Ngân hàng đề — Google Professional Cloud Architect

Tìm thấy 420 câu.

Câu 211

For this question, refer to the KnightMotives Automotive case study.

https://services.google.com/fh/files/misc/v6.1_pca_knightmotives_automotive_case_study_english.pdf


To fund modernization efforts, KnightMotives plans to offer data-driven services to internal teams and external partners, such as predictive maintenance insights and dealer performance benchmarks. The solution must support secure data sharing, comply with regional data governance requirements, and allow the business to experiment with AI models without rebuilding infrastructure. The architecture should also support gradual migration from on-premises systems. Which approach best enables secure data monetization and AI-driven insights under these constraints?

  1. A

    Deploy separate BigQuery projects per partner and fully duplicate datasets for isolation and security.

  2. B

    Use Pub/Sub to stream all vehicle and dealer data to partners in real time and let them store and analyze it independently.

  3. C

    Centralize data in BigQuery, apply row- and column-level security, publish datasets via Analytics Hub, and use Vertex AI to build and deploy monetizable ML models.

  4. D

    Build custom REST APIs on Cloud Run that query multiple backend systems directly and return raw data to consumers.

Xem giải thích

Đáp án

C — Gom dữ liệu về BigQuery, áp bảo mật ở mức hàng và cột, rồi công bố cho đối tác

Vì sao đúng

Bài toán là chia sẻ dữ liệu với đối tác mà không mất kiểm soát. BigQuery cho phép giữ một bản duy nhất rồi giới hạn tầm nhìn ngay tại chỗ: bảo mật mức hàng để mỗi đối tác chỉ thấy dữ liệu của mình, mức cột để che những trường nhạy cảm. Không phải nhân bản dữ liệu ra nhiều bản đã lược bớt — mà mỗi bản sao là một thứ có thể lệch và một chỗ có thể rò.

Vì sao các phương án khác sai

  • A. Mỗi đối tác một dự án BigQuery với dữ liệu nhân đôi — chi phí lưu trữ nhân lên, và các bản sao sẽ lệch nhau theo thời gian.
  • B. Đẩy toàn bộ dữ liệu cho đối tác qua Pub/Sub — trao dữ liệu ra ngoài rồi mất quyền kiểm soát hoàn toàn.
  • D. Tự viết REST API truy vấn nhiều hệ thống — phải tự xây và tự bảo mật một tầng trung gian, trong khi BigQuery đã có sẵn cơ chế phân quyền chi tiết.
Câu 212

An international retail chain is planning to extend its on-premises IT infrastructure to Google Cloud. The on-premises network is segmented into multiple VLANs to separate traffic for different departments, such as sales, inventory management, and finance. The company requires that these VLANs are extended to Google Cloud to maintain the same level of network segmentation and security controls. Additionally, the network extension must support dynamic routing updates as the company frequently adjusts its network topology based on changing business needs. Which solution would best allow the company to extend its on-premises VLANs to Google Cloud while supporting dynamic routing and maintaining network segmentation?

  1. A

    Deploy a Cloud CDN in front of each department's resources in Google Cloud to cache content and reduce the need for a direct network extension.

  2. B

    Implement VPC peering between the on-premises data center and Google Cloud, mapping each VLAN to a separate VPC subnet.

  3. C

    Use a Dedicated Interconnect to extend the on-premises network to Google Cloud and configure VLAN attachments for each department, with dynamic routing enabled via Cloud Router.

  4. D

    Set up a Cloud VPN tunnel for each VLAN, ensuring secure communication between on-premises segments and corresponding Google Cloud subnets.

Xem giải thích

Đáp án

C — Dùng Dedicated Interconnect để mở rộng mạng tại chỗ sang Google Cloud

Vì sao đúng

Mạng tại chỗ được chia thành nhiều VLAN cho các phòng ban, và đề muốn mở rộng cấu trúc đó chứ không dựng lại. Dedicated Interconnect cho phép mang nhiều VLAN attachment qua cùng một đường vật lý, mỗi VLAN nối vào một VPC hoặc một subnet tương ứng — nên cách phân đoạn hiện có được giữ nguyên trên đám mây, với băng thông cao và độ trễ ổn định.

Vì sao các phương án khác sai

  • D. Một đường hầm VPN cho mỗi VLAN — làm được nhưng số đường hầm tăng theo số VLAN, băng thông mỗi đường có trần, và tất cả đều đi qua Internet công cộng.
  • B. VPC peering giữa trung tâm dữ liệu và Google Cloud — peering chỉ nối hai VPC trong Google Cloud, không nối được mạng tại chỗ.
  • A. Cloud CDN cho tài nguyên từng phòng ban — CDN nhớ đệm nội dung cho người dùng cuối, chẳng liên quan tới việc mở rộng mạng nội bộ.
Câu 213 Chọn nhiều đáp án

Your company is launching a global media streaming platform that delivers high-definition (HD) video content to millions of users worldwide. The platform needs to support low-latency video streaming, scalable storage for a vast library of media files, and efficient data processing for real-time analytics on user behavior. You are tasked with designing the network and storage architecture for this platform on Google Cloud. Which two design choices would best meet the requirements for low-latency streaming, scalable storage, and real-time data processing? (Choose two)

  1. A

    Deploy the media streaming service on Google Kubernetes Engine (GKE) with horizontal pod autoscaling enabled.

  2. B

    Use Cloud CDN (Content Delivery Network) in combination with Regional persistent disks to store the media files.

  3. C

    Store media files in Google Cloud Storage using a multi-regional bucket and configure lifecycle rules for archival.

  4. D

    Utilize Cloud Spanner for storing metadata about the media files and user preferences.

  5. E

    Use Compute Engine instances with SSD persistent disks for storing media files and deploy a global load balancer for traffic distribution.

Xem giải thích

Đáp án

A và C — GKE với horizontal pod autoscaling, và tệp phương tiện trong bucket đa vùng kèm CDN

Vì sao đúng

Hai mảnh lo hai phần tách bạch của một nền tảng phát video:

  • C. Bucket đa vùng cộng CDN — đây là phần quyết định trải nghiệm. Video được nhớ đệm ở biên mạng gần người dùng, nên độ trễ thấp và máy chủ gốc không phải phục vụ lại cùng một tệp hàng triệu lần. Bucket đa vùng khiến bản gốc vừa bền vừa gần khi CDN cần lấy lại.
  • A. GKE với tự co giãn pod — lo tầng ứng dụng: xác thực, danh mục, tiến độ xem, và co giãn theo số người xem đồng thời.

Vì sao các phương án khác sai

  • B. CDN với đĩa bền vùng — đĩa vùng gắn với máy ảo và chỉ nhân bản trong một khu vực; không phải nơi chứa thư viện video toàn cầu.
  • E. Để tệp phương tiện trên đĩa SSD của máy ảo — không co giãn, không phân phối toàn cầu, và đắt hơn Cloud Storage nhiều lần.
  • D. Cloud Spanner cho siêu dữ liệu — dùng được, nhưng đắt và không phải mảnh quyết định cho yêu cầu mà đề nêu.
Câu 214

Your company runs a batch data processing pipeline on Compute Engine VMs. The jobs are CPU-intensive and can tolerate job restarts, but must complete within a defined daily window. You notice high costs due to sustained usage of on-demand VMs across multiple zones. As the lead architect, what is the most cost-effective approach to run these workloads without violating completion SLAs?

  1. A

    Switch to preemptible VMs in an unmanaged instance group and set up scripts to restart failed jobs manually.

  2. B

    Use Spot VMs with managed instance groups (MIGs), configure autoscaling, and use job checkpointing for resilience.

  3. C

    Move the batch pipeline to Dataflow with autoscaling enabled and use streaming mode for lower latency.

  4. D

    Shift the workload to App Engine flexible environment and enable budget alerts to monitor costs.

Xem giải thích

Đáp án

B — Spot VM trong managed instance group, có tự co giãn

Vì sao đúng

Ba dữ kiện của đề khớp đúng với Spot VM: công việc nặng CPU, chịu được việc bị khởi động lại, và phải xong trong một khung giờ xác định. Spot VM rẻ hơn máy thường rất nhiều, đổi lại có thể bị thu hồi — mà điều kiện thứ hai nói rõ là chấp nhận được.

Phần managed instance group mới là điểm phân biệt thật: nhóm tự thay ngay máy bị thu hồi, nên công việc vẫn tiến tới. Tự co giãn giúp thêm máy khi cần để kịp khung giờ.

Vì sao các phương án khác sai

  • A. Máy preemptible trong unmanaged instance group với script tự viết — nhóm loại này không tự thay máy và không tự co giãn, nên bạn phải tự viết đúng phần khó nhất.
  • C. Chuyển sang Dataflow ở chế độ streaming — đây là công việc theo lô, dùng chế độ luồng là sai mô hình và tốn hơn.
  • D. App Engine flexible với cảnh báo ngân sách — không phải nền tảng cho công việc theo lô nặng CPU, và cảnh báo ngân sách chỉ báo cho bạn biết đã tiêu bao nhiêu chứ không giảm chi phí.
Câu 215

A biotech company is planning to migrate its data-intensive bioinformatics analysis platform from an on-premises high-performance computing (HPC) cluster to Google Cloud. The platform processes large datasets using custom algorithms and requires significant computational resources. The company wants to conduct a proof of concept (PoC) to evaluate the feasibility of migrating the platform to Google Cloud, focusing on the performance, scalability, and cost-effectiveness of running the workloads in the cloud. The PoC needs to be representative of production workloads but should not disrupt current operations. Which approach should the company take to design an effective PoC for this migration?

  1. A

    Migrate a small subset of the datasets to Google Cloud and run the entire bioinformatics platform in a Google Cloud environment using preemptible VMs to minimize costs.

  2. B

    Select a representative subset of workloads and datasets, migrate them to Google Cloud, and use autoscaling Compute Engine instances with managed instance groups to test performance under varying loads.

  3. C

    Move the entire bioinformatics platform to Google Cloud for the PoC, running it in parallel with the on-premises environment to directly compare performance and costs.

  4. D

    Replicate the entire HPC environment in Google Cloud using Google Kubernetes Engine (GKE) and run scaled-down versions of the production workloads to test performance and scalability.

Xem giải thích

Đáp án

B — Chọn một tập con đại diện gồm cả khối lượng công việc lẫn dữ liệu, chuyển sang thử nghiệm

Vì sao đúng

Mục đích của một cuộc chạy thử là trả lời được câu hỏi thật với chi phí thấp: nền tảng mới có đủ hiệu năng không, chi phí thực tế bao nhiêu, đội có vận hành nổi không. Muốn vậy thì tập thử phải đại diện — có đủ các kiểu công việc và dữ liệu đủ lớn để đo được, chứ không phải phần dễ nhất. Kết quả đo trên tập đại diện mới ngoại suy được cho toàn hệ thống.

Vì sao các phương án khác sai

  • A. Chuyển một phần nhỏ dữ liệu nhưng chạy toàn bộ nền tảng — mất cân đối: dữ liệu quá nhỏ thì số đo hiệu năng và chi phí không nói lên gì.
  • C và D. Chuyển hoặc dựng lại toàn bộ môi trường — đó không còn là chạy thử mà là chuyển thật, tức là gánh trọn rủi ro trước khi kịp học được gì.
Câu 216

For this question, refer to the KnightMotives Automotive case study.

https://services.google.com/fh/files/misc/v6.1_pca_knightmotives_automotive_case_study_english.pdf


KnightMotives wants to foster a long-term, personalized relationship with drivers across BEV, hybrid, and ICE vehicles. The solution must deliver consistent, AI-driven in-vehicle experiences (voice assistance, personalized settings, proactive maintenance insights) even in areas with unreliable connectivity. The architecture must minimize fragmentation across vehicle models, support gradual rollout over five years, and align with Google Cloud best practices. Which architecture best meets KnightMotives’ goals while addressing connectivity constraints and technical debt?

  1. A

    Use only on-premises infrastructure to host AI models to ensure consistent behavior across all vehicles.

  2. B

    Deploy a centralized AI platform on Google Cloud using Vertex AI for personalization models, combined with lightweight edge inference in vehicles that synchronizes with the cloud when connectivity is available.

  3. C

    Build separate AI stacks for BEV, hybrid, and ICE vehicles, each optimized for its hardware and connectivity profile.

  4. D

    Run all AI inference exclusively in the cloud and require persistent connectivity from vehicles to deliver personalized experiences.

Xem giải thích

Đáp án

B — Dựng nền tảng AI tập trung trên Google Cloud bằng Vertex AI

Vì sao đúng

KnightMotives có nhiều dòng xe và nhiều kênh, nên vấn đề là tránh mỗi nơi một mô hình một kiểu. Nền tảng AI tập trung cho một chỗ duy nhất để huấn luyện, quản lý phiên bản, theo dõi và triển khai mô hình; mô hình được dùng lại cho các dòng xe khác nhau thay vì xây lại từ đầu, và việc kiểm toán cũng chỉ phải làm ở một nơi.

Vì sao các phương án khác sai

  • C. Xây ba ngăn xếp AI riêng cho xe điện, xe lai và xe xăng — nhân ba công sức và ba chỗ phải bảo trì, trong khi phần lớn năng lực là dùng chung được.
  • A. Chỉ chạy AI tại chỗ — không co giãn theo quy mô toàn cầu và mất phần công cụ được quản lý.
  • D. Chạy suy luận hoàn toàn trên đám mây, đòi kết nối liên tục — xe thường xuyên mất sóng; buộc phải có kết nối là thiết kế hỏng ngay từ giả định.
Câu 217

For this question, refer to the KnightMotives Automotive case study.

https://services.google.com/fh/files/misc/v6.1_pca_knightmotives_automotive_case_study_english.pdf


KnightMotives wants to modernize the in-vehicle experience across BEV, hybrid, and ICE vehicles within five years. The goal is to deliver a consistent UX with AI-powered features (voice assistant, recommendations, predictive maintenance hints) across all models, despite fragmented codebases and intermittent connectivity—especially in rural areas. Vehicles must continue to function when offline, while allowing centralized updates and rapid feature iteration. KnightMotives also wants to minimize operational overhead and avoid deploying new hardware to dealers. Which Google Cloud–based architecture best meets these requirements?

  1. A

    Standardize the in-vehicle software as containerized services running on an embedded runtime, use Anthos for consistent configuration, and deploy lightweight on-device inference models with Vertex AI Edge, syncing data asynchronously to Google Cloud.

  2. B

    Use Firebase Hosting for the in-vehicle UI and call Vertex AI endpoints directly from vehicles for inference.

  3. C

    Rebuild all vehicle software as a single Android Automotive application tightly coupled to Google Cloud APIs.

  4. D

    Deploy a centralized monolithic backend on Compute Engine and stream all in-vehicle interactions in real time to Google Cloud for AI processing.

Xem giải thích

Đáp án

A — Chuẩn hoá phần mềm trên xe thành các dịch vụ container chạy trên môi trường nhúng

Vì sao đúng

Container hoá cho phần mềm trên xe hai thứ quan trọng: cách đóng gói và triển khai thống nhất giữa các dòng xe, và cập nhật từng thành phần độc lập thay vì phải nạp lại toàn bộ hệ thống. Với đội xe đã bán ra ngoài đường thì khả năng cập nhật từng phần qua mạng là yếu tố quyết định chi phí bảo trì.

Vì sao các phương án khác sai

  • B. Dùng Firebase Hosting cho giao diện trên xe rồi gọi thẳng Vertex AI — phụ thuộc kết nối mạng liên tục, mà xe thì thường xuyên mất sóng.
  • C. Viết lại tất cả thành một ứng dụng Android Automotive duy nhất — quay về mô hình nguyên khối: sửa một chỗ phải phát hành lại tất cả.
  • D. Backend nguyên khối trên Compute Engine, đẩy mọi thứ về đó — mọi tính năng trên xe đều phụ thuộc mạng, và backend thành điểm hỏng duy nhất.
Câu 218

For this question, refer to the Altostrat Media case study.

https://services.google.com/fh/files/misc/v6.1_pca_altostrat_media_case_study_english.pdf


Altostrat serves media content to a global audience with variable demand spikes during major news events and documentary releases. Newly published media must be highly available with low latency worldwide, while older content should remain accessible but at minimal cost. The architecture should remain fully managed and integrate seamlessly with existing Cloud Storage and GKE-based delivery services. What is the most appropriate Google Cloud design to meet these requirements while optimizing storage costs?

  1. A

    Serve media directly from GKE node local SSDs for low latency and back up content to Cloud Storage.

  2. B

    Use regional Cloud Storage buckets and replicate data manually across regions using scheduled jobs.

  3. C

    Store all content in Cloud Storage Coldline and rely on aggressive caching at the application layer.

  4. D

    Use multi-region Cloud Storage for hot content and transition older content to single-region Coldline buckets using lifecycle rules.

Xem giải thích

Đáp án

D — Cloud Storage đa vùng cho nội dung đang nóng, chuyển nội dung cũ xuống lớp lạnh hơn

Vì sao đúng

Nội dung phương tiện có đường cong truy cập rất rõ: nóng lúc mới ra, nguội dần. Phương án này bám đúng đường cong đó — nội dung nóng nằm ở lớp đa vùng để phục vụ nhanh và bền trên phạm vi rộng, còn nội dung cũ được lifecycle policy tự chuyển xuống lớp rẻ hơn. Vừa nhanh cho phần cần nhanh, vừa rẻ cho phần chẳng ai xem.

Vì sao các phương án khác sai

  • A. Phục vụ thẳng từ local SSD của node GKE — local SSD mất dữ liệu khi node dừng, và không phục vụ được ở quy mô toàn cầu.
  • B. Bucket theo vùng rồi tự nhân bản bằng tay — thủ công, luôn có độ trễ, và chắc chắn sẽ lệch nhau.
  • C. Để tất cả ở lớp Coldline rồi dựa vào nhớ đệm — Coldline có phí truy xuất cao; nội dung mới ra bị xem nhiều sẽ tạo hoá đơn rất lớn, và lần xem đầu tiên nào cũng chậm.
Câu 219

As a cloud architect, you are working with a global company that uses Cloud Storage for data storage. The company has a large number of contractors who need to upload data to a specific Cloud Storage bucket, but they should not have any other access rights to the data or the other resources. At the same time, the data engineers should have the ability to manage all Cloud Storage resources. What IAM roles should be assigned to the contractors and the data engineers?

  1. A

    Assign roles/storage.objectAdmin to contractors and roles/storage.admin to data engineers.

  2. B

    Assign roles/storage.objectViewer to contractors and roles/storage.objectAdmin to data engineers.

  3. C

    Assign roles/storage.objectCreator to contractors and roles/storage.objectAdmin to data engineers.

  4. D

    Assign roles/storage.objectCreator to contractors and roles/storage.admin to data engineers.

Xem giải thích

Đáp án

D — Nhà thầu nhận roles/storage.objectCreator, kỹ sư dữ liệu nhận roles/storage.admin

Vì sao đúng

Hai nhu cầu, hai vai, và mỗi vai phải khớp chính xác:

  • Nhà thầu chỉ được tải dữ liệu lên, không được xem hay sửa gì khác → objectCreator cho đúng quyền tạo đối tượng mới, không cho quyền đọc. Đây là chi tiết dễ bỏ qua: nhà thầu ghi lên được nhưng không đọc lại được, và đó chính là điều đề muốn.
  • Kỹ sư dữ liệu cần toàn quyền kể cả quản lý chính bucket → storage.admin.

Vì sao các phương án khác sai

  • C. Nhà thầu đúng vai nhưng kỹ sư chỉ có objectAdmin — vai này quản lý đối tượng bên trong bucket, không quản lý được cấu hình bucket; thiếu so với "toàn quyền".
  • A. Nhà thầu nhận objectAdmin — cho cả quyền đọc, sửa và xoá; vượt xa mức "chỉ tải lên".
  • B. Nhà thầu nhận objectViewer — sai hẳn hướng: cho quyền đọc mà không cho quyền ghi.
Câu 220

You are a cloud architect for a retail company that has recently migrated its e-commerce platform to Google Cloud. The platform currently handles a peak load of 50,000 simultaneous users during sales events. The company anticipates a 10x increase in traffic over the next three years due to expansion into new markets and expects future traffic spikes to reach up to 500,000 simultaneous users. The company wants to ensure the architecture can scale to meet future demands while minimizing operational overhead. Additionally, the company is exploring the use of AI for personalized recommendations, which could significantly increase the demand on its data processing and storage systems. Which architectural approach should you recommend to ensure scalability and future growth, while also taking advantage of potential cloud and technology improvements?

  1. A

    Use pre-configured VM instances with fixed CPU and memory allocations to handle the expected peak load.

  2. B

    Deploy the application in multiple regions and use global load balancing to distribute traffic, paired with autoscaling.

  3. C

    Implement an auto-scaling group of managed instances with a high upper limit to automatically adjust to varying load.

  4. D

    Migrate the application to a monolithic architecture to simplify management and scaling.

Xem giải thích

Đáp án

B — Triển khai ở nhiều khu vực và dùng cân bằng tải toàn cầu

Vì sao đúng

Với nền tảng thương mại điện tử có đỉnh 50.000 người dùng đồng thời, hai vấn đề đi cùng nhau: chịu tải, và chịu được sự cố. Triển khai nhiều khu vực giải cả hai — tải được trải ra, người dùng được đưa tới khu vực gần nhất nên độ trễ thấp, và mất trọn một khu vực vẫn còn nơi khác phục vụ.

Vì sao các phương án khác sai

  • C. Một nhóm tự co giãn với trần rất cao — chịu được tải nhưng vẫn nằm trong một khu vực, nên sự cố cấp khu vực là sập toàn bộ.
  • A. Máy ảo cấu hình cố định dựng sẵn cho mức đỉnh — trả tiền cho mức đỉnh suốt cả năm, và vẫn hụt nếu đỉnh vượt dự đoán.
  • D. Quay về kiến trúc nguyên khối cho dễ quản lý — đánh đổi khả năng co giãn để lấy sự tiện, đi ngược mục tiêu.