Ngân hàng đề — Google Professional Cloud Architect
Tìm thấy 420 câu.
You are designing a cloud-based architecture for a company that requires a secure and scalable solution for its database. The database must be able to handle high volumes of transactions, and the data must be encrypted at rest and in transit. Which of the following options provides the best solution?
-
A
Use a hybrid approach with a self-managed database service and a third-party encryption tool.
-
B
Use a NoSQL database service with built-in encryption and automatic scaling.
-
C
Use a managed database service with automatic encryption and scale-up capability.
-
D
Use a self-managed database service with manual encryption and scale-out capability.
Xem giải thích
Đáp án
C — Dịch vụ CSDL được quản lý, có mã hoá tự động và mở rộng được
Vì sao đúng
Đề yêu cầu an toàn và co giãn, và dịch vụ được quản lý cho cả hai mà không tốn công: mã hoá khi lưu và khi truyền được bật sẵn, bản vá bảo mật do nhà cung cấp áp dụng, sao lưu tự động, và mở rộng chỉ là thay đổi cấu hình. Đội của bạn dồn sức vào lược đồ và truy vấn thay vì vào việc vận hành máy chủ CSDL.
Vì sao các phương án khác sai
- D. Tự quản lý với mã hoá làm thủ công — mã hoá thủ công là chỗ rất dễ sai, và bạn gánh toàn bộ việc vá lỗi.
- A. Kết hợp tự quản lý với công cụ mã hoá của bên thứ ba — thêm một nhà cung cấp và một điểm hỏng, mà vẫn phải tự vận hành CSDL.
- B. CSDL NoSQL — là lựa chọn hợp lệ cho nhiều bài toán, nhưng đề không nêu đặc điểm nào đòi NoSQL; chọn theo mô hình dữ liệu chứ không chọn vì nó có mã hoá.
A global e-commerce company is migrating its platform to Google Cloud. The platform will be deployed in multiple regions to ensure low latency and high availability for users worldwide. The company needs to design a network architecture that ensures secure, low-latency communication between services across regions. Additionally, the network should be resilient to regional failures and minimize costs related to inter-region traffic. The company also has compliance requirements that restrict certain types of data from leaving specific regions. Which network design approach should the company take to meet these requirements?
-
A
Use a shared VPC across all regions with global load balancing and enable VPC peering between regions to handle inter-region traffic.
-
B
Deploy separate VPCs in each region and use Cloud VPN to securely connect these VPCs, ensuring low-latency, secure communication between regions.
-
C
Set up a multi-region VPC using Google's global VPC capability, implement Private Google Access, and use Cloud Router with dynamic routing for managing inter-region traffic.
-
D
Create a regional VPC in the primary region, and use Cloud CDN to cache data in other regions, minimizing the need for inter-region traffic.
Xem giải thích
Đáp án
C — Dùng khả năng VPC toàn cầu của Google, kèm Private Google Access
Vì sao đúng
Điểm mấu chốt là VPC của Google Cloud vốn đã toàn cầu: một VPC duy nhất chứa subnet ở mọi khu vực, và các subnet nói chuyện với nhau bằng IP riêng qua mạng xương sống của Google — không cần peering, không cần đường hầm, và chỉ có một bộ luật tường lửa để quản lý. Private Google Access cho máy không có IP công khai vẫn gọi được API của Google qua đường nội bộ.
Vì sao các phương án khác sai
- B. Mỗi khu vực một VPC rồi nối bằng Cloud VPN — tự dựng lại thứ VPC toàn cầu đã cho sẵn, kèm chi phí và giới hạn băng thông của đường hầm.
- A — nhắc tới Shared VPC, vốn dùng để chia sẻ mạng giữa các dự án, không phải cơ chế nối các khu vực.
- D. Một VPC ở khu vực chính rồi dùng CDN — CDN nhớ đệm nội dung tĩnh, không thay được việc có hạ tầng ở khu vực gần người dùng.
Your company is migrating a critical payment-processing application to Google Cloud. The CTO wants to ensure that operations can scale without creating bottlenecks around a few experts and that incidents are detected and resolved quickly. As the cloud architect, which approach best aligns with the Operational Excellence pillar of the Google Cloud Well-Architected Framework?
-
A
Configure high-availability managed instance groups across multiple regions to minimize downtime.
-
B
Use the largest available machine types to avoid performance issues, and manually scale down during off-peak hours.
-
C
Enable VPC Service Controls and CMEK (Customer-Managed Encryption Keys) for all data stores to reduce security risks.
-
D
Implement Infrastructure as Code (IaC) with Terraform, use Cloud Build for CI/CD, define SLOs with Cloud Monitoring, and adopt blameless postmortems after incidents.
Xem giải thích
Đáp án
D — Hạ tầng dạng mã bằng Terraform, kèm Cloud Build cho CI/CD
Vì sao đúng
Đề nói rõ mối lo là nút thắt quanh khâu vận hành, chứ không phải quanh hiệu năng. Hạ tầng dạng mã gỡ đúng nút thắt đó: thay đổi hạ tầng trở thành mã được rà soát và tự động áp dụng, nên không phải chờ một người có quyền vào Console bấm tay. Cloud Build làm phần tự động hoá, khiến nhịp phát hành không phụ thuộc vào lịch của ai.
Vì sao các phương án khác sai
- A. Managed instance group ở nhiều khu vực — giải quyết tính sẵn sàng, không giải quyết nút thắt vận hành.
- B. Dùng máy lớn nhất rồi chỉnh tay — "chỉnh tay" chính là nút thắt mà đề muốn bỏ.
- C. VPC Service Controls và CMEK — biện pháp bảo mật đúng đắn cho hệ thống thanh toán, nhưng không trả lời câu hỏi về khả năng mở rộng vận hành.
A financial services company is planning to implement a high-performance computing solution on GCP to support its algorithmic trading operations. The company wants to ensure that the solution is scalable, low-latency, and able to handle a large volume of data. The company also wants to ensure that the solution is secure and that sensitive financial data is protected. Which of the following options would be the most effective approach to meet these requirements?
-
A
Use Cloud Functions to stream the data and Cloud Dataflow to process the data. Use BigQuery to store the data and Cloud IAM to control access to the data. Implement security using Cloud KMS.
-
B
Use Gogle Cloud Pub/Sub to stream the data and Cloud Dataflow to process the data. Use Cloud Bigtable to store the data and Cloud IAM to control access to the data. Implement security using Cloud KMS.
-
C
Use Cloud Pub/Sub to stream the data and Cloud Dataproc to process the data. Use BigQuery to store the data and Cloud IAM to control access to the data. Implement security using Cloud IAP.
-
D
Use Cloud Pub/Sub to stream the data and Cloud Dataproc to process the data. Use Cloud Bigtable to store the data and Cloud IAM to control access to the data. Implement security using Cloud IAP.
Xem giải thích
Đáp án
B — Pub/Sub để nhận luồng, Dataflow để xử lý, Bigtable để lưu, Cloud KMS cho phần mã hoá
Vì sao đúng
Bốn mảnh, mỗi mảnh có một phương án nhiễu tương ứng:
- Pub/Sub nhận luồng dữ liệu thị trường — chịu được tải bùng phát và không mất tin.
- Dataflow xử lý theo luồng, độ trễ thấp; đây là điểm phân biệt với Dataproc.
- Bigtable lưu dữ liệu chuỗi thời gian với độ trễ đọc ghi tính bằng mili giây; đây là điểm phân biệt với BigQuery, vốn là kho phân tích chứ không phục vụ truy vấn độ trễ thấp.
- Cloud KMS cho khoá mã hoá do bạn quản lý.
Vì sao các phương án khác sai
- A. Cloud Functions để nhận luồng — không kham nổi luồng dữ liệu thị trường tốc độ cao.
- C và D. Dataproc để xử lý — Dataproc là cụm Hadoop/Spark, mạnh cho xử lý theo lô nhưng không phải công cụ xử lý luồng độ trễ thấp. Cả hai còn dùng Cloud IAP cho phần bảo mật, mà IAP là proxy xác thực người dùng chứ không phải công cụ quản lý khoá mã hoá.
For this question, refer to the EHR Healthcare case study.
https://services.google.com/fh/files/misc/v6.1_pca_ehr_healthcare_case_study_english.pdf
EHR Healthcare wants to migrate a public-facing API that provides access to patient health data for authorized partners. The current API is hosted on an on-premises server and is experiencing latency issues and security concerns, particularly due to unauthorized access attempts. The company wants to move the API to Google Cloud and ensure robust security, including protection against IP spoofing and encryption of API responses. What should you do?
-
A
Migrate the API to Compute Engine instances, expose the API using an external HTTP(S) load balancer, and use a custom SSL certificate for encryption.
-
B
Deploy the API to App Engine Flexible Environment, enable Google Cloud Armor for security, and use built-in encryption in transit.
-
C
Deploy the API to Google Kubernetes Engine (GKE), expose the API using an external HTTP(S) load balancer, and configure Google Cloud Armor to block unauthorized IP addresses.
-
D
Use Cloud Functions to host the API, configure API Gateway to expose the API securely, and enforce encryption using Identity-Aware Proxy (IAP).
Xem giải thích
Đáp án
C — Triển khai API lên GKE và mở ra bằng load balancer ngoài
Vì sao đúng
EHR cần API phục vụ đối tác bên ngoài với khả năng co giãn và độ tin cậy cao. GKE cho co giãn ở cả mức pod lẫn mức node, tự thay thành phần hỏng, và triển khai cuốn chiếu không gián đoạn — quan trọng khi đối tác đang phụ thuộc vào API. Load balancer ngoài của Google hứng lưu lượng ở biên mạng toàn cầu và có sẵn TLS.
Vì sao các phương án khác sai
- A. Máy ảo với load balancer ngoài — chạy được nhưng phải tự lo ảnh máy, vá hệ điều hành và quy trình triển khai.
- B. App Engine Flexible — co giãn chậm hơn vì phải khởi động máy ảo bên dưới.
- D. Cloud Functions với API Gateway — hợp cho API nhỏ theo sự kiện; với API doanh nghiệp có logic phức tạp thì vướng giới hạn thời gian chạy và khó tổ chức mã.
You are a cloud architect for a company that has a multi-tier application running on GCP. The application includes a load balancer, several web servers, and a back-end database. As part of your security strategy, you want to allow HTTP(S) traffic only from the load balancer to the web servers. Which of the following would be the best approach?
-
A
Create a firewall rule with a high priority (low numeric value) to allow traffic from the load balancer, and a default rule to deny all other traffic.
-
B
Create two firewall rules with the same priority, one to allow traffic from the load balancer, and one to deny all other traffic.
-
C
Create a firewall rule with a high priority (low numeric value) to deny all traffic, and a rule with a low priority (high numeric value) to allow traffic from the load balancer.
-
D
Create a firewall rule with a low priority (high numeric value) to allow traffic from the load balancer, and a default rule to deny all other traffic.
Xem giải thích
Đáp án
A — Một luật ưu tiên cao (giá trị số thấp) cho phép lưu lượng từ load balancer, cộng luật mặc định chặn phần còn lại
Vì sao đúng
Hai điều cần nắm về tường lửa của Google Cloud:
- Số càng nhỏ thì ưu tiên càng cao — luật
1000thắng luật2000. - VPC đã có sẵn luật ngầm định chặn mọi lưu lượng đi vào ở mức ưu tiên thấp nhất.
Vì vậy chỉ cần một luật cho phép ở ưu tiên cao, cho đúng nguồn là load balancer; mọi thứ khác tự động bị luật ngầm định chặn. Đây là mô hình "chặn mặc định, mở có chọn lọc".
Vì sao các phương án khác sai
- C. Đặt luật chặn ở ưu tiên cao và luật cho phép ở ưu tiên thấp — luật chặn thắng, nên load balancer cũng không vào được; web server thành không truy cập được.
- D. Luật cho phép ở ưu tiên thấp — chạy được nhờ luật ngầm định, nhưng bất kỳ luật chặn nào thêm vào sau ở ưu tiên cao hơn cũng vô hiệu hoá nó; thiết kế mong manh.
- B. Hai luật cùng mức ưu tiên — khi trùng ưu tiên, luật chặn thắng, nên lưu lượng từ load balancer cũng bị chặn.
You are a cloud architect working for a fintech company that wants to deploy a critical, containerized application in a microservices architecture. The application needs to support high levels of incoming traffic with low latency, ensure zero-downtime deployments, allow for automatic scaling based on CPU utilization, and maintain end-to-end encryption. Which of the following deployment methods should you choose for this scenario?
-
A
Deploy the application on Google Kubernetes Engine (GKE) with an HTTPS load balancer.
-
B
Deploy the application on App Engine Standard environment.
-
C
Deploy the application on App Engine Flexible environment.
-
D
Deploy the application on Compute Engine instances behind a load balancer.
Xem giải thích
Đáp án
A — Triển khai lên GKE với HTTPS load balancer
Vì sao đúng
Ứng dụng đã được đóng gói container theo kiến trúc microservice thì GKE là nền tảng khớp nhất: nó điều phối nhiều dịch vụ có phụ thuộc lẫn nhau, co giãn từng dịch vụ độc lập, triển khai cuốn chiếu và quay lui nhanh. HTTPS load balancer lo phần kết thúc TLS và phân phối lưu lượng toàn cầu — với công ty fintech thì mã hoá trên đường truyền là bắt buộc.
Vì sao các phương án khác sai
- B. App Engine Standard — ràng buộc về môi trường chạy, và không cho kiểm soát mức container mà kiến trúc này cần.
- C. App Engine Flexible — chạy container được nhưng kém linh hoạt hơn hẳn khi điều phối nhiều dịch vụ.
- D. Máy ảo sau load balancer — bỏ đi mọi lợi ích của việc đã container hoá, và gánh nặng vận hành lớn nhất.
Your organization operates a large-scale web application on Google Cloud, and you need to design a solution to analyze logs from the application in near real-time to detect any potential issues or anomalies. You also want to do some transformation of log data before storing. Which of the following approaches should you recommend?
-
A
Store logs in Cloud Storage, then use Cloud Dataflow to move them to BigQuery for analysis.
-
B
Stream logs directly from the application to BigQuery.
-
C
Use Cloud Functions to process each log entry and send it to BigQuery.
-
D
Use Cloud Pub/Sub to ingest logs, Cloud Dataflow to transform, and then BigQuery to analyze.
Xem giải thích
Đáp án
D — Pub/Sub để nạp log, Dataflow để chuyển đổi, BigQuery để phân tích
Vì sao đúng
Yêu cầu là phân tích gần thời gian thực ở quy mô lớn. Ba tầng lo ba việc: Pub/Sub hấp thụ luồng log kể cả khi tải bùng phát và không mất bản ghi; Dataflow làm phần lọc, làm giàu và tổng hợp trên luồng, có cửa sổ thời gian và xử lý được dữ liệu tới muộn; BigQuery cho truy vấn ngay khi dữ liệu vừa vào.
Vì sao các phương án khác sai
- A. Qua Cloud Storage rồi mới xử lý — thêm một chặng lưu trữ trung gian, biến luồng thành xử lý theo lô nên mất tính thời gian thực.
- B. Đẩy thẳng log từ ứng dụng vào BigQuery — không có chỗ đệm, nên khi tải tăng đột ngột thì ứng dụng bị chặn hoặc log bị mất; cũng không có chỗ để chuyển đổi.
- C. Cloud Functions xử lý từng dòng log — chi phí gọi hàm ở quy mô log của ứng dụng lớn là không khả thi.
Your company needs to process large batches of transactional data every night. The processing involves complex calculations that must be completed before the start of the business day. This workload is highly parallelizable but requires significant compute power to ensure it completes within a specific time window. Cost-efficiency is also a key consideration, as this batch processing occurs daily. You need to select the most appropriate compute resources on Google Cloud for this workload. Which of the following options would best meet the needs of the batch processing system?
-
A
Use Compute Engine with high-memory machine types and SSD persistent disks to handle the processing within the required time window.
-
B
Use Google Kubernetes Engine (GKE) with preemptible VMs and set up a cron job to start the processing at night.
-
C
Use Google Cloud Dataproc with preemptible VMs for running a Hadoop or Spark cluster, and schedule jobs using Cloud Scheduler.
-
D
Use Compute Engine with standard machine types and set up a managed instance group with auto-scaling based on CPU utilization.
Xem giải thích
Đáp án
C — Dùng Cloud Dataproc với máy preemptible để chạy cụm Hadoop hoặc Spark
Vì sao đúng
Công việc theo lô hằng đêm có hai đặc điểm khiến máy preemptible hợp lý: nó chạy trong một cửa sổ thời gian xác định, và framework Hadoop/Spark tự chạy lại phần việc của node bị mất. Nhờ vậy máy bị thu hồi chỉ làm công việc chậm đi chút ít chứ không hỏng. Đổi lại là mức giảm giá rất lớn so với máy thường.
Cách làm thận trọng thường thấy: giữ các node chính là máy thường, còn phần lớn node công nhân dùng preemptible.
Vì sao các phương án khác sai
- A. Máy ảo bộ nhớ lớn với đĩa SSD — chạy được nhưng phải tự dựng và tự vận hành framework xử lý, và trả giá cao nhất.
- B. GKE với cron job — làm được, nhưng bạn tự lo phần chia việc và chịu lỗi mà Spark đã có sẵn.
- D. Máy ảo tiêu chuẩn trong managed instance group — cùng vấn đề: không có framework xử lý phân tán nào bên dưới.
Your organization is building a data-intensive application on Google Cloud that will process large volumes of data daily. The application performs batch processing and requires high throughput and low latency for both read and write operations. The processed data needs to be stored for long-term analysis and must be readily available for periodic querying. You are tasked with designing the storage solution for this application. Which of the following storage options would best meet the application's requirements?
-
A
Use Cloud Storage with Standard Storage Class for both processed and raw data.
-
B
Use Filestore for storing all raw and processed data to take advantage of shared file storage.
-
C
Use Persistent Disks with SSD for Compute Engine instances to handle batch processing and store processed data in BigQuery.
-
D
Use Cloud Bigtable for raw data and Cloud SQL for processed data.
Xem giải thích
Đáp án
C — Đĩa bền SSD gắn vào máy Compute Engine cho phần xử lý theo lô
Vì sao đúng
Xử lý theo lô trên khối lượng dữ liệu lớn tạo ra rất nhiều thao tác đọc ghi ngẫu nhiên — đọc dữ liệu trung gian, ghi kết quả tạm, sắp xếp và trộn. Đó chính là chỗ SSD hơn hẳn đĩa thường, vì thứ quyết định ở đây là IOPS chứ không phải thông lượng tuần tự. Đĩa bền còn giữ dữ liệu qua các lần khởi động lại, khác với local SSD.
Vì sao các phương án khác sai
- A. Cloud Storage lớp Standard cho mọi thứ — hợp làm kho dữ liệu nguồn và đích, nhưng không phải nơi ghi dữ liệu trung gian của công việc đang chạy: độ trễ cao hơn hệ tệp cục bộ nhiều.
- B. Filestore cho tất cả — hệ tệp chia sẻ qua mạng, đắt và chậm hơn đĩa gắn trực tiếp khi chỉ một máy dùng.
- D. Bigtable cho dữ liệu thô và Cloud SQL cho dữ liệu đã xử lý — hai CSDL cho thứ vốn là tệp; sai loại công cụ.