Ngân hàng đề — Google Professional Cloud Architect

Tìm thấy 420 câu.

Câu 131

Your company is restructuring its operations and you've been tasked with reorganizing your Google Cloud resources to match the new business units. You currently have all resources in one project. Your company is divided into several departments, each containing multiple teams. You need to ensure that billing reports can be generated per department, and resources can be isolated per team. What is the most effective way to reorganize your resources?

  1. A

    Create a separate project for each team and use labels to identify the departments.

  2. B

    Create a separate organization for each department and projects for each team under the organizations.

  3. C

    Keep all resources in one project but use different network subnets and labels to differentiate between departments and teams.

  4. D

    Create a folder for each department and then create projects under those folders for each team.

Xem giải thích

Đáp án

D — Tạo một thư mục cho mỗi phòng ban, rồi tạo dự án bên dưới các thư mục đó

Vì sao đúng

Thư mục là tầng được sinh ra đúng cho việc phản ánh cơ cấu tổ chức. Chính sách và quyền đặt ở thư mục kế thừa xuống mọi dự án bên dưới, nên mỗi phòng ban có ranh giới quản trị riêng mà vẫn nằm chung một tổ chức để áp chính sách toàn công ty. Cơ cấu đổi thì di chuyển dự án giữa các thư mục, không phải dựng lại gì.

Vì sao các phương án khác sai

  • B. Mỗi phòng ban một tổ chức riêng — mất gốc chung nên không áp được chính sách toàn công ty, và việc quản lý danh tính, thanh toán bị xé lẻ.
  • A. Mỗi đội một dự án, phân biệt phòng ban bằng nhãn — nhãn dùng để phân loại và tính chi phí; IAM và Organization Policy không áp theo nhãn được.
  • C. Giữ tất cả trong một dự án — không có ranh giới quyền nào giữa các phòng ban.
Câu 132

You are the lead cloud architect for a global company that is migrating its data processing workloads to Google Cloud Platform (GCP). The company's primary requirements include scalability, cost-effectiveness, and the ability to process and analyze data in real-time. You need to choose the most appropriate GCP service to meet these requirements. Which of the following would you recommend?

  1. A

    Cloud Functions

  2. B

    Dataflow

  3. C

    Compute Engine

  4. D

    App Engine

Xem giải thích

Đáp án

B — Dataflow

Vì sao đúng

Dataflow là dịch vụ xử lý dữ liệu không máy chủ dựa trên Apache Beam, và điểm mạnh của nó là một mô hình lập trình dùng chung cho cả xử lý luồng lẫn xử lý theo lô. Nó tự co giãn theo khối lượng dữ liệu, tự cân bằng lại công việc khi một phần chậm, và không có cụm nào phải dựng hay vá.

Vì sao các phương án khác sai

  • A. Cloud Functions — hàm ngắn theo sự kiện, có giới hạn thời gian chạy và bộ nhớ; không phải công cụ xử lý dữ liệu quy mô lớn.
  • C. Compute Engine — làm được mọi thứ, nhưng bạn tự lo toàn bộ khung xử lý, việc chia phần và khả năng chịu lỗi.
  • D. App Engine — nền tảng chạy ứng dụng web, không phải công cụ xử lý dữ liệu.
Câu 133

Your team is building a real-time multiplayer game backend on Google Cloud that must ensure minimal latency for players located across North America, Europe, and Asia. The backend uses a RESTful API, real-time state synchronization over WebSockets, and a Cloud Spanner database. What architectural design will best help reduce latency for players in all regions?

  1. A

    Deploy the backend in GKE clusters in three regions (e.g., us-central1, europe-west1, asia-east1), use global HTTP(S) Load Balancing with Cloud Armor, and use regional Cloud Spanner instances in each region.

  2. B

    Use a single-region App Engine flexible deployment and leverage Memorystore as a global cache for fast responses.

  3. C

    Deploy the backend to multiple regions with GKE, use Cloud Load Balancing with proximity-based routing, and configure a multi-region Cloud Spanner instance with leader placement in North America.

  4. D

    Deploy the application in a single GKE cluster in us-central1, use a global external Application Load Balancer, and serve all players from that region.

Xem giải thích

Đáp án

C — Triển khai GKE ở nhiều khu vực, kèm Cloud Load Balancing

Vì sao đúng

Với trò chơi nhiều người chơi thời gian thực, độ trễ do quãng đường vật lý là thứ không code nào bù được. Đặt backend ở cả ba châu lục rút ngắn quãng đường đó, còn cân bằng tải toàn cầu của Google tự đưa mỗi người chơi tới cụm gần nhất — quyết định định tuyến xảy ra ở biên mạng, ngay khi kết nối bắt đầu.

Vì sao các phương án khác sai

  • A. Dựng GKE ở ba khu vực nhưng thiếu cơ chế đưa người chơi tới đúng khu vực — có hạ tầng mà không có phần điều hướng thì người chơi vẫn có thể rơi vào cụm ở xa.
  • B. Một khu vực với Memorystore làm bộ đệm — bộ đệm giảm thời gian truy vấn dữ liệu, không giảm được thời gian gói tin bay nửa vòng trái đất.
  • D. Một cụm duy nhất ở us-central1 với IP toàn cầu — địa chỉ thì toàn cầu nhưng máy chủ vẫn ở một chỗ; người chơi châu Á vẫn chịu độ trễ cao.
Câu 134

For this question, refer to the Cymbal Retail case study.

https://services.google.com/fh/files/misc/v6.1_pca_cymbal_retail_case_study_english.pdf


Cymbal wants to automate product discovery by allowing customers to search for products using natural language queries such as “lightweight running shoes for trail running under $150”. The solution must scale with traffic spikes, integrate with Cymbal’s existing Kubernetes-based microservices, and reduce reliance on manual catalog tagging. Cymbal also wants to minimize operational overhead and avoid managing custom ML infrastructure. Which architecture best meets Cymbal’s requirements for automated, natural language–driven product discovery?

  1. A

    Use Vertex AI Search for Retail to index the product catalog and integrate it with the web and conversational channels via APIs

  2. B

    Index product data in Elasticsearch on Compute Engine and apply keyword-based search with synonyms

  3. C

    Use Cloud Natural Language API to extract entities from user queries and map them manually to product categories

  4. D

    Deploy a custom NLP model on GKE, trained on product descriptions stored in Cloud Storage

Xem giải thích

Đáp án

A — Dùng Vertex AI Search for Retail để đánh chỉ mục danh mục sản phẩm

Vì sao đúng

Đây là dịch vụ được quản lý dựng riêng cho tìm kiếm trong bán lẻ. Nó hiểu ý định mua hàng chứ không chỉ khớp từ khoá, chịu được lỗi chính tả và từ đồng nghĩa, và xếp hạng theo hành vi người dùng thật. Đồng bộ danh mục là chạy được, không phải huấn luyện mô hình hay vận hành cụm tìm kiếm.

Vì sao các phương án khác sai

  • B. Elasticsearch trên máy ảo với khớp từ khoá — phải vận hành cụm, và khớp từ khoá thuần không hiểu được ý định người mua.
  • C. Cloud Natural Language API — trích xuất thực thể từ câu chữ, nhưng không phải công cụ tìm kiếm và không có phần xếp hạng.
  • D. Tự huấn luyện mô hình NLP trên GKE — tốn nhất, và gần như chắc chắn không bằng dịch vụ đã được tối ưu cho ngành bán lẻ.
Câu 135

Your company is operating a multi-tier web application on Google Cloud. The frontend servers should be globally available and scale automatically to handle traffic, while the backend servers should be accessed only by the frontend servers and internal systems. The data transfer between backend and frontend servers needs to be encrypted. As a cloud architect, how should you design your network to fulfill these requirements?

  1. A

    Use two separate VPCs for frontend and backend servers, and connect them using VPN.

  2. B

    Deploy the frontend on App Engine and backend on Compute Engine within a shared VPC, and use SSL/TLS for encrypted communication.

  3. C

    Deploy both frontend and backend servers on Compute Engine instances within the same subnet.

  4. D

    Use Kubernetes Engine for both frontend and backend servers, and segregate them using network policies.

Xem giải thích

Đáp án

B — Giao diện chạy trên App Engine, backend chạy trên Compute Engine, trong một Shared VPC

Vì sao đúng

Hai tầng có hai yêu cầu khác nhau nên dùng hai nền tảng khác nhau là hợp lý: App Engine cho tầng giao diện vì nó có sẵn phạm vi toàn cầu và tự co giãn; Compute Engine trong VPC cho tầng backend vì nó chỉ cần truy cập nội bộ và bạn muốn kiểm soát mạng chặt. Shared VPC gắn hai phần lại trong một mạng được quản trị tập trung.

Vì sao các phương án khác sai

  • A. Hai VPC riêng nối bằng VPN — thêm một lớp phức tạp và một điểm hỏng, hoàn toàn thừa khi cả hai đều ở trong Google Cloud.
  • C. Cả hai tầng trên Compute Engine — tầng giao diện mất khả năng co giãn toàn cầu tự động mà đề yêu cầu.
  • D. Cả hai trên Kubernetes Engine — chạy được, nhưng phải vận hành cụm cho một tầng giao diện vốn hợp với nền tảng không máy chủ hơn.
Câu 136

You are a cloud architect at a multinational corporation that has recently decided to move its infrastructure to Google Cloud Platform. The company has several departments globally, with each department having multiple teams. You need to design a resource hierarchy that allows you to apply company-wide policies, segregate resources at the department level, and isolate resources at the team level. What would be the best way to set up your GCP resource hierarchy?

  1. A

    Create an organization for each department and projects for each team under those organizations.

  2. B

    Create a project for each department and use IAM roles to segregate resources at the team level.

  3. C

    Create an organization for the company, a project for each department, and folders for each team.

  4. D

    Create an organization for the company, a project for each team, and segregate departments using folders.

Xem giải thích

Đáp án

D — Một tổ chức cho công ty, một dự án cho mỗi đội

Vì sao đúng

Dự án là ranh giới cô lập thật sự trong Google Cloud: quyền, hạn mức, thanh toán và mạng đều tính theo dự án. Vì vậy đơn vị làm việc nhỏ nhất — đội — nên có dự án riêng, để tài nguyên của đội này không đụng tới đội kia và chi phí quy được về đúng nơi. Tất cả nằm dưới một tổ chức để chính sách toàn công ty vẫn áp được.

Vì sao các phương án khác sai

  • A. Mỗi phòng ban một tổ chức — mất gốc chung, không áp được chính sách toàn công ty và xé lẻ việc quản lý danh tính.
  • B. Mỗi phòng ban một dự án, các đội chia nhau bằng vai IAM — nhiều đội dùng chung một dự án nghĩa là chung hạn mức và chung không gian tên tài nguyên; một đội gây sự cố là ảnh hưởng cả phòng ban.
  • C — dùng thư mục ở tầng dưới dự án, ngược với thứ tự thật của cây tài nguyên.
Câu 137

Personally Identifiable Information (PII) and sensitive information about your company's customers should be stored securely in Cloud Storage. Several people from your company's compliance department need access to some of this information. As a cloud architect, what should you do to follow Google's best practices?

  1. A

    You should grant Storage Object Creator role to the entire compliance department.

  2. B

    You should grant Storage Object Viewer role to the entire compliance department.

  3. C

    You should create additional bucket, enable public access, and provide specific file URLs to the compliance department.

  4. D

    You should use granular ACLs on the bucket.

Xem giải thích

Đáp án

D — Dùng ACL chi tiết trên bucket

Vì sao đúng

Đề mô tả nhu cầu cấp quyền cho một số người cụ thể trên một số đối tượng cụ thể, chứ không phải cho cả một phòng ban. ACL chi tiết cho phép làm đúng mức đó, nên thoả nguyên tắc quyền tối thiểu: người cần đọc thì đọc được đúng phần họ cần, không ai thấy nhiều hơn mức cần thiết.

Vì sao các phương án khác sai

  • A. Cấp Storage Object Creator cho cả phòng ban — vừa sai vai (đây là quyền ghi), vừa cấp cho quá nhiều người.
  • B. Cấp Storage Object Viewer cho cả phòng ban — đúng loại quyền nhưng cấp cho toàn bộ phòng ban, tức là nhiều người thấy dữ liệu nhạy cảm hơn mức cần.
  • C. Tạo bucket phụ và bật truy cập công khai — phơi thông tin cá nhân ra Internet; đây là phương án nguy hiểm nhất.
Câu 138

FinServCorp, a financial services company, is migrating its trading platform to Google Cloud. The platform processes real-time financial transactions, and the company must comply with stringent financial regulations that require comprehensive logging, monitoring, and auditing of all transactions. The platform will be deployed using a microservices architecture on Google Kubernetes Engine (GKE) with multiple clusters across regions to ensure high availability. The company also needs to ensure that all logs are stored securely and meet the retention requirements specified by financial regulations. What is the most appropriate solution for ensuring compliance with financial regulations while providing full observability of the trading platform?

  1. A

    Deploy a third-party logging and monitoring solution to manage logs across GKE clusters, storing logs on-premises for compliance purposes.

  2. B

    Use Cloud Monitoring and Logging to capture all logs and metrics, configure log-based metrics for transaction tracking, and use CMEK (Customer-Managed Encryption Keys) for storing logs.

  3. C

    Use Google Cloud Logging with default settings to capture logs from GKE clusters and store them in Cloud Storage with lifecycle policies for retention.

  4. D

    Use Anthos to manage multiple GKE clusters across regions, and implement a hybrid logging solution where logs are collected on-premises and replicated to Google Cloud.

Xem giải thích

Đáp án

B — Dùng Cloud Monitoring và Cloud Logging, cấu hình log sink

Vì sao đúng

Nền tảng giao dịch tài chính có hai nhu cầu về nhật ký: theo dõi vận hành và giữ lại để tuân thủ. Cloud Logging thu thập tự động từ mọi dịch vụ Google Cloud, còn log sink định tuyến bản sao sang nơi lưu trữ dài hạn — Cloud Storage để giữ rẻ, BigQuery để phân tích. Cloud Monitoring lo phần cảnh báo. Tất cả là dịch vụ gốc nên không có agent nào phải cài và vá.

Vì sao các phương án khác sai

  • C. Cloud Logging với thiết lập mặc định — mặc định chỉ giữ log trong khoảng thời gian ngắn, không đạt yêu cầu lưu trữ để tuân thủ.
  • A. Giải pháp giám sát của bên thứ ba — thêm hệ thống phải vận hành và trả phí, trong khi công cụ gốc đã đủ.
  • D. Anthos với kiến trúc lai — Anthos giải bài toán quản lý nhiều cụm, không phải bài toán nhật ký và tuân thủ mà đề đang hỏi.
Câu 139

Production Compute Engine workload is running in a small subnet, which can be expanded. The recent spike in traffic has caused problems, but there are no free IP addresses for Managed Instances Group to autoscale. What should you do?

  1. A

    You should create a new subnet with a larger, overlapping range to automatically move all instances to the new subnet. Then, remove the old subnet.

  2. B

    You should create a new subnet with a larger, non-overlapping range. Move all instances to the new subnet and remove the old subnet.

  3. C

    You should create a new project and a new VPC. Share the new VPC with the existing project and configure all existing resources to use the new VPC.

  4. D

    You should expand the subnet IP range.

Xem giải thích

Đáp án

D — Mở rộng dải IP của chính subnet đó

Vì sao đúng

Google Cloud cho mở rộng dải địa chỉ của một subnet đang chạy mà không gián đoạn: máy đang hoạt động giữ nguyên địa chỉ, và dải mới lớn hơn có thêm chỗ cho máy sinh ra sau. Đề còn nói rõ subnet "có thể mở rộng được", tức là gợi ý thẳng vào đáp án này. Đây là thao tác một bước, không phải di chuyển gì.

Vì sao các phương án khác sai

  • **A. Tạo subnet mới với dải chồng lấn — không hợp lệ; các subnet trong cùng một VPC không được chồng dải địa chỉ.
  • B. Tạo subnet mới rồi chuyển toàn bộ máy sang — làm được nhưng gây gián đoạn và tốn công, trong khi có cách mở rộng tại chỗ.
  • C. Tạo dự án mới và VPC mới rồi chia sẻ — phức tạp hơn rất nhiều so với vấn đề thực tế.
Câu 140

For this question, refer to the Altostrat Media case study.

https://services.google.com/fh/files/misc/v6.1_pca_altostrat_media_case_study_english.pdf 


Altostrat plans to burst compute-intensive media processing workloads (e.g., video analysis and metadata enrichment) from its on-premises Kubernetes cluster into Google Cloud during peak demand. These workloads must scale quickly, maintain consistent networking and security policies, and integrate with existing GKE-based services. What is the most appropriate architecture to support elastic scaling across on-premises and cloud Kubernetes environments while meeting Altostrat’s performance and governance requirements?

  1. A

    Migrate batch workloads to Cloud Run Jobs and invoke them directly from on-premises systems.

  2. B

    Deploy separate GKE clusters per workload and connect them with public load balancers.

  3. C

    Run all burst workloads on preemptible Compute Engine VMs outside of Kubernetes.

  4. D

    Use Anthos clusters on-premises and GKE with shared VPC networking and fleet-based workload identity.

Xem giải thích

Đáp án

D — Dùng cụm Anthos tại chỗ cùng GKE, chung Shared VPC và quản lý theo fleet

Vì sao đúng

Đề mô tả nhu cầu tràn tải lên đám mây: khối lượng công việc bình thường chạy tại chỗ, khi cao điểm thì mở rộng sang Google Cloud. Anthos cho cả hai phía dùng cùng một cách triển khai và cùng một bộ chính sách, còn Shared VPC khiến hai bên nằm trong một không gian mạng thống nhất. Nhờ vậy khối lượng công việc di chuyển được giữa hai nơi mà không phải viết lại.

Vì sao các phương án khác sai

  • A. Cloud Run Jobs gọi thẳng từ tại chỗ — không dùng lại được cách triển khai Kubernetes hiện có, nên phải làm lại phần đóng gói và vận hành.
  • B. Mỗi khối lượng công việc một cụm GKE nối bằng load balancer công khai — đẩy lưu lượng nội bộ ra Internet, vừa kém an toàn vừa tốn.
  • C. Chạy trên máy preemptible ngoài Kubernetes — rẻ nhưng máy bị thu hồi bất cứ lúc nào, và tách khỏi cách vận hành chung.