi phí cao (always-on EC2 bills, không pay-per-use). Không phải backup mà là replication → Không đáp ứng "maintain backups", RPO chỉ nếu sync real-time (nhưng daily sync vẫn rủi ro data loss). Ops phức tạp (quản lý sync jobs). 🛠️ DataSync cho migration/sync, không DR backup.

Câu 898 Chọn nhiều đáp án
A company is designing a new website that hosts static content. The website will give users the ability to upload and download large files. According to company requirements, all data must be encrypted in transit and at rest. A solutions architect is building the solution by using Amazon S3 and Amazon CloudFront.

Which combination of steps will meet the encryption requirements? (Choose three.)
  1. A Turn on S3 server-side encryption for the S3 bucket that the web application uses.
  2. B Add a policy attribute of "aws:SecureTransport": "true" for read and write operations in the S3 ACLs.
  3. C Create a bucket policy that denies any unencrypted operations in the S3 bucket that the web application uses.
  4. D Configure encryption at rest on CloudFront by using server-side encryption with AWS KMS keys (SSE-KMS).
  5. E Configure redirection of HTTP requests to HTTPS requests in CloudFront.
  6. F Use the RequireSSL option in the creation of presigned URLs for the S3 bucket that the web application uses.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi xoay quanh việc thiết kế một website chứa nội dung tĩnh (static content) trên AWS, sử dụng Amazon S3 để lưu trữ và Amazon CloudFront làm CDN phân phối. Website cần hỗ trợ người dùng upload và download các file lớn. Yêu cầu cốt lõi: Tất cả dữ liệu phải được mã hóa (encrypted) cả khi lưu trữ (at rest) và khi truyền tải (in transit).
Solutions Architect phải chọn kết hợp 3 bước để đáp ứng yêu cầu này.
🔑 Mục tiêu chính:

  • Encryption at rest: Mã hóa dữ liệu trên S3.
  • Encryption in transit: Buộc sử dụng HTTPS cho mọi truy cập (qua CloudFront hoặc trực tiếp S3).
    Kiến thức AWS cập nhật đến 2026: S3 hỗ trợ Server-Side Encryption (SSE-S3 hoặc SSE-KMS) mặc định từ 2023, CloudFront bắt buộc HTTPS viewer policy, và bucket policy để deny HTTP.

✅ Đáp án đúng (Chọn 3 phương án sau)

Các phương án đúng đảm bảo mã hóa đầy đủ: SSE cho at rest trên S3, bucket policy deny unencrypted cho S3 direct access, và CloudFront redirect HTTP sang HTTPS cho transit qua CDN.
Lý do chọn:

  • Chúng trực tiếp giải quyết cả at rest (S3 SSE) và in transit (deny unencrypted + HTTPS redirect).
  • Phù hợp best practice AWS: Kết hợp bucket-level encryption, policy enforcement, và CloudFront security.

🛠️ Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Tôi đánh dấu ✅ (đúng) hoặc ❌ (sai), kèm giải thích lý do bằng tiếng Việt dựa trên tài liệu AWS mới nhất.

  • Turn on S3 server-side encryption for the S3 bucket that the web application uses.
    ✅ Đúng. Bước này kích hoạt Server-Side Encryption (SSE-S3 hoặc SSE-KMS) trên bucket S3, đảm bảo tất cả object được mã hóa tự động khi lưu trữ (at rest). Từ 2023, AWS khuyến nghị bucket default encryption (SSE-S3 miễn phí). Không ảnh hưởng transit.

  • Add a policy attribute of "aws:SecureTransport": "true" for read and write operations in the S3 ACLs.
    ❌ Sai. S3 ACLs đã deprecated từ 2023 (chuyển sang bucket/iam policies). Attibute "aws:SecureTransport" chỉ dùng trong bucket policy, không phải ACL. Sử dụng ACL sẽ lỗi và không enforce HTTPS hiệu quả.

  • Create a bucket policy that denies any unencrypted operations in the S3 bucket that the web application uses.
    ✅ Đúng. Bucket policy với điều kiện "aws:SecureTransport": "true" deny mọi s3:GetObject/PutObject qua HTTP (in transit). Bước này bảo vệ truy cập trực tiếp S3, bổ sung cho CloudFront. Best practice cho compliance.

  • Configure encryption at rest on CloudFront by using server-side encryption with AWS KMS keys (SSE-KMS).
    ❌ Sai. CloudFront không hỗ trợ SSE-KMS at rest cho edge cache (tính đến 2026). Cache của CloudFront được mã hóa tự động bởi AWS, nhưng phụ thuộc origin (S3). Không có tùy chọn cấu hình SSE-KMS trực tiếp trên CloudFront.

  • Configure redirection of HTTP requests to HTTPS requests in CloudFront.
    ✅ Đúng. Trong CloudFront Viewer Protocol Policy, chọn "Redirect HTTP to HTTPS" buộc mọi request từ user sử dụng HTTPS (in transit). Hoàn hảo cho website public, tránh MITM attacks.

  • Use the RequireSSL option in the creation of presigned URLs for the S3 bucket that the web application uses.
    ❌ Sai. Presigned URLs không có option RequireSSL (deprecated hoặc không tồn tại). Presigned URLs mặc định dùng HTTPS endpoint, nhưng không enforce toàn bộ; dễ bypass nếu dùng HTTP endpoint. Nên dùng bucket policy thay thế.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Câu 899
A company is implementing a serverless architecture by using AWS Lambda functions that need to access a Microsoft SQL Server DB instance on Amazon RDS. The company has separate environments for development and production, including a clone of the database system.

The company's developers are allowed to access the credentials for the development database. However, the credentials for the production database must be encrypted with a key that only members of the IT security team's IAM user group can access. This key must be rotated on a regular basis.

What should a solutions architect do in the production environment to meet these requirements?
  1. A Store the database credentials in AWS Systems Manager Parameter Store by using a SecureString parameter that is encrypted by an AWS Key Management Service (AWS KMS) customer managed key. Attach a role to each Lambda function to provide access to the SecureString parameter. Restrict access to the SecureString parameter and the customer managed key so that only the IT security team can access the parameter and the key.
  2. B Encrypt the database credentials by using the AWS Key Management Service (AWS KMS) default Lambda key. Store the credentials in the environment variables of each Lambda function. Load the credentials from the environment variables in the Lambda code. Restrict access to the KMS key so that only the IT security team can access the key.
  3. C Store the database credentials in the environment variables of each Lambda function. Encrypt the environment variables by using an AWS Key Management Service (AWS KMS) customer managed key. Restrict access to the customer managed key so that only the IT security team can access the key.
  4. D Store the database credentials in AWS Secrets Manager as a secret that is associated with an AWS Key Management Service (AWS KMS) customer managed key. Attach a role to each Lambda function to provide access to the secret. Restrict access to the secret and the customer managed key so that only the IT security team can access the secret and the key.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh việc triển khai kiến trúc serverless sử dụng AWS Lambda để truy cập cơ sở dữ liệu Microsoft SQL Server trên Amazon RDS. Công ty có hai môi trường riêng biệt: development (dev) và production (prod), với bản clone của hệ thống database.

🔑 Yêu cầu cụ thể cho môi trường production:

  • Nhà phát triển (developers) được phép truy cập credentials (tài khoản/mật khẩu) của database dev.
  • Credentials của database prod phải được mã hóa bằng một khóa (key) mà chỉ nhóm IAM user của IT security team mới truy cập được.
  • Khóa này phải được rotate (xoay vòng) định kỳ để tăng cường bảo mật.
  • Lambda functions cần truy cập credentials này một cách an toàn, không hardcode trực tiếp.

🛠️ Mục tiêu của Solutions Architect: Chọn giải pháp lưu trữ và quản lý credentials cho prod sao cho:

  • An toàn, hỗ trợ mã hóa bằng AWS KMS customer managed key (CMK).
  • Hạn chế truy cập nghiêm ngặt (IAM policies).
  • Hỗ trợ rotation định kỳ cho key (và lý tưởng là cho secrets).
  • Tích hợp tốt với Lambda (qua IAM role).

📘 Kiến thức cập nhật đến 2026: Theo AWS best practices (AWS Well-Architected Framework - Security Pillar, cập nhật 2025), AWS Secrets Manager là dịch vụ chuẩn để quản lý database credentials (như RDS), hỗ trợ automatic rotation (tích hợp RDS/SQL Server), mã hóa bằng KMS CMK, và resource-based policies để restrict access. Parameter Store phù hợp hơn cho config parameters, không phải secrets động.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Store the database credentials in AWS Secrets Manager as a secret that is associated with an AWS Key Management Service (AWS KMS) customer managed key. Attach a role to each Lambda function to provide access to the secret. Restrict access to the secret and the customer managed key so that only the IT security team can access the secret and the key.

Lý do chọn đáp án này 🏆:

  • Secrets Manager chuyên quản lý secrets như DB credentials, hỗ trợ mã hóa bằng KMS CMK (customer managed key) có thể rotate định kỳ qua KMS key rotation policy (tự động 1 năm hoặc tùy chỉnh).
  • Lambda access qua IAM role với policy secretsmanager:GetSecretValue.
  • Restrict access: Sử dụng resource-based policy trên secret và key policy trên KMS CMK để chỉ cho phép IT security IAM group truy cập (ví dụ: kms:Decrypt, secretsmanager:DescribeSecret).
  • Ưu điểm vượt trội: Tích hợp automatic rotation cho RDS credentials (bao gồm SQL Server), clone secret cho dev/prod dễ dàng. Không cần code thủ công load secrets.
  • Hoàn hảo khớp yêu cầu: Dev access dev (không restrict), prod chỉ IT security + Lambda role.

📋 Giải thích tất cả các phương án (đúng/sai)

  • Phương án A ❌:
    Store the database credentials in AWS Systems Manager Parameter Store by using a SecureString parameter that is encrypted by an AWS Key Management Service (AWS KMS) customer managed key. Attach a role to each Lambda function to provide access to the SecureString parameter. Restrict access to the SecureString parameter and the customer managed key so that only the IT security team can access the parameter and the key.
    Tại sao SAI? Parameter Store (SecureString) hỗ trợ mã hóa KMS CMK và restrict access tốt (qua IAM/SSM policies), Lambda access qua ssm:GetParameter. Tuy nhiên, không hỗ trợ automatic rotation cho DB credentials (như RDS/SQL Server) – phải rotate thủ công. Không phải best practice cho secrets động, dễ kém an toàn hơn Secrets Manager (thiếu audit logs chi tiết và rotation tích hợp).

  • Phương án B ❌:
    Encrypt the database credentials by using the AWS Key Management Service (AWS KMS) default Lambda key. Store the credentials in the environment variables of each Lambda function. Load the credentials from the environment variables in the Lambda code. Restrict access to the KMS key so that only the IT security team can access the key.
    Tại sao SAI? Sử dụng default Lambda KMS key (service-linked, không customer managed) – không thể restrict chỉ IT security vì key này public cho Lambda service. Env vars không khuyến khích cho secrets (hardcode, khó rotate, expose khi debug). Không hỗ trợ rotation tự động, vi phạm nguyên tắc least privilege.

  • Phương án C ❌:
    Store the database credentials in the environment variables of each Lambda function. Encrypt the environment variables by using an AWS Key Management Service (AWS KMS) customer managed key. Restrict access to the customer managed key so that only the IT security team can access the key.
    Tại sao SAI? Env vars của Lambda có thể mã hóa bằng KMS CMK, nhưng credentials vẫn lưu trực tiếp trong function config – dễ leak (CloudWatch Logs, Lambda console). Không hỗ trợ rotation tự động, phải update function code/env thủ công (downtime). Không an toàn cho prod secrets, vi phạm security best practices.

  • Phương án D ✅: (Như đã giải thích ở trên – đáp án đúng).

📚 Tài liệu tham khảo (AWS cập nhật 2025-2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần ví dụ code IAM policy, hỏi thêm nhé!

Câu 900
An online retail company is migrating its legacy on-premises .NET application to AWS. The application runs on load-balanced frontend web servers, load-balanced application servers, and a Microsoft SQL Server database.

The company wants to use AWS managed services where possible and does not want to rewrite the application. A solutions architect needs to implement a solution to resolve scaling issues and minimize licensing costs as the application scales.

Which solution will meet these requirements MOST cost-effectively?
  1. A Deploy Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer for the web tier and for the application tier. Use Amazon Aurora PostgreSQL with Babelfish turned on to replatform the SQL Server database.
  2. B Create images of all the servers by using AWS Database Migration Service (AWS DMS). Deploy Amazon EC2 instances that are based on the on-premises imports. Deploy the instances in an Auto Scaling group behind a Network Load Balancer for the web tier and for the application tier. Use Amazon DynamoDB as the database tier.
  3. C Containerize the web frontend tier and the application tier. Provision an Amazon Elastic Kubernetes Service (Amazon EKS) cluster. Create an Auto Scaling group behind a Network Load Balancer for the web tier and for the application tier. Use Amazon RDS for SQL Server to host the database.
  4. D Separate the application functions into AWS Lambda functions. Use Amazon API Gateway for the web frontend tier and the application tier. Migrate the data to Amazon S3. Use Amazon Athena to query the data.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi xoay quanh việc di chuyển (migrate) ứng dụng .NET legacy từ on-premises sang AWS cho một công ty bán lẻ trực tuyến. Ứng dụng bao gồm:

  • Frontend web servers và application servers được load-balanced.
  • Microsoft SQL Server database làm backend.

Yêu cầu chính:

  • Sử dụng AWS managed services càng nhiều càng tốt (ví dụ: Auto Scaling, Load Balancer, managed DB).
  • KHÔNG rewrite ứng dụng (giữ nguyên code .NET hiện tại).
  • Giải quyết vấn đề scaling (tự động scale theo nhu cầu).
  • Tối ưu chi phí license nhất có thể khi scale (tránh chi phí cao của Microsoft SQL Server license).
  • Tìm giải pháp MOST cost-effectively (tiết kiệm chi phí nhất).

🛠️ Thách thức chính: Ứng dụng .NET phụ thuộc SQL Server, cần tương thích mà không rewrite, đồng thời scale linh hoạt và giảm license (SQL Server đắt đỏ khi scale lớn).

✅ Đáp án đúng

Deploy Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer for the web tier and for the application tier. Use Amazon Aurora PostgreSQL with Babelfish turned on to replatform the SQL Server database.

Lý do lựa chọn:

  • ✅ Phù hợp hoàn hảo với yêu cầu không rewrite: EC2 ASG + ALB cho web/app tier giữ nguyên .NET app trên Windows/Linux instances, scale tự động (Auto Scaling Group theo CPU/traffic).
  • ✅ Giải quyết scaling: ASG + ALB (Application Load Balancer) hỗ trợ HTTP/HTTPS, sticky sessions, path-based routing – lý tưởng cho web/app .NET.
  • ✅ Tối ưu chi phí license: Aurora PostgreSQL với Babelfish (tính năng AWS ra mắt 2023, cập nhật 2026 hỗ trợ T-SQL đầy đủ) cho phép replatform SQL Server mà không thay đổi code – app .NET kết nối như SQL Server (hỗ trợ TDS protocol, stored procedures, triggers). Không cần license Microsoft SQL Server, Aurora rẻ hơn 50-70% so với RDS SQL Server khi scale.
  • 🛠️ Managed services: Aurora là fully managed DB, Babelfish enabled qua parameter group (dễ setup).
  • Cost-effective nhất: Kết hợp lift-and-shift cho app tier (EC2 rẻ với Spot/Reserved) + replatform DB tiết kiệm license lớn khi scale.

🔍 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn. Tôi giữ nguyên văn bản gốc tiếng Anh của phương án, chỉ giải thích bằng tiếng Việt với lý do đúng/sai dựa trên best practices AWS (cập nhật 2026: Babelfish hỗ trợ SQL Server 2019+ features đầy đủ).

  • ✅ [ĐÚNG] Deploy Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer for the web tier and for the application tier. Use Amazon Aurora PostgreSQL with Babelfish turned on to replatform the SQL Server database.
    🟢 Đúng vì: Như giải thích trên – lift-and-shift app tier (EC2 ASG + ALB scale dễ), replatform DB thông minh với Babelfish (không rewrite, tiết kiệm license). Hoàn hảo cho .NET legacy, managed cao, cost thấp khi scale lớn.

  • ❌ [SAI] Create images of all the servers by using AWS Database Migration Service (AWS DMS). Deploy Amazon EC2 instances that are based on the on-premises imports. Deploy the instances in an Auto Scaling group behind a Network Load Balancer for the web tier and for the application tier. Use Amazon DynamoDB as the database tier.
    🔴 Sai vì: DMS chỉ migrate dữ liệu DB, không tạo images servers (dùng AWS Application Migration Service hoặc VM Import/Export mới đúng). NLB (Layer 4) kém phù hợp web/app HTTP (.NET cần Layer 7 như ALB). DynamoDB không compatible SQL Server (NoSQL key-value, yêu cầu rewrite queries .NET lớn) → vi phạm "không rewrite" và tốn công migrate schema.

  • ❌ [SAI] Containerize the web frontend tier and the application tier. Provision an Amazon Elastic Kubernetes Service (Amazon EKS) cluster. Create an Auto Scaling group behind a Network Load Balancer for the web tier and for the application tier. Use Amazon RDS for SQL Server to host the database.
    🔴 Sai vì: Containerize yêu cầu refactor code (.NET legacy khó containerize mà không thay đổi, tốn effort lớn). EKS + ASG + NLB phức tạp/overkill, chi phí cao (EKS ~0.10$/hour/cluster). RDS SQL Server giữ nguyên license đắt đỏ khi scale (không minimize costs). Không cost-effective nhất.

  • ❌ [SAI] Separate the application functions into AWS Lambda functions. Use Amazon API Gateway for the web frontend tier and the application tier. Migrate the data to Amazon S3. Use Amazon Athena to query the data.
    🔴 Sai vì: Serverless hóa (Lambda + API Gateway) yêu cầu rewrite toàn bộ app từ monolithic .NET sang functions (vi phạm rõ ràng "không rewrite"). S3 + Athena là object storage + query engine cho analytics, không thay thế relational SQL Server (transactional queries kém, không hỗ trợ real-time app). Không scale đúng cho legacy app.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi DOP-C02 hiệu quả! 🚀 Nếu cần thêm chi tiết, hỏi nhé!