Ngân hàng đề — Google Cloud Professional Cloud Architect

Tìm thấy 333 câu.

Câu 301
Company Overview -

Altostrat is a prominent player in the media industry, with an extensive collection of audio and video content that comprises podcasts, interviews, news broadcasts, and documentaries. Their success in delivering premium content to a diverse audience requires a content management system that can keep pace with the dynamic media landscape.


Solution Concept -

Altostrat seeks to modernize its content management and user engagement strategies using Google Cloud's generative AI. They want a platform that empowers customers with personalized recommendations, natural language interactions and seamless self-service support. Simultaneously, they want to drive revenue growth through dynamic pricing targeted marketing, and personalized product suggestions.

The seamless integration of AI-powered tools into the existing Google Cloud environment will enable Altostrat to efficiently manage their vast media library, enhance user experiences, and unlock new revenue streams. Google Cloud's generative AI will solidify their leadership in the media industry.


Existing Technical Environment -

Altostrat’s content management and delivery platform leverages GKE for scalability and high availability, essential for handling their vast media library. Their extensive media library spanning various documents, audio and video formats is stored in Cloud Storage. To gain valuable insights into user behavior, content consumption patterns, and audience demographics, Altostrat leverages BigQuery as their primary data warehouse. Additionally, they use Cloud Run functions for serverless execution of event-driven tasks such as video transcoding metadata extraction, and personalized content recommendations.

While Altostrat has made significant strides in cloud adoption, they also maintain some legacy on-premises systems for specific workflows like content ingestion and archival. These systems are slated for modernization and migration to Google Cloud in the near future. User management and authentication are currently handled through a combination of Google Identity and third-party identity providers. For monitoring and observability, Altostrat relies on a mix of native Google Cloud tools like Cloud Monitoring and open-source solutions like Prometheus, with alerts primarily delivered via email notifications.


Business Requirements -

•Accelerate and enhance the reliability of operational workflows across all environments. [Google Cloud + On-premises]
•Simplify infrastructure management for rapid application deployment.
•Optimize cloud storage costs while maintaining high availability and scalability for media content.
•Enable natural language interaction with the platform with 24/7 user support.
•Automatically generate concise summaries of media content.
•Extract rich metadata from media assets using NLP and computer vision.
•Detect and filter inappropriate content.
•Analyze media content to identify trends and extract insights.
•Inform content strategy and decision making with data.


Technical Requirements -

•Modernize CI/CD for containerized deployments with a centralized management platform.
•Secure, high-performance hybrid cloud connectivity for data ingestion.
•Provide scalable, performant kubernetes environments both on-premises and in the cloud.
•Optimize cloud storage costs for growing media volumes.
•Design AI-powered detection of harmful content.
•Ensure that AI systems are auditable and their decisions can be explained.
•Leverage LLMs and conversational AI for personalized experiences and content virality.
•Develop advanced chatbots with natural language understanding to provide personalized assistance.
•Automated summarization for diverse media.


Executive Statement -

At Altostrat, we are embracing the next frontier of artificial intelligence to revolutionize our content strategy. By harnessing the power of generative AI, we will create an unparalleled user experience by empowering our audience with intelligent toots for content discovery, personalized recommendations, and seamless interaction. Reliability and cost management are our top priorities. This strategic initiative will deepen engagement, foster customer loyalty, and unlock new revenue streams through targeted marketing and tailored content offerings. We see a future where Al-driven innovation is central to our business, leading to greater success for our company and delivering exceptional value to our customers.


For this question, refer to the Altostrat Media case study. Altostrat needs to analyze the performance of its media processing pipeline running on Java-based Cloud Run function. You need to select the most effective tool for the task. What should you do?
  1. A Query logs in Cloud Logging.
  2. B Analyze the data via Cloud Profiler.
  3. C Instrument the code to use Cloud Trace.
  4. D Inspect data from Snapshot Debugger.
Xem giải thích

🧩 Giải thích nội dung câu hỏi

Câu hỏi tập trung vào case study của công ty Altostrat Media, một doanh nghiệp trong ngành truyền thông quản lý thư viện nội dung lớn (audio, video, podcast, v.v.) trên Google Cloud. Họ sử dụng GKE cho scalability, Cloud Storage lưu trữ media, BigQuery phân tích dữ liệu, và Cloud Run cho các tác vụ serverless như transcoding video, extract metadata, và recommendations cá nhân hóa.

Vấn đề cụ thể: Altostrat cần phân tích hiệu suất (performance) của media processing pipeline chạy trên Java-based Cloud Run function. Đây là một pipeline xử lý media (ví dụ: transcoding, metadata extraction), và nhiệm vụ là chọn công cụ hiệu quả nhất để phân tích performance. Performance ở đây thường bao gồm CPU usage, memory allocation, bottlenecks trong code Java, giúp tối ưu hóa chi phí và độ tin cậy – phù hợp với yêu cầu kinh doanh như "accelerate operational workflows" và "optimize cloud storage costs".

Câu hỏi yêu cầu kiến thức về các công cụ observability của Google Cloud (Logging, Profiler, Trace, Debugger), cập nhật đến phiên bản mới nhất 2026: Cloud Profiler hỗ trợ Java native trên Cloud Run mà không cần instrumentation thủ công, tích hợp seamless với Alloy agents cho continuous profiling.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Analyze the data via Cloud Profiler.

Lý do:

  • 🛠️ Cloud Profiler là công cụ chuyên dụng để phân tích performance chi tiết của ứng dụng (CPU, memory, wall time) trên Cloud Run, đặc biệt với Java apps. Nó thu thập dữ liệu profiling tự động (continuous profiling) mà không cần thay đổi code, hiển thị flame graphs để xác định bottlenecks trong media processing pipeline (như transcoding loops hoặc metadata extraction).
  • Phù hợp nhất với pipeline Java trên Cloud Run vì tích hợp native, giúp optimize chi phí và reliability – đúng với Technical Requirements (modernize workflows, auditable AI systems).
  • Hiệu quả hơn các tool khác vì tập trung vào code-level performance metrics, không chỉ logs hay traces.

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng phương án (giữ nguyên văn bản gốc tiếng Anh). Tôi đánh dấu ✅ đúng hoặc ❌ sai, kèm giải thích chi tiết bằng tiếng Việt:

  • ❌ [SAI] Query logs in Cloud Logging.
    Phương án này không hiệu quả nhất vì Cloud Logging chỉ thu thập và query logs (structured/unstructured data như error messages, timestamps), không cung cấp performance profiling sâu (CPU/memory hotspots). Dùng cho debugging events hoặc errors trong pipeline, nhưng không analyze bottlenecks code-level như loops chậm trong Java transcoding. Logs hữu ích bổ sung nhưng không phải tool chính cho performance analysis.

  • ✅ [ĐÚNG] Analyze the data via Cloud Profiler.
    Như đã giải thích ở trên: Công cụ lý tưởng cho performance của Java Cloud Run function. Tự động profile mà không instrument code, hỗ trợ media workloads lớn (ví dụ: detect high-memory allocation trong video processing). Kết quả trực quan (flame charts), giúp optimize ngay – khớp yêu cầu "enhance reliability of operational workflows".

  • ❌ [SAI] Instrument the code to use Cloud Trace.
    Cloud Trace dùng cho distributed tracing (latency, spans qua services), yêu cầu instrument code (thêm SDK vào Java app) – phức tạp và không tự động. Tốt cho end-to-end pipeline latency (ví dụ: trace từ Cloud Storage đến Run), nhưng không chuyên performance profiling như CPU hotspots. Không phải lựa chọn "most effective" vì tốn công instrument và ít chi tiết code-level hơn Profiler.

  • ❌ [SAI] Inspect data from Snapshot Debugger.
    Snapshot Debugger (Cloud Debugger) dùng để debug runtime states (inspect variables tại breakpoints mà không dừng app), phù hợp troubleshooting bugs chứ không phải performance analysis. Chỉ chụp snapshots theo điều kiện, không profile liên tục CPU/memory như Profiler. Không hiệu quả cho pipeline media lớn cần metrics tổng quát.

🧩 Tóm tắt khuyến nghị: Chọn Cloud Profiler để nhanh chóng identify và fix bottlenecks, sau đó kết hợp Logging/Trace cho observability toàn diện. Điều này giúp Altostrat đạt "top priorities: reliability and cost management" từ Executive Statement! 🚀

Câu 302
Company Overview -

Altostrat is a prominent player in the media industry, with an extensive collection of audio and video content that comprises podcasts, interviews, news broadcasts, and documentaries. Their success in delivering premium content to a diverse audience requires a content management system that can keep pace with the dynamic media landscape.


Solution Concept -

Altostrat seeks to modernize its content management and user engagement strategies using Google Cloud's generative AI. They want a platform that empowers customers with personalized recommendations, natural language interactions and seamless self-service support. Simultaneously, they want to drive revenue growth through dynamic pricing targeted marketing, and personalized product suggestions.

The seamless integration of AI-powered tools into the existing Google Cloud environment will enable Altostrat to efficiently manage their vast media library, enhance user experiences, and unlock new revenue streams. Google Cloud's generative AI will solidify their leadership in the media industry.


Existing Technical Environment -

Altostrat’s content management and delivery platform leverages GKE for scalability and high availability, essential for handling their vast media library. Their extensive media library spanning various documents, audio and video formats is stored in Cloud Storage. To gain valuable insights into user behavior, content consumption patterns, and audience demographics, Altostrat leverages BigQuery as their primary data warehouse. Additionally, they use Cloud Run functions for serverless execution of event-driven tasks such as video transcoding metadata extraction, and personalized content recommendations.

While Altostrat has made significant strides in cloud adoption, they also maintain some legacy on-premises systems for specific workflows like content ingestion and archival. These systems are slated for modernization and migration to Google Cloud in the near future. User management and authentication are currently handled through a combination of Google Identity and third-party identity providers. For monitoring and observability, Altostrat relies on a mix of native Google Cloud tools like Cloud Monitoring and open-source solutions like Prometheus, with alerts primarily delivered via email notifications.


Business Requirements -

•Accelerate and enhance the reliability of operational workflows across all environments. [Google Cloud + On-premises]
•Simplify infrastructure management for rapid application deployment.
•Optimize cloud storage costs while maintaining high availability and scalability for media content.
•Enable natural language interaction with the platform with 24/7 user support.
•Automatically generate concise summaries of media content.
•Extract rich metadata from media assets using NLP and computer vision.
•Detect and filter inappropriate content.
•Analyze media content to identify trends and extract insights.
•Inform content strategy and decision making with data.


Technical Requirements -

•Modernize CI/CD for containerized deployments with a centralized management platform.
•Secure, high-performance hybrid cloud connectivity for data ingestion.
•Provide scalable, performant kubernetes environments both on-premises and in the cloud.
•Optimize cloud storage costs for growing media volumes.
•Design AI-powered detection of harmful content.
•Ensure that AI systems are auditable and their decisions can be explained.
•Leverage LLMs and conversational AI for personalized experiences and content virality.
•Develop advanced chatbots with natural language understanding to provide personalized assistance.
•Automated summarization for diverse media.


Executive Statement -

At Altostrat, we are embracing the next frontier of artificial intelligence to revolutionize our content strategy. By harnessing the power of generative AI, we will create an unparalleled user experience by empowering our audience with intelligent toots for content discovery, personalized recommendations, and seamless interaction. Reliability and cost management are our top priorities. This strategic initiative will deepen engagement, foster customer loyalty, and unlock new revenue streams through targeted marketing and tailored content offerings. We see a future where Al-driven innovation is central to our business, leading to greater success for our company and delivering exceptional value to our customers.


For this question, refer to the Altostrat Media case study. Altostrat is concerned about sophisticated, multi-vector Distributed Denial of Service (DDoS) attacks targeting various layers of their infrastructure. DDoS attacks could potentially disrupt video streaming and cause financial losses. You need to mitigate this risk. What should you do?
  1. A Set up VPC Service Controls to restrict access to sensitive resources and prevent data exfiltration.
  2. B Configure Cloud Next Generation Firewall (NGFW) with custom rules to filter malicious traffic at the network level.
  3. C Deploy Google Cloud Armor with pre-configured and custom rules for L3/L4 and L7 protection
  4. D Activate Security Command Center to monitor security posture and detect potential threats.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào case study của công ty Altostrat Media, một doanh nghiệp lớn trong ngành truyền thông với thư viện nội dung phong phú (audio, video, podcast, v.v.). Họ đang sử dụng Google Cloud làm nền tảng chính: GKE cho scalability, Cloud Storage lưu trữ media, BigQuery phân tích dữ liệu, Cloud Run cho serverless tasks, và một số hệ thống on-premises legacy sắp migrate. Yêu cầu kinh doanh nhấn mạnh tăng tốc workflow, tối ưu chi phí storage, AI cho personalization, summarization, metadata extraction, content moderation, và hybrid cloud connectivity. Đặc biệt, họ lo ngại về DDoS attacks tinh vi, multi-vector nhắm vào nhiều layer (L3/L4/L7), có thể làm gián đoạn video streaming và gây thiệt hại tài chính.

📌 Vấn đề cốt lõi: Cần mitigate rủi ro DDoS một cách hiệu quả, bảo vệ infrastructure đa tầng (network, application), phù hợp với môi trường Google Cloud hybrid (cloud + on-prem), ưu tiên reliability và cost management theo Executive Statement.

🛠️ Yêu cầu kỹ thuật liên quan: Cung cấp high-performance hybrid connectivity, scalable Kubernetes, và AI-powered security (auditable, explainable). Giải pháp phải chặn traffic malicious tại các layer khác nhau, đặc biệt cho media streaming cao tải.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Deploy Google Cloud Armor with pre-configured and custom rules for L3/L4 and L7 protection

Lý do:
Google Cloud Armor là dịch vụ DDoS protection chuyên dụng của Google Cloud, được thiết kế để chống lại các cuộc tấn công DDoS multi-vector, sophisticated ở L3/L4 (network/transport layer) và L7 (application layer). Nó cung cấp:

  • Pre-configured rules dựa trên threat intelligence toàn cầu từ Google (bao gồm adaptive protection tự động scale dựa trên traffic baseline).
  • Custom rules cho policy tùy chỉnh, rate limiting, IP allow/deny lists, và Geo-based filtering.
  • Tích hợp seamless với Load Balancers (HTTP(S), TCP/SSL Proxy, Network LB), lý tưởng cho video streaming trên GKE/Cloud Run/Cloud Storage.
  • Zero-trust model với hiệu suất cao, không cần hardware riêng, và cost-effective (pay-per-use).
    Điều này trực tiếp giải quyết mối lo disrupt video streaming, phù hợp với môi trường hybrid (hỗ trợ Anthos cho on-prem GKE) và cập nhật mới nhất 2026: Cloud Armor v2 với Edge Security nâng cao, Bot Management, và ML-based anomaly detection (theo Google Cloud Next 2025 announcements).

Nguồn tham khảo:

❌ Phân tích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng phương án một cách chi tiết. Tôi giữ nguyên văn bản gốc tiếng Anh của phương án, chỉ giải thích bằng tiếng Việt với lý do đúng/sai, sử dụng kiến thức GCP mới nhất (2026).

  • [SAI] Set up VPC Service Controls to restrict access to sensitive resources and prevent data exfiltration.
    ❌ Sai vì: VPC Service Controls (VPC-SC) chủ yếu dùng để ngăn data exfiltration và access control nội bộ giữa các service GCP (như bảo vệ bucket Cloud Storage khỏi unauthorized access bên ngoài perimeter). Nó không phải công cụ chống DDoS, không filter traffic malicious ở L3/L4/L7, và không bảo vệ public-facing services như video streaming LB. VPC-SC tập trung vào contextual access chứ không phải traffic volume/flooding attacks. Không phù hợp với multi-vector DDoS nhắm infrastructure layers.

  • [SAI] Configure Cloud Next Generation Firewall (NGFW) with custom rules to filter malicious traffic at the network level.
    ❌ Sai vì: Cloud NGFW (dựa trên Secure Firewall) là firewall-as-a-service cho network-level filtering (L3/L4), hỗ trợ custom rules, IPS/IDS, và Threat Intelligence. Tuy nhiên, nó không chuyên sâu cho DDoS multi-vector ở L7 (application), thiếu adaptive protection tự động scale chống volumetric attacks lớn (hàng Tbps mà Google tự động absorb). NGFW phù hợp hơn cho east-west traffic trong VPC, không phải public DDoS protection cho streaming (cần tích hợp LB + Cloud Armor). Theo docs 2026, khuyến nghị kết hợp nhưng không thay thế Cloud Armor.

  • [ĐÚNG] Deploy Google Cloud Armor with pre-configured and custom rules for L3/L4 and L7 protection
    ✅ Đúng vì: Như giải thích ở phần đáp án trên. Đây là giải pháp chính thức, toàn diện nhất cho DDoS trên GCP, bảo vệ toàn stack (network/app), tích hợp AI/ML cho detection real-time, và scale tự động với Google's global anycast network (hấp thụ >10Tbps). Hoàn hảo cho Altostrat's high-availability media delivery.

  • [SAI] Activate Security Command Center to monitor security posture and detect potential threats.
    ❌ Sai vì: Security Command Center (SCC) Premium là monitoring/detection tool (SIEM-like), quét vulnerabilities, misconfigs, và threat detection (bao gồm DDoS signals qua Cloud Monitoring integration). Nó không block/mitigate attacks trực tiếp (chỉ alert/notify), thiếu filtering rules L3/L4/L7. SCC tốt cho observability (đã dùng Cloud Monitoring + Prometheus), nhưng cần actionable protection như Cloud Armor để prevent disruption. Không giải quyết real-time DDoS mitigation.

🧠 Tóm tắt khuyến nghị: Kết hợp Cloud Armor với Cloud Load Balancing cho frontend, Anthos Service Mesh cho hybrid, và SCC cho monitoring toàn diện. Điều này đảm bảo reliability 99.99%+ cho streaming, tối ưu chi phí theo yêu cầu Altostrat! 🚀

Câu 303
Company Overview -

Altostrat is a prominent player in the media industry, with an extensive collection of audio and video content that comprises podcasts, interviews, news broadcasts, and documentaries. Their success in delivering premium content to a diverse audience requires a content management system that can keep pace with the dynamic media landscape.


Solution Concept -

Altostrat seeks to modernize its content management and user engagement strategies using Google Cloud's generative AI. They want a platform that empowers customers with personalized recommendations, natural language interactions and seamless self-service support. Simultaneously, they want to drive revenue growth through dynamic pricing targeted marketing, and personalized product suggestions.

The seamless integration of AI-powered tools into the existing Google Cloud environment will enable Altostrat to efficiently manage their vast media library, enhance user experiences, and unlock new revenue streams. Google Cloud's generative AI will solidify their leadership in the media industry.


Existing Technical Environment -

Altostrat’s content management and delivery platform leverages GKE for scalability and high availability, essential for handling their vast media library. Their extensive media library spanning various documents, audio and video formats is stored in Cloud Storage. To gain valuable insights into user behavior, content consumption patterns, and audience demographics, Altostrat leverages BigQuery as their primary data warehouse. Additionally, they use Cloud Run functions for serverless execution of event-driven tasks such as video transcoding metadata extraction, and personalized content recommendations.

While Altostrat has made significant strides in cloud adoption, they also maintain some legacy on-premises systems for specific workflows like content ingestion and archival. These systems are slated for modernization and migration to Google Cloud in the near future. User management and authentication are currently handled through a combination of Google Identity and third-party identity providers. For monitoring and observability, Altostrat relies on a mix of native Google Cloud tools like Cloud Monitoring and open-source solutions like Prometheus, with alerts primarily delivered via email notifications.


Business Requirements -

•Accelerate and enhance the reliability of operational workflows across all environments. [Google Cloud + On-premises]
•Simplify infrastructure management for rapid application deployment.
•Optimize cloud storage costs while maintaining high availability and scalability for media content.
•Enable natural language interaction with the platform with 24/7 user support.
•Automatically generate concise summaries of media content.
•Extract rich metadata from media assets using NLP and computer vision.
•Detect and filter inappropriate content.
•Analyze media content to identify trends and extract insights.
•Inform content strategy and decision making with data.


Technical Requirements -

•Modernize CI/CD for containerized deployments with a centralized management platform.
•Secure, high-performance hybrid cloud connectivity for data ingestion.
•Provide scalable, performant kubernetes environments both on-premises and in the cloud.
•Optimize cloud storage costs for growing media volumes.
•Design AI-powered detection of harmful content.
•Ensure that AI systems are auditable and their decisions can be explained.
•Leverage LLMs and conversational AI for personalized experiences and content virality.
•Develop advanced chatbots with natural language understanding to provide personalized assistance.
•Automated summarization for diverse media.


Executive Statement -

At Altostrat, we are embracing the next frontier of artificial intelligence to revolutionize our content strategy. By harnessing the power of generative AI, we will create an unparalleled user experience by empowering our audience with intelligent toots for content discovery, personalized recommendations, and seamless interaction. Reliability and cost management are our top priorities. This strategic initiative will deepen engagement, foster customer loyalty, and unlock new revenue streams through targeted marketing and tailored content offerings. We see a future where Al-driven innovation is central to our business, leading to greater success for our company and delivering exceptional value to our customers.


For this question, refer to the Altostrat Media case study. Altostrat is using Apigee for API management and wants to ensure their APIs are protected from overuse and abuse. You need to implement an Apigee feature to control the total number of API calls for cost management. What should you do?
  1. A Set up API key validation.
  2. B Integrate OAuth 2.0 authorization.
  3. C Configure Quota policies.
  4. D Activate XML threat protection.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi thuộc case study về công ty Altostrat Media, một doanh nghiệp trong ngành truyền thông quản lý thư viện nội dung lớn (audio, video, podcasts, v.v.) trên Google Cloud. Họ đang sử dụng Apigee (nền tảng quản lý API của Google Cloud) để quản lý các API, và mục tiêu là bảo vệ API khỏi tình trạng lạm dụng (overuse và abuse), đồng thời kiểm soát tổng số lượng cuộc gọi API (API calls) nhằm quản lý chi phí (cost management).

  • Bối cảnh chính: Altostrat có môi trường hybrid (Google Cloud + on-premises), sử dụng GKE, Cloud Storage, BigQuery, Cloud Run, và sắp migrate legacy systems. Họ tập trung vào AI generative (LLMs, NLP, computer vision) cho recommendation, summarization, content moderation, nhưng câu hỏi cụ thể xoay quanh Apigee để enforce quota trên API calls – tránh chi phí phát sinh do API bị gọi quá mức (ví dụ: từ bots, tấn công DDoS-like, hoặc user lạm dụng).
  • Yêu cầu kỹ thuật liên quan: Secure APIs, cost optimization, reliability cho workflows.
  • Vấn đề cốt lõi: Cần một tính năng cụ thể của Apigee để limit tổng số API calls (ví dụ: theo thời gian, user, hoặc key), không chỉ auth hay threat protection thông thường.

Câu hỏi kiểm tra kiến thức về Apigee policies (cập nhật đến 2026: Apigee hỗ trợ Quota policy với spike arrest, rate limiting tinh vi hơn, tích hợp Vertex AI cho analytics).

✅ Đáp án đúng: Configure Quota policies

Lý do lựa chọn:

  • Quota policy trong Apigee chính là tính năng được thiết kế để kiểm soát tổng số lượng API calls theo các tiêu chí như thời gian (interval: phút/giờ/ngày), số lượng tối đa (allow), và buffer (exceed). Nó giúp ngăn chặn overuse/abuse bằng cách reject calls vượt quota, đồng thời hỗ trợ cost management bằng cách tránh billing spike từ API usage cao bất thường.
  • Phù hợp hoàn hảo với nhu cầu của Altostrat: Quản lý chi phí storage/AI processing liên quan đến API calls (ví dụ: calls đến transcoding, metadata extraction).
  • Cập nhật mới: Từ Apigee X (hybrid/multi-cloud), Quota tích hợp với Analytics để audit, distributed counting cho scale lớn.
  • Nguồn tham khảo: 📘 Apigee Quota Policy Reference (Google Cloud Docs, cập nhật 2024-2026).

🛠️ Giải thích tất cả các phương án

  • Set up API key validation ❌
    Sai vì: Tính năng này chỉ xác thực (validate) API key để kiểm tra key hợp lệ, không kiểm soát tổng số lượng calls. Nó ngăn anonymous access nhưng không limit overuse (key hợp lệ vẫn gọi vô hạn). Không giải quyết cost management từ abuse.

  • Integrate OAuth 2.0 authorization ❌
    Sai vì: OAuth 2.0 dùng cho authorization (quyền truy cập scopes), không phải quota limiting. Nó bảo vệ identity/user roles nhưng không count/track tổng calls để enforce limit. Altostrat đã dùng Google Identity + third-party, nên cần quota bổ sung chứ không thay thế.

  • Configure Quota policies ✅
    Đúng vì: Như giải thích trên, đây là policy chính xác để enforce total API calls limit (ví dụ: 1000 calls/giờ per developer/app), với reject/HTTP 429 nếu vượt. Hỗ trợ refill interval, phù hợp hybrid setup của Altostrat và cost control.

  • Activate XML threat protection ❌
    Sai vì: Policy này chỉ phát hiện/threat filter XML payloads (như XXE attacks, oversized XML), không liên quan đến số lượng calls. Nó bảo vệ syntax-level threats, không phải quota/rate cho cost management.

Kết luận tổng quát 🎯: Chọn Quota policies là optimal vì trực tiếp match yêu cầu "control the total number of API calls for cost management". Kết hợp với SpikeArrest policy nếu cần rate limiting mịn hơn (cập nhật Apigee 2026). Khuyến nghị test trên Apigee Edge/X playground! 🚀

Câu 304
Company Overview -

KnightMotives is a car manufacturer specializing in autonomous, self-driving vehicles, including Battery Electric Vehicles (BEVs), hybrids and traditional internal combustion engine (ICE) vehicles. While KnightMotives has made strides with the in-vehicle experience in their BEV fleet, the hybrid and ICE vehicles have yet to implement these new systems and are viewed poorly by critics and drivers. The lack of modern in-vehicle technology in hybrid and ICE vehicles has resulted in declining sales and customer satisfaction.

KnightMotives wants to modernize the consumer experience across all vehicles within five years Artificial Intelligence offers a unique opportunity to revolutionize the in-vehicle experience, as well as the shopping buying and service/maintenance experience. Investment in this new technology will require a shift in financial priorities on a global scale.

KnightMotives also wants to improve their online ordering system, which is unreliable. Systems for customers to build their vehicle online for acquisition through a dealer are not delivering the data or reliability that dealers need, causing. A strain in the relationship between KnightMotives and dealers. Service technicians and sales staff need better tooling to enhance dealer successes, including built-to-order vehicles.


Solution Concept -

KnightMotives wants to shift from manufacturing cars to creating a complete and compelling “automotive experience.” Then strategy prioritizes delivering a consistent experience across all models, developing AI-powered features, generating new revenue from data monetization, adopting a digital focus to differentiate their brand from competitors, and developing better tools for mechanics and salespeople.


Existing Technical Environment -

KnightMotives's IT is largely on-premises with some applications on major cloud platforms. Their supply chain runs on an outdated mainframe, and Enterprise Resource Planning (ERP) is also outdated, making new promotions and dealer discounts difficult to implement. Dealers have no budget for new equipment. There is fragmentation across vehicles with multiple code bases, and significant technical debt from supporting backwards compatibility. Network connectivity to manufacturing plants and vehicle connectivity in rural areas are challenges.


Business Requirements -

Key business requirements include fostering a personalized relationship with the driver and delivering a cohesive experience across all models. Creating a better build-to-order model will reduce time on the lot and provide transparency for both dealers and customers. Additionally, KnightMotives seeks to monetize corporate data to finance new technology investments, as their current AI infrastructure is obsolete and corporate data remains siloed. Security is a paramount concern due to past data breaches Adherence to European Union (EU) data protection regulations, especially for emerging autonomous platforms, is critical.

KnightMotives plans to make significant investments in fully autonomous driving capabilities, with initial implementation targeting regions with favorable regulatory environments. Prioritizing employee upskilling, attracting top-tier talent, and fostering better communication between business and technical teams are also critical objectives.


Technical Requirements -

•Modernizing the in-vehicle experience includes developing a consistent user experience (UX) that seamlessly integrates AI-powered features across all models, updating in-vehicle hardware and software in legacy models to support new UX features and AI capabilities, and ensuring reliable network connectivity, especially in rural areas, to support real-time AI features and data transmission.
•Network upgrades are necessary to support increased data traffic and improve connectivity between plants and headquarters.
•IT infrastructure modernization requires adopting a hybrid cloud strategy to leverage the benefits of both on-premises and cloud infrastructure, and gradually modernizing or replacing legacy systems to improve efficiency and agility.
•Autonomous vehicle development and testing requires investing in cutting-edge AI and machine learning technologies, building a robust simulation environment, and ensuring compliance with evolving regulations related to autonomous vehicles.
•Data monetization and insights requires implementing a robust data management platform, strict data security and privacy measures, and a scalable AI/ML infrastructure.
•Increased focus on security and risk management involves implementing a comprehensive security framework to protect against cyber threats and data breaches, developing an incident response plan, and providing security awareness training to employees.
•Providing a delightful experience for dealers and customers requires improving the online build-to-order system; developing modern dealer tools to streamline dealer operations, including sales, service, and inventory management; and implementing a comprehensive Customer Relationship Management (CRM) system to track customer interactions personalize experiences, and improve customer satisfaction.


Executive Statement -

KnightMotives is committed to enhancing safety and saving lives by leveraging an extensive body of data — encompassing driving, road conditions, behavioral studies, and crash safety statistics — to create compelling digital experiences for drivers. Our AI consistently outperforms national safety statistics, ensuring the unique and coveted KnightMotives experience is aligned across all our vehicle models.

Michael Knight, KnightMotives CEO


For this question, refer to the KnightMotives Automotive case study. KnightMotives has developed a new car configurator application to enhance both the dealer and customer experience. The new application will be deployed on Google Kubernetes Engine (GKE) KnightMotives wants you to replicate the deployment of the application across multiple locations to ensure this critical application is always available over the internet, even during regional outages. What should you do?
  1. A Create multiple GKE clusters in different regions. Deploy part of the microservices of the app in different clusters. Configure a multi-cluster Cloud Service Mesh.
  2. B Create multiple GKE clusters in different regions. Deploy the app on every cluster. Configure a multi-cluster Cloud Service Mesh.
  3. C Create a fleet of GKE clusters in different regions Deploy part of the microservices of the app in different clusters Configure a multi-cluster Gateway.
  4. D Create a fleet of GKE clusters in different regions. Deploy the app on every cluster. Configure a multi-cluster Gateway.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi thuộc case study KnightMotives Automotive, tập trung vào việc triển khai ứng dụng car configurator mới (công cụ cấu hình xe) trên Google Kubernetes Engine (GKE) để cải thiện trải nghiệm cho đại lý và khách hàng. Mục tiêu chính là đảm bảo ứng dụng luôn khả dụng qua internet (high availability - HA), ngay cả khi có sự cố khu vực (regional outages), bằng cách replicate deployment qua nhiều locations (regions).

  • Bối cảnh: KnightMotives đang hiện đại hóa IT, chuyển sang hybrid cloud, cần ứng dụng critical này luôn online để hỗ trợ build-to-order, giảm thời gian tồn kho và tăng sự hài lòng khách hàng/dealer.
  • Yêu cầu kỹ thuật: Sử dụng GKE multi-cluster để phân tán rủi ro, đảm bảo tính sẵn sàng cao (resiliency), phù hợp với technical requirements như network upgrades, IT modernization và delightful experience cho dealers/customers.
  • Thách thức: Ứng dụng microservices-based, cần replicate full để tránh downtime; phải expose qua internet an toàn, global.
  • Giải pháp mong muốn: Sử dụng các tính năng GKE/Anthos mới nhất (đến 2026): Fleet để quản lý multi-cluster, deploy full app trên mỗi cluster (active-active replication), và multi-cluster Gateway cho unified ingress với global load balancing.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create a fleet of GKE clusters in different regions. Deploy the app on every cluster. Configure a multi-cluster Gateway.

Lý do 🛠️:

  • Fleet cho phép quản lý tập trung nhiều GKE clusters qua regions, hỗ trợ multi-cluster services và config nhất quán (Anthos Fleet - cập nhật 2025).
  • Deploy the app on every cluster đảm bảo full replication (active-active), tránh single point of failure khi region outage – phù hợp yêu cầu "always available".
  • Multi-cluster Gateway (phần của Cloud Service Mesh) cung cấp single global IP/ingress cho traffic internet, với automatic failover và global load balancing, lý tưởng cho ứng dụng public-facing như car configurator.
  • Kết hợp này đạt zero-downtime HA multi-region, tuân thủ security/EU regs qua Istio-based Gateway.

📋 Giải thích tất cả các phương án (đúng/sai)

  • ❌ [SAI] Create multiple GKE clusters in different regions. Deploy part of the microservices of the app in different clusters. Configure a multi-cluster Cloud Service Mesh.
    Phân tích sai: Deploy partial microservices (sharding) tạo dependency cross-cluster, dẫn đến failure cascade nếu một region down (ví dụ: microservice A ở region 1 fail → toàn app down). Cloud Service Mesh tốt cho east-west traffic nội bộ nhưng không tối ưu cho ingress internet (north-south), thiếu unified global endpoint. Không dùng Fleet → quản lý lẻ tẻ, khó scale/HA.

  • ❌ [SAI] Create multiple GKE clusters in different regions. Deploy the app on every cluster. Configure a multi-cluster Cloud Service Mesh.
    Phân tích sai: Deploy full app ✅ tốt cho HA, nhưng Cloud Service Mesh chủ yếu quản lý service-to-service (mesh internal), không phải gateway cho internet traffic. Thiếu multi-cluster Gateway → không có single entry point/global LB, khó expose "always available over the internet". Không dùng Fleet → thiếu unified management multi-region.

  • ❌ [SAI] Create a fleet of GKE clusters in different regions Deploy part of the microservices of the app in different clusters Configure a multi-cluster Gateway.
    Phân tích sai: Fleet ✅ và Gateway ✅ cho ingress/HA internet, nhưng partial microservices gây rủi ro cao: ứng dụng không tự chứa (không active-active đầy đủ), dễ outage nếu cluster cụ thể fail. Không phù hợp yêu cầu replicate toàn bộ để chống regional outages.

  • ✅ [ĐÚNG] Create a fleet of GKE clusters in different regions. Deploy the app on every cluster. Configure a multi-cluster Gateway.
    Phân tích đúng (như phần trên): Kết hợp hoàn hảo – Fleet quản lý, full deploy HA, Gateway expose internet với failover tự động. Đáp ứng đầy đủ case study: resiliency, global availability, dễ tích hợp AI/data monetization sau này. 🚀

Câu 305
Company Overview -

KnightMotives is a car manufacturer specializing in autonomous, self-driving vehicles, including Battery Electric Vehicles (BEVs), hybrids and traditional internal combustion engine (ICE) vehicles. While KnightMotives has made strides with the in-vehicle experience in their BEV fleet, the hybrid and ICE vehicles have yet to implement these new systems and are viewed poorly by critics and drivers. The lack of modern in-vehicle technology in hybrid and ICE vehicles has resulted in declining sales and customer satisfaction.

KnightMotives wants to modernize the consumer experience across all vehicles within five years Artificial Intelligence offers a unique opportunity to revolutionize the in-vehicle experience, as well as the shopping buying and service/maintenance experience. Investment in this new technology will require a shift in financial priorities on a global scale.

KnightMotives also wants to improve their online ordering system, which is unreliable. Systems for customers to build their vehicle online for acquisition through a dealer are not delivering the data or reliability that dealers need, causing. A strain in the relationship between KnightMotives and dealers. Service technicians and sales staff need better tooling to enhance dealer successes, including built-to-order vehicles.


Solution Concept -

KnightMotives wants to shift from manufacturing cars to creating a complete and compelling “automotive experience.” Then strategy prioritizes delivering a consistent experience across all models, developing AI-powered features, generating new revenue from data monetization, adopting a digital focus to differentiate their brand from competitors, and developing better tools for mechanics and salespeople.


Existing Technical Environment -

KnightMotives's IT is largely on-premises with some applications on major cloud platforms. Their supply chain runs on an outdated mainframe, and Enterprise Resource Planning (ERP) is also outdated, making new promotions and dealer discounts difficult to implement. Dealers have no budget for new equipment. There is fragmentation across vehicles with multiple code bases, and significant technical debt from supporting backwards compatibility. Network connectivity to manufacturing plants and vehicle connectivity in rural areas are challenges.


Business Requirements -

Key business requirements include fostering a personalized relationship with the driver and delivering a cohesive experience across all models. Creating a better build-to-order model will reduce time on the lot and provide transparency for both dealers and customers. Additionally, KnightMotives seeks to monetize corporate data to finance new technology investments, as their current AI infrastructure is obsolete and corporate data remains siloed. Security is a paramount concern due to past data breaches Adherence to European Union (EU) data protection regulations, especially for emerging autonomous platforms, is critical.

KnightMotives plans to make significant investments in fully autonomous driving capabilities, with initial implementation targeting regions with favorable regulatory environments. Prioritizing employee upskilling, attracting top-tier talent, and fostering better communication between business and technical teams are also critical objectives.


Technical Requirements -

•Modernizing the in-vehicle experience includes developing a consistent user experience (UX) that seamlessly integrates AI-powered features across all models, updating in-vehicle hardware and software in legacy models to support new UX features and AI capabilities, and ensuring reliable network connectivity, especially in rural areas, to support real-time AI features and data transmission.
•Network upgrades are necessary to support increased data traffic and improve connectivity between plants and headquarters.
•IT infrastructure modernization requires adopting a hybrid cloud strategy to leverage the benefits of both on-premises and cloud infrastructure, and gradually modernizing or replacing legacy systems to improve efficiency and agility.
•Autonomous vehicle development and testing requires investing in cutting-edge AI and machine learning technologies, building a robust simulation environment, and ensuring compliance with evolving regulations related to autonomous vehicles.
•Data monetization and insights requires implementing a robust data management platform, strict data security and privacy measures, and a scalable AI/ML infrastructure.
•Increased focus on security and risk management involves implementing a comprehensive security framework to protect against cyber threats and data breaches, developing an incident response plan, and providing security awareness training to employees.
•Providing a delightful experience for dealers and customers requires improving the online build-to-order system; developing modern dealer tools to streamline dealer operations, including sales, service, and inventory management; and implementing a comprehensive Customer Relationship Management (CRM) system to track customer interactions personalize experiences, and improve customer satisfaction.


Executive Statement -

KnightMotives is committed to enhancing safety and saving lives by leveraging an extensive body of data — encompassing driving, road conditions, behavioral studies, and crash safety statistics — to create compelling digital experiences for drivers. Our AI consistently outperforms national safety statistics, ensuring the unique and coveted KnightMotives experience is aligned across all our vehicle models.

Michael Knight, KnightMotives CEO


For this question, refer to the KnightMotives Automotive case study. As part of its development of fully autonomous driving vehicles. KnightMotives wants to analyze all vehicle sensor data during test drives. The analysis will enable KnightMotives to improve its software based on insights from this data.
•Different event types, such as parking, overtaking and navigating, need to be analyzed. Each test vehicle and event type has an ID.
•Different categories of sensors, such as cameras, radars, and ultrasonic beams, also need to be analyzed. During each autonomously-initiated event, data from multiple sensors will be captured and sent to Google Cloud where the data will be stored in Bigtable.

During data analysis, you want to be able to retrieve all sensor data of occurrences of the same event type for a specific vehicle within a specific interval of time. You need to design a Bigtable schema that is optimized for read performance. What should you do?
  1. A Use the sensor category, event ID, and timestamp (in that order) as the row key. Create a column family for each individual sensor and a column qualifier for each vehicle.
  2. B Use the timestamp, vehicle ID, and event ID (in that order) as the row key. Create a column family per sensor category, and use a column qualifier for each individual sensor within its respective category.
  3. C Use the vehicle ID, event ID, and timestamp (in that order) as the row key. Create a column family per sensor category, and use a column qualifier for each individual sensor within its respective category.
  4. D Use the vehicle ID and event ID (in that order) as the row key. Create a column family per sensor category, and use a column qualifier for each individual sensor within its respective category. Utilize the timestamped versions of a cell to distinguish between different moments in time of similar events.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi thuộc case study KnightMotives Automotive, tập trung vào việc phát triển xe tự lái hoàn toàn. KnightMotives cần phân tích dữ liệu cảm biến từ các chuyến thử nghiệm (test drives) để cải thiện phần mềm dựa trên insights. Các điểm chính:

  • Dữ liệu đầu vào:

    • Các loại sự kiện (event types) khác nhau như đỗ xe (parking), vượt xe (overtaking), điều hướng (navigating). Mỗi xe thử nghiệm (test vehicle) và loại sự kiện có ID riêng.
    • Các loại cảm biến (sensor categories): camera, radar, ultrasonic beams. Trong mỗi sự kiện tự động khởi tạo, dữ liệu từ nhiều cảm biến được thu thập và lưu vào Google Cloud Bigtable.
  • Yêu cầu query chính: Truy xuất tất cả dữ liệu cảm biến của cùng một loại sự kiện (same event type) cho một xe cụ thể (specific vehicle) trong khoảng thời gian cụ thể (specific interval of time).

  • Mục tiêu: Thiết kế schema Bigtable tối ưu hóa hiệu suất đọc (read performance). Bigtable là NoSQL database phân tán, hiệu suất phụ thuộc vào row key (phải group dữ liệu cần query thường xuyên làm prefix, và sort theo thứ tự scan) để tránh hot spots và hỗ trợ range scan nhanh.

🛠️ Kiến thức cốt lõi (cập nhật đến 2026): Theo tài liệu Google Cloud Bigtable (phiên bản mới nhất 2026), schema design cho time-series data như sensor logs ưu tiên row key theo dạng {entity_id}:{sub_entity}:{timestamp} để group theo entity (vehicle), sub-group (event), và sort theo time cho range query hiệu quả. Sử dụng column family (CF) cho categories ổn định, column qualifier (CQ) cho chi tiết. Tránh timestamp làm prefix đầu để tránh hot-spotting (ghi đồng thời cao vào cùng row prefix).

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Use the vehicle ID, event ID, and timestamp (in that order) as the row key. Create a column family per sensor category, and use a column qualifier for each individual sensor within its respective category.

Lý do 🏆:

  • Row key theo thứ tự vehicle ID + event ID + timestamp tạo prefix hoàn hảo cho query: Tất cả rows của một vehicle + một event type sẽ liền kề, sorted theo timestamp → range scan nhanh cho interval thời gian (ví dụ: scan từ ts1 đến ts2).
  • CF per sensor category (e.g., "cameras", "radars") nhóm dữ liệu logic, giảm số CF (tối ưu <100 CF/table).
  • CQ per individual sensor (e.g., trong CF "cameras": "front_cam", "rear_cam") lưu dữ liệu chi tiết, hỗ trợ read targeted.
  • Tối ưu read performance: Không hot-spot (vehicle ID phân tán), hỗ trợ high QPS cho analytics real-time trên autonomous data.
  • Phù hợp time-series sensor data, scale petabyte theo best practices 2026.

📋 Giải thích tất cả các phương án

Dưới đây là phân tích từng lựa chọn (giữ nguyên văn bản gốc tiếng Anh). Mỗi phương án được đánh giá đúng/sai với lý do chi tiết dựa trên yêu cầu query và Bigtable best practices.

  • [SAI] Use the sensor category, event ID, and timestamp (in that order) as the row key. Create a column family for each individual sensor and a column qualifier for each vehicle.
    ❌ Sai vì: Row key bắt đầu bằng sensor category → dữ liệu không group theo vehicle và event type, khó scan range cho "specific vehicle + same event". Phải scatter scan toàn table (low performance). CF per individual sensor (quá nhiều CF nếu hàng trăm sensors → vượt limit 100 CF). CQ cho vehicle không hiệu quả vì vehicle là entity chính cần prefix.

  • [SAI] Use the timestamp, vehicle ID, and event ID (in that order) as the row key. Create a column family per sensor category, and use a column qualifier for each individual sensor within its respective category.
    ❌ Sai vì: Timestamp đầu tiên gây hot-spotting (tất cả event mới cùng lúc ghi vào prefix gần nhau → throttle writes). Query cho specific vehicle/event/time interval yêu cầu prefix filter phức tạp (không liền kề), phải full scan → chậm, không scale cho high-volume sensor data.

  • [ĐÚNG] Use the vehicle ID, event ID, and timestamp (in that order) as the row key. Create a column family per sensor category, and use a column qualifier for each individual sensor within its respective category.
    ✅ Đúng như đã giải thích ở trên: Prefix vehicle ID + event ID group chính xác dữ liệu cần query, timestamp sort cho time-range scan siêu nhanh. CF/CQ optimal cho sensor hierarchy → high read QPS, low latency cho AI analysis.

  • [SAI] Use the vehicle ID and event ID (in that order) as the row key. Create a column family per sensor category, and use a column qualifier for each individual sensor within its respective category. Utilize the timestamped versions of a cell to distinguish between different moments in time of similar events.
    ❌ Sai vì: Row key chỉ vehicle + event → tất cả timestamps cùng event cramming vào cùng một row (single row key). Dùng cell versions (max 100 versions/cell mặc định) cho time distinction → không hiệu quả cho time-range query (phải read toàn row rồi filter client-side, chậm với high-frequency events như sensor streams). Vi phạm best practices time-series (nên dùng timestamp in row key cho range scan native).

🎯 Kết luận: Schema đúng giúp KnightMotives xử lý petabyte sensor data cho autonomous testing mượt mà, hỗ trợ real-time insights và tuân thủ EU regs về data privacy! 🚀

Câu 306
Company Overview -

KnightMotives is a car manufacturer specializing in autonomous, self-driving vehicles, including Battery Electric Vehicles (BEVs), hybrids and traditional internal combustion engine (ICE) vehicles. While KnightMotives has made strides with the in-vehicle experience in their BEV fleet, the hybrid and ICE vehicles have yet to implement these new systems and are viewed poorly by critics and drivers. The lack of modern in-vehicle technology in hybrid and ICE vehicles has resulted in declining sales and customer satisfaction.

KnightMotives wants to modernize the consumer experience across all vehicles within five years Artificial Intelligence offers a unique opportunity to revolutionize the in-vehicle experience, as well as the shopping buying and service/maintenance experience. Investment in this new technology will require a shift in financial priorities on a global scale.

KnightMotives also wants to improve their online ordering system, which is unreliable. Systems for customers to build their vehicle online for acquisition through a dealer are not delivering the data or reliability that dealers need, causing. A strain in the relationship between KnightMotives and dealers. Service technicians and sales staff need better tooling to enhance dealer successes, including built-to-order vehicles.


Solution Concept -

KnightMotives wants to shift from manufacturing cars to creating a complete and compelling “automotive experience.” Then strategy prioritizes delivering a consistent experience across all models, developing AI-powered features, generating new revenue from data monetization, adopting a digital focus to differentiate their brand from competitors, and developing better tools for mechanics and salespeople.


Existing Technical Environment -

KnightMotives's IT is largely on-premises with some applications on major cloud platforms. Their supply chain runs on an outdated mainframe, and Enterprise Resource Planning (ERP) is also outdated, making new promotions and dealer discounts difficult to implement. Dealers have no budget for new equipment. There is fragmentation across vehicles with multiple code bases, and significant technical debt from supporting backwards compatibility. Network connectivity to manufacturing plants and vehicle connectivity in rural areas are challenges.


Business Requirements -

Key business requirements include fostering a personalized relationship with the driver and delivering a cohesive experience across all models. Creating a better build-to-order model will reduce time on the lot and provide transparency for both dealers and customers. Additionally, KnightMotives seeks to monetize corporate data to finance new technology investments, as their current AI infrastructure is obsolete and corporate data remains siloed. Security is a paramount concern due to past data breaches Adherence to European Union (EU) data protection regulations, especially for emerging autonomous platforms, is critical.

KnightMotives plans to make significant investments in fully autonomous driving capabilities, with initial implementation targeting regions with favorable regulatory environments. Prioritizing employee upskilling, attracting top-tier talent, and fostering better communication between business and technical teams are also critical objectives.


Technical Requirements -

•Modernizing the in-vehicle experience includes developing a consistent user experience (UX) that seamlessly integrates AI-powered features across all models, updating in-vehicle hardware and software in legacy models to support new UX features and AI capabilities, and ensuring reliable network connectivity, especially in rural areas, to support real-time AI features and data transmission.
•Network upgrades are necessary to support increased data traffic and improve connectivity between plants and headquarters.
•IT infrastructure modernization requires adopting a hybrid cloud strategy to leverage the benefits of both on-premises and cloud infrastructure, and gradually modernizing or replacing legacy systems to improve efficiency and agility.
•Autonomous vehicle development and testing requires investing in cutting-edge AI and machine learning technologies, building a robust simulation environment, and ensuring compliance with evolving regulations related to autonomous vehicles.
•Data monetization and insights requires implementing a robust data management platform, strict data security and privacy measures, and a scalable AI/ML infrastructure.
•Increased focus on security and risk management involves implementing a comprehensive security framework to protect against cyber threats and data breaches, developing an incident response plan, and providing security awareness training to employees.
•Providing a delightful experience for dealers and customers requires improving the online build-to-order system; developing modern dealer tools to streamline dealer operations, including sales, service, and inventory management; and implementing a comprehensive Customer Relationship Management (CRM) system to track customer interactions personalize experiences, and improve customer satisfaction.


Executive Statement -

KnightMotives is committed to enhancing safety and saving lives by leveraging an extensive body of data — encompassing driving, road conditions, behavioral studies, and crash safety statistics — to create compelling digital experiences for drivers. Our AI consistently outperforms national safety statistics, ensuring the unique and coveted KnightMotives experience is aligned across all our vehicle models.

Michael Knight, KnightMotives CEO


For this question, refer to the KnightMotives Automotive case study, KnightMotives has deployed their new Dealer Tools on Google Kubernetes Engine (GKE). You are supporting KnightMotives in the performance of the GKE workloads. Some of the Pods are Statefull. To ensure these Pods do not consume an unlimited amount of CPU, you have configured resource limits on the Deployments. You have identified that these Pods were allocated too much CPU and are actually consuming drastically less some of the time. You want to optimize resource usage and allow maximum flexibility in case of higher load. What should you do?
  1. A Configure resource requests per Deployment. Set resource requests slightly above the typical CPU usage observed during monitoring.
  2. B Configure resource requests per Deployment. Ensure the requests are equal to the current limits.
  3. C Enable vertical Pod autoscaling on each Deployment. Ensure the autoscaling mode is set to Auto.
  4. D Enable horizontal Pod autoscaling on each Deployment. Ensure the minimum number of Pods is lower than the currently configured amount in the Deployment.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi thuộc case study KnightMotives Automotive, tập trung vào việc hỗ trợ hiệu suất workloads trên Google Kubernetes Engine (GKE) cho ứng dụng Dealer Tools. Các Pods (bao gồm một số Stateful Pods) đã được cấu hình resource limits trên Deployments để tránh tiêu thụ CPU không giới hạn. Tuy nhiên, sau khi giám sát, phát hiện các Pods được cấp phát (allocated) quá nhiều CPU, trong khi thực tế chúng chỉ sử dụng ít hơn đáng kể một phần thời gian. Mục tiêu là tối ưu hóa sử dụng tài nguyên (giảm lãng phí CPU idle) đồng thời đảm bảo tính linh hoạt cao nhất khi tải tăng đột biến (higher load).

Vấn đề cốt lõi nằm ở Kubernetes resource management:

  • Resource requests: Quyết định lượng tài nguyên scheduler cấp phát và đảm bảo cho Pod (guarantee), ảnh hưởng đến node placement và bin-packing.
  • Resource limits: Giới hạn tối đa Pod có thể dùng (upper bound), tránh starve node. Hiện tại chỉ có limits, nên requests mặc định bằng limits → allocate thừa thãi. Giải pháp cần set requests hợp lý dựa trên monitoring (typical usage), giữ limits để burst an toàn. Điều này phù hợp với Technical Requirements về IT modernization, hybrid cloud, và tối ưu AI/ML workloads trên GKE.

📘 Kiến thức cập nhật: Dựa trên Kubernetes v1.29+ (GKE hỗ trợ đến 2026 với Autopilot mode), Vertical/Horizontal Pod Autoscaler được cải tiến, nhưng VPA vẫn hạn chế với Stateful workloads (Kubernetes docs 2024-2026).

✅ Đáp án đúng

Configure resource requests per Deployment. Set resource requests slightly above the typical CPU usage observed during monitoring.

Lý do lựa chọn:

  • Việc chỉ cấu hình limits mà không có requests dẫn đến requests mặc định = limits → Pods được scheduler cấp phát CPU thừa thãi, gây lãng phí tài nguyên node (over-provisioning).
  • Set requests hơi cao hơn typical CPU usage (dựa trên monitoring qua GKE Metrics/Cloud Monitoring) giúp: 🛠️ Tối ưu hóa: Scheduler bin-pack Pods hiệu quả hơn, giảm số node cần thiết, tiết kiệm chi phí. 🚀 Linh hoạt: Pods có thể burst lên đến limits khi load cao (nhờ QoS Burstable), phù hợp higher load mà không cần scale thủ công.
  • Hoàn hảo cho Stateful Pods (dùng StatefulSets), vì requests ổn định scheduling mà không thay đổi storage/PVC.
  • Align với best practices GKE: Right-sizing resources via observability (Prometheus/GKE Insights).

❌ Phân tích tất cả các phương án

  • ✅ [ĐÚNG] Configure resource requests per Deployment. Set resource requests slightly above the typical CPU usage observed during monitoring.
    🟢 Đúng vì: Như giải thích trên, đây là cách tối ưu chuẩn Kubernetes để giảm over-allocation dựa trên real metrics, đảm bảo burst capacity và bin-packing tốt. Không ảnh hưởng Stateful Pods.

  • ❌ [SAI] Configure resource requests per Deployment. Ensure the requests are equal to the current limits.
    🔴 Sai vì: Set requests = limits hiện tại không giải quyết vấn đề gốc (allocate thừa), chỉ làm requests explicit nhưng vẫn giữ over-provisioning cao. Pods vẫn consume ít hơn, lãng phí như cũ, không tối ưu hay linh hoạt hơn.

  • ❌ [SAI] Enable vertical Pod autoscaling on each Deployment. Ensure the autoscaling mode is set to Auto.
    🔴 Sai vì: Vertical Pod Autoscaler (VPA) tự động điều chỉnh requests/limits dựa trên usage, nhưng mode Auto (v2.13+) sẽ evict và restart Pods để resize – rất nguy hiểm cho Stateful Pods (mất trạng thái, PVC disruption). Không recommend cho production stateful workloads (Kubernetes docs cảnh báo). Chỉ phù hợp stateless, và không "maximum flexibility" ngay lập tức.

  • ❌ [SAI] Enable horizontal Pod autoscaling on each Deployment. Ensure the minimum number of Pods is lower than the currently configured amount in the Deployment.
    🔴 Sai vì: Horizontal Pod Autoscaler (HPA) scale số lượng Pods dựa trên metrics (CPU%), không điều chỉnh resources per Pod. Giảm min Pods chỉ scale down số lượng, nhưng mỗi Pod vẫn allocate thừa CPU → tổng resource usage không tối ưu. Không giải quyết over-allocation per Pod, và có thể tăng latency nếu load spike.

📚 Tài liệu tham khảo

🛡️ Khuyến nghị bổ sung: Kết hợp với GKE Autopilot (2026 updates) để auto-manage resources, và dùng Cloud Profiler theo dõi CPU thực tế!

Câu 307
Company Overview -

KnightMotives is a car manufacturer specializing in autonomous, self-driving vehicles, including Battery Electric Vehicles (BEVs), hybrids and traditional internal combustion engine (ICE) vehicles. While KnightMotives has made strides with the in-vehicle experience in their BEV fleet, the hybrid and ICE vehicles have yet to implement these new systems and are viewed poorly by critics and drivers. The lack of modern in-vehicle technology in hybrid and ICE vehicles has resulted in declining sales and customer satisfaction.

KnightMotives wants to modernize the consumer experience across all vehicles within five years Artificial Intelligence offers a unique opportunity to revolutionize the in-vehicle experience, as well as the shopping buying and service/maintenance experience. Investment in this new technology will require a shift in financial priorities on a global scale.

KnightMotives also wants to improve their online ordering system, which is unreliable. Systems for customers to build their vehicle online for acquisition through a dealer are not delivering the data or reliability that dealers need, causing. A strain in the relationship between KnightMotives and dealers. Service technicians and sales staff need better tooling to enhance dealer successes, including built-to-order vehicles.


Solution Concept -

KnightMotives wants to shift from manufacturing cars to creating a complete and compelling “automotive experience.” Then strategy prioritizes delivering a consistent experience across all models, developing AI-powered features, generating new revenue from data monetization, adopting a digital focus to differentiate their brand from competitors, and developing better tools for mechanics and salespeople.


Existing Technical Environment -

KnightMotives's IT is largely on-premises with some applications on major cloud platforms. Their supply chain runs on an outdated mainframe, and Enterprise Resource Planning (ERP) is also outdated, making new promotions and dealer discounts difficult to implement. Dealers have no budget for new equipment. There is fragmentation across vehicles with multiple code bases, and significant technical debt from supporting backwards compatibility. Network connectivity to manufacturing plants and vehicle connectivity in rural areas are challenges.


Business Requirements -

Key business requirements include fostering a personalized relationship with the driver and delivering a cohesive experience across all models. Creating a better build-to-order model will reduce time on the lot and provide transparency for both dealers and customers. Additionally, KnightMotives seeks to monetize corporate data to finance new technology investments, as their current AI infrastructure is obsolete and corporate data remains siloed. Security is a paramount concern due to past data breaches Adherence to European Union (EU) data protection regulations, especially for emerging autonomous platforms, is critical.

KnightMotives plans to make significant investments in fully autonomous driving capabilities, with initial implementation targeting regions with favorable regulatory environments. Prioritizing employee upskilling, attracting top-tier talent, and fostering better communication between business and technical teams are also critical objectives.


Technical Requirements -

•Modernizing the in-vehicle experience includes developing a consistent user experience (UX) that seamlessly integrates AI-powered features across all models, updating in-vehicle hardware and software in legacy models to support new UX features and AI capabilities, and ensuring reliable network connectivity, especially in rural areas, to support real-time AI features and data transmission.
•Network upgrades are necessary to support increased data traffic and improve connectivity between plants and headquarters.
•IT infrastructure modernization requires adopting a hybrid cloud strategy to leverage the benefits of both on-premises and cloud infrastructure, and gradually modernizing or replacing legacy systems to improve efficiency and agility.
•Autonomous vehicle development and testing requires investing in cutting-edge AI and machine learning technologies, building a robust simulation environment, and ensuring compliance with evolving regulations related to autonomous vehicles.
•Data monetization and insights requires implementing a robust data management platform, strict data security and privacy measures, and a scalable AI/ML infrastructure.
•Increased focus on security and risk management involves implementing a comprehensive security framework to protect against cyber threats and data breaches, developing an incident response plan, and providing security awareness training to employees.
•Providing a delightful experience for dealers and customers requires improving the online build-to-order system; developing modern dealer tools to streamline dealer operations, including sales, service, and inventory management; and implementing a comprehensive Customer Relationship Management (CRM) system to track customer interactions personalize experiences, and improve customer satisfaction.


Executive Statement -

KnightMotives is committed to enhancing safety and saving lives by leveraging an extensive body of data — encompassing driving, road conditions, behavioral studies, and crash safety statistics — to create compelling digital experiences for drivers. Our AI consistently outperforms national safety statistics, ensuring the unique and coveted KnightMotives experience is aligned across all our vehicle models.

Michael Knight, KnightMotives CEO


For this question, refer to the KnightMotives Automotive case study. KnightMotives has established a dedicated Google Cloud Interconnect with 99.99% availability between its headquarters and two different metropolitan areas corresponding to the us-central1 and us-east1 Google Cloud regions. To minimize cost and latency between these workloads, you want to ensure all workloads in Google Cloud are deployed in these two regions as the VLAN attachment for the Cloud Interconnect. What should you do?
  1. A Schedule an export of all assets via Asset Inventory into BigQuery. Schedule a daily Cloud Run function to query the export and send out an alert if resources are created in regions outside of the allowed list.
  2. B Ensure all deployments are done through Infrastructure as Code using standardized Terraform modules. Configure the region variable of all resources with a default value corresponding to one of the allowed regions.
  3. C Limit the Google Cloud VPC used by the Cloud Interconnect to only have subnets in the allowed regions.
  4. D Configure the Resource Location Restriction constraint organization policy at the organization level, and ensure only the allowed regions are listed.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi thuộc case study về công ty KnightMotives, một nhà sản xuất xe hơi tập trung vào xe tự lái, xe điện và xe lai. Họ đang hiện đại hóa trải nghiệm người dùng, hệ thống đặt hàng trực tuyến, và cơ sở hạ tầng IT từ on-premises sang hybrid cloud trên Google Cloud.

Vấn đề chính: KnightMotives đã thiết lập Dedicated Google Cloud Interconnect với độ khả dụng 99.99% giữa trụ sở chính và hai khu vực đô thị tương ứng với regions us-central1 và us-east1. Mục tiêu là đảm bảo tất cả workloads trên Google Cloud chỉ được triển khai ở hai regions này để tối ưu hóa chi phí và độ trễ (latency), vì VLAN attachment của Cloud Interconnect được gắn với các regions cụ thể. Điều này giúp giảm chi phí truyền dữ liệu và độ trễ giữa on-premises và cloud, đồng thời hỗ trợ kết nối đáng tin cậy cho các nhà máy sản xuất và xe hơi ở khu vực nông thôn.

Yêu cầu hành động: Chọn giải pháp enforce (ép buộc) để workloads không thể được tạo ở regions khác, phù hợp với technical requirements về hybrid cloud strategy, network upgrades, và security.

📘 Tài liệu tham khảo:

✅ Đáp án đúng

Configure the Resource Location Restriction constraint organization policy at the organization level, and ensure only the allowed regions are listed.

Lý do chọn:

  • Đây là giải pháp enforce chính sách tổ chức (Organization Policy) mạnh mẽ nhất ở mức organization level, ngăn chặn hoàn toàn việc tạo tài nguyên (resources) ở regions không được phép (chỉ cho phép us-central1 và us-east1).
  • Giảm thiểu rủi ro con người, tự động áp dụng cho tất cả projects/folder, hỗ trợ tuân thủ security và EU regulations (như GDPR).
  • Tối ưu chi phí/latency vì workloads buộc phải ở gần Interconnect regions.
  • Phù hợp kiến thức mới nhất (2026): Constraint constraints/gcp.resourceLocations cho phép list chính xác locations.

🛠️ Giải thích tất cả các phương án

  • ❌ [SAI] Schedule an export of all assets via Asset Inventory into BigQuery. Schedule a daily Cloud Run function to query the export and send out an alert if resources are created in regions outside of the allowed list.
    Phân tích sai: Đây chỉ là giám sát và cảnh báo (monitoring/alerting) sau khi tài nguyên đã được tạo, không ngăn chặn (preventive). Asset Inventory + BigQuery + Cloud Run tốn kém và chậm (daily), không enforce được workloads ở regions đúng ngay từ đầu, dẫn đến chi phí/latency cao nếu ai đó tạo resources ngoài danh sách.

  • ❌ [SAI] Ensure all deployments are done through Infrastructure as Code using standardized Terraform modules. Configure the region variable of all resources with a default value corresponding to one of the allowed regions.
    Phân tích sai: IaC với Terraform tốt cho consistency nhưng phụ thuộc vào developer tuân thủ (default value có thể bị override). Không enforce ở mức tổ chức, dễ bypass qua Console/CLI/gRPC, không đảm bảo 100% workloads ở us-central1/us-east1, vi phạm yêu cầu minimize cost/latency.

  • ❌ [SAI] Limit the Google Cloud VPC used by the Cloud Interconnect to only have subnets in the allowed regions.
    Phân tích sai: VPC có thể có subnets ở nhiều regions (multi-regional), việc limit subnets chỉ ảnh hưởng network routing, không ngăn tạo resources khác (như Compute Engine, GKE) ở regions ngoài. Cloud Interconnect chỉ optimize traffic qua VLAN attachment, nhưng workloads vẫn có thể deploy tự do, không giải quyết vấn đề enforce toàn diện.

  • ✅ [ĐÚNG] Configure the Resource Location Restriction constraint organization policy at the organization level, and ensure only the allowed regions are listed.
    Phân tích đúng: Như đã giải thích ở trên, đây là giải pháp chính thức và mạnh mẽ nhất từ Google Cloud, enforce deny cho tất cả resources mới ở locations không cho phép. Áp dụng ngay lập tức, scalable, và tích hợp với Security Command Center để audit. Hoàn hảo cho hybrid cloud của KnightMotives!

🛡️ Lời khuyên bổ sung: Kết hợp với Folders/Projects inheritance để linh hoạt, và test policy với gcloud org-policies trước khi deploy.

Câu 308
Company Overview -

KnightMotives is a car manufacturer specializing in autonomous, self-driving vehicles, including Battery Electric Vehicles (BEVs), hybrids and traditional internal combustion engine (ICE) vehicles. While KnightMotives has made strides with the in-vehicle experience in their BEV fleet, the hybrid and ICE vehicles have yet to implement these new systems and are viewed poorly by critics and drivers. The lack of modern in-vehicle technology in hybrid and ICE vehicles has resulted in declining sales and customer satisfaction.

KnightMotives wants to modernize the consumer experience across all vehicles within five years Artificial Intelligence offers a unique opportunity to revolutionize the in-vehicle experience, as well as the shopping buying and service/maintenance experience. Investment in this new technology will require a shift in financial priorities on a global scale.

KnightMotives also wants to improve their online ordering system, which is unreliable. Systems for customers to build their vehicle online for acquisition through a dealer are not delivering the data or reliability that dealers need, causing. A strain in the relationship between KnightMotives and dealers. Service technicians and sales staff need better tooling to enhance dealer successes, including built-to-order vehicles.


Solution Concept -

KnightMotives wants to shift from manufacturing cars to creating a complete and compelling “automotive experience.” Then strategy prioritizes delivering a consistent experience across all models, developing AI-powered features, generating new revenue from data monetization, adopting a digital focus to differentiate their brand from competitors, and developing better tools for mechanics and salespeople.


Existing Technical Environment -

KnightMotives's IT is largely on-premises with some applications on major cloud platforms. Their supply chain runs on an outdated mainframe, and Enterprise Resource Planning (ERP) is also outdated, making new promotions and dealer discounts difficult to implement. Dealers have no budget for new equipment. There is fragmentation across vehicles with multiple code bases, and significant technical debt from supporting backwards compatibility. Network connectivity to manufacturing plants and vehicle connectivity in rural areas are challenges.


Business Requirements -

Key business requirements include fostering a personalized relationship with the driver and delivering a cohesive experience across all models. Creating a better build-to-order model will reduce time on the lot and provide transparency for both dealers and customers. Additionally, KnightMotives seeks to monetize corporate data to finance new technology investments, as their current AI infrastructure is obsolete and corporate data remains siloed. Security is a paramount concern due to past data breaches Adherence to European Union (EU) data protection regulations, especially for emerging autonomous platforms, is critical.

KnightMotives plans to make significant investments in fully autonomous driving capabilities, with initial implementation targeting regions with favorable regulatory environments. Prioritizing employee upskilling, attracting top-tier talent, and fostering better communication between business and technical teams are also critical objectives.


Technical Requirements -

•Modernizing the in-vehicle experience includes developing a consistent user experience (UX) that seamlessly integrates AI-powered features across all models, updating in-vehicle hardware and software in legacy models to support new UX features and AI capabilities, and ensuring reliable network connectivity, especially in rural areas, to support real-time AI features and data transmission.
•Network upgrades are necessary to support increased data traffic and improve connectivity between plants and headquarters.
•IT infrastructure modernization requires adopting a hybrid cloud strategy to leverage the benefits of both on-premises and cloud infrastructure, and gradually modernizing or replacing legacy systems to improve efficiency and agility.
•Autonomous vehicle development and testing requires investing in cutting-edge AI and machine learning technologies, building a robust simulation environment, and ensuring compliance with evolving regulations related to autonomous vehicles.
•Data monetization and insights requires implementing a robust data management platform, strict data security and privacy measures, and a scalable AI/ML infrastructure.
•Increased focus on security and risk management involves implementing a comprehensive security framework to protect against cyber threats and data breaches, developing an incident response plan, and providing security awareness training to employees.
•Providing a delightful experience for dealers and customers requires improving the online build-to-order system; developing modern dealer tools to streamline dealer operations, including sales, service, and inventory management; and implementing a comprehensive Customer Relationship Management (CRM) system to track customer interactions personalize experiences, and improve customer satisfaction.


Executive Statement -

KnightMotives is committed to enhancing safety and saving lives by leveraging an extensive body of data — encompassing driving, road conditions, behavioral studies, and crash safety statistics — to create compelling digital experiences for drivers. Our AI consistently outperforms national safety statistics, ensuring the unique and coveted KnightMotives experience is aligned across all our vehicle models.

Michael Knight, KnightMotives CEO


For this question, refer to the KnightMotives Automotive case study. KnightMotives is managing supplier data and pricing in a central MySQL database at headquarters (HQ). Only personnel at HQ are allowed to change the data. Each local plant stores a copy of the data in their own MySQL database, often using a different database schema or version. Every night a batch job exports any product or price updates in XML format from the central database at HQ and stores the updated data on a central FTP server. Each local plant must download this XML file and update their local system with the new information. The local data kept by some plants has become inconsistent with the source data due to XML parsing issues. HQ wants to easily verify that all changes are applied correctly at each plant.
  1. A Create a Pub/Sub topic per supplier, and have HQ publish all changes related to the respective supplier in JSON format on that topic. Allow all plants to create Pub/Sub Pull subscription to receive messages for their suppliers and update their databases.
  2. B Create a Pub/Sub topic per supplier, and have HQ publish all changes related to the respective supplier in JSON format on that topic. Allow all plants to create Pub/Sub Push subscription to receive messages for their suppliers and update their databases.
  3. C Migrate the self-hosted MySQL database at HQ to Cloud SQL. Standardize the database schema across all plants, and configure the local databases as external read replicas in Cloud SQL.
  4. D Migrate the self-hosted MySQL database at HQ to Cloud SQL. Configure Database Migration Service between Cloud SQL and the on-premises databases. When creating the migration job. choose continuous migration instead of one-time migration.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi này xoay quanh case study của KnightMotives Automotive, tập trung vào vấn đề đồng bộ dữ liệu supplier (nhà cung cấp) và pricing (giá cả) giữa trụ sở chính (HQ) và các nhà máy địa phương (local plants).

  • Tình huống hiện tại 📊:
    • Dữ liệu được quản lý tập trung trong cơ sở dữ liệu MySQL tại HQ, chỉ nhân viên HQ mới được phép thay đổi.
    • Mỗi nhà máy lưu trữ bản sao dữ liệu trong MySQL riêng, nhưng thường sử dụng schema (cấu trúc bảng) hoặc version khác nhau, dẫn đến sự không nhất quán.
    • Quy trình đồng bộ hàng đêm: Batch job xuất changes (thay đổi sản phẩm/giá) dưới dạng XML từ HQ lên FTP server trung tâm. Các nhà máy phải download file XML này và tự update database local, nhưng gặp vấn đề parsing XML gây inconsistent data.
    • Yêu cầu chính từ HQ 🔍: Cần một giải pháp dễ dàng verify (xác minh) rằng tất cả changes đã được áp dụng đúng tại mỗi nhà máy, đồng thời giải quyết fragmentation và technical debt từ hệ thống legacy.

Giải pháp cần real-time hoặc near-real-time, dễ verify, hỗ trợ schema khác nhau (không yêu cầu standardize), và phù hợp với hybrid cloud strategy (on-premises + cloud). Đây là thách thức về data replication/replication với tính minh bạch cao.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create a Pub/Sub topic per supplier, and have HQ publish all changes related to the respective supplier in JSON format on that topic. Allow all plants to create Pub/Sub Pull subscription to receive messages for their suppliers and update their databases.

Lý do chọn đáp án này 🏆:

  • Giải pháp sử dụng Pub/Sub (Google Cloud Pub/Sub) để publish changes từ HQ dưới dạng JSON (dễ parse hơn XML, giảm lỗi), với topic riêng per supplier giúp granular control và scalability.
  • Các nhà máy tạo Pull subscription để tự pull messages khi cần, phù hợp với môi trường on-premises (không cần public endpoint như Push), đảm bảo reliability ở khu vực rural/network kém.
  • Dễ verify 📈: HQ có thể monitor metrics Pub/Sub (unack messages, delivery counts) để kiểm tra xem plants đã ack (xác nhận nhận) chưa, đảm bảo changes applied đúng mà không cần standardize schema (plants tự update DB local theo logic riêng).
  • Phù hợp technical requirements: Hybrid cloud, data monetization, security (Pub/Sub hỗ trợ IAM, encryption), và scalable cho AI/data traffic tăng.
  • Cập nhật 2026: Pub/Sub hỗ trợ JSON schema validation, dead-letter queues cho retry, đảm bảo zero data loss với at-least-once delivery.

Tài liệu tham khảo 📘:

🛠️ Giải thích tất cả các phương án (đúng và sai)

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Mỗi phương án được đánh giá ✅ (đúng) hoặc ❌ (sai), với lý do chi tiết bằng tiếng Việt.

  • Create a Pub/Sub topic per supplier, and have HQ publish all changes related to the respective supplier in JSON format on that topic. Allow all plants to create Pub/Sub Pull subscription to receive messages for their suppliers and update their databases.
    ✅ Đúng hoàn toàn – Như đã giải thích ở trên. Pull subscription lý tưởng cho on-premises plants (self-pull, firewall-friendly), JSON dễ parse, topic per supplier tránh overload, và metrics Pub/Sub giúp HQ verify dễ dàng (delivery success rate, ack latency). Giải quyết triệt để inconsistency từ XML/FTP batch.

  • Create a Pub/Sub topic per supplier, and have HQ publish all changes related to the respective supplier in JSON format on that topic. Allow all plants to create Pub/Sub Push subscription to receive messages for their suppliers and update their databases.
    ❌ Sai – Push subscription yêu cầu HTTP endpoint public tại plants để Google Push messages, nhưng plants on-premises với network challenges (rural areas, manufacturing plants) khó expose endpoint an toàn (security risk cao, firewall issues). Không phù hợp verify dễ dàng nếu push fail (cần retry logic phức tạp), vi phạm security paramount.

  • Migrate the self-hosted MySQL database at HQ to Cloud SQL. Standardize the database schema across all plants, and configure the local databases as external read replicas in Cloud SQL.
    ❌ Sai – Yêu cầu standardize schema across plants là không khả thi (plants dùng schema/version khác, no budget for new equipment, technical debt lớn). External read replicas chỉ hỗ trợ read-only (không update được), trong khi plants cần writable local DB. Không giải quyết verify changes applied (replicas chỉ sync từ master, không confirm local apply). Migrate HQ DB lớn, không focus vào real-time sync.

  • Migrate the self-hosted MySQL database at HQ to Cloud SQL. Configure Database Migration Service between Cloud SQL and the on-premises databases. When creating the migration job. choose continuous migration instead of one-time migration.
    ❌ Sai – DMS (Database Migration Service) continuous phù hợp one-way sync từ source (HQ) sang target, nhưng schema khác nhau gây lỗi mapping. Không bidirectional, plants không tự update mà chỉ replicate (có thể lag, không verify "applied correctly" tại local). Migrate HQ DB tốn kém/thời gian dài, không giải quyết batch/XML issues trực tiếp, và DMS không hỗ trợ multi-target plants dễ dàng mà không customize.

Kết luận tổng quát 🎯: Giải pháp Pub/Sub Pull là optimal cho decoupling, scalability, và verifiable replication trong hybrid setup, align với GCP best practices cho event-driven architecture đến 2026 (hỗ trợ Schema Registry, global topics). Tránh migration lớn để giảm disruption.

Câu 309
Company Overview -

KnightMotives is a car manufacturer specializing in autonomous, self-driving vehicles, including Battery Electric Vehicles (BEVs), hybrids and traditional internal combustion engine (ICE) vehicles. While KnightMotives has made strides with the in-vehicle experience in their BEV fleet, the hybrid and ICE vehicles have yet to implement these new systems and are viewed poorly by critics and drivers. The lack of modern in-vehicle technology in hybrid and ICE vehicles has resulted in declining sales and customer satisfaction.

KnightMotives wants to modernize the consumer experience across all vehicles within five years Artificial Intelligence offers a unique opportunity to revolutionize the in-vehicle experience, as well as the shopping buying and service/maintenance experience. Investment in this new technology will require a shift in financial priorities on a global scale.

KnightMotives also wants to improve their online ordering system, which is unreliable. Systems for customers to build their vehicle online for acquisition through a dealer are not delivering the data or reliability that dealers need, causing. A strain in the relationship between KnightMotives and dealers. Service technicians and sales staff need better tooling to enhance dealer successes, including built-to-order vehicles.


Solution Concept -

KnightMotives wants to shift from manufacturing cars to creating a complete and compelling “automotive experience.” Then strategy prioritizes delivering a consistent experience across all models, developing AI-powered features, generating new revenue from data monetization, adopting a digital focus to differentiate their brand from competitors, and developing better tools for mechanics and salespeople.


Existing Technical Environment -

KnightMotives's IT is largely on-premises with some applications on major cloud platforms. Their supply chain runs on an outdated mainframe, and Enterprise Resource Planning (ERP) is also outdated, making new promotions and dealer discounts difficult to implement. Dealers have no budget for new equipment. There is fragmentation across vehicles with multiple code bases, and significant technical debt from supporting backwards compatibility. Network connectivity to manufacturing plants and vehicle connectivity in rural areas are challenges.


Business Requirements -

Key business requirements include fostering a personalized relationship with the driver and delivering a cohesive experience across all models. Creating a better build-to-order model will reduce time on the lot and provide transparency for both dealers and customers. Additionally, KnightMotives seeks to monetize corporate data to finance new technology investments, as their current AI infrastructure is obsolete and corporate data remains siloed. Security is a paramount concern due to past data breaches Adherence to European Union (EU) data protection regulations, especially for emerging autonomous platforms, is critical.

KnightMotives plans to make significant investments in fully autonomous driving capabilities, with initial implementation targeting regions with favorable regulatory environments. Prioritizing employee upskilling, attracting top-tier talent, and fostering better communication between business and technical teams are also critical objectives.


Technical Requirements -

•Modernizing the in-vehicle experience includes developing a consistent user experience (UX) that seamlessly integrates AI-powered features across all models, updating in-vehicle hardware and software in legacy models to support new UX features and AI capabilities, and ensuring reliable network connectivity, especially in rural areas, to support real-time AI features and data transmission.
•Network upgrades are necessary to support increased data traffic and improve connectivity between plants and headquarters.
•IT infrastructure modernization requires adopting a hybrid cloud strategy to leverage the benefits of both on-premises and cloud infrastructure, and gradually modernizing or replacing legacy systems to improve efficiency and agility.
•Autonomous vehicle development and testing requires investing in cutting-edge AI and machine learning technologies, building a robust simulation environment, and ensuring compliance with evolving regulations related to autonomous vehicles.
•Data monetization and insights requires implementing a robust data management platform, strict data security and privacy measures, and a scalable AI/ML infrastructure.
•Increased focus on security and risk management involves implementing a comprehensive security framework to protect against cyber threats and data breaches, developing an incident response plan, and providing security awareness training to employees.
•Providing a delightful experience for dealers and customers requires improving the online build-to-order system; developing modern dealer tools to streamline dealer operations, including sales, service, and inventory management; and implementing a comprehensive Customer Relationship Management (CRM) system to track customer interactions personalize experiences, and improve customer satisfaction.


Executive Statement -

KnightMotives is committed to enhancing safety and saving lives by leveraging an extensive body of data — encompassing driving, road conditions, behavioral studies, and crash safety statistics — to create compelling digital experiences for drivers. Our AI consistently outperforms national safety statistics, ensuring the unique and coveted KnightMotives experience is aligned across all our vehicle models.

Michael Knight, KnightMotives CEO


For this question, refer to the KnightMotives Automotive case study. KnightMotives wants to personalize the dealer experience for its customers and has decided to train its own AI models for personalized recommendations. The company will start collecting personally identifiable information (PII) from its customers to use as part of the models’ training data. KnightMotives wants to ensure maximum security and compliance worldwide. You need to ensure the data is encrypted both at rest and during AI model training without impacting the models’ accuracy. What should you do?
  1. A Store the training data in BigQuery using column-level encryption. Train the model using Confidential GKE Nodes.
  2. B Store the training data in BigQuery using column-level encryption Train the model on VertexAI notebooks using customer-managed encryption keys.
  3. C Process all data with Sensitive Data Protection’s de-identification service. Replace any PII with a random string before storing it. Train the model using Confidential GKE Nodes.
  4. D Process all data with Sensitive Data Protection's de-identification service. Replace any PII with a random string before storing it. Train the model on VertexAI notebooks using customer-managed encryption keys.
Xem giải thích

🧩 Phân tích chi tiết câu hỏi

Câu hỏi thuộc case study KnightMotives Automotive, tập trung vào việc cá nhân hóa trải nghiệm dealer cho khách hàng bằng cách huấn luyện các mô hình AI riêng. Công ty sẽ thu thập PII (Personally Identifiable Information - thông tin nhận dạng cá nhân) từ khách hàng để làm dữ liệu huấn luyện. Yêu cầu chính là đảm bảo bảo mật tối đa và tuân thủ quy định toàn cầu (như EU data protection), với dữ liệu phải được mã hóa tại chỗ (at rest) và trong quá trình huấn luyện mô hình AI (during training), mà không ảnh hưởng đến độ chính xác của mô hình (không thay đổi dữ liệu gốc).

KnightMotives cần giải pháp an toàn cho PII nhạy cảm, hỗ trợ huấn luyện AI trên dữ liệu gốc để cá nhân hóa khuyến nghị, đồng thời tránh rủi ro lộ dữ liệu trong môi trường cloud. Đây là thách thức về confidential computing và encryption in use, phù hợp với hybrid cloud strategy và security focus trong case study. 📘

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Store the training data in BigQuery using column-level encryption. Train the model using Confidential GKE Nodes.

Lý do:

  • BigQuery column-level encryption (sử dụng Customer-Managed Encryption Keys - CMEK hoặc Cloud KMS) mã hóa chọn lọc các cột chứa PII tại chỗ (at rest), đảm bảo dữ liệu an toàn mà không ảnh hưởng đến truy vấn hoặc huấn luyện. Điều này tuân thủ GDPR/EU regs và bảo vệ chống breach.
  • Confidential GKE Nodes (dựa trên Confidential Computing với AMD SEV-SNP hoặc Intel TDX) mã hóa dữ liệu trong quá trình sử dụng (in use/during training) bằng hardware enclaves, ngăn attacker (kể cả cloud provider) truy cập memory. Mô hình huấn luyện trên dữ liệu gốc → không impact accuracy.
  • Phù hợp hoàn hảo với yêu cầu: Bảo mật worldwide, hỗ trợ AI training quy mô lớn, scalable cho data monetization. Không de-identify nên giữ nguyên tính cá nhân hóa. 🛡️️

🛠️ Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn giữ nguyên văn bản gốc bằng tiếng Anh, với giải thích hoàn toàn bằng tiếng Việt sử dụng kiến thức GCP cập nhật đến 2026 (Confidential Computing GA với SEV-SNP từ 2023, BigQuery column-level CMEK enhanced 2024-2025):

  • ✅ Store the training data in BigQuery using column-level encryption. Train the model using Confidential GKE Nodes.
    Đúng vì: Kết hợp mã hóa at-rest (column-level trong BigQuery) và in-use (Confidential GKE với TEE - Trusted Execution Environments). Dữ liệu PII gốc được bảo vệ toàn diện, không thay đổi → accuracy 100%. Hỗ trợ GKE Autopilot cho AI workloads lớn. Lý tưởng cho compliance (SOC, GDPR).
    Nguồn: GCP Confidential Computing Docs, BigQuery Encryption (cập nhật 2025).

  • ❌ Store the training data in BigQuery using column-level encryption Train the model on VertexAI notebooks using customer-managed encryption keys.
    Sai vì: BigQuery column-level OK cho at-rest, nhưng Vertex AI notebooks với CMEK chỉ mã hóa at-rest/in-transit, không bảo vệ in-use during training (dữ liệu plaintext trong CPU/GPU memory). Dễ bị side-channel attacks, không đạt "maximum security" cho PII. Notebooks không phải confidential computing.
    Nguồn: Vertex AI Security (CMEK limits in-use).

  • ❌ Process all data with Sensitive Data Protection’s de-identification service. Replace any PII with a random string before storing it. Train the model using Confidential GKE Nodes.
    Sai vì: De-identification bằng Sensitive Data Protection (DLP) thay PII bằng random string làm thay đổi dữ liệu gốc → impact accuracy nghiêm trọng (mô hình không học được personalization thực từ PII thật). Confidential GKE tốt nhưng de-id làm mất giá trị business. Không cần thiết vì confidential computing cho phép dùng PII gốc an toàn.
    Nguồn: DLP De-identification (random replacement là technique irreversible, không reversible cho training).

  • ❌ Process all data with Sensitive Data Protection's de-identification service. Replace any PII with a random string before storing it. Train the model on VertexAI notebooks using customer-managed encryption keys.
    Sai vì: Kết hợp hai vấn đề lớn: De-id impact accuracy (như trên) + Vertex AI notebooks thiếu in-use encryption (như lựa chọn 2). Không đạt bảo mật tối đa, vi phạm yêu cầu "without impacting accuracy".
    Nguồn: Tương tự trên, Vertex AI Limitations.

Kết luận: Giải pháp đúng tận dụng Confidential Computing (xu hướng 2025-2026 cho AI với PII), phù hợp Technical Requirements về security và AI/ML infrastructure. KnightMotives có thể scale với GKE cho autonomous AI features! 🚀

Câu 310
Company Overview -

KnightMotives is a car manufacturer specializing in autonomous, self-driving vehicles, including Battery Electric Vehicles (BEVs), hybrids and traditional internal combustion engine (ICE) vehicles. While KnightMotives has made strides with the in-vehicle experience in their BEV fleet, the hybrid and ICE vehicles have yet to implement these new systems and are viewed poorly by critics and drivers. The lack of modern in-vehicle technology in hybrid and ICE vehicles has resulted in declining sales and customer satisfaction.

KnightMotives wants to modernize the consumer experience across all vehicles within five years Artificial Intelligence offers a unique opportunity to revolutionize the in-vehicle experience, as well as the shopping buying and service/maintenance experience. Investment in this new technology will require a shift in financial priorities on a global scale.

KnightMotives also wants to improve their online ordering system, which is unreliable. Systems for customers to build their vehicle online for acquisition through a dealer are not delivering the data or reliability that dealers need, causing. A strain in the relationship between KnightMotives and dealers. Service technicians and sales staff need better tooling to enhance dealer successes, including built-to-order vehicles.


Solution Concept -

KnightMotives wants to shift from manufacturing cars to creating a complete and compelling “automotive experience.” Then strategy prioritizes delivering a consistent experience across all models, developing AI-powered features, generating new revenue from data monetization, adopting a digital focus to differentiate their brand from competitors, and developing better tools for mechanics and salespeople.


Existing Technical Environment -

KnightMotives's IT is largely on-premises with some applications on major cloud platforms. Their supply chain runs on an outdated mainframe, and Enterprise Resource Planning (ERP) is also outdated, making new promotions and dealer discounts difficult to implement. Dealers have no budget for new equipment. There is fragmentation across vehicles with multiple code bases, and significant technical debt from supporting backwards compatibility. Network connectivity to manufacturing plants and vehicle connectivity in rural areas are challenges.


Business Requirements -

Key business requirements include fostering a personalized relationship with the driver and delivering a cohesive experience across all models. Creating a better build-to-order model will reduce time on the lot and provide transparency for both dealers and customers. Additionally, KnightMotives seeks to monetize corporate data to finance new technology investments, as their current AI infrastructure is obsolete and corporate data remains siloed. Security is a paramount concern due to past data breaches Adherence to European Union (EU) data protection regulations, especially for emerging autonomous platforms, is critical.

KnightMotives plans to make significant investments in fully autonomous driving capabilities, with initial implementation targeting regions with favorable regulatory environments. Prioritizing employee upskilling, attracting top-tier talent, and fostering better communication between business and technical teams are also critical objectives.


Technical Requirements -

•Modernizing the in-vehicle experience includes developing a consistent user experience (UX) that seamlessly integrates AI-powered features across all models, updating in-vehicle hardware and software in legacy models to support new UX features and AI capabilities, and ensuring reliable network connectivity, especially in rural areas, to support real-time AI features and data transmission.
•Network upgrades are necessary to support increased data traffic and improve connectivity between plants and headquarters.
•IT infrastructure modernization requires adopting a hybrid cloud strategy to leverage the benefits of both on-premises and cloud infrastructure, and gradually modernizing or replacing legacy systems to improve efficiency and agility.
•Autonomous vehicle development and testing requires investing in cutting-edge AI and machine learning technologies, building a robust simulation environment, and ensuring compliance with evolving regulations related to autonomous vehicles.
•Data monetization and insights requires implementing a robust data management platform, strict data security and privacy measures, and a scalable AI/ML infrastructure.
•Increased focus on security and risk management involves implementing a comprehensive security framework to protect against cyber threats and data breaches, developing an incident response plan, and providing security awareness training to employees.
•Providing a delightful experience for dealers and customers requires improving the online build-to-order system; developing modern dealer tools to streamline dealer operations, including sales, service, and inventory management; and implementing a comprehensive Customer Relationship Management (CRM) system to track customer interactions personalize experiences, and improve customer satisfaction.


Executive Statement -

KnightMotives is committed to enhancing safety and saving lives by leveraging an extensive body of data — encompassing driving, road conditions, behavioral studies, and crash safety statistics — to create compelling digital experiences for drivers. Our AI consistently outperforms national safety statistics, ensuring the unique and coveted KnightMotives experience is aligned across all our vehicle models.

Michael Knight, KnightMotives CEO


For this question, refer to the KnightMotives Automotive case study. You are responsible for designing the network infrastructure architecture for KnightMotives's new environment on Google Cloud. You need to design the new VPC topology. You want to ensure a guaranteed bandwidth and low latency between the plants and Google Cloud resources. What should you do?
  1. A Create a Standard Tier VPC. and ensure a subnet is available in the region closest to a plant. Establish a Cloud Interconnect between each subnet and the local plant.
  2. B Create a Standard Tier VPC. and ensure a subnet is available in the region closest to a plant Establish Direct Peering between Google's Edge Network and the local plant.
  3. C Create a Premium Ter VPand ensure a subnet is available in the region closest to a plant. Establish a Cloud Interconnect between each subnet and the local plant.
  4. D Create a Premium Ter VPC. and ensure a subnet is available in the region closest to a plant. Establish Direct Peering between Google's Edge Network and the local plant.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi thuộc case study KnightMotives Automotive, tập trung vào việc thiết kế network infrastructure architecture trên Google Cloud cho môi trường mới. Cụ thể, bạn là kiến trúc sư chịu trách nhiệm thiết kế VPC topology mới. Mục tiêu chính là đảm bảo bandwidth được cam kết (guaranteed bandwidth) và độ trễ thấp (low latency) giữa các nhà máy sản xuất (plants) và tài nguyên Google Cloud.

Bối cảnh liên quan từ case study:

  • KnightMotives có các nhà máy với kết nối mạng kém, đặc biệt ở khu vực nông thôn 📡.
  • Yêu cầu kỹ thuật: Nâng cấp mạng để hỗ trợ lưu lượng dữ liệu tăng cao, cải thiện kết nối giữa nhà máy và trụ sở chính; hỗ trợ AI thời gian thực cần độ trễ thấp và băng thông ổn định 🚀.
  • Họ đang chuyển sang hybrid cloud, cần kết nối on-premises (nhà máy) với GCP một cách đáng tin cậy, an toàn, tuân thủ quy định EU về dữ liệu 🔒.

Vấn đề cốt lõi: Kết nối giữa on-premises plants và GCP VPC phải private, có SLA cao về bandwidth (cam kết) và low latency toàn cầu, tận dụng mạng premium của Google để hỗ trợ dữ liệu lớn từ xe tự lái, AI/ML, và simulation.

Kiến thức cập nhật (Google Cloud 2026): VPC trên GCP có 2 tier - Premium Tier (mạng toàn cầu, low latency ~50-100ms inter-region, tối ưu cho traffic cao) và Standard Tier (regional, latency cao hơn). Cloud Interconnect cung cấp dedicated private connection (1-100Gbps, SLA 99.9%) từ on-prem đến Google Edge, sau đó route vào VPC với low latency nếu dùng Premium Tier 🛤️.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create a Premium Ter VPand ensure a subnet is available in the region closest to a plant. Establish a Cloud Interconnect between each subnet and the local plant.
(Lưu ý: "Premium Ter VP" là lỗi chính tả của "Premium Tier VPC").

Lý do chọn đáp án này 🏆:

  • Premium Tier VPC sử dụng Google's premium global network, đảm bảo low latency (toàn cầu, tối ưu cho plants ở nhiều vùng) và hỗ trợ traffic cao từ AI/real-time data. Subnet gần plant giảm hop count.
  • Cloud Interconnect cung cấp guaranteed bandwidth (dedicated 10/50/100Gbps, SLA cao), kết nối private từ plant trực tiếp đến VPC subnet, tránh public internet, phù hợp hybrid cloud và security cao (tuân thủ EU regs). Kết hợp hoàn hảo cho case study: plants kết nối HQ/GCP với độ tin cậy cao 🚀.
  • Không dùng Standard Tier hay Direct Peering vì không đáp ứng guaranteed/low-latency.

🔍 Giải thích tất cả các phương án (đúng/sai)

  • ❌ Phương án SAI: Create a Standard Tier VPC. and ensure a subnet is available in the region closest to a plant. Establish a Cloud Interconnect between each subnet and the local plant.
    Giải thích: Standard Tier chỉ regional (không global), dẫn đến latency cao giữa plants đa vùng và GCP resources. Cloud Interconnect tốt cho bandwidth, nhưng kết hợp Standard Tier không tận dụng mạng premium của Google, không đáp ứng "low latency" toàn cầu. Phù hợp traffic local nhưng không cho AI/real-time đa nhà máy 🕒.

  • ❌ Phương án SAI: Create a Standard Tier VPC. and ensure a subnet is available in the region closest to a plant Establish Direct Peering between Google's Edge Network and the local plant.
    Giải thích: Standard Tier đã kém latency. Direct Peering là public peering với Google Edge (cho services như YouTube/Cloud public), không private/guaranteed bandwidth cho VPC/on-prem traffic. Không an toàn (public), không SLA bandwidth, không phù hợp security/data breaches trong case study 📡❌.

  • ✅ Phương án ĐÚNG: Create a Premium Ter VPand ensure a subnet is available in the region closest to a plant. Establish a Cloud Interconnect between each subnet and the local plant.
    Giải thích: Như trên - Premium Tier cho low latency global + subnet gần plant tối ưu route. Cloud Interconnect dedicated private với guaranteed bandwidth (1-100Gbps), lý tưởng cho plants hybrid cloud, hỗ trợ data lớn AI/ML/simulation mà không qua internet công cộng. Hoàn hảo cho yêu cầu case study 🛤️✅.

  • ❌ Phương án SAI: Create a Premium Ter VPC. and ensure a subnet is available in the region closest to a plant. Establish Direct Peering between Google's Edge Network and the local plant.
    Giải thích: Premium Tier tốt cho latency, nhưng Direct Peering chỉ public peering (không private đến VPC), không guaranteed bandwidth (best-effort), thiếu SLA/an toàn cho corporate data. Không dùng cho on-prem-to-VPC private traffic, vi phạm security/data monetization requirements 🔓❌.

Kết luận khuyến nghị 💡: Triển khai Premium Tier VPC với Cloud Interconnect là best practice cho enterprise hybrid như KnightMotives. Kết hợp Network Intelligence Center để monitor latency/bandwidth thời gian thực! 🧑‍💻