SAA-C02-EX1

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/132

flashcard set

Earn XP

Description and Tags

Exam 1

Last updated 6:59 AM on 8/21/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

133 Terms

1
New cards

Private EC2 cần outbound Internet qua IPv4 nhưng không được nhận inbound từ Internet dùng gì?

NAT Gateway trong public subnet.

2
New cards

NAT Gateway dùng cho IPv4 hay IPv6 Internet outbound?

Chủ yếu IPv4; IPv6 outbound-only thường dùng Egress-only Internet Gateway.

3
New cards

NAT Gateway phải đặt ở subnet nào?

Public subnet có route đến Internet Gateway.

4
New cards

Route 0.0.0.0/0 của private subnet khi dùng NAT Gateway trỏ tới đâu?

NAT Gateway.

5
New cards

Route 0.0.0.0/0 của public subnet thường trỏ tới đâu?

Internet Gateway.

6
New cards

Public NAT Gateway cần gắn gì để truy cập Internet?

Elastic IP address.

7
New cards

Elastic IP có gắn vào Internet Gateway không?

Không. Elastic IP có thể gắn cho NAT Gateway hoặc resource phù hợp, không gắn cho Internet Gateway.

8
New cards

IPv6 workload chỉ cần outbound Internet, không cho inbound dùng gì?

Egress-only Internet Gateway.

9
New cards

Keyword "IPv6 + outbound-only + reduce NAT Gateway cost" → ?

Egress-only Internet Gateway.

10
New cards

Egress-only Internet Gateway có cho Internet chủ động kết nối inbound vào resource không?

Không.

11
New cards

Nếu external API hỗ trợ cả IPv4 và IPv6 và mục tiêu là loại NAT Gateway để giảm phí, nên ưu tiên gì?

Cho workload dùng IPv6 và route qua Egress-only Internet Gateway.

12
New cards

Chuyển private EC2 sang public subnet chỉ để bỏ NAT Gateway có phải lựa chọn tốt khi đề yêu cầu outbound-only không?

Không, vì thay đổi mô hình bảo mật và có thể tạo khả năng Internet routing trực tiếp.

13
New cards
14
New cards

Hai hoặc vài VPC cần giao tiếp private với nhau, kiến trúc đơn giản dùng gì?

VPC Peering.

15
New cards

VPC Peering có transitive routing không?

Không.

16
New cards

Hơn 1.000 VPC cần giao tiếp với nhau nên dùng gì?

AWS Transit Gateway.

17
New cards

Keyword "hundreds/thousands of VPCs + centralized routing" → ?

Transit Gateway.

18
New cards

Transit Gateway sử dụng mô hình kiến trúc nào?

Hub-and-spoke.

19
New cards

Tại sao không dùng full-mesh VPC Peering cho hàng nghìn VPC?

Số lượng kết nối và route tăng cực lớn, khó vận hành và không scale tốt.

20
New cards

Direct Connect Gateway chủ yếu giải quyết bài toán nào?

Kết nối mạng on-premises với AWS thông qua Direct Connect, không phải giải pháp thuần VPC-to-VPC.

21
New cards

Public VIF của Direct Connect dùng chủ yếu cho gì?

Truy cập AWS public services qua Direct Connect.

22
New cards
23
New cards

Hai EC2 ở hai VPC khác nhau cần kết nối private dùng gì?

VPC Peering và cấu hình route table phù hợp.

24
New cards

Private connectivity có đồng nghĩa với application traffic đã được mã hóa không?

Không.

25
New cards

MySQL tự cài trên EC2 cần mã hóa traffic giữa application và database nên dùng gì?

SSL/TLS ở MySQL/application layer.

26
New cards

Amazon RDS Proxy có dùng được cho MySQL tự cài trên EC2 không?

Không; RDS Proxy dành cho các database được hỗ trợ trên Amazon RDS/Aurora.

27
New cards

Network ACL có thể reference Security Group ID không?

Không; Network ACL làm việc với IP/CIDR, protocol và port.

28
New cards

Nếu đề yêu cầu traffic private mà đáp án dùng public IP, thường xử lý thế nào?

Loại đáp án đó nếu không có yêu cầu đặc biệt khác.

29
New cards
30
New cards

UDP + người dùng toàn cầu + multi-Region + giảm latency/packet loss → ?

AWS Global Accelerator.

31
New cards

AWS Global Accelerator hỗ trợ TCP và UDP không?

Có.

32
New cards

Global Accelerator tối ưu traffic bằng cách nào?

Đưa traffic vào AWS global network/backbone và route đến endpoint/Region phù hợp.

33
New cards

CloudFront có hỗ trợ native UDP listener không?

Không.

34
New cards

CloudFront chủ yếu dùng giao thức application nào?

HTTP/HTTPS.

35
New cards

Transit Gateway có phải dịch vụ tối ưu Internet path từ end user toàn cầu đến application không?

Không; nó chủ yếu kết nối các network/VPC với nhau.

36
New cards

Global Accelerator khác CloudFront ở điểm thi quan trọng nào?

Global Accelerator tối ưu TCP/UDP network traffic; CloudFront chủ yếu CDN/cache cho HTTP/HTTPS content.

37
New cards
38
New cards

Virtual appliance + firewall/IDS/IPS + deep packet inspection → ?

Gateway Load Balancer.

39
New cards

Gateway Load Balancer dùng để làm gì?

Deploy, scale và đưa traffic qua các virtual network appliances.

40
New cards

VPC Flow Logs có chứa full packet payload để deep packet inspection không?

Không.

41
New cards

CloudTrail có dùng để inspect network packets không?

Không; CloudTrail ghi lại AWS API activity.

42
New cards

AWS WAF có thay thế Gateway Load Balancer cho generic deep packet inspection của toàn bộ network traffic không?

Không.

43
New cards

Keyword "all inbound/outbound packets must pass security appliance" → ?

Gateway Load Balancer và điều chỉnh routing.

44
New cards
45
New cards

Application chạy trong ECS task cần gọi S3 thì IAM permission nên gắn vào đâu?

ECS Task Role.

46
New cards

ECS Task Role dùng cho ai?

Application code chạy bên trong container.

47
New cards

ECS container instance role dùng cho ai?

ECS agent/EC2 host, không phải application logic của từng container.

48
New cards

Least privilege + một nhóm S3 bucket cụ thể → policy nên khai báo resource thế nào?

Dùng ARN cụ thể của các bucket/object cần thiết thay vì wildcard quá rộng.

49
New cards

Wildcard ARN có thể vi phạm nguyên tắc gì?

Least privilege.

50
New cards

Keyword "container application accesses AWS service" → ?

Task Role.

51
New cards
52
New cards

Multi-account AWS + centralized identity → ?

AWS IAM Identity Center.

53
New cards

IAM Identity Center tích hợp với dịch vụ nào để quản lý nhiều AWS account?

AWS Organizations.

54
New cards

Permission Set trong IAM Identity Center là gì?

Tập hợp permissions được gán cho user/group theo AWS account.

55
New cards

Multi-account + least privilege + centralized login → hai khái niệm chính?

IAM Identity Center + Permission Sets.

56
New cards

Tại sao không nên tạo IAM user riêng trong từng AWS account khi yêu cầu centralized identity?

Khó quản lý vòng đời user và không còn quản trị tập trung.

57
New cards

External IdP + nhiều AWS accounts nên tích hợp theo hướng nào?

Tích hợp với IAM Identity Center thay vì cấu hình federation lặp lại ở từng account khi bài yêu cầu centralized management.

58
New cards
59
New cards

AWS Organizations dùng để làm gì trong SAA-C03?

Quản lý tập trung nhiều AWS accounts, Organizational Units, policies và consolidated billing.

60
New cards

Ai quản lý Savings Plans discount sharing trong AWS Organizations?

Management account.

61
New cards

AWS Resource Access Manager có dùng để share Savings Plans discount không?

Không.

62
New cards

Savings Plans discount có thể được chia sẻ giữa các account trong Organization thông qua cơ chế nào?

Consolidated billing/discount sharing được quản lý từ management account.

63
New cards

Keyword "separate tenants into dedicated AWS accounts" → ?

AWS Organizations.

64
New cards

Keyword "multi-account centralized permissions" → ?

IAM Identity Center và Permission Sets.

65
New cards
66
New cards

S3 + Glue Data Catalog + fine-grained row/column/cell access → ?

AWS Lake Formation.

67
New cards

Lake Formation giải quyết vấn đề gì?

Quản lý data lake và fine-grained permissions trên dữ liệu/Data Catalog.

68
New cards

IAM policy thuần có thuận tiện bằng Lake Formation cho column-level access không?

Không.

69
New cards

Keyword "PII + Glue Catalog + fine-grained access" → ?

Lake Formation.

70
New cards

Glue chủ yếu liên quan đến gì?

Data integration/ETL và Data Catalog; fine-grained data lake permissions là use case mạnh của Lake Formation.

71
New cards
72
New cards

HDFS on-premises cần migrate dữ liệu sang S3 → ?

AWS DataSync.

73
New cards

AWS Application Migration Service chủ yếu migrate gì?

Server/workload theo kiểu lift-and-shift, không phải lựa chọn chính cho HDFS file-data migration vào S3.

74
New cards

DataSync có encryption in transit không?

Có.

75
New cards

Nếu DataSync tự đáp ứng encrypted transfer thì có cần thêm VPN chỉ để mã hóa traffic trong câu hỏi cost-effective không?

Không nhất thiết; tránh thêm component không cần thiết.

76
New cards

Keyword "file/data migration + on-premises + S3" → thường nghĩ tới?

AWS DataSync.

77
New cards
78
New cards

SFTP server tự quản lý cần chuyển sang managed AWS service → ?

AWS Transfer Family.

79
New cards

AWS Transfer Family SFTP server có thể lưu file trực tiếp vào đâu?

Amazon S3.

80
New cards

Transfer Family có hỗ trợ SSH key authentication không?

Có.

81
New cards

Transfer Family SFTP Server và SFTP Connector khác nhau thế nào?

Server nhận kết nối SFTP inbound từ client; Connector dùng AWS kết nối outbound tới remote SFTP server.

82
New cards

Keyword "clients still use SFTP + SSH keys + managed service" → ?

AWS Transfer Family SFTP server.

83
New cards

Nếu muốn giảm delay từ SFTP upload đến S3 processing, lợi ích của Transfer Family + S3 là gì?

File có thể được ghi trực tiếp vào S3 thay vì chờ script định kỳ trên EC2.

84
New cards
85
New cards

Microservices + content-based event routing + archive/replay → ?

Amazon EventBridge.

86
New cards

EventBridge có native Archive không?

Có.

87
New cards

SQS giữ message tối đa bao lâu?

14 ngày.

88
New cards

Nếu đề yêu cầu archive message 30 ngày, SQS retention trực tiếp có đáp ứng không?

Không.

89
New cards

Keyword "archive events + replay" → ?

EventBridge.

90
New cards

SNS có native EventBridge-style archive/replay không?

Không.

91
New cards

Nếu đề yêu cầu least development effort, nên ưu tiên gì?

Managed/native AWS feature thay vì tự viết Lambda hoặc custom routing nếu cùng đáp ứng yêu cầu.

92
New cards
93
New cards

DynamoDB maximum item size là bao nhiêu?

400 KB.

94
New cards

Document thường xuyên lớn hơn 1 MB có phù hợp để lưu trực tiếp trong một DynamoDB item không?

Không.

95
New cards

MongoDB-compatible managed document database trên AWS → ?

Amazon DocumentDB.

96
New cards

Variable workload + document database + cần giảm over-provisioning → ?

DocumentDB Serverless nếu đáp án/use case hỗ trợ.

97
New cards

Keyword ">400 KB item/document" → cần nhớ gì?

DynamoDB item limit 400 KB nên phải đổi thiết kế hoặc chọn storage/database khác.

98
New cards
99
New cards

DynamoDB traffic unpredictable → capacity mode nào?

On-demand.

100
New cards

DynamoDB traffic ổn định và dự đoán được → có thể cân nhắc mode nào?

Provisioned capacity.