Ngân hàng đề — Google Professional Cloud Architect
Tìm thấy 420 câu.
In the process of deploying an application on App Engine that requires integration with an on-premises database, you encounter a security constraint where the on-premises database cannot be accessed through the public Internet. What steps would you recommend taking to address this issue?
-
A
Deploy your application on App Engine Standard environment and use Cloud SQL for SQL Server to limit access to the on-premises database.
-
B
Deploy your application on App Engine Standard environment and use App Engine firewall rules to limit access to the open on-premises database.
-
C
Deploy your application on App Engine Flexible environment and use Cloud VPN to limit access to the on-premises database.
-
D
Deploy your application on App Engine Flexible environment and use App Engine firewall rules to limit access to the on-premises database.
Xem giải thích
Đáp án
C — Triển khai lên App Engine Flexible và dùng Cloud VPN
Vì sao đúng
Ràng buộc của đề là CSDL tại chỗ không truy cập được qua Internet công cộng, nên ứng dụng phải tới được nó bằng mạng riêng. Hai mảnh ghép lại:
- App Engine Flexible chạy trong VPC của bạn, nên nối được vào mạng riêng — App Engine Standard thì không có khả năng đó theo cách trực tiếp như vậy.
- Cloud VPN dựng đường hầm mã hoá giữa VPC và trung tâm dữ liệu, để lưu lượng đi bằng IP nội bộ.
Vì sao các phương án khác sai
- B và D. Dùng luật tường lửa của App Engine — luật này lọc lưu lượng đi vào ứng dụng App Engine, không tạo ra đường đi tới mạng tại chỗ.
- A. Dùng Cloud SQL for SQL Server — là một CSDL khác trên đám mây, không phải cách kết nối tới CSDL tại chỗ mà đề đang nói.
Your team is managing a database that processes large volumes of e-commerce transaction data. The database runs PostgreSQL on a Debian Linux Compute Engine instance. The instance is an n1-standard-4 VM with 16 GB of RAM and 50 GB of SSD zonal persistent disk. Users report slow query performance during peak hours. You cannot restart the virtual machine until the next scheduled maintenance window. What is the most cost-effective solution to improve performance immediately?
-
A
Add a regional persistent disk to the instance and use it for temporary data
-
B
Upgrade the virtual machine to an n1-standard-8 instance
-
C
Configure the database to use in-memory caching for frequently accessed data.
-
D
Enable database replication to distribute the load across multiple instances
Xem giải thích
Đáp án
C — Cấu hình CSDL dùng bộ nhớ đệm trong RAM cho dữ liệu hay truy cập
Vì sao đúng
Với PostgreSQL xử lý khối lượng lớn giao dịch, phần lớn độ trễ đến từ việc đọc đi đọc lại cùng những trang dữ liệu từ đĩa. Tăng bộ nhớ đệm — shared_buffers và bộ đệm của hệ điều hành — khiến tập dữ liệu nóng nằm sẵn trong RAM, và đọc từ RAM nhanh hơn đọc từ đĩa hàng trăm lần. Đây là cách chỉnh cho hiệu quả cao nhất trên mỗi đồng bỏ ra.
Vì sao các phương án khác sai
- B. Nâng máy lên
n1-standard-8— có thể giúp, nhưng là giải pháp thô: nếu nút thắt là đọc đĩa thì thêm vCPU chẳng giải quyết gì. - A. Gắn thêm đĩa bền vùng cho dữ liệu tạm — đĩa vùng nhân bản qua nhiều zone nên chậm hơn đĩa thường khi ghi; dùng cho dữ liệu tạm là chọn sai.
- D. Bật nhân bản để chia tải — chia được tải đọc, nhưng thêm hẳn một hệ thống phải vận hành, và không giúp gì cho tải ghi của khối lượng giao dịch.
For this question, refer to the Cymbal Retail case study.
https://services.google.com/fh/files/misc/v6.1_pca_ehr_healthcare_case_study_english.pdf
EHR's client in the healthcare sector is a world-renowned research and hospital facility. A significant number of the patients at this renowned research and hospital facility are prominent public figures. There have been consistent attempts from both internal and external sources to illicitly access the health information of these patients. To safeguard patient privacy, the hospital has implemented a policy that restricts the movement of patient information stored in Cloud Storage buckets beyond the geographic boundaries where the buckets are located. It is crucial for you to ensure that the data stored in Cloud Storage buckets within the europe-west2 region remains confined within this specific region and does not get transferred elsewhere. What actions are recommended?
-
A
You should assign the Identity and Access Management (IAM)
storage.objectViewerrole only to users and service accounts that need to use the data. -
B
You should create an access control list (ACL) that limits access to the bucket to authorized users only, and apply it to the buckets in the
europe-west2region. -
C
You should encrypt the data in the application on-premises before the data is stored in the
europe-west2region. -
D
You should enable Virtual Private Network Service Controls, and create a service perimeter around the Cloud Storage resources.
Xem giải thích
Đáp án
D — Bật VPC Service Controls và tạo một vành đai dịch vụ
Vì sao đúng
VPC Service Controls lập một vành đai quanh các dịch vụ được quản lý như Cloud Storage và BigQuery. Trong vành đai đó, dữ liệu không thể bị sao chép ra ngoài kể cả bởi người có thông tin đăng nhập hợp lệ — đây chính là lớp phòng thủ mà IAM không cung cấp được. IAM trả lời câu hỏi "ai được truy cập", còn Service Controls trả lời "dữ liệu được phép đi tới đâu".
Vì sao các phương án khác sai
- A. Cấp vai
storage.objectViewer— kiểm soát ai đọc được, nhưng người đọc được vẫn tải dữ liệu ra ngoài thoải mái. - B. Dùng ACL — cơ chế phân quyền cũ hơn, cùng hạn chế như trên và khó quản lý hơn.
- C. Mã hoá dữ liệu tại chỗ trước khi tải lên — bảo vệ nội dung, nhưng không ngăn dữ liệu bị đưa ra khỏi phạm vi cho phép, mà đó mới là yêu cầu.
Your company is migrating its existing on-premises data warehouse to Google Cloud Platform (GCP). The data warehouse is critical for daily operations, including real-time analytics and reporting. The on-premises data is stored in a PostgreSQL database, which is heavily used by various internal applications. The data warehouse will be moved to BigQuery on GCP, but it’s essential to maintain real-time synchronization between the on-premises PostgreSQL database and BigQuery. Your solution should be cost-effective and scalable, without requiring major changes to the existing on-premises infrastructure. Which solution best meets the requirements for integrating the on-premises PostgreSQL database with BigQuery for real-time synchronization?
-
A
Use Google Kubernetes Engine (GKE) to host a self-managed PostgreSQL database and use a custom application to sync data with BigQuery.
-
B
Use Cloud Dataflow with a custom streaming pipeline that reads changes from the PostgreSQL database and writes them to BigQuery.
-
C
Use Cloud Pub/Sub to capture changes from the PostgreSQL database and stream them into BigQuery using Dataflow.
-
D
Set up a Cloud SQL instance with PostgreSQL, replicate the on-premises database to Cloud SQL, and then use federated queries in BigQuery to access the data.
Xem giải thích
Đáp án
C — Dùng Cloud Pub/Sub để bắt thay đổi từ PostgreSQL và đưa lên theo luồng
Vì sao đúng
Đề đòi đồng bộ gần thời gian thực trong lúc kho dữ liệu cũ vẫn phải phục vụ vận hành hằng ngày. Pub/Sub làm lớp đệm giữa hệ thống nguồn và đích: thay đổi được đẩy vào topic ngay khi xảy ra, bên tiêu thụ đọc theo nhịp của mình, và nếu đích tạm chậm thì tin nhắn nằm chờ chứ không mất. Nhờ vậy hệ thống nguồn không bị đích kéo theo.
Vì sao các phương án khác sai
- A. Tự dựng PostgreSQL trên GKE — chỉ dời chỗ chạy, không giải quyết việc đồng bộ liên tục, và vẫn phải tự vận hành CSDL.
- B. Dataflow đọc thẳng thay đổi từ CSDL — đường ống nối cứng vào CSDL nguồn, nên khi đường ống nghẽn hoặc chết thì áp lực dội ngược lại hệ thống đang phục vụ vận hành.
- D. Cloud SQL với nhân bản — bản sao là bản đọc chạy sau, hợp cho việc chuyển đổi CSDL chứ không phải cho việc đưa dữ liệu vào kho phân tích.
Your company is building a customer support chatbot using generative AI. The goal is to provide helpful, fluent, and brand-aligned responses to customer queries across web and mobile channels. You decide to use Gemini 1.5 Pro via Vertex AI. Which of the following is the most appropriate way to ensure consistency and customization in the model's responses?
-
A
Use system instructions in the prompt to define the chatbot's tone and behavior
-
B
Use Gemini Nano instead, as it’s more powerful than Gemini 1.5 Pro
-
C
Enable automatic data logging to improve Gemini’s future responses
-
D
Retrain the Gemini model from scratch using internal customer service logs
Xem giải thích
Đáp án
A — Dùng system instruction trong prompt để định nghĩa giọng điệu và hành vi
Vì sao đúng
System instruction là cách rẻ nhất, nhanh nhất và sửa được ngay để định hình cách mô hình trả lời: giọng điệu, phạm vi được nói, điều cấm nói, cách xưng hô theo thương hiệu. Thay đổi chỉ là sửa một đoạn văn bản rồi phát hành lại, không phải huấn luyện gì. Với yêu cầu "trả lời trôi chảy và đúng chất thương hiệu" thì đây đúng là công cụ.
Vì sao các phương án khác sai
- D. Huấn luyện lại Gemini từ đầu — cực kỳ tốn kém, và hoàn toàn thừa cho việc chỉ chỉnh giọng điệu; nếu cần bám sát hơn nữa thì cũng chỉ tinh chỉnh chứ không huấn luyện lại.
- B. Dùng Gemini Nano vì mạnh hơn — sai về sự thật: Nano là bản nhỏ nhất, dựng cho thiết bị đầu cuối, kém hơn hẳn các bản Pro.
- C. Bật ghi log tự động để mô hình tự cải thiện — mô hình không tự học từ log hội thoại của bạn; đó không phải cách nó hoạt động.
Your company runs a mission-critical application on Google Cloud with multiple microservices. Recently, the application experienced downtime due to a service failure, which had a cascading effect. As a Cloud Architect, what should you do to enhance the solution's reliability and prevent such incidents in the future?
-
A
Implement load balancing and auto-scaling for all microservices.
-
B
Implement circuit breakers and retries with exponential backoff and jitter for inter-service communications.
-
C
Implement regular disaster recovery drills to ensure the readiness of the backup system.
-
D
Move the application to a monolithic architecture to simplify the complexity.
Xem giải thích
Đáp án
B — Dùng circuit breaker cùng cơ chế thử lại có exponential backoff và jitter
Vì sao đúng
Đề mô tả đúng hiện tượng hỏng dây chuyền: một dịch vụ chết kéo theo cả hệ thống. Hai kỹ thuật này chặn đúng cơ chế lan truyền đó:
- Circuit breaker — sau một số lần gọi thất bại thì ngắt hẳn, trả lỗi ngay thay vì để các yêu cầu xếp hàng chờ hết thời gian; nhờ vậy dịch vụ gọi không bị cạn luồng xử lý.
- Exponential backoff kèm jitter — mỗi lần thử lại giãn ra xa hơn, và jitter thêm độ lệch ngẫu nhiên để mọi máy khách không cùng thử lại tại một thời điểm. Thiếu jitter thì đám đông thử lại đồng loạt sẽ đánh sập dịch vụ vừa hồi phục.
Vì sao các phương án khác sai
- A. Cân bằng tải và tự co giãn — giúp chịu tải, nhưng khi một dịch vụ hỏng chức năng thì thêm bản sao chỉ nhân số lần hỏng lên.
- C. Diễn tập khôi phục thảm hoạ — cần thiết, nhưng là chuẩn bị cho sự cố chứ không ngăn được hỏng dây chuyền.
- D. Quay về kiến trúc nguyên khối — đánh đổi rất lớn để né một vấn đề đã có cách giải quyết.
A financial services company has migrated its legacy on-premises applications to Google Cloud. The goals of the migration included improving application performance, reducing operational costs, and enhancing security and compliance. Six months after the migration, the company’s leadership team wants to evaluate the success of the project. They have defined several key performance indicators (KPIs) to measure the impact of the migration.
The KPIs defined are:
-
KPI 1: Reduction in operational costs (target: 30% reduction).
-
KPI 2: Application response time (target: 50% improvement).
-
KPI 3: Incident resolution time (target: 40% faster resolution).
-
KPI 4: Compliance audit score (target: 100% compliance with industry regulations).
-
KPI 5: User satisfaction score (target: increase by 25%).
Which approach should the company take to effectively measure the success of the migration project?
-
A
Conduct a comprehensive review of all KPIs, weighting each according to its importance to the business goals. Use a balanced scorecard approach to ensure that cost, performance, compliance, and user experience are all considered in the evaluation.
-
B
Evaluate all KPIs equally, but prioritize those that are easily quantifiable, such as KPI 1, KPI 2, and KPI 3, since they provide clear numerical data. User satisfaction (KPI 5) should be given less importance due to its subjective nature.
-
C
Focus on KPI 1 and KPI 2, as these directly reflect cost savings and performance improvements, which were the primary goals of the migration. The other KPIs are secondary and can be reviewed later.
-
D
Use KPI 4 as the primary measure of success since compliance is crucial in the financial services industry. If compliance is achieved, the migration is considered successful regardless of the other KPIs.
Xem giải thích
Đáp án
A — Rà soát toàn diện mọi KPI, đánh trọng số theo mức quan trọng đối với doanh nghiệp
Vì sao đúng
Cuộc di chuyển có nhiều mục tiêu — hiệu năng, chi phí, tuân thủ — nên đánh giá thành công cũng phải nhìn đủ. Nhưng "nhìn đủ" không có nghĩa coi mọi chỉ số ngang nhau: với một tổ chức tài chính, tuân thủ nặng hơn một khoản tiết kiệm nhỏ. Đánh trọng số là cách diễn đạt thứ tự ưu tiên đó một cách tường minh, thay vì để nó ngầm định trong đầu vài người.
Vì sao các phương án khác sai
- B. Ưu tiên KPI nào dễ đo — dễ đo không có nghĩa là quan trọng; đây là cách bỏ sót đúng những thứ khó đo mà lại đáng giá nhất.
- C. Chỉ nhìn hai KPI về chi phí và hiệu năng — bỏ hẳn phần tuân thủ.
- D. Lấy riêng KPI tuân thủ làm thước đo chính — tuân thủ là điều kiện bắt buộc, nhưng chỉ đạt tuân thủ mà hiệu năng và chi phí đều tệ thì cuộc di chuyển vẫn thất bại.
Your team runs a nightly ETL pipeline that extracts data from Cloud Storage, transforms it using Apache Spark, and loads it into BigQuery. The job runs once a day at 2 AM and typically takes 45 minutes. You need a cost-effective, reliable solution with minimal operational overhead. Which architecture should you recommend?
-
A
Use Cloud Functions triggered by Cloud Scheduler to orchestrate and run the Spark job directly
-
B
Run the ETL job in a Compute Engine VM scheduled with cron and manage dependencies manually
-
C
Use Dataproc with a scheduled job to spin up a cluster on demand, run the ETL, and shut it down afterward
-
D
Run the ETL in a permanent Dataproc cluster that stays active 24/7 to reduce startup time
Xem giải thích
Đáp án
C — Dùng Dataproc với công việc theo lịch: dựng cụm khi cần, chạy xong thì xoá
Vì sao đúng
Công việc chỉ chạy mỗi đêm một lần, nên giữ cụm sống 24/7 là trả tiền cho 23 giờ không làm gì. Dataproc dựng cụm trong khoảng hai phút, chạy công việc Spark, rồi tự xoá — đây là mô hình cụm phù du, và nó cũng loại luôn chuyện cụm bị trôi cấu hình theo thời gian vì mỗi lần chạy đều bắt đầu từ trạng thái sạch.
Vì sao các phương án khác sai
- D. Giữ cụm Dataproc chạy suốt để tiết kiệm thời gian khởi động — đánh đổi sai: tiết kiệm hai phút mỗi ngày để trả tiền cho 23 giờ nhàn rỗi.
- B. Máy ảo với cron và tự quản lý phụ thuộc — tự dựng lại Dataproc bằng tay, kèm mọi việc vá lỗi và quản lý phiên bản Spark.
- A. Cloud Functions kích hoạt Spark — Cloud Functions có giới hạn thời gian chạy, không kham nổi một công việc ETL nặng.
Your SRE team is designing improvements to production operations. They want to reduce operational toil, improve incident response, and ensure teams are learning from failures. Which recommendation best reflects the operational excellence pillar of the Google Cloud Well-Architected Framework?
-
A
Allow engineers to bypass post-incident reviews (PIRs) for minor outages to save time
-
B
Rely primarily on dashboards and let engineers manually watch metrics during peak periods
-
C
Implement automated monitoring and alerting with well-defined SLOs and error budgets
-
D
Increase logging verbosity to maximum for all services to catch every potential issue
Xem giải thích
Đáp án
C — Giám sát và cảnh báo tự động, với SLO rõ ràng và ngân sách lỗi
Vì sao đúng
Ba mục tiêu của đội — giảm việc tay chân, xử lý sự cố tốt hơn, học được từ thất bại — đều quy về một nền tảng: số liệu khách quan. SLO biến "dịch vụ chạy tốt" thành con số; cảnh báo tự động thay việc ngồi canh biểu đồ; và ngân sách lỗi cho một quy tắc rõ ràng về khi nào được đẩy tính năng mới, khi nào phải dừng lại sửa độ tin cậy — thay vì tranh luận theo cảm tính.
Vì sao các phương án khác sai
- A. Bỏ qua rà soát sau sự cố với những lần hỏng nhỏ — chính những sự cố nhỏ mới là nơi học được nhiều nhất mà không phải trả giá đắt; bỏ qua là vứt đi mục tiêu "học từ thất bại".
- B. Ngồi canh biểu đồ bằng mắt — đúng là việc tay chân mà đề muốn giảm, và con người không canh nổi 24/7.
- D. Bật log ở mức chi tiết nhất cho mọi dịch vụ — chi phí tăng vọt và tín hiệu thật chìm trong nhiễu; log nhiều không đồng nghĩa với quan sát tốt.
For this question, refer to the Cymbal Retail case study.
https://services.google.com/fh/files/misc/v6.1_pca_cymbal_retail_case_study_english.pdf
Cymbal wants to reduce cart abandonment and increase completed purchases, especially for customers who currently fail to finish transactions and require call center assistance. The company plans to modernize its IVR system into a conversational commerce solution that can answer product questions, recommend alternatives, and guide users through checkout in real time. Which Google Cloud–based approach best supports this goal while aligning with Cymbal’s modernization strategy?
-
A
Build a conversational interface using Dialogflow CX integrated with product discovery and order APIs running on GKE.
-
B
Replace the IVR with a call center CRM system hosted on Compute Engine virtual machines.
-
C
Extend the existing IVR with additional decision trees and route complex requests to human agents earlier.
-
D
Implement a custom chatbot using open-source NLP libraries deployed on-premises.
Xem giải thích
Đáp án
A — Dựng giao diện hội thoại bằng Dialogflow CX, tích hợp dữ liệu sản phẩm
Vì sao đúng
Cymbal muốn giảm tải cho tổng đài. Dialogflow CX lo phần khó nhất: hiểu ngôn ngữ tự nhiên và quản lý hội thoại nhiều lượt có rẽ nhánh — thứ mà cây quyết định của IVR không làm được. Nối vào dữ liệu sản phẩm thì trợ lý trả lời được câu hỏi thật về đơn hàng và hàng tồn, nên khách được giải quyết ngay thay vì phải chờ người.
Vì sao các phương án khác sai
- C. Mở rộng IVR bằng thêm cây quyết định — càng thêm nhánh thì menu càng dài và khách càng bỏ cuộc; đây là làm nặng thêm cái đang hỏng.
- B. Thay IVR bằng hệ CRM trên máy ảo — CRM hỗ trợ nhân viên làm việc, không tự trả lời khách.
- D. Tự dựng chatbot bằng thư viện mã nguồn mở đặt tại chỗ — tự xây và tự nuôi phần hiểu ngôn ngữ, tốn nhất và chậm nhất.