Ngân hàng đề — Google Professional Cloud Architect

Tìm thấy 420 câu.

Câu 311

You are a cloud architect who is developing a system that needs to trigger a Cloud Function on a regular basis. You've decided to use Cloud Scheduler to achieve this task. The Cloud Function you've developed is designed to automatically update the inventory in a Cloud Firestore database every day at midnight based on information pulled from an external API. Given this scenario, which of the following approaches is the most suitable way to accomplish this task?

  1. A

    Create a Pub/Sub topic and use Cloud Scheduler to publish a message to that topic at midnight every day. Set up the Cloud Function to trigger on this topic.

  2. B

    Set up the Cloud Scheduler to trigger a Compute Engine instance that runs a script to call the Cloud Function at midnight every day.

  3. C

    Set up the Cloud Function to trigger at midnight every day using its built-in scheduling functionality.

  4. D

    Use Cloud Scheduler to create a cron job that runs on a Kubernetes Engine cluster to call the Cloud Function at midnight every day.

Xem giải thích

Đáp án

A — Tạo một topic Pub/Sub và cho Cloud Scheduler đăng thông điệp vào đó

Vì sao đúng

Đây là mô hình chuẩn để chạy Cloud Function theo lịch: Cloud Scheduler đẩy một thông điệp vào topic Pub/Sub theo biểu thức cron, còn Cloud Function đăng ký nhận sự kiện từ topic đó. Cách ghép này bền hơn gọi trực tiếp — Pub/Sub tự thử lại nếu hàm thất bại, và thông điệp không mất khi hàm tạm thời không sẵn sàng.

Vì sao các phương án khác sai

  • C. Dùng lịch tích hợp sẵn của Cloud Function — Cloud Functions không có cơ chế hẹn giờ nội tại; lịch phải đến từ bên ngoài.
  • B. Cho Scheduler khởi động một máy ảo chạy script — dựng cả một máy cho việc mà hàm đã làm được, kèm chi phí và việc vá lỗi.
  • D. Chạy cron job trên cụm Kubernetes — phải nuôi cả cụm chỉ để bấm giờ.
Câu 312

Your team is running an analytics application on a custom Compute Engine VM (e2-highmem-4) with a single SSD persistent disk (200 GB). The team has observed that disk I/O latency is higher than expected during peak hours. You are asked to improve disk performance without provisioning a new VM and while keeping costs low. Which action should you take?

  1. A

    Add a new 200 GB standard persistent disk and configure RAID 0 with the existing disk.

  2. B

    Increase the size of the existing SSD persistent disk to 1 TB.

  3. C

    Replace the SSD persistent disk with a balanced persistent disk.

  4. D

    Stop the VM and change the machine type to e2-standard-8.

Xem giải thích

Đáp án

B — Nới đĩa SSD hiện có từ 200 GB lên 1 TB

Vì sao đúng

Trên đĩa bền của Google Cloud, IOPS và thông lượng tỉ lệ thuận với dung lượng. Đĩa 200 GB có trần thấp hơn hẳn đĩa 1 TB dù bạn không dùng hết chỗ, nên khi ứng dụng bị nghẽn ở tầng đĩa thì nới dung lượng chính là cách nâng trần hiệu năng. Thao tác này làm được khi máy đang chạy.

Vì sao các phương án khác sai

  • A. Thêm đĩa standard 200 GB rồi ghép RAID-0 với đĩa SSD — trộn hai loại đĩa khác tốc độ thì đĩa chậm kéo cả nhóm xuống; RAID-0 chạy nhanh bằng thành phần chậm nhất.
  • C. Thay SSD bằng đĩa balanced — đĩa balanced có IOPS thấp hơn SSD, tức là đi lùi.
  • D. Đổi sang e2-standard-8 — thêm vCPU nhưng giảm bộ nhớ so với e2-highmem-4, mà nút thắt lại nằm ở đĩa chứ không ở CPU.
Câu 313

For this question, refer to the Altostrat Media case study.

https://services.google.com/fh/files/misc/v6.1_pca_altostrat_media_case_study_english.pdf 


Altostrat wants near–real-time visibility into trending topics and audience sentiment as new media content is published. These insights should be combined with user engagement data already stored in BigQuery to support dynamic pricing and targeted marketing campaigns. The architecture must be cost-efficient and require minimal manual intervention. Which approach best meets Altostrat’s requirements for timely trend detection and insight extraction?

  1. A

    Use Pub/Sub to stream content metadata events to Dataflow, apply NLP enrichment, and write results directly to BigQuery for real-time analysis.

  2. B

    Trigger Cloud Run jobs on content uploads, write intermediate results to Cloud Storage, and periodically load them into BigQuery.

  3. C

    Perform batch NLP processing nightly using Compute Engine and store results in a relational database.

  4. D

    Store enriched metadata in Cloud SQL and export it weekly to BigQuery for reporting.

Xem giải thích

Đáp án

A — Pub/Sub đưa sự kiện siêu dữ liệu vào Dataflow, làm giàu bằng NLP ngay trên luồng

Vì sao đúng

Altostrat cần siêu dữ liệu nội dung luôn mới, nên xử lý theo luồng là đúng mô hình. Pub/Sub hấp thụ sự kiện khi có nội dung mới, Dataflow áp phần làm giàu bằng NLP ngay lúc dữ liệu chảy qua, và kết quả sẵn sàng gần như tức thì. Cả hai đều không máy chủ nên không có gì phải vận hành.

Vì sao các phương án khác sai

  • C. Xử lý NLP theo lô hằng đêm trên máy ảo — siêu dữ liệu luôn chậm tới một ngày, và bạn phải vận hành máy.
  • B. Cloud Run job ghi kết quả trung gian ra Cloud Storage — thêm chặng lưu trữ trung gian, biến luồng thành nhiều bước rời rạc.
  • D. Lưu vào Cloud SQL rồi xuất sang BigQuery mỗi tuần — dữ liệu báo cáo chậm tới một tuần, và Cloud SQL không hợp quy mô này.
Câu 314

Your organization is preparing to build a complex data science solution on Google Cloud Platform. The solution involves various stages, including data collection, cleaning, analysis, machine learning model training, and deploying models for real-time predictions. The data volume is significant, and the solution will require multiple services on GCP for various stages. As the cloud architect, which of the following architectures will you recommend for managing this data science solution effectively?

  1. A

    Use Cloud Storage for data collection, Cloud Dataproc for cleaning and analysis, Cloud ML Engine for machine learning model training, and Cloud Endpoints for deploying models.

  2. B

    Use Cloud Storage for data collection, Dataflow for cleaning and analysis, Cloud Dataprep for machine learning model training, and App Engine for deploying models.

  3. C

    Use Cloud Pub/Sub for data collection, Dataflow for cleaning and analysis, AutoML for machine learning model training, and Cloud Run for deploying models.

  4. D

    Use Pub/Sub for data collection, Dataflow for cleaning and analysis, BigQuery ML for machine learning model training, and Cloud Functions for deploying models.

Xem giải thích

Đáp án

C — Pub/Sub thu thập dữ liệu, Dataflow làm sạch và phân tích, AutoML cho phần mô hình

Vì sao đúng

Ba mảnh khớp ba giai đoạn mà đề liệt kê, và điểm phân biệt nằm ở khâu thu thập: Pub/Sub là lớp đệm đúng cho dữ liệu tới liên tục — nó chịu được tải bùng phát, đảm bảo không mất tin, và tách rời bên sinh dữ liệu khỏi bên xử lý. Dataflow lo phần làm sạch và biến đổi, còn AutoML cho phép dựng mô hình mà không cần chuyên gia học máy.

Vì sao các phương án khác sai

  • A và B. Dùng Cloud Storage để thu thập — kho đối tượng biến quy trình thành xử lý theo lô; mất tính liên tục.
  • D. Pub/Sub và Dataflow đúng, nhưng dùng BigQuery cho khâu mô hình — BigQuery ML có chỗ dùng, nhưng nó không thay được nền tảng huấn luyện cho một quy trình khoa học dữ liệu đầy đủ như đề mô tả.
Câu 315

A large financial services company is looking to migrate its legacy data warehousing solution to the cloud to reduce costs and improve performance. The data warehousing solution must handle the following requirements:

  • store and process petabytes of financial data

  • support real-time data ingestion and analysis

  • ensure data security and compliance with industry regulations

  • provide a flexible and scalable architecture for future growth

Which of the following Google Cloud solutions would best meet these requirements?

  1. A

    Cloud Dataproc with Cloud Storage and Cloud Datastore

  2. B

    Cloud SQL with Cloud Storage and Cloud Data Fusion

  3. C

    Bigtable with Cloud Storage and Cloud Functions

  4. D

    BigQuery with Cloud Dataflow and Cloud Pub/Sub

Xem giải thích

Đáp án

D — BigQuery kết hợp Dataflow và Pub/Sub

Vì sao đúng

Thay một kho dữ liệu cũ thì phần lõi là kho dữ liệu mới, và BigQuery là lựa chọn đúng: không máy chủ, tách lưu trữ khỏi tính toán nên mở rộng tới petabyte, và trả tiền theo lượng dữ liệu quét nên chi phí giảm rõ so với hạ tầng cũ luôn phải dự phòng cho mức đỉnh. Dataflow lo khâu ETL, còn Pub/Sub lo khâu nạp dữ liệu liên tục.

Vì sao các phương án khác sai

  • A. Dataproc với Datastore — Dataproc là cụm Hadoop/Spark phải vận hành, và Datastore không phải kho phân tích.
  • B. Cloud SQL — CSDL giao dịch một máy chủ, không thay được kho dữ liệu.
  • C. Bigtable — đọc theo khoá rất nhanh nhưng không hỗ trợ SQL phân tích, mà đó là việc chính của một kho dữ liệu.
Câu 316

You are responsible for designing an infrastructure solution to train a machine learning (ML) model on a dataset that is approximately 1 PB in size. The dataset is stored in Google Cloud Storage (GCS), and you need to ensure high performance during the model training process. The model training jobs require significant computational resources, and there’s a need to minimize both training time and cost. You also need to ensure that the solution can scale based on the data size and computational requirements. Which of the following configurations would be the most suitable for this ML training pipeline?

  1. A

    Deploy a Dataproc cluster with SSD-backed persistent disks for storage and use Apache Spark to load the data from GCS for training.

  2. B

    Use Cloud AI Platform with preemptible Compute Engine VMs and a GCS bucket for data storage, leveraging TPUs for training.

  3. C

    Use Google Kubernetes Engine (GKE) with persistent disks attached to nodes, mounting GCS as a volume to access the data directly for training.

  4. D

    Use Cloud AI Platform with a custom TensorFlow image, NFS storage for the dataset, and standard Compute Engine VMs.

Xem giải thích

Đáp án

B — Cloud AI Platform với máy Compute Engine preemptible, dữ liệu để trong bucket GCS

Vì sao đúng

Với tập dữ liệu 1 PB, quyết định quan trọng nhất là không chép dữ liệu vào đĩa. Để nguyên trong Cloud Storage và cho công việc huấn luyện đọc thẳng từ đó: rẻ hơn nhiều lần, không có trần dung lượng đĩa, và nhiều worker đọc song song được. Máy preemptible cắt mạnh chi phí tính toán, và huấn luyện phân tán vốn chịu được việc mất một worker vì nó có cơ chế checkpoint.

Vì sao các phương án khác sai

  • A. Cụm Dataproc với đĩa SSD làm nơi chứa dữ liệu — chứa 1 PB trên đĩa bền là cực kỳ đắt, và Dataproc không phải nền tảng huấn luyện mô hình.
  • C. GKE với đĩa bền gắn vào node — cùng vấn đề về chi phí và trần dung lượng.
  • D. NFS làm nơi chứa dữ liệu — hệ tệp qua mạng không mở rộng tới petabyte và trở thành nút thắt khi nhiều worker cùng đọc.
Câu 317

An insurance company uses several third-party enterprise applications that require special licenses. These licenses are not transferrable to the cloud. The third-party software vendor offers an option to pay a licensing fee based on how long you use the application in the cloud. What is this approach called?

  1. A

    Bringing your own licenses

  2. B

    Flat-rate pricing

  3. C

    On-demand pricing

  4. D

    Pay-as-you-go license

Xem giải thích

Đáp án

D — Giấy phép trả theo mức sử dụng (pay-as-you-go license)

Vì sao đúng

Điều kiện khoá chặt đáp án nằm ngay trong đề: giấy phép hiện có không chuyển sang đám mây được. Điều đó loại thẳng mô hình mang giấy phép của bạn sang. Cách còn lại là dùng ảnh máy đã kèm sẵn giấy phép, trong đó chi phí bản quyền được tính vào giá theo giờ — bạn trả theo thời gian dùng thật và không cần thoả thuận bản quyền riêng nào.

Vì sao các phương án khác sai

  • A. Mang giấy phép của bạn sang (BYOL) — vi phạm trực tiếp điều kiện của đề.
  • B. Flat-rate pricing và C. On-demand pricing — là các mô hình tính tiền cho tài nguyên tính toán (đặc biệt của BigQuery), không phải mô hình cấp phép phần mềm.
Câu 318

Your organization has a suite of applications that have been containerized. You've been tasked to design a deployment strategy that leverages the power of Google Cloud's managed services, allows for auto-scaling based on demand, provides an ability to deploy updates with zero-downtime, and supports granular IAM roles and policies for your DevOps team. What would be your recommended approach?

  1. A

    Use Cloud Run to deploy the containerized applications and benefit from its automatic scaling and deployment features.

  2. B

    Utilize Google Kubernetes Engine (GKE) for deploying and managing the containerized applications, utilizing Kubernetes' native support for autoscaling and rolling updates.

  3. C

    Deploy the containers directly onto Compute Engine VM instances and manually manage scaling and updates.

  4. D

    Deploy the containers on App Engine standard environment and let App Engine handle scaling and updates.

Xem giải thích

Đáp án

B — Dùng Google Kubernetes Engine để triển khai và quản lý các ứng dụng container

Vì sao đúng

Đề nói tới một bộ nhiều ứng dụng đã container hoá và muốn tận dụng năng lực điều phối. Đó đúng là bài toán của GKE: đặt container lên node, tự khởi động lại khi chết, co giãn từng dịch vụ độc lập, khám phá dịch vụ và cân bằng tải nội bộ, triển khai cuốn chiếu và quay lui.

Vì sao các phương án khác sai

  • A. Cloud Run — rất tốt cho dịch vụ HTTP không trạng thái riêng lẻ, nhưng hạn chế khi cần điều phối nhiều thành phần phụ thuộc nhau hoặc chạy tiến trình nền lâu.
  • C. Chạy container thẳng trên máy ảo và tự quản lý — bỏ đi toàn bộ phần điều phối, nhiều việc vận hành nhất.
  • D. App Engine Standard — ràng buộc về môi trường chạy và không cho kiểm soát ở mức container.
Câu 319

An e-commerce company wants to migrate its payment microservice to Google Cloud. The service must be accessible globally with low latency, resilient to DDoS attacks, and must comply with strict security and audit requirements. The team has containerized the application and wants a solution that minimizes management overhead while still providing fine-grained traffic control and autoscaling. What should you do?

  1. A

    Deploy the container to Cloud Functions and use VPC Service Controls for network-level protection.

  2. B

    Deploy the container to Compute Engine VMs in multiple regions, and manage autoscaling using Instance Groups.

  3. C

    Deploy the container to Cloud Run with a global external HTTP(S) load balancer and protect it using Cloud Armor.

  4. D

    Use GKE Autopilot mode to deploy the application and expose it with an internal load balancer and network policy.

Xem giải thích

Đáp án

C — Cloud Run kèm load balancer HTTP(S) toàn cầu

Vì sao đúng

Ba yêu cầu của đề khớp đúng ba đặc điểm của bộ đôi này: truy cập toàn cầu độ trễ thấp nhờ load balancer hứng lưu lượng ở biên mạng và đưa tới khu vực gần nhất; chống DDoS nhờ hạ tầng của Google cộng Cloud Armor gắn được vào load balancer; và không phải vận hành gì vì Cloud Run co giãn theo lưu lượng, co về 0 khi rảnh.

Vì sao các phương án khác sai

  • **D. GKE Autopilot với load balancer nội bộ — nội bộ nghĩa là chỉ truy cập được từ trong VPC, trái hẳn yêu cầu phục vụ toàn cầu.
  • A. Cloud Functions với VPC Service Controls — Cloud Functions không nhận trực tiếp ảnh container theo cách đề mô tả, và Service Controls không phải cơ chế chống DDoS.
  • B. Máy ảo ở nhiều khu vực, tự quản lý co giãn — làm được nhưng gánh nặng vận hành lớn nhất.
Câu 320

For this question, refer to the Cymbal Retail case study.

https://services.google.com/fh/files/misc/v6.1_pca_cymbal_retail_case_study_english.pdf


Cymbal is consolidating customer and product data from multiple databases into Google Cloud to enable unified analytics and personalization. The data includes personally identifiable information (PII) and must comply with regulatory requirements. Cymbal wants fine-grained access control, strong auditing, and consistent security policies across analytics and machine learning workloads, without slowing down development teams. Which approach best meets Cymbal’s data security and compliance requirements while supporting scalable analytics?

  1. A

    Store sensitive customer data in Cloud SQL with private IP access and export anonymized data manually for analytics use cases.

  2. B

    Use BigQuery with column-level security and dynamic data masking, manage access through IAM groups, and enable Cloud Audit Logs for compliance reporting.

  3. C

    Replicate all sensitive data into separate projects for each team to ensure isolation and compliance.

  4. D

    Migrate all customer data into BigQuery and grant dataset-level access directly to individual users based on their roles.

Xem giải thích

Đáp án

B — BigQuery với bảo mật ở mức cột và che dữ liệu động

Vì sao đúng

Cymbal cần gom dữ liệu về một chỗ nhưng vẫn giới hạn ai thấy gì. BigQuery cho làm cả hai trên cùng một bản dữ liệu: bảo mật mức cột giấu hẳn những trường nhạy cảm khỏi người không có quyền, còn che dữ liệu động cho phép người khác vẫn truy vấn được nhưng chỉ thấy giá trị đã bị che. Không phải nhân bản dữ liệu ra nhiều bản đã lược bớt — mỗi bản sao là một chỗ có thể lệch và có thể rò.

Vì sao các phương án khác sai

  • C. Nhân bản dữ liệu nhạy cảm sang từng dự án riêng cho mỗi đội — chi phí nhân lên và các bản sao sẽ trôi khỏi nhau; nhiều bản sao dữ liệu nhạy cảm là nhiều bề mặt rủi ro.
  • D. Cấp quyền ở mức dataset — mức quá thô: hoặc thấy hết bảng hoặc không thấy gì.
  • A. Cloud SQL với IP riêng rồi xuất ra — không kham nổi quy mô phân tích, và việc xuất ra lại sinh thêm bản sao.