Ngân hàng đề — Google Cloud Professional Cloud DevOps Engineer

Tìm thấy 269 câu.

Câu 1
You created a Stackdriver chart for CPU utilization in a dashboard within your workspace project. You want to share the chart with your Site Reliability Engineering
(SRE) team only. You want to ensure you follow the principle of least privilege. What should you do?
  1. A Share the workspace Project ID with the SRE team. Assign the SRE team the Monitoring Viewer IAM role in the workspace project.
  2. B Share the workspace Project ID with the SRE team. Assign the SRE team the Dashboard Viewer IAM role in the workspace project.
  3. C Click ג€Share chart by URLג€ and provide the URL to the SRE team. Assign the SRE team the Monitoring Viewer IAM role in the workspace project.
  4. D Click ג€Share chart by URLג€ and provide the URL to the SRE team. Assign the SRE team the Dashboard Viewer IAM role in the workspace project.
Xem giải thích

Đáp án

C — Bấm "Share chart by URL" rồi cấp cho nhóm SRE quyền xem phù hợp

Vì sao đúng

Chia sẻ biểu đồ bằng URL là cách nhanh nhất, nhưng URL không tự cấp quyền. Người nhận vẫn phải có quyền đọc dữ liệu giám sát của dự án workspace, nếu không họ mở link chỉ thấy lỗi truy cập. Vì vậy đáp án đúng phải gồm cả hai vế: đưa URL và gán vai xem.

Vì sao các phương án khác sai

  • A và B. Chỉ chia sẻ Project ID — buộc nhóm SRE tự tìm lại đúng biểu đồ trong dashboard, bất tiện và dễ nhìn nhầm.
  • D — cùng cách chia sẻ nhưng gán sai vai, nên người nhận vẫn không xem được.

Nhớ nhanh

Chia sẻ trên đám mây luôn có hai phần: đường dẫn và quyền. Thiếu vế thứ hai là link vô dụng.

Câu 2
You have a set of applications running on a Google Kubernetes Engine (GKE) cluster, and you are using Stackdriver Kubernetes Engine Monitoring. You are bringing a new containerized application required by your company into production. This application is written by a third party and cannot be modified or reconfigured. The application writes its log information to /var/log/app_messages.log, and you want to send these log entries to Stackdriver Logging. What should you do?
  1. A Use the default Stackdriver Kubernetes Engine Monitoring agent configuration.
  2. B Deploy a Fluentd daemonset to GKE. Then create a customized input and output configuration to tail the log file in the application's pods and write to Stackdriver Logging.
  3. C Install Kubernetes on Google Compute Engine (GCE) and redeploy your applications. Then customize the built-in Stackdriver Logging configuration to tail the log file in the application's pods and write to Stackdriver Logging.
  4. D Write a script to tail the log file within the pod and write entries to standard output. Run the script as a sidecar container with the application's pod. Configure a shared volume between the containers to allow the script to have read access to /var/log in the application container.
Xem giải thích

Đáp án

B — Triển khai daemonset Fluentd lên GKE rồi khai cấu hình đầu vào và đầu ra riêng

Vì sao đúng

Agent giám sát mặc định của GKE thu log từ stdout và stderr của container. Ứng dụng ghi log ra tệp bên trong pod thì agent không thấy. Fluentd chạy dưới dạng daemonset — một bản trên mỗi node — cho phép khai đường dẫn tệp làm nguồn đầu vào và Cloud Logging làm đích, nên log trong tệp được thu về mà không phải sửa ứng dụng.

Vì sao các phương án khác sai

  • A. Dùng cấu hình mặc định — chính là thứ đang không thu được log trong tệp.
  • C. Cài Kubernetes tự quản trên Compute Engine — thay hẳn nền tảng để giải một vấn đề cấu hình thu log.
  • D. Viết script đọc đuôi tệp rồi ghi ra stdout — chạy được và là cách nhiều người dùng, nhưng phải sửa từng ứng dụng và tự lo phần xoay vòng tệp; daemonset giải một lần cho cả cụm.
Câu 3
You are running an application in a virtual machine (VM) using a custom Debian image. The image has the Stackdriver Logging agent installed. The VM has the cloud-platform scope. The application is logging information via syslog. You want to use Stackdriver Logging in the Google Cloud Platform Console to visualize the logs. You notice that syslog is not showing up in the "All logs" dropdown list of the Logs Viewer. What is the first thing you should do?
  1. A Look for the agent's test log entry in the Logs Viewer.
  2. B Install the most recent version of the Stackdriver agent.
  3. C Verify the VM service account access scope includes the monitoring.write scope.
  4. D SSH to the VM and execute the following commands on your VM: ps ax | grep fluentd.
Xem giải thích

Đáp án

D — SSH vào máy ảo và kiểm tra tiến trình của agent đang chạy hay không

Vì sao đúng

Khi log không xuất hiện, bước soát lỗi đầu tiên phải là xác nhận agent còn sống. Cài đặt thành công không đảm bảo tiến trình đang chạy — nó có thể đã chết vì thiếu quyền, sai cấu hình, hoặc hết bộ nhớ. Kiểm tra tiến trình trả lời dứt khoát câu hỏi đó trước khi đi tìm nguyên nhân phức tạp hơn.

Vì sao các phương án khác sai

  • A. Tìm dòng log thử của agent trong Logs Viewer — nếu agent không chạy thì chẳng có dòng nào để tìm; đây là kiểm tra kết quả chứ không phải nguyên nhân.
  • B. Cài lại bản agent mới nhất — thử vận may trước khi chẩn đoán.
  • C. Kiểm phạm vi truy cập có monitoring.write — hợp lý nhưng đề nói máy đã có phạm vi cloud-platform, vốn đã bao trùm.
Câu 4
You support an application running on App Engine. The application is used globally and accessed from various device types. You want to know the number of connections. You are using Stackdriver Monitoring for App Engine. What metric should you use?
  1. A flex/connections/current
  2. B tcp_ssl_proxy/new_connections
  3. C tcp_ssl_proxy/open_connections
  4. D flex/instance/connections/current
Xem giải thích

Đáp án

A — flex/connections/current

Vì sao đúng

Đề hỏi số kết nối hiện tại của ứng dụng chạy trên App Engine môi trường flexible, nên chỉ số phải thuộc nhóm tiền tố flex/. Đây là chỉ số đếm số kết nối đang mở tới ứng dụng, đúng thứ cần.

Vì sao các phương án khác sai

  • B và C. Nhóm tcp_ssl_proxy/ — thuộc về bộ cân bằng tải TCP/SSL proxy, một dịch vụ khác; chúng đo kết nối ở tầng cân bằng tải chứ không phải ở ứng dụng App Engine.
  • D. flex/instance/connections/current — đường dẫn chỉ số không tồn tại dưới dạng này.

Nhớ nhanh

Chọn chỉ số thì nhìn tiền tố trước: nó cho biết chỉ số thuộc dịch vụ nào.

Câu 5
You are developing a strategy for monitoring your Google Cloud Platform (GCP) projects in production using Stackdriver Workspaces. One of the requirements is to be able to quickly identify and react to production environment issues without false alerts from development and staging projects. You want to ensure that you adhere to the principle of least privilege when providing relevant team members with access to Stackdriver Workspaces. What should you do?
  1. A Grant relevant team members read access to all GCP production projects. Create Stackdriver workspaces inside each project.
  2. B Grant relevant team members the Project Viewer IAM role on all GCP production projects. Create Stackdriver workspaces inside each project.
  3. C Choose an existing GCP production project to host the monitoring workspace. Attach the production projects to this workspace. Grant relevant team members read access to the Stackdriver Workspace.
  4. D Create a new GCP monitoring project and create a Stackdriver Workspace inside it. Attach the production projects to this workspace. Grant relevant team members read access to the Stackdriver Workspace.
Xem giải thích

Đáp án

D — Tạo một dự án giám sát riêng và đặt workspace trong đó

Vì sao đúng

Đặt workspace trong một dự án riêng chỉ dùng để giám sát là cách làm chuẩn khi theo dõi nhiều dự án sản xuất. Lý do: quyền xem dữ liệu giám sát tách hẳn khỏi quyền trên tài nguyên sản xuất, nên cấp cho nhóm quyền xem bảng điều khiển mà không phải cấp quyền vào chính hệ thống sản xuất. Workspace đó gắn thêm được các dự án cần theo dõi.

Vì sao các phương án khác sai

  • A và B. Cấp quyền đọc trên mọi dự án sản xuất — mở rộng quyền hơn mức cần, trái nguyên tắc quyền tối thiểu.
  • C. Đặt workspace trong một dự án sản xuất có sẵn — chạy được nhưng ràng buộc việc giám sát vào vòng đời của dự án đó, và quyền lại lẫn với quyền vận hành.
Câu 6
You currently store the virtual machine (VM) utilization logs in Stackdriver. You need to provide an easy-to-share interactive VM utilization dashboard that is updated in real time and contains information aggregated on a quarterly basis. You want to use Google Cloud Platform solutions. What should you do?
  1. A 1. Export VM utilization logs from Stackdriver to BigQuery. 2. Create a dashboard in Data Studio. 3. Share the dashboard with your stakeholders.
  2. B 1. Export VM utilization logs from Stackdriver to Cloud Pub/Sub. 2. From Cloud Pub/Sub, send the logs to a Security Information and Event Management (SIEM) system. 3. Build the dashboards in the SIEM system and share with your stakeholders.
  3. C 1. Export VM utilization logs from Stackdriver to BigQuery. 2. From BigQuery, export the logs to a CSV file. 3. Import the CSV file into Google Sheets. 4. Build a dashboard in Google Sheets and share it with your stakeholders.
  4. D 1. Export VM utilization logs from Stackdriver to a Cloud Storage bucket. 2. Enable the Cloud Storage API to pull the logs programmatically. 3. Build a custom data visualization application. 4. Display the pulled logs in a custom dashboard.
Xem giải thích

Đáp án

A — Xuất log sang BigQuery, rồi dựng bảng điều khiển trong Data Studio và chia sẻ

Vì sao đúng

Ba yêu cầu của đề — tương tác được, dễ chia sẻ, tự cập nhật — được giải bằng hai bước:

  • Sink sang BigQuery đưa log vào một nơi truy vấn được bằng SQL, và sink chạy liên tục nên dữ liệu mới tự chảy vào; đó là phần "tự cập nhật".
  • Data Studio nối thẳng vào BigQuery, cho người xem lọc và đổi khoảng thời gian ngay trên biểu đồ, và chia sẻ bằng link như một tài liệu bình thường.

Vì sao các phương án khác sai

  • B. Qua Cloud Pub/Sub — Pub/Sub là kênh truyền thông điệp, không phải nơi lưu trữ để truy vấn; vẫn phải có consumer đưa dữ liệu đi tiếp.
  • C. Từ BigQuery xuất tiếp ra nơi khác — thêm một chặng làm dữ liệu cũ đi và mất tính tự cập nhật.
  • D. Xuất sang Cloud Storage — tệp trên kho đối tượng không tạo được bảng điều khiển tương tác; vẫn phải nạp vào đâu đó rồi mới vẽ được.
Câu 7
You support an application that stores product information in cached memory. For every cache miss, an entry is logged in Stackdriver Logging. You want to visualize how often a cache miss happens over time. What should you do?
  1. A Link Stackdriver Logging as a source in Google Data Studio. Filter the logs on the cache misses.
  2. B Configure Stackdriver Profiler to identify and visualize when the cache misses occur based on the logs.
  3. C Create a logs-based metric in Stackdriver Logging and a dashboard for that metric in Stackdriver Monitoring.
  4. D Configure BigQuery as a sink for Stackdriver Logging. Create a scheduled query to filter the cache miss logs and write them to a separate table.
Xem giải thích

Đáp án

C — Tạo logs-based metric rồi dựng bảng điều khiển cho chỉ số đó

Vì sao đúng

Logs-based metric biến việc đếm dòng log khớp một mẫu thành một chỉ số thời gian thực. Khai bộ lọc bắt các dòng ghi nhận cache miss, hệ thống tự đếm theo thời gian, rồi vẽ lên bảng điều khiển và đặt cảnh báo. Đây là cơ chế dựng sẵn cho đúng nhu cầu "trực quan hoá tần suất một sự kiện xuất hiện trong log".

Vì sao các phương án khác sai

  • A. Nối log vào Data Studio — làm được nhưng nặng hơn và không cho cảnh báo thời gian thực.
  • B. Dùng Profiler — Profiler phân tích hiệu năng mã nguồn (CPU, bộ nhớ theo hàm), không đếm sự kiện trong log.
  • D. Đổ log sang BigQuery rồi chạy truy vấn theo lịch — dùng khi cần phân tích sâu và giữ lâu, nhưng quá vòng vo cho một biểu đồ đếm đơn giản, và có độ trễ theo lịch chạy.
Câu 8
You are running an application on Compute Engine and collecting logs through Stackdriver. You discover that some personally identifiable information (PII) is leaking into certain log entry fields. All PII entries begin with the text userinfo. You want to capture these log entries in a secure location for later review and prevent them from leaking to Stackdriver Logging. What should you do?
  1. A Create a basic log filter matching userinfo, and then configure a log export in the Stackdriver console with Cloud Storage as a sink.
  2. B Use a Fluentd filter plugin with the Stackdriver Agent to remove log entries containing userinfo, and then copy the entries to a Cloud Storage bucket.
  3. C Create an advanced log filter matching userinfo, configure a log export in the Stackdriver console with Cloud Storage as a sink, and then configure a log exclusion with userinfo as a filter.
  4. D Use a Fluentd filter plugin with the Stackdriver Agent to remove log entries containing userinfo, create an advanced log filter matching userinfo, and then configure a log export in the Stackdriver console with Cloud Storage as a sink.
Xem giải thích

Đáp án

B — Dùng plugin lọc của Fluentd trong agent để loại bỏ dòng log chứa thông tin cá nhân

Vì sao đúng

Nguyên tắc với dữ liệu nhạy cảm là chặn ở nguồn. Lọc ngay trong agent nghĩa là thông tin cá nhân không bao giờ rời khỏi máy ảo và không bao giờ được ghi vào hệ thống log. Mọi cách xử lý ở phía sau đều đã muộn: dữ liệu đã nằm trong log, đã được nhân bản và đã vào bản sao lưu.

Vì sao các phương án khác sai

  • A và C. Tạo bộ lọc rồi cấu hình export — export quyết định log đi đâu tiếp, nhưng bản gốc vẫn đã được ghi lại; rò rỉ đã xảy ra.
  • D — cùng hướng đúng là lọc tại agent nhưng phần cấu hình còn lại không đạt.

Nhớ nhanh

Với dữ liệu nhạy cảm, câu hỏi luôn là "chặn được ở khâu sớm nhất nào", không phải "dọn ở đâu".

Câu 9
You manage an application that is writing logs to Stackdriver Logging. You need to give some team members the ability to export logs. What should you do?
  1. A Grant the team members the IAM role of logging.configWriter on Cloud IAM.
  2. B Configure Access Context Manager to allow only these members to export logs.
  3. C Create and grant a custom IAM role with the permissions logging.sinks.list and logging.sink.get.
  4. D Create an Organizational Policy in Cloud IAM to allow only these members to create log exports.
Xem giải thích

Đáp án

A — Cấp vai logging.configWriter

Vì sao đúng

Xuất log nghĩa là tạo và quản lý sink — khai bộ lọc và đích đến. Vai logging.configWriter gói sẵn đúng bộ quyền cho việc đó (logging.sinks.create, .get, .list, .update, .delete). Dùng vai dựng sẵn thay vì tự ghép quyền là cách gọn và ít sai nhất.

Vì sao các phương án khác sai

  • C. Tạo vai tuỳ chỉnh với quyền liệt kê và đọc sink — chỉ cho xem sink, không cho tạo, nên vẫn không xuất được log.
  • B. Access Context Manager — kiểm soát truy cập theo ngữ cảnh (địa chỉ, thiết bị), không cấp quyền trên tính năng.
  • D. Organizational Policy — đặt ràng buộc ở cấp tổ chức, không phải cơ chế cấp quyền cho từng người.
Câu 10
You support an application running on GCP and want to configure SMS notifications to your team for the most critical alerts in Stackdriver Monitoring. You have already identified the alerting policies you want to configure this for. What should you do?
  1. A Download and configure a third-party integration between Stackdriver Monitoring and an SMS gateway. Ensure that your team members add their SMS/phone numbers to the external tool.
  2. B Select the Webhook notifications option for each alerting policy, and configure it to use a third-party integration tool. Ensure that your team members add their SMS/phone numbers to the external tool.
  3. C Ensure that your team members set their SMS/phone numbers in their Stackdriver Profile. Select the SMS notification option for each alerting policy and then select the appropriate SMS/phone numbers from the list.
  4. D Configure a Slack notification for each alerting policy. Set up a Slack-to-SMS integration to send SMS messages when Slack messages are received. Ensure that your team members add their SMS/phone numbers to the external integration.
Xem giải thích

Đáp án

C — Yêu cầu các thành viên khai số điện thoại trong hồ sơ, rồi chọn kênh thông báo SMS

Vì sao đúng

Cloud Monitoring hỗ trợ SMS như một kênh thông báo dựng sẵn. Cơ chế: mỗi người tự khai và xác minh số điện thoại của mình trong hồ sơ, số đó trở thành một notification channel, rồi bạn gắn kênh đó vào các chính sách cảnh báo quan trọng. Không cần tích hợp bên thứ ba nào.

Vì sao các phương án khác sai

  • A. Tích hợp dịch vụ bên thứ ba — thừa, vì tính năng đã có sẵn.
  • B. Dùng webhook rồi tự dựng cầu nối gửi SMS — cũng là dựng lại thứ có sẵn, cộng thêm một thành phần phải vận hành.
  • D. Gửi qua Slack rồi cầu nối sang SMS — vòng vo và thêm một điểm hỏng vào đúng đường cảnh báo quan trọng nhất.