Ngân hàng đề — Google Professional Cloud Architect
Tìm thấy 420 câu.
For this question, refer to the KnightMotives Automotive case study.
https://services.google.com/fh/files/misc/v6.1_pca_knightmotives_automotive_case_study_english.pdf
KnightMotives plans to monetize vehicle telemetry, in-vehicle interaction data, and post-sale service data to generate insights for product design, predictive maintenance, and new subscription-based services. The data originates from millions of vehicles globally, includes sensitive customer information, and must comply with strict regional privacy regulations. KnightMotives also wants to enable data scientists to build and iterate on ML models at scale without creating data silos or duplicating sensitive datasets. Which architecture best supports secure data monetization and insights while minimizing operational overhead and aligning with privacy and scalability requirements?
-
A
Stream all vehicle data into Pub/Sub, process it with Dataflow, and store it only in Memorystore to ensure low-latency analytics for monetization use cases.
-
B
Centralize all raw and processed data in BigQuery with column-level security and policy tags, use Dataplex for data governance, and build ML models using BigQuery ML and Vertex AI.
-
C
Ingest all vehicle data into Cloud Storage buckets per region, grant analysts direct access using IAM roles, and train models directly from Cloud Storage using Compute Engine.
-
D
Replicate all data into on-premises Hadoop clusters to maintain full control over data sovereignty and use Cloud VPN for periodic synchronization.
Xem giải thích
Đáp án
B — Gom cả dữ liệu thô lẫn dữ liệu đã xử lý vào BigQuery, dùng bảo mật ở mức cột
Vì sao đúng
Với dữ liệu xe từ nhiều khu vực, việc chia nhỏ ra nhiều nơi khiến phân tích xuyên vùng rất khổ. Gom về BigQuery cho một chỗ duy nhất để truy vấn, và bảo mật ở mức cột giải quyết đúng lo ngại đi kèm: những cột nhạy cảm (định danh xe, vị trí) chỉ hiện với vai được cấp quyền, còn nhà phân tích vẫn dùng được phần còn lại. Không cần nhân bản dữ liệu ra nhiều bản đã lược bớt.
Vì sao các phương án khác sai
- A. Chỉ đưa qua Pub/Sub và Dataflow — đó là đường ống nạp dữ liệu, chưa trả lời câu hỏi lưu ở đâu và phân quyền ra sao.
- C. Mỗi khu vực một bucket rồi cấp quyền cho nhà phân tích — phân quyền ở mức tệp, không tới được mức cột, và phân tích xuyên vùng rất khó.
- D. Nhân bản về cụm Hadoop tại chỗ — đi ngược mục tiêu lên đám mây.
A SaaS company provides a critical service to its customers and must ensure high availability and quick recovery in case of a disaster. The company’s primary infrastructure is hosted on Google Cloud Platform (GCP) in the us-central1 region. The company is exploring cost-effective disaster recovery (DR) options in case of a regional outage. The DR strategy must minimize costs during normal operations while allowing rapid failover with minimal data loss. Which disaster recovery strategy would best meet the company's needs while optimizing costs?
-
A
Set up an active-active configuration with infrastructure duplicated in another region (e.g., us-west1) and replicate all data in real-time.
-
B
Use a warm standby approach with minimal running infrastructure in another region and replicate data to a multi-regional Cloud Storage bucket.
-
C
Implement a cold standby approach with infrastructure provisioned but stopped in another region, and replicate critical data to Cloud Storage using scheduled snapshots.
-
D
Implement a cold standby approach with no pre-provisioned infrastructure, and only store backups in a single-region Cloud Storage bucket in another region.
Xem giải thích
Đáp án
B — Dùng phương án warm standby: hạ tầng tối thiểu chạy sẵn ở vùng khác
Vì sao đúng
Warm standby là điểm cân bằng giữa chi phí và thời gian khôi phục: một bản thu nhỏ của hệ thống đã chạy sẵn ở vùng thứ hai, dữ liệu được nhân bản liên tục. Khi có sự cố, chỉ cần mở rộng quy mô và chuyển lưu lượng — tính bằng phút, không phải giờ. Với dịch vụ SaaS quan trọng thì đây thường là lựa chọn đúng.
Vì sao các phương án khác sai
- A. Active–active nhân đôi hạ tầng — khôi phục nhanh nhất nhưng đắt gấp đôi; chỉ đáng khi không chịu được vài phút gián đoạn.
- C. Cold standby có hạ tầng đã dựng nhưng tắt — rẻ hơn nhưng khởi động và đồng bộ dữ liệu mất nhiều thời gian.
- D. Cold standby không dựng sẵn gì — rẻ nhất, chậm nhất, và rủi ro nhất vì quy trình khôi phục chưa bao giờ được thử.
For this question, refer to the Altostrat Media case study.
https://services.google.com/fh/files/misc/v6.1_pca_altostrat_media_case_study_english.pdf
Altostrat is modernizing its media ingestion pipeline. Large audio and video files are currently ingested from legacy on-premises systems into Cloud Storage, where downstream processing on GKE and Cloud Run is triggered. The ingestion workloads are latency-sensitive, transfer multi-terabyte datasets daily, and must be secured end-to-end. Altostrat expects ingestion volume to grow steadily over the next several years and wants a solution that aligns with Google Cloud best practices while minimizing operational overhead. What is the most appropriate architecture for secure, high-performance hybrid connectivity to support Altostrat’s data ingestion needs?
-
A
Use Partner Interconnect with a single VLAN attachment and rely on Cloud Armor for traffic protection.
-
B
Deploy Transfer Appliance devices on-premises and periodically ship them to Google for offline ingestion.
-
C
Provision a Dedicated Interconnect with redundant connections, terminate it in a VPC, and ingest data directly into Cloud Storage using private IPs.
-
D
Use Cloud VPN over the public internet with HA VPN gateways and upload media directly to Cloud Storage.
Xem giải thích
Đáp án
C — Dùng Dedicated Interconnect với các kết nối dự phòng
Vì sao đúng
Truyền tệp phương tiện dung lượng lớn và đều đặn cần băng thông cao, ổn định, không đi qua Internet công cộng. Dedicated Interconnect cho đường vật lý riêng tới Google với dung lượng 10 hoặc 100 Gbps. Khai nhiều kết nối ở các vùng khả dụng khác nhau là điều kiện để đạt cam kết sẵn sàng — một đường đứt thì đường kia gánh.
Vì sao các phương án khác sai
- A. Partner Interconnect với một VLAN duy nhất — một đường là một điểm hỏng duy nhất.
- B. Gửi Transfer Appliance định kỳ — hợp cho lần chuyển dữ liệu lớn một lần, không hợp cho luồng liên tục.
- D. Cloud VPN qua Internet — băng thông bị giới hạn theo đường hầm và độ trễ phụ thuộc Internet công cộng.
After adding a new version of your application in App Engine Standard, users have reported experiencing slow performance issues. Your immediate objective is to revert to the previous version as quickly as possible in response to these complaints. What should you do?
-
A
You should set the previous version as default to route all traffic in App Engine Console.
-
B
You should deploy the previous version on a Kubernetes cluster and use traffic splitting feature to send all traffic to the new application.
-
C
You should deploy the previous version in Flexible environment and use traffic splitting feature to send all traffic to the new application.
-
D
You should deploy the previous version as a new App Engine Application and use traffic splitting feature to send all traffic to the new application.
Xem giải thích
Đáp án
A — Đặt phiên bản trước làm mặc định để chuyển toàn bộ lưu lượng về đó
Vì sao đúng
App Engine giữ lại các phiên bản đã triển khai, nên quay lui chỉ là chuyển lưu lượng, không phải triển khai lại. Thao tác này có hiệu lực gần như tức thì và không cần build hay khởi động gì — đúng thứ cần khi đang có sự cố hiệu năng và mục tiêu là khôi phục nhanh nhất.
Vì sao các phương án khác sai
Cả ba phương án còn lại đều đề xuất triển khai lại bản cũ ở một nơi khác — cụm Kubernetes, môi trường Flexible, hay một ứng dụng App Engine mới. Chúng mất nhiều phút tới nhiều chục phút trong khi bản cũ vẫn đang nằm sẵn ở đó, chờ được trỏ lưu lượng về.
As a cloud architect, you are responsible for preparing a cloud migration plan for services that include wide range of data. A company has 10 PB of different data in on-premises data center. This data need to be transferred to Cloud Storage and the network bandwidth between the on-premises data center and Google Cloud is 10 Gbps. What transfer option should you recommend?
-
A
Transfer Appliance
-
B
Transfer Service
-
C
gsutil -
D
gcloud -
E
BigQuery Data Transfer
Xem giải thích
Đáp án
A — Transfer Appliance
Vì sao đúng
Với 10 petabyte, chuyển qua mạng là không khả thi — kể cả đường 10 Gbps chạy hết công suất liên tục cũng mất khoảng ba tháng. Transfer Appliance là thiết bị lưu trữ vật lý được gửi tới trung tâm dữ liệu của bạn: chép dữ liệu vào, gửi trả Google, họ nạp lên Cloud Storage. Dữ liệu được mã hoá trong suốt quá trình.
Vì sao các phương án khác sai
- B. Storage Transfer Service — chuyển qua mạng, hợp khi nguồn đã ở trên đám mây khác hoặc khi băng thông dư dả.
- C.
gsutil— công cụ dòng lệnh cho vài gigabyte tới vài terabyte. - D.
gcloud— công cụ quản trị chung, không phải công cụ chuyển dữ liệu lớn. - E. BigQuery Data Transfer — nạp dữ liệu vào BigQuery từ các nguồn SaaS, sai loại bài toán.
Your company is migrating its applications to Google Cloud. The IT department needs to ensure that only authorized personnel can modify billing settings and access billing data for all projects under the organization. Which Identity and Access Management (IAM) roles should you assign to the billing team to meet these requirements while adhering to Google Cloud's best practices?
-
A
Billing Account Viewer, Billing Account Administrator
-
B
Billing Account User, Project Viewer
-
C
Billing Account Administrator, Project Owner
-
D
Billing Account User, Organization Administrator
Xem giải thích
Đáp án
A — Billing Account Viewer và Billing Account Administrator
Vì sao đúng
Đề có hai nhu cầu tách bạch và mỗi vai lo một:
- Billing Account Administrator — quyền sửa thiết lập thanh toán: gắn tài khoản vào dự án, đổi phương thức thanh toán, quản lý người dùng. Đây là vai nên cấp cho rất ít người.
- Billing Account Viewer — chỉ xem chi phí và báo cáo. Đây là vai cho những người cần theo dõi ngân sách mà không được đổi gì.
Cặp này thể hiện đúng nguyên tắc quyền tối thiểu: tách quyền đọc khỏi quyền ghi.
Vì sao các phương án khác sai
- B và D. Billing Account User — vai này cho phép gắn tài khoản thanh toán vào dự án mới, không phải vai chỉ để xem.
- C. Project Owner — quyền rất rộng trên tài nguyên dự án, vượt xa nhu cầu về thanh toán.
A global media company needs to build a cloud-based data analytics platform on GCP to analyze viewer data in real-time from multiple regions. The company requires the solution to support stream processing, handle petabytes of data daily, and allow data scientists to run ad-hoc queries efficiently. Data must be stored for at least 5 years for regulatory compliance, and the platform should be cost-effective, especially during off-peak times when data queries are less frequent. Which architecture would best meet the company's requirements?
-
A
Use Dataproc with Kafka for stream processing, Cloud Storage for storage, and BigQuery for analytics.
-
B
Deploy a Hadoop cluster on GCE for stream processing, Bigtable for storage, and Cloud Storage Nearline for long-term data storage.
-
C
Use Dataflow for stream processing, BigQuery for storage and analysis, and Cloud Storage for long-term data storage.
-
D
Implement Pub/Sub for stream processing, Cloud SQL for storage, and Cloud Spanner for analytics.
Xem giải thích
Đáp án
C — Dataflow để xử lý luồng, BigQuery để lưu và phân tích
Vì sao đúng
Đây là bộ đôi chuẩn của Google Cloud cho phân tích thời gian thực, và cả hai đều không máy chủ: Dataflow xử lý luồng dựa trên Apache Beam, tự co giãn theo lưu lượng và xử lý được dữ liệu tới muộn — điều luôn xảy ra khi thu thập từ nhiều khu vực. BigQuery nhận dữ liệu theo luồng và truy vấn được ngay, quy mô petabyte mà không phải quản lý cụm nào.
Vì sao các phương án khác sai
- A. Dataproc với Kafka — phải vận hành cụm, trái tinh thần dịch vụ được quản lý.
- B. Tự dựng Hadoop trên máy ảo — nặng nhất về vận hành.
- D. Pub/Sub để xử lý luồng, Cloud SQL để lưu — Pub/Sub chỉ truyền thông điệp chứ không xử lý, và Cloud SQL không kham nổi phân tích ở quy mô này.
You have been hired by a rapidly growing e-commerce company to design their new cloud infrastructure on Google Cloud Platform (GCP). The company anticipates a significant increase in user traffic during the holiday season, with peaks expected to be 10x their normal load. The solution needs to handle this increased traffic without any downtime and must also minimize operational costs when traffic is low. Additionally, the platform needs to ensure data consistency across regions, provide a reliable shopping cart experience, and comply with PCI DSS (Payment Card Industry Data Security Standard) requirements. Which architecture would best meet the company’s requirements?
-
A
Deploy the e-commerce application on a single GCE instance with a regional persistent disk, and manually scale the instance during peak times.
-
B
Implement the e-commerce application on Cloud Run, with a multi-regional Cloud SQL instance and a managed Redis instance for caching.
-
C
Deploy the e-commerce application using App Engine Standard Environment with auto-scaling, and use a single-region Cloud SQL instance for the database.
-
D
Use GKE (Google Kubernetes Engine) to deploy a containerized e-commerce application, with auto-scaling enabled based on CPU utilization and a multi-regional database with Cloud Spanner.
Xem giải thích
Đáp án
D — Dùng GKE triển khai ứng dụng thương mại điện tử đã đóng gói container
Vì sao đúng
Đề nêu tăng trưởng nhanh và lưu lượng biến động mạnh. GKE cho co giãn ở hai mức — số pod theo tải và số node theo nhu cầu pod — cùng khả năng triển khai từng phần độc lập, cuốn chiếu và quay lui. Với hệ thống thương mại điện tử nhiều thành phần và dự kiến phình to, đây là nền tảng có đường phát triển rõ ràng nhất.
Vì sao các phương án khác sai
- A. Một máy ảo duy nhất — điểm hỏng duy nhất và không co giãn.
- B. Cloud Run — rất tốt cho dịch vụ không trạng thái, nhưng hạn chế hơn khi cần điều phối nhiều thành phần chạy nền và tác vụ dài.
- C. App Engine Standard — co giãn tốt nhưng ràng buộc về môi trường chạy và thư viện, khó hơn khi hệ thống phức tạp dần.
For this question, refer to the Cymbal Retail case study.
https://services.google.com/fh/files/misc/v6.1_pca_cymbal_retail_case_study_english.pdf
Cymbal wants to increase online sales conversion by improving how customers discover products. Today, the web application only supports basic keyword and category searches against relational databases, which leads to poor results for customers who use natural language or vague product descriptions. Cymbal wants to introduce intelligent, personalized product discovery that works across web and conversational channels, while minimizing operational overhead and enabling rapid iteration. Which architecture should Cymbal adopt to best drive sales conversion while following Google Cloud best practices?
-
A
Migrate all product data into Cloud SQL and use SQL full-text search with custom ranking logic in the application layer.
-
B
Deploy a self-managed Elasticsearch cluster on GKE and build custom relevance and personalization models.
-
C
Index product data in BigQuery and build scheduled SQL-based recommendation queries exposed through a REST API.
-
D
Use Vertex AI Search for retail with product feeds synchronized from existing databases and integrate it with web and conversational interfaces.
Xem giải thích
Đáp án
D — Dùng Vertex AI Search for retail, đồng bộ nguồn dữ liệu sản phẩm sẵn có
Vì sao đúng
Đây là dịch vụ được quản lý dựng riêng cho tìm kiếm và gợi ý trong bán lẻ: hiểu ý định người mua, xếp hạng theo hành vi, xử lý được cả lỗi chính tả và từ đồng nghĩa. Đồng bộ danh mục sản phẩm là xong, không phải tự huấn luyện mô hình xếp hạng hay vận hành cụm tìm kiếm nào.
Vì sao các phương án khác sai
- A. Full-text search của Cloud SQL — tìm theo từ khoá cơ bản, không có xếp hạng theo hành vi.
- B. Tự dựng Elasticsearch trên GKE rồi tự viết công thức xếp hạng — làm được nhưng phải vận hành cụm và tự nuôi phần xếp hạng, tốn nhất trong bốn phương án.
- C. Đánh chỉ mục trong BigQuery rồi chạy SQL theo lịch — BigQuery là kho phân tích, không phải công cụ tìm kiếm độ trễ thấp; và gợi ý theo lịch thì luôn cũ.
For this question, refer to the Cymbal Retail case study.
https://services.google.com/fh/files/misc/v6.1_pca_cymbal_retail_case_study_english.pdf
Cymbal Retail is experiencing rapidly increasing traffic and catalog growth. The current architecture relies on multiple relational databases queried directly by a custom web application. This approach leads to high database costs during traffic spikes and inefficient scaling. Cymbal wants to reduce operational costs while improving scalability and performance for catalog browsing, without increasing operational overhead. Which Google Cloud architecture should Cymbal adopt to reduce costs while maintaining scalable, high-performance product catalog access?
-
A
Migrate all product catalog data into Cloud SQL and vertically scale the instances to handle peak traffic
-
B
Deploy larger Kubernetes clusters with autoscaling enabled and continue querying relational databases directly
-
C
Implement a caching layer using Memorystore in front of existing relational databases
-
D
Build a serverless API backed by Firestore for catalog queries, with Cloud CDN in front
Xem giải thích
Đáp án
D — Dựng API không máy chủ với Firestore làm nơi lưu danh mục
Vì sao đúng
Truy vấn danh mục sản phẩm có đặc điểm rất rõ: đọc nhiều, ghi ít, lưu lượng biến động. Firestore hợp đúng hình dạng đó — tự co giãn, đọc theo khoá ở mức mili giây, không cần điều chỉnh gì khi lượng truy cập tăng. Ghép với tầng API không máy chủ thì toàn bộ đường đọc không có máy nào phải vận hành.
Vì sao các phương án khác sai
- A. Dồn vào Cloud SQL rồi nâng cấu hình máy — mở rộng theo chiều dọc luôn có trần, và đắt dần.
- B. Cụm Kubernetes lớn hơn nhưng vẫn truy vấn CSDL quan hệ — nút thắt nằm ở tầng dữ liệu, thêm pod không giải quyết.
- C. Thêm Memorystore làm bộ đệm — giảm tải thật, nhưng chỉ hoãn vấn đề và thêm một tầng phải quản lý tính nhất quán.