Ngân hàng đề — Google Professional Cloud Architect
Tìm thấy 420 câu.
Your organization has decided to migrate their 50 TB of IoT sensor data to the cloud for analytics and disaster recovery. They require the ability to perform SQL-based queries on this data and ensure the archive can be accessed for compliance and disaster recovery purposes. Which two steps should they take? (Choose two)
-
A
Use Cloud Bigtable for querying and analytics.
-
B
Use Cloud SQL to store the IoT sensor data.
-
C
Load the data into BigQuery for analytics.
-
D
Ingest data into Cloud Logging for analysis.
-
E
Archive the IoT sensor data in Cloud Storage.
Xem giải thích
Đáp án
C và E — nạp dữ liệu vào BigQuery để phân tích, và lưu trữ trong Cloud Storage
Vì sao đúng
Đề nêu hai nhu cầu tách bạch:
- C. BigQuery cho truy vấn SQL — đề nói rõ cần khả năng này, và BigQuery làm được ở quy mô 50 TB mà không phải dựng cụm nào.
- E. Cloud Storage cho khôi phục thảm hoạ — bản gốc được giữ ở nơi rẻ và bền nhất, tách khỏi hệ thống phân tích.
Vì sao các phương án khác sai
- A. Bigtable để truy vấn và phân tích — Bigtable đọc theo khoá rất nhanh nhưng không hỗ trợ SQL phân tích, mà đó là yêu cầu tường minh của đề.
- B. Cloud SQL — không kham nổi 50 TB dữ liệu cảm biến.
- D. Đưa vào Cloud Logging để phân tích — Cloud Logging dựng cho log vận hành của hệ thống, đắt và sai mục đích cho dữ liệu cảm biến.
A company is planning to migrate its on-premises data center to Google Cloud Platform (GCP). The company has large amounts of data and wants to minimize downtime during the migration process and ensure that its data is secure during the transfer. Which of the following options should be used to meet these requirements?
-
A
Use
rsyncto transfer data from on-premises to GCP and encrypt data at rest using customer-supplied encryption keys. -
B
Use Google Transfer Appliance to physically transfer data from on-premises to GCP and encrypt data at rest using Google-managed encryption keys.
-
C
Use
gcloud compute scpto transfer data from on-premises to GCP and encrypt data in transit using SSH. -
D
Use
gsutilto transfer data from on-premises to GCP and encrypt data in transit using SSL.
Xem giải thích
Đáp án
B — Dùng Google Transfer Appliance để chuyển dữ liệu bằng thiết bị vật lý
Vì sao đúng
Hai dữ kiện quyết định: khối lượng dữ liệu lớn và muốn giảm thời gian gián đoạn. Chuyển qua mạng ở khối lượng lớn kéo dài rất lâu, và cửa sổ chuyển đổi kéo theo. Transfer Appliance tách hai thứ đó ra: phần lớn dữ liệu đi bằng thiết bị vật lý trong lúc hệ thống cũ vẫn chạy, tới lúc cắt chuyển chỉ còn phần thay đổi nhỏ phải đồng bộ.
Vì sao các phương án khác sai
- D.
gsutilvà A.rsync— đều đi qua chính đường mạng đang là nút thắt; ở khối lượng lớn thì mất rất nhiều thời gian và hay đứt giữa chừng. - C.
gcloud compute scp— dùng để chép vài tệp sang một máy ảo, hoàn toàn không phải công cụ di chuyển trung tâm dữ liệu.
Your company has a critical multi-tier application that needs to be deployed across two Google Cloud regions (us-central1 and europe-west1) to ensure high availability and disaster recovery. The application components include front-end services, an API layer, and a backend database. You are tasked with designing the network topology that allows secure and high-performance communication between these components across regions. You also need to ensure that this architecture can later be extended to connect with resources in another cloud provider. What network configuration should you implement to achieve this?
-
A
Set up a Dedicated Interconnect between us-central1 and europe-west1 for direct region-to-region communication. Use VPC Peering and Route Tables to manage traffic between the regions.
-
B
Use VPC Peering between the VPCs in us-central1 and europe-west1. Enable Cloud VPN to secure the communication, and use VPC Flow Logs to monitor the traffic.
-
C
Deploy a Global VPC that spans both regions (us-central1 and europe-west1). Use Cloud Router to manage dynamic routing across the regions, and configure Private Google Access for regional services.
-
D
Create a Shared VPC and host the network resources for both regions (us-central1 and europe-west1) within it. Use Firewall rules to control the inter-region traffic.
Xem giải thích
Đáp án
C — Triển khai một Global VPC trải cả hai khu vực
Vì sao đúng
VPC của Google Cloud vốn đã toàn cầu — một VPC chứa subnet ở nhiều khu vực, và các subnet nói chuyện với nhau bằng IP riêng qua mạng xương sống của Google. Không cần peering, không cần đường hầm, chỉ một bộ luật tường lửa để quản lý. Đây là khác biệt lớn so với các đám mây khác, nơi VPC bó trong một khu vực.
Vì sao các phương án khác sai
- B. VPC peering giữa hai VPC ở hai khu vực — tự dựng lại thứ đã có sẵn; peering còn không có tính bắc cầu nên mở rộng về sau sẽ vướng.
- A. Dedicated Interconnect giữa hai khu vực — Interconnect dùng để nối từ ngoài vào Google Cloud, không phải để nối hai khu vực bên trong.
- D. Shared VPC — cơ chế chia sẻ mạng giữa các dự án, không phải cơ chế nối các khu vực; đề không nêu nhu cầu nhiều dự án.
For this question, refer to the KnightMotives Automotive case study.
https://services.google.com/fh/files/misc/v6.1_pca_knightmotives_automotive_case_study_english.pdf
KnightMotives plans to roll out AI-powered in-vehicle features across all vehicle types, including hybrid and ICE models. These features will collect telemetry, driver interaction data, and sensor data from vehicles across Europe to support autonomous driving enhancements and personalized user experiences.
Due to strict European Union (EU) data protection regulations, KnightMotives must ensure that personal data remains within EU regions, supports data subject rights (such as deletion and access), and minimizes regulatory risk—while still enabling scalable AI development and analytics on Google Cloud. Which architecture best meets KnightMotives’ regulatory, scalability, and AI innovation requirements?
-
A
Deploy EU-only data ingestion pipelines using regional Pub/Sub, store data in EU-based BigQuery datasets, and enforce data residency using organization policies.
-
B
Use a single US-based Vertex AI environment and encrypt all EU data with customer-managed encryption keys (CMEK).
-
C
Stream vehicle data globally into a single multi-region BigQuery dataset and rely on IAM controls to restrict access by geography.
-
D
Store all vehicle data in Cloud Storage using global buckets and anonymize personal data after ingestion.
Xem giải thích
Đáp án
A — Đường ống nạp dữ liệu riêng cho châu Âu, dùng Pub/Sub theo khu vực và lưu dữ liệu trong EU
Vì sao đúng
Yêu cầu ở đây là chủ quyền dữ liệu: dữ liệu của người dùng châu Âu phải nằm lại châu Âu. Cách duy nhất đảm bảo được là dựng đường ống chỉ chạy trong EU — Pub/Sub cấu hình theo khu vực để thông điệp không rời khỏi vùng, và nơi lưu trữ cũng đặt trong EU. Ràng buộc pháp lý phải được thực thi bằng kiến trúc, không phải bằng quy trình.
Vì sao các phương án khác sai
- B. Một môi trường Vertex AI ở Mỹ, mã hoá dữ liệu EU bằng khoá riêng — mã hoá bảo vệ nội dung nhưng không thay đổi việc dữ liệu đã rời khỏi châu Âu; đó mới là điều luật quan tâm.
- C. Đưa dữ liệu toàn cầu vào một dataset BigQuery đa vùng — dữ liệu EU nằm lẫn với phần còn lại, vi phạm thẳng yêu cầu.
- D. Bucket toàn cầu rồi ẩn danh dữ liệu cá nhân — ẩn danh khó làm triệt để, và vẫn không giải quyết chuyện nơi lưu trữ.
A company is using Google Cloud Platform (GCP) for hosting its mission-critical applications and wants to ensure that the data stored in Google Cloud Storage is accessible from its on-premises data center. Which of the following options should be used to meet this requirement?
-
A
Enable Direct Peering between the company's on-premises data center and GCP.
-
B
Mount Cloud Storage as a network file system using GCSFuse.
-
C
Use Cloud Interconnect to connect the company's on-premises data center to GCP.
-
D
Use Transfer Appliance to physically transfer data from GCP to the company's on-premises data center.
Xem giải thích
Đáp án
C — Dùng Cloud Interconnect để nối trung tâm dữ liệu tại chỗ với Google Cloud
Vì sao đúng
Đề cần dữ liệu trong Cloud Storage truy cập được từ hệ thống tại chỗ một cách ổn định. Cloud Interconnect cho đường riêng vào mạng Google với băng thông cao và độ trễ đoán trước được, không phụ thuộc tình trạng Internet công cộng — điều kiện cần khi hệ thống trọng yếu phụ thuộc vào đường nối đó.
Vì sao các phương án khác sai
- A. Direct Peering — cho truy cập dịch vụ công khai của Google qua trao đổi lưu lượng, nhưng không vào được VPC riêng và không có cam kết dịch vụ như Interconnect.
- B. Gắn Cloud Storage bằng GCSFuse — là cách truy cập kho đối tượng như hệ tệp, nhưng nó vẫn đi qua đường mạng sẵn có; không giải quyết chuyện kết nối.
- D. Dùng Transfer Appliance để chuyển dữ liệu về lại — thiết bị chuyển một lần, không phải cơ chế truy cập thường trực.
Your team has developed a new e-commerce platform on Google Cloud, and it is now in public beta. You are tasked with defining Service Level Objectives (SLOs) to ensure the platform meets user expectations before launching it to the general public. What should you do?
-
A
Define one SLO as the service uptime aligns with Google Cloud's SLA for Load Balancers. Define the other SLO as API latency does not exceed 1 second.
-
B
Define one SLO as 99.9% server availability during business hours. Define the other SLO as all page loads are fully rendered within 1 second.
-
C
Define one SLO as 99% of HTTP requests return a 2xx status code within 300 ms. Define the other SLO as 99% of page loads are complete in under 500 ms.
-
D
Define one SLO as 99% service availability during peak shopping hours. Define the other SLO as 99% of API responses are returned within 1 second.
Xem giải thích
Đáp án
C — Một SLO là 99% yêu cầu HTTP trả mã 2xx trong vòng 300 ms
Vì sao đúng
SLO tốt phải đo được, đo đúng thứ người dùng cảm nhận, và đặt dưới 100%. Phương án này đạt cả ba: mã trạng thái HTTP là số liệu có sẵn không tranh cãi, ngưỡng 300 ms phản ánh trải nghiệm thật khi mua hàng, và 1% còn lại chính là ngân sách lỗi cho phép đội tiếp tục phát hành.
Điểm hay là nó gộp cả tính đúng (mã 2xx) và tốc độ (300 ms) vào một chỉ số — yêu cầu trả về nhanh nhưng lỗi thì không tính là thành công.
Vì sao các phương án khác sai
- A. Đặt SLO bằng SLA của Load Balancing — dịch vụ của bạn luôn kém tin cậy hơn tổng các thành phần nó phụ thuộc, nên đặt bằng SLA nhà cung cấp là đặt mục tiêu không đạt được.
- **B. 99,9% khả dụng trong giờ hành chính — sàn thương mại điện tử phục vụ 24/7; giới hạn theo giờ làm việc là bỏ qua phần lớn người mua.
- **D. 99% khả dụng trong giờ cao điểm mua sắm — cùng vấn đề: chỉ đo một lát cắt thời gian.
Your company wants to implement a scalable and highly available solution for a new web-based service. The service needs to be able to handle a large number of concurrent users, and must have the ability to automatically recover from individual machine failures. Which Google Cloud Platform service would you recommend to meet these requirements?
-
A
Compute Engine instances in an auto-scaling group behind a load balancer.
-
B
App Engine Standard environment.
-
C
Google Kubernetes Engine cluster.
-
D
Cloud Functions with a managed instance group.
Xem giải thích
Đáp án
A — Máy Compute Engine trong nhóm tự co giãn, đặt sau load balancer
Vì sao đúng
Đây là mô hình cổ điển và trực tiếp nhất cho dịch vụ web co giãn, sẵn sàng cao: nhóm tự thêm bớt máy theo tải và tự thay máy hỏng, load balancer phân phối lưu lượng và loại bỏ máy không qua health check. Không đòi hỏi đóng gói lại ứng dụng hay học nền tảng mới.
Vì sao các phương án khác sai
- D. Cloud Functions với managed instance group — hai thứ này không đi cùng nhau: Cloud Functions là nền tảng không máy chủ, nó không chạy trên instance group nào. Đây là phương án duy nhất sai về mặt kỹ thuật.
- B. App Engine Standard và C. GKE — cả hai đều là lựa chọn hợp lệ và đều co giãn tốt. Điểm khác là chúng đòi ứng dụng phải khớp với khuôn của nền tảng: App Engine ràng buộc về môi trường chạy, GKE đòi đóng gói container và vận hành cụm. Đề không nêu nhu cầu nào biện minh cho phần công thêm đó.
Your client is planning to deploy a multi-tier application in Google Cloud that involves storing and processing highly sensitive user data. What is the most secure method for managing secrets such as database credentials and API keys within this environment?
-
A
Utilize Cloud Security Command Center to automatically manage and rotate secrets.
-
B
Hard-code secrets into the application source code and rely on source code management for security.
-
C
Implement secrets using Google Cloud Secret Manager and enforce access control with IAM policies.
-
D
Store secrets in environment variables of the cloud VM instances.
Xem giải thích
Đáp án
C — Dùng Google Cloud Secret Manager và siết quyền truy cập bằng IAM
Vì sao đúng
Secret Manager là dịch vụ dựng riêng cho bí mật: mã hoá khi lưu, phân quyền tới từng bí mật qua IAM, quản lý phiên bản để xoay vòng mà không gãy ứng dụng, và ghi nhật ký kiểm toán mỗi lần bí mật được đọc. Vế cuối là thứ các cách khác không có: bạn biết được ai đã lấy bí mật nào, lúc nào.
Vì sao các phương án khác sai
- B. Nhúng bí mật thẳng vào mã nguồn — bí mật sẽ nằm trong kho mã, trong lịch sử commit, trong ảnh container và trong mọi bản sao lưu; đây là cách rò rỉ phổ biến nhất.
- D. Để trong biến môi trường của máy ảo — ai đọc được siêu dữ liệu hoặc vào được máy là thấy; không có xoay vòng, không có nhật ký.
- A. Dùng Security Command Center để quản lý và xoay vòng bí mật — SCC là công cụ phát hiện rủi ro và quản lý tư thế bảo mật, nó không lưu trữ hay xoay vòng bí mật.
You are a cloud architect working on a web application that requires horizontal scaling based on traffic load. The application runs on stateless virtual machines, and you plan to use Managed Instance Groups (MIGs) for this purpose. You also want to ensure that any updates to the instance templates do not disrupt the service. Which of the following deployment strategies would you recommend?
-
A
Use Rolling update strategy with Proactive update mode and Automatic scaling.
-
B
Use Canary update strategy with Proactive update mode and Manual scaling.
-
C
Use Opportunistic update mode with Maximum surge policy and Automatic scaling.
-
D
Use Rolling update strategy with Opportunistic update mode and Manual scaling.
Xem giải thích
Đáp án
A — Rolling update, chế độ Proactive, kèm Automatic scaling
Vì sao đúng
Ba lựa chọn khớp ba yêu cầu của đề:
- Rolling update — thay máy từng phần nên dịch vụ không gián đoạn.
- Proactive — nhóm chủ động áp bản mới lên các máy đang chạy ngay khi bạn khai. Chế độ Opportunistic thì ngược lại: nó chỉ áp khi có máy được tạo mới vì lý do khác, nên bản cập nhật có thể nằm đó rất lâu không được triển khai.
- Automatic scaling — đề nói rõ cần co giãn ngang theo tải.
Ứng dụng không trạng thái là điều kiện khiến việc thay máy tự do như vậy an toàn.
Vì sao các phương án khác sai
- D. Rolling nhưng Opportunistic và co giãn thủ công — sai cả hai vế còn lại.
- B. Canary với co giãn thủ công — mất phần tự co giãn mà đề yêu cầu.
- C. Opportunistic với chính sách maximum surge — vẫn vướng chuyện bản cập nhật không được chủ động áp.
A retail company wants to automate product image classification and defect detection using Google Cloud. The solution must require minimal custom ML training, integrate easily with Cloud Storage and BigQuery, and be scalable for millions of images uploaded monthly by multiple vendors. As the Cloud Architect, which configuration best meets these goals?
-
A
Deploy Vertex AI Forecasting models to predict product categories and detect visual anomalies from time-series image data.
-
B
Build a fully custom image classification model in Vertex AI Training, then deploy it on Vertex AI Endpoints after labeling all images manually.
-
C
Use Vertex AI Vision prebuilt models for image classification and object detection, connecting it to Cloud Storage for ingestion and exporting results to BigQuery.
-
D
Use Vertex AI Matching Engine to compare new images against a manually curated feature vector database for classification.
Xem giải thích
Đáp án
C — Dùng mô hình dựng sẵn của Vertex AI Vision cho phân loại ảnh và phát hiện đối tượng
Vì sao đúng
Đề nêu ràng buộc rất rõ: hạn chế tối đa việc tự huấn luyện. Mô hình dựng sẵn dùng được ngay qua API, không cần gán nhãn dữ liệu, không cần hạ tầng huấn luyện, và không cần chuyên gia học máy. Với phân loại sản phẩm và phát hiện lỗi ở mức phổ thông thì đây là con đường ngắn nhất tới kết quả dùng được.
Vì sao các phương án khác sai
- B. Tự xây mô hình phân loại ảnh hoàn toàn tuỳ chỉnh — vi phạm thẳng ràng buộc "ít huấn luyện nhất".
- A. Vertex AI Forecasting — dựng cho dự báo chuỗi thời gian, không xử lý ảnh.
- D. Vertex AI Matching Engine so ảnh với tập mẫu tự gom — công cụ tìm kiếm theo độ tương tự, và việc duy trì tập mẫu bằng tay lại thành gánh nặng mới.