Supplement · Cloud · Interview Questions

20 câu hỏi AWS/Azure governance và operations

Map capability theo semantics, scope, failure và cost—not chỉ tên dịch vụ.

1. Landing zone giải quyết gì?
Repeatable identity, hierarchy, policy, logging, security, connectivity, billing and account/subscription vending; không tự vận hành workload tốt.
2. AWS SCP vs Azure Policy?
SCP giới hạn effective IAM permissions, không grant; Azure Policy evaluates/resource compliance/effects. Azure RBAC tương ứng authorization grant hơn.
3. AWS account vs Azure subscription?
Đều là strong billing/quota/governance boundaries nhưng hierarchy, identity/root/tenant semantics khác; không map tuyệt đối.
4. Break-glass thiết kế?
Separate emergency principals, strong protected credentials/MFA where supported, excluded narrowly from risky dependencies, monitored/tested/reviewed and never routine.
5. Quota khác capacity?
Quota là permitted maximum; regional physical/service capacity có thể vẫn unavailable. Forecast, request, reserve and test target region/account.
6. Central network trade-off?
Consistent inspection/egress/DNS but routing/cost/latency/ownership and large blast radius; redundant design and bypass/emergency paths need governance.
7. Private endpoint tự secure?
Giảm public path nhưng identity/resource policy/DNS/route/exfiltration and endpoint policy still matter; costs and regional availability.
8. Log centralization risk?
Missing diagnostic coverage, identity disable, cost/retention/data residency, shared compromise and deletion. Separate archive ownership/immutability and test retrieval.
9. Migration wave chọn sao?
Dependency groups, business criticality, downtime/data/change rate, complexity and rollback; pilot representative then factories, not random server list.
10. Cutover validation?
Data reconciliation, performance/SLO, identity/network/DNS, observability/backup, rollback window and source decommission criteria.
11. Cloud incident containment?
Preserve evidence, scope identities/resources/regions, revoke sessions/keys, quarantine network/resources and persisted trust without destroying logs; recover with clean credentials/config.
12. Management/root tenant compromise?
Highest blast radius across guardrails/accounts/subscriptions/SaaS; dedicated identities, no workloads, strong controls and external/immutable audit.
13. Multi-AZ vs region DR?
Zones address datacenter failures within region; regional DR needs replicated data/config/identity/network/quotas, routing and failback.
14. Backup complete khi nào?
Restore drill proves RPO/RTO, keys/permissions/dependency order and post-restore reconciliation; copy existence alone insufficient.
15. FinOps allocation?
Hierarchy/tags/categories and shared-cost model mapped to owners/products/unit metrics; enforce tagging but handle untaggable/shared resources.
16. Commitment discount risk?
Locks spend/usage assumptions; rightsizing and stable baseline first, model growth/modernization/region/license and coverage/utilization.
17. NAT/Firewall/log costs bất ngờ?
Per-hour/per-GB processing, cross-zone/region/egress and telemetry ingestion/retention; architecture path and sampling/lifecycle drive bill.
18. Policy rollout an toàn?
Inventory current compliance, audit/dry-run, sandbox/canary scopes, exemptions owner/expiry, remediation identity and break-glass, then progressive enforce.
19. AWS/Azure service mapping?
Map requirement/control/data plane/failure/consistency/quota/cost and operational responsibility; names/features/regions differ.
20. Multi-cloud khi nào?
Regulation/customer/merger/specific capability or quantified resilience; costs duplicated platform/skills/data/identity/operations, avoid checkbox portability.
← AzureThực hành →