Ngân hàng đề — Google Professional Cloud Architect
Tìm thấy 420 câu.
Your organization operates multiple production services on Google Cloud. Some teams deploy updates manually, while others maintain long-lived VM instances with manual configuration changes. Leadership wants to improve operational excellence, reduce variance between environments, and ensure that deployments are predictable, repeatable, and auditable. Which approach best aligns with the operational excellence principles of the Google Cloud Well-Architected Framework?
-
A
Continue manual VM configuration but enforce a strict checklist all engineers must follow
-
B
Migrate all workloads to unmanaged instance groups to allow faster patching of individual VMs
-
C
Disable automated rollbacks to ensure teams manually validate each deployment issue
-
D
Adopt infrastructure-as-code (IaC) using tools like Terraform or Deployment Manager
Xem giải thích
Đáp án
D — Áp dụng hạ tầng dạng mã bằng Terraform hoặc Deployment Manager
Vì sao đúng
Vấn đề gốc là mỗi đội làm một kiểu và cấu hình được sửa bằng tay. Hạ tầng dạng mã đổi bản chất chuyện đó: cấu hình trở thành mã nguồn được rà soát, ghi vết trong lịch sử, và dựng lại được y hệt ở mọi môi trường. Sự trôi cấu hình biến mất vì trạng thái mong muốn nằm trong tệp chứ không nằm trong trí nhớ của ai.
Vì sao các phương án khác sai
- A. Giữ cách làm tay nhưng thêm danh sách kiểm tra — vẫn phụ thuộc con người nhớ và làm đúng mỗi lần; đây chính là thứ đang hỏng.
- B. Chuyển hết sang unmanaged instance group — bỏ mất tự co giãn và tự chữa lành, đi lùi.
- C. Tắt quay lui tự động — làm sự cố kéo dài hơn, đúng ngược mục tiêu.
An e-commerce platform expects a significant increase in traffic during its seasonal sale events. The platform requires a database solution that supports high transaction throughput, low latency, and scales automatically to handle unpredictable workloads. Security is critical, as the platform processes sensitive customer data, and compliance with data residency requirements is mandatory. Which solution would best meet these requirements?
-
A
Deploy a single-node Cloud Spanner instance.
-
B
Deploy MySQL on Compute Engine with manual scaling.
-
C
Use Cloud SQL with read replicas enabled.
-
D
Implement Cloud Spanner with multi-region configuration.
Xem giải thích
Đáp án
D — Cloud Spanner ở cấu hình đa vùng
Vì sao đúng
Đề đòi thông lượng giao dịch cao và co giãn được cho các đợt khuyến mãi theo mùa. Spanner là CSDL quan hệ duy nhất trong danh sách mở rộng theo chiều ngang mà vẫn giữ giao dịch ACID và nhất quán mạnh — thêm node là thêm năng lực, không phải chia mảnh thủ công. Cấu hình đa vùng còn cho tính sẵn sàng cao khi mất một khu vực.
Vì sao các phương án khác sai
- A. Spanner một node — tự tay bỏ đi ưu điểm mở rộng, và không có dự phòng.
- B. MySQL trên máy ảo co giãn thủ công — thao tác tay không kịp với đợt tải tăng đột ngột.
- C. Cloud SQL với bản sao đọc — bản sao đọc chia tải đọc, nhưng mọi thao tác ghi vẫn dồn về một máy chủ; với sàn thương mại điện tử lúc cao điểm thì ghi mới là nút thắt.
As a cloud architect, you are designing a complex deployment scenario for a client that involves using an unmanaged instance group with an active instance and a standby instance in different zones. You are required to use a regional persistent disk and a network load balancer in front of the instances. How do you ensure that in the event of a failure, traffic will be redirected to the standby instance?
-
A
Implement Cloud CDN for traffic redirection.
-
B
Use Google Cloud Armor for traffic redirection.
-
C
Use Cloud NAT for traffic redirection.
-
D
Implement a health check and use a regional network load balancer.
Xem giải thích
Đáp án
D — Dùng health check kết hợp regional network load balancer
Vì sao đúng
Mô hình chủ động – dự phòng cần hai thứ: một cơ chế biết máy chính đã chết, và một cơ chế chuyển lưu lượng sang máy dự phòng. Health check lo vế đầu, load balancer lo vế sau, và cả hai phối hợp tự động nên không cần ai can thiệp lúc nửa đêm.
Vì sao các phương án khác sai
- A. Cloud CDN — nhớ đệm nội dung ở biên mạng, không phải cơ chế chuyển đổi dự phòng.
- B. Cloud Armor — tường lửa ứng dụng web, lọc lưu lượng độc hại chứ không định tuyến lại.
- C. Cloud NAT — cho máy không có IP công khai đi ra Internet, chẳng liên quan tới lưu lượng đi vào.
Your company has multiple regional analytics teams across North America, Europe, and Asia. Each region uses its own data warehouse, but executives want to standardize KPIs globally using Looker. You are tasked with designing a solution that ensures centralized modeling, governed metrics, and consistency, while allowing regional teams to explore their data independently. What should you do?
-
A
Use federated queries to connect all data sources directly to Looker with no modeling
-
B
Export regional datasets to Cloud Storage and refresh them weekly for Looker to use
-
C
Use LookML to define centralized models and connect Looker to a shared BigQuery dataset with row-level access controls
-
D
Deploy Looker in each region and let each team maintain its own data model
Xem giải thích
Đáp án
C — Dùng LookML định nghĩa mô hình tập trung, nối Looker vào một dataset BigQuery dùng chung
Vì sao đúng
Vấn đề của ban lãnh đạo là cùng một chỉ số nhưng mỗi khu vực tính một kiểu. LookML giải quyết tận gốc: định nghĩa chỉ số được viết một lần dưới dạng mã, được rà soát và quản lý phiên bản, rồi mọi báo cáo ở mọi khu vực đều lấy từ định nghĩa đó. "Doanh thu" chỉ có đúng một cách tính.
Vì sao các phương án khác sai
- A. Truy vấn liên kết tới mọi nguồn, không có tầng mô hình — vẫn mỗi nơi một cách tính, đúng vấn đề đang gặp.
- B. Xuất ra Cloud Storage rồi làm mới hằng tuần — dữ liệu lạc hậu tới một tuần và vẫn không thống nhất được định nghĩa.
- D. Mỗi khu vực một Looker riêng với mô hình riêng — làm vấn đề trầm trọng thêm.
A global e-commerce company operates a platform that must be available 24/7 with minimal downtime, even in the event of regional outages. The platform handles sensitive customer data and needs to comply with strict data protection regulations. The company’s current infrastructure is hosted on Google Cloud, and they are considering implementing a disaster recovery (DR) plan to ensure business continuity in case of a failure in their primary region.
The company’s business requirements include:
-
Recovery Point Objective (RPO) of less than 1 hour.
-
Recovery Time Objective (RTO) of less than 15 minutes.
-
Data residency compliance in multiple regions.
-
Cost-effectiveness of the DR solution.
-
Ability to handle peak loads in the event of a failover.
Which DR solution should the company implement?
-
A
Set up a global load balancer to distribute traffic between two regions where the entire infrastructure is duplicated. Use Cloud Bigtable for storing critical data with replication enabled between the regions.
-
B
Use Google Cloud Storage for cross-region replication of all data, with a scheduled Cloud Function that spins up resources in a secondary region only when a failure is detected.
-
C
Deploy the entire platform using Google Kubernetes Engine (GKE) in a single region, with daily snapshots of Persistent Disks stored in a different region. Use a Cold DR strategy by only keeping critical resources active in a secondary region.
-
D
Implement a multi-region Cloud Spanner database for storing all critical customer data, with a load balancer configured to direct traffic to the nearest region. Use Managed Instance Groups (MIGs) for application servers in multiple regions with autoscaling enabled.
Xem giải thích
Đáp án
D — Cloud Spanner đa vùng cho toàn bộ dữ liệu khách hàng quan trọng
Vì sao đúng
Đề đòi hoạt động 24/7 kể cả khi mất trọn một khu vực, và dữ liệu là thông tin khách hàng nhạy cảm. Spanner đa vùng nhân bản đồng bộ qua nhiều khu vực và vẫn giữ nhất quán mạnh — mất một khu vực thì hệ thống tự chuyển, không mất dữ liệu và không phải thao tác gì. Với dữ liệu giao dịch của khách hàng thì đây là điểm khác biệt quyết định.
Vì sao các phương án khác sai
- A. Load balancer toàn cầu giữa hai khu vực — giải quyết tầng ứng dụng, nhưng đề đang hỏi về tầng dữ liệu; ứng dụng còn sống mà CSDL chết thì cũng vô nghĩa.
- B. Nhân bản qua Cloud Storage theo lịch — nhân bản định kỳ luôn có khoảng dữ liệu bị mất khi sự cố xảy ra giữa hai lần chạy.
- C. GKE trong một khu vực — không chịu được sự cố cấp khu vực.
To leverage Cloud Pub/Sub messages within your App Engine application, you find that the Cloud Pub/Sub API is currently disabled. In order to enable your application to utilize Cloud Pub/Sub, you plan to authenticate it to the API using a service account. What measures should you take to ensure seamless usage of Cloud Pub/Sub by your application?
-
A
You should grant the App Engine Default service account the role of Cloud Pub/Sub Admin. Have your application enable the API on the first connection to Cloud Pub/Sub.
-
B
You should use Deployment Manager to deploy your application. Rely on the automatic enablement of all APIs used by the application being deployed.
-
C
You should enable the Cloud Pub/Sub API in the API Library on the GCP Console.
-
D
You should rely on the automatic enablement of the Cloud Pub/Sub API when the Service Account accesses it.
Xem giải thích
Đáp án
C — Bật Cloud Pub/Sub API trong API Library trên GCP Console
Vì sao đúng
API phải được bật cho từng dự án trước khi dùng — đây là bước hay bị bỏ qua nhất. Khi chưa bật, mọi lời gọi đều thất bại kể cả khi tài khoản dịch vụ đã có đủ quyền, và thông báo lỗi rất dễ bị hiểu nhầm thành lỗi phân quyền, khiến người ta đi cấp thêm vai một cách vô ích.
Vì sao các phương án khác sai
- A. Cấp vai Pub/Sub cho tài khoản dịch vụ mặc định — cần thiết cho phần phân quyền, nhưng không bật được API.
- B và D. Trông chờ API tự bật — không có cơ chế tự bật khi ứng dụng gọi tới; API phải được bật tường minh, dù bằng Console,
gcloudhay hạ tầng dạng mã.
Your team is designing a critical Google Cloud-based application that must support rapid feature delivery, minimal downtime, and a clear operational responsibility model. According to the Operational Excellence pillar of the Well-Architected Framework, which approach best aligns with recommended practices?
-
A
Establish clear Service Level Objectives (SLOs) and implement automated monitoring and alerting based on them
-
B
Allow each development team to define its own incident response plan independently
-
C
Use preemptible VMs for all components to lower cost and restart them manually if needed
-
D
Focus solely on increasing test coverage and defer operational concerns until production
Xem giải thích
Đáp án
A — Thiết lập SLO rõ ràng và giám sát tự động
Vì sao đúng
Đề đòi ba thứ: phát hành nhanh, gián đoạn tối thiểu, và mô hình trách nhiệm vận hành rõ ràng. SLO là công cụ nối cả ba lại: nó biến "dịch vụ chạy tốt" thành con số cụ thể, và ngân sách lỗi sinh ra từ đó chính là cơ chế quyết định khi nào được đẩy tính năng mới và khi nào phải dừng lại để sửa độ tin cậy. Giám sát tự động khiến việc đó dựa trên số liệu chứ không dựa trên cảm tính.
Vì sao các phương án khác sai
- B. Mỗi đội tự viết quy trình xử lý sự cố riêng — sự cố thường trải qua nhiều dịch vụ; quy trình rời rạc khiến không ai biết ai chịu trách nhiệm phần nào.
- C. Dùng máy preemptible cho mọi thành phần — máy bị thu hồi bất cứ lúc nào, phá thẳng mục tiêu gián đoạn tối thiểu.
- D. Chỉ tăng độ phủ test rồi tính chuyện vận hành sau — test bắt lỗi trước khi phát hành, không thay được việc quan sát hệ thống đang chạy.
A financial services company requires a highly available and resilient application that serves users globally. The application handles sensitive financial transactions and must comply with strict regulatory requirements, including data residency. The company wants to deploy the application in multiple regions to ensure minimal downtime in case of a regional failure. However, the company is also concerned about the costs associated with maintaining a multi-region architecture and seeks to optimize costs while ensuring compliance and availability. Which design should you recommend for the disaster recovery solution?
-
A
Deploy the application in two regions with an active-passive setup using Compute Engine managed instance groups, with data replicated asynchronously using Cloud SQL.
-
B
Deploy the application in a single region with backups stored in a different region using Google Cloud Storage Nearline, and use Google Cloud DNS to redirect traffic during a failure.
-
C
Deploy the application in two regions with active-active load balancing using Cloud Load Balancing, and use Cloud Spanner for globally consistent data storage.
-
D
Deploy the application in multiple regions using Google Kubernetes Engine (GKE) with multi-cluster support, and use Cloud Memorystore for Redis to replicate session data globally.
Xem giải thích
Đáp án
C — Triển khai ở hai khu vực theo mô hình chủ động – chủ động có cân bằng tải
Vì sao đúng
Với giao dịch tài chính phục vụ người dùng toàn cầu, mô hình chủ động – chủ động cho hai lợi ích cùng lúc: cả hai khu vực đều đang phục vụ nên người dùng luôn được đưa tới nơi gần nhất, và khi một khu vực hỏng thì khu vực còn lại đã sẵn sàng — không có khoảng thời gian khởi động hay chuyển đổi. Đây là mức sẵn sàng cao nhất trong bốn phương án.
Vì sao các phương án khác sai
- A. Chủ động – bị động — khu vực dự phòng nằm chờ, nên vừa lãng phí vừa có độ trễ khi chuyển, và quy trình chuyển đổi hiếm khi được thử nên hay hỏng đúng lúc cần.
- B. Một khu vực, sao lưu ở khu vực khác — khôi phục từ bản sao lưu tính bằng giờ.
- D. GKE nhiều khu vực — nền tảng hợp lý, nhưng phương án không nêu cơ chế phân phối lưu lượng giữa các khu vực, tức là thiếu đúng phần quyết định.
A mission-critical application runs on several virtual machines in on-premise data center and needs to be migrated to GCP. As a cloud architect, you need to prepare a migration strategy. The company wants to benefit from Lift and Shift approach, and this application needs to be scaled automatically and efficiently based on the CPU utilization. What do you recommend?
-
A
This company should deploy the application to GKE cluster with Horizontal Pod Autoscaling enabled based on CPU utilization.
-
B
This company should deploy the application to Google Compute Engine Managed Instance Group with time-based autoscaling based on last months traffic patterns.
-
C
This company should deploy the application to Compute Engine Unmanaged Instance Group with autoscaling enabled based on CPU utilization.
-
D
This company should deploy the application to Compute Engine Managed Instance Group with autoscaling enabled based on CPU utilization.
Xem giải thích
Đáp án
D — Managed Instance Group với tự co giãn dựa trên mức dùng CPU
Vì sao đúng
Đề có ba điều kiện: lift and shift (giữ nguyên máy ảo, không đóng gói lại), tự co giãn, và co giãn theo tải thật. Managed Instance Group đáp ứng đủ — vẫn là máy ảo nên không phải sửa ứng dụng, mà lại có tự co giãn, tự chữa lành và cập nhật cuốn chiếu. Lấy mức dùng CPU làm tín hiệu nghĩa là hệ thống phản ứng với tải đang xảy ra.
Vì sao các phương án khác sai
- A. GKE với Horizontal Pod Autoscaling — phải đóng gói ứng dụng thành container, tức không còn là lift and shift.
- B. Co giãn theo lịch dựa trên lưu lượng tháng trước — chỉ đúng khi tải lặp lại đều; một đợt tăng bất thường là hụt năng lực, mà đây là ứng dụng trọng yếu.
- C. Unmanaged Instance Group có tự co giãn — nhóm loại này không hỗ trợ tự co giãn; đó là khác biệt cốt lõi giữa hai loại.
You are designing a cloud infrastructure for a financial analytics platform that processes large datasets in real-time. The platform needs to scale automatically based on the volume of incoming data, which can vary significantly throughout the day. The architecture includes Compute Engine instances for data processing, BigQuery for data analysis, and Cloud Storage for data archival. The platform has experienced intermittent failures during peak loads due to quota limitations, causing delays in data processing. You must design a solution that ensures the platform remains elastic and resilient to sudden spikes in demand while adhering to Google Cloud's quota and limit policies. Which of the following design choices best addresses the elasticity requirements while managing quota limits effectively?
-
A
Deploy a fixed number of non-preemptible VM instances in a single zone, increase the project's quota limits manually, and use a regional BigQuery dataset.
-
B
Use Kubernetes Engine with horizontal pod autoscaling, deploy the application across multiple regions, and set up regional BigQuery datasets with slots auto-scaling enabled.
-
C
Use managed instance groups with auto-scaling enabled across multiple regions, and distribute workloads using Cloud Load Balancing. Set up multiple BigQuery datasets, one for each region, to manage quota limits.
-
D
Deploy a large number of preemptible VM instances in a single region for data processing, and set up auto-scaling based on CPU utilization. Use a single BigQuery dataset for all regions.
Xem giải thích
Đáp án
C — Managed Instance Group có tự co giãn, trải trên nhiều khu vực
Vì sao đúng
Đề đòi tự co giãn theo tải và ngầm định là phải chịu được sự cố. Managed Instance Group cho tự co giãn và tự chữa lành, còn việc trải trên nhiều khu vực khiến mất một khu vực vẫn còn năng lực phục vụ. Với nền tảng phân tích tài chính xử lý dữ liệu lớn thì cả hai đều không thể thiếu.
Vì sao các phương án khác sai
- A. Số máy cố định trong một zone — không co giãn, và một zone hỏng là mất tất cả.
- B. GKE với horizontal pod autoscaling — bản thân là lựa chọn tốt, nhưng phương án giới hạn triển khai ở phạm vi hẹp hơn nên không đạt yêu cầu về khả năng chịu lỗi.
- D. Nhiều máy preemptible trong một khu vực — máy bị thu hồi bất cứ lúc nào; dùng cho công việc phân tích chịu được gián đoạn thì được, làm nền tảng chính thì không.