Ngân hàng đề — AWS Certified SysOps Administrator Associate

Tìm thấy 936 câu.

Câu 811 Chọn nhiều đáp án
A company wants to monitor the security groups of its Amazon EC2 instances to ensure that SSH is not open to the public. If the port is opened, the company needs to close the port as soon as possible.

Which combination of actions should a SysOps administrator take to meet these requirements? (Choose two.)
  1. A Add an Amazon CloudWatch alarm to detect the security groups that allow SSH.
  2. B Add an AWS Config rule to detect the security groups that allow SSH.
  3. C Add an assessment template to Amazon Inspector to detect the security groups that allow SSH.
  4. D Call an AWS Systems Manager Automation runbook to close the port.
  5. E Call AWS Systems Manager Run Command to close the port.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào việc giám sát và khắc phục tự động các security groups (SG) của Amazon EC2 instances để đảm bảo cổng SSH (thường là port 22) không được mở cho public (0.0.0.0/0 hoặc ::/0). Nếu phát hiện vi phạm, cần đóng cổng ngay lập tức. Đây là yêu cầu điển hình trong DevOps để duy trì tuân thủ bảo mật (compliance) và tự động hóa remediation.
SysOps administrator cần chọn hai hành động kết hợp (choose two): một để phát hiện (detect) và một để khắc phục (remediate). Giải pháp phải dựa trên các dịch vụ AWS gốc, tận dụng AWS Config cho giám sát cấu hình và Systems Manager (SSM) cho tự động hóa, phù hợp với best practices AWS Well-Architected Framework (Pillar: Security).

✅ Đáp án đúng và lý do lựa chọn

Hai đáp án đúng là:

  1. Add an AWS Config rule to detect the security groups that allow SSH.

    • Lý do: AWS Config rule chuyên dùng để đánh giá cấu hình liên tục (continuous compliance checking), có managed rule sẵn như ec2-security-group-ssh-open-to-world để detect SG mở SSH public. Khi vi phạm, trigger remediation tự động.
  2. Call an AWS Systems Manager Automation runbook to close the port.

    • Lý do: SSM Automation tự động hóa workflow đa bước, có runbook sẵn (như AWS-RemediateEC2SecurityGroup) để modify SG rules an toàn, đóng port SSH mà không cần can thiệp thủ công. Kết hợp với AWS Config để tạo remediation action tự động.

Kết hợp này tạo closed-loop automation: Config detect → trigger SSM Automation đóng port ngay lập tức. ✅ Hoàn hảo cho yêu cầu "close the port as soon as possible"!

📋 Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá đúng/sai dựa trên chức năng AWS mới nhất (2024-2026), với giải thích rõ ràng:

  • ❌ Add an Amazon CloudWatch alarm to detect the security groups that allow SSH.
    Sai vì: CloudWatch alarms chỉ giám sát metrics số học (như CPU, network traffic), không đánh giá cấu hình resource như SG rules. Không có metric trực tiếp cho "SSH open to public". Dùng CloudWatch Logs Insights hoặc metric filters cho logs, nhưng không phù hợp detect SG config. 🛑 Không đáp ứng detect chính xác.

  • ✅ Add an AWS Config rule to detect the security groups that allow SSH.
    Đúng vì: AWS Config là dịch vụ ghi nhận và đánh giá cấu hình (configuration recorder & evaluator). Managed rule ec2-security-group-ssh-open-to-world (cập nhật mới nhất AWS Config 2024) tự động scan tất cả SG, detect inbound rule SSH (TCP 22) mở 0.0.0.0/0, và gửi NON_COMPLIANT status. Có thể integrate với EventBridge để trigger remediation. 🛡️ Ideal cho monitoring liên tục!

  • ❌ Add an assessment template to Amazon Inspector to detect the security groups that allow SSH.
    Sai vì: Amazon Inspector (nay là Inspector v2, 2024+) tập trung scan vulnerabilities và misconfigurations trên instance level (software, network exposure), không scan SG rules trực tiếp. Assessment templates dùng cho EC2/Mac/ Lambda/ECS, detect CVEs hoặc package issues, chứ không phải SG config. 🕵️‍♂️ Không phải công cụ cho SG compliance.

  • ✅ Call an AWS Systems Manager Automation runbook to close the port.
    Đúng vì: SSM Automation cung cấp runbooks pre-defined (như AWS-UpdateSecurityGroup hoặc custom) để tự động modify SG (remove inbound rule SSH public). Hỗ trợ parameters an toàn (target SG ID), multi-account, và integrate với Config/SNS/EventBridge cho auto-remediation. Phiên bản mới (SSM 2025+) cải thiện idempotency và approval gates. ⚙️ Đáp ứng "close as soon as possible"!

  • ❌ Call AWS Systems Manager Run Command to close the port.
    Sai vì: SSM Run Command chỉ chạy commands/scripts trên instance OS (như shell scripts), không thể modify SG rules (SG là VPC resource, không phải instance-local). Để đóng port, cần API calls như ModifySecurityGroupRules qua SDK/CLI, không phải Run Command. 🚫 Không phù hợp, có thể gây lỗi permission hoặc không hiệu quả.

📘 Tài liệu tham khảo

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ code Terraform/CloudFormation, hãy hỏi nhé!

Câu 812
A company runs an application on Amazon EC2 instances that are in an Amazon EC2 Auto Scaling group. Scale-out actions take a long time to become complete because of long-running boot scripts. A SysOps administrator must implement a solution to reduce the required time for scale-out actions without overprovisioning the Auto Scaling group.

Which solution will meet these requirements?
  1. A Change the launch configuration to use a larger instance size.
  2. B Increase the minimum number of instances in the Auto Scaling group.
  3. C Add a predictive scaling policy to the Auto Scaling group.
  4. D Add a warm pool to the Auto Scaling group.
Xem giải thích

🧩 Phân tích nội dung câu hỏi
Câu hỏi mô tả một ứng dụng chạy trên các instance Amazon EC2 thuộc Amazon EC2 Auto Scaling group (ASG). Vấn đề chính là các hành động scale-out (mở rộng ra) mất nhiều thời gian để hoàn tất do boot scripts (các script khởi động) chạy lâu. SysOps administrator cần triển khai giải pháp để giảm thời gian scale-out mà không overprovisioning (không cung cấp dư thừa tài nguyên) ASG.
🎯 Yêu cầu cốt lõi: Giải pháp phải rút ngắn thời gian khởi động instance mới khi scale-out, đồng thời tránh việc giữ quá nhiều instance idle để tiết kiệm chi phí, phù hợp với tính năng mới nhất của AWS Auto Scaling (cập nhật đến 2026).

✅ Đáp án đúng: Add a warm pool to the Auto Scaling group.
Lý do chọn đáp án này: Warm Pool là tính năng của EC2 Auto Scaling cho phép duy trì một nhóm instance ở trạng thái stopped hoặc standby (sẵn sàng), đã được cấu hình sẵn boot scripts. Khi scale-out, ASG có thể nhanh chóng attach các instance từ warm pool vào group mà không cần khởi động từ đầu, giảm đáng kể thời gian scale-out (thường chỉ vài giây thay vì vài phút). Điều này tránh overprovisioning vì instance trong warm pool không tính phí khi stopped (chỉ trả cho EBS volumes), và có thể cấu hình min/max size pool phù hợp. Đây là giải pháp tối ưu theo best practices AWS hiện tại (2026).

📋 Giải thích tất cả các phương án (giữ nguyên văn bản gốc bằng tiếng Anh):

  • ❌ Change the launch configuration to use a larger instance size.
    Sai vì: Sử dụng instance lớn hơn (như từ t3.micro lên m5.large) chỉ tăng CPU/RAM, không giảm thời gian chạy boot scripts (vẫn phải boot từ đầu). Có thể làm tăng chi phí không cần thiết mà không giải quyết gốc rễ vấn đề scale-out chậm.

  • ❌ Increase the minimum number of instances in the Auto Scaling group.
    Sai vì: Tăng min size (ví dụ từ 2 lên 10) sẽ giữ luôn số lượng instance tối thiểu lớn hơn, dẫn đến overprovisioning (dư thừa tài nguyên idle), vi phạm yêu cầu rõ ràng của câu hỏi. Không giảm thời gian scale-out khi cần thêm instance mới.

  • ❌ Add a predictive scaling policy to the Auto Scaling group.
    Sai vì: Predictive scaling sử dụng ML để dự đoán và scale trước nhu cầu (dựa trên lịch sử CloudWatch), nhưng khi scale-out vẫn phải khởi động instance mới từ đầu, boot scripts vẫn chạy lâu như cũ. Không trực tiếp giảm thời gian boot, chỉ giúp scale sớm hơn.

  • ✅ Add a warm pool to the Auto Scaling group.
    Đúng vì: Như đã giải thích ở trên, warm pool giữ instance "ấm" sẵn sàng, giảm thời gian scale-out hiệu quả mà không overprovision (instance stopped không tính phí compute). Hỗ trợ cả Launch Template (khuyến nghị thay Launch Configuration từ 2023+).

🛠️ Lưu ý triển khai thực tế:

  • Cấu hình warm pool qua AWS Console/CLI: --min-size 2 --max-group-prepared-capacity 10 --pool-state Stopped.
  • Kết hợp Instance Metadata Service v2 (IMDSv2) và User Data scripts tối ưu để boot nhanh hơn nếu cần.

📘 Tài liệu tham khảo (AWS cập nhật 2026):

Câu 813
A company asks a SysOps administrator to provision an additional environment for an application in four additional AWS Regions. The application is running on more than 100 Amazon C2 instances in the us-east-1 Region, using fully configured Amazon Machine Images (AMIs). The company has an AWS CloudFormation template to deploy resources in us-east-1.

What should the SysOps administrator do to provision the application in the MOST operationally efficient manner?
  1. A Copy the AMI to each Region by using the aws ec2 copy-image command. Update the CloudFormation template to include mappings for the copied AMIs.
  2. B Create a snapshot of the running instance. Copy the snapshot to the other Regions. Create an AMI from the snapshots. Update the CloudFormation template for each Region to use the new AMI.
  3. C Run the existing CloudFormation template in each additional Region based on the success of the template that is used currently in us-east-1.
  4. D Update the CloudF ormation template to include the additional Regions in the Auto Scaling group. Update the existing stack in us-east-1.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai môi trường ứng dụng thêm ở 4 Region AWS khác ngoài us-east-1, nơi ứng dụng đang chạy trên hơn 100 instance EC2 sử dụng Amazon Machine Images (AMIs) đã được cấu hình đầy đủ. Công ty đã có AWS CloudFormation template để deploy tài nguyên ở us-east-1.
Mục tiêu chính: Tìm cách provision (triển khai) ứng dụng một cách hiệu quả vận hành nhất (MOST operationally efficient), nghĩa là giảm thiểu công sức thủ công, thời gian, rủi ro và dễ dàng mở rộng tự động hóa.
📌 Thách thức chính: AMI chỉ có sẵn ở Region tạo ra (us-east-1), nên không thể dùng trực tiếp ở các Region khác. CloudFormation cần được điều chỉnh để hỗ trợ multi-Region mà không thay đổi lớn.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Copy the AMI to each Region by using the aws ec2 copy-image command. Update the CloudFormation template to include mappings for the copied AMIs.

Lý do chọn đáp án này 🛠️:

  • Lệnh aws ec2 copy-image là cách chính thức và hiệu quả nhất của AWS để sao chép AMI giữa các Region (tính năng được cập nhật ổn định đến 2026). Nó copy trực tiếp AMI đã sẵn sàng (fully configured), giữ nguyên cấu hình, nhanh hơn snapshot (không cần tạo từ instance đang chạy).
  • Sau copy, AMI mới có ID riêng ở mỗi Region. Sử dụng Mappings trong CloudFormation (một tính năng core) để map AMI ID theo Region (ví dụ: Fn::FindInMap), giúp một template duy nhất deploy được ở tất cả Region mà không cần chỉnh sửa thủ công mỗi lần.
  • Hiệu quả vận hành cao nhất: Tự động hóa hoàn toàn, scalable cho >100 instances, giảm downtime và dễ maintain. Không cần chạm vào instances đang chạy.
    📘 Tài liệu tham khảo:
  • AWS CLI: CopyImage API (updated 2024).
  • CloudFormation Mappings: AWS::CloudFormation::Mapping.

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá hiệu quả vận hành dựa trên best practices AWS DevOps (tối ưu automation, minimal manual steps, cross-Region compatibility).

  • ✅ Copy the AMI to each Region by using the aws ec2 copy-image command. Update the CloudFormation template to include mappings for the copied AMIs.
    Giải thích đúng: Như trên, đây là cách tối ưu nhất 🏆. Copy AMI trực tiếp (parallel cho 4 Regions), dùng Mappings để template linh hoạt multi-Region. Thời gian copy nhanh (giờ thay vì ngày), không ảnh hưởng production instances.

  • ❌ Create a snapshot of the running instance. Copy the snapshot to the other Regions. Create an AMI from the snapshots. Update the CloudFormation template for each Region to use the new AMI.
    Giải thích sai: Quá phức tạp và kém hiệu quả 😩. Phải tạo snapshot từ instances đang chạy (>100 instances → rủi ro consistency, downtime nếu không quiesce). Copy snapshot rồi register AMI mới tốn thời gian dài hơn copy-image (snapshot lớn hơn AMI). Cần update template riêng cho từng Region (không dùng Mappings) → manual effort cao, dễ lỗi khi scale.

  • ❌ Run the existing CloudFormation template in each additional Region based on the success of the template that is used currently in us-east-1.
    Giải thích sai: Sẽ thất bại ngay 🚫. AMI ID trong template là Region-specific (chỉ valid ở us-east-1). Khi stack ở Region khác, CloudFormation không tìm thấy AMI → lỗi "Invalid AMI ID". Không efficient vì phải debug/fix thủ công mỗi Region.

  • ❌ Update the CloudF ormation template to include the additional Regions in the Auto Scaling group. Update the existing stack in us-east-1.
    Giải thích sai: Không khả thi về mặt kỹ thuật ⚠️. Auto Scaling Group (ASG) chỉ hoạt động trong một Region duy nhất (AWS limitation đến 2026, không cross-Region native). Update stack us-east-1 chỉ ảnh hưởng local, không provision instances ở Regions khác. Phải dùng multi-stack hoặc Cross-Region Actions (như EC2 Fleet), nhưng không phải cách đơn giản nhất ở đây.

Kết luận tổng quát 🎯: Cách đúng tận dụng native AWS tools (CopyImage + CF Mappings) để đạt zero-downtime, fully automated deployment multi-Region – phù hợp chuẩn DevOps Professional! Nếu implement, khuyến nghị dùng AWS CLI scripting hoặc CDK để automate copy process.

Câu 814
A company runs its applications on a large number of Amazon EC2 instances. A SysOps administrator must implement a solution to notify the operations team whenever an EC2 instance state changes.

What is the MOST operationally efficient solution that meets these requirements?
  1. A Create a script that captures instance state changes and publishes a notification to an Amazon Simple Notification Service (Amazon SNS) topic. Use AWS Systems Manager Run Command to run the script on all EC2 instances.
  2. B Create an Amazon EventBridge event rule that captures EC2 instance state changes. Set an Amazon Simple Notification Service (Amazon SNS) topic as the target
  3. C Create an Amazon EventBridge event rule that captures EC2 instance state changes. Set as the target an AWS Lambda function that publishes a notification to an Amazon Simple Notification Service (Amazon SNS) topic.
  4. D Create an AWS Config custom rule that evaluates instance state changes with automatic remediation. Use the rule to invoke an AWS Lambda function that publishes a notification to an Amazon Simple Notification Service (Amazon SNS) topic.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai một giải pháp hiệu quả nhất về mặt vận hành (MOST operationally efficient) cho một công ty đang chạy ứng dụng trên số lượng lớn Amazon EC2 instances. Nhiệm vụ của SysOps administrator là thông báo ngay lập tức cho đội ngũ operations mỗi khi trạng thái (state) của bất kỳ EC2 instance nào thay đổi, chẳng hạn như từ running sang stopping, stopped, terminated, hoặc các trạng thái khác (như pending, shutting-down).

🔑 Yêu cầu chính:

  • Giải pháp phải tự động, mở rộng quy mô (scale) cho hàng loạt instances mà không cần can thiệp thủ công.
  • Ưu tiên hiệu quả vận hành: Ít tài nguyên, serverless, event-driven, chi phí thấp, không yêu cầu polling hoặc script chạy liên tục trên instances.
  • Sử dụng các dịch vụ AWS hiện đại (cập nhật đến 2026): EventBridge là lựa chọn chuẩn cho event routing từ EC2 (hỗ trợ event source ec2.state-change).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create an Amazon EventBridge event rule that captures EC2 instance state changes. Set an Amazon Simple Notification Service (Amazon SNS) topic as the target.

Lý do chọn đáp án này 🛠️:

  • EventBridge (trước đây là CloudWatch Events) là dịch vụ serverless, event-driven được thiết kế chuyên biệt để capture events từ EC2 state changes (event pattern: {"source": ["aws.ec2"], "detail-type": ["EC2 Instance State-change Notification"]}).
  • Target trực tiếp SNS topic: Thông báo được gửi ngay lập tức qua email/SMS/Slack cho operations team mà không cần Lambda trung gian, giảm độ trễ (latency), chi phí và độ phức tạp.
  • Hiệu quả vận hành cao nhất: Tự động scale cho hàng triệu instances, không cần agent/install script trên EC2, chi phí theo pay-per-use (rẻ hơn so với các lựa chọn khác). Đây là best practice theo AWS Well-Architected Framework (Operational Excellence pillar).

📋 Phân tích chi tiết tất cả các phương án

Dưới đây là phân tích từng phương án, giữ nguyên nội dung gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai kèm lý do cụ thể dựa trên kiến thức AWS mới nhất (EventBridge v2.0 hỗ trợ enhanced filtering đến 2026).

  • Phương án 1: Create a script that captures instance state changes and publishes a notification to an Amazon Simple Notification Service (Amazon SNS) topic. Use AWS Systems Manager Run Command to run the script on all EC2 instances.
    ❌ Sai vì: Giải pháp này không event-driven, yêu cầu script chạy liên tục/polling DescribeInstanceStatus API trên tất cả EC2 instances qua SSM Run Command – rất tốn kém (chi phí SSM invocations cao với số lượng lớn instances), dễ lỗi (script fail nếu instance không healthy), và không efficient (overhead cao, không real-time). Không phù hợp cho scale lớn.

  • Phương án 2 (ĐÚNG): Create an Amazon EventBridge event rule that captures EC2 instance state changes. Set an Amazon Simple Notification Service (Amazon SNS) topic as the target.
    ✅ Đúng như đã giải thích ở trên: Tối ưu nhất với direct target SNS, zero custom code, hỗ trợ filtering chi tiết (instance ID, region, state name). EventBridge tự động capture từ EC2 API mà không cần agent.

  • Phương án 3: Create an Amazon EventBridge event rule that captures EC2 instance state changes. Set as the target an AWS Lambda function that publishes a notification to an Amazon Simple Notification Service (Amazon SNS) topic.
    ❌ Sai vì: Mặc dù dùng EventBridge đúng, nhưng thêm Lambda trung gian làm tăng độ phức tạp không cần thiết (extra cold starts, chi phí invocation ~$0.20/1M requests), độ trễ cao hơn (thêm 100-500ms), và không phải MOST efficient so với direct SNS target (SNS là native target của EventBridge từ 2019).

  • Phương án 4: Create an AWS Config custom rule that evaluates instance state changes with automatic remediation. Use the rule to invoke an AWS Lambda function that publishes a notification to an Amazon Simple Notification Service (Amazon SNS) topic.
    ❌ Sai vì: AWS Config dành cho thay đổi cấu hình (config drift) như security groups/AMIs, KHÔNG phải real-time state changes (như stop/start – Config chỉ evaluate định kỳ, không capture events tức thì). "Automatic remediation" không liên quan (chỉ fix config, không notify). Thêm Lambda làm phức tạp, không efficient và sai use case.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Giải pháp này đảm bảo 99.99% uptime notifications mà không tốn công maintain! 🚀

Câu 815 Chọn nhiều đáp án
A company has migrated its legacy on-premises web application to an Amazon EC2 instance. The web application requires a single static public IP address to accept traffic and process requests. End users must be able to reach the web application through the example.com domain. A SysOps administrator must implement a solution that maintains the web application with the least amount of effort.

Which combination of actions will meet these requirements? (Choose two.)
  1. A Configure an Application Load Balancer (ALB). Add the EC2 instance to a target group that is associated with the ALB.
  2. B Create an Amazon Route 53 A record for the associated EC2 IP address.
  3. C Create an Amazon Route 53 CNAME record for the associated EC2 IP address.
  4. D Create an Elastic IP address, and associate it with the EC2 instance.
  5. E Create an Auto Scaling group with a minimum capacity of 1 and a maximum capacity of 2.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi xoay quanh việc triển khai giải pháp đơn giản nhất (least effort) cho một ứng dụng web legacy đã migrate từ on-premises sang Amazon EC2 instance. Các yêu cầu chính bao gồm:

  • Ứng dụng cần một địa chỉ IP public tĩnh duy nhất (single static public IP) để nhận traffic và xử lý request.
  • End users phải truy cập qua domain example.com.
  • Giải pháp phải bảo trì ứng dụng với nỗ lực tối thiểu, nghĩa là tránh các thành phần phức tạp như load balancing hay scaling không cần thiết, vì chỉ dùng một EC2 instance đơn lẻ.

Mục tiêu là chọn hai hành động kết hợp để đáp ứng: cung cấp IP tĩnh cho EC2 và map domain đến IP đó. Kiến thức AWS cập nhật đến 2026 (theo AWS Well-Architected Framework và dịch vụ EC2/Route 53 phiên bản mới nhất): EC2 instance mặc định có public IP động (thay đổi khi stop/start), nên cần Elastic IP (EIP) để tĩnh hóa; Route 53 dùng để DNS resolution cho domain.

✅ Đáp án đúng (Chọn TWO)

Hai phương án đúng là:

  • Create an Amazon Route 53 A record for the associated EC2 IP address.
  • Create an Elastic IP address, and associate it with the EC2 instance.

Lý do lựa chọn 🛠️:

  • Kết hợp này cung cấp IP public tĩnh (EIP) cho EC2 (giải quyết vấn đề IP động của EC2) và DNS record A map domain example.com trực tiếp đến EIP. Đây là giải pháp least effort: chỉ cần tạo EIP (miễn phí khi associate), associate với instance, và hosted zone Route 53 với A record. Không cần thêm layer như ALB hay ASG, phù hợp cho single instance. End users resolve domain → EIP → EC2.

📋 Phân tích chi tiết từng phương án

Dưới đây là giải thích tất cả các phương án, với đánh giá đúng/sai dựa trên yêu cầu "least effort" và static IP:

✅ Create an Amazon Route 53 A record for the associated EC2 IP address.
Phương án này ĐÚNG vì: Route 53 A record map trực tiếp domain (như example.com) đến IPv4 address (EIP của EC2). Đây là cách chuẩn cho apex domain, hỗ trợ IPv4, và tích hợp mượt mà với EC2. Least effort khi kết hợp với EIP.

✅ Create an Elastic IP address, and associate it with the EC2 instance.
Phương án này ĐÚNG vì: Elastic IP (EIP) cung cấp static public IPv4 không thay đổi ngay cả khi stop/start/reboot instance (khác với public IP động của EC2). Associate EIP chỉ mất vài giây qua Console/CLI, miễn phí nếu attached, và là giải pháp chuẩn cho yêu cầu "single static public IP". Least effort cho single instance.

❌ Configure an Application Load Balancer (ALB). Add the EC2 instance to a target group that is associated with the ALB.
Phương án này SAI vì: ALB sử dụng DNS name động (không phải static IP) và yêu cầu target group phức tạp hơn. ALB listener port 80/443, nhưng thêm overhead quản lý (health checks, scaling), không least effort cho single EC2. Người dùng cần static IP trực tiếp, ALB chỉ phù hợp multi-instance.

❌ Create an Amazon Route 53 CNAME record for the associated EC2 IP address.
Phương án này SAI vì: CNAME record không map trực tiếp đến IP (chỉ alias domain khác), và không dùng cho apex domain như example.com (theo RFC 1034, apex phải dùng A/AAAA). Dù dùng EIP, CNAME vẫn sai chuẩn và gây lỗi resolution. Route 53 khuyến nghị A record cho IP.

❌ Create an Auto Scaling group with a minimum capacity of 1 and a maximum capacity of 2.
Phương án này SAI vì: ASG tự động launch/terminate instances dựa trên metric, nhưng không đảm bảo static IP (mỗi instance mới có IP khác). Thêm complexity (launch template, scaling policy) không cần cho single instance cố định. Không least effort, chỉ dùng khi cần high availability/scaling.

📘 Tài liệu tham khảo (AWS cập nhật 2026)

Giải pháp này failover-proof nếu dùng Route 53 health checks sau! 🚀

Câu 816
A company is using an Amazon DynamoDB table for data. A SysOps administrator must configure replication of the table to another AWS Region for disaster recovery.

What should the SysOps administrator do to meet this requirement?
  1. A Enable DynamoDB Accelerator (DAX).
  2. B Enable DynamoDB Streams, and add a global secondary index (GSI).
  3. C Enable DynamoDB Streams, and add a global table Region.
  4. D Enable point-in-time recovery.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc cấu hình sao chép (replication) bảng Amazon DynamoDB sang một AWS Region khác để phục vụ disaster recovery (DR). 🔄

  • Bối cảnh: Một công ty đang sử dụng bảng DynamoDB làm nguồn dữ liệu chính. Quản trị viên SysOps cần thiết lập cơ chế sao chép dữ liệu thời gian thực (real-time) đến Region khác để đảm bảo tính sẵn sàng cao, giảm thiểu thời gian gián đoạn nếu xảy ra sự cố ở Region gốc (ví dụ: thiên tai, lỗi hạ tầng).
  • Yêu cầu chính: Giải pháp phải hỗ trợ multi-region replication tự động, đồng bộ dữ liệu thay đổi (insert, update, delete) mà không cần code thủ công.
  • Kiến thức AWS cập nhật 2026: DynamoDB Global Tables là tính năng chuẩn (standard) cho replication cross-region, sử dụng DynamoDB Streams làm nền tảng để propagate dữ liệu. Không cần VPC peering hay Lambda custom. (Phiên bản mới nhất: DynamoDB hỗ trợ Global Tables v2 với cải tiến độ trễ thấp hơn, on-demand capacity, và tích hợp IAM fine-grained access).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Enable DynamoDB Streams, and add a global table Region.
🛠️ Lý do chi tiết:

  • Để kích hoạt Global Tables, bạn phải enable DynamoDB Streams (capture mọi thay đổi dữ liệu) trước, sau đó add Region mới vào global table qua AWS Console, CLI hoặc SDK.
  • Global Tables tự động replicate dữ liệu multi-master (mỗi Region độc lập writable/readable), lý tưởng cho DR với RTO/RPO thấp (<1 giây latency).
  • Đây là giải pháp native, serverless của AWS, không downtime khi add Region.
    📘 Dẫn nguồn: AWS DynamoDB Global Tables Documentation (cập nhật 2025-2026, hỗ trợ 30+ Regions).

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Mỗi phương án được đánh giá với lý do cụ thể dựa trên tính năng AWS:

  • ❌ Enable DynamoDB Accelerator (DAX).
    Sai vì DAX là bộ đệm in-memory (caching layer) để tăng tốc đọc dữ liệu cục bộ, không hỗ trợ replication cross-region. Nó chỉ hoạt động trong cùng Region, không dành cho DR. 🗑️

  • ❌ Enable DynamoDB Streams, and add a global secondary index (GSI).
    Sai vì DynamoDB Streams chỉ capture changes (không tự replicate). GSI là index phụ để query hiệu quả hơn trong cùng bảng/Region, không liên quan đến cross-region replication. Bạn cần code Lambda/DynamoDB Triggers để consume Streams thủ công – không phải giải pháp native cho DR. 🚫

  • ✅ Enable DynamoDB Streams, and add a global table Region.
    Đúng hoàn toàn! Như đã giải thích ở trên: Streams + Global Table là công thức chuẩn để enable replication tự động, multi-active across Regions. Hỗ trợ conflict resolution (last-writer-wins). Hoàn hảo cho DR! 🌟

  • ❌ Enable point-in-time recovery.
    Sai vì PITR cho phép backup và restore dữ liệu đến điểm thời gian cụ thể (35 ngày giữ), nhưng không phải replication real-time. Nó chỉ dùng cho recovery trong cùng Region, RPO cao (không đồng bộ liên tục). Phù hợp backup hơn DR cross-region. ⏰

Câu 817
A company has an existing public web application for www.example.com. The Application Load Balancer (ALB) is configured with a single HTTP 80 listener. A SysOps administrator must ensure that all web requests to www.example.com are encrypted between the client and the ALB.

The SysOps administrator already has requested and validated a public certificate for www.example.com in AWS Certificate Manager (ACM). Existing users of the application must not be required to change the endpoint to which they are connecting.

Which additional set of steps should the SysOps administrator take to meet these requirements?
  1. A Create an additional ALB listener for HTTPS on port 443. Set the default action to forward all traffic to the target group. Specify the ACM certificate that was created for www.example.com as the default SSL certificate.
  2. B Create an additional ALB listener for HTTPS on port 443. Set the default action to forward all traffic to the target group. Specify the ACM certificate that was created for www.example.com as the default SSL certificate. Delete the original HTTP listener on port 80.
  3. C Modify the ALB default rule for the HTTP port 80 listener. Create a rule in the listener to forward all traffic for the host www example.com to the target group. Specify the ACM certificate that was created for www.example.com as the default SSL certificate.
  4. D Modify the ALB default rule for the HTTP port 80 listener to redirect to HTTPS on port 443. Create an additional HTTPS listener on port 443. Set the default action to forward all traffic to the target group. Specify the ACM certificate that was created for www example.com as the default SSL certificate.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh việc bảo mật hóa kết nối (encryption) giữa client (người dùng) và Application Load Balancer (ALB) cho ứng dụng web công khai tại www.example.com. Hiện tại:

  • ALB chỉ có một listener HTTP trên port 80 (không mã hóa).
  • Yêu cầu: Tất cả request phải được mã hóa (HTTPS) giữa client và ALB.
  • Đã có chứng chỉ công khai (public certificate) được request và validate trong AWS Certificate Manager (ACM) cho domain www.example.com.
  • Quan trọng nhất: Người dùng hiện tại KHÔNG được yêu cầu thay đổi endpoint (vẫn truy cập http://www.example.com như cũ, không cần chuyển sang https:// thủ công).

Mục tiêu là thêm HTTPS mà không làm gián đoạn trải nghiệm người dùng, bằng cách sử dụng redirect từ HTTP sang HTTPS và cấu hình listener mới. Đây là best practice của AWS để enforce TLS/SSL termination tại ALB (theo cập nhật AWS ELBv2 đến 2026, hỗ trợ ACM integration seamless).

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Modify the ALB default rule for the HTTP port 80 listener to redirect to HTTPS on port 443. Create an additional HTTPS listener on port 443. Set the default action to forward all traffic to the target group. Specify the ACM certificate that was created for www example.com as the default SSL certificate.

Lý do 🛠️:

  • Redirect HTTP 80 sang HTTPS 443: Giữ nguyên listener HTTP để "bắt" request từ user cũ (không thay đổi endpoint), sau đó tự động redirect (HTTP 301/302) sang HTTPS → đảm bảo encryption mà không gián đoạn.
  • Thêm listener HTTPS 443: Forward traffic đến target group (EC2/ECS/Fargate), attach ACM cert để terminate SSL tại ALB (offload encryption).
  • Hoàn hảo match yêu cầu: Encryption enforced, user transparent, sử dụng ACM cert đã có. Đây là standard pattern trong AWS Well-Architected Framework (Security Pillar).

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng lựa chọn (giữ nguyên văn bản gốc bằng tiếng Anh). Tôi đánh dấu ✅ đúng hoặc ❌ sai, kèm lý do chi tiết bằng tiếng Việt.

  • ❌ [SAI] Create an additional ALB listener for HTTPS on port 443. Set the default action to forward all traffic to the target group. Specify the ACM certificate that was created for www.example.com as the default SSL certificate.
    Lý do sai: Chỉ thêm HTTPS 443 (tốt cho encryption), nhưng KHÔNG xử lý listener HTTP 80 hiện tại. User truy cập HTTP vẫn không được mã hóa (traffic plain-text), vi phạm "all web requests encrypted". Không redirect → user phải tự đổi endpoint (không cho phép).

  • ❌ [SAI] Create an additional ALB listener for HTTPS on port 443. Set the default action to forward all traffic to the target group. Specify the ACM certificate that was created for www.example.com as the default SSL certificate. Delete the original HTTP listener on port 80.
    Lý do sai: Thêm HTTPS tốt, nhưng delete HTTP 80 buộc user phải đổi endpoint sang https://www.example.com (vi phạm yêu cầu rõ ràng). Gây downtime/outage cho user cũ, không graceful migration.

  • ❌ [SAI] Modify the ALB default rule for the HTTP port 80 listener. Create a rule in the listener to forward all traffic for the host www example.com to the target group. Specify the ACM certificate that was created for www.example.com as the default SSL certificate.
    Lý do sai: Chỉ modify rule trên HTTP 80 (vẫn forward plain-text, không encryption). Cert ACM chỉ dùng cho HTTPS listener, không attach được vào HTTP (AWS không hỗ trợ SSL trên HTTP port). Không tạo HTTPS listener → không đạt encryption giữa client-ALB.

  • ✅ [ĐÚNG] Modify the ALB default rule for the HTTP port 80 listener to redirect to HTTPS on port 443. Create an additional HTTPS listener on port 443. Set the default action to forward all traffic to the target group. Specify the ACM certificate that was created for www example.com as the default SSL certificate.
    Lý do đúng (tóm tắt): Kết hợp redirect HTTP → HTTPS + listener HTTPS với cert → encryption full, user không đổi endpoint. Zero-downtime, scalable (ALB auto-scale theo traffic).

🔥 Lời khuyên thực tế: Sau implement, monitor CloudWatch metrics (HealthyHostCount, HTTPCode_ELB_3XX_Count) và enable AWS WAF để bảo vệ thêm. Test bằng curl -I http://www.example.com để verify redirect!

Câu 818
A company runs its entire suite of applications on Amazon EC2 instances. The company plans to move the applications to containers and AWS Fargate. Within 6 months, the company plans to retire its EC2 instances and use only Fargate. The company has been able to estimate its future Fargate costs.

A SysOps administrator needs to choose a purchasing option to help the company minimize costs. The SysOps administrator must maximize any discounts that are available and must ensure that there are no unused reservations.

Which purchasing option will meet these requirements?
  1. A Compute Savings Plans for 1 year with the No Upfront payment option
  2. B Compute Savings Plans for 1 year with the Partial Upfront payment option
  3. C EC2 Instance Savings Plans for 1 year with the All Upfront payment option
  4. D EC2 Reserved Instances for 1 year with the Partial Upfront payment option
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi xoay quanh một công ty đang chạy toàn bộ ứng dụng trên Amazon EC2 instances, nhưng họ lập kế hoạch chuyển sang containers và AWS Fargate trong vòng 6 tháng tới. Sau đó, họ sẽ ngừng sử dụng EC2 hoàn toàn (retire EC2) và chỉ dùng Fargate. Công ty đã ước tính được chi phí Fargate tương lai.

SysOps administrator cần chọn purchasing option (lựa chọn mua sắm) để:

  • Giảm thiểu chi phí tối đa (minimize costs).
  • Tối ưu hóa các khoản giảm giá có sẵn (maximize discounts).
  • Đảm bảo không có reservations không sử dụng (no unused reservations).

🔑 Điểm then chốt:

  • Trong 6 tháng đầu, vẫn dùng EC2 song song với Fargate.
  • Sau 6 tháng: Chỉ Fargate.
  • Cần purchasing option linh hoạt (flexible) áp dụng cho cả EC2 và Fargate, commitment 1 năm để cover toàn bộ giai đoạn chuyển đổi, và tối ưu discount mà không lãng phí (không apply cho instance cụ thể có thể unused).

📘 Kiến thức AWS cập nhật (tính đến 2026): AWS Fargate hỗ trợ Compute Savings Plans (ra mắt 2019, vẫn là standard). Compute Savings Plans áp dụng cho EC2, Lambda, Fargate với commitment hourly spend (không ràng buộc instance cụ thể). EC2 Instance Savings Plans và Reserved Instances (RI) chỉ dành riêng cho EC2 (không cover Fargate). Payment options: No Upfront (discount thấp nhất), Partial Upfront (cân bằng discount cao + linh hoạt cashflow), All Upfront (discount cao nhất nhưng khóa tiền).

Nguồn tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Compute Savings Plans for 1 year with the Partial Upfront payment option.

🛠️ Lý do chi tiết:

  • Compute Savings Plans linh hoạt nhất: Áp dụng cho EC2 (6 tháng đầu) và Fargate (sau đó), dựa trên hourly commitment (không unused vì tự động apply cho usage đúng mức ước tính).
  • 1 year term: Phù hợp kế hoạch chuyển đổi (6 tháng + tương lai), cover đầy đủ mà không ngắn/lâu.
  • Partial Upfront: Maximize discounts (discount cao hơn No Upfront ~20-40% so với On-Demand, gần All Upfront) + linh hoạt cashflow (không khóa hết tiền như All Upfront). Đảm bảo no unused reservations vì flexible, không ràng buộc instance/type.
  • Kết quả: Tiết kiệm tối đa (lên đến 66% vs On-Demand), phù hợp migrate workload.

📋 Giải thích tất cả các phương án (Đúng/Sai)

  • ✅ [ĐÚNG] Compute Savings Plans for 1 year with the Partial Upfront payment option
    🟢 Đúng vì: Như phân tích trên – Linh hoạt cover EC2 + Fargate, commitment 1 năm khớp kế hoạch, Partial Upfront tối ưu discount (cao hơn No Upfront) mà không rủi ro unused (tự động apply usage). Hoàn hảo cho migrate!

  • ❌ [SAI] Compute Savings Plans for 1 year with the No Upfront payment option
    🔴 Sai vì: Mặc dù Compute Savings Plans linh hoạt (cover EC2/Fargate), nhưng No Upfront chỉ discount thấp nhất (~15-30% vs On-Demand). Không maximize discounts như yêu cầu (Partial/All Upfront tiết kiệm hơn đáng kể).

  • ❌ [SAI] EC2 Instance Savings Plans for 1 year with the All Upfront payment option
    🔴 Sai vì: EC2 Instance Savings Plans chỉ apply cho instance families cụ thể trên EC2 (không cover Fargate). Sau 6 tháng retire EC2 → unused reservations (vi phạm yêu cầu), dù All Upfront discount cao (~50-70%).

  • ❌ [SAI] EC2 Reserved Instances for 1 year with the Partial Upfront payment option
    🔴 Sai vì: EC2 Reserved Instances (RI) ràng buộc instance type/size/zone cụ thể trên EC2 (không flexible sang Fargate). Khi retire EC2 → unused RI (phải modify/sell, phức tạp), không đảm bảo no unused và kém linh hoạt cho migrate.

🎯 Kết luận: Chọn Compute Savings Plans Partial Upfront là best practice cho workload containerized trên Fargate (AWS khuyến nghị trong Cost Optimization Pillar)! 🚀

Câu 819
A manufacturing company uses an Amazon RDS DB instance to store inventory of all stock items. The company maintains several AWS Lambda functions that interact with the database to add, update, and delete items. The Lambda functions use hardcoded credentials to connect to the database.

A SysOps administrator must ensure that the database credentials are never stored in plaintext and that the password is rotated every 30 days.

Which solution will meet these requirements in the MOST operationally efficient manner?
  1. A Store the database password as an environment variable for each Lambda function. Create a new Lambda function that is named PasswordRotate. Use Amazon EventBridge to schedule the PasswordRotate function every 30 days to change the database password and update the environment variable for each Lambda function.
  2. B Use AWS Key Management Service (AWS KMS) to encrypt the database password and to store the encrypted password as an environment variable for each Lambda function. Grant each Lambda function access to the KMS key so that the database password can be decrypted when required. Create a new Lambda function that is named PasswordRotate to change the password every 30 days.
  3. C Use AWS Secrets Manager to store credentials for the database. Create a Secrets Manager secret, and select the database so that Secrets Manager will use a Lambda function to update the database password automatically. Specify an automatic rotation schedule of 30 days. Update each Lambda function to access the database password from Secrets Manager.
  4. D Use AWS Systems Manager Parameter Store to create a secure string to store credentials for the database. Create a new Lambda function called PasswordRotate. Use Amazon EventBridge to schedule the PasswordRotate function every 30 days to change the database password and to update the secret within Parameter Store. Update each Lambda function to access the database password from Parameter Store.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả một công ty sản xuất sử dụng Amazon RDS DB instance để lưu trữ danh mục hàng tồn kho. Họ có nhiều AWS Lambda functions tương tác với cơ sở dữ liệu (thêm, cập nhật, xóa hàng hóa), nhưng hiện đang sử dụng hardcoded credentials (tên người dùng và mật khẩu cố định trực tiếp trong code) – điều này rất rủi ro vì credentials lưu plaintext và dễ bị lộ.

Yêu cầu chính của SysOps administrator:

  • Không lưu credentials dưới dạng plaintext (phải mã hóa hoặc quản lý an toàn).
  • Tự động xoay (rotate) password mỗi 30 ngày.
  • Giải pháp phải MOST operationally efficient (hiệu quả vận hành nhất: ít công sức quản lý, tự động hóa cao, ít component tùy chỉnh).

📘 Kiến thức cập nhật AWS (đến 2026): AWS khuyến nghị sử dụng AWS Secrets Manager cho việc quản lý secrets động với rotation tự động cho RDS (hỗ trợ MySQL, PostgreSQL, SQL Server, Oracle, MariaDB). Parameter Store (SecureString) chỉ mã hóa nhưng không rotate tự động. KMS dùng cho mã hóa nhưng không quản lý rotation. (Nguồn: AWS Secrets Manager Rotation Docs, RDS Integration).

✅ Đáp án đúng

Use AWS Secrets Manager to store credentials for the database. Create a Secrets Manager secret, and select the database so that Secrets Manager will use a Lambda function to update the database password automatically. Specify an automatic rotation schedule of 30 days. Update each Lambda function to access the database password from Secrets Manager.

Lý do chọn đáp án này (hiệu quả vận hành nhất):

  • 🛡️ Không lưu plaintext: Secrets Manager mã hóa secrets tại rest (dùng KMS default hoặc custom key) và cung cấp API để retrieve tạm thời.
  • 🔄 Rotation tự động: Chọn RDS DB khi tạo secret → Secrets Manager tự tạo Lambda rotation function (không cần code custom), cập nhật password trên DB và secret. Lên lịch 30 ngày qua console/CLI/API.
  • 🚀 Hiệu quả cao: Ít component (chỉ Secrets Manager + IAM roles cho Lambda retrieve secret), tích hợp native với RDS/Lambda. Lambda functions dùng get_secret_value() API để fetch password động (không env var cố định).
  • 💰 Chi phí tối ưu: Rotation Lambda chỉ chạy định kỳ, không cần EventBridge custom.
  • ✅ Hoàn toàn tuân thủ AWS best practices (zero-effort rotation cho RDS).

❌ Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá dựa trên yêu cầu (không plaintext + rotate 30 ngày + operationally efficient).

  • ❌ [SAI] Store the database password as an environment variable for each Lambda function. Create a new Lambda function that is named PasswordRotate. Use Amazon EventBridge to schedule thePasswordRotate function every 30 days to change the database password and update the environment variable for each Lambda function.

    • Lý do sai: Env var lưu plaintext (Lambda env vars không mã hóa mặc định, dễ đọc qua console/logs). Phải tự code Lambda PasswordRotate để update password RDS + update env vars (cần redeploy tất cả Lambda → downtime, phức tạp). EventBridge schedule thủ công → không efficient (nhiều component tùy chỉnh, dễ lỗi).
  • ❌ [SAI] Use AWS Key Management Service (AWS KMS) to encrypt the database password and to store the encrypted password as an environment variable for each Lambda function. Grant each Lambda function access to the KMS key so that the database password can be decrypted when required. Create a new Lambda function that is named PasswordRotate to change the password every 30 days.

    • Lý do sai: Env var encrypted bằng KMS vẫn yêu cầu Lambda decrypt lúc runtime (plaintext tạm thời trong memory/logs). Không tự động rotate – phải tự code Lambda PasswordRotate (update RDS + re-encrypt + redeploy env vars). Grant IAM policy cho KMS → phức tạp, không efficient (KMS chỉ mã hóa, không quản lý secrets/rotation).
  • ✅ [ĐÚNG] Use AWS Secrets Manager to store credentials for the database. Create a Secrets Manager secret, and select the database so that Secrets Manager will use a Lambda function to update the database password automatically. Specify an automatic rotation schedule of 30 days. Update each Lambda function to access the database password from Secrets Manager.

    • Lý do đúng (như phần trên): Native rotation cho RDS, zero custom code, fetch động qua API. Hoàn hảo về efficiency!
  • ❌ [SAI] Use AWS Systems Manager Parameter Store to create a secure string to store credentials for the database. Create a new Lambda function called PasswordRotate. Use Amazon EventBridge to schedule the PasswordRotate function every 30 days to change the database password and to update the secret within Parameter Store. Update each Lambda function to access the database password from Parameter Store.

    • Lý do sai: Parameter Store SecureString mã hóa tốt (dùng KMS), nhưng không hỗ trợ rotation tự động cho RDS (chỉ store, phải custom Lambda PasswordRotate + EventBridge để update DB và Parameter). Lambda fetch qua SSM API → thêm IAM policy, ít efficient hơn Secrets Manager (Secrets Manager rẻ hơn cho secrets động, tích hợp rotation native). (Nguồn: SSM Parameter Store Limits).

🛠️ Khuyến nghị triển khai thực tế

  • Tạo Secret: Console Secrets Manager → Store new secret → RDS → Chọn DB instance → Rotation: Enable, 30 days.
  • Lambda code: Dùng boto3.client('secretsmanager').get_secret_value(SecretId='my-rds-secret').
  • IAM: secretsmanager:GetSecretValue cho Lambda role.
  • Test rotation: Manual rotate trước khi enable schedule.

📘 Tài liệu tham khảo chính:

Câu 820
A developer creates a web application that runs on Amazon EC2 instances behind an Application Load Balancer (ALB). The instances are in an Auto Scaling group. The developer reviews the deployment and notices some suspicious traffic to the application. The traffic is malicious and is coming from a single public IP address. A SysOps administrator must block the public IP address.

Which solution will meet this requirement?
  1. A Create a security group rule to deny all inbound traffic from the suspicious IP address. Associate the security group with the ALB.
  2. B Implement Amazon Detective to monitor traffic and to block malicious activity from the internet. Configure Detective to integrate with the ALB.
  3. C Implement AWS Resource Access Manager (AWS RAM) to manage traffic rules and to block malicious activity from the internet. Associate AWS RAM with the ALB.
  4. D Add the malicious IP address to an IP set in AWS WAF. Create a web ACL. Include an IP set rule with the action set to BLOCK. Associate the web ACL with the ALB.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi mô tả một tình huống thực tế trong môi trường AWS: Một developer đã xây dựng ứng dụng web chạy trên các instance Amazon EC2, nằm sau Application Load Balancer (ALB) và thuộc Auto Scaling group (ASG). Khi kiểm tra deployment, phát hiện traffic đáng ngờ (malicious traffic) từ một địa chỉ IP public duy nhất. SysOps administrator cần block IP này một cách hiệu quả.

📌 Yêu cầu chính: Tìm giải pháp block traffic từ IP cụ thể mà không ảnh hưởng đến hệ thống khác. Điều này đòi hỏi công cụ bảo mật layer 7 (application layer) phù hợp với ALB, vì ALB xử lý HTTP/HTTPS traffic và cần filter tinh vi dựa trên IP nguồn. Giải pháp phải nhanh chóng, scalable và tích hợp trực tiếp với ALB. Kiến thức cập nhật đến 2026: AWS WAF v2.0 hỗ trợ IP sets động, rules với action BLOCK, và tích hợp seamless với ALB/ALB-integrated services.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng:
Add the malicious IP address to an IP set in AWS WAF. Create a web ACL. Include an IP set rule with the action set to BLOCK. Associate the web ACL with the ALB.

🛠️ Lý do chi tiết:

  • AWS WAF (Web Application Firewall) là dịch vụ bảo vệ layer 7 lý tưởng cho ALB, cho phép tạo IP set (bộ sưu tập IP/CIDR) chứa IP malicious, sau đó thêm vào web ACL (Access Control List) với rule IP set action BLOCK – chặn hoàn toàn traffic từ IP đó.
  • Quy trình: Tạo IP set → Web ACL → Rule BLOCK → Associate với ALB (hỗ trợ native từ AWS WAF v2).
  • Ưu điểm: Scalable, real-time update (thêm IP mới nhanh chóng), không ảnh hưởng ASG/EC2, chi phí pay-per-rule. Cập nhật 2026: WAF hỗ trợ Managed Rules cho DDoS/IP reputation tự động.
  • Đây là best practice cho ALB protection theo AWS Well-Architected Framework (Security Pillar).

🔍 Phân tích tất cả các phương án

  • Create a security group rule to deny all inbound traffic from the suspicious IP address. Associate the security group with the ALB.
    ❌ Sai: Security Groups (SG) chỉ hỗ trợ ALLOW rules (stateless, implicit deny all else), không có cơ chế DENY explicit cho IP cụ thể. ALB dùng SG chỉ filter layer 4 (port/protocol), không hiệu quả cho IP source filtering tinh vi ở layer 7. Nếu attach SG với rule deny giả lập, sẽ fail validation và không block được traffic HTTP malicious. Không phải best practice cho ALB.

  • Implement Amazon Detective để monitor traffic và to block malicious activity from the internet. Configure Detective to integrate with the ALB.
    ❌ Sai: Amazon Detective là tool investigative analytics (phân tích log từ VPC Flow Logs, GuardDuty) để phát hiện/thu thập evidence, không có chức năng block traffic real-time. Nó không integrate trực tiếp với ALB để block IP, chỉ hỗ trợ query data sau sự kiện. Sử dụng cho forensics, không phải mitigation.

  • Implement AWS Resource Access Manager (AWS RAM) để manage traffic rules và to block malicious activity from the internet. Associate AWS RAM with the ALB.
    ❌ Sai: AWS RAM dùng để chia sẻ resources cross-account (như SG, Transit Gateway), không quản lý traffic rules hay block IP. Không liên quan đến ALB protection hoặc WAF rules. Associate RAM với ALB sẽ không có hiệu quả, chỉ gây confusion.

  • Add the malicious IP address to an IP set in AWS WAF. Create a web ACL. Include an IP set rule with the action set to BLOCK. Associate the web ACL with the ALB.
    ✅ Đúng: Như giải thích ở trên. Đây là giải pháp chuẩn, nhanh (deploy <5 phút), và scalable cho single/multiple IPs. Hỗ trợ rate limiting/DDoS nếu cần mở rộng.

📘 Tài liệu tham khảo

Hy vọng phân tích này giúp bạn nắm vững kiến thức DevOps trên AWS! 🚀 Nếu cần lab thực hành, thử AWS Console WAF ngay nhé!