Ngân hàng đề — Google Professional Cloud Architect

Tìm thấy 420 câu.

Câu 231

For this question, refer to the Altostrat Media case study.

https://services.google.com/fh/files/misc/v6.1_pca_altostrat_media_case_study_english.pdf


Altostrat runs a large number of containerized microservices on GKE to support content ingestion, recommendation engines, and user-facing APIs. Currently, each engineering team maintains its own CI/CD pipelines using different tools and custom scripts. This has led to inconsistent deployment practices, limited visibility into releases, and increased risk during production rollouts.

Altostrat wants to standardize CI/CD across all teams, enforce consistent security and quality checks, and maintain a single, centralized management platform for container builds and deployments—while minimizing operational overhead. Which approach best meets Altostrat’s requirements?

  1. A

    Use Jenkins deployed on GKE for all pipelines, with container images stored on local cluster storage

  2. B

    Replace GKE with Compute Engine–based container deployments managed by startup scripts and instance groups

  3. C

    Allow each team to continue using its own CI/CD tools and enforce standards through documentation and periodic audits

  4. D

    Standardize on Cloud Build for CI, store images in Artifact Registry, and use Cloud Deploy to manage progressive rollouts to GKE clusters

Xem giải thích

Đáp án

D — Chuẩn hoá về Cloud Build cho CI, lưu ảnh trong Artifact Registry

Vì sao đúng

Vấn đề là mỗi đội một công cụ một kiểu. Chuẩn hoá về dịch vụ được quản lý giải quyết cả hai vế: Cloud Build cho một cách dựng thống nhất, tích hợp sẵn với IAM và nhật ký kiểm toán; Artifact Registry cho một nơi duy nhất chứa ảnh container, có quét lỗ hổng và phân quyền chi tiết. Không có máy chủ CI nào phải vá và không có kho ảnh nào nằm ngoài tầm kiểm soát.

Vì sao các phương án khác sai

  • A. Jenkins trên GKE với kho ảnh tự dựng — phải tự vận hành cả máy chủ CI lẫn kho ảnh, đúng thứ dịch vụ được quản lý bỏ đi.
  • B. Thay GKE bằng container trên máy ảo với startup script — đi lùi hẳn về mặt vận hành.
  • C. Để mỗi đội giữ công cụ riêng rồi ràng buộc bằng chính sách — không chuẩn hoá được thứ vốn cần chuẩn hoá; chính sách trên giấy không ngăn được sự khác biệt trong thực tế.
Câu 232

You are working with an organization that operates a complex microservices application on Google Kubernetes Engine (GKE). They want to utilize Service Mesh visualization in the Google Cloud Console to gain insights into their services' performance and interactions. However, after setting up their environment with Istio, they are unable to see any traffic flow between services. Which of the following could be a possible reason and the appropriate fix?

  1. A

    The Service Mesh visualization doesn't support GKE. They should use Stackdriver for visualizing service interactions.

  2. B

    Istio is not installed correctly. They should reinstall it and restart their services.

  3. C

    Service Mesh visualization does not support microservices. They should refactor their application into a monolith.

  4. D

    The required Envoy proxy sidecar containers might not have been injected into each relevant Kubernetes pod. They should ensure automatic or manual sidecar injection is configured.

Xem giải thích

Đáp án

D — Container sidecar Envoy có thể chưa được chèn vào các pod

Vì sao đúng

Service mesh nhìn thấy lưu lượng nhờ sidecar proxy chạy cạnh mỗi container ứng dụng: mọi kết nối vào ra đều đi qua Envoy, và chính nó báo cáo số liệu về. Không có sidecar thì mesh không có dữ liệu, nên màn hình trực quan hoá trống — đây là nguyên nhân phổ biến nhất.

Việc chèn sidecar thường được bật bằng nhãn trên namespace, và pod đã chạy từ trước không tự có sidecar — phải khởi động lại chúng sau khi bật.

Vì sao các phương án khác sai

  • A. Service Mesh không hỗ trợ GKE — sai; GKE là nền tảng được hỗ trợ tốt nhất.
  • B. Istio cài sai, phải cài lại — có thể xảy ra, nhưng cài lại là biện pháp mạnh tay khi nguyên nhân thường gặp hơn nhiều lại đơn giản hơn nhiều.
  • C. Không hỗ trợ microservice — sai; microservice chính là lý do service mesh tồn tại.
Câu 233

Your company is developing a new IoT application that is expected to produce massive amounts of data for real-time analytics and future predictive models. Currently, the IoT devices publish data to a Pub/Sub topic, which then triggers a Cloud Function to store the data in BigQuery. What can be done to enhance this solution as data volume increases?

  1. A

    Use Firestore to store IoT data because of its real-time capabilities.

  2. B

    Increase the memory and CPU allocated to the Cloud Function to process more data.

  3. C

    Migrate from BigQuery to Cloud SQL for data storage.

  4. D

    Migrate the data processing from Cloud Function to Dataflow to better manage streaming data.

Xem giải thích

Đáp án

D — Chuyển phần xử lý dữ liệu từ Cloud Function sang Dataflow

Vì sao đúng

Cloud Functions hợp cho việc ngắn, rời rạc, theo sự kiện. Ứng dụng IoT sinh dữ liệu liên tục ở khối lượng lớn thì nó vấp phải hàng loạt giới hạn: thời gian chạy tối đa, không có cửa sổ thời gian, không xử lý được dữ liệu tới muộn, và chi phí gọi hàm tăng tuyến tính theo số bản ghi.

Dataflow dựng đúng cho hình dạng đó: tự co giãn theo lưu lượng, có cửa sổ thời gian và xử lý trạng thái, xử lý được dữ liệu tới không đúng thứ tự — chuyện luôn xảy ra với cảm biến ở nhiều nơi.

Vì sao các phương án khác sai

  • B. Tăng bộ nhớ và CPU cho Cloud Function — nới trần một chút nhưng không đổi được bản chất mô hình xử lý.
  • A. Dùng Firestore để lưu dữ liệu IoT — không phải nơi chứa dữ liệu chuỗi thời gian khối lượng lớn.
  • C. Chuyển từ BigQuery sang Cloud SQL — bước lùi rõ rệt: Cloud SQL không kham nổi quy mô này.
Câu 234

You are preparing for a design review of a new multi-tier application on Google Cloud that uses Cloud Run, Cloud SQL, Memorystore, and Cloud Load Balancing. Your CTO wants to ensure that the design follows Google Cloud best practices for security, reliability, and cost optimization. You want to use Gemini Cloud Assist to quickly identify misconfigurations and get recommendations within the console before the review. How should you best use Gemini Cloud Assist in this scenario?

  1. A

    Ask Gemini Cloud Assist to review your existing cloud resources and configurations, then surface best-practice recommendations and potential misconfigurations.

  2. B

    Use Gemini Cloud Assist to automatically apply all recommended changes in production without human review.

  3. C

    Rely exclusively on Gemini Cloud Assist and stop running security or posture management tools like Security Command Center.

  4. D

    Use Gemini Cloud Assist only from your local IDE, so it has no access to your cloud project and cannot see any actual resource configuration.

Xem giải thích

Đáp án

A — Nhờ Gemini Cloud Assist rà soát tài nguyên và cấu hình hiện có

Vì sao đúng

Đây là cách dùng đúng của một trợ lý AI trong vận hành: nó đọc được cấu hình thật của các tài nguyên đang chạy, đối chiếu với thực hành tốt, và nêu ra những điểm đáng xem lại — nhanh hơn nhiều so với rà tay trước buổi duyệt thiết kế. Điểm quan trọng là nó đưa ra khuyến nghị, còn quyết định vẫn thuộc về con người.

Vì sao các phương án khác sai

  • B. Cho nó tự động áp mọi khuyến nghị lên production — bỏ hẳn khâu người xem xét, trên chính môi trường không được phép sai.
  • C. Dựa hẳn vào nó và bỏ các đợt rà soát bảo mật — trợ lý AI bổ sung cho quy trình, không thay thế được; và nó cũng có thể sai.
  • D. Chỉ dùng từ IDE, không cho truy cập tài nguyên — cắt mất đúng thứ làm nó hữu ích: khả năng nhìn vào cấu hình thật.
Câu 235

An analytics company has a batch data processing pipeline on a Compute Engine instance (n2-standard-16) using Debian Linux and writing large intermediate results to disk. The pipeline is experiencing write throughput bottlenecks. The team cannot shut down the VM or redesign the pipeline until the next planned release. They want to improve performance now with minimal cost. What should the team do?

  1. A

    Switch from zonal persistent disk to local SSD

  2. B

    Migrate the job to Dataproc and use HDFS

  3. C

    Resize the existing persistent disk from 200 GB to 1 TB

  4. D

    Use snapshots to create a disk clone and attach it as additional storage

Xem giải thích

Đáp án

C — Nới đĩa bền hiện có từ 200 GB lên 1 TB

Vì sao đúng

Trên đĩa bền của Google Cloud, IOPS và thông lượng tỉ lệ thuận với dung lượng. Công việc trong đề ghi kết quả trung gian lớn xuống đĩa, nên nút thắt nằm ở tầng lưu trữ — và nới đĩa từ 200 GB lên 1 TB nâng trần hiệu năng lên gấp năm, kể cả khi bạn không cần thêm chỗ chứa. Thao tác này làm được khi máy đang chạy, không phải dừng gì.

Vì sao các phương án khác sai

  • A. Chuyển sang local SSD — nhanh hơn thật, nhưng dữ liệu mất khi máy dừng; với công việc theo lô chạy dài thì đó là rủi ro lớn.
  • B. Chuyển sang Dataproc dùng HDFS — thay đổi kiến trúc rất lớn cho một vấn đề chỉnh được bằng một thao tác.
  • D. Tạo bản sao đĩa từ snapshot rồi gắn thêm — thêm dung lượng nhưng không tự nó gộp hiệu năng; và đây là cách phức tạp hơn hẳn việc nới chính đĩa đang dùng.
Câu 236

You are the lead architect at a large healthcare company that is transitioning its on-premises infrastructure to Google Cloud. Your team has successfully migrated several applications, but some stakeholders are resistant to adopting cloud-native technologies due to concerns about security, compliance, and operational complexity. The company plans to roll out a new patient portal that will leverage AI to improve patient care and diagnostics. As a cloud architect, your role includes not only designing the solution but also advocating for the adoption of cloud-native technologies across the organization. Which approach would best help you advocate for the adoption of cloud-native technologies while addressing the stakeholders' concerns?

  1. A

    Develop a detailed technical whitepaper outlining the benefits of cloud-native technologies, including cost savings, scalability, and security features, and distribute it to all stakeholders.

  2. B

    Focus on implementing the cloud-native solution with minimal input from resistant stakeholders to showcase the results and prove the technology's value through a successful launch.

  3. C

    Engage with a third-party consultant to independently validate the security and compliance aspects of the cloud-native architecture and present the findings to the stakeholders.

  4. D

    Conduct a series of workshops with stakeholders to demonstrate how Google Cloud's security features and compliance tools meet or exceed existing on-premises solutions.

Xem giải thích

Đáp án

D — Tổ chức chuỗi hội thảo với các bên liên quan để trình bày cách Google Cloud đáp ứng yêu cầu của họ

Vì sao đúng

Điểm chặn ở đây không phải kỹ thuật mà là con người — có những bên đang phản đối. Hội thảo giải quyết đúng chuyện đó: nó là kênh hai chiều, nên bạn nghe được mối lo thật của từng bên (thường là về tuân thủ, về mất kiểm soát, hoặc về kỹ năng), rồi trả lời trực tiếp mối lo đó. Người được lắng nghe và được thấy giải pháp áp vào chính vấn đề của mình thì mới đổi ý.

Vì sao các phương án khác sai

  • A. Viết một tài liệu kỹ thuật — một chiều; người đang phản đối thường không đọc, và có đọc cũng không được giải đáp mối lo riêng.
  • B. Cứ triển khai, ít hỏi ý những bên phản đối — đẩy xung đột về sau, và họ sẽ chặn ở khâu phê duyệt hoặc vận hành.
  • C. Thuê tư vấn bên ngoài thẩm định — có ích cho phần bằng chứng, nhưng không thay được việc đối thoại trực tiếp.
Câu 237

A large healthcare organization is looking to build a secure and scalable platform for storing and analyzing medical records. The platform must meet the following requirements:

  • support high volumes of medical records with low latency

  • ensure secure storage and processing of sensitive medical information

  • enable real-time data analysis and reporting on patient health and treatment outcomes

  • minimize downtime during maintenance and upgrades

  • minimize costs while still providing high performance

Which solution would you recommend to meet these requirements?

  1. A

    Implementing a custom-built solution using Cloud Pub/Sub for real-time data processing, Bigtable for data storage, and Google Kubernetes Engine (GKE) for deployment and scaling.

  2. B

    Implementing a serverless solution using Cloud Functions for data processing,  Cloud Firestore for data storage, and Cloud Pub/Sub for real-time data processing.

  3. C

    Implementing a managed solution using Cloud Healthcare API for data analysis, Cloud Storage for data storage, and Cloud Load Balancing for high-availability data access.

  4. D

    Implementing a hybrid solution using Compute Engine for data processing, Cloud SQL for data storage, and BigQuery for real-time analytics.

Xem giải thích

Đáp án

C — Giải pháp được quản lý dùng Cloud Healthcare API

Vì sao đúng

Hồ sơ y tế có yêu cầu riêng mà kho lưu trữ đa năng không đáp ứng được: hiểu các chuẩn FHIR, HL7v2, DICOM, kiểm soát truy cập ở mức phù hợp với quy định, và nhật ký kiểm toán đầy đủ. Cloud Healthcare API có sẵn tất cả, đồng thời nối thẳng sang BigQuery để phân tích và sang Cloud DLP để khử định danh — nên vừa an toàn vừa dùng được cho nghiên cứu.

Vì sao các phương án khác sai

  • A. Tự xây trên Pub/Sub — Pub/Sub chỉ truyền thông điệp; phần lưu trữ, chuẩn dữ liệu và tuân thủ phải tự làm hết.
  • B. Cloud Functions không máy chủ — lo phần tính toán, bỏ ngỏ phần lưu trữ và tuân thủ.
  • D. Máy ảo cộng Cloud SQL — không hiểu định dạng y tế, và toàn bộ gánh nặng tuân thủ dồn lên đội của bạn.
Câu 238

You are a cloud architect tasked with architecting a data storage solution for a media company. The company has the following data storage requirements:

  • store large media files that are regularly accessed for the first month

  • archive media files that have not been accessed for over a year

  • ensure redundancy and high availability

  • keep costs optimized based on the frequency of data access

Which combination of storage classes should be used for Google Cloud Storage to meet these requirements?

  1. A

    Use Multi-Regional Storage for the large media files and Coldline Storage for archiving files not accessed in over a year.

  2. B

    Use Nearline Storage for all media files and enable Object Lifecycle Management to change the storage class to Coldline for files not accessed in over a year.

  3. C

    Use Standard Storage for the large media files and enable Object Lifecycle Management to change the storage class to Archive for files not accessed in over a year.

  4. D

    Use Standard Storage for all media files and enable Object Lifecycle Management to change the storage class to Nearline for files not accessed in over a year.

Xem giải thích

Đáp án

C — Standard cho tệp phương tiện lớn, kèm Object Lifecycle Management chuyển sang Archive sau một năm không truy cập

Vì sao đúng

Đề cho ba mốc và đáp án phải khớp cả ba:

  • Truy cập đều trong tháng đầu → Standard, vì lớp này không có phí truy xuất và không ràng buộc thời gian lưu tối thiểu.
  • Không đụng tới hơn một năm → Archive, vì đó chính là lớp dành cho nhịp truy cập ít hơn một lần mỗi năm, và là lớp rẻ nhất.
  • Dư thừa và sẵn sàng cao → Cloud Storage đã có sẵn ở mọi lớp.

Vì sao các phương án khác sai

  • D. Chuyển sang Nearline — Nearline dành cho nhịp khoảng hàng tháng, quá đắt cho dữ liệu cả năm không ai xem.
  • A. Chuyển sang Coldline — Coldline dành cho nhịp hàng quý, vẫn đắt hơn Archive ở trường hợp này.
  • B. Để mọi thứ ở Nearline ngay từ đầu — tháng đầu tệp được truy cập đều, mà Nearline có phí truy xuất và ràng buộc lưu tối thiểu 30 ngày; sẽ tốn hơn Standard.
Câu 239

Your organization is planning to create a custom VPC network on Google Cloud for deploying a multi-tier application. The application includes frontend servers, backend servers, and database servers, each of which requires a separate subnet. What considerations should you keep in mind while creating this VPC?

  1. A

    Assign one large CIDR block to the VPC and divide it into smaller CIDR blocks for each subnet.

  2. B

    Use Shared VPC to host all the tiers of the application.

  3. C

    Use Cloud NAT for the frontend servers to connect with the internet.

  4. D

    Use the same CIDR block for all the subnets.

Xem giải thích

Đáp án

A — Cấp một khối CIDR lớn cho VPC rồi chia thành các khối nhỏ hơn cho từng subnet

Vì sao đúng

Quy hoạch địa chỉ là việc phải làm trước và làm đúng ngay, vì sửa về sau rất tốn. Cách đúng là lấy một dải lớn rồi chia cho từng tầng, với hai lợi ích: các subnet không chồng lấn nhau, và bạn chừa sẵn chỗ cho những subnet sẽ thêm sau mà không phải đánh lại địa chỉ.

Vì sao các phương án khác sai

  • D. Dùng chung một khối CIDR cho mọi subnet — không hợp lệ: các subnet trong cùng VPC không được chồng dải địa chỉ.
  • B. Dùng Shared VPC — cơ chế chia sẻ mạng giữa các dự án; đề chỉ nói về một ứng dụng nhiều tầng, chưa cần tới.
  • C. Dùng Cloud NAT cho tầng giao diện — Cloud NAT cho máy không có IP công khai đi ra Internet; đó là một chi tiết triển khai, không phải câu trả lời cho việc quy hoạch mạng.
Câu 240

Your SRE team wants to reduce MTTR for a GKE-based payments system. They currently pivot across logs and metrics manually. They want to ask Gemini Cloud Assist questions like “Why did latency spike last night?” and get guided analysis across logs, metrics, and related config—without giving them overly broad IAM permissions. What should you do?

  1. A

    Export all logs to BigQuery and rely on Gemini to analyze them via SQL only.

  2. B

    Enable Gemini Cloud Assist at the billing account level—this automatically grants SREs access to all telemetry in all projects.

  3. C

    Use Gemini Code Assist in the IDE to summarize stack traces for production debugging.

  4. D

    Enable Cloud Hub and Gemini Cloud Assist, ensure logging/monitoring ingestion is set up, and assign least-privilege observability + Gemini roles to the SREs.

Xem giải thích

Đáp án

D — Bật Cloud Hub và Gemini Cloud Assist, đảm bảo dữ liệu log và số liệu được thu thập đầy đủ

Vì sao đúng

Trợ lý AI chỉ trả lời được câu hỏi vận hành khi nó có dữ liệu để đọc. Vì vậy điều kiện tiên quyết là log và số liệu phải được thu thập đầy đủ từ cụm GKE và các dịch vụ liên quan; bật trợ lý mà thiếu dữ liệu nguồn thì nó chỉ đoán. Cloud Hub gom bức tranh vận hành về một chỗ, và đó chính là thứ giúp giảm thời gian khôi phục — đội không phải nhảy qua lại giữa nhiều màn hình nữa.

Vì sao các phương án khác sai

  • A. Xuất hết log sang BigQuery rồi chỉ phân tích bằng SQL — bỏ mất phần số liệu và phần ngữ cảnh vận hành thời gian thực.
  • B. Bật ở mức tài khoản thanh toán là tự động có quyền — sai: quyền truy cập dữ liệu vẫn do IAM quyết định, bật ở mức thanh toán không cấp quyền gì.
  • C. Dùng Gemini Code Assist trong IDE — công cụ hỗ trợ viết mã, không phải công cụ chẩn đoán sự cố production.