Ngân hàng đề — Google Professional Cloud Architect

Tìm thấy 420 câu.

Câu 31

For this question, refer to the KnightMotives Automotive case study.

https://services.google.com/fh/files/misc/v6.1_pca_knightmotives_automotive_case_study_english.pdf


KnightMotives employees—including developers, data scientists, and dealer support staff—are transitioning to cloud-based systems and AI-driven workflows. Due to recent industry-wide automotive cyberattacks, leadership requires improved security awareness training and stricter access controls. The solution must enforce least privilege, reduce credential misuse, and integrate with a centralized incident response strategy while supporting a global workforce. What is the most effective Google Cloud–aligned approach to meet these security and risk management objectives?

  1. A

    Grant broad project-level Owner access to reduce permission management overhead and rely on employee trust.

  2. B

    Use service account keys shared across teams and rotate them annually.

  3. C

    Implement IAM with predefined roles, enforce workforce identity federation, enable Cloud Audit Logs, and conduct regular security training tied to incident response procedures.

  4. D

    Store user credentials in application configuration files and monitor access manually.

Xem giải thích

Đáp án

C — Dùng IAM với vai dựng sẵn, và liên kết danh tính lực lượng lao động

Vì sao đúng

Hai thành phần này là nền của quản lý truy cập ở quy mô doanh nghiệp. Vai dựng sẵn đã được Google thiết kế theo nguyên tắc quyền tối thiểu cho từng công việc, nên dùng chúng an toàn hơn tự ghép quyền. Workforce identity federation cho nhân viên đăng nhập bằng danh tính có sẵn của công ty, nên khi ai đó nghỉ việc thì thu hồi ở một chỗ là mất quyền ở mọi nơi.

Vì sao các phương án khác sai

  • A. Cấp vai Owner ở mức dự án cho gọn — trao quyền rộng nhất có thể để đỡ phải quản lý, đúng thứ nguyên tắc quyền tối thiểu cấm.
  • B. Dùng chung khoá tài khoản dịch vụ và xoay vòng mỗi năm — khoá dài hạn dùng chung thì không truy được ai đã làm gì, và một năm là quá dài.
  • D. Để thông tin đăng nhập trong tệp cấu hình — cách rò rỉ thông tin phổ biến nhất.
Câu 32

A financial services company is developing a new cloud-native application on Google Cloud Platform (GCP) that will process financial transactions in real-time. The application is designed using a microservices architecture to ensure scalability, reliability, and ease of maintenance. The company requires each microservice to be independently deployable, with robust inter-service communication, secure access to sensitive data, and a focus on high availability. They also need to minimize latency in communication between services, as transaction processing speed is critical. Which architecture best supports the application’s design requirements?

  1. A

    Implement each microservice as a separate App Engine service, using Cloud Pub/Sub for inter-service communication and VPC Service Controls for securing access.

  2. B

    Run microservices in Google Cloud Run, use Pub/Sub for asynchronous messaging, and secure communication with Google Cloud Armor.

  3. C

    Use Google Kubernetes Engine (GKE) to deploy microservices in containers, with Istio for service mesh, and secure communication using mutual TLS (mTLS) between services.

  4. D

    Deploy each microservice as a separate Compute Engine instance, use a Cloud Load Balancer for routing traffic, and implement inter-service communication via HTTP(S).

Xem giải thích

Đáp án

C — Dùng GKE triển khai các microservice trong container

Vì sao đúng

Với hệ thống xử lý giao dịch tài chính thời gian thực gồm nhiều microservice, GKE cho những thứ mà các lựa chọn còn lại thiếu: điều phối nhiều dịch vụ có phụ thuộc lẫn nhau, co giãn từng dịch vụ độc lập, triển khai cuốn chiếu và quay lui nhanh, cùng kiểm soát chi tiết về mạng và tài nguyên giữa các thành phần.

Vì sao các phương án khác sai

  • A. Mỗi microservice là một service của App Engine — làm được nhưng ràng buộc về môi trường chạy, và khó kiểm soát mạng giữa các dịch vụ.
  • B. Cloud Run — rất tốt cho dịch vụ không trạng thái theo yêu cầu, nhưng hạn chế với tiến trình chạy nền lâu và điều phối phức tạp.
  • D. Mỗi microservice một máy ảo riêng — chi phí vận hành cao nhất và co giãn chậm nhất.
Câu 33

In your organization, there is an application that operates on multiple Compute Engine instances. The objective is to establish seamless communication between your application and an on-premises service, which demands high throughput, using internal IP addresses. The goal is to minimize latency as much as possible. As a cloud architect, what recommendations should you provide in this scenario?

  1. A

    You should use Cloud VPN to configure a VPN tunnel between the on-premises environment and Google Cloud.

  2. B

    You should configure a Cloud Dedicated Interconnect connection between the on-premises environment and Google Cloud.

  3. C

    You should use OpenVPN to configure a VPN tunnel between the on-premises environment and Google Cloud.

  4. D

    You should configure a direct peering connection between the on-premises environment and Google Cloud.

Xem giải thích

Đáp án

B — Thiết lập kết nối Dedicated Interconnect

Vì sao đúng

Khi cần liên lạc liền mạch, băng thông cao và độ trễ ổn định giữa hệ thống tại chỗ và các máy ảo trên Google Cloud, Dedicated Interconnect cho đường vật lý riêng vào mạng Google. Lưu lượng không đi qua Internet công cộng, nên vừa nhanh vừa đoán trước được — điều mà VPN không đảm bảo.

Vì sao các phương án khác sai

  • A và C. Dựng đường hầm VPN — chạy trên Internet công cộng nên độ trễ và băng thông biến động; hợp cho nhu cầu nhỏ hoặc làm đường dự phòng.
  • D. Direct peering — cho truy cập dịch vụ công khai của Google, không nối vào VPC riêng nên không đến được máy ảo của bạn.
Câu 34

Your company operates a multi-tier financial application in Google Cloud. The architecture includes frontend servers, middleware processing, and backend databases. Each tier is hosted within a separate Managed Instance Group (MIG), and communication between tiers is strictly directional: frontend servers communicate only with middleware servers, middleware servers communicate only with database servers. Direct communication between frontend servers and database servers must be prevented. How can you configure your network security to meet these requirements efficiently?

  1. A

    Create separate VPC networks for each tier.

  2. B

    Use network tags on each MIG and create firewall rules based on these tags.

  3. C

    Set firewall rules based on the internal IP addresses of the VMs.

  4. D

    Assign each tier to its own subnet within the same VPC.

Xem giải thích

Đáp án

B — Gắn network tag cho từng nhóm instance rồi viết luật tường lửa theo tag

Vì sao đúng

Network tag là cách phân đoạn đúng trong Google Cloud vì nó bám theo vai trò chứ không bám theo địa chỉ. Gắn tag cho từng tầng, rồi viết luật kiểu "chỉ nguồn có tag frontend mới tới được đích có tag middleware". Khi nhóm co giãn và máy mới sinh ra, chúng thừa hưởng tag nên luật áp dụng ngay, không phải sửa gì.

Vì sao các phương án khác sai

  • C. Viết luật theo địa chỉ IP nội bộ — IP thay đổi mỗi khi nhóm co giãn, nên luật hỏng liên tục. Đây là phương án sai kinh điển.
  • A. Mỗi tầng một VPC riêng — cô lập rất mạnh nhưng phải dựng peering giữa các VPC, phức tạp hơn nhiều so với nhu cầu.
  • D. Mỗi tầng một subnet trong cùng VPC — giúp tổ chức địa chỉ nhưng tự nó không chặn gì; vẫn phải có luật tường lửa.
Câu 35

You are designing a data processing pipeline on Google Cloud to handle large-scale batch jobs for a retail company. The pipeline processes sales data once a day, generates daily reports, and stores them in Cloud Storage. The reports are then processed by a BigQuery analytics system. The batch jobs will run on Google Dataproc, and Cloud Storage will be used to store both raw and processed data. You need to estimate the monthly cost of the solution based on the following usage:

  • Dataproc cluster with 5 worker nodes running 4 hours per day.

  • 10 TB of data storage in Cloud Storage (Regional storage).

  • 5 TB of processed data queried daily in BigQuery.

  • Network egress costs to export 1 TB of data monthly to an external service.

Which approach is the most accurate for estimating the monthly cost of this solution?

  1. A

    Estimate Dataproc cluster costs by calculating the cost of the master node and ignore the worker nodes since they only run for 4 hours per day. Use Cloud Storage Nearline pricing to save costs on storing 10 TB of data. Include BigQuery costs for querying 5 TB of data and network egress charges for exporting 1 TB.

  2. B

    Estimate the Dataproc cluster costs by calculating the hourly rate for 5 nodes, estimate Cloud Storage costs based on Standard storage pricing for 10 TB, and BigQuery costs using the on-demand pricing model for querying 5 TB of data daily. Ignore network egress costs as they are negligible for only 1 TB of data.

  3. C

    Calculate Dataproc costs using the preemptible VMs pricing for worker nodes to reduce costs, estimate Cloud Storage costs using Multi-Regional storage for redundancy, and calculate BigQuery costs assuming a flat-rate pricing model. Ignore network egress costs since they are included in the flat-rate plan.

  4. D

    Use the Google Cloud Pricing Calculator to estimate costs for the Dataproc cluster, include Cloud Storage costs for storing 10 TB of data, BigQuery pricing for 5 TB of daily queries, and network egress charges for exporting 1 TB of data.

Xem giải thích

Đáp án

D — Dùng Google Cloud Pricing Calculator để ước tính

Vì sao đúng

Chi phí một cụm Dataproc không chỉ là giá máy: còn có phí quản lý tính theo vCPU, chi phí đĩa, lưu lượng mạng, và mức giảm giá theo thời lượng sử dụng. Tự nhân tay rất dễ sót một khoản. Pricing Calculator gộp đủ các thành phần theo đúng cấu hình bạn khai, nên con số sát thực tế hơn hẳn.

Vì sao các phương án khác sai

  • A, B và C — đều là những phép nhân tay chỉ tính một phần: hoặc chỉ tính node, hoặc chỉ tính giá theo giờ, hoặc chỉ tính giá máy preemptible. Chúng bỏ sót các khoản còn lại và cho ra con số thấp hơn thực tế.
Câu 36

Your company wants to integrate a conversational AI assistant into its customer support platform. The assistant should use a Google Gemini model for natural language understanding and generation, connect securely to internal APIs, and leverage existing company knowledge bases. As the Cloud Architect, which Google Cloud solution provides the most efficient and scalable way to build and deploy this AI assistant?

  1. A

    Use Cloud Functions to host a custom inference server for Gemini models integrated with Firestore for session storage.

  2. B

    Use Vertex AI Agent Builder to build the conversational agent, connect it to internal APIs, and deploy it using a Gemini model as the underlying LLM.

  3. C

    Use Dialogflow ES with a custom backend hosted on Cloud Run for integrating Gemini models manually via REST API.

  4. D

    Deploy Gemini models directly from Model Garden to a Compute Engine instance with a Flask API.

Xem giải thích

Đáp án

B — Dùng Vertex AI Agent Builder để dựng trợ lý hội thoại, nối vào nguồn dữ liệu nội bộ

Vì sao đúng

Vertex AI Agent Builder là dịch vụ được quản lý dựng riêng cho đúng bài toán này: nó lo phần hiểu ngôn ngữ tự nhiên bằng mô hình Gemini, quản lý luồng hội thoại nhiều lượt, và nối thẳng vào kho dữ liệu của bạn để trả lời dựa trên tài liệu thật thay vì bịa. Không phải tự dựng máy chủ suy luận, không phải tự nuôi hạ tầng.

Vì sao các phương án khác sai

  • A. Tự dựng máy chủ suy luận trên Cloud Functions — Cloud Functions có giới hạn thời gian chạy và bộ nhớ, không hợp để phục vụ mô hình ngôn ngữ lớn.
  • C. Dialogflow ES với backend tự viết — ES là thế hệ cũ, kém hơn CX về luồng hội thoại phức tạp, và phải tự ghép phần Gemini vào.
  • D. Triển khai Gemini từ Model Garden lên máy ảo — tự vận hành GPU cho thứ đã có dịch vụ được quản lý, tốn nhất trong bốn phương án.
Câu 37

For this question, refer to the EHR Healthcare case study.

https://services.google.com/fh/files/misc/v6.1_pca_ehr_healthcare_case_study_english.pdf


EHR Healthcare's data analysis team runs an analytics application to process public health data. The application is currently hosted on-premises but has seen significant growth, leading to performance issues. The team wants to migrate the application to Google Cloud, reduce latency, and ensure security from potential attacks. Additionally, the application must comply with regulations to encrypt data in transit. What should you do?

  1. A

    Move the application to Compute Engine, deploy a Cloud VPN to encrypt traffic, and use VPC firewall rules to block untrusted IP addresses.

  2. B

    Use Compute Engine to deploy virtual machines, configure an internal load balancer, and encrypt traffic using custom SSL certificates.

  3. C

    Use App Engine Standard Environment to deploy the application and configure firewall rules to block DDoS traffic.

  4. D

    Deploy the application to Google Kubernetes Engine (GKE), expose the application using an external HTTP(S) load balancer, and configure Google Cloud Armor for DDoS protection.

Xem giải thích

Đáp án

D — Triển khai lên GKE và mở dịch vụ ra bằng load balancer nội bộ

Vì sao đúng

EHR Healthcare cần ứng dụng nội bộ chỉ truy cập được từ trong mạng riêng. Ghép GKE với internal load balancer cho đúng hai thứ: điều phối container để co giãn và tự chữa lành, cộng với một điểm truy cập chỉ tồn tại trong VPC — không có IP công khai nào, nên bề mặt tấn công gần như bằng không.

Vì sao các phương án khác sai

  • A. Chuyển sang máy ảo rồi dựng Cloud VPN — VPN dùng để nối hai mạng, không phải cách phơi một dịch vụ cho ứng dụng khác trong cùng VPC.
  • B. Máy ảo với load balancer nội bộ — đúng phần mạng nhưng mất khả năng co giãn và tự chữa lành của nền tảng container.
  • C. App Engine Standard với luật tường lửa — App Engine phục vụ qua điểm cuối công khai; lọc bằng tường lửa là chắp vá so với việc không có điểm cuối công khai ngay từ đầu.
Câu 38

As a cloud architect, you set up the optimal combination of CPU and memory resources for nodes in a Kubernetes cluster. You want to be notified whenever CPU utilization exceeds 80% for 5 minutes or when memory utilization exceeds 90% for 1 minute. What do you need to specify to receive such notifications?

  1. A

    An alerting policy

  2. B

    A logging message specification

  3. C

    An alerting condition

  4. D

    Cloud Pub/Sub topic

Xem giải thích

Đáp án

A — Một alerting policy

Vì sao đúng

Trong Cloud Monitoring, alerting policy là đối tượng hoàn chỉnh mà bạn tạo ra: nó gói cả điều kiện cần theo dõi, ngưỡng, khoảng thời gian, và kênh thông báo gửi tin cho bạn. Đề yêu cầu "được báo khi mức dùng CPU vượt ngưỡng" — muốn có thông báo thì phải tạo policy.

Vì sao các phương án khác sai

  • C. Alerting condition — điều kiện là một phần bên trong policy, không phải thứ tồn tại độc lập; chỉ có điều kiện thì không ai được báo.
  • B. Khai báo thông điệp log — ghi lại sự việc, nhưng tự nó không chủ động báo cho ai.
  • D. Topic của Cloud Pub/Sub — có thể làm kênh nhận thông báo, nhưng vẫn phải có policy quyết định khi nào đẩy tin vào topic đó.
Câu 39

Your team has created an updated version of an application that is currently hosted on the App Engine Standard environment. You aim to migrate 2% of your users to the new version while minimizing complexity. What course of action would you recommend?

  1. A

    You should create a new App Engine application in the same project. Deploy a new version in that application. Configure your network load balancer to send 2% of the traffic to that new application.

  2. B

    You should create a new App Engine application in the same project. Deploy a new version in that application. Use the App Engine to split the traffic.

  3. C

    You should deploy a new version in the same application and use the --migrate option.

  4. D

    You should deploy a new version in the same application and split the traffic (98% to 2%).

Xem giải thích

Đáp án

D — Triển khai phiên bản mới trong cùng ứng dụng và chia lưu lượng 98% – 2%

Vì sao đúng

App Engine có sẵn cơ chế chia lưu lượng giữa các phiên bản trong cùng một ứng dụng. Đó đúng là công cụ cho việc phát hành thăm dò: khai tỷ lệ là xong, không cần thêm hạ tầng nào, và muốn lùi thì kéo tỷ lệ về 0. Đề nhấn mạnh giảm thiểu độ phức tạp — đây là phương án ít phần chuyển động nhất.

Vì sao các phương án khác sai

  • A và B. Tạo một ứng dụng App Engine mới — một dự án chỉ có một ứng dụng App Engine, nên phương án này không thực hiện được; kể cả bỏ qua điều đó thì việc dựng thêm load balancer cũng phức tạp hơn hẳn.
  • C. Dùng tuỳ chọn --migrate — lệnh này chuyển toàn bộ lưu lượng sang bản mới, đúng thứ ngược với mục tiêu 2%.
Câu 40

A large retail chain with stores across multiple continents is moving its e-commerce platform to Google Cloud Platform (GCP). The platform must handle high traffic during sales events, ensure zero downtime, and offer a consistent user experience globally. The business requires the application to be highly available, automatically scalable, and capable of handling localized traffic efficiently. Additionally, the platform needs to integrate with legacy systems hosted on-premises for inventory and order management. The company also wants to optimize costs by paying for resources based on demand. Which architecture best meets the company’s requirements?

  1. A

    Implement the application using Google Kubernetes Engine (GKE) with multi-regional clusters, Cloud Spanner for the database, and Cloud Interconnect for high-bandwidth on-premises connectivity.

  2. B

    Use App Engine Flexible Environment with auto-scaling enabled, multi-regional Cloud SQL instances for the database, and Cloud VPN for secure on-premises connections.

  3. C

    Utilize Cloud Functions for the application logic, Bigtable for the database, and Cloud Pub/Sub for communication between GCP and on-premises systems.

  4. D

    Deploy the application on Compute Engine instances with regional persistent disks, use a global load balancer, and implement Cloud VPN for on-premises connectivity.

Xem giải thích

Đáp án

A — Dùng GKE với cụm ở nhiều khu vực

Vì sao đúng

Đề nêu ba ràng buộc cùng lúc: khách hàng ở nhiều châu lục, lưu lượng dồn theo mùa, và cần sẵn sàng cao. GKE nhiều khu vực trả lời được cả ba — phục vụ từ khu vực gần người dùng nhất để giảm độ trễ, co giãn cả pod lẫn node khi cao điểm, và vẫn chạy khi mất trọn một khu vực.

Vì sao các phương án khác sai

  • B. App Engine Flexible — co giãn chậm hơn vì phải khởi động máy ảo bên dưới, và kém linh hoạt khi nền tảng thương mại điện tử phình ra nhiều thành phần.
  • C. Cloud Functions cho toàn bộ logic — hàm theo sự kiện không hợp làm xương sống cho một nền tảng có trạng thái và phiên làm việc.
  • D. Máy ảo với đĩa bền vùng — đĩa vùng chỉ nhân bản trong một khu vực, nên không chịu được sự cố cấp khu vực.