CLF-C02 Mock Exam #08 — Solutions with Trap Analysis
Theme: Subtle wording, "BEST" vs "VALID", common gotchas in CLF-C02
This guide teaches you to RECOGNIZE and AVOID trap patterns — a critical exam skill.
How to Use This Guide
For EACH question, the solution explains:
- Correct Answer — with why it's best
- 🪤 Trap(s) — what mistake the test is catching
- Why distractors are tempting — the trap mechanics
- Knowledge reference — which domain/concept to review
🪤 Trap icon marks questions designed to catch common misunderstandings.
Domain 1: Cloud Concepts — Solutions (Q1–Q16)
Domain 1: Cloud Concepts (Q1–Q16)
Q1.
A company wants to deploy a web application that automatically scales based on traffic. Which benefit of cloud computing does this BEST demonstrate?
Bản dịch tiếng Việt: Một công ty muốn triển khai một ứng dụng web tự động mở rộng quy mô dựa trên lưu lượng truy cập. Lợi ích nào của điện toán đám mây thể hiện TỐT NHẤT này?
A. Ability to purchase servers at lower prices B. Ability to gain competitive advantage through rapid deployment C. Ability to trade capital expenditure for operational expenditure D. Ability to stop guessing capacity requirements
Correct answer: D Bản dịch đáp án đúng: D. Khả năng ngừng đoán yêu cầu năng lực
🇬🇧 Explanation:
The scenario describes automatic scaling, which solves the problem of "guessing capacity requirements." While A, B, C are valid benefits of cloud, only D directly addresses automatic scaling's purpose.
🇻🇳 Giải thích:
Tình huống mô tả việc tự động scaling — chính là giải quyết vấn đề "đoán mò dung lượng" (guess capacity). A, B, C đều là lợi ích hợp lệ (valid) của cloud, nhưng chỉ D đúng trực tiếp với mục đích của auto-scaling. Đây là bẫy 🪤 "BEST vs VALID": nhiều đáp án đúng về mặt lý thuyết, nhưng bạn phải chọn cái sát nhất với kịch bản.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (lower prices) — True benefit but not what this scenario shows / Đúng là lợi ích, nhưng không phải điều kịch bản này minh họa
- B (competitive advantage) — Too general / Quá chung chung
- C (CapEx→OpEx) — True but not the KEY benefit here / Đúng nhưng không phải lợi ích chính ở đây
🔑 Key Concept / Khái niệm cốt lõi: Auto-scaling = "stop guessing capacity" / Auto-scaling chính là lợi ích "ngừng đoán mò dung lượng"
📚 Reference: Domain 1 | Advantages of Cloud Computing
Q2.
Which of the following CORRECTLY describes the relationship between an AWS Region and an Availability Zone?
Bản dịch tiếng Việt: Câu nào sau đây mô tả ĐÚNG mối quan hệ giữa AWS Region và Availability Zone?
A. A Region contains multiple Availability Zones, each containing isolated data centers B. An Availability Zone is a physical location that spans multiple Regions C. Regions and Availability Zones are the same thing in different terminology D. A Region is contained within a single Availability Zone
Correct answer: A Bản dịch đáp án đúng: A. Một AWS Region chứa nhiều Availability Zone, mỗi Vùng chứa các trung tâm dữ liệu biệt lập
🇬🇧 Explanation:
A Region contains 2+ Availability Zones. Each AZ contains one or more isolated data centers. This is the foundational geography of AWS infrastructure.
🇻🇳 Giải thích:
Một Region chứa từ 2 Availability Zones (AZ) trở lên. Mỗi AZ lại chứa một hoặc nhiều data center độc lập. Đây là nền tảng địa lý của hạ tầng AWS. Bẫy 🪤 ở đây là nhầm lẫn Region với AZ — hãy nhớ mô hình phân cấp: Quốc gia (Region) → Tỉnh (AZ) → Thành phố (Data Center).
❌ Why others are wrong / Vì sao đáp án khác sai:
- B — AZ doesn't span Regions; it's contained within one / AZ không trải rộng qua nhiều Region, nó nằm gọn trong một Region
- C — They have a parent-child relationship, not equivalence / Quan hệ cha-con, không phải tương đương
- D — A Region contains MULTIPLE AZs, not just one / Một Region chứa NHIỀU AZ, không chỉ một
🔑 Key Concept / Khái niệm cốt lõi: Region ≥ 2 AZs; AZ ≥ 1 data center / Region ≥ 2 AZ; mỗi AZ ≥ 1 data center
📚 Reference: Domain 1 | AWS Global Infrastructure
Q3. (Select TWO)
Which of the following are characteristics of AWS Edge Locations that DISTINGUISH them from AWS Regions? (Select TWO)
Bản dịch tiếng Việt: Đặc điểm nào sau đây là đặc điểm của Edge Location AWS giúp phân biệt chúng với AWS Region? (Chọn HAI)
A. Edge Locations are used by CloudFront to cache content closer to users B. Edge Locations are used to deploy and scale applications C. There are more Edge Locations worldwide than Regions D. Edge Locations provide database storage capabilities E. Edge Locations reduce latency for content delivery
Correct answer: A, C Bản dịch đáp án đúng: A. CloudFront sử dụng Edge Locations để lưu nội dung vào bộ nhớ đệm gần hơn với người dùng; C. Có nhiều Edge Location trên toàn thế giới hơn Region
🇬🇧 Explanation:
A — CloudFront uses Edge Locations to cache content globally. C — There are ~500+ Edge Locations worldwide vs ~30 Regions. The trap 🪤 is "Edge Locations ≠ Regions": Edge Locations are for CDN (CloudFront), NOT for compute or databases.
🇻🇳 Giải thích:
A — CloudFront dùng Edge Locations để cache nội dung trên toàn cầu. C — Có khoảng 500+ Edge Locations trên thế giới so với ~30 Regions. Bẫy 🪤 ở đây là nhầm Edge Location với Region: Edge Location chỉ dùng cho CDN (CloudFront), KHÔNG dùng để chạy compute hay lưu database.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B — Apps deploy in Regions/AZs, not Edge Locations / Ứng dụng chạy ở Region/AZ, không phải Edge Location
- D — Edge Locations cache content, they don't store databases / Edge Location cache nội dung, không lưu database
- E — True but NOT a distinguishing feature (Regions also reduce latency) / Đúng nhưng không phải đặc điểm phân biệt (Region cũng giảm latency)
🔑 Key Concept / Khái niệm cốt lõi: Edge Location = CDN caching, not compute/DB / Edge Location dùng để cache CDN, không phải compute/database
📚 Reference: Domain 1 | Edge Locations vs Regions
Q4.
A startup is deciding between hosting on-premises versus using AWS. Which statement BEST explains the CapEx-to-OpEx shift?
Bản dịch tiếng Việt: Một công ty khởi nghiệp đang quyết định giữa việc lưu trữ tại chỗ và sử dụng AWS. Tuyên bố nào TỐT NHẤT giải thích sự thay đổi CapEx-to-OpEx?
A. AWS eliminates all capital costs by sharing infrastructure B. AWS shifts from upfront hardware purchases to monthly subscription payments C. AWS requires less operational expense but higher capital expense D. AWS reduces total cost of ownership by eliminating labor costs
Correct answer: B Bản dịch đáp án đúng: B. AWS chuyển từ mua phần cứng trả trước sang thanh toán đăng ký hàng tháng
🇬🇧 Explanation:
CapEx-to-OpEx shift means moving from large upfront hardware purchases to monthly operational expenses (cloud subscription).
🇻🇳 Giải thích:
Chuyển từ CapEx sang OpEx nghĩa là không còn mua phần cứng trả trước số lớn, mà chuyển sang chi phí vận hành hàng tháng (thuê bao cloud). Bẫy 🪤 ở đây là kiểu "overgeneralization" — các đáp án dùng từ tuyệt đối như "all", "eliminates" hiếm khi đúng trong cloud, bạn luôn phải để ý sắc thái (nuance).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — "eliminates all capital costs" is too extreme (you still pay AWS, just not directly) / "Loại bỏ toàn bộ chi phí vốn" là quá tuyệt đối (bạn vẫn trả tiền cho AWS, chỉ là không trực tiếp)
- C — Reversed: OpEx goes up, CapEx goes down in cloud / Ngược: trong cloud OpEx tăng, CapEx giảm
- D — Labor costs don't disappear; they shift from hardware maintenance to cloud operations / Chi phí nhân công không biến mất, chỉ chuyển từ bảo trì phần cứng sang vận hành cloud
🔑 Key Concept / Khái niệm cốt lõi: Watch out for absolute words ("all", "eliminates") / Cảnh giác với từ tuyệt đối ("all", "eliminates")
📚 Reference: Domain 1 | Cloud Computing Benefits
Q5.
Which AWS service allows defining infrastructure using code templates and is considered Infrastructure as Code?
Bản dịch tiếng Việt: Dịch vụ AWS nào cho phép xác định cơ sở hạ tầng bằng cách sử dụng mẫu mã và được coi Cơ sở hạ tầng là Mã?
A. AWS CloudWatch B. AWS CloudFormation C. AWS Elastic Beanstalk D. AWS Systems Manager
Correct answer: B Bản dịch đáp án đúng: B. Đám mây AWSFormation
🇬🇧 Explanation:
AWS CloudFormation is the Infrastructure-as-Code service. You write JSON/YAML templates to define infrastructure.
🇻🇳 Giải thích:
AWS CloudFormation là dịch vụ Infrastructure-as-Code (IaC). Bạn viết template bằng JSON/YAML để định nghĩa hạ tầng. Bẫy 🪤 ở đây là các tên dịch vụ na ná nhau (CloudWatch, CloudFormation) dễ gây nhầm.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (CloudWatch) — Monitoring, not IaC / Giám sát, không phải IaC
- C (Elastic Beanstalk) — PaaS that abstracts infra, but not explicitly IaC / PaaS trừu tượng hóa hạ tầng, nhưng không phải IaC đúng nghĩa
🔑 Key Concept / Khái niệm cốt lõi: CloudFormation = JSON/YAML IaC templates / CloudFormation = template IaC bằng JSON/YAML
📚 Reference: Domain 1 | Infrastructure as Code
Q6. (Select TWO)
A company needs to ensure an application remains available even if an entire data center fails. Which of the following would BEST achieve this? (Select TWO)
Bản dịch tiếng Việt: Công ty cần đảm bảo ứng dụng vẫn khả dụng ngay cả khi toàn bộ trung tâm dữ liệu bị lỗi. Điều nào sau đây TỐT NHẤT sẽ đạt được điều này? (Chọn HAI)
A. Deploy the application in a single AWS Region with one Availability Zone B. Deploy the application across multiple Availability Zones in the same Region C. Deploy the application in a single Availability Zone with Auto Scaling enabled D. Deploy the application across multiple AWS Regions E. Deploy the application on-premises with cloud backup
Correct answer: B, D Bản dịch đáp án đúng: B. Triển khai ứng dụng trên nhiều Availability Zone trong cùng một Region; D. Triển khai ứng dụng trên nhiều AWS Region
🇬🇧 Explanation:
B — Multi-AZ deployment within the same Region tolerates data center failure. D — Multi-Region deployment is the ultimate high availability. The trap 🪤 is confusing Auto Scaling with High Availability: Auto Scaling adds CAPACITY, not REDUNDANCY. If the AZ fails, no amount of auto-scaling saves you — the whole AZ is gone.
🇻🇳 Giải thích:
B — Triển khai Multi-AZ trong cùng một Region giúp chịu được lỗi data center. D — Triển khai Multi-Region là mức high availability cao nhất. Bẫy 🪤 ở đây là nhầm Auto Scaling với High Availability: Auto Scaling thêm DUNG LƯỢNG (capacity), không phải DỰ PHÒNG (redundancy). Nếu cả AZ sập thì auto-scaling cũng vô dụng vì toàn bộ AZ đã mất.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — Single AZ = single point of failure / Một AZ duy nhất = điểm lỗi đơn
- C — Single AZ + Auto Scaling doesn't help if the AZ goes down / Một AZ + Auto Scaling vô ích nếu AZ đó sập
- E — On-premises backup doesn't guarantee AWS availability / Backup on-premises không đảm bảo tính sẵn sàng trên AWS
🔑 Key Concept / Khái niệm cốt lõi: Auto Scaling ≠ Fault Tolerance; Multi-AZ/Multi-Region = Fault Tolerance / Auto Scaling ≠ chịu lỗi; Multi-AZ/Multi-Region mới là chịu lỗi
📚 Reference: Domain 1 | Availability Zones, High Availability
Q7.
Which statement CORRECTLY reflects the AWS Well-Architected Framework's focus on Operational Excellence?
Bản dịch tiếng Việt: Tuyên bố nào phản ánh ĐÚNG CÁCH sự tập trung của AWS Well-Architected Framework vào Hoạt động xuất sắc?
A. It requires all workloads to run on EC2 instances B. It emphasizes the ability to run and monitor systems to deliver business value C. It eliminates the need for automation D. It mandates the use of AWS Outposts for all deployments
Correct answer: B Bản dịch đáp án đúng: B. Nó nhấn mạnh khả năng vận hành và giám sát các hệ thống để mang lại giá trị kinh doanh
🇬🇧 Explanation:
The Operational Excellence pillar focuses on running and monitoring systems to deliver business value and continuously improve processes.
🇻🇳 Giải thích:
Trụ cột Operational Excellence tập trung vào việc vận hành và giám sát hệ thống để tạo ra giá trị kinh doanh và liên tục cải tiến quy trình. Bẫy 🪤 ở đây là nhầm Operational Excellence với Cost Optimization và gán các yêu cầu cứng nhắc không tồn tại.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — Doesn't mandate EC2 (serverless is also operational excellence) / Không bắt buộc dùng EC2 (serverless cũng là OE)
- C — OE actually REQUIRES automation / OE thực ra YÊU CẦU tự động hóa
- D — Doesn't mandate Outposts / Không bắt buộc dùng Outposts
🔑 Key Concept / Khái niệm cốt lõi: Operational Excellence = run, monitor, improve / Operational Excellence = vận hành, giám sát, cải tiến
📚 Reference: Domain 1 | Well-Architected Framework
Q8.
According to the AWS Shared Responsibility Model, which of the following is EXCLUSIVELY the customer's responsibility?
Bản dịch tiếng Việt: Theo Mô hình trách nhiệm chung của AWS, trách nhiệm nào sau đây ĐỘC QUYỀN của khách hàng?
A. Patching the hypervisor that EC2 runs on B. Patching the operating system installed on an EC2 instance C. Securing the physical data center where servers are located D. Maintaining the network infrastructure between AWS Regions
Correct answer: B Bản dịch đáp án đúng: B. Vá hệ điều hành được cài đặt trên phiên bản EC2
🇬🇧 Explanation:
Under the Shared Responsibility Model, the customer patches the guest OS on EC2 instances, while AWS patches the hypervisor. This is one of the TOP traps on CLF-C02.
🇻🇳 Giải thích:
Theo Shared Responsibility Model, khách hàng chịu trách nhiệm vá (patch) hệ điều hành guest OS trên EC2, còn AWS lo phần hypervisor. Đây là một trong những bẫy 🪤 hay gặp nhất trong CLF-C02— bạn phải nhớ rõ "ai vá cái gì".
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — Hypervisor is infrastructure (AWS's job) / Hypervisor thuộc hạ tầng, là việc của AWS
- C — AWS's responsibility / Trách nhiệm của AWS
- D — AWS's responsibility / Trách nhiệm của AWS
🔑 Key Concept / Khái niệm cốt lõi: EC2 OS patching = customer; hypervisor = AWS / Vá OS của EC2 = khách hàng; hypervisor = AWS
📚 Reference: Domain 2 | Shared Responsibility Model
Q9. (Select THREE)
Which of the following are valid service models of cloud computing? (Select THREE)
Bản dịch tiếng Việt: Mô hình nào sau đây là mô hình dịch vụ hợp lệ của điện toán đám mây? (Chọn BA)
A. IaaS (Infrastructure as a Service) B. PaaS (Platform as a Service) C. SaaS (Software as a Service) D. MaaS (Maintenance as a Service) E. DaaS (Database as a Service)
Correct answer: A, B, C Bản dịch đáp án đúng: A. IaaS (Cơ sở hạ tầng như một dịch vụ); B. PaaS (Nền tảng là một dịch vụ); C. SaaS (Phần mềm dưới dạng dịch vụ)
🇬🇧 Explanation:
IaaS, PaaS, and SaaS are the 3 standard cloud service models. The trap 🪤 is fake service models: "MaaS" and "DaaS" are distractors testing whether you memorized the official three.
🇻🇳 Giải thích:
IaaS, PaaS và SaaS là 3 mô hình dịch vụ cloud chuẩn. Bẫy 🪤 ở đây là các mô hình "giả": "MaaS" và "DaaS" là đáp án nhiễu để kiểm tra xem bạn có nhớ chính xác 3 mô hình chính thức hay không.
❌ Why others are wrong / Vì sao đáp án khác sai:
- D — "MaaS" is not a standard model (made up) / "MaaS" không phải mô hình chuẩn (bịa ra)
- E — "DaaS" used informally but not in official AWS definitions / "DaaS" đôi khi dùng không chính thức, nhưng không có trong định nghĩa chính thức của AWS
🔑 Key Concept / Khái niệm cốt lõi: Only IaaS, PaaS, SaaS are official / Chỉ có IaaS, PaaS, SaaS là chính thức
📚 Reference: Domain 1 | Cloud Service Models (IaaS/PaaS/SaaS)
Q10.
A company wants to migrate legacy applications to AWS with MINIMAL re-architecture. Which migration strategy is MOST appropriate?
Bản dịch tiếng Việt: Một công ty muốn di chuyển các ứng dụng cũ sang AWS với kiến trúc lại TỐI THIỂU. Chiến lược di chuyển nào là phù hợp NHẤT?
A. Retire B. Retain C. Rehost (Lift-and-shift) D. Refactor
Correct answer: C Bản dịch đáp án đúng: C. Rehost (lift-and-shift)
🇬🇧 Explanation:
Rehost (lift-and-shift) means moving applications to AWS with minimal changes — perfect for legacy apps where re-architecture is not desired.
🇻🇳 Giải thích:
Rehost (lift-and-shift) nghĩa là chuyển ứng dụng lên AWS với thay đổi tối thiểu — lý tưởng cho ứng dụng legacy mà bạn không muốn tái kiến trúc. Bẫy 🪤 ở đây là phải phân biệt được "6 Rs" trong chiến lược migration: Retire (gỡ bỏ), Retain (giữ on-premises), Rehost (chuyển nguyên trạng), Refactor (tái kiến trúc), Repurchase (thay bằng SaaS), Replatform (tối ưu một phần).
❌ Why others are wrong / Vì sao đáp án khác sai:
- Refactor — Re-architect for cloud (more effort) / Tái kiến trúc cho cloud (tốn công hơn)
- Repurchase — Replace with a SaaS product / Thay bằng sản phẩm SaaS
- Replatform — Some optimizations, not minimal / Tối ưu một phần, không phải tối thiểu
🔑 Key Concept / Khái niệm cốt lõi: Rehost = move as-is, minimal change / Rehost = chuyển nguyên trạng, thay đổi tối thiểu
📚 Reference: Domain 1 | Migration Strategies
Q11.
An organization wants to distribute content (images, videos) to users globally with LOW latency. Which AWS component BEST serves this purpose?
Bản dịch tiếng Việt: Một tổ chức muốn phân phối nội dung (hình ảnh, video) tới người dùng trên toàn cầu với độ trễ THẤP. Thành phần AWS nào TỐT NHẤT phục vụ mục đích này?
A. AWS Regions B. AWS Availability Zones C. AWS Edge Locations used by CloudFront D. AWS Local Zones
Correct answer: C Bản dịch đáp án đúng: C. Edge Location AWS được CloudFront sử dụng
🇬🇧 Explanation:
CloudFront uses Edge Locations to cache and deliver content globally with low latency.
🇻🇳 Giải thích:
CloudFront dùng Edge Locations để cache và phân phối nội dung toàn cầu với độ trễ thấp. Bẫy 🪤 ở đây là nhầm lẫn giữa các tầng hạ tầng (Region, AZ, Edge Location, Local Zone).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Regions) — Too few for truly global low-latency / Quá ít để đạt độ trễ thấp thực sự toàn cầu
- B (AZs) — For disaster recovery, not global distribution / Dùng cho disaster recovery, không phải phân phối toàn cầu
- D (Local Zones) — Newer, for latency but not as widespread / Mới hơn, giảm latency nhưng không phủ rộng bằng
🔑 Key Concept / Khái niệm cốt lõi: Edge Locations = global content delivery / Edge Location = phân phối nội dung toàn cầu
📚 Reference: Domain 1 | CloudFront and Edge Locations
Q12.
Which of the following BEST describes the difference between scalability and elasticity?
Bản dịch tiếng Việt: Điều nào sau đây TỐT NHẤT mô tả sự khác biệt giữa khả năng mở rộng và độ co giãn?
A. They are the same concept with different names B. Scalability is vertical scaling; elasticity is horizontal scaling C. Scalability is the ability to handle growth; elasticity is the ability to automatically adjust resources D. Elasticity is permanent; scalability is temporary
Correct answer: C Bản dịch đáp án đúng: C. Khả năng mở rộng là khả năng xử lý sự tăng trưởng; tính co giãn là khả năng tự động điều chỉnh nguồn lực
🇬🇧 Explanation:
Scalability is the ability to handle growth (vertical or horizontal). Elasticity is the ability to automatically adjust resources dynamically. Memory trick: Scalability = "Can I grow?" (static); Elasticity = "Do I automatically grow/shrink?" (dynamic).
🇻🇳 Giải thích:
Scalability là khả năng xử lý tăng trưởng (theo chiều dọc vertical hoặc ngang horizontal). Elasticity là khả năng TỰ ĐỘNG điều chỉnh tài nguyên một cách linh hoạt. Bẫy 🪤 ở đây là coi hai khái niệm này như nhau. Mẹo nhớ: Scalability = "Tôi có thể lớn lên không?" (định nghĩa tĩnh); Elasticity = "Tôi có tự động co giãn không?" (hành động động).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — They're related but different / Liên quan nhưng khác nhau
- B — Scalability isn't limited to vertical / Scalability không chỉ giới hạn ở chiều dọc
- D — Both can be permanent or temporary / Cả hai đều có thể là vĩnh viễn hoặc tạm thời
🔑 Key Concept / Khái niệm cốt lõi: Elasticity adds the AUTO/dynamic part to scalability / Elasticity thêm yếu tố TỰ ĐỘNG/động vào scalability
📚 Reference: Domain 1 | Cloud Computing Concepts
Q13. (Select TWO)
Which of the following statements are TRUE regarding the AWS Global Infrastructure? (Select TWO)
Bản dịch tiếng Việt: Nhận định nào sau đây là ĐÚNG về Cơ sở hạ tầng toàn cầu của AWS? (Chọn HAI)
A. CloudFront uses Edge Locations to cache and deliver content globally B. DynamoDB tables MUST be deployed in multiple Regions for replication C. Availability Zones are connected by low-latency network links within a Region D. Regions are geographically isolated and do not share network infrastructure E. Every AWS Region automatically includes Local Zones by default
Correct answer: A, C Bản dịch đáp án đúng: A. CloudFront sử dụng Edge Locations để lưu vào bộ nhớ đệm và phân phối nội dung trên toàn cầu; C. Availability Zone được kết nối bằng các liên kết mạng có độ trễ thấp trong một Region
🇬🇧 Explanation:
A — CloudFront DOES use Edge Locations. C — AZs ARE connected by a low-latency network. The trap 🪤 is mandatory-vs-optional / absolute wording: the wrong options use "MUST" or "every... automatically" to disguise optional or select features as mandatory or universal ones.
🇻🇳 Giải thích:
A — CloudFront thực sự dùng Edge Locations. C — Các AZ được kết nối với nhau bằng mạng độ trễ thấp. Bẫy 🪤 ở đây là "bắt buộc vs tùy chọn" / từ ngữ tuyệt đối: các đáp án sai dùng "PHẢI" (MUST) hoặc "mọi... tự động" để ngụy trang tính năng tùy chọn/giới hạn thành bắt buộc/phổ quát.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B — DynamoDB doesn't REQUIRE multi-Region; it's optional via Global Tables / DynamoDB không BẮT BUỘC multi-Region; đó là tùy chọn qua Global Tables
- D — Regions ARE interconnected over the AWS global backbone (not isolated) / Các Region được nối qua mạng backbone toàn cầu của AWS (không tách biệt)
- E — Local Zones are NOT automatic; they are opt-in and only in select metro areas / Local Zones KHÔNG tự động; phải bật và chỉ có ở một số khu đô thị nhất định
🔑 Key Concept / Khái niệm cốt lõi: Beware "MUST" / "every...automatically" wording / Cảnh giác từ ngữ "PHẢI" / "mọi...tự động"
📚 Reference: Domain 1 | Global Infrastructure
Q14.
Which pillar of the AWS Well-Architected Framework emphasizes using managed services to reduce operational burden?
Bản dịch tiếng Việt: Trụ cột nào của AWS Well-Architected Framework nhấn mạnh việc sử dụng các dịch vụ được quản lý để giảm bớt gánh nặng vận hành?
A. Operational Excellence B. Performance Efficiency C. Cost Optimization D. Sustainability
Correct answer: B Bản dịch đáp án đúng: B. Hiệu quả hoạt động
🇬🇧 Explanation:
The Performance Efficiency pillar emphasizes using the right resource type and managed services to reduce operational burden.
🇻🇳 Giải thích:
Trụ cột Performance Efficiency nhấn mạnh việc dùng đúng loại tài nguyên và các managed service để giảm gánh nặng vận hành. Bẫy 🪤 ở đây là gán nhầm trụ cột (pillar misattribution) — dễ lẫn với Operational Excellence hoặc Cost Optimization.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Operational Excellence) — About running systems, not resource efficiency / Về vận hành hệ thống, không phải hiệu quả tài nguyên
- C (Cost Optimization) — About spending wisely / Về chi tiêu hợp lý
- D (Sustainability) — About environmental impact / Về tác động môi trường
🔑 Key Concept / Khái niệm cốt lõi: Performance Efficiency = right tools (managed services, serverless) / Performance Efficiency = dùng đúng công cụ (managed service, serverless)
📚 Reference: Domain 1 | Well-Architected Framework Pillars
Q15.
A company implements auto-scaling to reduce the number of EC2 instances during low-traffic periods and add instances during peak traffic. Which cloud principle is this BEST demonstrating?
Bản dịch tiếng Việt: Một công ty triển khai tính năng tự động mở rộng quy mô để giảm số lượng phiên bản EC2 trong khoảng thời gian lưu lượng truy cập thấp và thêm phiên bản trong thời gian lưu lượng truy cập cao điểm. Nguyên tắc đám mây nào được thể hiện TỐT NHẤT?
A. Agility B. Elasticity C. High Availability D. Fault Tolerance
Correct answer: B Bản dịch đáp án đúng: B. độ đàn hồi
🇬🇧 Explanation:
Elasticity is the ability to automatically scale resources up or down based on demand — exactly what auto-scaling does.
🇻🇳 Giải thích:
Elasticity là khả năng tự động scaling tài nguyên lên hoặc xuống theo nhu cầu — chính là điều mà auto-scaling làm. Bẫy 🪤 ở đây là các khái niệm na ná nhau (Agility, High Availability, Fault Tolerance) dễ gây nhầm.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Agility) — Speed of innovation / Tốc độ đổi mới
- C (High Availability) — System stays up / Hệ thống luôn sẵn sàng
- D (Fault Tolerance) — System survives failures / Hệ thống chịu được lỗi
🔑 Key Concept / Khái niệm cốt lõi: Elasticity = automatic scale up/down on demand / Elasticity = tự động co giãn theo nhu cầu
📚 Reference: Domain 1 | Cloud Computing Characteristics
Q16.
According to the AWS 6 Advantages of Cloud Computing, which advantage is BEST described as "reducing time to launch new applications"?
Bản dịch tiếng Việt: Theo Ưu điểm của Điện toán đám mây AWS 6, ưu điểm nào được mô tả TỐT NHẤT là "giảm thời gian khởi chạy ứng dụng mới"?
A. Trade CapEx for OpEx B. Economies of scale C. Stop guessing capacity D. Increase speed and agility
Correct answer: D Bản dịch đáp án đúng: D. Tăng tốc độ và sự nhanh nhẹn
🇬🇧 Explanation:
"Increase speed and agility" means reducing time to launch. You can provision resources in minutes vs months on-premises.
🇻🇳 Giải thích:
"Tăng tốc độ và tính linh hoạt" (speed and agility) nghĩa là giảm thời gian để khởi chạy. Trên cloud bạn cấp phát tài nguyên trong vài phút thay vì hàng tháng như on-premises. Bẫy 🪤 ở đây là phải khớp đúng lợi ích cụ thể với kịch bản (specific advantage matching).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (CapEx→OpEx) — Financial, not time-to-market / Về tài chính, không phải thời gian ra thị trường
- B (Economies of scale) — Cost, not speed / Về chi phí, không phải tốc độ
- C (Stop guessing capacity) — About prediction, not speed / Về dự đoán dung lượng, không phải tốc độ
🔑 Key Concept / Khái niệm cốt lõi: Speed and agility = launch in minutes, not months / Speed and agility = khởi chạy trong vài phút, không phải vài tháng
📚 Reference: Domain 1 | 6 Advantages of Cloud Computing
Domain 2: Security and Compliance (Q17–Q36)
Q17.
In the AWS Shared Responsibility Model, which of the following is AWS responsible for?
Bản dịch tiếng Việt: Trong Mô hình trách nhiệm chung của AWS, AWS chịu trách nhiệm về nội dung nào sau đây?
A. Enabling encryption on S3 buckets B. Patching the operating system on an EC2 instance C. Patching the underlying hypervisor that powers EC2 D. Configuring IAM policies for user access
Correct answer: C Bản dịch đáp án đúng: C. Vá bộ ảo hóa cơ bản hỗ trợ EC2
🇬🇧 Explanation:
AWS is responsible for hypervisor security (infrastructure). The customer patches the OS (application level). This is a repeat of the Q8 trap — it's that important.
🇻🇳 Giải thích:
AWS chịu trách nhiệm bảo mật hypervisor (phần hạ tầng). Khách hàng vá hệ điều hành (mức ứng dụng). Đây là bẫy 🪤 lặp lại từ Q8 — quan trọng đến mức xuất hiện nhiều lần. Hãy nhớ rõ ranh giới Shared Responsibility.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — Customer enables encryption / Khách hàng bật mã hóa
- B — Customer patches OS / Khách hàng vá OS
- D — Customer configures failover / Khách hàng cấu hình failover
🔑 Key Concept / Khái niệm cốt lõi: AWS owns the hypervisor; customer owns OS/data/config / AWS lo hypervisor; khách hàng lo OS/dữ liệu/cấu hình
📚 Reference: Domain 2 | Shared Responsibility Model (Service-by-service)
Q18. (Select TWO)
Which of the following statements are CORRECT regarding IAM in AWS? (Select TWO)
Bản dịch tiếng Việt: Câu nào sau đây ĐÚNG về IAM trong AWS? (Chọn HAI)
A. IAM Users require passwords, but IAM Roles use temporary credentials B. IAM policies are region-specific and cannot be used across Regions C. The root account cannot be deleted and should be protected with MFA D. IAM automatically grants every new user full administrator access by default E. IAM must be configured separately in each Region you operate in
Correct answer: A, C Bản dịch đáp án đúng: A. Người dùng IAM yêu cầu mật khẩu, nhưng Vai trò IAM sử dụng thông tin xác thực tạm thời; C. Tài khoản root không thể bị xóa và cần được bảo vệ bằng MFA
🇬🇧 Explanation:
A — IAM Users sign in with passwords (or access keys); IAM Roles deliver short-lived temporary credentials. C — The root account cannot be deleted and AWS strongly recommends protecting it with MFA. The trap 🪤 targets IAM misconceptions: the "IAM is regional" myth and the assumption that cloud defaults are permissive.
🇻🇳 Giải thích:
A — IAM User đăng nhập bằng mật khẩu (hoặc access key); IAM Role cấp credential tạm thời ngắn hạn. C — Tài khoản root không thể xóa và AWS khuyến nghị mạnh việc bảo vệ nó bằng MFA. Bẫy 🪤 ở đây nhắm vào hai hiểu lầm về IAM: lầm tưởng "IAM theo Region" và lầm tưởng cloud mặc định cho phép (permissive). Thực ra IAM là dịch vụ toàn cầu và mặc định từ chối (default-deny).
❌ Why others are wrong / Vì sao đáp án khác sai:
- B — IAM is a GLOBAL service; policies aren't region-specific / IAM là dịch vụ TOÀN CẦU; policy không theo Region
- D — IAM is default-deny; a new user has NO permissions until you attach a policy / IAM mặc định từ chối; user mới KHÔNG có quyền gì cho tới khi bạn gắn policy
- E — IAM is global, not configured per-Region / IAM toàn cầu, không cấu hình theo từng Region
🔑 Key Concept / Khái niệm cốt lõi: IAM = global + default-deny (like Route 53, CloudFront) / IAM = toàn cầu + mặc định từ chối (giống Route 53, CloudFront)
📚 Reference: Domain 2 | IAM (global service, Users vs Roles, default-deny)
Q19.
A developer needs to give an application running on an EC2 instance permission to access an S3 bucket. What is the BEST approach?
Bản dịch tiếng Việt: Nhà phát triển cần cấp cho ứng dụng chạy trên phiên bản EC2 quyền truy cập vào bộ chứa S3. Cách tiếp cận TỐT NHẤT là gì?
A. Create an IAM User access key and store it in the application code B. Store the root account access key on the EC2 instance C. Attach an IAM Role to the EC2 instance with S3 permissions D. Share the root account credentials with the developer
Correct answer: C Bản dịch đáp án đúng: C. Đính kèm Vai trò IAM vào phiên bản EC2 với quyền S3
🇬🇧 Explanation:
Best practice: attach an IAM Role to the EC2 instance with S3 permissions. Roles use temporary credentials that are automatically rotated.
🇻🇳 Giải thích:
Cách làm tốt nhất: gắn một IAM Role có quyền truy cập S3 vào EC2 instance. Role dùng credential tạm thời được tự động xoay vòng (rotated). Bẫy 🪤 ở đây là "hardcode credentials" — đây là lỗ hổng bảo mật THẬT mà nhiều lập trình viên hay mắc.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — Storing access keys in code is a security risk / Lưu access key trong code là rủi ro bảo mật
- B — Never share root credentials / Không bao giờ chia sẻ credential root
- D — Never share credentials / Không bao giờ chia sẻ credential
🔑 Key Concept / Khái niệm cốt lõi: Use IAM Roles (temporary, auto-rotated), never hardcode keys / Dùng IAM Role (tạm thời, tự xoay vòng), đừng hardcode key
📚 Reference: Domain 2 | IAM Best Practices
Q20.
Which AWS service logs all API calls made to an AWS account and is used for auditing and compliance purposes?
Bản dịch tiếng Việt: Dịch vụ AWS nào ghi lại tất cả lệnh gọi API được thực hiện tới tài khoản AWS và được sử dụng cho mục đích kiểm tra và tuân thủ?
A. AWS CloudWatch B. AWS CloudTrail C. AWS Config D. AWS X-Ray
Correct answer: B Bản dịch đáp án đúng: B. Đường mòn đám mây AWS
🇬🇧 Explanation:
CloudTrail logs all API calls; CloudWatch logs metrics. CloudTrail answers "Who did what and when" (audit). This is a CRITICAL distinction for Domain 2.
🇻🇳 Giải thích:
CloudTrail ghi lại tất cả lệnh gọi API; CloudWatch ghi lại metric. CloudTrail trả lời câu hỏi "Ai làm gì, lúc nào" (audit). Đây là sự phân biệt CỰC KỲ quan trọng trong Domain 2. Bẫy 🪤 ở đây là nhầm CloudTrail với CloudWatch.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (CloudWatch) — Metrics and logs / Metric và log
- C (Config) — Configuration tracking / Theo dõi cấu hình
- D (X-Ray) — Application tracing / Truy vết ứng dụng
🔑 Key Concept / Khái niệm cốt lõi: CloudTrail = who/what/when API audit / CloudTrail = audit ai/làm gì/lúc nào trên API
📚 Reference: Domain 2 | CloudTrail
Q21.
A company wants to track configuration changes made to resources (e.g., when a security group was modified). Which service is BEST suited for this?
Bản dịch tiếng Việt: Một công ty muốn theo dõi các thay đổi cấu hình được thực hiện đối với tài nguyên (ví dụ: khi nhóm bảo mật được sửa đổi). Dịch vụ nào phù hợp nhất cho việc này?
A. AWS CloudTrail (logs API calls) B. AWS Config (tracks configuration changes) C. AWS CloudWatch (monitors metrics) D. AWS GuardDuty (detects threats)
Correct answer: B Bản dịch đáp án đúng: B. AWS Config (theo dõi các thay đổi về cấu hình)
🇬🇧 Explanation:
AWS Config tracks configuration changes over time (e.g., when a Security Group was modified). CloudTrail logs WHO made the change; Config tracks WHAT changed.
🇻🇳 Giải thích:
AWS Config theo dõi các thay đổi cấu hình theo thời gian (ví dụ: khi một Security Group bị sửa). CloudTrail ghi lại AI thực hiện thay đổi, còn Config theo dõi CÁI GÌ đã thay đổi. Bẫy 🪤 ở đây là nhầm mục đích của CloudTrail với Config.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (CloudTrail) — API calls, not config tracking / Lệnh gọi API, không phải theo dõi cấu hình
- C (CloudWatch) — Metrics / Metric
- D (GuardDuty) — Threats / Phát hiện mối đe dọa
🔑 Key Concept / Khái niệm cốt lõi: CloudTrail = API logs; Config = config change history / CloudTrail = log API; Config = lịch sử thay đổi cấu hình
📚 Reference: Domain 2 | AWS Config
Q22. (Select TWO)
Which of the following statements are CORRECT regarding CloudTrail and CloudWatch? (Select TWO)
Bản dịch tiếng Việt: Câu nào sau đây ĐÚNG về CloudTrail và CloudWatch? (Chọn HAI)
A. CloudTrail logs WHO did WHAT and WHEN B. CloudWatch is the primary service for auditing AWS account API call history C. Both CloudTrail and CloudWatch provide the same functionality D. CloudTrail records physical infrastructure changes made by AWS E. CloudWatch is used to monitor EC2 CPU utilization and set alarms
Correct answer: A, E Bản dịch đáp án đúng: A. Nhật ký CloudTrail AI đã làm CÁI GÌ và KHI NÀO; E. CloudWatch được dùng để giám sát việc sử dụng CPU EC2 và đặt cảnh báo
🇬🇧 Explanation:
A — CloudTrail logs WHO/WHAT/WHEN. E — CloudWatch monitors EC2 CPU utilization and sets alarms. The trap 🪤 is functional-overlap confusion: students mix CloudTrail and CloudWatch because both "log something," but CloudTrail = API audit, CloudWatch = metrics/monitoring.
🇻🇳 Giải thích:
A — CloudTrail ghi lại AI/CÁI GÌ/LÚC NÀO. E — CloudWatch giám sát mức sử dụng CPU của EC2 và đặt cảnh báo (alarm). Bẫy 🪤 ở đây là nhầm lẫn chức năng chồng chéo: nhiều bạn lẫn CloudTrail với CloudWatch vì cả hai đều "log gì đó", nhưng CloudTrail = audit API, còn CloudWatch = metric/giám sát.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B — Auditing API call history is CloudTrail's role, not CloudWatch's / Audit lịch sử lệnh gọi API là việc của CloudTrail, không phải CloudWatch
- C — They do DIFFERENT things / Chúng làm những việc KHÁC nhau
- D — CloudTrail logs API calls, not physical infrastructure changes / CloudTrail log lệnh API, không phải thay đổi hạ tầng vật lý
🔑 Key Concept / Khái niệm cốt lõi: CloudTrail = API audit; CloudWatch = metrics/monitoring / CloudTrail = audit API; CloudWatch = metric/giám sát
📚 Reference: Domain 2 | CloudTrail vs CloudWatch
Q23.
Which AWS service provides automatic DDoS protection for the AWS infrastructure WITHOUT additional charge?
Bản dịch tiếng Việt: Dịch vụ AWS nào cung cấp khả năng bảo vệ DDoS tự động cho cơ sở hạ tầng AWS mà KHÔNG tính thêm phí?
A. AWS Shield Standard B. AWS Shield Advanced C. AWS WAF (Web Application Firewall) D. AWS Security Groups
Correct answer: A Bản dịch đáp án đúng: A. Tiêu chuẩn lá chắn AWS
🇬🇧 Explanation:
AWS Shield Standard is free and provides automatic DDoS protection for all AWS customers. Shield Advanced is paid and provides enhanced protection.
🇻🇳 Giải thích:
AWS Shield Standard miễn phí và cung cấp bảo vệ DDoS tự động cho tất cả khách hàng AWS. Shield Advanced thì trả phí và cho bảo vệ nâng cao. Bẫy 🪤 ở đây là phân biệt Standard với Advanced (miễn phí vs trả phí).
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (Shield Advanced) — Paid (~$3K/month) / Trả phí (~3K USD/tháng)
- C (WAF) — Protects web apps, not infrastructure-level DDoS / Bảo vệ web app, không phải DDoS tầng hạ tầng
- D (Security Group) — Firewall, not DDoS protection / Tường lửa, không phải bảo vệ DDoS
🔑 Key Concept / Khái niệm cốt lõi: Shield Standard = free/automatic; Advanced = paid / Shield Standard = miễn phí/tự động; Advanced = trả phí
📚 Reference: Domain 2 | AWS Shield
Q24.
A company wants to protect its web application from attacks like SQL injection and cross-site scripting (XSS). Which service BEST addresses this?
Bản dịch tiếng Việt: Một công ty muốn bảo vệ ứng dụng web của mình khỏi các cuộc tấn công như SQL injection và Cross-site scripting (XSS). Dịch vụ nào TỐT NHẤT giải quyết vấn đề này?
A. AWS Shield Standard B. AWS WAF (Web Application Firewall) C. AWS Security Groups D. AWS GuardDuty
Correct answer: B Bản dịch đáp án đúng: B. AWS WAF (Tường lửa ứng dụng web)
🇬🇧 Explanation:
WAF protects against Layer 7 (application) attacks like SQL injection and XSS. Shield protects against Layer 3-4 DDoS attacks. SQL injection and XSS are Layer 7 attacks → use WAF.
🇻🇳 Giải thích:
WAF bảo vệ chống các cuộc tấn công Layer 7 (tầng ứng dụng) như SQL injection và XSS. Shield bảo vệ chống tấn công DDoS Layer 3-4. SQL injection và XSS là tấn công Layer 7 → dùng WAF. Bẫy 🪤 ở đây là nhầm tầng bảo vệ (protection layer).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Shield) — DDoS attacks (Layer 3-4) / Tấn công DDoS (Layer 3-4)
- C (Security Group) — Stateful firewall at IP/port level / Tường lửa stateful ở mức IP/port
- D (GuardDuty) — Threat detection, not active protection / Phát hiện mối đe dọa, không chủ động chặn
🔑 Key Concept / Khái niệm cốt lõi: WAF = Layer 7 (SQLi/XSS); Shield = Layer 3-4 DDoS / WAF = Layer 7 (SQLi/XSS); Shield = DDoS Layer 3-4
📚 Reference: Domain 2 | AWS WAF
Q25. (Select TWO)
Which of the following are CORRECT regarding AWS KMS (Key Management Service)? (Select TWO)
Bản dịch tiếng Việt: Điều nào sau đây ĐÚNG về AWS KMS (Dịch vụ quản lý khóa)? (Chọn HAI)
A. KMS is used to encrypt data at rest in S3, EBS, and RDS B. AWS KMS encryption CANNOT be used for real-time data protection C. KMS customer-managed keys can be exported in plaintext for offline backup D. KMS is free for all AWS customers E. KMS integrates with CloudTrail to log encryption key usage
Correct answer: A, E Bản dịch đáp án đúng: A. KMS được sử dụng để mã hóa dữ liệu ở phần còn lại trong S3, EBS và RDS; E. KMS tích hợp với CloudTrail để ghi lại việc sử dụng khóa mã hóa
🇬🇧 Explanation:
A — KMS encrypts S3, EBS, RDS. E — CloudTrail logs KMS key usage. The trap 🪤 combines KMS pricing and a key-material misconception: many free-tier users think all AWS services are free (KMS is not), and others wrongly believe they can extract raw key material.
🇻🇳 Giải thích:
A — KMS mã hóa S3, EBS, RDS. E — CloudTrail ghi lại việc sử dụng key của KMS. Bẫy 🪤 ở đây kết hợp hai hiểu lầm: về giá KMS và về key material. Nhiều người dùng free-tier tưởng mọi dịch vụ AWS đều miễn phí (KMS thì không), và một số tưởng có thể trích xuất key material thô — không được, vì KMS là dịch vụ dựa trên phần cứng, key luôn nằm trong KMS.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B — KMS encrypts real-time data (this statement is incorrect as posed) / Mệnh đề này sai theo cách diễn đạt
- C — KMS key material NEVER leaves KMS in plaintext; you can't export a customer-managed key as cleartext / Key material trong KMS KHÔNG bao giờ rời KMS dưới dạng plaintext; không thể export key dạng rõ
- D — KMS is NOT free (pay per key, per request) / KMS KHÔNG miễn phí (trả tiền theo key, theo request)
🔑 Key Concept / Khái niệm cốt lõi: KMS keys stay inside KMS; KMS is paid; CloudTrail logs key usage / Key của KMS luôn ở trong KMS; KMS trả phí; CloudTrail ghi log dùng key
📚 Reference: Domain 2 | AWS KMS
Q26.
A financial services company needs to comply with regulatory audits. Which AWS service provides pre-built compliance reports (e.g., SOC 2, PCI DSS)?
Bản dịch tiếng Việt: Một công ty dịch vụ tài chính cần phải tuân thủ kiểm toán theo quy định. Dịch vụ AWS nào cung cấp báo cáo tuân thủ dựng sẵn (ví dụ: SOC 2, PCI DSS)?
A. AWS Artifact B. AWS Trusted Advisor C. AWS Config D. AWS Inspector
Correct answer: A Bản dịch đáp án đúng: A. Cấu phần AWS
🇬🇧 Explanation:
AWS Artifact is a self-service portal for downloading compliance reports (SOC 2, PCI DSS, etc.).
🇻🇳 Giải thích:
AWS Artifact là cổng self-service để tải các báo cáo tuân thủ (compliance) như SOC 2, PCI DSS, v.v. Bẫy 🪤 ở đây là nhầm lẫn giữa các dịch vụ — hãy nhớ Artifact = tài liệu compliance.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (Trusted Advisor) — Best practice checks, not compliance reports / Kiểm tra best practice, không phải báo cáo compliance
- C (Config) — Configuration tracking / Theo dõi cấu hình
- D (Inspector) — EC2 vulnerability assessment / Đánh giá lỗ hổng EC2
🔑 Key Concept / Khái niệm cốt lõi: Artifact = compliance documents (SOC, PCI) / Artifact = tài liệu compliance (SOC, PCI)
📚 Reference: Domain 2 | AWS Artifact
Q27.
According to the Shared Responsibility Model, who is responsible for patching a MySQL database engine running on Amazon RDS?
Bản dịch tiếng Việt: Theo Mô hình trách nhiệm chung, ai chịu trách nhiệm vá công cụ cơ sở dữ liệu MySQL chạy trên Amazon RDS?
A. The customer is responsible B. AWS is responsible C. Both share the responsibility D. The responsibility depends on the RDS instance type
Correct answer: B Bản dịch đáp án đúng: B. AWS chịu trách nhiệm
🇬🇧 Explanation:
Under Shared Responsibility, AWS patches the RDS database engine (the managed service itself). For EC2, the customer patches the OS. This is one of the MOST TESTED differences in CLF-C02.
🇻🇳 Giải thích:
Theo Shared Responsibility, AWS vá engine database của RDS (chính dịch vụ managed). Còn với EC2, khách hàng phải vá OS. Đây là một trong những điểm khác biệt ĐƯỢC HỎI NHIỀU NHẤT trong CLF-C02. Bẫy 🪤 ở đây là phân biệt việc vá của EC2 với RDS.
❌ Why others are wrong / Vì sao đáp án khác sai:
- EC2 OS patching is the customer's job, not AWS's / Vá OS của EC2 là việc của khách hàng, không phải AWS
- RDS = AWS patches the engine, not the customer / RDS = AWS vá engine, không phải khách hàng
🔑 Key Concept / Khái niệm cốt lõi: RDS = AWS patches engine; EC2 = customer patches OS / RDS = AWS vá engine; EC2 = khách hàng vá OS
📚 Reference: Domain 2 | Shared Responsibility (Service-specific)
Q28. (Select TWO)
Which of the following statements about AWS Organizations are TRUE? (Select TWO)
Bản dịch tiếng Việt: Nhận định nào sau đây về Tổ chức AWS là ĐÚNG? (Chọn HAI)
A. AWS Organizations allows centralized billing across multiple AWS accounts B. Service Control Policies (SCPs) can be used to restrict which services member accounts can use C. Organizations eliminates the need for individual IAM policies D. All member accounts inherit the master account's security groups E. Consolidated billing merges all member accounts into a single shared IAM user directory
Correct answer: A, B Bản dịch đáp án đúng: A. AWS Organizations cho phép thanh toán tập trung trên nhiều tài khoản AWS; B. Chính sách kiểm soát dịch vụ (SCP) có thể được sử dụng để hạn chế những dịch vụ mà tài khoản thành viên có thể sử dụng
🇬🇧 Explanation:
A — Organizations provides centralized/consolidated billing across accounts. B — SCPs RESTRICT which services can be used. The trap 🪤 covers SCP functionality and billing scope: SCPs restrict SERVICES (not individual permissions), and consolidated billing does NOT consolidate identity.
🇻🇳 Giải thích:
A — Organizations cung cấp consolidated billing (gộp hóa đơn) tập trung trên nhiều tài khoản. B — SCP HẠN CHẾ những dịch vụ nào được dùng. Bẫy 🪤 ở đây liên quan tới chức năng SCP và phạm vi billing: SCP hạn chế DỊCH VỤ (không phải từng quyền lẻ), và consolidated billing KHÔNG gộp danh tính (identity).
❌ Why others are wrong / Vì sao đáp án khác sai:
- C — Organizations doesn't eliminate IAM policies / Organizations không loại bỏ IAM policy
- D — Member accounts have their own Security Groups (not inherited) / Tài khoản thành viên có Security Group riêng (không kế thừa)
- E — Consolidated billing pools usage/payment only; each account keeps its own IAM users/roles / Consolidated billing chỉ gộp usage/thanh toán; mỗi tài khoản vẫn giữ IAM user/role riêng
🔑 Key Concept / Khái niệm cốt lõi: SCP restricts services; consolidated billing ≠ consolidated identity / SCP hạn chế dịch vụ; gộp hóa đơn ≠ gộp danh tính
📚 Reference: Domain 2 | AWS Organizations
Q29.
Which service is BEST used to check whether resources are compliant with your organization's policies and configuration standards?
Bản dịch tiếng Việt: Dịch vụ nào được sử dụng TỐT NHẤT để kiểm tra xem tài nguyên có tuân thủ các chính sách và tiêu chuẩn cấu hình của tổ chức bạn không?
A. AWS Trusted Advisor B. AWS Config C. AWS CloudTrail D. AWS GuardDuty
Correct answer: B Bản dịch đáp án đúng: B. Cấu hình AWS
🇬🇧 Explanation:
AWS Config tracks whether resources comply with your defined standards. Config answers "Is this configured correctly according to my standards?"
🇻🇳 Giải thích:
AWS Config theo dõi xem các tài nguyên có tuân thủ tiêu chuẩn bạn định nghĩa hay không. Config trả lời câu hỏi "Cái này có được cấu hình đúng theo tiêu chuẩn của tôi không?". Bẫy 🪤 ở đây là nhầm lẫn giữa các công cụ compliance.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Trusted Advisor) — General best practices / Best practice tổng quát
- C (CloudTrail) — API audit / Audit API
- D (GuardDuty) — Threat detection / Phát hiện mối đe dọa
🔑 Key Concept / Khái niệm cốt lõi: Config = compliance tracking against your standards / Config = theo dõi tuân thủ theo tiêu chuẩn của bạn
📚 Reference: Domain 2 | AWS Config
Q30.
A company wants to ensure that a specific AWS service (e.g., EC2) CANNOT be used in a member account within AWS Organizations. Which tool should be used?
Bản dịch tiếng Việt: Một công ty muốn đảm bảo rằng KHÔNG THỂ sử dụng một dịch vụ AWS cụ thể (ví dụ: EC2) trong tài khoản thành viên trong AWS Organizations. Nên sử dụng công cụ nào?
A. IAM Policy B. Security Group C. Service Control Policy (SCP) D. NACL
Correct answer: C Bản dịch đáp án đúng: C. Chính sách kiểm soát dịch vụ (SCP)
🇬🇧 Explanation:
Service Control Policies (SCPs) block or allow specific AWS services at the account level. SCP = "Block this service for this entire account."
🇻🇳 Giải thích:
Service Control Policies (SCPs) chặn hoặc cho phép các dịch vụ AWS cụ thể ở cấp tài khoản. SCP nghĩa là "Chặn dịch vụ này cho toàn bộ tài khoản này". Bẫy 🪤 ở đây là nhầm lẫn cơ chế policy (IAM Policy vs SCP vs SG vs NACL).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (IAM Policy) — Controls user permissions, not service availability / Kiểm soát quyền của user, không phải khả dụng của dịch vụ
- B (Security Group) — Network firewall / Tường lửa mạng
- D (NACL) — Network firewall / Tường lửa mạng
🔑 Key Concept / Khái niệm cốt lõi: SCP = block/allow services for the whole account / SCP = chặn/cho phép dịch vụ cho toàn tài khoản
📚 Reference: Domain 2 | AWS Organizations (SCPs)
Q31.
Which of the following is a valid statement about GuardDuty?
Bản dịch tiếng Việt: Câu nào sau đây là tuyên bố hợp lệ về GuardDuty?
A. GuardDuty uses machine learning to detect potential threats and malicious activity B. GuardDuty patches EC2 instances automatically C. GuardDuty replaces the need for security groups D. GuardDuty encrypts data at rest for all services
Correct answer: A Bản dịch đáp án đúng: A. GuardDuty sử dụng công nghệ máy học để phát hiện các mối đe dọa tiềm ẩn và hoạt động độc hại
🇬🇧 Explanation:
GuardDuty uses machine learning to analyze CloudTrail and VPC Flow Logs for threats.
🇻🇳 Giải thích:
GuardDuty dùng machine learning để phân tích CloudTrail và VPC Flow Logs nhằm phát hiện mối đe dọa. Bẫy 🪤 ở đây là gán sai khả năng của dịch vụ (service capabilities).
❌ Why others are wrong / Vì sao đáp án khác sai:
- B — GuardDuty doesn't patch (Systems Manager does) / GuardDuty không vá (Systems Manager mới làm)
- C — GuardDuty is detection, not a replacement for Security Groups / GuardDuty là phát hiện, không thay thế Security Group
- D — GuardDuty analyzes logs, doesn't encrypt data / GuardDuty phân tích log, không mã hóa dữ liệu
🔑 Key Concept / Khái niệm cốt lõi: GuardDuty = ML-based threat detection from logs / GuardDuty = phát hiện mối đe dọa bằng ML từ log
📚 Reference: Domain 2 | AWS GuardDuty
Q32.
A security team needs to identify unused IAM credentials in the AWS account. Which service or feature would BEST help?
Bản dịch tiếng Việt: Nhóm bảo mật cần xác định thông tin đăng nhập IAM không được sử dụng trong tài khoản AWS. Dịch vụ hoặc tính năng nào sẽ trợ giúp TỐT NHẤT?
A. AWS Trusted Advisor (checks for unused credentials) B. AWS CloudTrail (logs API calls) C. AWS Config (tracks configuration changes) D. AWS GuardDuty (detects threats)
Correct answer: A Bản dịch đáp án đúng: A. AWS Trusted Advisor (kiểm tra các thông tin xác thực chưa được sử dụng)
🇬🇧 Explanation:
Trusted Advisor includes a check for "Security Groups – Specific Ports Unrestricted" and can detect unused IAM credentials.
🇻🇳 Giải thích:
Trusted Advisor có sẵn check cho "Security Groups – Specific Ports Unrestricted" và có thể phát hiện IAM credential không dùng tới. Bẫy 🪤 ở đây là "công cụ nào cho việc nào" (which tool for what task).
❌ Why others are wrong / Vì sao đáp án khác sai:
- B (CloudTrail) — Logs all API calls, doesn't detect unused creds / Ghi log mọi lệnh API, không phát hiện credential không dùng
- C (Config) — Doesn't specifically check credential usage / Không kiểm tra cụ thể việc dùng credential
- D (GuardDuty) — Threat detection, not credential auditing / Phát hiện mối đe dọa, không audit credential
🔑 Key Concept / Khái niệm cốt lõi: Trusted Advisor = best-practice checks (incl. unused credentials) / Trusted Advisor = check best-practice (gồm credential không dùng)
📚 Reference: Domain 2 | Trusted Advisor
Q33. (Select TWO)
Which of the following are components of the AWS Shared Responsibility Model for EC2? (Select TWO)
Bản dịch tiếng Việt: Thành phần nào sau đây là thành phần của Mô hình trách nhiệm chung của AWS dành cho EC2? (Chọn HAI)
A. AWS is responsible for patching the guest operating system B. Customer is responsible for configuring security groups C. AWS is responsible for hypervisor security D. Customer is responsible for physical data center locks E. AWS is responsible for encrypting data stored on EBS volumes
Correct answer: B, C Bản dịch đáp án đúng: B. Khách hàng chịu trách nhiệm cấu hình các nhóm bảo mật; C. AWS chịu trách nhiệm về bảo mật của trình ảo hóa
🇬🇧 Explanation:
B — Security Group configuration IS the customer's responsibility. C — Hypervisor security IS AWS's responsibility. The trap 🪤 is the customer-vs-AWS split: many wrongly think AWS patches the OS (it doesn't), and many forget the customer must enable EBS encryption (AWS provides KMS but won't force it).
🇻🇳 Giải thích:
B — Cấu hình Security Group LÀ trách nhiệm của khách hàng. C — Bảo mật hypervisor LÀ trách nhiệm của AWS. Bẫy 🪤 ở đây là ranh giới khách hàng vs AWS: nhiều người tưởng AWS vá OS (không phải vậy), và nhiều người quên rằng khách hàng phải tự bật mã hóa EBS (AWS cung cấp KMS nhưng không ép buộc).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — Customer patches the guest OS (AWS doesn't) / Khách hàng vá guest OS (AWS không làm)
- D — AWS manages the physical data center / AWS quản lý data center vật lý
- E — Customer must enable EBS encryption (AWS doesn't force it) / Khách hàng phải tự bật mã hóa EBS (AWS không ép)
🔑 Key Concept / Khái niệm cốt lõi: Customer: OS, SG, encryption; AWS: hypervisor, physical DC / Khách hàng: OS, SG, mã hóa; AWS: hypervisor, data center vật lý
📚 Reference: Domain 2 | Shared Responsibility (EC2-specific)
Q34.
Which statement BEST describes the difference between a Security Group and a Network ACL?
Bản dịch tiếng Việt: Tuyên bố nào TỐT NHẤT mô tả sự khác biệt giữa Nhóm bảo mật và ACL mạng?
A. Security Groups are stateless; NACLs are stateful B. Security Groups are stateful and operate at the instance level; NACLs are stateless and operate at the subnet level C. Both are stateless firewalls D. NACLs are more secure than Security Groups
Correct answer: B Bản dịch đáp án đúng: B. Nhóm bảo mật có trạng thái và hoạt động ở cấp độ phiên bản; NACL không có trạng thái và hoạt động ở cấp mạng con
🇬🇧 Explanation:
Security Groups are stateful (remember outbound traffic), operate at the instance level, and support ALLOW rules only. NACLs are stateless (no memory), operate at the subnet level, and support both ALLOW and DENY rules. This is a CRITICAL trap for networking questions.
🇻🇳 Giải thích:
Security Group là stateful (nhớ chiều ra outbound), hoạt động ở mức instance, và chỉ hỗ trợ rule ALLOW. NACL là stateless (không nhớ), hoạt động ở mức subnet, và hỗ trợ cả ALLOW lẫn DENY. Đây là bẫy 🪤 CỰC KỲ quan trọng trong câu hỏi mạng — đừng nhầm stateful với stateless.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — Reversed: SGs are stateful, NACLs are stateless / Ngược: SG là stateful, NACL là stateless
- C — Both are NOT stateless / Cả hai KHÔNG đều là stateless
- D — Security level is NOT the differentiator / Mức bảo mật KHÔNG phải điểm phân biệt
🔑 Key Concept / Khái niệm cốt lõi: SG = stateful, instance, ALLOW-only; NACL = stateless, subnet, ALLOW+DENY / SG = stateful, instance, chỉ ALLOW; NACL = stateless, subnet, ALLOW+DENY
📚 Reference: Domain 2 | Security Groups vs NACLs
Q35.
A company uses RDS Multi-AZ. Which statement BEST describes the purpose of the standby database?
Bản dịch tiếng Việt: Một công ty sử dụng RDS Multi-AZ. Câu nào mô tả TỐT NHẤT mục đích của cơ sở dữ liệu dự phòng?
A. To serve read traffic and improve performance B. To provide automatic synchronous failover in case of failure C. To reduce database licensing costs D. To improve write throughput for the database
Correct answer: B Bản dịch đáp án đúng: B. Để cung cấp chuyển đổi dự phòng đồng bộ tự động trong trường hợp có lỗi
🇬🇧 Explanation:
RDS Multi-AZ provides a synchronous standby database that automatically fails over if the primary fails. Multi-AZ = High Availability; Read Replicas = Read Scaling.
🇻🇳 Giải thích:
RDS Multi-AZ cung cấp một database standby đồng bộ (synchronous) và tự động failover nếu primary gặp sự cố. Multi-AZ = tính sẵn sàng cao (High Availability); Read Replicas = mở rộng đọc (Read Scaling). Bẫy 🪤 ở đây là nhầm use case của Multi-AZ.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — Read scaling = Read Replicas, not Multi-AZ / Mở rộng đọc = Read Replicas, không phải Multi-AZ
- C — Cost is actually higher for Multi-AZ / Multi-AZ thực ra tốn chi phí hơn
- D — Write throughput not improved (same primary) / Không cải thiện thông lượng ghi (vẫn cùng một primary)
🔑 Key Concept / Khái niệm cốt lõi: Multi-AZ = HA/auto-failover; Read Replicas = read scaling / Multi-AZ = HA/tự failover; Read Replicas = mở rộng đọc
📚 Reference: Domain 3 | RDS Multi-AZ vs Read Replicas
Q36.
Which statement is CORRECT regarding RDS Read Replicas versus RDS Multi-AZ?
Bản dịch tiếng Việt: Nhận định nào ĐÚNG về Bản sao chỉ có quyền đọc RDS so với RDS Multi-AZ?
A. Both automatically failover to the replica in case of failure B. Multi-AZ is synchronous; Read Replicas are asynchronous C. Read Replicas are for disaster recovery; Multi-AZ is for read scaling D. Both are located in the same Availability Zone
Correct answer: B Bản dịch đáp án đúng: B. Multi-AZ có tính đồng bộ; Bản sao đọc không đồng bộ
🇬🇧 Explanation:
Multi-AZ uses synchronous replication with automatic failover within the same Region. Read Replicas use asynchronous replication with manual promotion and can live in different Regions. Read Replicas are ASYNC (eventual consistency); Multi-AZ is SYNC (immediate consistency).
🇻🇳 Giải thích:
Multi-AZ dùng replication đồng bộ (synchronous) với tự động failover trong cùng một Region. Read Replicas dùng replication bất đồng bộ (asynchronous) với promote thủ công và có thể nằm ở Region khác. Read Replicas là ASYNC (nhất quán cuối eventual consistency); Multi-AZ là SYNC (nhất quán tức thì). Bẫy 🪤 ở đây là nhầm sync với async.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — Read Replicas do NOT automatically failover / Read Replicas KHÔNG tự động failover
- C — Both relate to availability/scaling, but purposes differ / Cả hai liên quan sẵn sàng/mở rộng, nhưng mục đích khác nhau
- D — Read Replicas can be in different Regions; Multi-AZ is same Region / Read Replicas có thể ở Region khác; Multi-AZ cùng một Region
🔑 Key Concept / Khái niệm cốt lõi: Multi-AZ = SYNC; Read Replicas = ASYNC / Multi-AZ = SYNC; Read Replicas = ASYNC
📚 Reference: Domain 3 | RDS Multi-AZ vs Read Replicas (detailed)
Domain 3: Cloud Technology and Services (Q37–Q58)
Q37.
A company wants to launch a web server that can automatically scale and requires minimal management overhead. Which solution is BEST?
Bản dịch tiếng Việt: Một công ty muốn ra mắt một máy chủ web có thể tự động mở rộng quy mô và yêu cầu chi phí quản lý tối thiểu. Giải pháp nào là TỐT NHẤT?
A. Launch EC2 instances with manual scaling based on monitoring B. Use AWS Elastic Beanstalk with auto-scaling enabled C. Use AWS Lambda for all web server tasks D. Deploy containers manually on EC2 instances
Correct answer: B Bản dịch đáp án đúng: B. Sử dụng AWS Elastic Beanstalk có bật tính năng tự động thay đổi quy mô
🇬🇧 Explanation:
Elastic Beanstalk abstracts EC2 management and handles auto-scaling automatically. Elastic Beanstalk = "I want managed scaling without managing EC2 directly."
🇻🇳 Giải thích:
Elastic Beanstalk trừu tượng hóa việc quản lý EC2 và tự động lo auto-scaling. Hiểu nôm na: Elastic Beanstalk = "Tôi muốn scaling được quản lý sẵn mà không phải tự tay quản lý EC2". Bẫy 🪤 ở đây là chọn đúng mức trừu tượng (abstraction level).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (EC2 manual) — Requires manual scaling; high overhead / Phải scaling thủ công; tốn công
- C (Lambda) — Not ideal for web servers (timeouts, memory limits) / Không lý tưởng cho web server (giới hạn timeout, bộ nhớ)
- D (Manual containers) — Still requires management / Vẫn phải tự quản lý
🔑 Key Concept / Khái niệm cốt lõi: Elastic Beanstalk = managed PaaS with auto-scaling / Elastic Beanstalk = PaaS được quản lý có auto-scaling
📚 Reference: Domain 3 | AWS Compute Services
Q38.
S3 bucket names MUST be globally unique. What does this mean?
Bản dịch tiếng Việt: Tên nhóm S3 PHẢI là duy nhất trên toàn cầu. Điều này có nghĩa là gì?
A. Unique within your AWS account only B. Unique across all AWS customers worldwide C. Unique within your AWS Region D. Unique within your VPC
Correct answer: B Bản dịch đáp án đúng: B. Duy nhất đối với tất cả khách hàng AWS trên toàn thế giới
🇬🇧 Explanation:
S3 bucket names must be globally unique across ALL AWS customers worldwide, not just within your account. This is why bucket names often include company names, UUIDs, or account IDs.
🇻🇳 Giải thích:
Tên S3 bucket phải duy nhất trên TOÀN CẦU đối với TẤT CẢ khách hàng AWS, không chỉ trong tài khoản của bạn. Đó là lý do tên bucket thường kèm tên công ty, UUID hoặc account ID. Bẫy 🪤 ở đây là phạm vi duy nhất (scope of uniqueness).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — Not just unique within account (if a name is taken globally, you can't create it) / Không chỉ duy nhất trong tài khoản (nếu tên đã bị chiếm toàn cầu, bạn không tạo được)
- C — Not just by Region / Không chỉ theo Region
- D — Not just by VPC / Không chỉ theo VPC
🔑 Key Concept / Khái niệm cốt lõi: S3 bucket names = globally unique across all AWS / Tên S3 bucket = duy nhất toàn cầu trên toàn AWS
📚 Reference: Domain 3 | S3
Q39. (Select TWO)
Which of the following statements are CORRECT regarding S3 storage classes? (Select TWO)
Bản dịch tiếng Việt: Câu nào sau đây ĐÚNG về lớp lưu trữ S3? (Chọn HAI)
A. S3 Standard-IA is stored in a single Availability Zone B. S3 One Zone-IA is cheaper than S3 Standard-IA because data is in one AZ C. S3 Glacier Instant Retrieval requires 12 or more hours to retrieve data D. S3 Glacier Flexible Retrieval can take minutes to hours for retrieval E. S3 Intelligent-Tiering requires you to manually move objects between tiers
Correct answer: B, D Bản dịch đáp án đúng: B. S3 One Zone-IA rẻ hơn S3 Standard-IA vì dữ liệu nằm trong một AZ; D. Truy xuất linh hoạt S3 Glacier có thể mất vài phút đến vài giờ để truy xuất
🇬🇧 Explanation:
B — One Zone-IA stores in ONE AZ (cheaper than Standard-IA). D — Glacier Flexible Retrieval takes minutes to hours. The trap 🪤 is S3 storage-class confusion: wrong options reverse the AZ count, misuse the word "Instant," and confuse automatic vs manual tiering.
🇻🇳 Giải thích:
B — One Zone-IA lưu trong MỘT AZ (rẻ hơn Standard-IA). D — Glacier Flexible Retrieval mất từ vài phút đến vài giờ. Bẫy 🪤 ở đây là nhầm các storage class của S3: các đáp án sai đảo ngược số AZ, dùng sai từ "Instant", và lẫn giữa tiering tự động vs thủ công.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — Standard-IA is multi-AZ; only One Zone-IA uses a single AZ / Standard-IA là multi-AZ; chỉ One Zone-IA dùng một AZ
- C — Glacier Instant Retrieval is milliseconds; 12+ hours describes Deep Archive / Glacier Instant Retrieval là mili-giây; 12+ giờ là Deep Archive
- E — Intelligent-Tiering moves objects automatically, never manually / Intelligent-Tiering chuyển object tự động, không bao giờ thủ công
🔑 Key Concept / Khái niệm cốt lõi: Cost order: Standard > Standard-IA > One Zone-IA > Intelligent-Tiering > Glacier Instant > Flexible > Deep Archive / Thứ tự chi phí: Standard > Standard-IA > One Zone-IA > Intelligent-Tiering > Glacier Instant > Flexible > Deep Archive
📚 Reference: Domain 3 | S3 Storage Classes
Q40.
Which storage service is BEST for a company that needs to share files across multiple EC2 instances in different Availability Zones?
Bản dịch tiếng Việt: Dịch vụ lưu trữ nào TỐT NHẤT cho một công ty cần chia sẻ tệp trên nhiều phiên bản EC2 trong nhiều Availability Zone khác nhau?
A. EBS (Elastic Block Store) B. EFS (Elastic File System) C. S3 (Simple Storage Service) D. Instance Store
Correct answer: B Bản dịch đáp án đúng: B. EFS (Hệ thống tệp đàn hồi)
🇬🇧 Explanation:
EFS is the shared file system that works across multiple EC2 instances and AZs. EBS = exclusive to one instance; EFS = shared across instances.
🇻🇳 Giải thích:
EFS là hệ thống file dùng chung, hoạt động được trên nhiều EC2 instance và nhiều AZ. EBS = gắn riêng cho một instance; EFS = dùng chung cho nhiều instance. Bẫy 🪤 ở đây là nhầm loại storage (storage type confusion).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (EBS) — Block storage, attached to ONE EC2 instance / Block storage, gắn cho MỘT EC2
- C (S3) — Object storage, good for archival, not ideal for file sharing at scale / Object storage, hợp lưu trữ, không lý tưởng cho chia sẻ file quy mô lớn
- D (Instance Store) — Ephemeral, not suitable for sharing / Tạm thời, không phù hợp chia sẻ
🔑 Key Concept / Khái niệm cốt lõi: EBS = one instance; EFS = shared file storage / EBS = một instance; EFS = file storage dùng chung
📚 Reference: Domain 3 | Storage Services (EBS vs EFS vs S3)
Q41.
A company hosts a website on an EC2 instance in us-east-1. To deliver static content (images, CSS) to users with LOW latency globally, which service should be used?
Bản dịch tiếng Việt: Một công ty lưu trữ một trang web trên phiên bản EC2 ở us-east-1. Để cung cấp nội dung tĩnh (hình ảnh, CSS) cho người dùng có độ trễ THẤP trên toàn cầu, nên sử dụng dịch vụ nào?
A. AWS Regions B. AWS CloudFront C. AWS Route 53 D. AWS VPN
Correct answer: B Bản dịch đáp án đúng: B. Mặt trận đám mây AWS
🇬🇧 Explanation:
CloudFront is a CDN that caches content at Edge Locations, reducing latency for global users. CloudFront = global content delivery.
🇻🇳 Giải thích:
CloudFront là CDN cache nội dung tại các Edge Location, giảm độ trễ cho người dùng toàn cầu. CloudFront = phân phối nội dung toàn cầu. Bẫy 🪤 ở đây là nhầm lẫn giữa các tầng hạ tầng (infrastructure tier).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Regions) — Not enough coverage for true global low-latency / Không đủ phủ để đạt độ trễ thấp toàn cầu
- C (Route 53) — DNS routing (still needs content delivery) / Định tuyến DNS (vẫn cần khâu phân phối nội dung)
- D (VPN) — For security, not performance / Cho bảo mật, không phải hiệu năng
🔑 Key Concept / Khái niệm cốt lõi: CloudFront = CDN at Edge Locations / CloudFront = CDN tại Edge Location
📚 Reference: Domain 3 | CloudFront
Q42. (Select TWO)
Which statements about CloudFront are CORRECT? (Select TWO)
Bản dịch tiếng Việt: Những nhận định nào về CloudFront là ĐÚNG? (Chọn HAI)
A. CloudFront caches content at Edge Locations, not in AWS Regions B. CloudFront always caches all content, regardless of headers C. CloudFront includes AWS Shield Advanced at no additional cost on every distribution D. CloudFront requires the origin to be an EC2 instance only E. CloudFront reduces latency by delivering content from servers closer to users
Correct answer: A, E Bản dịch đáp án đúng: A. CloudFront lưu trữ nội dung tại Edge Location, không phải trong AWS Region; E. CloudFront giảm độ trễ bằng cách cung cấp nội dung từ máy chủ đến gần người dùng hơn
🇬🇧 Explanation:
A — CloudFront caches at Edge Locations (not Regions). E — CloudFront delivers from edge servers for lower latency. The trap 🪤 covers cache behavior and Shield tiers: CloudFront respects cache-control headers (doesn't cache everything), and only Shield Standard is free.
🇻🇳 Giải thích:
A — CloudFront cache tại Edge Location (không phải Region). E — CloudFront phân phối từ edge server để giảm độ trễ. Bẫy 🪤 ở đây liên quan tới hành vi cache và các tier của Shield: CloudFront tôn trọng cache-control header (không cache mọi thứ), và chỉ Shield Standard mới miễn phí.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B — Cache headers determine what's cached, not all content / Cache header quyết định cái gì được cache, không phải mọi nội dung
- C — Shield Standard is free, but Shield Advanced is paid (~$3K/month) — not free on every distribution / Shield Standard miễn phí, nhưng Shield Advanced trả phí (~3K USD/tháng) — không miễn phí trên mọi distribution
- D — Origin can be S3, EC2, ALB, etc., not just EC2 / Origin có thể là S3, EC2, ALB, v.v., không chỉ EC2
🔑 Key Concept / Khái niệm cốt lõi: CloudFront caches per cache-control headers; only Shield Standard is free / CloudFront cache theo cache-control header; chỉ Shield Standard miễn phí
📚 Reference: Domain 3 | CloudFront
Q43.
Which statement CORRECTLY describes the difference between RDS (Relational Database Service) and DynamoDB?
Bản dịch tiếng Việt: Câu nào mô tả ĐÚNG sự khác biệt giữa RDS (Dịch vụ cơ sở dữ liệu quan hệ) và DynamoDB?
A. RDS is NoSQL; DynamoDB is relational B. RDS is a managed relational database; DynamoDB is a managed NoSQL database C. Both are NoSQL databases D. DynamoDB supports SQL queries like RDS
Correct answer: B Bản dịch đáp án đúng: B. RDS là cơ sở dữ liệu quan hệ được quản lý; DynamoDB là cơ sở dữ liệu NoSQL được quản lý
🇬🇧 Explanation:
RDS is relational and SQL-based (MySQL, PostgreSQL, etc.). DynamoDB is NoSQL and key-value. RDS = SQL; DynamoDB = NoSQL.
🇻🇳 Giải thích:
RDS là database quan hệ, dựa trên SQL (MySQL, PostgreSQL, v.v.). DynamoDB là NoSQL kiểu key-value. RDS = SQL; DynamoDB = NoSQL. Bẫy 🪤 ở đây là nhầm loại database.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — Reversed: RDS is relational, not NoSQL / Ngược: RDS là quan hệ, không phải NoSQL
- C — Both are NOT NoSQL / Cả hai KHÔNG đều là NoSQL
- D — DynamoDB doesn't support SQL (it's key-value) / DynamoDB không hỗ trợ SQL (là key-value)
🔑 Key Concept / Khái niệm cốt lõi: RDS = relational SQL; DynamoDB = NoSQL key-value / RDS = SQL quan hệ; DynamoDB = NoSQL key-value
📚 Reference: Domain 3 | RDS vs DynamoDB
Q44.
A development team needs a database that can scale horizontally and handle inconsistent traffic with single-digit millisecond latency. Which service is BEST?
Bản dịch tiếng Việt: Nhóm phát triển cần một cơ sở dữ liệu có thể mở rộng theo chiều ngang và xử lý lưu lượng truy cập không nhất quán với độ trễ một phần nghìn giây. Dịch vụ nào TỐT NHẤT?
A. Amazon RDS (MySQL) B. Amazon DynamoDB C. Amazon Redshift D. Amazon ElastiCache
Correct answer: B Bản dịch đáp án đúng: B. Amazon DynamoDB
🇬🇧 Explanation:
DynamoDB is designed for high scalability, variable traffic, and single-digit millisecond latency. DynamoDB = "I need massive scale and low latency with NoSQL data."
🇻🇳 Giải thích:
DynamoDB được thiết kế cho khả năng mở rộng cao, traffic biến động, và độ trễ ở mức mili-giây một chữ số. Hiểu nôm na: DynamoDB = "Tôi cần quy mô khổng lồ và độ trễ thấp với dữ liệu NoSQL". Bẫy 🪤 ở đây là chọn đúng database (database selection).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (RDS) — Good for relational data, but not as horizontally scalable / Hợp dữ liệu quan hệ, nhưng không mở rộng ngang tốt bằng
- C (Redshift) — Data warehouse, not real-time transactional / Data warehouse, không phải giao dịch thời gian thực
- D (ElastiCache) — Cache layer, not primary database / Lớp cache, không phải database chính
🔑 Key Concept / Khái niệm cốt lõi: DynamoDB = serverless NoSQL, auto-scaling, ms latency / DynamoDB = NoSQL serverless, tự scaling, độ trễ ms
📚 Reference: Domain 3 | DynamoDB
Q45. (Select TWO)
Which of the following statements about RDS Multi-AZ and RDS Read Replicas are CORRECT? (Select TWO)
Bản dịch tiếng Việt: Câu nào sau đây về RDS Multi-AZ và Bản sao chỉ có quyền đọc RDS là ĐÚNG? (Chọn HAI)
A. Multi-AZ is synchronous replication for high availability and failover B. Read Replicas must always reside in the same AZ as the primary instance C. Multi-AZ requires you to manually trigger failover to the standby D. Read Replicas serve read traffic and improve performance E. Both Multi-AZ and Read Replicas can serve write traffic
Correct answer: A, D Bản dịch đáp án đúng: A. Multi-AZ là bản sao đồng bộ để có tính sẵn sàng cao và chuyển đổi dự phòng; D. Bản sao có quyền đọc phục vụ lưu lượng đọc và cải thiện hiệu suất
🇬🇧 Explanation:
A — Multi-AZ IS synchronous replication for failover. D — Read Replicas serve read traffic and improve read performance. The trap 🪤 targets replica/Multi-AZ behavior: replicas don't handle writes until promoted, there's no fixed AZ restriction, and Multi-AZ failover is automatic.
🇻🇳 Giải thích:
A — Multi-AZ LÀ replication đồng bộ để failover. D — Read Replicas phục vụ traffic đọc và cải thiện hiệu năng đọc. Bẫy 🪤 ở đây nhắm vào hành vi của replica/Multi-AZ: replica không xử lý ghi cho tới khi được promote, không có ràng buộc AZ cứng nhắc, và failover của Multi-AZ là tự động.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B — Read Replicas can be same AZ, different AZ, or different Region — not required to share primary's AZ / Read Replicas có thể cùng AZ, khác AZ, hoặc khác Region — không bắt buộc cùng AZ với primary
- C — Multi-AZ failover is AUTOMATIC; AWS promotes the standby / Failover Multi-AZ là TỰ ĐỘNG; AWS tự promote standby
- E — Read Replicas are READ-ONLY until promoted / Read Replicas CHỈ ĐỌC cho tới khi được promote
🔑 Key Concept / Khái niệm cốt lõi: Multi-AZ = sync auto-failover; Read Replicas = read-only scaling / Multi-AZ = sync tự failover; Read Replicas = chỉ-đọc để mở rộng
📚 Reference: Domain 3 | RDS Multi-AZ vs Read Replicas
Q46.
A company wants to cache frequently accessed data in memory to improve application performance. Which service is BEST?
Bản dịch tiếng Việt: Một công ty muốn lưu trữ dữ liệu được truy cập thường xuyên vào bộ nhớ để cải thiện hiệu suất ứng dụng. Dịch vụ nào TỐT NHẤT?
A. S3 B. EBS C. ElastiCache D. RDS
Correct answer: C Bản dịch đáp án đúng: C. ElastiCache
🇬🇧 Explanation:
ElastiCache provides in-memory caching (Redis, Memcached) for frequently accessed data. ElastiCache = "Make my hot data faster by caching in memory."
🇻🇳 Giải thích:
ElastiCache cung cấp caching trong bộ nhớ (Redis, Memcached) cho dữ liệu truy cập thường xuyên. Hiểu nôm na: ElastiCache = "Làm dữ liệu nóng (hot data) nhanh hơn bằng cách cache trong bộ nhớ". Bẫy 🪤 ở đây là nhầm cache với storage.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (S3) — Object storage, not in-memory cache / Object storage, không phải cache trong bộ nhớ
- B (EBS) — Block storage for EC2 / Block storage cho EC2
- D (RDS) — Database, not cache / Database, không phải cache
🔑 Key Concept / Khái niệm cốt lõi: ElastiCache = in-memory cache (Redis/Memcached) / ElastiCache = cache trong bộ nhớ (Redis/Memcached)
📚 Reference: Domain 3 | ElastiCache
Q47.
Which statement is CORRECT regarding Lambda?
Bản dịch tiếng Việt: Câu nào ĐÚNG về Lambda?
A. Lambda functions can run indefinitely B. Lambda functions have a maximum execution duration of 15 minutes C. Lambda requires you to provision servers in advance D. Lambda is billed per stored code, not per execution
Correct answer: B Bản dịch đáp án đúng: B. Hàm Lambda có thời gian thực hiện tối đa là 15 phút
🇬🇧 Explanation:
Lambda has a maximum execution time of 15 minutes (900 seconds). Lambda = serverless, event-driven, max 15-min execution.
🇻🇳 Giải thích:
Lambda có thời gian chạy tối đa là 15 phút (900 giây). Lambda = serverless, hướng sự kiện (event-driven), chạy tối đa 15 phút. Bẫy 🪤 ở đây là giới hạn thời gian chạy của Lambda (duration limit).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — Lambda CANNOT run indefinitely / Lambda KHÔNG thể chạy vô thời hạn
- C — Lambda doesn't require provisioning (serverless) / Lambda không cần provisioning (serverless)
- D — Billed per execution time, not storage / Tính phí theo thời gian chạy, không phải lưu trữ
🔑 Key Concept / Khái niệm cốt lõi: Lambda max execution = 15 minutes / Lambda chạy tối đa = 15 phút
📚 Reference: Domain 3 | AWS Lambda
Q48. (Select TWO)
Which of the following are characteristics of AWS Lambda? (Select TWO)
Bản dịch tiếng Việt: Đặc điểm nào sau đây là đặc điểm của AWS Lambda? (Chọn HAI)
A. Lambda automatically scales based on invocation requests B. Lambda requires you to manage underlying infrastructure C. You are billed for compute time only when code is executing D. Lambda functions have a maximum timeout of 5 minutes E. Lambda functions can only be invoked manually from the AWS Management Console
Correct answer: A, C Bản dịch đáp án đúng: A. Lambda tự động chia tỷ lệ dựa trên yêu cầu gọi; C. Bạn chỉ bị tính phí cho thời gian tính toán khi mã đang thực thi
🇬🇧 Explanation:
A — Lambda auto-scales based on requests. C — Billed only when code executes. The trap 🪤 targets the Lambda execution model: there's no infrastructure to manage, the timeout is 15 minutes (not 5), and Lambda is event-driven (not manual-only).
🇻🇳 Giải thích:
A — Lambda tự động scaling theo số request. C — Chỉ tính phí khi code thực thi. Bẫy 🪤 ở đây nhắm vào mô hình thực thi của Lambda: không có hạ tầng để quản lý, timeout là 15 phút (không phải 5), và Lambda hướng sự kiện (không chỉ chạy thủ công).
❌ Why others are wrong / Vì sao đáp án khác sai:
- B — Lambda is serverless (no infrastructure management) / Lambda là serverless (không quản lý hạ tầng)
- D — Max timeout is 15 minutes, not 5 minutes / Timeout tối đa là 15 phút, không phải 5 phút
- E — Lambda is event-driven — triggered by S3, DynamoDB, API Gateway, EventBridge, etc., not only manual console invocation / Lambda hướng sự kiện — được kích hoạt bởi S3, DynamoDB, API Gateway, EventBridge, v.v., không chỉ gọi tay từ console
🔑 Key Concept / Khái niệm cốt lõi: Lambda = serverless, auto-scale, pay-per-execution, event-driven / Lambda = serverless, tự scaling, trả theo lần chạy, hướng sự kiện
📚 Reference: Domain 3 | AWS Lambda
Q49.
A company wants to process millions of records from an S3 bucket using a distributed computing approach. Which service is BEST?
Bản dịch tiếng Việt: Một công ty muốn xử lý hàng triệu bản ghi từ bộ chứa S3 bằng cách sử dụng phương pháp điện toán phân tán. Dịch vụ nào TỐT NHẤT?
A. AWS Lambda B. AWS Batch C. AWS Glue D. AWS Step Functions
Correct answer: B Bản dịch đáp án đúng: B. Lô AWS
🇬🇧 Explanation:
AWS Batch is designed for batch computing jobs (processing millions of records distributed across compute resources). AWS Batch = "I need to process millions of records in parallel."
🇻🇳 Giải thích:
AWS Batch được thiết kế cho các tác vụ tính toán theo lô (batch) — xử lý hàng triệu bản ghi phân tán trên nhiều tài nguyên compute. Hiểu nôm na: AWS Batch = "Tôi cần xử lý hàng triệu bản ghi song song". Bẫy 🪤 ở đây là chọn đúng dịch vụ compute.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Lambda) — Good for event-driven, but limited to 15 min / Hợp event-driven, nhưng giới hạn 15 phút
- C (Glue) — ETL service for data integration / Dịch vụ ETL để tích hợp dữ liệu
- D (Step Functions) — Workflow orchestration / Điều phối workflow
🔑 Key Concept / Khái niệm cốt lõi: AWS Batch = distributed large-scale batch processing / AWS Batch = xử lý batch quy mô lớn phân tán
📚 Reference: Domain 3 | AWS Batch
Q50.
Which statement CORRECTLY describes the difference between an EBS snapshot and an AMI?
Bản dịch tiếng Việt: Câu nào mô tả ĐÚNG sự khác biệt giữa ảnh chụp nhanh EBS và AMI?
A. Snapshots are used to create new AMIs; AMIs are used to launch instances B. Both are the same thing C. AMIs are snapshots of the entire instance; snapshots are copies of volumes D. Snapshots are faster than AMIs
Correct answer: A Bản dịch đáp án đúng: A. Ảnh chụp nhanh được sử dụng để tạo AMI mới; AMI được sử dụng để khởi chạy phiên bản
🇬🇧 Explanation:
Snapshots are point-in-time copies of EBS volumes (stored in S3). AMIs are complete machine images (OS + software + data) used to launch instances. Snapshot = "Save disk state"; AMI = "Save entire machine blueprint."
🇻🇳 Giải thích:
Snapshot là bản sao tại một thời điểm của EBS volume (lưu trong S3). AMI là image máy đầy đủ (OS + phần mềm + dữ liệu) dùng để khởi chạy instance. Snapshot = "Lưu trạng thái đĩa"; AMI = "Lưu bản thiết kế toàn bộ máy". Bẫy 🪤 ở đây là quan hệ giữa Snapshot và AMI — snapshot là viên gạch (building block) tạo nên AMI.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B — They're related but different / Liên quan nhưng khác nhau
- C — AMI ≠ full instance snapshot; it's a template / AMI ≠ snapshot toàn instance; nó là một template
- D — Speed isn't the main difference / Tốc độ không phải điểm khác biệt chính
🔑 Key Concept / Khái niệm cốt lõi: Snapshot = disk state; AMI = machine blueprint built on snapshots / Snapshot = trạng thái đĩa; AMI = bản thiết kế máy dựng từ snapshot
📚 Reference: Domain 3 | EBS Snapshots vs AMIs
Q51. (Select TWO)
Which of the following are advantages of using a managed database service like RDS instead of installing a database on EC2? (Select TWO)
Bản dịch tiếng Việt: Ưu điểm nào sau đây của việc sử dụng dịch vụ cơ sở dữ liệu được quản lý như RDS thay vì cài đặt cơ sở dữ liệu trên EC2? (Chọn HAI)
A. AWS automatically patches the database engine B. RDS eliminates the need for backups C. RDS provides automated failover capabilities with Multi-AZ D. RDS is always cheaper than self-managed databases E. AWS manages OS and application patching automatically
Correct answer: A, C Bản dịch đáp án đúng: A. AWS tự động vá công cụ cơ sở dữ liệu; C. RDS cung cấp khả năng chuyển đổi dự phòng tự động với Multi-AZ
🇬🇧 Explanation:
A — RDS DOES auto-patch the database engine. C — Multi-AZ provides automatic failover. The trap 🪤 is RDS automation scope: RDS automates DATABASE patching (not EC2 OS patching), and backups still need to be managed.
🇻🇳 Giải thích:
A — RDS THỰC SỰ tự động vá engine database. C — Multi-AZ cung cấp failover tự động. Bẫy 🪤 ở đây là phạm vi tự động hóa của RDS: RDS tự động vá DATABASE (không phải vá OS của EC2), và backup vẫn cần được cấu hình/quản lý.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B — Backups must still be configured (RDS can automate, not eliminate the need) / Backup vẫn phải cấu hình (RDS tự động hóa được, nhưng không loại bỏ nhu cầu)
- D — RDS isn't always cheaper (depends on usage) / RDS không phải lúc nào cũng rẻ hơn (tùy mức dùng)
- E — RDS only manages engine patching; customer still patches OS/apps / RDS chỉ quản lý vá engine; khách hàng vẫn vá OS/ứng dụng
🔑 Key Concept / Khái niệm cốt lõi: RDS = managed engine patching, not EC2 OS patching / RDS = vá engine được quản lý, không phải vá OS của EC2
📚 Reference: Domain 3 | RDS (Managed Database)
Q52.
A company runs batch processing jobs that are not time-sensitive. To MINIMIZE cost, which EC2 pricing model should be used?
Bản dịch tiếng Việt: Một công ty thực hiện các công việc xử lý hàng loạt không nhạy cảm về thời gian. Để TỐI THIỂU chi phí, nên sử dụng mô hình định giá EC2 nào?
A. On-Demand B. Reserved Instances C. Spot Instances D. Dedicated Hosts
Correct answer: C Bản dịch đáp án đúng: C. Phiên bản Spot
🇬🇧 Explanation:
Spot Instances offer up to 90% discount for non-critical, fault-tolerant jobs. Spot = "I can tolerate interruptions for massive savings."
🇻🇳 Giải thích:
Spot Instances giảm giá tới 90% cho các tác vụ không quan trọng, chịu lỗi được (fault-tolerant). Hiểu nôm na: Spot = "Tôi chấp nhận bị gián đoạn để tiết kiệm cực lớn". Bẫy 🪤 ở đây là chọn đúng mô hình giá cho từng use case.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (On-Demand) — Most expensive / Đắt nhất
- B (Reserved) — Good for steady, predictable workloads / Hợp workload ổn định, dự đoán được
- D (Dedicated Hosts) — For licensing compliance, expensive / Cho tuân thủ license, đắt
🔑 Key Concept / Khái niệm cốt lõi: Spot = cheapest, for interruptible/fault-tolerant jobs / Spot = rẻ nhất, cho tác vụ gián đoạn được/chịu lỗi
📚 Reference: Domain 4 | EC2 Pricing Models
Q53.
Which service provides a fully managed data warehouse for analytics?
Bản dịch tiếng Việt: Dịch vụ nào cung cấp kho dữ liệu được quản lý hoàn toàn để phân tích?
A. Amazon RDS B. Amazon DynamoDB C. Amazon Redshift D. Amazon Athena
Correct answer: C Bản dịch đáp án đúng: C. Amazon Redshift
🇬🇧 Explanation:
Amazon Redshift is the managed data warehouse for analytics queries on large datasets. Redshift = "I need to run complex analytics on massive datasets."
🇻🇳 Giải thích:
Amazon Redshift là data warehouse được quản lý, dùng cho các truy vấn phân tích (analytics) trên tập dữ liệu lớn. Hiểu nôm na: Redshift = "Tôi cần chạy phân tích phức tạp trên dữ liệu khổng lồ". Bẫy 🪤 ở đây là nhầm loại database.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (RDS) — Online transaction processing (OLTP) / Xử lý giao dịch trực tuyến (OLTP)
- B (DynamoDB) — NoSQL key-value / NoSQL key-value
- D (Athena) — Query S3 directly with SQL / Truy vấn S3 trực tiếp bằng SQL
🔑 Key Concept / Khái niệm cốt lõi: Redshift = OLAP data warehouse for analytics / Redshift = data warehouse OLAP cho phân tích
📚 Reference: Domain 3 | Redshift
Q54. (Select TWO)
Which statements about CloudFront and Route 53 are CORRECT? (Select TWO)
Bản dịch tiếng Việt: Những nhận định nào về CloudFront và Route 53 là ĐÚNG? (Chọn HAI)
A. CloudFront is a DNS service B. Route 53 is a DNS service that routes traffic based on policies C. CloudFront caches content inside the customer's VPC private subnets D. Route 53 caches content globally E. Both services improve application performance for global users
Correct answer: B, E Bản dịch đáp án đúng: B. Route 53 là dịch vụ DNS định tuyến lưu lượng truy cập dựa trên chính sách; E. Cả hai dịch vụ đều cải thiện hiệu suất ứng dụng cho người dùng toàn cầu
🇬🇧 Explanation:
B — Route 53 IS a DNS service with routing policies. E — Both improve performance for global users. The trap 🪤 is the CloudFront-vs-Route 53 roles: CloudFront is a CDN (not DNS), its cache lives at global Edge Locations (not your VPC), and Route 53 routes traffic but doesn't cache content.
🇻🇳 Giải thích:
B — Route 53 LÀ dịch vụ DNS với các routing policy. E — Cả hai đều cải thiện hiệu năng cho người dùng toàn cầu. Bẫy 🪤 ở đây là vai trò của CloudFront vs Route 53: CloudFront là CDN (không phải DNS), cache của nó nằm ở các Edge Location toàn cầu (không phải trong VPC của bạn), và Route 53 định tuyến traffic chứ không cache nội dung.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — CloudFront is NOT DNS (it's a CDN) / CloudFront KHÔNG phải DNS (là CDN)
- C — CloudFront caches at AWS Edge Locations worldwide, NOT inside your VPC private subnets / CloudFront cache tại các Edge Location toàn cầu, KHÔNG nằm trong subnet riêng của VPC
- D — Route 53 routes traffic via DNS; it doesn't cache content / Route 53 định tuyến qua DNS; không cache nội dung
🔑 Key Concept / Khái niệm cốt lõi: CloudFront = CDN (caching); Route 53 = DNS (routing) / CloudFront = CDN (cache); Route 53 = DNS (định tuyến)
📚 Reference: Domain 3 | CloudFront vs Route 53
Q55.
A company wants to run Docker containers in AWS without managing EC2 instances. Which service should they use?
Bản dịch tiếng Việt: Một công ty muốn chạy bộ chứa Docker trong AWS mà không cần quản lý phiên bản EC2. Họ nên sử dụng dịch vụ nào?
A. AWS EC2 B. AWS ECS (Elastic Container Service) C. AWS Fargate D. AWS Lambda
Correct answer: C Bản dịch đáp án đúng: C. Cổng xa AWS
🇬🇧 Explanation:
AWS Fargate is serverless container orchestration — you don't manage EC2 instances. Fargate = "I want containers without managing servers."
🇻🇳 Giải thích:
AWS Fargate là cách chạy container kiểu serverless — bạn không phải quản lý EC2 instance. Hiểu nôm na: Fargate = "Tôi muốn chạy container mà không phải quản lý server". Bẫy 🪤 ở đây là các lựa chọn điều phối container (ECS, EC2, Fargate, Lambda).
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (EC2) — Requires instance management / Phải quản lý instance
- B (ECS) — Can run on EC2 (managed) or Fargate (serverless) / Có thể chạy trên EC2 (phải quản lý) hoặc Fargate (serverless)
- D (Lambda) — Serverless but not containers / Serverless nhưng không phải container
🔑 Key Concept / Khái niệm cốt lõi: Fargate = serverless containers (no EC2 to manage) / Fargate = container serverless (không phải quản lý EC2)
📚 Reference: Domain 3 | ECS vs Fargate
Q56.
Which statement BEST describes the purpose of VPC (Virtual Private Cloud)?
Bản dịch tiếng Việt: Câu nào mô tả TỐT NHẤT mục đích của VPC (Đám mây riêng ảo)?
A. To provide a public internet connection B. To create an isolated network environment within AWS C. To manage AWS Regions D. To provide DNS services
Correct answer: B Bản dịch đáp án đúng: B. Để tạo môi trường mạng biệt lập trong AWS
🇬🇧 Explanation:
A VPC creates an isolated virtual network environment within AWS where you control networking, subnets, routing, etc. VPC = "My private, isolated network in AWS."
🇻🇳 Giải thích:
VPC tạo ra một môi trường mạng ảo cô lập (isolated) trong AWS, nơi bạn kiểm soát networking, subnet, routing, v.v. Hiểu nôm na: VPC = "Mạng riêng, cô lập của tôi trong AWS". Bẫy 🪤 ở đây là nhầm mục đích của VPC.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — VPC provides the isolated environment; you add an Internet Gateway for internet access / VPC cung cấp môi trường cô lập; bạn thêm Internet Gateway để truy cập internet
- C — VPC doesn't manage Regions / VPC không quản lý Region
- D — Route 53 handles DNS, not VPC / Route 53 lo DNS, không phải VPC
🔑 Key Concept / Khái niệm cốt lõi: VPC = your private isolated network in AWS / VPC = mạng riêng cô lập của bạn trong AWS
📚 Reference: Domain 3 | VPC
Q57. (Select TWO)
Which of the following are CORRECT about subnets within a VPC? (Select TWO)
Bản dịch tiếng Việt: Điều nào sau đây ĐÚNG về mạng con trong VPC? (Chọn HAI)
A. A public subnet has a route to the Internet Gateway B. A private subnet cannot communicate with the internet C. All subnets in a VPC must span multiple Availability Zones D. A subnet can span multiple Availability Zones E. Subnets provide an additional layer of security within a VPC
Correct answer: A, E Bản dịch đáp án đúng: A. Mạng con công cộng có đường dẫn đến Cổng Internet; E. Mạng con cung cấp một lớp bảo mật bổ sung trong VPC
🇬🇧 Explanation:
A — Public subnets have a route to the Internet Gateway. E — Subnets provide security boundaries within a VPC. The trap 🪤 is subnet-scope confusion: a subnet lives in exactly ONE AZ (never spans AZs), and a private subnet CAN still reach the internet outbound via a NAT Gateway.
🇻🇳 Giải thích:
A — Public subnet có route tới Internet Gateway. E — Subnet tạo ranh giới bảo mật bên trong VPC. Bẫy 🪤 ở đây là nhầm phạm vi subnet: một subnet nằm trong ĐÚNG MỘT AZ (không bao giờ trải qua nhiều AZ), và private subnet VẪN có thể ra internet chiều outbound qua NAT Gateway.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B — As an absolute it's false: a private subnet CAN reach the internet outbound via a NAT Gateway; it only lacks a direct Internet Gateway route / Diễn đạt tuyệt đối là sai: private subnet CÓ thể ra internet outbound qua NAT Gateway; chỉ thiếu route trực tiếp tới Internet Gateway
- C — Subnets live in ONE AZ (not multiple) / Subnet nằm trong MỘT AZ (không phải nhiều)
- D — A subnet cannot span AZs — it exists in exactly ONE AZ / Subnet không trải qua nhiều AZ — chỉ tồn tại trong ĐÚNG MỘT AZ
🔑 Key Concept / Khái niệm cốt lõi: A subnet = one AZ; private subnets reach internet via NAT Gateway / Một subnet = một AZ; private subnet ra internet qua NAT Gateway
📚 Reference: Domain 3 | VPC Subnets
Q58.
A company wants to block incoming traffic on port 3389 (RDP) from the internet to an EC2 instance. Which tool is BEST for this?
Bản dịch tiếng Việt: Một công ty muốn chặn lưu lượng truy cập đến trên cổng 3389 (RDP) từ Internet đến phiên bản EC2. Công cụ nào là TỐT NHẤT cho việc này?
A. Network ACL only B. Security Group only C. Both Security Group and NACL D. AWS Shield
Correct answer: B Bản dịch đáp án đúng: B. Chỉ nhóm bảo mật
🇬🇧 Explanation:
A Security Group is the instance-level firewall and is the BEST tool here. Security Groups support ALLOW rules only and are default-deny: any inbound port that is not explicitly allowed is already blocked. To "block" RDP from the internet you simply ensure there is no inbound allow rule for port 3389 (0.0.0.0/0) on the instance's Security Group. Because the SG is the default-deny gatekeeper at the instance, no extra configuration is required to keep RDP closed — that is exactly why it is the simplest, correct control.
🇻🇳 Giải thích:
Security Group là tường lửa ở mức instance và là công cụ TỐT NHẤT ở đây. Security Group chỉ hỗ trợ rule ALLOW và mặc định là default-deny: bất kỳ port inbound nào không được cho phép rõ ràng thì đã bị chặn sẵn. Để "chặn" RDP từ internet, bạn chỉ cần đảm bảo không có rule allow inbound nào cho port 3389 (0.0.0.0/0) trên Security Group của instance. Vì SG đóng vai trò "người gác cổng" default-deny ngay tại instance, bạn không cần cấu hình thêm gì để giữ RDP đóng — đó chính là lý do nó là cách kiểm soát đơn giản và đúng nhất.
⚠️ Fact check: Security Groups CANNOT contain explicit DENY rules. Only a Network ACL (NACL) — which is stateless and operates at the subnet level — supports explicit DENY entries. If a question instead asked for an explicit deny of a specific source/port (e.g., blocklist one IP while allowing others), the NACL would be the correct tool.
⚠️ Kiểm chứng (VN): Security Group KHÔNG thể chứa rule DENY tường minh. Chỉ có Network ACL (NACL) — vốn stateless và hoạt động ở mức subnet — mới hỗ trợ mục DENY tường minh. Nếu câu hỏi yêu cầu deny tường minh một nguồn/port cụ thể (ví dụ: chặn một IP trong khi vẫn cho phép các IP khác), thì NACL mới là công cụ đúng.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (NACL only) — A NACL can explicitly deny 3389, but it is subnet-wide and overkill when the goal is just to keep RDP closed on the instance / NACL có thể deny 3389 tường minh, nhưng nó áp cho cả subnet và là thừa thãi khi mục tiêu chỉ là giữ RDP đóng trên instance
- C (Both) — Overkill; the SG alone keeps RDP closed / Thừa; chỉ riêng SG đã giữ RDP đóng
- D (Shield) — DDoS protection (Layer 3/4), not port-level access control / Bảo vệ DDoS (Layer 3/4), không phải kiểm soát truy cập theo port
🔑 Key Concept / Khái niệm cốt lõi: SG = ALLOW-only + default-deny (block = don't allow); NACL = the only one with explicit DENY / SG = chỉ ALLOW + default-deny (chặn = không cho phép); NACL = thứ duy nhất có DENY tường minh
📚 Reference: Domain 2 | Security Groups (allow-only, default-deny) vs NACLs (stateless, supports deny)
Domain 4: Billing, Pricing, and Support (Q59–Q65)
Q59.
AWS Free Tier covers all AWS services. Which statement CORRECTLY describes the Free Tier?
Bản dịch tiếng Việt: Bậc miễn phí của AWS bao gồm tất cả các dịch vụ AWS. Câu nào mô tả ĐÚNG về Bậc miễn phí?
A. All AWS services are covered by Free Tier indefinitely B. Free Tier includes specific services for 12 months; some services have an Always Free option C. Free Tier is unlimited for all services D. Free Tier covers only EC2 instances
Correct answer: B Bản dịch đáp án đúng: B. Bậc miễn phí bao gồm các dịch vụ cụ thể trong 12 tháng; một số dịch vụ có tùy chọn Luôn miễn phí
🇬🇧 Explanation:
The AWS Free Tier has 3 types: (1) Always Free — services like Lambda, DynamoDB (limited), CloudWatch (limited); (2) 12-Month Free — services like EC2 t2.micro, S3, RDS (time-limited); (3) Trials — services like SageMaker (limited time). Free Tier ≠ Free Forever: the Always Free tier is persistent, but the 12-Month tier expires.
🇻🇳 Giải thích:
AWS Free Tier có 3 loại: (1) Always Free — các dịch vụ như Lambda, DynamoDB (giới hạn), CloudWatch (giới hạn); (2) 12-Month Free — các dịch vụ như EC2 t2.micro, S3, RDS (có thời hạn); (3) Trials — các dịch vụ như SageMaker (dùng thử có hạn). Free Tier ≠ miễn phí mãi mãi: tier Always Free là vĩnh viễn, nhưng tier 12 tháng sẽ hết hạn. Bẫy 🪤 ở đây là các lầm tưởng về Free Tier.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — Not all services are free, and the 12-month tier expires / Không phải mọi dịch vụ đều miễn phí, và tier 12 tháng sẽ hết hạn
- C — Free Tier has LIMITS (not unlimited) / Free Tier có GIỚI HẠN (không phải vô hạn)
- D — Only EC2 t2.micro, not all EC2 / Chỉ EC2 t2.micro, không phải mọi EC2
🔑 Key Concept / Khái niệm cốt lõi: Always Free persists; 12-Month Free expires / Always Free là vĩnh viễn; 12-Month Free hết hạn
📚 Reference: Domain 4 | AWS Free Tier
Q60. (Select TWO)
Which of the following are true about AWS Support Plans? (Select TWO)
Bản dịch tiếng Việt: Điều nào sau đây đúng về Gói hỗ trợ AWS? (Chọn HAI)
A. Business and Enterprise plans provide 24/7 phone support B. A designated Technical Account Manager (TAM) is included with the Enterprise plan C. Developer plan includes TAM support D. Basic plan includes 24/7 phone access to Cloud Support Engineers E. Enterprise On-Ramp includes a designated TAM
Correct answer: A, B Bản dịch đáp án đúng: A. Các gói Doanh nghiệp và Doanh nghiệp cung cấp hỗ trợ qua điện thoại 24/7; B. Người quản lý tài khoản kỹ thuật (TAM) được chỉ định được bao gồm trong gói Doanh nghiệp
🇬🇧 Explanation:
A — Business and Enterprise provide 24/7 phone and chat support. B — A designated TAM is included with the Enterprise plan. The trap 🪤 is support-plan TAM confusion: Enterprise On-Ramp has a POOLED TAM while full Enterprise has a DESIGNATED TAM, and neither Developer nor Basic includes a TAM.
🇻🇳 Giải thích:
A — Gói Business và Enterprise có hỗ trợ điện thoại và chat 24/7. B — Một TAM được chỉ định riêng (designated) đi kèm gói Enterprise. Bẫy 🪤 ở đây là nhầm lẫn về TAM giữa các gói support: Enterprise On-Ramp có TAM dùng chung (pooled), còn Enterprise đầy đủ mới có TAM chỉ định riêng (designated); cả Developer lẫn Basic đều KHÔNG có TAM.
❌ Why others are wrong / Vì sao đáp án khác sai:
- C — Developer plan does NOT include a TAM / Gói Developer KHÔNG có TAM
- D — Basic plan has NO phone/chat support with engineers (only docs, forums, core Trusted Advisor/Health checks) / Gói Basic KHÔNG có hỗ trợ điện thoại/chat với kỹ sư (chỉ có tài liệu, diễn đàn, và check Trusted Advisor/Health cốt lõi)
- E — Enterprise On-Ramp includes a pooled TAM, not a designated one; only full Enterprise gets a designated TAM / Enterprise On-Ramp có TAM dùng chung (pooled), không phải chỉ định riêng; chỉ Enterprise đầy đủ mới có TAM chỉ định
🔑 Key Concept / Khái niệm cốt lõi: TAM = Enterprise (designated), Enterprise On-Ramp (pooled), NOT Developer/Basic / TAM = Enterprise (chỉ định), Enterprise On-Ramp (dùng chung), KHÔNG có ở Developer/Basic
📚 Reference: Domain 4 | AWS Support Plans
Q61.
Which statement is CORRECT regarding AWS Reserved Instances?
Bản dịch tiếng Việt: Câu nào ĐÚNG về Phiên bản dự trữ AWS?
A. Reserved Instances guarantee availability of capacity B. Reserved Instances offer no upfront payment option C. Reserved Instances can be exchanged or modified for a different instance type D. Reserved Instances provide unlimited savings
Correct answer: C Bản dịch đáp án đúng: C. Phiên bản dự trữ có thể được trao đổi hoặc sửa đổi cho một loại phiên bản khác
🇬🇧 Explanation:
Reserved Instances can be modified or exchanged (e.g., change instance type) under AWS's modification policies. Reserved Instances = commitment for discount + modification flexibility (in some cases).
🇻🇳 Giải thích:
Reserved Instances có thể được sửa đổi hoặc trao đổi (ví dụ: đổi loại instance) theo các chính sách modification của AWS. Reserved Instances = cam kết để được giảm giá + sự linh hoạt khi sửa đổi (trong một số trường hợp). Bẫy 🪤 ở đây là sự linh hoạt của Reserved Instance.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — RIs don't guarantee capacity (only a discount) / RI không đảm bảo capacity (chỉ giảm giá)
- B — RIs offer "All Upfront", "Partial Upfront", and "No Upfront" / RI có cả "All Upfront", "Partial Upfront" và "No Upfront"
- D — Savings are capped at the commitment discount / Tiết kiệm bị giới hạn ở mức giảm giá theo cam kết
🔑 Key Concept / Khái niệm cốt lõi: RIs = commit for discount, with some modify/exchange flexibility / RI = cam kết để giảm giá, có thể sửa đổi/trao đổi ở mức nhất định
📚 Reference: Domain 4 | EC2 Reserved Instances
Q62.
A company wants to estimate the cost of running applications on AWS before deployment. Which tool is BEST?
Bản dịch tiếng Việt: Một công ty muốn ước tính chi phí chạy ứng dụng trên AWS trước khi triển khai. Công cụ nào là TỐT NHẤT?
A. AWS Cost Explorer B. AWS Budgets C. AWS Pricing Calculator D. AWS Cost Anomaly Detection
Correct answer: C Bản dịch đáp án đúng: C. Công cụ tính giá AWS
🇬🇧 Explanation:
AWS Pricing Calculator lets you estimate costs before deployment by selecting services and configurations. Pricing Calculator = "What will this cost?"; Cost Explorer = "What did this cost?"
🇻🇳 Giải thích:
AWS Pricing Calculator cho phép bạn ước tính chi phí trước khi triển khai bằng cách chọn dịch vụ và cấu hình. Pricing Calculator = "Cái này sẽ tốn bao nhiêu?"; Cost Explorer = "Cái này đã tốn bao nhiêu?". Bẫy 🪤 ở đây là phân biệt các công cụ ước tính chi phí.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A (Cost Explorer) — Analyzes PAST spending / Phân tích chi tiêu QUÁ KHỨ
- B (Budgets) — Sets spending LIMITS and alerts / Đặt GIỚI HẠN chi tiêu và cảnh báo
- D (Cost Anomaly Detection) — Detects unusual spending / Phát hiện chi tiêu bất thường
🔑 Key Concept / Khái niệm cốt lõi: Pricing Calculator = estimate future costs / Pricing Calculator = ước tính chi phí tương lai
📚 Reference: Domain 4 | AWS Cost Management Tools
Q63. (Select TWO)
Which of the following statements about AWS Trusted Advisor are CORRECT? (Select TWO)
Bản dịch tiếng Việt: Nhận định nào sau đây về AWS Trusted Advisor là ĐÚNG? (Chọn HAI)
A. Trusted Advisor provides recommendations across cost optimization, security, and performance B. Trusted Advisor provides all checks for free C. Business and Enterprise support plans have access to all Trusted Advisor checks D. Trusted Advisor replaces the need for AWS Config E. Trusted Advisor performs security assessments on EC2 instances
Correct answer: A, C Bản dịch đáp án đúng: A. Trusted Advisor cung cấp các đề xuất về tối ưu hóa chi phí, bảo mật và hiệu suất; C. Các gói hỗ trợ Doanh nghiệp và Doanh nghiệp có quyền truy cập vào tất cả các bước kiểm tra của Trusted Advisor
🇬🇧 Explanation:
A — Trusted Advisor checks cost optimization, security, performance, etc. C — Business and Enterprise plans have full Trusted Advisor checks. The trap 🪤 is Trusted Advisor vs other tools: free plans have SOME checks (not all), Config is a different (more detailed compliance) tool, and Inspector — not Trusted Advisor — assesses EC2.
🇻🇳 Giải thích:
A — Trusted Advisor kiểm tra tối ưu chi phí, bảo mật, hiệu năng, v.v. C — Gói Business và Enterprise có đầy đủ các check của Trusted Advisor. Bẫy 🪤 ở đây là nhầm Trusted Advisor với các công cụ khác: gói miễn phí chỉ có MỘT SỐ check (không phải tất cả), Config là công cụ khác (compliance chi tiết hơn), và Inspector — chứ không phải Trusted Advisor — mới đánh giá EC2.
❌ Why others are wrong / Vì sao đáp án khác sai:
- B — Basic/Developer plans have limited checks (core checks only) / Gói Basic/Developer chỉ có số check hạn chế (các check cốt lõi)
- D — Trusted Advisor and AWS Config are different (Config = more detailed compliance) / Trusted Advisor và AWS Config khác nhau (Config = compliance chi tiết hơn)
- E — Trusted Advisor doesn't assess EC2 instances (Inspector does) / Trusted Advisor không đánh giá EC2 instance (Inspector mới làm)
🔑 Key Concept / Khái niệm cốt lõi: Trusted Advisor = general best-practice checks; Inspector = EC2 security assessment / Trusted Advisor = check best-practice tổng quát; Inspector = đánh giá bảo mật EC2
📚 Reference: Domain 4 | Trusted Advisor
Q64.
A company uses AWS Organizations for consolidated billing across 10 accounts. Which benefit does this provide?
Bản dịch tiếng Việt: Một công ty sử dụng AWS Organizations để thanh toán tổng hợp cho 10 tài khoản. Điều này mang lại lợi ích gì?
A. Eliminates the need for IAM policies B. Provides volume discounts on services used across all accounts C. Automatically encrypts all data D. Removes the need for separate AWS accounts
Correct answer: B Bản dịch đáp án đúng: B. Cung cấp giảm giá theo số lượng cho các dịch vụ được sử dụng trên tất cả các tài khoản
🇬🇧 Explanation:
Consolidated Billing in AWS Organizations pools usage across all accounts to earn volume discounts on services. Consolidated Billing = "Pool all usage for better pricing."
🇻🇳 Giải thích:
Consolidated Billing trong AWS Organizations gộp usage của tất cả tài khoản lại để được giảm giá theo khối lượng (volume discount) trên các dịch vụ. Hiểu nôm na: Consolidated Billing = "Gộp toàn bộ usage để có giá tốt hơn". Bẫy 🪤 ở đây là các lợi ích của Organizations.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — IAM policies still required per account / Vẫn cần IAM policy riêng cho từng tài khoản
- C — Encryption is per-service, not automatic / Mã hóa theo từng dịch vụ, không tự động
- D — Separate accounts still needed (billing is just consolidated) / Vẫn cần các tài khoản riêng (chỉ gộp phần hóa đơn)
🔑 Key Concept / Khái niệm cốt lõi: Consolidated Billing = pool usage for volume discounts / Consolidated Billing = gộp usage để giảm giá theo khối lượng
📚 Reference: Domain 4 | AWS Organizations (Consolidated Billing)
Q65.
Spot Instances are BEST suited for which workload?
Bản dịch tiếng Việt: Phiên bản Spot phù hợp NHẤT với khối lượng công việc nào?
A. Production databases that require guaranteed availability B. Web servers that must handle consistent traffic C. Batch processing jobs that can tolerate interruptions D. Real-time financial transactions
Correct answer: C Bản dịch đáp án đúng: C. Các công việc xử lý hàng loạt có thể chịu đựng được sự gián đoạn
🇬🇧 Explanation:
Spot Instances are perfect for batch jobs that can tolerate being interrupted. Spot = fault-tolerant, flexible workloads — NOT for critical, guaranteed-availability workloads.
🇻🇳 Giải thích:
Spot Instances rất hợp cho các batch job có thể chịu được việc bị gián đoạn. Spot = workload chịu lỗi (fault-tolerant), linh hoạt — KHÔNG dùng cho workload quan trọng cần đảm bảo sẵn sàng. Bẫy 🪤 ở đây là các use case của Spot Instance.
❌ Why others are wrong / Vì sao đáp án khác sai:
- A — Production databases need guaranteed availability / Database production cần đảm bảo sẵn sàng
- B — Web servers need consistent availability / Web server cần sẵn sàng ổn định
- D — Real-time transactions cannot tolerate interruptions / Giao dịch thời gian thực không chịu được gián đoạn
🔑 Key Concept / Khái niệm cốt lõi: Spot = interruptible/fault-tolerant jobs only / Spot = chỉ cho tác vụ gián đoạn được/chịu lỗi
📚 Reference: Domain 4 | EC2 Spot Instances
Trap Pattern Summary — Study Guide
| Trap Pattern | How to Avoid | Example Questions |
|---|---|---|
| BEST vs VALID | Read carefully. Multiple may be valid; only one is BEST for scenario | Q1, Q4, Q37, Q41 |
| Region/AZ/Edge confusion | Region ⊃ AZ ⊃ Data Center. CloudFront = Edge (not Region) | Q2, Q3, Q11 |
| Sync vs Async | Multi-AZ = sync (immediate failover). Replicas = async (eventual) | Q36, Q45 |
| Shared Responsibility | AWS = infrastructure. Customer = OS, app, data, config | Q8, Q17, Q27, Q33 |
| CloudTrail vs CloudWatch vs Config | CloudTrail = API audit. CloudWatch = metrics. Config = config changes | Q20, Q21, Q22 |
| Security Group vs NACL | SG = stateful, instance-level, ALLOW only. NACL = stateless, subnet-level | Q34, Q58 |
| Free Tier myths | Free ≠ unlimited, free ≠ forever. 12-month tier expires | Q59 |
| EC2 vs RDS patching | EC2 = customer patches OS. RDS = AWS patches engine | Q8, Q27 |
| TAM availability | Enterprise = designated TAM. Enterprise On-Ramp = pooled TAM. Developer = NO TAM | Q60 |
| Multi-AZ for scaling | Multi-AZ = failover. Read Replicas = scaling reads | Q36, Q45 |
| Storage class confusion | Standard-IA > One Zone-IA. Know retrieval times: Instant (ms), Flexible (hrs), Deep (12-48h) | Q39 |
| EBS vs EFS vs S3 | EBS = one instance. EFS = shared. S3 = object storage | Q40 |
| Service selection | Always ask: "BEST for THIS scenario?" not "Is this valid?" | Q37, Q44, Q52 |
Final Review Checklist
Before exam day, ensure you can:
- Distinguish Region, AZ, Edge Location by size and purpose
- Explain Shared Responsibility for EC2, RDS, Lambda
- Explain difference: CloudTrail vs CloudWatch vs Config
- Explain difference: Security Group (stateful) vs NACL (stateless)
- Explain difference: Multi-AZ (sync failover) vs Read Replicas (async reads)
- Explain EC2 patching (customer) vs RDS patching (AWS)
- Understand Free Tier: NOT unlimited, NOT forever
- Understand TAM: Enterprise ONLY (and Enterprise On-Ramp has pooled TAM)
- Understand S3 bucket names: globally unique (all AWS customers)
- Understand pricing models: On-Demand > Reserved > Spot (cost order)
Good luck on exam day! Focus on reading carefully, catching wording differences, and avoiding the trap patterns. You've got this!