Ngân hàng đề — Google Professional Cloud Architect

Tìm thấy 420 câu.

Câu 141

As a cloud architect, it is your responsibility to monitor any modifications made to the Cloud Storage bucket. For each change, you are required to trigger an action that will promptly validate the compliance of the modification in near real-time. What action should you take?

  1. A

    You should use the built-in triggering mechanism of Cloud Storage to run your security script.

  2. B

    You should use a Python script to get appropriate logs, analyze them, and run the security script.

  3. C

    You should use Crone Scheduler to schedule your security script.

  4. D

    You should use Cloud Function events, and call your security script from the Cloud Function triggers.

Xem giải thích

Đáp án

D — Dùng sự kiện của Cloud Storage để gọi Cloud Function

Vì sao đúng

Cloud Storage phát sinh sự kiện cho mỗi thay đổi trên đối tượng (finalize, delete, metadataUpdate), và Cloud Function đăng ký nhận sự kiện đó rồi chạy ngay. Đây là mô hình đẩy: script bảo mật chạy tại thời điểm thay đổi xảy ra, không có độ trễ và không bỏ sót.

Vì sao các phương án khác sai

  • C. Dùng bộ lập lịch chạy định kỳ — luôn có khoảng trễ giữa lúc thay đổi xảy ra và lúc script chạy; với mục đích bảo mật thì khoảng trễ đó chính là cửa sổ rủi ro.
  • B. Viết script Python đọc và phân tích log — tự dựng lại cơ chế sự kiện, phức tạp và vẫn có độ trễ.
  • A. "Cơ chế kích hoạt có sẵn của Cloud Storage" — cách kích hoạt chính thức là qua sự kiện gắn với Cloud Functions hoặc Pub/Sub, tức là chính phương án D.
Câu 142

Your company, a mid-sized financial institution, plans to migrate its legacy core banking application from on-premises data centers to Google Cloud. The application is built on an outdated custom Java framework and uses an Oracle database. The application has strict compliance requirements, including data residency within specific regions, and it relies heavily on software licenses that are currently tied to physical servers. The company also needs to minimize downtime during the migration due to the critical nature of the application. Which of the following steps should be included in your migration plan to address software license mapping and compliance requirements?

  1. A

    Rebuild the application from scratch using Google Kubernetes Engine (GKE) to eliminate all legacy license dependencies.

  2. B

    Use Google Cloud Migrate for Compute Engine to automatically map and migrate existing software licenses to Google Cloud VMs, ensuring compliance.

  3. C

    Transfer all existing Oracle licenses to Google Cloud's managed services (e.g., Cloud SQL or Cloud Spanner) to simplify license management.

  4. D

    Leverage Google Cloud's Sole-Tenant Nodes to maintain software license compliance and ensure data residency requirements are met.

Xem giải thích

Đáp án

D — Dùng Sole-Tenant Nodes để giữ tuân thủ giấy phép phần mềm

Vì sao đúng

Giấy phép của nhiều phần mềm doanh nghiệp — Oracle là ví dụ điển hình — tính theo lõi vật lý và đòi biết chính xác phần cứng đang chạy. Trên hạ tầng dùng chung thì không thoả điều kiện đó. Sole-Tenant Node cấp cho bạn một máy chủ vật lý riêng, không ai khác chạy trên đó, nên mô hình "mang giấy phép của bạn sang" trở nên hợp lệ.

Vì sao các phương án khác sai

  • A. Viết lại từ đầu trên GKE — dự án nhiều năm cho một ứng dụng ngân hàng lõi, rủi ro cao nhất.
  • B. Dùng Migrate for Compute Engine chuyển tự động — công cụ tốt cho việc chuyển máy ảo, nhưng không giải quyết ràng buộc giấy phép, mà đó mới là điểm chặn ở đây.
  • C. Chuyển giấy phép Oracle sang dịch vụ được quản lý của Google — Cloud SQL không hỗ trợ Oracle, nên phương án này không thực hiện được.
Câu 143

A logistics company is developing a distributed application on Google Kubernetes Engine (GKE) to manage its global operations. The application consists of microservices running in containers that need to communicate securely with each other across multiple GKE clusters in different regions. The company also requires the ability to scale the application horizontally as demand fluctuates, while ensuring minimal latency and high availability. Additionally, the company wants to ensure that its internal traffic remains private and does not traverse the public internet. Which of the following approaches would best meet the company’s requirements for container networking?

  1. A

    Use GKE with private clusters and enable Kubernetes Network Policy for traffic management. Rely on Google Cloud’s default routing to manage cross-region communication between clusters.

  2. B

    Use GKE with VPC-native (alias IP) mode enabled, and configure Network Policy to restrict traffic between microservices. Deploy a multi-cluster ingress controller for cross-cluster communication.

  3. C

    Set up each GKE cluster with its own VPC and connect them using VPC Peering. Use Calico for network policy enforcement and rely on public IPs for cross-cluster communication.

  4. D

    Implement GKE with VPC-native (alias IP) mode and enable Istio for service mesh, using mTLS for securing communication between services. Configure Private Service Connect to keep internal traffic private.

Xem giải thích

Đáp án

D — GKE ở chế độ VPC-native (alias IP) kèm Istio làm service mesh

Vì sao đúng

Ứng dụng phân tán gồm nhiều microservice cần hai lớp:

  • VPC-native (alias IP) — pod nhận địa chỉ IP thật trong VPC, nên định tuyến và luật tường lửa áp trực tiếp lên pod thay vì phải đi qua lớp NAT.
  • Istio — quản lý lưu lượng giữa các dịch vụ: mã hoá mTLS giữa các dịch vụ, chính sách truy cập chi tiết, thử lại, ngắt mạch, và quan sát được toàn bộ luồng gọi.

Với ứng dụng toàn cầu nhiều dịch vụ, lớp mesh là thứ mà Network Policy đơn thuần không thay được.

Vì sao các phương án khác sai

  • A và B. Chỉ dùng Network Policy — kiểm soát được pod nào nói chuyện với pod nào, nhưng không có mã hoá giữa các dịch vụ, không có thử lại hay ngắt mạch, và quan sát rất hạn chế.
  • C. Mỗi cụm một VPC rồi nối bằng peering — peering không bắc cầu nên mô hình nhiều cụm sẽ phình rất nhanh.
Câu 144

You are a cloud architect and have been tasked with creating a data retention policy on a Google Cloud Storage (GCS) bucket that holds sensitive client information. This policy should ensure that objects older than 90 days are not accessible, even if they haven't been deleted. Also, to ensure business continuity, deleted objects should be restorable within 5 days. Which of the following methods would be the most suitable for implementing this policy?

  1. A

    Apply a 90-day lifecycle rule to delete objects, enable versioning, and use a 5-day lifecycle rule to delete previous versions of objects.

  2. B

    Apply a 90-day lifecycle rule to delete objects and a 5-day retention policy to retain deleted objects.

  3. C

    Apply a 90-day lifecycle rule to archive objects and enable versioning with a 5-day lifecycle rule to delete previous versions of objects.

  4. D

    Apply a 90-day retention policy to the bucket and a 5-day lifecycle rule to delete older versions of objects.

Xem giải thích

Đáp án

A — Luật vòng đời xoá đối tượng sau 90 ngày, bật versioning, kèm chính sách giữ bản cũ ngắn hạn

Vì sao đúng

Hai cơ chế của Cloud Storage lo hai việc khác nhau và đề cần cả hai:

  • Lifecycle rule — tự động xoá đối tượng khi quá 90 ngày, tức là thực thi chính sách lưu trữ.
  • Versioning — giữ lại bản cũ khi đối tượng bị ghi đè hoặc xoá, nên xoá nhầm vẫn khôi phục được; ràng buộc thời gian ngắn cho bản cũ khiến chúng không tích tụ vô hạn.

Vì sao các phương án khác sai

  • D — đảo vai của hai cơ chế: retention policy ngăn xoá trước hạn chứ không tự xoá, còn lifecycle mới là thứ xoá. Đặt nhầm vai thì dữ liệu không bao giờ bị dọn.
  • B. Có lifecycle nhưng không có versioning — xoá nhầm là mất hẳn.
  • C. Chuyển sang lớp lưu trữ nguội thay vì xoá — không đạt yêu cầu về chính sách lưu trữ, và dữ liệu nhạy cảm vẫn nằm đó mãi.
Câu 145

For this question, refer to the EHR Healthcare case study.

https://services.google.com/fh/files/misc/v6.1_pca_ehr_healthcare_case_study_english.pdf


The sales employees of EHR work remotely and travel to various locations for their job. These employees require access to web-based sales tools located in the EHR data center. EHR has made the decision to retire their existing Virtual Private Network (VPN) infrastructure, necessitating the migration of the web-based sales tools to a BeyondCorp access model. Each sales employee possesses a Google Workspace account, which they utilize for single sign-on (SSO) purposes. What should you do?

  1. A

    You should create a Google group for the sales tool application, and upgrade that group to a security group.

  2. B

    You should deploy an external HTTP(S) load balancer and create a custom Cloud Armor policy for the sales tool application.

  3. C

    You should create an Identity-Aware Proxy (IAP) connector that points to the sales tool application.

  4. D

    For every sales employee who needs access to the sales tool application, you should give their Google Workspace user account the predefined AppEngine Viewer role.

Xem giải thích

Đáp án

C — Tạo một IAP connector trỏ tới ứng dụng bán hàng

Vì sao đúng

Identity-Aware Proxy cho phép đặt lớp xác thực bằng danh tính công ty trước ứng dụng, kể cả ứng dụng chạy tại chỗ, mà không phải sửa mã và không phải dựng VPN cho từng nhân viên. Kết quả: nhân viên bán hàng đăng nhập bằng tài khoản công ty là dùng được ở bất cứ đâu, còn người ngoài không tới được ứng dụng dù biết địa chỉ.

Vì sao các phương án khác sai

  • A. Tạo Google group và nâng cấp gì đó — nhóm giúp quản lý ai được quyền, nhưng tự nó không tạo ra lớp kiểm soát truy cập đứng trước ứng dụng.
  • B. Load balancer ngoài với Cloud Armor — Cloud Armor lọc theo IP và mẫu tấn công, không xác thực danh tính người dùng.
  • D. Dựng kết nối riêng cho từng nhân viên — không mở rộng được và là gánh nặng quản trị lớn.
Câu 146

As a cloud architect, while utilizing the Google Network Intelligence Center's Firewall Insights feature, you observe that there are no log rows available for viewing when accessing the Firewall Insights page in the Google Cloud console. This prompts the need for assessing the effectiveness of the applied firewall ruleset, considering the existence of multiple firewall rules associated with the Compute Engine instance. To troubleshoot the issue, what steps should you take?

  1. A

    Enable Firewall Rules Logging for the firewall rules you want to monitor.

  2. B

    Verify that your user account is assigned the compute.networkAdmin Identity and Access Management (IAM) role.

  3. C

    Enable Virtual Private Cloud (VPC) flow logging.

  4. D

    Install the Google Cloud SDK, and verify that there are no Firewall logs in the command line output.

Xem giải thích

Đáp án

A — Bật Firewall Rules Logging cho những luật muốn theo dõi

Vì sao đúng

Firewall Insights phân tích nhật ký của luật tường lửa, mà nhật ký đó mặc định tắt — bật theo từng luật một. Không có dữ liệu đầu vào thì màn hình trống là đúng, không phải lỗi. Đây cũng là lựa chọn có chủ ý của Google: ghi log mọi luật trên mọi VPC sẽ tạo lượng dữ liệu và chi phí rất lớn.

Vì sao các phương án khác sai

  • C. Bật VPC flow logs — đó là nguồn dữ liệu khác, ghi lại luồng lưu lượng chứ không ghi việc luật nào khớp; Firewall Insights không đọc nó.
  • B. Kiểm tra vai compute.networkAdmin — thiếu quyền thì thường báo lỗi truy cập chứ không hiện bảng trống.
  • D. Cài Cloud SDK để kiểm tra — không liên quan; log nằm ở phía máy chủ.
Câu 147

A SaaS company is running its multi-tenant analytics platform on BigQuery and notices rising storage and query costs. Tenants have varying workloads—some perform frequent queries, while others are occasional users. As the cloud architect, how can you optimize BigQuery cost while maintaining performance and tenant isolation?

  1. A

    Assign tenants with heavy workloads to flat-rate reservations and keep light users on on-demand, using multi-tenant slots with reservation assignments.

  2. B

    Use on-demand pricing and instruct tenants to optimize their SQL queries for performance.

  3. C

    Move all tenants to a flat-rate pricing model using a single reservation for predictable costs.

  4. D

    Create separate BigQuery projects per tenant to isolate billing and performance, and apply maximum cost thresholds using quotas.

Xem giải thích

Đáp án

A — Khách hàng dùng nhiều thì gán vào flat-rate reservation, khách hàng dùng ít giữ nguyên on-demand

Vì sao đúng

Hai mô hình giá của BigQuery hợp với hai kiểu tải khác nhau, và đề nói rõ các khách hàng không giống nhau:

  • Flat-rate (reservation) — trả một mức cố định cho năng lực tính toán; đáng khi truy vấn nhiều và đều, vì chi phí đoán trước được và không tăng theo lượng dữ liệu quét.
  • On-demand — trả theo lượng dữ liệu quét; rẻ hơn hẳn khi chỉ thỉnh thoảng chạy vài truy vấn.

Chia theo hành vi thật là cách duy nhất tối ưu được cho cả hai nhóm.

Vì sao các phương án khác sai

  • C. Dồn tất cả vào một reservation chung — khách dùng ít phải gánh chi phí cố định, và các khách hàng tranh nhau cùng một nhóm năng lực nên hiệu năng lẫn lộn.
  • B. Giữ on-demand cho tất cả rồi nhờ khách tự tối ưu SQL — chi phí vẫn không đoán trước được, và dựa vào việc người khác làm đúng.
  • D. Mỗi khách một dự án riêng — tách được hoá đơn nhưng không tự nó giảm chi phí.
Câu 148

Your retail analytics platform needs to integrate a conversational AI assistant that can perform product search, summarize customer reviews, and generate personalized recommendations. The company requires Google-managed foundational models, tight integration with Vertex AI, and the ability to customize the model with proprietary retail data while maintaining strong data governance. Which Google Cloud service best meets these requirements?

  1. A

    Running a self-hosted open-source LLM on GKE

  2. B

    Cloud Functions with a custom Python NLP model

  3. C

    Vertex AI Gemini models in Model Garden

  4. D

    Dialogflow CX with a custom intent-based agent

Xem giải thích

Đáp án

C — Mô hình Vertex AI Gemini trong Model Garden

Vì sao đúng

Ba việc mà đề yêu cầu — tìm sản phẩm, tóm tắt đánh giá của khách, sinh gợi ý cá nhân hoá — đều là việc của mô hình ngôn ngữ lớn đa năng. Gemini qua Model Garden cho dùng ngay qua API được quản lý, có sẵn phần suy luận co giãn, và tinh chỉnh được nếu cần bám sát dữ liệu riêng. Không phải vận hành GPU nào.

Vì sao các phương án khác sai

  • D. Dialogflow CX với intent tự khai — mô hình dựa trên ý định khai sẵn rất tốt cho hội thoại có kịch bản, nhưng không tóm tắt hay sinh nội dung tự do được.
  • A. Tự chạy mô hình mã nguồn mở trên GKE — phải tự lo GPU, tối ưu suy luận và cập nhật mô hình; tốn nhất.
  • B. Cloud Functions với mô hình NLP tự viết — giới hạn tài nguyên khiến không chạy nổi mô hình cỡ lớn.
Câu 149

An e-commerce company has petabytes of customer behavior data stored in private data center. Due to storage limitations in private data center, this company decided to migrate this data to GCP. The data must be available for your analysts, who have strong SQL background. How should you store the data to meet these requirements?

  1. A

    You should import data into BigQuery.

  2. B

    You should import flat files into Cloud Storage.

  3. C

    You should import data into Cloud SQL.

  4. D

    You should import data into Cloud Datastore.

Xem giải thích

Đáp án

A — Nạp dữ liệu vào BigQuery

Vì sao đúng

Dữ liệu hành vi khách hàng ở mức petabyte và mục đích là phân tích. BigQuery là kho dữ liệu không máy chủ, tách rời phần lưu trữ khỏi phần tính toán, nên nó xử lý được quy mô đó mà không cần dựng cụm hay chia mảnh. Đây là dịch vụ duy nhất trong danh sách hợp cả về quy mô lẫn mục đích.

Vì sao các phương án khác sai

  • B. Đưa tệp phẳng vào Cloud Storage — lưu được, rẻ, nhưng tự nó không phân tích được; đây thường là bước trung gian trước khi nạp vào BigQuery.
  • C. Cloud SQL — CSDL giao dịch một máy chủ, không kham nổi petabyte.
  • D. Cloud Datastore — kho tài liệu cho ứng dụng, không phải công cụ phân tích.
Câu 150

Your company has several applications running on GCP and on-premises. You need to create a hybrid cloud strategy to allow applications running on GCP to access data from your on-premises data center with low latency. What is the best strategy?

  1. A

    Use Cloud Storage to store a copy of your on-premises data and access it from your applications on GCP.

  2. B

    Use Cloud Interconnect to create a dedicated connection from your on-premises network to your VPC network on Google Cloud.

  3. C

    Use VPC Network Peering to connect the on-premises network to your VPC network on Google Cloud.

  4. D

    Use Cloud VPN to create an IPsec VPN tunnel from the on-premises network to your VPC network on Google Cloud.

Xem giải thích

Đáp án

B — Dùng Cloud Interconnect để có đường nối riêng từ trung tâm dữ liệu tới VPC

Vì sao đúng

Chiến lược lai cần đường nối ổn định, băng thông cao và riêng tư vì ứng dụng trên đám mây sẽ truy cập dữ liệu tại chỗ liên tục, không phải thỉnh thoảng. Interconnect cho đường vật lý riêng vào mạng Google với độ trễ đoán trước được, không phụ thuộc tình trạng Internet công cộng.

Vì sao các phương án khác sai

  • C. VPC Network Peering — chỉ nối được hai VPC trong Google Cloud với nhau; không dùng để nối mạng tại chỗ. Đây là bẫy chính của câu.
  • D. Cloud VPN — chạy được và rẻ hơn, nhưng độ trễ và băng thông biến động theo Internet; hợp làm đường dự phòng hoặc cho nhu cầu nhỏ.
  • A. Chép một bản dữ liệu sang Cloud Storage — dữ liệu luôn cũ và phải tự lo đồng bộ; không phải "truy cập dữ liệu tại chỗ".