Ngân hàng đề — Google Cloud Associate Cloud Engineer

Tìm thấy 449 câu.

Câu 391
Your customer wants you to create a secure website with autoscaling based on the compute instance CPU load. You want to enhance performance by storing static content in Cloud Storage. Which resources are needed to distribute the user traffic?
  1. A An external HTTP(S) load balancer with a managed SSL certificate to distribute the load and a URL map to target the requests for the static content to the Cloud Storage backend.
  2. B An external network load balancer pointing to the backend instances to distribute the load evenly. The web servers will forward the request to the Cloud Storage as needed.
  3. C An internal HTTP(S) load balancer together with Identity-Aware Proxy to allow only HTTPS traffic.
  4. D An external HTTP(S) load balancer to distribute the load and a URL map to target the requests for the static content to the Cloud Storage backend. Install the HTTPS certificates on the instance.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi yêu cầu thiết kế một website an toàn (secure) với tự động mở rộng (autoscaling) dựa trên tải CPU của instance tính toán, đồng thời tối ưu hiệu suất bằng cách lưu trữ nội dung tĩnh (static content) trong Cloud Storage. Mục tiêu chính là xác định các tài nguyên cần thiết để phân phối traffic từ người dùng (distribute user traffic).

🛠️ Yêu cầu chính:

  • Website phải secure → Hỗ trợ HTTPS với chứng chỉ SSL.
  • Autoscaling dựa trên CPU → Cần backend service hỗ trợ MIG (Managed Instance Group) hoặc tương tự.
  • Static content ở Cloud Storage → Sử dụng backend bucket để route request tĩnh trực tiếp đến bucket, giảm tải cho compute instances.
  • Phân phối traffic → Sử dụng Load Balancer phù hợp để xử lý public traffic, routing thông minh qua URL map.

📘 Bối cảnh Google Cloud (GCP): Đây là kiến thức chuẩn cho Associate Cloud Engineer exam (cập nhật đến 2024-2026, theo tài liệu chính thức GCP Load Balancing v2.x). External HTTP(S) Load Balancer (Global hoặc Classic) là lựa chọn lý tưởng cho web public, hỗ trợ backend buckets cho Cloud Storage.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: An external HTTP(S) load balancer with a managed SSL certificate to distribute the load and a URL map to target the requests for the static content to the Cloud Storage backend.

Lý do 🏆:

  • External HTTP(S) Load Balancer (L7) xử lý public traffic, phân phối tải đến backend services (như MIG cho autoscaling CPU-based).
  • Managed SSL certificate tự động từ Google, dễ quản lý, không cần cài trên instance → Đảm bảo secure HTTPS.
  • URL map routing chính xác: Static content (/images/, /css/) → Cloud Storage backend bucket; Dynamic → Compute instances.
  • Hoàn hảo cho autoscaling (Unmanaged/Regional MIG với autoscaler CPU threshold) và hiệu suất cao (caching, CDN integration).

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn giữ nguyên văn bản gốc tiếng Anh, với đánh giá đúng/sai dựa trên best practices GCP (không vi phạm security/performance):

  • An external HTTP(S) load balancer with a managed SSL certificate to distribute the load and a URL map to target the requests for the static content to the Cloud Storage backend.
    ✅ Đúng hoàn toàn 🥇: Như giải thích trên, đây là giải pháp chuẩn. External HTTP(S) LB hỗ trợ backend bucket cho Cloud Storage (path-based routing qua URL map), managed cert (Google-managed hoặc tự upload), và tích hợp autoscaler MIG. Không cần chạm vào instance cho SSL/static.

  • An external network load balancer pointing to the backend instances to distribute the load evenly. The web servers will forward the request to the Cloud Storage as needed.
    ❌ Sai 🚫: External Network LB (L4 TCP/UDP) chỉ cân bằng tải cơ bản đến instances, không hỗ trợ URL map hay backend bucket cho Cloud Storage → Web servers phải proxy static requests (tăng tải CPU, không autoscaling hiệu quả). Không handle HTTPS termination tốt, kém secure/performance.

  • An internal HTTP(S) load balancer together with Identity-Aware Proxy to allow only HTTPS traffic.
    ❌ Sai 🔒: Internal HTTP(S) LB chỉ cho traffic nội bộ VPC (không public-facing), không phân phối user traffic từ internet. IAP thêm IAM/2FA nhưng không giải quyết autoscaling public website hay Cloud Storage routing. Không phù hợp cho external users.

  • An external HTTP(S) load balancer to distribute the load and a URL map to target the requests for the static content to the Cloud Storage backend. Install the HTTPS certificates on the instance.
    ❌ Sai 🔑: External HTTP(S) LB + URL map + backend bucket là đúng, nhưng cài cert trên instance là thừa/thiếu best practice. LB phải HTTPS terminate với managed/self-managed cert (không pass qua instance), tránh phức tạp quản lý cert và tăng latency.

📚 Tài liệu tham khảo (cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi hiệu quả! 🚀 Nếu cần thêm ví dụ thực hành, hỏi nhé!

Câu 392
The core business of your company is to rent out construction equipment at large scale. All the equipment that is being rented out has been equipped with multiple sensors that send event information every few seconds. These signals can vary from engine status, distance traveled, fuel level, and more. Customers are billed based on the consumption monitored by these sensors. You expect high throughput – up to thousands of events per hour per device – and need to retrieve consistent data based on the time of the event. Storing and retrieving individual signals should be atomic. What should you do?
  1. A Create files in Cloud Storage as data comes in.
  2. B Create a file in Filestore per device, and append new data to that file.
  3. C Ingest the data into Cloud SQL. Use multiple read replicas to match the throughput.
  4. D Ingest the data into Bigtable. Create a row key based on the event timestamp.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả một công ty chuyên cho thuê thiết bị xây dựng quy mô lớn, với các thiết bị được trang bị nhiều cảm biến gửi dữ liệu sự kiện (event) mỗi vài giây. Dữ liệu bao gồm trạng thái động cơ, quãng đường di chuyển, mức nhiên liệu, v.v. Khách hàng được tính phí dựa trên dữ liệu tiêu thụ từ cảm biến. Yêu cầu chính:

  • Thông lượng cao: Lên đến hàng nghìn sự kiện/giờ/thiết bị.
  • Truy xuất dữ liệu nhất quán dựa trên thời gian sự kiện.
  • Lưu trữ và truy xuất từng tín hiệu riêng lẻ phải là nguyên tử (atomic).

Mục tiêu là chọn dịch vụ lưu trữ phù hợp để xử lý dữ liệu thời gian thực (time-series data) với tính nhất quán mạnh (strong consistency), hiệu suất cao và hoạt động nguyên tử. Đây là tình huống điển hình cho dữ liệu IoT cao tần suất, cần dịch vụ NoSQL phân tán như Bigtable trên Google Cloud (dựa trên kiến thức GCP cập nhật đến 2026). 📈

✅ Đáp án đúng: Ingest the data into Bigtable. Create a row key based on the event timestamp.

Lý do lựa chọn:

  • Bigtable là cơ sở dữ liệu NoSQL wide-column, được thiết kế tối ưu cho dữ liệu thời gian thực với thông lượng cực cao (hàng triệu ops/giây), phù hợp hoàn hảo với hàng nghìn sự kiện/giờ/thiết bị. 🛠️
  • Row key dựa trên timestamp (ví dụ: device_id#timestamp) đảm bảo truy xuất nhất quán theo thời gian (time-based queries) và hoạt động nguyên tử trên từng row (atomic row mutations), tránh race conditions.
  • Bigtable hỗ trợ strong consistency tự nhiên, phục vụ đọc/ghi nhanh với latency thấp (<10ms), và scale ngang vô hạn. Hoàn hảo cho IoT billing dựa trên sensor data. 🚀
  • Tài liệu tham khảo: Google Cloud Bigtable Documentation - Time-series data (cập nhật 2025); Best practices for IoT workloads.

❌ Phân tích tất cả các phương án

  • [SAI] Create files in Cloud Storage as data comes in.
    ❌ Sai vì: Cloud Storage là object storage, không hỗ trợ ghi nguyên tử từng tín hiệu riêng lẻ (atomic append khó khăn, cần object versioning phức tạp). Với thông lượng cao, việc tạo file liên tục gây overhead lớn, không hiệu quả cho truy xuất time-series (scan toàn bộ object chậm). Phù hợp batch storage hơn là real-time. 📦

  • [SAI] Create a file in Filestore per device, and append new data to that file.
    ❌ Sai vì: Filestore (NFS file system) có giới hạn throughput thấp (~10GB/s max per instance), không scale cho hàng nghìn sự kiện/giây/thiết bị. Append liên tục gây contention và không đảm bảo atomicity mạnh cho từng event. Latency cao, không phù hợp IoT high-frequency. Không hỗ trợ time-based queries hiệu quả. 🗂️

  • [SAI] Ingest the data into Cloud SQL. Use multiple read replicas to match the throughput.
    ❌ Sai vì: Cloud SQL (MySQL/PostgreSQL) là relational DB, không scale throughput cao (giới hạn ~100k ops/giây max, dù dùng replicas). Replicas chỉ hỗ trợ read scaling, nhưng write throughput vẫn bottleneck. Không tối ưu time-series (cần index phức tạp), và atomicity per event kém dưới tải cao. Chi phí cao cho IoT scale. 🗄️

Tóm lại, Bigtable là lựa chọn duy nhất đáp ứng đầy đủ yêu cầu high-throughput, time-series consistency và atomic ops. Nếu triển khai, kết hợp Pub/Sub cho ingest và Dataflow cho processing! 🌟

Câu 393 Chọn nhiều đáp án
You just installed the Google Cloud CLI on your new corporate laptop. You need to list the existing instances of your company on Google Cloud. What must you do before you run the gcloud compute instances list command? (Choose two.)
  1. A Run gcloud auth login, enter your login credentials in the dialog window, and paste the received login token to gcloud CLI.
  2. B Create a Google Cloud service account, and download the service account key. Place the key file in a folder on your machine where gcloud CLI can find it.
  3. C Download your Cloud Identity user account key. Place the key file in a folder on your machine where gcloud CLI can find it.
  4. D Run gcloud config set compute/zone $my_zone to set the default zone for gcloud CLI.
  5. E Run gcloud config set project $my_project to set the default project for gcloud CLI.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào quy trình khởi tạo và xác thực Google Cloud CLI (gcloud) sau khi cài đặt trên laptop mới của công ty. Cụ thể, bạn cần liệt kê các Compute Engine instances hiện có của công ty bằng lệnh gcloud compute instances list. Tuy nhiên, trước khi chạy lệnh này, phải thực hiện hai bước bắt buộc để CLI có thể truy cập tài nguyên Google Cloud:

  • Xác thực (authentication): CLI cần biết bạn là ai và có quyền truy cập không.
  • Cấu hình project: Lệnh list instances mặc định sẽ lấy từ project hiện tại, nên phải set project trước. 📘 Lưu ý: Lệnh gcloud compute instances list không yêu cầu set zone (vì nó list toàn project), và chỉ hoạt động sau khi auth + set project. Kiến thức dựa trên Google Cloud CLI phiên bản mới nhất 2024-2026 (SDK 470+), không thay đổi cơ bản so với trước.

✅ Đáp án đúng (Chọn hai)

Hai đáp án đúng là:

  1. Run gcloud auth login, enter your login credentials in the dialog window, and paste the received login token to gcloud CLI.
  2. Run gcloud config set project $my_project to set the default project for gcloud CLI.

Lý do lựa chọn 🛠️:

  • gcloud auth login là bước xác thực user account đầu tiên và bắt buộc cho người dùng cá nhân (như trên laptop công ty). Nó mở browser để login Google account, nhận authorization code, và lưu credentials vào CLI. Không auth thì CLI không kết nối được với Google Cloud API.
  • gcloud config set project set project mặc định, vì lệnh list instances yêu cầu project cụ thể (nếu không set, CLI báo lỗi "No active account" hoặc "No project"). Đây là hai bước cơ bản theo quickstart guide của Google Cloud SDK.

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng lựa chọn một, với ✅ cho đúng và ❌ cho sai. Tôi giữ nguyên văn bản gốc tiếng Anh, chỉ giải thích bằng tiếng Việt:

  • ✅ Run gcloud auth login, enter your login credentials in the dialog window, and paste the received login token to gcloud CLI.
    🟢 Đúng: Đây là lệnh chuẩn để authenticate user account qua OAuth 2.0. CLI mở trình duyệt, bạn login tài khoản Google Cloud, copy code về paste. Sau đó, CLI có quyền truy cập API (bao gồm Compute Engine). Bắt buộc cho lần đầu sử dụng.

  • ❌ Create a Google Cloud service account, and download the service account key. Place the key file in a folder on your machine where gcloud CLI can find it.
    🔴 Sai: Service account dành cho ứng dụng/server tự động (không phải user cá nhân trên laptop). Để dùng key, phải gcloud auth activate-service-account --key-file=KEY.json, nhưng câu hỏi dành cho "corporate laptop" cá nhân, ưu tiên user login. Service account kém an toàn hơn (key file dễ lộ), không phải bước đầu tiên.

  • ❌ Download your Cloud Identity user account key. Place the key file in a folder on your machine where gcloud CLI can find it.
    🔴 Sai: Cloud Identity không hỗ trợ "user account key" như service account. User account dùng OAuth (qua gcloud auth login), không download key. Lựa chọn này không tồn tại trong Google Cloud, sẽ gây lỗi nếu thử.

  • ❌ Run gcloud config set compute/zone $my_zone to set the default zone for gcloud CLI.
    🔴 Sai: Set zone chỉ ảnh hưởng lệnh tạo/list resource trong zone cụ thể (như gcloud compute instances create). Lệnh gcloud compute instances list list toàn project, không cần zone. Set zone không bắt buộc và không giải quyết auth/project.

  • ✅ Run gcloud config set project $my_project to set the default project for gcloud CLI.
    🟢 Đúng: Project là container cho tất cả resources (instances thuộc project). Phải set trước để CLI biết lấy dữ liệu từ project nào của công ty. Có thể check bằng gcloud config get-value project.

📚 Tài liệu tham khảo

Hy vọng phân tích này giúp bạn ôn thi Associate Cloud Engineer hiệu quả! 🚀 Nếu cần ví dụ lệnh thực tế, hỏi thêm nhé!

Câu 394
You are planning to migrate your on-premises data to Google Cloud. The data includes:

•200 TB of video files in SAN storage
•Data warehouse data stored on Amazon Redshift
•20 GB of PNG files stored on an S3 bucket

You need to load the video files into a Cloud Storage bucket, transfer the data warehouse data into BigQuery, and load the PNG files into a second Cloud Storage bucket. You want to follow Google-recommended practices and avoid writing any code for the migration. What should you do?
  1. A Use gcloud storage for the video files, Dataflow for the data warehouse data, and Storage Transfer Service for the PNG files.
  2. B Use Transfer Appliance for the videos, BigQuery Data Transfer Service for the data warehouse data, and Storage Transfer Service for the PNG files.
  3. C Use Storage Transfer Service for the video files, BigQuery Data Transfer Service for the data warehouse data, and Storage Transfer Service for the PNG files.
  4. D Use Cloud Data Fusion for the video files, Dataflow for the data warehouse data, and Storage Transfer Service for the PNG files.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi này tập trung vào việc di chuyển dữ liệu (migration) từ môi trường on-premises và AWS sang Google Cloud theo các thực hành khuyến nghị của Google (Google-recommended practices), không viết bất kỳ code nào. Dữ liệu cụ thể bao gồm:

  • 200 TB video files lưu trữ trên SAN storage (on-premises): Cần load vào một Cloud Storage bucket.
  • Data warehouse data trên Amazon Redshift (AWS): Cần chuyển vào BigQuery.
  • 20 GB PNG files trên S3 bucket (AWS): Cần load vào một Cloud Storage bucket khác.

📌 Yêu cầu chính: Sử dụng các công cụ tự động, không code, phù hợp với quy mô dữ liệu lớn (200 TB cần phương pháp offline để tránh bottleneck mạng), và hỗ trợ trực tiếp từ các nguồn này. Đây là tình huống thực tế trong chứng chỉ Google Cloud Associate Cloud Engineer, nhấn mạnh các dịch vụ migration như Transfer Appliance, Storage Transfer Service (STS), và BigQuery Data Transfer Service (trong phiên bản mới nhất 2024-2026).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use Transfer Appliance for the videos, BigQuery Data Transfer Service for the data warehouse data, and Storage Transfer Service for the PNG files.

Lý do:

  • 🛠️ Transfer Appliance lý tưởng cho 200 TB video on-premises (SAN): Dữ liệu lớn như vậy không phù hợp transfer qua mạng (chậm, tốn kém), nên dùng thiết bị vật lý (appliance) để load dữ liệu offline, gửi về Google, họ xử lý và upload vào Cloud Storage. Đây là best practice cho >100 TB theo Google.
  • 🛠️ BigQuery Data Transfer Service hỗ trợ trực tiếp chuyển dữ liệu từ Amazon Redshift sang BigQuery mà không code (automated scheduled transfers), bao gồm schema mapping và incremental loads (cập nhật 2024-2026).
  • 🛠️ Storage Transfer Service (STS) hoàn hảo cho 20 GB PNG từ S3 sang Cloud Storage: Hỗ trợ AWS S3 làm nguồn, transfer nhanh, resumable, không code.
  • ✅ Toàn bộ giải pháp không code, theo recommended practices, tối ưu chi phí/thời gian.

❌ Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh:

  • Use gcloud storage for the video files, Dataflow for the data warehouse data, and Storage Transfer Service for the PNG files.
    ❌ Sai: gcloud storage là CLI command-line tool, yêu cầu script/code để tự động hóa 200 TB (không no-code). Dataflow là Apache Beam-based ETL, đòi viết pipeline code cho Redshift → BigQuery (vi phạm no-code). Chỉ STS cho PNG đúng, nhưng tổng thể không recommended.

  • Use Transfer Appliance for the videos, BigQuery Data Transfer Service for the data warehouse data, and Storage Transfer Service for the PNG files.
    ✅ Đúng: Như giải thích trên, kết hợp hoàn hảo các công cụ no-code, phù hợp quy mô và nguồn dữ liệu. Best practice cho hybrid migration (on-prem + AWS → GCP).

  • Use Storage Transfer Service for the video files, BigQuery Data Transfer Service for the data warehouse data, and Storage Transfer Service for the PNG files.
    ❌ Sai: Storage Transfer Service không phù hợp cho 200 TB on-premises SAN (thiết kế cho cloud-to-cloud hoặc nhỏ, mạng upload 200 TB có thể mất hàng tháng, tốn kém bandwidth). BigQuery Data Transfer và STS cho PNG/Redshift đúng, nhưng video fail → không toàn diện.

  • Use Cloud Data Fusion for the video files, Dataflow for the data warehouse data, and Storage Transfer Service for the PNG files.
    ❌ Sai: Cloud Data Fusion là fully-managed ETL (dựa CDAP), yêu cầu thiết kế pipeline (có thể no-code GUI nhưng phức tạp, không recommended cho simple file copy như video SAN). Dataflow lại đòi code cho Redshift. Chỉ STS cho PNG đúng, nhưng không no-code thuần và không optimal.

📘 Tài liệu tham khảo (cập nhật 2024-2026)

🧠 Lưu ý: Giải pháp này scalable, secure (IAM-based), và chi phí hiệu quả theo AWS/GCP integration mới nhất!

Câu 395
You want to deploy a new containerized application into Google Cloud by using a Kubernetes manifest. You want to have full control over the Kubernetes deployment, and at the same time, you want to minimize configuring infrastructure. What should you do?
  1. A Deploy the application on GKE Autopilot.
  2. B Deploy the application on Cloud Run.
  3. C Deploy the application on GKE Standard.
  4. D Deploy the application on Cloud Functions.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi yêu cầu triển khai một ứng dụng container hóa mới vào Google Cloud bằng cách sử dụng Kubernetes manifest (tệp YAML mô tả tài nguyên Kubernetes như Deployment, Service...). Yêu cầu chính là:

  • Full control over the Kubernetes deployment: Người dùng muốn kiểm soát hoàn toàn quá trình triển khai Kubernetes (ví dụ: cấu hình Pod, ReplicaSet, Ingress... qua manifest).
  • Minimize configuring infrastructure: Giảm thiểu việc cấu hình hạ tầng (như node pools, scaling autoscaler, networking cơ bản).

🛠️ Đây là tình huống điển hình trong Google Kubernetes Engine (GKE), nơi cần sự cân bằng giữa tự quản lý ứng dụng Kubernetes và tự động hóa hạ tầng. Kiến thức dựa trên phiên bản GKE mới nhất (đến 2026), với GKE Autopilot được khuyến nghị cho các workload containerized cần Kubernetes-native mà không lo hạ tầng.

📘 Tài liệu tham khảo:

✅ Đáp án đúng

Deploy the application on GKE Autopilot.

Lý do lựa chọn:

  • GKE Autopilot cho phép triển khai trực tiếp qua Kubernetes manifest mà không cần cấu hình hạ tầng (Google tự động quản lý node provisioning, scaling, upgrades, billing).
  • Bạn vẫn có full control trên deployment (Pod specs, HPA, etc.) vì đây là Kubernetes thuần túy.
  • Lý tưởng cho dev/ops muốn tập trung vào app, giảm chi phí vận hành lên đến 99% so với self-managed. ✅ Hoàn hảo khớp yêu cầu!

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai với lý do cụ thể:

  • Deploy the application on GKE Autopilot.
    ✅ Đúng. Như đã giải thích, Autopilot hỗ trợ Kubernetes manifest đầy đủ, tự động hóa toàn bộ hạ tầng (nodes, etcd, control plane), cho full control trên app mà minimize config. Phù hợp workload containerized production-scale. (Cập nhật 2026: Hỗ trợ Workload Identity Federation, Zonal Autopilot).

  • Deploy the application on Cloud Run.
    ❌ Sai. Cloud Run là serverless container platform, không sử dụng Kubernetes manifest trực tiếp (dùng gcloud run deploy hoặc YAML riêng, không phải kubectl apply). Không có full control Kubernetes (không chỉnh Pod topology, affinity), chỉ scale-to-zero HTTP/ gRPC. Phù hợp stateless web apps, không phải Kubernetes deployment.

  • Deploy the application on GKE Standard.
    ❌ Sai. GKE Standard cho full Kubernetes control qua manifest, nhưng yêu cầu cấu hình hạ tầng thủ công (node pools, machine types, autoscaling, taints). Không minimize config như yêu cầu – bạn phải quản lý nodes, tăng complexity và chi phí ops.

  • Deploy the application on Cloud Functions.
    ❌ Sai. Cloud Functions là serverless cho functions code (Node.js/Python/Go...), không hỗ trợ containerized apps hay Kubernetes manifest. Chỉ event-driven, stateless functions (max 60s/9min tùy gen), không full control deployment Kubernetes. Hoàn toàn không phù hợp!

🧠 Tóm tắt nhanh: Chọn Autopilot để "Kubernetes power + zero infra hassle"! Nếu cần thực hành, dùng gcloud container clusters create-auto để test. 🚀

Câu 396
Your team is building a website that handles votes from a large user population. The incoming votes will arrive at various rates. You want to optimize the storage and processing of the votes. What should you do?
  1. A Save the incoming votes to Firestore. Use Cloud Scheduler to trigger a Cloud Functions instance to periodically process the votes.
  2. B Use a dedicated instance to process the incoming votes. Send the votes directly to this instance.
  3. C Save the incoming votes to a JSON file on Cloud Storage. Process the votes in a batch at the end of the day.
  4. D Save the incoming votes to Pub/Sub. Use the Pub/Sub topic to trigger a Cloud Functions instance to process the votes.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả tình huống: Đội ngũ của bạn đang xây dựng một website xử lý phiếu bầu từ một lượng lớn người dùng. Các phiếu bầu đến với tốc độ biến đổi (various rates), nghĩa là có lúc nhiều, lúc ít. Mục tiêu là tối ưu hóa lưu trữ và xử lý phiếu bầu (optimize storage and processing), đòi hỏi giải pháp phải:

  • Xử lý tải biến động mà không bị nghẽn (scalable và resilient).
  • Decouple giữa việc nhận dữ liệu (producer) và xử lý (consumer) để tránh mất dữ liệu.
  • Serverless và cost-effective, phù hợp với Google Cloud Platform (GCP).

Đây là câu hỏi kinh điển về messaging system trong GCP, nhấn mạnh việc sử dụng Pub/Sub để làm message queue, giúp xử lý asynchronous và auto-scale. Kiến thức dựa trên tài liệu GCP cập nhật đến 2026 (Pub/Sub phiên bản 2.0+, Cloud Functions 2nd gen với event-driven triggers).
📘 Nguồn tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Save the incoming votes to Pub/Sub. Use the Pub/Sub topic to trigger a Cloud Functions instance to process the votes.

Lý do:
🛠️ Pub/Sub là message queue fully managed của GCP, lý tưởng cho high-throughput và variable rates. Nó decouples producer (website nhận votes) và consumer (Cloud Functions xử lý), đảm bảo không mất dữ liệu ngay cả khi consumer chậm hoặc scale up/down. Pub/Sub auto-scales (lên đến hàng triệu messages/giây), at-least-once delivery, và trigger trực tiếp Cloud Functions (event-driven, serverless). Giải pháp này tối ưu chi phí, real-time processing, phù hợp quy mô lớn. Không cần quản lý server, hoàn hảo cho votes đến liên tục!

📋 Giải thích chi tiết tất cả các phương án

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai với lý do cụ thể:

  • [SAI] Save the incoming votes to Firestore. Use Cloud Scheduler to trigger a Cloud Functions instance to periodically process the votes.
    ❌ Sai vì: Firestore là NoSQL database (không phải queue), dễ bị hotspots và throttling khi votes đến đột ngột (variable rates). Cloud Scheduler chỉ trigger định kỳ (ví dụ hàng giờ), dẫn đến xử lý không real-time, tích tụ dữ liệu lớn gây tốn kém và chậm trễ. Không decouple tốt, dễ mất dữ liệu nếu Functions fail giữa chừng. Không tối ưu cho high-volume streaming.

  • [SAI] Use a dedicated instance to process the incoming votes. Send the votes directly to this instance.
    ❌ Sai vì: "Dedicated instance" (như VM trên Compute Engine) là tightly coupled, không auto-scale tự động với traffic biến đổi → dễ overloaded hoặc underutilized. Single point of failure (nếu instance down, mất votes). Phải tự quản lý scaling (Managed Instance Groups), tốn công sức và chi phí cao hơn serverless. Không phù hợp optimize storage/processing cho large user population.

  • [SAI] Save the incoming votes to a JSON file on Cloud Storage. Process the votes in a batch at the end of day.
    ❌ Sai vì: Cloud Storage là object storage rẻ cho archival, không phải queue → không hỗ trợ atomic writes hoặc ordering cho votes real-time. Batch end-of-day gây delay lớn (không real-time), khó handle variable rates (file lớn gây bottleneck). Không decouple, dễ race conditions khi append JSON. Chỉ phù hợp batch jobs thấp tần suất, không optimize cho votes liên tục.

  • [ĐÚNG] Save the incoming votes to Pub/Sub. Use the Pub/Sub topic to trigger a Cloud Functions instance to process the votes.
    ✅ Đúng vì: Như đã giải thích ở trên, Pub/Sub + Cloud Functions là best practice cho event-driven architecture. Pub/Sub lưu trữ tạm (retention lên 7 ngày), trigger Functions automatically và scale infinitely. Xử lý votes ngay lập tức, resilient với retries, cost chỉ tính per message. Hoàn hảo cho scenario này!
    🏆 Khuyến nghị thực tế: Sử dụng Dataflow nếu cần complex processing sau Pub/Sub.

Câu 397
You are deploying an application on Google Cloud that requires a relational database for storage. To satisfy your company’s security policies, your application must connect to your database through an encrypted and authenticated connection that requires minimal management and integrates with Identity and Access Management (IAM). What should you do?
  1. A Deploy a Cloud SQL database with the SSL mode set to encrypted only, configure SSL/TLS client certificates, and configure a database user and password.
  2. B Deploy a Cloud SQL database with the SSL mode set to encrypted only, configure SSL/TLS client certificates, and configure IAM database authentication.
  3. C Deploy a Cloud SQL database and configure IAM database authentication. Access the database through the Cloud SQL Auth Proxy.
  4. D Deploy a Cloud SQL database and configure a database user and password. Access the database through the Cloud SQL Auth Proxy.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi này tập trung vào việc triển khai một ứng dụng trên Google Cloud cần sử dụng cơ sở dữ liệu quan hệ (relational database). Yêu cầu chính là kết nối đến database phải mã hóa (encrypted), xác thực (authenticated), yêu cầu quản lý tối thiểu (minimal management), và tích hợp với Identity and Access Management (IAM) để tuân thủ chính sách bảo mật của công ty.
📌 Các yếu tố then chốt:

  • Sử dụng Cloud SQL (dịch vụ managed relational DB của Google Cloud, hỗ trợ MySQL, PostgreSQL, SQL Server).
  • Kết nối phải an toàn, không cần quản lý phức tạp như certificate hoặc password thủ công.
  • Tích hợp IAM để xác thực dựa trên quyền truy cập Google Cloud (không dùng user/password truyền thống).
    🛠️ Bối cảnh cập nhật 2026: Theo tài liệu Google Cloud mới nhất (phiên bản Cloud SQL v2024+), Cloud SQL Auth Proxy là giải pháp khuyến nghị cho kết nối IAM-based, hỗ trợ encryption tự động qua TLS 1.3 và xác thực không trạng thái (stateless) với service accounts.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Deploy a Cloud SQL database and configure IAM database authentication. Access the database through the Cloud SQL Auth Proxy.

Lý do:

  • Phương án này đáp ứng toàn bộ yêu cầu:
    • Encrypted & Authenticated: Cloud SQL Auth Proxy tự động mã hóa kết nối qua TLS và xác thực bằng IAM (sử dụng service account tokens).
    • Minimal management: Không cần quản lý SSL/TLS certificates, database user/password, hoặc public IP (proxy xử lý tất cả).
    • Integrates with IAM: Bật IAM database authentication trên Cloud SQL (hỗ trợ MySQL/PostgreSQL), kết hợp proxy để ứng dụng kết nối an toàn từ bất kỳ đâu.
      🧩 Đây là best practice theo Google Cloud, giảm rủi ro lộ thông tin xác thực và dễ scale.

📘 Giải thích tất cả các phương án

Dưới đây là phân tích từng lựa chọn (giữ nguyên văn bản gốc bằng tiếng Anh). Tôi đánh dấu ✅ đúng, ❌ sai và giải thích chi tiết bằng tiếng Việt:

  • [SAI] Deploy a Cloud SQL database with the SSL mode set to encrypted only, configure SSL/TLS client certificates, and configure a database user and password.
    ❌ Sai vì: Yêu cầu quản lý thủ công SSL/TLS client certificates và database user/password, vi phạm "minimal management". Không tích hợp IAM (vẫn dùng password truyền thống). Encryption chỉ một phần, nhưng phức tạp hơn cần thiết.

  • [SAI] Deploy a Cloud SQL database with the SSL mode set to encrypted only, configure SSL/TLS client certificates, and configure IAM database authentication.
    ❌ Sai vì: Vẫn phải cấu hình và quản lý SSL/TLS client certificates thủ công (cần generate, rotate certs định kỳ), không "minimal management". IAM auth chỉ là một phần, nhưng thiếu proxy để simplify kết nối.

  • [ĐÚNG] Deploy a Cloud SQL database and configure IAM database authentication. Access the database through the Cloud SQL Auth Proxy.
    ✅ Đúng vì: Hoàn hảo khớp yêu cầu – IAM auth + Auth Proxy cung cấp encryption TLS tự động, xác thực qua service accounts, zero management certs/passwords. Proxy chạy local hoặc containerized, hỗ trợ private IP.

  • [SAI] Deploy a Cloud SQL database and configure a database user and password. Access the database through the Cloud SQL Auth Proxy.
    ❌ Sai vì: Sử dụng user/password thay vì IAM, không "integrates with IAM". Proxy hỗ trợ password nhưng khuyến nghị IAM để secure hơn; phương án này vẫn cần quản lý credentials database.

📚 Tài liệu tham khảo (cập nhật 2026)

Câu 398
You have two Google Cloud projects: project-a with VPC vpc-a (10.0.0.0/16) and project-b with VPC vpc-b (10.8.0.0/16). Your frontend application resides in vpc-a and the backend API services are deployed in vpc-b. You need to efficiently and cost-effectively enable communication between these Google Cloud projects. You also want to follow Google-recommended practices. What should you do?
  1. A Create an OpenVPN connection between vpc-a and vpc-b.
  2. B Create VPC Network Peering between vpc-a and vpc-b.
  3. C Configure a Cloud Router in vpc-a and another Cloud Router in vpc-b.
  4. D Configure a Cloud Interconnect connection between vpc-a and vpc-b.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi mô tả tình huống bạn có hai Google Cloud projects riêng biệt:

  • project-a chứa VPC vpc-a với dải địa chỉ 10.0.0.0/16.
  • project-b chứa VPC vpc-b với dải địa chỉ 10.8.0.0/16.

Ứng dụng frontend nằm trong vpc-a, còn backend API services nằm trong vpc-b.
Yêu cầu là kích hoạt giao tiếp giữa hai VPC này một cách hiệu quả (efficient), tiết kiệm chi phí (cost-effective), và tuân thủ các thực hành khuyến nghị của Google (Google-recommended practices).

📌 Điểm quan trọng: Hai VPC thuộc hai projects khác nhau (cross-project), subnets không overlap (không chồng chéo địa chỉ IP), nên cần giải pháp kết nối private network nội bộ GCP mà không qua internet công cộng. Giải pháp phải đơn giản, rẻ tiền, và đáng tin cậy.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create VPC Network Peering between vpc-a and vpc-b.

🛠️ Lý do chi tiết:

  • VPC Network Peering là giải pháp khuyến nghị chính thức của Google để kết nối hai VPC (cùng hoặc khác project/region) qua private IP, không qua internet, với độ trễ thấp và chi phí thấp nhất (chỉ tính theo dữ liệu truyền, không phí kết nối cố định).
  • Hỗ trợ cross-project peering hoàn hảo cho trường hợp này: frontend ở vpc-a có thể gọi trực tiếp backend ở vpc-b qua IP private (ví dụ: 10.8.x.x).
  • Tuân thủ best practices: Dễ thiết lập qua Console/CLI/gcloud, tự động route traffic giữa peered networks, không cần thiết bị trung gian.
  • Cập nhật 2026: VPC Peering vẫn là lựa chọn hàng đầu (Global VPC Network Peering hỗ trợ multi-region), theo docs GCP mới nhất (không có thay đổi cơ bản từ 2023-2026).

Nguồn tham khảo:
📘 Google Cloud VPC Peering Docs
📘 Best Practices for VPC Design

❌ Phân tích tất cả các phương án (đúng/sai)

Dưới đây là giải thích từng lựa chọn một cách chi tiết, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá đúng/sai dựa trên yêu cầu "efficient, cost-effective, Google-recommended".

  • Create an OpenVPN connection between vpc-a and vpc-b.
    ❌ Sai: OpenVPN tạo tunnel VPN qua internet công cộng, dẫn đến độ trễ cao, không an toàn (cần mã hóa), và chi phí cao hơn (phí dữ liệu outbound + license VPN). Không phải best practice của Google cho kết nối nội bộ GCP; chỉ dùng cho hybrid cloud (on-prem to GCP). Không efficient cho cross-project VPC.

  • Create VPC Network Peering between vpc-a and vpc-b.
    ✅ Đúng: Như đã giải thích ở trên. Giải pháp tối ưu nhất: private, nhanh, rẻ, dễ quản lý. Hỗ trợ non-overlapping CIDR và cross-project peering trực tiếp.

  • Configure a Cloud Router in vpc-a and another Cloud Router in vpc-b.
    ❌ Sai: Cloud Router dùng cho dynamic routing (BGP) với VPN/Interconnect/HA VPN, không phải để kết nối trực tiếp hai VPC. Chỉ thiết lập router riêng lẻ không tạo kết nối; cần peering hoặc gateway trước. Không giải quyết vấn đề, lãng phí và không recommended cho trường hợp đơn giản này.

  • Configure a Cloud Interconnect connection between vpc-a and vpc-b.
    ❌ Sai: Cloud Interconnect (Dedicated/Partner) dành cho kết nối on-premises đến GCP với bandwidth cao (10Gbps+), chi phí rất cao (phí port + cross-connect). Không áp dụng cho hai VPC nội bộ GCP; phức tạp, không efficient/cost-effective. Google khuyến nghị peering thay thế.

Tóm tắt nhanh 🎯: VPC Peering là "one-click" solution lý tưởng, các phương án khác overkill hoặc không phù hợp! Nếu triển khai, dùng lệnh gcloud compute networks peerings create để peering nhanh chóng.

Câu 399
Your company is running a critical workload on a single Compute Engine VM instance. Your company's disaster recovery policies require you to back up the entire instance’s disk data every day. The backups must be retained for 7 days. You must configure a backup solution that complies with your company’s security policies and requires minimal setup and configuration. What should you do?
  1. A Configure the instance to use persistent disk asynchronous replication.
  2. B Configure daily scheduled persistent disk snapshots with a retention period of 7 days.
  3. C Configure Cloud Scheduler to trigger a Cloud Function each day that creates a new machine image and deletes machine images that are older than 7 days.
  4. D Configure a bash script using gsutil to run daily through a cron job. Copy the disk’s files to a Cloud Storage bucket with archive storage class and an object lifecycle rule to delete the objects after 7 days.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi này thuộc chủ đề quản lý backup và disaster recovery trong Google Cloud Platform (GCP), cụ thể là với Compute Engine VM instances.

  • Bối cảnh: Công ty đang chạy một workload quan trọng trên một VM instance duy nhất. Chính sách disaster recovery yêu cầu backup toàn bộ dữ liệu đĩa (disk data) của instance hàng ngày, và giữ backup trong 7 ngày.
  • Yêu cầu chính:
    • Giải pháp phải tuân thủ chính sách bảo mật của công ty (security policies).
    • Cấu hình tối thiểu (minimal setup and configuration) – nghĩa là dễ thiết lập, tự động, không cần code phức tạp hay script thủ công.
  • Mục tiêu: Tìm giải pháp backup disk data (không phải toàn bộ instance), hàng ngày, retention 7 ngày, incremental và hiệu quả để tiết kiệm chi phí lưu trữ.

Đây là câu hỏi kiểu Google Associate Cloud Engineer, kiểm tra kiến thức về Persistent Disk Snapshots – công cụ backup chuẩn của GCP cho disks. (Lưu ý: Người dùng đề cập "AWS" có thể là nhầm lẫn, vì toàn bộ thuật ngữ là GCP: Compute Engine, Persistent Disk, Cloud Scheduler, gsutil, Cloud Storage).

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Configure daily scheduled persistent disk snapshots with a retention period of 7 days.

Lý do 🛠️:

  • Persistent Disk Snapshots là giải pháp chính thức, tự động của GCP để backup toàn bộ dữ liệu disk (incremental, chỉ lưu thay đổi).
  • Scheduled snapshots: Có thể thiết lập lịch hàng ngày qua Console/CLI/gcloud, retention policy 7 ngày tự động xóa snapshot cũ – minimal setup (chỉ vài cú click, không code).
  • Tuân thủ security: Snapshots mã hóa mặc định (customer-managed keys nếu cần), lưu ở regional/multi-regional, an toàn cho DR.
  • Hiệu quả: Chi phí thấp (lưu incremental), phù hợp workload critical trên single VM.
  • Phiên bản mới nhất (2026): Hỗ trợ Snapshot Schedules với auto-retention, integration IAM cho security.

📋 Giải thích tất cả các phương án (đúng/sai)

  • [SAI] Configure the instance to use persistent disk asynchronous replication.
    ❌ Sai vì: Asynchronous replication (qua Regional PD hoặc Zonal PD với replication) chỉ dùng cho high availability (HA) giữa các zone/region, không phải backup. Nó replicate real-time data cho failover, không có retention 7 ngày, không snapshot lịch, và không minimal (cần config multi-zone). Không backup "entire disk data" mà chỉ sync live data. (Không phù hợp DR policy).

  • [ĐÚNG] Configure daily scheduled persistent disk snapshots with a retention period of 7 days.
    ✅ Đúng vì: Như giải thích trên – giải pháp chuẩn, minimal setup (gcloud compute snapshot-schedule hoặc Console), backup full disk daily, auto-delete sau 7 ngày. Hoàn hảo cho yêu cầu!

  • [SAI] Configure Cloud Scheduler to trigger a Cloud Function each day that creates a new machine image and deletes machine images that are older than 7 days.
    ❌ Sai vì: Machine images backup toàn bộ instance (disk + metadata), không chỉ disk data, tốn kém hơn snapshots (full copy mỗi lần). Cần code Cloud Function + logic delete – không minimal setup. Cloud Scheduler + Function phức tạp, dễ lỗi, không hiệu quả cho daily disk backup. (Tốt hơn cho full instance migration, không phải DR disk).

  • [SAI] Configure a bash script using gsutil to run daily through a cron job. Copy the disk’s files to a Cloud Storage bucket with archive storage class and an object lifecycle rule to delete the objects after 7 days.
    ❌ Sai vì: Script gsutil chỉ copy files (cần mount disk, sync files), không backup toàn bộ disk (mất cấu trúc filesystem, quyền, boot sector). Cron job trên VM không reliable (VM down thì fail), không minimal (viết script, manage cron, IAM). Archive class rẻ nhưng chậm restore. Vi phạm security (dữ liệu raw upload bucket). Không incremental, tốn bandwidth/storage.

🏆 Kết luận: Snapshots là lựa chọn tối ưu nhất cho minimal config, security, và hiệu suất GCP! Nếu cần thực hành, dùng gcloud: gcloud compute disks snapshot <disk-name> --snapshot-names=daily-backup.

Câu 400
Your company requires that Google Cloud products are created with a specific configuration to comply with your company’s security policies. You need to implement a mechanism that will allow software engineers at your company to deploy and update Google Cloud products in a preconfigured and approved manner. What should you do?
  1. A Create Java packages that utilize the Google Cloud Client Libraries for Java to configure Google Cloud products. Store and share the packages in a source code repository.
  2. B Create bash scripts that utilize the Google Cloud CLI to configure Google Cloud products. Store and share the bash scripts in a source code repository.
  3. C Use the Google Cloud APIs by using curl to configure Google Cloud products. Store and share the curl commands in a source code repository.
  4. D Create Terraform modules that utilize the Google Cloud Terraform Provider to configure Google Cloud products. Store and share the modules in a source code repository.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi này thuộc chủ đề Infrastructure as Code (IaC) trên Google Cloud Platform (GCP), tập trung vào việc triển khai và cập nhật các sản phẩm Google Cloud (như VM, mạng, storage, v.v.) một cách tiêu chuẩn hóa, tự động hóa và tuân thủ chính sách bảo mật công ty.

  • Yêu cầu chính: Công ty cần một cơ chế để các kỹ sư phần mềm có thể deploy và update tài nguyên GCP với cấu hình đã được pre-configure và approved (cấu hình chuẩn hóa và được phê duyệt trước), tránh việc cấu hình thủ công dẫn đến sai sót hoặc vi phạm security policies.
  • Mục tiêu: Đảm bảo tính lặp lại (repeatable), kiểm soát phiên bản (version-controlled), kiểm toán (auditable) và tích hợp CI/CD, phù hợp với best practices của GCP đến năm 2026 (Terraform Provider for Google Cloud phiên bản mới nhất là v6.x, hỗ trợ đầy đủ các dịch vụ như GKE, Cloud Run, AlloyDB).
  • Ngữ cảnh: Đây là bài kiểm tra kỹ năng Associate Cloud Engineer, nhấn mạnh sử dụng công cụ IaC chuyên dụng thay vì scripts thủ công.

📘 Tài liệu tham khảo:

✅ Đáp án đúng

Create Terraform modules that utilize the Google Cloud Terraform Provider to configure Google Cloud products. Store and share the modules in a source code repository.

Lý do lựa chọn:

  • Terraform là công cụ IaC declarative (mô tả trạng thái mong muốn) được Google Cloud chính thức khuyến nghị cho việc quản lý hạ tầng đa cloud, hỗ trợ modules tái sử dụng để pre-configure tài nguyên theo security policies (ví dụ: VPC với firewall rules chuẩn, IAM roles approved).
  • Lợi ích:
    • Tự động hóa deploy/update qua plan/apply (kiểm tra trước khi thay đổi).
    • Version control trong Git repo, dễ review/merge PR.
    • Tích hợp CI/CD (Cloud Build, GitHub Actions), hỗ trợ state management với Cloud Storage backend.
    • Đảm bảo compliance qua policies-as-code (OPA/Conftest) và drift detection.
  • Phù hợp nhất với yêu cầu "preconfigured and approved manner" vì modules có thể được private registry (Terraform Registry hoặc Artifact Registry trên GCP).

🛠️ Phân tích tất cả các phương án

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên nội dung gốc tiếng Anh. Tôi đánh dấu ✅ cho đúng và ❌ cho sai, kèm giải thích bằng tiếng Việt:

  • ❌ Create Java packages that utilize the Google Cloud Client Libraries for Java to configure Google Cloud products. Store and share the packages in a source code repository.

    • Sai vì: Đây chỉ là SDK lập trình (Client Libraries v2.x mới nhất 2026), dùng cho ứng dụng tùy chỉnh chứ không phải IaC. Không declarative, khó đảm bảo cấu hình chuẩn hóa (dễ lỗi code imperative), không có plan/apply hay state management. Phù hợp dev app hơn là infra deploy.
  • ❌ Create bash scripts that utilize the Google Cloud CLI to configure Google Cloud products. Store and share the bash scripts in a source code repository.

    • Sai vì: gcloud CLI (phiên bản 450+ năm 2026) là công cụ imperative (chạy lệnh theo thứ tự), dễ sai sót khi scale/update, không kiểm tra drift hay preview thay đổi. Bash scripts khó maintain, không tái sử dụng tốt như modules, vi phạm yêu cầu "preconfigured" (phải hardcode config).
  • ❌ Use the Google Cloud APIs by using curl to configure Google Cloud products. Store and share the curl commands in a source code repository.

    • Sai vì: REST APIs qua curl là thủ công nhất, không tự động hóa, không version control state, dễ lỗi auth/token và thứ tự gọi API. Không phù hợp IaC, chỉ dùng cho testing/debug, không đảm bảo compliance security policies khi engineers tự deploy.
  • ✅ Create Terraform modules that utilize the Google Cloud Terraform Provider to configure Google Cloud products. Store and share the modules in a source code repository.

    • Đúng vì: Như đã giải thích ở trên, là best practice IaC của GCP, hỗ trợ modules reusable, HCL syntax dễ đọc, tích hợp đầy đủ với GCP services (ví dụ: google_project_iam_member cho security). Repo lưu trữ cho phép collaboration an toàn.

🧩 Kết luận: Terraform là lựa chọn tối ưu cho IaC trên GCP, giúp công ty kiểm soát chặt chẽ security policies mà không hy sinh tốc độ phát triển! Nếu cần ví dụ code Terraform module, hãy hỏi thêm nhé 🚀.