CertHub
AWSFoundationalCLF-C02

AWS Certified Cloud Practitioner

Tất cả lời giải

CLF-C02 Mock Exam #02 — Solutions / Giải đề chi tiết

Bilingual: 🇬🇧 English + 🇻🇳 Vietnamese
References: Knowledge/ domain files | Difficulty: Medium-Hard (Real-world scenarios)


Score Calculation / Cách tính điểm

Formula: (# correct ÷ 65) × 1000 = score

ScoreStatusInterpretation
700–800✅ PASSComfortable pass (70-80% correct)
800–900✅ PASS+Strong understanding
900+✅ PASS (Expert)Excellent — ready for SAA-C03
0–699❌ FAILStudy more (focus weak domains)

Passing: ≥ 700 points (~46 questions correct out of 65)


Domain Score Tracker

Use this to identify weak areas:

DomainQuestionsYour ScoreTargetStatus
Domain 1 Cloud Concepts1-16__/16≥12
Domain 2 Security & Compliance17-36__/20≥15
Domain 3 Cloud Tech & Services37-58__/22≥16
Domain 4 Billing & Support59-65__/7≥5
TOTAL1-65__/65≥46 (700pts)

DOMAIN 1: Cloud Concepts (Questions 1-16)


Domain 1: Cloud Concepts (Q1–Q16)

Q1. Startup Migration Strategy

A fintech startup is migrating from on-premises to AWS. They have a monolithic legacy banking system running on physical servers. The CTO wants to move quickly with minimal code changes to test AWS benefits. Which migration strategy best fits?

Bản dịch tiếng Việt: Một công ty khởi nghiệp fintech đang chuyển từ tại chỗ sang AWS. Họ có một hệ thống ngân hàng kế thừa nguyên khối chạy trên các máy chủ vật lý. CTO muốn tiến hành nhanh chóng với những thay đổi mã tối thiểu để kiểm tra các lợi ích của AWS. Chiến lược di chuyển nào phù hợp nhất?

A. Refactor — rebuild entire app as microservices B. Rehost — lift-and-shift to EC2, same code, same OS C. Retire — discontinue old system D. Repurchase — switch to SaaS core banking platform

Correct answer: B Bản dịch đáp án đúng: B. Rehost - nâng và chuyển sang EC2, cùng mã, cùng hệ điều hành

🇬🇧 Explanation: Rehost (Lift-and-Shift) is the fastest migration strategy. You move application as-is from on-premises to EC2 without code changes. Minimal effort, quick ROI. Perfect for "test AWS benefits" scenario.

🇻🇳 Giải thích: Rehost (Lift-and-Shift) là strategy nhanh nhất. Di chuyển ứng dụng từ on-prem sang EC2 mà không thay đổi code. Bạn muốn test AWS benefits nhanh → Rehost là tối ưu.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Refactor) — Complete rewrite to microservices = 1-2 years, too slow for this timeline / Viết lại hoàn toàn thành microservices mất 1-2 năm, quá chậm cho timeline này.
  • C (Retire) — Discontinue system = loses functionality / Ngừng hệ thống làm mất chức năng.
  • D (Repurchase) — Switch to SaaS = requires changing core business logic / Chuyển sang SaaS đòi hỏi thay đổi business logic cốt lõi.

🔑 Key Concept / Khái niệm cốt lõi: 7 R's migration strategies — Rehost = speed, minimal change / 7 chiến lược migration 7 R's — Rehost = nhanh, ít thay đổi.

Domain: 1 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-1-cloud-concepts.md § Cloud Migration Strategies


Q2. Global Infrastructure for Low Latency

A Vietnamese e-commerce company wants to serve users across Southeast Asia with lowest possible latency. They deploy S3 and EC2 in ap-southeast-1 (Singapore). What should they add for ultra-fast content delivery to end-users?

Bản dịch tiếng Việt: Một công ty thương mại điện tử Việt Nam muốn phục vụ người dùng trên khắp Đông Nam Á với độ trễ thấp nhất có thể. Họ triển khai S3 và EC2 tại ap-đông nam-1 ( Singapore). Họ nên thêm gì để phân phối nội dung cực nhanh đến người dùng cuối?

A. Replicate S3 to us-east-1 region B. CloudFront — cache at 700+ edge locations C. Add more EC2 instances in same AZ D. Use AWS Global Accelerator for all requests

Correct answer: B Bản dịch đáp án đúng: B. CloudFront - bộ đệm tại hơn 700 vị trí biên

🇬🇧 Explanation: CloudFront is AWS CDN with 700+ edge locations globally. Caches content near users. S3 alone = region endpoint (200ms latency). CloudFront = cached at edge (10-50ms). Critical for global low-latency delivery.

🇻🇳 Giải thích: CloudFront là CDN của AWS, có 700+ edge locations. Cache content gần users, giảm latency từ 200ms xuống 10-50ms. Quan trọng nhất cho e-commerce (user experience).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Replicate to us-east-1) — Opposite direction, worse latency / Sai hướng, latency còn tệ hơn cho SE Asia.
  • C (More EC2 same AZ) — Doesn't reduce latency, doesn't scale globally / Không giảm latency, không mở rộng được toàn cầu.
  • D (Global Accelerator) — Network layer, not content delivery / Tối ưu network layer, không phải content delivery (caching).

🔑 Key Concept / Khái niệm cốt lõi: Edge Locations >> Regions; CloudFront = CDN / Edge Locations gần user hơn Regions; CloudFront chính là CDN.

Domain: 1 | Difficulty: Easy-Medium | Type: Multiple Choice
Reference: Knowledge/domain-3-cloud-technology-and-services.md § Networking


Q3. Healthcare Data Compliance

A hospital system must store patient records on-premises due to HIPAA regulations (physical data residency). But they want cloud benefits for non-sensitive analytics. Which deployment model?

Bản dịch tiếng Việt: Hệ thống bệnh viện phải lưu trữ hồ sơ bệnh nhân tại chỗ do các quy định của HIPAA (nơi lưu trữ dữ liệu vật lý). Nhưng họ muốn lợi ích đám mây dành cho những phân tích không nhạy cảm. Mô hình triển khai nào?

A. Public Cloud (AWS regions) B. Private Cloud (on-premises only) C. Hybrid Cloud — on-prem (patient records) + AWS (analytics) D. Multi-cloud (AWS + Azure)

Correct answer: C Bản dịch đáp án đúng: C. Đám mây lai — tại chỗ (hồ sơ bệnh nhân) + AWS (phân tích)

🇬🇧 Explanation: Hybrid Cloud = part on-premises (sensitive data, regulatory) + part public cloud (analytics, non-sensitive). HIPAA often requires data residency on-prem, but non-critical workloads can run in AWS cloud.

🇻🇳 Giải thích: Hybrid Cloud = part on-prem (bệnh nhân records, HIPAA cần on-prem) + part AWS (analytics, backup, non-sensitive). Bạn tận dụng cloud benefits mà vẫn comply regulations.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Public Cloud only) — Violates HIPAA data residency requirements / Vi phạm yêu cầu data residency của HIPAA.
  • B (Private Cloud only) — No cloud benefits for the analytics workload / Không tận dụng được lợi ích cloud cho phần analytics.
  • D (Multi-cloud) — Unnecessarily complex for this scenario / Phức tạp không cần thiết cho tình huống này.

🔑 Key Concept / Khái niệm cốt lõi: Deployment models — when to choose hybrid / Các mô hình triển khai — khi nào chọn hybrid.

Domain: 1 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-1-cloud-concepts.md § Deployment Models


Q4. 6 Advantages of Cloud — Use Case

A manufacturing company abandons their data center. Saves $500K/year on cooling, power, physical security, and IT staff. Which advantage of cloud computing does this demonstrate?

Bản dịch tiếng Việt: Một công ty sản xuất từ ​​bỏ trung tâm dữ liệu của họ. Tiết kiệm $500K/năm cho chi phí làm mát, điện, bảo mật vật lý và nhân viên CNTT. Điều này thể hiện ưu điểm nào của điện toán đám mây?

A. Trade CapEx for OpEx B. Stop guessing capacity C. Stop spending money running & maintaining data centers D. Increase speed and agility

Correct answer: C Bản dịch đáp án đúng: C. Ngừng chi tiền để vận hành và bảo trì trung tâm dữ liệu

🇬🇧 Explanation: AWS responsibility = data center operations (power, cooling, physical security, staff). Customer responsibility eliminated. Saves CapEx + OpEx overhead. Classic TCO improvement.

🇻🇳 Giải thích: AWS lo xây dựng DC, điều hòa, điện, bảo vệ vật lý, nhân viên. Bạn không phải chi tiền cho những thứ này. Tiết kiệm lớn.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Trade CapEx to OpEx) — True benefit but less specific to the eliminated data-center "costs" / Là lợi ích đúng nhưng không khớp cụ thể với chi phí data center bị loại bỏ.
  • B (Stop guessing capacity) — About scaling, not cost elimination / Nói về scaling, không phải loại bỏ chi phí.
  • D (Speed & agility) — About deployment speed, not cost / Nói về tốc độ triển khai, không phải chi phí.

🔑 Key Concept / Khái niệm cốt lõi: 6 Advantages of Cloud / 6 lợi thế của cloud.

Domain: 1 | Difficulty: Easy | Type: Multiple Choice
Reference: Knowledge/domain-1-cloud-concepts.md § 6 Advantages


Q5. CapEx vs OpEx

An IT director compares two models: buy servers ($50K upfront), depreciate 5 years = $10K/year. OR rent from AWS, pay $1K/month. Which principle best describes the AWS approach?

Bản dịch tiếng Việt: Một giám đốc CNTT so sánh hai mô hình: mua máy chủ (trả trước $50K), khấu hao 5 năm = $10K/năm. HOẶC thuê từ AWS, trả $1K/tháng. Nguyên tắc nào mô tả đúng nhất cách tiếp cận của AWS?

A. Cost optimization B. Trade Capital Expense for Operational Expense C. Stop guessing capacity D. Elasticity

Correct answer: B Bản dịch đáp án đúng: B. Chi phí vốn thương mại cho chi phí hoạt động

🇬🇧 Explanation:

  • CapEx = large upfront capital investment (depreciated over years)
  • OpEx = ongoing operational costs (flexible, can adjust)
  • AWS = OpEx model (pay-per-use, no upfront hardware investment)

This is THE fundamental financial benefit of cloud.

🇻🇳 Giải thích: CapEx = vốn đầu tư (50K server, một lần). OpEx = chi phí vận hành (1K/tháng, linh hoạt). Cloud = OpEx → không phải bỏ vốn lớn trước → better cash flow.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Economies of scale) — Real benefit, but doesn't describe the upfront-vs-monthly shift in this scenario / Là lợi ích thật, nhưng không mô tả việc chuyển từ trả trước sang trả hàng tháng ở đây.
  • C (Stop guessing capacity) — About elasticity/scaling, not the financial expense model / Nói về elasticity/scaling, không phải mô hình chi phí tài chính.
  • D (Increase speed and agility) — About deployment speed, not the CapEx-to-OpEx shift / Nói về tốc độ triển khai, không phải chuyển dịch CapEx sang OpEx.

🔑 Key Concept / Khái niệm cốt lõi: Cloud Economics — CapEx → OpEx / Kinh tế cloud — chuyển CapEx sang OpEx.

Domain: 1 | Difficulty: Easy | Type: Multiple Choice
Reference: Knowledge/domain-1-cloud-concepts.md § Cloud Economics


Q6. Well-Architected — Operational Excellence

A DevOps team wants to deploy new features 10x per day with minimal manual work and quick rollback if issues arise. Which pillar?

Bản dịch tiếng Việt: Nhóm DevOps muốn triển khai các tính năng mới 10 lần mỗi ngày với công việc thủ công tối thiểu và khôi phục nhanh chóng nếu có vấn đề phát sinh. Trụ cột nào?

A. Reliability B. Operational Excellence — automate, small reversible changes, anticipate failure C. Performance Efficiency D. Cost Optimization

Correct answer: B Bản dịch đáp án đúng: B. Hoạt động xuất sắc - tự động hóa, những thay đổi nhỏ có thể đảo ngược, lường trước thất bại

🇬🇧 Explanation: Operational Excellence pillar focuses on:

  • Automate deployments (CI/CD)
  • Small, reversible changes (safe rollback)
  • Anticipate failure (resilience)

This matches the scenario perfectly (automation + safe rollback).

🇻🇳 Giải thích: Operational Excellence = automate, small changes, quick rollback. Đó là toàn bộ DevOps philosophy.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Reliability) — Auto-recovery, multi-AZ, not deployment speed / Tự phục hồi, multi-AZ, không phải tốc độ deployment.
  • C (Performance Efficiency) — Right resources, serverless, not deployment / Chọn đúng tài nguyên, serverless, không phải deployment.
  • D (Cost Optimization) — Reduce waste, not deployment / Giảm lãng phí, không phải deployment.

🔑 Key Concept / Khái niệm cốt lõi: 6 Pillars of Well-Architected Framework / 6 trụ cột của Well-Architected Framework.

Domain: 1 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-1-cloud-concepts.md § Well-Architected Framework


Q7. Availability Zones — High Availability

A financial trading platform requires 99.99% uptime (52 minutes downtime/year max). Architect deploys to 3 Availability Zones in us-east-1. Which TWO statements are true? (Select TWO)

Bản dịch tiếng Việt: Nền tảng giao dịch tài chính yêu cầu thời gian hoạt động 99,99% (thời gian ngừng hoạt động tối đa 52 phút/năm). Kiến trúc sư triển khai tới 3 Availability Zone ở us-east-1. HAI câu nào là đúng? (Chọn HAI)

A. Each AZ is isolated — separate power, cooling, networking B. All 3 AZs are in same physical building (share cooling) C. If 1 AZ down, 2 others still serve traffic (automatic failover) D. Multi-AZ increases cost but guarantees 99.99% SLA E. AZs are separated by 1000+ miles for disaster recovery

Correct answer: A, C Bản dịch đáp án đúng: A. Mỗi AZ được cách ly — nguồn điện, hệ thống làm mát, mạng riêng biệt; C. Nếu 1 AZ bị hỏng, 2 AZ khác vẫn phục vụ lưu lượng truy cập (tự động chuyển đổi dự phòng)

🇬🇧 Explanation:

A. Each AZ is isolated — separate power, cooling, networking (true) ✅ C. If 1 AZ down, 2 others still serve traffic (true, automatic failover)

🇻🇳 Giải thích:

✅ A: Mỗi AZ cách ly độc lập (power, cooling, networking riêng) ✅ C: Một AZ down, 2 AZ còn lại vẫn handle traffic (automatic failover)

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B (All in same building) — AZs are geographically separated, not one building / Các AZ tách biệt về địa lý, không nằm chung một tòa nhà.
  • D (Guarantees 99.99% SLA) — Multi-AZ helps but doesn't by itself guarantee the SLA / Multi-AZ giúp ích nhưng tự nó không đảm bảo SLA 99.99%.
  • E (1000+ miles apart) — AZs are usually ~10-50 km apart, not continents / AZ thường cách nhau ~10-50 km, không phải hàng nghìn dặm.

🔑 Key Concept / Khái niệm cốt lõi: AZ isolation = HA foundation / Sự cô lập giữa các AZ là nền tảng của high availability.

Domain: 1 | Difficulty: Medium | Type: Multi-Select (2/4)
Reference: Knowledge/domain-1-cloud-concepts.md § Availability Zones


Q8. Cloud Adoption Framework (CAF)

A bank migrating to AWS is conducting training for IT staff (how to use AWS tools), hiring cloud architects, and defining governance policies. Which CAF perspectives are these? (Select TWO)

Bản dịch tiếng Việt: Một ngân hàng chuyển sang AWS đang tiến hành đào tạo nhân viên CNTT (cách sử dụng các công cụ AWS), thuê kiến ​​trúc sư đám mây và xác định các chính sách quản trị. Đây là những quan điểm nào của CAF? (Chọn HAI)

A. People Perspective — skills, training, staffing B. Governance Perspective — controls, audit, spending approval C. Platform Perspective (technical architecture) D. Business Perspective (ROI, revenue) E. Security Perspective (encryption, IAM)

Correct answer: A, B Bản dịch đáp án đúng: A. Quan điểm con người - kỹ năng, đào tạo, nhân sự; B. Quan điểm quản trị - kiểm soát, kiểm toán, phê duyệt chi tiêu

🇬🇧 Explanation:

A. People Perspective — skills, training, staffing (training staff) ✅ B. Governance Perspective — controls, audit, spending (governance policies)

🇻🇳 Giải thích: People = skills, training, staffing (đào tạo nhân viên). Governance = policies, controls, audit, chi tiêu (chính sách quản trị).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • C (Platform Perspective) — Technical architecture, not mentioned in scenario / Kiến trúc kỹ thuật, không được nhắc tới trong tình huống.
  • D (Business Perspective) — ROI, revenue, not mentioned / ROI, doanh thu, không được nhắc tới.
  • E (Security Perspective) — Encryption, IAM, not mentioned / Mã hóa, IAM, không được nhắc tới.

🔑 Key Concept / Khái niệm cốt lõi: CAF 6 Perspectives / 6 góc nhìn của Cloud Adoption Framework.

Domain: 1 | Difficulty: Medium | Type: Multi-Select (2/5)
Reference: Knowledge/domain-1-cloud-concepts.md § Cloud Adoption Framework


Q9. On-Demand Self-Service (NIST)

A developer launches an EC2 instance from AWS Console in 2 minutes without asking IT team. This is an example of which cloud characteristic?

Bản dịch tiếng Việt: Nhà phát triển khởi chạy phiên bản EC2 từ Bảng điều khiển AWS trong 2 phút mà không cần hỏi nhóm CNTT. Đây là ví dụ về đặc điểm nào của đám mây?

A. Broad Network Access B. On-Demand Self-Service — provision without IT involvement C. Rapid Elasticity D. Resource Pooling

Correct answer: B Bản dịch đáp án đúng: B. Tự phục vụ theo yêu cầu - cung cấp mà không cần sự tham gia của CNTT

🇬🇧 Explanation: NIST characteristic: "Users can provision resources without requesting from IT team"

This is the classic "self-service" cloud moment — no gatekeeping.

🇻🇳 Giải thích: On-Demand Self-Service = người dùng tự cấp tài nguyên cho mình, không cần gọi IT team.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Broad Network Access) — Accessibility from anywhere over the network, not self-provisioning / Truy cập từ mọi nơi qua mạng, không phải tự cấp phát.
  • C (Rapid Elasticity) — Auto-scaling up/down, not manual provisioning without IT / Tự co giãn lên/xuống, không phải tự cấp phát mà bỏ qua IT.
  • D (Resource Pooling) — Multi-tenant resource sharing, not self-service / Chia sẻ tài nguyên đa khách hàng, không phải self-service.

🔑 Key Concept / Khái niệm cốt lõi: NIST 5 Characteristics of Cloud / 5 đặc điểm của cloud theo NIST.

Domain: 1 | Difficulty: Easy | Type: Multiple Choice
Reference: Knowledge/domain-1-cloud-concepts.md § Cloud Computing Definition


Q10. IaaS vs PaaS Comparison

Scenario 1: Developer manually installs OS, patches, app dependencies on EC2 Scenario 2: Developer uploads code to Elastic Beanstalk, AWS manages servers, OS, scaling

Which statements are correct? (Select TWO)

Bản dịch tiếng Việt: Tình huống 1: Nhà phát triển cài đặt thủ công hệ điều hành, bản vá, phần phụ thuộc ứng dụng trên EC2 Tình huống 2: Nhà phát triển tải mã lên Elastic Beanstalk, AWS quản lý máy chủ, hệ điều hành, mở rộng quy mô Câu phát biểu nào đúng? (Chọn HAI)

A. Scenario 1 = IaaS (customer manages more) B. Scenario 2 = PaaS (AWS manages more) C. Scenario 1 requires less operational overhead D. Scenario 2 is cheaper (less AWS responsibility) E. Both have same level of customer responsibility

Correct answer: A, B Bản dịch đáp án đúng: A. Kịch bản 1 = IaaS (khách hàng quản lý nhiều hơn); B. Kịch bản 2 = PaaS (AWS quản lý nhiều hơn)

🇬🇧 Explanation:

A. Scenario 1 = IaaS — customer manages application, OS, runtime (more responsibility) ✅ B. Scenario 2 = PaaS — AWS manages servers, OS, auto-scaling (less responsibility)

🇻🇳 Giải thích: IaaS = bạn quản lý nhiều hơn (EC2). PaaS = AWS quản lý nhiều hơn (Beanstalk).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • C (Scenario 1 requires less overhead) — False, IaaS requires MORE overhead (patching, OS, etc.) / Sai, IaaS đòi hỏi NHIỀU công sức hơn (patching, OS...).
  • D (Scenario 2 is cheaper) — Wrong reasoning; cost isn't the defining difference between the models / Lý do sai; chi phí không phải điểm khác biệt định nghĩa giữa hai mô hình.
  • E (Both have same responsibility) — False, they sit at different responsibility layers / Sai, chúng ở các tầng trách nhiệm khác nhau.

🔑 Key Concept / Khái niệm cốt lõi: Service Models — IaaS vs PaaS / Mô hình dịch vụ — IaaS so với PaaS.

Domain: 1 | Difficulty: Medium | Type: Multi-Select (2/5)
Reference: Knowledge/domain-1-cloud-concepts.md § IaaS vs PaaS vs SaaS


Q11. AWS Global Infrastructure Layers

A company wants absolute lowest latency for users in Tokyo (sub-10ms). Which infrastructure should they choose?

Bản dịch tiếng Việt: Một công ty muốn độ trễ tuyệt đối thấp nhất cho người dùng ở Tokyo (dưới 10 mili giây). Họ nên chọn cơ sở hạ tầng nào?

A. Regional endpoint (Tokyo Region ap-northeast-1) B. Edge Location near Tokyo C. AWS Local Zone in Tokyo — ultra-low latency (1ms) D. Wavelength Zone (for 5G mobile)

Correct answer: C Bản dịch đáp án đúng: C. AWS Local Zone ở Tokyo — độ trễ cực thấp (1ms)

🇬🇧 Explanation: Local Zone (C) delivers 1-3ms latency — it extends region services ultra-close to a specific city. Local Zones are AWS infrastructure for ultra-low latency in cities (Tokyo, Los Angeles, Sydney, etc.). Perfect for real-time apps (gaming, trading).

🇻🇳 Giải thích: Local Zone = infra siêu gần cities, latency 1-3ms. Perfect cho Tokyo gamers.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Region) — ~40-50ms latency from Tokyo, too high for sub-10ms / Latency ~40-50ms từ Tokyo, quá cao cho yêu cầu dưới 10ms.
  • B (Edge Location) — 10-20ms and it caches content, not for compute / 10-20ms và chỉ cache nội dung, không chạy compute.
  • D (Wavelength) — 5G mobile edge, a different use case / Edge cho mạng 5G, use case khác.

🔑 Key Concept / Khái niệm cốt lõi: AWS Global Infrastructure layers (Region > AZ > Local Zone) / Các tầng hạ tầng toàn cầu của AWS (Region > AZ > Local Zone).

Domain: 1 | Difficulty: Hard | Type: Multiple Choice
Reference: Knowledge/domain-1-cloud-concepts.md § AWS Global Infrastructure


Q12. Migration Strategy — 7 R's

A legacy mainframe runs payroll. CIO says "We're locked in with licenses, not moving." What's the strategy?

Bản dịch tiếng Việt: Một máy tính lớn kế thừa chạy bảng lương. CIO nói "Chúng tôi bị khóa bằng giấy phép, không thể di chuyển." Chiến lược là gì?

A. Rehost B. Refactor C. Repurchase D. Retain — keep on-premises, not worth migrating

Correct answer: D Bản dịch đáp án đúng: D. Giữ lại - giữ tại chỗ, không đáng để di chuyển

🇬🇧 Explanation: Retain = keep on-premises, don't migrate. Used when:

  • Cost of migration > benefits
  • Licensing constraints
  • Regulatory locked to on-prem

🇻🇳 Giải thích: Retain = giữ on-prem, không migrate. Không phải loại gì khác.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Rehost) — Lift-and-shift to AWS, but CIO explicitly says "not moving" / Lift-and-shift lên AWS, nhưng CIO nói rõ "không chuyển".
  • B (Replatform) — Minor optimizations during migration, still a migration / Tối ưu nhẹ khi migrate, vẫn là migrate.
  • C (Retire) — Decommission the system, but it's still in use / Loại bỏ hệ thống, nhưng hệ thống vẫn đang dùng.

🔑 Key Concept / Khái niệm cốt lõi: 7 R's Migration Strategies / 7 chiến lược migration 7 R's.

Domain: 1 | Difficulty: Easy | Type: Multiple Choice
Reference: Knowledge/domain-1-cloud-concepts.md § Cloud Migration Strategies


Q13. Elasticity vs Scalability

Which statement best distinguishes these?

Bản dịch tiếng Việt: Tuyên bố nào phân biệt tốt nhất những điều này?

A. Elasticity = horizontal scaling only B. Elasticity = auto scale up/down based on demand; Scalability = designed to grow C. Both mean same thing D. Scalability = fast, Elasticity = slow

Correct answer: B Bản dịch đáp án đúng: B. Độ co giãn = tự động tăng/giảm quy mô dựa trên nhu cầu; Khả năng mở rộng = được thiết kế để phát triển

🇬🇧 Explanation:

  • Elasticity: Automatic, real-time scaling (Lambda scales 0 → 10K concurrency)
  • Scalability: Capability to grow (architecture supports 10K users, can scale to 1M)

Elasticity is dynamic. Scalability is structural.

🇻🇳 Giải thích: Elasticity = tự động giãn dãn theo demand. Scalability = thiết kế để phát triển.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (definitions reversed) — Swaps the two terms; elasticity is the dynamic one, not scalability / Đảo ngược hai khái niệm; elasticity mới là cái động, không phải scalability.
  • C (they are the same thing) — They are related but distinct: one is dynamic, one is structural / Liên quan nhưng khác nhau: một cái động, một cái thuộc thiết kế.
  • D (both refer only to manual scaling) — Elasticity is automatic, not manual / Elasticity là tự động, không phải thủ công.

🔑 Key Concept / Khái niệm cốt lõi: Cloud Design Principles / Nguyên lý thiết kế cloud.

Domain: 1 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-1-cloud-concepts.md § Design Principles


Q14. Well-Architected — Reliability + Auto-Recovery

An e-commerce app uses Multi-AZ RDS with auto-failover. If primary AZ fails, secondary takes over automatically within 1 minute. Which pillar?

Bản dịch tiếng Việt: Ứng dụng thương mại điện tử sử dụng Multi-AZ RDS với tính năng tự động chuyển đổi dự phòng. Nếu AZ chính không thành công, AZ phụ sẽ tự động tiếp quản trong vòng 1 phút. Trụ cột nào?

A. Performance Efficiency B. Cost Optimization C. Reliability — automatically recover from failure D. Operational Excellence

Correct answer: C Bản dịch đáp án đúng: C. Độ tin cậy - tự động phục hồi sau thất bại

🇬🇧 Explanation: Reliability pillar = "automatically recover from failure"

Multi-AZ RDS = if primary AZ fails, secondary takes over automatically. This is the definition of reliable architecture.

🇻🇳 Giải thích: Reliability = tự động recover từ failures. Multi-AZ auto-failover là perfect example.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Operational Excellence) — Automation/CI-CD of operations, not auto-failover recovery / Tự động hóa vận hành/CI-CD, không phải auto-failover.
  • B (Security) — Protecting data and systems, not recovery from failure / Bảo vệ dữ liệu/hệ thống, không phải phục hồi sau lỗi.
  • D (Cost Optimization) — Reducing waste, unrelated to failover / Giảm lãng phí, không liên quan failover.

🔑 Key Concept / Khái niệm cốt lõi: 6 Pillars — Reliability pillar / 6 trụ cột — trụ cột Reliability.

Domain: 1 | Difficulty: Easy-Medium | Type: Multiple Choice
Reference: Knowledge/domain-1-cloud-concepts.md § Well-Architected Framework


Q15. Shared Responsibility — Who owns what?

A media company stores videos in S3. Bucket was accidentally set public (anyone can download). Data exposed. According to Shared Responsibility Model, who bears responsibility?

Bản dịch tiếng Việt: Một công ty truyền thông lưu trữ video trong S3. Nhóm vô tình được đặt ở chế độ công khai (bất kỳ ai cũng có thể tải xuống). Dữ liệu bị lộ. Theo Mô hình chia sẻ trách nhiệm, ai chịu trách nhiệm?

A. AWS — should have blocked public access B. Customer — bucket access config is "Security IN the Cloud" C. Both share responsibility D. Neither — no one to blame

Correct answer: B Bản dịch đáp án đúng: B. Khách hàng — cấu hình truy cập nhóm là "Bảo mật TRÊN Đám mây"

🇬🇧 Explanation: Bucket access configuration = "Security IN the Cloud" = customer responsibility.

AWS doesn't know your business logic. You decide who can access your bucket.

🇻🇳 Giải thích: Bucket config là "Security IN the Cloud" = bạn chịu trách nhiệm. AWS chỉ cung cấp infrastructure.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (AWS) — AWS secures the infrastructure, not your bucket access settings / AWS bảo vệ hạ tầng, không phải cấu hình truy cập bucket của bạn.
  • C (Shared equally) — Bucket access config is solely the customer's responsibility / Cấu hình truy cập bucket hoàn toàn là trách nhiệm của khách hàng.
  • D (No one / it's a bug) — It's a misconfiguration the customer owns, not an AWS bug / Đây là lỗi cấu hình của khách hàng, không phải lỗi của AWS.

🔑 Key Concept / Khái niệm cốt lõi: Shared Responsibility Model / Mô hình trách nhiệm chia sẻ.

Domain: 2 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-2-security-and-compliance.md § Shared Responsibility Model


Q16. Cloud Economics — Right-Sizing

An IT team finds EC2 instance running at 5% CPU utilization for months. What's the financial benefit of "right-sizing"?

Bản dịch tiếng Việt: Một nhóm CNTT nhận thấy phiên bản EC2 chạy ở mức sử dụng CPU 5% trong nhiều tháng. Lợi ích tài chính của việc "đúng kích cỡ" là gì?

A. 10% cost reduction B. 30% cost reduction C. ~90% cost reduction (downsize to smaller instance type) D. Cost stays same (same region)

Correct answer: C Bản dịch đáp án đúng: C. Giảm ~90% chi phí (giảm kích thước xuống loại phiên bản nhỏ hơn)

🇬🇧 Explanation: If running t2.xlarge ($0.15/hr) at 5% CPU, downsize to t2.micro ($0.011/hr):

  • Cost reduction: (0.15 - 0.011) / 0.15 = ~93%

Right-sizing is one of the easiest cost optimizations.

🇻🇳 Giải thích: Nếu instance chỉ dùng 5%, downsize → giảm ~90% chi phí.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (~10% reduction) — Far too low; right-sizing a 5%-CPU instance down saves much more / Quá thấp; downsize instance chỉ dùng 5% tiết kiệm nhiều hơn nhiều.
  • B (~50% reduction) — Still understates the saving when going to a much smaller class / Vẫn ước thiếu khi chuyển sang class nhỏ hơn nhiều.
  • D (No savings possible) — Wrong; an idle oversized instance is the prime right-sizing target / Sai; instance lớn mà nhàn rỗi chính là đối tượng right-sizing tốt nhất.

🔑 Key Concept / Khái niệm cốt lõi: Cloud Economics — Right-Sizing / Kinh tế cloud — Right-Sizing (chọn đúng kích cỡ).

Domain: 1 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-1-cloud-concepts.md § Cloud Economics


Domain 2: Security and Compliance (Q17–Q36)

Q17. RDS Patching — Shared Responsibility

A healthcare company runs RDS PostgreSQL. A critical vulnerability (CVE-2024-1234) is found in PostgreSQL engine. Who patches the database engine?

Bản dịch tiếng Việt: Một công ty chăm sóc sức khỏe điều hành RDS PostgreSQL. Một lỗ hổng nghiêm trọng (CVE-2024-1234) được tìm thấy trong công cụ PostgreSQL. Ai vá công cụ cơ sở dữ liệu?

A. Customer must download patch and apply B. AWS patches automatically (managed database service) C. AWS sends patch, customer installs D. AWS provides patch recommendation, customer decides

Correct answer: B Bản dịch đáp án đúng: B. AWS tự động vá lỗi (dịch vụ cơ sở dữ liệu được quản lý)

🇬🇧 Explanation: RDS = managed database service. AWS patches the database engine automatically.

Key distinction:

  • RDS patching = AWS responsibility (managed)
  • EC2 OS patching = customer responsibility (unmanaged)

🇻🇳 Giải thích: RDS = managed service → AWS patch engine tự động. Bạn không cần lo.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Customer patches manually) — RDS is managed; the customer does not patch the DB engine / RDS là managed; khách hàng không patch DB engine.
  • C (Shared equally) — Engine patching is fully AWS's responsibility for RDS / Patch engine hoàn toàn là trách nhiệm của AWS với RDS.
  • D (No patching needed) — Patches are needed; AWS just applies them for you / Vẫn cần patch; chỉ là AWS thực hiện thay bạn.

🔑 Key Concept / Khái niệm cốt lõi: Shared Responsibility by service / Trách nhiệm chia sẻ thay đổi theo từng dịch vụ.

Domain: 2 | Difficulty: Easy-Medium | Type: Multiple Choice
Reference: Knowledge/domain-2-security-and-compliance.md § Shared Responsibility (service variation)


Q18. EC2 Patching — Shared Responsibility

Same healthcare company runs custom medical software on EC2 Linux instances. A critical OS vulnerability is released. Who patches the OS?

Bản dịch tiếng Việt: Cùng một công ty chăm sóc sức khỏe chạy phần mềm y tế tùy chỉnh trên các phiên bản EC2 Linux. Một lỗ hổng hệ điều hành nghiêm trọng được phát hành. Ai vá hệ điều hành?

A. Customer responsible (infrastructure you manage) B. AWS patches Linux automatically C. Customer and AWS share patching D. Operating system vendor patches through AWS

Correct answer: A Bản dịch đáp án đúng: A. Khách hàng chịu trách nhiệm (cơ sở hạ tầng bạn quản lý)

🇬🇧 Explanation: EC2 = infrastructure you manage. You launch instances, you patch OS.

AWS provides the hypervisor, customer patches OS/applications.

🇻🇳 Giải thích: EC2 = bạn quản lý toàn bộ instance. Bạn patch OS, bạn patch app.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B (AWS patches the OS) — AWS only manages the hypervisor; OS patching is yours on EC2 / AWS chỉ quản lý hypervisor; patch OS là việc của bạn trên EC2.
  • C (Shared equally) — Guest OS patching sits entirely with the customer / Patch guest OS hoàn toàn thuộc về khách hàng.
  • D (No patching needed) — Unpatched OS is a real vulnerability you must fix / OS không patch là lỗ hổng thật bạn phải xử lý.

🔑 Key Concept / Khái niệm cốt lõi: Shared Responsibility — EC2 vs RDS / Trách nhiệm chia sẻ — EC2 so với RDS.

Domain: 2 | Difficulty: Easy-Medium | Type: Multiple Choice
Reference: Knowledge/domain-2-security-and-compliance.md § Shared Responsibility (EC2 vs RDS)


Q19. IAM Best Practice — EC2 S3 Access

A developer's EC2 instance needs to read from S3 bucket. What's the BEST approach?

Bản dịch tiếng Việt: Phiên bản EC2 của nhà phát triển cần đọc từ nhóm S3. Cách tiếp cận TỐT NHẤT là gì?

A. Store AWS access keys in EC2 user data script B. Hardcode access keys in application code C. Attach IAM role to EC2 instance — temp credentials, automatic rotation D. Use root account credentials

Correct answer: C Bản dịch đáp án đúng: C. Đính kèm vai trò IAM vào phiên bản EC2 — thông tin xác thực tạm thời, xoay vòng tự động

🇬🇧 Explanation: IAM roles = temporary credentials, automatic rotation, no hardcoding.

Don't hardcode access keys. Attach role → EC2 automatically assumes role → temp credentials → automatic refresh.

🇻🇳 Giải thích: IAM role = credentials tạm thời, tự động rotate. Đó là AWS best practice (không hardcode keys).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Hardcode access keys in the app) — Long-lived keys in code are a major security anti-pattern / Nhúng key cố định vào code là anti-pattern bảo mật nghiêm trọng.
  • B (Store keys in an environment variable) — Still static credentials that can leak and don't rotate / Vẫn là credentials tĩnh, có thể rò rỉ và không tự rotate.
  • D (Make the bucket public) — Exposes data to everyone; never the right access method / Phơi bày dữ liệu cho tất cả; không bao giờ là cách cấp quyền đúng.

🔑 Key Concept / Khái niệm cốt lõi: IAM Best Practice — Roles for EC2 / Best practice IAM — dùng Role cho EC2.

Domain: 2 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-2-security-and-compliance.md § IAM Best Practices


Q20. IAM Policy — JSON Interpretation

Review this policy:

{
  "Effect": "Allow",
  "Action": ["s3:GetObject", "s3:PutObject"],
  "Resource": "arn:aws:s3:::company-bucket/*"
}

What actions are allowed?

Bản dịch tiếng Việt: Xem lại chính sách này: json { "Effect": "Allow", "Action": ["s3:GetObject", "s3:PutObject"], "Resource": "arn:aws:s3:::company-bucket/*" } Những hành động nào được phép?

A. GetObject only B. GetObject + PutObject (read + write to objects) C. Full S3 access D. DeleteObject

Correct answer: B Bản dịch đáp án đúng: B. GetObject + PutObject (đọc + ghi vào đối tượng)

🇬🇧 Explanation: Action array = ["s3:GetObject", "s3:PutObject"] = both actions allowed.

  • GetObject = read
  • PutObject = write
  • Full access = "*" (not listed here)

🇻🇳 Giải thích: Action array có 2 actions → 2 actions được phép. Cơ bản lắm.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (GetObject only) — The Action array lists two actions, not one / Mảng Action liệt kê hai action, không phải một.
  • C (Full S3 access) — Full access requires "s3:", which isn't in this policy / Full access cần "s3:", không có trong policy này.
  • D (DeleteObject) — Delete is not in the Action array, so it's denied by default / Delete không có trong Action array nên bị từ chối mặc định.

🔑 Key Concept / Khái niệm cốt lõi: IAM Policy structure / Cấu trúc của IAM policy.

Domain: 2 | Difficulty: Easy | Type: Multiple Choice
Reference: Knowledge/domain-2-security-and-compliance.md § IAM Policy


Q21. MFA — Root Account Protection

Best practice after creating AWS account?

Bản dịch tiếng Việt: Cách thực hành tốt nhất sau khi tạo tài khoản AWS?

A. Create access keys for root account for programmatic access B. Enable MFA on root account immediately C. Share root password with team leads D. Root account disabled by default

Correct answer: B Bản dịch đáp án đúng: B. Kích hoạt MFA trên tài khoản root ngay lập tức

🇬🇧 Explanation: Root account = master key to everything. Always enable MFA.

Day 1 checklist:

  1. Enable MFA on root
  2. Create first IAM user (admin)
  3. Use IAM user going forward
  4. NEVER use root for daily tasks

🇻🇳 Giải thích: Root account = full power. MFA = bắt buộc. Đó là cơ bản.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Use root for all daily tasks) — Root should be locked away, not used daily / Root nên được khóa kỹ, không dùng hằng ngày.
  • C (Share root credentials with the team) — Credentials must never be shared / Không bao giờ được chia sẻ credentials.
  • D (Delete the root account) — Root cannot be deleted and is still needed for some tasks / Không thể xóa root và vẫn cần cho một số tác vụ.

🔑 Key Concept / Khái niệm cốt lõi: IAM Best Practices — MFA / Best practice IAM — bật MFA.

Domain: 2 | Difficulty: Easy | Type: Multiple Choice
Reference: Knowledge/domain-2-security-and-compliance.md § IAM Best Practices


Q22. Compliance Program — HIPAA

A hospital processes patient records with SSNs, diagnoses, medications. Which compliance framework mandates data protection?

Bản dịch tiếng Việt: Bệnh viện xử lý hồ sơ bệnh nhân bằng SSN, chẩn đoán, thuốc men. Khung tuân thủ nào bắt buộc phải bảo vệ dữ liệu?

A. PCI-DSS (payment cards) B. HIPAA (healthcare data) C. GDPR (EU privacy) D. SOC 2 (audit controls)

Correct answer: B Bản dịch đáp án đúng: B. HIPAA (dữ liệu chăm sóc sức khỏe)

🇬🇧 Explanation: HIPAA = Health Insurance Portability & Accountability Act — the US regulation governing protected health information (patient records, diagnoses, SSNs in a clinical context). Healthcare = HIPAA.

🇻🇳 Giải thích: Healthcare data (patient records) = HIPAA. Đó là regulatory requirement cho bệnh viện.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (PCI-DSS) — Payment card industry standard for credit card data, not health records / Tiêu chuẩn cho dữ liệu thẻ tín dụng, không phải hồ sơ y tế.
  • C (GDPR) — EU privacy regulation for EU resident data, not US healthcare-specific / Quy định bảo mật của EU cho dữ liệu cư dân EU, không chuyên cho y tế Mỹ.
  • D (SOC 2) — General audit/controls framework, not a healthcare data law / Khung kiểm toán/kiểm soát chung, không phải luật dữ liệu y tế.

🔑 Key Concept / Khái niệm cốt lõi: Compliance Programs / Các chương trình tuân thủ.

Domain: 2 | Difficulty: Easy | Type: Multiple Choice
Reference: Knowledge/domain-2-security-and-compliance.md § Compliance Programs


Q23. CloudTrail vs CloudWatch vs AWS Config

A security team needs to investigate: "Which user deleted the S3 bucket last Tuesday at 3 PM?" Which tool?

Bản dịch tiếng Việt: Nhóm bảo mật cần điều tra: "Người dùng nào đã xóa bộ chứa S3 lúc 3 giờ chiều Thứ Ba tuần trước?" Công cụ nào?

A. CloudWatch — application performance B. AWS Config — configuration changes C. CloudTrail — API audit log ("who did what when") D. AWS Trusted Advisor — best practices

Correct answer: C Bản dịch đáp án đúng: C. CloudTrail — Nhật ký kiểm tra API ("ai đã làm gì khi nào")

🇬🇧 Explanation: CloudTrail = "who did what when" (API audit log)

Shows every API call: user, action, timestamp, result. Perfect for investigation.

🇻🇳 Giải thích: CloudTrail = API audit log. Bạn muốn biết "ai xóa gì lúc nào" → CloudTrail.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (CloudWatch) — Metrics/performance logs, not a record of who made which API call / Metrics/log hiệu năng, không ghi lại ai gọi API nào.
  • B (AWS Config) — Tracks resource configuration changes, not user-action audit / Theo dõi thay đổi cấu hình tài nguyên, không phải audit hành động người dùng.
  • D (Trusted Advisor) — Best-practice recommendations, not an audit trail / Khuyến nghị best-practice, không phải nhật ký audit.

🔑 Key Concept / Khái niệm cốt lõi: CloudTrail vs CloudWatch vs Config / Phân biệt CloudTrail và CloudWatch và Config.

Domain: 2 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-2-security-and-compliance.md § Audit Services


Q24. DDoS Attack — AWS Shield

A website suddenly receives millions of requests from thousands of IPs, causing service down. The company has AWS Shield Standard (free). Is protection included?

Bản dịch tiếng Việt: Một trang web đột nhiên nhận được hàng triệu yêu cầu từ hàng nghìn IP, khiến dịch vụ ngừng hoạt động. Công ty có AWS Shield Standard (miễn phí). Có bao gồm bảo vệ không?

A. No — must purchase Shield Advanced B. Yes — Shield Standard (free) provides basic Layer 3-4 DDoS protection C. Only for AWS infrastructure, not customer apps D. Shield only works for CloudFront

Correct answer: B Bản dịch đáp án đúng: B. Có — Shield Standard (miễn phí) cung cấp khả năng bảo vệ DDoS Lớp 3-4 cơ bản

🇬🇧 Explanation:

  • Shield Standard (free): Included for all AWS customers. Blocks Layer 3-4 attacks (network, transport).
  • Shield Advanced (paid): Layer 3-7 (includes application), DRT team, DDoS cost protection.

Website gets DDoS → Shield Standard helps. If not enough, upgrade to Advanced.

🇻🇳 Giải thích: Shield Standard = free, included. Protect Layer 3-4 automatically.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (No — Shield is paid only) — Shield Standard is free and on by default for all customers / Shield Standard miễn phí và bật mặc định cho mọi khách hàng.
  • C (Only WAF can stop this) — WAF handles Layer 7; Shield Standard already covers Layer 3-4 DDoS / WAF lo Layer 7; Shield Standard đã chặn DDoS Layer 3-4.
  • D (Need Shield Advanced for any DDoS) — Advanced adds Layer 3-7 + DRT, but Standard handles basic L3-4 / Advanced thêm Layer 3-7 + DRT, nhưng Standard đã xử lý L3-4 cơ bản.

🔑 Key Concept / Khái niệm cốt lõi: DDoS Protection — Shield tiers / Bảo vệ DDoS — các mức Shield.

Domain: 2 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-2-security-and-compliance.md § AWS Shield


Q25. SQL Injection Attack — WAF

An e-commerce site is receiving requests with payloads like: '; DROP TABLE users;--

Which service blocks this?

Bản dịch tiếng Việt: Một trang thương mại điện tử đang nhận được các yêu cầu có tải trọng như: '; Người dùng DROP TABLE;-- Dịch vụ nào chặn điều này?

A. AWS Shield B. Security Groups C. AWS WAF (Web Application Firewall — blocks Layer 7 attacks) D. Network ACLs

Correct answer: C Bản dịch đáp án đúng: C. AWS WAF (Tường lửa ứng dụng web - chặn các cuộc tấn công Lớp 7)

🇬🇧 Explanation: WAF = Web Application Firewall. Blocks Layer 7 attacks (SQL injection, XSS, etc.).

Typical pattern:

  • SQL Injection → WAF
  • DDoS → Shield
  • Port scanning → Security Group

🇻🇳 Giải thích: SQL injection = Layer 7 attack (application). WAF block nó.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (AWS Shield) — Stops L3-4 DDoS, not application-layer SQL injection / Chặn DDoS L3-4, không chặn SQL injection ở tầng ứng dụng.
  • B (Security Group) — Stateful firewall by port/IP, can't inspect SQL payloads / Firewall theo port/IP, không soi được payload SQL.
  • D (NACL) — Subnet-level port/IP filtering, no Layer 7 inspection / Lọc port/IP ở subnet, không soi Layer 7.

🔑 Key Concept / Khái niệm cốt lõi: Application Security — WAF / Bảo mật ứng dụng — WAF.

Domain: 2 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-2-security-and-compliance.md § AWS WAF


Q26. GuardDuty — Threat Detection

A company suspects an EC2 instance has been compromised and might be mining cryptocurrency. Which service detects this using ML?

Bản dịch tiếng Việt: Một công ty nghi ngờ một phiên bản EC2 đã bị xâm phạm và có thể đang khai thác tiền điện tử. Dịch vụ nào phát hiện điều này bằng ML?

A. AWS Config B. Amazon GuardDuty — analyzes CloudTrail/VPC logs, detects anomalies/malware C. CloudTrail D. AWS Inspector

Correct answer: B Bản dịch đáp án đúng: B. Amazon GuardDuty — phân tích nhật ký CloudTrail/VPC, phát hiện các điểm bất thường/phần mềm độc hại

🇬🇧 Explanation: GuardDuty = ML-based threat detection. Analyzes:

  • CloudTrail logs (unusual API calls)
  • VPC Flow Logs (unusual network)
  • DNS logs (suspicious domains)

Detects: compromised instances, cryptomining, malware, unusual access.

🇻🇳 Giải thích: GuardDuty = ML-based threat detection. Bạn nghi ngờ compromised → GuardDuty detect.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Amazon Inspector) — Finds vulnerabilities/CVEs, not active threat behavior like cryptomining / Tìm lỗ hổng/CVE, không phát hiện hành vi tấn công đang diễn ra như cryptomining.
  • C (AWS Config) — Tracks config compliance, not threat detection / Theo dõi tuân thủ cấu hình, không phát hiện mối đe dọa.
  • D (Amazon Macie) — Discovers PII in S3, not compromised-instance detection / Phát hiện PII trong S3, không phát hiện instance bị xâm nhập.

🔑 Key Concept / Khái niệm cốt lõi: Threat Detection Services / Các dịch vụ phát hiện mối đe dọa.

Domain: 2 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-2-security-and-compliance.md § GuardDuty


Q27. Encryption at-Rest vs In-Transit

Match:

  1. S3 objects encrypted with KMS when stored
  2. HTTPS connection sending data to S3

Bản dịch tiếng Việt: So khớp: 1. Đối tượng S3 được mã hóa bằng KMS khi được lưu trữ 2. Kết nối HTTPS gửi dữ liệu tới S3

A. Both at-rest B. Both in-transit C. 1 = at-rest, 2 = in-transit D. Opposite

Correct answer: C Bản dịch đáp án đúng: C. 1 = ở trạng thái nghỉ, 2 = đang di chuyển

🇬🇧 Explanation:

  • At-rest: Data stored (S3 with KMS = encrypted when written)
  • In-transit: Data traveling (HTTPS = encrypted while moving)

Both needed for security.

🇻🇳 Giải thích: At-rest = lưu trữ. In-transit = trên đường. Cả hai đều quan trọng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (1 = in-transit, 2 = at-rest) — Reversed; stored data is at-rest, traveling data is in-transit / Đảo ngược; dữ liệu lưu trữ là at-rest, dữ liệu di chuyển là in-transit.
  • B (both at-rest) — Item 2 (traveling) is in-transit, not at-rest / Mục 2 (đang di chuyển) là in-transit, không phải at-rest.
  • D (both in-transit) — Item 1 (stored) is at-rest, not in-transit / Mục 1 (đang lưu trữ) là at-rest, không phải in-transit.

🔑 Key Concept / Khái niệm cốt lõi: Encryption concepts / Khái niệm mã hóa.

Domain: 2 | Difficulty: Easy | Type: Multiple Choice
Reference: Knowledge/domain-2-security-and-compliance.md § Encryption


Q28. KMS Customer-Managed Key

Company needs to encrypt S3 objects and have FULL control over encryption key (rotate, enable/disable, view audit logs). Should use:

Bản dịch tiếng Việt: Công ty cần mã hóa các đối tượng S3 và có toàn quyền kiểm soát khóa mã hóa (xoay, bật/tắt, xem nhật ký kiểm tra). Nên sử dụng:

A. AWS-managed KMS key (free, AWS controls) B. Customer-managed KMS key (paid, you control) C. S3 default encryption D. Client-side encryption only

Correct answer: B Bản dịch đáp án đúng: B. Khóa KMS do khách hàng quản lý (trả phí, bạn kiểm soát)

🇬🇧 Explanation:

  • AWS-managed key: Free, AWS controls, you can't rotate manually
  • Customer-managed key: Paid (~$1/month), you have full control (rotate, audit)

For HIPAA compliance or high-security, customer-managed is often required.

🇻🇳 Giải thích: Customer-managed key = bạn control toàn bộ. Đó là yêu cầu cho compliance như HIPAA.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (AWS-managed key) — AWS controls it; you can't manually rotate/disable it / AWS kiểm soát; bạn không thể tự rotate/disable.
  • C (AWS-owned key) — Fully managed by AWS, no customer control or visibility / AWS quản lý hoàn toàn, khách hàng không kiểm soát hay thấy được.
  • D (No encryption key) — Leaves data unencrypted, failing the requirement / Để dữ liệu không mã hóa, không đạt yêu cầu.

🔑 Key Concept / Khái niệm cốt lõi: KMS — Key management / KMS — quản lý khóa mã hóa.

Domain: 2 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-2-security-and-compliance.md § KMS


Q29. AWS Artifact — Compliance Reports

A SaaS company wants to prove SOC 2 compliance to enterprise customers. Where do they get official reports?

Bản dịch tiếng Việt: Một công ty SaaS muốn chứng minh sự tuân thủ SOC 2 với khách hàng doanh nghiệp. Họ lấy báo cáo chính thức ở đâu?

A. AWS Trusted Advisor B. AWS Artifact — self-service compliance reports (SOC, PCI, HIPAA, ISO) C. AWS CloudTrail D. AWS Config

Correct answer: B Bản dịch đáp án đúng: B. AWS Artifact — báo cáo tuân thủ tự phục vụ (SOC, PCI, HIPAA, ISO)

🇬🇧 Explanation: AWS Artifact = self-service portal with compliance reports:

  • SOC 1/2/3 (audit)
  • PCI DSS (payment)
  • ISO 27001 (security)
  • HIPAA BAA (healthcare)
  • FedRAMP (government)

Artifact = official AWS certifications. Perfect for proving compliance to customers.

🇻🇳 Giải thích: AWS Artifact = official compliance reports. SaaS company dùng để chứng minh SOC 2 cho khách.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (AWS Config) — Tracks your config compliance, not AWS's audit reports / Theo dõi tuân thủ cấu hình của bạn, không phải báo cáo audit của AWS.
  • C (Trusted Advisor) — Best-practice checks, not downloadable compliance documents / Kiểm tra best-practice, không phải tài liệu compliance tải về.
  • D (AWS Audit Manager) — Helps you collect evidence for your audits, but the AWS attestation reports come from Artifact / Giúp thu thập bằng chứng cho audit của bạn, nhưng báo cáo chứng nhận của AWS lấy từ Artifact.

🔑 Key Concept / Khái niệm cốt lõi: Compliance documentation / Tài liệu tuân thủ compliance.

Domain: 2 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-2-security-and-compliance.md § AWS Artifact


Q30. Organizations + SCP (Service Control Policy)

An enterprise with 20 AWS accounts wants to block all EC2 launches in development accounts to control costs. Use:

Bản dịch tiếng Việt: Một doanh nghiệp có 20 tài khoản AWS muốn chặn tất cả các lần khởi chạy EC2 trong tài khoản phát triển để kiểm soát chi phí. Sử dụng:

A. IAM policy in each account B. Service Control Policy (SCP) on Organization Development OU C. Security Group rules D. AWS Budgets

Correct answer: B Bản dịch đáp án đúng: B. Chính sách kiểm soát dịch vụ (SCP) trên OU phát triển tổ chức

🇬🇧 Explanation: SCP = service control policy. Blocks services at account level (guardrail).

Apply to Organization OU → all member accounts in that OU inherit restriction.

IAM policy = user-level. SCP = account-level (higher authority).

🇻🇳 Giải thích: SCP = khóa service cho cả account. EC2 disabled → dev team không launch được.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (IAM policy per user) — Operates at user level; users could be missed and it's harder to enforce org-wide / Hoạt động ở mức user; dễ bỏ sót user và khó áp dụng toàn tổ chức.
  • C (Security Group) — Controls network traffic, not which services can be launched / Kiểm soát lưu lượng mạng, không kiểm soát được phép launch service nào.
  • D (Ask developers not to) — A policy, not a technical guardrail; not enforceable / Chỉ là yêu cầu, không phải guardrail kỹ thuật; không cưỡng chế được.

🔑 Key Concept / Khái niệm cốt lõi: AWS Organizations — SCP / AWS Organizations — Service Control Policy.

Domain: 2 | Difficulty: Hard | Type: Multiple Choice
Reference: Knowledge/domain-2-security-and-compliance.md § Organizations & SCP


Q31. AWS Secrets Manager vs Parameter Store

What are the key differences? (Select TWO)

Bản dịch tiếng Việt: Sự khác biệt chính là gì? (Chọn HAI)

A. Secrets Manager auto-rotates passwords; Parameter Store is manual B. Secrets Manager paid, Parameter Store free C. Both support encryption D. Parameter Store only stores non-sensitive data E. Secrets Manager for APIs, Parameter Store for configs

Correct answer: A, B Bản dịch đáp án đúng: A. Trình quản lý bí mật tự động luân chuyển mật khẩu; Lưu trữ tham số là thủ công; B. Trình quản lý bí mật phải trả phí, Cửa hàng thông số miễn phí

🇬🇧 Explanation:

A. Secrets Manager auto-rotates; Parameter Store is manual — built-in rotation is a key Secrets Manager differentiator ✅ B. Secrets Manager is paid; Parameter Store (Standard) is free — pricing is a real difference

🇻🇳 Giải thích: Secrets Manager = auto-rotate, có phí. Parameter Store (Standard) = rotate thủ công, miễn phí.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • C (Both support encryption) — True, but it's a shared feature, not a difference / Đúng, nhưng là điểm chung, không phải điểm khác biệt.
  • D (Parameter Store only stores non-sensitive data) — False; Parameter Store can store SecureString secrets too / Sai; Parameter Store cũng lưu được SecureString (dữ liệu nhạy cảm).
  • E (Only Secrets Manager works for API keys) — False; both can store API keys / Sai; cả hai đều lưu được API key.

🔑 Key Concept / Khái niệm cốt lõi: Secrets vs Configuration / Phân biệt lưu secret và lưu cấu hình.

Domain: 2 | Difficulty: Medium | Type: Multi-Select (2/5)
Reference: Knowledge/domain-2-security-and-compliance.md § Secrets Manager vs Parameter Store


Q32. Inspector — Vulnerability Assessment

An organization needs to scan EC2 instances for security vulnerabilities (missing OS patches, insecure configurations). Tool?

Bản dịch tiếng Việt: Tổ chức cần quét các phiên bản EC2 để tìm lỗ hổng bảo mật (thiếu bản vá hệ điều hành, cấu hình không an toàn). Dụng cụ?

A. GuardDuty B. Amazon Inspector — automated vulnerability assessment C. AWS Config D. CloudTrail

Correct answer: B Bản dịch đáp án đúng: B. Amazon Inspector — đánh giá lỗ hổng bảo mật tự động

🇬🇧 Explanation: Inspector = automated vulnerability assessment for:

  • EC2 instances (OS vulnerabilities)
  • ECR container images (CVEs in dependencies)
  • Lambda functions (code/dependency vulnerabilities)

Generates findings: "Missing OS patch CVE-2024-1234", "Security group too permissive".

🇻🇳 Giải thích: Inspector = auto scan EC2 cho vulnerabilities. Bạn cần biết cái gì missing patch → dùng Inspector.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Amazon GuardDuty) — Detects active threats from logs, not vulnerability/patch scanning / Phát hiện mối đe dọa đang xảy ra từ log, không quét lỗ hổng/patch.
  • C (AWS Config) — Tracks config compliance, not OS-level CVEs / Theo dõi tuân thủ cấu hình, không quét CVE ở mức OS.
  • D (Amazon Macie) — Scans S3 for PII, not EC2 vulnerabilities / Quét PII trong S3, không quét lỗ hổng EC2.

🔑 Key Concept / Khái niệm cốt lõi: Vulnerability Assessment / Đánh giá lỗ hổng bảo mật.

Domain: 2 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-2-security-and-compliance.md § Amazon Inspector


Q33. Macie — PII Detection

A company stores customer data (credit cards, SSNs) in S3 but unsure which buckets contain sensitive info. Detect with:

Bản dịch tiếng Việt: Một công ty lưu trữ dữ liệu khách hàng (thẻ tín dụng, SSN) trong S3 nhưng không chắc nhóm nào chứa thông tin nhạy cảm. Phát hiện với:

A. GuardDuty B. AWS Config C. Amazon Macie — ML-based PII discovery in S3 D. AWS Secrets Manager

Correct answer: C Bản dịch đáp án đúng: C. Amazon Macie — Phát hiện PII dựa trên ML trong S3

🇬🇧 Explanation: Macie = ML-based PII discovery in S3.

Scans buckets, finds:

  • Credit card numbers
  • SSNs
  • Email addresses
  • Passport numbers

Generates findings: "Found 500 unencrypted credit card numbers in bucket X".

🇻🇳 Giải thích: Macie = find PII in S3. Bạn muốn biết "chúng tôi có credit card numbers nào trong S3 không?" → dùng Macie.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Amazon Inspector) — Scans for vulnerabilities/CVEs, not PII in data / Quét lỗ hổng/CVE, không tìm PII trong dữ liệu.
  • B (Amazon GuardDuty) — Detects threats from logs, not sensitive-data discovery / Phát hiện mối đe dọa từ log, không phát hiện dữ liệu nhạy cảm.
  • D (AWS Config) — Tracks resource configuration, not data contents / Theo dõi cấu hình tài nguyên, không soi nội dung dữ liệu.

🔑 Key Concept / Khái niệm cốt lõi: Data Discovery — PII detection / Phát hiện dữ liệu — tìm PII.

Domain: 2 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-2-security-and-compliance.md § Amazon Macie


Q34. CloudTrail Retention

How long does CloudTrail keep API logs in console by default?

Bản dịch tiếng Việt: Theo mặc định, CloudTrail lưu giữ nhật ký API trong bảng điều khiển trong bao lâu?

A. 7 days B. 30 days C. 90 days (then delete unless archiving to S3) D. 1 year

Correct answer: C Bản dịch đáp án đúng: C. 90 ngày (sau đó xóa trừ khi lưu trữ vào S3)

🇬🇧 Explanation: CloudTrail console shows 90 days of logs by default.

For longer retention, enable S3 bucket archival.

🇻🇳 Giải thích: CloudTrail console (Event history) = 90 ngày mặc định. Lâu hơn → lưu vào S3.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (7 days) — Too short; the console keeps 90 days of event history / Quá ngắn; console giữ 90 ngày event history.
  • B (30 days) — Not the default; the default is 90 days / Không phải mặc định; mặc định là 90 ngày.
  • D (Forever / unlimited) — Only if you archive to S3; the console itself keeps 90 days / Chỉ khi lưu sang S3; bản thân console giữ 90 ngày.

🔑 Key Concept / Khái niệm cốt lõi: CloudTrail configuration / Cấu hình CloudTrail.

Domain: 2 | Difficulty: Easy | Type: Multiple Choice
Reference: Knowledge/domain-2-security-and-compliance.md § CloudTrail


Q35. Trusted Advisor — Security Checks

Which security issues does Trusted Advisor detect? (Select TWO)

Bản dịch tiếng Việt: Trusted Advisor phát hiện những vấn đề bảo mật nào? (Chọn HAI)

A. MFA not enabled on root account B. Security groups allowing SSH (port 22) to 0.0.0.0/0 (world) C. Application-level SQL injection vulnerabilities D. Insufficient RDS backups E. IAM user passwords expired

Correct answer: A, B Bản dịch đáp án đúng: A. MFA không được kích hoạt trên tài khoản root; B. Nhóm bảo mật cho phép SSH (cổng 22) đến 0.0.0.0/0 (thế giới)

🇬🇧 Explanation:

A. MFA not enabled on root account — a core Trusted Advisor security check ✅ B. Security groups allowing SSH (port 22) to 0.0.0.0/0 (world) — flagged as an open-port security risk

🇻🇳 Giải thích: Trusted Advisor = các core check bảo mật, gồm MFA chưa bật trên root và Security Group mở SSH ra 0.0.0.0/0.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • C (SQL injection vulnerabilities) — Code-level issue; needs SAST/Inspector, not Trusted Advisor / Vấn đề ở tầng code; cần SAST/Inspector, không phải Trusted Advisor.
  • D (Insufficient RDS backups) — Config-level, not part of the core security checks / Ở tầng cấu hình, không thuộc core security check.
  • E (IAM passwords expired) — Not one of the core Trusted Advisor checks / Không nằm trong core check của Trusted Advisor.

🔑 Key Concept / Khái niệm cốt lõi: Trusted Advisor checks / Các kiểm tra của Trusted Advisor.

Domain: 2 | Difficulty: Medium | Type: Multi-Select (2/5)
Reference: Knowledge/domain-2-security-and-compliance.md § Trusted Advisor


Q36. S3 Public Access Block

A company wants to prevent accidental bucket publicness (compliance). Configuration:

Bản dịch tiếng Việt: Một công ty muốn ngăn chặn việc vô tình công khai nhóm (tuân thủ). Cấu hình:

A. S3 Bucket Policy (manual) B. S3 Block Public Access — automated blocks C. CloudTrail (audit only) D. No prevention possible

Correct answer: B Bản dịch đáp án đúng: B. S3 Chặn quyền truy cập công cộng - khối tự động

🇬🇧 Explanation: S3 Block Public Access = automated guardrail. Prevents:

  • Public ACLs
  • Public bucket policies
  • Other public access

Even if someone tries to make bucket public → blocked.

🇻🇳 Giải thích: Block Public Access = tự động chặn mọi nỗ lực làm bucket public. Lớp safety guard mạnh nhất.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Bucket policy alone) — A policy can still be misconfigured to allow public access / Bucket policy vẫn có thể bị cấu hình sai cho phép public.
  • C (IAM policy) — Controls who can call APIs, not the bucket's public-access guardrail / Kiểm soát ai gọi API, không phải guardrail chặn public của bucket.
  • D (Encryption) — Protects data contents, doesn't prevent public exposure / Bảo vệ nội dung dữ liệu, không ngăn bucket bị phơi bày public.

🔑 Key Concept / Khái niệm cốt lõi: S3 Security / Bảo mật S3.

Domain: 2 | Difficulty: Easy-Medium | Type: Multiple Choice
Reference: Knowledge/domain-2-security-and-compliance.md § S3 (via Domain 3 storage)


Domain 3: Cloud Technology and Services (Q37–Q58)

Q37. Startup Scale Problem — Auto Scaling

A startup's API gets 10 requests/sec at night, 10,000 req/sec during day. Manual EC2 scaling too slow. Solution?

Bản dịch tiếng Việt: API của một công ty khởi nghiệp nhận được 10 yêu cầu/giây vào ban đêm, 10.000 yêu cầu/giây vào ban ngày. Chia tỷ lệ EC2 thủ công quá chậm. Giải pháp?

A. Buy 20 on-demand EC2 instances upfront B. Auto Scaling Group — automatically launch/terminate instances based on load C. Lambda (but API is long-running) D. Reserve 20 instances (wasted at night)

Correct answer: B Bản dịch đáp án đúng: B. Nhóm Auto Scaling - tự động khởi chạy/chấm dứt các phiên bản dựa trên tải

🇬🇧 Explanation: Auto Scaling Group (ASG) = automatically launch/terminate instances based on demand.

Scales up during peak → down during off-hours. Cost-optimized, high-availability.

🇻🇳 Giải thích: ASG = tự động scale up lúc peak, scale down lúc off-hours. Perfect cho spiky workloads.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Larger single EC2 instance) — Vertical scaling is fixed; it can't shrink at night to save cost / Scale dọc là cố định; không co lại ban đêm để tiết kiệm.
  • C (Manual instance launches) — Too slow and error-prone for 1000x daily swings / Quá chậm và dễ sai cho biến động 1000 lần mỗi ngày.
  • D (Reserved Instances) — A pricing model, not an automatic scaling mechanism / Là mô hình giá, không phải cơ chế tự scale.

🔑 Key Concept / Khái niệm cốt lõi: Auto Scaling / Tự động co giãn (Auto Scaling).

Domain: 3 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-3-cloud-technology-and-services.md § Auto Scaling


Q38. E-Commerce Video Storage — S3 Storage Class

An online retailer stores product videos (~5 TB, $1000/month in S3 Standard). Users access frequently. Videos are backed up elsewhere. Cost optimization?

Bản dịch tiếng Việt: Một nhà bán lẻ trực tuyến lưu trữ video sản phẩm (~5 TB, $1000/tháng ở S3 Standard). Người dùng truy cập thường xuyên. Video được sao lưu ở nơi khác. Tối ưu hóa chi phí?

A. Move to Glacier (retrieval latency acceptable) B. Enable Intelligent-Tiering — auto-move between tiers based on access C. S3 One Zone-IA (cheaper, 1 AZ only) D. Manual lifecycle policy to Glacier Deep Archive

Correct answer: B Bản dịch đáp án đúng: B. Bật phân bậc thông minh - tự động di chuyển giữa các bậc dựa trên quyền truy cập

🇬🇧 Explanation: Intelligent-Tiering = auto-moves objects between tiers based on access pattern:

  • Frequent access last 30 days → S3 Standard (~$0.023/GB)
  • No access 30-90 days → S3 Standard-IA (~$0.013/GB)
  • No access 90+ days → Glacier (~$0.004/GB)

No manual intervention. Cost auto-optimizes.

🇻🇳 Giải thích: Intelligent-Tiering = tự động move giữa tiers. Bạn không làm gì, AWS tối ưu cost.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (S3 Standard) — Always full price even when access drops; no auto-optimization / Luôn giá đầy đủ kể cả khi ít truy cập; không tự tối ưu.
  • C (S3 Glacier) — Too cold for frequently accessed videos (retrieval delays) / Quá "lạnh" cho video truy cập thường xuyên (trễ khi lấy).
  • D (S3 One Zone-IA) — Lower durability and not auto-tiering for changing access patterns / Độ bền thấp hơn và không tự chuyển tier theo pattern truy cập.

🔑 Key Concept / Khái niệm cốt lõi: S3 Storage Classes / Các lớp lưu trữ S3.

Domain: 3 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-3-cloud-technology-and-services.md § S3 Storage Classes


Q39. Archive Compliance — Glacier Deep Archive

A law firm must retain case documents for 7 years per regulation. Files rarely accessed, 48-hour retrieval is acceptable. Cost-effective storage?

Bản dịch tiếng Việt: Một công ty luật phải lưu giữ hồ sơ vụ việc trong thời gian 7 năm theo quy định. Các tập tin hiếm khi được truy cập, thời gian truy xuất trong 48 giờ là chấp nhận được. Tiết kiệm chi phí lưu trữ?

A. S3 Standard ($0.023/GB/mo) B. S3 Glacier Flexible ($0.0036/GB/mo) C. S3 Glacier Deep Archive ($0.00099/GB/mo) — lowest cost, 48hr retrieval OK D. EBS snapshots

Correct answer: C Bản dịch đáp án đúng: C. S3 Glacier Deep Archive ($0,00099/GB/tháng) — chi phí thấp nhất, truy xuất trong 48 giờ OK

🇬🇧 Explanation: Glacier Deep Archive = cheapest S3 tier ($0.00099/GB/month).

  • 48-hour retrieval (matches requirement)
  • Compliance archival (long-term retention)

Perfect for "cold" compliance storage.

🇻🇳 Giải thích: Deep Archive = cheapest tier, 48h retrieval. Đó là chính xác cho compliance archives.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (S3 Standard) — Far more expensive; wasteful for rarely accessed archives / Đắt hơn nhiều; lãng phí cho dữ liệu hiếm khi truy cập.
  • B (S3 Glacier Flexible Retrieval) — Cheap but pricier than Deep Archive when 48h retrieval is acceptable / Rẻ nhưng vẫn đắt hơn Deep Archive khi chấp nhận lấy trong 48h.
  • D (S3 Standard-IA) — For infrequent but quick access, not the cheapest long-term archive / Cho truy cập không thường xuyên nhưng nhanh, không phải archive dài hạn rẻ nhất.

🔑 Key Concept / Khái niệm cốt lõi: S3 Storage Classes — Deep Archive / Các lớp lưu trữ S3 — Deep Archive.

Domain: 3 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-3-cloud-technology-and-services.md § S3 Storage Classes


Q40. Database Choice — Financial Trading

A fintech company processes stock trades (high write frequency, ACID transactions, strict consistency). Database?

Bản dịch tiếng Việt: Một công ty fintech xử lý các giao dịch chứng khoán (tần suất ghi cao, giao dịch ACID, tính nhất quán nghiêm ngặt). Cơ sở dữ liệu?

A. DynamoDB (NoSQL, flexible schema) B. RDS PostgreSQL or Aurora (relational, transactions, strict consistency) C. Redshift (analytics, not transactional) D. ElastiCache (cache, not primary storage)

Correct answer: B Bản dịch đáp án đúng: B. RDS PostgreSQL hoặc Aurora (quan hệ, giao dịch, tính nhất quán nghiêm ngặt)

🇬🇧 Explanation: Relational DB = ACID compliance, strict consistency. Trading = strict rules → relational database.

🇻🇳 Giải thích: Stock trading = ACID, strict consistency. Relational DB là must-have (RDS hoặc Aurora).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (DynamoDB) — NoSQL with eventual consistency, not acceptable for ACID trades / NoSQL, eventual consistency, không phù hợp cho giao dịch cần ACID.
  • C (Redshift) — Analytics data warehouse, not transactional / Data warehouse cho analytics, không phải transactional.
  • D (ElastiCache) — In-memory cache, not persistent ACID storage / Cache in-memory, không phải lưu trữ ACID bền vững.

🔑 Key Concept / Khái niệm cốt lõi: Database selection / Lựa chọn database.

Domain: 3 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-3-cloud-technology-and-services.md § Database Services


Q41. Serverless Database — Unpredictable Traffic

A mobile game experiences spiky traffic (10 users → 100K users during viral moments). Database needs to scale automatically. Choose:

Bản dịch tiếng Việt: Trò chơi trên thiết bị di động có lưu lượng truy cập tăng đột biến (10 người dùng → 100 nghìn người dùng trong thời điểm lan truyền). Cơ sở dữ liệu cần phải tự động mở rộng quy mô. Chọn:

A. RDS (requires pre-provisioned capacity) B. DynamoDB on-demand — serverless, scales automatically, pay per request C. Redshift (data warehouse, not real-time) D. ElastiCache (in-memory, not persistent)

Correct answer: B Bản dịch đáp án đúng: B. DynamoDB theo yêu cầu — không có máy chủ, tự động thay đổi quy mô, thanh toán theo yêu cầu

🇬🇧 Explanation: DynamoDB on-demand = serverless, pay per request.

Auto-scales 0 to unlimited based on traffic. No capacity planning.

🇻🇳 Giải thích: DynamoDB on-demand = serverless, auto-scale. Perfect cho mobile game với unpredictable traffic.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (RDS) — Requires pre-provisioned capacity; doesn't auto-scale to spikes like on-demand / Cần cấp capacity trước; không tự scale theo đột biến như on-demand.
  • C (Redshift) — Data warehouse for analytics, not a real-time app database / Data warehouse cho analytics, không phải DB real-time cho app.
  • D (ElastiCache) — Cache layer, not the primary data store / Lớp cache, không phải kho dữ liệu chính.

🔑 Key Concept / Khái niệm cốt lõi: DynamoDB — serverless option / DynamoDB — chế độ serverless (on-demand).

Domain: 3 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-3-cloud-technology-and-services.md § DynamoDB


Q42. Shared File Storage — EFS

A media production team (30 editors) needs shared file access for video editing project files. Must work cross-AZ. Storage?

Bản dịch tiếng Việt: Nhóm sản xuất phương tiện truyền thông (30 biên tập viên) cần quyền truy cập tệp được chia sẻ cho các tệp dự án chỉnh sửa video. Phải làm việc chéo AZ. Kho?

A. S3 (REST API, not file mount) B. EBS (single EC2 instance only) C. EFS (NFS, multi-EC2, cross-AZ, auto-scales) D. Storage Gateway (on-premises hybrid)

Correct answer: C Bản dịch đáp án đúng: C. EFS (NFS, multi-EC2, cross-AZ, tự động chia tỷ lệ)

🇬🇧 Explanation: EFS = Elastic File System (NFS), shared across multiple EC2, cross-AZ, auto-scales. Media editing = file system (NFS mount) → EFS.

🇻🇳 Giải thích: EFS = NFS shared file system. 30 editors mount same folder → edit together.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (S3) — Object storage via REST API, not a mountable shared file system / Lưu trữ object qua REST API, không mount được như file system chia sẻ.
  • B (EBS) — Block storage attached to a single EC2, not shared across many / Block storage gắn vào một EC2, không chia sẻ cho nhiều máy.
  • D (Storage Gateway) — Hybrid on-premises/cloud bridge, not the in-cloud shared FS / Cầu nối lai on-prem/cloud, không phải file system chia sẻ trong cloud.

🔑 Key Concept / Khái niệm cốt lõi: Storage — EFS for shared files / Lưu trữ — EFS cho file chia sẻ.

Domain: 3 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-3-cloud-technology-and-services.md § EFS


Q43. Batch Data Migration — Snow Family

A data center needs to migrate 500 TB of archives to AWS S3. Internet bandwidth is 10 Mbps (would take 1 year). Solution?

Bản dịch tiếng Việt: Một trung tâm dữ liệu cần di chuyển 500 TB kho lưu trữ sang AWS S3. Băng thông Internet là 10 Mbps (sẽ mất 1 năm). Giải pháp?

A. Over-the-internet (S3 direct upload) B. AWS Direct Connect (takes weeks to set up) C. AWS Snowball — AWS ships device, fill 50-80TB, ship back, import to S3 D. AWS Storage Gateway (slower)

Correct answer: C Bản dịch đáp án đúng: C. AWS Snowball — AWS vận chuyển thiết bị, lấp đầy 50-80TB, vận chuyển lại, nhập vào S3

🇬🇧 Explanation: Snowball = AWS ships device (50-80TB), you fill it, ship back, import to S3.

Much faster than internet. Perfect for petabyte-scale migrations.

🇻🇳 Giải thích: Snowball = AWS gửi device, bạn fill data, ship back. Nhanh hơn internet rất nhiều.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Upload over the internet) — 500 TB at 10 Mbps would take ~1 year; impractical / 500 TB ở 10 Mbps mất ~1 năm; không khả thi.
  • B (Direct Connect) — A dedicated network link helps ongoing transfer but is overkill/slow for a one-time 500 TB move / Đường mạng riêng giúp truyền liên tục nhưng quá mức/chậm cho lần chuyển 500 TB một lần.
  • D (Database Migration Service) — For migrating databases, not bulk archive file transfer / Dùng để migrate database, không phải chuyển khối file archive lớn.

🔑 Key Concept / Khái niệm cốt lõi: Snow Family — data transfer / Snow Family — chuyển dữ liệu vật lý.

Domain: 3 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-3-cloud-technology-and-services.md § AWS Snow Family


Q44. Disaster Recovery — RDS Multi-Region

A hospital system wants DR (Recovery Time Objective 1 hour if primary region fails). Database approach?

Bản dịch tiếng Việt: Hệ thống bệnh viện muốn DR (Mục tiêu thời gian phục hồi là 1 giờ nếu khu vực chính bị lỗi). Cách tiếp cận cơ sở dữ liệu?

A. Single RDS in us-east-1 (no DR) B. Multi-AZ RDS (automatic failover, same region) C. Cross-Region Read Replica (manual failover to different region) D. DynamoDB Global Tables (only for NoSQL)

Correct answer: C Bản dịch đáp án đúng: C. Bản sao đọc liên khu vực (chuyển đổi dự phòng thủ công sang khu vực khác)

🇬🇧 Explanation: Cross-Region Read Replica (C) lets you promote a replica in a different region. If the primary region goes down → manual failover to the replica in another region (~5 minutes), comfortably meeting the 1-hour RTO.

🇻🇳 Giải thích: DR = different region. Multi-AZ = same region. Hospital needs region-level DR → Cross-Region Replica.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Single-AZ RDS) — No failover at all; a region outage loses the database / Không có failover; mất region là mất database.
  • B (Multi-AZ) — Auto-failover but within the same region, so it doesn't survive a region failure / Auto-failover nhưng cùng region, không chịu được sự cố cả region.
  • D (Daily snapshots only) — Restore is slow and may exceed the 1-hour RTO with data loss / Khôi phục chậm, có thể vượt RTO 1h và mất dữ liệu.

🔑 Key Concept / Khái niệm cốt lõi: Disaster Recovery (DR) / Khôi phục sau thảm họa (DR).

Domain: 3 | Difficulty: Hard | Type: Multiple Choice
Reference: Knowledge/domain-3-cloud-technology-and-services.md § RDS


Q45. Caching Performance — ElastiCache

A web app queries RDS database repeatedly for user profiles (slow, database becomes bottleneck). Speed up reads?

Bản dịch tiếng Việt: Ứng dụng web truy vấn cơ sở dữ liệu RDS nhiều lần để tìm hồ sơ người dùng (chậm, cơ sở dữ liệu trở nên tắc nghẽn). Tăng tốc độ đọc?

A. Larger RDS instance (vertical scale) B. ElastiCache Redis — cache frequently-accessed data in memory (1-10ms latency) C. CloudFront (for static content, not dynamic DB data) D. More RDS read replicas (still queries database)

Correct answer: B Bản dịch đáp án đúng: B. ElastiCache Redis — lưu vào bộ nhớ đệm dữ liệu được truy cập thường xuyên trong bộ nhớ (độ trễ 1-10ms)

🇬🇧 Explanation: ElastiCache = in-memory cache (Redis/Memcached).

Cache frequently-accessed data → 1-10ms latency (vs RDS 100ms+).

🇻🇳 Giải thích: ElastiCache = in-memory cache. Bạn lấy user profile lần đầu từ RDS → cache → lần sau 1ms.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Upgrade RDS instance) — Vertical scaling hits the same query bottleneck, not as fast as caching / Scale dọc vẫn gặp bottleneck truy vấn, không nhanh bằng cache.
  • C (CloudFront) — CDN for static content, not dynamic DB query results / CDN cho nội dung tĩnh, không cache kết quả truy vấn DB động.
  • D (Read replicas) — Still issues database queries; slower than in-memory cache / Vẫn truy vấn database; chậm hơn cache in-memory.

🔑 Key Concept / Khái niệm cốt lõi: Caching — ElastiCache / Caching — ElastiCache.

Domain: 3 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-3-cloud-technology-and-services.md § ElastiCache


Q46. Global Content Delivery — CloudFront

A news website serves articles to readers worldwide. Images stored in S3 (us-east-1). Users in Australia get 200ms latency. Optimize?

Bản dịch tiếng Việt: Một trang web tin tức phục vụ các bài viết cho độc giả trên toàn thế giới. Hình ảnh được lưu trữ trong S3 (us-east-1). Người dùng ở Úc có độ trễ 200ms. Tối ưu hóa?

A. Move S3 to ap-southeast-2 (replication cost) B. CloudFront CDN — cache at 700+ edge locations near users (~20ms for AU) C. Use EC2 in multiple regions (cost) D. Compress images (minor improvement)

Correct answer: B Bản dịch đáp án đúng: B. CloudFront CDN — bộ nhớ đệm tại hơn 700 vị trí biên gần người dùng (~20 mili giây đối với AU)

🇬🇧 Explanation: CloudFront = 700+ edge locations globally. Caches content near users.

Users in Australia → content cached at Sydney edge (10-50ms instead of 200ms).

🇻🇳 Giải thích: CloudFront = CDN. Cache image ở Sydney edge → AU users 20ms latency (not 200ms).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Move the S3 bucket to ap-southeast-2) — Helps AU but hurts other regions; CDN serves everyone / Giúp AU nhưng hại các region khác; CDN phục vụ tất cả.
  • C (Larger EC2 instance) — Compute size doesn't fix geographic latency to static images / Kích cỡ compute không khắc phục latency địa lý cho ảnh tĩnh.
  • D (S3 Transfer Acceleration) — Speeds uploads to S3, not delivery latency to end users / Tăng tốc upload lên S3, không giảm latency phân phối tới người dùng.

🔑 Key Concept / Khái niệm cốt lõi: CloudFront — global content delivery / CloudFront — phân phối nội dung toàn cầu.

Domain: 3 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-3-cloud-technology-and-services.md § CloudFront


Q47. Container Orchestration — ECS vs Fargate

A startup wants to deploy Docker containers without managing EC2 cluster. Choose:

Bản dịch tiếng Việt: Một công ty khởi nghiệp muốn triển khai các vùng chứa Docker mà không cần quản lý cụm EC2. Chọn:

A. EC2 + ECS (still manage EC2) B. Fargate + ECS — serverless containers, AWS manages infrastructure C. Lambda (max 15 min execution, not long-running containers) D. Elastic Beanstalk (supports containers but more overhead)

Correct answer: B Bản dịch đáp án đúng: B. Fargate + ECS — bộ chứa không có máy chủ, AWS quản lý cơ sở hạ tầng

🇬🇧 Explanation: Fargate = serverless containers. Launch Docker containers, AWS manages infrastructure.

No EC2 management needed (unlike ECS with EC2).

🇻🇳 Giải thích: Fargate = serverless containers. Bạn deploy Docker, AWS quản lý infrastructure.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (ECS on EC2) — You still provision and manage the EC2 hosts / Bạn vẫn phải cấp và quản lý các host EC2.
  • C (EC2 with Docker installed) — Maximum management overhead; the opposite of what's wanted / Tốn công quản lý nhất; ngược lại điều mong muốn.
  • D (Lambda) — For short event-driven functions, not running long-lived Docker containers / Cho hàm ngắn theo sự kiện, không chạy container Docker dài hạn.

🔑 Key Concept / Khái niệm cốt lõi: Containers — Fargate / Container — Fargate (serverless).

Domain: 3 | Difficulty: Medium | Type: Multiple Choice
Reference: Knowledge/domain-3-cloud-technology-and-services.md § Containers


Q48. API Gateway + Lambda — Serverless API

A mobile app needs REST API backend. Expect 0 to 1M requests/day (unpredictable). Approach?

Bản dịch tiếng Việt: Ứng dụng di động cần có chương trình phụ trợ API REST. Dự kiến ​​từ 0 đến 1 triệu yêu cầu/ngày (không thể đoán trước). Tiếp cận?

A. EC2 + load balancer (always running, wasteful) B. API Gateway + Lambda — serverless, pay per request, auto-scale C. ECS containers (overkill) D. Elastic Beanstalk (still instances running)

Correct answer: B Bản dịch đáp án đúng: B. API Gateway + Lambda — serverless, trả tiền theo yêu cầu, tự động mở rộng quy mô

🇬🇧 Explanation: Serverless API:

  • API Gateway = REST endpoint
  • Lambda = backend logic
  • Auto-scales 0 to unlimited
  • Pay per request

Perfect for unpredictable mobile traffic.

🇻🇳 Giải thích: API Gateway + Lambda = serverless API. Auto-scale từ 0 đến 1M requests. Pay-per-request.

Domain: 3 | Difficulty: Medium | Type: Multiple Choice
Key Concept: API Gateway + Lambda (serverless pattern)
Reference: Knowledge/domain-3-cloud-technology-and-services.md § API Gateway & Lambda


Q49. VPC Isolation — Security

A healthcare company wants isolated network for patient database (HIPAA). Resource isolation?

Bản dịch tiếng Việt: Một công ty chăm sóc sức khỏe muốn có mạng cách ly cho cơ sở dữ liệu bệnh nhân (HIPAA). Cô lập tài nguyên?

A. Public internet (No!) B. VPC with private subnet — no internet access, access only from internal C. VPC public subnet (accessible from internet) D. AWS default VPC (shared)

Correct answer: B Bản dịch đáp án đúng: B. VPC có mạng con riêng - không có quyền truy cập internet, chỉ truy cập từ nội bộ

🇬🇧 Explanation: VPC = isolated network. Private subnet = no internet access, only internal access.

HIPAA requirement = data isolated from internet.

🇻🇳 Giải thích: VPC private subnet = không access từ internet. Patient data isolated.

Domain: 3 | Difficulty: Medium | Type: Multiple Choice
Key Concept: VPC — security isolation
Reference: Knowledge/domain-3-cloud-technology-and-services.md § VPC


Q50. NAT Gateway — Private EC2 Internet Access

An EC2 in private subnet needs to pull updates from internet. How?

Bản dịch tiếng Việt: EC2 trong mạng con riêng tư cần lấy các bản cập nhật từ internet. Làm sao?

A. Internet Gateway (breaks privacy) B. NAT Gateway in public subnet — routes private instance outbound traffic C. Direct internet (not possible from private) D. VPN only

Correct answer: B Bản dịch đáp án đúng: B. Cổng NAT trong mạng con công cộng - định tuyến lưu lượng truy cập ra bên ngoài của phiên bản riêng tư

🇬🇧 Explanation: NAT Gateway = allows private instances to initiate outbound internet connections.

Located in public subnet, routes private traffic out. Inbound from internet NOT allowed.

🇻🇳 Giải thích: NAT Gateway = private instance → outbound internet. Không inbound.

Domain: 3 | Difficulty: Medium | Type: Multiple Choice
Key Concept: NAT Gateway — hybrid connectivity
Reference: Knowledge/domain-3-cloud-technology-and-services.md § NAT


Q51. Load Balancing — Traffic Distribution

A web app receives 10,000 requests/sec. 2 EC2 instances should share load. Choose:

Bản dịch tiếng Việt: Một ứng dụng web nhận được 10.000 yêu cầu/giây. 2 phiên bản EC2 sẽ chia sẻ tải. Chọn:

A. Security Group rules B. Application Load Balancer (ALB) — Layer 7, HTTP/HTTPS, distribute traffic C. NACL (wrong layer) D. Route 53 only (DNS, not traffic)

Correct answer: B Bản dịch đáp án đúng: B. Cân bằng tải ứng dụng (ALB) — Lớp 7, HTTP/HTTPS, phân phối lưu lượng

🇬🇧 Explanation: ALB = Layer 7 (HTTP/HTTPS), distributes requests across instances.

  • Security Group (A): Firewall, not load balancing
  • NACL (C): Firewall, wrong layer
  • Route 53 (D): DNS, not traffic distribution

🇻🇳 Giải thích: ALB = HTTP load balancer. Distribute 10K req/sec across 2 EC2.

Domain: 3 | Difficulty: Medium | Type: Multiple Choice
Key Concept: Load Balancing — ALB
Reference: Knowledge/domain-3-cloud-technology-and-services.md § ELB


Q52. Route 53 Failover Policy

A banking site has primary server in us-east-1, backup in eu-west-1. If primary fails, auto-switch to backup. Routing policy?

Bản dịch tiếng Việt: Một trang web ngân hàng có máy chủ chính ở us-east-1, dự phòng ở eu-west-1. Nếu lỗi chính, tự động chuyển sang sao lưu. Chính sách định tuyến?

A. Simple routing B. Failover routing — active-passive, auto-switch on health check fail C. Weighted routing (load split, not failover) D. Latency routing (chooses closest, doesn't failover)

Correct answer: B Bản dịch đáp án đúng: B. Định tuyến chuyển đổi dự phòng - chủ động-thụ động, tự động bật kiểm tra tình trạng không thành công

🇬🇧 Explanation: Failover routing = active-passive. Health check primary → if unhealthy, switch to secondary.

  • Weighted routing (C): Load split, not failover
  • Latency routing (D): Chooses closest, doesn't failover

🇻🇳 Giải thích: Failover policy = health check primary, auto-switch backup if fail.

Domain: 3 | Difficulty: Medium | Type: Multiple Choice
Key Concept: Route 53 routing policies
Reference: Knowledge/domain-3-cloud-technology-and-services.md § Route 53


Q53. CloudFormation — Infrastructure as Code

An ops team wants repeatable, versioned infrastructure (EC2, RDS, S3 in code). Approach?

Bản dịch tiếng Việt: Nhóm vận hành muốn cơ sở hạ tầng có phiên bản, có thể lặp lại (trong mã EC2, RDS, S3). Tiếp cận?

A. Manual AWS Console clicks (not repeatable) B. AWS CloudFormation (JSON/YAML templates, version control, stack management) C. AWS CLI one-liners (not version-controlled) D. Terraform only

Correct answer: B Bản dịch đáp án đúng: B. AWS CloudFormation (mẫu JSON/YAML, kiểm soát phiên bản, quản lý ngăn xếp)

🇬🇧 Explanation: CloudFormation = Infrastructure as Code (JSON/YAML templates).

Benefits:

  • Version control
  • Repeatable deployments
  • Stack management (update, delete)
  • Change sets (preview before apply)

🇻🇳 Giải thích: CloudFormation = IaC. Template → stack → repeatable, versionable.

Domain: 3 | Difficulty: Medium | Type: Multiple Choice
Key Concept: CloudFormation — IaC
Reference: Knowledge/domain-3-cloud-technology-and-services.md § CloudFormation


Q54. Lambda — Serverless vs EC2

An ETL job runs once per day (5 minutes), processes data, ends. Compare Lambda vs EC2:

Bản dịch tiếng Việt: Công việc ETL chạy một lần mỗi ngày (5 phút), xử lý dữ liệu và kết thúc. So sánh Lambda với EC2:

A. EC2 cheaper (always-on cost, overkill for 5 min) B. Lambda cheaper (pay only 5 min, auto-scales to 0) C. Same cost (no difference) D. Lambda can't handle data processing

Correct answer: B Bản dịch đáp án đúng: B. Lambda rẻ hơn (chỉ trả 5 phút, tự động chia tỷ lệ thành 0)

🇬🇧 Explanation: Lambda = pay per request + duration. 5 min/day = ~$0.01/month. EC2 = always-on cost, 24/7. Minimum ~$3-5/month.

Lambda auto-scales to 0 after execution. Cost-optimized.

🇻🇳 Giải thích: Lambda = chỉ tính 5 phút chạy. EC2 = 24/7 tính tiền. Lambda rẻ hơn.

Domain: 3 | Difficulty: Medium | Type: Multiple Choice
Key Concept: Lambda — serverless cost model
Reference: Knowledge/domain-3-cloud-technology-and-services.md § Lambda


Q55. CloudWatch — Monitoring Performance

An app owner wants to monitor EC2 CPU usage and get alert if > 80%. Tool?

Bản dịch tiếng Việt: Chủ sở hữu ứng dụng muốn theo dõi việc sử dụng CPU EC2 và nhận cảnh báo nếu > 80%. Dụng cụ?

A. AWS Config (configuration changes) B. CloudWatch — metrics, dashboards, alarms C. CloudTrail (API audit) D. AWS Trusted Advisor (best practices)

Correct answer: B Bản dịch đáp án đúng: B. CloudWatch — số liệu, bảng thông tin, cảnh báo

🇬🇧 Explanation: CloudWatch = monitoring service.

Features:

  • Metrics (CPU, memory, network)
  • Dashboards
  • Alarms (notify SNS, auto-scale, etc.)
  • Logs

🇻🇳 Giải thích: CloudWatch = monitoring. CPU > 80% → alarm → notify.

Domain: 3 | Difficulty: Easy | Type: Multiple Choice
Key Concept: CloudWatch — monitoring & alarms
Reference: Knowledge/domain-3-cloud-technology-and-services.md § CloudWatch


Q56. Kinesis — Real-Time Streaming

An IoT company collects sensor data from 1M devices (1 GB/sec throughput). Process in real-time. Service?

Bản dịch tiếng Việt: Một công ty IoT thu thập dữ liệu cảm biến từ 1 triệu thiết bị (thông lượng 1 GB/giây). Xử lý trong thời gian thực. Dịch vụ?

A. Lambda (max 15 min, not continuous) B. Kinesis Data Streams — real-time ingestion, parallel processing C. SQS (lower throughput, ordered) D. Batch via S3 (not real-time)

Correct answer: B Bản dịch đáp án đúng: B. Kinesis Data Streams — nhập theo thời gian thực, xử lý song song

🇬🇧 Explanation: Kinesis = real-time streaming data platform.

Handles:

  • High throughput (1 GB/sec)

  • Parallel processing (multiple consumers)

  • Real-time analytics

  • Lambda (A): Max 15 min, not continuous

  • SQS (C): Lower throughput, not real-time

  • Batch S3 (D): Historical, not real-time

🇻🇳 Giải thích: Kinesis = real-time streaming. 1 GB/sec IoT data → Kinesis.

Domain: 3 | Difficulty: Hard | Type: Multiple Choice
Key Concept: Kinesis — streaming data
Reference: Knowledge/domain-3-cloud-technology-and-services.md § Kinesis


Q57. Athena — SQL on S3

A data analyst wants to query S3 logs (1 TB) with SQL. No infrastructure management. Tool?

Bản dịch tiếng Việt: Một nhà phân tích dữ liệu muốn truy vấn nhật ký S3 (1 TB) bằng SQL. Không quản lý cơ sở hạ tầng. Dụng cụ?

A. RDS (for cloud DB, not S3) B. Redshift (overkill, requires cluster) C. Amazon Athena — serverless SQL on S3 D. DynamoDB (NoSQL, wrong data format)

Correct answer: C Bản dịch đáp án đúng: C. Amazon Athena - SQL không có máy chủ trên S3

🇬🇧 Explanation: Athena = serverless SQL query engine for S3.

Write SQL → query S3 data → results returned. Pay per GB scanned (~$5/TB).

  • RDS (A): Cloud database, not S3
  • Redshift (B): Data warehouse cluster, setup overhead
  • DynamoDB (D): NoSQL, wrong format

🇻🇳 Giải thích: Athena = serverless SQL on S3. Analyst write SQL → query logs → result. Không setup.

Domain: 3 | Difficulty: Medium | Type: Multiple Choice
Key Concept: Athena — SQL analytics
Reference: Knowledge/domain-3-cloud-technology-and-services.md § Athena


Q58. Systems Manager — Fleet Management

An admin needs to apply OS patches to 100 EC2 instances across regions without SSH to each. Approach?

Bản dịch tiếng Việt: Quản trị viên cần áp dụng các bản vá hệ điều hành cho 100 phiên bản EC2 trên khắp các khu vực mà không cần SSH cho từng phiên bản. Tiếp cận?

A. SSH into each instance manually B. AWS Systems Manager Patch Manager — centralized patching fleet C. Auto Scaling rolling update (not patching) D. Custom script (complex)

Correct answer: B Bản dịch đáp án đúng: B. AWS Systems Manager Patch Manager — nhóm vá lỗi tập trung

🇬🇧 Explanation: Systems Manager Patch Manager = centralized OS patching for EC2 fleet.

Define patch policy → AWS applies patches automatically across all instances → no SSH needed.

🇻🇳 Giải thích: Systems Manager Patch Manager = patch 100 instances at once, centralized, no manual SSH.

Domain: 3 | Difficulty: Medium | Type: Multiple Choice
Key Concept: Systems Manager — patch management
Reference: Knowledge/domain-3-cloud-technology-and-services.md § Systems Manager


Domain 4: Billing, Pricing, and Support (Q59–Q65)

Q59. Reserved Instances — Production Workload

A company runs stable production workload (same 10 EC2 instances for 3 years). Cost optimization?

Bản dịch tiếng Việt: Một công ty vận hành khối lượng công việc sản xuất ổn định (10 phiên bản EC2 giống nhau trong 3 năm). Tối ưu hóa chi phí?

A. On-Demand (~$0.0116/hr per t2.micro) B. Reserved Instance 3-year (~72% discount, ~$0.003/hr) C. Spot Instances (can be terminated) D. Savings Plans (flexible, less discount)

Correct answer: B Bản dịch đáp án đúng: B. Phiên bản dự trữ 3 năm (giảm giá ~72%, ~$0,003/giờ)

🇬🇧 Explanation: Reserved Instance 3-year = ~72% discount vs On-Demand.

Saves cost for stable, predictable workloads.

🇻🇳 Giải thích: RI 3 năm = 72% discount. Stable production = perfect case cho RI.

Domain: 4 | Difficulty: Medium | Type: Multiple Choice
Key Concept: EC2 Pricing — Reserved Instances
Reference: Knowledge/domain-4-billing-pricing-and-support.md § Reserved Instances


Q60. Spot Instances — Batch Processing

A research lab runs ML model training (fault-tolerant, 10-hour job), can restart if interrupted. Cost-optimized?

Bản dịch tiếng Việt: Một phòng thí nghiệm nghiên cứu chạy đào tạo mô hình ML (có khả năng chịu lỗi, công việc kéo dài 10 giờ), có thể khởi động lại nếu bị gián đoạn. Tối ưu hóa chi phí?

A. On-Demand (expensive) B. Reserved Instance (overkill, 3-year commitment) C. Spot Instance (90% discount, acceptable 2-min interruption) D. Dedicated Host (too expensive)

Correct answer: C Bản dịch đáp án đúng: C. Phiên bản Spot (giảm giá 90%, gián đoạn 2 phút có thể chấp nhận được)

🇬🇧 Explanation: Spot = ~90% discount. Can be interrupted (2-min notice), but fault-tolerant workloads can restart.

Batch processing = perfect Spot use case.

  • Dedicated Host (D): Very expensive

🇻🇳 Giải thích: Spot = rẻ 90%, acceptable interrupt cho batch job. Model training fault-tolerant → restart no problem.

Domain: 4 | Difficulty: Medium | Type: Multiple Choice
Key Concept: EC2 Pricing — Spot Instances
Reference: Knowledge/domain-4-billing-pricing-and-support.md § Spot Instances


Q61. AWS Budgets — Spending Control

A manager wants to alert when team's monthly AWS spend approaches $5,000. Tool?

Bản dịch tiếng Việt: Người quản lý muốn cảnh báo khi mức chi tiêu AWS hàng tháng của nhóm đạt tới 5.000 USD. Dụng cụ?

A. Billing Dashboard (overview only) B. AWS Budgets — set limit $5K, alert at 80% ($4K) C. AWS Pricing Calculator (pre-deploy estimate) D. Cost Allocation Tags (track, not alert)

Correct answer: B Bản dịch đáp án đúng: B. Ngân sách AWS — đặt giới hạn $5K, cảnh báo ở mức 80% ($4K)

🇬🇧 Explanation: AWS Budgets = set spending limits + alerts.

Create budget $5K/month → alert at 80% ($4K) and 100% ($5K).

🇻🇳 Giải thích: AWS Budgets = set limit + alert. $5K limit → alert lúc $4K (80%).

Domain: 4 | Difficulty: Easy-Medium | Type: Multiple Choice
Key Concept: Cost Management — Budgets
Reference: Knowledge/domain-4-billing-pricing-and-support.md § AWS Budgets


Q62. Cost Explorer — Cost Analysis

A CFO needs to see spending trends over past 12 months and forecast next 6 months. Tool?

Bản dịch tiếng Việt: Giám đốc tài chính cần xem xu hướng chi tiêu trong 12 tháng qua và dự báo trong 6 tháng tới. Dụng cụ?

A. Billing Dashboard (current month only) B. AWS Cost Explorer — historical trends + 12-month forecast + RI recommendations C. AWS Pricing Calculator (estimate, not historical) D. AWS Budgets (alerts, not forecasting)

Correct answer: B Bản dịch đáp án đúng: B. AWS Cost Explorer — xu hướng lịch sử + dự báo 12 tháng + đề xuất RI

🇬🇧 Explanation: Cost Explorer = historical trends + ML forecast + RI recommendations.

Shows cost by service, by tag, trends over time, forecasts future spending.

🇻🇳 Giải thích: Cost Explorer = trends + forecast. CFO muốn predict future → dùng Cost Explorer.

Domain: 4 | Difficulty: Easy-Medium | Type: Multiple Choice
Key Concept: Cost Management — Cost Explorer
Reference: Knowledge/domain-4-billing-pricing-and-support.md § AWS Cost Explorer


Q63. Support Plan — Production Down Response Time

A company has Business support. Production system is completely down. AWS response time SLA?

Bản dịch tiếng Việt: Một công ty có hỗ trợ kinh doanh. Hệ thống sản xuất hoàn toàn ngừng hoạt động. SLA thời gian phản hồi của AWS?

A. 4 hours B. 2 hours C. 1 hour (Business plan: production down = 1h SLA) D. 15 minutes (Enterprise only)

Correct answer: C Bản dịch đáp án đúng: C. 1 giờ (Kế hoạch kinh doanh: giảm sản lượng = 1h SLA)

🇬🇧 Explanation: Business support SLA:

  • General guidance: 24h
  • System impaired: 12h
  • Production system down: 1h ← Key SLA
  • Business-critical: Not supported (Enterprise only)

🇻🇳 Giải thích: Business support: production down = 1 hour SLA. Đó là contract.

Domain: 4 | Difficulty: Easy-Medium | Type: Multiple Choice
Key Concept: Support Plans — SLA
Reference: Knowledge/domain-4-billing-pricing-and-support.md § Support Plans


Q64. Enterprise Support — Technical Account Manager (TAM)

A large enterprise gets assigned a dedicated AWS technical expert to review architecture, recommend optimization. This benefit is in which support plan(s)? (Select TWO)

Bản dịch tiếng Việt: Một doanh nghiệp lớn được phân công một chuyên gia kỹ thuật AWS chuyên trách để xem xét kiến ​​trúc, đề xuất tối ưu hóa. Lợi ích này nằm trong (các) kế hoạch hỗ trợ nào? (Chọn HAI)

A. Basic B. Developer C. Business D. Enterprise On-Ramp (pooled TAM) E. Enterprise (dedicated TAM)

Correct answer: D, E Bản dịch đáp án đúng: D. Enterprise On-Ramp (TAM gộp); E. Doanh nghiệp (TAM chuyên dụng)

🇬🇧 Explanation: TAM = Technical Account Manager

  • Enterprise On-Ramp: Pooled TAM (shared among customers)
  • Enterprise: Dedicated TAM (1:1, your company only)

Business plan = no TAM, but Proactive Support

🇻🇳 Giải thích: TAM = dedicated expert. Chỉ có Enterprise On-Ramp (shared) + Enterprise (dedicated).

Domain: 4 | Difficulty: Hard | Type: Multi-Select (2/5)
Key Concept: Support Plans — TAM
Reference: Knowledge/domain-4-billing-pricing-and-support.md § Support Plans


Q65. Consolidated Billing — Multiple Accounts

A company has 3 AWS accounts. Total monthly spend: $10K. Using AWS Organizations + Consolidated Billing. Benefit?

Bản dịch tiếng Việt: Một công ty có 3 tài khoản AWS. Tổng chi tiêu hàng tháng: 10.000 USD. Sử dụng Tổ chức AWS + Thanh toán tổng hợp. Lợi ích?

A. No change in bill (same cost) B. Volume discounts applied across all 3 accounts (~10-20% savings pooled) C. Must merge accounts (not required) D. No consolidation possible

Correct answer: B Bản dịch đáp án đúng: B. Giảm giá theo số lượng áp dụng cho cả 3 tài khoản (tổng mức tiết kiệm ~ 10-20%)

🇬🇧 Explanation: AWS Organizations + Consolidated Billing = 1 bill, volume discounts pooled.

Instead of treating each account separately, AWS sees $10K total → applies bulk pricing.

Savings: 10-20% typically.

🇻🇳 Giải thích: Consolidated Billing = pool 3 accounts → AWS see 10K spending → give volume discount.

Domain: 4 | Difficulty: Medium | Type: Multiple Choice
Key Concept: Consolidated Billing
Reference: Knowledge/domain-4-billing-pricing-and-support.md § Consolidated Billing



Final Checklist — Did you cover all bases?

Domain 1 (16 questions)

  • ☐ 7 R's migration strategies
  • ☐ Global infrastructure (Regions, AZs, Edge)
  • ☐ Cloud Deployment Models (Public, Private, Hybrid)
  • ☐ 6 Advantages of Cloud
  • ☐ CapEx vs OpEx
  • ☐ Well-Architected Framework (6 Pillars)
  • ☐ NIST Cloud Characteristics
  • ☐ IaaS vs PaaS vs SaaS
  • ☐ CAF 6 Perspectives
  • ☐ Cloud Economics (Right-sizing)

Domain 2 (20 questions)

  • ☐ Shared Responsibility Model (by service)
  • ☐ IAM (Users, Groups, Roles, Policies)
  • ☐ MFA + Best Practices
  • ☐ Encryption (at-rest vs in-transit)
  • ☐ KMS (AWS-managed vs customer-managed)
  • ☐ CloudTrail vs CloudWatch vs AWS Config
  • ☐ DDoS (Shield) vs WAF
  • ☐ GuardDuty, Inspector, Macie
  • ☐ Compliance (HIPAA, PCI, SOC 2)
  • ☐ AWS Artifact, Trusted Advisor
  • ☐ S3 Block Public Access
  • ☐ Organizations + SCP

Domain 3 (22 questions)

  • ☐ Compute (EC2, Lambda, Containers, Fargate)
  • ☐ Storage (S3 classes, EBS, EFS)
  • ☐ Database (RDS vs Aurora vs DynamoDB)
  • ☐ Networking (VPC, Security Group, NAT)
  • ☐ Load Balancing (ALB, NLB)
  • ☐ Auto Scaling
  • ☐ CloudFront CDN
  • ☐ Route 53
  • ☐ CloudFormation IaC
  • ☐ Monitoring (CloudWatch)
  • ☐ Athena, Kinesis

Domain 4 (7 questions)

  • ☐ EC2 Pricing Models (On-Demand, RI, Spot, Savings Plans)
  • ☐ Free Tier (Always Free, 12-month, trials)
  • ☐ Cost Management (Cost Explorer, Budgets, CUR)
  • ☐ Cost Allocation Tags
  • ☐ Support Plans (SLA, TAM, Concierge)
  • ☐ Consolidated Billing

Score: __/65 × (1000/65) = __pts
Status: ☐ PASS (≥700) | ☐ FAIL (<700)


End of Exam #02 Solutions. Good luck on exam day!