CLF-C02 Mock Exam #04 — Solutions & Explanations
Theme: Cost Optimization Focus
Difficulty: Medium
Format: Bilingual (English + Vietnamese) | Cost implications included for every answer
Domain 1: Cloud Concepts (Q1–Q16)
Q1.
A company operating on-premises data centers pays $500,000 annually in capital expenditure (hardware, cooling, maintenance staff) with irregular demand. Which AWS benefit best addresses this challenge?
Bản dịch tiếng Việt: Một công ty vận hành các trung tâm dữ liệu tại chỗ phải trả 500.000 USD hàng năm cho chi phí vốn (nhân viên phần cứng, làm mát, bảo trì) với nhu cầu không thường xuyên. Lợi ích AWS nào giải quyết tốt nhất thách thức này?
A. Economies of scale—AWS spreads infrastructure costs across millions of customers, reducing per-unit cost B. Purchasing reserved servers in bulk to negotiate lower pricing C. Building additional data centers to handle traffic spikes D. Investing in redundant on-premises hardware for high availability
Correct answer: A Bản dịch đáp án đúng: A. Tính kinh tế nhờ quy mô—AWS phân bổ chi phí cơ sở hạ tầng cho hàng triệu khách hàng, giảm chi phí trên mỗi đơn vị
🇬🇧 Explanation: AWS's massive global infrastructure is shared across millions of customers. This economies-of-scale benefit means AWS can spread infrastructure costs (data center construction, power, cooling, staff) across the customer base, resulting in lower per-unit cost for each customer.
🇻🇳 Giải thích: AWS chia sẻ hạ tầng (infrastructure) cho hàng triệu khách hàng. Nhờ lợi thế economies-of-scale này, AWS phân bổ chi phí xây data center, điện, làm mát, nhân sự ra toàn bộ tập khách hàng, nên chi phí mỗi đơn vị (per-unit) mà bạn trả thấp hơn nhiều so với tự làm on-premises.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (bulk purchasing) — AWS already negotiates optimal pricing; customers don't benefit by buying in bulk themselves / AWS đã đàm phán giá tối ưu rồi, bạn tự mua số lượng lớn không được lợi thêm.
- C (build more data centers) — Adding on-premises data centers increases CapEx, doesn't solve scaling costs / Xây thêm data center on-premises làm tăng CapEx, không giải quyết được chi phí mở rộng.
- D (redundant hardware) — Over-provisioning is exactly what cloud elasticity avoids / Dự phòng thừa phần cứng chính là điều mà elasticity của cloud giúp tránh.
🔑 Key Concept / Khái niệm cốt lõi: Shared infrastructure across millions of customers lowers per-unit cost / Hạ tầng dùng chung cho hàng triệu khách hàng kéo chi phí mỗi đơn vị xuống.
Q2.
An organization wants to shift from CapEx (capital expenditure) to OpEx (operational expenditure). How does AWS cloud help achieve this?
Bản dịch tiếng Việt: Một tổ chức muốn chuyển từ CapEx (chi phí vốn) sang OpEx (chi phí hoạt động). Đám mây AWS giúp đạt được điều này như thế nào?
A. Eliminates the need to purchase physical servers, replacing it with pay-as-you-go monthly billing B. Guarantees the company will never spend money on IT infrastructure again C. Requires a one-time upfront payment for all cloud services D. Forces the company to purchase reserved instances for all workloads
Correct answer: A Bản dịch đáp án đúng: A. Loại bỏ nhu cầu mua máy chủ vật lý, thay thế bằng hình thức thanh toán hàng tháng theo nhu cầu sử dụng
🇬🇧 Explanation: AWS shifts from CapEx (Capital Expenditure) — large upfront investment in hardware, data center construction, long-term amortization — to OpEx (Operational Expenditure) — monthly pay-as-you-go bills. This is fundamental to cloud cost advantage: "convert fixed assets to variable costs."
🇻🇳 Giải thích: AWS chuyển bạn từ CapEx (Capital Expenditure) — đầu tư lớn trả trước cho phần cứng, xây data center, khấu hao dài hạn — sang OpEx (Operational Expenditure) — hóa đơn pay-as-you-go hàng tháng. Đây là lợi thế chi phí cốt lõi của cloud: "biến tài sản cố định thành chi phí biến đổi".
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (never spend again) — Cloud still costs money, just differently structured / Cloud vẫn tốn tiền, chỉ là cấu trúc chi phí khác đi.
- C (one-time upfront) — Cloud models are pay-as-you-go, NOT upfront / Mô hình cloud là trả theo mức dùng, không phải trả trước một lần.
- D (forced RIs) — Reserved Instances are optional, not required / Reserved Instances là tùy chọn, không bắt buộc.
🔑 Key Concept / Khái niệm cốt lõi: Trade upfront CapEx for flexible monthly OpEx / Đổi CapEx trả trước lấy OpEx hàng tháng linh hoạt.
Q3.
Which AWS cloud advantage directly reduces the cost of building and maintaining on-premises data center infrastructure?
Bản dịch tiếng Việt: Lợi thế nào của đám mây AWS trực tiếp giúp giảm chi phí xây dựng và duy trì cơ sở hạ tầng trung tâm dữ liệu tại chỗ?
A. Ability to stop guessing capacity needs and pay only for what you use B. Shared responsibility model eliminates all customer security costs C. Automatic currency conversion for international payments D. Unlimited storage at no additional cost
Correct answer: A Bản dịch đáp án đúng: A. Khả năng ngừng đoán nhu cầu dung lượng và chỉ trả tiền cho những gì bạn sử dụng
🇬🇧 Explanation: "Stop guessing capacity" is one of AWS's six key cloud advantages. On-premises forces you to over-provision for peak demand (waste during low demand) or under-provision and risk performance. AWS elasticity scales to match actual demand, paying only for what's used. This directly eliminates waste and reduces cost.
🇻🇳 Giải thích: "Stop guessing capacity" là một trong sáu lợi thế cốt lõi của cloud. On-premises buộc bạn hoặc cấp phát dư cho lúc cao điểm (lãng phí khi tải thấp), hoặc cấp thiếu và chịu rủi ro hiệu năng. Elasticity của AWS co giãn đúng theo nhu cầu thực, bạn chỉ trả cho phần dùng, nhờ đó xóa bỏ lãng phí và giảm chi phí.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (shared responsibility eliminates security costs) — SR is about responsibility, not elimination of security costs / Shared Responsibility nói về phân chia trách nhiệm, không phải xóa bỏ chi phí bảo mật.
- C (currency conversion) — Not a cloud advantage, irrelevant to cost structure / Không phải lợi thế cloud, không liên quan tới cấu trúc chi phí.
- D (unlimited storage free) — S3 has per-GB charges, not unlimited free / S3 tính phí theo GB, không miễn phí vô hạn.
🔑 Key Concept / Khái niệm cốt lõi: Elasticity scales to actual demand, ending over-provisioning waste / Elasticity co giãn theo nhu cầu thực, chấm dứt lãng phí do cấp dư.
Q4. (Select TWO)
Which of the following represent financial benefits of cloud computing vs. on-premises? (Select TWO)
Bản dịch tiếng Việt: Điều nào sau đây thể hiện lợi ích tài chính của điện toán đám mây so với tại chỗ? (Chọn HAI)
A. No upfront capital investment in hardware and infrastructure B. Pay-as-you-go model reduces cost of unused/over-provisioned resources C. Cloud services automatically eliminate the need for a security team D. Fixed monthly costs make budgeting completely predictable E. Reduced operational overhead from AWS managing data centers
Correct answer: A, B Bản dịch đáp án đúng: A. Không cần đầu tư vốn ban đầu vào phần cứng và cơ sở hạ tầng; B. Mô hình thanh toán khi sử dụng giúp giảm chi phí của các tài nguyên không được sử dụng/cung cấp quá mức
🇬🇧 Explanation:
- A (no upfront capital): Cloud eliminates large upfront hardware purchases (major CapEx)
- B (pay only for what you use): Auto-scaling ensures you don't pay for idle over-provisioned capacity
🇻🇳 Giải thích:
- A (không cần vốn trả trước): Cloud loại bỏ việc mua phần cứng lớn ngay từ đầu (CapEx lớn).
- B (chỉ trả cho phần dùng): Auto-scaling đảm bảo bạn không phải trả cho capacity cấp dư đang nằm không.
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (eliminates security costs) — Security is still necessary and costs money / Bảo mật vẫn cần thiết và vẫn tốn tiền.
- D (completely predictable costs) — Costs are predictable with budgeting tools, but not "completely" fixed / Chi phí có thể dự đoán nhờ công cụ budget, nhưng không "hoàn toàn" cố định.
- E (no security team needed) — Customer still manages IAM, data, application security / Bạn vẫn phải quản lý IAM, dữ liệu, bảo mật ứng dụng.
🔑 Key Concept / Khái niệm cốt lõi: No upfront CapEx + pay-only-for-use are the two headline cost wins / Không CapEx trả trước + chỉ trả cho phần dùng là hai lợi ích chi phí nổi bật.
Q5.
A startup with unpredictable workload spikes (low traffic most days, occasional traffic bursts) migrates to AWS. Which business advantage most directly impacts cost savings?
Bản dịch tiếng Việt: Một công ty khởi nghiệp có khối lượng công việc tăng đột biến không thể đoán trước (lưu lượng truy cập thấp hầu hết các ngày, lưu lượng truy cập không thường xuyên tăng vọt) sẽ di chuyển sang AWS. Lợi thế kinh doanh nào tác động trực tiếp nhất đến việc tiết kiệm chi phí?
A. AWS elasticity allows automatic resource scaling without over-provisioning for peak load B. AWS root account enables free administrative access to all services C. Hybrid cloud deployment reduces the need for an IT team D. Multi-region deployment eliminates the need for security
Correct answer: A Bản dịch đáp án đúng: A. Độ co giãn của AWS cho phép tự động điều chỉnh quy mô tài nguyên mà không cần cung cấp quá mức cho tải cao điểm
🇬🇧 Explanation: This is the core cost advantage: elasticity. A company with unpredictable spikes (100-500% variation) must over-provision for peak on-premises (enormous waste during low periods). AWS Auto Scaling adds instances only when needed, removes them when traffic drops. Cost savings are proportional to demand variance.
🇻🇳 Giải thích: Đây là lợi thế chi phí cốt lõi: elasticity. Công ty có spike khó đoán (biến động 100-500%) nếu chạy on-premises buộc phải cấp dư cho đỉnh (lãng phí khổng lồ lúc tải thấp). AWS Auto Scaling chỉ thêm instance khi cần và gỡ bỏ khi traffic giảm. Mức tiết kiệm tỉ lệ thuận với độ biến động của nhu cầu.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (root account free access) — Root account doesn't save money, increases risk / Root account không tiết kiệm tiền mà còn tăng rủi ro.
- C (hybrid reduces IT staff) — Hybrid can reduce staff somewhat, but elasticity is the primary cost benefit / Hybrid có thể giảm nhân sự phần nào, nhưng elasticity mới là lợi ích chi phí chính.
- D (multi-region eliminates security) — Multi-region doesn't eliminate security needs / Multi-region không loại bỏ nhu cầu bảo mật.
🔑 Key Concept / Khái niệm cốt lõi: Variable workloads are where elasticity delivers the biggest savings / Workload biến động chính là nơi elasticity tiết kiệm nhiều nhất.
Q6.
A company currently owns a large data center with excess capacity during off-peak hours. Which AWS principle best explains the cost benefit of migrating to cloud?
Bản dịch tiếng Việt: Một công ty hiện đang sở hữu một trung tâm dữ liệu lớn với công suất dư thừa vào giờ thấp điểm. Nguyên tắc AWS nào giải thích rõ nhất lợi ích chi phí của việc di chuyển sang đám mây?
A. Ability to right-size resources — use resources only when needed, pay for only what is consumed B. Cloud services are always cheaper than on-premises C. AWS provides free data center infrastructure D. Hybrid cloud removes all infrastructure maintenance
Correct answer: A Bản dịch đáp án đúng: A. Khả năng điều chỉnh kích thước tài nguyên - chỉ sử dụng tài nguyên khi cần, chỉ trả tiền cho những gì đã tiêu thụ
🇬🇧 Explanation: Right-sizing — matching resource quantity to actual demand, not fixed over-provisioning. On-premises with excess capacity during off-peak = wasted infrastructure cost (hardware, cooling, power already paid even when idle). AWS lets you provision "by the minute" to match demand.
🇻🇳 Giải thích: Right-sizing là khớp lượng tài nguyên với nhu cầu thực, không cấp dư cố định. On-premises dư capacity lúc thấp điểm = lãng phí chi phí hạ tầng (phần cứng, làm mát, điện đã trả dù đang nằm không). AWS cho bạn cấp phát "theo phút" để khớp nhu cầu.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (cloud always cheaper) — Depends on workload; some stable workloads may favor on-premises / Tùy workload; một số workload ổn định có thể hợp on-premises hơn.
- C (AWS free data centers) — AWS is not free, just structured differently / AWS không miễn phí, chỉ là cấu trúc chi phí khác.
- D (hybrid removes maintenance) — Maintenance costs exist in both models; the advantage is elasticity / Cả hai mô hình đều có chi phí bảo trì; lợi thế nằm ở elasticity.
🔑 Key Concept / Khái niệm cốt lõi: Right-sizing matches resources to real demand, not peak guesses / Right-sizing khớp tài nguyên với nhu cầu thực, không phải đoán đỉnh.
Q7. (Select TWO)
Which of the following are characteristics of the AWS Well-Architected Framework's Cost Optimization pillar? (Select TWO)
Bản dịch tiếng Việt: Đặc điểm nào sau đây là đặc điểm của trụ cột Tối ưu hóa chi phí của AWS Well-Architected Framework? (Chọn HAI)
A. Always provision for the maximum possible peak load to guarantee performance at any cost B. Pay for what you use and implement right-sizing recommendations C. All AWS services must be free to use D. Analyze third-party cost auditing tools for compliance E. Stop guessing capacity needs and match supply to demand dynamically
Correct answer: B, E Bản dịch đáp án đúng: B. Trả tiền cho những gì bạn sử dụng và thực hiện các đề xuất định cỡ phù hợp; E. Ngừng đoán nhu cầu năng lực và kết hợp cung với cầu một cách linh hoạt
🇬🇧 Explanation:
- B (measure efficiency & right-size): Cost Optimization pillar explicitly includes right-sizing to reduce waste
- E (stop guessing capacity): Directly from AWS's six advantages, core to cost optimization
🇻🇳 Giải thích:
- B (đo hiệu quả & right-size): Pillar Cost Optimization nêu rõ việc right-sizing để giảm lãng phí.
- E (stop guessing capacity): Lấy thẳng từ sáu lợi thế của AWS, là cốt lõi của tối ưu chi phí.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (provision for max peak at any cost) — Opposite of cost optimization; over-provisioning for peak is exactly the waste the pillar tells you to avoid / Trái ngược tối ưu chi phí; cấp dư cho đỉnh chính là lãng phí mà pillar khuyên tránh.
- C (all services free) — No AWS service is free; you pay for what you use / Không service AWS nào miễn phí; bạn trả theo mức dùng.
- D (analyze third-party tools for compliance) — That's a Security/compliance concern, not the Cost Optimization pillar / Đó là việc của Security/compliance, không phải pillar Cost Optimization.
🔑 Key Concept / Khái niệm cốt lõi: Measure efficiency + stop guessing capacity = heart of Cost Optimization / Đo hiệu quả + ngừng đoán capacity = cốt lõi của Cost Optimization.
Q8.
A company considering AWS is concerned about unpredictable monthly bills. How does AWS infrastructure enable predictable cost management?
Bản dịch tiếng Việt: Một công ty đang cân nhắc sử dụng AWS lo ngại về các hóa đơn hàng tháng khó dự đoán. Cơ sở hạ tầng AWS cho phép quản lý chi phí có thể dự đoán được như thế nào?
A. AWS services always cost the same regardless of usage B. Tools like Cost Explorer, Budgets, and Trusted Advisor help forecast, monitor, and optimize spending C. AWS guarantees the company will spend less than on-premises (no refund if it doesn't) D. All AWS services are included in the AWS Free Tier
Correct answer: B Bản dịch đáp án đúng: B. Các công cụ như Cost Explorer, Budgets và Trusted Advisor giúp dự báo, giám sát và tối ưu hóa chi tiêu
🇬🇧 Explanation: AWS provides three main cost management tools:
- Cost Explorer: Visualize spending trends, forecast future spend (helps predict monthly bills)
- AWS Budgets: Set spending limits, receive alerts when threshold crossed
- Trusted Advisor: Free recommendations (7 core checks) including cost optimization
These enable predictable cost management vs. surprise bills.
🇻🇳 Giải thích: AWS có ba công cụ quản lý chi phí chính:
- Cost Explorer: Trực quan hóa xu hướng chi tiêu, dự báo chi phí tương lai (giúp đoán hóa đơn hàng tháng).
- AWS Budgets: Đặt giới hạn chi tiêu, nhận cảnh báo khi vượt ngưỡng.
- Trusted Advisor: Khuyến nghị miễn phí (7 core checks) bao gồm tối ưu chi phí.
Bộ ba này giúp bạn quản lý chi phí có thể đoán trước, tránh hóa đơn bất ngờ.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (services always same cost) — Costs vary by usage, region, instance type / Chi phí thay đổi theo mức dùng, region, loại instance.
- C (guaranteed cheaper) — No such guarantee; cloud can cost more than on-prem if poorly designed / Không có đảm bảo đó; thiết kế tệ thì cloud còn đắt hơn on-prem.
- D (all services in Free Tier) — Only specific services/amounts included; most services cost money / Chỉ một số service/định mức được miễn; phần lớn service vẫn tốn tiền.
🔑 Key Concept / Khái niệm cốt lõi: Cost Explorer + Budgets + Trusted Advisor = predict, monitor, optimize / Cost Explorer + Budgets + Trusted Advisor = dự báo, giám sát, tối ưu.
Q9.
An organization wants to implement a hybrid cloud strategy to keep some workloads on-premises while moving others to AWS. Which cost advantage applies?
Bản dịch tiếng Việt: Một tổ chức muốn triển khai chiến lược đám mây lai để duy trì một số khối lượng công việc tại chỗ trong khi chuyển các khối lượng công việc khác sang AWS. Lợi thế chi phí nào được áp dụng?
A. Hybrid cloud eliminates the cost of on-premises infrastructure B. AWS Storage Gateway and Direct Connect enable cost-effective hybrid architectures without replacing all on-premises systems C. Hybrid cloud always costs more than pure cloud or pure on-premises D. Hybrid deployment requires purchasing dedicated AWS hardware
Correct answer: B Bản dịch đáp án đúng: B. AWS Storage Gateway và Direct Connect hỗ trợ kiến trúc kết hợp tiết kiệm chi phí mà không cần thay thế tất cả hệ thống tại chỗ
🇬🇧 Explanation: Hybrid cloud doesn't replace on-premises infrastructure entirely (that's not the goal). Instead, AWS Storage Gateway and AWS Direct Connect enable cost-effective hybrid architectures:
- Storage Gateway: On-premises storage gateway with S3 caching → keep legacy systems while using cloud storage
- Direct Connect: Dedicated network connection reduces data transfer costs vs. public internet
Hybrid avoids "rip-and-replace" CapEx while leveraging cloud benefits.
🇻🇳 Giải thích: Hybrid cloud không nhằm thay thế hoàn toàn hạ tầng on-premises. Thay vào đó, AWS Storage Gateway và AWS Direct Connect giúp xây kiến trúc hybrid tiết kiệm:
- Storage Gateway: Gateway lưu trữ tại chỗ có cache lên S3 → giữ hệ thống cũ trong khi vẫn dùng lưu trữ cloud.
- Direct Connect: Kết nối mạng riêng chuyên dụng giảm chi phí truyền dữ liệu so với internet công cộng.
Hybrid tránh CapEx kiểu "đập đi xây lại" mà vẫn tận dụng lợi ích cloud.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (eliminates on-premises) — Hybrid keeps on-premises + adds cloud (not elimination) / Hybrid giữ on-premises rồi thêm cloud, không loại bỏ.
- C (always costs more) — If designed well, hybrid can reduce overall costs / Nếu thiết kế tốt, hybrid có thể giảm tổng chi phí.
- D (requires dedicated hardware) — Hybrid uses standard connectivity + some AWS services / Hybrid dùng kết nối tiêu chuẩn + một số service AWS.
🔑 Key Concept / Khái niệm cốt lõi: Storage Gateway + Direct Connect enable cost-effective hybrid without rip-and-replace / Storage Gateway + Direct Connect dựng hybrid tiết kiệm mà không phải đập đi xây lại.
Q10.
Which deployment model provides the lowest total cost of ownership (TCO) when an organization wants the flexibility to shift workloads between public and private cloud?
Bản dịch tiếng Việt: Mô hình triển khai nào cung cấp tổng chi phí sở hữu (TCO) thấp nhất khi tổ chức muốn linh hoạt chuyển đổi khối lượng công việc giữa đám mây công cộng và riêng tư?
A. Public Cloud only B. Private Cloud (on-premises) only C. Hybrid Cloud — leverage AWS cost efficiency while retaining sensitive/legacy systems on-premises D. Multi-Cloud (multiple vendors) — distributedrisk reduces overall costs
Correct answer: C Bản dịch đáp án đúng: C. Đám mây lai — tận dụng hiệu quả chi phí của AWS trong khi vẫn duy trì các hệ thống nhạy cảm/cũ tại chỗ
🇬🇧 Explanation: Hybrid Cloud provides the best TCO (Total Cost of Ownership) balance:
- Hybrid: Leverage AWS elasticity cost savings for variable workloads, keep stable/sensitive workloads on-premises (avoid rip-and-replace CapEx)
- Public cloud only: Forces migration of all systems, large upfront CapEx for new cloud infrastructure
- Private cloud only: High infrastructure costs, limited elasticity benefits
Hybrid is the pragmatic choice for organizations with mixed legacy + new systems.
🇻🇳 Giải thích: Hybrid Cloud cho cân bằng TCO (Total Cost of Ownership) tốt nhất:
- Hybrid: Tận dụng tiết kiệm nhờ elasticity của AWS cho workload biến động, giữ workload ổn định/nhạy cảm trên on-premises (tránh CapEx kiểu đập đi xây lại).
- Public cloud only: Buộc migrate toàn bộ hệ thống, CapEx trả trước lớn cho hạ tầng cloud mới.
- Private cloud only: Chi phí hạ tầng cao, ít lợi ích elasticity.
Hybrid là lựa chọn thực dụng cho tổ chức có cả hệ thống cũ lẫn mới.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (public only) — Can be optimal for some, but not always best for TCO / Có thể tối ưu với một số trường hợp, nhưng không luôn tốt nhất về TCO.
- B (private only) — Highest infrastructure costs / Chi phí hạ tầng cao nhất.
- D (multi-cloud) — Increases management overhead, not necessarily lower cost / Tăng gánh nặng quản lý, chưa chắc rẻ hơn.
🔑 Key Concept / Khái niệm cốt lõi: Hybrid keeps stable workloads on-prem and bursts variable ones to cloud for best TCO / Hybrid giữ workload ổn định ở on-prem và đẩy phần biến động lên cloud để TCO tốt nhất.
Q11. (Select THREE)
AWS Six Advantages of Cloud Computing include cost-related benefits. Which of the following are accurate? (Select THREE)
Bản dịch tiếng Việt: Sáu ưu điểm của Điện toán đám mây của AWS bao gồm các lợi ích liên quan đến chi phí. Điều nào sau đây là chính xác? (Chọn BA)
A. Go global in minutes—deploy to multiple regions for low latency without huge upfront investment B. Increase speed and agility—launch applications quickly without CapEx on infrastructure C. Economies of scale—reduce per-unit infrastructure costs via AWS's massive scale D. Eliminate the need for an IT operations team entirely E. Access to proprietary AWS hardware at retail customer prices
Correct answer: A, B, C Bản dịch đáp án đúng: A. Vươn ra toàn cầu trong vài phút—triển khai tới nhiều khu vực với độ trễ thấp mà không cần đầu tư ban đầu lớn; B. Tăng tốc độ và tính linh hoạt — khởi chạy ứng dụng nhanh chóng mà không cần CapEx trên cơ sở hạ tầng; C. Tính kinh tế nhờ quy mô—giảm chi phí cơ sở hạ tầng trên mỗi đơn vị thông qua quy mô lớn của AWS
🇬🇧 Explanation: AWS's Six Advantages of Cloud — three with direct cost impact:
- A (go global in minutes): Deploy to multiple regions without massive upfront infrastructure investment
- B (speed and agility): Launch applications quickly, avoid CapEx on building-out infrastructure
- C (economies of scale): Share infrastructure costs across millions of customers
🇻🇳 Giải thích: Sáu lợi thế của Cloud từ AWS — ba lợi thế có tác động chi phí trực tiếp:
- A (go global in minutes): Triển khai ra nhiều region mà không cần đầu tư hạ tầng trả trước khổng lồ.
- B (speed and agility): Tung ứng dụng nhanh, tránh CapEx cho việc dựng hạ tầng.
- C (economies of scale): Chia sẻ chi phí hạ tầng cho hàng triệu khách hàng.
❌ Why others are wrong / Vì sao đáp án khác sai:
- D (eliminate IT ops team) — Unrealistic; customers still manage IAM, data, application support / Phi thực tế; bạn vẫn phải quản lý IAM, dữ liệu, hỗ trợ ứng dụng.
- E (proprietary hardware at retail) — No such offer; pricing is standardized / Không có ưu đãi như vậy; giá được chuẩn hóa.
🔑 Key Concept / Khái niệm cốt lõi: Go global, agility, and economies of scale are the top cost-impacting advantages / Go global, agility và economies of scale là ba lợi thế tác động chi phí mạnh nhất.
Q12.
A financial services firm is evaluating cloud vs. on-premises for a 5-year project. Which scenario favors a cloud solution from a cost perspective?
Bản dịch tiếng Việt: Một công ty dịch vụ tài chính đang đánh giá đám mây so với tại chỗ cho một dự án 5 năm. Kịch bản nào ủng hộ giải pháp đám mây từ góc độ chi phí?
A. Workload has highly variable demand with unpredictable spikes → cloud elasticity avoids over-provisioning B. Workload requires 100% guaranteed uptime with zero latency variation → only achievable on-premises C. Company has existing data center leases with 5 years remaining → must use on-premises to amortize cost D. Workload is stable and fully predictable for 5 years → guarantees lowest cost on-premises
Correct answer: A Bản dịch đáp án đúng: A. Khối lượng công việc có nhu cầu rất khác nhau với mức tăng đột biến không thể đoán trước → độ co giãn của đám mây tránh cung cấp quá mức
🇬🇧 Explanation: Highly variable demand with unpredictable spikes is where cloud shines cost-wise:
- Cloud elasticity scales to peak demand → avoid 5-year over-provisioning
- CapEx on-premises scales for 5-year peak demand → massive waste during normal periods
On-premises favors stable, predictable workloads where you can optimize once.
🇻🇳 Giải thích: Nhu cầu biến động cao với spike khó đoán là nơi cloud tỏa sáng về chi phí:
- Elasticity của cloud co giãn theo đỉnh nhu cầu → tránh cấp dư cho 5 năm.
- CapEx on-premises phải cấp đủ cho đỉnh trong 5 năm → lãng phí khổng lồ lúc bình thường.
On-premises hợp với workload ổn định, dễ đoán, nơi bạn tối ưu một lần là xong.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (100% uptime only on-prem) — AWS can achieve higher uptime via Multi-AZ, failover / AWS đạt uptime cao hơn nhờ Multi-AZ, failover.
- C (existing leases) — Legacy commitment, but doesn't change TCO analysis / Cam kết cũ, nhưng không đổi được phân tích TCO.
- D (stable 5 years) — Stable workloads may favor on-premises RI or even hybrid / Workload ổn định có thể hợp on-premises hay RI hơn.
🔑 Key Concept / Khái niệm cốt lõi: Variable demand favors cloud; stable predictable demand can favor on-prem/RI / Nhu cầu biến động hợp cloud; nhu cầu ổn định, dễ đoán có thể hợp on-prem/RI.
Q13.
Which AWS principle best describes the shift from "guessing capacity" to cost optimization?
Bản dịch tiếng Việt: Nguyên tắc nào của AWS mô tả đúng nhất quá trình chuyển đổi từ "khả năng dự đoán" sang tối ưu hóa chi phí?
A. Customers must over-provision resources to guarantee performance B. Auto Scaling and serverless services (Lambda, Fargate) match resource capacity to actual demand in real-time C. AWS offers free capacity planning services D. Capacity forecasting is impossible in the cloud
Correct answer: B Bản dịch đáp án đúng: B. Các dịch vụ Auto Scaling và serverless (Lambda, Fargate) khớp công suất tài nguyên với nhu cầu thực tế trong thời gian thực
🇬🇧 Explanation: "Stop guessing capacity" = Traditional on-premises model: predict peak demand, buy infrastructure to match, pay for it year-round even during low-demand periods.
AWS model: Auto Scaling and serverless services (Lambda, Fargate) automatically adjust capacity to match real-time demand. You pay for actual usage, not theoretical peak.
🇻🇳 Giải thích: "Stop guessing capacity" = Mô hình on-premises truyền thống: đoán đỉnh nhu cầu, mua hạ tầng cho khớp, rồi trả tiền quanh năm kể cả lúc tải thấp.
Mô hình AWS: Auto Scaling và serverless (Lambda, Fargate) tự điều chỉnh capacity theo nhu cầu thời gian thực. Bạn trả cho mức dùng thực, không phải đỉnh lý thuyết.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (must over-provision) — Over-provisioning defeats the purpose of cloud / Cấp dư đi ngược lại mục đích của cloud.
- C (AWS offers free planning) — Cost planning tools aren't free; they're services / Công cụ lập kế hoạch chi phí không miễn phí; chúng là service.
- D (forecasting impossible) — AWS provides tools (Cost Explorer, Pricing Calculator) for forecasting / AWS có công cụ (Cost Explorer, Pricing Calculator) để dự báo.
🔑 Key Concept / Khái niệm cốt lõi: Auto Scaling + serverless adjust capacity to real-time demand, no guessing / Auto Scaling + serverless điều chỉnh capacity theo nhu cầu thời gian thực, không cần đoán.
Q14. (Select TWO)
Which of the following best describe cost-effective architecture decisions? (Select TWO)
Bản dịch tiếng Việt: Điều nào sau đây mô tả tốt nhất các quyết định kiến trúc hiệu quả về chi phí? (Chọn HAI)
A. Use serverless services (Lambda, Fargate) to pay only for actual execution time, not idle time B. Implement auto-scaling to scale down when demand decreases, reducing hourly costs C. Run all workloads on the largest available instances to maximize feature access D. Use Reserved Instances or Savings Plans for predictable, long-running workloads to reduce per-unit cost E. Provision 2-3x your expected peak demand to ensure no performance degradation
Correct answer: B, D Bản dịch đáp án đúng: B. Triển khai tự động mở rộng quy mô để giảm quy mô khi nhu cầu giảm, giảm chi phí theo giờ; D. Sử dụng Phiên bản dự trữ hoặc Savings Plans cho khối lượng công việc dài hạn, có thể dự đoán nhằm giảm chi phí trên mỗi đơn vị
🇬🇧 Explanation:
- B (serverless pays only for execution): Lambda/Fargate scale to zero when idle, eliminating idle costs
- D (auto-scaling down reduces costs): When demand drops, fewer instances running = lower hourly cost
🇻🇳 Giải thích:
- B (serverless chỉ trả cho lúc chạy): Lambda/Fargate co về 0 khi rảnh, xóa bỏ chi phí lúc nằm không.
- D (auto-scaling xuống giảm chi phí): Khi nhu cầu giảm, ít instance chạy hơn = chi phí theo giờ thấp hơn.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (largest instances maximize feature access) — Wrong; this increases cost / Sai; cách này làm tăng chi phí.
- C (2-3x over-provisioning) — Defeats the purpose, maximizes waste / Đi ngược mục đích, tối đa hóa lãng phí.
- E (provision 2-3x demand) — Same as C, enormous waste / Như C, lãng phí khổng lồ.
🔑 Key Concept / Khái niệm cốt lõi: Serverless scale-to-zero + scaling down are core cost-optimization moves / Serverless co về 0 + scale down là các thao tác tối ưu chi phí cốt lõi.
Q15.
A company building a new application wants to avoid capital expenditure and maintain low operational overhead. Which cloud advantage supports this?
Bản dịch tiếng Việt: Một công ty xây dựng một ứng dụng mới muốn tránh chi phí vốn và duy trì chi phí hoạt động ở mức thấp. Lợi thế đám mây nào hỗ trợ điều này?
A. AWS handles infrastructure maintenance, scaling, and availability — the customer focuses only on application code B. On-premises infrastructure provides better cost control C. Hybrid cloud requires less operational overhead than public cloud D. Cloud services always require large upfront contracts
Correct answer: A Bản dịch đáp án đúng: A. AWS xử lý việc bảo trì, mở rộng quy mô và tính khả dụng của cơ sở hạ tầng — khách hàng chỉ tập trung vào mã ứng dụng
🇬🇧 Explanation: AWS managed services (RDS, ECS, Lambda, etc.) shift infrastructure management from the customer to AWS:
- AWS handles: Patching, backups, failover, capacity management, security patches
- Customer focuses on: Application code, data, business logic
This dramatically reduces operational overhead (ops team size, maintenance costs).
🇻🇳 Giải thích: Managed services của AWS (RDS, ECS, Lambda, v.v.) chuyển việc quản lý hạ tầng từ bạn sang AWS:
- AWS lo: Patching, backup, failover, quản lý capacity, vá bảo mật.
- Bạn tập trung vào: Code ứng dụng, dữ liệu, logic nghiệp vụ.
Nhờ vậy gánh nặng vận hành (số nhân sự ops, chi phí bảo trì) giảm mạnh.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (on-premises better cost control) — On-premises requires full infrastructure ops team (higher cost) / On-premises cần đội ops hạ tầng đầy đủ (chi phí cao hơn).
- C (hybrid less overhead) — Hybrid still requires management of on-premises systems / Hybrid vẫn phải quản lý hệ thống on-premises.
- D (upfront contracts) — Cloud models are month-to-month or flexible / Mô hình cloud trả theo tháng hoặc linh hoạt.
🔑 Key Concept / Khái niệm cốt lõi: Managed services offload ops to AWS, lowering operational overhead / Managed services dồn việc vận hành sang AWS, giảm gánh nặng vận hành.
Q16.
Which scenario demonstrates cost-effective use of AWS elasticity?
Bản dịch tiếng Việt: Kịch bản nào thể hiện việc sử dụng độ co giãn của AWS một cách hiệu quả về mặt chi phí?
A. An e-commerce site experiences 100x traffic during holiday season → Auto Scaling adds capacity automatically for peak days, scales down after, avoiding year-round over-provisioning B. A stable internal HR system needs constant 10 instances → must commit to 10 on-demand instances 24/7 to minimize cost C. A batch processing job runs monthly → should reserve capacity all 12 months even if not used D. A startup with growing traffic → purchase the largest instance upfront to avoid upgrading later
Correct answer: A Bản dịch đáp án đúng: A. Trang web thương mại điện tử có lưu lượng truy cập gấp 100 lần trong mùa lễ → Tự động mở rộng quy mô tự động tăng công suất vào những ngày cao điểm, giảm quy mô sau đó, tránh cung cấp quá mức quanh năm
🇬🇧 Explanation: E-commerce site with 100x seasonal surge:
- On-premises: Maintain year-round capacity for peak season (11 months of waste) = ~$500K/year × 12/13 = $461K wasted
- AWS with elasticity: 1 month peak capacity × 1x cost + 11 months baseline capacity = 99% cost savings during off-peak
This is the quintessential cloud elasticity value.
🇻🇳 Giải thích: Site thương mại điện tử có cao điểm mùa vụ gấp 100 lần:
- On-premises: Duy trì capacity đỉnh quanh năm (11 tháng lãng phí) = ~$500K/năm × 12/13 = $461K bị phí.
- AWS với elasticity: 1 tháng capacity đỉnh × chi phí 1x + 11 tháng capacity nền = tiết kiệm 99% lúc ngoài cao điểm.
Đây là giá trị kinh điển của elasticity trên cloud.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (constant 10 instances) — Defeats elasticity advantage, high idle cost / Phá bỏ lợi thế elasticity, chi phí nằm không cao.
- C (reserve capacity yearly) — Reserving for on-demand-style usage costs more than spot/scaling down / Đặt trước cho kiểu dùng on-demand đắt hơn spot/scale down.
- D (largest instance upfront) — Over-provisioning, wastes money during low demand / Cấp dư, phí tiền lúc nhu cầu thấp.
🔑 Key Concept / Khái niệm cốt lõi: Elasticity adds capacity at peaks and removes it after, yielding huge seasonal savings / Elasticity thêm capacity lúc đỉnh rồi gỡ đi, tiết kiệm lớn theo mùa.
Domain 2: Security & Compliance (Q17–Q36)
Q17.
According to the AWS Shared Responsibility Model, who bears the cost of patching the EC2 operating system?
Bản dịch tiếng Việt: Theo Mô hình trách nhiệm chung của AWS, ai chịu chi phí vá lỗi hệ điều hành EC2?
A. AWS handles EC2 OS patching automatically at no additional cost B. The customer is responsible for OS patching — this responsibility impacts total cost of EC2 ownership C. Both AWS and customer split the patching cost D. Patching is optional and costs are borne equally
Correct answer: B Bản dịch đáp án đúng: B. Khách hàng chịu trách nhiệm vá lỗi hệ điều hành - trách nhiệm này ảnh hưởng đến tổng chi phí sở hữu EC2
🇬🇧 Explanation: Shared Responsibility Model:
- AWS: Patches the hypervisor, underlying infrastructure
- Customer: Patches the EC2 operating system (Windows, Linux, etc.)
EC2 OS patching is a customer responsibility, part of the Total Cost of Ownership calculation. AWS RDS, by contrast, patches the DB engine automatically (AWS responsibility).
🇻🇳 Giải thích: Shared Responsibility Model:
- AWS: Vá hypervisor và hạ tầng nền.
- Khách hàng: Vá hệ điều hành EC2 (Windows, Linux, v.v.).
Vá OS của EC2 là trách nhiệm của bạn, và nằm trong tính toán Total Cost of Ownership. Ngược lại, AWS RDS tự vá DB engine (trách nhiệm của AWS).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (AWS patches EC2 OS) — No; AWS only handles hypervisor patching / Không; AWS chỉ lo vá hypervisor.
- C (shared) — No; it's clearly customer responsibility / Không; rõ ràng là trách nhiệm của bạn.
- D (optional) — Patching is required for security; it's not optional / Vá là bắt buộc để bảo mật; không phải tùy chọn.
🔑 Key Concept / Khái niệm cốt lõi: Customer patches EC2 OS; AWS patches RDS engine / Bạn vá OS của EC2; AWS vá engine của RDS.
Q18. (Select THREE)
Which of the following security implementations in AWS have ZERO incremental cost beyond the service itself? (Select THREE)
Bản dịch tiếng Việt: Cách triển khai bảo mật nào sau đây trong AWS có chi phí gia tăng bằng 0 ngoài bản thân dịch vụ? (Chọn BA)
A. Configuring Security Groups (firewall rules at instance level) B. Enabling Multi-Factor Authentication (MFA) on the root account C. Creating IAM users and assigning least-privilege policies D. Using AWS Shield Advanced for DDoS protection (requires monthly fee) E. Implementing network encryption via VPC Flow Logs
Correct answer: A, B, C Bản dịch đáp án đúng: A. Định cấu hình Nhóm bảo mật (quy tắc tường lửa ở cấp phiên bản); B. Kích hoạt xác thực đa yếu tố (MFA) trên tài khoản root; C. Tạo người dùng IAM và chỉ định chính sách có ít đặc quyền nhất
🇬🇧 Explanation: These security controls are free to implement:
- A (Security Groups): Create/modify firewall rules at instance level → no additional charge
- B (MFA): Enable via virtual device (Google Authenticator, Authy) → no charge
- C (IAM): Create users, groups, policies → no per-user or per-API charge; IAM itself is free
Security doesn't require large spending in AWS; best practices use free IAM + Security Groups + MFA.
🇻🇳 Giải thích: Các kiểm soát bảo mật sau triển khai miễn phí:
- A (Security Groups): Tạo/sửa luật firewall ở cấp instance → không tính thêm phí.
- B (MFA): Bật qua thiết bị ảo (Google Authenticator, Authy) → miễn phí.
- C (IAM): Tạo user, group, policy → không tính phí theo user hay theo API; bản thân IAM miễn phí.
Bảo mật trên AWS không cần chi nhiều tiền; best practice dùng IAM + Security Groups + MFA đều miễn phí.
❌ Why others are wrong / Vì sao đáp án khác sai:
- D (Shield Advanced) — ~$3,000/month, not free / Khoảng $3,000/tháng, không miễn phí.
- E (VPC Flow Logs) — Flow Logs are free to enable, but S3 storage costs apply if exported / Bật Flow Logs miễn phí, nhưng tốn phí lưu trữ S3 nếu export.
🔑 Key Concept / Khái niệm cốt lõi: Security Groups, MFA, and IAM add no extra cost / Security Groups, MFA và IAM không tốn thêm chi phí.
Q19.
Which security decision can indirectly reduce total cost of ownership by preventing breaches?
Bản dịch tiếng Việt: Quyết định bảo mật nào có thể gián tiếp giảm tổng chi phí sở hữu bằng cách ngăn chặn vi phạm?
A. Using MFA and least-privilege IAM policies to prevent unauthorized access that could lead to costly security incidents B. Disabling logging to reduce storage costs C. Using the root account for all operations to simplify management D. Removing encryption to improve application performance and reduce licensing costs
Correct answer: A Bản dịch đáp án đúng: A. Sử dụng chính sách MFA và IAM có ít đặc quyền nhất để ngăn chặn truy cập trái phép có thể dẫn đến sự cố bảo mật tốn kém
🇬🇧 Explanation: Breach prevention saves money by avoiding incident response costs:
- MFA + least-privilege IAM → prevents unauthorized access → prevents costly breach
- Breach costs include: incident response, forensics, notification, potential fines, reputation damage (e.g., Capital One breach = $80M settlement)
Prevention is dramatically cheaper than responding to a breach.
🇻🇳 Giải thích: Phòng ngừa sự cố (breach) giúp tiết kiệm tiền nhờ tránh chi phí ứng cứu:
- MFA + IAM least-privilege → chặn truy cập trái phép → tránh sự cố tốn kém.
- Chi phí một vụ breach gồm: ứng cứu sự cố, điều tra forensics, thông báo, phạt tiềm tàng, tổn hại uy tín (ví dụ vụ Capital One = dàn xếp $80M).
Phòng ngừa rẻ hơn rất nhiều so với xử lý hậu quả breach.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (disable logging) — Reduces cost but increases breach risk (false savings) / Giảm chi phí nhưng tăng rủi ro breach (tiết kiệm giả).
- C (root account daily) — Increases breach risk (bad practice) / Tăng rủi ro breach (thói quen xấu).
- D (remove encryption) — Increases breach risk and data exposure liability / Tăng rủi ro breach và trách nhiệm lộ dữ liệu.
🔑 Key Concept / Khái niệm cốt lõi: MFA + least-privilege prevent breaches far more cheaply than incident response / MFA + least-privilege ngừa breach rẻ hơn nhiều so với ứng cứu sự cố.
Q20.
AWS provides the free Trusted Advisor service with core checks. Which cost-optimization check does Trusted Advisor provide at no additional cost?
Bản dịch tiếng Việt: AWS cung cấp dịch vụ Trusted Advisor miễn phí với các bước kiểm tra cốt lõi. Trusted Advisor cung cấp biện pháp kiểm tra tối ưu hóa chi phí nào mà không mất thêm phí?
A. Identifies underutilized EC2 instances and suggests right-sizing or Spot Instances B. Recommends Reserved Instances for long-running workloads C. Detects idling RDS instances to optimize database costs D. All of the above — the core checks include multiple cost optimization recommendations
Correct answer: D Bản dịch đáp án đúng: D. Tất cả những điều trên — các bước kiểm tra cốt lõi bao gồm nhiều đề xuất tối ưu hóa chi phí
🇬🇧 Explanation: Trusted Advisor core checks (free in all tiers) include:
- Cost Optimization: Identifies underutilized instances, idle DB instances, unassociated elastic IPs (all cost money)
- Performance: Identify service limits approaching
- Security: Identify public S3 buckets, MFA not enabled on root, etc.
- Fault Tolerance: Multi-AZ deployment checks
- Service Limits: Warn when approaching limits
These cost-optimization checks help identify wasted spending.
🇻🇳 Giải thích: Các Trusted Advisor core check (miễn phí ở mọi tier) gồm:
- Cost Optimization: Phát hiện instance dùng ít, DB instance nằm không, elastic IP không gắn (đều tốn tiền).
- Performance: Phát hiện sắp chạm service limit.
- Security: Phát hiện S3 bucket công khai, root chưa bật MFA, v.v.
- Fault Tolerance: Kiểm tra triển khai Multi-AZ.
- Service Limits: Cảnh báo khi sắp chạm giới hạn.
Các check tối ưu chi phí này giúp bạn tìm ra khoản chi lãng phí.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (only A) — True but incomplete; B and C also included / Đúng nhưng thiếu; B và C cũng nằm trong đó.
- B (only B) — True but incomplete / Đúng nhưng thiếu.
- C (only C) — True but incomplete / Đúng nhưng thiếu.
🔑 Key Concept / Khái niệm cốt lõi: Trusted Advisor's free core checks include cost-optimization recommendations / Core check miễn phí của Trusted Advisor có cả khuyến nghị tối ưu chi phí.
Q21.
Which AWS security service helps prevent costly security breaches by detecting unauthorized access patterns?
Bản dịch tiếng Việt: Dịch vụ bảo mật AWS nào giúp ngăn chặn các vi phạm bảo mật tốn kém bằng cách phát hiện các mẫu truy cập trái phép?
A. AWS GuardDuty — uses machine learning to detect threats, costing ~$30/month per million CloudTrail events B. AWS CloudTrail is automatically enabled and logs all API calls at no cost (storage in S3 incurs charges) C. MFA on root account is free and prevents unauthorized access (avoiding costly breach incidents) D. All of the above provide layers of threat detection
Correct answer: D Bản dịch đáp án đúng: D. Tất cả những điều trên cung cấp các lớp phát hiện mối đe dọa
🇬🇧 Explanation: All three provide layers of threat detection at different costs:
- A (GuardDuty ~$30/month per M CloudTrail events): ML-based threat detection
- B (CloudTrail free to enable, S3 storage ~$0.023/GB/mo): Logs all API calls, free to turn on
- C (MFA free): Prevents unauthorized access entirely
Together they provide defense-in-depth.
🇻🇳 Giải thích: Cả ba đều cung cấp lớp phát hiện mối đe dọa với chi phí khác nhau:
- A (GuardDuty ~$30/tháng cho mỗi triệu sự kiện CloudTrail): Phát hiện mối đe dọa bằng ML.
- B (CloudTrail bật miễn phí, lưu S3 ~$0.023/GB/tháng): Ghi log mọi API call, bật miễn phí.
- C (MFA miễn phí): Chặn hoàn toàn truy cập trái phép.
Kết hợp lại tạo nên defense-in-depth.
❌ Why others are wrong / Vì sao đáp án khác sai:
- None; all three are accurate threat prevention strategies / Không có; cả ba đều là chiến lược phòng ngừa đúng.
🔑 Key Concept / Khái niệm cốt lõi: GuardDuty + CloudTrail + MFA combine into layered threat detection / GuardDuty + CloudTrail + MFA kết hợp thành phát hiện mối đe dọa nhiều lớp.
Q22. (Select THREE)
Which statements about AWS encryption and cost are correct? (Select THREE)
Bản dịch tiếng Việt: Tuyên bố nào về mã hóa và chi phí AWS là chính xác? (Chọn BA)
A. AWS KMS encryption has per-request costs but prevents data breach costs B. Encryption at-rest in S3 using SSE-S3 (Amazon-managed keys) is free C. Using customer-managed CMK keys in AWS KMS incurs a cost per key per month D. Encryption automatically eliminates the need for other security measures, reducing total security spending E. Enabling encryption on an S3 bucket always doubles your S3 storage bill
Correct answer: A, B, C Bản dịch đáp án đúng: A. Mã hóa AWS KMS có chi phí theo yêu cầu nhưng ngăn ngừa chi phí vi phạm dữ liệu; B. Mã hóa ở trạng thái lưu trữ trong S3 bằng SSE-S3 (khóa do Amazon quản lý) là miễn phí; C. Việc sử dụng khóa CMK do khách hàng quản lý trong AWS KMS sẽ phát sinh chi phí cho mỗi khóa mỗi tháng
🇬🇧 Explanation:
- A (KMS per-request cost ~$0.03/10K requests): Has cost but prevents breach costs
- B (SSE-S3 free): Amazon-managed S3 encryption at no extra charge
- C (Customer-managed CMK ~$1/month + per-request): Per-key monthly fee + request charges
🇻🇳 Giải thích:
- A (KMS tính phí theo request ~$0.03/10K request): Có chi phí nhưng ngừa được chi phí breach.
- B (SSE-S3 miễn phí): Mã hóa S3 do Amazon quản lý, không tính phí thêm.
- C (CMK do khách quản lý ~$1/tháng + phí request): Phí hàng tháng mỗi key + phí theo request.
❌ Why others are wrong / Vì sao đáp án khác sai:
- D (encryption eliminates other controls) — Encryption is one layer of defense, not comprehensive / Mã hóa chỉ là một lớp phòng thủ, không bao trùm tất cả.
- E (encryption doubles S3 bill) — False; SSE-S3/default bucket encryption adds no storage charge / Sai; SSE-S3/mã hóa mặc định không tính thêm phí lưu trữ, không làm hóa đơn tăng gấp đôi.
🔑 Key Concept / Khái niệm cốt lõi: Encryption cost ranges from free (SSE-S3) to paid (KMS CMK), all cheaper than a breach / Chi phí mã hóa từ miễn phí (SSE-S3) đến trả phí (KMS CMK), đều rẻ hơn một vụ breach.
Q23.
Which AWS service provides free security features that help reduce operational costs?
Bản dịch tiếng Việt: Dịch vụ AWS nào cung cấp các tính năng bảo mật miễn phí giúp giảm chi phí vận hành?
A. IAM (users, groups, roles, policies) is completely free — no per-user or per-API call charges B. Security Groups are free to create and configure — only EC2 compute hours cost money C. CloudTrail API logging has free tier but S3 storage costs apply D. All of the above are cost-effective security controls
Correct answer: D Bản dịch đáp án đúng: D. Tất cả những điều trên là kiểm soát an ninh hiệu quả về chi phí
🇬🇧 Explanation:
- A (IAM free): No per-user or per-policy charges
- B (Security Groups free): No charge to create/modify
- C (CloudTrail free to enable, S3 storage charges): API logging is free, but storage costs apply
All provide cost-effective security controls.
🇻🇳 Giải thích:
- A (IAM miễn phí): Không tính phí theo user hay theo policy.
- B (Security Groups miễn phí): Không tính phí khi tạo/sửa.
- C (CloudTrail bật miễn phí, tốn phí lưu S3): Ghi log API miễn phí, nhưng tốn phí lưu trữ.
Tất cả đều là kiểm soát bảo mật tiết kiệm chi phí.
❌ Why others are wrong / Vì sao đáp án khác sai:
- None; all three are accurate / Không có; cả ba đều đúng.
🔑 Key Concept / Khái niệm cốt lõi: IAM + Security Groups + CloudTrail are cost-effective security controls / IAM + Security Groups + CloudTrail là các kiểm soát bảo mật tiết kiệm.
Q24.
A company wants to detect misconfigurations and prevent expensive security incidents. Which compliance service offers cost-effective monitoring?
Bản dịch tiếng Việt: Một công ty muốn phát hiện các cấu hình sai và ngăn chặn các sự cố bảo mật tốn kém. Dịch vụ tuân thủ nào cung cấp dịch vụ giám sát hiệu quả về mặt chi phí?
A. AWS Config tracks configuration changes and can trigger alerts for non-compliance — helps prevent costly mistakes B. AWS Artifact provides free compliance report downloads (SOC 2, PCI DSS) — reduces third-party audit costs C. Both A and B provide cost-effective compliance monitoring D. Compliance is expensive regardless of which service is used
Correct answer: C Bản dịch đáp án đúng: C. Cả A và B đều cung cấp dịch vụ giám sát tuân thủ hiệu quả về mặt chi phí
🇬🇧 Explanation:
- A (AWS Config tracks configuration changes): Enables audit of "when/how did this resource get misconfigured?" — helps prevent expensive mistakes
- B (AWS Artifact free compliance reports): Downloads SOC 2, PCI DSS reports → eliminates need for expensive third-party audits
Both reduce compliance costs.
🇻🇳 Giải thích:
- A (AWS Config theo dõi thay đổi cấu hình): Cho phép audit "tài nguyên này bị cấu hình sai khi nào/như thế nào?" — giúp ngừa sai sót tốn kém.
- B (AWS Artifact báo cáo tuân thủ miễn phí): Tải báo cáo SOC 2, PCI DSS → bỏ được nhu cầu thuê audit bên thứ ba đắt đỏ.
Cả hai đều giảm chi phí tuân thủ.
❌ Why others are wrong / Vì sao đáp án khác sai:
- None; both are accurate / Không có; cả hai đều đúng.
🔑 Key Concept / Khái niệm cốt lõi: AWS Config + Artifact deliver cost-effective compliance monitoring / AWS Config + Artifact mang lại giám sát tuân thủ tiết kiệm.
Q25.
Which best practice prevents costly data exposure in S3?
Bản dịch tiếng Việt: Phương pháp tốt nhất nào ngăn chặn việc lộ dữ liệu tốn kém trong S3?
A. Enable S3 block public access by default (free) to prevent accidental public exposure of sensitive data B. Use Amazon Macie to automatically detect PII in S3 buckets (~$1-10 per month depending on bucket size) C. Store all sensitive data in a highly encrypted format to increase retrieval time D. Both A and B provide defense-in-depth against costly data breaches
Correct answer: D Bản dịch đáp án đúng: D. Cả A và B đều cung cấp khả năng bảo vệ chuyên sâu chống lại các hành vi vi phạm dữ liệu tốn kém
🇬🇧 Explanation:
- A (S3 block public access free): Prevents accidental public exposure of sensitive data
- B (Amazon Macie ~$1-10/month): Automatically detects PII (credit cards, SSN, etc.) in S3
Both prevent costly data exposure incidents.
🇻🇳 Giải thích:
- A (S3 block public access miễn phí): Ngăn lộ dữ liệu nhạy cảm ra công khai do sơ suất.
- B (Amazon Macie ~$1-10/tháng): Tự động phát hiện PII (thẻ tín dụng, SSN, v.v.) trong S3.
Cả hai đều ngăn các sự cố lộ dữ liệu tốn kém.
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (encrypted format + retrieval time) — Doesn't directly prevent exposure; encryption helps post-exposure / Không trực tiếp ngăn lộ; mã hóa chỉ giúp sau khi đã lộ.
🔑 Key Concept / Khái niệm cốt lõi: Block public access (free) + Macie (paid) form defense-in-depth against data exposure / Block public access (miễn phí) + Macie (trả phí) tạo defense-in-depth chống lộ dữ liệu.
Q26. (Select TWO)
Which of the following security implementations offer cost advantages? (Select TWO)
Bản dịch tiếng Việt: Việc triển khai bảo mật nào sau đây mang lại lợi thế về chi phí? (Chọn HAI)
A. AWS Organizations with SCPs can prevent member accounts from launching expensive services (e.g., limit region usage, block certain instance types) B. Implementing network segmentation with private subnets reduces data transfer costs compared to public internet routes C. Using AWS Systems Manager Session Manager (free) instead of bastion hosts reduces EC2 costs D. Encryption always increases total cost regardless of implementation method E. IAM access logging is free and helps audit cost anomalies for unauthorized API calls
Correct answer: A, C Bản dịch đáp án đúng: A. Các tổ chức AWS có SCP có thể ngăn tài khoản thành viên khởi chạy các dịch vụ đắt tiền (ví dụ: giới hạn mức sử dụng theo khu vực, chặn một số loại phiên bản nhất định); C. Sử dụng Trình quản lý phiên của Trình quản lý hệ thống AWS (miễn phí) thay vì máy chủ pháo đài giúp giảm chi phí EC2
🇬🇧 Explanation:
- A (AWS Organizations SCPs prevent expensive service launch): Block member accounts from launching expensive services (e.g., p3.8xlarge GPU instances = $24.48/hr) → cost control at organization level
- C (Session Manager free vs. bastion host EC2): AWS Systems Manager Session Manager provides shell access without managing a separate bastion EC2 → save EC2 hourly cost
🇻🇳 Giải thích:
- A (SCP của AWS Organizations chặn launch service đắt): Chặn member account khởi chạy service đắt (ví dụ GPU instance p3.8xlarge = $24.48/giờ) → kiểm soát chi phí ở cấp tổ chức.
- C (Session Manager miễn phí thay cho bastion host EC2): AWS Systems Manager Session Manager cho truy cập shell mà không cần quản lý EC2 bastion riêng → tiết kiệm chi phí EC2 theo giờ.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (network segmentation reduces data transfer) — Somewhat true but not the primary cost advantage / Phần nào đúng nhưng không phải lợi thế chi phí chính.
- D (encryption always increases cost) — Some encryption is free (SSE-S3); cost depends on method / Một số mã hóa miễn phí (SSE-S3); chi phí tùy phương thức.
- E (IAM logging free) — True but mostly audit-related, not direct cost savings / Đúng nhưng chủ yếu phục vụ audit, không phải tiết kiệm chi phí trực tiếp.
🔑 Key Concept / Khái niệm cốt lõi: SCPs block expensive launches and Session Manager removes bastion EC2 costs / SCP chặn launch đắt và Session Manager bỏ chi phí EC2 bastion.
Q27.
A sensitive S3 bucket was misconfigured to public, exposing customer data. Who bears the financial cost of a resulting security breach?
Bản dịch tiếng Việt: Một bộ chứa S3 nhạy cảm đã bị định cấu hình sai ở chế độ công khai, làm lộ dữ liệu khách hàng. Ai chịu chi phí tài chính do vi phạm an ninh gây ra?
A. AWS, because S3 should be private by default B. The customer — breach response, notification, potential fines, and reputation damage fall on the customer C. Both equally share the cost D. Neither, it's just an accident with no financial impact
Correct answer: B Bản dịch đáp án đúng: B. Khách hàng - phản hồi vi phạm, thông báo, tiền phạt có thể xảy ra và thiệt hại về danh tiếng thuộc về khách hàng
🇬🇧 Explanation: Customer responsibility (per Shared Responsibility Model):
- Customer configures S3 bucket permissions
- Customer's misconfiguration → public access → customer bears breach response costs
AWS is not responsible for customer configuration mistakes.
🇻🇳 Giải thích: Trách nhiệm của khách hàng (theo Shared Responsibility Model):
- Bạn cấu hình quyền cho S3 bucket.
- Cấu hình sai của bạn → public access → bạn chịu chi phí ứng cứu breach.
AWS không chịu trách nhiệm cho lỗi cấu hình của khách hàng.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (AWS responsible) — No; S3 is private by default, customer enabled public / Không; S3 mặc định riêng tư, chính khách bật public.
- C (both equally) — No; customer configured it / Không; khách hàng là người cấu hình.
- D (no financial impact) — Breaches have massive costs / Breach gây chi phí khổng lồ.
🔑 Key Concept / Khái niệm cốt lõi: Customer misconfiguration is the customer's responsibility and cost / Cấu hình sai của khách hàng là trách nhiệm và chi phí của khách hàng.
Q28.
Which security service has the lowest additional cost while providing critical audit capabilities?
Bản dịch tiếng Việt: Dịch vụ bảo mật nào có chi phí bổ sung thấp nhất trong khi vẫn cung cấp khả năng kiểm tra quan trọng?
A. AWS CloudTrail is free to enable, but storing logs in S3 incurs storage costs (~$0.023 per GB/month) B. CloudTrail is completely free including storage C. CloudTrail logs must be exported to third-party tools (additional cost) D. CloudTrail cost depends on the number of users in IAM
Correct answer: A Bản dịch đáp án đúng: A. AWS CloudTrail được kích hoạt miễn phí nhưng việc lưu trữ nhật ký trong S3 sẽ phát sinh chi phí lưu trữ (~0,023 USD mỗi GB/tháng)
🇬🇧 Explanation: CloudTrail is free to enable but has costs to store logs in S3:
- Enable CloudTrail: Free (logs to S3)
- S3 storage: ~$0.023 per GB/month (if storing 1TB = ~$23/month)
This is often the lowest-cost audit solution for most organizations.
🇻🇳 Giải thích: CloudTrail bật miễn phí nhưng tốn phí lưu log trong S3:
- Bật CloudTrail: Miễn phí (ghi log vào S3).
- Lưu S3: ~$0.023/GB/tháng (lưu 1TB = ~$23/tháng).
Đây thường là giải pháp audit chi phí thấp nhất cho phần lớn tổ chức.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (completely free) — Storage costs apply / Vẫn tốn phí lưu trữ.
- C (must export to third-party) — Can export but not required / Có thể export nhưng không bắt buộc.
- D (depends on IAM user count) — CloudTrail logs all API calls regardless of user count / CloudTrail ghi mọi API call bất kể số lượng user.
🔑 Key Concept / Khái niệm cốt lõi: CloudTrail is free to enable; only S3 log storage ($0.023/GB/mo) costs money / CloudTrail bật miễn phí; chỉ tốn phí lưu log S3 ($0.023/GB/tháng).
Q29.
When evaluating which AWS support plan to purchase, which cost-related security consideration applies?
Bản dịch tiếng Việt: Khi đánh giá nên mua gói hỗ trợ AWS nào, cân nhắc bảo mật liên quan đến chi phí nào sẽ được áp dụng?
A. Business and Enterprise support plans include Trusted Advisor full checks that identify security misconfigurations before they become costly incidents B. Basic plan includes all security recommendations at no cost C. Security is entirely AWS's responsibility, so support plan choice doesn't affect security costs D. All support plans provide equivalent security monitoring
Correct answer: A Bản dịch đáp án đúng: A. Các gói hỗ trợ Doanh nghiệp và Doanh nghiệp bao gồm các bước kiểm tra toàn diện của Trusted Advisor nhằm xác định các cấu hình sai về bảo mật trước khi chúng trở thành sự cố tốn kém
🇬🇧 Explanation: Business and Enterprise support plans include full Trusted Advisor checks:
- Basic plan: 7 core checks (free)
- Business/Enterprise: All checks including cost optimization, security depth, fault tolerance
Full checks identify misconfigurations before they cause costly incidents (e.g., a public S3 bucket with sensitive data before breach).
🇻🇳 Giải thích: Gói support Business và Enterprise bao gồm toàn bộ Trusted Advisor checks:
- Gói Basic: 7 core check (miễn phí).
- Business/Enterprise: Tất cả check gồm tối ưu chi phí, bảo mật chuyên sâu, fault tolerance.
Bộ check đầy đủ phát hiện cấu hình sai trước khi chúng gây sự cố tốn kém (ví dụ S3 bucket công khai chứa dữ liệu nhạy cảm trước khi xảy ra breach).
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (Basic all checks) — Basic plan has only 7 core checks / Gói Basic chỉ có 7 core check.
- C (security entirely AWS) — Customer still responsible for configuration / Khách hàng vẫn chịu trách nhiệm cấu hình.
- D (all equal) — Support plan tiers differ significantly / Các tier gói support khác nhau đáng kể.
🔑 Key Concept / Khái niệm cốt lõi: Business+ support unlocks full Trusted Advisor checks for early detection of costly mistakes / Support Business trở lên mở khóa toàn bộ Trusted Advisor check để phát hiện sớm sai sót tốn kém.
Q30. (Select TWO)
Which security and compliance tools help reduce operational costs? (Select TWO)
Bản dịch tiếng Việt: Những công cụ bảo mật và tuân thủ nào giúp giảm chi phí hoạt động? (Chọn HAI)
A. AWS Inspector provides automated security assessments for EC2/Lambda to identify vulnerabilities before costly exploitation B. AWS Trusted Advisor includes cost optimization checks alongside security checks (Basic plan = 7 checks, all tiers) C. CloudFormation ensures consistent security configuration across resources, reducing manual configuration mistakes D. All AWS security services are billed per-incident, so costs are only incurred when problems occur E. AWS IAM password policies are free to implement and prevent unauthorized access
Correct answer: A, B Bản dịch đáp án đúng: A. Thanh tra AWS cung cấp các đánh giá bảo mật tự động cho EC2/Lambda để xác định các lỗ hổng trước khi khai thác tốn kém; B. AWS Trusted Advisor bao gồm kiểm tra tối ưu hóa chi phí cùng với kiểm tra bảo mật (Gói cơ bản = 7 kiểm tra, tất cả các bậc)
🇬🇧 Explanation:
- A (AWS Inspector automated security assessment): Identifies vulnerabilities in EC2/Lambda before exploitation → prevents costly breach
- B (Trusted Advisor includes cost checks): Basic plan (free) includes cost optimization checks
🇻🇳 Giải thích:
- A (AWS Inspector đánh giá bảo mật tự động): Phát hiện lỗ hổng trong EC2/Lambda trước khi bị khai thác → ngừa breach tốn kém.
- B (Trusted Advisor có cost check): Gói Basic (miễn phí) đã có check tối ưu chi phí.
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (CloudFormation ensures consistency) — CloudFormation aids deployment but doesn't directly find cost/security issues / CloudFormation hỗ trợ triển khai nhưng không trực tiếp tìm vấn đề chi phí/bảo mật.
- D (services billed per-incident) — Most AWS services don't work this way; charges are structural / Phần lớn service AWS không tính theo sự cố; phí mang tính cấu trúc.
- E (IAM password policies free) — True but less directly valuable than A/B / Đúng nhưng kém giá trị trực tiếp hơn A/B.
🔑 Key Concept / Khái niệm cốt lõi: Inspector finds vulnerabilities; Trusted Advisor's free checks find cost waste / Inspector tìm lỗ hổng; check miễn phí của Trusted Advisor tìm lãng phí chi phí.
Q31.
Which AWS service, when enabled, provides free logging to help identify cost anomalies caused by unauthorized API calls?
Bản dịch tiếng Việt: Dịch vụ AWS nào khi được bật sẽ cung cấp tính năng ghi nhật ký miễn phí để giúp xác định các điểm bất thường về chi phí do lệnh gọi API trái phép gây ra?
A. CloudTrail — logs all API calls, enabling audit of who accessed/modified resources (storage fees apply) B. VPC Flow Logs — shows network traffic patterns, can identify unusual activity C. CloudWatch Logs — centralizes application and system logs D. All of the above support cost anomaly detection
Correct answer: D Bản dịch đáp án đúng: D. Tất cả những điều trên đều hỗ trợ phát hiện chi phí bất thường
🇬🇧 Explanation:
- A (CloudTrail logs API calls): Enables audit of "who accessed this resource" → identify suspicious access patterns
- B (VPC Flow Logs shows network traffic): Can identify unusual connection patterns
- C (CloudWatch Logs centralizes app logs): Application and system logs can show anomalies
All can help detect cost anomalies caused by unauthorized API calls (e.g., adversary launching expensive instances).
🇻🇳 Giải thích:
- A (CloudTrail ghi log API call): Cho phép audit "ai đã truy cập tài nguyên này" → nhận diện mẫu truy cập đáng ngờ.
- B (VPC Flow Logs hiện lưu lượng mạng): Nhận diện mẫu kết nối bất thường.
- C (CloudWatch Logs gom log ứng dụng): Log ứng dụng và hệ thống có thể lộ ra bất thường.
Tất cả đều giúp phát hiện bất thường chi phí do API call trái phép (ví dụ kẻ tấn công launch instance đắt tiền).
❌ Why others are wrong / Vì sao đáp án khác sai:
- None; all three support anomaly detection / Không có; cả ba đều hỗ trợ phát hiện bất thường.
🔑 Key Concept / Khái niệm cốt lõi: CloudTrail + VPC Flow Logs + CloudWatch surface cost anomalies from unauthorized activity / CloudTrail + VPC Flow Logs + CloudWatch phát lộ bất thường chi phí từ hoạt động trái phép.
Q32.
How does AWS Artifact help reduce costs for organizations with compliance requirements?
Bản dịch tiếng Việt: AWS Artifact giúp giảm chi phí cho các tổ chức có yêu cầu tuân thủ như thế nào?
A. Provides free access to SOC 1/2/3, PCI DSS, and other compliance reports — eliminates need for expensive third-party audits B. Artifact charges high fees for each compliance report C. Only available for Enterprise support customers D. Compliance reports from Artifact carry legal liability
Correct answer: A Bản dịch đáp án đúng: A. Cung cấp quyền truy cập miễn phí vào SOC 1/2/3, PCI DSS và các báo cáo tuân thủ khác - loại bỏ nhu cầu kiểm tra tốn kém của bên thứ ba
🇬🇧 Explanation: AWS Artifact provides free download of compliance reports:
- SOC 1/2/3 (System and Organization Controls)
- PCI DSS (Payment Card Industry Data Security Standard)
- HIPAA, ISO, etc.
This eliminates need for expensive third-party auditors ($10K–50K per audit).
🇻🇳 Giải thích: AWS Artifact cho tải báo cáo tuân thủ miễn phí:
- SOC 1/2/3 (System and Organization Controls).
- PCI DSS (Payment Card Industry Data Security Standard).
- HIPAA, ISO, v.v.
Nhờ vậy bạn không cần thuê auditor bên thứ ba đắt đỏ ($10K–50K mỗi lần audit).
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (charges high fees) — Reports are free / Báo cáo miễn phí.
- C (Enterprise only) — Available to all AWS customers / Mọi khách hàng AWS đều dùng được.
- D (carries legal liability) — Not the primary purpose / Không phải mục đích chính.
🔑 Key Concept / Khái niệm cốt lõi: Artifact's free compliance reports remove third-party audit costs / Báo cáo tuân thủ miễn phí của Artifact loại bỏ chi phí audit bên thứ ba.
Q33. (Select THREE)
Which statements accurately describe cost implications of security decisions? (Select THREE)
Bản dịch tiếng Việt: Những tuyên bố nào mô tả chính xác ý nghĩa chi phí của các quyết định bảo mật? (Chọn BA)
A. Implementing MFA (free) prevents unauthorized access that could lead to expensive security breaches B. Enabling encryption always increases application latency and reduces user experience C. Using least-privilege IAM policies may add administrative overhead but prevents overly-permissive access that leads to breaches D. Breach response and incident investigation costs typically exceed proactive security spending E. Security is always the most expensive pillar of the Well-Architected Framework
Correct answer: A, C, D Bản dịch đáp án đúng: A. Triển khai MFA (miễn phí) ngăn chặn truy cập trái phép có thể dẫn đến các vi phạm bảo mật tốn kém; C. Việc sử dụng các chính sách IAM có ít đặc quyền nhất có thể tăng thêm chi phí quản trị nhưng ngăn chặn quyền truy cập quá mức dẫn đến vi phạm; D. Chi phí ứng phó vi phạm và điều tra sự cố thường vượt quá chi tiêu bảo mật chủ động
🇬🇧 Explanation:
- A (MFA prevents breach → saves costs): Free prevention is cheaper than breach response ($1M+ typical)
- C (least-privilege admin overhead vs. breach): Admin overhead is minimal cost compared to breach response
- D (breach response >> security spending): Breach response costs $1M–100M+; preventive security is 1% of that
🇻🇳 Giải thích:
- A (MFA ngừa breach → tiết kiệm): Phòng ngừa miễn phí rẻ hơn ứng cứu breach (thường $1M+).
- C (chi phí quản trị least-privilege so với breach): Chi phí quản trị rất nhỏ so với ứng cứu breach.
- D (ứng cứu breach >> chi cho bảo mật): Ứng cứu breach tốn $1M–100M+; bảo mật phòng ngừa chỉ chiếm 1% con số đó.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (encryption reduces latency) — Encryption may add minimal latency, not remove it / Mã hóa có thể thêm chút độ trễ, không giảm.
- E (security most expensive pillar) — Cost Optimization typically has the highest savings potential / Cost Optimization thường là pillar có tiềm năng tiết kiệm cao nhất.
🔑 Key Concept / Khái niệm cốt lõi: Low-cost preventive security beats expensive breach response many times over / Bảo mật phòng ngừa chi phí thấp đánh bại ứng cứu breach đắt đỏ nhiều lần.
Q34.
Which service provides cost-effective continuous compliance monitoring for AWS infrastructure?
Bản dịch tiếng Việt: Dịch vụ nào cung cấp khả năng giám sát tuân thủ liên tục, tiết kiệm chi phí cho cơ sở hạ tầng AWS?
A. AWS Config rules can automatically audit resource configurations — helps catch expensive misconfigurations early B. Only Enterprise support customers can use AWS Config C. AWS Config costs are prohibitive for small organizations D. Compliance monitoring requires hiring a dedicated compliance team
Correct answer: A Bản dịch đáp án đúng: A. Quy tắc AWS Config có thể tự động kiểm tra cấu hình tài nguyên — giúp sớm phát hiện các cấu hình sai tốn kém
🇬🇧 Explanation: AWS Config rules automatically audit whether resources comply with configuration standards:
- Rule examples: "S3 buckets must have versioning enabled," "EC2 must have security groups," "RDS must be encrypted"
- Catches misconfigurations early (prevents expensive incidents) before they propagate
🇻🇳 Giải thích: AWS Config rules tự động kiểm tra tài nguyên có tuân thủ chuẩn cấu hình hay không:
- Ví dụ rule: "S3 bucket phải bật versioning", "EC2 phải có security group", "RDS phải được mã hóa".
- Bắt cấu hình sai sớm (ngừa sự cố tốn kém) trước khi lan rộng.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (Enterprise only) — Available to all AWS customers / Mọi khách hàng AWS đều dùng được.
- C (prohibitive cost) — Config costs ~$0.003 per evaluation (negligible for most orgs) / Config tốn ~$0.003 mỗi đánh giá (không đáng kể với hầu hết tổ chức).
- D (requires dedicated team) — Config is automated; a team is only needed to act on findings / Config tự động; chỉ cần đội ngũ để xử lý kết quả.
🔑 Key Concept / Khái niệm cốt lõi: Config rules automatically audit configurations to catch costly mistakes early / Config rules tự động audit cấu hình để bắt sớm sai sót tốn kém.
Q35.
When implementing encryption with AWS KMS, which cost consideration applies?
Bản dịch tiếng Việt: Khi triển khai mã hóa bằng AWS KMS, việc cân nhắc chi phí nào sẽ được áp dụng?
A. AWS KMS has a monthly fee per key ($1) plus per-request charges ($0.03 per 10K requests)
B. KMS encryption is completely free
C. KMS costs depend on the size of data encrypted
D. KMS is only available as an add-on to premium support plans
Correct answer: A Bản dịch đáp án đúng: A. AWS KMS có phí hàng tháng cho mỗi khóa (~$1) cộng với phí theo yêu cầu (~0,03 USD cho mỗi 10 nghìn yêu cầu)
🇬🇧 Explanation: AWS KMS (Key Management Service) pricing:
- Monthly fee per customer-managed key: ~$1/month (on top of AWS account)
- Per-request API charge: ~$0.03 per 10,000 requests
KMS is not free but is cost-effective for protecting sensitive encryption keys.
🇻🇳 Giải thích: Giá AWS KMS (Key Management Service):
- Phí hàng tháng mỗi customer-managed key: ~$1/tháng (cộng thêm vào account AWS).
- Phí API theo request: ~$0.03 cho mỗi 10,000 request.
KMS không miễn phí nhưng tiết kiệm cho việc bảo vệ khóa mã hóa nhạy cảm.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (completely free) — KMS has monthly + per-request charges / KMS có phí hàng tháng + phí theo request.
- C (depends on data size) — Per-request charges don't scale with data size / Phí theo request không tăng theo kích thước dữ liệu.
- D (premium support only) — Available to all AWS customers / Mọi khách hàng AWS đều dùng được.
🔑 Key Concept / Khái niệm cốt lõi: KMS costs ~$1/month/key + ~$0.03/10K requests, affordable for key management / KMS tốn ~$1/tháng/key + ~$0.03/10K request, vừa túi tiền cho quản lý khóa.
Q36.
Which IAM security practice reduces cost by preventing resource waste?
Bản dịch tiếng Việt: Biện pháp bảo mật IAM nào giúp giảm chi phí bằng cách ngăn ngừa lãng phí tài nguyên?
A. Restrict permissions to prevent developers from accidentally launching expensive services or changing Reserved Instance settings B. Grant root account access to simplify management C. Allow all users full access to all services to avoid per-permission billing D. IAM permissions have no impact on cost, only on access control
Correct answer: A Bản dịch đáp án đúng: A. Hạn chế quyền để ngăn nhà phát triển vô tình khởi chạy các dịch vụ đắt tiền hoặc thay đổi cài đặt Phiên bản dự trữ
🇬🇧 Explanation: Least privilege prevents:
- Developers accidentally launching expensive services (e.g., p3.8xlarge GPU = $24.48/hr)
- Developers modifying Reserved Instance commitments
- Overly permissive policies that enable accidental resource deletion/recreation
Restricting permissions to "minimum necessary" prevents costly mistakes.
🇻🇳 Giải thích: Least privilege ngăn:
- Developer vô tình launch service đắt (ví dụ GPU p3.8xlarge = $24.48/giờ).
- Developer chỉnh sửa cam kết Reserved Instance.
- Policy quá rộng dẫn tới xóa/tạo lại tài nguyên ngoài ý muốn.
Giới hạn quyền ở mức "tối thiểu cần thiết" giúp ngừa sai sót tốn kém.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (all read-only) — Too restrictive; legitimate operations require write access / Quá hạn chế; thao tác hợp lệ cần quyền ghi.
- C (root for all ops) — Root has no restrictions; dangerous for cost control / Root không bị hạn chế; nguy hiểm cho kiểm soát chi phí.
- D (no policies) — No policies = no restrictions = uncontrolled spending / Không policy = không hạn chế = chi tiêu mất kiểm soát.
🔑 Key Concept / Khái niệm cốt lõi: Least privilege restricts permissions to the minimum, preventing expensive mistakes / Least privilege giới hạn quyền ở mức tối thiểu, ngừa sai sót tốn kém.
Domain 3: Cloud Technology and Services (Q37–Q58)
Q37.
A company needs fault-tolerant batch processing that can tolerate interruptions. Which EC2 pricing model offers the lowest cost?
Bản dịch tiếng Việt: Một công ty cần xử lý hàng loạt có khả năng chịu lỗi để có thể chịu được sự gián đoạn. Mô hình định giá EC2 nào mang lại chi phí thấp nhất?
A. On-Demand — provides reliability but costs 100% of full hourly rate B. Reserved Instances — requires 1–3 year commitment, reduces cost ~72% but not optimized for batch C. Spot Instances — offers up to 90% discount, ideal for fault-tolerant batch jobs that can handle interruptions D. Dedicated Hosts — guarantees physical isolation but costs more than on-demand
Correct answer: C Bản dịch đáp án đúng: C. Phiên bản dùng ngay — giảm giá lên tới 90%, lý tưởng cho các công việc hàng loạt có khả năng chịu lỗi cao và có thể xử lý tình trạng gián đoạn
🇬🇧 Explanation: EC2 pricing comparison for fault-tolerant batch processing:
- On-Demand: $0.0832/hour × 730 hours/month = ~$60/month (expensive for one-time job)
- Reserved Instance: Requires 1–3 year commitment; not ideal for ad-hoc batch
- Spot Instance: as low as ~$0.012/hour (up to ~90% discount) for t3.large = ~$9/month for same workload
- Spot is ideal for fault-tolerant batch processing (can handle interruptions)
Cost difference: On-Demand $60 vs. Spot ~$9 = up to ~90% savings for batch.
🇻🇳 Giải thích: So sánh giá EC2 cho batch processing chịu lỗi (fault-tolerant):
- On-Demand: $0.0832/giờ × 730 giờ/tháng = ~$60/tháng (đắt cho job một lần).
- Reserved Instance: Cần cam kết 1–3 năm; không hợp batch ad-hoc.
- Spot Instance: Thấp tới ~$0.012/giờ (giảm tới ~90%) cho t3.large = ~$9/tháng cho cùng workload.
- Spot lý tưởng cho batch processing chịu lỗi (xử lý được khi bị ngắt).
Chênh lệch: On-Demand $60 so với Spot ~$9 = tiết kiệm tới ~90% cho batch.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (On-Demand) — Reliable but costs the full hourly rate; Spot can be up to ~90% cheaper / Tin cậy nhưng trả full giá giờ; Spot rẻ hơn tới ~90%.
- B (RI) — Requires long-term commitment, overkill for batch / Cần cam kết dài hạn, dư thừa cho batch.
- D (Dedicated Hosts) — Expensive; for license compliance, not cost optimization / Đắt; dành cho tuân thủ license, không phải tối ưu chi phí.
🔑 Key Concept / Khái niệm cốt lõi: Fault-tolerant batch → Spot Instances for up to ~90% savings / Batch chịu lỗi → Spot Instances tiết kiệm tới ~90%.
Q38. (Select THREE)
Which of the following represent cost-effective EC2 purchasing strategies? (Select THREE)
Bản dịch tiếng Việt: Điều nào sau đây thể hiện chiến lược mua EC2 hiệu quả về mặt chi phí? (Chọn BA)
A. Use Reserved Instances for 3-year stable workloads to reduce per-unit cost ~72% B. Use Spot Instances for fault-tolerant or batch workloads to save ~90% on compute C. Use On-Demand for all workloads to simplify billing D. Combine multiple pricing models (RIs for baseline + Spot for variable demand) for cost optimization E. Purchase the largest available instance to get the best per-vCPU cost
Correct answer: A, B, D Bản dịch đáp án đúng: A. Sử dụng Phiên bản dự trữ cho khối lượng công việc ổn định trong 3 năm để giảm chi phí trên mỗi đơn vị ~72%; B. Sử dụng Phiên bản dùng ngay cho khối lượng công việc có dung sai lỗi hoặc khối lượng công việc theo lô để tiết kiệm ~90% chi phí điện toán; D. Kết hợp nhiều mô hình định giá (RI cho đường cơ sở + Giao ngay cho nhu cầu thay đổi) để tối ưu hóa chi phí
🇬🇧 Explanation:
- A (RIs ~72% discount): Stable 3-year workload → commit to RI = 72% savings
- B (Spot ~90% discount): Fault-tolerant batch → 90% savings
- D (RI baseline + Spot variable): Hybrid approach → RIs cover baseline, Spot handles spikes = cost optimized
🇻🇳 Giải thích:
- A (RI giảm ~72%): Workload ổn định 3 năm → cam kết RI = tiết kiệm 72%.
- B (Spot giảm ~90%): Batch chịu lỗi → tiết kiệm 90%.
- D (RI cho nền + Spot cho biến động): Cách hybrid → RI lo phần nền, Spot lo spike = tối ưu chi phí.
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (all On-Demand) — Most expensive strategy / Chiến lược đắt nhất.
- E (largest instance best per-vCPU) — False; larger instances have worse per-vCPU pricing (t3.xlarge ~$0.166/hr vs t3.micro ~$0.0104/hr) / Sai; instance lớn hơn có giá mỗi vCPU tệ hơn.
🔑 Key Concept / Khái niệm cốt lõi: RI for baseline + Spot for spikes is the optimal pricing mix / RI cho nền + Spot cho spike là cách phối giá tối ưu.
Q39.
A development team needs to frequently scale up and down their infrastructure. Which combination offers best cost management?
Bản dịch tiếng Việt: Nhóm phát triển cần thường xuyên mở rộng quy mô cơ sở hạ tầng của họ. Sự kết hợp nào cung cấp quản lý chi phí tốt nhất?
A. Reserved Instances locked for 3 years regardless of usage B. Savings Plans (flexible across instance family/region) for baseline load + On-Demand for spikes + Spot for fault-tolerant workloads C. All on-demand to maintain flexibility (highest cost) D. Dedicated Hosts to guarantee lowest total cost
Correct answer: B Bản dịch đáp án đúng: B. Kế hoạch tiết kiệm (linh hoạt giữa các dòng phiên bản/khu vực) cho tải cơ bản + Theo yêu cầu đối với mức tăng đột biến + Spot cho khối lượng công việc có khả năng chịu lỗi
🇬🇧 Explanation: Hybrid EC2 pricing strategy for variable workloads:
- Savings Plans (flexible across instance families/regions): $X per hour commitment, covers baseline
- On-Demand: For predictable spikes beyond baseline
- Spot: For fault-tolerant or background workloads above on-demand
Example: 10 baseline instances (RI/Savings Plan = $X/hr) + 5 spike instances (On-Demand = $Y/hr) + background batch (Spot = $Z/hr with 90% discount).
🇻🇳 Giải thích: Chiến lược giá EC2 hybrid cho workload biến động:
- Savings Plans (linh hoạt qua instance family/region): Cam kết $X/giờ, lo phần nền.
- On-Demand: Cho spike dễ đoán vượt nền.
- Spot: Cho workload chịu lỗi hoặc chạy nền vượt mức on-demand.
Ví dụ: 10 instance nền (RI/Savings Plan = $X/giờ) + 5 instance spike (On-Demand = $Y/giờ) + batch chạy nền (Spot = $Z/giờ giảm 90%).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (RIs locked 3 years) — Inflexible for variable demand / Thiếu linh hoạt cho nhu cầu biến động.
- C (all on-demand) — Most expensive / Đắt nhất.
- D (Dedicated Hosts) — Not for cost optimization / Không dành cho tối ưu chi phí.
🔑 Key Concept / Khái niệm cốt lõi: Savings Plan baseline + On-Demand spikes + Spot batch is cost-optimal for variable load / Savings Plan cho nền + On-Demand cho spike + Spot cho batch là tối ưu chi phí cho tải biến động.
Q40.
An organization runs a database with steady, predictable traffic. Which database pricing strategy minimizes cost?
Bản dịch tiếng Việt: Một tổ chức vận hành cơ sở dữ liệu với lưu lượng truy cập ổn định và có thể dự đoán được. Chiến lược định giá cơ sở dữ liệu nào giúp giảm thiểu chi phí?
A. Amazon RDS On-Demand pay-per-hour without commitment B. Amazon RDS Reserved Instance (1–3 year) reduces cost ~72% for predictable workloads C. Amazon Aurora Serverless — pay per ACU (Aurora Capacity Unit) consumed, best for variable workloads D. Amazon DynamoDB on-demand mode for unpredictable throughput
Correct answer: B Bản dịch đáp án đúng: B. Phiên bản dự trữ Amazon RDS (1–3 năm) giảm chi phí ~72% cho khối lượng công việc có thể dự đoán được
🇬🇧 Explanation: Database pricing for predictable production workload:
- RDS On-Demand: ~$0.09/hour (t3.medium) = ~$65/month (no commitment)
- RDS Reserved Instance (1-year): ~$0.025/hour = ~$18/month (72% savings)
- Aurora Serverless: Best for variable workloads, billed per ACU consumed
Stable, predictable database → RI is ~4x cheaper over 1-3 year horizon.
🇻🇳 Giải thích: Giá database cho production workload dễ đoán:
- RDS On-Demand: ~$0.09/giờ (t3.medium) = ~$65/tháng (không cam kết).
- RDS Reserved Instance (1 năm): ~$0.025/giờ = ~$18/tháng (tiết kiệm 72%).
- Aurora Serverless: Tốt nhất cho workload biến động, tính theo ACU tiêu thụ.
Database ổn định, dễ đoán → RI rẻ hơn ~4 lần trong vòng 1-3 năm.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (On-Demand) — No commitment, but 72% more expensive than RI / Không cam kết, nhưng đắt hơn RI 72%.
- C (Aurora Serverless) — Designed for variable load, overkill for stable DB / Thiết kế cho tải biến động, dư thừa cho DB ổn định.
- D (DynamoDB on-demand) — For NoSQL unpredictable workloads / Dành cho workload NoSQL khó đoán.
🔑 Key Concept / Khái niệm cốt lõi: Stable DB → RDS Reserved Instance for ~72% savings / DB ổn định → RDS Reserved Instance tiết kiệm ~72%.
Q41. (Select THREE)
Which of the following AWS Lambda pricing characteristics make it cost-effective for certain workloads? (Select THREE)
Bản dịch tiếng Việt: Đặc điểm giá AWS Lambda nào sau đây giúp tiết kiệm chi phí cho một số khối lượng công việc nhất định? (Chọn BA)
A. Charged per invocation ($0.0000002 per request) plus GB-seconds ($0.0000166 per GB-second)
B. Always cheaper than EC2 regardless of workload pattern
C. Scales from zero — when idle, no charges apply (unlike EC2 always-on)
D. Bills a flat 24/7 hourly charge even when the function is never invoked
E. Includes free tier (1 million invocations, 400,000 GB-seconds per month)
Correct answer: A, C, E Bản dịch đáp án đúng: A. Được tính phí cho mỗi lệnh gọi (~0,0000002 USD mỗi yêu cầu) cộng với GB-giây (~0,0000166 USD mỗi GB-giây); C. Cân từ 0 — khi không hoạt động, không tính phí (không giống như EC2 luôn bật); E. Bao gồm bậc miễn phí (1 triệu lệnh gọi, 400.000 GB giây mỗi tháng)
🇬🇧 Explanation: AWS Lambda cost characteristics that make it cost-effective:
- A (pricing): ~$0.0000002 per request + ~$0.0000166 per GB-second — pay only for actual usage
- C (scales to zero): When not invoked, zero cost (unlike EC2 always-on)
- E (free tier): 1 million invocations + 400,000 GB-seconds free per month (huge for small projects)
🇻🇳 Giải thích: Các đặc điểm chi phí khiến AWS Lambda tiết kiệm:
- A (giá): ~$0.0000002 mỗi request + ~$0.0000166 mỗi GB-giây — chỉ trả cho mức dùng thực.
- C (co về 0): Khi không được gọi, chi phí bằng 0 (khác EC2 luôn bật).
- E (free tier): 1 triệu lần gọi + 400,000 GB-giây miễn phí mỗi tháng (rất lợi cho dự án nhỏ).
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (always cheaper than EC2) — False; high-volume steady long-running workloads can be cheaper on EC2/Fargate / Sai; workload tải cao, ổn định, chạy lâu có thể rẻ hơn trên EC2/Fargate.
- D (flat 24/7 hourly charge when not invoked) — False; that describes EC2. Lambda charges nothing when idle / Sai; đó là EC2. Lambda không tính phí khi idle.
🔑 Key Concept / Khái niệm cốt lõi: Lambda = pay-per-invocation + scale-to-zero + free tier, ideal for event-driven workloads / Lambda = trả theo lần gọi + co về 0 + free tier, lý tưởng cho workload event-driven.
Q42.
A company wants to host a static website with minimal operational overhead and lowest cost. Which service combination is most cost-effective?
Bản dịch tiếng Việt: Một công ty muốn lưu trữ một trang web tĩnh với chi phí hoạt động tối thiểu và chi phí thấp nhất. Sự kết hợp dịch vụ nào là hiệu quả nhất về chi phí?
A. EC2 instance + EBS storage + RDS database → significant operational cost and higher per-month cost B. S3 for static assets + CloudFront CDN → S3 Standard ~$0.023/GB/mo, CloudFront egress ~$0.085/GB, minimal operational overhead C. Lambda + DynamoDB → overkill for static content, higher cost D. Lightsail with fixed pricing — simpler but higher cost than S3+CloudFront
Correct answer: B Bản dịch đáp án đúng: B. S3 cho nội dung tĩnh + CloudFront CDN → Tiêu chuẩn S3 ~$0,023/GB/tháng, đầu ra CloudFront ~$0,085/GB, chi phí vận hành tối thiểu
🇬🇧 Explanation: Static website cost breakdown:
- A (EC2 + EBS + RDS): $0.0832/hr EC2 (
$60/mo) + EBS ($1/mo) + RDS (~$30/mo) = ~$90+/month minimum (+ operational overhead) - B (S3 + CloudFront): S3 Standard ~$0.023/GB/mo (negligible for static assets ~100GB = $2) + CloudFront egress ~$0.085/GB (negligible for cached content) + no operational overhead = ~$5-10/month
- C (Lambda + DynamoDB): Overkill for static content
- D (Lightsail): Simpler pricing (~$5-40/month) but higher per-unit cost than S3+CloudFront
B is 10-100x cheaper than A for static websites.
🇻🇳 Giải thích: Phân tích chi phí website tĩnh:
- A (EC2 + EBS + RDS): EC2 $0.0832/giờ (
$60/tháng) + EBS ($1/tháng) + RDS (~$30/tháng) = tối thiểu ~$90+/tháng (+ gánh nặng vận hành). - B (S3 + CloudFront): S3 Standard ~$0.023/GB/tháng (không đáng kể với asset tĩnh ~100GB = $2) + egress CloudFront ~$0.085/GB (không đáng kể với nội dung đã cache) + không gánh nặng vận hành = ~$5-10/tháng.
- C (Lambda + DynamoDB): Dư thừa cho nội dung tĩnh.
- D (Lightsail): Giá đơn giản hơn (~$5-40/tháng) nhưng chi phí mỗi đơn vị cao hơn S3+CloudFront.
B rẻ hơn A 10-100 lần cho website tĩnh.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (EC2 + EBS + RDS) — ~$90+/month with operational overhead, far more than S3+CloudFront / ~$90+/tháng kèm gánh nặng vận hành, đắt hơn nhiều S3+CloudFront.
- C (Lambda + DynamoDB) — Overkill for static content / Dư thừa cho nội dung tĩnh.
- D (Lightsail) — Higher per-unit cost than S3+CloudFront / Chi phí mỗi đơn vị cao hơn S3+CloudFront.
🔑 Key Concept / Khái niệm cốt lõi: S3 + CloudFront is the cheapest way to host a static website / S3 + CloudFront là cách rẻ nhất để host website tĩnh.
Q43.
Which S3 storage class ladder represents cost per GB from highest to lowest?
Bản dịch tiếng Việt: Thang lớp lưu trữ S3 nào thể hiện chi phí trên mỗi GB từ cao nhất đến thấp nhất?
A. Standard > Standard-IA > Glacier Instant Retrieval > Glacier Flexible Retrieval > Glacier Deep Archive (exact: $0.023 > $0.0125 > $0.004 > $0.0036 > $0.00099) B. All S3 storage classes cost the same C. Deep Archive is the most expensive (largest retention requirement) D. Storage class cost is independent of retrieval frequency
Correct answer: A Bản dịch đáp án đúng: A. Tiêu chuẩn > Tiêu chuẩn-IA > Truy xuất tức thì Glacier > Truy xuất linh hoạt Glacier > Lưu trữ sâu Glacier (chính xác: 0,023 USD > 0,0125 USD > 0,004 USD > 0,0036 USD > 0,00099 USD)
🇬🇧 Explanation: S3 Storage Class pricing (approximate per GB/month):
- Standard: $0.023 (frequent access)
- Standard-IA: $0.0125 (infrequent, higher retrieval cost)
- Glacier Instant Retrieval: ~$0.004 (archived, millisecond retrieval) — MORE expensive than Flexible
- Glacier Flexible Retrieval: ~$0.0036 (archived, minutes–hours retrieval) — cheaper than Instant
- Glacier Deep Archive: $0.00099 (cheapest, 12-48h retrieval)
Price decreases as retrieval latency increases. Note Glacier Instant Retrieval costs more per GB than Glacier Flexible Retrieval precisely because it offers millisecond access.
🇻🇳 Giải thích: Giá S3 Storage Class (xấp xỉ mỗi GB/tháng):
- Standard: $0.023 (truy cập thường xuyên).
- Standard-IA: $0.0125 (ít truy cập, phí lấy ra cao hơn).
- Glacier Instant Retrieval: ~$0.004 (lưu trữ, lấy ra trong mili-giây) — ĐẮT hơn Flexible.
- Glacier Flexible Retrieval: ~$0.0036 (lưu trữ, lấy ra trong phút–giờ) — rẻ hơn Instant.
- Glacier Deep Archive: $0.00099 (rẻ nhất, lấy ra 12-48 giờ).
Giá giảm khi độ trễ lấy ra tăng. Lưu ý Glacier Instant Retrieval đắt hơn Glacier Flexible Retrieval mỗi GB chính vì nó cho truy cập trong mili-giây.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (all same cost) — False; 23x difference between Standard and Deep Archive / Sai; chênh 23 lần giữa Standard và Deep Archive.
- C (Deep Archive expensive) — False; it's the cheapest / Sai; đây là loại rẻ nhất.
- D (cost independent of retrieval) — False; there's an inverse relationship / Sai; có quan hệ nghịch.
🔑 Key Concept / Khái niệm cốt lõi: Cheaper S3 classes trade slower retrieval for lower storage cost / Các class S3 rẻ hơn đánh đổi tốc độ lấy ra chậm hơn lấy chi phí lưu trữ thấp hơn.
Q44. (Select THREE)
Which statements accurately describe cost-effective use of S3 storage classes? (Select THREE)
Bản dịch tiếng Việt: Câu nào mô tả chính xác việc sử dụng các lớp lưu trữ S3 một cách tiết kiệm chi phí? (Chọn BA)
A. Use S3 Standard for frequent access (worst case 11 nines durability) B. Use S3 Standard-IA for infrequent access to reduce storage cost, accept higher retrieval cost C. Use S3 Glacier for archive data rarely accessed — lowest cost (~$0.004/GB) with retrieval delay (hours) D. Use S3 Intelligent-Tiering to auto-move objects between tiers based on access patterns, reducing manual optimization E. All S3 classes offer identical retrieval costs
Correct answer: A, B, D Bản dịch đáp án đúng: A. Sử dụng S3 Standard để truy cập thường xuyên (trong trường hợp xấu nhất là độ bền 11 giây); B. Sử dụng S3 Standard-IA cho những trường hợp truy cập không thường xuyên nhằm giảm chi phí lưu trữ, chấp nhận chi phí truy xuất cao hơn; D. Sử dụng S3 Phân bậc thông minh để tự động di chuyển đối tượng giữa các bậc dựa trên mẫu truy cập, giảm tối ưu hóa thủ công
🇬🇧 Explanation:
- A (Standard for frequent): Best practice for frequently accessed data
- B (IA for infrequent): Cheaper storage (~45% reduction) but higher retrieval cost; good tradeoff if accessed < monthly
- D (Intelligent-Tiering auto-moves): Automatically transitions objects between tiers based on access patterns → optimal cost without manual configuration
🇻🇳 Giải thích:
- A (Standard cho truy cập thường xuyên): Best practice cho dữ liệu truy cập thường xuyên.
- B (IA cho ít truy cập): Lưu trữ rẻ hơn (~45%) nhưng phí lấy ra cao hơn; đánh đổi tốt nếu truy cập < hàng tháng.
- D (Intelligent-Tiering tự chuyển): Tự động chuyển object giữa các tier theo mẫu truy cập → tối ưu chi phí mà không phải cấu hình thủ công.
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (Glacier retrieval cost) — Glacier is cheaper for rarely-accessed, but Deep Archive is cheaper still / Glacier rẻ hơn cho dữ liệu hiếm truy cập, nhưng Deep Archive còn rẻ hơn.
- E (identical retrieval costs) — False; retrieval costs vary significantly / Sai; phí lấy ra khác nhau đáng kể.
🔑 Key Concept / Khái niệm cốt lõi: Match S3 class to access pattern; Intelligent-Tiering automates it / Khớp class S3 với mẫu truy cập; Intelligent-Tiering tự động hóa việc đó.
Q45.
An organization stores 10TB of backup data accessed ~2x per year. Which S3 class minimizes cost?
Bản dịch tiếng Việt: Một tổ chức lưu trữ 10TB dữ liệu sao lưu được truy cập ~ 2 lần mỗi năm. Lớp S3 nào giảm thiểu chi phí?
A. S3 Standard (frequent access tier) — $0.023/GB = $230/mo for 10TB B. S3 Glacier Deep Archive (archive, rarely accessed) — $0.00099/GB = ~$10/mo for 10TB, plus retrieval cost when needed C. S3 One Zone-IA — intermediate tier for infrequently accessed data D. S3 Standard-IA — more expensive than Deep Archive for rarely-accessed data
Correct answer: B Bản dịch đáp án đúng: B. S3 Glacier Deep Archive (kho lưu trữ, hiếm khi được truy cập) — 0,00099 USD/GB = ~$10/tháng cho 10TB, cộng với chi phí truy xuất khi cần
🇬🇧 Explanation: 10TB backup data accessed 2x/year (rarely):
- S3 Standard: $0.023/GB × 10,000GB = $230/month = ~$2,760/year
- S3 Deep Archive: $0.00099/GB × 10,000GB = ~$10/month + retrieval cost when accessed
- Retrieval: $0.0000099 per GB, so 10TB retrieval = ~$100 (2x/year = $200 cost)
- Total: ~$120 + $200 = $320/year
- Savings: $2,760 - $320 = $2,440/year (85% savings!)
Deep Archive is dramatically cheaper for rarely-accessed archives.
🇻🇳 Giải thích: 10TB dữ liệu backup truy cập 2 lần/năm (hiếm):
- S3 Standard: $0.023/GB × 10,000GB = $230/tháng = ~$2,760/năm.
- S3 Deep Archive: $0.00099/GB × 10,000GB = ~$10/tháng + phí lấy ra khi truy cập.
- Lấy ra: $0.0000099/GB, nên lấy 10TB = ~$100 (2 lần/năm = $200).
- Tổng: ~$120 + $200 = $320/năm.
- Tiết kiệm: $2,760 - $320 = $2,440/năm (85%!).
Deep Archive rẻ hơn nhiều cho lưu trữ hiếm truy cập.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Standard) — 8-9x more expensive / Đắt hơn 8-9 lần.
- C (One Zone-IA) — $0.0125/GB = $125/mo (still 12x more than Deep Archive) / $0.0125/GB = $125/tháng (vẫn gấp 12 lần Deep Archive).
- D (Standard-IA) — $0.0125/GB (more than Deep Archive) / $0.0125/GB (đắt hơn Deep Archive).
🔑 Key Concept / Khái niệm cốt lõi: Rarely-accessed backups → Deep Archive saves ~85% vs. Standard / Backup hiếm truy cập → Deep Archive tiết kiệm ~85% so với Standard.
Q46. (Select THREE)
Which of the following enable cost optimization through right-sizing and scheduling? (Select THREE)
Bản dịch tiếng Việt: Điều nào sau đây cho phép tối ưu hóa chi phí thông qua việc định cỡ và lập kế hoạch phù hợp? (Chọn BA)
A. AWS Auto Scaling groups with target tracking policies automatically adjust EC2 count based on CPU/memory demand B. AWS Trusted Advisor identifies underutilized instances and recommends right-sizing C. AWS Compute Optimizer analyzes workload patterns and recommends instance types for cost optimization D. Reserved Instances must be purchased for every dev/test instance to enable nightly shutdown scheduling E. All EC2 instances should always run at maximum capacity for performance
Correct answer: A, B, C Bản dịch đáp án đúng: A. Nhóm AWS Auto Scaling với chính sách theo dõi mục tiêu sẽ tự động điều chỉnh số lượng EC2 dựa trên nhu cầu CPU/bộ nhớ; B. AWS Trusted Advisor xác định các phiên bản không được sử dụng đúng mức và đề xuất kích thước phù hợp; C. Trình tối ưu hóa điện toán AWS phân tích các mẫu khối lượng công việc và đề xuất các loại phiên bản để tối ưu hóa chi phí
🇬🇧 Explanation:
- A (Auto Scaling + target tracking): Automatically adjusts EC2 count based on demand (CPU/memory) → right-size to demand, eliminate idle instances
- B (Trusted Advisor): Recommends right-sizing (e.g., "you're using 5% CPU on a t3.large, downsize to t3.micro")
- C (Compute Optimizer): ML analyzes workload patterns, recommends optimal instance types for cost/performance balance
🇻🇳 Giải thích:
- A (Auto Scaling + target tracking): Tự điều chỉnh số EC2 theo nhu cầu (CPU/memory) → right-size theo nhu cầu, bỏ instance nằm không.
- B (Trusted Advisor): Gợi ý right-sizing (ví dụ "bạn dùng 5% CPU trên t3.large, hạ xuống t3.micro").
- C (Compute Optimizer): ML phân tích mẫu workload, gợi ý loại instance tối ưu cân bằng chi phí/hiệu năng.
❌ Why others are wrong / Vì sao đáp án khác sai:
- D (RIs required for nightly shutdown) — False; scheduled scaling/instance scheduler stops instances on a schedule with no RIs needed / Sai; scheduled scaling/instance scheduler tắt instance theo lịch mà không cần RI.
- E (always run at max capacity) — False; running at max 24/7 maximizes cost and defeats right-sizing / Sai; chạy max 24/7 tối đa hóa chi phí và phá bỏ right-sizing.
🔑 Key Concept / Khái niệm cốt lõi: Auto Scaling + Trusted Advisor + Compute Optimizer are the right-sizing toolkit / Auto Scaling + Trusted Advisor + Compute Optimizer là bộ công cụ right-sizing.
Q47.
A distributed application requires low-latency data access across multiple geographic regions. Which AWS service minimizes global data transfer costs?
Bản dịch tiếng Việt: Ứng dụng phân tán yêu cầu truy cập dữ liệu có độ trễ thấp trên nhiều vùng địa lý. Dịch vụ AWS nào giảm thiểu chi phí truyền dữ liệu toàn cầu?
A. Amazon CloudFront (CDN) caches content at 400+ edge locations worldwide, reducing origin data transfer costs B. Amazon DynamoDB global tables replicate data across regions, best for transactional workloads C. AWS Direct Connect private connections reduce data transfer costs vs. public internet D. All of the above reduce transfer costs differently for different use cases
Correct answer: D Bản dịch đáp án đúng: D. Tất cả những điều trên làm giảm chi phí chuyển nhượng khác nhau cho các trường hợp sử dụng khác nhau
🇬🇧 Explanation: All three reduce global data transfer costs differently:
- A (CloudFront CDN): Cache at 400+ edge locations, reduce origin bandwidth charges
- B (DynamoDB global tables): Replicate across regions for low-latency access, reduce inter-region transfer
- C (Direct Connect): Private dedicated connection reduces NAT gateway charges, more consistent vs. public internet
Choice depends on architecture (CDN for content delivery, global tables for databases, Direct Connect for hybrid).
🇻🇳 Giải thích: Cả ba giảm chi phí truyền dữ liệu toàn cầu theo cách khác nhau:
- A (CloudFront CDN): Cache tại 400+ edge location, giảm phí băng thông origin.
- B (DynamoDB global tables): Nhân bản qua các region cho truy cập độ trễ thấp, giảm truyền liên region.
- C (Direct Connect): Kết nối riêng chuyên dụng giảm phí NAT gateway, ổn định hơn internet công cộng.
Chọn loại nào tùy kiến trúc (CDN cho phân phối nội dung, global tables cho database, Direct Connect cho hybrid).
❌ Why others are wrong / Vì sao đáp án khác sai:
- None; all three are accurate transfer cost reduction strategies / Không có; cả ba đều là chiến lược giảm chi phí truyền đúng.
🔑 Key Concept / Khái niệm cốt lõi: CloudFront, DynamoDB global tables, and Direct Connect each cut transfer costs for different use cases / CloudFront, DynamoDB global tables và Direct Connect đều giảm chi phí truyền cho các use case khác nhau.
Q48.
Which AWS serverless service provides the best cost model for variable workloads?
Bản dịch tiếng Việt: Dịch vụ serverless nào của AWS cung cấp mô hình chi phí tốt nhất cho khối lượng công việc thay đổi?
A. AWS Fargate (serverless containers) — pay per vCPU-hour + GB-hour consumed, auto-scales to zero B. AWS Lambda — pay per invocation + GB-second, scales to zero, includes free tier C. AWS App Runner — pay per second of compute when running, simpler than ECS but higher per-unit cost D. EC2 reserved instance — lowest per-unit cost but requires upfront commitment
Correct answer: B Bản dịch đáp án đúng: B. AWS Lambda — trả tiền cho mỗi lệnh gọi + GB-giây, tỷ lệ về 0, bao gồm bậc miễn phí
🇬🇧 Explanation: Serverless cost advantage for variable workloads:
- Lambda: $0.0000002 per invocation + $0.0000166 per GB-second, scales to zero when idle
- Fargate: Charges per vCPU-hour + GB-hour consumed, also scales to zero
- App Runner: Charges per second of compute when running (simpler but higher per-unit cost)
- EC2 Reserved: Locked cost, doesn't scale to zero
Serverless (Lambda/Fargate) excels at cost optimization for variable workloads due to zero idle cost.
🇻🇳 Giải thích: Lợi thế chi phí của serverless cho workload biến động:
- Lambda: $0.0000002 mỗi lần gọi + $0.0000166 mỗi GB-giây, co về 0 khi idle.
- Fargate: Tính theo vCPU-giờ + GB-giờ tiêu thụ, cũng co về 0.
- App Runner: Tính theo giây compute khi chạy (đơn giản hơn nhưng chi phí mỗi đơn vị cao hơn).
- EC2 Reserved: Chi phí cố định, không co về 0.
Serverless (Lambda/Fargate) vượt trội về tối ưu chi phí cho workload biến động nhờ chi phí idle bằng 0.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Fargate cheaper than Lambda here) — Both are serverless; Lambda is often cheaper for event-driven / Cả hai đều serverless; Lambda thường rẻ hơn cho event-driven.
- C (App Runner best) — Simpler but higher per-unit cost / Đơn giản hơn nhưng chi phí mỗi đơn vị cao hơn.
- D (EC2 RI lowest) — Lowest per-unit but requires upfront commitment, doesn't scale to zero / Mỗi đơn vị rẻ nhất nhưng cần cam kết trả trước, không co về 0.
🔑 Key Concept / Khái niệm cốt lõi: Serverless scale-to-zero makes Lambda/Fargate best for variable workloads / Serverless co về 0 khiến Lambda/Fargate tốt nhất cho workload biến động.
Q49. (Select THREE)
Which of the following reduce data transfer costs in AWS architectures? (Select THREE)
Bản dịch tiếng Việt: Điều nào sau đây giúp giảm chi phí truyền dữ liệu trong kiến trúc AWS? (Chọn BA)
A. Use CloudFront CDN to cache content at edge locations, reducing origin bandwidth (CloudFront egress $0.085/GB vs S3 origin egress $0.04 per 100M objects) for faster uploads from global locations$0.09/GB for some regions)
B. Use VPC endpoints for S3/DynamoDB to avoid NAT gateway charges ($0.45/month + $0.45 per million requests)
C. Transfer data within the same AZ (free) vs. cross-AZ (costs) or across regions (expensive)
D. Always use the largest available bandwidth to minimize per-Mbps costs
E. Enable S3 Transfer Acceleration (
Correct answer: A, B, C Bản dịch đáp án đúng: A. Sử dụng CloudFront CDN để lưu vào bộ nhớ đệm nội dung ở các vị trí biên, giảm băng thông gốc (đầu ra CloudFront ~0,085 USD/GB so với đầu ra gốc S3 ~0,09 USD/GB đối với một số vùng); B. Sử dụng điểm cuối VPC cho S3/DynamoDB để tránh phí cổng NAT (~0,45 USD/tháng + 0,45 USD trên một triệu yêu cầu); C. Truyền dữ liệu trong cùng một AZ (miễn phí) so với nhiều AZ (chi phí) hoặc giữa các khu vực (đắt tiền)
🇬🇧 Explanation:
- A (CloudFront reduces origin bandwidth): Caching at edge locations reduces S3 origin data transfer charges (saves ~$0.005/GB if cached efficiently)
- B (VPC endpoints for S3/DynamoDB): Avoid NAT gateway charges (~$0.45/million requests per month), reduce data transfer cost through private connectivity
- C (within AZ free, cross-AZ/region expensive): Data transfer within AZ = free, cross-AZ = ~$0.02/GB (1000x more!), cross-region = even more expensive
🇻🇳 Giải thích:
- A (CloudFront giảm băng thông origin): Cache tại edge location giảm phí truyền dữ liệu từ origin S3 (tiết kiệm ~$0.005/GB nếu cache hiệu quả).
- B (VPC endpoints cho S3/DynamoDB): Tránh phí NAT gateway (~$0.45/triệu request mỗi tháng), giảm chi phí truyền nhờ kết nối riêng.
- C (trong AZ miễn phí, qua AZ/region tốn phí): Truyền trong cùng AZ = miễn phí, qua AZ = ~$0.02/GB (gấp 1000 lần!), qua region = còn đắt hơn.
❌ Why others are wrong / Vì sao đáp án khác sai:
- D (largest bandwidth best) — False; larger bandwidth often increases cost, not decreases / Sai; băng thông lớn hơn thường tăng chi phí, không giảm.
- E (S3 Transfer Acceleration) — Accelerates uploads but adds cost (
$0.04 per 100M objects); only use if speed critical / Tăng tốc upload nhưng tốn thêm ($0.04/100M object); chỉ dùng khi tốc độ quan trọng.
🔑 Key Concept / Khái niệm cốt lõi: CloudFront caching + VPC endpoints + same-AZ traffic minimize transfer cost / CloudFront cache + VPC endpoints + lưu lượng trong cùng AZ giảm thiểu chi phí truyền.
Q50.
A company needs to migrate petabytes of data from on-premises to AWS S3. Which service minimizes data transfer costs?
Bản dịch tiếng Việt: Một công ty cần di chuyển hàng petabyte dữ liệu từ tại chỗ sang AWS S3. Dịch vụ nào giảm thiểu chi phí truyền dữ liệu?
A. AWS DataSync for ongoing continuous sync (pays per TB moved) B. AWS Snow Family (Snowball Edge devices, used in parallel for very large datasets) for one-time bulk transfers — eliminates expensive internet bandwidth charges C. Direct internet upload (free bandwidth) — only practical for small amounts D. AWS DMS (Database Migration Service) — designed for databases, not object storage
Correct answer: B Bản dịch đáp án đúng: B. AWS Snow Family (thiết bị Snowball Edge, được sử dụng song song cho các tập dữ liệu rất lớn) để truyền số lượng lớn một lần — loại bỏ phí băng thông internet tốn kém
🇬🇧 Explanation: Petabyte-scale data migration cost:
- AWS DataSync: Pay per GB moved over the network; for petabyte volumes the transfer fees plus internet bandwidth become very expensive and slow
- AWS Snow Family (Snowball Edge): Physical storage devices shipped to your site; for very large datasets you order multiple devices and transfer them in parallel. A flat per-device service fee replaces expensive per-GB internet egress/ingress
- Example: 1 Snowball Edge (~80TB usable) = a fixed service fee vs. moving 80TB over the internet, which would be far slower and incur ongoing bandwidth costs
- DMS: For databases, not object storage
Snow Family is dramatically cheaper and faster for bulk one-time transfers of large datasets. (AWS Snowmobile, the exabyte-scale truck, has been discontinued — use Snowball Edge devices in parallel for the largest jobs.)
🇻🇳 Giải thích: Chi phí migrate dữ liệu quy mô petabyte:
- AWS DataSync: Trả theo GB truyền qua mạng; với khối lượng petabyte, phí truyền cộng băng thông internet trở nên rất đắt và chậm.
- AWS Snow Family (Snowball Edge): Thiết bị lưu trữ vật lý gửi tới chỗ bạn; với dataset rất lớn bạn đặt nhiều thiết bị và truyền song song. Phí dịch vụ cố định mỗi thiết bị thay cho phí egress/ingress internet đắt đỏ theo GB.
- Ví dụ: 1 Snowball Edge (~80TB dùng được) = phí dịch vụ cố định, so với chuyển 80TB qua internet vốn chậm hơn nhiều và phát sinh phí băng thông liên tục.
- DMS: Dành cho database, không phải object storage.
Snow Family rẻ và nhanh hơn rất nhiều cho việc chuyển dataset lớn một lần. (AWS Snowmobile, chiếc xe tải quy mô exabyte, đã ngừng cung cấp — dùng nhiều thiết bị Snowball Edge song song cho job lớn nhất.)
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (DataSync) — Expensive for petabyte-scale / Đắt cho quy mô petabyte.
- C (internet free) — Data egress from AWS to internet = paid / Egress dữ liệu từ AWS ra internet = tốn phí.
- D (DMS) — For databases, not object storage / Dành cho database, không phải object storage.
🔑 Key Concept / Khái niệm cốt lõi: Petabyte one-time migration → Snow Family physical devices beat internet bandwidth / Migrate petabyte một lần → thiết bị vật lý Snow Family thắng băng thông internet.
Q51.
Which Auto Scaling policy provides the most cost-effective real-time response to demand changes?
Bản dịch tiếng Việt: Chính sách Auto Scaling nào cung cấp phản hồi theo thời gian thực hiệu quả nhất về chi phí đối với những thay đổi về nhu cầu?
A. Manual scaling — requires human intervention, slow to respond B. Scheduled scaling — assumes predictable patterns, may miss unexpected spikes C. Target Tracking scaling — automatically adds/removes instances to maintain target metric (e.g., 70% CPU), responds immediately to demand D. Predictive scaling — uses ML to forecast demand, proactively adjusts capacity
Correct answer: C Bản dịch đáp án đúng: C. Chia tỷ lệ theo dõi mục tiêu - tự động thêm/xóa phiên bản để duy trì chỉ số mục tiêu (ví dụ: 70% CPU), đáp ứng ngay lập tức theo nhu cầu
🇬🇧 Explanation: Auto Scaling target tracking provides the most cost-effective real-time response:
- Manual: Slow, requires human action (hours/days delay in cost optimization)
- Scheduled: Assumes predictable patterns; misses unexpected spikes
- Target Tracking (e.g., 70% CPU): Automatically adds/removes instances within seconds to maintain target → immediate cost response
- Predictive: Uses ML to forecast; most advanced but overkill for most use cases
Target Tracking balances simplicity, speed, and cost efficiency.
🇻🇳 Giải thích: Auto Scaling target tracking cho phản ứng thời gian thực tiết kiệm nhất:
- Manual: Chậm, cần con người (trễ hàng giờ/ngày trong tối ưu chi phí).
- Scheduled: Giả định mẫu dễ đoán; bỏ lỡ spike bất ngờ.
- Target Tracking (ví dụ 70% CPU): Tự thêm/gỡ instance trong vài giây để giữ mục tiêu → phản ứng chi phí tức thì.
- Predictive: Dùng ML để dự báo; tiên tiến nhất nhưng dư thừa cho hầu hết use case.
Target Tracking cân bằng giữa đơn giản, tốc độ và hiệu quả chi phí.
❌ Why others are wrong / Vì sao đáp án khác sai:
- None; Target Tracking is the best balance for most workloads / Không có; Target Tracking cân bằng tốt nhất cho hầu hết workload.
🔑 Key Concept / Khái niệm cốt lõi: Target Tracking auto-adjusts capacity in seconds for optimal cost / Target Tracking tự điều chỉnh capacity trong vài giây để tối ưu chi phí.
Q52. (Select THREE)
Which of the following database choices optimize cost for different access patterns? (Select THREE)
Bản dịch tiếng Việt: Lựa chọn cơ sở dữ liệu nào sau đây tối ưu hóa chi phí cho các kiểu truy cập khác nhau? (Chọn BA)
A. Amazon RDS with reserved instances for stable, predictable production databases B. Amazon Aurora Serverless for variable-load applications — auto-scales ACUs, pay only when in use C. Amazon DynamoDB for unpredictable NoSQL workloads with on-demand billing D. Redshift for real-time transactional systems (OLTP) — it's optimized for OLAP only, wrong use case = wasted cost E. ElastiCache should replace your primary database entirely to eliminate all RDS and DynamoDB costs
Correct answer: A, B, C Bản dịch đáp án đúng: A. Amazon RDS với các phiên bản dành riêng cho cơ sở dữ liệu sản xuất ổn định, có thể dự đoán được; B. Amazon Aurora Serverless dành cho các ứng dụng có tải thay đổi — tự động thay đổi quy mô ACU, chỉ thanh toán khi sử dụng; C. Amazon DynamoDB dành cho khối lượng công việc NoSQL không thể đoán trước với tính năng thanh toán theo yêu cầu
🇬🇧 Explanation:
- A (RDS RI stable production): 1–3 year RI reduces cost ~72% for predictable DB workloads
- B (Aurora Serverless variable load): Auto-scales Aurora Capacity Units (ACUs) based on demand, pay only for consumed ACUs (vs. always-on instance)
- C (DynamoDB on-demand NoSQL): Unpredictable throughput, on-demand mode scales automatically
🇻🇳 Giải thích:
- A (RDS RI cho production ổn định): RI 1–3 năm giảm chi phí ~72% cho DB workload dễ đoán.
- B (Aurora Serverless cho tải biến động): Tự co giãn Aurora Capacity Unit (ACU) theo nhu cầu, chỉ trả cho ACU tiêu thụ (thay vì instance luôn bật).
- C (DynamoDB on-demand cho NoSQL): Throughput khó đoán, chế độ on-demand tự co giãn.
❌ Why others are wrong / Vì sao đáp án khác sai:
- D (Redshift for OLTP) — Wrong use case; Redshift is for OLAP (analytics), not transactional systems / Sai use case; Redshift dành cho OLAP (phân tích), không phải hệ giao dịch.
- E (ElastiCache replaces primary database) — False; ElastiCache is an in-memory cache in front of a database, not durable primary storage / Sai; ElastiCache là cache in-memory đặt trước database, không phải lưu trữ chính bền vững.
🔑 Key Concept / Khái niệm cốt lõi: Match DB choice to pattern: RI (stable), Aurora Serverless (variable), DynamoDB on-demand (unpredictable) / Khớp lựa chọn DB với mẫu: RI (ổn định), Aurora Serverless (biến động), DynamoDB on-demand (khó đoán).
Q53.
Which combination provides the most cost-effective high-availability setup for a web application?
Bản dịch tiếng Việt: Sự kết hợp nào cung cấp thiết lập có tính sẵn sàng cao, hiệu quả nhất về chi phí cho ứng dụng web?
A. Single large EC2 instance in one AZ — no redundancy but lowest hourly cost B. Auto Scaling group (min 2, max 10) across 2 AZs + Application Load Balancer + RDS Multi-AZ — balances cost and availability C. 100 instances across 10 regions — maximum redundancy but prohibitive cost D. Lightsail instances across multiple regions — simpler than EC2 but higher per-unit cost
Correct answer: B Bản dịch đáp án đúng: B. Nhóm Auto Scaling (tối thiểu 2, tối đa 10) trên 2 AZ + Cân bằng tải ứng dụng + RDS Multi-AZ — cân bằng chi phí và tính khả dụng
🇬🇧 Explanation: Cost-effective HA architecture:
- Auto Scaling group (min 2, max 10): Ensures 2 instances always running (HA) across 2 AZs, scales up to 10 during demand spikes
- Application Load Balancer: Distributes traffic across instances
- RDS Multi-AZ: DB failover across AZs (automatic)
- Cost:
2 instances baseline ($0.166/hr) + spikes + RDS Multi-AZ (~$200/mo) = ~$500-600/mo balanced HA
Balances high availability with reasonable cost.
🇻🇳 Giải thích: Kiến trúc HA tiết kiệm:
- Auto Scaling group (min 2, max 10): Đảm bảo luôn có 2 instance chạy (HA) qua 2 AZ, co lên 10 khi spike.
- Application Load Balancer: Phân phối traffic giữa các instance.
- RDS Multi-AZ: DB failover qua các AZ (tự động).
- Chi phí:
2 instance nền ($0.166/giờ) + spike + RDS Multi-AZ (~$200/tháng) = ~$500-600/tháng cho HA cân bằng.
Cân bằng giữa high availability và chi phí hợp lý.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (single instance) — No HA (no redundancy), highest risk / Không HA (không dự phòng), rủi ro cao nhất.
- C (100 instances 10 regions) — Massive overkill, extremely expensive / Dư thừa khổng lồ, cực kỳ đắt.
- D (Lightsail multi-region) — Simpler but higher per-unit cost (
$20/mo × 10 regions = $200 minimum) / Đơn giản hơn nhưng chi phí mỗi đơn vị cao hơn ($20/tháng × 10 region = tối thiểu $200).
🔑 Key Concept / Khái niệm cốt lõi: 2-AZ Auto Scaling + ALB + RDS Multi-AZ balance HA and cost / 2-AZ Auto Scaling + ALB + RDS Multi-AZ cân bằng HA và chi phí.
Q54.
A batch processing job needs to run weekly and complete within 30 minutes. Which combination minimizes cost?
Bản dịch tiếng Việt: Công việc xử lý hàng loạt cần được thực hiện hàng tuần và hoàn thành trong vòng 30 phút. Sự kết hợp nào giảm thiểu chi phí?
A. EC2 On-Demand t3.large (~$0.0832/hr) always running = $60/month wasted
B. EC2 Spot instance ($0.025/hr for same t3.large) + Scheduled Scaling to launch at scheduled time = ~$0.20/week = ~$0.80/month
C. Lambda triggered weekly — but Lambda's maximum timeout is 15 minutes, so it cannot complete a 30-minute job in a single invocation
D. Keep the t3.large running 24/7 but switch it to a 3-year Reserved Instance to lock in the lowest rate
Correct answer: B Bản dịch đáp án đúng: B. Phiên bản EC2 Spot (~$0,025/giờ cho cùng một t3.large) + Mở rộng quy mô theo lịch trình để khởi chạy vào thời gian đã lên lịch = ~$0,20/tuần = ~$0,80/tháng
🇬🇧 Explanation: Batch processing weekly, 30-minute execution:
- B (Spot + scheduled scaling): Scheduled scaling launches a Spot instance only at batch time (~30 min/week ≈ 2 hr/month). At ~$0.025/hr Spot, this is roughly $0.05–$0.20/week — about 98% cheaper than running 24/7. This is the cost-optimal answer.
🇻🇳 Giải thích: Batch processing hàng tuần, chạy 30 phút:
- B (Spot + scheduled scaling): Scheduled scaling chỉ launch một Spot instance vào giờ batch (~30 phút/tuần ≈ 2 giờ/tháng). Với Spot ~$0.025/giờ, tốn khoảng $0.05–$0.20/tuần — rẻ hơn khoảng 98% so với chạy 24/7. Đây là đáp án tối ưu chi phí.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (On-Demand always running) — $0.0832/hr × 730 hr/mo = ~$60/month wasted for a job that runs ~2 hours/month / ~$60/tháng lãng phí cho job chỉ chạy ~2 giờ/tháng.
- C (Lambda for a 30-minute job) — Invalid; Lambda's max execution time is 15 minutes, so it cannot finish a 30-minute job / Không hợp lệ; Lambda chạy tối đa 15 phút nên không xong job 30 phút.
- D (24/7 t3.large on a 3-year RI) — Still pays for the instance 730 hours/month for a job needing ~2 hours — committing to mostly-idle capacity / Vẫn trả cho instance 730 giờ/tháng cho job chỉ cần ~2 giờ — cam kết vào capacity hầu như nằm không.
🔑 Key Concept / Khái niệm cốt lõi: Scheduled scaling + Spot runs a short weekly batch at ~98% lower cost than 24/7 / Scheduled scaling + Spot chạy batch ngắn hàng tuần rẻ hơn ~98% so với 24/7.
Q55.
Which combination optimizes costs for a web application with unpredictable traffic spikes?
Bản dịch tiếng Việt: Sự kết hợp nào tối ưu hóa chi phí cho một ứng dụng web có lưu lượng truy cập tăng đột biến không thể đoán trước?
A. On-Demand EC2 instances only — simple but expensive during spikes B. Reserved Instances only — locked into capacity, wastes money during low-traffic periods C. Reserved Instances (baseline) + Spot Instances (spikes) + Auto Scaling to dynamically balance — hybrid approach minimizes waste D. All Spot Instances — risk of interruption during critical traffic peaks
Correct answer: C Bản dịch đáp án đúng: C. Phiên bản dự trữ (cơ sở) + Phiên bản Spot (tăng đột biến) + Tự động thay đổi quy mô để cân bằng động — phương pháp kết hợp giúp giảm thiểu lãng phí
🇬🇧 Explanation: Unpredictable traffic spikes (e.g., e-commerce flash sales):
- On-Demand only: Always pay full price for capacity you might not use during slow periods
- Reserved only: Locked into baseline cost, but spikes exceed capacity → no auto-scaling, risk
- RI (baseline) + Spot (spikes): RI covers baseline cost (~$X/hr for 10 instances always on), Spot covers spikes (when demand exceeds 10, launch additional Spot at 90% discount). Auto Scaling manages the blend.
- All Spot: Risk of interruption during critical sales peaks
Hybrid approach (RI baseline + Spot spikes) provides cost optimization + reliability.
🇻🇳 Giải thích: Spike traffic khó đoán (ví dụ flash sale thương mại điện tử):
- On-Demand only: Luôn trả full giá cho capacity có thể không dùng lúc vắng.
- Reserved only: Khóa vào chi phí nền, nhưng spike vượt capacity → không auto-scaling, rủi ro.
- RI (nền) + Spot (spike): RI lo chi phí nền (~$X/giờ cho 10 instance luôn bật), Spot lo spike (khi nhu cầu vượt 10, launch thêm Spot giảm 90%). Auto Scaling điều phối hỗn hợp này.
- All Spot: Rủi ro bị ngắt vào đỉnh bán hàng quan trọng.
Cách hybrid (RI nền + Spot spike) cho tối ưu chi phí + độ tin cậy.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (On-Demand only) — Most expensive / Đắt nhất.
- B (RI only) — Inflexible, wastes money during low periods / Thiếu linh hoạt, phí tiền lúc tải thấp.
- D (All Spot) — Risky for critical traffic / Rủi ro cho traffic quan trọng.
🔑 Key Concept / Khái niệm cốt lõi: RI baseline + Spot spikes + Auto Scaling is cost-optimal and reliable / RI nền + Spot spike + Auto Scaling vừa tối ưu chi phí vừa tin cậy.
Q56. (Select THREE)
Which architecture patterns reduce infrastructure costs? (Select THREE)
Bản dịch tiếng Việt: Những mô hình kiến trúc nào làm giảm chi phí cơ sở hạ tầng? (Chọn BA)
A. Monolith on large EC2 + RDS → high baseline cost, hard to scale parts independently B. Microservices on ECS/Fargate with auto-scaling per service — scale only the services that need more capacity C. Serverless (Lambda + DynamoDB) for event-driven workloads — pay only when invoked, auto-scales to zero D. Always use multi-region redundancy to guarantee lowest regional pricing E. Separate dev/test environments that shut down during non-business hours to eliminate off-peak costs
Correct answer: B, C, E Bản dịch đáp án đúng: B. Vi dịch vụ trên ECS/Fargate với khả năng tự động thay đổi quy mô cho mỗi dịch vụ — chỉ mở rộng quy mô cho những dịch vụ cần nhiều dung lượng hơn; C. Serverless (Lambda + DynamoDB) dành cho khối lượng công việc theo sự kiện — chỉ thanh toán khi được gọi, tự động điều chỉnh quy mô về 0; E. Tách biệt các môi trường phát triển/thử nghiệm ngừng hoạt động ngoài giờ làm việc để loại bỏ chi phí ngoài giờ cao điểm
🇬🇧 Explanation:
- B (Microservices on Fargate): Scale only the services that need more capacity, eliminate waste from over-scaling entire monolith
- C (Serverless Lambda + DynamoDB): Auto-scales to zero, pay per invocation
- E (Shut down dev/test after hours): Dev/test rarely runs 24/7; shutting down saves 50-70% of infrastructure cost (e.g., 8-5 business hours = 50% cost savings)
🇻🇳 Giải thích:
- B (Microservices trên Fargate): Chỉ scale các service cần thêm capacity, bỏ lãng phí do scale dư cả monolith.
- C (Serverless Lambda + DynamoDB): Tự co về 0, trả theo lần gọi.
- E (Tắt dev/test ngoài giờ): Dev/test hiếm khi chạy 24/7; tắt đi tiết kiệm 50-70% chi phí hạ tầng (ví dụ giờ làm 8-5 = tiết kiệm 50%).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (monolith) — Difficult to scale parts independently, often leads to over-provisioning / Khó scale từng phần riêng, thường dẫn tới cấp dư.
- D (multi-region) — Increases cost; doesn't reduce / Tăng chi phí; không giảm.
🔑 Key Concept / Khái niệm cốt lõi: Microservices, serverless scale-to-zero, and dev/test shutdown all cut cost / Microservices, serverless co về 0 và tắt dev/test đều giảm chi phí.
Q57.
Which managed AWS service eliminates infrastructure cost without sacrificing reliability?
Bản dịch tiếng Việt: Dịch vụ AWS được quản lý nào giúp loại bỏ chi phí cơ sở hạ tầng mà không làm giảm độ tin cậy?
A. Amazon RDS with Multi-AZ — AWS handles failover, backups, patches; you pay for managed DB service instead of DIY EC2+database B. AWS Elastic Beanstalk — upload code, Elastic Beanstalk handles EC2 provisioning, load balancing, auto-scaling (still pay for underlying EC2) C. AWS Lambda — pay only for invocations + compute time, no servers to manage D. All of the above reduce operational cost through managed services
Correct answer: D Bản dịch đáp án đúng: D. Tất cả những điều trên giúp giảm chi phí vận hành thông qua các dịch vụ được quản lý
🇬🇧 Explanation: All three are managed services that reduce operational cost:
- A (RDS Multi-AZ): AWS handles failover, backups, patching; customer pays for managed DB service vs. DIY EC2+database maintenance
- B (Elastic Beanstalk): AWS handles EC2 provisioning, load balancing, scaling; customer uploads code
- C (Lambda): Fully serverless, auto-scales, no servers to manage
All reduce operational overhead (ops team size, manual scaling tasks).
🇻🇳 Giải thích: Cả ba đều là managed service giảm chi phí vận hành:
- A (RDS Multi-AZ): AWS lo failover, backup, patching; bạn trả cho dịch vụ DB được quản lý thay vì tự bảo trì EC2+database.
- B (Elastic Beanstalk): AWS lo cấp EC2, load balancing, scaling; bạn chỉ upload code.
- C (Lambda): Hoàn toàn serverless, tự co giãn, không server để quản lý.
Tất cả đều giảm gánh nặng vận hành (số nhân sự ops, việc scale thủ công).
❌ Why others are wrong / Vì sao đáp án khác sai:
- None; all are accurate / Không có; cả ba đều đúng.
🔑 Key Concept / Khái niệm cốt lõi: RDS, Beanstalk, and Lambda offload ops to AWS, lowering operational cost / RDS, Beanstalk và Lambda dồn việc vận hành sang AWS, giảm chi phí vận hành.
Q58.
A company wants to analyze CloudTrail logs without running a database or managing servers. Which service provides the lowest cost?
Bản dịch tiếng Việt: Một công ty muốn phân tích nhật ký CloudTrail mà không cần chạy cơ sở dữ liệu hoặc quản lý máy chủ. Dịch vụ nào cung cấp chi phí thấp nhất?
A. Amazon Athena — query S3 logs directly with SQL, pay ~$5 per TB scanned (serverless) B. Amazon RDS — store logs in database, pay for instance + storage (managed but requires instance) C. Amazon Redshift — data warehouse, minimum cluster cost ~$0.25/hour even for small queries D. AWS Glue + Athena — ETL + query, adds cost over Athena alone for simple use cases
Correct answer: A Bản dịch đáp án đúng: A. Amazon Athena — truy vấn S3 ghi nhật ký trực tiếp bằng SQL, trả ~$5 cho mỗi TB được quét (không có máy chủ)
🇬🇧 Explanation: CloudTrail log analysis without a database:
- Amazon Athena: Query S3 directly with SQL, pay ~$5 per TB of data scanned (not stored)
- Example: 100GB CloudTrail logs scanned = $0.50 per query (extremely cheap)
- RDS: Must provision instance (~$30+/mo) + storage, then run queries
- Redshift: Minimum cluster cost ~$0.25/hr even for tiny datasets = ~$180/month minimum
- Glue + Athena: Adds ETL cost on top of Athena
Athena is the cheapest serverless option for ad-hoc queries on S3 data.
🇻🇳 Giải thích: Phân tích log CloudTrail mà không cần database:
- Amazon Athena: Truy vấn trực tiếp S3 bằng SQL, trả ~$5 mỗi TB dữ liệu được quét (không phải lưu trữ).
- Ví dụ: quét 100GB log CloudTrail = $0.50 mỗi query (cực rẻ).
- RDS: Phải cấp instance (~$30+/tháng) + lưu trữ, rồi mới query.
- Redshift: Chi phí cluster tối thiểu ~$0.25/giờ ngay cả với dataset nhỏ = tối thiểu ~$180/tháng.
- Glue + Athena: Thêm chi phí ETL lên trên Athena.
Athena là lựa chọn serverless rẻ nhất cho query ad-hoc trên dữ liệu S3.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (RDS) — Requires an instance, more expensive / Cần instance, đắt hơn.
- C (Redshift) — Expensive minimum cost for analytics / Chi phí tối thiểu cao cho phân tích.
- D (Glue + Athena) — Unnecessary ETL overhead / Gánh nặng ETL không cần thiết.
🔑 Key Concept / Khái niệm cốt lõi: Athena queries S3 at ~$5/TB scanned, the cheapest serverless log analysis / Athena query S3 ở mức ~$5/TB quét, phân tích log serverless rẻ nhất.
Domain 4: Billing, Pricing, and Support (Q59–Q65)
Q59.
A company has 5 AWS accounts with separate billing. How can they reduce total cost through consolidation?
Bản dịch tiếng Việt: Một công ty có 5 tài khoản AWS có thanh toán riêng. Làm thế nào họ có thể giảm tổng chi phí thông qua hợp nhất?
A. AWS Organizations Consolidated Billing combines all accounts into one bill, unlocks volume discounts (e.g., $0.0850/GB for S3 if combined usage qualifies) B. Consolidation always increases costs due to management overhead C. Each account must maintain separate billing for security reasons D. Volume discounts only apply to accounts with >$100K monthly spend
Correct answer: A Bản dịch đáp án đúng: A. Thanh toán tổng hợp của tổ chức AWS kết hợp tất cả các tài khoản vào một hóa đơn, mở khóa chiết khấu theo số lượng (ví dụ: 0,0850 USD/GB cho S3 nếu mức sử dụng kết hợp đủ điều kiện)
🇬🇧 Explanation: AWS Organizations Consolidated Billing combines billing across 5 accounts:
- Single consolidated bill instead of 5 separate invoices
- Volume discounts unlock: If combined usage reaches discount threshold (e.g., 100TB S3), all accounts receive volume price (~$0.0850/GB instead of $0.023/GB retail)
- Example: 5 accounts × 20TB = 100TB combined → unlock volume discount → save ~$0.0025/GB × 100TB = $250/month!
Consolidated Billing is essential for multi-account organizations.
🇻🇳 Giải thích: AWS Organizations Consolidated Billing gộp hóa đơn của 5 account:
- Một hóa đơn gộp thay vì 5 hóa đơn riêng.
- Mở khóa volume discount: Nếu tổng mức dùng đạt ngưỡng giảm giá (ví dụ 100TB S3), mọi account đều hưởng giá volume (~$0.0850/GB thay vì giá lẻ $0.023/GB).
- Ví dụ: 5 account × 20TB = 100TB gộp → mở khóa volume discount → tiết kiệm ~$0.0025/GB × 100TB = $250/tháng!
Consolidated Billing là thiết yếu cho tổ chức nhiều account.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (consolidation increases cost) — False; consolidation unlocks discounts / Sai; gộp lại mở khóa giảm giá.
- C (must keep separate) — Consolidation is optional but recommended for cost / Gộp là tùy chọn nhưng nên làm để tiết kiệm.
- D (discount threshold $100K) — No such requirement; discounts based on usage volume / Không có yêu cầu đó; giảm giá theo khối lượng dùng.
🔑 Key Concept / Khái niệm cốt lõi: Consolidated Billing pools usage to unlock volume discounts across accounts / Consolidated Billing gộp mức dùng để mở khóa volume discount cho các account.
Q60.
Which AWS tool helps forecast monthly spend before deployment?
Bản dịch tiếng Việt: Công cụ AWS nào giúp dự báo chi tiêu hàng tháng trước khi triển khai?
A. AWS Pricing Calculator — estimates costs for proposed architecture, helps avoid surprises B. AWS Cost Explorer — visualizes historical spending (past tense, not forecast) C. AWS Budgets — alerts when spending exceeds thresholds (reactive) D. AWS TCO Calculator — estimates on-premises vs. cloud costs
Correct answer: A Bản dịch đáp án đúng: A. Công cụ tính giá AWS — ước tính chi phí cho kiến trúc được đề xuất, giúp tránh những bất ngờ
🇬🇧 Explanation: AWS Pricing Calculator estimates costs before deployment:
- Input: Desired architecture (EC2 instances, RDS, S3, etc.) + regions + instance types
- Output: Estimated monthly/annual cost
- Use case: "What will this application cost per month?" → Plan budget before launch
🇻🇳 Giải thích: AWS Pricing Calculator ước tính chi phí trước khi triển khai:
- Đầu vào: Kiến trúc mong muốn (EC2, RDS, S3, v.v.) + region + loại instance.
- Đầu ra: Chi phí hàng tháng/hàng năm ước tính.
- Use case: "Ứng dụng này tốn bao nhiêu mỗi tháng?" → Lập ngân sách trước khi launch.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (Cost Explorer) — Shows historical spending (past-tense), not forward forecast / Hiện chi tiêu quá khứ, không dự báo tương lai.
- C (Budgets) — Alerts when spending exceeds threshold (reactive control) / Cảnh báo khi chi vượt ngưỡng (kiểm soát phản ứng).
- D (TCO Calculator) — Compares on-premises vs. cloud, not detailed architecture forecast / So sánh on-premises với cloud, không phải dự báo kiến trúc chi tiết.
🔑 Key Concept / Khái niệm cốt lõi: Pricing Calculator forecasts cost before deploy; Cost Explorer analyzes past cost / Pricing Calculator dự báo chi phí trước deploy; Cost Explorer phân tích chi phí quá khứ.
Q61. (Select TWO)
Which of the following are accurate about AWS Free Tier cost benefits? (Select TWO)
Bản dịch tiếng Việt: Câu nào sau đây là chính xác về lợi ích chi phí Bậc miễn phí của AWS? (Chọn HAI)
A. Always Free — Lambda (1M invocations/mo), DynamoDB (25GB storage), EC2 (none—but 750h t2.micro in 12-month tier) B. 12-Month Free — t2.micro EC2 (750h), 5GB S3, 750h RDS, 20GB data transfer C. Trials — 12 months free access to all AWS services D. Once enrolled, the AWS Free Tier never expires and covers unlimited usage of every service E. Free Tier is equivalent to a permanent discount on all services
Correct answer: A, B Bản dịch đáp án đúng: A. Luôn miễn phí — Lambda (1 triệu lệnh gọi/tháng), DynamoDB (bộ nhớ 25 GB), EC2 (không có—nhưng 750 giờ t2.micro trong bậc 12 tháng); B. Miễn phí 12 tháng — t2.micro EC2 (750h), 5GB S3, 750h RDS, truyền dữ liệu 20GB
🇬🇧 Explanation: AWS Free Tier structure:
- A (Always Free):
- Lambda: 1 million invocations/month, 3.2 million seconds compute/month
- DynamoDB: 25GB storage
- (EC2 t2.micro is not Always Free; it's 12-Month Free)
- B (12-Month Free):
- EC2 t2.micro: 750 hours/month (~1 instance always-on)
- S3: 5GB storage
- RDS: 750 hours (similar to EC2)
- NAT Gateway: 45GB data transfer
🇻🇳 Giải thích: Cấu trúc AWS Free Tier:
- A (Always Free):
- Lambda: 1 triệu lần gọi/tháng, 3.2 triệu giây compute/tháng.
- DynamoDB: 25GB lưu trữ.
- (EC2 t2.micro không thuộc Always Free; nó thuộc 12-Month Free.)
- B (12-Month Free):
- EC2 t2.micro: 750 giờ/tháng (~1 instance luôn bật).
- S3: 5GB lưu trữ.
- RDS: 750 giờ (tương tự EC2).
- NAT Gateway: 45GB truyền dữ liệu.
❌ Why others are wrong / Vì sao đáp án khác sai:
- C (Trials) — Time-limited trials, not "12 months free all services" / Bản dùng thử có hạn, không phải "12 tháng miễn phí mọi service".
- D (never expires, unlimited every service) — False; the 12-month tier expires and all tiers have caps; overages billed at full price / Sai; tier 12 tháng hết hạn và mọi tier đều có giới hạn; vượt mức tính giá đầy đủ.
- E (permanent discount) — False; free tier is separate from pricing tiers / Sai; free tier tách biệt với các pricing tier.
🔑 Key Concept / Khái niệm cốt lõi: Always Free (Lambda, DynamoDB) + 12-Month Free (EC2 t2.micro, S3) cut startup costs / Always Free (Lambda, DynamoDB) + 12-Month Free (EC2 t2.micro, S3) giảm chi phí khởi nghiệp.
Q62.
Which AWS support plan includes a dedicated Technical Account Manager (TAM) for proactive cost optimization review?
Bản dịch tiếng Việt: Gói hỗ trợ AWS nào bao gồm Trình quản lý tài khoản kỹ thuật (TAM) chuyên dụng để chủ động xem xét tối ưu hóa chi phí?
A. Basic — no TAM, no cost optimization recommendations
B. Developer — no TAM ($29/month)
C. Business ($100–500/month depending on spend) — 24/7 support but no TAM
D. Enterprise / Enterprise On-Ramp — includes TAM for cost optimization guidance, infrastructure architecture review
Correct answer: D Bản dịch đáp án đúng: D. Enterprise / Enterprise On-Ramp — bao gồm TAM để được hướng dẫn tối ưu hóa chi phí, đánh giá kiến trúc cơ sở hạ tầng
🇬🇧 Explanation: Dedicated Technical Account Manager (TAM) included in:
- Enterprise (~$15K+/month): Full-time TAM assigned to customer
- Enterprise On-Ramp: Also includes TAM (mid-tier option)
- Not included in: Basic, Developer, Business
TAM proactively reviews infrastructure, recommends cost optimization, architectural improvements → significant cost savings (often 5-10x TAM cost).
🇻🇳 Giải thích: Technical Account Manager (TAM) riêng được bao gồm trong:
- Enterprise (~$15K+/tháng): TAM toàn thời gian gán cho khách hàng.
- Enterprise On-Ramp: Cũng có TAM (tùy chọn tầm trung).
- Không có trong: Basic, Developer, Business.
TAM chủ động rà soát hạ tầng, gợi ý tối ưu chi phí, cải tiến kiến trúc → tiết kiệm đáng kể (thường gấp 5-10 lần chi phí TAM).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Basic) — No TAM / Không có TAM.
- B (Developer) — No TAM (
$29+/month) / Không có TAM ($29+/tháng). - C (Business) — No TAM (
$100–500+/month depending on spend) / Không có TAM ($100–500+/tháng tùy mức chi).
🔑 Key Concept / Khái niệm cốt lõi: Enterprise and Enterprise On-Ramp include a TAM who proactively optimizes cost and architecture / Enterprise và Enterprise On-Ramp có TAM chủ động tối ưu chi phí và kiến trúc.
Q63.
A startup wants to control AWS spending and receive alerts before costs exceed budget. Which combination of services is most effective?
Bản dịch tiếng Việt: Một công ty khởi nghiệp muốn kiểm soát chi tiêu của AWS và nhận thông báo trước khi chi phí vượt quá ngân sách. Sự kết hợp dịch vụ nào là hiệu quả nhất?
A. AWS Budgets (set threshold, receive alerts) + AWS Cost Explorer (analyze trends) + Cost Anomaly Detection (auto-detect unusual spending) B. CloudWatch alarms alone C. Support plan subscriptions only D. Manual monthly billing dashboard review
Correct answer: A Bản dịch đáp án đúng: A. Ngân sách AWS (đặt ngưỡng, nhận thông báo) + AWS Cost Explorer (phân tích xu hướng) + Phát hiện chi phí bất thường (tự động phát hiện chi tiêu bất thường)
🇬🇧 Explanation: Cost control toolkit:
- AWS Budgets: Set spending threshold (e.g., $1,000/month), receive alert when spend reaches 50%, 80%, 100%
- Cost Explorer: Analyze spending trends, identify cost drivers (which services cost most)
- Cost Anomaly Detection: ML detects unusual spending patterns (e.g., "spend jumped 30% this month") → alert to unusual activity
Together they provide: Plan → Monitor → Alert → Detect anomalies = full cost control.
🇻🇳 Giải thích: Bộ công cụ kiểm soát chi phí:
- AWS Budgets: Đặt ngưỡng chi (ví dụ $1,000/tháng), nhận cảnh báo khi chi chạm 50%, 80%, 100%.
- Cost Explorer: Phân tích xu hướng chi tiêu, nhận diện đâu là khoản tốn nhiều nhất.
- Cost Anomaly Detection: ML phát hiện mẫu chi bất thường (ví dụ "chi vọt 30% tháng này") → cảnh báo hoạt động lạ.
Kết hợp lại cho: Lập kế hoạch → Giám sát → Cảnh báo → Phát hiện bất thường = kiểm soát chi phí toàn diện.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (CloudWatch alone) — CloudWatch is infrastructure monitoring, not cost monitoring / CloudWatch giám sát hạ tầng, không phải giám sát chi phí.
- C (support plan) — Support plans provide expert guidance, not automatic alerts / Gói support cho tư vấn chuyên gia, không phải cảnh báo tự động.
- D (manual review) — Slow, reactive / Chậm, mang tính phản ứng.
🔑 Key Concept / Khái niệm cốt lõi: Budgets + Cost Explorer + Anomaly Detection give comprehensive cost control / Budgets + Cost Explorer + Anomaly Detection cho kiểm soát chi phí toàn diện.
Q64. (Select THREE)
Which billing features are included in the AWS Free Tier? (Select THREE)
Bản dịch tiếng Việt: Những tính năng thanh toán nào được bao gồm trong Bậc miễn phí của AWS? (Chọn BA)
A. Consolidated Billing (no cost, part of AWS Organizations — free feature) B. AWS Cost Explorer (free tier allows basic analysis) C. AWS Budgets (free to create budgets + alerts, though full reports may incur charges) D. Trusted Advisor full checks (only with Business+ support plan) E. AWS Pricing Calculator requires a paid Business support subscription before you can generate any estimate
Correct answer: A, B, C Bản dịch đáp án đúng: A. Thanh toán tổng hợp (miễn phí, một phần của AWS Organizations — tính năng miễn phí); B. AWS Cost Explorer (cấp miễn phí cho phép phân tích cơ bản); C. Ngân sách AWS (miễn phí tạo ngân sách + cảnh báo, mặc dù báo cáo đầy đủ có thể phải trả phí)
🇬🇧 Explanation: Free tier billing features:
- A (Consolidated Billing): Free feature of AWS Organizations (no charge to consolidate)
- B (Cost Explorer): Free basic tier to analyze costs
- C (Budgets): Free to create budgets + alerts (the first 2 action-enabled budgets are free; additional budgets ~$0.02/day each)
🇻🇳 Giải thích: Các tính năng billing miễn phí:
- A (Consolidated Billing): Tính năng miễn phí của AWS Organizations (gộp không tính phí).
- B (Cost Explorer): Tier cơ bản miễn phí để phân tích chi phí.
- C (Budgets): Tạo budget + cảnh báo miễn phí (2 budget có action đầu tiên miễn phí; budget thêm ~$0.02/ngày mỗi cái).
❌ Why others are wrong / Vì sao đáp án khác sai:
- D (Trusted Advisor full checks) — Only with Business+ support plan (paid), not free tier / Chỉ có với gói support Business trở lên (trả phí), không thuộc free tier.
- E (Pricing Calculator requires paid Business support) — False; the AWS Pricing Calculator is a completely free public tool, no support subscription or even an AWS account required / Sai; AWS Pricing Calculator là công cụ công khai hoàn toàn miễn phí, không cần gói support hay thậm chí account AWS.
🔑 Key Concept / Khái niệm cốt lõi: Consolidated Billing, Cost Explorer, and Budgets (first 2) are free; full Trusted Advisor needs Business+ / Consolidated Billing, Cost Explorer và Budgets (2 cái đầu) miễn phí; Trusted Advisor đầy đủ cần Business+.
Q65.
Which AWS service provides real-time TCO (Total Cost of Ownership) comparison between on-premises and AWS?
Bản dịch tiếng Việt: Dịch vụ AWS nào cung cấp khả năng so sánh TCO (Tổng chi phí sở hữu) theo thời gian thực giữa tại chỗ và AWS?
A. AWS Pricing Calculator — estimate AWS costs for proposed architecture B. AWS TCO Calculator — compare total on-premises costs vs. cloud over 3–5 year period C. AWS Cost Explorer — analyzes historical AWS spending D. Both A and B provide different perspectives on cost comparison
Correct answer: D Bản dịch đáp án đúng: D. Cả A và B đều đưa ra những quan điểm khác nhau về so sánh chi phí
🇬🇧 Explanation: Both tools serve different purposes:
- AWS Pricing Calculator (A): Estimates detailed cost for proposed AWS architecture
- Input: EC2 instances, regions, duration, storage
- Output: Monthly/annual AWS cost estimate
- AWS TCO Calculator (B): Compares total on-premises costs vs. cloud over 3–5 year period
- Factors in: Server hardware, cooling, power, real estate, IT staff salaries, etc. vs. AWS service costs
- Output: "On-premises $500K/year vs. AWS $200K/year = 60% savings"
Both are essential for cost analysis but serve different questions:
- "How much will my cloud architecture cost?" → Pricing Calculator
- "Should I move from on-premises to cloud?" → TCO Calculator
🇻🇳 Giải thích: Hai công cụ phục vụ mục đích khác nhau:
- AWS Pricing Calculator (A): Ước tính chi phí chi tiết cho kiến trúc AWS đề xuất.
- Đầu vào: EC2 instance, region, thời lượng, lưu trữ.
- Đầu ra: Ước tính chi phí AWS hàng tháng/hàng năm.
- AWS TCO Calculator (B): So sánh tổng chi phí on-premises với cloud trong 3–5 năm.
- Tính tới: Phần cứng server, làm mát, điện, mặt bằng, lương nhân sự IT, v.v. so với chi phí service AWS.
- Đầu ra: "On-premises $500K/năm so với AWS $200K/năm = tiết kiệm 60%".
Cả hai đều thiết yếu cho phân tích chi phí nhưng trả lời câu hỏi khác nhau:
- "Kiến trúc cloud của tôi tốn bao nhiêu?" → Pricing Calculator.
- "Có nên chuyển từ on-premises sang cloud không?" → TCO Calculator.
❌ Why others are wrong / Vì sao đáp án khác sai:
- None; both are accurate comparison tools / Không có; cả hai đều là công cụ so sánh đúng.
🔑 Key Concept / Khái niệm cốt lõi: Pricing Calculator estimates a cloud architecture; TCO Calculator compares on-prem vs. cloud / Pricing Calculator ước tính kiến trúc cloud; TCO Calculator so sánh on-prem với cloud.
Summary: Cost Optimization Theme
This exam emphasizes the financial decision-making across all four domains:
- Domain 1 (Cloud Concepts): Shift from CapEx → OpEx, elasticity, economies of scale
- Domain 2 (Security & Compliance): Free security controls (IAM, SGs, MFA) prevent costly breaches
- Domain 3 (Cloud Tech): Right-sizing, pricing models (RI/Spot/Savings Plans), storage classes, serverless
- Domain 4 (Billing): Cost tools, support plans, free tier, consolidated billing
Key takeaways:
- Always ask: "What is the cheapest option that meets requirements?"
- Avoid over-provisioning: Use elasticity, auto-scaling, right-sizing
- Match pricing to workload: Spot for batch, RI for stable, On-Demand for spikes, Savings Plans for flexibility
- Leverage managed services: Reduce operational overhead (ops team cost)
- Use free tools: Budgets, Cost Explorer, Pricing Calculator, Trusted Advisor
- Prevent breaches: Security investments (MFA, least-privilege) save 1000x their cost in breach prevention
End of Solutions
Estimated study time: 2–3 hours for thorough review
Expected passing score: 700/1000 (52/65 questions)