Ngân hàng đề — Google Professional Cloud Architect
Tìm thấy 420 câu.
For this question, refer to the KnightMotives Automotive case study.
https://services.google.com/fh/files/misc/v6.1_pca_knightmotives_automotive_case_study_english.pdf
KnightMotives must ensure that autonomous driving models are trained, tested, and validated in compliance with regional safety regulations. Regulatory bodies require traceability of training data, reproducibility of model versions, and auditable testing results from simulation environments. At the same time, KnightMotives wants to enable data scientists to iterate quickly without duplicating infrastructure across regions. What is the most appropriate approach to manage compliance, reproducibility, and global scalability for autonomous vehicle model development?
-
A
Use Vertex AI Experiments and Model Registry for versioning, Cloud Storage for immutable datasets, and IAM with audit logs to enforce access control and traceability.
-
B
Centralize all datasets in a single region to simplify governance and replicate models manually to other regions as needed.
-
C
Export trained models to on-premises systems for compliance validation and maintain simulation logs in local databases.
-
D
Store all training data and models in Cloud Storage buckets per region and rely on naming conventions to track versions manually.
Xem giải thích
Đáp án
A — Vertex AI Experiments và Model Registry cho quản lý phiên bản, Cloud Storage cho dữ liệu
Vì sao đúng
Đây là bộ công cụ cho vòng đời mô hình có thể kiểm toán: Experiments ghi lại từng lần huấn luyện — dữ liệu nào, siêu tham số nào, kết quả ra sao — nên so sánh được và lặp lại được; Model Registry quản lý phiên bản mô hình đã duyệt và bản nào đang phục vụ. Với ngành ô tô có yêu cầu tuân thủ, câu hỏi "mô hình nào đã ra quyết định này, huấn luyện từ dữ liệu nào" phải trả lời được, và không có hai thứ này thì không trả lời nổi.
Vì sao các phương án khác sai
- B. Dồn mọi tập dữ liệu về một khu vực — có thể vi phạm yêu cầu về nơi lưu trữ dữ liệu, và không giải quyết gì về quản lý phiên bản mô hình.
- C. Xuất mô hình về hệ thống tại chỗ để thẩm định — tạo quy trình thủ công tách rời, dễ lệch khỏi bản đang chạy thật.
- D. Để mô hình trong bucket theo từng khu vực — bucket không phải sổ đăng ký; không có siêu dữ liệu, không có trạng thái duyệt, không có lịch sử.
As a cloud architect, you are tasked with creating a signed URL for a Google Cloud Storage (GCS) bucket. The requirement is to allow access to a certain object in the bucket for a third-party service, but only for 30 minutes. The solution should ensure minimum privileges and security. Which of the following options should you choose to implement this?
-
A
Create a signed URL using the bucket's default service account with a 30-minute expiration.
-
B
Create a signed URL using a user-managed service account with full access on the bucket and a 30-minute expiration.
-
C
Create a signed URL using a user-managed service account with read access on the bucket and a 30-minute expiration.
-
D
Create a signed URL using the bucket's default service account with no expiration, and manually invalidate the URL after 30 minutes.
Xem giải thích
Đáp án
C — Signed URL ký bằng tài khoản dịch vụ do bạn quản lý, chỉ có quyền đọc, hết hạn sau 30 phút
Vì sao đúng
Đề yêu cầu quyền tối thiểu, và có ba lớp cùng thu hẹp quyền:
- Tài khoản dịch vụ do bạn tạo — bạn kiểm soát chính xác nó có quyền gì, khác với tài khoản mặc định thường mang quyền rộng hơn nhu cầu.
- Chỉ quyền đọc — bên thứ ba chỉ cần tải đối tượng về, không cần ghi hay xoá.
- Hết hạn sau 30 phút — đúng khoảng thời gian đề cho.
Một điểm quan trọng: signed URL kế thừa quyền của tài khoản đã ký nó, nên ký bằng tài khoản quyền rộng là trao quyền rộng đó cho bất kỳ ai cầm được đường dẫn.
Vì sao các phương án khác sai
- B. Tài khoản do bạn quản lý nhưng có toàn quyền — đúng thời hạn, sai mức quyền.
- A. Dùng tài khoản dịch vụ mặc định — quyền thường rộng hơn cần thiết và khó kiểm soát.
- D. Không đặt hạn rồi định vô hiệu hoá bằng tay — không vô hiệu hoá signed URL được; đã ký là nó có hiệu lực tới khi hết hạn. Đây là phương án nguy hiểm nhất.
Your company has multiple Google Cloud projects spread across different departments. You need to implement a centralized monitoring solution that aggregates logs and metrics from all these projects to monitor company operations effectively. Which solution would best address this requirement?
-
A
Set up a Shared VPC and use it to monitor logs and metrics from all service projects.
-
B
Enable Cloud Monitoring in each project and use the Cloud Console to view logs and metrics project by project.
-
C
Use Cloud Functions to periodically pull logs and metrics from all projects and store them in Cloud Storage for analysis.
-
D
Configure Cloud Logging sinks in each project to route logs to a central logging project and use Cloud Monitoring to aggregate metrics.
Xem giải thích
Đáp án
D — Cấu hình log sink ở từng dự án để dồn log về một dự án ghi log trung tâm
Vì sao đúng
Log sink là cơ chế gốc của Cloud Logging để định tuyến bản ghi sang nơi khác — sang dự án khác, sang bucket, hay sang BigQuery. Khai sink ở mỗi dự án rồi trỏ về một dự án trung tâm cho bạn đúng thứ đề cần: một chỗ duy nhất để tra cứu và cảnh báo trên toàn công ty, đồng thời tách quyền — đội bảo mật đọc được kho trung tâm mà không cần quyền trong từng dự án của các phòng ban.
Vì sao các phương án khác sai
- B. Bật Cloud Monitoring ở từng dự án rồi tự xem — vẫn phải mở nhiều nơi, đúng thứ đề muốn bỏ.
- C. Cloud Functions định kỳ kéo log về — tự dựng lại thứ log sink làm sẵn, có độ trễ và thêm chỗ hỏng.
- A. Shared VPC — cơ chế chia sẻ mạng giữa các dự án, chẳng liên quan tới việc gom log.
The database administration team has asked you to help them improve the performance of a new database server running on Compute Engine. The database is used to import and normalize company performance statistics. It is built with MySQL running on Debian Linux. They have an n1-standard-8 VM with 80 GB of SSD zonal persistent disk which they can't restart until the next maintenance event. What should they change to get better performance from this system as soon as possible and in a cost-effective manner?
-
A
Dynamically resize the SSD persistent disk to 500 GB.
-
B
Create a new virtual machine running PostgreSQL.
-
C
Migrate their performance metrics warehouse to BigQuery.
-
D
Increase the virtual machine’s memory to 64 GB.
Xem giải thích
Đáp án
A — Nới dung lượng đĩa bền SSD lên 500 GB
Vì sao đúng
Trên đĩa bền của Google Cloud, IOPS và thông lượng tăng theo dung lượng đĩa. CSDL làm việc nhập và xuất khối lượng lớn thì nút thắt gần như luôn nằm ở tầng lưu trữ, nên nới đĩa lớn hơn là cách trực tiếp nhất để nâng trần hiệu năng — kể cả khi bạn không cần thêm chỗ chứa. Thao tác này làm được khi máy đang chạy.
Vì sao các phương án khác sai
- D. Tăng bộ nhớ lên 64 GB — giúp khi nút thắt là bộ nhớ đệm, nhưng với khối lượng nhập xuất lớn thì đĩa mới là chỗ nghẽn.
- B. Dựng thêm một máy ảo chạy PostgreSQL — thêm một máy chủ CSDL không tự nó chia được tải, và làm phát sinh bài toán đồng bộ.
- C. Chuyển kho số liệu sang BigQuery — thay đổi kiến trúc rất lớn, không phải cách chỉnh hiệu năng cho máy chủ hiện tại.
Your company has an existing monolithic application running on-premises and you've been tasked to migrate this application to Google Cloud Platform (GCP). The company wants to start taking advantage of microservices for scalability and maintainability. What strategy should you use?
-
A
Refactor the monolithic application into microservices and deploy each one as a Cloud Function.
-
B
Migrate the application to Cloud Run without refactoring, then move individual services to GKE as they are broken out.
-
C
Refactor the monolithic application into microservices and deploy using GKE.
-
D
Migrate the monolithic application to App Engine Standard, then refactor for microservices.
Xem giải thích
Đáp án
C — Tách khối nguyên thành microservice và triển khai trên GKE
Vì sao đúng
Công ty nói rõ muốn hưởng lợi từ microservice để co giãn và dễ bảo trì, nên việc tách là bắt buộc chứ không phải tuỳ chọn. GKE là nền tảng phù hợp nhất cho kết quả sau khi tách: điều phối nhiều dịch vụ phụ thuộc nhau, co giãn từng dịch vụ độc lập, khám phá dịch vụ và cân bằng tải nội bộ, triển khai cuốn chiếu và quay lui.
Vì sao các phương án khác sai
- A. Mỗi microservice là một Cloud Function — Cloud Functions dựng cho hàm ngắn theo sự kiện; vướng giới hạn thời gian chạy và rất khó điều phối khi các dịch vụ gọi lẫn nhau.
- B. Đưa nguyên khối lên Cloud Run rồi tách dần — nghe hợp lý, nhưng một ứng dụng nguyên khối cũ thường có trạng thái và tiến trình chạy nền, không hợp mô hình của Cloud Run.
- D. Đưa lên App Engine Standard rồi tách sau — ràng buộc môi trường chạy của Standard thường buộc phải sửa ứng dụng ngay từ bước đầu, tức là tốn công hai lần.
A large retail company is planning to migrate its e-commerce platform, which runs on a licensed enterprise software suite (including a database and middleware), from an on-premises data center to Google Cloud. The software licensing model is based on CPU cores, and the company has already invested heavily in these licenses. The company aims to optimize cost while ensuring that it remains compliant with the licensing agreements during and after the migration. The e-commerce platform is critical to business operations, so minimizing downtime during the migration is also essential. Which approach should the company take to map its software licenses during the migration?
-
A
Utilize Google Cloud's BYOL (Bring Your Own License) model, deploying the e-commerce platform on Compute Engine instances and configuring the instances to match the licensed CPU cores.
-
B
Move the e-commerce platform to Google Cloud's managed services like App Engine or Cloud SQL, as they automatically handle software license compliance.
-
C
Deploy the e-commerce platform on Google Cloud's Preemptible VMs to reduce costs while leveraging existing software licenses.
-
D
Implement Google Cloud VMware Engine to run the e-commerce platform as-is, maintaining the on-premises licensing model without modifications.
Xem giải thích
Đáp án
A — Dùng mô hình BYOL, mang giấy phép sẵn có sang Google Cloud
Vì sao đúng
Điểm chặn của đề là bộ phần mềm doanh nghiệp có giấy phép. BYOL cho phép công ty tiếp tục dùng giấy phép đã mua thay vì mua lại từ đầu, nên vừa giữ được khoản đầu tư vừa tránh phải viết lại ứng dụng. Với những giấy phép tính theo lõi vật lý thì thường ghép thêm sole-tenant node để thoả điều kiện của nhà cung cấp.
Vì sao các phương án khác sai
- B. Chuyển sang dịch vụ được quản lý như App Engine — buộc phải viết lại ứng dụng, và bộ phần mềm có giấy phép thường không chạy được trên nền đó.
- C. Dùng máy preemptible cho rẻ — máy bị thu hồi bất cứ lúc nào; sai hoàn toàn với nền tảng thương mại điện tử đang phục vụ khách.
- D. Google Cloud VMware Engine — là lựa chọn hợp lệ để chạy nguyên trạng, nhưng nó giải quyết bài toán nền ảo hoá, còn điểm chặn ở đây là giấy phép phần mềm.
The IT team has been tasked with migrating a batch processing system from on-premises servers to Google Cloud. The batch system processes large datasets twice daily and requires temporary compute resources. The solution should minimize costs while allowing the team to monitor and allocate costs by project. Which two actions should you take? (Choose two)
-
A
Use Local SSDs for storage to minimize costs and snapshot them for persistence.
-
B
Use committed use discounts to reduce the cost of always-on compute resources.
-
C
Use preemptible VMs for batch processing jobs to reduce compute costs.
-
D
Use BigQuery billing export and apply project-specific labels to resources.
Xem giải thích
Đáp án
C và D — dùng máy preemptible cho công việc theo lô, và dùng BigQuery billing export kèm nhãn theo dự án
Vì sao đúng
Đề có hai vế và mỗi phương án lo một:
- C. Máy preemptible — công việc theo lô chịu được việc bị khởi động lại, đúng điều kiện để dùng loại máy rẻ nhất. Đây là phần tiết kiệm lớn nhất.
- D. Billing export sang BigQuery kèm nhãn — cho biết tiền đi đâu, cắt theo dự án hay theo loại công việc; không có nó thì không biết việc tối ưu có hiệu quả không.
Vì sao các phương án khác sai
- A. Local SSD rồi chụp snapshot để giữ dữ liệu — dữ liệu trên Local SSD mất khi máy dừng, mà máy preemptible thì bị dừng thường xuyên; snapshot không cứu được.
- B. Committed use discount cho tài nguyên chạy suốt — hợp với tải chạy liên tục, nhưng đây là công việc chạy hai lần mỗi ngày; cam kết dài hạn cho tài nguyên phần lớn thời gian nhàn rỗi là trả thừa.
Your company runs several critical applications on Google Cloud. There has been a significant increase in the number of user-reported incidents recently, indicating performance issues. As a cloud architect, how would you improve the monitoring to proactively identify and address performance issues?
-
A
Use Cloud Debugger to debug the applications in real-time.
-
B
Use Cloud Trace to trace all requests to the applications.
-
C
Use Cloud Profiler to continuously profile the applications.
-
D
Set up custom metrics in Cloud Monitoring for all critical applications and configure alerting based on those metrics.
Xem giải thích
Đáp án
D — Đặt custom metric trong Cloud Monitoring cho các ứng dụng trọng yếu và cấu hình cảnh báo
Vì sao đúng
Vấn đề là người dùng báo sự cố trước khi đội biết. Cách chữa đúng là đảo ngược thứ tự đó bằng giám sát chủ động: đo những chỉ số phản ánh trải nghiệm thật — độ trễ, tỷ lệ lỗi, thông lượng — và đặt cảnh báo trên chúng. Custom metric quan trọng vì chỉ số hạ tầng mặc định không phản ánh sức khoẻ nghiệp vụ; CPU thấp mà tỷ lệ lỗi cao là chuyện thường gặp.
Vì sao các phương án khác sai
Ba phương án còn lại đều là công cụ chẩn đoán, dùng sau khi đã biết có vấn đề:
- B. Cloud Trace — tìm ra chặng nào chậm, nhưng ai đó phải mở nó ra xem.
- C. Cloud Profiler — chỉ ra hàm nào tốn tài nguyên trong mã.
- A. Cloud Debugger — soi trạng thái tại một điểm trong mã.
Chúng đều hữu ích, nhưng không cái nào chủ động báo cho bạn biết có chuyện.
A financial services company is deploying a multi-tier application in Google Cloud using Google Kubernetes Engine (GKE). The application consists of three tiers: frontend (web), backend (application logic), and database. Each tier is deployed as a separate set of microservices within the GKE cluster. The company needs to ensure that:
-
The frontend tier is accessible from the internet, but only the backend tier can communicate with the database tier.
-
Internal communication between the backend and database tiers must be secured and should not be exposed to the public internet.
-
The solution should be scalable and maintainable, with minimal administrative overhead.
-
Network policies should be enforced at the container level to prevent unauthorized access.
Which two of the following solutions should you implement? (Choose two)
-
A
Deploy a Google Cloud Armor security policy to protect the frontend tier and restrict access to the backend and database tiers.
-
B
Use a Google Cloud Internal TCP/UDP Load Balancer to manage internal traffic between the backend and database tiers, ensuring it stays within the private network.
-
C
Enable VPC Service Controls to create a security perimeter around the GKE cluster, ensuring that only authorized services can access the backend and database tiers.
-
D
Configure a Cloud NAT gateway to allow the backend and database tiers to initiate outbound connections to the internet while keeping their IP addresses private.
-
E
Use Kubernetes Network Policies to restrict traffic between the frontend, backend, and database tiers, allowing only necessary communication.
Xem giải thích
Đáp án
B và E — internal TCP/UDP load balancer cho lưu lượng nội bộ, và Kubernetes Network Policy để hạn chế lưu lượng giữa các tầng
Vì sao đúng
Hai lớp bổ sung nhau:
- E. Network Policy — lớp kiểm soát chính giữa các tầng, vì cả ba tầng là pod trong cùng cụm. Nó lọc theo nhãn pod, nên luật vẫn đúng khi pod được tạo lại với IP khác.
- B. Internal load balancer — cho tầng backend và database một điểm truy cập ổn định chỉ tồn tại trong VPC, không có IP công khai nào.
Vì sao các phương án khác sai
- A. Cloud Armor cho tầng giao diện — là biện pháp hợp lý cho phần phơi ra Internet, nhưng không kiểm soát lưu lượng giữa các tầng như đề hỏi.
- C. VPC Service Controls — lập vành đai quanh dịch vụ được quản lý để chống rò dữ liệu, không phải công cụ phân đoạn nội bộ.
- D. Cloud NAT — cho tầng sau đi ra Internet; đề đang muốn hạn chế lưu lượng nội bộ, không phải mở đường ra.
For this question, refer to the Altostrat Media case study.
https://services.google.com/fh/files/misc/v6.1_pca_altostrat_media_case_study_english.pdf
Altostrat stores several petabytes of media content in Cloud Storage, including newly released premium videos, frequently accessed podcasts, and long-tail archival content that is rarely accessed after the first few months. The platform must maintain high availability and global scalability for active content while significantly reducing storage costs for older assets. Access patterns are predictable and can be classified by content age and popularity. Which storage architecture best optimizes costs while maintaining availability and scalability?
-
A
Store all media objects in Cloud Storage Standard (multi-region) and rely on lifecycle rules only for object deletion.
-
B
Export rarely accessed media from Cloud Storage to BigQuery for long-term storage and analysis.
-
C
Apply Cloud Storage lifecycle policies to transition older media from Standard to Nearline and then to Coldline storage.
-
D
Use Cloud Storage Standard for all content and enable Object Versioning to protect against accidental deletions.
Xem giải thích
Đáp án
C — Áp lifecycle policy để chuyển nội dung cũ từ Standard xuống lớp lạnh hơn
Vì sao đúng
Nội dung phương tiện có mẫu truy cập rất rõ: nóng lúc mới phát hành, nguội dần theo thời gian. Lifecycle policy tự động hoá đúng đường cong đó — sau N ngày chuyển sang Nearline, sau M ngày nữa xuống Coldline hoặc Archive. Không phải ai nhớ làm, và nội dung vẫn truy cập được ngay nếu bất chợt có người xem lại.
Vì sao các phương án khác sai
- A. Giữ mọi thứ ở Standard đa vùng — trả giá lưu trữ cao nhất cho cả kho nội dung mà phần lớn chẳng ai đụng tới.
- B. Xuất nội dung ít dùng sang BigQuery — BigQuery không phải nơi chứa tệp phương tiện; sai loại lưu trữ.
- D. Bật Object Versioning — giữ thêm các bản cũ, tức là tăng chi phí lưu trữ; đây là cơ chế chống mất dữ liệu, không phải cơ chế tối ưu chi phí.