Ngân hàng đề — Google Professional Cloud Architect
Tìm thấy 420 câu.
As a cloud architect, you are working with a global gaming company that needs a database for their new real-time, multi-player game. They require low latency, high transaction throughput, and the ability to scale to millions of users worldwide. Which of the following approaches would be the most effective way to use Google Cloud Spanner to meet these requirements?
-
A
Create a single Cloud Spanner instance and rely on Google's global network for low latency.
-
B
Use Cloud Spanner's multi-region configurations and configure the game to direct traffic based on user location.
-
C
Set up multiple Cloud Spanner instances in each region where the game has users, and manually replicate data between instances.
-
D
Create a single-region Cloud Spanner instance for the lowest possible latency and manually partition the database by user location.
Xem giải thích
Đáp án
B — Dùng cấu hình đa vùng của Cloud Spanner và cho trò chơi nối tới nơi gần nhất
Vì sao đúng
Trò chơi nhiều người chơi thời gian thực cần độ trễ thấp ở mọi châu lục nhưng dữ liệu vẫn phải nhất quán — điểm số và vật phẩm không được lệch nhau. Spanner đa vùng là thứ duy nhất cho cả hai: nó nhân bản đồng bộ qua nhiều khu vực, giữ nhất quán mạnh, mà vẫn cho đọc từ bản sao gần người chơi nhất.
Vì sao các phương án khác sai
- A. Một instance Spanner rồi trông vào mạng Google — mạng Google nhanh, nhưng khoảng cách vật lý vẫn còn đó; người chơi ở xa vẫn chịu độ trễ cao.
- C. Mỗi khu vực một instance Spanner riêng — thành nhiều CSDL tách rời, và bạn phải tự đồng bộ chúng; mất luôn tính nhất quán mà Spanner mang lại.
- D. Một instance ở một khu vực cho độ trễ thấp nhất — thấp nhất cho người chơi ở khu vực đó, cao nhất cho tất cả những người còn lại.
As a cloud architect, you are designing a secure architecture for a client who needs to limit the use of external IP addresses on their Compute Engine instances. The client wants to ensure that only specific, approved instances can be assigned external IP addresses. What method would be the most appropriate for enforcing this requirement?
-
A
Use VPC Service Controls to restrict instances from obtaining external IP addresses.
-
B
Use an organization policy to restrict external IP addresses and apply it to the project.
-
C
Use firewall rules to block outbound traffic from instances without approved external IPs.
-
D
Use Shared VPC to restrict instances from obtaining external IP addresses.
Xem giải thích
Đáp án
B — Dùng Organization Policy để cấm địa chỉ IP ngoài, áp ở mức tổ chức
Vì sao đúng
Organization Policy là cơ chế ràng buộc cấu hình của Google Cloud: nó không phân quyền cho ai mà đặt ra giới hạn về những gì được phép tồn tại. Ràng buộc constraints/compute.vmExternalIpAccess cấm gán IP ngoài cho máy ảo, và vì áp ở mức tổ chức nên nó kế thừa xuống mọi thư mục và dự án — kể cả dự án tạo mới sau này. Người có quyền tạo máy cũng không lách được.
Vì sao các phương án khác sai
- A. VPC Service Controls — lập vành đai quanh dịch vụ được quản lý để chống rò dữ liệu, không kiểm soát việc máy ảo có IP ngoài hay không.
- C. Luật tường lửa chặn lưu lượng đi ra — chặn được đường đi, nhưng IP ngoài vẫn được gán và vẫn là bề mặt tấn công; đây là chữa triệu chứng.
- D. Shared VPC — cơ chế chia sẻ mạng giữa các dự án, không phải công cụ áp ràng buộc.
You are working with an organization that wants to have granular control over its Google Cloud resources. The organization has multiple projects, each managed by different teams and belonging to different departments. The company wants to enforce the principle of least privilege and ensure that the resources are only accessible to the team that needs them, while also keeping the management simple and efficient. Which of the following approaches should you recommend?
-
A
Assign roles to the departments at the organization level and let the departments manage their individual teams' access.
-
B
Create Google Groups for each team, assign roles to the groups at the project level, and add the team members to the appropriate groups.
-
C
Assign individual roles to each team member at the project level.
-
D
Assign roles to the teams at the organization level.
Xem giải thích
Đáp án
B — Tạo Google Group cho từng đội và gán vai cho nhóm ở mức dự án
Vì sao đúng
Hai quyết định độc lập, và đề cần cả hai:
- Gán ở mức dự án — mỗi dự án do một đội khác nhau quản lý, nên quyền phải dừng lại ở ranh giới dự án. Gán ở mức tổ chức là cho đội này thấy tài nguyên của đội kia.
- Gán cho nhóm chứ không cho từng người — nhân sự thay đổi thì chỉ sửa thành viên nhóm, không phải sửa chính sách IAM ở từng dự án.
Vì sao các phương án khác sai
- A và D. Gán vai ở mức tổ chức — quyền kế thừa xuống mọi dự án, phá vỡ đúng sự phân tách mà đề yêu cầu.
- C. Gán vai cho từng người ở mức dự án — đúng phạm vi nhưng sai cách quản lý: gánh nặng tăng theo số người và rất dễ quên thu hồi.
When deploying your application to App Engine, your development team aims to scale the number of instances in response to the request rate. It is necessary to maintain a minimum of five idle instances at all times. Which scaling method should they employ?
-
A
Automatic Scaling with
min_idle_instancesset to 5. -
B
Basic Scaling with
max_instancesset to 5. -
C
Basic Scaling with
min_instancesset to 5. -
D
Manual Scaling with 5 instances.
Xem giải thích
Đáp án
A — Automatic Scaling với min_idle_instances đặt bằng 5
Vì sao đúng
Đề có hai yêu cầu: co giãn theo tốc độ yêu cầu, và luôn giữ sẵn một số bản chạy. Chỉ Automatic Scaling đáp ứng vế đầu — nó theo dõi lượng yêu cầu và tự thêm bớt bản chạy. Còn min_idle_instances lo vế sau: giữ sẵn 5 bản đã khởi động và đang rảnh, nên khi lưu lượng tăng đột ngột thì có ngay chỗ nhận việc mà người dùng không phải chờ khởi động lạnh.
Vì sao các phương án khác sai
- B và C. Basic Scaling — chế độ này bật bản chạy khi có yêu cầu và tắt khi rảnh, dựng cho tải thưa và không nhạy với tốc độ yêu cầu như đề cần.
- D. Manual Scaling với 5 bản — cố định đúng 5 bản, tức là không co giãn gì cả.
For this question, refer to the Cymbal Retail case study.
https://services.google.com/fh/files/misc/v6.1_pca_cymbal_retail_case_study_english.pdf
Cymbal’s product catalog has grown to millions of SKUs across multiple retail sub-verticals. Customers frequently browse and search products by name, category, and attributes. During peak shopping periods, the existing relational databases experience latency spikes, leading to slow page loads and abandoned sessions. Cymbal expects rapid growth over the next two years and wants to modernize its architecture on Google Cloud to ensure low-latency product discovery at scale while minimizing operational overhead. Which architecture best addresses Cymbal’s scalability and performance requirements for product catalog search and browsing?
-
A
Store the catalog in BigQuery and query it directly from the web application for each user request
-
B
Deploy larger GKE nodes and rely on application-level caching inside the containers
-
C
Index the product catalog in a managed search service and cache frequent queries using an in-memory data store
-
D
Migrate all catalog data into Cloud SQL and vertically scale the database during peak traffic
Xem giải thích
Đáp án
C — Đánh chỉ mục danh mục sản phẩm trong dịch vụ tìm kiếm được quản lý, kèm nhớ đệm truy vấn hay dùng
Vì sao đúng
Danh mục sản phẩm bị truy vấn rất nhiều với đủ kiểu bộ lọc, và CSDL quan hệ không phải công cụ cho việc đó. Dịch vụ tìm kiếm được quản lý dựng riêng để trả kết quả ở độ trễ thấp trên tập dữ liệu lớn, có xếp hạng và lọc theo thuộc tính. Thêm lớp nhớ đệm cho những truy vấn lặp lại nhiều thì cắt được phần lớn tải còn lại.
Vì sao các phương án khác sai
- A. Truy vấn thẳng BigQuery từ ứng dụng web — BigQuery là kho phân tích, độ trễ tính bằng giây; không hợp đường phục vụ người dùng.
- B. Dùng node GKE lớn hơn và nhớ đệm trong container — nhớ đệm cục bộ trong từng container thì mỗi bản một kiểu, tỷ lệ trúng đệm thấp và không giải quyết được gốc.
- D. Dồn vào Cloud SQL rồi nâng cấu hình máy khi cao điểm — mở rộng theo chiều dọc luôn có trần và luôn đắt dần.
A large financial services company wants to build a new trading platform that can process millions of transactions per second. The platform should be able to handle high levels of volatility, and provide low latency data access for real-time decision making. Which of the following options would be the best solution for this requirement?
-
A
Use Cloud Datastore for data storage and Cloud Functions for data processing.
-
B
Use BigQuery for data storage and processing.
-
C
Use Cloud Pub/Sub for data streaming and BigTable for data storage.
-
D
Use Cloud Spanner for data storage and Cloud Dataflow for data processing.
Xem giải thích
Đáp án
C — Cloud Pub/Sub cho luồng dữ liệu, Bigtable cho phần lưu trữ
Vì sao đúng
Nền tảng giao dịch xử lý hàng triệu giao dịch mỗi giây thì hai chỗ dễ vỡ nhất là khâu nhận và khâu ghi. Pub/Sub hấp thụ được luồng ở quy mô đó mà không mất tin. Bigtable ghi được hàng triệu thao tác mỗi giây với độ trễ mili giây ổn định, và mô hình dữ liệu chuỗi thời gian của nó khớp đúng với dữ liệu giao dịch.
Vì sao các phương án khác sai
- B. BigQuery cho cả lưu trữ lẫn xử lý — BigQuery mạnh về phân tích nhưng không phục vụ được truy vấn độ trễ thấp ở đường nóng.
- D. Spanner cộng Dataflow — Spanner cho nhất quán mạnh nhưng thông lượng ghi không đạt mức hàng triệu mỗi giây như Bigtable.
- A. Datastore cộng Cloud Functions — cả hai đều không kham nổi quy mô này.
You are working with an organization to structure their BigQuery permissions. The company has three teams: data analysts, data scientists, and data engineers. The data analysts should be able to run SQL queries, the data scientists need to create and run machine learning models in BigQuery, and the data engineers should have full control over BigQuery resources. What is the most appropriate IAM role assignment for these teams?
-
A
Assign the roles/bigquery.dataViewer role to the data analysts, roles/bigquery.mlUser role to the data scientists, and roles/bigquery.dataOwner role to the data engineers.
-
B
Assign the roles/bigquery.dataEditor role to the data analysts, roles/bigquery.mlUser role to the data scientists, and roles/bigquery.admin role to the data engineers.
-
C
Assign the roles/bigquery.user role to the data analysts, roles/bigquery.mlUser role to the data scientists, and roles/bigquery.admin role to the data engineers.
-
D
Assign the roles/bigquery.jobUser role to the data analysts, roles/bigquery.mlUser role to the data scientists, and roles/bigquery.dataEditor role to the data engineers.
Xem giải thích
Đáp án
C — bigquery.user cho nhà phân tích, bigquery.mlUser cho nhà khoa học dữ liệu, bigquery.admin cho kỹ sư dữ liệu
Vì sao đúng
Điểm mấu chốt nằm ở vai của nhà phân tích, và đây là chỗ hay nhầm nhất trong IAM của BigQuery:
| Vai | Cho phép |
|---|---|
dataViewer |
Đọc dữ liệu, nhưng không chạy được truy vấn vì không tạo được job |
jobUser |
Chạy job, nhưng không đọc được dữ liệu nào |
user |
Cả hai — chạy truy vấn trên dữ liệu mình được phép đọc |
Nhà phân tích cần chạy SQL, nên phải là user. mlUser cho phép tạo và chạy mô hình học máy, đúng nhu cầu nhà khoa học dữ liệu. admin là toàn quyền, đúng cho kỹ sư dữ liệu.
Vì sao các phương án khác sai
- A.
dataViewercho nhà phân tích — đọc được nhưng không chạy nổi truy vấn nào; đây là bẫy chính. - D.
jobUsercho nhà phân tích — chạy được job nhưng không đọc được dữ liệu; hỏng theo chiều ngược lại. VaidataEditorcho kỹ sư cũng thiếu so với "toàn quyền". - B.
dataEditorcho nhà phân tích — cho quyền sửa dữ liệu, vượt xa nhu cầu chỉ chạy truy vấn.
A government agency runs a static content website to share weather alerts and emergency information with the public. The website currently runs on-premises and is overwhelmed during peak events such as natural disasters, leading to frequent downtime. Additionally, the agency wants to ensure global access with minimal latency and must protect the site from large-scale distributed denial-of-service (DDoS) attacks. You are tasked with migrating this website to Google Cloud with minimal changes to the existing content. What should you do?
-
A
Migrate the application to App Engine Standard Environment with autoscaling enabled and use a global internal HTTP(S) load balancer.
-
B
Deploy the website using Cloud Run and use Identity-Aware Proxy (IAP) to secure access.
-
C
Move the static content to a Compute Engine instance behind a global HTTP(S) load balancer, and configure Cloud Armor to mitigate DDoS attacks.
-
D
Migrate the website to a Google Cloud Storage bucket, configure it to serve static website content, and place it behind Cloud CDN with Google Cloud Armor.
Xem giải thích
Đáp án
D — Chuyển trang web sang một bucket Cloud Storage, cấu hình phục vụ nội dung tĩnh
Vì sao đúng
Đề nói rõ đây là trang nội dung tĩnh và nó đang quá tải. Cloud Storage phục vụ nội dung tĩnh với chi phí thấp nhất và khả năng chịu tải gần như không giới hạn — không có máy chủ nào để quá tải cả. Đây đúng là tình huống mà cảnh báo thời tiết khẩn cấp cần: lượng truy cập bùng nổ đúng lúc sự kiện xảy ra, mà hệ thống vẫn phải đứng vững.
Vì sao các phương án khác sai
- A. App Engine Standard — chạy được nhưng là nền tảng cho ứng dụng động; trả tiền tính toán cho thứ không cần tính toán gì.
- C. Máy ảo sau load balancer — vẫn có máy chủ để quá tải, và phải vận hành nó.
- B. Cloud Run với IAP — Cloud Run cũng thừa cho nội dung tĩnh, còn IAP thì sai hẳn mục đích: đây là trang công khai cho toàn dân, không phải trang cần xác thực.
As a cloud architect, you are working with a company to deploy their multi-tier application on Google Kubernetes Engine (GKE). The application includes a front-end service that needs to maintain high availability. The company has requested that at least five replicas of the front-end service run at all times to meet their availability requirements. Which field in the Kubernetes deployment manifest should you use to specify this requirement?
-
A
metadata.scale -
B
spec.pods -
C
metadata.replicas -
D
spec.replicas
Xem giải thích
Đáp án
D — spec.replicas
Vì sao đúng
Trong manifest của Kubernetes, spec mô tả trạng thái mong muốn của đối tượng, còn metadata chứa thông tin nhận dạng như tên, nhãn và không gian tên. Số bản sao là trạng thái mong muốn, nên nó nằm ở spec.replicas:
apiVersion: apps/v1
kind: Deployment
metadata:
name: frontend
spec:
replicas: 3
Vì sao các phương án khác sai
- C.
metadata.replicas— sai vị trí:metadatakhông mô tả hành vi mong muốn. - A.
metadata.scalevà B.spec.pods— không phải trường có thật trong manifest của Deployment.
As a cloud architect, you are working with a media company that runs a complex application on a Kubernetes cluster in Google Kubernetes Engine (GKE). After evaluating the application's resource usage over the past few months, you've determined that the cluster is over-provisioned and you need to resize it to save costs. The application is stateless, and there are no user sessions to maintain. The application is also globally distributed and must maintain high availability during the resizing process. What is the best approach to resize the cluster?
-
A
Manually remove nodes from the existing cluster until you reach the desired size.
-
B
Delete the existing cluster and create a new one with fewer nodes.
-
C
Use the
gcloud container clusters resizecommand to reduce the number of nodes in the cluster. -
D
Adjust the number of vCPUs and memory allocated to each node in the cluster.
Xem giải thích
Đáp án
C — Dùng lệnh gcloud container clusters resize để giảm số node
Vì sao đúng
Đây là lệnh dựng riêng cho việc thay đổi số node của một node pool. Nó xử lý đúng cách: rút cạn node trước khi gỡ, tức là các pod đang chạy trên đó được chuyển sang node khác trước, nên ứng dụng không gián đoạn. Cụm vẫn chạy suốt quá trình.
Vì sao các phương án khác sai
- A. Gỡ node bằng tay từng cái — không có bước rút cạn, nên pod đang chạy bị giết đột ngột; ngoài ra bộ quản lý node pool sẽ tự tạo lại node cho đủ số đã khai.
- B. Xoá cụm rồi tạo cụm mới nhỏ hơn — gây gián đoạn hoàn toàn và phải triển khai lại mọi thứ.
- D. Chỉnh vCPU và bộ nhớ của từng node — đó là đổi loại máy, không phải giảm số lượng node như đề hỏi.