Ngân hàng đề — Google Professional Cloud Architect

Tìm thấy 420 câu.

Câu 161

As a cloud architect, you are working on a complex scenario where you have to deploy a monitoring pod in a DaemonSet object across a GKE cluster for a client's application. You want the monitoring pod to be deployed on every node of the GKE cluster. Which approach will allow you to efficiently achieve this objective?

  1. A

    Deploy the monitoring pod using a DaemonSet across the nodes in the GKE cluster.

  2. B

    Deploy the monitoring pod as a ReplicaSet across the nodes in the GKE cluster.

  3. C

    Deploy the monitoring pod using a StatefulSet across the nodes in the GKE cluster.

  4. D

    Deploy the monitoring pod individually on each node in the GKE cluster.

Xem giải thích

Đáp án

A — Triển khai pod giám sát bằng DaemonSet

Vì sao đúng

DaemonSet đảm bảo mỗi node có đúng một bản của pod, và quan trọng hơn: node mới thêm vào cụm thì pod tự được tạo trên đó, node bị gỡ thì pod tự biến mất. Với tác nhân giám sát hay thu thập log — thứ phải có mặt ở mọi node — đây là đối tượng được sinh ra đúng cho mục đích đó.

Vì sao các phương án khác sai

  • B. ReplicaSet — chỉ đảm bảo tổng số bản sao, không đảm bảo phân bố mỗi node một bản; có thể hai bản dồn vào một node và node khác không có bản nào.
  • C. StatefulSet — dựng cho ứng dụng có trạng thái cần danh tính và lưu trữ ổn định; tác nhân giám sát không cần điều đó.
  • D. Triển khai tay từng node — không tự động theo khi cụm co giãn, và đó chính là việc mà DaemonSet sinh ra để thay thế.
Câu 162

Your company, XYZ Corp, is planning to migrate its on-premises applications to Google Cloud. These applications include a critical database running on a legacy Oracle system that must remain on-premises due to compliance requirements. The migration plan needs to ensure minimal disruption and maintain low-latency access to the database from the cloud applications. The solution should also provide high availability and scalability for the migrated applications. Which architectural approach would best address XYZ Corp's requirements while integrating the on-premises Oracle database with the cloud applications?

  1. A

    Migrate the applications to Google App Engine and use a multi-cloud strategy to connect to the Oracle database through a third-party API management platform.

  2. B

    Deploy the applications on Google Kubernetes Engine (GKE) and use Google Cloud Interconnect to establish a direct peering connection with the on-premises Oracle database.

  3. C

    Migrate the applications to Google Compute Engine instances and use Cloud VPN to establish a secure connection to the on-premises Oracle database.

  4. D

    Refactor the applications to use Google Cloud SQL and create a custom API gateway to interact with the on-premises Oracle database.

Xem giải thích

Đáp án

B — Triển khai ứng dụng lên GKE và dùng dịch vụ được quản lý của Google Cloud

Vì sao đúng

Đề có một hệ CSDL Oracle cũ cộng nhiều ứng dụng. GKE cho tầng ứng dụng khả năng co giãn, tự chữa lành và triển khai không gián đoạn, đồng thời cho một cách vận hành thống nhất thay vì mỗi ứng dụng một kiểu. Phần còn lại dựa vào dịch vụ được quản lý để giảm gánh nặng vận hành xuống mức thấp nhất có thể.

Vì sao các phương án khác sai

  • A. App Engine với chiến lược đa đám mây — thêm hẳn một nền tảng nữa phải vận hành, làm phức tạp thay vì đơn giản hoá.
  • C. Máy ảo nối bằng Cloud VPN — chạy được nhưng giữ nguyên gánh nặng vận hành ở mức máy ảo, không cải thiện gì về co giãn.
  • D. Viết lại để dùng Cloud SQL — Cloud SQL không hỗ trợ Oracle, nên phần CSDL lõi không chuyển sang đó được nếu không viết lại rất lớn.
Câu 163

You are tasked with designing a scalable and highly available platform for processing financial transactions. The platform must handle sudden traffic spikes during peak hours, ensure data consistency, and provide fault tolerance. Which of the following architectures best meets these requirements?

  1. A

    Set up App Engine with Datastore for transactional data, using eventual consistency.

  2. B

    Deploy multiple Compute Engine instances behind a global HTTP(S) Load Balancer and use Cloud SQL with a read replica.

  3. C

    Implement a Kubernetes Engine (GKE) cluster with auto-scaling and a Cloud Spanner database.

  4. D

    Use Cloud Functions triggered by Pub/Sub messages, with Cloud Storage for storing transactional data.

Xem giải thích

Đáp án

C — Cụm GKE có tự co giãn, kết hợp Cloud Spanner

Vì sao đúng

Xử lý giao dịch tài chính có hai yêu cầu, và phương án này lo cả hai đúng chỗ:

  • GKE có tự co giãn cho tầng ứng dụng hấp thụ các đợt tăng tải đột ngột.
  • Cloud Spanner cho tầng dữ liệu vừa mở rộng theo chiều ngang vừa giữ giao dịch ACID và nhất quán mạnh — với tiền bạc thì đọc ra số liệu cũ là không chấp nhận được.

Vì sao các phương án khác sai

  • A. App Engine với Datastore, chấp nhận nhất quán cuối cùng — nhất quán cuối cùng nghĩa là một giao dịch vừa ghi có thể chưa thấy ngay; sai với dữ liệu tài chính.
  • B. Máy ảo sau load balancer toàn cầu — giải quyết tầng ứng dụng nhưng bỏ ngỏ tầng dữ liệu.
  • D. Cloud Functions với Cloud Storage — Cloud Storage không phải CSDL giao dịch, không có khoá hay tính nguyên tử.
Câu 164

For this question, refer to the Altostrat Media case study.

https://services.google.com/fh/files/misc/v6.1_pca_altostrat_media_case_study_english.pdf


Altostrat plans to deploy a generative AI–powered recommendation and conversational assistant that suggests audio and video content based on user behavior stored in BigQuery. Due to increasing regulatory scrutiny and internal governance requirements, Altostrat’s leadership mandates that all AI-driven recommendations must be auditable, explainable, and traceable to the underlying data and model versions. Data scientists also need the ability to analyze why specific recommendations were generated for individual users without significantly increasing operational overhead. Which architecture best ensures that generative AI recommendations are auditable and explainable while aligning with best practices?

  1. A

    Use Vertex AI models with Model Registry, enable prediction logging to BigQuery, and integrate with Vertex AI Explainable AI features.

  2. B

    Deploy third-party generative AI APIs and rely on vendor-provided transparency reports for audit purposes.

  3. C

    Deploy a custom large language model on GKE and store inference logs as application logs in Cloud Logging only.

  4. D

    Use Cloud Run–based inference endpoints and store user prompts and responses in Cloud Storage for later analysis.

Xem giải thích

Đáp án

A — Dùng mô hình Vertex AI với Model Registry, bật ghi log dự đoán sang BigQuery

Vì sao đúng

Đề hướng tới tính minh bạch và khả năng kiểm toán của hệ thống AI, và hai công cụ này lo đúng hai vế:

  • Model Registry — quản lý phiên bản mô hình: bản nào đang phục vụ, được huấn luyện từ dữ liệu nào, ai duyệt. Không có nó thì không trả lời được câu hỏi "hồi tháng trước mô hình nào đã đưa ra quyết định này".
  • Ghi log dự đoán sang BigQuery — lưu lại đầu vào và đầu ra để truy vết, phát hiện trôi dữ liệu, và phân tích khi có khiếu nại.

Vì sao các phương án khác sai

  • B. Dựa vào báo cáo minh bạch của nhà cung cấp bên thứ ba — bạn không kiểm soát được và cũng không kiểm toán được.
  • C. Tự chạy mô hình trên GKE, log dạng log ứng dụng — log ứng dụng không có cấu trúc để phân tích, và thiếu hẳn phần quản lý phiên bản mô hình.
  • D. Điểm cuối trên Cloud Run, lưu prompt và phản hồi — có phần log nhưng vẫn thiếu quản lý phiên bản mô hình.
Câu 165

Your organization is planning to migrate a legacy Enterprise Resource Planning (ERP) system from a private data center to Google Cloud. The system consists of multiple components: a monolithic application server written in C++, a legacy Oracle database, and a batch processing component that generates reports based on large datasets stored on a network-attached storage (NAS) system. The migration plan needs to minimize downtime, ensure data integrity, and modernize the infrastructure to support future enhancements. Which migration strategy should you recommend to ensure a successful migration while minimizing downtime and supporting future modernization?

  1. A

    Rehost the application server on Google Compute Engine, migrate the Oracle database to Bare Metal Solution, and use Google Cloud Storage with Dataproc for batch processing and report generation.

  2. B

    Rehost the entire ERP system on Google Compute Engine, using Persistent Disks for storage, and migrate the Oracle database to a managed instance on Cloud SQL.

  3. C

    Refactor the application server to use Google App Engine, migrate the Oracle database to BigQuery, and use Filestore as a replacement for the NAS system.

  4. D

    Replatform the application server to Google Kubernetes Engine (GKE) using Docker containers, migrate the Oracle database to Cloud Spanner, and use Google Cloud Storage to replace NAS.

Xem giải thích

Đáp án

A — Rehost máy chủ ứng dụng lên Compute Engine, chuyển CSDL Oracle sang nền tảng phù hợp

Vì sao đúng

Hệ ERP cũ gồm nhiều thành phần gắn chặt nhau, và cách chuyển ít rủi ro nhất là rehost — giữ nguyên ứng dụng, chỉ đổi nơi chạy. Máy chủ ứng dụng lên máy ảo là ánh xạ gần như một–một, còn CSDL Oracle được xử lý riêng vì nó có ràng buộc về giấy phép và hiệu năng mà tầng ứng dụng không có. Hiện đại hoá để sau, khi hệ thống đã chạy ổn trên nền mới.

Vì sao các phương án khác sai

  • C. Viết lại máy chủ ứng dụng cho App Engine — refactor một hệ ERP cũ là dự án rất lớn và rủi ro cao, thường không cần ở giai đoạn đầu.
  • D. Chuyển sang GKE bằng cách đóng gói Docker — ứng dụng doanh nghiệp cũ thường không đóng gói container gọn được nếu chưa tách phụ thuộc.
  • B. Rehost toàn bộ kể cả CSDL lên máy ảo với đĩa bền — bỏ qua các ràng buộc riêng của Oracle về giấy phép và hiệu năng lưu trữ.
Câu 166

As a cloud architect, you are working with a media company to develop a web application for live streaming events. The application needs to handle high incoming traffic during popular events. It's also important for the company to keep costs as low as possible when there are no live events (low traffic). Which environment of App Engine should you choose for this scenario?

  1. A

    App Engine Flexible environment, because it can scale to zero instances when there's no traffic.

  2. B

    App Engine Standard environment, because it can scale to zero instances when there's no traffic.

  3. C

    Both environments would suit this application equally well.

  4. D

    App Engine Flexible environment, because it supports third-party software.

Xem giải thích

Đáp án

B — App Engine Standard, vì nó co được về 0 bản chạy khi không có lưu lượng

Vì sao đúng

Đây là khác biệt cốt lõi giữa hai môi trường của App Engine:

Standard Flexible
Co về 0 khi rảnh Có Không, luôn giữ ít nhất một bản
Tốc độ co giãn Rất nhanh (giây) Chậm hơn, phải khởi động máy ảo
Trả tiền lúc rảnh Không Có

Ứng dụng phát trực tiếp sự kiện có lưu lượng rất cao lúc có sự kiện và gần bằng không giữa các sự kiện — đúng hình dạng mà Standard tiết kiệm nhất, và cũng là môi trường co giãn nhanh nhất khi sự kiện bắt đầu.

Vì sao các phương án khác sai

  • A. Flexible vì co được về 0 — sai về sự thật: Flexible không co về 0.
  • D. Flexible vì hỗ trợ phần mềm bên thứ ba — đúng là ưu điểm của Flexible, nhưng đề không nêu nhu cầu nào cần tới nó.
  • C. Hai môi trường như nhau — chúng khác nhau rõ rệt ở đúng điểm mà đề quan tâm.
Câu 167

Your company is migrating a legacy on-premise monolithic application to Google Cloud. The application must be split into services to improve scalability and maintainability. However, the team has limited experience with container orchestration. You must choose a platform that provides built-in service discovery, load balancing, automated rollout and rollback, and autoscaling, while minimizing the operational overhead. What is the most appropriate GCP service to host the refactored application?

  1. A

    Compute Engine with managed instance groups

  2. B

    App Engine Flexible Environment

  3. C

    Cloud Run

  4. D

    Google Kubernetes Engine (GKE)

Xem giải thích

Đáp án

C — Cloud Run

Vì sao đúng

Đề nói tách khối nguyên thành các dịch vụ nhỏ để dễ co giãn và dễ bảo trì. Cloud Run cho từng dịch vụ triển khai và co giãn độc lập, co về 0 khi rảnh, và quan trọng nhất là không có cụm nào phải vận hành — đội vừa mới tách microservice không phải học thêm cả Kubernetes cùng lúc. Dịch vụ vẫn là container nên về sau chuyển sang GKE cũng không phải đóng gói lại.

Vì sao các phương án khác sai

  • D. GKE — mạnh hơn và linh hoạt hơn, nhưng kèm gánh nặng vận hành cụm; chỉ đáng khi thật sự cần điều phối phức tạp, dịch vụ chạy nền lâu hoặc kiểm soát mạng chi tiết.
  • B. App Engine Flexible — không co về 0 và co giãn chậm hơn.
  • A. Máy ảo với managed instance group — quản lý ở mức máy ảo, nhiều việc vận hành nhất và không tận dụng được việc đã tách thành dịch vụ nhỏ.
Câu 168

Your organization uses BigQuery extensively for data analysis and you are developing a new solution to automate some recurring tasks. As part of this solution, you need to create a new table in BigQuery and load data into it from a CSV file in Cloud Storage, all from a Compute Engine instance. What would be the correct approach?

  1. A

    Use the gsutil command to create the table in BigQuery and then the bq command-line tool to load the data.

  2. B

    Use the bq command-line tool to create the table and then the gsutil cp command to copy the data from Cloud Storage to BigQuery.

  3. C

    Use the gcloud command-line tool to create the table and load the data into BigQuery.

  4. D

    Use the bq command-line tool to both create the table and load the data from Cloud Storage.

Xem giải thích

Đáp án

D — Dùng công cụ dòng lệnh bq cho cả việc tạo bảng lẫn nạp dữ liệu từ Cloud Storage

Vì sao đúng

bq là công cụ dòng lệnh của riêng BigQuery, và nó làm được cả hai việc trong đề: bq mk tạo bảng, bq load nạp dữ liệu thẳng từ Cloud Storage vào bảng đó. Chỉ cần một công cụ cho toàn bộ quy trình, nên script tự động hoá cũng gọn.

Vì sao các phương án khác sai

  • A và B. Trộn gsutil với bq — gsutil là công cụ của Cloud Storage, dùng để sao chép tệp giữa máy và bucket. Nó không tạo bảng BigQuery và cũng không nạp dữ liệu vào BigQuery được; gsutil cp chỉ chép tệp từ chỗ này sang chỗ khác trong kho đối tượng.
  • C. Dùng gcloud — là công cụ quản trị chung cho Google Cloud, nhưng các thao tác dữ liệu của BigQuery nằm ở bq chứ không nằm ở gcloud.
Câu 169

You are a cloud architect and have been assigned a task to develop a model that will predict the type of product a customer is most likely to purchase next, based on their past purchases and behavior. The client has a massive amount of historic data available but lacks machine learning expertise. Furthermore, the solution needs to be able to constantly learn from new data. Which of the following would be the best approach for this situation?

  1. A

    Use BigQuery ML, retrain the model manually with new data.

  2. B

    Use AutoML Tables, retrain the model periodically with new data.

  3. C

    Use Cloud Machine Learning Engine with TensorFlow and retrain the model manually with new data.

  4. D

    Use AutoML Vision, retrain the model periodically with new data.

Xem giải thích

Đáp án

B — Dùng AutoML Tables, huấn luyện lại định kỳ với dữ liệu mới

Vì sao đúng

Hai vế phải khớp cùng lúc:

  • AutoML Tables — dữ liệu đầu vào là lịch sử mua hàng, tức là dữ liệu dạng bảng. AutoML tự chọn kiến trúc mô hình và tự tinh chỉnh siêu tham số, nên đội không cần chuyên gia học máy.
  • Huấn luyện lại định kỳ — hành vi mua sắm thay đổi theo mùa và theo xu hướng, nên mô hình không cập nhật sẽ kém dần. Tự động hoá việc này quan trọng hơn là làm tay.

Vì sao các phương án khác sai

  • D. AutoML Vision — dành cho ảnh, sai hẳn loại dữ liệu.
  • A. BigQuery ML, huấn luyện lại thủ công — BigQuery ML là lựa chọn hợp lý, nhưng "thủ công" là điểm hỏng: sớm muộn cũng có người quên.
  • C. Cloud ML Engine với TensorFlow, huấn luyện lại thủ công — vừa đòi kỹ năng cao hơn hẳn, vừa vướng cùng vấn đề làm tay.
Câu 170

Your company is deploying a highly available, global web application on Google Cloud. The application needs to serve users from multiple regions with low latency and must be able to scale automatically based on traffic. The application stack consists of containerized microservices that communicate with each other via HTTP. The team has decided to use Google Kubernetes Engine (GKE) for orchestration, and you need to choose the appropriate compute resources for the worker nodes. Which of the following options would be the most appropriate choice for the GKE nodes to ensure high availability, cost-efficiency, and scalability?

  1. A

    Deploy GKE clusters with regional managed instance groups using custom machine types with optimized CPU and memory settings based on the workload.

  2. B

    Use preemptible VMs for the GKE nodes in all regions.

  3. C

    Use standard machine types in a single region with auto-scaling enabled.

  4. D

    Use sole-tenant nodes to run GKE clusters for better isolation and performance.

Xem giải thích

Đáp án

A — Cụm GKE với managed instance group theo vùng, dùng custom machine type

Vì sao đúng

Đề đòi sẵn sàng cao, phục vụ nhiều khu vực, độ trễ thấp. Managed instance group theo vùng (regional) trải node qua nhiều zone trong khu vực, nên mất một zone không làm sập cụm. Custom machine type cho khai đúng tỉ lệ CPU và bộ nhớ mà ứng dụng cần, tránh trả tiền cho phần thừa của các loại máy dựng sẵn.

Vì sao các phương án khác sai

  • B. Dùng máy preemptible cho mọi node — máy bị thu hồi bất cứ lúc nào; với ứng dụng web đòi sẵn sàng cao thì đây là lựa chọn sai về bản chất.
  • C. Một khu vực duy nhất có tự co giãn — không phục vụ được người dùng nhiều khu vực với độ trễ thấp, và mất khu vực đó là mất tất cả.
  • D. Sole-tenant node — dùng khi có ràng buộc về giấy phép hoặc yêu cầu cách ly phần cứng; đề không nêu nhu cầu nào như vậy, mà nó lại đắt và kém linh hoạt hơn.