CertHub
AWSFoundationalCLF-C02

AWS Certified Cloud Practitioner

Tất cả lời giải

CLF-C02 Mock Exam #01 — Solutions / Giải đề chi tiết

Bilingual: 🇬🇧 English + 🇻🇳 Tiếng Việt
Each answer references back to Knowledge/ files
How to use: Compare your answers, read explanations, understand the "why"


Score Calculation / Cách tính điểm

  • 50/65 questions are scored (15 unscored — you don't know which ones)
  • Pass mark: ≥700/1000 → equivalent to ~35/50 scored questions correct
  • Self-target: ≥52/65 (80%) = very confident for exam day

Domain Score Tracker

DomainYour ScoreTotal%
1: Cloud Concepts__/1616__
2: Security & Compliance__/2020__
3: Cloud Tech & Services__/2222__
4: Billing, Pricing, Support__/77__
TOTAL__/6565__

Domain 1: Cloud Concepts (Q1–Q16)

Q1.

Which of the following best describes the concept of elasticity in cloud computing?

Bản dịch tiếng Việt: Điều nào sau đây mô tả đúng nhất khái niệm về tính đàn hồi trong điện toán đám mây?

A. The ability to purchase servers at a lower cost due to volume discounts B. The ability to automatically scale computing resources based on demand and reduce them when not needed C. The ability to run applications on multiple servers simultaneously for performance D. The ability to migrate applications between different cloud providers

Correct answer: B Bản dịch đáp án đúng: B. Khả năng tự động mở rộng quy mô tài nguyên máy tính dựa trên nhu cầu và giảm bớt chúng khi không cần thiết

🇬🇧 Explanation:
Elasticity is a core cloud principle — resources automatically scale up when demand increases and scale down when demand decreases, without manual intervention. This is what makes cloud "elastic" — it adapts to your needs like a rubber band.

🇻🇳 Giải thích:
Elasticity là khả năng tự động mở rộng/thu nhỏ tài nguyên theo nhu cầu thực tế. Khi traffic tăng → thêm servers; khi traffic giảm → xóa servers. Không phải mua sắn trước (fixed), mà co giãn theo nhu cầu.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — "volume discounts" ≠ elasticity (that's "economies of scale") / "Giảm giá theo số lượng" không phải elasticity, mà là "economies of scale".
  • C — Simultaneous servers ≠ elasticity (that's "scalability") / Chạy nhiều servers cùng lúc không phải elasticity, mà là "scalability".
  • D — Multi-cloud migration ≠ elasticity (that's "portability") / Di chuyển multi-cloud không phải elasticity, mà là "portability".

🔑 Key Concept / Khái niệm cốt lõi: Elasticity = automatic scale-up/down based on demand (Scalability = can grow, but might be manual) / Elasticity = tự động mở rộng/thu nhỏ theo nhu cầu (Scalability = có thể tăng nhưng có thể phải làm thủ công).

📚 Reference: Domain 1 § "NIST 5 Characteristics" — Rapid Elasticity


Q2.

A company is transitioning from on-premises infrastructure to AWS. Which of the following best describes the financial advantage of this transition?

Bản dịch tiếng Việt: Một công ty đang chuyển đổi từ cơ sở hạ tầng tại chỗ sang AWS. Điều nào sau đây mô tả đúng nhất lợi ích tài chính của quá trình chuyển đổi này?

A. Eliminates the need for capital expenditure and shifts to operational expenditure B. Reduces the total cost of ownership by 100% C. Allows the company to avoid all hardware purchases D. Guarantees lower monthly costs than on-premises solutions

Correct answer: A Bản dịch đáp án đúng: A. Loại bỏ nhu cầu chi tiêu vốn và chuyển sang chi tiêu hoạt động

🇬🇧 Explanation:
Cloud computing shifts from CapEx (capital expenditure — buying servers upfront) to OpEx (operational expenditure — monthly billing). This is a fundamental business advantage of cloud.

🇻🇳 Giải thích:
Trước: Công ty phải mua servers đắt tiền (CapEx, viết là tài sản). Bây giờ: Dùng AWS, chỉ trả tiền hàng tháng theo dùng (OpEx, viết là chi phí). Linh hoạt hơn, không bị vốn "chết".

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B — Cloud doesn't reduce cost by 100% — it optimizes, not eliminates / Cloud không giảm chi phí 100% — nó tối ưu chứ không loại bỏ hoàn toàn.
  • C — You still buy/rent services, just not physical servers / Bạn vẫn mua/thuê dịch vụ, chỉ là không mua servers vật lý.
  • D — AWS isn't always cheaper — depends on usage pattern / AWS không phải lúc nào cũng rẻ hơn — tùy vào mô hình sử dụng.

🔑 Key Concept / Khái niệm cốt lõi: CapEx → OpEx = financial model shift, not guarantee of cost reduction / CapEx → OpEx = thay đổi mô hình tài chính, không phải đảm bảo giảm chi phí.

📚 Reference: Domain 1 § "6 Advantages of Cloud" — Trade CapEx for OpEx


Q3.

Which AWS cloud deployment model requires the customer to own and maintain all physical infrastructure?

Bản dịch tiếng Việt: Mô hình triển khai đám mây AWS nào yêu cầu khách hàng sở hữu và duy trì tất cả cơ sở hạ tầng vật lý?

A. Public Cloud B. Private Cloud (on-premises) C. Hybrid Cloud D. Multi-Cloud

Correct answer: B Bản dịch đáp án đúng: B. Đám mây riêng (tại chỗ)

🇬🇧 Explanation:
Private Cloud means the infrastructure is owned and operated by the company itself (on-premises). The company is responsible for building, maintaining, and securing the physical data center.

🇻🇳 Giải thích:
Private Cloud = Công ty sở hữu servers riêng (trên máy chủ của công ty, gọi là on-premises). Công ty quản lý hết: mua, bảo trì, bảo mật.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Public Cloud is owned by AWS/cloud provider / Public Cloud thuộc sở hữu của AWS/nhà cung cấp cloud.
  • C — Hybrid Cloud is mix of public + private / Hybrid Cloud là kết hợp public + private.
  • D — Multi-Cloud is 2+ providers (not ownership model) / Multi-Cloud là dùng 2+ nhà cung cấp (không phải mô hình sở hữu).

🔑 Key Concept / Khái niệm cốt lõi: Private Cloud = on-premises = customer-owned infrastructure / Private Cloud = on-premises = hạ tầng do khách hàng sở hữu.

📚 Reference: Domain 1 § "Cloud Deployment Models" — Private Cloud


Q4. (Select TWO)

Which of the following are advantages of cloud computing according to AWS? (Select TWO)

Bản dịch tiếng Việt: Đâu là ưu điểm của điện toán đám mây theo AWS? (Chọn HAI)

A. Ability to instantly increase computing capacity without upfront investment B. Responsibility for maintaining all data center infrastructure C. Ability to pay only for what you use rather than guessing capacity D. Elimination of the need for security measures E. Guaranteed elimination of all application downtime

Correct answer: A, C Bản dịch đáp án đúng: A. Khả năng tăng ngay lập tức khả năng tính toán mà không cần đầu tư trước; C. Khả năng chỉ trả tiền cho những gì bạn sử dụng hơn là đoán khả năng

🇬🇧 Explanation:

  • A (Instant capacity without upfront) ✅ = "Stop guessing capacity" advantage
  • C (Pay for what you use) ✅ = "Trade CapEx for OpEx" + metering advantage
  • B ❌ = AWS maintains data centers, not the customer
  • D ❌ = Cloud still requires security measures
  • E ❌ = AWS never guarantees the elimination of all downtime; cloud improves availability but does not promise zero downtime

🇻🇳 Giải thích:
Câu A: Thêm servers ngay (không cần chờ vài tuần để mua + setup) = lợi ích của "Rapid Elasticity"
Câu C: Dùng bao nhiêu trả bấy nhiêu (không mua thừa) = lợi ích của "Metering" + OpEx

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B — AWS maintains data centers, not customer / AWS bảo trì data center, không phải khách hàng.
  • D — Cloud requires SAME security measures, just different responsibility / Cloud vẫn cần các biện pháp bảo mật như cũ, chỉ khác về phân chia trách nhiệm.
  • E — AWS does not guarantee zero downtime — it improves availability, not a guarantee / AWS không đảm bảo zero downtime — nó cải thiện độ sẵn sàng chứ không cam kết.

🔑 Key Concept / Khái niệm cốt lõi: AWS 6 Advantages — Rapid capacity, Economies of scale, CapEx→OpEx, Speed/agility, No DC cost, Go global / 6 lợi ích của AWS — Năng lực tức thì, Lợi thế quy mô, CapEx→OpEx, Tốc độ/linh hoạt, Không tốn chi phí data center, Vươn ra toàn cầu.

📚 Reference: Domain 1 § "6 Advantages of Cloud Computing"


Q5.

A startup needs to serve users globally with low latency. Which AWS capability best enables this?

Bản dịch tiếng Việt: Một công ty khởi nghiệp cần phục vụ người dùng trên toàn cầu với độ trễ thấp. Khả năng AWS nào cho phép điều này tốt nhất?

A. AWS Regions distributed worldwide that can be deployed in minutes B. On-premises infrastructure optimization C. Consolidated billing across multiple accounts D. AWS Organizations management console

Correct answer: A Bản dịch đáp án đúng: A. Các khu vực AWS được phân phối trên toàn thế giới có thể được triển khai trong vài phút

🇬🇧 Explanation:
AWS Regions are distributed worldwide (33+ regions). You can deploy your application in a region closest to users, and CloudFront caches content at edge locations for even lower latency.

🇻🇳 Giải thích:
AWS có ~30 regions toàn thế giới. Bạn deploy app ở region gần users (e.g., Singapore region cho users Đông Nam Á) = latency thấp. Không cần xây data center riêng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B — On-premises means local only, not global / On-premises chỉ phục vụ cục bộ, không toàn cầu.
  • C — Consolidated billing is cost management, not latency / Consolidated billing là quản lý chi phí, không liên quan latency.
  • D — Organizations is account management, not latency / Organizations là quản lý account, không liên quan latency.

🔑 Key Concept / Khái niệm cốt lõi: Regions + CloudFront = global low-latency delivery / Regions + CloudFront = phân phối toàn cầu với latency thấp.

📚 Reference: Domain 1 § "AWS Global Infrastructure" — Regions & Edge Locations


Q6.

What is an Availability Zone (AZ) in AWS?

Bản dịch tiếng Việt: Availability Zone (AZ) trong AWS là gì?

A. A geographical area that spans multiple countries B. A physical location containing isolated data centers with independent power and cooling C. A software layer that manages all AWS services D. A security perimeter that protects resources from external access

Correct answer: B Bản dịch đáp án đúng: B. Một vị trí vật lý chứa các trung tâm dữ liệu biệt lập với nguồn điện và hệ thống làm mát độc lập

🇬🇧 Explanation:
An AZ is a physical location with one or more isolated data centers. Each AZ has independent power, cooling, and networking — if one AZ fails, others are unaffected.

🇻🇳 Giải thích:
AZ = 1+ data centers độc lập (có power riêng, cooling riêng, network riêng). Nếu AZ1 mất điện → AZ2, AZ3 vẫn hoạt động. Đó là chìa khóa HA (High Availability).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Spans multiple countries = Region (not AZ) / Trải rộng nhiều quốc gia là Region (không phải AZ).
  • C — AWS services layer ≠ AZ (AZ is physical location) / Lớp dịch vụ AWS không phải AZ (AZ là vị trí vật lý).
  • D — Security perimeter = Security Group (not AZ) / Vành đai bảo mật là Security Group (không phải AZ).

🔑 Key Concept / Khái niệm cốt lõi: AZ = isolation + low-latency cross-AZ (10ms) / AZ = cô lập + độ trễ thấp giữa các AZ (10ms).

📚 Reference: Domain 1 § "AWS Global Infrastructure" — Availability Zones


Q7. (Select TWO)

Which of the following are characteristics of the AWS Well-Architected Framework? (Select TWO)

Bản dịch tiếng Việt: Đặc điểm nào sau đây là đặc điểm của AWS Well-Architected Framework? (Chọn HAI)

A. It requires all applications to run on EC2 instances B. Operational Excellence focuses on running and monitoring systems efficiently C. Reliability emphasizes the ability to automatically recover from failures D. It mandates the use of AWS Outposts E. It applies only to applications hosted in a single Availability Zone

Correct answer: B, C Bản dịch đáp án đúng: B. Hoạt động xuất sắc tập trung vào việc vận hành và giám sát hệ thống một cách hiệu quả; C. Độ tin cậy nhấn mạnh khả năng tự động phục hồi sau lỗi

🇬🇧 Explanation:

  • B ✅ = Operational Excellence pillar focuses on automate, small changes, anticipate failure, continuous improvement
  • C ✅ = Reliability pillar emphasizes auto-recovery, multi-AZ, health checks, auto-scaling
  • A ❌ = No requirement to use EC2
  • D ❌ = No mandate for Outposts
  • E ❌ = The framework is not limited to single-AZ apps; it explicitly promotes multi-AZ/multi-Region resilience

🇻🇳 Giải thích:
Câu B: Operational Excellence = chạy & cải tiến hiệu quả (tự động hóa, thay đổi nhỏ)
Câu C: Reliability = tự phục hồi từ lỗi (multi-AZ, health checks, auto-scale)

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Framework is service-agnostic / Framework không phụ thuộc dịch vụ cụ thể.
  • D — Outposts is optional for hybrid / Outposts là tùy chọn cho hybrid.
  • E — Framework applies to any architecture and encourages multi-AZ/multi-Region, not single-AZ only / Framework áp dụng cho mọi kiến trúc và khuyến khích multi-AZ/multi-Region, không chỉ single-AZ.

🔑 Key Concept / Khái niệm cốt lõi: 6 Pillars = Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, Sustainability / 6 trụ cột = Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, Sustainability.

📚 Reference: Domain 1 § "Well-Architected Framework — 6 Pillars"


Q8.

In the AWS Shared Responsibility Model, who is responsible for patching the Windows Server operating system on an EC2 instance?

Bản dịch tiếng Việt: Trong Mô hình trách nhiệm chung của AWS, ai chịu trách nhiệm vá lỗi hệ điều hành Windows Server trên phiên bản EC2?

A. AWS is responsible B. The customer is responsible C. Both AWS and the customer share this responsibility D. Neither party is responsible

Correct answer: B Bản dịch đáp án đúng: B. Khách hàng chịu trách nhiệm

🇬🇧 Explanation:
In the Shared Responsibility Model, AWS manages the hypervisor and infrastructure, but the customer is responsible for patching the OS. For RDS (managed database), AWS patches the DB engine, but for EC2 (you manage), you patch the OS.

🇻🇳 Giải thích:
Câu hỏi về Shared Responsibility — EC2 = Infrastructure you manage (IaaS). AWS lo: hypervisor, hardware. Bạn lo: OS, patches, app, security.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — AWS doesn't patch EC2 OS (customer responsibility) / AWS không vá OS của EC2 (trách nhiệm của khách hàng).
  • C — Not shared — customer responsibility is clear / Không phải trách nhiệm chia sẻ — rõ ràng là của khách hàng.
  • D — Customer is responsible / Khách hàng chịu trách nhiệm.

🔑 Key Concept / Khái niệm cốt lõi: EC2 = customer patches OS | RDS = AWS patches DB engine / EC2 = khách hàng vá OS | RDS = AWS vá database engine.

📚 Reference: Domain 2 § "AWS Shared Responsibility Model" — Service-by-service variation


Q9.

What does "Infrastructure as Code" (IaC) allow you to do in AWS?

Bản dịch tiếng Việt: "Cơ sở hạ tầng dưới dạng mã" (IaC) cho phép bạn làm gì trong AWS?

A. Define and provision AWS infrastructure using code (JSON/YAML) templates B. Execute arbitrary code on any AWS resource C. Guarantee zero downtime for all applications D. Eliminate the need for security policies

Correct answer: A Bản dịch đáp án đúng: A. Xác định và cung cấp cơ sở hạ tầng AWS bằng cách sử dụng các mẫu mã (JSON/YAML)

🇬🇧 Explanation:
IaC allows you to define infrastructure (servers, networks, storage) in code/templates (CloudFormation JSON/YAML). You can version control, automate, and reproduce infrastructure consistently.

🇻🇳 Giải thích:
IaC = viết code để tạo infrastructure (thay vì click UI). Ví dụ: CloudFormation template = JSON/YAML mô tả 10 EC2 instances, 1 RDS, 1 S3 bucket. Deploy = tạo tất cả 1 lúc.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B — Can't execute arbitrary code / Không thể thực thi mã tùy ý.
  • C — IaC helps ensure uptime, not guarantee zero-downtime / IaC giúp tăng độ ổn định, không đảm bảo zero-downtime.
  • D — Doesn't eliminate security policies / Không loại bỏ các chính sách bảo mật.

🔑 Key Concept / Khái niệm cốt lõi: IaC = CloudFormation/CDK = automation + reproducibility / IaC = CloudFormation/CDK = tự động hóa + tái lập được.

📚 Reference: Domain 3 § "Infrastructure as Code — CloudFormation & CDK"


Q10.

Which of the following best describes the difference between a Public Cloud and a Hybrid Cloud?

Bản dịch tiếng Việt: Điều nào sau đây mô tả đúng nhất sự khác biệt giữa Đám mây công cộng và Đám mây lai?

A. Public Cloud is free; Hybrid Cloud requires payment B. Public Cloud allows public access to infrastructure; Hybrid Cloud combines on-premises and public cloud C. Public Cloud is only for development; Hybrid Cloud is for production D. Public Cloud is owned by the customer; Hybrid Cloud is owned by AWS

Correct answer: B Bản dịch đáp án đúng: B. Public Cloud cho phép công chúng truy cập vào cơ sở hạ tầng; Đám mây lai kết hợp đám mây tại chỗ và đám mây công cộng

🇬🇧 Explanation:
Public Cloud = AWS/Azure/GCP owned, public access (anyone can sign up)
Hybrid Cloud = Mix of on-premises (private) + public cloud (AWS)

🇻🇳 Giải thích:
Public Cloud: Ai cũng dùng được AWS (công chúng)
Hybrid: Công ty keep sensitive data on-premises, dùng AWS cho non-sensitive (migration scenario)

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Price difference, not ownership / Khác biệt về giá, không phải về quyền sở hữu.
  • C — Both are for all environments / Cả hai đều dùng cho mọi môi trường.
  • D — Customer doesn't own either / Khách hàng không sở hữu cả hai.

🔑 Key Concept / Khái niệm cốt lõi: Public = provider-owned | Hybrid = customer + provider / Public = nhà cung cấp sở hữu | Hybrid = khách hàng + nhà cung cấp.

📚 Reference: Domain 1 § "Cloud Deployment Models"


Q11. (Select TWO)

Which of the following are components of the AWS Global Infrastructure? (Select TWO)

Bản dịch tiếng Việt: Thành phần nào sau đây là thành phần của Cơ sở hạ tầng toàn cầu AWS? (Chọn HAI)

A. Security Groups B. Edge Locations (used by CloudFront) C. Availability Zones D. Route Tables E. VPC Subnets

Correct answer: B, C Bản dịch đáp án đúng: B. Edge Location (được CloudFront sử dụng); C. Availability Zone

🇬🇧 Explanation:

  • B ✅ = Edge Locations (700+) are used by CloudFront for content delivery
  • C ✅ = Availability Zones (100+) contain isolated data centers
  • A ❌ = Security Groups are instance-level security, not infrastructure
  • D ❌ = Route Tables are VPC networking, not global infrastructure
  • E ❌ = Subnets are VPC subdivisions, not global

🇻🇳 Giải thích:
Câu B: Edge Locations = CloudFront cache points (600+ globally)
Câu C: Availability Zones = Data centers within regions (100+)

🔑 Key Concept / Khái niệm cốt lõi: Global Infrastructure hierarchy: Edge Locations (700+) > Regions (33+) > AZs (105+) / Phân cấp hạ tầng toàn cầu: Edge Locations (700+) > Regions (33+) > AZs (105+).

📚 Reference: Domain 1 § "AWS Global Infrastructure"


Q12.

A company wants to migrate a legacy application to AWS. The company prefers to change only the hosting platform and avoid a complete redesign. Which migration strategy is most appropriate?

Bản dịch tiếng Việt: Một công ty muốn di chuyển một ứng dụng cũ sang AWS. Công ty chỉ muốn thay đổi nền tảng lưu trữ và tránh thiết kế lại hoàn toàn. Chiến lược di chuyển nào là phù hợp nhất?

A. Retire B. Retain C. Rehost (Lift-and-shift) D. Refactor

Correct answer: C Bản dịch đáp án đúng: C. Rehost (lift-and-shift)

🇬🇧 Explanation:
Rehost (Lift-and-shift) = move application as-is to EC2, minimal code change. Perfect for companies that want to move off on-premises without redesigning.

🇻🇳 Giải thích:
Rehost = copy app from on-premises → EC2, không đổi code. Nhanh, rẻ, risk thấp. Trái lại, Refactor = rewrite để cloud-native (mất thời gian).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Retire = delete unused app / Retire = loại bỏ ứng dụng không dùng.
  • B — Retain = keep on-premises / Retain = giữ lại on-premises.
  • D — Refactor = rewrite (takes years, not for "avoid redesign") / Refactor = viết lại (mất nhiều năm, không phải để "tránh thiết kế lại").

🔑 Key Concept / Khái niệm cốt lõi: 7 R's = Retire, Retain, Relocate, Rehost, Repurchase, Replatform, Refactor / 7 R's = Retire, Retain, Relocate, Rehost, Repurchase, Replatform, Refactor.

📚 Reference: Domain 1 § "Cloud Migration Strategies — 7 R's"


Q13.

Which AWS service allows you to define and manage infrastructure using code templates?

Bản dịch tiếng Việt: Dịch vụ AWS nào cho phép bạn xác định và quản lý cơ sở hạ tầng bằng mẫu mã?

A. AWS Lambda B. AWS CloudFormation C. AWS Elastic Beanstalk D. AWS Systems Manager

Correct answer: B Bản dịch đáp án đúng: B. Đám mây AWSFormation

🇬🇧 Explanation:
AWS CloudFormation allows you to define infrastructure in JSON/YAML templates and deploy them as stacks. It's the native IaC service on AWS.

🇻🇳 Giải thích:
CloudFormation = AWS service để làm IaC. Viết JSON/YAML → tạo stack → deploy.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Lambda is compute, not IaC / Lambda là compute, không phải IaC.
  • C — Beanstalk is PaaS, not pure IaC / Beanstalk là PaaS, không phải IaC thuần.
  • D — Systems Manager is fleet management / Systems Manager là quản lý fleet.

🔑 Key Concept / Khái niệm cốt lõi: CloudFormation = IaC on AWS / CloudFormation = IaC trên AWS.

📚 Reference: Domain 1 § "Infrastructure as Code — AWS CloudFormation"


Q14. (Select THREE)

Which of the following are valid service models of cloud computing? (Select THREE)

Bản dịch tiếng Việt: Mô hình nào sau đây là mô hình dịch vụ hợp lệ của điện toán đám mây? (Chọn BA)

A. IaaS (Infrastructure as a Service) B. PaaS (Platform as a Service) C. SaaS (Software as a Service) D. HaaS (Hardware as a Service) E. BaaS (Backup as a Service)

Correct answer: A, B, C Bản dịch đáp án đúng: A. IaaS (Cơ sở hạ tầng như một dịch vụ); B. PaaS (Nền tảng là một dịch vụ); C. SaaS (Phần mềm dưới dạng dịch vụ)

🇬🇧 Explanation:
The three valid service models:

  • A ✅ = IaaS (Infrastructure) — EC2, S3, EBS
  • B ✅ = PaaS (Platform) — Elastic Beanstalk, RDS
  • C ✅ = SaaS (Software) — Gmail, Office 365
  • D ❌ = HaaS (Hardware as Service) doesn't exist in standard cloud terminology
  • E ❌ = BaaS (Backup as Service) is sometimes used but not a standard NIST model

🇻🇳 Giải thích:
IaaS: Bạn quản lý app, data, OS. AWS quản lý hardware
PaaS: Bạn quản lý app, data. AWS quản lý OS, runtime
SaaS: AWS quản lý hết. Bạn chỉ dùng

🔑 Key Concept / Khái niệm cốt lõi: NIST defines 3 service models — IaaS, PaaS, SaaS / NIST định nghĩa 3 mô hình dịch vụ — IaaS, PaaS, SaaS.

📚 Reference: Domain 1 § "IaaS vs PaaS vs SaaS"


Q15.

Which pillar of the AWS Well-Architected Framework emphasizes implementing strong identity and access management?

Bản dịch tiếng Việt: Trụ cột nào của AWS Well-Architected Framework nhấn mạnh việc triển khai quản lý danh tính và quyền truy cập mạnh mẽ?

A. Operational Excellence B. Security C. Reliability D. Performance Efficiency

Correct answer: B Bản dịch đáp án đúng: B. Bảo vệ

🇬🇧 Explanation:
The Security pillar emphasizes strong identity and access management (IAM), encryption, least privilege, and threat detection.

🇻🇳 Giải thích:
Security pillar = 5 design principles: IAM, encryption, automate security, detect threats, protect accounts.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Operational Excellence focuses on automation, small changes / Operational Excellence tập trung vào tự động hóa, thay đổi nhỏ.
  • C — Reliability focuses on auto-recovery, scaling / Reliability tập trung vào tự phục hồi, mở rộng.
  • D — Performance Efficiency focuses on right-sizing, serverless / Performance Efficiency tập trung vào right-sizing, serverless.

🔑 Key Concept / Khái niệm cốt lõi: Security pillar = IAM + Encryption + Threat detection + Compliance / Trụ cột Security = IAM + Mã hóa + Phát hiện mối đe dọa + Tuân thủ.

📚 Reference: Domain 1 § "Well-Architected Framework — Security Pillar"


Q16.

An organization needs to ensure their application is available even if one entire data center fails. Which AWS deployment approach best meets this requirement?

Bản dịch tiếng Việt: Một tổ chức cần đảm bảo ứng dụng của họ luôn sẵn sàng ngay cả khi toàn bộ một trung tâm dữ liệu bị lỗi. Phương pháp triển khai AWS nào đáp ứng tốt nhất yêu cầu này?

A. Deploy in a single Availability Zone B. Deploy across multiple Availability Zones in the same Region C. Deploy in a single AWS Region D. Deploy on-premises only

Correct answer: B Bản dịch đáp án đúng: B. Triển khai trên nhiều Availability Zone trong cùng một Region

🇬🇧 Explanation:
Deploying across multiple Availability Zones (multi-AZ) ensures that if one AZ fails, your application continues running in other AZs. This is the definition of High Availability (99.99% uptime SLA).

🇻🇳 Giải thích:
Multi-AZ = app chạy ở 2-3 AZ khác nhau (tách biệt, independent power/cooling). Nếu AZ1 down → AZ2, AZ3 vẫn serve users = HA.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Single AZ = vulnerable to data center failure / Single AZ = dễ tổn thương khi data center gặp sự cố.
  • C — Single Region (multiple AZs in same region) = regional failure risk / Single Region (nhiều AZ trong cùng region) = rủi ro lỗi cấp region.
  • D — On-premises only = no redundancy / Chỉ on-premises = không có dự phòng.

🔑 Key Concept / Khái niệm cốt lõi: Multi-AZ = HA | Multi-Region = DR / Multi-AZ = High Availability | Multi-Region = Disaster Recovery.

📚 Reference: Domain 1 § "Design Principles Overview" — High Availability


Domain 2: Security and Compliance (Q17–Q36)

Q17.

According to the AWS Shared Responsibility Model, which of the following is the customer responsible for?

Bản dịch tiếng Việt: Theo Mô hình trách nhiệm chung của AWS, khách hàng chịu trách nhiệm về vấn đề nào sau đây?

A. Patching the underlying hypervisor B. Maintaining physical data center security C. Configuring security groups for EC2 instances D. Providing automatic failover infrastructure

Correct answer: C Bản dịch đáp án đúng: C. Định cấu hình nhóm bảo mật cho phiên bản EC2

🇬🇧 Explanation:
Security Groups are instance-level firewall configuration — 100% customer responsibility (in the "Security IN the Cloud" category).

🇻🇳 Giải thích:
Security Group = bạn configure (ai có quyền connect instance). AWS không quản lý cái này. Đó là "Security IN the Cloud".

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Patching the hypervisor = AWS responsibility (hypervisor = physical layer) / Vá hypervisor là trách nhiệm AWS (hypervisor = lớp vật lý).
  • B — Data center security = AWS responsibility / Bảo mật data center là trách nhiệm AWS.
  • D — Failover infrastructure = AWS responsibility / Hạ tầng failover là trách nhiệm AWS.

🔑 Key Concept / Khái niệm cốt lõi: Customer = Data + IAM + SG config + OS patches + Encryption keys / Khách hàng = Dữ liệu + IAM + cấu hình SG + vá OS + khóa mã hóa.

📚 Reference: Domain 2 § "AWS Shared Responsibility Model" — Customer responsibility


Q18. (Select TWO)

Which of the following are features of AWS Identity and Access Management (IAM)? (Select TWO)

Bản dịch tiếng Việt: Tính năng nào sau đây là tính năng của AWS Identity and Access Management (IAM)? (Chọn HAI)

A. Allows you to create users and assign permissions B. Eliminates the need for passwords C. Provides temporary security credentials via roles D. Automatically encrypts all data in transit E. Manages all encryption keys

Correct answer: A, C Bản dịch đáp án đúng: A. Cho phép bạn tạo người dùng và phân quyền; C. Cung cấp thông tin xác thực bảo mật tạm thời thông qua vai trò

🇬🇧 Explanation:

  • A ✅ = IAM lets you create users and assign granular permissions (policies)
  • C ✅ = IAM roles provide temporary security credentials (STS)
  • B ❌ = IAM still requires passwords (just more securely)
  • D ❌ = IAM is for access control; KMS handles encryption
  • E ❌ = KMS manages keys, not IAM

🇻🇳 Giải thích:
Câu A: IAM = Users + Groups + Roles + Policies (granular access)
Câu C: IAM Roles = temporary credentials (EC2 roles chạy với temp creds, auto-expire)

🔑 Key Concept / Khái niệm cốt lõi: IAM = access control | KMS = encryption keys / IAM = kiểm soát truy cập | KMS = khóa mã hóa.

📚 Reference: Domain 2 § "IAM — Identity & Access Management"


Q19.

What is the best practice for accessing the AWS management console on a newly created account?

Bản dịch tiếng Việt: Cách tốt nhất để truy cập bảng điều khiển quản lý AWS trên tài khoản mới tạo là gì?

A. Use the root account credentials daily B. Share root account credentials with team members C. Create an IAM user with appropriate permissions and use that for daily work D. Disable the root account immediately

Correct answer: C Bản dịch đáp án đúng: C. Tạo người dùng IAM với các quyền thích hợp và sử dụng quyền đó cho công việc hàng ngày

🇬🇧 Explanation:
AWS best practice day 1: Enable MFA on root → Create IAM user with admin permissions → Use IAM user for daily work, not root. Root account is for emergencies only.

🇻🇳 Giải thích:
Root account = master key toàn quyền, rất nguy hiểm. Bạn nên tạo IAM user (admin permissions) dùng hàng ngày. Root chỉ dùng khi cần (billing, reset password).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Never use root for daily work / Không bao giờ dùng root cho công việc hàng ngày.
  • B — Never share root credentials / Không bao giờ chia sẻ thông tin đăng nhập root.
  • D — Don't disable root, just enable MFA and lock away / Đừng vô hiệu hóa root, chỉ cần bật MFA và cất giữ an toàn.

🔑 Key Concept / Khái niệm cốt lõi: Root = master, IAM User = daily work / Root = tài khoản chủ, IAM User = công việc hàng ngày.

📚 Reference: Domain 2 § "IAM — Root User vs IAM User"


Q20.

Which AWS service is used to log all API calls made to your AWS account for compliance and auditing purposes?

Bản dịch tiếng Việt: Dịch vụ AWS nào được sử dụng để ghi lại tất cả lệnh gọi API được thực hiện tới tài khoản AWS của bạn nhằm mục đích tuân thủ và kiểm tra?

A. AWS CloudWatch B. AWS CloudTrail C. AWS Config D. AWS Trusted Advisor

Correct answer: B Bản dịch đáp án đúng: B. Đường mòn đám mây AWS

🇬🇧 Explanation:
AWS CloudTrail logs ALL API calls (who, what, when, where) — essential for compliance audits. CloudWatch logs metrics/application logs; Config tracks configuration changes.

🇻🇳 Giải thích:
CloudTrail = "audit log của AWS" — ghi lại mọi API call (ai gọi, api nào, khi nào, từ đâu). Dùng cho compliance + forensics.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — CloudWatch = metrics, application logs (not API audit) / CloudWatch = metrics, log ứng dụng (không phải audit API).
  • C — Config = configuration changes (not API calls) / Config = thay đổi cấu hình (không phải API calls).
  • D — Trusted Advisor = recommendations (not logging) / Trusted Advisor = khuyến nghị (không phải ghi log).

🔑 Key Concept / Khái niệm cốt lõi: CloudTrail = "who did what API call" | CloudWatch = "how is app performing" / CloudTrail = "ai gọi API gì" | CloudWatch = "ứng dụng đang hoạt động ra sao".

📚 Reference: Domain 2 § "AWS CloudTrail"


Q21.

An organization wants to protect its website from DDoS attacks. Which AWS service provides automatic DDoS protection at no additional cost?

Bản dịch tiếng Việt: Một tổ chức muốn bảo vệ trang web của mình khỏi các cuộc tấn công DDoS. Dịch vụ AWS nào cung cấp khả năng bảo vệ DDoS tự động mà không mất thêm phí?

A. AWS WAF (Web Application Firewall) B. AWS Shield Standard C. AWS Shield Advanced D. AWS Security Groups

Correct answer: B Bản dịch đáp án đúng: B. Tiêu chuẩn lá chắn AWS

🇬🇧 Explanation:
AWS Shield Standard provides automatic DDoS protection for all AWS customers at no additional cost. It protects against Layer 3-4 attacks. Shield Advanced ($3K/year) adds Layer 7 protection and 24/7 response team.

🇻🇳 Giải thích:
Shield Standard = miễn phí, tự động bảo vệ DDoS (network layer). Shield Advanced = trả phí, protection tốt hơn (application layer) + 24/7 team.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — WAF is for application-layer attacks (SQL injection), not DDoS / WAF dành cho tấn công lớp ứng dụng (SQL injection), không phải DDoS.
  • C — Shield Advanced costs money / Shield Advanced tốn phí.
  • D — Security Groups are firewall, not DDoS protection / Security Groups là firewall, không phải bảo vệ DDoS.

🔑 Key Concept / Khái niệm cốt lõi: Shield Standard = free | Shield Advanced = paid + team / Shield Standard = miễn phí | Shield Advanced = trả phí + đội hỗ trợ.

📚 Reference: Domain 2 § "AWS Shield (DDoS Protection)"


Q22. (Select TWO)

Which of the following statements about encryption are correct? (Select TWO)

Bản dịch tiếng Việt: Phát biểu nào sau đây về mã hóa là đúng? (Chọn HAI)

A. Encryption at-rest protects data while it is stored B. Encryption in-transit protects data while it travels over networks C. All AWS services automatically encrypt data without configuration D. AWS KMS can only be used for S3 bucket encryption E. Encryption eliminates the need for other security measures

Correct answer: A, B Bản dịch đáp án đúng: A. Mã hóa ở trạng thái lưu trữ bảo vệ dữ liệu trong khi nó được lưu trữ; B. Mã hóa khi truyền giúp bảo vệ dữ liệu khi truyền qua mạng

🇬🇧 Explanation:

  • A ✅ = Encryption at-rest protects data when stored (S3, RDS, EBS)
  • B ✅ = Encryption in-transit protects data over network (HTTPS/TLS)
  • C ❌ = Not all services auto-encrypt (S3 default now, but RDS requires config)
  • D ❌ = KMS can encrypt many services, not just S3
  • E ❌ = Encryption is one layer; IAM, network security also needed

🇻🇧 Giải thích:
Câu A: At-rest = dữ liệu lưu trữ (S3, RDS) — encrypt bằng KMS
Câu B: In-transit = dữ liệu đi trên mạng (HTTPS) — encrypt bằng TLS

🔑 Key Concept / Khái niệm cốt lõi: At-rest + In-transit = defense in depth / At-rest + In-transit = phòng thủ theo chiều sâu.

📚 Reference: Domain 2 § "Encryption Concepts" — At-Rest vs In-Transit


Q23.

Who is responsible for patching an Amazon RDS database engine when a security vulnerability is discovered?

Bản dịch tiếng Việt: Ai chịu trách nhiệm vá công cụ cơ sở dữ liệu Amazon RDS khi phát hiện ra lỗ hổng bảo mật?

A. The customer (you) must patch it manually B. AWS patches it automatically C. Both the customer and AWS share this responsibility D. The database vendor patches it directly

Correct answer: B Bản dịch đáp án đúng: B. AWS tự động vá nó

🇬🇧 Explanation:
RDS is a managed database — AWS automatically patches the database engine. The customer configures backup retention and parameter groups, but engine patching is AWS responsibility.

🇻🇳 Giải thích:
RDS = AWS-managed database. AWS patch database engine tự động (định kỳ). Bạn chỉ cần config backup policy, not patch.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — AWS patches RDS (managed service) / AWS vá RDS (dịch vụ được quản lý).
  • C — Not shared — AWS responsibility / Không phải chia sẻ — trách nhiệm của AWS.
  • D — Vendor patches directly (AWS handles it) / Không phải nhà cung cấp vá trực tiếp (AWS lo việc đó).

🔑 Key Concept / Khái niệm cốt lõi: RDS patching = AWS | EC2 OS patching = customer / Vá RDS = AWS | Vá OS của EC2 = khách hàng.

📚 Reference: Domain 2 § "Service-by-service variation — RDS"


Q24.

Which AWS service detects threats and anomalies by analyzing CloudTrail logs and VPC Flow Logs using machine learning?

Bản dịch tiếng Việt: Dịch vụ AWS nào phát hiện các mối đe dọa và sự bất thường bằng cách phân tích nhật ký CloudTrail và Nhật ký lưu lượng VPC bằng máy học?

A. AWS Config B. Amazon GuardDuty C. Amazon Inspector D. AWS Trusted Advisor

Correct answer: B Bản dịch đáp án đúng: B. Nhiệm vụ bảo vệ của Amazon

🇬🇧 Explanation:
Amazon GuardDuty uses machine learning to analyze CloudTrail logs and VPC Flow Logs, detecting threats like unusual API calls, compromised credentials, or malware activity.

🇻🇳 Giải thích:
GuardDuty = ML-based threat detection. Phân tích CloudTrail → detect suspicious activity (unusual login, malware, API pattern).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Config tracks configuration changes, not threats / Config theo dõi thay đổi cấu hình, không phải mối đe dọa.
  • C — Inspector scans vulnerabilities in EC2/Lambda, not threats / Inspector quét lỗ hổng trong EC2/Lambda, không phải mối đe dọa.
  • D — Trusted Advisor gives best-practice recommendations / Trusted Advisor đưa ra khuyến nghị best-practice.

🔑 Key Concept / Khái niệm cốt lõi: GuardDuty = threat detection | Inspector = vulnerability scan / GuardDuty = phát hiện mối đe dọa | Inspector = quét lỗ hổng.

📚 Reference: Domain 2 § "Amazon GuardDuty"


Q25.

What is the primary purpose of Multi-Factor Authentication (MFA) for the AWS root account?

Bản dịch tiếng Việt: Mục đích chính của Xác thực đa yếu tố (MFA) cho tài khoản gốc AWS là gì?

A. To replace the need for strong passwords B. To add an extra layer of security requiring a second factor beyond a password C. To automatically detect and block unauthorized access D. To encrypt all API calls

Correct answer: B Bản dịch đáp án đúng: B. Để thêm một lớp bảo mật bổ sung yêu cầu yếu tố thứ hai ngoài mật khẩu

🇬🇧 Explanation:
MFA adds a second factor (physical device, app code) beyond just password. Even if password is stolen, attacker can't login without the 2nd factor. This is the definition and best practice for root account security.

🇻🇳 Giải thích:
MFA = 2 factors: (1) password (something you know) + (2) device code (something you have). Nếu password bị lộ, attacker vẫn cần device để login. Root account PHẢI enable MFA.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — MFA complements passwords, doesn't replace / MFA bổ sung cho mật khẩu, không thay thế.
  • C — MFA doesn't auto-block access (it requires 2nd factor) / MFA không tự chặn truy cập (nó yêu cầu yếu tố thứ 2).
  • D — MFA ≠ encryption / MFA không phải mã hóa.

🔑 Key Concept / Khái niệm cốt lõi: MFA on root = Day 1 best practice / Bật MFA cho root = best practice ngay từ ngày đầu.

📚 Reference: Domain 2 § "IAM Best Practices" — MFA


Q26. (Select TWO)

Which of the following are true about AWS Organizations? (Select TWO)

Bản dịch tiếng Việt: Điều nào sau đây đúng về AWS Organizations? (Chọn HAI)

A. It enables centralized billing for multiple AWS accounts B. It is required to have more than one AWS account C. Service Control Policies (SCPs) can be used to restrict what actions accounts can perform D. It automatically patches all resources E. It is only available for large enterprises

Correct answer: A, C Bản dịch đáp án đúng: A. Nó cho phép thanh toán tập trung cho nhiều tài khoản AWS; C. Chính sách kiểm soát dịch vụ (SCP) có thể được sử dụng để hạn chế những hành động mà tài khoản có thể thực hiện

🇬🇧 Explanation:

  • A ✅ = Organizations enables consolidated billing (one bill for multiple accounts + volume discounts)
  • C ✅ = SCPs (Service Control Policies) restrict what services/actions accounts can use
  • B ❌ = Organizations is optional (can have 1 account)
  • D ❌ = Organizations doesn't patch resources (that's Systems Manager)
  • E ❌ = Organizations is available for all, not just enterprises

🇻🇳 Giải thích:
Câu A: Consolidated Billing = 1 bill, pooled volume discounts (Account A + B + C billing merged)
Câu C: SCPs = guardrails (e.g., "block all EC2 in dev account")

🔑 Key Concept / Khái niệm cốt lõi: Organizations = multi-account management + consolidated billing + SCPs / Organizations = quản lý nhiều account + consolidated billing + SCPs.

📚 Reference: Domain 2 § "AWS Organizations & Multi-Account Management"


Q27.

A sensitive S3 bucket was inadvertently made public, exposing customer data. According to the Shared Responsibility Model, who bears responsibility for this misconfiguration?

Bản dịch tiếng Việt: Một bộ chứa S3 nhạy cảm đã vô tình bị công khai, làm lộ dữ liệu của khách hàng. Theo Mô hình trách nhiệm chung, ai chịu trách nhiệm về việc cấu hình sai này?

A. AWS, because S3 should be private by default B. The customer, because they configured the bucket permissions C. Both equally D. Neither, it's an accident

Correct answer: B Bản dịch đáp án đúng: B. Khách hàng vì họ đã định cấu hình quyền của nhóm

🇬🇧 Explanation:
S3 bucket access configuration (public/private) is 100% customer responsibility. AWS provides the tool (bucket policies, ACLs), but the customer must configure it correctly. This is "Security IN the Cloud".

🇻🇳 Giải thích:
S3 bucket access config = bạn set policy (công khai hoặc riêng tư). AWS không auto-block. Bạn phải configure + test. Nếu public vô tình = bạn chịu trách nhiệm.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — AWS doesn't default to private (S3 default is private, but config is customer's) / AWS không "tự" để private (S3 mặc định private, nhưng cấu hình là của khách hàng).
  • C — Not shared — clear customer responsibility / Không phải chia sẻ — rõ ràng là trách nhiệm khách hàng.
  • D — Not an "accident" — it's a configuration error / Không phải "tai nạn" — đó là lỗi cấu hình.

🔑 Key Concept / Khái niệm cốt lõi: S3 bucket access = customer responsibility (Shared Responsibility Model) / Quyền truy cập S3 bucket = trách nhiệm khách hàng (Shared Responsibility Model).

📚 Reference: Domain 2 § "Service-by-service variation — S3"


Q28.

Which AWS service provides a collection of SSL/TLS certificates that can be deployed to CloudFront, ALB, or API Gateway with automatic renewal?

Bản dịch tiếng Việt: Dịch vụ AWS nào cung cấp tập hợp chứng chỉ SSL/TLS có thể được triển khai lên CloudFront, ALB hoặc API Gateway với tính năng tự động gia hạn?

A. AWS KMS B. AWS Certificate Manager (ACM) C. AWS Secrets Manager D. AWS Key Pair service

Correct answer: B Bản dịch đáp án đúng: B. Trình quản lý chứng chỉ AWS (ACM)

🇬🇧 Explanation:
AWS Certificate Manager (ACM) provisions, manages, and auto-renews SSL/TLS certificates. No upfront payment; free if used with AWS services (CloudFront, ALB). Easy HTTPS deployment.

🇻🇳 Giải thích:
ACM = AWS quản lý certificate (auto-renew, deploy to CloudFront/ALB). Không phải lo hạn cuối certificate.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — KMS = encryption keys, not SSL certs / KMS = khóa mã hóa, không phải SSL certs.
  • C — Secrets Manager = database passwords, not SSL certs / Secrets Manager = mật khẩu database, không phải SSL certs.
  • D — No Key Pair service for certificates / Không có dịch vụ Key Pair cho certificates.

🔑 Key Concept / Khái niệm cốt lõi: ACM = SSL/TLS cert management + auto-renewal / ACM = quản lý SSL/TLS cert + tự động gia hạn.

📚 Reference: Domain 2 § "AWS Certificate Manager (ACM)"


Q29.

What is the primary use case for AWS WAF (Web Application Firewall)?

Bản dịch tiếng Việt: Trường hợp sử dụng chính của AWS WAF (Tường lửa ứng dụng web) là gì?

A. Prevent DDoS attacks at the network layer B. Block application-layer attacks such as SQL injection and cross-site scripting C. Encrypt data at rest in S3 D. Manage user identities and access control

Correct answer: B Bản dịch đáp án đúng: B. Chặn các cuộc tấn công lớp ứng dụng như SQL injection và tập lệnh chéo trang

🇬🇧 Explanation:
AWS WAF (Web Application Firewall) protects against application-layer attacks: SQL injection, cross-site scripting (XSS), cross-site request forgery (CSRF). It sits in front of CloudFront, ALB, or API Gateway.

🇻🇳 Giải thích:
WAF = bảo vệ app layer (Layer 7 HTTP/HTTPS). Chặn SQL injection (SELECT * FROM users WHERE id = 1; DROP TABLE users;), XSS ().

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Shield (not WAF) prevents DDoS at network layer / Shield (không phải WAF) chống DDoS ở lớp mạng.
  • C — Encryption ≠ WAF (KMS does this) / Mã hóa không phải WAF (KMS làm việc này).
  • D — IAM does this (not WAF) / IAM làm việc này (không phải WAF).

🔑 Key Concept / Khái niệm cốt lõi: WAF = application-layer firewall | Shield = network-layer DDoS / WAF = firewall lớp ứng dụng | Shield = DDoS lớp mạng.

📚 Reference: Domain 2 § "AWS WAF (Web Application Firewall)"


Q30.

Which AWS service automatically assesses EC2 instances and Lambda functions for software vulnerabilities and unintended network exposure, and provides prioritized findings?

Bản dịch tiếng Việt: Dịch vụ AWS nào tự động đánh giá các phiên bản EC2 và chức năng Lambda để tìm lỗ hổng phần mềm cũng như khả năng xảy ra lỗi ngoài ý muốn trên mạng, đồng thời đưa ra các phát hiện được ưu tiên?

A. Amazon Inspector B. Amazon GuardDuty C. AWS Config D. Amazon Macie E. AWS Trusted Advisor

Correct answer: A Bản dịch đáp án đúng: A. Thanh tra Amazon

🇬🇧 Explanation:
Amazon Inspector is the AWS vulnerability-management service that automatically and continually scans EC2 instances and Lambda functions for software vulnerabilities (CVEs) and unintended network exposure, producing prioritized findings.

🇻🇳 Giải thích:
Amazon Inspector = dịch vụ quét lỗ hổng tự động cho EC2 và Lambda (CVE phần mềm + cổng mạng phơi nhiễm), đưa ra findings được xếp ưu tiên.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B — GuardDuty detects threats (malware, unusual activity), not software vulnerabilities / GuardDuty phát hiện mối đe dọa (malware, hoạt động bất thường), không phải lỗ hổng phần mềm.
  • C — Config tracks configuration changes/compliance, not vulnerabilities / Config theo dõi thay đổi cấu hình/tuân thủ, không phải lỗ hổng.
  • D — Macie finds sensitive data (PII) in S3, not vulnerabilities / Macie tìm dữ liệu nhạy cảm (PII) trong S3, không phải lỗ hổng.
  • E — Trusted Advisor gives best-practice checks/recommendations; it does NOT perform vulnerability assessment of EC2/Lambda / Trusted Advisor đưa ra kiểm tra/khuyến nghị best-practice; nó KHÔNG đánh giá lỗ hổng cho EC2/Lambda.

🔑 Key Concept / Khái niệm cốt lõi: Inspector = vulnerability scan | GuardDuty = threat detection | Trusted Advisor = best-practice checks / Inspector = quét lỗ hổng | GuardDuty = phát hiện mối đe dọa | Trusted Advisor = kiểm tra best-practice.

📚 Reference: Domain 2 § "Amazon Inspector"


Q31.

Which AWS service scans S3 buckets to discover and protect sensitive data such as credit card numbers and personally identifiable information (PII)?

Bản dịch tiếng Việt: Dịch vụ AWS nào quét bộ chứa S3 để khám phá và bảo vệ dữ liệu nhạy cảm như số thẻ tín dụng và thông tin nhận dạng cá nhân (PII)?

A. AWS Config B. Amazon Macie C. AWS CloudTrail D. Amazon GuardDuty

Correct answer: B Bản dịch đáp án đúng: B. Amazon Macie

🇬🇧 Explanation:
Amazon Macie uses machine learning to scan S3 buckets and find sensitive data (credit card numbers, social security numbers, passport numbers, PII). It creates findings and recommends remediation (encryption, block public access).

🇻🇳 Giải thích:
Macie = ML-based PII detection trong S3. Scan bucket → find credit card numbers, SSN, passport, email → create findings → recommend encryption/block access.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Config tracks configuration, not PII / Config theo dõi cấu hình, không phải PII.
  • C — CloudTrail logs API calls, not PII content / CloudTrail ghi log API calls, không phải nội dung PII.
  • D — GuardDuty detects threats, not PII / GuardDuty phát hiện mối đe dọa, không phải PII.

🔑 Key Concept / Khái niệm cốt lõi: Macie = PII detection in S3 / Macie = phát hiện PII trong S3.

📚 Reference: Domain 2 § "Amazon Macie"


Q32.

What is the difference between IAM Users and IAM Roles?

Bản dịch tiếng Việt: Sự khác biệt giữa Người dùng IAM và Vai trò IAM là gì?

A. Users are for people; Roles are for AWS services and cross-account access B. Users are permanent; Roles are temporary C. Roles do not have access keys; Users always do D. Both A and B are correct

Correct answer: D Bản dịch đáp án đúng: D. Cả A và B đều đúng

🇬🇧 Explanation:

  • Users are for people/applications — permanent credentials (long-lived)
  • Roles are for services/cross-account — temporary credentials (1-hour STS tokens) Both A and B are correct, so D is the best answer.

🇻🇳 Giải thích:
Users = người hoặc app (access keys dài hạn)
Roles = services hoặc cross-account (temporary credentials, auto-expire)

🔑 Key Concept / Khái niệm cốt lõi: Users = permanent | Roles = temporary + services / Users = thông tin đăng nhập lâu dài | Roles = tạm thời + cho dịch vụ.

📚 Reference: Domain 2 § "IAM — IAM Role vs IAM User"


Q33. (Select TWO)

Which of the following are included in the AWS Artifact service? (Select TWO)

Bản dịch tiếng Việt: Điều nào sau đây được bao gồm trong dịch vụ AWS Artifact? (Chọn HAI)

A. Training courses and certifications B. SOC 1/2/3 compliance reports C. Automated vulnerability scanning tools D. PCI DSS attestations E. Real-time network monitoring

Correct answer: B, D Bản dịch đáp án đúng: B. Báo cáo tuân thủ SOC 1/2/3; D. Chứng thực PCI DSS

🇬🇧 Explanation:

  • B ✅ = AWS Artifact provides SOC 1/2/3 compliance reports (audit controls)
  • D ✅ = AWS Artifact provides PCI DSS attestations (payment security compliance)
  • A ❌ = Artifact is NOT a training platform (Skill Builder is)
  • C ❌ = Artifact provides reports, not scanning tools (Inspector does that)
  • E ❌ = Artifact provides documents, not monitoring

🇻🇳 Giải thích:
Câu B: SOC reports = Service Organization Control reports (audit)
Câu D: PCI DSS = Payment Card Industry Data Security Standard attestation

🔑 Key Concept / Khái niệm cốt lõi: Artifact = compliance documents (download + use for audit) / Artifact = tài liệu tuân thủ (tải về + dùng cho audit).

📚 Reference: Domain 2 § "AWS Artifact"


Q34.

In a company using AWS, which pillar of the Well-Architected Framework is most concerned with encrypting data, implementing least privilege access, and detecting threats?

Bản dịch tiếng Việt: Trong một công ty sử dụng AWS, trụ cột nào của Well-Architected Framework quan tâm nhất đến việc mã hóa dữ liệu, triển khai quyền truy cập đặc quyền tối thiểu và phát hiện các mối đe dọa?

A. Operational Excellence B. Security C. Reliability D. Cost Optimization

Correct answer: B Bản dịch đáp án đúng: B. Bảo vệ

🇬🇧 Explanation:
The Security pillar emphasizes: IAM (least privilege), encryption (at-rest + in-transit), and threat detection (CloudTrail, GuardDuty). All the question describes are Security concerns.

🇻🇳 Giải thích:
Câu hỏi: "encrypt data, least privilege IAM, detect threats" = tất cả là Security pillar.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Operational Excellence focuses on automation, not security / Operational Excellence tập trung vào tự động hóa, không phải bảo mật.
  • C — Reliability focuses on recovery, not encryption / Reliability tập trung vào phục hồi, không phải mã hóa.
  • D — Cost Optimization focuses on pricing, not security / Cost Optimization tập trung vào giá cả, không phải bảo mật.

🔑 Key Concept / Khái niệm cốt lõi: Security pillar = IAM + Encryption + Threat detection / Trụ cột Security = IAM + Mã hóa + Phát hiện mối đe dọa.

📚 Reference: Domain 1 § "Well-Architected Framework — Security Pillar"


Q35.

Which AWS service allows you to store and automatically rotate sensitive information such as database passwords and API keys?

Bản dịch tiếng Việt: Dịch vụ AWS nào cho phép bạn lưu trữ và tự động xoay vòng thông tin nhạy cảm như mật khẩu cơ sở dữ liệu và khóa API?

A. AWS Systems Manager Parameter Store B. AWS Secrets Manager C. AWS KMS D. AWS IAM

Correct answer: B Bản dịch đáp án đúng: B. Trình quản lý bí mật AWS

🇬🇧 Explanation:
AWS Secrets Manager automatically rotates secrets (database passwords, API keys) without application changes. Parameter Store is static (manual rotation). Secrets Manager is the right choice for automated rotation.

🇻🇳 Giải thích:
Secrets Manager = tự động rotate password (tích hợp Lambda). Parameter Store = chỉ lưu config (không auto-rotate).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Parameter Store doesn't auto-rotate / Parameter Store không tự động xoay vòng.
  • C — KMS is for encryption keys, not secret rotation / KMS dành cho khóa mã hóa, không phải xoay vòng secret.
  • D — IAM is for user access, not secret rotation / IAM dành cho truy cập người dùng, không phải xoay vòng secret.

🔑 Key Concept / Khái niệm cốt lõi: Secrets Manager = auto-rotation | Parameter Store = manual / Secrets Manager = tự động xoay vòng | Parameter Store = thủ công.

📚 Reference: Domain 2 § "AWS Secrets Manager vs Systems Manager Parameter Store"


Q36.

What does the principle of "least privilege" in AWS security mean?

Bản dịch tiếng Việt: Nguyên tắc "đặc quyền tối thiểu" trong bảo mật AWS có nghĩa là gì?

A. Users should have the minimum permissions necessary to perform their job B. All users should have read-only permissions C. The root account should be used for all operations D. No security policies are needed

Correct answer: A Bản dịch đáp án đúng: A. Người dùng phải có các quyền tối thiểu cần thiết để thực hiện công việc của họ

🇬🇧 Explanation:
Least privilege means granting only the minimum permissions needed for a user/role to perform their job. Don't grant "admin" or "*" — grant only specific actions on specific resources.

🇻🇳 Giải thích:
Least privilege = grant đủ permission để làm job, không thêm. Ví dụ: nếu developer chỉ cần read S3 → grant s3:GetObject, không grant s3:DeleteObject.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B — Read-only is too restrictive (developers need to write code) / Chỉ đọc thì quá hạn chế (developer cần ghi code).
  • C — Root account violates least privilege / Tài khoản root vi phạm least privilege.
  • D — Security policies are essential / Các chính sách bảo mật là thiết yếu.

🔑 Key Concept / Khái niệm cốt lõi: Least privilege = minimum permissions needed / Least privilege = cấp quyền tối thiểu cần thiết.

📚 Reference: Domain 2 § "IAM Best Practices" — Principle of Least Privilege


Domain 3: Cloud Technology and Services (Q37–Q58)

Q37.

Which AWS service is a virtual machine that allows you to run any operating system and application?

Bản dịch tiếng Việt: Dịch vụ AWS nào là máy ảo cho phép bạn chạy bất kỳ hệ điều hành và ứng dụng nào?

A. AWS Lambda B. Amazon EC2 C. AWS Elastic Beanstalk D. Amazon Lightsail

Correct answer: B Bản dịch đáp án đúng: B. Amazon EC2

🇬🇧 Explanation:
Amazon EC2 provides virtual machines (instances) where you select CPU, memory, storage, and OS. You have full control and responsibility for the instance.

🇻🇳 Giải thích:
EC2 = virtual server (bạn chọn OS, config, install app, patch). Đó là IaaS — bạn quản lý nhiều.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Lambda is serverless (no choice of OS) / Lambda là serverless (không chọn OS).
  • C — Beanstalk is PaaS (AWS manages servers) / Beanstalk là PaaS (AWS quản lý servers).
  • D — Lightsail is simpler VPS (fixed configs) / Lightsail là VPS đơn giản hơn (cấu hình cố định).

🔑 Key Concept / Khái niệm cốt lõi: EC2 = IaaS virtual machine / EC2 = máy ảo IaaS.

📚 Reference: Domain 3 § "Amazon EC2 (Elastic Compute Cloud)"


Q38. (Select TWO)

Which of the following are storage services in AWS? (Select TWO)

Bản dịch tiếng Việt: Dịch vụ nào sau đây là dịch vụ lưu trữ trong AWS? (Chọn HAI)

A. Amazon EC2 B. Amazon S3 C. Amazon EBS D. Amazon RDS E. Amazon ElastiCache

Correct answer: B, C Bản dịch đáp án đúng: B. Amazon S3; C. Amazon EBS

🇬🇧 Explanation:

  • B ✅ = S3 is object storage (unlimited objects, REST API)
  • C ✅ = EBS is block storage (attached to EC2, same AZ)
  • A ❌ = EC2 is compute (not storage)
  • D ❌ = RDS is database (not storage)
  • E ❌ = ElastiCache is in-memory cache (not primary storage)

🇻🇳 Giải thích:
Câu B: S3 = object storage (files, REST API)
Câu C: EBS = block storage (mounted to EC2)

🔑 Key Concept / Khái niệm cốt lõi: S3 = object | EBS = block | EFS = file system / S3 = lưu trữ object | EBS = lưu trữ block | EFS = hệ thống file.

📚 Reference: Domain 3 § "Amazon S3 & EBS"


Q39.

A developer needs to store files that are accessed infrequently but must be retrievable within seconds. Which S3 storage class is most cost-effective?

Bản dịch tiếng Việt: Nhà phát triển cần lưu trữ các tệp không được truy cập thường xuyên nhưng phải có thể truy xuất được trong vòng vài giây. Lớp lưu trữ S3 nào tiết kiệm chi phí nhất?

A. S3 Standard B. S3 Intelligent-Tiering C. S3 Standard-IA D. S3 Glacier Deep Archive

Correct answer: C Bản dịch đáp án đúng: C. Tiêu chuẩn S3-IA

🇬🇧 Explanation:
S3 Standard-IA (Infrequent Access) is cost-effective for data accessed infrequently but needs instant retrieval. You pay storage + retrieval fee, but storage is cheaper than Standard.

🇻🇳 Giải thích:
Standard-IA = truy cập ít (backup files), nhưng cần lấy ngay (not hours like Glacier). Chi phí: storage rẻ hơn Standard, nhưng retrieval tính phí.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Standard = expensive for infrequent access / Standard = đắt cho dữ liệu ít truy cập.
  • B — Intelligent-Tiering = auto-tier (more complex) / Intelligent-Tiering = tự động phân tầng (phức tạp hơn).
  • D — Glacier Deep Archive = needs 12-48 hours (slow) / Glacier Deep Archive = cần 12-48 giờ (chậm).

🔑 Key Concept / Khái niệm cốt lõi: Standard-IA = infrequent + instant retrieval / Standard-IA = ít truy cập + lấy ra tức thì.

📚 Reference: Domain 3 § "S3 Storage Classes"


Q40.

Which AWS service provides a fully managed relational database with automatic failover across Availability Zones?

Bản dịch tiếng Việt: Dịch vụ AWS nào cung cấp cơ sở dữ liệu quan hệ được quản lý toàn phần với khả năng chuyển đổi dự phòng tự động trên nhiều Availability Zone?

A. Amazon EC2 running MySQL B. Amazon RDS with Multi-AZ deployment C. Amazon DynamoDB D. Amazon Redshift

Correct answer: B Bản dịch đáp án đúng: B. Amazon RDS với triển khai Multi-AZ

🇬🇧 Explanation:
Amazon RDS with Multi-AZ deployment provides automatic failover. If the primary instance fails, AWS automatically promotes the standby replica in a different AZ.

🇻🇳 Giải thích:
RDS Multi-AZ = primary + standby (different AZ). Nếu primary down → auto-failover to standby (tự động, user không biết).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — EC2 MySQL = you manage failover (not automatic) / EC2 MySQL = bạn tự quản lý failover (không tự động).
  • C — DynamoDB = NoSQL (not relational) / DynamoDB = NoSQL (không phải quan hệ).
  • D — Redshift = data warehouse (not transactional DB) / Redshift = data warehouse (không phải DB giao dịch).

🔑 Key Concept / Khái niệm cốt lõi: RDS Multi-AZ = automatic failover = HA / RDS Multi-AZ = tự động failover = High Availability.

📚 Reference: Domain 3 § "Amazon RDS (Relational Database Service)"


Q41. (Select TWO)

Which of the following are advantages of serverless computing with AWS Lambda? (Select TWO)

Bản dịch tiếng Việt: Đâu là ưu điểm của điện toán serverless với AWS Lambda? (Chọn HAI)

A. Pay per invocation and GB-seconds, not per hour B. Functions can run continuously for days without any timeout C. You must pre-provision and reserve servers before each invocation D. No need to manage servers or infrastructure E. Lower security requirements than EC2

Correct answer: A, D Bản dịch đáp án đúng: A. Trả tiền cho mỗi lệnh gọi và GB-giây, không phải mỗi giờ; D. Không cần quản lý máy chủ hoặc cơ sở hạ tầng

🇬🇧 Explanation:

  • A ✅ = Lambda charges per invocation + GB-seconds (pay only for execution)
  • D ✅ = Lambda is serverless — no servers/infrastructure to manage, and it auto-scales
  • B ❌ = Lambda has a hard 15-minute max execution timeout; it cannot run continuously for days
  • C ❌ = Lambda is serverless — you never pre-provision or reserve servers per invocation
  • E ❌ = Security is just as important; the customer still owns code, IAM, and data security

🇻🇳 Giải thích:
Câu A: Lambda billing = per call + memory-duration (pay for actual execution)
Câu D: Serverless = bạn viết code, AWS quản lý servers + scaling

🔑 Key Concept / Khái niệm cốt lõi: Lambda = serverless + pay-per-invocation + auto-scale / Lambda = serverless + trả theo lần gọi + tự động mở rộng.

📚 Reference: Domain 3 § "AWS Lambda — Serverless Compute"


Q42.

An organization needs to host a static website with minimal operational overhead. Which combination of services is most appropriate?

Bản dịch tiếng Việt: Một tổ chức cần lưu trữ một trang web tĩnh với chi phí hoạt động tối thiểu. Sự kết hợp dịch vụ nào là phù hợp nhất?

A. EC2 instance + Amazon RDS B. Amazon S3 + Amazon CloudFront C. Amazon DynamoDB + AWS Lambda D. Amazon ECS + Application Load Balancer

Correct answer: B Bản dịch đáp án đúng: B. Amazon S3 + Amazon CloudFront

🇬🇧 Explanation:
S3 + CloudFront is the go-to solution: S3 hosts static files (HTML, CSS, JS, images), CloudFront caches them at edge locations globally. Minimal operational overhead, highly scalable, low cost.

🇻🇳 Giải thích:
S3 + CloudFront = website tĩnh toàn thế giới, latency thấp, auto-scale, rẻ. Không cần server.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — EC2 + RDS = overkill, more management / EC2 + RDS = quá mức cần thiết, tốn công quản lý.
  • C — DynamoDB + Lambda = dynamic app, not static site / DynamoDB + Lambda = ứng dụng động, không phải site tĩnh.
  • D — ECS + ALB = containerized app, complex / ECS + ALB = ứng dụng container hóa, phức tạp.

🔑 Key Concept / Khái niệm cốt lõi: Static website = S3 + CloudFront / Website tĩnh = S3 + CloudFront.

📚 Reference: Domain 3 § "Amazon S3" — Use case: Static website hosting


Q43.

Which EC2 pricing model should be used for a stable production workload with predictable usage for the next 3 years?

Bản dịch tiếng Việt: Nên sử dụng mô hình định giá EC2 nào cho khối lượng công việc sản xuất ổn định với mức sử dụng có thể dự đoán được trong 3 năm tới?

A. On-Demand B. Reserved Instances C. Spot Instances D. Dedicated Hosts

Correct answer: B Bản dịch đáp án đúng: B. Phiên bản dự trữ

🇬🇧 Explanation:
Reserved Instances (1-3 year commitment) save 31-72% for stable workloads. If you know you'll run the same servers for 3 years, RI is cost-optimal.

🇻🇳 Giải thích:
Stable production 3 years = Reserved Instances (72% discount). On-Demand = 3 năm tốn gấp 3-4 lần giá RI.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — On-Demand = most expensive / On-Demand = đắt nhất.
  • C — Spot = can be terminated (not suitable for production) / Spot = có thể bị thu hồi (không phù hợp production).
  • D — Dedicated Hosts = even more expensive / Dedicated Hosts = còn đắt hơn.

🔑 Key Concept / Khái niệm cốt lõi: Stable long-term = Reserved Instances / Ổn định dài hạn = Reserved Instances.

📚 Reference: Domain 4 § "AWS Pricing Models" — Reserved Instances


Q44.

What is the primary difference between Amazon RDS and Amazon DynamoDB?

Bản dịch tiếng Việt: Sự khác biệt chính giữa Amazon RDS và Amazon DynamoDB là gì?

A. RDS is NoSQL; DynamoDB is relational B. RDS is relational with schema; DynamoDB is NoSQL key-value C. DynamoDB is more expensive than RDS D. RDS supports more concurrent users than DynamoDB

Correct answer: B Bản dịch đáp án đúng: B. RDS có quan hệ với lược đồ; DynamoDB là khóa-giá trị NoSQL

🇬🇧 Explanation:
RDS = relational database with schema (SQL, tables, joins); DynamoDB = NoSQL key-value (flexible schema, single-digit latency). For relational data (customers, orders, products with joins), use RDS. For simple key-value or high-throughput, use DynamoDB.

🇻🇳 Giải thích:
RDS = schema cứng (tables, columns định trước). DynamoDB = NoSQL (key-value, flexible). Nếu cần joins (Orders table + Customers table) → RDS.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Flipped definitions / Định nghĩa bị đảo ngược.
  • C — DynamoDB can be cheaper (on-demand pricing) / DynamoDB có thể rẻ hơn (định giá on-demand).
  • D — DynamoDB handles high concurrency better / DynamoDB xử lý đồng thời cao tốt hơn.

🔑 Key Concept / Khái niệm cốt lõi: RDS = relational + SQL | DynamoDB = NoSQL + key-value / RDS = quan hệ + SQL | DynamoDB = NoSQL + key-value.

📚 Reference: Domain 3 § "RDS vs DynamoDB"


Q45. (Select TWO)

Which of the following services provide data analytics capabilities in AWS? (Select TWO)

Bản dịch tiếng Việt: Dịch vụ nào sau đây cung cấp khả năng phân tích dữ liệu trong AWS? (Chọn HAI)

A. Amazon Redshift B. Amazon Athena C. Amazon EC2 D. AWS Lambda E. Amazon Route 53

Correct answer: A, B Bản dịch đáp án đúng: A. Amazon Redshift; B. Amazon Athena

🇬🇧 Explanation:

  • A ✅ = Redshift = data warehouse for analytics (columnar, petabyte-scale)
  • B ✅ = Athena = query S3 with SQL (serverless analytics)
  • C ❌ = EC2 = compute (not analytics)
  • D ❌ = Lambda = compute (not analytics)
  • E ❌ = Route 53 = DNS / domain routing (not an analytics service)

🇻🇳 Giải thích:
Câu A: Redshift = data warehouse (analytics queries on huge data)
Câu B: Athena = query S3 (serverless SQL on S3 logs)

🔑 Key Concept / Khái niệm cốt lõi: Analytics = Redshift, Athena, Kinesis, Glue, QuickSight / Analytics = Redshift, Athena, Kinesis, Glue, QuickSight.

📚 Reference: Domain 3 § "Analytics Services"


Q46.

An application requires a file system that can be shared across multiple EC2 instances. Which service is best?

Bản dịch tiếng Việt: Một ứng dụng yêu cầu một hệ thống tệp có thể được chia sẻ trên nhiều phiên bản EC2. Dịch vụ nào là tốt nhất?

A. Amazon EBS B. Amazon EFS C. Amazon S3 D. AWS Storage Gateway

Correct answer: B Bản dịch đáp án đúng: B. Amazon EFS

🇬🇧 Explanation:
Amazon EFS (Elastic File System) is a managed NFS that can be mounted on multiple EC2 instances across Availability Zones. Perfect for shared file systems.

🇻🇳 Giải thích:
EFS = file system (NFS) mount được trên 2-3 EC2 instances khác nhau (cross-AZ). Tất cả instances thấy cùng files.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — EBS is block storage (attached to single instance only) / EBS là block storage (chỉ gắn vào một instance).
  • C — S3 is object storage (not mounted as file system) / S3 là object storage (không mount như file system).
  • D — Storage Gateway is hybrid (on-premises connection) / Storage Gateway là hybrid (kết nối on-premises).

🔑 Key Concept / Khái niệm cốt lõi: Shared file system = EFS | Single instance = EBS / Hệ thống file chia sẻ = EFS | Một instance = EBS.

📚 Reference: Domain 3 § "Amazon EFS (Elastic File System)"


Q47.

Which AWS service allows you to create REST APIs that can trigger AWS Lambda functions?

Bản dịch tiếng Việt: Dịch vụ AWS nào cho phép bạn tạo API REST có thể kích hoạt các chức năng AWS Lambda?

A. Amazon Route 53 B. AWS API Gateway C. AWS AppSync D. Amazon CloudFront

Correct answer: B Bản dịch đáp án đúng: B. AWS API Gateway

🇬🇧 Explanation:
AWS API Gateway creates REST/HTTP APIs. You define resources/methods, configure authorizers, and trigger Lambda functions on requests. Client calls API Gateway endpoint → Lambda processes → response.

🇻🇳 Giải thích:
API Gateway = create REST API endpoint (HTTP). Client call endpoint → API Gateway → Lambda → response JSON. Không cần server.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Route 53 = DNS, not API creation / Route 53 = DNS, không phải tạo API.
  • C — AppSync = GraphQL (not REST) / AppSync = GraphQL (không phải REST).
  • D — CloudFront = CDN (not API creation) / CloudFront = CDN (không phải tạo API).

🔑 Key Concept / Khái niệm cốt lõi: REST API = API Gateway + Lambda / REST API = API Gateway + Lambda.

📚 Reference: Domain 3 § "API Gateway"


Q48.

What is the primary purpose of an Application Load Balancer (ALB)?

Bản dịch tiếng Việt: Mục đích chính của Cân bằng tải ứng dụng (ALB) là gì?

A. Store static website content B. Distribute incoming HTTP/HTTPS traffic across multiple targets C. Encrypt data in transit D. Monitor application performance metrics

Correct answer: B Bản dịch đáp án đúng: B. Phân phối lưu lượng HTTP/HTTPS đến trên nhiều mục tiêu

🇬🇧 Explanation:
ALB distributes incoming HTTP/HTTPS traffic across multiple targets (EC2, containers). Supports host-based and path-based routing. Essential for high-availability and scaling.

🇻🇳 Giải thích:
ALB = load balancer (Layer 7). Client requests → ALB → distribute to 3 EC2 instances. Nếu 1 instance down → ALB send traffic to other 2.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — S3 stores content (not ALB) / S3 lưu nội dung (không phải ALB).
  • C — Encryption ≠ ALB (KMS does this) / Mã hóa không phải ALB (KMS làm việc này).
  • D — CloudWatch monitors (not ALB) / CloudWatch giám sát (không phải ALB).

🔑 Key Concept / Khái niệm cốt lõi: ALB = distribute traffic across instances / ALB = phân phối traffic giữa các instance.

📚 Reference: Domain 3 § "Elastic Load Balancing (ELB)" — ALB


Q49. (Select THREE)

Which of the following are valid EC2 instance families commonly tested on CLF-C02? (Select THREE)

Bản dịch tiếng Việt: Dòng phiên bản EC2 nào sau đây hợp lệ thường được thử nghiệm trên CLF-C02? (Chọn BA)

A. T-series (burstable, general-purpose) B. M-series (balanced CPU/memory) C. C-series (compute-optimized) D. B-series (blockchain-optimized) E. Q-series (quantum computing)

Correct answer: A, B, C Bản dịch đáp án đúng: A. Dòng T (có thể nổ, đa năng); B. Dòng M (cân bằng CPU/bộ nhớ); C. Dòng C (được tối ưu hóa cho máy tính)

🇬🇧 Explanation:

  • A ✅ = T-series (t2, t3, t4) = general-purpose, burstable (cheap)
  • B ✅ = M-series (m5, m6) = general-purpose, balanced
  • C ✅ = C-series (c5, c6) = compute-optimized (high CPU)
  • D ❌ = "B-series (blockchain-optimized)" is not a real AWS EC2 family
  • E ❌ = "Q-series (quantum computing)" is not a real AWS EC2 family

🇻🇳 Giải thích:
Câu A: T-family = burstable (dev, web)
Câu B: M-family = balanced (default for most)
Câu C: C-family = compute-intensive (batch, analytics)

🔑 Key Concept / Khái niệm cốt lõi: T, M, C, R, X, I, D, P, G = instance families / T, M, C, R, X, I, D, P, G = các dòng instance.

📚 Reference: Domain 3 § "EC2 Instance Families"


Q50.

Which AWS service allows you to run Docker containers without managing the underlying EC2 instances?

Bản dịch tiếng Việt: Dịch vụ AWS nào cho phép bạn chạy bộ chứa Docker mà không cần quản lý các phiên bản EC2 cơ bản?

A. Amazon EC2 B. Amazon ECS + Fargate C. AWS Lambda D. AWS Elastic Beanstalk

Correct answer: B Bản dịch đáp án đúng: B. Amazon ECS + Fargate

🇬🇧 Explanation:
AWS Fargate is serverless containers. You define Docker image + CPU/memory, Fargate handles EC2 instances automatically. No EC2 management needed.

🇻🇳 Giải thích:
Fargate = serverless containers. Bạn push Docker image → Fargate deploy (không quản lý EC2 cluster).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — EC2 = you manage / EC2 = bạn tự quản lý.
  • C — Lambda = not for long-running containers / Lambda = không dành cho container chạy lâu.
  • D — Beanstalk = PaaS (can use containers, but more overhead) / Beanstalk = PaaS (có thể dùng container, nhưng tốn công hơn).

🔑 Key Concept / Khái niệm cốt lõi: Docker serverless = Fargate / Docker serverless = Fargate.

📚 Reference: Domain 3 § "AWS Fargate"


Q51.

What is the maximum runtime for an AWS Lambda function?

Bản dịch tiếng Việt: Thời gian chạy tối đa cho hàm AWS Lambda là bao nhiêu?

A. 5 minutes B. 15 minutes C. 1 hour D. Unlimited (as long as it runs)

Correct answer: B Bản dịch đáp án đúng: B. 15 phút

🇬🇧 Explanation:
AWS Lambda has a maximum execution duration of 15 minutes (900 seconds). For longer tasks, use EC2, ECS, or Step Functions.

🇻🇳 Giải thích:
Lambda max timeout = 15 phút. Sau đó function tự động terminate. Nếu cần >15p → dùng EC2 hoặc Step Functions (orchestrate Lambda tasks).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — 5 minutes is insufficient / 5 phút là không đủ.
  • C — 1 hour exceeds limit / 1 giờ vượt quá giới hạn.
  • D — Unlimited is false / "Không giới hạn" là sai.

🔑 Key Concept / Khái niệm cốt lõi: Lambda = max 15 minutes / Lambda = tối đa 15 phút.

📚 Reference: Domain 3 § "AWS Lambda — Serverless Compute"


Q52.

Which AWS service is a content delivery network (CDN) that caches content at edge locations worldwide?

Bản dịch tiếng Việt: Dịch vụ AWS nào là mạng phân phối nội dung (CDN) lưu trữ nội dung ở các vị trí biên trên toàn thế giới?

A. Amazon Route 53 B. AWS Global Accelerator C. Amazon CloudFront D. AWS Direct Connect

Correct answer: C Bản dịch đáp án đúng: C. Mặt trận đám mây của Amazon

🇬🇧 Explanation:
Amazon CloudFront is AWS's CDN. It caches content (S3, images, videos) at 700+ edge locations worldwide. User requests go to nearest edge → cache hit or fetch from origin.

🇻🇳 Giải thích:
CloudFront = CDN. Content cached tại 700+ edge locations. Users ở Việt Nam → gọi edge location gần (Bangkok, Singapore) → latency thấp.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Route 53 = DNS (not content cache) / Route 53 = DNS (không phải cache nội dung).
  • B — Global Accelerator = network acceleration (not content cache) / Global Accelerator = tăng tốc mạng (không phải cache nội dung).
  • D — Direct Connect = dedicated network (not cache) / Direct Connect = mạng riêng (không phải cache).

🔑 Key Concept / Khái niệm cốt lõi: CloudFront = CDN = edge locations / CloudFront = CDN = các edge location.

📚 Reference: Domain 3 § "Amazon CloudFront — CDN"


Q53.

A company needs to migrate a large amount of data (several petabytes) from on-premises to AWS. Which service is most appropriate?

Bản dịch tiếng Việt: Một công ty cần di chuyển một lượng lớn dữ liệu (vài petabyte) từ tại chỗ sang AWS. Dịch vụ nào phù hợp nhất?

A. AWS DataSync B. AWS Snow Family (Snowball/Snowball Edge) C. AWS DMS (Database Migration Service) D. AWS Direct Connect

Correct answer: B Bản dịch đáp án đúng: B. Dòng AWS Snow (Snowball/Snowball Edge)

🇬🇧 Explanation:
AWS Snow Family (Snowcone, Snowball, Snowball Edge) physically ships hardware to your data center. You fill it with data, ship it back to AWS. For petabyte-scale, use multiple Snowball Edge devices (each holds tens to ~hundreds of TB). Much faster than internet transfer.

🇻🇳 Giải thích:
Petabytes = transfer network = months/years. AWS gửi Snowball (thiết bị vật lý) → bạn copy data → gửi lại AWS → import S3. Mấy tuần xong.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — DataSync = incremental sync (not bulk) / DataSync = đồng bộ tăng dần (không phải khối lượng lớn).
  • C — DMS = database migration (not general data) / DMS = di chuyển database (không phải dữ liệu chung).
  • D — Direct Connect = network link (not fast for petabytes) / Direct Connect = liên kết mạng (không nhanh cho petabytes).

🔑 Key Concept / Khái niệm cốt lõi: Large data transfer = Snow Family (physical) / Chuyển dữ liệu lớn = Snow Family (vật lý).

📚 Reference: Domain 3 § "AWS Snow Family — Physical Data Transfer"


Q54. (Select TWO)

Which of the following statements about VPCs and Security Groups are correct? (Select TWO)

Bản dịch tiếng Việt: Câu nào sau đây về VPC và Nhóm bảo mật là đúng? (Chọn HAI)

A. A Security Group is a stateless firewall at the subnet level B. A Security Group is a stateful firewall at the instance level C. A Network ACL operates at the subnet level and can explicitly deny traffic D. Security Groups support explicit "deny" rules just like Network ACLs E. Network ACLs are stateful and automatically allow return traffic

Correct answer: B, C Bản dịch đáp án đúng: B. Nhóm bảo mật là một tường lửa có trạng thái ở cấp độ phiên bản; C. Mạng ACL hoạt động ở cấp mạng con và có thể từ chối lưu lượng truy cập một cách rõ ràng

🇬🇧 Explanation:

  • B ✅ = Security Group is a stateful firewall at the instance level (remembers responses)
  • C ✅ = NACL is a stateless firewall at the subnet level (can explicitly deny)
  • A ❌ = Security Group is stateful (not stateless) and instance-level (not subnet)
  • D ❌ = Security Groups support allow rules only — they have NO explicit deny rules (unlike NACLs)
  • E ❌ = Network ACLs are stateless, not stateful — return traffic must be explicitly allowed by a rule

🇻🇳 Giải thích:
Câu B: Security Group = stateful (nếu outbound → inbound response auto-allow)
Câu C: NACL = stateless (explicit rules) + can deny

🔑 Key Concept / Khái niệm cốt lõi: SG = instance + stateful | NACL = subnet + stateless / SG = mức instance + stateful | NACL = mức subnet + stateless.

📚 Reference: Domain 3 § "Security Groups vs Network ACLs"


Q55.

Which AWS service is used to manage DNS for domains and route traffic based on health checks and routing policies?

Bản dịch tiếng Việt: Dịch vụ AWS nào được sử dụng để quản lý DNS cho miền và định tuyến lưu lượng truy cập dựa trên các chính sách định tuyến và kiểm tra tình trạng?

A. AWS VPN B. Amazon Route 53 C. AWS Direct Connect D. AWS API Gateway

Correct answer: B Bản dịch đáp án đúng: B. Tuyến đường Amazon 53

🇬🇧 Explanation:
Amazon Route 53 is AWS's DNS service. It registers domains, creates hosted zones, and supports routing policies (simple, weighted, latency, geolocation, failover, multivalue, geoproximity). Health checks enable failover.

🇻🇳 Giải thích:
Route 53 = DNS + domain registration. Bạn define routing policy (e.g., latency-based → users ở Asia → route to Asia region).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — VPN = network encryption (not DNS) / VPN = mã hóa mạng (không phải DNS).
  • C — Direct Connect = dedicated link (not DNS) / Direct Connect = liên kết riêng (không phải DNS).
  • D — API Gateway = API management (not DNS) / API Gateway = quản lý API (không phải DNS).

🔑 Key Concept / Khái niệm cốt lõi: Route 53 = DNS + routing policies / Route 53 = DNS + các chính sách định tuyến.

📚 Reference: Domain 3 § "Amazon Route 53 — DNS"


Q56.

Which Auto Scaling feature automatically adjusts EC2 instances based on CPU utilization?

Bản dịch tiếng Việt: Tính năng Auto Scaling nào tự động điều chỉnh các phiên bản EC2 dựa trên mức sử dụng CPU?

A. Scheduled Scaling B. Manual Scaling C. Target Tracking Scaling D. Predictive Scaling

Correct answer: C Bản dịch đáp án đúng: C. Mở rộng quy mô theo dõi mục tiêu

🇬🇧 Explanation:
Target Tracking Scaling automatically adjusts instances to maintain a target metric (e.g., 70% CPU). If CPU > 70%, add instances; if CPU < 70%, remove instances.

🇻🇳 Giải thích:
Target Tracking = ASG adjust instances to keep metric at target (e.g., CPU = 70%). Không cần manual scaling.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Scheduled Scaling = scale at specific times / Scheduled Scaling = mở rộng vào thời điểm định trước.
  • B — Manual Scaling = you add/remove / Manual Scaling = bạn tự thêm/bớt.
  • D — Predictive Scaling = ML forecast (newer feature) / Predictive Scaling = dự báo bằng ML (tính năng mới hơn).

🔑 Key Concept / Khái niệm cốt lõi: Target Tracking = automatic based on metric / Target Tracking = tự động dựa trên metric.

📚 Reference: Domain 3 § "Auto Scaling"


Q57. (Select TWO)

Which of the following are true about AWS database services? (Select TWO)

Bản dịch tiếng Việt: Điều nào sau đây đúng về dịch vụ cơ sở dữ liệu AWS? (Chọn HAI)

A. Aurora is AWS-native and 5x faster than MySQL B. DynamoDB is a relational database with SQL support C. Redshift is an in-memory caching service for sub-millisecond reads D. ElastiCache stores data in-memory to speed up reads E. RDS supports NoSQL and relational databases

Correct answer: A, D Bản dịch đáp án đúng: A. Aurora có nguồn gốc từ AWS và nhanh hơn 5 lần so với MySQL; D. ElastiCache lưu trữ dữ liệu trong bộ nhớ để tăng tốc độ đọc

🇬🇧 Explanation:

  • A ✅ = Aurora is 5x faster than MySQL (AWS-native, optimized)
  • D ✅ = ElastiCache stores in-memory data (Redis/Memcached)
  • B ❌ = DynamoDB is NoSQL (not relational, no SQL)
  • C ❌ = Redshift is a columnar data warehouse for analytics, NOT an in-memory caching service (that's ElastiCache)
  • E ❌ = RDS supports relational engines only (MySQL, PostgreSQL, etc.), not NoSQL

🇻🇳 Giải thích:
Câu A: Aurora = AWS relational DB, faster than MySQL
Câu D: ElastiCache = in-memory cache (speed up reads)

🔑 Key Concept / Khái niệm cốt lõi: Aurora > MySQL | DynamoDB = NoSQL | ElastiCache = cache / Aurora nhanh hơn MySQL | DynamoDB = NoSQL | ElastiCache = bộ nhớ đệm.

📚 Reference: Domain 3 § "RDS vs Aurora vs DynamoDB"


Q58.

A company wants to analyze CloudTrail logs to generate reports without running a database. Which service should they use?

Bản dịch tiếng Việt: Một công ty muốn phân tích nhật ký CloudTrail để tạo báo cáo mà không cần chạy cơ sở dữ liệu. Họ nên sử dụng dịch vụ nào?

A. Amazon RDS B. AWS Glue C. Amazon Athena D. Amazon QuickSight

Correct answer: C Bản dịch đáp án đúng: C. Amazon Athena

🇬🇧 Explanation:
Amazon Athena lets you query S3 data directly using SQL without setting up a database. CloudTrail logs are stored in S3 → use Athena to query them with SQL.

🇻🇳 Giải thích:
Athena = SQL query on S3 (serverless). CloudTrail logs → S3 → Athena query (no database setup).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — RDS = traditional database (requires setup) / RDS = database truyền thống (cần cài đặt).
  • B — Glue = ETL (not direct query) / Glue = ETL (không phải truy vấn trực tiếp).
  • D — QuickSight = visualization (not query engine) / QuickSight = trực quan hóa (không phải engine truy vấn).

🔑 Key Concept / Khái niệm cốt lõi: Query S3 with SQL = Athena / Truy vấn S3 bằng SQL = Athena.

📚 Reference: Domain 3 § "Amazon Athena"


Domain 4: Billing, Pricing, and Support (Q59–Q65)

Q59.

Which AWS pricing model is most suitable for a batch processing job that can tolerate interruptions and needs to minimize cost?

Bản dịch tiếng Việt: Mô hình định giá AWS nào phù hợp nhất cho công việc xử lý hàng loạt có thể chịu được sự gián đoạn và cần giảm thiểu chi phí?

A. On-Demand B. Reserved Instances C. Spot Instances D. Dedicated Hosts

Correct answer: C Bản dịch đáp án đúng: C. Phiên bản Spot

🇬🇧 Explanation:
Spot Instances save up to 90% compared to On-Demand. AWS can reclaim them with 2-minute notice, but batch jobs can tolerate interruptions (restart on another instance). Perfect for cost optimization.

🇻🇳 Giải thích:
Spot = 90% cheaper (rẻ nhất). Nhưng AWS có thể terminate. Batch jobs = có thể restart → tolerate interruption. Savings = siêu lớn.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — On-Demand = most expensive / On-Demand = đắt nhất.
  • B — Reserved = commitment cost (not minimum cost) / Reserved = chi phí cam kết (không phải chi phí thấp nhất).
  • D — Dedicated Hosts = very expensive / Dedicated Hosts = rất đắt.

🔑 Key Concept / Khái niệm cốt lõi: Batch fault-tolerant = Spot Instances / Batch chịu được gián đoạn = Spot Instances.

📚 Reference: Domain 4 § "AWS Pricing Models" — Spot Instances


Q60.

What is the primary purpose of the AWS Cost Explorer tool?

Bản dịch tiếng Việt: Mục đích chính của công cụ AWS Cost Explorer là gì?

A. To block unauthorized API calls B. To visualize, analyze, and forecast AWS spending trends over time C. To enforce encryption on all resources D. To automate resource deployment

Correct answer: B Bản dịch đáp án đúng: B. Để trực quan hóa, phân tích và dự báo xu hướng chi tiêu AWS theo thời gian

🇬🇧 Explanation:
Cost Explorer visualizes and analyzes AWS spending trends, forecasts future spending, and recommends Reserved Instances or Savings Plans to save money. It's your main tool for cost analysis and optimization.

🇻🇳 Giải thích:
Cost Explorer = xem chi phí theo thời gian (EC2 $500, S3 $200, ...). Forecast tháng tới. Recommend RI/SP.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Shield blocks API calls (not Cost) / Shield chặn tấn công (không phải chi phí).
  • C — KMS encrypts (not Cost) / KMS mã hóa (không phải chi phí).
  • D — CloudFormation deploys (not Cost) / CloudFormation triển khai (không phải chi phí).

🔑 Key Concept / Khái niệm cốt lõi: Cost trends + forecast + RI recommendations = Cost Explorer / Xu hướng chi phí + dự báo + khuyến nghị RI = Cost Explorer.

📚 Reference: Domain 4 § "AWS Cost Explorer"


Q61. (Select TWO)

Which of the following support features are included in AWS Business support plan? (Select TWO)

Bản dịch tiếng Việt: Tính năng hỗ trợ nào sau đây có trong gói hỗ trợ AWS Business? (Chọn HAI)

A. 24/7 phone and chat support B. A 15-minute response-time SLA for business-critical system down C. 7 core Trusted Advisor checks D. All Trusted Advisor checks E. Dedicated Technical Account Manager

Correct answer: A, D Bản dịch đáp án đúng: A. Hỗ trợ qua điện thoại và trò chuyện 24/7; D. Tất cả các bài kiểm tra của Trusted Advisor

🇬🇧 Explanation:

  • A ✅ = Business plan includes 24/7 phone, chat, and email support
  • D ✅ = Business plan includes the full set of Trusted Advisor checks (not just the core checks)
  • B ❌ = Business SLA for a production system down is < 1 hour, NOT 15 minutes; the 15-minute SLA (for business-critical systems down) belongs to Enterprise
  • C ❌ = The limited set of core Trusted Advisor checks applies to Basic/Developer; Business gets all checks
  • E ❌ = A dedicated Technical Account Manager (TAM) is Enterprise / Enterprise On-Ramp only

🇻🇳 Giải thích:
Câu A: Business = 24/7 support (phone + chat + email)
Câu D: Business = full Trusted Advisor checks (vs Basic = core checks only)

🔑 Key Concept / Khái niệm cốt lõi: Business = 24/7 phone + all checks / Business = hỗ trợ điện thoại 24/7 + đầy đủ các checks.

📚 Reference: Domain 4 § "AWS Support Plans" — Business


Q62.

Which AWS support plan provides a dedicated Technical Account Manager (TAM)?

Bản dịch tiếng Việt: Gói hỗ trợ AWS nào cung cấp Trình quản lý tài khoản kỹ thuật (TAM) chuyên dụng?

A. Basic B. Developer C. Business D. Enterprise (and Enterprise On-Ramp)

Correct answer: D Bản dịch đáp án đúng: D. Doanh nghiệp (và Doanh nghiệp On-Ramp)

🇬🇧 Explanation:
TAM (Technical Account Manager) is available in Enterprise and Enterprise On-Ramp support plans. Enterprise gets a dedicated TAM; On-Ramp gets a pooled TAM shared with other customers.

🇻🇳 Giải thích:
TAM = technical expert dành cho bạn (Enterprise = riêng, On-Ramp = chia sẻ). Basic/Developer/Business = không có.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Basic = no TAM / Basic = không có TAM.
  • B — Developer = no TAM / Developer = không có TAM.
  • C — Business = no TAM / Business = không có TAM.

🔑 Key Concept / Khái niệm cốt lõi: TAM = Enterprise/On-Ramp only / TAM = chỉ có ở Enterprise/On-Ramp.

📚 Reference: Domain 4 § "AWS Support Plans" — TAM vs Concierge


Q63.

What is the AWS Free Tier?

Bản dịch tiếng Việt: Bậc miễn phí của AWS là gì?

A. A temporary free trial that lasts 30 days B. Free usage of specific services with limits (Always Free, 12-Month Free, and Trials) C. A permanent discount on all AWS services D. Free access to on-premises AWS Outposts

Correct answer: B Bản dịch đáp án đúng: B. Sử dụng miễn phí các dịch vụ cụ thể có giới hạn (Luôn miễn phí, Miễn phí 12 tháng và Dùng thử)

🇬🇧 Explanation:
AWS Free Tier includes: Always Free (Lambda 1M requests, DynamoDB 25GB, indefinitely), 12-Month Free (EC2 750h/mo, S3 5GB, RDS 750h/mo), and Trials (SageMaker 2mo, etc.).

🇻🇳 Giải thích:
Free Tier = 3 loại: (1) Always Free (vĩnh viễn), (2) 12-Month Free (12 tháng đầu), (3) Trials (2-12 tháng trial).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Not just 30-day trial (has Always Free + 12-Month) / Không chỉ là bản dùng thử 30 ngày (có Always Free + 12 tháng).
  • C — Not a permanent discount (just free usage tiers) / Không phải giảm giá vĩnh viễn (chỉ là các bậc dùng miễn phí).
  • D — No free Outposts / Không có Outposts miễn phí.

🔑 Key Concept / Khái niệm cốt lõi: Free Tier = Always Free + 12-Month Free + Trials / Free Tier = Always Free + Miễn phí 12 tháng + Trials.

📚 Reference: Domain 4 § "AWS Free Tier"


Q64. (Select TWO)

Which of the following are tools to manage and optimize AWS costs? (Select TWO)

Bản dịch tiếng Việt: Công cụ nào sau đây là công cụ giúp quản lý và tối ưu hóa chi phí AWS? (Chọn HAI)

A. AWS Cost Explorer B. AWS Budgets C. AWS CloudTrail D. AWS CloudFormation E. AWS CloudHSM

Correct answer: A, B Bản dịch đáp án đúng: A. Trình khám phá chi phí AWS; B. Ngân sách AWS

🇬🇧 Explanation:

  • A ✅ = Cost Explorer = visualize, analyze, forecast spending
  • B ✅ = Budgets = set spending limits and alerts
  • C ❌ = CloudTrail = API logging (not cost management)
  • D ❌ = CloudFormation = IaC (not cost management)
  • E ❌ = CloudHSM = dedicated hardware security modules for key storage (not a cost-management tool)

🇻🇳 Giải thích:
Câu A: Cost Explorer = xem trends + forecast
Câu B: Budgets = alert when approaching limit

🔑 Key Concept / Khái niệm cốt lõi: Cost management = Cost Explorer + Budgets + Cost Tags + Anomaly Detection / Quản lý chi phí = Cost Explorer + Budgets + Cost Tags + Anomaly Detection.

📚 Reference: Domain 4 § "AWS Billing & Cost Management Tools"


Q65.

A company with multiple AWS accounts wants to consolidate billing and share volume discounts. Which AWS service enables this?

Bản dịch tiếng Việt: Một công ty có nhiều tài khoản AWS muốn hợp nhất việc thanh toán và chia sẻ chiết khấu theo số lượng. Dịch vụ AWS nào cho phép điều này?

A. AWS IAM B. AWS CloudFormation C. AWS Organizations with Consolidated Billing D. AWS Budgets

Correct answer: C Bản dịch đáp án đúng: C. Các tổ chức AWS có thanh toán tổng hợp

🇬🇧 Explanation:
AWS Organizations with Consolidated Billing enables one bill for multiple accounts and applies volume discounts across all accounts. This is how large companies manage accounts centrally.

🇻🇳 Giải thích:
Organizations + Consolidated Billing = 1 bill cho 5-10 accounts. AWS apply volume discount to tất cả (Account A: $500 + Account B: $300 = tính như $800, không tính riêng).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — IAM = user access (not billing) / IAM = truy cập người dùng (không phải billing).
  • B — CloudFormation = IaC (not billing) / CloudFormation = IaC (không phải billing).
  • D — Budgets = alerts (not consolidation) / Budgets = cảnh báo (không phải hợp nhất).

🔑 Key Concept / Khái niệm cốt lõi: Multi-account billing = Organizations + Consolidated Billing / Billing đa account = Organizations + Consolidated Billing.

📚 Reference: Domain 4 § "Consolidated Billing (AWS Organizations)"


Self-Scoring Worksheet

Your Score

  • Count correct answers per domain
  • Calculate percentage: (your score / total questions) × 100
  • Target: ≥52/65 (80%) for confidence

Identified Weak Areas

If you scored <70% on any domain:

  • Domain 1 (<11/16) → Review Domain 1 notes: Cloud concepts, Well-Architected, Shared Responsibility
  • Domain 2 (<14/20) → Review Domain 2 notes: IAM, CloudTrail/Config/CloudWatch, Encryption, Compliance
  • Domain 3 (<16/22) → Review Domain 3 notes: EC2, S3, RDS/DynamoDB, Networking, Services
  • Domain 4 (<5/7) → Review Domain 4 notes: Pricing models, Support plans, Cost tools

Next Steps

  1. Re-read weak sections in Knowledge/ files
  2. Take practice questions from ExamTopics (100+ questions per domain)
  3. Target ≥80% before exam day
  4. Review: Shared Responsibility Model + IAM + EC2 Pricing + Support Plans (highest-weight topics)

Unresolved / Areas needing verification

  • Pricing changes 2025/2026 — use AWS Pricing Calculator for latest
  • Support Plan response times — verify latest SLAs on aws.amazon.com/support
  • Free Tier eligibility — always confirm on Free Tier page (eligibility may vary by region)
  • Service availability — some services may not be available in all regions

Exam file created: 2026-05-21
Bilingual: English + Tiếng Việt (mentor tone)
Aligned with: CLF-C02 official exam format & Knowledge base files
Ready for: Self-scoring and review

Good luck on exam day! 🎯