Ngân hàng đề — Google Professional Cloud Architect
Tìm thấy 420 câu.
You have a web application operating on a Managed Instance Group, which receives a high volume of requests every minute. Your objective is to apply patches to the application without reducing the number of instances in the MIG. What action should you take?
-
A
You should deploy the update in a new Managed Instance Group and add it as a backend service to the existing production Load Balancer. Then remove the old Managed Instance Group from the Load Balancer backend and remove the group.
-
B
You should update the existing Managed Instance Group to point to a new instance template containing the updated version. Terminate all existing instances in this group and wait until they are all replaced by new instances created from the new template.
-
C
You should perform a rolling-action start-update with
max-unavailableset to 0 andmax-surgeset to 1. -
D
You should perform a rolling-action start-update with
max-unavailableset to 1 andmax-surgeset to 0.
Xem giải thích
Đáp án
C — rolling-action start-update với max-unavailable đặt bằng 0
Vì sao đúng
Đề đòi vá ứng dụng mà không mất bản chạy nào trong khi lưu lượng vẫn cao. max-unavailable=0 diễn đạt đúng ràng buộc đó: nhóm phải tạo máy mới trước, chờ nó qua health check, rồi mới gỡ máy cũ. Nhờ vậy tổng năng lực phục vụ không bao giờ tụt xuống dưới mức ban đầu.
Cái giá phải trả là trong lúc cập nhật, nhóm tạm thời có nhiều máy hơn bình thường — tức là tốn thêm một chút, đổi lấy việc không gián đoạn.
Vì sao các phương án khác sai
- D.
max-unavailable=1— cho phép một máy ngừng phục vụ tại mỗi thời điểm; với lưu lượng rất cao thì đó là phần năng lực bị mất thật. - A. Dựng nhóm mới rồi thêm làm backend — về bản chất là blue/green, làm được nhưng tốn gấp đôi tài nguyên và cần thao tác tay chuyển lưu lượng.
- B. Trỏ nhóm hiện có sang instance template mới — chỉ khai template mới thôi thì máy đang chạy không tự đổi; vẫn phải khởi động một đợt cập nhật.
Your company's data science team anticipates a significant increase in the number and complexity of machine learning (ML) models they plan to train over the next year. Currently, the team uses Compute Engine instances for training. What would be the best approach to accommodate this increase?
-
A
Use AI Platform Training to offload and scale model training tasks.
-
B
Upgrade the Compute Engine instances to have more CPUs and more memory.
-
C
Use Cloud Functions to train individual models in response to events.
-
D
Increase the disk size for the Compute Engine instances to store more training data.
Xem giải thích
Đáp án
A — Dùng AI Platform Training để đẩy việc huấn luyện ra ngoài và co giãn theo nhu cầu
Vì sao đúng
Vấn đề là số lượng và độ phức tạp mô hình sẽ tăng mạnh, trong khi đội đang huấn luyện trên máy ảo cố định. Dịch vụ huấn luyện được quản lý giải đúng chỗ: tài nguyên được cấp cho từng công việc huấn luyện rồi trả lại khi xong, nên chạy nhiều mô hình song song mà không phải giữ máy nhàn rỗi giữa các đợt. Nó cũng lo sẵn phần huấn luyện phân tán và tinh chỉnh siêu tham số.
Vì sao các phương án khác sai
- B. Nâng cấu hình máy ảo — mở rộng theo chiều dọc có trần, và bạn vẫn trả tiền cho máy lúc không huấn luyện gì.
- C. Dùng Cloud Functions để huấn luyện từng mô hình — giới hạn thời gian chạy và không có GPU; không huấn luyện được.
- D. Tăng dung lượng đĩa — giải quyết chỗ chứa, không giải quyết năng lực tính toán.
A financial services company operates a critical on-premises application that handles sensitive customer data and must comply with strict regulatory requirements. The company plans to extend its infrastructure to Google Cloud to take advantage of cloud scalability for non-sensitive workloads. However, the on-premises environment must continue to interact securely and efficiently with the cloud environment. The company also needs to ensure low-latency connections between the on-premises data center and Google Cloud for seamless operation of hybrid workloads. Which networking solution would best meet the company’s requirements for a secure and low-latency hybrid environment?
-
A
Implement Cloud Interconnect with a Partner Interconnect service to establish a dedicated connection with SLA guarantees, ensuring low-latency and high-availability communication.
-
B
Set up a Cloud VPN tunnel between the on-premises data center and Google Cloud, ensuring all data is encrypted during transit.
-
C
Establish a multi-region VPC peering between Google Cloud and the on-premises data center to ensure low-latency communication across all locations.
-
D
Use Direct Peering to establish a private connection between the on-premises data center and Google Cloud, ensuring low-latency communication.
Xem giải thích
Đáp án
A — Cloud Interconnect ở dạng Partner Interconnect
Vì sao đúng
Công ty tài chính có dữ liệu nhạy cảm và yêu cầu tuân thủ nghiêm, nên lưu lượng không nên đi qua Internet công cộng. Partner Interconnect cho kết nối riêng vào VPC thông qua một nhà cung cấp đối tác — phù hợp khi công ty không có mặt tại cơ sở colocation của Google hoặc nhu cầu băng thông chưa tới ngưỡng của Dedicated Interconnect, mà vẫn đạt yêu cầu về đường truyền riêng.
Vì sao các phương án khác sai
- B. Cloud VPN — có mã hoá nhưng vẫn chạy trên Internet công cộng, nên độ trễ biến động và thường không thoả yêu cầu tuân thủ về đường truyền riêng.
- C. VPC peering với trung tâm dữ liệu tại chỗ — peering chỉ nối hai VPC trong Google Cloud.
- D. Direct Peering — cho truy cập dịch vụ công khai của Google, không vào được VPC riêng của bạn.
You are tasked with designing a scalable compute architecture for a new media streaming service that your company is launching. The service will be available globally and is expected to handle millions of users streaming video content simultaneously. The content is primarily video-on-demand (VoD), but there will also be live events that require real-time streaming. The solution must be cost-efficient while ensuring low latency and high availability. You need to select appropriate compute resources that can handle both the VoD and live streaming workloads. Which two compute solutions should you choose to meet these requirements? (Choose two)
-
A
Use Google Kubernetes Engine (GKE) with autoscaling enabled to manage containerized microservices for video encoding and streaming.
-
B
Deploy preemptible VM instances for all workloads to reduce costs.
-
C
Use Compute Engine instances in a managed instance group with autoscaling enabled.
-
D
Deploy the entire workload on a single large Compute Engine instance with local SSD for low-latency storage.
-
E
Use Cloud Run for serving the video content, scaling automatically based on the number of incoming requests.
Xem giải thích
Đáp án
A và C — GKE có tự co giãn, và managed instance group có tự co giãn
Vì sao đúng
Đề hỏi kiến trúc tính toán co giãn được cho dịch vụ phát video toàn cầu, và hai phương án này là hai cách hợp lệ để đạt điều đó:
- A. GKE với tự co giãn — hợp cho phần đã đóng gói container, co giãn ở cả mức pod và mức node.
- C. Managed instance group với tự co giãn — hợp cho phần chạy trên máy ảo, tự thêm bớt máy theo tải và tự thay máy hỏng.
Điểm chung là cả hai đều tự co giãn và tự chữa lành, đúng thứ dịch vụ toàn cầu cần.
Vì sao các phương án khác sai
- B. Dùng máy preemptible cho mọi khối lượng công việc — máy bị thu hồi bất cứ lúc nào; không hợp cho dịch vụ đang phục vụ người xem.
- D. Một máy ảo lớn duy nhất với local SSD — điểm hỏng duy nhất, không co giãn, và local SSD mất dữ liệu khi máy dừng.
- E. Cloud Run để phục vụ chính nội dung video — Cloud Run mạnh cho dịch vụ HTTP ngắn; luồng video là kết nối dài và nặng băng thông, thường phục vụ từ Cloud Storage qua CDN thì đúng hơn.
A multinational retail company wants to implement a new e-commerce platform that can handle high traffic and provide real-time recommendations to users. The platform should also be able to track user behavior and provide insights into customer preferences. The company wants to use the Google Cloud Platform for this implementation. Which of the following options would be the best solution for this requirement?
-
A
Use Cloud SQL to store customer data, Cloud Pub/Sub to ingest customer data, and Cloud Dataflow to process customer analytics.
-
B
Use Cloud Firestore to store customer data, Cloud Functions to process customer data, and Cloud Datalab to store customer analytics.
-
C
Use Cloud Bigtable to store customer data, Cloud Pub/Sub to ingest customer data, and Cloud Functions to process customer analytics.
-
D
Use Cloud Storage to store customer data, Cloud Functions to process customer data, and Cloud Datastore to store analytics data.
Xem giải thích
Đáp án
A — Cloud SQL lưu dữ liệu khách hàng, Pub/Sub nhận dữ liệu, Dataflow xử lý phân tích
Vì sao đúng
Điểm mạnh của phương án này là đường ống phân tích hoàn chỉnh và đúng vai: Pub/Sub hấp thụ luồng sự kiện hành vi người dùng, Dataflow xử lý luồng đó để sinh dữ liệu cho phần gợi ý thời gian thực. Ba phương án còn lại đều đứt gãy ở chính khâu này.
Vì sao các phương án khác sai
- B. Dùng Cloud Datalab để lưu dữ liệu phân tích — Datalab là công cụ notebook cho nhà khoa học dữ liệu, hoàn toàn không phải nơi lưu trữ. Đây là lỗi nặng nhất trong bốn phương án.
- C. Dùng Cloud Functions để xử lý phân tích — hàm ngắn theo sự kiện, không có cửa sổ thời gian và không xử lý được dữ liệu tới muộn như một đường ống luồng thật.
- D. Cloud Storage lưu dữ liệu khách hàng, Datastore lưu phân tích — Cloud Storage là kho đối tượng, không truy vấn được dữ liệu khách hàng theo cách ứng dụng cần.
Một điểm cần nói thẳng
Cloud SQL không phải lựa chọn mạnh nhất cho tầng dữ liệu của một sàn thương mại điện tử lưu lượng cao — Spanner hay Firestore mở rộng tốt hơn. Câu này đúng theo kiểu loại trừ: ba phương án kia có lỗi rõ ràng hơn hẳn ở khâu xử lý phân tích.
Your client is a manufacturer that collects temperature and vibration data from thousands of IoT sensors embedded in machines across several factories. They want to analyze this data in near real-time to detect equipment anomalies and generate alerts within 30 seconds of unusual readings. However, the client also wants to run nightly batch reports for historical trends and machine health scoring. What architecture should you recommend to meet both real-time and batch processing needs efficiently?
-
A
Use Cloud Dataproc for real-time alerts and Cloud Composer for batch ETL
-
B
Use Cloud Dataflow with a unified pipeline for streaming and batch processing
-
C
Use only Cloud Storage and schedule Dataflow batch jobs to run every 30 seconds
-
D
Use BigQuery for both streaming ingestion and historical batch queries
Xem giải thích
Đáp án
B — Dùng Cloud Dataflow với một đường ống thống nhất cho cả luồng lẫn lô
Vì sao đúng
Đề có hai nhu cầu: cảnh báo thời gian thực trên dữ liệu cảm biến, và phân tích lịch sử. Điểm mạnh riêng của Dataflow là mô hình Apache Beam cho phép viết một lần, chạy được cả hai chế độ — cùng một logic biến đổi dùng cho luồng trực tiếp và cho việc chạy lại trên dữ liệu cũ. Nhờ vậy không có nguy cơ hai đường ống cho ra hai kết quả khác nhau, thứ rất hay xảy ra khi tách riêng.
Vì sao các phương án khác sai
- A. Dataproc cho cảnh báo, Composer cho ETL — hai công cụ, hai đoạn logic phải giữ đồng bộ với nhau; Dataproc cũng không phải công cụ xử lý luồng độ trễ thấp.
- C. Lên lịch chạy job Dataflow mỗi 30 giây — đó là giả lập thời gian thực bằng cách chạy lô liên tục: tốn kém và vẫn có độ trễ.
- D. Dùng BigQuery cho cả nạp luồng lẫn truy vấn lịch sử — BigQuery nhận được dữ liệu theo luồng, nhưng nó là kho phân tích chứ không phải nơi xử lý luồng và phát cảnh báo.
Your company has a massive amount of data (approx 50 TB) in its on-premises data center, which needs to be transferred to Cloud Storage for further analysis and machine learning processing. Due to security concerns, your company has decided not to use physical data transfer services like Transfer Appliance. Your company has a very high-speed internet connection, but the rate of data generation is also high, leading to a shrinking time window for data transfer. What would be the best way to migrate this data over the internet in a reasonable amount of time?
-
A
Use Storage Transfer Service with Cloud VPN for secure data transfer.
-
B
Use a combination of Google Cloud's Data Transfer Service and gsutil for multi-threaded transfers.
-
C
Use Cloud Dataflow to transfer the data.
-
D
Use gsutil with multi-threaded/multi-processing options to copy data directly into Cloud Storage.
Xem giải thích
Đáp án
A — Storage Transfer Service kết hợp Cloud VPN để truyền an toàn
Vì sao đúng
Với 50 TB, chuyển qua mạng vẫn khả thi nếu băng thông đủ — đề không nói đường truyền chậm. Khi đó Storage Transfer Service là công cụ đúng: nó là dịch vụ được quản lý, tự thử lại khi lỗi, kiểm tra toàn vẹn bằng checksum, chạy song song nhiều luồng, và ở những lần sau chỉ chuyển phần thay đổi. Cloud VPN lo phần đường truyền riêng tư.
Vì sao các phương án khác sai
- D.
gsutilvới nhiều luồng — làm được nhưng bạn tự lo việc theo dõi tiến độ, tự xử lý khi đứt giữa chừng, và tự kiểm tra toàn vẹn. Ở mức 50 TB thì việc đứt giữa chừng là chắc chắn xảy ra. - B. Trộn hai công cụ lại — thêm phức tạp mà không được lợi gì.
- C. Cloud Dataflow — công cụ xử lý dữ liệu, không phải công cụ vận chuyển.
Your organization uses Google Kubernetes Engine (GKE) for its microservices-based application. The number of services is expected to grow significantly over the next two years. What would be the best approach to ensure manageability and operational efficiency as the number of services increases?
-
A
Implement Cloud Logging for better log management.
-
B
Increase the size of the GKE cluster nodes to accommodate the growing number of services.
-
C
Migrate to Compute Engine instances to reduce the complexity of managing Kubernetes.
-
D
Implement a Service Mesh using Istio for fine-grained control and observability.
Xem giải thích
Đáp án
D — Triển khai service mesh bằng Istio để kiểm soát chi tiết và quan sát được
Vì sao đúng
Vấn đề của đề không phải tài nguyên mà là số lượng dịch vụ sẽ tăng mạnh. Khi đó những chuyện trước đây làm bằng tay trở nên không kham nổi: mã hoá giữa các dịch vụ, chính sách ai gọi được ai, thử lại và ngắt mạch, chia lưu lượng khi phát hành. Service mesh đưa tất cả những thứ đó xuống tầng hạ tầng, nên không phải sửa mã của từng dịch vụ, và cho quan sát được toàn bộ luồng gọi.
Vì sao các phương án khác sai
- A. Triển khai Cloud Logging — hữu ích, nhưng log không cho biết dịch vụ nào gọi dịch vụ nào và tốn bao lâu ở mỗi chặng.
- B. Tăng kích thước node — giải quyết chuyện tài nguyên, không giải quyết chuyện quản trị số lượng dịch vụ.
- C. Chuyển về máy ảo cho đỡ phức tạp — bỏ đi khả năng điều phối, khiến vấn đề nặng hơn hẳn khi số dịch vụ tăng.
Your organization has launched a video streaming service on Google Cloud, and it is currently in public beta. Before scaling globally, you want to define Service Level Objectives (SLOs) to ensure the quality of service for end-users. What should you do?
-
A
Define one SLO as service availability that matches the SLA of Google Cloud's Compute Engine. Define the other SLO as a maximum response time of 500 ms for all API requests.
-
B
Define one SLO as 95% of API calls complete within 200 ms. Define the other SLO as 95% of video streams maintain a bitrate of at least 5 Mbps.
-
C
Define one SLO as 99% of video streams start playback within 2 seconds. Define the other SLO as 99% of streaming sessions maintain less than 1% buffering.
-
D
Define one SLO as 99.9% service uptime over a month. Define the other SLO as all streaming sessions must achieve zero buffering.
Xem giải thích
Đáp án
C — Một SLO là 99% luồng video bắt đầu phát trong vòng 2 giây
Vì sao đúng
SLO tốt phải đo thứ người dùng thật sự cảm nhận được. Với dịch vụ phát video, trải nghiệm quyết định chính là bao lâu thì video bắt đầu chạy — người xem bỏ đi vì màn hình quay vòng, chứ không vì một con số uptime trên bảng điều khiển. Mức 99% cũng hợp lý: đủ cao để có ý nghĩa, và chừa lại 1% làm ngân sách lỗi để đội còn phát hành được.
Vì sao các phương án khác sai
- A. Lấy SLA của dịch vụ Google Cloud làm SLO — SLO phải nói về dịch vụ của bạn, mà dịch vụ của bạn luôn kém tin cậy hơn tổng các thành phần nó phụ thuộc; đặt bằng SLA nhà cung cấp là đặt mục tiêu không thể đạt.
- D. 99,9% uptime trong một tháng — "uptime" chung chung không phản ánh trải nghiệm xem; máy chủ sống mà video không chạy nổi vẫn tính là hoạt động.
- B. 95% lời gọi API xong trong 200 ms — đo được, nhưng là chỉ số kỹ thuật ở tầng dưới, không phải thứ người xem cảm nhận.
As a cloud architect, you are working with an organization that frequently provisions and de-provisions a set of Google Cloud resources for temporary projects. They are looking for an automated and reproducible way to manage this. Which of the following approaches best utilizes Google Cloud Deployment Manager for this purpose?
-
A
Create a Deployment Manager configuration file for the required resources, and use Deployment Manager to create and delete these resources as needed.
-
B
Use Deployment Manager to automate the process of manually creating and deleting resources in the Google Cloud Console.
-
C
Use the Deployment Manager API to manually create and delete resources as needed.
-
D
Use Deployment Manager to periodically check for unused resources and delete them.
Xem giải thích
Đáp án
A — Viết tệp cấu hình Deployment Manager cho các tài nguyên cần thiết
Vì sao đúng
Đề mô tả việc dựng lên rồi dỡ đi liên tục cho các dự án tạm. Hạ tầng dạng mã giải đúng chỗ đó: toàn bộ tập tài nguyên được mô tả trong một tệp cấu hình, nên dựng là một lệnh và dỡ cũng là một lệnh — xoá deployment thì mọi tài nguyên nó tạo ra biến mất cùng. Không sót tài nguyên mồ côi tiếp tục tính tiền, và lần dựng nào cũng giống hệt lần trước.
Vì sao các phương án khác sai
- B và C. Dùng Deployment Manager nhưng vẫn tạo và xoá bằng tay — mâu thuẫn với chính lý do dùng công cụ này; phần giá trị nằm ở việc mô tả bằng mã.
- D. Định kỳ quét tìm tài nguyên không dùng rồi xoá — đây là dọn dẹp sau khi đã sót, dựa trên phỏng đoán "cái này chắc không ai dùng" — cách rất dễ xoá nhầm.