Ngân hàng đề — Google Professional Cloud Architect
Tìm thấy 420 câu.
As a cloud architect, you are assisting a global organization in migrating its petabyte-scale on-premises data to Google Cloud. The organization has an extremely slow internet connection, strict compliance and security standards, and cannot tolerate any downtime during working hours. The migration should be completed as quickly as possible without interrupting business operations. Which of the following strategies would you recommend?
-
A
Use
gsutilcommand-line tool to upload data to Cloud Storage. -
B
Use Transfer Appliance to ship data to Google Cloud.
-
C
Use Cloud Dataflow to process and migrate data.
-
D
Use Storage Transfer Service for online transfer.
Xem giải thích
Đáp án
B — Dùng Transfer Appliance để chuyển dữ liệu bằng thiết bị vật lý
Vì sao đúng
Hai dữ kiện của đề khoá chặt đáp án: dữ liệu ở mức petabyte, và đường Internet rất chậm. Ở tình huống đó, chuyển qua mạng mất hàng tháng tới hàng năm. Transfer Appliance là thiết bị lưu trữ được gửi tới trung tâm dữ liệu của bạn: chép dữ liệu vào, gửi trả Google, họ nạp lên Cloud Storage. Dữ liệu được mã hoá suốt quá trình.
Vì sao các phương án khác sai
- A.
gsutil— công cụ dòng lệnh cho vài gigabyte tới vài terabyte, và vẫn đi qua chính đường mạng đang là nút thắt. - D. Storage Transfer Service — dịch vụ chuyển trực tuyến, hợp khi băng thông dư dả hoặc nguồn đã nằm trên một đám mây khác; ở đây vẫn vướng đúng nút thắt.
- C. Dataflow — công cụ xử lý dữ liệu, không phải công cụ vận chuyển dữ liệu lớn.
A mobile gaming company decided to migrate its analytics to BigQuery. Their analytics team needs access to perform queries against the data in BigQuery to improve user acquisition expenses for marketing campaigns. This analytics team members may change frequently. With Google best practices in mind, how do you grant access?
-
A
You should create a Cloud Identity account for each analyst. Then, grant BigQuery Data Owner role to each account.
-
B
You should create a Cloud Identity account for each analyst and add them all to a group. Then, grant BigQuery Data Viewer role to this group.
-
C
You should create a Cloud Identity account for each analyst and add them all to a group. Then, grant BigQuery Data Owner role to this group.
-
D
You should create a Cloud Identity account for each analyst. Then, grant BigQuery Data Viewer role to each account.
Xem giải thích
Đáp án
B — Tạo tài khoản Cloud Identity cho từng người, gom vào một nhóm, rồi cấp vai BigQuery Data Viewer cho nhóm
Vì sao đúng
Hai quyết định độc lập, và đề gợi ý cả hai:
- Cấp quyền cho nhóm chứ không cho từng người — đề nói rõ thành viên thay đổi thường xuyên. Có người mới thì thêm vào nhóm, người nghỉ thì bỏ ra; không phải sửa chính sách IAM lần nào.
- Vai Data Viewer chứ không phải Data Owner — đội phân tích chỉ cần chạy truy vấn, tức là quyền đọc. Data Owner cho phép sửa và xoá dữ liệu, vượt xa nhu cầu.
Vì sao các phương án khác sai
- C. Nhóm nhưng cấp Data Owner — đúng phần quản lý, sai phần quyền: cả đội có quyền xoá dữ liệu.
- A và D. Cấp cho từng tài khoản — gánh nặng quản trị tăng theo số người, và rất dễ quên thu hồi khi ai đó rời đội. Riêng A còn cấp cả quyền Data Owner.
A media streaming company is migrating its services to Google Cloud. The company's platform requires high bandwidth and low latency to ensure smooth video streaming for millions of users. The infrastructure needs to scale automatically based on demand, and security is a top priority to protect user data. The company plans to deploy its services across multiple regions, utilizing a mix of virtual machines, containers, and serverless functions. You are tasked with designing the network architecture to meet these requirements. Which of the following approaches would best address the company's needs for a secure, scalable, and high-performance network?
-
A
Deploy multiple VPCs, one for each region, and connect them using VPC Peering. Use Google Cloud Load Balancing to distribute traffic across regions and set up firewall rules to deny all inbound traffic except from specific IP ranges.
-
B
Create a single VPC with default subnets in each region, and rely on Google Cloud’s default network security settings for firewall rules and routing to minimize configuration overhead.
-
C
Utilize Shared VPC to centralize network management, with each service running in its own project. Configure Private Google Access for all resources and implement Identity-Aware Proxy (IAP) to secure access to the services.
-
D
Create a single VPC spanning multiple regions with custom subnets for each region. Implement Cloud NAT for outbound internet traffic and set up firewall rules to allow only necessary traffic.
Xem giải thích
Đáp án
D — Một VPC duy nhất trải nhiều khu vực, mỗi khu vực một subnet tuỳ chỉnh
Vì sao đúng
VPC của Google Cloud vốn đã toàn cầu — đây là khác biệt lớn so với các đám mây khác. Một VPC chứa subnet ở mọi khu vực, và các subnet nói chuyện với nhau bằng IP riêng qua mạng xương sống của Google: băng thông cao, độ trễ thấp, không cần peering hay đường hầm, và chỉ có một bộ luật tường lửa để quản lý. Với nền tảng phát video thì đó đúng là thứ cần.
Vì sao các phương án khác sai
- A. Mỗi khu vực một VPC rồi peering — tự dựng lại thứ đã có sẵn, và peering không bắc cầu nên càng thêm khu vực càng rối.
- B. Dùng subnet mặc định — chạy được nhưng dải địa chỉ do Google định sẵn, mất quyền quy hoạch mạng.
- C. Shared VPC — công cụ để chia sẻ mạng giữa các dự án, không phải cơ chế nối các khu vực; đề không nêu nhu cầu nhiều dự án.
Your company has several Looker Studio dashboards backed by BigQuery datasets. Some dashboards are refreshed every hour using scheduled queries. After reviewing billing reports, you notice high query costs despite relatively static data. You are asked to reduce ongoing costs without impacting dashboard freshness or user access. What should you do?
-
A
Upgrade to BigQuery BI Engine and enable streaming mode
-
B
Cache dashboard queries in BigQuery using
ALLOW_RESULT_CACHE -
C
Convert scheduled queries into materialized views and reference them in dashboards
-
D
Disable scheduled queries and require manual refresh during business hours
Xem giải thích
Đáp án
C — Chuyển scheduled query thành materialized view và trỏ dashboard vào đó
Vì sao đúng
Vấn đề là scheduled query tính lại toàn bộ mỗi giờ, kể cả khi dữ liệu nguồn chỉ đổi một phần nhỏ. Materialized view khác ở chỗ nó tự cập nhật theo phần tăng thêm: chỉ phần dữ liệu mới được xử lý, nên lượng dữ liệu quét giảm mạnh và hoá đơn giảm theo. Dashboard vẫn thấy dữ liệu mới mà không phải chờ mẻ chạy tiếp theo.
Vì sao các phương án khác sai
- A. BI Engine với chế độ streaming — BI Engine tăng tốc truy vấn bằng bộ nhớ đệm, nhưng là thêm chi phí, không cắt được phần tính toán lặp lại.
- B. Dựa vào bộ nhớ đệm kết quả — bộ đệm của BigQuery chỉ dùng lại được khi truy vấn y hệt và dữ liệu nguồn chưa đổi; dashboard có bộ lọc thay đổi nên gần như không bao giờ trúng đệm.
- D. Tắt scheduled query, làm mới bằng tay — giảm chi phí bằng cách giảm giá trị sử dụng.
For this question, refer to the Altostrat Media case study.
https://services.google.com/fh/files/misc/v6.1_pca_altostrat_media_case_study_english.pdf
Altostrat plans to introduce frequent feature releases for personalized recommendations and dynamic pricing models. They want to reduce deployment risk by using progressive delivery techniques such as canary and staged rollouts across multiple GKE environments (dev, staging, production).
The platform team also wants centralized visibility into release status and the ability to roll back deployments automatically if issues are detected. Which solution best supports these requirements while aligning with architectural best practices?
-
A
Implement custom rollout logic using Cloud Functions triggered after Cloud Build completes
-
B
Perform blue/green deployments manually by duplicating GKE clusters for each release
-
C
Rely on Kubernetes rolling updates without a centralized deployment orchestration service
-
D
Use Cloud Deploy with defined delivery pipelines and targets for each GKE environment
Xem giải thích
Đáp án
D — Dùng Cloud Deploy với delivery pipeline và target cho từng môi trường GKE
Vì sao đúng
Cloud Deploy là dịch vụ được quản lý cho phát hành liên tục: bạn khai một đường ống với các chặng (dev → staging → prod), mỗi chặng là một target GKE, kèm điểm phê duyệt và khả năng quay lui. Nhờ vậy việc phát hành ra nhiều môi trường trở thành quy trình có ghi vết và lặp lại được, thay vì phụ thuộc script tự viết.
Vì sao các phương án khác sai
- A. Tự viết logic phát hành bằng Cloud Functions — tự dựng lại thứ đã có dịch vụ làm sẵn, và phần khó nhất (quay lui, phê duyệt, theo dõi trạng thái) là chỗ script tự viết hay thiếu.
- B. Blue/green thủ công bằng cách nhân đôi cụm — tốn gấp đôi tài nguyên và cần thao tác tay mỗi lần.
- C. Chỉ dựa vào rolling update, không có bộ điều phối tập trung — mỗi môi trường một kiểu, và không có cái nhìn chung về việc phiên bản nào đang ở đâu.
A company runs multiple environments (dev, test, prod) across several teams. Security requirements mandate that:
-
Production resources must comply with strict organization policies.
-
Development teams should have flexibility to experiment without impacting production.
-
Billing reports must clearly separate production and non-production costs.
Which resource hierarchy approach best satisfies these requirements?
-
A
Place all environments in a single project and separate them using IAM roles
-
B
Apply all policies at the project level and avoid folders
-
C
Create environment-specific folders under the organization and place projects accordingly
-
D
Create separate organizations for each environment
Xem giải thích
Đáp án
C — Tạo thư mục riêng cho từng môi trường dưới tổ chức, đặt dự án vào đúng thư mục
Vì sao đúng
Yêu cầu là production chịu chính sách nghiêm ngặt, còn dev và test thì thoáng hơn. Thư mục là tầng cho phép diễn đạt đúng sự khác biệt đó: Organization Policy đặt ở thư mục prod chỉ ràng buộc những gì nằm trong đó, còn thư mục dev có bộ luật riêng. Chính sách kế thừa xuống mọi dự án bên dưới, nên thêm dự án mới vào đúng thư mục là tự động thừa hưởng đúng mức kiểm soát.
Vì sao các phương án khác sai
- B. Đặt mọi chính sách ở mức dự án, không dùng thư mục — phải lặp lại cấu hình cho từng dự án và chắc chắn sẽ có chỗ bị bỏ sót.
- A. Gộp mọi môi trường vào một dự án, phân biệt bằng vai IAM — không có ranh giới thật; một thử nghiệm ở dev có thể chạm vào tài nguyên production.
- D. Mỗi môi trường một tổ chức riêng — mất gốc chung nên không áp được chính sách toàn công ty, và xé lẻ việc quản lý danh tính lẫn thanh toán.
For this question, refer to the Cymbal Retail case study.
https://services.google.com/fh/files/misc/v6.1_pca_cymbal_retail_case_study_english.pdf
Cymbal plans to introduce conversational commerce, allowing customers to discover products through chat and voice interactions. These interactions must query the product catalog in real time and handle unpredictable traffic spikes caused by promotions and seasonal demand. The solution must scale automatically, provide consistent low latency, and integrate cleanly with existing containerized services. What is the most appropriate design to support scalable, high-performance conversational product discovery?
-
A
Use serverless APIs backed by a horizontally scalable data store and asynchronous messaging for downstream processing
-
B
Deploy a monolithic application on Compute Engine and scale it using instance groups
-
C
Process conversational requests in batch jobs to reduce load on backend systems
-
D
Route all requests directly to on-premises databases to maintain data consistency
Xem giải thích
Đáp án
A — API không máy chủ, phía sau là kho dữ liệu mở rộng theo chiều ngang, xử lý bất đồng bộ
Vì sao đúng
Ba mảnh khớp ba đặc điểm của tải hội thoại: API không máy chủ co giãn theo lượng yêu cầu mà không phải dự phòng máy; kho dữ liệu mở rộng ngang không có trần như CSDL một máy chủ; và xử lý bất đồng bộ tách phần việc nặng ra khỏi đường trả lời, nên người dùng nhận phản hồi nhanh trong lúc việc nặng chạy nền.
Vì sao các phương án khác sai
- B. Ứng dụng nguyên khối trên máy ảo với instance group — co giãn được nhưng chậm hơn và tốn hơn, lại không tách được phần việc nặng.
- C. Xử lý yêu cầu hội thoại theo lô — hội thoại đòi trả lời ngay; xử lý theo lô là hỏng ngay ở yêu cầu cơ bản nhất.
- D. Gọi thẳng vào CSDL tại chỗ — biến hệ thống cũ thành nút thắt và điểm hỏng duy nhất.
A financial services company is migrating latency-sensitive trading applications from an on-premises data center to Google Cloud. Requirements:
-
Consistent low latency and high throughput
-
99.99% availability for connectivity
-
Traffic must remain private and not traverse the public internet
-
The solution should scale to multiple Gbps without complex VPN management
Which connectivity option should the architect recommend?
-
A
Partner Interconnect without redundancy
-
B
Dedicated Interconnect with redundant connections and Cloud Router
-
C
VPC Peering between on-premises and Google Cloud networks
-
D
HA VPN with Cloud Router using BGP
Xem giải thích
Đáp án
B — Dedicated Interconnect với kết nối dự phòng, kèm Cloud Router
Vì sao đúng
Ba mảnh đúng ba yêu cầu:
- Dedicated Interconnect — đường vật lý riêng vào mạng Google, cho độ trễ thấp và ổn định, không phụ thuộc Internet công cộng. Ứng dụng giao dịch không chấp nhận độ trễ biến động.
- Kết nối dự phòng — một đường là một điểm hỏng duy nhất; nhiều đường là điều kiện để đạt cam kết sẵn sàng.
- Cloud Router — dùng BGP để học và quảng bá tuyến tự động, nên khi một đường chết thì tuyến được tính lại ngay chứ không chờ người sửa tay.
Vì sao các phương án khác sai
- A. Partner Interconnect không có dự phòng — thiếu hẳn phần chịu lỗi.
- D. HA VPN với Cloud Router — có dự phòng và định tuyến động, nhưng chạy trên Internet công cộng nên độ trễ biến động; đó là điểm chặn với ứng dụng giao dịch.
- C. VPC Peering — chỉ nối hai VPC trong Google Cloud, không nối được mạng tại chỗ.
For this question, refer to the Cymbal Retail case study.
https://services.google.com/fh/files/misc/v6.1_pca_cymbal_retail_case_study_english.pdf
Cymbal plans to extend automated product discovery to conversational channels, including a web chatbot and a future replacement for its IVR system. Customers should be able to describe products conversationally, refine results iteratively, and receive consistent recommendations across channels. The solution must integrate with backend catalog services and support future AI enhancements. Which architecture best supports Cymbal’s conversational product discovery goals while aligning with Google Cloud best practices?
-
A
Build a rules-based chatbot using Cloud Functions and hardcoded product filters
-
B
Extend the existing IVR system to accept speech-to-text input and forward transcripts to call center agents
-
C
Use Dialogflow CX integrated with Vertex AI Search for Retail, orchestrated by backend services running on GKE
-
D
Use Pub/Sub to stream user messages into BigQuery and generate responses using SQL-based logic
Xem giải thích
Đáp án
C — Dialogflow CX kết hợp Vertex AI Search for Retail
Vì sao đúng
Hai công cụ lo hai phần khác nhau và cần cả hai: Dialogflow CX quản lý hội thoại nhiều lượt có rẽ nhánh và hiểu ý định người dùng; Vertex AI Search for Retail lo phần tìm sản phẩm — hiểu ý định mua hàng, chịu được lỗi chính tả, xếp hạng theo hành vi thật. Thiếu cái sau thì trợ lý nói chuyện tốt nhưng tìm sản phẩm dở; thiếu cái trước thì có tìm kiếm tốt mà không hội thoại được.
Vì sao các phương án khác sai
- A. Chatbot theo luật với bộ lọc viết cứng — không co giãn theo danh mục và hỏng ngay khi khách hỏi khác kịch bản.
- B. Mở rộng IVR bằng chuyển giọng nói thành văn bản — chỉ đổi cách nhập liệu, phần hiểu và phần tìm kiếm vẫn không có.
- D. Đẩy tin nhắn vào BigQuery rồi sinh câu trả lời — BigQuery là kho phân tích, không phải nền tảng phục vụ hội thoại theo thời gian thực.
A SaaS company runs a microservices-based application on GKE. Operations teams are struggling with:
-
Frequent production incidents caused by inconsistent configuration between environments.
-
Long mean time to recovery (MTTR) because incident response is ad hoc.
-
Limited insight into how changes impact user experience.
As the new cloud architect, which strategy best aligns with the Operational Excellence pillar to address these issues?
-
A
Introduce strict change-freeze windows during business hours and restrict production changes to once per month.
-
B
Standardize on GitOps for configuration management, define runbooks and incident playbooks, implement SLOs with error budgets, and use Cloud Monitoring dashboards and alerts.
-
C
Create a dedicated “production SWAT team” of senior engineers to handle all incidents, while other teams focus solely on feature development.
-
D
Migrate all microservices from GKE to Cloud Run to reduce infrastructure management overhead.
Xem giải thích
Đáp án
B — Chuẩn hoá về GitOps cho quản lý cấu hình, kèm runbook và quy trình xử lý sự cố
Vì sao đúng
Đề nêu nguyên nhân rất cụ thể: cấu hình không nhất quán. GitOps giải đúng gốc đó — trạng thái mong muốn của hệ thống nằm trong Git, mọi thay đổi đều qua rà soát và có ghi vết, và một tác nhân tự kéo về áp dụng nên trạng thái thật luôn khớp với trạng thái đã khai. Sự trôi cấu hình biến mất. Runbook lo vế còn lại: khi có sự cố thì ai cũng xử lý theo cùng một cách.
Vì sao các phương án khác sai
- A. Đóng băng thay đổi trong giờ làm việc — giảm số lần triển khai chứ không sửa nguyên nhân; còn dồn thay đổi vào một cửa sổ hẹp thường làm sự cố nặng hơn.
- C. Lập một đội tinh nhuệ lo mọi sự cố — tạo nút thắt và khiến các đội khác không bao giờ học được cách vận hành phần của mình.
- D. Chuyển hết sang Cloud Run — đổi nền tảng không sửa được thói quen cấu hình bằng tay.