CertHub
AWSFoundationalCLF-C02

AWS Certified Cloud Practitioner

Tất cả lời giải

CLF-C02 Mock Exam #07 — Solutions & Explanations

Exam: exam-07.md | Theme: Multi-Response Heavy (20 of 65 questions) For detailed exam questions: See ../MockExams/exam-07.md Bilingual: 🇬🇧 English + 🇻🇳 Tiếng Việt — every question has both blocks.


Answer Summary (Quick Reference)

QTypeAnswerDomainDifficulty
1MCAD1Easy
2MCBD1Easy
3MCBD1Medium
4MCCD1Medium
5MR (3)B, C, DD1Medium
6MCCD1Medium
7MR (2)B, DD1Medium
8MCBD1Medium
9MCBD1Medium
10MCBD1Medium
11MCBD1Easy
12MCBD1Medium
13MR (2)B, CD1Medium
14MCBD1Easy
15MCCD1Medium
16MCCD1Medium
17MCCD2Easy
18MCBD2Medium
19MR (2)B, DD2Medium
20MCBD2Medium
21MCBD2Medium
22MCCD2Medium
23MR (3)A, B, CD2Medium
24MCBD2Easy
25MCBD2Medium
26MCBD2Medium
27MR (3)B, C, ED2Medium
28MCBD2Medium
29MCBD2Medium
30MCBD2Medium
31MR (2)A, CD2Medium
32MCBD2Easy
33MCAD2Medium
34MR (2)B, DD2Medium
35MCBD2Medium
36MCCD2Medium
37MCBD3Easy
38MCBD3Medium
39MCBD3Medium
40MR (3)B, C, ED3Medium
41MCBD3Medium
42MCBD3Medium
43MR (2)B, DD3Medium
44MCBD3Medium
45MCBD3Medium
46MCCD3Easy
47MR (2)A, CD3Medium
48MCBD3Medium
49MCBD3Medium
50MR (3)A, B, DD3Medium
51MCBD3Medium
52MCCD3Medium
53MR (2)A, BD3Medium
54MCBD3Easy
55MCBD3Medium
56MCAD3Medium
57MR (2)B, DD3Medium
58MCBD3Medium
59MR (3)A, C, ED4Easy
60MR (2)C, DD4Easy
61MCBD4Easy
62MR (2)A, DD4Easy
63MR (2)A, DD4Medium
64MR (3)A, B, DD4Easy
65MR (2)A, DD4Medium


DETAILED SOLUTIONS

DOMAIN 1: CLOUD CONCEPTS

Domain Distribution

Q1.

A company is evaluating cloud computing for the first time. According to NIST definition, which of the following is NOT a characteristic of cloud computing?

Bản dịch tiếng Việt: Một công ty đang đánh giá điện toán đám mây lần đầu tiên. Theo định nghĩa của NIST, điều nào sau đây KHÔNG phải là đặc điểm của điện toán đám mây?

A. Users must purchase and maintain physical servers before accessing resources B. Resources are automatically scaled based on demand C. Users pay for only the resources they consume D. Resources can be provisioned on-demand without IT team intervention

Correct answer: A Bản dịch đáp án đúng: A. Người dùng phải mua và bảo trì máy chủ vật lý trước khi truy cập tài nguyên

🇬🇧 Explanation: Cloud computing's On-Demand Self-Service characteristic means users provision resources WITHOUT purchasing physical hardware upfront. Option A ("Users must purchase and maintain physical servers before accessing resources") directly contradicts this definition, so it is NOT a cloud characteristic. The question asks which is NOT a characteristic — cloud eliminates upfront hardware purchase.

🇻🇳 Giải thích: Bạn cần nhớ đặc tính On-Demand Self-Service: người dùng tự cấp phát tài nguyên mà KHÔNG phải mua phần cứng trước. Đáp án A nói "phải mua và bảo trì server vật lý trước khi dùng" — điều này đi ngược hoàn toàn định nghĩa cloud, nên A KHÔNG phải đặc tính cloud. Câu hỏi dạng "Cái nào KHÔNG phải" buộc bạn chọn phát biểu sai.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B (Auto-scale on demand) — IS a NIST characteristic (Rapid Elasticity) / Là đặc tính NIST (Rapid Elasticity)
  • C (Pay-per-use) — IS a NIST characteristic (Measured Service) / Là đặc tính NIST (Measured Service)
  • D (Self-service provisioning) — IS a NIST characteristic (On-Demand Self-Service) / Là đặc tính NIST (On-Demand Self-Service)

🔑 Key Concept / Khái niệm cốt lõi: Cloud eliminates upfront hardware purchase via On-Demand Self-Service. / Cloud loại bỏ việc mua phần cứng trước nhờ On-Demand Self-Service.


Q2.

Which of the following best describes the difference between IaaS and PaaS?

Bản dịch tiếng Việt: Điều nào sau đây mô tả đúng nhất sự khác biệt giữa IaaS và PaaS?

A. IaaS requires the customer to manage the database, while PaaS does not B. IaaS provides virtualized computing resources, while PaaS provides a platform for application development C. IaaS is cheaper than PaaS D. PaaS requires more customer management than IaaS

Correct answer: B Bản dịch đáp án đúng: B. IaaS cung cấp tài nguyên điện toán ảo hóa, trong khi PaaS cung cấp nền tảng để phát triển ứng dụng

🇬🇧 Explanation: IaaS provides virtualized computing resources (EC2, EBS, VPC) where you manage OS, middleware, and runtime. PaaS provides a platform for application development (Elastic Beanstalk, RDS) where AWS manages the infrastructure plus the OS. Responsibility decreases as you move IaaS → PaaS → SaaS.

🇻🇳 Giải thích: IaaS là hạ tầng (EC2, EBS, VPC) — bạn tự quản OS, middleware, runtime. PaaS là nền tảng phát triển ứng dụng (Elastic Beanstalk, RDS) — AWS quản hạ tầng và cả OS. Bạn nhớ quy luật: đi từ IaaS → PaaS → SaaS thì trách nhiệm của khách hàng giảm dần.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — False; PaaS also provides databases (RDS is PaaS) and IaaS doesn't handle DB. / Sai; PaaS cũng cung cấp database (RDS là PaaS), IaaS không lo DB.
  • C — Irrelevant to the difference. / Không liên quan đến sự khác biệt.
  • D — Opposite; IaaS requires MORE customer management (you patch OS). / Ngược lại; IaaS đòi khách hàng quản nhiều hơn (tự patch OS).

🔑 Key Concept / Khái niệm cốt lõi: IaaS > PaaS > SaaS = decreasing customer responsibility. / IaaS > PaaS > SaaS = trách nhiệm khách hàng giảm dần.


Q3.

A startup wants to deploy a web application but does not want to manage servers, databases, or infrastructure. Which service model is most appropriate?

Bản dịch tiếng Việt: Một công ty khởi nghiệp muốn triển khai một ứng dụng web nhưng không muốn quản lý máy chủ, cơ sở dữ liệu hoặc cơ sở hạ tầng. Mô hình dịch vụ nào phù hợp nhất?

A. IaaS B. PaaS C. SaaS D. On-premises

Correct answer: B Bản dịch đáp án đúng: B. PaaS

🇬🇧 Explanation: A startup that wants to deploy a web app with no infrastructure or DB management needs PaaS. Elastic Beanstalk (AWS PaaS) lets you deploy code while AWS manages servers, auto-scaling, and database options. The startup doesn't want the infrastructure burden, so PaaS is the answer.

🇻🇳 Giải thích: Startup muốn triển khai web app mà không phải quản hạ tầng hay database → chọn PaaS. Với Elastic Beanstalk (PaaS của AWS), bạn chỉ cần đẩy code lên, còn AWS lo server, auto-scaling, và tùy chọn database. Vì startup không muốn gánh nặng hạ tầng nên PaaS là đáp án.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (IaaS) — EC2 requires you to manage OS, patching, scaling. / EC2 buộc bạn quản OS, patching, scaling.
  • C (SaaS) — For complete apps (Gmail, Salesforce), not "build your own app". / Dành cho ứng dụng hoàn chỉnh, không phải "tự xây app".
  • D (On-premises) — Contradicts "cloud". / Mâu thuẫn với "cloud".

🔑 Key Concept / Khái niệm cốt lõi: "No infrastructure management" = PaaS; "full control" = IaaS; "just use" = SaaS. / "Không quản hạ tầng" = PaaS; "toàn quyền" = IaaS; "chỉ dùng" = SaaS.


Q4.

Which AWS region selection factor ensures compliance with local data residency regulations in the European Union?

Bản dịch tiếng Việt: Yếu tố lựa chọn khu vực AWS nào đảm bảo tuân thủ các quy định về nơi lưu trữ dữ liệu địa phương trong Liên minh Châu Âu?

A. Cost optimization B. Service availability C. Compliance and data residency requirements D. Latency reduction

Correct answer: C Bản dịch đáp án đúng: C. Yêu cầu về tuân thủ và nơi lưu trữ dữ liệu

🇬🇧 Explanation: GDPR (EU law) requires customer data to stay in EU regions. Region choice is driven by latency, cost, compliance, and service availability — but compliance/data residency is a HARD requirement, not optional. So compliance and data residency is the factor that ensures EU compliance.

🇻🇳 Giải thích: GDPR (luật EU) yêu cầu dữ liệu khách hàng phải nằm trong các region của EU. Việc chọn region phụ thuộc vào độ trễ, chi phí, tuân thủ và mức khả dụng dịch vụ — nhưng yêu cầu tuân thủ/lưu trú dữ liệu là điều kiện BẮT BUỘC, không phải tùy chọn. Vì vậy yếu tố compliance và data residency là câu trả lời.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Cost) — A factor, but compliance outweighs it. / Là một yếu tố, nhưng tuân thủ quan trọng hơn.
  • B (Service availability) — Secondary to compliance. / Phụ so với tuân thủ.
  • D (Latency) — Matters for performance, not compliance. / Ảnh hưởng hiệu năng, không phải tuân thủ.

🔑 Key Concept / Khái niệm cốt lõi: When compliance/regulation is mentioned, region selection is driven by data residency. / Khi đề nhắc compliance/quy định, việc chọn region do data residency quyết định.


Q5.

A company wants to understand the six advantages of cloud computing. Which of the following are among AWS's six key advantages? (Select THREE)

Bản dịch tiếng Việt: Một công ty muốn hiểu sáu ưu điểm của điện toán đám mây. Điều nào sau đây nằm trong số sáu lợi thế chính của AWS? (Chọn BA)

A. Eliminates the need for all IT staff in an organization B. Allows companies to trade capital expenses for operational expenses C. Enables businesses to stop spending money on running and maintaining data centers D. Eliminates the need to estimate capacity requirements E. Provides unlimited geographic presence in all world countries

Correct answer: B, C, D Bản dịch đáp án đúng: B. Cho phép các công ty chuyển đổi chi phí vốn lấy chi phí hoạt động; C. Cho phép doanh nghiệp ngừng chi tiền cho việc vận hành và bảo trì trung tâm dữ liệu; D. Loại bỏ sự cần thiết phải ước tính yêu cầu năng lực

🇬🇧 Explanation: Three of AWS's six advantages appear here. B ("trade capital expenses for operational expenses") is Advantage #1 (CapEx → OpEx) — you pay monthly instead of buying servers upfront. C ("stop spending money on running and maintaining data centers") is Advantage #5 — AWS handles the physical facility, cooling, power, networking. D ("eliminates the need to estimate capacity requirements") is Advantage #3 (stop guessing capacity) — scale up/down on demand instead of over- or under-provisioning.

🇻🇳 Giải thích: Có ba trong sáu lợi thế của AWS xuất hiện ở đây. B ("đổi chi phí vốn lấy chi phí vận hành") là Lợi thế #1 (CapEx → OpEx) — bạn trả hằng tháng thay vì mua server trước. C ("thôi tốn tiền chạy và bảo trì data center") là Lợi thế #5 — AWS lo cơ sở vật lý, làm mát, điện, mạng. D ("không cần ước lượng nhu cầu công suất") là Lợi thế #3 (thôi đoán công suất) — co giãn theo nhu cầu thay vì cấp dư hoặc thiếu.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Eliminates all IT staff) — Cloud still needs IT staff (DevOps, security, architecture); only data center ops staff is reduced. / Cloud vẫn cần nhân sự IT (DevOps, bảo mật, kiến trúc); chỉ giảm nhân sự vận hành data center.
  • E (Unlimited geographic presence in all countries) — AWS has ~30+ regions + 600+ edge locations but not everywhere; some countries are restricted. / AWS có ~30+ region + 600+ edge location nhưng không phải khắp nơi; một số nước bị hạn chế.

🔑 Key Concept / Khái niệm cốt lõi: The 6 advantages: CapEx→OpEx, economies of scale, stop guessing capacity, speed & agility, stop maintaining data centers, go global in minutes. / 6 lợi thế: CapEx→OpEx, lợi thế quy mô, thôi đoán công suất, tốc độ & linh hoạt, thôi bảo trì data center, vươn ra toàn cầu trong vài phút.

📚 Reference: Domain 1, sections 2.1 / 2.5 / 2.3


Q6.

A financial services company is implementing a hybrid cloud strategy. It will keep sensitive customer data on-premises while using AWS for non-sensitive workloads. Which deployment model describes this approach?

Bản dịch tiếng Việt: Một công ty dịch vụ tài chính đang triển khai chiến lược đám mây lai. Nó sẽ lưu giữ dữ liệu nhạy cảm của khách hàng tại chỗ trong khi sử dụng AWS cho khối lượng công việc không nhạy cảm. Mô hình triển khai nào mô tả cách tiếp cận này?

A. Public Cloud B. Private Cloud C. Hybrid Cloud D. Multi-Cloud

Correct answer: C Bản dịch đáp án đúng: C. Đám mây lai

🇬🇧 Explanation: Keeping sensitive data on-premises while putting non-sensitive data on AWS is the Hybrid Cloud model — a mix of on-premises (private) and cloud (public). Sensitive data stays on-prem for compliance, non-sensitive goes to cloud for scalability.

🇻🇳 Giải thích: Giữ dữ liệu nhạy cảm tại on-premises trong khi đưa dữ liệu không nhạy cảm lên AWS chính là mô hình Hybrid Cloud — kết hợp on-premises (private) và cloud (public). Dữ liệu nhạy cảm ở on-prem để tuân thủ, dữ liệu không nhạy cảm lên cloud để mở rộng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Public) — All in AWS, no on-prem. / Toàn bộ trên AWS, không có on-prem.
  • B (Private) — All on-prem, no cloud. / Toàn bộ on-prem, không có cloud.
  • D (Multi) — Multiple cloud providers (AWS + Azure), not on-prem + cloud. / Nhiều nhà cung cấp cloud, không phải on-prem + cloud.

🔑 Key Concept / Khái niệm cốt lõi: "On-prem AND cloud" = Hybrid. / "On-prem VÀ cloud" = Hybrid.


Q7.

Which of the following represent part of the AWS Well-Architected Framework's six pillars? (Select TWO)

Bản dịch tiếng Việt: Điều nào sau đây đại diện cho một phần trong sáu trụ cột của AWS Well-Architected Framework? (Chọn HAI)

A. Scalability Pillar B. Reliability Pillar C. Elasticity Pillar D. Security Pillar E. Cost Tracking Pillar

Correct answer: B, D Bản dịch đáp án đúng: B. Trụ cột độ tin cậy; D. Trụ cột an ninh

🇬🇧 Explanation: B (Reliability) and D (Security) are two of the 6 official Well-Architected pillars. Reliability focuses on auto-recovery, multi-AZ, and health checks; Security focuses on least privilege, encryption, and threat detection.

🇻🇳 Giải thích: B (Reliability) và D (Security) là hai trong 6 pillar chính thức của Well-Architected Framework. Reliability tập trung vào tự phục hồi, multi-AZ, health check; Security tập trung vào least privilege, mã hóa, và phát hiện mối đe dọa.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Scalability Pillar) — Scalability is a design principle, not a pillar (part of Reliability). / Scalability là nguyên tắc thiết kế, không phải pillar (nằm trong Reliability).
  • C (Elasticity Pillar) — Elasticity is a cloud trait, not a pillar (part of Performance Efficiency & Cost Optimization). / Elasticity là đặc tính cloud, không phải pillar.
  • E (Cost Tracking Pillar) — The pillar is "Cost Optimization," not "Cost Tracking". / Pillar đúng là "Cost Optimization".

🔑 Key Concept / Khái niệm cốt lõi: 6 Pillars: Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, Sustainability. / 6 Pillar: Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, Sustainability.


Q8.

A company is executing a cloud migration strategy. It has identified that a legacy application is no longer being used by the business and cannot be justified for cloud investment. Which 7 Rs migration strategy applies?

Bản dịch tiếng Việt: Một công ty đang thực hiện chiến lược di chuyển sang đám mây. Nó đã xác định rằng một ứng dụng cũ không còn được doanh nghiệp sử dụng nữa và không thể biện minh cho việc đầu tư vào đám mây. Chiến lược di chuyển 7 Rs nào được áp dụng?

A. Rehost B. Retire C. Retain D. Refactor

Correct answer: B Bản dịch đáp án đúng: B. Về hưu

🇬🇧 Explanation: A legacy app that is no longer used should be Retired — stop using it, no migration needed. With no business value there's no point moving it to cloud, and retiring saves the cost of maintaining it.

🇻🇳 Giải thích: Một ứng dụng cũ không còn dùng nữa thì nên Retire — ngừng dùng, không cần di chuyển. Vì không còn giá trị kinh doanh nên chẳng cần đưa lên cloud, và việc retire giúp tiết kiệm chi phí bảo trì.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Rehost) — "Lift-and-shift" for apps that still have value. / "Lift-and-shift" cho app vẫn còn giá trị.
  • C (Retain) — Keep running on-prem; still has some value. / Giữ chạy on-prem; vẫn còn chút giá trị.
  • D (Refactor) — Full rewrite, requires investment. / Viết lại toàn bộ, tốn đầu tư.

🔑 Key Concept / Khái niệm cốt lõi: 7 R's — Retire, Retain, Relocate, Rehost, Repurchase, Replatform, Refactor; "no value" = Retire. / 7 R's; "không còn giá trị" = Retire.


Q9.

Which AWS global infrastructure component provides the lowest latency for content delivery and DNS query resolution to end users?

Bản dịch tiếng Việt: Thành phần cơ sở hạ tầng toàn cầu nào của AWS cung cấp độ trễ thấp nhất cho việc phân phối nội dung và phân giải truy vấn DNS cho người dùng cuối?

A. Availability Zones B. Edge Locations C. AWS Regions D. Local Zones

Correct answer: B Bản dịch đáp án đúng: B. Vị trí cạnh

🇬🇧 Explanation: Edge Locations (600+ globally) provide the lowest latency for content delivery. CloudFront (CDN) uses them to cache content near users — a user in Vietnam downloading from S3 US can be served via a Vietnam edge location (~20ms instead of ~200ms).

🇻🇳 Giải thích: Edge Location (hơn 600 điểm trên toàn cầu) cho độ trễ thấp nhất khi phân phối nội dung. CloudFront (CDN) dùng chúng để cache nội dung gần người dùng — người dùng ở Việt Nam tải từ S3 ở Mỹ có thể được phục vụ qua edge location tại Việt Nam (~20ms thay vì ~200ms).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (AZs) — ~100+ AZs, isolated data centers, not for CDN. / ~100+ AZ, data center độc lập, không dùng làm CDN.
  • C (Regions) — ~30+ regions, too few for lowest latency everywhere. / ~30+ region, quá ít để cho độ trễ thấp khắp nơi.
  • D (Local Zones) — Ultra-low latency but only in specific cities, not global. / Độ trễ cực thấp nhưng chỉ ở một số thành phố, không toàn cầu.

🔑 Key Concept / Khái niệm cốt lõi: Hierarchy by count: Edge Locations (600+) > AZs (~100+) > Regions (~30+). / Thứ tự theo số lượng: Edge Locations (600+) > AZ (~100+) > Region (~30+).


Q10.

A company requires that its application remain available even if a single data center fails. Which architectural approach best meets this requirement?

Bản dịch tiếng Việt: Một công ty yêu cầu ứng dụng của họ vẫn khả dụng ngay cả khi một trung tâm dữ liệu bị lỗi. Phương pháp kiến ​​trúc nào đáp ứng tốt nhất yêu cầu này?

A. Deploy the application to a single Availability Zone B. Deploy the application to multiple Availability Zones within the same region C. Deploy the application to a single region only D. Deploy the application on-premises

Correct answer: B Bản dịch đáp án đúng: B. Triển khai ứng dụng tới nhiều Availability Zone trong cùng một khu vực

🇬🇧 Explanation: To survive a data center failure, deploy to multiple AZs in the same region. Each AZ is a separate data center; if one AZ goes down, the others keep the app running. Same-region keeps latency low (~10ms between AZs) and achieves 99.99% availability.

🇻🇳 Giải thích: Để sống sót khi một data center hỏng, hãy triển khai trên nhiều AZ trong cùng một region. Mỗi AZ là một data center riêng; nếu một AZ sập, các AZ còn lại vẫn giữ app chạy. Cùng region giúp độ trễ thấp (~10ms giữa các AZ) và đạt mức khả dụng 99.99%.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Single AZ) — Vulnerable to AZ failure. / Dễ tổn thương khi AZ hỏng.
  • C (Single region) — Helps with AZ, not region-level disasters. / Giúp cấp AZ, không xử lý thảm họa cấp region.
  • D (On-prem) — Not cloud-based. / Không phải trên cloud.

🔑 Key Concept / Khái niệm cốt lõi: HA = Multi-AZ same region; DR = multi-region. / HA = Multi-AZ cùng region; DR = nhiều region.


Q11.

Which of the following best describes the relationship between capital expenditures (CapEx) and operational expenditures (OpEx) in cloud computing?

Bản dịch tiếng Việt: Điều nào sau đây mô tả đúng nhất mối quan hệ giữa chi tiêu vốn (CapEx) và chi phí hoạt động (OpEx) trong điện toán đám mây?

A. Cloud computing increases both CapEx and OpEx B. Cloud computing allows companies to trade CapEx for OpEx C. Cloud computing eliminates the need for OpEx D. Cloud computing increases CapEx while reducing OpEx

Correct answer: B Bản dịch đáp án đúng: B. Điện toán đám mây cho phép các công ty giao dịch CapEx lấy OpEx

🇬🇧 Explanation: Cloud lets companies trade CapEx for OpEx. CapEx (capital expenditure) means buying servers upfront ($50K+); OpEx (operational expenditure) means a monthly subscription ($100/month). Cloud requires no upfront investment and is pay-per-use — an OpEx model.

🇻🇳 Giải thích: Cloud cho phép công ty đổi CapEx lấy OpEx. CapEx (chi phí vốn) là mua server trước (hàng chục nghìn USD); OpEx (chi phí vận hành) là thuê bao hằng tháng ($100/tháng). Cloud không cần đầu tư trước và trả theo mức dùng — đúng mô hình OpEx.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Cloud reduces CapEx and increases OpEx (a good trade). / Cloud giảm CapEx, tăng OpEx (đánh đổi có lợi).
  • C — OpEx is still needed (you pay bills). / Vẫn cần OpEx (bạn trả hóa đơn).
  • D — Cloud increases OpEx and reduces CapEx, not "increases both". / Cloud tăng OpEx, giảm CapEx, không phải "tăng cả hai".

🔑 Key Concept / Khái niệm cốt lõi: "Trade CapEx for OpEx" = fundamental cloud value proposition. / "Đổi CapEx lấy OpEx" = giá trị cốt lõi của cloud.


Q12.

An organization is choosing between multiple AWS regions. Latency to end users is a critical requirement. Which factor should be prioritized?

Bản dịch tiếng Việt: Một tổ chức đang lựa chọn giữa nhiều khu vực AWS. Độ trễ đối với người dùng cuối là một yêu cầu quan trọng. Yếu tố nào cần được ưu tiên?

A. Cost of the region B. Physical proximity of the region to users C. Number of services available in that region D. The region's compliance certifications

Correct answer: B Bản dịch đáp án đúng: B. Khoảng cách vật lý của khu vực với người dùng

🇬🇧 Explanation: When latency is critical, prioritize physical proximity of the region to users. Latency is governed by distance and the speed of light, so a closer region means lower latency — Vietnam users on ap-southeast-1 (Singapore) get ~50ms vs ~200ms on us-east-1 (Virginia).

🇻🇳 Giải thích: Khi độ trễ là yếu tố then chốt, hãy ưu tiên khoảng cách vật lý của region tới người dùng. Độ trễ phụ thuộc khoảng cách và tốc độ ánh sáng, nên region càng gần thì độ trễ càng thấp — người dùng Việt Nam dùng ap-southeast-1 (Singapore) chỉ ~50ms so với ~200ms khi dùng us-east-1 (Virginia).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Cost) — Secondary to the latency requirement. / Phụ so với yêu cầu độ trễ.
  • C (Service availability) — Secondary. / Phụ.
  • D (Compliance) — Secondary if not mentioned. / Phụ nếu đề không nhắc.

🔑 Key Concept / Khái niệm cốt lõi: 4 region factors: latency, compliance, cost, service availability — latency-critical means proximity. / 4 yếu tố chọn region: độ trễ, tuân thủ, chi phí, khả dụng dịch vụ — yêu cầu độ trễ thì chọn theo khoảng cách.


Q13.

Which of the following are components of the AWS Cloud Adoption Framework (CAF)? (Select TWO)

Bản dịch tiếng Việt: Thành phần nào sau đây là thành phần của Khung áp dụng đám mây AWS (CAF)? (Chọn HAI)

A. Infrastructure Perspective B. Business Perspective C. Platform Perspective D. Sustainability Perspective E. Container Perspective

Correct answer: B, C Bản dịch đáp án đúng: B. Quan điểm kinh doanh; C. Phối cảnh nền tảng

🇬🇧 Explanation: B (Business Perspective) and C (Platform Perspective) are two of the 6 official Cloud Adoption Framework perspectives. Business focuses on ROI, cost savings, revenue growth (CEO, CFO, PMO); Platform focuses on architecture, tech choices, infrastructure (solutions architects, IT ops).

🇻🇳 Giải thích: B (Business Perspective) và C (Platform Perspective) là hai trong 6 perspective chính thức của Cloud Adoption Framework. Business tập trung vào ROI, tiết kiệm chi phí, tăng doanh thu (CEO, CFO, PMO); Platform tập trung vào kiến trúc, lựa chọn công nghệ, hạ tầng (solutions architect, IT ops).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Infrastructure Perspective) — The perspective is "Platform," not "Infrastructure". / Perspective đúng là "Platform".
  • D (Sustainability Perspective) — Sustainability is a Well-Architected pillar, not a CAF perspective. / Sustainability là pillar của Well-Architected, không phải perspective CAF.
  • E (Container Perspective) — Not part of CAF. / Không thuộc CAF.

🔑 Key Concept / Khái niệm cốt lõi: 6 CAF Perspectives: Business, Governance, Platform, People, Security, Operations. / 6 perspective CAF: Business, Governance, Platform, People, Security, Operations.

📚 Reference: Domain 1, sections 5.1 / 5.4


Q14.

What does the term "elasticity" mean in the context of cloud computing?

Bản dịch tiếng Việt: Thuật ngữ "độ co giãn" có nghĩa là gì trong bối cảnh điện toán đám mây?

A. The ability to purchase reserved capacity B. The ability to increase or decrease resources automatically based on demand C. The ability to move workloads between regions D. The ability to set fixed costs for infrastructure

Correct answer: B Bản dịch đáp án đúng: B. Khả năng tăng hoặc giảm tài nguyên tự động dựa trên nhu cầu

🇬🇧 Explanation: Elasticity is the ability to increase or decrease resources automatically based on demand. When demand rises, AWS auto-adds EC2 instances; when it drops, AWS auto-removes them — so you pay only for what you use.

🇻🇳 Giải thích: Elasticity là khả năng tự động tăng hoặc giảm tài nguyên theo nhu cầu. Khi nhu cầu tăng, AWS tự thêm EC2 instance; khi nhu cầu giảm, AWS tự bớt đi — nhờ vậy bạn chỉ trả cho phần thực dùng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Purchased reserved capacity) — That's Reserved Instances, not elasticity. / Đó là Reserved Instances, không phải elasticity.
  • C (Move between regions) — That's migration. / Đó là di chuyển (migration).
  • D (Fixed costs) — Opposite of elasticity. / Ngược với elasticity.

🔑 Key Concept / Khái niệm cốt lõi: Scalability = can scale up; Elasticity = auto scale up/down (includes shrinking). / Scalability = mở rộng được; Elasticity = tự co giãn (gồm cả thu nhỏ).


Q15.

A company performs batch processing jobs only during the last weekend of every month. Which pricing approach would be most cost-effective?

Bản dịch tiếng Việt: Một công ty chỉ thực hiện các công việc xử lý hàng loạt vào cuối tuần cuối cùng hàng tháng. Phương pháp định giá nào sẽ hiệu quả nhất về mặt chi phí?

A. Reserved Instances for 1 year B. On-Demand pricing C. Spot Instances D. Dedicated Hosts

Correct answer: C Bản dịch đáp án đúng: C. Phiên bản Spot

🇬🇧 Explanation: Batch jobs that run only the last weekend of each month are fault-tolerant and intermittent, so Spot Instances are most cost-effective — up to 90% cheaper than On-Demand. AWS can terminate Spot instances, but a batch job can simply restart, so the deep discount applies perfectly.

🇻🇳 Giải thích: Các tác vụ batch chỉ chạy vào cuối tuần cuối mỗi tháng vốn chịu lỗi tốt (fault-tolerant) và chạy ngắt quãng, nên Spot Instances là tiết kiệm nhất — rẻ tới 90% so với On-Demand. AWS có thể thu hồi Spot, nhưng job batch chỉ cần chạy lại, nên mức giảm sâu này rất phù hợp.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Reserved 1yr) — Commit 1 year but only used 4 days/month = wasteful. / Cam kết 1 năm nhưng chỉ dùng 4 ngày/tháng = lãng phí.
  • B (On-Demand) — No discount, expensive. / Không giảm giá, đắt.
  • D (Dedicated) — Most expensive, unnecessary for batch. / Đắt nhất, không cần cho batch.

🔑 Key Concept / Khái niệm cốt lõi: Batch + fault-tolerant + intermittent = Spot. / Batch + chịu lỗi + ngắt quãng = Spot.


Q16.

Which Well-Architected Framework pillar focuses on minimizing environmental impact and using renewable energy?

Bản dịch tiếng Việt: Trụ cột AWS Well-Architected Framework nào tập trung vào việc giảm thiểu tác động đến môi trường và sử dụng năng lượng tái tạo?

A. Operational Excellence B. Security C. Sustainability D. Cost Optimization

Correct answer: C Bản dịch đáp án đúng: C. Tính bền vững

🇬🇧 Explanation: The Sustainability pillar minimizes environmental impact. Its design principles include choosing renewable-energy regions, minimizing idle resources, and using managed services to reduce footprint.

🇻🇳 Giải thích: Pillar Sustainability nhằm giảm thiểu tác động môi trường. Các nguyên tắc thiết kế gồm chọn region dùng năng lượng tái tạo, giảm tài nguyên nhàn rỗi, và dùng managed service để giảm dấu chân môi trường.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Operational Excellence) — Automation, efficiency, not environmental focus. / Tự động hóa, hiệu quả, không tập trung môi trường.
  • B (Security) — Data protection, not environmental. / Bảo vệ dữ liệu, không phải môi trường.
  • D (Cost Optimization) — Money savings, not environmental. / Tiết kiệm tiền, không phải môi trường.

🔑 Key Concept / Khái niệm cốt lõi: Sustainability pillar = reduce environmental footprint. / Pillar Sustainability = giảm dấu chân môi trường.

📚 Reference: Domain 1, section 4.6


Domain Distribution

Q17.

According to the AWS Shared Responsibility Model, which of the following is AWS's responsibility (Security OF the Cloud)?

Bản dịch tiếng Việt: Theo Mô hình trách nhiệm chung của AWS, trách nhiệm nào sau đây là trách nhiệm của AWS (Bảo mật của đám mây)?

A. Managing IAM user accounts and permissions B. Patching the operating system on EC2 instances C. Providing physical security for AWS data centers D. Configuring security group rules

Correct answer: C Bản dịch đáp án đúng: C. Cung cấp bảo mật vật lý cho trung tâm dữ liệu AWS

🇬🇧 Explanation: "Security OF the Cloud" is AWS's responsibility — providing physical security for AWS data centers (facilities, guards, cameras, fire suppression). This is the infrastructure layer customers never touch.

🇻🇳 Giải thích: "Security OF the Cloud" là trách nhiệm của AWS — bảo đảm an ninh vật lý cho data center của AWS (cơ sở, bảo vệ, camera, hệ thống chữa cháy). Đây là lớp hạ tầng mà khách hàng không bao giờ chạm tới.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (IAM users) — Customer responsibility (Security IN the Cloud). / Trách nhiệm khách hàng (Security IN the Cloud).
  • B (OS patching on EC2) — Customer responsibility. / Trách nhiệm khách hàng.
  • D (Security group rules) — Customer responsibility (firewall config). / Trách nhiệm khách hàng (cấu hình firewall).

🔑 Key Concept / Khái niệm cốt lõi: AWS = facilities, hardware, hypervisor, network; Customer = data, IAM, OS patches, app, encryption, firewall. / AWS = cơ sở, phần cứng, hypervisor, mạng; Khách hàng = dữ liệu, IAM, vá OS, ứng dụng, mã hóa, firewall.

📚 Reference: Domain 2, section 1.2


Q18.

A company deploys a MySQL database using AWS RDS. Who is responsible for patching the database engine?

Bản dịch tiếng Việt: Một công ty triển khai cơ sở dữ liệu MySQL bằng AWS RDS. Ai chịu trách nhiệm vá công cụ cơ sở dữ liệu?

A. The customer must patch the RDS database engine B. AWS automatically patches the RDS database engine C. Both AWS and the customer share patching responsibility D. The database vendor (Oracle MySQL) patches directly

Correct answer: B Bản dịch đáp án đúng: B. AWS tự động vá công cụ cơ sở dữ liệu RDS

🇬🇧 Explanation: RDS is a managed database service, so AWS automatically patches the RDS database engine (unlike EC2 where the customer patches the OS). AWS applies patches during customer-selectable maintenance windows.

🇻🇳 Giải thích: RDS là dịch vụ database được quản lý, nên AWS tự động vá database engine của RDS (khác với EC2 nơi khách hàng tự vá OS). AWS áp dụng bản vá trong các maintenance window mà khách hàng có thể chọn.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Customer does not patch the RDS engine (that's AWS's job). / Khách hàng không vá engine RDS (đó là việc của AWS).
  • C — Not shared; AWS owns engine patching. / Không phải chia sẻ; AWS lo việc vá engine.
  • D — The Oracle/MySQL vendor doesn't patch AWS RDS directly; AWS does. / Nhà cung cấp Oracle/MySQL không vá RDS trực tiếp; AWS làm.

🔑 Key Concept / Khái niệm cốt lõi: EC2 → customer patches OS; RDS → AWS patches engine; Lambda → AWS patches everything. / EC2 → khách vá OS; RDS → AWS vá engine; Lambda → AWS vá tất cả.

📚 Reference: Domain 2, section 1.5


Q19.

Which of the following are customer responsibilities under the Shared Responsibility Model? (Select TWO)

Bản dịch tiếng Việt: Đâu là trách nhiệm của khách hàng trong Mô hình trách nhiệm chung? (Chọn HAI)

A. Patching the hypervisor B. Configuring Security Group rules for EC2 instances C. Maintaining physical data center infrastructure D. Encrypting data at rest using KMS E. Upgrading the AWS API layer

Correct answer: B, D Bản dịch đáp án đúng: B. Định cấu hình quy tắc Nhóm bảo mật cho phiên bản EC2; D. Mã hóa dữ liệu ở phần còn lại bằng KMS

🇬🇧 Explanation: B and D are "Security IN the Cloud" customer responsibilities. B ("Configuring Security Group rules for EC2 instances") — Security Groups are the instance-level firewall and the customer decides which ports/IPs are allowed. D ("Encrypting data at rest using KMS") — AWS provides KMS, but the customer decides to enable encryption.

🇻🇳 Giải thích: B và D là trách nhiệm "Security IN the Cloud" của khách hàng. B ("cấu hình rule Security Group cho EC2") — Security Group là firewall cấp instance và khách hàng quyết định cổng/IP nào được phép. D ("mã hóa dữ liệu at rest bằng KMS") — AWS cung cấp KMS, nhưng khách hàng quyết định bật mã hóa.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Patching the hypervisor) — AWS responsibility (infrastructure). / Trách nhiệm AWS (hạ tầng).
  • C (Maintaining physical data center) — AWS responsibility (facilities). / Trách nhiệm AWS (cơ sở vật chất).
  • E (Upgrading the AWS API layer) — AWS responsibility (service layer). / Trách nhiệm AWS (lớp dịch vụ).

🔑 Key Concept / Khái niệm cốt lõi: Customer controls config (Security Groups, encryption); AWS controls infrastructure. / Khách hàng quản cấu hình (Security Group, mã hóa); AWS quản hạ tầng.

📚 Reference: Domain 2, section 1.3


Q20.

What is the primary purpose of AWS CloudTrail?

Bản dịch tiếng Việt: Mục đích chính của AWS CloudTrail là gì?

A. Encrypt data in transit B. Log all API calls and actions taken in an AWS account C. Monitor real-time application performance metrics D. Automatically scale resources based on demand

Correct answer: B Bản dịch đáp án đúng: B. Ghi lại tất cả các lệnh gọi và hành động API được thực hiện trong tài khoản AWS

🇬🇧 Explanation: CloudTrail's primary purpose is to log all API calls and actions taken in an AWS account — the "who did what when" audit log across Console, CLI, SDK, and services. It's used for forensics, compliance, and security investigation.

🇻🇳 Giải thích: Mục đích chính của CloudTrail là ghi lại mọi API call và hành động trong tài khoản AWS — nhật ký kiểm toán "ai làm gì khi nào" qua Console, CLI, SDK và các dịch vụ. Nó dùng cho điều tra pháp lý, tuân thủ và điều tra bảo mật.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Encrypt data) — That's KMS. / Đó là KMS.
  • C (Monitor performance metrics) — That's CloudWatch. / Đó là CloudWatch.
  • D (Auto-scale) — That's Auto Scaling. / Đó là Auto Scaling.

🔑 Key Concept / Khái niệm cốt lõi: CloudTrail = API audit (WHO did WHAT); CloudWatch = metrics; AWS Config = config changes. / CloudTrail = kiểm toán API (AI làm GÌ); CloudWatch = metrics; AWS Config = thay đổi cấu hình.


Q21.

A company needs to monitor changes to resource configurations over time for compliance purposes. Which AWS service is best suited?

Bản dịch tiếng Việt: Một công ty cần giám sát các thay đổi đối với cấu hình tài nguyên theo thời gian nhằm mục đích tuân thủ. Dịch vụ AWS nào phù hợp nhất?

A. CloudWatch B. AWS Config C. CloudTrail D. Amazon Inspector

Correct answer: B Bản dịch đáp án đúng: B. Cấu hình AWS

🇬🇧 Explanation: AWS Config tracks resource configuration changes over time, detects drift (unexpected config changes), and checks compliance rules (e.g., "S3 bucket must have versioning enabled"). It's used for compliance audits.

🇻🇳 Giải thích: AWS Config theo dõi thay đổi cấu hình tài nguyên theo thời gian, phát hiện drift (cấu hình bị đổi ngoài ý muốn), và kiểm tra rule tuân thủ (ví dụ "S3 bucket phải bật versioning"). Nó dùng cho kiểm toán tuân thủ.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (CloudWatch) — Metrics/alarms, not config changes. / Metrics/alarm, không phải thay đổi cấu hình.
  • C (CloudTrail) — API audit logs, not config state. / Nhật ký API, không phải trạng thái cấu hình.
  • D (Inspector) — Vulnerability assessment on EC2/Lambda. / Đánh giá lỗ hổng trên EC2/Lambda.

🔑 Key Concept / Khái niệm cốt lõi: AWS Config = track and audit resource configuration changes. / AWS Config = theo dõi và kiểm toán thay đổi cấu hình tài nguyên.


Q22.

Which IAM best practice helps prevent accidental misconfiguration and unauthorized access?

Bản dịch tiếng Việt: Phương pháp hay nhất nào của IAM giúp ngăn chặn việc vô tình cấu hình sai và truy cập trái phép?

A. Use the root account for all daily operations B. Enable MFA only for critical staff C. Apply the principle of least privilege when assigning permissions D. Share IAM access keys with trusted colleagues

Correct answer: C Bản dịch đáp án đúng: C. Áp dụng nguyên tắc đặc quyền tối thiểu khi phân quyền

🇬🇧 Explanation: Applying the principle of least privilege — granting only the permissions needed to do a job — best prevents misconfiguration and unauthorized access. For example, an EC2 role should access only bucket X, not all buckets, minimizing the blast radius if credentials are stolen.

🇻🇳 Giải thích: Áp dụng nguyên tắc least privilege — chỉ cấp đúng quyền cần để làm việc — là cách tốt nhất ngăn cấu hình sai và truy cập trái phép. Ví dụ, một EC2 role chỉ nên truy cập bucket X, không phải mọi bucket, để giảm phạm vi thiệt hại nếu credential bị lộ.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Use root account) — Never use root for daily tasks. / Không bao giờ dùng root cho việc hằng ngày.
  • B (MFA only for critical) — MFA should always be on, especially root. / MFA nên luôn bật, nhất là root.
  • D (Share keys) — Never share access keys. / Không bao giờ chia sẻ access key.

🔑 Key Concept / Khái niệm cốt lõi: Least privilege = grant only the minimum permissions needed. / Least privilege = chỉ cấp quyền tối thiểu cần thiết.

📚 Reference: Domain 2, section 1.3


Q23.

Which of the following are services that provide DDoS protection or threat detection in AWS? (Select THREE)

Bản dịch tiếng Việt: Dịch vụ nào sau đây cung cấp khả năng bảo vệ DDoS hoặc phát hiện mối đe dọa trong AWS? (Chọn BA)

A. AWS Shield B. AWS WAF C. Amazon GuardDuty D. AWS IAM E. AWS Backup F. Amazon Polly

Correct answer: A, B, C Bản dịch đáp án đúng: A. Khiên AWS; B. AWS WAF; C. Nhiệm vụ bảo vệ của Amazon

🇬🇧 Explanation: A (AWS Shield) is the DDoS protection service — Standard is free/basic, Advanced is paid. B (AWS WAF) is a Web Application Firewall protecting against SQL injection, XSS, and layer-7 attacks. C (Amazon GuardDuty) is ML-based threat detection analyzing CloudTrail and VPC Flow Logs to spot unusual API activity and compromised instances.

🇻🇳 Giải thích: A (AWS Shield) là dịch vụ chống DDoS — Standard miễn phí/cơ bản, Advanced trả phí. B (AWS WAF) là Web Application Firewall chống SQL injection, XSS và các tấn công lớp 7. C (Amazon GuardDuty) là phát hiện mối đe dọa dựa trên ML, phân tích CloudTrail và VPC Flow Logs để nhận diện hoạt động API bất thường và instance bị xâm nhập.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • D (AWS IAM) — Identity & access management, not threat detection. / Quản lý danh tính & truy cập, không phải phát hiện mối đe dọa.
  • E (AWS Backup) — Backup/restore service, not security/threat detection. / Dịch vụ sao lưu/khôi phục, không phải bảo mật/phát hiện đe dọa.
  • F (Amazon Polly) — Text-to-speech service, unrelated to security. / Dịch vụ chuyển văn bản thành giọng nói, không liên quan bảo mật.

🔑 Key Concept / Khái niệm cốt lõi: Shield (DDoS L3-4), WAF (L7 web attacks), GuardDuty (threat detection). / Shield (DDoS L3-4), WAF (tấn công web L7), GuardDuty (phát hiện đe dọa).


Q24.

What is AWS Shield Standard?

Bản dịch tiếng Việt: Tiêu chuẩn lá chắn AWS là gì?

A. A premium DDoS protection service that requires additional cost B. A free, automatic DDoS protection service for all AWS customers C. A manual service that requires customer configuration D. A service for monitoring application logs

Correct answer: B Bản dịch đáp án đúng: B. Dịch vụ bảo vệ DDoS tự động, miễn phí dành cho tất cả khách hàng AWS

🇬🇧 Explanation: AWS Shield Standard is a free, automatic DDoS protection service for all AWS customers. Every account gets it with no cost and no setup, providing layer 3-4 DDoS protection.

🇻🇳 Giải thích: AWS Shield Standard là dịch vụ chống DDoS miễn phí, tự động cho mọi khách hàng AWS. Mọi tài khoản đều có, không tốn phí, không cần thiết lập, cung cấp bảo vệ DDoS lớp 3-4.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Premium/paid) — Shield Standard is free; Advanced is paid. / Shield Standard miễn phí; Advanced trả phí.
  • C (Manual config) — It's automatic, no config needed. / Tự động, không cần cấu hình.
  • D (Monitoring logs) — That's CloudWatch. / Đó là CloudWatch.

🔑 Key Concept / Khái niệm cốt lõi: Shield Standard = free, automatic, L3-4; Advanced = paid, 24/7 support, L7 + WAF. / Shield Standard = miễn phí, tự động, L3-4; Advanced = trả phí, hỗ trợ 24/7, L7 + WAF.


Q25.

A web application needs protection against SQL injection and cross-site scripting (XSS) attacks. Which AWS service is most appropriate?

Bản dịch tiếng Việt: Một ứng dụng web cần được bảo vệ chống lại các cuộc tấn công SQL injection và tấn công tập lệnh chéo trang (XSS). Dịch vụ AWS nào phù hợp nhất?

A. AWS Shield B. AWS WAF C. Amazon GuardDuty D. AWS Config

Correct answer: B Bản dịch đáp án đúng: B. AWS WAF

🇬🇧 Explanation: AWS WAF (Web Application Firewall) operates at layer 7 and blocks malicious patterns like SQL injection, XSS, and CSRF. It attaches to ALB, API Gateway, or CloudFront.

🇻🇳 Giải thích: AWS WAF (Web Application Firewall) hoạt động ở lớp 7 và chặn các mẫu độc hại như SQL injection, XSS, CSRF. Nó gắn vào ALB, API Gateway, hoặc CloudFront.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Shield) — Layer 3-4, not application-layer attacks. / Lớp 3-4, không phải tấn công lớp ứng dụng.
  • C (GuardDuty) — Threat detection, not application filtering. / Phát hiện đe dọa, không lọc ứng dụng.
  • D (Config) — Configuration tracking, not security filtering. / Theo dõi cấu hình, không lọc bảo mật.

🔑 Key Concept / Khái niệm cốt lõi: Shield = L3-4 DDoS; WAF = L7 web attacks (SQLi, XSS). / Shield = DDoS L3-4; WAF = tấn công web L7 (SQLi, XSS).


Q26.

What is the primary use case for AWS Key Management Service (KMS)?

Bản dịch tiếng Việt: Trường hợp sử dụng chính của Dịch vụ quản lý khóa AWS (KMS) là gì?

A. Manage user access and permissions B. Create and manage encryption keys C. Monitor application performance D. Detect malware in S3 buckets

Correct answer: B Bản dịch đáp án đúng: B. Tạo và quản lý khóa mã hóa

🇬🇧 Explanation: KMS (Key Management Service) is used to create and manage encryption keys. You create, rotate, and manage keys for AWS services to encrypt data at-rest (S3, EBS, RDS, etc.).

🇻🇳 Giải thích: KMS (Key Management Service) dùng để tạo và quản lý khóa mã hóa. Bạn tạo, xoay vòng và quản lý khóa cho các dịch vụ AWS nhằm mã hóa dữ liệu at-rest (S3, EBS, RDS...).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (IAM access) — That's IAM. / Đó là IAM.
  • C (Performance) — That's CloudWatch/monitoring. / Đó là CloudWatch/giám sát.
  • D (Malware detection) — That's Macie or Inspector. / Đó là Macie hoặc Inspector.

🔑 Key Concept / Khái niệm cốt lõi: KMS = create and manage encryption keys. / KMS = tạo và quản lý khóa mã hóa.


Q27.

Which of the following are best practices for securing an AWS account? (Select THREE)

Bản dịch tiếng Việt: Biện pháp nào sau đây là biện pháp tốt nhất để bảo mật tài khoản AWS? (Chọn BA)

A. Use the root account for daily administrative tasks B. Enable Multi-Factor Authentication (MFA) on the root account C. Create IAM users for each person who needs AWS access D. Store IAM access keys in application source code for convenience E. Rotate access keys periodically

Correct answer: B, C, E Bản dịch đáp án đúng: B. Kích hoạt Xác thực đa yếu tố (MFA) trên tài khoản root; C. Tạo người dùng IAM cho từng người cần quyền truy cập AWS; E. Xoay khóa truy cập định kỳ

🇬🇧 Explanation: B ("Enable MFA on the root account") — root has full access, so MFA (a 2nd factor) is mandatory. C ("Create IAM users for each person") — never share credentials; each person gets a unique IAM user. E ("Rotate access keys periodically") — keys can be stolen, so rotate every 90 days (or per policy).

🇻🇳 Giải thích: B ("bật MFA cho tài khoản root") — root có toàn quyền nên MFA (yếu tố thứ 2) là bắt buộc. C ("tạo IAM user cho mỗi người") — không bao giờ dùng chung credential; mỗi người một IAM user riêng. E ("xoay access key định kỳ") — key có thể bị đánh cắp, nên xoay mỗi 90 ngày (hoặc theo chính sách).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Use root for daily tasks) — Root should be locked down; use IAM users for daily work. / Root nên khóa lại; dùng IAM user cho việc hằng ngày.
  • D (Store keys in source code) — Never hardcode secrets; use IAM roles or Secrets Manager. / Không bao giờ nhúng secret vào code; dùng IAM role hoặc Secrets Manager.

🔑 Key Concept / Khái niệm cốt lõi: MFA on root + unique IAM users + key rotation = core account hygiene. / MFA cho root + IAM user riêng + xoay key = vệ sinh tài khoản cốt lõi.


Q28.

A company must comply with PCI DSS requirements for payment card data. Which AWS service helps track compliance and resource configuration changes?

Bản dịch tiếng Việt: Công ty phải tuân thủ các yêu cầu PCI DSS đối với dữ liệu thẻ thanh toán. Dịch vụ AWS nào giúp theo dõi các thay đổi về cấu hình tài nguyên và tuân thủ?

A. AWS Organizations B. AWS Artifact C. AWS Config D. CloudTrail

Correct answer: B Bản dịch đáp án đúng: B. Cấu phần AWS

🇬🇧 Explanation: AWS Artifact is a self-service portal for compliance documentation. You can access pre-signed compliance reports (PCI DSS, SOC 2, HIPAA, etc.) to prove compliance to auditors.

🇻🇳 Giải thích: AWS Artifact là cổng tự phục vụ cho tài liệu tuân thủ. Bạn có thể truy cập các báo cáo tuân thủ đã ký sẵn (PCI DSS, SOC 2, HIPAA...) để chứng minh tuân thủ với kiểm toán viên.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Organizations) — Multi-account management, not compliance docs. / Quản lý đa tài khoản, không phải tài liệu tuân thủ.
  • C (Config) — Resource config tracking, not compliance reports. / Theo dõi cấu hình tài nguyên, không phải báo cáo tuân thủ.
  • D (CloudTrail) — API audit logs, not compliance docs. / Nhật ký API, không phải tài liệu tuân thủ.

🔑 Key Concept / Khái niệm cốt lõi: Artifact = download compliance reports. / Artifact = tải báo cáo tuân thủ.


Q29.

Which service provides a centralized way to access compliance documents and certifications?

Bản dịch tiếng Việt: Dịch vụ nào cung cấp một cách tập trung để truy cập các tài liệu và chứng nhận tuân thủ?

A. AWS Trusted Advisor B. AWS Artifact C. AWS Security Hub D. AWS Organizations

Correct answer: B Bản dịch đáp án đúng: B. Cấu phần AWS

🇬🇧 Explanation: AWS Artifact provides centralized, self-service access to compliance documents — download certifications (SOC 2, PCI DSS, HIPAA, etc.) without emailing AWS support.

🇻🇳 Giải thích: AWS Artifact cung cấp quyền truy cập tập trung, tự phục vụ tới tài liệu tuân thủ — tải các chứng nhận (SOC 2, PCI DSS, HIPAA...) mà không phải email cho AWS support.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Trusted Advisor) — Best-practice checks, not compliance docs. / Kiểm tra best practice, không phải tài liệu tuân thủ.
  • C (Security Hub) — Centralized security findings, not compliance docs. / Tập trung phát hiện bảo mật, không phải tài liệu tuân thủ.
  • D (Organizations) — Multi-account billing, not compliance docs. / Tính tiền đa tài khoản, không phải tài liệu tuân thủ.

🔑 Key Concept / Khái niệm cốt lõi: Artifact = centralized compliance document portal. / Artifact = cổng tài liệu tuân thủ tập trung.


Q30.

What does AWS Trusted Advisor check for?

Bản dịch tiếng Việt: AWS Trusted Advisor kiểm tra những gì?

A. API call logging and audit trails B. Best practices in five categories: cost, performance, security, fault tolerance, and service limits C. Real-time threat detection D. Configuration management and change tracking

Correct answer: B Bản dịch đáp án đúng: B. Các phương pháp hay nhất trong năm loại: chi phí, hiệu suất, bảo mật, khả năng chịu lỗi và giới hạn dịch vụ

🇬🇧 Explanation: Trusted Advisor runs automated best-practice checks across five categories: cost optimization, performance, security, fault tolerance, and service limits — e.g., "you have an unused EIP" (cost) or "you're approaching a service limit" (limits).

🇻🇳 Giải thích: Trusted Advisor chạy các kiểm tra best practice tự động trên năm nhóm: tối ưu chi phí, hiệu năng, bảo mật, khả năng chịu lỗi, và giới hạn dịch vụ — ví dụ "bạn có một EIP không dùng" (chi phí) hay "bạn sắp chạm giới hạn dịch vụ" (giới hạn).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (CloudTrail) — API audit logging. / Ghi nhật ký API.
  • C (GuardDuty) — Real-time threat detection. / Phát hiện đe dọa thời gian thực.
  • D (Config) — Config change tracking. / Theo dõi thay đổi cấu hình.

🔑 Key Concept / Khái niệm cốt lõi: Trusted Advisor 5 categories: cost, performance, security, fault tolerance, service limits. / 5 nhóm của Trusted Advisor: chi phí, hiệu năng, bảo mật, chịu lỗi, giới hạn dịch vụ.


Q31.

An organization wants to implement a multi-account AWS environment with centralized control. Which of the following support this goal? (Select TWO)

Bản dịch tiếng Việt: Một tổ chức muốn triển khai môi trường AWS nhiều tài khoản với khả năng kiểm soát tập trung. Điều nào sau đây hỗ trợ mục tiêu này? (Chọn HAI)

A. AWS Organizations B. AWS CloudTrail C. Service Control Policies (SCPs) D. AWS Artifact E. AWS IAM Roles

Correct answer: A, C Bản dịch đáp án đúng: A. Tổ chức AWS; C. Chính sách kiểm soát dịch vụ (SCP)

🇬🇧 Explanation: A (AWS Organizations) provides multi-account management and consolidated billing — create accounts, organize them in OUs, and centralize control. C (Service Control Policies) restrict what services member accounts can use, e.g., "block all EC2 in the production account except t3.micro".

🇻🇳 Giải thích: A (AWS Organizations) cung cấp quản lý đa tài khoản và gộp hóa đơn — tạo tài khoản, sắp xếp vào OU, và quản lý tập trung. C (Service Control Policies) giới hạn dịch vụ mà các tài khoản thành viên được dùng, ví dụ "chặn mọi EC2 trong tài khoản production trừ t3.micro".

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B (CloudTrail) — Audit logging, not a control mechanism. / Ghi nhật ký kiểm toán, không phải cơ chế kiểm soát.
  • D (AWS Artifact) — Compliance documentation, not account control. / Tài liệu tuân thủ, không kiểm soát tài khoản.
  • E (IAM Roles) — Roles for single/cross-account access, not multi-account management. / Role cho truy cập một/chéo tài khoản, không phải quản lý đa tài khoản.

🔑 Key Concept / Khái niệm cốt lõi: Organizations + SCPs = centralized multi-account governance. / Organizations + SCP = quản trị đa tài khoản tập trung.


Q32.

Which AWS service is primarily used for detecting unusual or suspicious API activity in real time?

Bản dịch tiếng Việt: Dịch vụ AWS nào chủ yếu được sử dụng để phát hiện hoạt động API bất thường hoặc đáng ngờ trong thời gian thực?

A. AWS Config B. Amazon GuardDuty C. AWS CloudTrail D. AWS Inspector

Correct answer: B Bản dịch đáp án đúng: B. Nhiệm vụ bảo vệ của Amazon

🇬🇧 Explanation: Amazon GuardDuty is ML-based threat detection that analyzes CloudTrail logs and VPC Flow Logs in real time, detecting brute-force attempts, unusual API calls, and compromised instances, then surfacing findings via console/SNS.

🇻🇳 Giải thích: Amazon GuardDuty là phát hiện mối đe dọa dựa trên ML, phân tích CloudTrail logs và VPC Flow Logs theo thời gian thực, nhận diện tấn công brute-force, API call bất thường, và instance bị xâm nhập, rồi báo qua console/SNS.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Config) — Configuration changes, not threat detection. / Thay đổi cấu hình, không phát hiện đe dọa.
  • C (CloudTrail) — Audit logs, not real-time analysis. / Nhật ký kiểm toán, không phân tích thời gian thực.
  • D (Inspector) — Vulnerability assessment, not API activity. / Đánh giá lỗ hổng, không phải hoạt động API.

🔑 Key Concept / Khái niệm cốt lõi: GuardDuty = real-time, ML-based threat detection. / GuardDuty = phát hiện đe dọa thời gian thực, dựa trên ML.


Q33.

A company wants to assess its EC2 instances for security vulnerabilities and compliance deviations. Which service should be used?

Bản dịch tiếng Việt: Một công ty muốn đánh giá các phiên bản EC2 của mình để tìm lỗ hổng bảo mật và sai lệch về tuân thủ. Nên sử dụng dịch vụ nào?

A. AWS Inspector B. AWS WAF C. Amazon GuardDuty D. AWS Security Hub

Correct answer: A Bản dịch đáp án đúng: A. Thanh tra AWS

🇬🇧 Explanation: AWS Inspector is an automated security assessment service that scans EC2 instances for vulnerabilities and compliance deviations. It fits the "agent installed, scan now" use case.

🇻🇳 Giải thích: AWS Inspector là dịch vụ đánh giá bảo mật tự động, quét các EC2 instance để tìm lỗ hổng và sai lệch tuân thủ. Nó phù hợp với tình huống "đã cài agent, quét ngay".

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B (WAF) — Application firewall, not vulnerability scanning. / Firewall ứng dụng, không quét lỗ hổng.
  • C (GuardDuty) — Behavioral threat detection, not vulnerability scanning. / Phát hiện đe dọa theo hành vi, không quét lỗ hổng.
  • D (Security Hub) — Centralized findings dashboard, not a scanning tool. / Bảng tổng hợp phát hiện, không phải công cụ quét.

🔑 Key Concept / Khái niệm cốt lõi: Inspector = automated vulnerability/compliance scanning for EC2/Lambda. / Inspector = quét lỗ hổng/tuân thủ tự động cho EC2/Lambda.


Q34.

Which of the following are components of the Shared Responsibility Model for a customer using AWS services? (Select TWO)

Bản dịch tiếng Việt: Thành phần nào sau đây là thành phần của Mô hình trách nhiệm chung dành cho khách hàng sử dụng dịch vụ AWS? (Chọn HAI)

A. Managing the hypervisor B. Applying OS patches to EC2 instances C. Providing physical data center security D. Configuring network ACLs and security groups E. Upgrading AWS infrastructure

Correct answer: B, D Bản dịch đáp án đúng: B. Áp dụng các bản vá hệ điều hành cho phiên bản EC2; D. Định cấu hình ACL mạng và nhóm bảo mật

🇬🇧 Explanation: B ("Applying OS patches to EC2 instances") — the customer patches the OS (Windows, Linux) on EC2; AWS patches only the hypervisor. D ("Configuring network ACLs and security groups") — the customer configures firewall rules (NACL at subnet level, Security Group at instance level).

🇻🇳 Giải thích: B ("vá OS cho các EC2 instance") — khách hàng vá OS (Windows, Linux) trên EC2; AWS chỉ vá hypervisor. D ("cấu hình network ACL và security group") — khách hàng cấu hình rule firewall (NACL ở cấp subnet, Security Group ở cấp instance).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Managing the hypervisor) — AWS responsibility (infrastructure). / Trách nhiệm AWS (hạ tầng).
  • C (Physical data center security) — AWS responsibility (facilities). / Trách nhiệm AWS (cơ sở vật chất).
  • E (Upgrading AWS infrastructure) — AWS responsibility. / Trách nhiệm AWS.

🔑 Key Concept / Khái niệm cốt lõi: Customer = OS patches + firewall config; AWS = hypervisor + facilities. / Khách hàng = vá OS + cấu hình firewall; AWS = hypervisor + cơ sở.

📚 Reference: Domain 2, sections 1.3 / 1.5


Q35.

What does the principle of "least privilege" mean in the context of IAM?

Bản dịch tiếng Việt: Nguyên tắc "đặc quyền tối thiểu" có nghĩa là gì trong bối cảnh IAM?

A. All users should have the same permissions B. Only grant users the minimum permissions required to perform their jobs C. Grant broad permissions to reduce administrative overhead D. Only the root account should have full permissions

Correct answer: B Bản dịch đáp án đúng: B. Chỉ cấp cho người dùng những quyền tối thiểu cần thiết để thực hiện công việc của họ

🇬🇧 Explanation: Least privilege means granting users only the minimum permissions required to perform their jobs — deny by default. This reduces risk: if an account is stolen, the attacker has limited access (e.g., an EC2 role can reach only bucket X, not all buckets).

🇻🇳 Giải thích: Least privilege nghĩa là chỉ cấp cho người dùng quyền tối thiểu cần để làm việc — mặc định là từ chối. Điều này giảm rủi ro: nếu tài khoản bị đánh cắp, kẻ tấn công chỉ có quyền hạn chế (ví dụ EC2 role chỉ chạm bucket X, không phải mọi bucket).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Same permissions for all) — Opposite; everyone has different needs. / Ngược lại; mỗi người nhu cầu khác nhau.
  • C (Broad permissions) — Opposite; maximizes risk. / Ngược lại; tăng tối đa rủi ro.
  • D (Root only) — Too restrictive; nobody else can work. / Quá hạn chế; không ai khác làm việc được.

🔑 Key Concept / Khái niệm cốt lõi: Least privilege = minimum permissions, deny by default. / Least privilege = quyền tối thiểu, mặc định từ chối.

📚 Reference: Domain 2, section 1.3


Q36.

Which service would be most appropriate for monitoring and logging database activities for compliance purposes?

Bản dịch tiếng Việt: Dịch vụ nào phù hợp nhất để giám sát và ghi lại các hoạt động cơ sở dữ liệu nhằm mục đích tuân thủ?

A. CloudWatch B. AWS Config C. CloudTrail D. AWS Inspector

Correct answer: C Bản dịch đáp án đúng: C. Đường mòn đám mây

🇬🇧 Explanation: CloudTrail logs all API calls to AWS services (including the RDS API), so it can monitor and log database activities for compliance audits (HIPAA, PCI, SOX).

🇻🇳 Giải thích: CloudTrail ghi lại mọi API call tới các dịch vụ AWS (bao gồm RDS API), nên có thể giám sát và ghi lại hoạt động database phục vụ kiểm toán tuân thủ (HIPAA, PCI, SOX).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (CloudWatch) — Metrics/alarms, not detailed activity logs. / Metrics/alarm, không phải nhật ký hoạt động chi tiết.
  • B (Config) — Configuration changes, not detailed activities. / Thay đổi cấu hình, không phải hoạt động chi tiết.
  • D (Inspector) — Vulnerability scanning, not activity logging. / Quét lỗ hổng, không ghi hoạt động.

🔑 Key Concept / Khái niệm cốt lõi: CloudTrail = API-level activity logging for audit/compliance. / CloudTrail = ghi hoạt động cấp API cho kiểm toán/tuân thủ.


Domain Distribution

Q37.

Which of the following is an example of Infrastructure as Code (IaC)?

Bản dịch tiếng Việt: Điều nào sau đây là ví dụ về Cơ sở hạ tầng dưới dạng mã (IaC)?

A. Using AWS Management Console to create resources manually B. Using AWS CloudFormation to define infrastructure in JSON/YAML templates C. Running ad-hoc CLI commands D. Manually patching servers

Correct answer: B Bản dịch đáp án đúng: B. Sử dụng AWS CloudFormation để xác định cơ sở hạ tầng trong các mẫu JSON/YAML

🇬🇧 Explanation: Infrastructure as Code means defining infrastructure as version-controlled, repeatable code. Using AWS CloudFormation to define infrastructure in JSON/YAML templates is the classic IaC example — reproducible, supports change sets, and is easy to roll back.

🇻🇳 Giải thích: Infrastructure as Code nghĩa là định nghĩa hạ tầng bằng code có version, lặp lại được. Dùng AWS CloudFormation để định nghĩa hạ tầng trong template JSON/YAML là ví dụ IaC kinh điển — tái lập được, hỗ trợ change set, và dễ rollback.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Console manual) — Click-and-build, not IaC. / Bấm tay, không phải IaC.
  • C (CLI commands) — Scripting, but not traditional IaC. / Viết script, nhưng không phải IaC truyền thống.
  • D (Manual patching) — Opposite of automation. / Ngược với tự động hóa.

🔑 Key Concept / Khái niệm cốt lõi: CloudFormation (JSON/YAML templates) = AWS's IaC tool. / CloudFormation (template JSON/YAML) = công cụ IaC của AWS.


Q38.

A company needs a virtual machine with complete control over the OS, middleware, and application layers. Which AWS service is most suitable?

Bản dịch tiếng Việt: Một công ty cần một máy ảo có toàn quyền kiểm soát hệ điều hành, phần mềm trung gian và các lớp ứng dụng. Dịch vụ AWS nào phù hợp nhất?

A. AWS Lambda B. Amazon EC2 C. AWS Elastic Beanstalk D. Amazon RDS

Correct answer: B Bản dịch đáp án đúng: B. Amazon EC2

🇬🇧 Explanation: Amazon EC2 is a virtual machine giving complete control — the customer manages the OS, patches, middleware, and application. It fits "I need to install custom software".

🇻🇳 Giải thích: Amazon EC2 là máy ảo cho toàn quyền kiểm soát — khách hàng quản OS, bản vá, middleware, và ứng dụng. Nó phù hợp với "tôi cần cài phần mềm tùy chỉnh".

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Lambda) — Serverless, no OS control. / Serverless, không kiểm soát OS.
  • C (Beanstalk) — PaaS, AWS manages OS/runtime. / PaaS, AWS quản OS/runtime.
  • D (RDS) — Managed database, no OS access. / Database được quản, không truy cập OS.

🔑 Key Concept / Khái niệm cốt lõi: EC2 = full OS control (IaaS). / EC2 = toàn quyền OS (IaaS).


Q39.

Which EC2 instance family is optimized for compute-intensive workloads such as high-performance web servers and batch processing?

Bản dịch tiếng Việt: Dòng phiên bản EC2 nào được tối ưu hóa cho khối lượng công việc điện toán chuyên sâu như máy chủ web hiệu suất cao và xử lý hàng loạt?

A. T3 (General Purpose) B. C5 (Compute Optimized) C. R5 (Memory Optimized) D. I3 (Storage Optimized)

Correct answer: B Bản dịch đáp án đúng: B. C5 (Tối ưu hóa tính toán)

🇬🇧 Explanation: The C5 (Compute Optimized) family is for compute-intensive workloads — high CPU, low memory. Use cases include high-performance web servers, batch processing, and scientific simulations. Mnemonic: C = Compute.

🇻🇳 Giải thích: Họ C5 (Compute Optimized) dành cho workload nặng tính toán — CPU cao, RAM thấp. Ứng dụng gồm web server hiệu năng cao, xử lý batch, và mô phỏng khoa học. Mẹo nhớ: C = Compute.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A — Not compute-optimized. / Không tối ưu tính toán.
  • C — Not compute-optimized. / Không tối ưu tính toán.
  • D — Not compute-optimized. / Không tối ưu tính toán.

🔑 Key Concept / Khái niệm cốt lõi: Families — T/M (general), C (compute), R (memory), I/D (storage), P/G (GPU). / Họ instance — T/M (chung), C (tính toán), R (bộ nhớ), I/D (lưu trữ), P/G (GPU).


Q40.

Which of the following are valid EC2 pricing models? (Select THREE)

Bản dịch tiếng Việt: Mô hình định giá EC2 nào sau đây hợp lệ? (Chọn BA)

A. Always-On Instances B. Reserved Instances C. Spot Instances D. Perpetual License Instances E. Savings Plans

Correct answer: B, C, E Bản dịch đáp án đúng: B. Phiên bản dự trữ; C. Phiên bản Spot; E. Kế hoạch tiết kiệm

🇬🇧 Explanation: B (Reserved Instances) — commit 1-3 years to save up to 72%. C (Spot Instances) — bid price to save up to 90%. E (Savings Plans) — commit a $ amount per hour, flexible across instance types. These are three of the valid EC2 pricing models.

🇻🇳 Giải thích: B (Reserved Instances) — cam kết 1-3 năm, tiết kiệm tới 72%. C (Spot Instances) — giá đấu, tiết kiệm tới 90%. E (Savings Plans) — cam kết một mức $ mỗi giờ, linh hoạt giữa các loại instance. Đây là ba trong số các mô hình giá EC2 hợp lệ.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Always-On Instances) — Not an official model (likely means On-Demand). / Không phải mô hình chính thức (có lẽ ý là On-Demand).
  • D (Perpetual License Instances) — AWS offers subscriptions, not perpetual licenses. / AWS bán thuê bao, không bán license vĩnh viễn.

🔑 Key Concept / Khái niệm cốt lõi: 5 EC2 models: On-Demand, Reserved, Spot, Savings Plans, Dedicated Hosts. / 5 mô hình EC2: On-Demand, Reserved, Spot, Savings Plans, Dedicated Hosts.

📚 Reference: Domain 4 study guide


Q41.

A company runs a web application with unpredictable traffic patterns. Which EC2 pricing option provides the most cost efficiency?

Bản dịch tiếng Việt: Một công ty chạy một ứng dụng web có lưu lượng truy cập không thể đoán trước. Tùy chọn định giá EC2 nào mang lại hiệu quả chi phí cao nhất?

A. Reserved Instances (1-year) B. On-Demand Instances C. Spot Instances D. Dedicated Hosts

Correct answer: B Bản dịch đáp án đúng: B. Phiên bản theo yêu cầu

🇬🇧 Explanation: With unpredictable traffic you can't commit to Reserved or risk Spot termination, so On-Demand Instances (pay per hour, no commitment) are most cost-efficient. Flexibility beats cost savings when demand is uncertain — e.g., a startup that doesn't yet know its traffic pattern.

🇻🇳 Giải thích: Với traffic khó đoán, bạn không thể cam kết Reserved hay chịu rủi ro Spot bị thu hồi, nên On-Demand Instances (trả theo giờ, không cam kết) là tiết kiệm nhất. Khi nhu cầu chưa chắc, tính linh hoạt quan trọng hơn tiết kiệm — ví dụ startup chưa biết mẫu traffic của mình.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Reserved 1yr) — Can't commit; risk of unused capacity. / Không thể cam kết; nguy cơ công suất bỏ phí.
  • C (Spot) — Can be terminated; unsuitable if always-on. / Có thể bị thu hồi; không hợp nếu phải luôn chạy.
  • D (Dedicated) — Most expensive, unnecessary. / Đắt nhất, không cần.

🔑 Key Concept / Khái niệm cốt lõi: Unpredictable/spiky workload = On-Demand. / Workload khó đoán/đột biến = On-Demand.

📚 Reference: Domain 4 study guide


Q42.

Which AWS storage service is designed for long-term archival of infrequently accessed data?

Bản dịch tiếng Việt: Dịch vụ lưu trữ AWS nào được thiết kế để lưu trữ lâu dài dữ liệu được truy cập không thường xuyên?

A. Amazon S3 Standard B. Amazon S3 Glacier Flexible Retrieval C. Amazon EBS D. Amazon EFS

Correct answer: B Bản dịch đáp án đúng: B. Truy xuất linh hoạt Amazon S3 Glacier

🇬🇧 Explanation: Amazon S3 Glacier Flexible Retrieval is archive storage about 90% cheaper than Standard, with retrieval in minutes to hours — acceptable for compliance archives, backups, and historical data.

🇻🇳 Giải thích: Amazon S3 Glacier Flexible Retrieval là lưu trữ archive rẻ hơn Standard khoảng 90%, thời gian lấy lại từ vài phút đến vài giờ — chấp nhận được cho lưu trữ tuân thủ, sao lưu, và dữ liệu lịch sử.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (S3 Standard) — Most expensive, for frequent access. / Đắt nhất, cho truy cập thường xuyên.
  • C (EBS) — Block storage, not archival. / Lưu trữ block, không phải archive.
  • D (EFS) — File storage, not archival. / Lưu trữ file, không phải archive.

🔑 Key Concept / Khái niệm cốt lõi: Archival of infrequent data = Glacier (Flexible/Deep Archive). / Lưu trữ dữ liệu ít truy cập = Glacier (Flexible/Deep Archive).


Q43.

Which of the following statements about S3 storage classes are correct? (Select TWO)

Bản dịch tiếng Việt: Câu nào sau đây về lớp lưu trữ S3 là đúng? (Chọn HAI)

A. S3 Standard is the most cost-effective for long-term archival B. S3 Glacier Deep Archive has the lowest storage cost but longest retrieval time C. S3 One Zone-IA stores data across multiple availability zones D. S3 Intelligent-Tiering automatically moves objects between access tiers E. S3 Standard-IA is suitable for frequently accessed data

Correct answer: B, D Bản dịch đáp án đúng: B. S3 Glacier Deep Archive có chi phí lưu trữ thấp nhất nhưng thời gian truy xuất lâu nhất; D. S3 Phân bậc thông minh tự động di chuyển các đối tượng giữa các tầng truy cập

🇬🇧 Explanation: B ("S3 Glacier Deep Archive has the lowest storage cost but longest retrieval time") — ~$0.0036/GB/month vs Standard $0.023, with 12-48 hour retrieval. D ("S3 Intelligent-Tiering automatically moves objects between access tiers") — auto-tiering based on access pattern, with no retrieval fees while AWS handles moving.

🇻🇳 Giải thích: B ("S3 Glacier Deep Archive có chi phí lưu trữ thấp nhất nhưng thời gian lấy lại lâu nhất") — ~$0.0036/GB/tháng so với Standard $0.023, lấy lại 12-48 giờ. D ("S3 Intelligent-Tiering tự động chuyển object giữa các tier truy cập") — tự động phân tầng theo mẫu truy cập, không tính phí lấy lại trong khi AWS lo việc chuyển.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (S3 Standard best for archival) — Standard is expensive; Deep Archive is cheapest for archival. / Standard đắt; Deep Archive rẻ nhất cho archive.
  • C (One Zone-IA stores across multiple AZs) — One Zone-IA is single-AZ only. / One Zone-IA chỉ một AZ.
  • E (Standard-IA for frequent access) — IA = Infrequent Access. / IA = truy cập không thường xuyên.

🔑 Key Concept / Khái niệm cốt lõi: Deep Archive = cheapest/slowest; Intelligent-Tiering = auto-move tiers. / Deep Archive = rẻ nhất/chậm nhất; Intelligent-Tiering = tự chuyển tier.


Q44.

What is the primary difference between EBS and EFS?

Bản dịch tiếng Việt: Sự khác biệt chính giữa EBS và EFS là gì?

A. EBS is a file storage service; EFS is block storage B. EBS is block storage for a single EC2 instance; EFS is shared file storage across multiple instances C. EBS is cheaper than EFS D. EBS is managed by AWS; EFS is managed by the customer

Correct answer: B Bản dịch đáp án đúng: B. EBS là khối lưu trữ cho một phiên bản EC2; EFS là nơi lưu trữ tệp được chia sẻ trên nhiều phiên bản

🇬🇧 Explanation: EBS is block storage attached to a single EC2 instance (same AZ); EFS is shared file storage (NFS) across multiple instances and cross-AZ. Example: one web server uses EBS; three web servers sharing data use EFS.

🇻🇳 Giải thích: EBS là lưu trữ block gắn vào một EC2 instance (cùng AZ); EFS là lưu trữ file chia sẻ (NFS) qua nhiều instance và xuyên AZ. Ví dụ: một web server dùng EBS; ba web server cùng chia sẻ dữ liệu dùng EFS.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (EBS file, EFS block) — Reversed/wrong. / Đảo ngược/sai.
  • C (EBS cheaper) — EBS is cheaper per GB but that's not the primary difference. / EBS rẻ hơn mỗi GB nhưng không phải khác biệt chính.
  • D (EBS managed, EFS customer) — Both are managed by AWS. / Cả hai đều do AWS quản.

🔑 Key Concept / Khái niệm cốt lõi: EBS = block, single EC2; EFS = file, shared multi-EC2 cross-AZ. / EBS = block, một EC2; EFS = file, chia sẻ nhiều EC2 xuyên AZ.


Q45.

A company needs to serve content to users globally with low latency. Which AWS service should be used?

Bản dịch tiếng Việt: Một công ty cần cung cấp nội dung cho người dùng trên toàn cầu với độ trễ thấp. Nên sử dụng dịch vụ AWS nào?

A. Amazon Route 53 B. Amazon CloudFront C. AWS Global Accelerator D. Amazon API Gateway

Correct answer: B Bản dịch đáp án đúng: B. Mặt trận đám mây của Amazon

🇬🇧 Explanation: Amazon CloudFront is a CDN that caches content at 600+ edge locations to serve content globally with low latency — a Vietnam user pulling from S3 US drops from ~200ms to ~20ms via a local edge.

🇻🇳 Giải thích: Amazon CloudFront là CDN cache nội dung tại hơn 600 edge location để phân phối nội dung toàn cầu với độ trễ thấp — người dùng Việt Nam kéo dữ liệu từ S3 ở Mỹ giảm từ ~200ms còn ~20ms nhờ edge gần.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Route 53) — DNS service, not CDN caching. / Dịch vụ DNS, không phải cache CDN.
  • C (Global Accelerator) — Global routing, not content caching. / Định tuyến toàn cầu, không cache nội dung.
  • D (API Gateway) — API management, not content delivery. / Quản lý API, không phân phối nội dung.

🔑 Key Concept / Khái niệm cốt lõi: CloudFront = CDN for low-latency global content delivery. / CloudFront = CDN phân phối nội dung toàn cầu độ trễ thấp.


Q46.

What is the primary function of Route 53?

Bản dịch tiếng Việt: Chức năng chính của Tuyến đường 53 là gì?

A. Load balancing traffic across EC2 instances B. Content delivery and caching C. DNS service and domain registration D. SSL/TLS certificate management

Correct answer: C Bản dịch đáp án đúng: C. Dịch vụ DNS và đăng ký tên miền

🇬🇧 Explanation: Route 53 is AWS's DNS service and domain registrar. It translates domain names to IP addresses and also provides health checks and routing policies (weighted, geolocation, etc.).

🇻🇳 Giải thích: Route 53 là dịch vụ DNS và nhà đăng ký tên miền của AWS. Nó dịch tên miền thành địa chỉ IP, đồng thời cung cấp health check và các routing policy (weighted, geolocation...).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Load balancing) — That's ALB/NLB (Route 53 routes to them). / Đó là ALB/NLB (Route 53 định tuyến tới chúng).
  • B (Content caching) — That's CloudFront. / Đó là CloudFront.
  • D (SSL/TLS certs) — That's AWS Certificate Manager. / Đó là AWS Certificate Manager.

🔑 Key Concept / Khái niệm cốt lõi: Route 53 = DNS + domain registration + routing policies. / Route 53 = DNS + đăng ký tên miền + routing policy.


Q47.

Which of the following are use cases for Route 53 routing policies? (Select TWO)

Bản dịch tiếng Việt: Trường hợp nào sau đây là trường hợp sử dụng cho chính sách định tuyến của Route 53? (Chọn HAI)

A. Routing traffic to the nearest geographic location B. Encrypting data in transit C. Distributing traffic based on custom weights D. Compressing images in S3 buckets E. Managing IAM access

Correct answer: A, C Bản dịch đáp án đúng: A. Định tuyến lưu lượng truy cập đến vị trí địa lý gần nhất; C. Phân phối lưu lượng truy cập dựa trên trọng số tùy chỉnh

🇬🇧 Explanation: A ("Routing traffic to the nearest geographic location") — geolocation routing policy directs users to the lowest-latency region. C ("Distributing traffic based on custom weights") — weighted routing assigns weights to records (e.g., 70% to A, 30% to B for canary releases).

🇻🇳 Giải thích: A ("định tuyến đến vị trí địa lý gần nhất") — geolocation routing đưa người dùng tới region độ trễ thấp nhất. C ("phân phối lưu lượng theo trọng số tùy chỉnh") — weighted routing gán trọng số cho từng record (ví dụ 70% sang A, 30% sang B để canary).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B (Encrypting data in transit) — That's TLS/SSL or ACM. / Đó là TLS/SSL hoặc ACM.
  • D (Compressing images in S3) — That's CloudFront or Lambda@Edge. / Đó là CloudFront hoặc Lambda@Edge.
  • E (Managing IAM access) — That's IAM. / Đó là IAM.

🔑 Key Concept / Khái niệm cốt lõi: Route 53 policies: Simple, Weighted, Geolocation, Latency, Failover, Multivalue. / Các policy của Route 53: Simple, Weighted, Geolocation, Latency, Failover, Multivalue.


Q48.

Which database service is best suited for applications that require complex JOIN operations and ACID compliance?

Bản dịch tiếng Việt: Dịch vụ cơ sở dữ liệu nào phù hợp nhất cho các ứng dụng yêu cầu hoạt động THAM GIA phức tạp và tuân thủ ACID?

A. Amazon DynamoDB B. Amazon RDS C. Amazon Redshift D. Amazon Neptune

Correct answer: B Bản dịch đáp án đúng: B. Amazon RDS

🇬🇧 Explanation: Complex JOINs and ACID compliance point to a relational database, so Amazon RDS (MySQL, PostgreSQL, Oracle, SQL Server) is the best fit — it supports SQL, ACID transactions, and multi-table queries.

🇻🇳 Giải thích: JOIN phức tạp và tuân thủ ACID chỉ tới database quan hệ, nên Amazon RDS (MySQL, PostgreSQL, Oracle, SQL Server) là phù hợp nhất — hỗ trợ SQL, giao dịch ACID, và truy vấn nhiều bảng.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (DynamoDB) — NoSQL, no JOINs, eventual consistency. / NoSQL, không JOIN, nhất quán cuối cùng.
  • C (Redshift) — Data warehouse, not transactional. / Kho dữ liệu, không phải giao dịch.
  • D (Neptune) — Graph database, not relational. / Database đồ thị, không phải quan hệ.

🔑 Key Concept / Khái niệm cốt lõi: Relational + ACID + JOINs = RDS/Aurora. / Quan hệ + ACID + JOIN = RDS/Aurora.


Q49.

A startup wants a serverless database option for a mobile application with unpredictable traffic. Which service is most appropriate?

Bản dịch tiếng Việt: Một công ty khởi nghiệp muốn có tùy chọn cơ sở dữ liệu không có máy chủ cho ứng dụng di động có lưu lượng truy cập không thể đoán trước. Dịch vụ nào phù hợp nhất?

A. Amazon RDS B. Amazon DynamoDB with on-demand billing C. Amazon Aurora D. Amazon Redshift

Correct answer: B Bản dịch đáp án đúng: B. Amazon DynamoDB với tính năng thanh toán theo yêu cầu

🇬🇧 Explanation: Amazon DynamoDB with on-demand billing is serverless, auto-scales, and bills per request — no provisioned capacity — making it perfect for a mobile app with spiky, unpredictable traffic.

🇻🇳 Giải thích: Amazon DynamoDB với on-demand billing là serverless, tự co giãn, và tính tiền theo từng request — không cần provision capacity — rất phù hợp cho app di động có traffic đột biến, khó đoán.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (RDS) — Requires provisioning capacity, not serverless. / Cần provision capacity, không serverless.
  • C (Aurora) — Managed but not serverless by default. / Được quản nhưng mặc định không serverless.
  • D (Redshift) — Data warehouse, not for transactional mobile apps. / Kho dữ liệu, không cho app di động giao dịch.

🔑 Key Concept / Khái niệm cốt lõi: Serverless + unpredictable + pay-per-request = DynamoDB on-demand. / Serverless + khó đoán + trả theo request = DynamoDB on-demand.


Q50.

Which of the following are benefits of using AWS Lambda? (Select THREE)

Bản dịch tiếng Việt: Lợi ích nào sau đây là của việc sử dụng AWS Lambda? (Chọn BA)

A. No need to manage servers or infrastructure B. Auto-scaling based on request volume C. Guarantees data encryption at rest D. Pay only for the time code is executing E. Supports indefinite execution duration F. Provides root SSH access to the underlying server

Correct answer: A, B, D Bản dịch đáp án đúng: A. Không cần quản lý máy chủ hoặc cơ sở hạ tầng; B. Tự động mở rộng quy mô dựa trên khối lượng yêu cầu; D. Chỉ trả tiền cho mã thời gian đang thực thi

🇬🇧 Explanation: A ("No need to manage servers or infrastructure") — serverless means AWS manages everything. B ("Auto-scaling based on request volume") — Lambda scales from 0 to thousands of concurrent executions with no config. D ("Pay only for the time code is executing") — billed per 100ms, so if code runs 100ms you pay for 100ms (not a full hour like EC2).

🇻🇳 Giải thích: A ("không cần quản server hay hạ tầng") — serverless nghĩa là AWS lo tất cả. B ("tự co giãn theo lượng request") — Lambda mở rộng từ 0 đến hàng nghìn execution đồng thời mà không cần cấu hình. D ("chỉ trả cho thời gian code chạy") — tính theo từng 100ms, nên nếu code chạy 100ms bạn chỉ trả 100ms (không trả cả giờ như EC2).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • C (Guarantees data encryption at rest) — Encryption is optional; you must enable it. / Mã hóa là tùy chọn; bạn phải bật.
  • E (Supports indefinite execution duration) — Max is 15 minutes. / Tối đa 15 phút.
  • F (Provides root SSH access to the server) — Serverless means no OS/SSH access; AWS fully manages the environment. / Serverless nên không có quyền OS/SSH; AWS quản toàn bộ môi trường.

🔑 Key Concept / Khái niệm cốt lõi: Lambda = serverless, auto-scaling, pay-per-execution (max 15 min). / Lambda = serverless, tự co giãn, trả theo lần chạy (tối đa 15 phút).

📚 Reference: Domain 3 study guide


Q51.

What is the maximum execution duration for an AWS Lambda function?

Bản dịch tiếng Việt: Thời lượng thực thi tối đa của hàm AWS Lambda là bao nhiêu?

A. 5 minutes B. 15 minutes C. 1 hour D. Unlimited

Correct answer: B Bản dịch đáp án đúng: B. 15 phút

🇬🇧 Explanation: Lambda's maximum execution duration is 15 minutes (900 seconds). If code runs longer, Lambda kills it; for longer jobs use Step Functions or AWS Glue.

🇻🇳 Giải thích: Thời lượng chạy tối đa của Lambda là 15 phút (900 giây). Nếu code chạy lâu hơn, Lambda sẽ kết thúc nó; với job dài hơn hãy dùng Step Functions hoặc AWS Glue.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (5 min) — Too short; real limit is 15 min. / Quá ngắn; giới hạn thật là 15 phút.
  • C (1 hour) — Too long; real limit is 15 min. / Quá dài; giới hạn thật là 15 phút.
  • D (Unlimited) — No, hard limit 15 min. / Không, giới hạn cứng 15 phút.

🔑 Key Concept / Khái niệm cốt lõi: Lambda hard timeout = 15 minutes. / Timeout cứng của Lambda = 15 phút.


Q52.

Which AWS service is used for containerized application orchestration?

Bản dịch tiếng Việt: Dịch vụ AWS nào được sử dụng để điều phối ứng dụng trong bộ chứa?

A. AWS Lambda B. Amazon EC2 C. Amazon ECS or Amazon EKS D. AWS Elastic Beanstalk

Correct answer: C Bản dịch đáp án đúng: C. Amazon ECS hoặc Amazon EKS

🇬🇧 Explanation: Amazon ECS (AWS container orchestration for Docker) and Amazon EKS (Kubernetes on AWS) are the container orchestration services — both manage containerized workloads.

🇻🇳 Giải thích: Amazon ECS (điều phối container Docker của AWS) và Amazon EKS (Kubernetes trên AWS) là các dịch vụ điều phối container — cả hai đều quản lý workload container hóa.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Lambda) — Serverless functions, not containers. / Hàm serverless, không phải container.
  • B (EC2) — VMs; you manage containers manually. / Máy ảo; bạn tự quản container.
  • D (Beanstalk) — PaaS, no direct container orchestration. / PaaS, không điều phối container trực tiếp.

🔑 Key Concept / Khái niệm cốt lõi: ECS/EKS = container orchestration. / ECS/EKS = điều phối container.


Q53.

Which of the following are valid methods to interact with AWS services? (Select TWO)

Bản dịch tiếng Việt: Phương pháp nào sau đây là hợp lệ để tương tác với dịch vụ AWS? (Chọn HAI)

A. AWS Management Console (web interface) B. AWS Command Line Interface (CLI) C. AWS Telepathy Interface D. AWS Quantum SDK E. AWS Mobile Console

Correct answer: A, B Bản dịch đáp án đúng: A. Bảng điều khiển quản lý AWS (giao diện web); B. Giao diện dòng lệnh AWS (CLI)

🇬🇧 Explanation: A (AWS Management Console) is the point-and-click web GUI at console.aws.amazon.com. B (AWS Command Line Interface) supports automation and scripts (e.g., aws ec2 describe-instances). These are real ways to interact with AWS.

🇻🇳 Giải thích: A (AWS Management Console) là giao diện web bấm chuột tại console.aws.amazon.com. B (AWS Command Line Interface) hỗ trợ tự động hóa và script (ví dụ aws ec2 describe-instances). Đây là các cách thực để tương tác với AWS.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • C (AWS Telepathy Interface) — No such service; AWS is accessed via Console, CLI, SDKs, and APIs only. / Không có dịch vụ này; AWS chỉ truy cập qua Console, CLI, SDK, API.
  • D (AWS Quantum SDK) — Not a standard AWS interaction method. / Không phải cách tương tác chuẩn của AWS.
  • E (AWS Mobile Console) — Not an official term. / Không phải thuật ngữ chính thức.

🔑 Key Concept / Khái niệm cốt lõi: Interact via Console, CLI, SDKs, CloudShell, and APIs. / Tương tác qua Console, CLI, SDK, CloudShell, và API.


Q54.

What is AWS Elastic Beanstalk?

Bản dịch tiếng Việt: Cây đậu đàn hồi AWS là gì?

A. A service for managing databases B. A PaaS service for deploying web applications without managing infrastructure C. A service for managing EC2 instances only D. A service for creating containers

Correct answer: B Bản dịch đáp án đúng: B. Dịch vụ PaaS để triển khai các ứng dụng web mà không cần quản lý cơ sở hạ tầng

🇬🇧 Explanation: Elastic Beanstalk is a PaaS service for deploying web applications without managing infrastructure — upload code and Beanstalk handles servers, load balancing, and scaling.

🇻🇳 Giải thích: Elastic Beanstalk là dịch vụ PaaS để triển khai ứng dụng web mà không phải quản hạ tầng — đẩy code lên và Beanstalk lo server, cân bằng tải, và co giãn.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Database management) — That's RDS/DynamoDB. / Đó là RDS/DynamoDB.
  • C (EC2 only) — Beanstalk includes ALB, auto-scaling, and more. / Beanstalk gồm cả ALB, auto-scaling và hơn nữa.
  • D (Container management) — That's ECS/EKS. / Đó là ECS/EKS.

🔑 Key Concept / Khái niệm cốt lõi: Beanstalk = PaaS for easy app deployment. / Beanstalk = PaaS triển khai ứng dụng dễ dàng.


Q55.

Which VPC component controls traffic at the subnet level?

Bản dịch tiếng Việt: Thành phần VPC nào kiểm soát lưu lượng ở cấp mạng con?

A. Security Groups B. Network Access Control Lists (NACLs) C. Internet Gateways D. NAT Gateways

Correct answer: B Bản dịch đáp án đúng: B. Danh sách kiểm soát truy cập mạng (NACL)

🇬🇧 Explanation: Network Access Control Lists (NACLs) are a stateless firewall at the subnet level, with inbound and outbound allow/deny rules that affect all instances in the subnet.

🇻🇳 Giải thích: Network Access Control Lists (NACL) là firewall stateless ở cấp subnet, có rule allow/deny cho inbound và outbound áp dụng cho mọi instance trong subnet.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Security Groups) — Instance-level, not subnet-level. / Cấp instance, không phải cấp subnet.
  • C (Internet Gateway) — For internet access, not a firewall. / Cho truy cập internet, không phải firewall.
  • D (NAT Gateway) — For private subnet outbound access, not filtering. / Cho subnet riêng ra ngoài, không lọc.

🔑 Key Concept / Khái niệm cốt lõi: NACL = stateless, subnet-level (allow + deny); SG = stateful, instance-level. / NACL = stateless, cấp subnet (allow + deny); SG = stateful, cấp instance.


Q56.

A company wants to establish a dedicated, private connection from its on-premises data center to AWS. Which service is most appropriate?

Bản dịch tiếng Việt: Một công ty muốn thiết lập kết nối riêng, chuyên dụng từ trung tâm dữ liệu tại chỗ của mình tới AWS. Dịch vụ nào phù hợp nhất?

A. AWS Direct Connect B. AWS VPN C. AWS Site-to-Site VPN D. Amazon CloudFront

Correct answer: A Bản dịch đáp án đúng: A. Kết nối trực tiếp AWS

🇬🇧 Explanation: AWS Direct Connect provides a dedicated, private physical network connection from on-premises to AWS — faster and more stable than VPN, suited to hybrid cloud needing 1 Gbps+.

🇻🇳 Giải thích: AWS Direct Connect cung cấp kết nối mạng vật lý riêng, chuyên dụng từ on-premises tới AWS — nhanh và ổn định hơn VPN, phù hợp hybrid cloud cần 1 Gbps trở lên.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B (VPN) — Encrypted but over the public internet (slower, higher latency). / Mã hóa nhưng đi qua internet công cộng (chậm hơn, độ trễ cao hơn).
  • C (Site-to-Site VPN) — Same as B. / Giống B.
  • D (CloudFront) — CDN, not a connection. / CDN, không phải kết nối.

🔑 Key Concept / Khái niệm cốt lõi: Direct Connect = dedicated, consistent, high-bandwidth on-prem-to-AWS link. / Direct Connect = liên kết on-prem tới AWS chuyên dụng, ổn định, băng thông cao.


Q57.

Which of the following statements about Application Load Balancer (ALB) are correct? (Select TWO)

Bản dịch tiếng Việt: Câu nào sau đây về Cân bằng tải ứng dụng (ALB) là đúng? (Chọn HAI)

A. ALB operates at Layer 3 (Network layer) B. ALB can distribute traffic based on hostname or path-based routing C. ALB is suitable for non-HTTP protocols D. ALB performs health checks on target instances E. ALB is deprecated in favor of NLB

Correct answer: B, D Bản dịch đáp án đúng: B. ALB có thể phân phối lưu lượng truy cập dựa trên tên máy chủ hoặc định tuyến dựa trên đường dẫn; D. ALB thực hiện kiểm tra tình trạng trên các phiên bản mục tiêu

🇬🇧 Explanation: B ("ALB can distribute traffic based on hostname or path-based routing") — host routing (www vs api) and path routing (/images/* vs /api/*). D ("ALB performs health checks on target instances") — ALB pings targets via HTTP GET, removes unhealthy ones, and fails over to healthy instances.

🇻🇳 Giải thích: B ("ALB có thể phân phối lưu lượng theo hostname hoặc path") — định tuyến theo host (www vs api) và theo path (/images/* vs /api/*). D ("ALB thực hiện health check trên các instance đích") — ALB ping target qua HTTP GET, loại bỏ instance không khỏe, và chuyển sang instance khỏe.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (ALB at Layer 3) — ALB is Layer 7; NLB is Layer 4. / ALB ở lớp 7; NLB ở lớp 4.
  • C (ALB for non-HTTP protocols) — ALB is for HTTP/HTTPS; NLB handles TCP/UDP. / ALB cho HTTP/HTTPS; NLB lo TCP/UDP.
  • E (ALB deprecated in favor of NLB) — Both are actively used. / Cả hai vẫn được dùng.

🔑 Key Concept / Khái niệm cốt lõi: ALB = Layer 7, host/path routing + health checks. / ALB = lớp 7, định tuyến host/path + health check.


Q58.

Which AWS service allows you to build, test, and deploy serverless applications?

Bản dịch tiếng Việt: Dịch vụ AWS nào cho phép bạn xây dựng, thử nghiệm và triển khai các ứng dụng serverless?

A. AWS CodeBuild B. AWS SAM (Serverless Application Model) C. AWS CloudFormation D. AWS CodeDeploy

Correct answer: B Bản dịch đáp án đúng: B. AWS SAM (Mô hình ứng dụng không có máy chủ)

🇬🇧 Explanation: AWS SAM (Serverless Application Model) is a framework for building, testing, and deploying serverless apps (Lambda, API Gateway, DynamoDB), with a workflow of sam initsam buildsam deploy.

🇻🇳 Giải thích: AWS SAM (Serverless Application Model) là framework để build, test, và deploy ứng dụng serverless (Lambda, API Gateway, DynamoDB), với quy trình sam initsam buildsam deploy.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (CodeBuild) — Build service (compile code). / Dịch vụ build (biên dịch code).
  • C (CloudFormation) — IaC (SAM builds on it). / IaC (SAM xây trên nó).
  • D (CodeDeploy) — Deployment automation, not serverless-specific. / Tự động hóa triển khai, không riêng serverless.

🔑 Key Concept / Khái niệm cốt lõi: SAM = serverless app build/test/deploy framework. / SAM = framework build/test/deploy ứng dụng serverless.


Domain Distribution

Q59.

Which of the following are among AWS's pricing principles? (Select THREE)

Bản dịch tiếng Việt: Điều nào sau đây nằm trong số các nguyên tắc định giá của AWS? (Chọn BA)

A. Pay less as you use more (volume discounts) B. Pay upfront for all services before use C. Pay as you go without long-term commitment D. AWS guarantees fixed pricing forever E. Pay less when you reserve capacity

Correct answer: A, C, E Bản dịch đáp án đúng: A. Trả ít hơn khi bạn sử dụng nhiều hơn (giảm giá theo số lượng); C. Thanh toán theo mức sử dụng mà không cần cam kết lâu dài; E. Trả ít hơn khi bạn dự trữ năng lực

🇬🇧 Explanation: A ("Pay less as you use more") — tiered/volume discounts and consolidated billing across accounts. C ("Pay as you go without long-term commitment") — On-Demand pricing, ideal for new apps and unpredictable demand. E ("Pay less when you reserve capacity") — Reserved Instances save 40-72% with a 1-3 year commitment.

🇻🇳 Giải thích: A ("dùng càng nhiều trả càng ít") — giảm giá theo bậc/khối lượng và gộp hóa đơn giữa các tài khoản. C ("trả theo mức dùng không cam kết dài hạn") — giá On-Demand, lý tưởng cho app mới và nhu cầu khó đoán. E ("trả ít hơn khi đặt trước capacity") — Reserved Instances tiết kiệm 40-72% với cam kết 1-3 năm.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B (Pay upfront for all services before use) — Opposite of cloud's pay-per-use model. / Ngược với mô hình trả theo mức dùng của cloud.
  • D (AWS guarantees fixed pricing forever) — AWS reduces prices over time as it scales. / AWS giảm giá theo thời gian khi mở rộng.

🔑 Key Concept / Khái niệm cốt lõi: 4 principles: pay as you go, pay less per unit at scale, pay less when reserving, pay less as AWS grows. / 4 nguyên tắc: trả theo dùng, đơn giá giảm theo quy mô, trả ít khi đặt trước, trả ít hơn khi AWS lớn lên.

📚 Reference: Domain 4 study guide


Q60.

Which support plans include 24/7 phone and chat support? (Select TWO)

Bản dịch tiếng Việt: Những gói hỗ trợ nào bao gồm hỗ trợ qua điện thoại và trò chuyện 24/7? (Chọn HAI)

A. Basic Plan B. Developer Plan C. Business Plan D. Enterprise Plan E. Startup Plan

Correct answer: C, D Bản dịch đáp án đúng: C. Kế hoạch kinh doanh; D. Kế hoạch doanh nghiệp

🇬🇧 Explanation: C (Business Plan) and D (Enterprise Plan) both include 24/7 phone and chat support. Enterprise additionally provides a Technical Account Manager (TAM).

🇻🇳 Giải thích: C (Business Plan) và D (Enterprise Plan) đều bao gồm hỗ trợ điện thoại và chat 24/7. Enterprise còn có thêm Technical Account Manager (TAM).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Basic Plan) — Email/forums only, no phone/chat. / Chỉ email/diễn đàn, không điện thoại/chat.
  • B (Developer Plan) — Email only (business hours), no phone. / Chỉ email (giờ hành chính), không điện thoại.
  • E (Startup Plan) — Not an official plan. / Không phải gói chính thức.

🔑 Key Concept / Khái niệm cốt lõi: 24/7 phone/chat = Business and Enterprise plans. / Điện thoại/chat 24/7 = gói Business và Enterprise.

📚 Reference: Domain 4 study guide


Q61.

Which AWS tool helps estimate costs before deploying resources?

Bản dịch tiếng Việt: Công cụ AWS nào giúp ước tính chi phí trước khi triển khai tài nguyên?

A. AWS Cost Explorer B. AWS Pricing Calculator C. AWS Budgets D. AWS Cost Anomaly Detection

Correct answer: B Bản dịch đáp án đúng: B. Công cụ tính giá AWS

🇬🇧 Explanation: The AWS Pricing Calculator is an online tool to estimate costs before deploying — select services, region, and usage to get a monthly estimate for budgeting.

🇻🇳 Giải thích: AWS Pricing Calculator là công cụ online để ước tính chi phí trước khi triển khai — chọn dịch vụ, region, mức dùng để có ước tính hằng tháng phục vụ lập ngân sách.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • A (Cost Explorer) — Historical cost tracking, not pre-deployment. / Theo dõi chi phí lịch sử, không phải trước triển khai.
  • C (Budgets) — Alert system, not a calculator. / Hệ thống cảnh báo, không phải máy tính.
  • D (Anomaly Detection) — Detect unusual spending, not estimate. / Phát hiện chi tiêu bất thường, không ước tính.

🔑 Key Concept / Khái niệm cốt lõi: Pricing Calculator = estimate before deploy. / Pricing Calculator = ước tính trước khi triển khai.


Q62.

Which of the following are functions of AWS Cost Explorer? (Select TWO)

Bản dịch tiếng Việt: Chức năng nào sau đây là của AWS Cost Explorer? (Chọn HAI)

A. Monitor and track AWS spending over time B. Automatically apply discounts to lower your monthly invoice C. Automatically patch EC2 instances D. View costs broken down by service, region, or tag E. Manage IAM permissions

Correct answer: A, D Bản dịch đáp án đúng: A. Giám sát và theo dõi chi tiêu AWS theo thời gian; D. Xem chi phí được chia nhỏ theo dịch vụ, khu vực hoặc thẻ

🇬🇧 Explanation: A ("Monitor and track AWS spending over time") — historical cost tracking (daily/monthly/yearly). D ("View costs broken down by service, region, or tag") — group and filter costs (EC2 $100, S3 $50; by region, tag, linked account).

🇻🇳 Giải thích: A ("giám sát và theo dõi chi tiêu AWS theo thời gian") — theo dõi chi phí lịch sử (ngày/tháng/năm). D ("xem chi phí phân theo dịch vụ, region hoặc tag") — nhóm và lọc chi phí (EC2 $100, S3 $50; theo region, tag, tài khoản liên kết).

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B (Automatically apply discounts) — Cost Explorer only visualizes/analyzes; discounts come from RIs/Savings Plans. / Cost Explorer chỉ trực quan hóa/phân tích; giảm giá đến từ RI/Savings Plans.
  • C (Automatically patch EC2) — That's Systems Manager Patch Manager. / Đó là Systems Manager Patch Manager.
  • E (Manage IAM permissions) — That's IAM. / Đó là IAM.

🔑 Key Concept / Khái niệm cốt lõi: Cost Explorer = visualize/track spending by service, region, tag. / Cost Explorer = trực quan hóa/theo dõi chi tiêu theo dịch vụ, region, tag.


Q63.

Which AWS tools help manage and optimize cloud spending? (Select TWO)

Bản dịch tiếng Việt: Công cụ AWS nào giúp quản lý và tối ưu hóa chi tiêu trên đám mây? (Chọn HAI)

A. AWS Budgets B. Amazon Rekognition C. AWS CloudTrail D. Cost Allocation Tags E. AWS CloudWatch

Correct answer: A, D Bản dịch đáp án đúng: A. Ngân sách AWS; D. Thẻ phân bổ chi phí

🇬🇧 Explanation: A (AWS Budgets) lets you set spending limits and get alerts ("alert me if spending >$100/month"). D (Cost Allocation Tags) let you tag resources (team, project, environment) to track spending by tag and identify expensive projects/teams.

🇻🇳 Giải thích: A (AWS Budgets) cho phép đặt hạn mức chi tiêu và nhận cảnh báo ("báo tôi nếu chi tiêu >$100/tháng"). D (Cost Allocation Tags) cho phép gắn tag tài nguyên (nhóm, dự án, môi trường) để theo dõi chi tiêu theo tag và nhận diện dự án/nhóm tốn kém.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B (Amazon Rekognition) — Image/video analysis (computer vision), unrelated to cost. / Phân tích ảnh/video (thị giác máy tính), không liên quan chi phí.
  • C (AWS CloudTrail) — Audit logging, not cost management. / Ghi nhật ký kiểm toán, không quản chi phí.
  • E (AWS CloudWatch) — Monitoring metrics, not cost management. / Giám sát metrics, không quản chi phí.

🔑 Key Concept / Khái niệm cốt lõi: Budgets + Cost Allocation Tags = spend control and attribution. / Budgets + Cost Allocation Tags = kiểm soát và phân bổ chi tiêu.


Q64.

Which of the following are features of AWS Trusted Advisor? (Select THREE)

Bản dịch tiếng Việt: Tính năng nào sau đây là của AWS Trusted Advisor? (Chọn BA)

A. Checking cost optimization opportunities B. Identifying security vulnerabilities C. Monitoring real-time performance metrics D. Verifying service limits E. Encrypting data at rest

Correct answer: A, B, D Bản dịch đáp án đúng: A. Kiểm tra các cơ hội tối ưu hóa chi phí; B. Xác định các lỗ hổng bảo mật; D. Xác minh giới hạn dịch vụ

🇬🇧 Explanation: A ("Checking cost optimization opportunities") — e.g., unused EIPs or Reserved Instance savings. B ("Identifying security vulnerabilities") — e.g., open security group ports. D ("Verifying service limits") — e.g., approaching the EC2 instance limit.

🇻🇳 Giải thích: A ("kiểm tra cơ hội tối ưu chi phí") — ví dụ EIP không dùng hay tiết kiệm Reserved Instances. B ("nhận diện lỗ hổng bảo mật") — ví dụ cổng security group bị mở. D ("kiểm tra giới hạn dịch vụ") — ví dụ sắp chạm giới hạn EC2 instance.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • C (Real-time performance metrics) — That's CloudWatch; Trusted Advisor runs periodic checks. / Đó là CloudWatch; Trusted Advisor chạy kiểm tra định kỳ.
  • E (Encrypting data at rest) — That's KMS/S3 encryption; Trusted Advisor only checks if encryption is enabled. / Đó là mã hóa KMS/S3; Trusted Advisor chỉ kiểm tra xem đã bật mã hóa chưa.

🔑 Key Concept / Khái niệm cốt lõi: Trusted Advisor categories: cost, performance, security, fault tolerance, service limits. / Nhóm của Trusted Advisor: chi phí, hiệu năng, bảo mật, chịu lỗi, giới hạn dịch vụ.

📚 Reference: Domain 4 study guide


Q65.

Which of the following correctly describe AWS support plans? (Select TWO)

Bản dịch tiếng Việt: Câu nào sau đây mô tả chính xác các gói hỗ trợ của AWS? (Chọn HAI)

A. Enterprise plan includes a Technical Account Manager (TAM) B. All plans include access to Trusted Advisor with full checks C. Developer plan provides 1-hour response time for urgent issues D. Business plan offers 24/7 phone support E. Basic plan offers email support

Correct answer: A, D Bản dịch đáp án đúng: A. Gói doanh nghiệp bao gồm Trình quản lý tài khoản kỹ thuật (TAM); D. Kế hoạch kinh doanh cung cấp hỗ trợ qua điện thoại 24/7

🇬🇧 Explanation: A ("Enterprise plan includes a Technical Account Manager (TAM)") — a dedicated person providing proactive support and architecture advice, Enterprise only. D ("Business plan offers 24/7 phone support") — both Business and Enterprise include 24/7 phone support.

🇻🇳 Giải thích: A ("gói Enterprise có Technical Account Manager (TAM)") — một người chuyên trách cung cấp hỗ trợ chủ động và tư vấn kiến trúc, chỉ ở Enterprise. D ("gói Business có hỗ trợ điện thoại 24/7") — cả Business và Enterprise đều có hỗ trợ điện thoại 24/7.

❌ Why others are wrong / Vì sao đáp án khác sai:

  • B (All plans include full Trusted Advisor) — Only Business/Enterprise get full checks; Basic/Developer get 7 core checks. / Chỉ Business/Enterprise có đầy đủ; Basic/Developer chỉ có 7 kiểm tra cốt lõi.
  • C (Developer plan: 1-hour response) — Developer has no SLA response times; Business has 1-hour for production down. / Developer không có SLA thời gian phản hồi; Business có 1 giờ cho production down.
  • E (Basic plan offers email support) — Basic has community forums only; Developer has email. / Basic chỉ có diễn đàn cộng đồng; Developer mới có email.

🔑 Key Concept / Khái niệm cốt lõi: TAM = Enterprise only; 24/7 phone = Business + Enterprise. / TAM = chỉ Enterprise; điện thoại 24/7 = Business + Enterprise.

📚 Reference: Domain 4 study guide



Summary

Multi-Response Questions (20 total):

DomainCountQ Numbers
D13Q5, Q7, Q13
D25Q19, Q23, Q27, Q31, Q34
D36Q40, Q43, Q47, Q50, Q53, Q57
D46Q59, Q60, Q62, Q63, Q64, Q65
TOTAL20

Exam Breakdown:

  • Total: 65 questions
  • Multiple Choice (MC): 45 questions (1 answer each)
  • Multi-Response (MR): 20 questions (2–3 answers each)
  • Passing: 700/1000 (68%)

Performance Target:

  • MC: 80%+ accuracy
  • MR: 90%+ accuracy (harder; ensure you read all options)

End of Solutions

Next Step: Compare your answers. For each wrong answer, review the corresponding knowledge file section. Aim for 80%+ on full-length practice exams before attempting the real CLF-C02.