CertHub
AWSFoundationalCLF-C02

AWS Certified Cloud Practitioner

Tất cả lời giải

CLF-C02 Mock Exam #05 — Security Heavy: Solutions

Answer key + detailed explanations — Bilingual format (EN + VN phần lớn)
Themes: Shared Responsibility nuance, IAM scenarios, encryption at-rest/transit, threat detection, multi-account governance
Reference: Domain 2 knowledge base + AWS official docs


Domain 1: Cloud Concepts (Q1–Q16)

Q1.

Which of the following best describes the Security pillar of the AWS Well-Architected Framework?

Bản dịch tiếng Việt: Câu nào sau đây mô tả đúng nhất trụ cột Bảo mật của AWS Well-Architected Framework?

A. Ensuring applications scale automatically to meet demand B. Implementing strong identity access management and protecting data with encryption C. Optimizing costs by using spot instances and reserved capacity D. Designing systems to recover automatically from failures

Correct answer: B Bản dịch đáp án đúng: B. Triển khai quản lý truy cập danh tính mạnh mẽ và bảo vệ dữ liệu bằng mã hóa

🇬🇧 Explanation:

  • Security pillar focuses on protecting data and implementing strong identity & access management
  • Also includes encryption, network security, and audit/logging
  • B is directly about the Security pillar

🇻🇳 Giải thích: Trụ cột Security của Well-Architected Framework tập trung vào quản lý danh tính & truy cập (IAM), kèm theo encryption, bảo mật network và audit/logging. Đáp án B nói thẳng về Security pillar nên là đáp án đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Performance Efficiency) — about scaling/right-sizing, not access control / về scaling & chọn đúng tài nguyên, không phải kiểm soát truy cập
  • C (Cost Optimization) — about pricing/spend, not IAM / về tối ưu chi phí, không phải IAM
  • D (Reliability) — about recovery & availability / về phục hồi & độ sẵn sàng

🔑 Key Concept / Khái niệm cốt lõi: IAM + encryption + audit = Security pillar. / IAM + encryption + audit thuộc trụ cột Security.

📚 Reference: Domain 1 study guide, Section 4 (Well-Architected Framework)


Q2.

A company wants to move from on-premises to AWS. They are concerned about who manages security. Which statement best describes the AWS Shared Responsibility Model?

Bản dịch tiếng Việt: Một công ty muốn chuyển từ tại chỗ sang AWS. Họ lo ngại về việc ai quản lý an ninh. Câu nào mô tả đúng nhất về Mô hình trách nhiệm chung của AWS?

A. AWS is responsible for all security; the customer has no security obligations B. The customer is responsible for all security; AWS provides the infrastructure C. AWS secures the infrastructure; the customer secures their data and access controls D. Both parties are equally responsible for all security aspects

Correct answer: C Bản dịch đáp án đúng: C. AWS bảo mật cơ sở hạ tầng; khách hàng bảo mật dữ liệu và kiểm soát quyền truy cập của họ

🇬🇧 Explanation:

  • Correct mindset: AWS = "Security OF the Cloud" (infrastructure, hypervisor, facilities)
  • Customer = "Security IN the Cloud" (data, access control, encryption)
  • C captures this split correctly

🇻🇳 Giải thích: Tư duy chuẩn: AWS lo "Security OF the Cloud" (facilities, hypervisor, network — phần hạ tầng bạn không thấy), còn khách hàng lo "Security IN the Cloud" (data, kiểm soát truy cập, encryption). Đáp án C mô tả đúng sự phân chia này.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — AWS is NOT responsible for everything / AWS không chịu trách nhiệm tất cả
  • B — customer does NOT handle infrastructure / khách hàng không quản lý hạ tầng
  • D — not split equally; it varies by service / không chia đều, tùy theo service

🔑 Key Concept / Khái niệm cốt lõi: AWS = OF the cloud (hạ tầng); Customer = IN the cloud (data + access). / AWS lo hạ tầng, khách hàng lo data + truy cập.

📚 Reference: Domain 2, Section 1 (Shared Responsibility Model)


Q3.

An organization runs a MySQL database on RDS. A security vulnerability is discovered in the MySQL engine. Who is responsible for applying the patch?

Bản dịch tiếng Việt: Một tổ chức chạy cơ sở dữ liệu MySQL trên RDS. Một lỗ hổng bảo mật được phát hiện trong công cụ MySQL. Ai chịu trách nhiệm áp dụng bản vá?

A. The customer must patch the database engine themselves B. AWS patches the engine automatically C. The customer and AWS share this responsibility equally D. Neither party is responsible; the customer should migrate to DynamoDB

Correct answer: B Bản dịch đáp án đúng: B. AWS tự động vá lỗi động cơ

🇬🇧 Explanation:

  • RDS is a managed database → AWS handles engine patching
  • EC2 is unmanaged → customer patches the OS
  • Common exam trap: confuse EC2 (customer) vs RDS (AWS)

🇻🇳 Giải thích: RDS là managed service nên AWS tự động patch database engine (MySQL, PostgreSQL...). Ngược lại EC2 là unmanaged → bạn (khách hàng) phải tự patch OS. Đề hay bẫy bạn nhầm giữa EC2 (customer) và RDS (AWS) — đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — customer does NOT patch the RDS engine / khách hàng không patch engine của RDS
  • C — AWS doesn't handle the customer's data/config fully, only the managed layer / AWS chỉ lo phần managed, không lo hết
  • D — engine patching is AWS's job for RDS / patch engine RDS là việc của AWS

🔑 Key Concept / Khái niệm cốt lõi: RDS engine patch = AWS; EC2 OS patch = customer. / Patch engine RDS là AWS; patch OS của EC2 là khách hàng.

📚 Reference: Domain 2, Section 1.5 (Service-by-service variation)


Q4. (Select TWO)

Which of the following are AWS responsibilities under the Shared Responsibility Model? (Select TWO)

Bản dịch tiếng Việt: Trách nhiệm nào sau đây của AWS theo Mô hình trách nhiệm chung? (Chọn HAI)

A. Patching the Windows OS on EC2 instances B. Securing the physical infrastructure and hypervisor C. Configuring Security Groups and NACLs D. Managing the AWS data center facilities and network E. Encrypting data stored in customer applications

Correct answer: B, D Bản dịch đáp án đúng: B. Bảo mật cơ sở hạ tầng vật lý và bộ ảo hóa; D. Quản lý cơ sở vật chất và mạng của trung tâm dữ liệu AWS

🇬🇧 Explanation:

  • B: Secure physical infrastructure & hypervisor ✓ AWS responsibility
  • D: Manage data center facilities & network ✓ AWS responsibility

🇻🇳 Giải thích: AWS chịu trách nhiệm phần hạ tầng vật lý: facilities (data center), hypervisor, và network infrastructure → đó là B và D. Mọi thứ thuộc "Security IN the Cloud" (OS patching, cấu hình SG, encryption data) là việc của khách hàng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — customer patches Windows on EC2 / khách hàng patch Windows trên EC2
  • C — customer configures SG/NACL / khách hàng cấu hình SG/NACL
  • E — customer encrypts their app data / khách hàng tự encrypt data ứng dụng

🔑 Key Concept / Khái niệm cốt lõi: AWS = physical infra + hypervisor + network. / AWS lo hạ tầng vật lý + hypervisor + network.


Q5.

A startup is using Lambda functions to process sensitive customer data. Under the Shared Responsibility Model, what is the customer responsible for?

Bản dịch tiếng Việt: Một công ty khởi nghiệp đang sử dụng các hàm Lambda để xử lý dữ liệu nhạy cảm của khách hàng. Theo Mô hình Trách nhiệm Chung, khách hàng chịu trách nhiệm về những gì?

A. Patching the Lambda runtime to fix vulnerabilities B. Securing their application code and managing IAM roles for the Lambda function C. Maintaining the underlying Lambda infrastructure and scaling D. Both A and C

Correct answer: B Bản dịch đáp án đúng: B. Bảo mật mã ứng dụng của họ và quản lý vai trò IAM cho hàm Lambda

🇬🇧 Explanation:

  • AWS manages: Lambda runtime, infrastructure, scaling
  • Customer manages: application code + IAM roles + securing environment variables
  • B captures the customer's responsibility

🇻🇳 Giải thích: Với Lambda, AWS quản lý gần như toàn bộ: runtime, infrastructure, scaling. Khách hàng chỉ chịu trách nhiệm phần code (lỗ hổng trong code), IAM role gắn cho function, và bảo vệ environment variables (không hardcode secret). Vì vậy B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — AWS patches the runtime, not the customer / AWS patch runtime, không phải khách hàng
  • C — AWS manages the infrastructure / AWS quản lý hạ tầng
  • D — only B is correct / chỉ B đúng

🔑 Key Concept / Khái niệm cốt lõi: Lambda: AWS runs everything; customer owns code + IAM. / Lambda: AWS lo hết hạ tầng; khách hàng lo code + IAM.


Q6.

Which AWS service allows you to define infrastructure as code while enforcing security best practices from the start?

Bản dịch tiếng Việt: Dịch vụ AWS nào cho phép bạn xác định cơ sở hạ tầng dưới dạng mã trong khi thực thi các biện pháp bảo mật tốt nhất ngay từ đầu?

A. AWS CloudWatch B. AWS CloudFormation C. AWS Lambda D. AWS Systems Manager

Correct answer: B Bản dịch đáp án đúng: B. Đám mây AWSFormation

🇬🇧 Explanation:

  • CloudFormation = Infrastructure as Code (JSON/YAML templates)
  • Lets you enforce best practices through reusable, version-controlled templates

🇻🇳 Giải thích: CloudFormation là dịch vụ Infrastructure as Code (template JSON/YAML), cho phép định nghĩa hạ tầng bằng code và enforce best practices một cách nhất quán, có version control. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (CloudWatch) — monitoring/logs, not IaC / giám sát & log, không phải IaC
  • C (Lambda) — serverless compute / compute serverless
  • D (Systems Manager) — patch & fleet management / patch & quản lý fleet

🔑 Key Concept / Khái niệm cốt lõi: IaC (JSON/YAML templates) = CloudFormation. / IaC bằng template JSON/YAML là CloudFormation.


Q7. (Select TWO)

Which of the following align with the principle of Least Privilege in IAM? (Select TWO)

Bản dịch tiếng Việt: Điều nào sau đây phù hợp với nguyên tắc Đặc quyền tối thiểu trong IAM? (Chọn HAI)

A. Granting ":" permissions to all users for simplicity B. Assigning only the specific permissions a user needs to perform their job C. Creating a single "PowerUser" group for all employees D. Regularly reviewing and revoking unnecessary permissions E. Using temporary security credentials instead of long-term access keys

Correct answer: B, D Bản dịch đáp án đúng: B. Chỉ gán các quyền cụ thể mà người dùng cần để thực hiện công việc của họ; D. Thường xuyên xem xét và thu hồi các quyền không cần thiết

🇬🇧 Explanation:

  • B: Grant only the specific permissions needed ✓ definition of least privilege
  • D: Regularly review & revoke unnecessary permissions ✓ best practice

🇻🇳 Giải thích: Least Privilege (đặc quyền tối thiểu) = chỉ cấp đúng permission cần thiết cho công việc (B), và thường xuyên review & thu hồi quyền không cần (D). Hai ý này đúng định nghĩa.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — granting *:* is the opposite of least privilege / cấp *:* là ngược với least privilege
  • C — a PowerUser group violates least privilege / nhóm PowerUser vi phạm least privilege
  • E — temporary credentials is good practice but about credential lifecycle, not the scope-of-permissions definition / temp credentials là tốt nhưng thuộc vòng đời credential, không phải định nghĩa phạm vi quyền

🔑 Key Concept / Khái niệm cốt lõi: Least privilege = minimum permissions + periodic review. / Least privilege = quyền tối thiểu + review định kỳ.


Q8.

A company wants to ensure that root account access is protected. Which of the following is a best practice?

Bản dịch tiếng Việt: Một công ty muốn đảm bảo rằng quyền truy cập tài khoản root được bảo vệ. Cách thực hành nào sau đây là tốt nhất?

A. Use the root account for daily administrative tasks B. Store the root account password in a shared text file C. Enable MFA (Multi-Factor Authentication) on the root account D. Create multiple root accounts to distribute access

Correct answer: C Bản dịch đáp án đúng: C. Kích hoạt MFA (Xác thực đa yếu tố) trên tài khoản root

🇬🇧 Explanation:

  • Enable MFA is the fundamental best practice for the root account
  • Combined with: don't use root daily, don't create root access keys

🇻🇳 Giải thích: Bảo vệ root account: bật MFA là việc cơ bản & quan trọng nhất, kèm theo KHÔNG dùng root hằng ngày và KHÔNG tạo access key cho root. Đáp án C đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — never use root for daily work / không dùng root cho việc hằng ngày
  • B — never store the password in a shared file / không lưu mật khẩu vào file dùng chung
  • D — you cannot create multiple root accounts / không thể tạo nhiều root account

🔑 Key Concept / Khái niệm cốt lõi: Protect root = enable MFA + stop daily use. / Bảo vệ root = bật MFA + ngừng dùng hằng ngày.


Q9.

Which of the following best describes the concept of "defense in depth" in cloud security?

Bản dịch tiếng Việt: Điều nào sau đây mô tả đúng nhất khái niệm "phòng thủ theo chiều sâu" trong bảo mật đám mây?

A. Using only one strong password to protect all resources B. Implementing multiple security layers (network, application, data) to protect against threats C. Blocking all external access to the application D. Relying solely on AWS Shield for protection

Correct answer: B Bản dịch đáp án đúng: B. Triển khai nhiều lớp bảo mật (mạng, ứng dụng, dữ liệu) để bảo vệ khỏi các mối đe dọa

🇬🇧 Explanation:

  • Defense in depth = multiple security layers (network, application, data)
  • Principle: never rely on a single security measure

🇻🇳 Giải thích: "Defense in depth" (phòng thủ nhiều lớp) = xếp chồng nhiều tầng bảo vệ: network (SG/NACL), application (WAF), và data (encryption). Nguyên tắc cốt lõi: đừng phụ thuộc vào MỘT biện pháp duy nhất. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — a single password is weak / một mật khẩu đơn lẻ thì yếu
  • C — blocking all access defeats the purpose / chặn hết truy cập thì mất mục đích
  • D — Shield alone is not enough / chỉ mỗi Shield là chưa đủ

🔑 Key Concept / Khái niệm cốt lõi: Defense in depth = layered, redundant controls. / Defense in depth = nhiều lớp kiểm soát chồng nhau.


Q10.

An EC2 instance needs to access an S3 bucket securely. What is the AWS-recommended approach?

Bản dịch tiếng Việt: Phiên bản EC2 cần truy cập vào nhóm S3 một cách an toàn. Phương pháp được AWS khuyến nghị là gì?

A. Store AWS access keys in the EC2 user data script B. Create an IAM role and attach it to the EC2 instance C. Use the root account credentials on the instance D. Share the S3 bucket ACL with all EC2 instances

Correct answer: B Bản dịch đáp án đúng: B. Tạo vai trò IAM và đính kèm nó vào phiên bản EC2

🇬🇧 Explanation:

  • IAM role + instance profile is the AWS-recommended approach
  • Provides temporary, auto-rotated credentials with no hardcoding

🇻🇳 Giải thích: Cho EC2 truy cập S3, best practice là gắn IAM role (instance profile) vào EC2 — role cấp credentials tạm thời, tự xoay vòng, không cần hardcode key. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — hardcoding keys in user data is insecure / hardcode key trong user data là không an toàn
  • C — root credentials are dangerous / dùng credential root rất nguy hiểm
  • D — the ACL approach is outdated / cách dùng ACL đã lỗi thời

🔑 Key Concept / Khái niệm cốt lõi: EC2 → AWS service access = IAM role, never hardcoded keys. / EC2 truy cập service = IAM role, không hardcode key.


Q11. (Select THREE)

Which of the following are characteristics of the AWS Well-Architected Framework's Security pillar? (Select THREE)

Bản dịch tiếng Việt: Đặc điểm nào sau đây là đặc điểm của trụ cột Bảo mật của AWS Well-Architected Framework? (Chọn BA)

A. Implementing strong identity and access management with MFA B. Reducing operational costs by minimizing security controls C. Encrypting data at rest and in transit D. Eliminating the need for firewalls in cloud environments E. Automating security compliance checks

Correct answer: A, C, E Bản dịch đáp án đúng: A. Triển khai quản lý quyền truy cập và nhận dạng mạnh mẽ bằng MFA; C. Mã hóa dữ liệu ở trạng thái nghỉ và đang di chuyển; E. Tự động kiểm tra tuân thủ bảo mật

🇬🇧 Explanation:

  • A: Strong IAM with MFA ✅ core of the Security pillar
  • C: Encrypt data at rest & in transit ✅ core of the Security pillar
  • E: Automate security compliance checks ✅ "Automate security best practices" is an explicit Security design principle

🇻🇳 Giải thích: Đặc trưng của trụ cột Security: IAM mạnh + MFA (A), mã hóa data at-rest & in-transit (C), và tự động hóa kiểm tra tuân thủ bảo mật (E — "automate security best practices"). Đáp án A, C, E đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B — security adds controls; you don't cut them to save cost / bảo mật là thêm kiểm soát, không cắt để tiết kiệm
  • D — firewalls/network controls are still needed in the cloud / vẫn cần firewall/kiểm soát network trên cloud

🔑 Key Concept / Khái niệm cốt lõi: Security pillar = IAM/MFA + encryption + automation. / Trụ cột Security = IAM/MFA + mã hóa + tự động hóa.


Q12.

A development team wants to deploy an application to EC2 instances in multiple Availability Zones for high availability. Which security consideration is most important?

Bản dịch tiếng Việt: Nhóm phát triển muốn triển khai một ứng dụng cho các phiên bản EC2 trong nhiều Availability Zone để có tính sẵn sàng cao. Cân nhắc bảo mật nào là quan trọng nhất?

A. Disable all security groups to improve performance B. Configure Security Groups and NACLs to restrict traffic appropriately C. Use the same key pair across all instances D. Store database passwords in environment variables

Correct answer: B Bản dịch đáp án đúng: B. Định cấu hình Nhóm bảo mật và NACL để hạn chế lưu lượng truy cập một cách thích hợp

🇬🇧 Explanation:

  • Properly configuring Security Groups & NACLs is the key network-security requirement
  • Controls inbound/outbound traffic at instance and subnet levels

🇻🇳 Giải thích: Khi deploy EC2 multi-AZ, yêu cầu bảo mật quan trọng nhất là cấu hình đúng Security Group & NACL để kiểm soát traffic vào/ra ở mức instance và subnet. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — never disable security groups / không bao giờ tắt security group
  • C — never reuse key pairs across instances / không tái dùng key pair giữa các instance
  • D — never store passwords in environment variables / không lưu mật khẩu trong biến môi trường

🔑 Key Concept / Khái niệm cốt lõi: Network security = correct SG (instance) + NACL (subnet). / Bảo mật network = SG đúng (instance) + NACL (subnet).


Q13.

Which AWS service helps identify and remediate security vulnerabilities in EC2 instances and container images?

Bản dịch tiếng Việt: Dịch vụ AWS nào giúp xác định và khắc phục các lỗ hổng bảo mật trong phiên bản EC2 và hình ảnh vùng chứa?

A. AWS Trusted Advisor B. Amazon Inspector C. AWS CloudTrail D. AWS Config

Correct answer: B Bản dịch đáp án đúng: B. Thanh tra Amazon

🇬🇧 Explanation:

  • Amazon Inspector = automated vulnerability scanner for EC2, ECR, Lambda
  • Detects CVEs, missing patches, and unintended network exposure

🇻🇳 Giải thích: Amazon Inspector là dịch vụ tự động quét lỗ hổng cho EC2, container images (ECR) và Lambda — phát hiện CVE, thiếu patch, cổng mạng hở. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Trusted Advisor) — best-practice checks, not deep vuln scanning / kiểm tra best practice, không quét lỗ hổng sâu
  • C (CloudTrail) — API audit, not vulnerability scanning / audit API, không quét lỗ hổng
  • D (Config) — compliance/config tracking, not scanning / theo dõi cấu hình, không quét

🔑 Key Concept / Khái niệm cốt lõi: "Scan EC2/Lambda for vulnerabilities" = Inspector. / "Quét lỗ hổng EC2/Lambda" = Inspector.


Q14. (Select TWO)

Which of the following represent the CORRECT relationship between AWS and customer responsibilities in the Shared Responsibility Model? (Select TWO)

Bản dịch tiếng Việt: Điều nào sau đây thể hiện mối quan hệ ĐÚNG giữa AWS và trách nhiệm của khách hàng trong Mô hình trách nhiệm chung? (Chọn HAI)

A. AWS patches EC2 OS; customer patches RDS database engine B. AWS secures the hypervisor; customer configures Security Groups C. Customer encrypts data; AWS manages encryption keys D. AWS manages VPC routing; customer configures IAM policies E. Customer patches Lambda code; AWS patches Lambda runtime

Correct answer: B, D Bản dịch đáp án đúng: B. AWS bảo mật bộ ảo hóa; khách hàng định cấu hình Nhóm bảo mật; D. AWS quản lý định tuyến VPC; khách hàng định cấu hình chính sách IAM

🇬🇧 Explanation:

  • B: AWS secures the hypervisor; customer configures SG ✓ correct division
  • D: AWS manages VPC routing; customer configures IAM ✓ correct division

🇻🇳 Giải thích: Phân chia trách nhiệm đúng: AWS lo hypervisor — khách hàng cấu hình SG (B); AWS quản lý routing của VPC — khách hàng cấu hình IAM (D). Đáp án B, D đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — reversed: customer patches EC2 OS, AWS patches RDS engine / ngược: khách hàng patch OS EC2, AWS patch engine RDS
  • C — customer manages keys, AWS manages infrastructure / khách hàng quản key, AWS quản hạ tầng
  • E — reversed: AWS patches Lambda runtime, customer owns the code / ngược: AWS patch runtime Lambda, khách hàng lo code

🔑 Key Concept / Khái niệm cốt lõi: Don't reverse the split: EC2 OS = customer, RDS engine = AWS. / Đừng đảo: OS EC2 = khách hàng, engine RDS = AWS.


Q15.

A company uses multiple AWS accounts for different business units. Which service enables centralized security governance and control?

Bản dịch tiếng Việt: Một công ty sử dụng nhiều tài khoản AWS cho các đơn vị kinh doanh khác nhau. Dịch vụ nào cho phép quản trị và kiểm soát bảo mật tập trung?

A. AWS Organizations with Service Control Policies B. AWS IAM with multiple root accounts C. AWS CloudFormation D. AWS Budgets

Correct answer: A Bản dịch đáp án đúng: A. Các tổ chức AWS có chính sách kiểm soát dịch vụ

🇬🇧 Explanation:

  • AWS Organizations + Service Control Policies (SCPs) = centralized governance
  • SCPs set guardrails (deny actions) across all member accounts

🇻🇳 Giải thích: Để quản trị bảo mật tập trung cho nhiều account, dùng AWS Organizations + SCPs. SCP đặt "guardrails" (chặn action) áp cho toàn bộ member account. Đáp án A đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B — multiple root accounts defeats the purpose / nhiều root account thì mất mục đích
  • C — CloudFormation provisions infra, doesn't govern policy / CloudFormation tạo hạ tầng, không quản trị policy
  • D — Budgets are for cost, not security / Budgets dành cho chi phí, không phải bảo mật

🔑 Key Concept / Khái niệm cốt lõi: Multi-account guardrails = Organizations + SCPs. / Guardrails đa account = Organizations + SCPs.


Q16.

Which of the following best represents the principle of "encrypt everywhere" in AWS security?

Bản dịch tiếng Việt: Điều nào sau đây thể hiện đúng nhất nguyên tắc "mã hóa mọi nơi" trong bảo mật AWS?

A. Encrypt data only when it's transmitted over the internet B. Encrypt data at rest AND in transit using appropriate services (KMS, TLS) C. Encrypt only the most sensitive data to reduce costs D. Use encryption only for compliance requirements

Correct answer: B Bản dịch đáp án đúng: B. Mã hóa dữ liệu ở trạng thái nghỉ VÀ đang truyền bằng các dịch vụ thích hợp (KMS, TLS)

🇬🇧 Explanation:

  • Encrypt at-rest AND in-transit = "everywhere"
  • KMS for at-rest, TLS/HTTPS for in-transit

🇻🇳 Giải thích: "Encrypt everywhere" = mã hóa cả khi lưu trữ (at-rest) lẫn khi truyền tải (in-transit): dùng KMS cho at-rest và TLS/HTTPS cho in-transit. Đáp án B đúng vì bao trùm cả hai.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — incomplete, covers in-transit only / thiếu, chỉ có in-transit
  • C — cost should not limit encryption / chi phí không nên giới hạn việc mã hóa
  • D — compliance is a driver, not the only reason / tuân thủ là một lý do, không phải lý do duy nhất

🔑 Key Concept / Khái niệm cốt lõi: Encrypt everywhere = at-rest (KMS) + in-transit (TLS). / Mã hóa mọi nơi = at-rest (KMS) + in-transit (TLS).


Domain 2: Security and Compliance (Q17–Q36)

Q17.

A company stores customer credit card data in an S3 bucket. Which AWS service should they use to automatically detect and identify PII (Personally Identifiable Information) in the bucket?

Bản dịch tiếng Việt: Một công ty lưu trữ dữ liệu thẻ tín dụng của khách hàng trong bộ chứa S3. Họ nên sử dụng dịch vụ AWS nào để tự động phát hiện và xác định PII (Thông tin nhận dạng cá nhân) trong nhóm?

A. AWS CloudTrail B. Amazon Macie C. Amazon GuardDuty D. AWS Config

Correct answer: B Bản dịch đáp án đúng: B. Amazon Macie

🇬🇧 Explanation:

  • Amazon Macie uses ML to discover PII in S3 (credit cards, SSN, passport numbers)
  • Purpose-built for sensitive-data discovery & protection

🇻🇳 Giải thích: Amazon Macie dùng ML để phát hiện dữ liệu nhạy cảm (PII) trong S3 — số thẻ tín dụng, SSN, hộ chiếu, email... Đây là dịch vụ chuyên cho việc tìm & bảo vệ PII, nên đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (CloudTrail) — API audit only / chỉ audit API
  • C (GuardDuty) — threat detection via anomalies, not PII discovery / phát hiện mối đe dọa, không tìm PII
  • D (Config) — tracks configuration changes / theo dõi thay đổi cấu hình

🔑 Key Concept / Khái niệm cốt lõi: "Find PII/sensitive data in S3" = Macie. / "Tìm PII trong S3" = Macie.

📚 Reference: Domain 2, Section 6.3 (Amazon Macie)


Q18. (Select TWO)

Which of the following are valid ways to encrypt data stored in S3? (Select TWO)

Bản dịch tiếng Việt: Cách nào sau đây là hợp lệ để mã hóa dữ liệu được lưu trữ trong S3? (Chọn HAI)

A. Server-side encryption with AWS-managed keys (SSE-S3) B. Enabling S3 Transfer Acceleration on the bucket C. Compression algorithms built into S3 D. Server-side encryption with customer-managed KMS keys (SSE-KMS) E. S3 versioning

Correct answer: A, D Bản dịch đáp án đúng: A. Mã hóa phía máy chủ bằng khóa do AWS quản lý (SSE-S3); D. Mã hóa phía máy chủ với khóa KMS do khách hàng quản lý (SSE-KMS)

🇬🇧 Explanation:

  • A: SSE-S3 (AWS-managed keys) ✅ built-in server-side encryption
  • D: SSE-KMS (customer-managed keys) ✅ server-side encryption with KMS control

🇻🇳 Giải thích: Phương thức mã hóa S3 hợp lệ: SSE-S3 (AWS quản lý key) và SSE-KMS (khách hàng kiểm soát key qua KMS). Đừng nhầm với các tính năng không phải mã hóa như Transfer Acceleration hay versioning. Đáp án A, D đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B — S3 Transfer Acceleration speeds up uploads, not encryption / tăng tốc upload, không phải mã hóa
  • C — compression reduces size, not encryption / nén giảm dung lượng, không phải mã hóa
  • E — versioning keeps object versions, not encryption / giữ phiên bản object, không phải mã hóa

🔑 Key Concept / Khái niệm cốt lõi: S3 encryption = SSE-S3 / SSE-KMS / SSE-C / client-side. / Mã hóa S3 = SSE-S3 / SSE-KMS / SSE-C / client-side.

📚 Reference: Domain 2, Section 4.2 (KMS)


Q19.

An organization wants to ensure that all API calls made in their AWS account are logged for audit and compliance purposes. Which service should they enable?

Bản dịch tiếng Việt: Một tổ chức muốn đảm bảo rằng tất cả các lệnh gọi API được thực hiện trong tài khoản AWS của họ đều được ghi lại cho mục đích kiểm tra và tuân thủ. Họ nên kích hoạt dịch vụ nào?

A. Amazon CloudWatch Logs B. AWS CloudTrail C. AWS Config D. Amazon GuardDuty

Correct answer: B Bản dịch đáp án đúng: B. Đường mòn đám mây AWS

🇬🇧 Explanation:

  • AWS CloudTrail = central API audit log
  • Records who, what, when, where, and result of every API call

🇻🇳 Giải thích: AWS CloudTrail ghi lại toàn bộ API call trong account — ai làm, làm gì, khi nào, từ đâu, kết quả ra sao — phục vụ audit & compliance. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (CloudWatch) — metrics/logs, not API audit / metric & log, không phải audit API
  • C (Config) — configuration changes, not API calls / thay đổi cấu hình, không phải API call
  • D (GuardDuty) — threat detection, not an audit log / phát hiện mối đe dọa, không phải audit log

🔑 Key Concept / Khái niệm cốt lõi: "Who did what API call" = CloudTrail. / "Ai gọi API gì" = CloudTrail.

📚 Reference: Domain 2, Section 7.1 (CloudTrail)


Q20.

A developer accidentally configured an S3 bucket to allow public read access, exposing sensitive files. Under the Shared Responsibility Model, who bears responsibility for this security breach?

Bản dịch tiếng Việt: Một nhà phát triển đã vô tình định cấu hình bộ chứa S3 để cho phép truy cập đọc công khai, làm lộ các tệp nhạy cảm. Theo Mô hình trách nhiệm chung, ai chịu trách nhiệm về vi phạm an ninh này?

A. AWS is responsible for securing bucket access B. The customer is responsible for configuring bucket access controls correctly C. Both AWS and the customer share equal responsibility D. Neither party is responsible; the customer should switch to a different service

Correct answer: B Bản dịch đáp án đúng: B. Khách hàng có trách nhiệm định cấu hình chính xác các biện pháp kiểm soát truy cập bộ chứa

🇬🇧 Explanation:

  • The customer is responsible for bucket access configuration
  • Shared Responsibility: AWS manages storage infrastructure; the customer manages access/policies

🇻🇳 Giải thích: Cấu hình quyền truy cập của S3 bucket là trách nhiệm khách hàng ("Security IN the Cloud"). Bucket bị public do cấu hình sai là lỗi của khách hàng, không phải AWS. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — AWS does not control your bucket access settings / AWS không kiểm soát cấu hình truy cập bucket của bạn
  • C — the customer bears primary responsibility here / khách hàng chịu trách nhiệm chính
  • D — switching services doesn't fix a misconfiguration / đổi service không sửa được lỗi cấu hình

🔑 Key Concept / Khái niệm cốt lõi: S3 bucket access config = customer responsibility. / Cấu hình truy cập S3 là trách nhiệm khách hàng.


Q21. (Select THREE)

Which of the following are features of AWS Identity and Access Management (IAM)? (Select THREE)

Bản dịch tiếng Việt: Tính năng nào sau đây là tính năng của AWS Identity and Access Management (IAM)? (Chọn BA)

A. IAM allows you to manage user access to AWS resources and enforce permissions B. The root account should be used for all daily administrative tasks C. IAM supports multi-factor authentication (MFA) for enhanced security D. IAM roles can be assumed by EC2 instances to access other AWS services E. IAM provides automatic encryption of all AWS resources

Correct answer: A, C, D Bản dịch đáp án đúng: A. IAM cho phép bạn quản lý quyền truy cập của người dùng vào tài nguyên AWS và thực thi quyền; C. IAM hỗ trợ xác thực đa yếu tố (MFA) để tăng cường bảo mật; D. Các phiên bản EC2 có thể đảm nhận vai trò IAM để truy cập các dịch vụ AWS khác

🇬🇧 Explanation:

  • A: Manage user access & enforce permissions ✅ core IAM function
  • C: Support MFA ✅ IAM supports MFA for users and root
  • D: Roles assumable by EC2 ✅ IAM roles + instance profiles

🇻🇳 Giải thích: Tính năng của IAM: quản lý truy cập & gán quyền cho user (A), hỗ trợ MFA cho user và root (C), và role mà EC2 có thể assume qua instance profile (D). Đáp án A, C, D đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B — "root used daily" is bad practice, not an IAM feature / dùng root hằng ngày là sai, không phải tính năng IAM
  • E — IAM doesn't encrypt resources; KMS does / IAM không mã hóa tài nguyên, đó là việc của KMS

🔑 Key Concept / Khái niệm cốt lõi: IAM = identities + permissions + MFA + roles. / IAM = danh tính + quyền + MFA + role.

📚 Reference: Domain 2, Section 2 (IAM)


Q22.

A company runs a sensitive application on RDS. They want to ensure that the database password is rotated automatically. Which AWS service should they use?

Bản dịch tiếng Việt: Một công ty chạy một ứng dụng nhạy cảm trên RDS. Họ muốn đảm bảo rằng mật khẩu cơ sở dữ liệu được luân chuyển tự động. Họ nên sử dụng dịch vụ AWS nào?

A. AWS Systems Manager Parameter Store B. AWS Secrets Manager C. AWS Key Management Service (KMS) D. AWS Certificate Manager

Correct answer: B Bản dịch đáp án đúng: B. Trình quản lý bí mật AWS

🇬🇧 Explanation:

  • AWS Secrets Manager provides automatic password rotation (integrates with Lambda)
  • Purpose-built for rotating DB credentials, API keys, etc.

🇻🇳 Giải thích: AWS Secrets Manager hỗ trợ tự động xoay vòng (rotate) mật khẩu database qua Lambda — đúng nhu cầu đề bài. Parameter Store chỉ lưu config và rotate thủ công. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Parameter Store) — manual rotation only / chỉ rotate thủ công
  • C (KMS) — manages encryption keys, not passwords / quản lý key mã hóa, không phải mật khẩu
  • D (ACM) — SSL/TLS certificates / chứng chỉ SSL/TLS

🔑 Key Concept / Khái niệm cốt lõi: "Auto-rotate DB password" = Secrets Manager. / "Tự rotate mật khẩu DB" = Secrets Manager.

📚 Reference: Domain 2, Section 4.5 (Secrets Manager vs Parameter Store)


Q23.

An organization has multiple AWS accounts and wants to prevent any account from launching expensive services (e.g., p3 GPU instances). Which service enables this control?

Bản dịch tiếng Việt: Một tổ chức có nhiều tài khoản AWS và muốn ngăn bất kỳ tài khoản nào khởi chạy các dịch vụ đắt tiền (ví dụ: phiên bản GPU p3). Dịch vụ nào cho phép điều khiển này?

A. AWS CloudTrail B. AWS Organizations with Service Control Policies (SCPs) C. AWS IAM with managed policies D. AWS Config rules

Correct answer: B Bản dịch đáp án đúng: B. Các tổ chức AWS có Chính sách kiểm soát dịch vụ (SCP)

🇬🇧 Explanation:

  • AWS Organizations + Service Control Policies (SCPs) enforce account-level restrictions
  • An SCP can deny ec2:RunInstances (e.g., for expensive instance types) across accounts

🇻🇳 Giải thích: Để chặn việc khởi chạy service đắt tiền ở các member account, dùng Organizations + SCPs. SCP hoạt động ở mức account (không phải mức user), có thể deny ec2:RunInstances. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (CloudTrail) — audit only, no prevention / chỉ audit, không ngăn chặn
  • C (IAM policies) — per-user, not account-wide / theo từng user, không bao trùm account
  • D (Config) — compliance check only, doesn't prevent / chỉ kiểm tra tuân thủ, không ngăn

🔑 Key Concept / Khái niệm cốt lõi: Account-wide service block = SCP. / Chặn service toàn account = SCP.

📚 Reference: Domain 2, Section 3.2 (Service Control Policies)


Q24. (Select TWO)

Which of the following describe the difference between CloudTrail, CloudWatch, and AWS Config? (Select TWO)

Bản dịch tiếng Việt: Điều nào sau đây mô tả sự khác biệt giữa CloudTrail, CloudWatch và AWS Config? (Chọn HAI)

A. CloudTrail logs API calls; AWS Config tracks configuration changes; CloudWatch monitors performance metrics B. CloudTrail stores data for 90 days; CloudWatch stores indefinitely; Config stores for 30 days C. CloudTrail is only for security audits; CloudWatch is for development monitoring; Config is for compliance D. All three services provide identical functionality but use different names E. CloudTrail can be used to audit who made which API call; AWS Config shows when resource configurations changed

Correct answer: A, E Bản dịch đáp án đúng: A. CloudTrail ghi lại các lệnh gọi API; AWS Config theo dõi các thay đổi về cấu hình; CloudWatch giám sát số liệu hiệu suất; E. CloudTrail có thể được sử dụng để kiểm tra xem ai đã thực hiện lệnh gọi API nào; Cấu hình AWS hiển thị khi cấu hình tài nguyên thay đổi

🇬🇧 Explanation:

  • A: CloudTrail = API calls, Config = config changes, CloudWatch = metrics ✓ correct distinction
  • E: CloudTrail audits API, Config tracks configuration changes ✓ correct distinction

🇻🇳 Giải thích: Phân biệt 3 dịch vụ dễ nhầm: CloudTrail = audit API call (ai làm gì), Config = theo dõi thay đổi cấu hình, CloudWatch = metric/log hiệu năng. Đáp án A, E mô tả đúng. Đây là điểm bẫy hay gặp trên đề!

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B — retention differs but isn't the core distinction / thời gian lưu khác nhau nhưng không phải điểm phân biệt chính
  • C — the three are used together, not mutually exclusive / ba dịch vụ dùng cùng nhau, không loại trừ
  • D — they are not identical; different data types / không giống nhau, khác loại dữ liệu

🔑 Key Concept / Khái niệm cốt lõi: CloudTrail (API) vs Config (config) vs CloudWatch (metrics). / CloudTrail (API) vs Config (cấu hình) vs CloudWatch (metric).

📚 Reference: Domain 2, Section 7.1 (CloudTrail vs CloudWatch vs Config)


Q25.

A company wants to enable encryption for an RDS database. They want to use AWS-managed keys for simplicity. Which encryption service should they use?

Bản dịch tiếng Việt: Một công ty muốn kích hoạt mã hóa cho cơ sở dữ liệu RDS. Họ muốn sử dụng các khóa do AWS quản lý để đơn giản hóa. Họ nên sử dụng dịch vụ mã hóa nào?

A. AWS Certificate Manager B. AWS Secrets Manager C. AWS Key Management Service (KMS) D. AWS CloudHSM

Correct answer: C Bản dịch đáp án đúng: C. Dịch vụ quản lý khóa AWS (KMS)

🇬🇧 Explanation:

  • AWS Key Management Service (KMS) manages encryption keys
  • AWS-managed KMS keys are free and used by default for RDS encryption

🇻🇳 Giải thích: Để mã hóa RDS bằng key do AWS quản lý, dùng KMS. AWS-managed key trong KMS miễn phí và tự động rotate. Đáp án C đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (ACM) — SSL/TLS certificates only / chỉ chứng chỉ SSL/TLS
  • B (Secrets Manager) — passwords/credentials, not data encryption keys / mật khẩu/credential, không phải key mã hóa data
  • D (CloudHSM) — dedicated hardware, overkill when no special compliance / phần cứng riêng, thừa khi không có yêu cầu compliance đặc biệt

🔑 Key Concept / Khái niệm cốt lõi: Default data encryption keys = KMS (AWS-managed = free). / Key mã hóa mặc định = KMS (AWS-managed = free).

📚 Reference: Domain 2, Section 4.2 (KMS)


Q26. (Select TWO)

Which of the following are best practices for protecting the AWS root account? (Select TWO)

Bản dịch tiếng Việt: Biện pháp nào sau đây là biện pháp tốt nhất để bảo vệ tài khoản root AWS? (Chọn HAI)

A. Enable MFA on the root account B. Create access keys for the root account and use them for daily tasks C. Use the root account only for account-level operations like billing and account recovery D. Share the root account password with senior team members for redundancy E. Disable CloudTrail logging so root activity is not recorded

Correct answer: A, C Bản dịch đáp án đúng: A. Kích hoạt MFA trên tài khoản root; C. Chỉ sử dụng tài khoản gốc cho các hoạt động cấp tài khoản như thanh toán và khôi phục tài khoản

🇬🇧 Explanation:

  • A: Enable MFA ✅ essential first step for the root account
  • C: Use root only for account-level ops (billing, recovery) ✅ minimize root usage

🇻🇳 Giải thích: Best practice cho root account: bật MFA (A) và chỉ dùng root cho việc account-level như billing & account recovery (C). Đáp án A, C đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B — never create root access keys, especially for daily use / không tạo access key cho root
  • D — never share the root password / không chia sẻ mật khẩu root
  • E — disabling CloudTrail removes the audit trail (opposite of protection) / tắt CloudTrail là mất audit, ngược với bảo vệ

🔑 Key Concept / Khái niệm cốt lõi: Root = MFA on + use rarely (billing/recovery only). / Root = bật MFA + chỉ dùng khi cần (billing/recovery).


Q27.

An organization experienced a security incident and wants to analyze which user deleted a critical S3 object. Which service provides this information?

Bản dịch tiếng Việt: Một tổ chức đã gặp sự cố bảo mật và muốn phân tích xem người dùng nào đã xóa đối tượng S3 quan trọng. Dịch vụ nào cung cấp thông tin này?

A. Amazon GuardDuty B. AWS CloudTrail C. AWS Config D. Amazon Inspector

Correct answer: B Bản dịch đáp án đúng: B. Đường mòn đám mây AWS

🇬🇧 Explanation:

  • AWS CloudTrail logs all API calls, including DeleteObject
  • Shows who, what, when, where, and result

🇻🇳 Giải thích: Để biết ai đã xóa object trong S3, dùng CloudTrail — nó log mọi API call (gồm cả DeleteObject) kèm ai/làm gì/khi nào/từ đâu/kết quả. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (GuardDuty) — threat detection, not an audit log / phát hiện mối đe dọa, không phải audit log
  • C (Config) — configuration changes, not object deletion / thay đổi cấu hình, không phải xóa object
  • D (Inspector) — vulnerability scanning / quét lỗ hổng

🔑 Key Concept / Khái niệm cốt lõi: "Who deleted the object" = CloudTrail. / "Ai đã xóa object" = CloudTrail.


Q28.

A company wants to prevent specific users from assuming certain IAM roles across their organization. Which approach is correct?

Bản dịch tiếng Việt: Một công ty muốn ngăn người dùng cụ thể đảm nhận một số vai trò IAM nhất định trong tổ chức của họ. Cách tiếp cận nào là đúng?

A. Use an explicit Deny statement in the role's trust policy or an SCP B. Delete the IAM user account C. Use AWS CloudWatch to monitor role assumption D. Enable S3 bucket policies to block role access

Correct answer: A Bản dịch đáp án đúng: A. Sử dụng tuyên bố Từ chối rõ ràng trong chính sách tin cậy của vai trò hoặc SCP

🇬🇧 Explanation:

  • Use an explicit Deny (in the trust policy or an SCP) to block role assumption
  • In IAM, an explicit Deny always wins over any Allow

🇻🇳 Giải thích: Để chặn user assume một role, dùng explicit Deny trong trust policy hoặc SCP. Trong IAM, explicit Deny luôn thắng mọi Allow. Đáp án A đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B — deleting the user is too drastic / xóa user là quá tay
  • C — CloudWatch doesn't enforce access / CloudWatch không kiểm soát truy cập
  • D — S3 policies don't govern IAM role assumption / policy S3 không quản role IAM

🔑 Key Concept / Khái niệm cốt lõi: Block an action = explicit Deny (Deny > Allow). / Chặn hành động = explicit Deny (Deny > Allow).


Q29. (Select TWO)

Which of the following represent differences between AWS-managed KMS keys and customer-managed KMS keys? (Select TWO)

Bản dịch tiếng Việt: Điều nào sau đây thể hiện sự khác biệt giữa khóa KMS do AWS quản lý và khóa KMS do khách hàng quản lý? (Chọn HAI)

A. AWS-managed keys are free; customer-managed keys are paid B. AWS-managed keys are automatically rotated annually; customer-managed keys require manual rotation configuration C. Customer-managed keys provide full control and audit capability D. AWS-managed keys can be shared across AWS accounts; customer-managed keys cannot E. Customers can view AWS-managed keys in the KMS console; customer-managed keys are hidden

Correct answer: A, C Bản dịch đáp án đúng: A. Khóa do AWS quản lý là miễn phí; khóa do khách hàng quản lý được thanh toán; C. Khóa do khách hàng quản lý cung cấp khả năng kiểm soát và kiểm tra hoàn toàn

🇬🇧 Explanation:

  • A: AWS-managed keys are free; customer-managed keys are paid ✓ cost distinction
  • C: Customer-managed keys give full control & audit ✓ control distinction

🇻🇳 Giải thích: Khác biệt KMS keys: AWS-managed miễn phí, AWS tự rotate (A); customer-managed trả phí nhưng cho bạn toàn quyền kiểm soát rotation, policy & audit (C). Đáp án A, C đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B — both can rotate; customer-managed lets you control it / cả hai rotate được, customer-managed cho bạn kiểm soát
  • D — customer-managed keys can be shared cross-account / customer-managed có thể chia sẻ cross-account
  • E — both are visible, customer-managed just gives more detail / cả hai đều thấy được, customer-managed chi tiết hơn

🔑 Key Concept / Khái niệm cốt lõi: AWS-managed = free/auto; customer-managed = paid/full control. / AWS-managed = free/tự động; customer-managed = trả phí/toàn quyền.


Q30.

A company wants to use AWS's DDoS protection service to protect their CloudFront distribution. They want the most comprehensive protection including Layer 7 attacks and a dedicated response team. Which option should they choose?

Bản dịch tiếng Việt: Một công ty muốn sử dụng dịch vụ bảo vệ DDoS của AWS để bảo vệ hoạt động phân phối CloudFront của họ. Họ muốn sự bảo vệ toàn diện nhất bao gồm các cuộc tấn công Lớp 7 và một đội phản ứng chuyên trách. Họ nên chọn phương án nào?

A. AWS Shield Standard (included automatically) B. AWS Shield Advanced C. AWS WAF only D. AWS Firewall Manager

Correct answer: B Bản dịch đáp án đúng: B. Khiên AWS nâng cao

🇬🇧 Explanation:

  • AWS Shield Advanced = Layer 3–7 DDoS protection + 24/7 DDoS Response Team (DRT)
  • Adds cost protection and advanced reporting over Standard

🇻🇳 Giải thích: Khi cần bảo vệ DDoS ở cả Layer 7 kèm đội phản ứng 24/7, dùng Shield Advanced (Layer 3–7 + DDoS Response Team). Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Shield Standard) — Layer 3–4 only, free, no response team / chỉ Layer 3–4, miễn phí, không có đội phản ứng
  • C (WAF) — application-layer filtering, no DDoS response team / lọc tầng ứng dụng, không có đội DDoS
  • D (Firewall Manager) — multi-account rule management / quản lý rule đa account

🔑 Key Concept / Khái niệm cốt lõi: Layer 7 DDoS + response team = Shield Advanced. / DDoS Layer 7 + đội phản ứng = Shield Advanced.

📚 Reference: Domain 2, Section 5.1 (AWS Shield)


Q31. (Select TWO)

Which of the following attacks can AWS WAF help prevent? (Select TWO)

Bản dịch tiếng Việt: AWS WAF có thể giúp ngăn chặn cuộc tấn công nào sau đây? (Chọn HAI)

A. DDoS attacks at Layer 3 (network level) B. SQL injection attacks at the application layer C. Cross-Site Scripting (XSS) attacks D. EC2 instance-level network attacks E. Malware distribution through S3

Correct answer: B, C Bản dịch đáp án đúng: B. Tấn công tiêm SQL vào lớp ứng dụng; C. Các cuộc tấn công tập lệnh chéo trang (XSS)

🇬🇧 Explanation:

  • B: SQL injection ✓ application-layer attack (WAF specialty)
  • C: XSS (Cross-Site Scripting) ✓ application-layer attack

🇻🇳 Giải thích: AWS WAF chặn các tấn công tầng ứng dụng (Layer 7): SQL injection (B) và XSS (C) — cùng CSRF, bot. WAF KHÔNG phải để chống DDoS. Đáp án B, C đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Layer 3 DDoS is Shield's job, not WAF / DDoS Layer 3 là việc của Shield
  • D — network-layer filtering = NACL/SG / lọc tầng network = NACL/SG
  • E — malware distribution is an S3/Macie concern / phát tán malware liên quan S3/Macie

🔑 Key Concept / Khái niệm cốt lõi: WAF = app-layer (SQLi/XSS); Shield = DDoS. / WAF = tầng ứng dụng (SQLi/XSS); Shield = DDoS.

📚 Reference: Domain 2, Section 5.2 (AWS WAF)


Q32.

An organization wants to consolidate security findings from GuardDuty, Inspector, and Macie into one dashboard. Which service should they use?

Bản dịch tiếng Việt: Một tổ chức muốn hợp nhất các phát hiện bảo mật từ GuardDuty, Inspector và Macie vào một bảng thông tin. Họ nên sử dụng dịch vụ nào?

A. AWS CloudWatch B. AWS Security Hub C. AWS Systems Manager D. AWS Organizations

Correct answer: B Bản dịch đáp án đúng: B. Trung tâm bảo mật AWS

🇬🇧 Explanation:

  • AWS Security Hub = central dashboard aggregating all security findings
  • Consolidates GuardDuty, Inspector, Macie, Config into one console

🇻🇳 Giải thích: Để gom findings từ GuardDuty, Inspector, Macie, Config về một dashboard duy nhất, dùng AWS Security Hub. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (CloudWatch) — metrics/logs only / chỉ metric & log
  • C (Systems Manager) — patch & fleet management / patch & quản lý fleet
  • D (Organizations) — multi-account governance, not findings / quản trị đa account, không gom findings

🔑 Key Concept / Khái niệm cốt lõi: Central security findings dashboard = Security Hub. / Dashboard tổng hợp findings = Security Hub.

📚 Reference: Domain 2, Section 6.4 (AWS Security Hub)


Q33.

A company is deploying applications across multiple AWS accounts and wants to ensure that all accounts have consistent security group configurations. Which service enables this centralized management?

Bản dịch tiếng Việt: Một công ty đang triển khai ứng dụng trên nhiều tài khoản AWS và muốn đảm bảo rằng tất cả các tài khoản đều có cấu hình nhóm bảo mật nhất quán. Dịch vụ nào cho phép quản lý tập trung này?

A. AWS Systems Manager B. AWS Firewall Manager C. AWS Organizations D. AWS Inspector

Correct answer: B Bản dịch đáp án đúng: B. Trình quản lý tường lửa AWS

🇬🇧 Explanation:

  • AWS Firewall Manager centrally manages WAF, Shield, Security Groups, and NACLs across accounts
  • Enforces consistent firewall rules org-wide

🇻🇳 Giải thích: Để áp cấu hình Security Group / firewall nhất quán trên nhiều account, dùng AWS Firewall Manager (quản lý tập trung WAF, Shield, SG, NACL qua Organizations). Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Systems Manager) — patch management / quản lý patch
  • C (Organizations) — governance, not firewall config management / quản trị, không quản cấu hình firewall
  • D (Inspector) — vulnerability scanning / quét lỗ hổng

🔑 Key Concept / Khái niệm cốt lõi: Multi-account firewall/SG rules = Firewall Manager. / Rule firewall/SG đa account = Firewall Manager.


Q34. (Select TWO)

Which of the following statements about AWS Lambda and the Shared Responsibility Model are correct? (Select TWO)

Bản dịch tiếng Việt: Câu nào sau đây về AWS Lambda và Mô hình trách nhiệm chung là đúng? (Chọn HAI)

A. The customer is responsible for patching the Lambda runtime B. AWS is responsible for the Lambda execution environment and scaling C. The customer is responsible for securing their Lambda function code and IAM roles D. AWS is responsible for encrypting customer code before execution E. The customer must manage the underlying Lambda infrastructure

Correct answer: B, C Bản dịch đáp án đúng: B. AWS chịu trách nhiệm về môi trường thực thi Lambda và mở rộng quy mô; C. Khách hàng chịu trách nhiệm bảo mật mã chức năng Lambda và vai trò IAM của mình

🇬🇧 Explanation:

  • B: AWS manages the Lambda execution environment & scaling ✓ AWS responsibility
  • C: Customer is responsible for code security & IAM roles ✓ customer responsibility

🇻🇳 Giải thích: Với Lambda: AWS lo execution environment, runtime & scaling (B); khách hàng lo bảo mật code và IAM role gắn cho function (C). Đáp án B, C đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — AWS patches the runtime / AWS patch runtime
  • D — customer must still secure their data/secrets in code / khách hàng vẫn phải bảo vệ data/secret trong code
  • E — AWS manages the Lambda infrastructure / AWS quản lý hạ tầng Lambda

🔑 Key Concept / Khái niệm cốt lõi: Lambda: AWS runs it; customer owns code + IAM. / Lambda: AWS vận hành; khách hàng lo code + IAM.


Q35.

A company wants to detect unusual API access patterns and identify potentially compromised credentials. Which AWS service uses machine learning to identify these threats?

Bản dịch tiếng Việt: Một công ty muốn phát hiện các kiểu truy cập API bất thường và xác định thông tin xác thực có khả năng bị xâm phạm. Dịch vụ AWS nào sử dụng công nghệ máy học để xác định những mối đe dọa này?

A. AWS Config B. Amazon GuardDuty C. Amazon Inspector D. AWS CloudTrail

Correct answer: B Bản dịch đáp án đúng: B. Nhiệm vụ bảo vệ của Amazon

🇬🇧 Explanation:

  • Amazon GuardDuty uses ML on CloudTrail, VPC Flow, and DNS logs to detect anomalies
  • Identifies unusual access patterns and compromised credentials

🇻🇳 Giải thích: Để phát hiện API pattern bất thường + credential bị lộ, dùng GuardDuty — dịch vụ threat detection dùng ML phân tích CloudTrail/VPC Flow/DNS logs. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Config) — compliance/config tracking / theo dõi cấu hình & tuân thủ
  • C (Inspector) — vulnerability scanning / quét lỗ hổng
  • D (CloudTrail) — logs API calls but does no ML analysis itself / log API nhưng không tự phân tích ML

🔑 Key Concept / Khái niệm cốt lõi: ML threat detection on logs = GuardDuty. / Phát hiện mối đe dọa bằng ML từ log = GuardDuty.

📚 Reference: Domain 2, Section 6.1 (Amazon GuardDuty)


Q36.

An organization has a compliance requirement to maintain encryption keys in a dedicated hardware module with physical control. Which service is most appropriate?

Bản dịch tiếng Việt: Một tổ chức có yêu cầu tuân thủ để duy trì các khóa mã hóa trong mô-đun phần cứng chuyên dụng có khả năng kiểm soát vật lý. Dịch vụ nào phù hợp nhất?

A. AWS Key Management Service (KMS) B. AWS Secrets Manager C. AWS CloudHSM D. AWS Certificate Manager

Correct answer: C Bản dịch đáp án đúng: C. Đám mây AWSHSM

🇬🇧 Explanation:

  • AWS CloudHSM = dedicated hardware security module (HSM)
  • Gives you single-tenant, FIPS 140-2 Level 3 hardware control of keys

🇻🇳 Giải thích: Khi compliance yêu cầu module phần cứng riêng để quản lý key, dùng AWS CloudHSM — phần cứng dành riêng, đạt chuẩn FIPS, bạn toàn quyền kiểm soát. Đáp án C đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (KMS) — AWS-managed, multi-tenant, no dedicated hardware / AWS quản lý, dùng chung, không phần cứng riêng
  • B (Secrets Manager) — stores passwords, not raw keys / lưu mật khẩu, không phải key
  • D (ACM) — SSL/TLS certificates / chứng chỉ SSL/TLS

🔑 Key Concept / Khái niệm cốt lõi: "Dedicated hardware for keys / FIPS" = CloudHSM. / "Phần cứng riêng cho key / FIPS" = CloudHSM.

📚 Reference: Domain 2, Section 4.3 (AWS CloudHSM)


Domain 3: Cloud Technology and Services (Q37–Q58)

Q37.

A company needs to allow EC2 instances in a public subnet to communicate with the internet while remaining secure. Which component is essential?

Bản dịch tiếng Việt: Công ty cần cho phép các phiên bản EC2 trong mạng con công cộng giao tiếp với Internet trong khi vẫn đảm bảo an toàn. Thành phần nào là thiết yếu?

A. Network Access Control List (NACL) only B. Internet Gateway attached to the VPC C. AWS Shield Advanced D. AWS WAF

Correct answer: B Bản dịch đáp án đúng: B. Cổng Internet gắn liền với VPC

🇬🇧 Explanation:

  • An Internet Gateway (IGW) attached to the VPC is the essential component
  • Lets EC2 in a public subnet reach the internet (and be reached)

🇻🇳 Giải thích: Để EC2 trong public subnet ra internet, cần gắn Internet Gateway (IGW) vào VPC kèm route 0.0.0.0/0 → IGW. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (NACL) — a subnet firewall, doesn't provide internet access / là firewall subnet, không cấp internet
  • C/D (DDoS/WAF) — security layers, not required for basic internet access / lớp bảo mật, không cần cho việc ra internet cơ bản

🔑 Key Concept / Khái niệm cốt lõi: Public subnet internet = IGW + route. / Public subnet ra internet = IGW + route.


Q38. (Select TWO)

Which of the following are characteristics of Security Groups? (Select TWO)

Bản dịch tiếng Việt: Đặc điểm nào sau đây là đặc điểm của Nhóm bảo mật? (Chọn HAI)

A. They operate at the network layer (Layer 3) B. They are stateful — a response to an outbound request is automatically allowed C. They can have both explicit Allow and Deny rules D. They operate at the subnet level, not the instance level E. By default, they deny all inbound traffic unless explicitly allowed

Correct answer: B, E Bản dịch đáp án đúng: B. Chúng có trạng thái - phản hồi cho yêu cầu gửi đi được tự động cho phép; E. Theo mặc định, họ từ chối tất cả lưu lượng truy cập vào trừ khi được cho phép rõ ràng

🇬🇧 Explanation:

  • B: Stateful — return traffic is allowed automatically ✓ key characteristic
  • E: Denies all inbound by default ✓ default behavior

🇻🇳 Giải thích: Đặc điểm Security Group: stateful (traffic phản hồi được tự động cho qua — B) và mặc định chặn toàn bộ inbound (E). Đáp án B, E đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — SG works at Layer 4 (port/protocol), not Layer 3 / SG ở Layer 4, không phải Layer 3
  • C — SG is Allow-only; no explicit Deny rules / SG chỉ Allow, không có rule Deny
  • D — SG is instance-level, not subnet-level (that's NACL) / SG ở mức instance, không phải subnet (đó là NACL)

🔑 Key Concept / Khái niệm cốt lõi: SG = stateful, instance-level, Allow-only, default-deny inbound. / SG = stateful, mức instance, chỉ Allow, mặc định chặn inbound.


Q39.

A company wants to encrypt data in transit between their application and an API Gateway. Which certificate service should they use?

Bản dịch tiếng Việt: Một công ty muốn mã hóa dữ liệu khi truyền giữa ứng dụng của họ và API Gateway. Họ nên sử dụng dịch vụ chứng chỉ nào?

A. AWS Key Management Service (KMS) B. AWS Certificate Manager (ACM) C. AWS Secrets Manager D. AWS CloudHSM

Correct answer: B Bản dịch đáp án đúng: B. Trình quản lý chứng chỉ AWS (ACM)

🇬🇧 Explanation:

  • AWS Certificate Manager (ACM) provisions SSL/TLS certificates
  • Enables HTTPS (encryption in transit) on API Gateway, ALB, CloudFront

🇻🇳 Giải thích: Để mã hóa dữ liệu in-transit tới API Gateway, dùng ACM cấp chứng chỉ SSL/TLS để bật HTTPS. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (KMS) — encryption at-rest / keys / mã hóa at-rest / key
  • C (Secrets Manager) — password/credential storage / lưu mật khẩu/credential
  • D (CloudHSM) — dedicated key hardware / phần cứng key riêng

🔑 Key Concept / Khái niệm cốt lõi: HTTPS / in-transit cert = ACM. / Chứng chỉ HTTPS / in-transit = ACM.

📚 Reference: Domain 2, Section 4.4 (AWS Certificate Manager)


Q40. (Select TWO)

Which of the following encryption options are available for RDS databases? (Select TWO)

Bản dịch tiếng Việt: Tùy chọn mã hóa nào sau đây có sẵn cho cơ sở dữ liệu RDS? (Chọn HAI)

A. Server-side encryption with AWS-managed keys B. Server-side encryption with customer-managed KMS keys C. Client-side encryption before data is sent to RDS D. Encryption using AWS Secrets Manager only E. No encryption available for RDS

Correct answer: A, B Bản dịch đáp án đúng: A. Mã hóa phía máy chủ bằng khóa do AWS quản lý; B. Mã hóa phía máy chủ với khóa KMS do khách hàng quản lý

🇬🇧 Explanation:

  • A: Server-side encryption with AWS-managed keys ✅ default KMS option
  • B: Server-side encryption with customer-managed KMS keys ✅ customer-controlled keys

🇻🇳 Giải thích: RDS hỗ trợ mã hóa at-rest qua KMS: dùng AWS-managed key (mặc định — A) hoặc customer-managed KMS key (B). Đáp án A, B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • C — client-side encryption is done in your app, not a native RDS at-rest option / mã hóa client-side làm trong app, không phải tùy chọn RDS
  • D — Secrets Manager rotates credentials, doesn't encrypt the volume / Secrets Manager xoay credential, không mã hóa volume
  • E — RDS DOES support encryption at rest via KMS / RDS CÓ hỗ trợ mã hóa at-rest qua KMS

🔑 Key Concept / Khái niệm cốt lõi: RDS at-rest = KMS (AWS-managed or customer-managed). / Mã hóa RDS at-rest = KMS (AWS- hoặc customer-managed).


Q41.

An application requires a reusable connection to read from an S3 bucket in another AWS account. What is the best approach?

Bản dịch tiếng Việt: Ứng dụng yêu cầu kết nối có thể sử dụng lại để đọc từ bộ chứa S3 trong tài khoản AWS khác. Cách tiếp cận tốt nhất là gì?

A. Store access keys from the other account in environment variables B. Create a cross-account IAM role and assume it via STS C. Use the root account credentials from both accounts D. Replicate all S3 data to the current account

Correct answer: B Bản dịch đáp án đúng: B. Tạo vai trò IAM trên nhiều tài khoản và đảm nhận vai trò đó thông qua STS

🇬🇧 Explanation:

  • Create a cross-account IAM role and assume it via STS = the proper approach
  • The role in Account B trusts Account A; access is temporary and reusable

🇻🇳 Giải thích: Để truy cập S3 ở account khác một cách tái sử dụng, tạo cross-account role ở Account B (tin tưởng Account A) rồi assume role qua STS. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — hardcoded keys are dangerous / hardcode key rất nguy hiểm
  • C — never use root credentials / không dùng credential root
  • D — replication isn't required for access / replication không cần cho việc truy cập

🔑 Key Concept / Khái niệm cốt lõi: Cross-account access = role + STS AssumeRole. / Truy cập cross-account = role + STS AssumeRole.


Q42. (Select TWO)

Which of the following are valid IAM authentication methods? (Select TWO)

Bản dịch tiếng Việt: Phương thức xác thực IAM nào sau đây hợp lệ? (Chọn HAI)

A. Username and password for AWS Console login B. Access Key ID and Secret Access Key for programmatic access (CLI/SDK) C. Biometric fingerprint scan on AWS Console D. Embedding the root account email address in application headers E. Hardware key fob for all access methods

Correct answer: A, B Bản dịch đáp án đúng: A. Tên người dùng và mật khẩu để đăng nhập vào Bảng điều khiển AWS; B. ID khóa truy cập và Khóa truy cập bí mật để truy cập theo chương trình (CLI/SDK)

🇬🇧 Explanation:

  • A: Username + password for the Console ✅ standard console authentication
  • B: Access Key ID + Secret for CLI/SDK ✅ programmatic authentication

🇻🇳 Giải thích: Hai cách xác thực IAM hợp lệ: username + password (đăng nhập Console — A) và Access Key ID + Secret (CLI/SDK — B). Đáp án A, B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • C — biometric fingerprint isn't an IAM auth method / vân tay không phải cách xác thực IAM
  • D — embedding the root email in headers isn't authentication / nhét email root vào header không phải xác thực
  • E — a hardware key fob is an MFA device, not a standalone auth method / key fob là thiết bị MFA, không phải cách xác thực độc lập

🔑 Key Concept / Khái niệm cốt lõi: IAM auth = password (Console) or access keys (CLI/SDK). / Xác thực IAM = password (Console) hoặc access key (CLI/SDK).


Q43.

A company wants to monitor and audit all changes to their VPC configuration (e.g., security group changes, subnet modifications). Which service should they use?

Bản dịch tiếng Việt: Một công ty muốn giám sát và kiểm tra tất cả các thay đổi đối với cấu hình VPC của họ (ví dụ: thay đổi nhóm bảo mật, sửa đổi mạng con). Họ nên sử dụng dịch vụ nào?

A. Amazon CloudWatch B. AWS Config C. AWS CloudTrail D. AWS Organizations

Correct answer: B Bản dịch đáp án đúng: B. Cấu hình AWS

🇬🇧 Explanation:

  • AWS Config records configuration snapshots and tracks changes over time
  • Captures SG rule changes, subnet modifications, etc.

🇻🇳 Giải thích: Để theo dõi thay đổi cấu hình của VPC (rule SG, subnet...), dùng AWS Config — nó chụp snapshot cấu hình và ghi lại lịch sử thay đổi. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (CloudWatch) — metrics/performance / metric & hiệu năng
  • C (CloudTrail) — API calls, not configuration state / API call, không phải trạng thái cấu hình
  • D (Organizations) — multi-account governance / quản trị đa account

🔑 Key Concept / Khái niệm cốt lõi: "When did config change" = AWS Config. / "Cấu hình đổi khi nào" = AWS Config.


Q44.

An EC2 instance in a private subnet needs to download patches from the internet. Which service should be configured?

Bản dịch tiếng Việt: Phiên bản EC2 trong mạng con riêng tư cần tải xuống các bản vá từ Internet. Dịch vụ nào nên được cấu hình?

A. Internet Gateway B. NAT Gateway (in public subnet) or NAT Instance C. Virtual Private Gateway D. AWS Direct Connect

Correct answer: B Bản dịch đáp án đúng: B. NAT Gateway (trong mạng con công cộng) hoặc NAT Instance

🇬🇧 Explanation:

  • A NAT Gateway in a public subnet lets private-subnet EC2 reach the internet outbound
  • Private instances route 0.0.0.0/0 → NAT for patches/updates (no inbound exposure)

🇻🇳 Giải thích: Để EC2 ở private subnet tải patch/update từ internet (chỉ outbound), dùng NAT Gateway đặt trong public subnet; private route 0.0.0.0/0 → NAT. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (IGW) — for public subnets, gives inbound+outbound / cho public subnet, hai chiều
  • C (Virtual Private Gateway) — VPN to on-premises / VPN tới on-premises
  • D (Direct Connect) — dedicated private link / đường truyền riêng

🔑 Key Concept / Khái niệm cốt lõi: Private subnet outbound internet = NAT Gateway. / Private subnet ra internet = NAT Gateway.


Q45. (Select TWO)

Which of the following distinguish NACLs from Security Groups in a VPC? (Select TWO)

Bản dịch tiếng Việt: Điều nào sau đây phân biệt NACL với Nhóm bảo mật trong VPC? (Chọn HAI)

A. NACLs are stateful; Security Groups are stateless B. Security Groups operate at the instance level; NACLs operate at the subnet level C. NACLs have both Allow and Deny rules; Security Groups allow only Allow rules D. NACLs are cheaper; Security Groups cost additional fees E. Both can block specific IP addresses

Correct answer: B, C Bản dịch đáp án đúng: B. Nhóm bảo mật hoạt động ở cấp độ phiên bản; NACL hoạt động ở cấp mạng con; C. NACL có cả quy tắc Cho phép và Từ chối; Nhóm bảo mật chỉ cho phép quy tắc Cho phép

🇬🇧 Explanation:

  • B: SG operates at instance level; NACL at subnet level ✓ key difference
  • C: NACL supports Deny; SG is Allow-only ✓ correct distinction

🇻🇳 Giải thích: Khác biệt chính: SG ở mức instance, chỉ Allow, stateful; NACL ở mức subnet, có cả Deny, stateless. Đáp án B, C đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — reversed: SG is stateful, NACL is stateless / ngược: SG stateful, NACL stateless
  • D — cost is not the distinction / chi phí không phải điểm phân biệt
  • E — true but not a distinguishing feature / đúng nhưng không phải đặc điểm phân biệt

🔑 Key Concept / Khái niệm cốt lõi: SG = instance/stateful/Allow; NACL = subnet/stateless/Allow+Deny. / SG = instance/stateful/Allow; NACL = subnet/stateless/Allow+Deny.


Q46.

A company stores SSL/TLS certificates and wants to automate renewal to prevent expiration. Which service provides automatic certificate renewal?

Bản dịch tiếng Việt: Một công ty lưu trữ chứng chỉ SSL/TLS và muốn tự động gia hạn để tránh hết hạn. Dịch vụ nào cung cấp khả năng gia hạn chứng chỉ tự động?

A. AWS Secrets Manager B. AWS Key Management Service C. AWS Certificate Manager D. AWS Systems Manager Parameter Store

Correct answer: C Bản dịch đáp án đúng: C. Trình quản lý chứng chỉ AWS

🇬🇧 Explanation:

  • AWS Certificate Manager (ACM) auto-renews SSL/TLS certificates before expiration
  • Eliminates manual certificate management

🇻🇳 Giải thích: Để tự động gia hạn chứng chỉ SSL/TLS trước khi hết hạn, dùng ACM — không cần thao tác thủ công. Đáp án C đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Secrets Manager) — passwords/credentials / mật khẩu/credential
  • B (KMS) — encryption keys / key mã hóa
  • D (Parameter Store) — config values / giá trị cấu hình

🔑 Key Concept / Khái niệm cốt lõi: Auto-renew TLS certs = ACM. / Tự gia hạn chứng chỉ TLS = ACM.


Q47. (Select THREE)

Which of the following are use cases for IAM roles in AWS? (Select THREE)

Bản dịch tiếng Việt: Trường hợp nào sau đây là trường hợp sử dụng cho vai trò IAM trong AWS? (Chọn BA)

A. Allowing an EC2 instance to access S3 without hardcoding credentials B. Enabling temporary access for users from a corporate identity provider (federated identity) C. Storing long-term credentials for database access D. Replacing IAM users for human access to the AWS Console E. Granting cross-account access via role assumption

Correct answer: A, B, E Bản dịch đáp án đúng: A. Cho phép phiên bản EC2 truy cập S3 mà không cần thông tin xác thực mã hóa cứng; B. Cho phép truy cập tạm thời cho người dùng từ nhà cung cấp danh tính công ty (danh tính liên kết); E. Cấp quyền truy cập nhiều tài khoản thông qua giả định vai trò

🇬🇧 Explanation:

  • A: EC2 accessing S3 without hardcoded creds ✅ primary use case (instance profile)
  • B: Temporary access from a corporate IdP ✅ federated identity (SAML/OIDC)
  • E: Cross-account access via role assumption ✅ assume role across accounts via STS

🇻🇳 Giải thích: Các use case của IAM role: EC2 truy cập S3 không cần hardcode key (A), federated identity từ IdP doanh nghiệp (B), và cross-account access qua AssumeRole/STS (E). Đáp án A, B, E đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • C — roles give temporary credentials, not long-term stored creds / role cấp credential tạm thời, không lưu lâu dài
  • D — roles federate access but don't "replace" IAM users for direct console sign-in / role federate truy cập nhưng không thay user cho việc login Console trực tiếp

🔑 Key Concept / Khái niệm cốt lõi: Roles = EC2/service access, federation, cross-account. / Role = truy cập service, federation, cross-account.


Q48.

An S3 bucket contains sensitive backup data. The company wants to ensure that all objects are encrypted and versioning is enabled for compliance. What policies should be applied?

Bản dịch tiếng Việt: Vùng lưu trữ S3 chứa dữ liệu sao lưu nhạy cảm. Công ty muốn đảm bảo rằng tất cả các đối tượng đều được mã hóa và phiên bản được kích hoạt để tuân thủ. Nên áp dụng những chính sách gì?

A. S3 bucket policies only B. S3 ACLs only C. S3 bucket policies, encryption settings, and versioning configuration D. AWS IAM policies only

Correct answer: C Bản dịch đáp án đúng: C. Chính sách bộ chứa S3, cài đặt mã hóa và cấu hình phiên bản

🇬🇧 Explanation:

  • Securing an S3 backup needs bucket policy + encryption (SSE-KMS) + versioning together
  • These are separate, complementary configurations — not a single setting

🇻🇳 Giải thích: Để backup S3 vừa được mã hóa vừa có versioning, cần kết hợp bucket policy + encryption (SSE-KMS) + versioning — đây là các cấu hình riêng biệt, không chỉ mỗi bucket policy. Đáp án C đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — bucket policies alone are insufficient / chỉ bucket policy là chưa đủ
  • B — ACLs alone are insufficient / chỉ ACL là chưa đủ
  • D — IAM policies alone are insufficient / chỉ IAM policy là chưa đủ

🔑 Key Concept / Khái niệm cốt lõi: S3 protection = access control + encryption + versioning combined. / Bảo vệ S3 = kiểm soát truy cập + mã hóa + versioning kết hợp.


Q49. (Select TWO)

Which services should be used to achieve both "encryption at rest" and "encryption in transit"? (Select TWO)

Bản dịch tiếng Việt: Nên sử dụng dịch vụ nào để đạt được cả "mã hóa ở trạng thái nghỉ" và "mã hóa khi truyền"? (Chọn HAI)

A. AWS KMS for encryption at rest B. AWS Certificate Manager for HTTPS/TLS encryption in transit C. S3 versioning for both at-rest and in-transit encryption D. AWS Secrets Manager for all encryption needs E. AWS Config for both at-rest and in-transit encryption

Correct answer: A, B Bản dịch đáp án đúng: A. AWS KMS để mã hóa ở trạng thái lưu trữ; B. Trình quản lý chứng chỉ AWS để mã hóa HTTPS/TLS khi truyền

🇬🇧 Explanation:

  • A: KMS for at-rest encryption ✅ manages keys for data at rest
  • B: ACM for HTTPS/TLS in-transit ✅ provisions TLS certs for data in transit

🇻🇳 Giải thích: Mã hóa "mọi nơi": KMS cho at-rest và ACM/TLS cho in-transit. Đáp án A, B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • C — versioning protects against overwrite/delete, not encryption / versioning chống ghi đè/xóa, không phải mã hóa
  • D — Secrets Manager protects credentials, not general encryption / Secrets Manager bảo vệ credential, không phải mã hóa chung
  • E — AWS Config tracks config, doesn't encrypt / Config theo dõi cấu hình, không mã hóa

🔑 Key Concept / Khái niệm cốt lõi: At-rest = KMS; in-transit = ACM/TLS. / At-rest = KMS; in-transit = ACM/TLS.


Q50.

A company wants to ensure that all data stored in EBS volumes is encrypted. Which approach is most efficient?

Bản dịch tiếng Việt: Một công ty muốn đảm bảo rằng tất cả dữ liệu được lưu trữ trong khối EBS đều được mã hóa. Cách tiếp cận nào hiệu quả nhất?

A. Manually encrypt each volume after creation B. Enable default encryption at the account level C. Use software-based encryption inside the application D. Store encrypted data on S3 instead

Correct answer: B Bản dịch đáp án đúng: B. Bật mã hóa mặc định ở cấp tài khoản

🇬🇧 Explanation:

  • Enable EBS default encryption at the account/Region level → all new volumes are encrypted automatically
  • Most efficient: no manual per-volume setup

🇻🇳 Giải thích: Cách hiệu quả nhất để mọi EBS volume được mã hóa là bật default encryption ở mức account/Region — mọi volume mới tự động encrypt, không phải làm thủ công từng cái. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — encrypting each volume manually is inefficient / mã hóa thủ công từng volume kém hiệu quả
  • C — software encryption is redundant with native EBS encryption / mã hóa phần mềm thừa so với EBS
  • D — moving to S3 changes the architecture / chuyển sang S3 là đổi kiến trúc

🔑 Key Concept / Khái niệm cốt lõi: Encrypt all new EBS = account-level default encryption. / Mã hóa mọi EBS mới = default encryption mức account.


Q51. (Select TWO)

Which of the following are required for secure EC2 access? (Select TWO)

Bản dịch tiếng Việt: Điều nào sau đây là bắt buộc để truy cập EC2 an toàn? (Chọn HAI)

A. A key pair (public/private keys) or EC2 Instance Connect B. An IAM role attached to access other AWS services C. A publicly routable IP address D. Proper Security Group rules to allow SSH/RDP traffic E. AWS Shield Advanced enabled

Correct answer: A, D Bản dịch đáp án đúng: A. Một cặp khóa (khóa chung/riêng) hoặc Kết nối phiên bản EC2; D. Quy tắc Nhóm bảo mật phù hợp để cho phép lưu lượng SSH/RDP

🇬🇧 Explanation:

  • A: Key pair or EC2 Instance Connect ✓ required for SSH/RDP authentication
  • D: SG rules allowing SSH/RDP traffic ✓ required for connectivity

🇻🇳 Giải thích: Để truy cập EC2 an toàn cần: key pair (hoặc EC2 Instance Connect) để xác thực (A) và rule SG cho phép cổng SSH/RDP để thông mạng (D). Đáp án A, D đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B — IAM role is for accessing other AWS services, not for logging into EC2 / IAM role để truy cập service khác, không phải login EC2
  • C — a public IP isn't required (use a bastion / SSM) / không bắt buộc public IP (có thể dùng bastion / SSM)
  • E — Shield Advanced isn't needed for basic access / Shield Advanced không cần cho truy cập cơ bản

🔑 Key Concept / Khái niệm cốt lõi: EC2 access = key/Instance Connect + SG allowing the port. / Truy cập EC2 = key/Instance Connect + SG mở cổng.


Q52.

A company wants to log all changes to resources across their AWS account (including who accessed what and when). Which combination of services provides complete audit coverage?

Bản dịch tiếng Việt: Một công ty muốn ghi lại tất cả các thay đổi đối với tài nguyên trên tài khoản AWS của họ (bao gồm cả ai đã truy cập nội dung và thời điểm). Sự kết hợp dịch vụ nào cung cấp phạm vi kiểm toán đầy đủ?

A. CloudWatch only B. CloudTrail and AWS Config C. AWS Organizations only D. Amazon GuardDuty only

Correct answer: B Bản dịch đáp án đúng: B. Cấu hình CloudTrail và AWS

🇬🇧 Explanation:

  • CloudTrail (API audit) + AWS Config (config tracking) together = complete coverage
  • CloudTrail = "who did what"; Config = "when did config change"

🇻🇳 Giải thích: Để phủ audit đầy đủ cả API call lẫn thay đổi cấu hình, kết hợp CloudTrail (ai làm gì) + AWS Config (cấu hình đổi khi nào). Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — CloudWatch alone is insufficient (metrics, not API/config audit) / chỉ CloudWatch là chưa đủ
  • C — Organizations is governance, not audit / Organizations là quản trị, không phải audit
  • D — GuardDuty is threat detection, not an audit trail / GuardDuty phát hiện mối đe dọa, không phải audit

🔑 Key Concept / Khái niệm cốt lõi: Full audit = CloudTrail (API) + Config (configuration). / Audit đầy đủ = CloudTrail (API) + Config (cấu hình).


Q53. (Select TWO)

Which of the following correctly describe the relationship between encryption keys in S3? (Select TWO)

Bản dịch tiếng Việt: Câu nào sau đây mô tả chính xác mối quan hệ giữa các khóa mã hóa trong S3? (Chọn HAI)

A. SSE-S3 requires the customer to upload and manage their own encryption keys B. SSE-KMS allows the customer to control and rotate their own KMS keys C. SSE-C means the customer provides and manages the encryption key D. All S3 data is encrypted by default with SSE-S3 only E. Customers can choose between SSE-S3, SSE-KMS, or no encryption

Correct answer: B, C Bản dịch đáp án đúng: B. SSE-KMS cho phép khách hàng kiểm soát và xoay khóa KMS của riêng mình; C. SSE-C có nghĩa là khách hàng cung cấp và quản lý khóa mã hóa

🇬🇧 Explanation:

  • B: SSE-KMS gives customer control + key rotation ✅ correct
  • C: SSE-C means the customer provides their own key ✅ correct

🇻🇳 Giải thích: Quan hệ key trong mã hóa S3: SSE-KMS cho khách hàng kiểm soát + rotate key (B); SSE-C khách hàng tự cung cấp key (C). (SSE-S3 thì AWS quản key, là mặc định.) Đáp án B, C đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — SSE-S3 uses AWS-managed keys; the customer doesn't upload them (that's SSE-C) / SSE-S3 dùng key AWS quản, không phải khách upload (đó là SSE-C)
  • D — S3 defaults to SSE-S3 but you can choose SSE-KMS/SSE-C too / S3 mặc định SSE-S3 nhưng vẫn chọn được SSE-KMS/SSE-C
  • E — S3 encrypts all objects by default; "no encryption" isn't an option / S3 mặc định mã hóa mọi object

🔑 Key Concept / Khái niệm cốt lõi: SSE-S3 (AWS keys) / SSE-KMS (KMS control) / SSE-C (your key). / SSE-S3 (key AWS) / SSE-KMS (kiểm soát KMS) / SSE-C (key của bạn).


Q54.

A database administrator wants to allow specific EC2 instances to connect to an RDS database securely. How should they configure access?

Bản dịch tiếng Việt: Quản trị viên cơ sở dữ liệu muốn cho phép các phiên bản EC2 cụ thể kết nối với cơ sở dữ liệu RDS một cách an toàn. Họ nên cấu hình quyền truy cập như thế nào?

A. Create a database user password and store it in plaintext in the EC2 instance B. Use the RDS security group to allow traffic from the EC2 instance security group C. Allow all inbound traffic to RDS on port 3306 D. Configure SSH tunneling through a bastion host only

Correct answer: B Bản dịch đáp án đúng: B. Sử dụng nhóm bảo mật RDS để cho phép lưu lượng truy cập từ nhóm bảo mật phiên bản EC2

🇬🇧 Explanation:

  • Configure the RDS security group to allow traffic from the EC2 security group (SG referencing)
  • EC2-SG → RDS-SG: least-privilege, no IP hardcoding

🇻🇳 Giải thích: Cách an toàn cho EC2 kết nối RDS: cấu hình SG của RDS cho phép traffic từ SG của EC2 (SG referencing, ví dụ port 3306) — không mở ra Internet, không hardcode IP. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — plaintext password is insecure / mật khẩu plaintext không an toàn
  • C — opening port 3306 to the world is dangerous / mở 3306 ra toàn Internet rất nguy hiểm
  • D — a bastion adds unnecessary complexity here / bastion thêm phức tạp không cần thiết

🔑 Key Concept / Khái niệm cốt lõi: EC2→RDS = SG referencing (allow from EC2-SG). / EC2→RDS = SG tham chiếu (cho phép từ SG của EC2).


Q55. (Select TWO)

Which AWS services provide network-level DDoS protection or mitigation? (Select TWO)

Bản dịch tiếng Việt: Dịch vụ AWS nào cung cấp khả năng bảo vệ hoặc giảm thiểu DDoS ở cấp độ mạng? (Chọn HAI)

A. AWS Shield (Standard and Advanced) B. AWS WAF C. AWS Secrets Manager D. AWS CloudFront (edge locations absorb and disperse DDoS traffic) E. AWS IAM

Correct answer: A, D Bản dịch đáp án đúng: A. AWS Shield (Tiêu chuẩn và nâng cao); D. AWS CloudFront (các vị trí biên hấp thụ và phân tán lưu lượng DDoS)

🇬🇧 Explanation:

  • A: AWS Shield (Standard & Advanced) ✅ dedicated DDoS protection (L3/L4 always-on; L7 with Advanced)
  • D: AWS CloudFront ✅ the global edge network absorbs/disperses attack traffic near the source (AWS-documented DDoS mitigation; also true of Route 53)

🇻🇳 Giải thích: Bảo vệ/giảm thiểu DDoS ở tầng network: Shield (dịch vụ DDoS chuyên dụng) và CloudFront (mạng edge toàn cầu hấp thụ & phân tán lưu lượng tấn công gần nguồn). Đáp án A, D đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B (WAF) — filters L7 HTTP (SQLi/XSS), not network DDoS / lọc L7 (SQLi/XSS), không phải DDoS network
  • C (Secrets Manager) — stores/rotates credentials, unrelated / lưu/xoay credential, không liên quan
  • E (IAM) — access control, not DDoS / kiểm soát truy cập, không phải DDoS

🔑 Key Concept / Khái niệm cốt lõi: Network DDoS = Shield + edge (CloudFront/Route 53). / DDoS network = Shield + edge (CloudFront/Route 53).


Q56.

A company wants to implement fine-grained access control where different teams can access only their respective S3 buckets. Which approach is most secure and scalable?

Bản dịch tiếng Việt: Một công ty muốn triển khai kiểm soát truy cập chi tiết trong đó các nhóm khác nhau chỉ có thể truy cập vào nhóm S3 tương ứng của họ. Cách tiếp cận nào là an toàn nhất và có thể mở rộng?

A. Create unique IAM users for each person and attach individual policies B. Create IAM groups per team with managed policies limiting bucket access per group C. Use S3 bucket policies to allow all users in the organization access D. Share a single set of access keys across each team

Correct answer: B Bản dịch đáp án đúng: B. Tạo nhóm IAM cho mỗi nhóm với các chính sách được quản lý giới hạn quyền truy cập nhóm cho mỗi nhóm

🇬🇧 Explanation:

  • IAM groups per team + managed policies scoped per bucket = scalable, fine-grained
  • Each group gets a policy allowing access only to its team's buckets

🇻🇳 Giải thích: Để cấp quyền chi tiết cho từng team vào đúng bucket của họ, tạo IAM group theo team rồi gắn managed policy giới hạn theo bucket. Cách này dễ mở rộng. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — one policy per person doesn't scale / mỗi người một policy thì không mở rộng nổi
  • C — too open / quá mở
  • D — shared keys are not secure / dùng chung key không an toàn

🔑 Key Concept / Khái niệm cốt lõi: Scalable access = groups + scoped policies. / Phân quyền dễ mở rộng = group + policy giới hạn phạm vi.


Q57. (Select TWO)

Which of the following statements about VPC and network security are correct? (Select TWO)

Bản dịch tiếng Việt: Câu nào sau đây về VPC và bảo mật mạng là đúng? (Chọn HAI)

A. A VPC is a logically isolated network within AWS B. All EC2 instances are automatically in the same VPC regardless of region C. Subnets within a VPC can have different route tables and NACLs D. A single VPC automatically spans every AWS Region by default E. Public subnets require NAT Gateways to access the internet

Correct answer: A, C Bản dịch đáp án đúng: A. VPC là một mạng được cách ly hợp lý trong AWS; C. Các mạng con trong VPC có thể có các bảng định tuyến và NACL khác nhau

🇬🇧 Explanation:

  • A: A VPC is a logically isolated network ✅ correct
  • C: Subnets have their own route tables & NACLs ✅ correct (per-subnet config)

🇻🇳 Giải thích: Bảo mật network của VPC: VPC là mạng cô lập logic (A), và mỗi subnet có route table + NACL riêng (C). Đáp án A, C đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B — instances in a Region can be in different VPCs, not all in one / instance trong Region có thể ở nhiều VPC khác nhau
  • D — a VPC is Region-scoped, doesn't span every Region / VPC giới hạn 1 Region, không trải mọi Region
  • E — public subnets reach the internet via IGW, not NAT / public subnet ra internet qua IGW, không phải NAT

🔑 Key Concept / Khái niệm cốt lõi: VPC = isolated, Region-scoped; subnets have own RT/NACL. / VPC = cô lập, theo Region; subnet có RT/NACL riêng.


Q58.

An organization stores sensitive employee records in DynamoDB and wants to ensure encryption at rest. Which approach is correct?

Bản dịch tiếng Việt: Một tổ chức lưu trữ hồ sơ nhân viên nhạy cảm trong DynamoDB và muốn đảm bảo mã hóa ở trạng thái lưu trữ. Cách tiếp cận nào là đúng?

A. DynamoDB does not support encryption at rest B. Enable DynamoDB encryption using AWS-managed keys or customer-managed KMS keys C. Use third-party encryption before storing data in DynamoDB D. DynamoDB encrypts data only if using DynamoDB Streams

Correct answer: B Bản dịch đáp án đúng: B. Kích hoạt mã hóa DynamoDB bằng khóa do AWS quản lý hoặc khóa KMS do khách hàng quản lý

🇬🇧 Explanation:

  • Enable DynamoDB encryption at rest using AWS-managed or customer-managed KMS keys
  • DynamoDB encrypts all tables at rest by default

🇻🇳 Giải thích: DynamoDB hỗ trợ mã hóa at-rest bằng KMS key (AWS-managed hoặc customer-managed) — thực ra bật mặc định cho mọi table. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — DynamoDB DOES support encryption / DynamoDB CÓ hỗ trợ mã hóa
  • C — third-party encryption isn't necessary / không cần mã hóa bên thứ ba
  • D — encryption isn't limited to Streams / mã hóa không chỉ cho Streams

🔑 Key Concept / Khái niệm cốt lõi: DynamoDB at-rest = KMS (encrypted by default). / DynamoDB at-rest = KMS (mặc định đã mã hóa).


Domain 4: Billing, Pricing, and Support (Q59–Q65)

Q59.

An organization wants to ensure that critical security issues in their AWS account are addressed promptly. Which support plan includes 24/7 phone support and a dedicated Technical Account Manager (TAM)?

Bản dịch tiếng Việt: Một tổ chức muốn đảm bảo rằng các vấn đề bảo mật quan trọng trong tài khoản AWS của họ được giải quyết kịp thời. Gói hỗ trợ nào bao gồm hỗ trợ qua điện thoại 24/7 và Trình quản lý tài khoản kỹ thuật (TAM) chuyên dụng?

A. Basic B. Developer C. Business D. Enterprise

Correct answer: D Bản dịch đáp án đúng: D. Doanh nghiệp

🇬🇧 Explanation:

  • A designated TAM plus 24/7 phone support is an Enterprise feature
  • (Enterprise On-Ramp has a pooled TAM; Enterprise has a designated TAM)

🇻🇳 Giải thích:TAM riêng + hỗ trợ 24/7 qua điện thoại là đặc quyền của gói Enterprise. Đáp án D đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Basic) — no technical support / không hỗ trợ kỹ thuật
  • B (Developer) — email in business hours only / chỉ email giờ hành chính
  • C (Business) — 24/7 support but no TAM / có 24/7 nhưng không có TAM

🔑 Key Concept / Khái niệm cốt lõi: Designated TAM = Enterprise. / TAM riêng = Enterprise.

📚 Reference: Domain 4 study guide (Support Plans table)


Q60.

A company wants to receive security alerts and recommendations (like "Your S3 bucket is public" or "RDS not encrypted"). Which AWS service is free and provides these recommendations?

Bản dịch tiếng Việt: Một công ty muốn nhận được cảnh báo và đề xuất bảo mật (chẳng hạn như "Bộ lưu trữ S3 của bạn ở chế độ công khai" hoặc "RDS không được mã hóa"). Dịch vụ AWS nào miễn phí và cung cấp những đề xuất này?

A. AWS Security Hub B. AWS Trusted Advisor (core checks in free tier) C. Amazon GuardDuty D. AWS Inspector

Correct answer: B Bản dịch đáp án đúng: B. Cố vấn đáng tin cậy của AWS (kiểm tra cốt lõi ở bậc miễn phí)

🇬🇧 Explanation:

  • AWS Trusted Advisor core checks are free and include security recommendations
  • Full checks come with Business/Enterprise support plans

🇻🇳 Giải thích: Để có khuyến nghị bảo mật miễn phí (S3 public, RDS encryption...), dùng Trusted Advisor core checks. Full checks cần gói Business/Enterprise. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Security Hub) — paid / trả phí
  • C (GuardDuty) — paid / trả phí
  • D (Inspector) — paid / trả phí

🔑 Key Concept / Khái niệm cốt lõi: Free best-practice/security checks = Trusted Advisor (core). / Kiểm tra bảo mật miễn phí = Trusted Advisor (core).


Q61. (Select TWO)

Which of the following are included in AWS Trusted Advisor security checks? (Select TWO)

Bản dịch tiếng Việt: Nội dung nào sau đây được bao gồm trong quá trình kiểm tra bảo mật AWS Trusted Advisor? (Chọn HAI)

A. Security group restrictions (open ports to internet) B. Root account usage and MFA status C. DDoS attack prevention capabilities D. Automatically remediating misconfigured resources without user action E. Real-time threat detection

Correct answer: A, B Bản dịch đáp án đúng: A. Hạn chế của nhóm bảo mật (mở cổng vào internet); B. Việc sử dụng tài khoản root và trạng thái MFA

🇬🇧 Explanation:

  • A: Security group restrictions (open ports) ✅ core (free) security check
  • B: Root account usage & MFA status ✅ core (free) security check

🇻🇳 Giải thích: Trusted Advisor security checks (core/free) gồm: cảnh báo SG mở cổng (A) và MFA của root account (B), IAM, access key lộ. Đáp án A, B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • C — DDoS prevention is Shield's job, not a TA check / chống DDoS là việc của Shield, không phải TA
  • D — Trusted Advisor only flags/recommends, it doesn't auto-remediate / TA chỉ cảnh báo, không tự sửa
  • E — real-time threat detection is GuardDuty / phát hiện mối đe dọa real-time là GuardDuty

🔑 Key Concept / Khái niệm cốt lõi: TA security checks = flag misconfig (open ports, root MFA). / TA security = cảnh báo cấu hình sai (cổng mở, MFA root).


Q62.

An Enterprise support plan customer experiences a security incident affecting their production systems. What response time should AWS provide?

Bản dịch tiếng Việt: Khách hàng của gói hỗ trợ Doanh nghiệp gặp phải sự cố bảo mật ảnh hưởng đến hệ thống sản xuất của họ. AWS nên cung cấp thời gian phản hồi như thế nào?

A. 12 hours B. 4 hours C. 1 hour D. 15 minutes

Correct answer: D Bản dịch đáp án đúng: D. 15 phút

🇬🇧 Explanation:

  • Enterprise = 15-minute response SLA for business-critical issues
  • A security incident counts as business-critical

🇻🇳 Giải thích: Gói Enterprise có SLA phản hồi 15 phút cho sự cố business-critical (sự cố bảo mật được xem là critical). Đáp án D đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — general guidance is a lower tier (Developer) / hướng dẫn chung là tier thấp hơn (Developer)
  • B — production-down (1h) is Business tier / production-down (1h) là Business
  • C — 1-hour is also Business, not the business-critical SLA / 1 giờ cũng là Business, không phải SLA business-critical

🔑 Key Concept / Khái niệm cốt lõi: 15-min business-critical SLA = Enterprise. / SLA 15 phút business-critical = Enterprise.


Q63.

A startup is building a web application and wants to understand AWS compliance certifications (HIPAA, PCI DSS, SOC 2). Where can they find official compliance documents?

Bản dịch tiếng Việt: Một công ty khởi nghiệp đang xây dựng một ứng dụng web và muốn hiểu các chứng chỉ tuân thủ AWS (HIPAA, PCI DSS, SOC 2). Họ có thể tìm tài liệu tuân thủ chính thức ở đâu?

A. AWS Trusted Advisor B. AWS Artifact C. AWS CloudTrail logs D. AWS Organizations dashboard

Correct answer: B Bản dịch đáp án đúng: B. Cấu phần AWS

🇬🇧 Explanation:

  • AWS Artifact = self-service portal for AWS compliance reports (SOC, PCI DSS, HIPAA, ISO)
  • On-demand access to audit artifacts & agreements

🇻🇳 Giải thích: Để lấy tài liệu tuân thủ của AWS (HIPAA, PCI DSS, SOC...), dùng AWS Artifact — portal self-service tải báo cáo & thỏa thuận compliance. Đáp án B đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Trusted Advisor) — best-practice recommendations / khuyến nghị best practice
  • C (CloudTrail) — API logs / log API
  • D (Organizations) — multi-account management / quản lý đa account

🔑 Key Concept / Khái niệm cốt lõi: Compliance reports = AWS Artifact. / Báo cáo tuân thủ = AWS Artifact.


Q64. (Select TWO)

Which of the following describe the differences between AWS support plans regarding security features? (Select TWO)

Bản dịch tiếng Việt: Điều nào sau đây mô tả sự khác biệt giữa các gói hỗ trợ của AWS về tính năng bảo mật? (Chọn HAI)

A. The Basic (free) plan includes a dedicated Technical Account Manager (TAM) B. Enterprise plan includes a TAM for proactive security reviews C. Business plan includes full Trusted Advisor checks (beyond core security) D. Shield Advanced is bundled free with the Developer support plan E. The Developer plan includes 24/7 phone support for security incidents

Correct answer: B, C Bản dịch đáp án đúng: B. Gói doanh nghiệp bao gồm TAM để chủ động đánh giá bảo mật; C. Kế hoạch kinh doanh bao gồm các bước kiểm tra Trusted Advisor đầy đủ (ngoài bảo mật cốt lõi)

🇬🇧 Explanation:

  • B: Enterprise TAM for proactive security reviews ✅ TAM is an Enterprise (& Enterprise On-Ramp) feature
  • C: Business plan includes full Trusted Advisor ✅ full checks start at Business

🇻🇳 Giải thích: Khác biệt bảo mật giữa các gói support: Enterprise có TAM cho review chủ động (B); Business mở khóa full Trusted Advisor (C). Đáp án B, C đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — TAM is Enterprise-tier, not part of free Basic / TAM thuộc Enterprise, không có ở Basic miễn phí
  • D — Shield Advanced is a separate paid subscription, not bundled with Developer / Shield Advanced trả phí riêng, không kèm Developer
  • E — 24/7 phone support starts at Business, not Developer / hỗ trợ điện thoại 24/7 bắt đầu từ Business

🔑 Key Concept / Khái niệm cốt lõi: Full TA = Business+; TAM = Enterprise(+On-Ramp). / Full TA = từ Business; TAM = Enterprise(+On-Ramp).


Q65.

A financial services company requires access to AWS compliance reports (e.g., PCI DSS certification, SOC 2 audit reports) to meet their own audit requirements. Which AWS service provides these documents?

Bản dịch tiếng Việt: Công ty dịch vụ tài chính yêu cầu quyền truy cập vào các báo cáo tuân thủ AWS (ví dụ: chứng nhận PCI DSS, báo cáo kiểm tra SOC 2) để đáp ứng các yêu cầu kiểm tra của riêng họ. Dịch vụ AWS nào cung cấp những tài liệu này?

A. AWS Artifact — offers access to compliance documents B. AWS Compliance Center — publishes all documents publicly C. AWS Config — generates compliance reports automatically D. AWS Organizations — central compliance portal

Correct answer: A Bản dịch đáp án đúng: A. AWS Artifact — cung cấp quyền truy cập vào các tài liệu tuân thủ

🇬🇧 Explanation:

  • AWS Artifact lets you download official compliance documents (SOC 2, PCI DSS, etc.) for your own audit
  • Self-service, on-demand audit artifacts

🇻🇳 Giải thích: Để truy cập báo cáo tuân thủ phục vụ audit của tổ chức, dùng AWS Artifact tải tài liệu chính thức (SOC 2, PCI DSS...). Đáp án A đúng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B (Compliance Center) — public AWS info, not account-specific audit docs / thông tin công khai, không phải tài liệu audit riêng
  • C (Config) — compliance rules, not official documents / rule tuân thủ, không phải tài liệu chính thức
  • D (Organizations) — multi-account management, not docs / quản lý đa account, không phải tài liệu

🔑 Key Concept / Khái niệm cốt lõi: Download audit/compliance docs = AWS Artifact. / Tải tài liệu audit/tuân thủ = AWS Artifact.


Summary: Key Concepts by Domain

Domain 1: Security Pillar Foundation

  • Shared Responsibility = AWS (infrastructure), Customer (data + access)
  • Service variation = EC2 (customer patches), RDS (AWS patches), Lambda (AWS all)
  • Defense in depth = multiple security layers
  • Least Privilege = grant only necessary permissions
  • MFA = mandatory for root account

Domain 2: Security Deep Dive (Highest exam pressure)

  • CloudTrail = API audit ("who did what")
  • AWS Config = configuration tracking ("when did config change")
  • CloudWatch = metrics/performance (NOT security-focused)
  • IAM = users, groups, roles, policies (principle of least privilege)
  • KMS = encryption key management (AWS-managed vs customer-managed)
  • Secrets Manager = auto-rotate passwords/credentials
  • Macie = detect PII in S3
  • GuardDuty = ML-based threat detection
  • Shield Standard = free DDoS (L3-L4)
  • Shield Advanced = paid + response team
  • WAF = web application firewall (SQL injection, XSS)
  • Organizations + SCPs = multi-account governance

Domain 3: Service Security

  • SG = stateful firewall (instance level, Allow only)
  • NACL = stateless firewall (subnet level, Allow + Deny)
  • IGW = internet access for public subnet
  • NAT Gateway = private subnet→internet access
  • ACM = SSL/TLS certificates for HTTPS
  • S3 encryption = SSE-S3 (default), SSE-KMS (control), SSE-C (customer key)
  • RDS encryption = AWS-managed or customer-managed KMS keys
  • IAM roles = EC2 access AWS services securely

Domain 4: Support & Compliance

  • Trusted Advisor = free core checks (security, cost, performance)
  • Artifact = compliance documents download
  • Enterprise plan = 15min response + TAM + IEM

Exam Preparation Notes

High-confidence questions:

  • Shared Responsibility (service-specific)
  • CloudTrail vs Config vs CloudWatch
  • IAM (users, groups, roles, principle of least privilege)
  • Encryption (at-rest vs in-transit)
  • Multi-account governance (Organizations + SCPs)

Common pitfalls to avoid:

  1. Confuse EC2 vs RDS patching → EC2=customer, RDS=AWS
  2. Confuse CloudTrail + Config + CloudWatch → Each has different purpose
  3. Forget NACL has Deny rules → SG has Allow only
  4. Forget temporary creds expire → Roles provide temp creds, not permanent
  5. Confuse Trusted Advisor tiers → Core=free, Full=Business+

If you scored low (< 50):

  • Re-read Domain 2, Section 1 (Shared Responsibility) — foundational
  • Re-read Domain 2, Section 2 (IAM) — 30% of exam
  • Re-read Domain 2, Section 7 (CloudTrail vs Config) — very common confusion

If you scored 50-70:

  • Focus on Domain 2 deep scenarios (Shared Responsibility edges)
  • Practice distinguishing similar services (Shield vs WAF, GuardDuty vs Inspector)
  • Review multi-account governance (Organizations, SCPs)

If you scored 70+:

  • Review only weak domain (likely Domain 3 or Domain 4)
  • Take another practice exam to build confidence
  • Ready for real exam if consistent 70+ on multiple exams

Total exam time estimate: 90 min (exam) + 45 min (review)
Recommended next: Take 1-2 more full-length practice exams (exams 01-04) before actual exam