CLF-C02 Mock Exam #03 — Solutions & Chi tiết giải đề
Exam Theme: Service Comparison & Selection
Bilingual: English + Tiếng Việt (dành cho bạn)
Target: ≥52/65 (80%) = Ready for real exam
Score Tracker
| Domain | Your Score | Target | Status |
|---|---|---|---|
| D1: Cloud Concepts (Q1–Q16) | ___/16 | ≥13 | ☐ |
| D2: Security & Compliance (Q17–Q36) | ___/20 | ≥16 | ☐ |
| D3: Cloud Tech & Services (Q37–Q58) | ___/22 | ≥17 | ☐ |
| D4: Billing & Support (Q59–Q65) | ___/7 | ≥6 | ☐ |
| TOTAL | ___/65 | ≥52 | ☐ |
Domain 1: Cloud Concepts (Q1–Q16)
Q1.
An organization needs to distribute workloads across multiple geographic regions to comply with data residency laws. Which AWS deployment model best supports this requirement?
Bản dịch tiếng Việt: Một tổ chức cần phân phối khối lượng công việc trên nhiều khu vực địa lý để tuân thủ luật về nơi lưu trữ dữ liệu. Mô hình triển khai AWS nào hỗ trợ tốt nhất cho yêu cầu này?
A. Single-region deployment with automatic replication B. Multi-region deployment across different AWS Regions C. Hybrid cloud with all data on-premises D. Single Availability Zone for simplicity
Correct answer: B Bản dịch đáp án đúng: B. Triển khai đa khu vực trên các AWS Region khác nhau
🇬🇧 Explanation: For data residency compliance across regions, multi-region deployment is essential. Data residency laws (GDPR, etc.) require data storage in specific geographic regions, and a multi-region deployment is what allows this compliance.
🇻🇳 Giải thích: Để tuân thủ luật lưu trữ dữ liệu (data residency) ở các quốc gia khác nhau, triển khai multi-region là cần thiết. Các luật như GDPR yêu cầu dữ liệu phải được lưu trong region địa lý cụ thể, và chỉ có triển khai multi-region mới đáp ứng được yêu cầu tuân thủ này.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Single-region replication) — Cannot meet residency if data must stay in EU, US, etc. / Không đáp ứng được residency nếu dữ liệu phải nằm trong EU, US, v.v.
- C (Hybrid on-premises) — Defeats the purpose of cloud's geographic distribution / Làm mất đi lợi ích phân bố địa lý của cloud.
- D (Single AZ) — Same region only, no multi-region capability / Chỉ trong một region, không có khả năng multi-region.
🔑 Key Concept / Khái niệm cốt lõi: AWS Regions are separate geographic areas; choose regions based on compliance needs. / AWS Regions là các khu vực địa lý riêng biệt; chọn region dựa trên nhu cầu tuân thủ.
Q2. (Select TWO)
A company is evaluating cloud deployment models. Which of the following correctly describe when to use Public Cloud vs Hybrid Cloud? (Select TWO)
Bản dịch tiếng Việt: Một công ty đang đánh giá các mô hình triển khai đám mây. Câu nào sau đây mô tả chính xác thời điểm sử dụng Đám mây công cộng và Đám mây lai? (Chọn HAI)
A. Public Cloud is best when no compliance restrictions exist and cost optimization is priority B. Hybrid Cloud is required for all healthcare applications C. Hybrid Cloud is suitable when legacy on-premises systems must coexist with cloud D. Public Cloud eliminates all security concerns E. Public Cloud provides better latency than Hybrid Cloud for global applications
Correct answer: A, C Bản dịch đáp án đúng: A. Đám mây công cộng hoạt động tốt nhất khi không tồn tại hạn chế tuân thủ và ưu tiên tối ưu hóa chi phí; C. Đám mây lai phù hợp khi các hệ thống tại chỗ cũ phải cùng tồn tại với đám mây
🇬🇧 Explanation: Public Cloud suits low-compliance workloads; Hybrid Cloud bridges legacy and cloud. A is correct because Public Cloud is ideal when there are no compliance restrictions and cost optimization is the priority. C is correct because Hybrid Cloud is designed to let legacy on-premises systems coexist with cloud services.
🇻🇳 Giải thích: Public Cloud phù hợp cho workload ít quy định; Hybrid Cloud kết nối legacy và cloud. A đúng vì Public Cloud lý tưởng khi không có ràng buộc tuân thủ và ưu tiên tối ưu chi phí. C đúng vì Hybrid Cloud được thiết kế để hệ thống legacy on-premises cùng tồn tại với cloud services.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (All healthcare uses Hybrid) — Not true; some use public cloud with HIPAA / Không đúng; một số dùng public cloud với HIPAA.
- D (Public Cloud = no security) — False; public cloud has security services / Sai; public cloud có đầy đủ security services.
- E (Public Cloud = better latency) — Depends on user location; Hybrid may be better for on-site users / Tùy vị trí người dùng; Hybrid có thể tốt hơn cho người dùng tại chỗ.
🔑 Key Concept / Khái niệm cốt lõi: Model selection depends on compliance, legacy systems, and data residency. / Việc chọn mô hình phụ thuộc vào tuân thủ, hệ thống legacy và data residency.
Q3.
A startup needs infrastructure with minimal upfront capital investment and the ability to scale elastically. Which cloud service model best fits this need?
Bản dịch tiếng Việt: Một công ty khởi nghiệp cần có cơ sở hạ tầng với vốn đầu tư trả trước tối thiểu và khả năng mở rộng quy mô một cách linh hoạt. Mô hình dịch vụ đám mây nào phù hợp nhất với nhu cầu này?
A. SaaS — provides software directly B. IaaS — provides compute, storage, and networking infrastructure C. PaaS — provides complete development platform D. On-premises data center
Correct answer: B Bản dịch đáp án đúng: B. IaaS - cung cấp cơ sở hạ tầng điện toán, lưu trữ và kết nối mạng
🇬🇧 Explanation: IaaS (Infrastructure as a Service) provides compute/storage/network with minimal CapEx. IaaS (EC2, RDS, S3) lets the customer control software/applications, requires minimal upfront investment (OpEx-based), and has elastic scalability built in.
🇻🇳 Giải thích: IaaS cung cấp compute/storage/network với CapEx tối thiểu. IaaS (EC2, RDS, S3) cho khách hàng kiểm soát software/applications, đầu tư ban đầu tối thiểu (theo OpEx), và có sẵn elastic scalability.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (SaaS) — Provides finished software (Gmail, Salesforce), not infrastructure / Cung cấp phần mềm hoàn chỉnh (Gmail, Salesforce), không phải hạ tầng.
- C (PaaS) — Provides platform but less control; Elastic Beanstalk is example / Cung cấp nền tảng nhưng ít kiểm soát hơn; Elastic Beanstalk là ví dụ.
- D (On-premises) — Requires huge upfront CapEx / Yêu cầu CapEx đầu tư ban đầu rất lớn.
🔑 Key Concept / Khái niệm cốt lõi: IaaS = customer manages applications; AWS manages infrastructure. / IaaS = khách hàng quản lý applications; AWS quản lý hạ tầng.
Q4.
Which of the following best describes the difference between elasticity and scalability in cloud computing?
Bản dịch tiếng Việt: Điều nào sau đây mô tả đúng nhất sự khác biệt giữa tính linh hoạt và khả năng mở rộng trong điện toán đám mây?
A. Elasticity = permanent capacity increases; Scalability = temporary growth B. Elasticity = automatic adjustment based on demand; Scalability = manual planning for growth C. They are identical concepts D. Elasticity applies only to databases
Correct answer: B Bản dịch đáp án đúng: B. Độ co giãn = điều chỉnh tự động dựa trên nhu cầu; Khả năng mở rộng = lập kế hoạch tăng trưởng thủ công
🇬🇧 Explanation: Elasticity = automatic (Cloud automatically adjusts); Scalability = planned growth. Elasticity means auto-scaling up/down in minutes based on current demand, while Scalability is the ability to grow infrastructure to meet future demand — they are related but distinct concepts.
🇻🇳 Giải thích: Elasticity = tự động điều chỉnh; Scalability = lên kế hoạch tăng trưởng. Elasticity là tự động scale lên/xuống trong vài phút theo nhu cầu hiện tại, còn Scalability là khả năng mở rộng hạ tầng để đáp ứng nhu cầu tương lai — hai khái niệm liên quan nhưng khác nhau.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Elasticity permanent, Scalability temporary) — Backwards / Ngược lại với thực tế.
- C (Identical) — They're complementary but different / Chúng bổ trợ nhau nhưng khác nhau.
- D (Elasticity only for databases) — Applies to EC2, Lambda, RDS, etc. / Áp dụng cho EC2, Lambda, RDS, v.v.
🔑 Key Concept / Khái niệm cốt lõi: Elasticity = reactive auto-scaling; Scalability = proactive growth planning. / Elasticity = auto-scaling phản ứng; Scalability = lập kế hoạch tăng trưởng chủ động.
Q5. (Select TWO)
A company is choosing between Public Cloud and Hybrid Cloud. Which statements are true? (Select TWO)
Bản dịch tiếng Việt: Một công ty đang lựa chọn giữa Public Cloud và Hybrid Cloud. Những tuyên bố nào là đúng? (Chọn HAI)
A. Public Cloud is fully owned and operated by AWS B. Hybrid Cloud requires AWS Outposts or storage gateway integration C. Public Cloud eliminates the need for firewalls D. Hybrid Cloud allows on-premises systems to securely connect to AWS services E. Public Cloud is cheaper than Hybrid Cloud in all scenarios
Correct answer: A, D Bản dịch đáp án đúng: A. Đám mây công cộng được sở hữu và vận hành hoàn toàn bởi AWS; D. Đám mây lai cho phép các hệ thống tại chỗ kết nối an toàn với các dịch vụ AWS
🇬🇧 Explanation: Public Cloud is AWS-owned; Hybrid Cloud connects on-premises to AWS. A is correct because Public Cloud is fully owned and operated by AWS (not the customer). D is correct because Hybrid Cloud uses Storage Gateway or Outposts to securely connect on-premises to AWS.
🇻🇳 Giải thích: Public Cloud do AWS sở hữu; Hybrid Cloud kết nối on-premises với AWS. A đúng vì Public Cloud hoàn toàn thuộc sở hữu và vận hành bởi AWS (không phải khách hàng). D đúng vì Hybrid Cloud dùng Storage Gateway hoặc Outposts để kết nối an toàn on-premises với AWS.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (Hybrid requires Outposts) — Outposts is one approach; Storage Gateway is another / Outposts chỉ là một cách; Storage Gateway là cách khác.
- C (Public Cloud no firewalls) — False; Security Groups and NACLs are firewalls / Sai; Security Groups và NACLs chính là firewall.
- E (Public Cloud always cheaper) — Not true; Hybrid can be cheaper for organizations needing both / Không đúng; Hybrid có thể rẻ hơn cho tổ chức cần cả hai.
🔑 Key Concept / Khái niệm cốt lõi: Public = AWS-managed; Hybrid = mixed ownership and location. / Public = AWS quản lý; Hybrid = sở hữu và vị trí kết hợp.
Q6.
A multinational company needs to comply with GDPR (data stored in EU) and HIPAA (healthcare data in US). Which AWS capability enables this?
Bản dịch tiếng Việt: Một công ty đa quốc gia cần tuân thủ GDPR (dữ liệu được lưu trữ ở EU) và HIPAA (dữ liệu chăm sóc sức khỏe ở Hoa Kỳ). Khả năng AWS nào cho phép điều này?
A. AWS Organizations to separate accounts B. Multiple AWS Regions where data residency requirements can be met C. Single region deployment with encryption D. AWS Direct Connect for all traffic
Correct answer: B Bản dịch đáp án đúng: B. Nhiều khu vực AWS nơi có thể đáp ứng các yêu cầu về nơi lưu trữ dữ liệu
🇬🇧 Explanation: Multiple AWS Regions allow data to be stored in specific geographic locations per law. AWS Regions are independent geographic areas (EU, US, APAC, etc.), each can host services independently, and this enables compliance with region-specific laws (GDPR = EU, HIPAA = US, etc.).
🇻🇳 Giải thích: Nhiều AWS Regions cho phép lưu dữ liệu tại vị trí địa lý cụ thể theo luật. AWS Regions là các khu vực địa lý độc lập (EU, US, APAC, v.v.), mỗi region có thể host services độc lập, giúp tuân thủ luật riêng của từng khu vực (GDPR = EU, HIPAA = US, v.v.).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Organizations) — Separates accounts, not geographic data location / Phân tách accounts, không phải vị trí địa lý của dữ liệu.
- C (Single region encryption) — Can't meet GDPR (data in EU) + HIPAA (data in US) simultaneously / Không thể đáp ứng đồng thời GDPR (dữ liệu ở EU) và HIPAA (dữ liệu ở US).
- D (Direct Connect) — Connects on-premises to AWS, doesn't affect region selection / Kết nối on-premises với AWS, không ảnh hưởng đến việc chọn region.
🔑 Key Concept / Khái niệm cốt lõi: Choose AWS Regions based on data residency compliance requirements. / Chọn AWS Regions dựa trên yêu cầu tuân thủ data residency.
Q7. (Select TWO)
Which pillars of the AWS Well-Architected Framework are most related to choosing the right AWS services? (Select TWO)
Bản dịch tiếng Việt: Những trụ cột nào của AWS Well-Architected Framework có liên quan nhiều nhất đến việc lựa chọn dịch vụ AWS phù hợp? (Chọn HAI)
A. Operational Excellence (choosing services that minimize manual effort) B. Security (choosing services with strong security controls) C. Reliability (using managed services for automatic failover) D. Networking (choosing services based on bandwidth) E. Cost Optimization (choosing services based on pricing models)
Correct answer: A, E Bản dịch đáp án đúng: A. Hoạt động xuất sắc (chọn dịch vụ giảm thiểu nỗ lực thủ công); E. Tối ưu hóa chi phí (lựa chọn dịch vụ dựa trên mô hình định giá)
🇬🇧 Explanation: Operational Excellence reduces overhead; Cost Optimization considers pricing models. A is correct because Operational Excellence means choosing services that minimize manual effort (managed services). E is correct because Cost Optimization means choosing services based on pricing and value.
🇻🇳 Giải thích: Operational Excellence giảm overhead; Cost Optimization xem xét pricing. A đúng vì Operational Excellence là chọn services giảm thiểu công sức thủ công (managed services). E đúng vì Cost Optimization là chọn services dựa trên giá và giá trị.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (Security pillar) — A real pillar, but framed here around controls generally, not the service-selection criteria the question asks for / Là một pillar thật, nhưng ở đây nói về controls nói chung, không phải tiêu chí chọn service mà câu hỏi yêu cầu.
- C (Reliability) — A real pillar (failover/managed services), but not framed as the primary service-selection lens here / Là pillar thật (failover/managed services), nhưng không phải lăng kính chọn service chính ở đây.
- D (Networking) — FALSE; "Networking" is NOT one of the AWS Well-Architected Framework pillars (the pillars are Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, and Sustainability) / SAI; "Networking" KHÔNG phải một pillar của Well-Architected Framework (các pillar là Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization và Sustainability).
🔑 Key Concept / Khái niệm cốt lõi: Well-Architected Framework includes service selection criteria. / Well-Architected Framework bao gồm tiêu chí lựa chọn service.
Q8.
In the Shared Responsibility Model, when choosing between EC2 (self-managed) and RDS (managed), what is the key difference in patching responsibility?
Bản dịch tiếng Việt: Trong Mô hình trách nhiệm chung, khi lựa chọn giữa EC2 (tự quản lý) và RDS (được quản lý), điểm khác biệt chính trong trách nhiệm vá lỗi là gì?
A. AWS patches both OS and database software for both services B. EC2 requires customer OS patching; RDS is patched by AWS C. Customer patches both OS and database in all cases D. Both services are customer responsibility
Correct answer: B Bản dịch đáp án đúng: B. EC2 yêu cầu bản vá hệ điều hành của khách hàng; RDS được vá bởi AWS
🇬🇧 Explanation: EC2 = customer patches OS; RDS = AWS patches database engine (Shared Responsibility). With EC2, AWS manages the hypervisor and you manage OS (Windows/Linux) patches; with RDS, AWS manages the OS AND the database engine patches. This is the core difference between self-managed and managed services.
🇻🇳 Giải thích: EC2 = customer patch OS; RDS = AWS patch database engine (Shared Responsibility). Với EC2, AWS quản lý hypervisor còn bạn patch OS (Windows/Linux); với RDS, AWS quản lý cả OS LẪN database engine patches. Đây là khác biệt cốt lõi giữa self-managed và managed services.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (AWS patches both EC2 OS and RDS DB) — Wrong; you patch EC2 OS / Sai; bạn phải patch OS của EC2.
- C (Customer patches both) — Wrong; AWS patches RDS engine / Sai; AWS patch RDS engine.
- D (Both customer) — Wrong; AWS patches RDS / Sai; AWS patch RDS.
🔑 Key Concept / Khái niệm cốt lõi: Shared Responsibility Model — higher layer of stack = your responsibility. / Shared Responsibility Model — tầng càng cao trong stack = trách nhiệm của bạn.
Q9.
A company wants to move a 10-year-old legacy application to AWS with minimal code changes. Which migration strategy and deployment model are most appropriate?
Bản dịch tiếng Việt: Một công ty muốn chuyển một ứng dụng cũ đã 10 năm tuổi sang AWS với những thay đổi mã tối thiểu. Chiến lược di chuyển và mô hình triển khai nào phù hợp nhất?
A. Refactor to use AWS-native services and run on Lambda B. Rehost (Lift-and-shift) on EC2 instances in a VPC C. Retire the application and build new D. Retain on-premises and use Direct Connect only
Correct answer: B Bản dịch đáp án đúng: B. Rehost (lift-and-shift) trên các phiên bản EC2 trong VPC
🇬🇧 Explanation: Rehost (Lift-and-shift) to EC2 requires minimal code changes; keep architecture same. Rehost means moving the application to EC2 as-is, which for a 10-year-old legacy app minimizes refactoring risk; EC2 is the "compute in the cloud" replacement for on-premises servers.
🇻🇳 Giải thích: Rehost (Lift-and-shift) sang EC2 yêu cầu thay đổi code tối thiểu, giữ nguyên kiến trúc. Rehost nghĩa là chuyển ứng dụng lên EC2 nguyên trạng, với app legacy 10 năm tuổi thì cách này giảm thiểu rủi ro refactor; EC2 là "compute trên cloud" thay thế cho server on-premises.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Refactor to Lambda) — Would require significant code rewrite; not "minimal changes" / Phải viết lại code đáng kể; không phải "thay đổi tối thiểu".
- C (Retire) — Eliminates the application entirely / Loại bỏ hoàn toàn ứng dụng.
- D (Retain on-premises) — Not migrating to cloud / Không di chuyển lên cloud.
🔑 Key Concept / Khái niệm cốt lõi: Cloud migration strategies — Rehost = quickest, least refactoring. / Chiến lược migration — Rehost = nhanh nhất, ít refactor nhất.
Q10.
Which AWS deployment approach provides the best balance between AWS-managed infrastructure and on-premises data center control?
Bản dịch tiếng Việt: Phương pháp triển khai AWS nào mang lại sự cân bằng tốt nhất giữa cơ sở hạ tầng do AWS quản lý và khả năng kiểm soát trung tâm dữ liệu tại chỗ?
A. Pure Public Cloud (all in AWS) B. Hybrid Cloud with AWS Outposts or Storage Gateway C. Private Cloud (all on-premises) D. Multi-cloud (AWS + Azure + GCP)
Correct answer: B Bản dịch đáp án đúng: B. Đám mây lai với AWS Outposts hoặc Storage Gateway
🇬🇧 Explanation: Hybrid Cloud with Outposts or Storage Gateway balances AWS cloud + on-premises control. Hybrid Cloud integrates on-premises with AWS cloud; AWS Outposts puts AWS infrastructure in the customer's data center, and Storage Gateway bridges on-premises to S3/backup in the cloud — providing a balance of control.
🇻🇳 Giải thích: Hybrid Cloud với Outposts hoặc Storage Gateway cân bằng giữa AWS cloud và kiểm soát on-premises. Hybrid Cloud tích hợp on-premises với AWS cloud; AWS Outposts đặt hạ tầng AWS trong data center của khách hàng, còn Storage Gateway kết nối on-premises tới S3/backup trên cloud — tạo sự cân bằng về kiểm soát.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Pure Public Cloud) — No on-premises integration / Không tích hợp on-premises.
- C (Private Cloud) — No AWS integration / Không tích hợp AWS.
- D (Multi-cloud) — Different vendors, not specific to on-premises / Nhiều nhà cung cấp khác nhau, không liên quan đến on-premises.
🔑 Key Concept / Khái niệm cốt lõi: Hybrid = best of both worlds (legacy + cloud modernization). / Hybrid = kết hợp ưu điểm cả hai (legacy + hiện đại hóa cloud).
Q11. (Select TWO)
A company is designing a global application and must choose between deploying in one region vs multiple regions. Which are valid reasons to choose multiple regions? (Select TWO)
Bản dịch tiếng Việt: Một công ty đang thiết kế một ứng dụng toàn cầu và phải lựa chọn giữa việc triển khai ở một khu vực và nhiều khu vực. Lý do hợp lệ nào để chọn nhiều khu vực? (Chọn HAI)
A. Reduction in per-request API call costs B. Compliance with data residency laws in different countries C. Lower latency for users in distant geographic locations D. Elimination of the need for load balancing E. Reduction in AWS service costs (lower pricing in multiple regions)
Correct answer: B, C Bản dịch đáp án đúng: B. Tuân thủ luật cư trú dữ liệu ở các quốc gia khác nhau; C. Độ trễ thấp hơn cho người dùng ở các vị trí địa lý xa
🇬🇧 Explanation: Multi-region for compliance, latency; single region for simplicity and cost. B is correct because different countries have data residency laws requiring local storage. C is correct because users in distant regions benefit from a local region (lower latency).
🇻🇳 Giải thích: Multi-region cho compliance và latency; single region cho đơn giản và chi phí. B đúng vì các quốc gia khác nhau có luật data residency yêu cầu lưu trữ tại chỗ. C đúng vì người dùng ở các region xa được hưởng lợi từ region cục bộ (latency thấp hơn).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Reduction in API costs) — Not a benefit; costs increase with more regions / Không phải lợi ích; càng nhiều region chi phí càng tăng.
- D (Eliminates load balancing need) — False; load balancing still required within region / Sai; vẫn cần load balancing trong từng region.
- E (Lower pricing in multiple regions) — False; pricing is per region, total cost increases / Sai; giá tính theo từng region, tổng chi phí tăng.
🔑 Key Concept / Khái niệm cốt lõi: Multi-region trade-off = higher cost for better compliance and UX (latency). / Đánh đổi multi-region = chi phí cao hơn để có compliance và UX (latency) tốt hơn.
Q12.
Which of the following best describes Infrastructure as Code (IaC) and its relationship to service selection?
Bản dịch tiếng Việt: Câu nào sau đây mô tả đúng nhất Cơ sở hạ tầng dưới dạng Mã (IaC) và mối quan hệ của nó với việc lựa chọn dịch vụ?
A. IaC eliminates the need to choose services; AWS chooses automatically B. IaC allows repeatable infrastructure deployment using templates, enabling consistent service selection across environments C. IaC is only for database services D. IaC requires manual service provisioning
Correct answer: B Bản dịch đáp án đúng: B. IaC cho phép triển khai cơ sở hạ tầng lặp lại bằng cách sử dụng các mẫu, cho phép lựa chọn dịch vụ nhất quán trên các môi trường
🇬🇧 Explanation: IaC (CloudFormation) enables repeatable, consistent service selection across environments. CloudFormation/Terraform is Infrastructure as Code that allows the same service selection to be deployed repeatedly (dev, staging, prod) and ensures consistency across environments.
🇻🇳 Giải thích: IaC (CloudFormation) cho phép lặp lại việc chọn service một cách nhất quán giữa các môi trường. CloudFormation/Terraform là Infrastructure as Code, cho phép triển khai cùng một lựa chọn service lặp đi lặp lại (dev, staging, prod) và đảm bảo tính nhất quán giữa các môi trường.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Eliminates service choice) — False; still requires deciding which services to use / Sai; vẫn phải quyết định dùng service nào.
- C (Only for databases) — No; IaC covers all services / Không; IaC bao phủ mọi service.
- D (Requires manual provisioning) — False; IaC is automated / Sai; IaC là tự động.
🔑 Key Concept / Khái niệm cốt lõi: IaC = repeatable, version-controlled infrastructure templates. / IaC = template hạ tầng có thể lặp lại, quản lý theo version.
Q13.
A team is comparing two deployment models: one Region with multiple Availability Zones (MZ setup) vs. multiple Regions with single AZs each. For a critical production application, which is superior?
Bản dịch tiếng Việt: Một nhóm đang so sánh hai mô hình triển khai: một AWS Region có nhiều Availability Zone (thiết lập multi-AZ) với nhiều AWS Region nhưng mỗi Region chỉ có một AZ riêng lẻ. Đối với một ứng dụng sản xuất quan trọng, cái nào tốt hơn?
A. Multiple Regions is always better B. Multiple AZs in single Region provides AZ-level fault tolerance; multiple Regions adds region-level disaster recovery C. Single AZ is sufficient for all applications D. Availability Zones don't affect application availability
Correct answer: B Bản dịch đáp án đúng: B. Nhiều AZ trong một Vùng duy nhất cung cấp khả năng chịu lỗi cấp AZ; nhiều Region bổ sung khả năng disaster recovery cấp khu vực
🇬🇧 Explanation: Multiple AZs provide AZ-level redundancy; multiple Regions add region-level disaster recovery. Multi-AZ in a single region protects against AZ failure (any one data center down, app still up), while multi-region protects against region-wide failure (earthquake, power outage); for critical apps both are ideal (multi-AZ + multi-region failover).
🇻🇳 Giải thích: Nhiều AZs cho redundancy cấp AZ; nhiều Regions thêm disaster recovery cấp region. Multi-AZ trong một region bảo vệ khỏi sự cố AZ (một data center sập, app vẫn chạy), còn multi-region bảo vệ khỏi sự cố toàn region (động đất, mất điện); với app quan trọng thì cả hai đều lý tưởng (multi-AZ + failover multi-region).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Multiple Regions always better) — More expensive; multi-AZ is first priority / Đắt hơn; multi-AZ là ưu tiên đầu tiên.
- C (Single AZ sufficient) — Single point of failure (entire region down = app down) / Điểm lỗi đơn (cả region sập = app sập).
- D (AZs don't affect availability) — Fundamentally wrong; AZ design is core redundancy / Sai về bản chất; thiết kế AZ là cốt lõi của redundancy.
🔑 Key Concept / Khái niệm cốt lõi: Availability Zones = fault isolation; Regions = disaster recovery. / Availability Zones = cô lập lỗi; Regions = disaster recovery.
Q14. (Select THREE)
Which of the following are characteristics of cloud services that influence the decision to migrate from on-premises? (Select THREE)
Bản dịch tiếng Việt: Đặc điểm nào sau đây của dịch vụ đám mây ảnh hưởng đến quyết định di chuyển từ tại chỗ? (Chọn BA)
A. Ability to avoid capital expenditure (CapEx) for infrastructure B. Automatic scaling without manual intervention C. Guaranteed 100% uptime SLA for all services D. Reduced operational burden through managed services E. Lower total cost of ownership for most workloads
Correct answer: A, B, D Bản dịch đáp án đúng: A. Khả năng tránh chi phí vốn (CapEx) cho cơ sở hạ tầng; B. Tự động chia tỷ lệ mà không cần can thiệp thủ công; D. Giảm gánh nặng vận hành thông qua các dịch vụ được quản lý
🇬🇧 Explanation: Cloud advantages: no CapEx, auto-scaling, reduced ops burden. A is correct because you avoid capital expenditure (CapEx) and pay OpEx instead. B is correct because scaling is automatic without manual intervention. D is correct because managed services reduce operational burden (RDS vs self-managed DB).
🇻🇳 Giải thích: Lợi ích của cloud: không CapEx, auto-scaling, giảm gánh nặng vận hành. A đúng vì tránh được chi phí đầu tư ban đầu (CapEx) và trả theo OpEx. B đúng vì scaling tự động không cần can thiệp thủ công. D đúng vì managed services giảm gánh nặng vận hành (RDS so với DB tự quản lý).
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (Guaranteed 100% SLA) — AWS doesn't guarantee 100%; 99.99% is high but not 100% / AWS không đảm bảo 100%; 99.99% là cao nhưng không phải 100%.
- E (Lower TCO always) — Not always true; some workloads are cheaper on-premises / Không phải lúc nào cũng đúng; một số workload rẻ hơn khi on-premises.
🔑 Key Concept / Khái niệm cốt lõi: Cloud value = flexibility, reduced CapEx, automation, managed services. / Giá trị của cloud = linh hoạt, giảm CapEx, tự động hóa, managed services.
Q15.
A startup must choose between implementing their own data center vs using AWS. Which AWS advantage is most relevant to a startup's rapid growth needs?
Bản dịch tiếng Việt: Công ty khởi nghiệp phải lựa chọn giữa việc triển khai trung tâm dữ liệu của riêng họ và sử dụng AWS. Lợi thế nào của AWS phù hợp nhất với nhu cầu tăng trưởng nhanh chóng của công ty khởi nghiệp?
A. AWS guarantees lower costs than on-premises in all scenarios B. AWS provides elasticity and scalability without predicting capacity requirements C. AWS eliminates the need for networking and security D. AWS provides unlimited storage for free
Correct answer: B Bản dịch đáp án đúng: B. AWS cung cấp tính linh hoạt và khả năng mở rộng mà không cần dự đoán các yêu cầu về năng lực
🇬🇧 Explanation: Elasticity (auto-scaling) allows startups to grow without predicting exact capacity. Startups have unpredictable growth, AWS elasticity scales automatically without manual intervention, and you pay only for what you use (no over-provisioning).
🇻🇳 Giải thích: Elasticity (auto-scaling) cho phép startup tăng trưởng mà không cần dự đoán chính xác capacity. Startup có tăng trưởng khó đoán, AWS elasticity tự động scale không cần can thiệp thủ công, và bạn chỉ trả cho phần đã dùng (không over-provisioning).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (AWS always cheaper) — False; depends on workload and on-premises comparison / Sai; tùy workload và so sánh với on-premises.
- C (Eliminates networking/security) — False; still need VPC, SGs, firewalls / Sai; vẫn cần VPC, SGs, firewall.
- D (Unlimited storage free) — False; S3 has free tier limits / Sai; S3 có giới hạn free tier.
🔑 Key Concept / Khái niệm cốt lõi: Cloud elasticity = perfect for unpredictable startup growth. / Elasticity của cloud = hoàn hảo cho tăng trưởng khó đoán của startup.
Q16.
Which AWS global infrastructure components should a company consider when choosing where to deploy an application requiring low latency for end users?
Bản dịch tiếng Việt: Công ty nên cân nhắc thành phần cơ sở hạ tầng toàn cầu nào của AWS khi chọn nơi triển khai ứng dụng yêu cầu độ trễ thấp cho người dùng cuối?
A. Only AWS Regions (larger coverage) B. Edge Locations and CloudFront for content delivery C. Availability Zones for application redundancy D. All of the above for optimal placement decisions
Correct answer: D Bản dịch đáp án đúng: D. Tất cả những điều trên để đưa ra quyết định vị trí tối ưu
🇬🇧 Explanation: Low latency requires considering Regions (app server location), AZs (redundancy), Edge Locations (CDN). Choose the region closest to users, use multiple AZs for redundancy within the region, and use Edge Locations (CloudFront) for static content caching — all three matter for optimal low-latency placement.
🇻🇳 Giải thích: Latency thấp yêu cầu xem xét Regions (vị trí app server), AZs (redundancy) và Edge Locations (CDN). Chọn region gần người dùng nhất, dùng nhiều AZs để redundancy trong region, và dùng Edge Locations (CloudFront) để cache nội dung tĩnh — cả ba yếu tố đều quan trọng để đặt vị trí tối ưu cho latency thấp.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Only Regions) — Incomplete; ignores AZ redundancy and CDN / Chưa đủ; bỏ qua AZ redundancy và CDN.
- B (Only Edge Locations) — CloudFront is for static content, not app logic / CloudFront dành cho nội dung tĩnh, không phải logic ứng dụng.
- C (Only AZs) — Doesn't address geographic distance (cross-country latency) / Không giải quyết khoảng cách địa lý (latency xuyên quốc gia).
🔑 Key Concept / Khái niệm cốt lõi: Low-latency strategy = region proximity + edge caching + multi-AZ redundancy. / Chiến lược latency thấp = region gần + edge caching + multi-AZ redundancy.
Domain 2: Security and Compliance (Q17–Q36)
Q17.
A company needs to implement fine-grained access control where different users have different permissions to specific AWS resources. Which service is the primary choice?
Bản dịch tiếng Việt: Công ty cần triển khai kiểm soát truy cập chi tiết trong đó những người dùng khác nhau có các quyền khác nhau đối với các tài nguyên AWS cụ thể. Dịch vụ nào là lựa chọn hàng đầu?
A. AWS KMS (encryption only) B. AWS IAM (users, groups, roles, and policies) C. AWS CloudTrail (logging only) D. AWS Config (configuration compliance)
Correct answer: B Bản dịch đáp án đúng: B. AWS IAM (người dùng, nhóm, vai trò và chính sách)
🇬🇧 Explanation: IAM (Identity & Access Management) provides fine-grained access control via users, groups, roles, policies. It covers Users (people/apps), Groups (collections), Roles (temporary), and Policies (permissions) — this is THE service for access control.
🇻🇳 Giải thích: IAM cung cấp kiểm soát truy cập chi tiết qua users, groups, roles, policies. Gồm Users (người/ứng dụng), Groups (nhóm), Roles (tạm thời), Policies (quyền) — đây chính là service dành cho kiểm soát truy cập.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (KMS) — Encryption keys, not identity/access / Khóa mã hóa, không phải identity/access.
- C (CloudTrail) — Logs what happened, doesn't control access / Ghi log việc đã xảy ra, không kiểm soát truy cập.
- D (Config) — Tracks configuration, not identity / Theo dõi cấu hình, không phải identity.
🔑 Key Concept / Khái niệm cốt lõi: IAM = access control; CloudTrail = audit logging. / IAM = kiểm soát truy cập; CloudTrail = ghi log kiểm toán.
Q18. (Select TWO)
A company must track who accessed resources and what actions were performed for audit purposes. Which AWS services provide this capability? (Select TWO)
Bản dịch tiếng Việt: Công ty phải theo dõi ai đã truy cập tài nguyên và hành động nào được thực hiện cho mục đích kiểm toán. Dịch vụ AWS nào cung cấp khả năng này? (Chọn HAI)
A. AWS CloudTrail (logs all API calls) B. AWS Config (tracks resource configuration changes) C. AWS CloudWatch (monitors performance metrics) D. AWS GuardDuty (threat detection) E. AWS WAF (blocks malicious web requests)
Correct answer: A, B Bản dịch đáp án đúng: A. AWS CloudTrail (ghi lại tất cả lệnh gọi API); B. AWS Config (theo dõi các thay đổi cấu hình tài nguyên)
🇬🇧 Explanation: CloudTrail logs API calls ("who did what"); Config tracks configuration changes ("what changed"). A is correct because CloudTrail logs all API calls with timestamp, user, and action. B is correct because AWS Config tracks resource configuration state and changes.
🇻🇳 Giải thích: CloudTrail ghi log API calls ("ai đã làm gì"); Config theo dõi thay đổi cấu hình ("cái gì đã thay đổi"). A đúng vì CloudTrail ghi mọi API call kèm timestamp, user, action. B đúng vì AWS Config theo dõi trạng thái cấu hình resource và các thay đổi.
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (CloudWatch) — Performance metrics, not audit / Metrics hiệu năng, không phải kiểm toán.
- D (GuardDuty) — Threat detection, not audit logging / Phát hiện threat, không phải ghi log kiểm toán.
- E (WAF) — Web protection, not logging / Bảo vệ web, không phải logging.
🔑 Key Concept / Khái niệm cốt lõi: CloudTrail = "who did what"; Config = "what is the state". / CloudTrail = "ai làm gì"; Config = "trạng thái là gì".
Q19.
An organization needs to protect against distributed denial-of-service (DDoS) attacks. Which AWS service is the primary choice?
Bản dịch tiếng Việt: Một tổ chức cần bảo vệ chống lại các cuộc tấn công từ chối dịch vụ (DDoS) phân tán. Dịch vụ AWS nào là lựa chọn chính?
A. AWS WAF (protects web applications from SQL injection) B. AWS Config (checks compliance) C. AWS Shield (DDoS protection) D. AWS CloudTrail (logs API calls)
Correct answer: C Bản dịch đáp án đúng: C. Lá chắn AWS (bảo vệ DDoS)
🇬🇧 Explanation: AWS Shield protects against DDoS attacks (distributed denial of service). Shield Standard provides automatic DDoS protection (free) and Shield Advanced provides more advanced DDoS protection ($3K/month) — this is the ONLY service specifically for DDoS.
🇻🇳 Giải thích: AWS Shield bảo vệ chống DDoS (distributed denial of service). Shield Standard cung cấp bảo vệ DDoS tự động (miễn phí) và Shield Advanced cung cấp bảo vệ DDoS nâng cao hơn ($3K/tháng) — đây là service DUY NHẤT chuyên cho DDoS.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (WAF) — Blocks SQL injection/XSS, not DDoS / Chặn SQL injection/XSS, không phải DDoS.
- B (Config) — Configuration compliance, not DDoS / Tuân thủ cấu hình, không phải DDoS.
- D (CloudTrail) — Logging, not protection / Ghi log, không phải bảo vệ.
🔑 Key Concept / Khái niệm cốt lõi: DDoS = Shield; Web attacks = WAF. / DDoS = Shield; tấn công web = WAF.
Q20.
A web application is frequently targeted by SQL injection and cross-site scripting attacks. Which AWS service should be deployed?
Bản dịch tiếng Việt: Một ứng dụng web thường xuyên là mục tiêu của các cuộc tấn công SQL injection và tấn công tập lệnh chéo trang. Dịch vụ AWS nào nên được triển khai?
A. AWS Shield Standard (DDoS only) B. AWS WAF (Web Application Firewall) C. AWS GuardDuty (threat detection) D. AWS Config (configuration management)
Correct answer: B Bản dịch đáp án đúng: B. AWS WAF (Tường lửa ứng dụng web)
🇬🇧 Explanation: AWS WAF (Web Application Firewall) blocks SQL injection, XSS, and web attacks. WAF blocks Layer 7 (application) attacks (SQL injection, XSS, CSRF) and is deployed in front of ALB, CloudFront, or API Gateway.
🇻🇳 Giải thích: AWS WAF (Web Application Firewall) chặn SQL injection, XSS và các tấn công web. WAF chặn tấn công Layer 7 (ứng dụng) như SQL injection, XSS, CSRF và được đặt phía trước ALB, CloudFront hoặc API Gateway.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Shield) — DDoS protection, not web attacks / Bảo vệ DDoS, không phải tấn công web.
- C (GuardDuty) — Threat detection, not blocking / Phát hiện threat, không chặn.
- D (Config) — Compliance, not attack blocking / Tuân thủ, không chặn tấn công.
🔑 Key Concept / Khái niệm cốt lõi: Web attacks = WAF; DDoS = Shield. / Tấn công web = WAF; DDoS = Shield.
Q21. (Select TWO)
A company uses CloudTrail for API logging and AWS Config for configuration compliance. What is the correct use case for each? (Select TWO)
Bản dịch tiếng Việt: Một công ty sử dụng CloudTrail để ghi nhật ký API và AWS Config để tuân thủ cấu hình. Trường hợp sử dụng chính xác cho mỗi trường hợp là gì? (Chọn HAI)
A. CloudTrail answers "Who did what and when" for all API activities B. AWS Config answers "What is the current configuration state" and detects drift C. CloudTrail and Config are interchangeable D. AWS Config provides network DDoS protection E. CloudTrail is only for security audit trails
Correct answer: A, B Bản dịch đáp án đúng: A. CloudTrail trả lời "Ai làm gì và khi nào" cho tất cả hoạt động API; B. AWS Config trả lời "Trạng thái cấu hình hiện tại là gì" và phát hiện độ lệch
🇬🇧 Explanation: CloudTrail = "who did what"; Config = "what is the state" and compliance. A is correct because CloudTrail answers "who, what, when" — all API activity. B is correct because Config answers "what is the current state" and detects configuration drift.
🇻🇳 Giải thích: CloudTrail = "ai đã làm gì"; Config = "trạng thái là gì" và compliance. A đúng vì CloudTrail trả lời "ai, làm gì, khi nào" — toàn bộ hoạt động API. B đúng vì Config trả lời "trạng thái hiện tại là gì" và phát hiện configuration drift.
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (Interchangeable) — No; different purposes / Không; mục đích khác nhau.
- D (Config provides DDoS) — False; Config is compliance / Sai; Config là compliance.
- E (CloudTrail for security audit only) — CloudTrail logs ALL API calls, not just security / CloudTrail ghi TẤT CẢ API calls, không chỉ bảo mật.
🔑 Key Concept / Khái niệm cốt lõi: CloudTrail = audit log; Config = compliance monitoring. / CloudTrail = log kiểm toán; Config = giám sát compliance.
Q22.
An organization must prevent security misconfigurations (e.g., S3 buckets becoming public). Which service continuously monitors for this?
Bản dịch tiếng Việt: Tổ chức phải ngăn chặn các hành vi cấu hình sai về bảo mật (ví dụ: nhóm S3 trở nên công khai). Dịch vụ nào liên tục giám sát việc này?
A. AWS IAM B. AWS Config (configuration compliance monitoring) C. AWS CloudTrail D. AWS CloudWatch
Correct answer: B Bản dịch đáp án đúng: B. AWS Config (giám sát việc tuân thủ cấu hình)
🇬🇧 Explanation: AWS Config continuously monitors configuration and detects drift (e.g., S3 bucket becoming public). AWS Config tracks configuration state, uses Config Rules as compliance checks (e.g., "S3 buckets must be private"), and detects drift automatically.
🇻🇳 Giải thích: AWS Config liên tục theo dõi cấu hình và phát hiện drift (ví dụ S3 bucket bị mở public). AWS Config theo dõi trạng thái cấu hình, dùng Config Rules làm kiểm tra compliance (ví dụ "S3 buckets phải private") và tự động phát hiện drift.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (IAM) — Access control, not configuration monitoring / Kiểm soát truy cập, không phải giám sát cấu hình.
- C (CloudTrail) — Logs changes, but doesn't enforce rules / Ghi log thay đổi, nhưng không thực thi rules.
- D (CloudWatch) — Performance metrics, not configuration / Metrics hiệu năng, không phải cấu hình.
🔑 Key Concept / Khái niệm cốt lõi: Config = compliance monitoring & drift detection. / Config = giám sát compliance & phát hiện drift.
Q23.
A company wants to encrypt sensitive data at rest in S3 and needs to manage encryption keys. Which service handles key management?
Bản dịch tiếng Việt: Một công ty muốn mã hóa dữ liệu nhạy cảm ở phần còn lại trong S3 và cần quản lý các khóa mã hóa. Dịch vụ nào xử lý việc quản lý khóa?
A. AWS WAF B. AWS KMS (Key Management Service) C. AWS Secrets Manager (secrets only, not general encryption) D. AWS CloudHSM (hardware security module, more complex)
Correct answer: B Bản dịch đáp án đúng: B. AWS KMS (Dịch vụ quản lý khóa)
🇬🇧 Explanation: AWS KMS (Key Management Service) manages encryption keys for S3 and other services. KMS handles encryption key management, integrates with S3, EBS, RDS, etc., and supports customer-managed keys (CMK) or AWS-managed keys.
🇻🇳 Giải thích: AWS KMS (Key Management Service) quản lý encryption keys cho S3 và các services khác. KMS xử lý quản lý encryption key, tích hợp với S3, EBS, RDS, v.v., và hỗ trợ customer-managed keys (CMK) hoặc AWS-managed keys.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (WAF) — Web protection, not encryption / Bảo vệ web, không phải mã hóa.
- C (Secrets Manager) — Stores secrets (passwords), not general encryption keys / Lưu secrets (mật khẩu), không phải encryption keys chung.
- D (CloudHSM) — Hardware security module (more complex, not first choice) / Hardware security module (phức tạp hơn, không phải lựa chọn đầu tiên).
🔑 Key Concept / Khái niệm cốt lõi: KMS = encryption keys; Secrets Manager = secrets (passwords/API keys). / KMS = encryption keys; Secrets Manager = secrets (mật khẩu/API keys).
Q24. (Select TWO)
A company is choosing between KMS and CloudHSM for encryption key management. Which statements are correct? (Select TWO)
Bản dịch tiếng Việt: Một công ty đang lựa chọn giữa KMS và CloudHSM để quản lý khóa mã hóa. Những phát biểu nào đúng? (Chọn HAI)
A. KMS is AWS-managed and recommended for most use cases B. CloudHSM is a hardware device where customer manages keys (FIPS 140-2 compliance) C. KMS is more expensive than CloudHSM D. CloudHSM requires customer to own and manage the hardware E. Both KMS and CloudHSM are fully AWS-managed
Correct answer: A, B Bản dịch đáp án đúng: A. KMS được AWS quản lý và khuyên dùng cho hầu hết các trường hợp sử dụng; B. CloudHSM là thiết bị phần cứng nơi khách hàng quản lý khóa (tuân thủ FIPS 140-2)
🇬🇧 Explanation: KMS is AWS-managed and easy; CloudHSM is customer-managed hardware for compliance. A is correct because KMS is AWS-managed (the easiest choice for most). B is correct because CloudHSM is customer-managed hardware for FIPS 140-2 compliance.
🇻🇳 Giải thích: KMS do AWS quản lý và dễ dùng; CloudHSM là phần cứng do khách hàng quản lý cho compliance. A đúng vì KMS do AWS quản lý (lựa chọn dễ nhất cho hầu hết). B đúng vì CloudHSM là hardware do khách hàng quản lý cho compliance FIPS 140-2.
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (CloudHSM is cheaper) — False; CloudHSM is MORE expensive than KMS / Sai; CloudHSM ĐẮT hơn KMS.
- D (Customer owns and manages the hardware) — False; the HSM hardware sits in AWS data centers. The customer manages the keys and HSM, not the physical hardware. / Sai; phần cứng HSM nằm trong data center của AWS. Khách hàng quản lý keys và HSM, không phải phần cứng vật lý.
- E (Both AWS-managed) — False; with CloudHSM the customer controls the keys/HSM / Sai; với CloudHSM khách hàng kiểm soát keys/HSM.
🔑 Key Concept / Khái niệm cốt lõi: KMS = managed keys; CloudHSM = FIPS compliance (expensive). / KMS = keys được quản lý; CloudHSM = compliance FIPS (đắt).
Q25.
An application needs to securely store database passwords and API keys. Which service is best suited?
Bản dịch tiếng Việt: Ứng dụng cần lưu trữ mật khẩu cơ sở dữ liệu và khóa API một cách an toàn. Dịch vụ nào phù hợp nhất?
A. AWS KMS (encryption keys, not secrets) B. AWS Secrets Manager (stores and rotates secrets) C. AWS Config (compliance tracking) D. AWS Systems Manager Parameter Store (can work, but less automation)
Correct answer: B Bản dịch đáp án đúng: B. AWS Secrets Manager (lưu trữ và luân chuyển bí mật)
🇬🇧 Explanation: AWS Secrets Manager stores and automatically rotates secrets (passwords, API keys, tokens). It handles passwords, API keys, and database credentials, supports automatic rotation (configurable), and integrates with RDS, Lambda, etc.
🇻🇳 Giải thích: AWS Secrets Manager lưu trữ và tự động rotate secrets (mật khẩu, API keys, tokens). Nó xử lý mật khẩu, API keys, database credentials, hỗ trợ rotation tự động (cấu hình được) và tích hợp với RDS, Lambda, v.v.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (KMS) — Encryption keys, not secrets management / Encryption keys, không phải quản lý secrets.
- C (Config) — Compliance, not secrets / Compliance, không phải secrets.
- D (Systems Manager Parameter Store) — Can store secrets but less automation than Secrets Manager / Có thể lưu secrets nhưng ít tự động hóa hơn Secrets Manager.
🔑 Key Concept / Khái niệm cốt lõi: Secrets Manager = automatic password/API key rotation. / Secrets Manager = tự động rotate mật khẩu/API key.
Q26. (Select TWO)
A company is comparing GuardDuty and Inspector for security assessments. Which correctly describes their use cases? (Select TWO)
Bản dịch tiếng Việt: Một công ty đang so sánh GuardDuty và Inspector để đánh giá bảo mật. Điều nào mô tả chính xác trường hợp sử dụng của họ? (Chọn HAI)
A. GuardDuty detects threats and anomalies using ML on CloudTrail/VPC logs B. Inspector scans EC2 instances and Lambda functions for vulnerabilities C. Both GuardDuty and Inspector protect against DDoS D. GuardDuty requires manual vulnerability scanning E. Inspector is AWS-managed threat detection service
Correct answer: A, B Bản dịch đáp án đúng: A. GuardDuty phát hiện các mối đe dọa và sự bất thường bằng cách sử dụng ML trên nhật ký CloudTrail/VPC; B. Thanh tra quét các phiên bản EC2 và hàm Lambda để tìm lỗ hổng
🇬🇧 Explanation: GuardDuty detects threats via ML; Inspector scans for vulnerabilities. A is correct because GuardDuty does threat detection (unauthorized access, malware, anomalies) using ML. B is correct because Inspector is a vulnerability scanner (EC2 instances, Lambda, container images).
🇻🇳 Giải thích: GuardDuty phát hiện threats bằng ML; Inspector quét vulnerabilities. A đúng vì GuardDuty phát hiện threat (truy cập trái phép, malware, bất thường) bằng ML. B đúng vì Inspector là trình quét lỗ hổng (EC2 instances, Lambda, container images).
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (Both protect DDoS) — False; Shield protects DDoS / Sai; Shield mới bảo vệ DDoS.
- D (GuardDuty requires manual scanning) — False; GuardDuty is automatic / Sai; GuardDuty là tự động.
- E (Inspector is threat detection) — False; Inspector is vulnerability assessment / Sai; Inspector là đánh giá lỗ hổng.
🔑 Key Concept / Khái niệm cốt lõi: GuardDuty = threat detection; Inspector = vulnerability scan. / GuardDuty = phát hiện threat; Inspector = quét lỗ hổng.
Q27.
A company wants to detect unusual network traffic and potential security breaches. Which service provides this?
Bản dịch tiếng Việt: Một công ty muốn phát hiện lưu lượng truy cập mạng bất thường và các vi phạm an ninh tiềm ẩn. Dịch vụ nào cung cấp điều này?
A. AWS WAF (blocks web requests) B. AWS Shield (DDoS protection) C. AWS GuardDuty (threat detection using ML) D. AWS Config (configuration compliance)
Correct answer: C Bản dịch đáp án đúng: C. AWS GuardDuty (phát hiện mối đe dọa bằng ML)
🇬🇧 Explanation: AWS GuardDuty uses ML to detect unauthorized access, malware, and network anomalies. It analyzes CloudTrail, VPC Flow Logs, and DNS logs for ML-based threat detection, identifying suspicious access patterns and malware.
🇻🇳 Giải thích: AWS GuardDuty dùng ML phát hiện truy cập trái phép, malware và bất thường mạng. Nó phân tích CloudTrail, VPC Flow Logs, DNS logs để phát hiện threat bằng ML, nhận diện các mẫu truy cập đáng ngờ và malware.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (WAF) — Blocks web attacks, not unusual traffic / Chặn tấn công web, không phải lưu lượng bất thường.
- B (Shield) — DDoS protection, not breach detection / Bảo vệ DDoS, không phát hiện xâm nhập.
- D (Config) — Configuration compliance, not threat detection / Tuân thủ cấu hình, không phát hiện threat.
🔑 Key Concept / Khái niệm cốt lõi: GuardDuty = automated threat intelligence. / GuardDuty = threat intelligence tự động.
Q28.
Which service provides compliance documentation and audit reports (e.g., SOC 2, PCI-DSS)?
Bản dịch tiếng Việt: Dịch vụ nào cung cấp tài liệu tuân thủ và báo cáo kiểm tra (ví dụ: SOC 2, PCI-DSS)?
A. AWS CloudTrail B. AWS Config C. AWS Artifact (provides compliance reports and agreements) D. AWS Systems Manager
Correct answer: C Bản dịch đáp án đúng: C. AWS Artifact (cung cấp các báo cáo và thỏa thuận tuân thủ)
🇬🇧 Explanation: AWS Artifact provides compliance documentation (SOC 2, PCI-DSS, ISO, etc.). Artifact gives self-service access to compliance reports and certifications such as SOC 2, PCI-DSS, and ISO 27001.
🇻🇳 Giải thích: AWS Artifact cung cấp tài liệu compliance (SOC 2, PCI-DSS, ISO, v.v.). Artifact cho phép tự truy cập các báo cáo và chứng nhận compliance như SOC 2, PCI-DSS, ISO 27001.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (CloudTrail) — Audit logging, not compliance docs / Ghi log kiểm toán, không phải tài liệu compliance.
- B (Config) — Compliance checking, not reports / Kiểm tra compliance, không phải báo cáo.
- D (Systems Manager) — Patch management, not compliance / Quản lý patch, không phải compliance.
🔑 Key Concept / Khái niệm cốt lõi: Artifact = compliance certification repository. / Artifact = kho chứng nhận compliance.
Q29. (Select TWO)
A company uses multiple AWS accounts and needs to enforce that certain AWS services cannot be used for compliance reasons. Which approach is best? (Select TWO)
Bản dịch tiếng Việt: Một công ty sử dụng nhiều tài khoản AWS và cần thực thi rằng không thể sử dụng một số dịch vụ AWS nhất định vì lý do tuân thủ. Cách tiếp cận nào là tốt nhất? (Chọn HAI)
A. AWS IAM policies (user-level restrictions) B. AWS Organizations with Service Control Policies (account-level restrictions) C. AWS CloudTrail (only logs violations) D. AWS Config (only detects misconfigurations) E. Individual security groups per account
Correct answer: A, B Bản dịch đáp án đúng: A. Chính sách AWS IAM (hạn chế ở cấp độ người dùng); B. Các tổ chức AWS có chính sách kiểm soát dịch vụ (hạn chế cấp tài khoản)
🇬🇧 Explanation: IAM policies restrict users; Service Control Policies restrict services for entire accounts. A is correct because IAM policies can restrict (deny) services per user/role. B is correct because Service Control Policies (SCPs) in Organizations restrict services at the account level.
🇻🇳 Giải thích: IAM policies hạn chế users; SCPs hạn chế services cho toàn bộ accounts. A đúng vì IAM policies có thể hạn chế (deny) services theo từng user/role. B đúng vì Service Control Policies (SCPs) trong Organizations hạn chế services ở cấp account.
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (CloudTrail) — Only logs violations, doesn't prevent / Chỉ ghi log vi phạm, không ngăn chặn.
- D (Config) — Detects violations, doesn't prevent / Phát hiện vi phạm, không ngăn chặn.
- E (Security Groups) — Network firewall, not service restrictions / Firewall mạng, không phải hạn chế service.
🔑 Key Concept / Khái niệm cốt lõi: SCPs = organizational service restrictions; IAM = identity-based restrictions. / SCPs = hạn chế service cấp tổ chức; IAM = hạn chế dựa trên identity.
Q30.
A regulated company must ensure encryption in transit for all API calls to AWS. Which feature provides this?
Bản dịch tiếng Việt: Công ty được quản lý phải đảm bảo mã hóa trong quá trình truyền tải tất cả các lệnh gọi API tới AWS. Tính năng nào cung cấp điều này?
A. AWS Shield B. AWS WAF C. HTTPS/TLS (enforced by default for AWS APIs) D. VPN (required for all AWS connections)
Correct answer: C Bản dịch đáp án đúng: C. HTTPS/TLS (được thực thi theo mặc định cho API AWS)
🇬🇧 Explanation: HTTPS/TLS is enforced by default for all AWS API calls (encryption in transit). All AWS APIs require HTTPS (TLS encryption), which protects data in transit between client and AWS with no configuration needed — it is automatic.
🇻🇳 Giải thích: HTTPS/TLS được enforce mặc định cho tất cả AWS API calls (mã hóa khi truyền). Mọi AWS API yêu cầu HTTPS (mã hóa TLS), bảo vệ dữ liệu khi truyền giữa client và AWS, không cần cấu hình — nó tự động.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Shield) — DDoS protection, not encryption / Bảo vệ DDoS, không phải mã hóa.
- B (WAF) — Web attack blocking, not encryption / Chặn tấn công web, không phải mã hóa.
- D (VPN required) — False; HTTPS is sufficient; VPN is optional for extra security / Sai; HTTPS là đủ; VPN là tùy chọn để tăng bảo mật.
🔑 Key Concept / Khái niệm cốt lõi: AWS = HTTPS/TLS by default. / AWS = HTTPS/TLS mặc định.
Q31.
A company needs multi-factor authentication (MFA) for its root AWS account. Which service manages this?
Bản dịch tiếng Việt: Một công ty cần xác thực đa yếu tố (MFA) cho tài khoản AWS gốc của mình. Dịch vụ nào quản lý việc này?
A. AWS CloudTrail B. AWS IAM (manages MFA devices and policies) C. AWS KMS D. AWS CloudWatch
Correct answer: B Bản dịch đáp án đúng: B. AWS IAM (quản lý các chính sách và thiết bị MFA)
🇬🇧 Explanation: IAM manages MFA devices (hardware or virtual authenticators) for root and users. As the identity and access management service, IAM supports MFA that can be virtual (Google Authenticator) or hardware (YubiKey), enabled in the IAM console.
🇻🇳 Giải thích: IAM quản lý MFA devices (authenticator phần cứng hoặc ảo) cho root và users. Là service quản lý identity và access, IAM hỗ trợ MFA dạng ảo (Google Authenticator) hoặc phần cứng (YubiKey), bật trong IAM console.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (CloudTrail) — Logs events, doesn't manage MFA / Ghi log sự kiện, không quản lý MFA.
- C (KMS) — Encryption keys, not authentication / Encryption keys, không phải xác thực.
- D (CloudWatch) — Monitoring, not authentication / Giám sát, không phải xác thực.
🔑 Key Concept / Khái niệm cốt lõi: IAM = MFA management. / IAM = quản lý MFA.
Q32. (Select TWO)
Which two services are most important for a comprehensive security posture in AWS? (Select TWO)
Bản dịch tiếng Việt: Hai dịch vụ nào quan trọng nhất để có được trạng thái bảo mật toàn diện trong AWS? (Chọn HAI)
A. AWS CloudTrail (audit logging) B. AWS IAM (access control) C. AWS CloudWatch (performance metrics) D. AWS Config (compliance monitoring) E. AWS Direct Connect (network acceleration)
Correct answer: A, B Bản dịch đáp án đúng: A. AWS CloudTrail (ghi nhật ký kiểm tra); B. AWS IAM (kiểm soát truy cập)
🇬🇧 Explanation: CloudTrail (audit) and IAM (access control) are foundational for security. A is correct because CloudTrail is the audit trail for accountability. B is correct because IAM is access control (the first line of defense). Together they enable "least privilege + audit."
🇻🇳 Giải thích: CloudTrail (audit) và IAM (access control) là nền tảng cho security. A đúng vì CloudTrail là audit trail cho trách nhiệm giải trình. B đúng vì IAM là kiểm soát truy cập (tuyến phòng thủ đầu tiên). Cùng nhau chúng tạo nên "least privilege + audit".
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (CloudWatch) — Monitoring, not security / Giám sát, không phải security.
- D (Config) — Compliance checking, important but not as foundational / Kiểm tra compliance, quan trọng nhưng không nền tảng bằng.
- E (Direct Connect) — Network, not security / Mạng, không phải security.
🔑 Key Concept / Khái niệm cốt lõi: Security foundation = IAM (prevent bad access) + CloudTrail (audit who accessed). / Nền tảng bảo mật = IAM (ngăn truy cập xấu) + CloudTrail (kiểm toán ai đã truy cập).
Q33.
A company must detect and respond to attempts to access resources without proper credentials. Which service provides this alert capability?
Bản dịch tiếng Việt: Công ty phải phát hiện và phản hồi các nỗ lực truy cập tài nguyên mà không có thông tin xác thực phù hợp. Dịch vụ nào cung cấp khả năng cảnh báo này?
A. AWS CloudTrail (logs the event) B. AWS GuardDuty (detects threats) C. AWS Config (tracks changes) D. All of the above
Correct answer: D Bản dịch đáp án đúng: D. Tất cả những điều trên
🇬🇧 Explanation: All three services detect unauthorized access attempts (CloudTrail logs, GuardDuty alerts, Config tracks). CloudTrail logs all API calls (including failed auth attempts), GuardDuty detects suspicious access patterns via ML, and Config can track IAM configuration changes — for comprehensive detection, use all three.
🇻🇳 Giải thích: Cả ba services phát hiện các nỗ lực truy cập trái phép. CloudTrail ghi log mọi API call (gồm cả nỗ lực xác thực thất bại), GuardDuty phát hiện các mẫu truy cập đáng ngờ bằng ML, và Config có thể theo dõi thay đổi cấu hình IAM — để phát hiện toàn diện, dùng cả ba.
❌ Why others are wrong / Vì sao đáp án khác sai:
- CloudTrail alone — just logs, no automatic alerting / Chỉ ghi log, không cảnh báo tự động.
- GuardDuty alone — detects threats but needs context / Phát hiện threat nhưng cần ngữ cảnh.
- Config alone — tracks config, not real-time access attempts / Theo dõi cấu hình, không phải nỗ lực truy cập real-time.
🔑 Key Concept / Khái niệm cốt lõi: Defense in depth = CloudTrail (logs) + GuardDuty (detects) + Config (tracks). / Phòng thủ theo lớp = CloudTrail (log) + GuardDuty (phát hiện) + Config (theo dõi).
Q34.
Which of the following best describes the difference between Security Groups and Network ACLs?
Bản dịch tiếng Việt: Điều nào sau đây mô tả đúng nhất sự khác biệt giữa Nhóm bảo mật và ACL mạng?
A. Security Groups and NACLs are identical B. Security Groups are stateful instance-level firewalls; NACLs are stateless subnet-level firewalls C. Security Groups protect databases; NACLs protect EC2 D. NACLs are more powerful than Security Groups
Correct answer: B Bản dịch đáp án đúng: B. Nhóm bảo mật là tường lửa cấp phiên bản có trạng thái; NACL là tường lửa cấp mạng con không trạng thái
🇬🇧 Explanation: Security Groups = stateful instance firewall; NACLs = stateless subnet firewall. Security Groups are stateful (remember return traffic), instance-level, and ALLOW-only; NACLs are stateless (require explicit return rules), subnet-level, and support ALLOW + DENY. Security Groups are easier; NACLs are more granular.
🇻🇳 Giải thích: Security Groups = firewall stateful cấp instance; NACLs = firewall stateless cấp subnet. Security Groups là stateful (nhớ traffic phản hồi), cấp instance, chỉ ALLOW; NACLs là stateless (cần rule phản hồi rõ ràng), cấp subnet, hỗ trợ ALLOW + DENY. Security Groups dễ dùng hơn; NACLs chi tiết hơn.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Identical) — No; fundamental differences / Không; khác biệt cơ bản.
- C (SG protects DB, NACL protects EC2) — False; both can protect both / Sai; cả hai đều bảo vệ được cả hai.
- D (NACLs more powerful) — Depends on use case; SGs are actually more commonly used / Tùy use case; SGs thực ra được dùng phổ biến hơn.
🔑 Key Concept / Khái niệm cốt lõi: SGs = default firewall (easier); NACLs = subnet-level firewall (explicit DENY). / SGs = firewall mặc định (dễ hơn); NACLs = firewall cấp subnet (có DENY rõ ràng).
Q35. (Select TWO)
A company is comparing Security Groups (stateful) vs NACLs (stateless). When would each be most appropriate? (Select TWO)
Bản dịch tiếng Việt: Một công ty đang so sánh Nhóm bảo mật (trạng thái) với NACL (không trạng thái). Khi nào thì thích hợp nhất? (Chọn HAI)
A. Security Groups for fine-grained instance-level traffic control B. NACLs for blanket subnet-level rules and explicit DENY C. Both protect against DDoS attacks D. Security Groups require manual state tracking E. NACLs are more commonly customized than default Security Groups
Correct answer: A, B Bản dịch đáp án đúng: A. Nhóm bảo mật để kiểm soát lưu lượng cấp phiên bản chi tiết; B. NACL dành cho các quy tắc cấp mạng con tổng thể và TỪ CHỐI rõ ràng
🇬🇧 Explanation: SGs for instance control; NACLs for subnet-level explicit deny rules. A is correct because SGs are perfect for instance-level rules (port, protocol, source IP). B is correct because NACLs are used for subnet-level blanket rules and explicit DENY (block entire subnets).
🇻🇳 Giải thích: SGs cho kiểm soát cấp instance; NACLs cho rule deny rõ ràng cấp subnet. A đúng vì SGs hoàn hảo cho rule cấp instance (port, protocol, source IP). B đúng vì NACLs dùng cho rule tổng quát cấp subnet và DENY rõ ràng (chặn cả subnet).
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (Both protect DDoS) — Neither directly; use Shield for DDoS / Cả hai đều không trực tiếp; dùng Shield cho DDoS.
- D (SGs require state tracking) — False; SGs are stateful (automatic) / Sai; SGs là stateful (tự động).
- E (NACLs more customized) — False; SGs are more commonly customized / Sai; SGs được tùy chỉnh phổ biến hơn.
🔑 Key Concept / Khái niệm cốt lõi: SGs = easy instance rules; NACLs = complex subnet rules with explicit DENY. / SGs = rule cấp instance dễ dùng; NACLs = rule cấp subnet phức tạp có DENY rõ ràng.
Q36.
A company wants to ensure that all data stored in S3 is encrypted and that encryption keys are managed by AWS. Which combination of services is appropriate?
Bản dịch tiếng Việt: Một công ty muốn đảm bảo rằng tất cả dữ liệu được lưu trữ trong S3 đều được mã hóa và các khóa mã hóa được quản lý bởi AWS. Sự kết hợp dịch vụ nào là phù hợp?
A. S3 with AWS KMS encryption (customer-managed or AWS-managed keys) B. S3 with CloudHSM only C. Direct Connect with onsite encryption D. RDS encryption only
Correct answer: A Bản dịch đáp án đúng: A. S3 với mã hóa AWS KMS (khóa do khách hàng quản lý hoặc do AWS quản lý)
🇬🇧 Explanation: S3 encryption with KMS (AWS-managed or customer-managed keys) is standard. S3 Server-Side Encryption with KMS (SSE-KMS) uses AWS-managed keys (easy, free) or customer-managed keys (more control, additional cost).
🇻🇳 Giải thích: Mã hóa S3 với KMS (AWS-managed hoặc customer-managed keys) là chuẩn. S3 Server-Side Encryption với KMS (SSE-KMS) dùng AWS-managed keys (dễ, miễn phí) hoặc customer-managed keys (kiểm soát nhiều hơn, tốn thêm chi phí).
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (CloudHSM only) — Overkill; KMS is sufficient / Quá mức cần thiết; KMS là đủ.
- C (Direct Connect + on-site) — Doesn't encrypt in S3; defeats cloud benefit / Không mã hóa trong S3; làm mất lợi ích cloud.
- D (RDS only) — Doesn't address S3 / Không giải quyết vấn đề S3.
🔑 Key Concept / Khái niệm cốt lõi: S3 encryption = KMS (AWS-managed by default). / Mã hóa S3 = KMS (mặc định AWS-managed).
Domain 3: Cloud Technology and Services (Q37–Q58)
Q37.
A startup needs to run a 5-minute task that processes an API request without maintaining running servers. Which compute service is most cost-effective?
Bản dịch tiếng Việt: Một công ty khởi nghiệp cần chạy một tác vụ kéo dài 5 phút để xử lý yêu cầu API mà không cần duy trì các máy chủ đang chạy. Dịch vụ điện toán nào tiết kiệm chi phí nhất?
A. EC2 On-Demand instances B. AWS Lambda (serverless, pay per invocation) C. Elastic Beanstalk D. AWS Batch
Correct answer: B Bản dịch đáp án đúng: B. AWS Lambda (không có máy chủ, trả tiền cho mỗi lệnh gọi)
🇬🇧 Explanation: Lambda = serverless, pay per invocation, perfect for short-lived tasks. A 5-minute task is ideal for Lambda: no server management, cost is invocations + GB-seconds (not hourly), and you pay only for execution time.
🇻🇳 Giải thích: Lambda = serverless, trả theo lần gọi, hoàn hảo cho tác vụ ngắn. Tác vụ 5 phút lý tưởng cho Lambda: không quản lý server, chi phí tính theo invocations + GB-seconds (không theo giờ), và chỉ trả cho thời gian thực thi.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (EC2) — Overkill; requires server management; costs 24/7 / Quá mức; cần quản lý server; tốn chi phí 24/7.
- C (Beanstalk) — PaaS, still requires managing instances / PaaS, vẫn phải quản lý instances.
- D (Batch) — Designed for long batch jobs, not 5-minute API responses / Dành cho batch job dài, không phải phản hồi API 5 phút.
🔑 Key Concept / Khái niệm cốt lõi: Lambda = event-driven, short-duration, serverless compute. / Lambda = compute serverless, hướng sự kiện, thời lượng ngắn.
Q38. (Select TWO)
A company is comparing EC2 and Lambda for their workload. Which statements correctly describe their differences? (Select TWO)
Bản dịch tiếng Việt: Một công ty đang so sánh EC2 và Lambda về khối lượng công việc của họ. Những tuyên bố nào mô tả chính xác sự khác biệt của họ? (Chọn HAI)
A. EC2 requires you to manage the underlying OS and patches B. Lambda automatically scales to handle traffic spikes C. EC2 always costs less than Lambda D. Lambda runs your code on EC2 instances that you must launch and patch first E. EC2 instances scale automatically with zero configuration and require no capacity planning
Correct answer: A, B Bản dịch đáp án đúng: A. EC2 yêu cầu bạn quản lý hệ điều hành và các bản vá cơ bản; B. Lambda tự động điều chỉnh quy mô để xử lý lưu lượng truy cập tăng đột biến
🇬🇧 Explanation: EC2 requires OS patching; Lambda auto-scales and has a 15-min limit. A is correct because with EC2 you manage OS patches (Shared Responsibility). B is correct because Lambda automatically scales (no capacity planning).
🇻🇳 Giải thích: EC2 yêu cầu OS patching; Lambda auto-scale và có giới hạn 15 phút. A đúng vì với EC2 bạn quản lý OS patches (Shared Responsibility). B đúng vì Lambda tự động scale (không cần lập kế hoạch capacity).
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (EC2 always cheaper) — False; Lambda is cheaper for spiky/low-volume workloads / Sai; Lambda rẻ hơn cho workload đột biến/khối lượng thấp.
- D (Lambda runs on EC2 you launch/patch first) — False; Lambda is serverless. AWS provisions and patches the underlying execution environment; you never launch or patch servers. / Sai; Lambda là serverless. AWS cấp phát và patch môi trường thực thi; bạn không bao giờ khởi chạy hay patch server.
- E (EC2 scales automatically with zero config, no capacity planning) — False; EC2 requires you to provision capacity and configure EC2 Auto Scaling. It is not automatic with zero configuration. / Sai; EC2 yêu cầu bạn cấp phát capacity và cấu hình EC2 Auto Scaling. Không tự động với cấu hình bằng không.
🔑 Key Concept / Khái niệm cốt lõi: EC2 = persistent, you manage everything; Lambda = event-driven, AWS manages. / EC2 = bền vững, bạn quản lý mọi thứ; Lambda = hướng sự kiện, AWS quản lý.
Q39.
A company needs to containerize an application and run it without managing EC2 instances. Which service handles container orchestration with minimal operational overhead?
Bản dịch tiếng Việt: Một công ty cần chứa một ứng dụng và chạy nó mà không cần quản lý các phiên bản EC2. Dịch vụ nào xử lý việc điều phối vùng chứa với chi phí vận hành tối thiểu?
A. EC2 with Docker B. Amazon ECS on EC2 (requires EC2 management) C. AWS Fargate (serverless containers) D. AWS Lightsail (limited container support)
Correct answer: C Bản dịch đáp án đúng: C. AWS Fargate (vùng chứa không có máy chủ)
🇬🇧 Explanation: AWS Fargate = serverless containers (no EC2 management needed). Fargate runs ECS without managing EC2 instances, with container orchestration handled by AWS and pricing similar to Lambda but for containers.
🇻🇳 Giải thích: AWS Fargate = serverless containers (không cần quản lý EC2). Fargate chạy ECS mà không cần quản lý EC2 instances, AWS lo phần điều phối container, giá tương tự Lambda nhưng dành cho container.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (EC2 with Docker) — Requires managing EC2 instances / Phải quản lý EC2 instances.
- B (ECS on EC2) — Still requires managing EC2 instances / Vẫn phải quản lý EC2 instances.
- D (Lightsail) — VPS, not container orchestration / VPS, không phải điều phối container.
🔑 Key Concept / Khái niệm cốt lõi: Fargate = serverless containers; ECS on EC2 = managed containers. / Fargate = container serverless; ECS trên EC2 = container được quản lý.
Q40.
An application requires persistent block storage attached to EC2 instances in the same Availability Zone. Which storage service is appropriate?
Bản dịch tiếng Việt: Một ứng dụng yêu cầu lưu trữ khối liên tục gắn liền với các phiên bản EC2 trong cùng Availability Zone. Dịch vụ lưu trữ nào phù hợp?
A. Amazon S3 (object storage, not block) B. Amazon EBS (block storage for EC2) C. Amazon EFS (shared file storage, cross-AZ) D. AWS Glacier (archive storage)
Correct answer: B Bản dịch đáp án đúng: B. Amazon EBS (lưu trữ khối cho EC2)
🇬🇧 Explanation: EBS = block storage attached to EC2 in the same AZ. EBS (Elastic Block Store) is persistent, survives instance restart, and must be in the same AZ as the EC2 instance.
🇻🇳 Giải thích: EBS = block storage gắn vào EC2 trong cùng AZ. EBS (Elastic Block Store) là bền vững, tồn tại qua restart instance, và phải nằm cùng AZ với EC2 instance.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (S3) — Object storage, not block; not attached to instances / Object storage, không phải block; không gắn vào instance.
- C (EFS) — Cross-AZ shared file storage; the question asks for block storage in a single AZ, so EFS does not fit / Shared file storage cross-AZ; câu hỏi cần block storage trong một AZ nên EFS không phù hợp.
- D (Glacier) — Archive storage, not for live EC2 attachment / Archive storage, không dùng gắn EC2 đang chạy.
🔑 Key Concept / Khái niệm cốt lõi: EBS = EC2 persistent block storage; S3 = object storage. / EBS = block storage bền vững cho EC2; S3 = object storage.
Q41. (Select TWO)
A company is comparing storage services for different use cases. Which pairings are correct? (Select TWO)
Bản dịch tiếng Việt: Một công ty đang so sánh các dịch vụ lưu trữ cho các trường hợp sử dụng khác nhau. Những cặp nào đúng? (Chọn HAI)
A. S3 for object storage with unlimited scalability B. EBS for persistent block storage attached to EC2 C. EBS for shared file storage mounted by many EC2 instances at once D. S3 for databases and transactional data E. EFS for static website hosting
Correct answer: A, B Bản dịch đáp án đúng: A. S3 để lưu trữ đối tượng với khả năng mở rộng không giới hạn; B. EBS để lưu trữ khối liên tục được gắn vào EC2
🇬🇧 Explanation: S3 for objects; EBS for EC2 block storage; EFS for shared file storage. A is correct because S3 is for object storage (unlimited, REST API). B is correct because EBS is for persistent block storage attached to EC2.
🇻🇳 Giải thích: S3 cho objects; EBS cho block storage của EC2; EFS cho shared file storage. A đúng vì S3 dùng cho object storage (không giới hạn, REST API). B đúng vì EBS dùng cho block storage bền vững gắn vào EC2.
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (EBS for shared file storage mounted by many instances) — False; a standard EBS volume attaches to a single EC2 instance. For shared file storage across many instances use EFS. / Sai; một EBS volume tiêu chuẩn gắn vào một EC2 instance. Để shared file storage qua nhiều instance dùng EFS.
- D (S3 for databases) — False; S3 is object storage, not structured/transactional data / Sai; S3 là object storage, không phải dữ liệu có cấu trúc/giao dịch.
- E (EFS for static website) — False; use S3 for static website hosting / Sai; dùng S3 để host static website.
🔑 Key Concept / Khái niệm cốt lõi: S3 = object; EBS = block (single instance); EFS = file (shared across instances). / S3 = object; EBS = block (một instance); EFS = file (chia sẻ nhiều instance).
Q42.
A startup stores 500 GB of infrequently accessed backup files. Which S3 storage class provides the lowest cost?
Bản dịch tiếng Việt: Một công ty khởi động lưu trữ 500 GB tệp sao lưu được truy cập không thường xuyên. Lớp lưu trữ S3 nào cung cấp chi phí thấp nhất?
A. S3 Standard B. S3 Standard-IA (Infrequent Access) C. S3 Glacier Flexible Retrieval (archive class) D. S3 One Zone-IA
Correct answer: C Bản dịch đáp án đúng: C. Truy xuất linh hoạt S3 Glacier (lớp lưu trữ)
🇬🇧 Explanation: S3 Glacier Flexible = cheapest storage for infrequent access (archive backup). Glacier Flexible is archive storage (cheapest), retrieval takes hours (acceptable for backups), and the cost per GB per month is the lowest tier.
🇻🇳 Giải thích: S3 Glacier Flexible = rẻ nhất cho dữ liệu ít truy cập (archive backup). Glacier Flexible là archive storage (rẻ nhất), truy xuất mất hàng giờ (chấp nhận được cho backup), và chi phí mỗi GB mỗi tháng là tầng thấp nhất.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (S3 Standard) — More expensive storage / Storage đắt hơn.
- B (S3 Standard-IA) — Better for monthly access; Standard-IA has retrieval fee / Tốt hơn cho truy cập hàng tháng; Standard-IA có phí truy xuất.
- D (One Zone-IA) — More expensive than Glacier; data loss risk / Đắt hơn Glacier; rủi ro mất dữ liệu.
🔑 Key Concept / Khái niệm cốt lõi: Glacier Flexible = cheapest archive (slow retrieval); Standard-IA = balance. / Glacier Flexible = archive rẻ nhất (truy xuất chậm); Standard-IA = cân bằng.
Q43.
A company needs to share a file system across multiple EC2 instances in different Availability Zones without managing NFS servers. Which service is best?
Bản dịch tiếng Việt: Một công ty cần chia sẻ hệ thống tệp trên nhiều phiên bản EC2 trong nhiều Availability Zone khác nhau mà không cần quản lý máy chủ NFS. Dịch vụ nào là tốt nhất?
A. Amazon EBS B. Amazon S3 C. Amazon EFS (managed NFS, shared across AZs) D. AWS Storage Gateway
Correct answer: C Bản dịch đáp án đúng: C. Amazon EFS (NFS được quản lý, chia sẻ trên các AZ)
🇬🇧 Explanation: EFS = managed NFS, shared across multiple EC2 instances, cross-AZ. EFS (Elastic File System, NFS protocol) is shared by multiple EC2 instances, works cross-AZ (unlike EBS), and needs no server management.
🇻🇳 Giải thích: EFS = managed NFS, chia sẻ qua nhiều EC2 instances, cross-AZ. EFS (Elastic File System, giao thức NFS) được chia sẻ bởi nhiều EC2 instances, hoạt động cross-AZ (khác EBS), và không cần quản lý server.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (EBS) — Single instance only, same AZ / Chỉ một instance, cùng AZ.
- B (S3) — Object storage, not file system; requires application-level access / Object storage, không phải file system; cần truy cập ở tầng ứng dụng.
- D (Storage Gateway) — Hybrid, not purely cloud / Hybrid, không thuần cloud.
🔑 Key Concept / Khái niệm cốt lõi: EFS = shared file storage for multiple EC2 instances. / EFS = shared file storage cho nhiều EC2 instances.
Q44. (Select TWO)
A company is choosing between RDS and DynamoDB for their database. Which statements are accurate? (Select TWO)
Bản dịch tiếng Việt: Một công ty đang lựa chọn giữa RDS và DynamoDB cho cơ sở dữ liệu của họ. Những tuyên bố nào là chính xác? (Chọn HAI)
A. RDS is a relational database supporting SQL B. DynamoDB is a NoSQL database for key-value data C. RDS and DynamoDB are interchangeable D. DynamoDB requires patching the database engine E. RDS is AWS-managed but customer chooses engine (MySQL, PostgreSQL, Oracle)
Correct answer: A, B Bản dịch đáp án đúng: A. RDS là cơ sở dữ liệu quan hệ hỗ trợ SQL; B. DynamoDB là cơ sở dữ liệu NoSQL dành cho dữ liệu khóa-giá trị
🇬🇧 Explanation: RDS = SQL relational; DynamoDB = NoSQL key-value. A is correct because RDS supports SQL (MySQL, PostgreSQL, Oracle, SQL Server). B is correct because DynamoDB is NoSQL (key-value, no complex joins).
🇻🇳 Giải thích: RDS = quan hệ SQL; DynamoDB = NoSQL key-value. A đúng vì RDS hỗ trợ SQL (MySQL, PostgreSQL, Oracle, SQL Server). B đúng vì DynamoDB là NoSQL (key-value, không có join phức tạp).
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (Interchangeable) — No; fundamentally different models / Không; mô hình khác nhau cơ bản.
- D (DynamoDB patching) — False; AWS manages patching / Sai; AWS quản lý patching.
- E (RDS customer patches) — False; AWS patches RDS engine (but you patch EC2 OS) / Sai; AWS patch RDS engine (nhưng bạn patch OS của EC2).
🔑 Key Concept / Khái niệm cốt lõi: RDS = SQL; DynamoDB = NoSQL. / RDS = SQL; DynamoDB = NoSQL.
Q45.
A company stores structured customer data with frequent joins and transactions. Which database service is most appropriate?
Bản dịch tiếng Việt: Một công ty lưu trữ dữ liệu khách hàng có cấu trúc với các lần tham gia và giao dịch thường xuyên. Dịch vụ cơ sở dữ liệu nào là phù hợp nhất?
A. Amazon DynamoDB (NoSQL, no joins) B. Amazon RDS (relational database with SQL) C. Amazon Redshift (data warehouse, analytics) D. Amazon ElastiCache (in-memory cache)
Correct answer: B Bản dịch đáp án đúng: B. Amazon RDS (cơ sở dữ liệu quan hệ với SQL)
🇬🇧 Explanation: Relational data with joins and transactions = RDS (SQL). RDS is a relational database (ACID transactions) that supports complex queries with JOINs; customer orders, inventory, and billing are relational use cases.
🇻🇳 Giải thích: Dữ liệu quan hệ với joins và transactions = RDS (SQL). RDS là cơ sở dữ liệu quan hệ (giao dịch ACID) hỗ trợ truy vấn phức tạp với JOIN; đơn hàng, kho hàng, hóa đơn là các use case quan hệ.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (DynamoDB) — No joins; denormalized data model / Không có join; mô hình dữ liệu phi chuẩn hóa.
- C (Redshift) — Data warehouse (OLAP), not transactional (OLTP) / Data warehouse (OLAP), không phải giao dịch (OLTP).
- D (ElastiCache) — Caching, not primary storage / Caching, không phải storage chính.
🔑 Key Concept / Khái niệm cốt lõi: RDS = OLTP (transactional); Redshift = OLAP (analytical). / RDS = OLTP (giao dịch); Redshift = OLAP (phân tích).
Q46.
A company needs to perform analytics on billions of rows of data and generate executive dashboards. Which service is most efficient?
Bản dịch tiếng Việt: Một công ty cần thực hiện phân tích trên hàng tỷ hàng dữ liệu và tạo bảng thông tin điều hành. Dịch vụ nào hiệu quả nhất?
A. Amazon RDS (OLTP, transactional) B. Amazon Redshift (data warehouse for OLAP/analytics) C. Amazon DynamoDB (NoSQL, not for analytics) D. Amazon ElastiCache (caching only)
Correct answer: B Bản dịch đáp án đúng: B. Amazon Redshift (kho dữ liệu cho OLAP/phân tích)
🇬🇧 Explanation: Redshift = data warehouse optimized for analytics on massive datasets. Redshift is a columnar data warehouse optimized for large analytical queries (scanning billions of rows); executive dashboards are a BI analytics use case.
🇻🇳 Giải thích: Redshift = data warehouse tối ưu cho phân tích trên tập dữ liệu khổng lồ. Redshift là data warehouse dạng cột (columnar) tối ưu cho truy vấn phân tích lớn (quét hàng tỷ dòng); dashboard điều hành là use case phân tích BI.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (RDS) — OLTP (transactional), not analytics / OLTP (giao dịch), không phải phân tích.
- C (DynamoDB) — Not designed for analytics / Không thiết kế cho phân tích.
- D (ElastiCache) — Caching, not analytics / Caching, không phải phân tích.
🔑 Key Concept / Khái niệm cốt lõi: Redshift = BI analytics warehouse. / Redshift = data warehouse phân tích BI.
Q47. (Select TWO)
A company is comparing ALB (Application Load Balancer) and NLB (Network Load Balancer). Which correctly describes their use cases? (Select TWO)
Bản dịch tiếng Việt: Một công ty đang so sánh ALB (Cân bằng tải ứng dụng) và NLB (Cân bằng tải mạng). Điều nào mô tả chính xác trường hợp sử dụng của họ? (Chọn HAI)
A. ALB is Layer 7, suitable for HTTP/HTTPS routing rules B. NLB is Layer 4, designed for extreme performance and UDP traffic C. ALB and NLB are identical D. NLB is recommended for all web applications E. ALB operates at Layer 4 and cannot route based on HTTP paths or hostnames
Correct answer: A, B Bản dịch đáp án đúng: A. ALB là Lớp 7, phù hợp với quy tắc định tuyến HTTP/HTTPS; B. NLB là Lớp 4, được thiết kế cho hiệu suất cực cao và lưu lượng UDP
🇬🇧 Explanation: ALB = Layer 7 HTTP routing; NLB = Layer 4 extreme performance. A is correct because ALB (Application Load Balancer) operates at Layer 7 with content-based routing. B is correct because NLB (Network Load Balancer) operates at Layer 4 (TCP/UDP) with ultra-high performance.
🇻🇳 Giải thích: ALB = định tuyến HTTP Layer 7; NLB = hiệu năng cực cao Layer 4. A đúng vì ALB (Application Load Balancer) hoạt động ở Layer 7 với định tuyến theo nội dung. B đúng vì NLB (Network Load Balancer) hoạt động ở Layer 4 (TCP/UDP) với hiệu năng cực cao.
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (Identical) — False; they operate at different layers / Sai; chúng hoạt động ở các tầng khác nhau.
- D (NLB for all web apps) — False; ALB is the standard choice for HTTP/HTTPS web traffic / Sai; ALB là lựa chọn chuẩn cho traffic web HTTP/HTTPS.
- E (ALB is Layer 4 and cannot route by path/hostname) — False; ALB is a Layer 7 load balancer and DOES route by HTTP path and hostname / Sai; ALB là load balancer Layer 7 và CÓ định tuyến theo HTTP path và hostname.
🔑 Key Concept / Khái niệm cốt lõi: ALB = Layer 7 (HTTP/HTTPS); NLB = Layer 4 (TCP/UDP). / ALB = Layer 7 (HTTP/HTTPS); NLB = Layer 4 (TCP/UDP).
Q48.
A company needs to distribute traffic across EC2 instances based on HTTP path and hostname. Which load balancer is appropriate?
Bản dịch tiếng Việt: Một công ty cần phân phối lưu lượng truy cập trên các phiên bản EC2 dựa trên đường dẫn HTTP và tên máy chủ. Cân bằng tải nào phù hợp?
A. Classic Load Balancer (CLB) — Layer 4 only B. Network Load Balancer (NLB) — Layer 4 extreme performance C. Application Load Balancer (ALB) — Layer 7 with advanced routing D. Gateway Load Balancer (GLB) — for appliance scaling
Correct answer: C Bản dịch đáp án đúng: C. Cân bằng tải ứng dụng (ALB) — Lớp 7 với tính năng định tuyến nâng cao
🇬🇧 Explanation: ALB = Layer 7, supports HTTP path and hostname-based routing. As an Application Load Balancer (Layer 7), ALB supports hostname routing (example.com vs api.example.com), path routing (/api/users vs /api/orders), and HTTP header-based routing.
🇻🇳 Giải thích: ALB = Layer 7, hỗ trợ định tuyến theo HTTP path và hostname. Là Application Load Balancer (Layer 7), ALB hỗ trợ định tuyến theo hostname (example.com vs api.example.com), theo path (/api/users vs /api/orders) và theo HTTP header.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (CLB) — Layer 4 only, no advanced routing / Chỉ Layer 4, không có định tuyến nâng cao.
- B (NLB) — Layer 4, no HTTP routing / Layer 4, không định tuyến HTTP.
- D (GLB) — For appliance scaling, not web routing / Dùng để scale appliance, không phải định tuyến web.
🔑 Key Concept / Khái niệm cốt lõi: ALB = smart routing; NLB = dumb but fast. / ALB = định tuyến thông minh; NLB = đơn giản nhưng nhanh.
Q49. (Select THREE)
A company is evaluating database services for different scenarios. Which pairings are correct? (Select THREE)
Bản dịch tiếng Việt: Một công ty đang đánh giá các dịch vụ cơ sở dữ liệu cho các tình huống khác nhau. Những cặp nào đúng? (Chọn BA)
A. RDS for relational data with SQL queries B. Aurora for AWS-optimized database with MySQL/PostgreSQL compatibility C. DynamoDB for unstructured key-value data at scale D. Redshift for storing and rotating database credentials and secrets E. ElastiCache for persistent data storage
Correct answer: A, B, C Bản dịch đáp án đúng: A. RDS cho dữ liệu quan hệ với truy vấn SQL; B. Aurora cho cơ sở dữ liệu được tối ưu hóa AWS có khả năng tương thích với MySQL/PostgreSQL; C. DynamoDB cho dữ liệu khóa-giá trị phi cấu trúc trên quy mô lớn
🇬🇧 Explanation: RDS/Aurora = relational; DynamoDB = key-value. A is correct because RDS is a relational database with SQL queries. B is correct because Aurora is an AWS relational DB with MySQL/PostgreSQL compatibility. C is correct because DynamoDB handles unstructured key-value data at scale. (Select THREE.)
🇻🇳 Giải thích: RDS/Aurora = quan hệ; DynamoDB = key-value. A đúng vì RDS là cơ sở dữ liệu quan hệ với truy vấn SQL. B đúng vì Aurora là DB quan hệ của AWS tương thích MySQL/PostgreSQL. C đúng vì DynamoDB xử lý dữ liệu key-value phi cấu trúc ở quy mô lớn. (Chọn BA đáp án.)
❌ Why others are wrong / Vì sao đáp án khác sai:
- D (Redshift for storing/rotating credentials) — FALSE; Redshift is a data warehouse for analytics, not a secrets store. Use AWS Secrets Manager to store and rotate database credentials. / SAI; Redshift là data warehouse cho phân tích, không phải nơi lưu secrets. Dùng AWS Secrets Manager để lưu và rotate database credentials.
- E (ElastiCache for persistent storage) — FALSE; ElastiCache is an in-memory cache (volatile), not durable primary storage. / SAI; ElastiCache là cache trong bộ nhớ (dễ mất), không phải storage chính bền vững.
🔑 Key Concept / Khái niệm cốt lõi: Database service selection depends on data model (relational vs NoSQL vs analytical); credential storage/rotation belongs to Secrets Manager. / Việc chọn database service phụ thuộc vào mô hình dữ liệu (quan hệ vs NoSQL vs phân tích); lưu/rotate credential thuộc về Secrets Manager.
Q50.
An application serves static images to millions of users globally and needs minimal latency. Which service provides global content delivery?
Bản dịch tiếng Việt: Một ứng dụng phục vụ hình ảnh tĩnh cho hàng triệu người dùng trên toàn cầu và cần độ trễ tối thiểu. Dịch vụ nào cung cấp khả năng phân phối nội dung toàn cầu?
A. Amazon S3 alone B. Amazon CloudFront (CDN with edge locations) C. Amazon Route 53 (DNS only) D. AWS Direct Connect (dedicated connection)
Correct answer: B Bản dịch đáp án đúng: B. Amazon CloudFront (CDN với các vị trí biên)
🇬🇧 Explanation: CloudFront (CDN) caches content at edge locations globally for low latency. CloudFront is a Content Delivery Network whose edge locations are close to users worldwide, caching static/dynamic content — perfect for images served to millions.
🇻🇳 Giải thích: CloudFront (CDN) cache nội dung tại edge locations toàn cầu để giảm latency. CloudFront là Content Delivery Network có edge locations gần người dùng khắp thế giới, cache nội dung tĩnh/động — hoàn hảo cho hình ảnh phục vụ hàng triệu người.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (S3 alone) — High latency for users far away / Latency cao cho người dùng ở xa.
- C (Route 53) — DNS only, doesn't cache content / Chỉ DNS, không cache nội dung.
- D (Direct Connect) — Dedicated connection, not CDN / Kết nối riêng, không phải CDN.
🔑 Key Concept / Khái niệm cốt lõi: CloudFront = global content delivery (low latency). / CloudFront = phân phối nội dung toàn cầu (latency thấp).
Q51.
A company needs to connect its on-premises data center to AWS with a dedicated physical connection for high bandwidth and consistent network performance. Which service is appropriate?
Bản dịch tiếng Việt: Một công ty cần kết nối trung tâm dữ liệu tại chỗ của mình với AWS bằng kết nối vật lý chuyên dụng để có băng thông cao và hiệu suất mạng ổn định. Dịch vụ nào phù hợp?
A. Site-to-Site VPN (encrypted, over internet) B. AWS Direct Connect (dedicated physical connection) C. AWS Batch (compute service, not networking) D. CloudFront (CDN, not data center connection)
Correct answer: B Bản dịch đáp án đúng: B. AWS Direct Connect (kết nối vật lý chuyên dụng)
🇬🇧 Explanation: Direct Connect = dedicated physical connection to AWS (not internet). It is a dedicated network connection (1 Gbps or 10 Gbps) that bypasses the public internet for consistent performance, is perfect for high-bandwidth and low-latency needs, and requires lead time to establish.
🇻🇳 Giải thích: Direct Connect = kết nối vật lý riêng tới AWS (không qua internet). Đây là kết nối mạng riêng (1 Gbps hoặc 10 Gbps) bỏ qua internet công cộng để có hiệu năng ổn định, hoàn hảo cho nhu cầu băng thông cao và latency thấp, và cần thời gian chuẩn bị để thiết lập.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (VPN) — Over public internet (variable latency) / Qua internet công cộng (latency biến động).
- C (Batch) — Compute service, not networking / Service compute, không phải networking.
- D (CloudFront) — CDN, not data center connection / CDN, không phải kết nối data center.
🔑 Key Concept / Khái niệm cốt lõi: Direct Connect = dedicated; VPN = encrypted internet connection. / Direct Connect = riêng; VPN = kết nối internet được mã hóa.
Q52. (Select TWO)
A company is comparing VPN and Direct Connect for hybrid connectivity. Which statements are correct? (Select TWO)
Bản dịch tiếng Việt: Một công ty đang so sánh VPN và Direct Connect về kết nối lai. Những phát biểu nào đúng? (Chọn HAI)
A. VPN uses the public internet with encryption B. Direct Connect provides a dedicated physical circuit C. VPN is more expensive than Direct Connect D. Direct Connect does not require AWS Direct Connect LOA-CFA documentation E. Both VPN and Direct Connect provide private connectivity to AWS
Correct answer: A, B Bản dịch đáp án đúng: A. VPN sử dụng internet công cộng có mã hóa; B. Direct Connect cung cấp một mạch vật lý chuyên dụng
🇬🇧 Explanation: VPN = encrypted internet connection; Direct Connect = dedicated physical. A is correct because VPN uses the public internet with encryption. B is correct because Direct Connect provides a dedicated physical circuit (not internet).
🇻🇳 Giải thích: VPN = kết nối internet được mã hóa; Direct Connect = kết nối vật lý riêng. A đúng vì VPN dùng internet công cộng có mã hóa. B đúng vì Direct Connect cung cấp mạch vật lý riêng (không phải internet).
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (VPN more expensive) — False; Direct Connect is MORE expensive / Sai; Direct Connect ĐẮT hơn.
- D (Direct Connect no LOA-CFA) — False; you need LOA-CFA letter / Sai; bạn cần thư LOA-CFA.
- E (Both are private) — Not exactly; VPN goes over internet (encrypted), Direct Connect is physical / Không hẳn; VPN đi qua internet (mã hóa), Direct Connect là vật lý.
🔑 Key Concept / Khái niệm cốt lõi: Both provide connectivity, but Direct Connect is more expensive/reliable. / Cả hai đều cung cấp kết nối, nhưng Direct Connect đắt hơn/ổn định hơn.
Q53.
A company needs to send asynchronous messages between microservices with guaranteed delivery. Which service is appropriate?
Bản dịch tiếng Việt: Một công ty cần gửi tin nhắn không đồng bộ giữa các vi dịch vụ với việc gửi tin nhắn được đảm bảo. Dịch vụ nào phù hợp?
A. Amazon SNS (pub/sub notifications, not guaranteed delivery) B. Amazon SQS (message queue with guaranteed delivery) C. Amazon EventBridge (event bus, more complex routing) D. AWS Lambda (not a messaging service)
Correct answer: B Bản dịch đáp án đúng: B. Amazon SQS (hàng đợi tin nhắn với việc gửi được đảm bảo)
🇬🇧 Explanation: SQS = message queue with guaranteed delivery and persistence. SQS (Simple Queue Service, FIFO or Standard) keeps messages in the queue until processed, guarantees delivery (at least once), and decouples producers and consumers.
🇻🇳 Giải thích: SQS = message queue với đảm bảo gửi và lưu trữ. SQS (Simple Queue Service, FIFO hoặc Standard) giữ message trong queue đến khi được xử lý, đảm bảo gửi (ít nhất một lần) và tách rời producer với consumer.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (SNS) — Pub/sub, no persistence, best-effort delivery / Pub/sub, không lưu trữ, gửi theo best-effort.
- C (EventBridge) — Event bus, more complex routing / Event bus, định tuyến phức tạp hơn.
- D (Lambda) — Compute, not messaging / Compute, không phải messaging.
🔑 Key Concept / Khái niệm cốt lõi: SQS = persistent queue (guaranteed delivery); SNS = broadcast (best effort). / SQS = queue bền vững (đảm bảo gửi); SNS = broadcast (best effort).
Q54. (Select TWO)
A company is comparing SQS and SNS for their messaging needs. Which correctly describes their use cases? (Select TWO)
Bản dịch tiếng Việt: Một công ty đang so sánh SQS và SNS về nhu cầu nhắn tin của họ. Điều nào mô tả chính xác trường hợp sử dụng của họ? (Chọn HAI)
A. SQS is a queue (1-to-1 producer to consumer, guaranteed delivery) B. SNS is pub/sub (1-to-many broadcast, no guaranteed storage) C. SQS and SNS are interchangeable D. SNS stores messages for later retrieval E. SQS broadcasts to multiple subscribers
Correct answer: A, B Bản dịch đáp án đúng: A. SQS là một hàng đợi (nhà sản xuất 1-1 đến người tiêu dùng, giao hàng được đảm bảo); B. SNS là pub/sub (phát sóng 1-nhiều, không có dung lượng lưu trữ được đảm bảo)
🇬🇧 Explanation: SQS = 1-to-1 queue; SNS = 1-to-many pub/sub. A is correct because SQS is a queue (producer sends, consumer receives, message stored). B is correct because SNS is pub/sub (publisher sends, multiple subscribers receive, no storage).
🇻🇳 Giải thích: SQS = queue 1-tới-1; SNS = pub/sub 1-tới-nhiều. A đúng vì SQS là queue (producer gửi, consumer nhận, message được lưu). B đúng vì SNS là pub/sub (publisher gửi, nhiều subscriber nhận, không lưu trữ).
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (Interchangeable) — No; fundamentally different patterns / Không; mô hình khác nhau cơ bản.
- D (SNS stores messages) — False; SNS doesn't persist / Sai; SNS không lưu trữ.
- E (SQS broadcasts) — False; SQS is queue (1-to-1) / Sai; SQS là queue (1-tới-1).
🔑 Key Concept / Khái niệm cốt lõi: SQS = queue (persistent, 1-to-1); SNS = pub/sub (transient, 1-to-many). / SQS = queue (bền vững, 1-tới-1); SNS = pub/sub (tạm thời, 1-tới-nhiều).
Q55.
A company wants to automatically trigger Lambda functions when files are uploaded to S3. Which service orchestrates this workflow?
Bản dịch tiếng Việt: Một công ty muốn tự động kích hoạt các chức năng Lambda khi tệp được tải lên S3. Dịch vụ nào sắp xếp quy trình làm việc này?
A. Amazon SQS (queuing, not triggering) B. AWS EventBridge (event bus with S3 integration) or S3 event notifications C. Amazon SNS (notifications, not automation) D. AWS Systems Manager (not for S3 integration)
Correct answer: B Bản dịch đáp án đúng: B. AWS EventBridge (bus sự kiện có tích hợp S3) hoặc thông báo sự kiện S3
🇬🇧 Explanation: EventBridge or S3 event notifications trigger Lambda when files are uploaded. S3 can directly trigger Lambda on object upload, EventBridge provides more advanced event routing, and both solve the "S3 upload → trigger function" use case.
🇻🇳 Giải thích: EventBridge hoặc S3 event notifications trigger Lambda khi có file upload. S3 có thể trigger Lambda trực tiếp khi upload object, EventBridge cung cấp định tuyến sự kiện nâng cao hơn, và cả hai đều giải quyết use case "S3 upload → trigger function".
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (SQS) — Queuing, not triggering (requires polling) / Xếp hàng, không phải trigger (cần polling).
- C (SNS) — Notifications, not automation / Thông báo, không phải tự động hóa.
- D (Systems Manager) — Patch management, not S3 integration / Quản lý patch, không tích hợp S3.
🔑 Key Concept / Khái niệm cốt lõi: S3 events → Lambda (direct trigger); S3 → SNS → Lambda (indirect); S3 → EventBridge → Lambda (advanced). / S3 events → Lambda (trigger trực tiếp); S3 → SNS → Lambda (gián tiếp); S3 → EventBridge → Lambda (nâng cao).
Q56.
A company needs to store data that changes frequently and must query it by primary key with single-digit millisecond latency. Which database is best?
Bản dịch tiếng Việt: Một công ty cần lưu trữ dữ liệu thay đổi thường xuyên và phải truy vấn dữ liệu đó bằng khóa chính với độ trễ một phần nghìn giây. Cơ sở dữ liệu nào là tốt nhất?
A. Amazon RDS (SQL, higher latency for key-value) B. Amazon DynamoDB (NoSQL, optimized for key-value access) C. Amazon S3 (object storage, not for frequent queries) D. Amazon Redshift (data warehouse, not transactional)
Correct answer: B Bản dịch đáp án đúng: B. Amazon DynamoDB (NoSQL, được tối ưu hóa để truy cập khóa-giá trị)
🇬🇧 Explanation: DynamoDB = optimized for key-value access with single-digit ms latency. DynamoDB is a NoSQL key-value database designed for fast, consistent low-latency access, with a serverless option available — perfect for "frequent, fast queries by key."
🇻🇳 Giải thích: DynamoDB = tối ưu cho truy cập key-value với latency vài mili-giây. DynamoDB là cơ sở dữ liệu NoSQL key-value thiết kế cho truy cập nhanh, nhất quán, latency thấp, có tùy chọn serverless — hoàn hảo cho "truy vấn theo key thường xuyên và nhanh".
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (RDS) — Higher latency for key-value (designed for complex queries) / Latency cao hơn cho key-value (thiết kế cho truy vấn phức tạp).
- C (S3) — Object storage, not for frequent queries / Object storage, không dành cho truy vấn thường xuyên.
- D (Redshift) — Analytics, not transactional / Phân tích, không phải giao dịch.
🔑 Key Concept / Khái niệm cốt lõi: DynamoDB = fast key-value NoSQL; RDS = complex relational queries. / DynamoDB = NoSQL key-value nhanh; RDS = truy vấn quan hệ phức tạp.
Q57. (Select TWO)
A company is choosing between Glacier and S3 Standard for long-term archival. Which statements are accurate? (Select TWO)
Bản dịch tiếng Việt: Một công ty đang lựa chọn giữa Glacier và S3 Standard để lưu trữ lâu dài. Những tuyên bố nào là chính xác? (Chọn HAI)
A. S3 Glacier provides cheaper storage with slower retrieval times B. S3 Standard has higher storage cost but immediate access C. Glacier is suitable for data accessed monthly D. Standard is suitable for backup data accessed annually E. S3 Glacier offers lower-latency, instant retrieval than S3 Standard
Correct answer: A, B Bản dịch đáp án đúng: A. S3 Glacier cung cấp dung lượng lưu trữ rẻ hơn với thời gian truy xuất chậm hơn; B. S3 Standard có chi phí lưu trữ cao hơn nhưng truy cập ngay lập tức
🇬🇧 Explanation: Glacier = cheap archive (slow retrieval); S3 Standard = expensive but fast. A is correct because Glacier is cheaper storage with slower retrieval (good for archives). B is correct because S3 Standard has higher storage cost but immediate access.
🇻🇳 Giải thích: Glacier = archive rẻ (truy xuất chậm); S3 Standard = đắt nhưng nhanh. A đúng vì Glacier là storage rẻ hơn với truy xuất chậm hơn (tốt cho archive). B đúng vì S3 Standard có chi phí lưu trữ cao hơn nhưng truy cập ngay lập tức.
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (Glacier for monthly access) — False; for monthly access use S3 Standard-IA, not Glacier / Sai; truy cập hàng tháng nên dùng S3 Standard-IA, không phải Glacier.
- D (Standard for annual access) — False; for annually-accessed data use Glacier (cheaper archive) / Sai; dữ liệu truy cập hàng năm nên dùng Glacier (archive rẻ hơn).
- E (Glacier offers lower-latency, instant retrieval than Standard) — False; Glacier Flexible Retrieval is slower (minutes to hours) than S3 Standard's immediate access / Sai; Glacier Flexible Retrieval chậm hơn (vài phút đến vài giờ) so với truy cập tức thì của S3 Standard.
🔑 Key Concept / Khái niệm cốt lõi: Glacier = cheapest (slow retrieval); Standard = fastest (expensive); IA = balance. / Glacier = rẻ nhất (truy xuất chậm); Standard = nhanh nhất (đắt); IA = cân bằng.
Q58.
A company needs to monitor application performance, collect logs, and set alarms for metrics. Which service is primarily responsible?
Bản dịch tiếng Việt: Công ty cần giám sát hiệu suất ứng dụng, thu thập nhật ký và đặt cảnh báo cho các số liệu. Dịch vụ nào chịu trách nhiệm chính?
A. AWS CloudTrail (API audit logs) B. AWS CloudWatch (monitoring, logs, alarms) C. AWS Config (configuration compliance) D. AWS Systems Manager (patch management)
Correct answer: B Bản dịch đáp án đúng: B. AWS CloudWatch (giám sát, nhật ký, cảnh báo)
🇬🇧 Explanation: CloudWatch = monitoring, logs, metrics, and alarms. CloudWatch is an integrated monitoring and logging service covering metrics (CPU, memory, custom), logs (application, system), and alarms (trigger actions on thresholds).
🇻🇳 Giải thích: CloudWatch = giám sát, logs, metrics và alarms. CloudWatch là service giám sát và logging tích hợp, bao gồm metrics (CPU, memory, tùy chỉnh), logs (ứng dụng, hệ thống) và alarms (kích hoạt hành động theo ngưỡng).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (CloudTrail) — API audit logs, not performance monitoring / Log kiểm toán API, không phải giám sát hiệu năng.
- C (Config) — Configuration compliance, not metrics / Tuân thủ cấu hình, không phải metrics.
- D (Systems Manager) — Patch management, not monitoring / Quản lý patch, không phải giám sát.
🔑 Key Concept / Khái niệm cốt lõi: CloudWatch = observability (metrics, logs, alarms). / CloudWatch = khả năng quan sát (metrics, logs, alarms).
Domain 4: Billing, Pricing, and Support (Q59–Q65)
Q59.
A company runs a stable production database with predictable usage for 3 years. Which EC2 pricing model offers the most cost savings?
Bản dịch tiếng Việt: Một công ty vận hành cơ sở dữ liệu sản xuất ổn định với mức sử dụng có thể dự đoán được trong 3 năm. Mô hình định giá EC2 nào giúp tiết kiệm chi phí nhất?
A. On-Demand (highest cost) B. Spot Instances (interruptible, not for production) C. Reserved Instances 3-year commitment (up to 72% savings) D. Dedicated Hosts (most expensive)
Correct answer: C Bản dịch đáp án đúng: C. Phiên bản dự trữ Cam kết 3 năm (tiết kiệm tới 72%)
🇬🇧 Explanation: Reserved Instances (3-year) = up to 72% savings for stable workloads. A stable database has predictable load, a 3-year RI gives the biggest discount (72% vs On-Demand), and committing upfront produces the savings.
🇻🇳 Giải thích: Reserved Instances (3 năm) = tiết kiệm tới 72% cho workload ổn định. Database ổn định có tải dự đoán được, RI 3 năm cho mức giảm giá lớn nhất (72% so với On-Demand), và cam kết trả trước tạo ra khoản tiết kiệm.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (On-Demand) — Highest cost / Chi phí cao nhất.
- B (Spot) — Can be interrupted (not suitable for production DB) / Có thể bị gián đoạn (không phù hợp cho DB production).
- D (Dedicated Hosts) — Most expensive (licensing only) / Đắt nhất (chỉ dùng cho licensing).
🔑 Key Concept / Khái niệm cốt lõi: Production stable workload = Reserved Instances. / Workload production ổn định = Reserved Instances.
Q60. (Select TWO)
A company is comparing Reserved Instances, Savings Plans, and Spot Instances. Which statements are correct? (Select TWO)
Bản dịch tiếng Việt: Một công ty đang so sánh các Phiên bản dự trữ, Savings Plans và Spot Instances. Những phát biểu nào đúng? (Chọn HAI)
A. Reserved Instances commit to specific instance type and region B. Savings Plans provide flexibility across instance types and regions C. Spot Instances are the cheapest but can be interrupted D. Reserved Instances have no upfront cost E. Savings Plans are more expensive than Reserved Instances
Correct answer: A, B Bản dịch đáp án đúng: A. Phiên bản dự trữ cam kết với loại phiên bản và khu vực cụ thể; B. Savings Plans mang đến sự linh hoạt giữa các loại phiên bản và khu vực
🇬🇧 Explanation: Reserved Instances commit to type/region; Savings Plans are flexible. A is correct because RIs are specific to instance type and region. B is correct because Savings Plans work across instance types and regions (more flexibility).
🇻🇳 Giải thích: Reserved Instances cam kết theo type/region; Savings Plans linh hoạt. A đúng vì RIs gắn với instance type và region cụ thể. B đúng vì Savings Plans áp dụng xuyên các instance type và region (linh hoạt hơn).
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (RIs cheaper than SP) — Depends; SP is often better value / Tùy; SP thường có giá trị tốt hơn.
- D (RIs no upfront) — False; RIs require upfront payment / Sai; RIs yêu cầu trả trước.
- E (SP more expensive) — False; SP is often cheaper due to flexibility / Sai; SP thường rẻ hơn nhờ linh hoạt.
🔑 Key Concept / Khái niệm cốt lõi: Reserved Instances = specific; Savings Plans = flexible. / Reserved Instances = cụ thể; Savings Plans = linh hoạt.
Q61.
A company wants to estimate the monthly cost of running 10 t3.medium EC2 instances in us-east-1. Which tool should they use?
Bản dịch tiếng Việt: Một công ty muốn ước tính chi phí hàng tháng để chạy 10 phiên bản t3.medium EC2 ở us-east-1. Họ nên sử dụng công cụ nào?
A. AWS Cost Explorer (analyzes past spending) B. AWS Budgets (sets spending limits) C. AWS Pricing Calculator (estimates costs before deployment) D. AWS Trusted Advisor (cost optimization recommendations)
Correct answer: C Bản dịch đáp án đúng: C. Công cụ tính giá AWS (ước tính chi phí trước khi triển khai)
🇬🇧 Explanation: AWS Pricing Calculator = estimates costs BEFORE deployment. It is a "what-if" tool used before deploying resources, showing estimated monthly cost — for example, calculating pricing for 10 t3.medium instances.
🇻🇳 Giải thích: AWS Pricing Calculator = ước tính chi phí TRƯỚC khi deployment. Đây là công cụ "what-if" dùng trước khi triển khai resource, hiển thị chi phí hàng tháng ước tính — ví dụ tính giá cho 10 t3.medium instances.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Cost Explorer) — Analyzes PAST spending, not estimates / Phân tích chi tiêu QUÁ KHỨ, không phải ước tính.
- B (Budgets) — Sets spending limits, not estimates / Đặt giới hạn chi tiêu, không phải ước tính.
- D (Trusted Advisor) — Cost optimization recommendations, not estimates / Gợi ý tối ưu chi phí, không phải ước tính.
🔑 Key Concept / Khái niệm cốt lõi: Cost Calculator = pre-deployment estimate; Cost Explorer = post-deployment analysis. / Cost Calculator = ước tính trước deployment; Cost Explorer = phân tích sau deployment.
Q62.
A company has multiple AWS accounts and wants to see a consolidated bill with volume discounts. Which AWS feature enables this?
Bản dịch tiếng Việt: Một công ty có nhiều tài khoản AWS và muốn xem hóa đơn tổng hợp có chiết khấu theo số lượng. Tính năng AWS nào cho phép điều này?
A. AWS Organizations with Consolidated Billing B. AWS CloudFormation (infrastructure management) C. AWS Systems Manager (resource management) D. Individual billing for each account
Correct answer: A Bản dịch đáp án đúng: A. Các tổ chức AWS có thanh toán tổng hợp
🇬🇧 Explanation: AWS Organizations with Consolidated Billing = consolidated bill + volume discounts. Organizations provides multi-account management, Consolidated Billing produces a single bill for all accounts, volume discounts apply across all accounts, and this simplifies billing while maximizing savings.
🇻🇳 Giải thích: AWS Organizations với Consolidated Billing = hóa đơn gộp + chiết khấu theo khối lượng. Organizations cung cấp quản lý nhiều account, Consolidated Billing tạo một hóa đơn duy nhất cho tất cả account, chiết khấu theo khối lượng áp dụng trên toàn bộ account, giúp đơn giản hóa billing và tối đa hóa tiết kiệm.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (CloudFormation) — Infrastructure deployment, not billing / Triển khai hạ tầng, không phải billing.
- C (Systems Manager) — Resource management, not billing / Quản lý resource, không phải billing.
- D (Individual billing) — Opposite of consolidated billing / Ngược lại với consolidated billing.
🔑 Key Concept / Khái niệm cốt lõi: Organizations + Consolidated Billing = shared volume discounts. / Organizations + Consolidated Billing = chia sẻ chiết khấu theo khối lượng.
Q63. (Select TWO)
A company is implementing cost optimization practices. Which approaches are effective? (Select TWO)
Bản dịch tiếng Việt: Một công ty đang thực hiện các biện pháp tối ưu hóa chi phí. Những cách tiếp cận nào có hiệu quả? (Chọn HAI)
A. Using Reserved Instances for stable, predictable workloads B. Always over-provisioning the largest instance type to avoid resizing later C. Running all instances as On-Demand for flexibility D. Using Spot Instances for fault-tolerant workloads E. Ignoring CloudWatch alarms and letting services run 24/7
Correct answer: A, D Bản dịch đáp án đúng: A. Sử dụng Phiên bản dự trữ để có khối lượng công việc ổn định, có thể dự đoán được; D. Sử dụng Phiên bản dùng ngay cho khối lượng công việc có khả năng chịu lỗi
🇬🇧 Explanation: Reserved Instances for stable; Spot for fault-tolerant batch jobs. A is correct because RIs suit stable, predictable workloads (production databases). D is correct because Spot suits fault-tolerant jobs (batch, analytics, CI/CD).
🇻🇳 Giải thích: Reserved Instances cho workload ổn định; Spot cho batch job chịu lỗi. A đúng vì RIs phù hợp workload ổn định, dự đoán được (database production). D đúng vì Spot phù hợp job chịu lỗi (batch, analytics, CI/CD).
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (Always over-provisioning the largest instance type) — False; over-provisioning wastes money. Right-sizing to the workload is the correct practice. / Sai; over-provisioning lãng phí tiền. Right-sizing theo workload mới là cách đúng.
- C (All On-Demand) — Expensive; contradicts cost optimization / Đắt; đi ngược tối ưu chi phí.
- E (Ignore alarms) — Increases costs and risks / Tăng chi phí và rủi ro.
🔑 Key Concept / Khái niệm cốt lõi: Cost optimization = right service + right pricing model + right instance size. / Tối ưu chi phí = đúng service + đúng pricing model + đúng kích thước instance.
Q64.
A company wants to set a monthly spending limit and receive alerts when approaching the limit. Which service should they use?
Bản dịch tiếng Việt: Một công ty muốn đặt giới hạn chi tiêu hàng tháng và nhận thông báo khi đạt đến giới hạn. Họ nên sử dụng dịch vụ nào?
A. AWS Cost Explorer (visualization, not alerts) B. AWS Budgets (spending limits and alerts) C. AWS Pricing Calculator (estimation tool) D. AWS CloudTrail (audit logging, not costs)
Correct answer: B Bản dịch đáp án đúng: B. Ngân sách AWS (giới hạn chi tiêu và cảnh báo)
🇬🇧 Explanation: AWS Budgets = spending limits with alerts. Budgets enforce "do not exceed X per month" with email/SNS alerts, set a threshold (e.g., $500/month), alert when approaching or exceeding, and prevent unexpected bills.
🇻🇳 Giải thích: AWS Budgets = giới hạn chi tiêu kèm cảnh báo. Budgets thực thi "không vượt quá X mỗi tháng" với cảnh báo email/SNS, đặt ngưỡng (ví dụ $500/tháng), cảnh báo khi sắp đạt hoặc vượt, và ngăn hóa đơn bất ngờ.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Cost Explorer) — Visualization and analysis, not alerts / Trực quan hóa và phân tích, không phải cảnh báo.
- C (Pricing Calculator) — Estimation only / Chỉ ước tính.
- D (CloudTrail) — Audit logging, not cost alerts / Ghi log kiểm toán, không phải cảnh báo chi phí.
🔑 Key Concept / Khái niệm cốt lõi: Budgets = cost guardrails with alerts. / Budgets = rào chắn chi phí kèm cảnh báo.
Q65.
A company qualifies for the AWS Free Tier and wants to know what's included. Which of the following is true about Free Tier?
Bản dịch tiếng Việt: Một công ty đủ điều kiện tham gia Bậc miễn phí của AWS và muốn biết những gì được bao gồm. Điều nào sau đây đúng về Bậc miễn phí?
A. All AWS services are free forever B. Specific services have free tier limits (Always Free, 12-Month Free, Trials) C. Free Tier is only for development, not production D. Free Tier requires a prepaid contract
Correct answer: B Bản dịch đáp án đúng: B. Các dịch vụ cụ thể có giới hạn bậc miễn phí (Luôn miễn phí, Miễn phí 12 tháng, Dùng thử)
🇬🇧 Explanation: Free Tier = specific services with limits (Always Free, 12-month, Trials). The AWS Free Tier has three categories: Always Free (Lambda 1M invocations/month, S3 5GB, etc. — forever), 12-Month Free (EC2 t2.micro, RDS, etc. — first 12 months only), and Trials (EMR 2 months, SageMaker 250 hours/month, etc.).
🇻🇳 Giải thích: Free Tier = các service cụ thể với giới hạn (Always Free, 12 tháng, Trials). AWS Free Tier có ba nhóm: Always Free (Lambda 1M lần gọi/tháng, S3 5GB, v.v. — mãi mãi), 12-Month Free (EC2 t2.micro, RDS, v.v. — chỉ 12 tháng đầu), và Trials (EMR 2 tháng, SageMaker 250 giờ/tháng, v.v.).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (All services free) — False; only specific services / Sai; chỉ các service cụ thể.
- C (Development only) — False; you can run production on Free Tier / Sai; có thể chạy production trên Free Tier.
- D (Requires prepaid) — False; Free Tier is actually free (no credit card charge) / Sai; Free Tier thực sự miễn phí (không tính tiền thẻ).
🔑 Key Concept / Khái niệm cốt lõi: Free Tier is limited but generous for learning and small projects. / Free Tier có giới hạn nhưng hào phóng cho học tập và dự án nhỏ.
Scoring Analysis
| Score Range | Status | Next Steps |
|---|---|---|
| ≥52/65 (80%) | ✅ READY FOR EXAM | Review weak domains, take final practice exam |
| 45-51/65 (70-79%) | ⚠️ ALMOST READY | Focus on weak domains, do more practice |
| <45/65 (<70%) | ❌ NOT READY | Review study guide, rewatch video lessons, repeat practice exams |
Common Patterns by Theme
Service Selection (Most Tested)
| Use Case | Best Service | Why |
|---|---|---|
| Serverless compute | Lambda | Pay per invocation, auto-scale |
| Containers (no EC2) | Fargate | Serverless containers |
| Relational queries | RDS/Aurora | SQL support, transactions |
| Key-value access | DynamoDB | Single-digit latency |
| Data analytics | Redshift | Columnar warehouse |
| Global CDN | CloudFront | Edge locations |
| Message queue | SQS | Persistent, guaranteed delivery |
| Pub/sub | SNS | Broadcast to many subscribers |
| Block storage | EBS | Attached to EC2 same AZ |
| Shared file storage | EFS | Multi-EC2, cross-AZ |
| DDoS protection | Shield | AWS-managed DDoS defense |
| Web attack protection | WAF | SQL injection, XSS blocking |
| Access control | IAM | Users, groups, roles, policies |
| API audit logging | CloudTrail | Who did what, when |
| Config compliance | Config | What is current state |
| Threat detection | GuardDuty | ML-based anomalies |
| Encryption keys | KMS | Managed encryption keys |
| Secrets management | Secrets Manager | Auto-rotate passwords |
Common Misconceptions
- CloudTrail vs Config: CloudTrail = audit trail; Config = compliance monitoring
- SQS vs SNS: SQS = queue (persistent); SNS = pub/sub (broadcast)
- EC2 vs Lambda: EC2 = you manage; Lambda = AWS manages
- EBS vs EFS: EBS = one instance; EFS = shared across instances
- RDS vs DynamoDB: RDS = relational/SQL; DynamoDB = key-value/NoSQL
- Direct Connect vs VPN: Direct Connect = physical; VPN = internet (encrypted)
- ALB vs NLB: ALB = Layer 7 (HTTP); NLB = Layer 4 (TCP/UDP)
- Reserved Instances vs Spot: RI = commit (cheap); Spot = interruptible (cheapest)
Good luck bạn! You've got this. 💪
Lời khuyên cuối cùng: Don't memorize; understand WHY each service is chosen. The exam tests understanding, not rote memory.