Ngân hàng đề — AWS Certified SysOps Administrator Associate

Tìm thấy 936 câu.

Câu 731
A SysOps administrator needs to collect the content of log files from a custom application that is deployed across hundreds of Amazon EC2 instances running Ubuntu. The log files need to be stored in Amazon CloudWatch Logs.

How should the SysOps administrator collect the application log files with the LOWEST operational overhead?
  1. A Configure the syslogd service on each EC2 instance to collect and send the application log files to CloudWatch Logs.
  2. B Install the CloudWatch agent by using the Amazon Linux package manager on each EC2 instance. Configure each agent to collect the application log files.
  3. C Install the CloudWatch agent on each EC2 instance by using AWS Systems Manager. Create an agent configuration on each instance by using the CloudWatch configuration wizard. Configure each agent to collect the application log files.
  4. D Store a CloudWatch agent configuration in the AWS Systems Manager Parameter Store. Install the CloudWatch agent on each EC2 instance by using Systems Manager. Configure each agent to collect the application log files.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào một SysOps Administrator cần thu thập nội dung log files từ ứng dụng tùy chỉnh (custom application) chạy trên hàng trăm Amazon EC2 instances sử dụng hệ điều hành Ubuntu. Các log này phải được lưu trữ vào Amazon CloudWatch Logs. Yêu cầu chính là chọn phương pháp có LOWEST operational overhead (chi phí vận hành thấp nhất), nghĩa là phương án tự động hóa cao nhất, dễ scale, ít can thiệp thủ công cho số lượng lớn instances.

🛠️ Bối cảnh kỹ thuật:

  • EC2 Ubuntu: Không phải Amazon Linux, nên cần agent tương thích (CloudWatch agent hỗ trợ Ubuntu).
  • Hàng trăm instances: Cần giải pháp centralized (tập trung), tránh config thủ công từng máy.
  • CloudWatch Logs: Sử dụng CloudWatch agent để thu thập log custom (không chỉ hệ thống).
  • Kiến thức cập nhật 2026: AWS khuyến nghị AWS Systems Manager (SSM) kết hợp Parameter Store cho deployment agent大规模, theo docs CloudWatch agent v1.300+ và SSM State Manager.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Store a CloudWatch agent configuration in the AWS Systems Manager Parameter Store. Install the CloudWatch agent on each EC2 instance by using Systems Manager. Configure each agent to collect the application log files.

Lý do 🏆:

  • Phương án này sử dụng SSM Parameter Store để lưu config agent tập trung (một nơi duy nhất), sau đó SSM (Node Management/State Manager) tự động install agent và pull config về từng EC2.
  • Lowest overhead: Scale cho hàng trăm instances, không cần config thủ công từng máy, tự động update. Hỗ trợ Ubuntu via SSM packages.
  • Tối ưu theo AWS best practices: Giảm lỗi con người, dễ audit/maintain.

📋 Giải thích tất cả các phương án (đúng/sai)

  • ❌ Phương án SAI: Configure the syslogd service on each EC2 instance to collect and send the application log files to CloudWatch Logs.
    Giải thích: Syslogd là daemon Linux cơ bản (trên Ubuntu), nhưng cần config thủ công từng instance (chỉnh /etc/rsyslog.conf, restart service). Không tự động scale cho hàng trăm máy, overhead cao (thủ công, dễ lỗi). Syslog chỉ forward log hệ thống, custom app cần thêm script phức tạp. Không phải best practice AWS.

  • ❌ Phương án SAI: Install the CloudWatch agent by using the Amazon Linux package manager on each EC2 instance. Configure each agent to collect the application log files.
    Giải thích: Amazon Linux dùng yum/dnf, nhưng instances là Ubuntu (dùng apt). Không tương thích trực tiếp, phải dùng wget/download manual. Vẫn config agent thủ công từng máy (JSON file), overhead lớn cho scale. Không centralized.

  • ❌ Phương án SAI: Install the CloudWatch agent on each EC2 instance by using AWS Systems Manager. Create an agent configuration on each instance by using the CloudWatch configuration wizard. Configure each agent to collect the application log files.
    Giải thích: SSM install agent tốt (tự động), nhưng CloudWatch configuration wizard tạo config từng instance riêng lẻ (UI manual hoặc API per-instance). Overhead vẫn cao vì không centralized, phải lặp lại hàng trăm lần. Wizard không scale tốt.

  • ✅ Phương án ĐÚNG: Store a CloudWatch agent configuration in the AWS Systems Manager Parameter Store. Install the CloudWatch agent on each EC2 instance by using Systems Manager. Configure each agent to collect the application log files.
    Giải thích chi tiết:

    • Lưu JSON config (log paths, metrics) vào SSM Parameter Store (SecureString/Standard).
    • SSM State Manager hoặc Run Command deploy agent + pull config tự động (agent đọc từ Parameter Store tại runtime).
    • Lowest overhead: Một config duy nhất → apply toàn fleet via SSM documents. Hỗ trợ Ubuntu, IAM role SSM tự động. Dễ update central (change param → agent restart pull new config).

🛠️ Tips thực hiện: Tạo SSM document YAML cho State Manager, tham chiếu param /cloudwatch-agent/config. Test với aws ssm get-parameter. Hoàn hảo cho DOP-C02 exam! 🚀

Câu 732 Chọn nhiều đáp án
A SysOps administrator needs to design a disaster recovery (DR) plan for an application on AWS. The application runs on Amazon EC2 instances behind an Application Load Balancer (ALB). The instances are in an Auto Scaling group. The application uses an Amazon Aurora PostgreSQL database. The recovery time objective (RTO) and recovery point objective (RPO) are 15 minutes each.

Which combination of steps should the SysOps administrator take to meet these requirements MOST cost-effectively? (Choose two.)
  1. A Configure Aurora backups to be exported to the DR Region.
  2. B Configure the Aurora cluster to replicate data to the DR Region by using the Aurora global database option.
  3. C Configure the DR Region with an ALB and an Auto Scaling group. Use the same configuration as in the primary Region.
  4. D Configure the DR Region with an ALB and an Auto Scaling group. Set the Auto Scaling group's minimum capacity, maximum capacity, and desired capacity to 1.
  5. E Manually launch a new ALB and a new Auto Scaling group by using AWS CloudFormation during a failover activity.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi yêu cầu thiết kế kế hoạch disaster recovery (DR) cho một ứng dụng chạy trên Amazon EC2 (đứng sau Application Load Balancer - ALB), thuộc Auto Scaling group (ASG), và sử dụng cơ sở dữ liệu Amazon Aurora PostgreSQL. Yêu cầu chính là đạt RTO (Recovery Time Objective) và RPO (Recovery Point Objective) đều là 15 phút, đồng thời phải tiết kiệm chi phí nhất (MOST cost-effectively).

  • RTO 15 phút: Thời gian để khôi phục ứng dụng sau sự cố phải dưới 15 phút (tập trung vào tính sẵn sàng nhanh chóng mà không lãng phí tài nguyên).
  • RPO 15 phút: Mất dữ liệu tối đa 15 phút (cần sao chép dữ liệu liên tục, gần thời gian thực).
  • Đây là chiến lược pilot light (giữ tài nguyên tối thiểu ở vùng DR để "sưởi ấm" và scale nhanh), phù hợp với kiến thức AWS Well-Architected Framework (DR pillar) phiên bản mới nhất 2024-2026, nhấn mạnh replication đa vùng cho database và ASG nhỏ ở DR để cân bằng chi phí/RTO/RPO.

📘 Nguồn tham khảo:

✅ Đáp án đúng (Chọn TWO)

Hai bước đúng là:

  • Configure the Aurora cluster to replicate data to the DR Region by using the Aurora global database option.
  • Configure the DR Region with an ALB and an Auto Scaling group. Set the Auto Scaling group's minimum capacity, maximum capacity, and desired capacity to 1.

Lý do lựa chọn:

  • Kết hợp Aurora Global Database đảm bảo RPO <1 phút (replication liên tục, lag thấp) và RTO thấp (promote secondary cluster chỉ vài phút).
  • ASG ở DR với min/desired/max=1 áp dụng mô hình pilot light 🛠️: Giữ 1 instance EC2 + ALB "warm" ở DR (chi phí thấp ~10-20% so với full production), scale nhanh lên khi failover (scale out trong <5 phút nhờ warm pool). Tổng thể đạt RTO/RPO 15 phút, cost-effective nhất vì tránh chạy full stack ở DR và không cần manual intervention. Không dùng full replica hoặc backup sẽ tốn kém hơn.

📋 Giải thích chi tiết TẤT CẢ các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh, kèm giải thích đúng/sai bằng tiếng Việt:

  • Configure Aurora backups to be exported to the DR Region.
    ❌ SAI: Aurora backups (snapshot/continuous) khi export sang DR Region mất 2-24 giờ để restore, không đạt RPO 15 phút (mất dữ liệu nhiều hơn). Chi phí lưu trữ S3 cao, không replication real-time. Không phù hợp DR active (chỉ passive backup). 🛑

  • Configure the Aurora cluster to replicate data to the DR Region by using the Aurora global database option.
    ✅ ĐÚNG: Aurora Global Database replicate asynchronous cross-region với RPO <1 phút (read replicas lag thấp), RTO ~1-5 phút (failover promote cluster). Hỗ trợ PostgreSQL, scale đọc toàn cầu. Cost-effective vì chỉ tính phí replication + secondary cluster idle. Phù hợp yêu cầu nhất! 🌟
    📘 Nguồn: AWS Aurora Docs (2024).

  • Configure the DR Region with an ALB and an Auto Scaling group. Use the same configuration as in the primary Region.
    ❌ SAI: Copy full config (min/desired/max cao như production) tạo warm standby tốn kém (chi phí EC2/ALB gấp đôi ~50-100%). Không "MOST cost-effectively", dù đạt RTO thấp. Nên dùng pilot light (min=1). 💸

  • Configure the DR Region with an ALB and an Auto Scaling group. Set the Auto Scaling group's minimum capacity, maximum capacity, and desired capacity to 1.
    ✅ ĐÚNG: Pilot light strategy 🛠️: Giữ 1 instance EC2 + ALB ở DR (chi phí thấp), scale nhanh (Warm Pools/Instance Refresh <5 phút) khi failover via Route 53/CloudWatch. Kết hợp Aurora Global đạt RTO/RPO 15 phút, tiết kiệm nhất (chỉ ~1 instance idle). Hoàn hảo! ⚡
    📘 Nguồn: AWS Best Practices (DR Whitepaper 2024).

  • Manually launch a new ALB and a new Auto Scaling group by using AWS CloudFormation during a failover activity.
    ❌ SAI: Manual process mất 30+ phút (deploy CFN stack), không đạt RTO 15 phút. Không tự động, rủi ro lỗi con người, không cost-effective dài hạn (phải automate bằng Lambda/EventBridge). 🕒

Câu 733
A SysOps administrator is creating a simple, public-facing website running on Amazon EC2. The SysOps administrator created the EC2 instance in an existing public subnet and assigned an Elastic IP address to the instance. Next, the SysOps administrator created and applied a new security group to the instance to allow incoming HTTP traffic from 0.0.0.0/0. Finally, the SysOps administrator created a new network ACL and applied it to the subnet to allow incoming HTTP traffic from 0.0.0.0/0. However, the website cannot be reached from the internet.

What is the cause of this issue?
  1. A The SysOps administrator did not create an outbound rule that allows ephemeral port return traffic in the new network ACL.
  2. B The SysOps administrator did not create an outbound rule in the security group that allows HTTP traffic from port 80.
  3. C The Elastic IP address assigned to the EC2 instance has changed.
  4. D There is an additional network ACL associated with the subnet that includes a rule that denies inbound HTTP traffic from port 80.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả tình huống một SysOps administrator đang thiết lập một website công khai đơn giản chạy trên Amazon EC2 instance trong public subnet (subnet công khai). Các bước đã thực hiện bao gồm:

  • Tạo EC2 instance trong public subnet và gán Elastic IP address (địa chỉ IP đàn hồi cố định).
  • Tạo và áp dụng Security Group (SG) mới cho instance, cho phép incoming HTTP traffic (lưu lượng vào cổng 80) từ 0.0.0.0/0 (tất cả nguồn).
  • Tạo Network ACL (NACL) mới và áp dụng cho subnet, cũng chỉ cho phép incoming HTTP traffic từ 0.0.0.0/0.

Vấn đề: Website không thể truy cập được từ internet, mặc dù các thiết lập inbound dường như đã đúng.
🛠️ Nguyên nhân cốt lõi: Đây là vấn đề liên quan đến sự khác biệt giữa Security Group (stateful - có trạng thái) và Network ACL (stateless - không trạng thái). SG tự động cho phép lưu lượng phản hồi (return traffic), nhưng NACL yêu cầu quy tắc outbound rõ ràng cho ephemeral ports (cổng tạm thời từ 1024-65535) để server EC2 có thể gửi response về client. Nếu thiếu outbound rule này trong NACL, kết nối sẽ bị chặn ở lớp mạng.

📘 Tài liệu tham khảo:

  • AWS Documentation: Network ACLs (cập nhật 2024-2026, xác nhận NACL stateless yêu cầu inbound/outbound đối xứng).
  • AWS Well-Architected Framework: Security Pillar - Ephemeral ports for return traffic.
  • Exam guide DOP-C02 (DevOps Engineer Professional, phiên bản mới nhất 2024).

✅ Đáp án đúng

Đáp án đúng: The SysOps administrator did not create an outbound rule that allows ephemeral port return traffic in the new network ACL.

Lý do lựa chọn:

  • NACL hoạt động stateless, nghĩa là mọi lưu lượng (inbound/outbound) đều cần quy tắc riêng biệt. Admin chỉ tạo inbound HTTP (port 80), nhưng thiếu outbound rule cho ephemeral ports (1024-65535) để EC2 gửi response về client.
  • SG đã stateful nên tự xử lý return traffic, Elastic IP ổn định, không có NACL khác. Đây là lỗi phổ biến nhất trong thiết lập public-facing EC2! 🛡️

📋 Giải thích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, với ✅ đúng hoặc ❌ sai, giữ nguyên văn bản gốc:

  • ✅ [ĐÚNG] The SysOps administrator did not create an outbound rule that allows ephemeral port return traffic in the new network ACL.
    Như đã giải thích: NACL stateless yêu cầu outbound ephemeral ports (1024-65535) cho response traffic từ EC2 về internet. Inbound HTTP thôi chưa đủ, dẫn đến kết nối bị drop. Giải pháp: Thêm rule outbound ALLOW từ ephemeral ports đến 0.0.0.0/0. 🔄

  • ❌ [SAI] The SysOps administrator did not create an outbound rule in the security group that allows HTTP traffic from port 80.
    SG là stateful, tự động cho phép return traffic (bao gồm outbound HTTP port 80) khi inbound được approve. Không cần outbound rule thủ công trong SG. Lỗi này không phải nguyên nhân! 🚫

  • ❌ [SAI] The Elastic IP address assigned to the EC2 instance has changed.
    Elastic IP là cố định khi đã gán cho instance, không tự thay đổi trừ khi detach thủ công. Câu hỏi không đề cập hành động detach, nên IP vẫn ổn định và public-facing. Không liên quan! 📍

  • ❌ [SAI] There is an additional network ACL associated with the subnet that includes a rule that denies inbound HTTP traffic from port 80.
    Câu hỏi chỉ rõ "created a new network ACL and applied it to the subnet" – chỉ có một NACL mới được áp dụng, không đề cập NACL khác. NACL mặc định cho phép all traffic, và inbound HTTP đã được ALLOW. Không có deny rule ẩn! 🔒

Câu 734
A company has an application that uses an Amazon Elastic File System (Amazon EFS) file system. A recent incident that involved an application logic error corrupted several files. The company wants to improve its ability to back up and recover the EFS file system. The company must be able to recover individual files rapidly.

Which solution meets these requirements MOST cost-effectively?
  1. A Configure Amazon Data Lifecycle Manager (Amazon DLM) to archive a copy of the data to an Amazon S3 Glacier vault. Use S3 Glacier retrieval requests to retrieve individual files.
  2. B Create a second EFS file system in another AWS Region. Configure AWS DataSync to copy the data to the backup file system. Recover files by copying them from the backup EFS file system.
  3. C Enable AWS Backup in Amazon EFS to back up the file system to an Amazon S3 Glacier vault. Use S3 Glacier retrieval requests to retrieve individual files.
  4. D Enable AWS Backup in Amazon EFS to back up the file system to a backup vault. Use a partial restore job to retrieve individual files.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi xoay quanh một công ty sử dụng ứng dụng trên Amazon Elastic File System (Amazon EFS), nơi một sự cố logic ứng dụng đã làm hỏng nhiều file. Công ty muốn cải thiện khả năng sao lưu và khôi phục EFS, với yêu cầu chính là khôi phục từng file riêng lẻ một cách nhanh chóng và tiết kiệm chi phí nhất (MOST cost-effectively).

🛠️ Yêu cầu cụ thể: Giải pháp phải hỗ trợ backup EFS, cho phép recover individual files nhanh, tránh chi phí cao từ replication cross-region hoặc lưu trữ Glacier chậm chạp. Đây là chủ đề trong kỳ thi AWS Certified DevOps Engineer Professional, liên quan đến dịch vụ AWS Backup (cập nhật mới nhất 2024-2026), hỗ trợ EFS với tính năng partial restore để khôi phục file riêng lẻ từ backup vault mà không cần restore toàn bộ filesystem.

✅ Đáp án đúng: Phương án D

Enable AWS Backup in Amazon EFS to back up the file system to a backup vault. Use a partial restore job to retrieve individual files.

Lý do lựa chọn:

  • AWS Backup là dịch vụ quản lý backup tập trung cho EFS (hỗ trợ từ năm 2020, cập nhật partial restore từ 2022), sao lưu dữ liệu vào backup vault (dựa trên S3 với lifecycle tự động, không phải Glacier).
  • Partial restore job cho phép khôi phục chỉ các file riêng lẻ nhanh chóng (thường trong vài phút), không cần restore toàn bộ EFS, giúp cost-effective vì chỉ tính phí lưu trữ và restore phần cần thiết.
  • Tiết kiệm nhất so với replication cross-region hay Glacier: Không tốn phí DataSync liên tục, không phí retrieve chậm từ Glacier.
  • Phù hợp DevOps: Tích hợp IAM policies, audit trail qua CloudTrail, và scale tự động.

📋 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai với lý do cụ thể dựa trên tài liệu AWS mới nhất (2026).

  • ❌ Phương án A (SAI):
    Configure Amazon Data Lifecycle Manager (Amazon DLM) to archive a copy of the data to an Amazon S3 Glacier vault. Use S3 Glacier retrieval requests to retrieve individual files.
    Lý do sai: Amazon DLM chỉ hỗ trợ backup cho EBS volumes và EC2 instances, KHÔNG hỗ trợ EFS. EFS không thể dùng DLM để archive trực tiếp vào S3 Glacier. Hơn nữa, Glacier retrieval mất 3-12 giờ (Expedited), không "rapid" cho individual files, và chi phí cao cho retrieve thường xuyên.

  • ❌ Phương án B (SAI):
    Create a second EFS file system in another AWS Region. Configure AWS DataSync to copy the data to the backup file system. Recover files by copying them from the backup EFS file system.
    Lý do sai: DataSync dùng cho replication liên tục cross-region, không phải backup/recovery (tốn phí transfer data outbound cao, ~$0.0125/GB). Tạo EFS thứ 2 đắt đỏ (provisioned throughput), thời gian copy lâu cho large datasets, và recover bằng copy thủ công không nhanh cho individual files. Không cost-effective cho backup định kỳ.

  • ❌ Phương án C (SAI):
    Enable AWS Backup in Amazon EFS to back up the file system to an Amazon S3 Glacier vault. Use S3 Glacier retrieval requests to retrieve individual files.
    Lý do sai: AWS Backup cho EFS lưu vào backup vault (S3-based), KHÔNG trực tiếp vào S3 Glacier vault. Glacier chỉ dùng qua lifecycle policy trên vault (mất 30-90 ngày transition), retrieve chậm (Standard: 3-5 giờ), không hỗ trợ rapid individual file recovery. Vi phạm yêu cầu "recover rapidly" và kém cost-effective hơn partial restore.

  • ✅ Phương án D (ĐÚNG):
    Enable AWS Backup in Amazon EFS to back up the file system to a backup vault. Use a partial restore job to retrieve individual files.
    Lý do đúng (như phần trên): Hoàn hảo cho rapid partial restore, chi phí thấp (~$0.05/GB-month lưu trữ, $0.02/GB restore), tích hợp native với EFS.

📘 Tài liệu tham khảo

Giải pháp này đảm bảo high availability, low RTO/RPO cho EFS trong môi trường DevOps! 🚀

Câu 735 Chọn nhiều đáp án
A company migrates a write-once, ready-many (WORM) drive to an Amazon S3 bucket that has S3 Object Lock configured in governance mode. During the migration, the company copies unneeded data to the S3 bucket.

A SysOps administrator attempts to delete the unneeded data from the S3 bucket by using the AWS CLI. However, the SysOps administrator receives an error.

Which combination of steps should the SysOps administrator take to successfully delete the unneeded data? (Choose two.)
  1. A Increase the Retain Until Date.
  2. B Assume a role that has the s3:BypassLegalRetention permission.
  3. C Assume a role that has the s3:BypassGovernanceRetention permission.
  4. D Include the x-amz-bypass-governance-retention:true header in the request when issuing the delete command.
  5. E Include the x-amz-bypass-legal-retention:true header in the request when issuing the delete command.
Xem giải thích

🧩 Giải thích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh tình huống một công ty di chuyển dữ liệu từ ổ đĩa write-once, read-many (WORM) sang Amazon S3 bucket đã kích hoạt S3 Object Lock ở chế độ Governance mode. Trong quá trình di chuyển, họ copy nhầm dữ liệu không cần thiết vào bucket. Khi SysOps administrator cố gắng xóa dữ liệu thừa bằng AWS CLI, gặp lỗi vì Object Lock ngăn chặn việc xóa hoặc ghi đè object bị khóa.

Mục tiêu: Tìm kết hợp 2 bước để SysOps admin có thể xóa thành công dữ liệu thừa.
🛠️ Lý do lỗi: Ở Governance mode (phiên bản AWS mới nhất đến 2026), Object Lock khóa object đến Retain Until Date. Để bypass và xóa, cần quyền IAM đặc biệt (s3:BypassGovernanceRetention) VÀ header cụ thể trong request (x-amz-bypass-governance-retention: true). Không có bypass đơn giản ở mode này trừ khi thỏa mãn cả hai.

✅ Đáp án đúng (Chọn 2)

Hai bước đúng là:

  • Assume a role that has the s3:BypassGovernanceRetention permission.
  • Include the x-amz-bypass-governance-retention:true header in the request when issuing the delete command.

Lý do lựa chọn: Theo tài liệu AWS S3 Object Lock (cập nhật 2024-2026), ở Governance mode, để xóa object WORM locked, phải kết hợp IAM permission s3:BypassGovernanceRetention (giả sử role) VÀ header x-amz-bypass-governance-retention: true trong CLI request (ví dụ: aws s3api delete-object --bucket mybucket --key mykey --bypass-governance-retention). Chỉ một trong hai sẽ không đủ! 📘

🔍 Phân tích tất cả các phương án (Đúng/Sai)

  • ❌ Increase the Retain Until Date.
    Sai: Việc tăng Retain Until Date chỉ kéo dài thời gian khóa object (làm object bị lock lâu hơn), không giúp xóa dữ liệu. Thậm chí làm tình huống tệ hơn vì phải chờ lâu hơn mới tự động hết hạn.

  • ❌ Assume a role that has the s3:BypassLegalRetention permission.
    Sai: Permission s3:BypassLegalRetention không tồn tại trong AWS IAM (danh sách policy S3 đầy đủ đến 2026). Đây là nhầm lẫn với Legal Hold hoặc Compliance mode. Chỉ s3:BypassGovernanceRetention mới áp dụng cho Governance mode.

  • ✅ Assume a role that has the s3:BypassGovernanceRetention permission.
    Đúng: Permission IAM này cho phép bypass Governance retention trên object locked. SysOps admin phải assume role có policy chứa action s3:BypassGovernanceRetention (ví dụ: trong aws iam attach-role-policy). Bước cần thiết đầu tiên!

  • ✅ Include the x-amz-bypass-governance-retention:true header in the request when issuing the delete command.
    Đúng: Header này phải thêm vào mọi request xóa/ghi đè (CLI: --bypass-governance-retention). Nếu thiếu, AWS từ chối ngay cả với permission. Phải kết hợp với bước trên!

  • ❌ Include the x-amz-bypass-legal-retention:true header in the request when issuing the delete command.
    Sai: Header x-amz-bypass-legal-retention:true không tồn tại hoặc không áp dụng (liên quan nhầm với Legal Hold). Chỉ x-amz-bypass-governance-retention hợp lệ cho Governance mode.

📚 Tài liệu tham khảo (AWS cập nhật mới nhất đến 2026)

Hy vọng phân tích giúp bạn nắm vững chủ đề DOP-C02! 🚀 Nếu cần ví dụ CLI cụ thể, hỏi thêm nhé!

Câu 736
A company needs to view a list of security groups that are open to the internet on port 3389.

What should a SysOps administrator do to meet this requirement?
  1. A Configure Amazon GuardDuty to scan security groups and report unrestricted access on port 3389.
  2. B Configure a service control policy (SCP) to identify security groups that allow unrestricted access on port 3389.
  3. C Use AWS Identity and Access Management Access Analyzer to find any instances that have unrestricted access on port 3389.
  4. D Use AWS Trusted Advisor to find security groups that allow unrestricted access on port 3389.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi gốc:
A company needs to view a list of security groups that are open to the internet on port 3389. What should a SysOps administrator do to meet this requirement?

Giải thích câu hỏi:
📘 Câu hỏi tập trung vào một yêu cầu bảo mật phổ biến trong AWS: Công ty cần xem danh sách các Security Groups (nhóm bảo mật) đang mở cửa (allow traffic) ra internet (0.0.0.0/0 hoặc ::/0) trên port 3389 – đây là cổng mặc định cho giao thức RDP (Remote Desktop Protocol), thường dùng cho Windows instances. SysOps Administrator cần một công cụ tự động để liệt kê các Security Group vi phạm quy tắc này, giúp phát hiện rủi ro bảo mật (như mở cửa hậu cho attacker).
🛠️ Yêu cầu nhấn mạnh vào việc kiểm tra và báo cáo nhanh chóng, không phải cấu hình mới hay thay đổi policy, phù hợp với các công cụ monitoring/auditing có sẵn của AWS (cập nhật đến 2026, theo AWS Well-Architected Framework Security Pillar).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use AWS Trusted Advisor to find security groups that allow unrestricted access on port 3389.

Lý do chi tiết:
✅ AWS Trusted Advisor là dịch vụ kiểm tra best practices tự động, bao gồm Security Checks chuyên biệt như "Security Groups - World-Wide Open Ports" hoặc "Restricted SSH/RDP Access". Nó quét toàn bộ tài khoản AWS và liệt kê chính xác các Security Groups mở public (unrestricted) trên port 3389 (RDP), 22 (SSH), và các port phổ biến khác. SysOps Admin chỉ cần truy cập dashboard Trusted Advisor (Support Center) để xem danh sách ngay lập tức, không cần cấu hình thêm. Đây là giải pháp tối ưu, native cho yêu cầu, hỗ trợ Business/Enterprise Support Plan (miễn phí một số check cơ bản).
📈 Cập nhật 2026: Trusted Advisor tích hợp AI/ML để ưu tiên rủi ro cao, và hỗ trợ multi-account qua AWS Organizations.

📋 Phân tích tất cả các phương án (đúng/sai)

  • ❌ Configure Amazon GuardDuty to scan security groups and report unrestricted access on port 3389.
    ❌ Sai vì: GuardDuty là dịch vụ threat detection dựa trên ML, phát hiện hoạt động đáng ngờ (malware, reconnaissance, crypto mining) từ logs CloudTrail/VPC Flow Logs/DNS. Nó không quét trực tiếp Security Groups hay báo cáo cấu hình mở port (như 3389). GuardDuty focus vào runtime threats, không phải config auditing. Sử dụng nó ở đây sẽ không đáp ứng yêu cầu liệt kê Security Groups.

  • ❌ Configure a service control policy (SCP) to identify security groups that allow unrestricted access on port 3389.
    ❌ Sai vì: SCP là policy ở AWS Organizations level, dùng để giới hạn permissions (deny actions như tạo Security Group mở port). Nó không quét hoặc liệt kê Security Groups hiện có, mà chỉ enforce policy tương lai. SCP không có khả năng audit/extract danh sách tài nguyên, và không monitor port-specific rules.

  • ❌ Use AWS Identity and Access Management Access Analyzer to find any instances that have unrestricted access on port 3389.
    ❌ Sai vì: IAM Access Analyzer phân tích IAM policies, S3 buckets, KMS keys để tìm external access (principal/policy statements). Nó không quét Security Groups hoặc EC2 instances theo network ports (như 3389). Access Analyzer focus vào identity-based access, không phải network ACL/Security Group rules. (Lưu ý: Config Analyzer hoặc Network Access Analyzer là các tool khác, nhưng không khớp chính xác).

  • ✅ Use AWS Trusted Advisor to find security groups that allow unrestricted access on port 3389.
    ✅ Đúng như đã giải thích ở trên: Đây là check chuẩn, liệt kê trực tiếp Security Groups vi phạm, dễ sử dụng cho SysOps.

📚 Tài liệu tham khảo (cập nhật AWS 2026)

  • AWS Trusted Advisor Documentation: Security Checks – Chi tiết "Open Ports" cho RDP/SSH.
  • AWS Well-Architected Framework (Security Pillar): Best Practices for Security Groups.
  • AWS Support Center: Truy cập Trusted Advisor qua console.aws.amazon.com/support/home (Business Support trở lên cho full checks).
  • Blog AWS: "Using Trusted Advisor for Security Auditing" (2025 update với ML enhancements).

🛡️ Kết luận: Sử dụng Trusted Advisor là cách nhanh nhất, không tốn kém để audit Security Groups – khuyến nghị thực hành DevOps Professional!

Câu 737 Chọn nhiều đáp án
A company website contains a web tier and a database tier on AWS. The web tier consists of Amazon EC2 instances that run in an Auto Scaling group across two Availability Zones. The database tier runs on an Amazon RDS for MySQL Multi-AZ DB instance. The database subnet network ACLs are restricted to only the web subnets that need access to the database. The web subnets use the default network ACL with the default rules.

The company's operations team has added a third subnet to the Auto Scaling group configuration. After an Auto Scaling event occurs, some users report that they intermittently receive an error message. The error message states that the server cannot connect to the database. The operations team has confirmed that the route tables are correct and that the required ports are open on all security groups.

Which combination of actions should a SysOps administrator take so that the web servers can communicate with the DB instance? (Choose two.)
  1. A On the default ACL, create inbound Allow rules of type TCP with the ephemeral port range and the source as the database subnets.
  2. B On the default ACL, create outbound Allow rules of type MySQL/Aurora (3306). Specify the destinations as the database subnets.
  3. C On the network ACLs for the database subnets, create an inbound Allow rule of type MySQL/Aurora (3306). Specify the source as the third web subnet.
  4. D On the network ACLs for the database subnets, create an outbound Allow rule of type TCP with the ephemeral port range and the destination as the third web subnet.
  5. E On the network ACLs for the database subnets, create an outbound Allow rule of type MySQL/Aurora (3306). Specify the destination as the third web subnet.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả một kiến trúc AWS cho website công ty với web tier gồm các instance Amazon EC2 chạy trong Auto Scaling Group (ASG) trải rộng qua hai Availability Zones (AZs), và database tier sử dụng Amazon RDS for MySQL Multi-AZ.

  • Network ACLs (NACLs) cho các database subnets được hạn chế chỉ cho phép truy cập từ các web subnets cần thiết (stateless firewall tại subnet level).
  • Web subnets sử dụng default NACL với quy tắc mặc định (cho phép tất cả inbound/outbound traffic).
  • Đội ngũ operations thêm third subnet (subnet thứ ba) vào cấu hình ASG. Sau sự kiện Auto Scaling, người dùng gặp lỗi intermittent connection từ web servers đến DB: "server cannot connect to the database".
  • Đã xác nhận: Route tables đúng, security groups (SGs) mở các port cần thiết.

🛠️ Vấn đề cốt lõi: NACLs là stateless (không theo dõi trạng thái kết nối), nên cần quy tắc inbound và outbound riêng biệt cho cả chiều đi và về. Traffic từ web (client) đến RDS MySQL (port 3306), response từ DB dùng ephemeral ports (1024-65535). Default NACL của web đã allow all, nhưng DB NACL chưa có quy tắc cho third web subnet mới → traffic bị block ngẫu nhiên sau ASG scale.

📘 Kiến thức AWS cập nhật (đến 2026): NACLs vẫn stateless, RDS Multi-AZ dùng primary/standby với failover tự động. Không thay đổi cơ bản từ VPC User Guide.

✅ Đáp án đúng (Chọn TWO)

Hai hành động đúng là:

  • On the network ACLs for the database subnets, create an inbound Allow rule of type MySQL/Aurora (3306). Specify the source as the third web subnet.
  • On the network ACLs for the database subnets, create an outbound Allow rule of type TCP with the ephemeral port range and the destination as the third web subnet.

Lý do lựa chọn:

  • DB NACL hiện chỉ allow từ original web subnets. Third subnet mới cần inbound rule để web servers gửi traffic MySQL (3306) vào DB subnets.
  • Vì NACL stateless, cần outbound rule từ DB response (ephemeral ports) về third web subnet. Điều này giải quyết lỗi intermittent (do traffic bidirectional bị block một chiều).

🔍 Phân tích chi tiết tất cả các phương án

  • ❌ [SAI] On the default ACL, create inbound Allow rules of type TCP with the ephemeral port range and the source as the database subnets.
    Giải thích sai: Default NACL (của web subnets) đã allow tất cả inbound/outbound theo quy tắc mặc định (ALLOW ALL). Thêm rule inbound ephemeral từ DB subnets là không cần thiết và sai hướng (web là client nhận response ephemeral từ DB, nhưng default đã cho phép). Vấn đề nằm ở DB NACL, không phải default ACL.

  • ❌ [SAI] On the default ACL, create outbound Allow rules of type MySQL/Aurora (3306). Specify the destinations as the database subnets.
    Giải thích sai: Default NACL đã allow all outbound. Web servers gửi outbound 3306 TO DB (không phải từ DB), nên rule này thừa và không giải quyết vấn đề cốt lõi ở DB NACL bị hạn chế với third subnet.

  • ✅ [ĐÚNG] On the network ACLs for the database subnets, create an inbound Allow rule of type MySQL/Aurora (3306). Specify the source as the third web subnet.
    Giải thích đúng: DB NACL cần rule inbound ALLOW TCP 3306 từ third web subnet CIDR để web instances mới (sau ASG) kết nối RDS MySQL. Không có rule này → inbound traffic bị deny → lỗi connect.

  • ✅ [ĐÚNG] On the network ACLs for the database subnets, create an outbound Allow rule of type TCP with the ephemeral port range and the destination as the third web subnet.
    Giải thích đúng: NACL stateless yêu cầu explicit outbound rule cho response từ DB (ephemeral ports 1024-65535) ĐẾN third web subnet. Thiếu rule → response bị drop → kết nối intermittent (một chiều thành công, chiều về fail).

  • ❌ [SAI] On the network ACLs for the database subnets, create an outbound Allow rule of type MySQL/Aurora (3306). Specify the destination as the third web subnet.
    Giải thích sai: Outbound từ DB KHÔNG dùng port 3306 (đó là listening port của server). Response dùng ephemeral ports, nên rule 3306 outbound là sai và không match traffic thực tế.

📚 Tài liệu tham khảo AWS (cập nhật 2026)

🧠 Mẹo DevOps: Luôn kiểm tra NACL inbound/outbound đôi khi SG đã mở. Sử dụng VPC Flow Logs để debug traffic deny!

Câu 738
A SysOps administrator has been able to consolidate multiple, secure websites onto a single server, and each site is running on a different port. The administrator now wants to start a duplicate server in a second Availability Zone and put both behind a load balancer for high availability.

What would be the command line necessary to deploy one of the sites’ certificates to the load balancer?
  1. A aws kms modify-listener –-load-balancer-name my-load-balancer
    -–certificates CertificateArn=arn:aws:iam::123456789012:server-certifiate/my-new-server-cert
  2. B aws elb set-load-balancer-listener-ssl-certificate --load-balancer-name my-load-balancer –-load-balancer-port 443 –-ssl-certificate-id arn:aws:iam::123456789012:server-certificate/new-server-cert
  3. C aws ec2 put-ssl-certificate –-load-balancer-name my-load-balancer –-load-balancer-port 443 –-ssl-certificate-id arn:aws:iam::123456789012:server-certificate/new-server-cert
  4. D aws acm put-ssl-certificate –-load-balancer-name my-load-balancer –-load-balancer-port 443 –-ssl-certificate-id arn:aws:iam::123456789012:server-certificate/new-server-cert
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả tình huống một SysOps administrator đã hợp nhất nhiều website bảo mật (secure websites) vào một server duy nhất, mỗi site chạy trên port khác nhau. Bây giờ, admin muốn triển khai server duplicate ở Availability Zone (AZ) thứ hai và đặt cả hai server sau load balancer để đạt high availability (HA).
📌 Vấn đề cốt lõi: Cần tìm lệnh AWS CLI để deploy (gắn) certificate SSL của một site vào load balancer.
🛠️ Bối cảnh kỹ thuật: Đây là Classic Load Balancer (ELB v1) vì liên quan đến server chạy nhiều port, cert từ IAM (server-certificate), và nhu cầu HA cơ bản. Load balancer cần listener SSL trên port 443 để terminate HTTPS traffic và forward đến backend servers trên các port khác nhau.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
aws elb set-load-balancer-listener-ssl-certificate --load-balancer-name my-load-balancer –-load-balancer-port 443 –-ssl-certificate-id arn:aws:iam::123456789012:server-certificate/new-server-cert

Lý do:
Lệnh này là AWS CLI chuẩn cho Classic Load Balancer (ELB) để gắn SSL certificate từ IAM vào listener cụ thể trên port 443. Nó chỉ định chính xác --load-balancer-name, --load-balancer-port (port HTTPS), và --ssl-certificate-id (ARN của IAM server certificate). Điều này cho phép load balancer xử lý HTTPS traffic cho site tương ứng, hỗ trợ HA khi scale sang AZ thứ hai. Kiến thức cập nhật đến 2026: Lệnh vẫn hợp lệ cho ELB Classic (dù AWS khuyến nghị migrate sang ALB/NLB), theo AWS CLI v2 mới nhất.

🔍 Giải thích tất cả các phương án

Dưới đây là phân tích từng lựa chọn (giữ nguyên văn bản gốc bằng tiếng Anh). Tôi đánh dấu ✅ đúng hoặc ❌ sai, kèm giải thích chi tiết bằng tiếng Việt:

  • ❌ Phương án SAI:
    aws kms modify-listener –-load-balancer-name my-load-balancer<br>-–certificates CertificateArn=arn:aws:iam::123456789012:server-certifiate/my-new-server-cert
    Giải thích: Lệnh dùng KMS (Key Management Service) sai hoàn toàn vì KMS chỉ quản lý encryption keys (không phải SSL certificates). modify-listener thuộc về ALB/ELBv2 (dùng aws elbv2 modify-listener), không phải ELB Classic. ARN có lỗi chính tả ("certifiate") và format không chuẩn cho KMS. Không deploy cert được.

  • ✅ Phương án ĐÚNG (như đã giải thích ở trên):
    aws elb set-load-balancer-listener-ssl-certificate --load-balancer-name my-load-balancer –-load-balancer-port 443 –-ssl-certificate-id arn:aws:iam::123456789012:server-certificate/new-server-cert
    Giải thích: Hoàn hảo cho ELB Classic, gắn cert IAM vào listener port 443. Hỗ trợ multi-port backend sites sau khi setup HA.

  • ❌ Phương án SAI:
    aws ec2 put-ssl-certificate –-load-balancer-name my-load-balancer –-load-balancer-port 443 –-ssl-certificate-id arn:aws:iam::123456789012:server-certificate/new-server-cert
    Giải thích: EC2 CLI không có lệnh put-ssl-certificate. EC2 chỉ quản lý instances/security groups, không attach cert vào load balancer. Lệnh này sẽ báo lỗi "command not found" ngay lập tức.

  • ❌ Phương án SAI:
    aws acm put-ssl-certificate –-load-balancer-name my-load-balancer –-load-balancer-port 443 –-ssl-certificate-id arn:aws:iam::123456789012:server-certificate/new-server-cert
    Giải thích: ACM (AWS Certificate Manager) không có lệnh put-ssl-certificate. ACM dùng import-certificate hoặc request-certificate để tạo/import cert (ARN từ ACM, không phải IAM server-cert). ACM cert chỉ attach vào ALB/NLB/CloudFront qua modify-listener, không phải ELB Classic hoặc lệnh này.

📘 Tài liệu tham khảo (cập nhật AWS 2026)

  • AWS CLI Reference cho ELB Classic: set-load-balancer-listener-ssl-certificate – Xác nhận lệnh chính xác.
  • Classic Load Balancer SSL Guide: AWS ELB Listener Config – Hướng dẫn attach IAM certs.
  • ACM vs IAM Certs: ACM for ELB – Chỉ hỗ trợ ALB/NLB, không ELB Classic.
  • Migration Note (2026): AWS vẫn hỗ trợ ELB Classic đến ít nhất 2030, nhưng recommend ALB cho multi-port sites (dùng target groups).
    🛠️ Lời khuyên: Sau khi attach cert, test bằng curl -k https://my-load-balancer và monitor CloudWatch metrics cho HealthyHostCount!
Câu 739
A SysOps administrator is preparing to deploy an application to Amazon EC2 instances that are in an Auto Scaling group. The application requires dependencies to be installed. Application updates are issued weekly.

The SysOps administrator needs to implement a solution to incorporate the application updates on a regular basis. The solution also must conduct a vulnerability scan during Amazon Machine Image (AMI) creation.

What is the MOST operationally efficient solution that meets these requirements?
  1. A Create a script that uses Packer. Schedule a cron job to run the script.
  2. B Install the application and its dependencies on an EC2 instance. Create an AMI of the EC2 instance.
  3. C Use EC2 Image Builder with a custom recipe to install the application and its dependencies.
  4. D Invoke the EC2 CreateImage API operation by using an Amazon EventBridge scheduled rule.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào một SysOps administrator đang chuẩn bị triển khai ứng dụng lên các Amazon EC2 instances thuộc Auto Scaling group (ASG). Ứng dụng cần cài đặt dependencies (các thư viện phụ thuộc), và cập nhật ứng dụng hàng tuần. Giải pháp phải tích hợp vulnerability scan (quét lỗ hổng bảo mật) trong quá trình tạo Amazon Machine Image (AMI), đồng thời đảm bảo operationally efficient nhất (hiệu quả vận hành cao, tự động hóa tối ưu, ít can thiệp thủ công).

Yêu cầu chính:

  • Tự động hóa việc cập nhật ứng dụng định kỳ (hàng tuần).
  • Cài đặt dependencies và ứng dụng vào AMI.
  • Quét vulnerability tự động khi build AMI.
  • Phù hợp với môi trường ASG (các instance mới scale out sẽ dùng AMI mới nhất).

Giải pháp lý tưởng phải tự động, lặp lại định kỳ, tích hợp scan bảo mật native, sử dụng dịch vụ AWS managed để giảm chi phí vận hành và tăng độ tin cậy. (Kiến thức cập nhật: EC2 Image Builder phiên bản mới nhất 2026 hỗ trợ pipelines tự động, custom components, và tích hợp Amazon Inspector cho vulnerability scanning).

✅ Đáp án đúng

Use EC2 Image Builder with a custom recipe to install the application and its dependencies.

Lý do lựa chọn:

  • EC2 Image Builder là dịch vụ AWS managed chuyên build, test và phân phối AMI một cách tự động hóa cao nhất.
  • Sử dụng custom recipe (công thức tùy chỉnh) để cài đặt ứng dụng + dependencies qua các components (script PowerShell/Yum/APT).
  • Tự động hóa định kỳ: Pipeline Image Builder có thể schedule hàng tuần qua Amazon EventBridge hoặc cron-like scheduler tích hợp.
  • Vulnerability scan tích hợp: Image Builder hỗ trợ built-in vulnerability scanning sử dụng Amazon Inspector hoặc custom components (như Lynis/Trivy), quét ngay trong giai đoạn build/test AMI.
  • Operationally efficient: Không cần quản lý EC2 thủ công, tích hợp ASG qua Launch Template, hỗ trợ versioning AMI, rollback tự động. Hoàn hảo cho cập nhật weekly mà không downtime.

📋 Giải thích tất cả các phương án (đúng/sai)

  • ✅ [ĐÚNG] Use EC2 Image Builder with a custom recipe to install the application and its dependencies.
    🛠️ Phân tích: Như đã giải thích ở trên, đây là giải pháp native AWS, serverless, tự động hóa đầy đủ (build → install → scan → distribute AMI). Hỗ trợ Infrastructure as Code (IaC) qua AWS CLI/SDK, tích hợp CI/CD (CodePipeline). Đáp ứng 100% yêu cầu với chi phí thấp và scalability cao.

  • ❌ [SAI] Create a script that uses Packer. Schedule a cron job to run the script.
    🛠️ Phân tích: Packer (của HashiCorp) là công cụ mạnh để build AMI, nhưng không phải AWS native → phải tự quản lý script, cron job trên EC2 (tăng overhead). Không có vulnerability scan tích hợp tự động (phải custom thêm tool như Clair/Anchore). Ít efficient hơn Image Builder vì thiếu managed pipeline, versioning, và test phases.

  • ❌ [SAI] Install the application and its dependencies on an EC2 instance. Create an AMI of the EC2 instance.
    🛠️ Phân tích: Đây là cách thủ công hoàn toàn (bake AMI golden), chỉ làm một lần → không hỗ trợ cập nhật weekly tự động. Không có scan vulnerability tự động (phải chạy riêng Amazon Inspector sau). Không efficient cho ASG vì phải rebuild thủ công mỗi tuần, dễ lỗi con người và drift configuration.

  • ❌ [SAI] Invoke the EC2 CreateImage API operation by using an Amazon EventBridge scheduled rule.
    🛠️ Phân tích: Chỉ tạo snapshot AMI từ instance hiện tại định kỳ qua EventBridge, nhưng không cài dependencies/ứng dụng (giả sử instance đã có sẵn). Không có vulnerulnerability scan trong quá trình tạo. Không giải quyết cập nhật ứng dụng → instance ASG sẽ dùng AMI cũ, dẫn đến inconsistency và rủi ro bảo mật.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Giải pháp này đảm bảo zero-downtime updates cho ASG! 🚀

Câu 740
An AWS CloudFormation template creates an Amazon RDS instance. This template is used to build up development environments as needed and then delete the stack when the environment is no longer required. The RDS-persisted data must be retained for further use, even after the CloudFormation stack is deleted.

How can this be achieved in a reliable and efficient way?
  1. A Write a script to continue backing up the RDS instance every five minutes.
  2. B Create an AWS Lambda function to take a snapshot of the RDS instance, and manually invoke the function before deleting the stack.
  3. C Use the Snapshot Deletion Policy in the CloudFormation template definition of the RDS instance.
  4. D Create a new CloudFormation template to perform backups of the RDS instance, and run this template before deleting the stack.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc quản lý Amazon RDS instance được tạo bởi AWS CloudFormation template trong môi trường phát triển (development environments). 📝 Cụ thể:

  • Template dùng để xây dựng môi trường dev tạm thời, sau đó xóa stack khi không cần nữa.
  • Yêu cầu quan trọng: Dữ liệu persisted (dữ liệu đã lưu trữ lâu dài) trên RDS phải được giữ lại để sử dụng sau, ngay cả sau khi stack bị xóa.
  • Mục tiêu: Tìm cách reliable (đáng tin cậy) và efficient (hiệu quả) để đạt được điều này, tránh mất dữ liệu và không cần can thiệp thủ công phức tạp.

Vấn đề cốt lõi là CloudFormation mặc định sẽ xóa tất cả resources (bao gồm RDS) khi delete stack, dẫn đến mất dữ liệu. Cần cơ chế tự động bảo vệ dữ liệu RDS mà không làm gián đoạn quy trình. 🛡️

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use the Snapshot Deletion Policy in the CloudFormation template definition of the RDS instance.

Lý do:

  • DeletionPolicy: Snapshot là thuộc tính tích hợp sẵn trong CloudFormation cho RDS (và các resource khác như EBS). Khi stack bị xóa, CloudFormation tự động tạo một final snapshot của RDS trước khi xóa instance, và snapshot này được giữ lại vĩnh viễn (không bị xóa theo stack).
  • Reliable: Hoàn toàn tự động, không phụ thuộc script hay thủ công, tránh lỗi con người. ✅
  • Efficient: Chỉ thêm một dòng code vào template (ví dụ: "DeletionPolicy": "Snapshot"), không tốn thêm tài nguyên hay thời gian.
  • Áp dụng phiên bản mới nhất AWS (2026): Vẫn là best practice, hỗ trợ full cho RDS Multi-AZ, Aurora, v.v. 📈

🧪 Giải thích tất cả các phương án (đúng/sai)

  • ❌ [SAI] Write a script to continue backing up the RDS instance every five minutes.

    • Giải thích: Phương án này không reliable vì script backup thủ công không tự động giữ snapshot sau delete stack – RDS sẽ bị xóa, snapshot cũ có thể hết hạn hoặc không đầy đủ. Backup 5 phút quá thường xuyên gây tốn chi phí lưu trữ và IOPS cao, không efficient. Không liên kết với lifecycle CloudFormation. 🚫
  • ❌ [SAI] Create an AWS Lambda function to take a snapshot of the RDS instance, and manually invoke the function before deleting the stack.

    • Giải thích: Yêu cầu thủ công invoke Lambda trước delete, dễ quên hoặc lỗi (không reliable cho môi trường dev tự động). Lambda chỉ snapshot một lần, không đảm bảo dữ liệu latest nếu delay. Thêm complexity không cần thiết so với native CloudFormation. ❌
  • ✅ [ĐÚNG] Use the Snapshot Deletion Policy in the CloudFormation template definition of the RDS instance.

    • Giải thích: Như đã nêu ở trên, đây là cách tích hợp sẵn, tự động và an toàn nhất. CloudFormation xử lý toàn bộ: tạo snapshot named theo stack, giữ lại sau delete. Hỗ trợ tùy chỉnh tên snapshot qua AWS::RDS::DBInstance properties. Hoàn hảo cho use case này! 🎯
  • ❌ [SAI] Create a new CloudFormation template to perform backups of the RDS instance, and run this template before deleting the stack.

    • Giải thích: Tạo template riêng để backup là overkill và không sync, phải run thủ công trước delete (dễ miss latest data). Không tự động như DeletionPolicy, tăng overhead quản lý nhiều stack/template. Không efficient cho quy trình delete nhanh. 🗑️

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Phương án đúng giúp quy trình zero-downtime data retention! Nếu cần ví dụ YAML template, hỏi thêm nhé. 🚀