Ngân hàng đề — Google Professional Cloud Architect
Tìm thấy 420 câu.
A financial services company needs to build a cloud-based system for processing and storing various types of financial data, including real-time transaction records, large historical datasets, and audit logs. The system must ensure data integrity, compliance with financial regulations, and cost-effective storage for large amounts of historical data that are infrequently accessed. You are tasked with designing the storage architecture for this system on Google Cloud. Which two storage types would best satisfy the requirements for data integrity, compliance, and cost-effectiveness? (Choose two)
-
A
Deploy a Cloud SQL instance with automated backups for storing real-time transaction records.
-
B
Store real-time transaction records in Cloud Firestore for strong consistency and low-latency access.
-
C
Use BigQuery to store and analyze large historical datasets.
-
D
Store audit logs in Cloud Storage with a Coldline storage class for cost-effective long-term retention.
-
E
Store historical datasets in Google Drive for easy access and sharing among teams.
Xem giải thích
Đáp án
C và D — BigQuery cho tập dữ liệu lịch sử lớn, và Cloud Storage lớp Coldline cho nhật ký kiểm toán
Vì sao đúng
Mỗi loại dữ liệu về đúng nơi hợp với mẫu truy cập của nó:
- C. BigQuery cho dữ liệu lịch sử — được truy vấn và phân tích thường xuyên ở quy mô lớn, đúng thứ BigQuery làm tốt nhất.
- D. Coldline cho nhật ký kiểm toán — phải giữ vì quy định nhưng gần như không bao giờ đọc; Coldline là mức giá hợp với nhịp truy cập hàng quý trở lên.
Vì sao các phương án khác sai
- E. Để dữ liệu lịch sử trên Google Drive — không phải kho dữ liệu, không truy vấn được, và không đạt yêu cầu quản trị của ngành tài chính.
- A. Cloud SQL cho bản ghi giao dịch thời gian thực — có sao lưu tự động nhưng vẫn là CSDL một máy chủ, có trần thông lượng.
- B. Firestore cho bản ghi giao dịch — Firestore mạnh về đồng bộ thời gian thực nhưng không phải sổ cái giao dịch tài chính khối lượng lớn.
Your retail company deploys environmental sensors across 2,000 stores to monitor temperature and humidity. Each sensor emits data every second. The sensors have intermittent internet access and can only buffer data locally for a few minutes. The data must be ingested reliably for real-time alerts and historical analysis. What ingestion architecture should you implement?
-
A
Configure Cloud Run to expose an HTTP endpoint for device ingestion and log events to Cloud Logging.
-
B
Use Pub/Sub with an MQTT bridge to publish messages from devices to a shared topic.
-
C
Use Firebase Realtime Database to stream telemetry from devices to backend services.
-
D
Collect data using Cloud Storage signed URLs that devices write to every minute.
Xem giải thích
Đáp án
B — Pub/Sub kèm cầu nối MQTT để thiết bị đăng thông điệp vào topic dùng chung
Vì sao đúng
Hai đặc điểm của đề quyết định lựa chọn: hàng nghìn thiết bị gửi dữ liệu mỗi giây, và kết nối chập chờn. MQTT là giao thức dựng riêng cho thiết bị IoT — nhẹ, chịu được mạng kém, có cơ chế đảm bảo giao tin. Đưa qua Pub/Sub thì phần đệm và phân phối được lo sẵn: thiết bị mất sóng rồi kết nối lại vẫn gửi được, và bên tiêu thụ đọc theo nhịp của mình.
Vì sao các phương án khác sai
- A. Cloud Run mở điểm cuối HTTP cho thiết bị gọi vào — HTTP nặng hơn MQTT nhiều và không chịu mạng chập chờn tốt; mỗi lần gửi lại phải bắt tay lại.
- D. Thiết bị ghi vào Cloud Storage qua signed URL mỗi phút — dữ liệu bị gom thành lô một phút, mất tính thời gian thực, và số lượng đối tượng nhỏ sinh ra rất lớn.
- C. Firebase Realtime Database — dựng cho đồng bộ trạng thái ứng dụng di động, không phải kênh nạp dữ liệu đo lường khối lượng lớn.
A multinational corporation with offices in multiple regions is looking to deploy a disaster recovery solution to ensure business continuity in the event of a regional disaster. They have the following requirements:
-
minimize downtime in the event of a disaster
-
automatically failover to a secondary site in the event of a disaster
-
ensure data consistency between the primary and secondary sites
-
cost-effective solution
Which of the following Google Cloud solutions would best meet these requirements?
-
A
Cloud Load Balancer with auto-scaling groups.
-
B
Cloud SQL with read replicas in multiple regions.
-
C
Cloud Storage with object versioning and multi-region bucket replication.
-
D
Cloud Datastore with multi-region replication.
Xem giải thích
Đáp án
C — Cloud Storage với object versioning và bucket nhân bản đa vùng
Vì sao đúng
Đề hỏi giải pháp khôi phục sau thảm hoạ cấp khu vực, và phương án này phủ hai kiểu mất mát khác nhau:
- Bucket đa vùng — dữ liệu được nhân bản qua nhiều khu vực, nên mất trọn một khu vực vẫn còn bản khác.
- Object versioning — giữ lại bản cũ khi đối tượng bị ghi đè hoặc xoá, nên xoá nhầm hay bị mã hoá tống tiền vẫn quay lại được. Nhân bản không cứu được kiểu mất mát này, vì thao tác xoá cũng được nhân bản theo.
Vì sao các phương án khác sai
- B. Cloud SQL với bản sao đọc ở nhiều khu vực — chỉ lo tầng CSDL và bản sao vẫn chạy sau bản chính.
- A. Load balancer với nhóm tự co giãn — lo tính sẵn sàng của tầng ứng dụng, không phải khôi phục dữ liệu.
- D. Datastore nhân bản đa vùng — chỉ áp cho dữ liệu trong Datastore, hẹp hơn nhiều so với nhu cầu chung của đề.
You have deployed a managed instance group (MIG) as the backend for a global HTTP(S) load balancer. The load balancer intermittently marks some instances as unhealthy and removes them from serving traffic. You verify that the VM instances are serving the correct responses. What should you do to resolve this issue?
-
A
Add an additional health check with TCP protocol to supplement the existing HTTP health check.
-
B
Assign public IP addresses to the backend instances and update the health check configuration to use the public IPs.
-
C
Create a firewall rule that allows HTTP traffic from any source to the backend instances.
-
D
Configure a health check on the load balancer with a URL path that matches the application’s status endpoint.
Xem giải thích
Đáp án
D — Cấu hình health check với đường dẫn URL khớp điểm kiểm tra sức khoẻ của ứng dụng
Vì sao đúng
Máy bị đánh dấu hỏng không đều thường là dấu hiệu health check đang gọi sai chỗ: nếu nó gọi / mà đường dẫn đó nặng hoặc phụ thuộc dịch vụ khác, thì lúc nào ứng dụng bận là kiểm tra thất bại. Trỏ health check vào một điểm cuối nhẹ dựng riêng cho việc này — trả về nhanh và chỉ phản ánh tình trạng của chính bản chạy đó — khiến kết quả kiểm tra ổn định và đúng.
Vì sao các phương án khác sai
- A. Thêm health check TCP bổ sung — TCP chỉ kiểm tra cổng có mở không; máy có ứng dụng đã treo vẫn bị coi là khoẻ, tức là làm kết quả tệ hơn.
- **C. Mở luật tường lửa cho HTTP từ mọi nguồn — vừa quá rộng về bảo mật, vừa không đúng nguyên nhân khi vấn đề là chập chờn chứ không phải hỏng hoàn toàn.
- B. Gán IP công khai cho từng máy backend — phơi máy ra Internet mà không cần thiết; health check đến từ dải riêng của Google.
A company is planning to migrate a large number of virtual machines (VMs) from an on-premises data center to Google Cloud Platform (GCP). The VMs are running a mix of Linux and Windows operating systems and have varying CPU, memory, and storage requirements. Which of the following options would be the most effective approach to automate the migration process and minimize downtime?
-
A
Use the Google Cloud Migrate for Compute Engine to automate the discovery, assessment, and migration of the VMs to Google Compute Engine.
-
B
Use the Google Cloud Deployment Manager to automate the creation and configuration of new instances in Google Compute Engine, and then manually transfer data to the new instances.
-
C
Use Google Cloud Storage Transfer Service to transfer data to GCP and then manually create and configure new instances in Google Compute Engine.
-
D
Use the Google Cloud Dataproc to automate the creation and configuration of new instances in Google Compute Engine, and then use the Hadoop Distributed File System (HDFS) to transfer data to the new instances.
Xem giải thích
Đáp án
A — Dùng Migrate for Compute Engine để tự động phát hiện, đánh giá và di chuyển
Vì sao đúng
Đây là công cụ dựng riêng cho việc chuyển hàng loạt máy ảo từ trung tâm dữ liệu lên Google Cloud. Nó lo cả ba khâu: quét để lập danh sách máy và phụ thuộc giữa chúng, đánh giá để ước tính tài nguyên và chi phí, rồi chuyển với thời gian gián đoạn rất ngắn nhờ nhân bản dữ liệu trước khi cắt chuyển. Hỗ trợ cả Linux lẫn Windows.
Vì sao các phương án khác sai
- B. Deployment Manager — công cụ hạ tầng dạng mã để tạo tài nguyên mới, không di chuyển máy đang chạy.
- C. Storage Transfer Service rồi dựng lại máy bằng tay — chỉ chuyển dữ liệu; phần dựng lại từng máy làm tay là nơi tốn công và sinh lỗi nhất.
- D. Dataproc — cụm Hadoop/Spark, hoàn toàn không liên quan.
A company is planning to deploy a new web application on Google Cloud Platform (GCP) that will handle sensitive customer data. In order to meet security and compliance requirements, which of the following strategies should be considered when designing the application's architecture?
-
A
Store sensitive data in Cloud Bigtable and use Identity and Access Management (IAM) to manage access.
-
B
Store sensitive data in Cloud Datastore and use Cloud Data Loss Prevention (DLP) to classify and redact sensitive data.
-
C
Store sensitive data in Cloud SQL and implement role-based access controls to restrict access.
-
D
Store sensitive data in Cloud Storage and use customer-managed encryption keys to secure data at rest.
Xem giải thích
Đáp án
B — Lưu dữ liệu nhạy cảm trong Datastore và dùng Cloud DLP
Vì sao đúng
Điểm phân biệt của phương án này là Cloud DLP — công cụ duy nhất trong danh sách thực sự xử lý bản thân dữ liệu nhạy cảm: nó phát hiện thông tin cá nhân nằm rải trong dữ liệu bằng hơn một trăm bộ nhận dạng, rồi khử định danh bằng cách che, thay bằng token hoặc mã hoá giữ định dạng. Ba phương án còn lại chỉ kiểm soát ai truy cập, không đụng tới nội dung.
Vì sao các phương án khác sai
- A. Bigtable với IAM và C. Cloud SQL với phân quyền theo vai — kiểm soát truy cập là cần thiết nhưng chưa đủ: người có quyền vẫn thấy nguyên thông tin cá nhân.
- D. Cloud Storage với khoá mã hoá do khách hàng quản lý — bảo vệ khi lưu trữ, nhưng ai giải mã được là thấy hết; và không phát hiện được dữ liệu nhạy cảm nằm ở đâu.
Your company has a service that needs to run on a fleet of identical instances and scales according to traffic patterns. You are tasked with setting up a Managed Instance Group (MIG) on Google Cloud Platform. The instances are created from an instance template and a startup script, which fetches the latest version of the application code from a Cloud Storage bucket every time an instance starts. However, your company wants to avoid any potential downtime when deploying updates to the application. Which strategy should you recommend?
-
A
Manually replace instances in the MIG after updating the application.
-
B
Use a rolling update to gradually replace instances in the MIG.
-
C
Increase the number of instances in the MIG before deploying an update to the application.
-
D
Modify the application code to poll the Cloud Storage bucket for updates periodically.
Xem giải thích
Đáp án
B — Dùng rolling update để thay dần các máy trong nhóm
Vì sao đúng
Rolling update là cơ chế cập nhật có sẵn của managed instance group: nó thay máy từng phần theo tham số bạn khai (max-surge, max-unavailable), chờ máy mới qua health check rồi mới gỡ máy cũ. Nhờ vậy dịch vụ không gián đoạn, tiến độ theo dõi được, và có vấn đề thì dừng hoặc quay lui giữa chừng.
Vì sao các phương án khác sai
- A. Thay máy bằng tay sau khi cập nhật — không mở rộng được, và thao tác tay là chỗ sinh lỗi.
- C. Tăng số máy trước rồi mới triển khai — có thêm năng lực dự phòng nhưng không giải quyết chuyện cập nhật thế nào; vẫn phải có cơ chế thay máy.
- D. Sửa ứng dụng để tự hỏi vòng Cloud Storage tìm bản mới — tự dựng một cơ chế triển khai riêng bên trong ứng dụng, khó theo dõi và không quay lui được.
Your organization is operating several Compute Engine instances on Google Cloud Platform. You've been asked to ensure that logs from these instances are centralized and accessible from the Cloud Logging. Given the different operational needs and data sensitivities across instances, which strategy would ensure appropriate setup of the Cloud Logging agent?
-
A
Install the Cloud Logging agent on each instance and have it log data to individual Cloud Logging projects based on each instance's operational needs and data sensitivity.
-
B
Install the Cloud Logging agent on each instance and log data to a single Cloud Logging project to consolidate all logs.
-
C
Install the Cloud Logging agent on each instance and configure the agent to log data to Cloud Storage instead of Cloud Logging to save costs.
-
D
Install the Cloud Logging agent on a single, dedicated instance and use that to log data from all other instances.
Xem giải thích
Đáp án
A — Cài Cloud Logging agent trên từng máy
Vì sao đúng
Điểm mấu chốt là agent phải chạy trên mỗi máy sinh ra log. Agent đọc log cục bộ của máy đó rồi đẩy lên Cloud Logging, nên dữ liệu được gom về một nơi để tra cứu, đặt cảnh báo và định tuyến sang nơi lưu trữ dài hạn bằng log sink. Máy bị thay hay bị xoá cũng không mất log, vì chúng đã rời khỏi máy.
Vì sao các phương án khác sai
- D. Chỉ cài agent trên một máy chuyên trách rồi gom qua đó — máy đó không đọc được log nằm trên các máy khác; muốn vậy phải tự dựng cơ chế chuyển log, tức là làm lại thứ agent đã có. Nó cũng thành điểm hỏng duy nhất.
- B và C — cùng đặt sai nơi ghi hoặc sai phạm vi gom, nên không đạt yêu cầu vừa tập trung vừa truy cập được từ một chỗ.
You are a cloud architect for a healthcare provider that must deploy a multi-region application on Google Cloud to manage patient data. The application needs to comply with HIPAA regulations, ensuring strong encryption, access control, and protection against data breaches. The application is deployed across two regions, with the front-end services, API layer, and database distributed for high availability. You need to design a network topology that provides robust security, including intrusion protection, and ensures that only authorized healthcare professionals can access sensitive data. What network configuration should you implement to meet these requirements?
-
A
Utilize a Global VPC that spans both regions, with separate subnets for the application tiers in each region. Deploy Cloud Armor for DDoS protection, enable Cloud DNS with DNSSEC for secure name resolution, and use VPC Service Controls to enforce access policies.
-
B
Deploy the application across two VPCs, one in each region, connected via VPC Peering. Use Cloud VPN to secure inter-region traffic, implement Firewall rules for access control, and enable Cloud IDS for intrusion detection.
-
C
Set up a Shared VPC with subnets in each region. Use Cloud Interconnect to connect the regions, configure Firewall rules to manage inter-tier communication, deploy Cloud IDS for intrusion detection, and implement IAM conditions for fine-grained access control.
-
D
Deploy the application in a Global VPC with Private Google Access enabled. Implement Cloud NAT for secure outgoing traffic, use Cloud Router with dynamic routing for inter-region communication, and deploy Security Command Center for centralized security management.
Xem giải thích
Đáp án
A — Global VPC trải cả hai khu vực, mỗi tầng một subnet riêng
Vì sao đúng
VPC của Google Cloud vốn đã toàn cầu, nên một VPC chứa subnet ở cả hai khu vực và chúng nói chuyện bằng IP riêng qua mạng xương sống của Google — không cần peering, không cần đường hầm. Với dữ liệu bệnh nhân, việc chỉ có một bộ luật tường lửa để quản lý cũng là ưu điểm thật: ít chỗ cấu hình sai hơn.
Vì sao các phương án khác sai
- B. Hai VPC nối bằng peering — tự dựng lại thứ đã có sẵn, và thành hai bộ luật tường lửa phải giữ đồng bộ.
- C. Shared VPC với Cloud Interconnect — Shared VPC dùng để chia sẻ mạng giữa các dự án, còn Interconnect để nối từ ngoài vào; cả hai đều không phải công cụ nối hai khu vực.
- D — có Global VPC nhưng phần còn lại của phương án không đáp ứng yêu cầu phân tách các tầng.
Within your company, each developer possesses an individual development Google Cloud Platform (GCP) project associated with a central billing account. You have recommended that they establish alerts for any situations where a developer exceeds a monthly expenditure of $500. What actions should they take to implement these alerts?
-
A
They should set up a single budget for all development projects. Then, set an alert for budget when expenses exceed $ 500.
-
B
Export billing data from all development projects to a single BigQuery dataset. Use a Data Studio dashboard to plot expenses.
-
C
They should set up a single budget for all development projects. Then, set an alert for budget when expenses exceed $ 500 multiplied by the number of developers.
-
D
They should set up a budget for each development projects. Then, set an alert for each budget when expenses exceed $ 500.
Xem giải thích
Đáp án
D — Đặt một ngân sách cho từng dự án, mỗi ngân sách đặt cảnh báo ở mức 500 đô la
Vì sao đúng
Yêu cầu là biết khi một lập trình viên nào đó vượt 500 đô la mỗi tháng. Vì mỗi người có dự án riêng, ngân sách phải đặt ở mức dự án thì cảnh báo mới chỉ đích danh người vượt.
Vì sao các phương án khác sai
- A. Một ngân sách chung cho mọi dự án, cảnh báo ở 500 đô la — cảnh báo sẽ kêu ngay khi tổng chi tiêu của cả đội vượt 500, tức là gần như lập tức, dù chưa ai vượt mức cá nhân.
- C. Một ngân sách chung, cảnh báo ở 500 nhân số lập trình viên — chỉ đúng khi mọi người tiêu đều nhau. Một người tiêu 3.000 trong khi năm người còn lại gần như không tiêu gì thì tổng vẫn dưới ngưỡng và cảnh báo không bao giờ kêu — đúng lúc cần nhất.
- B. Xuất dữ liệu thanh toán ra BigQuery rồi vẽ biểu đồ — cho cái nhìn tốt về chi phí nhưng không chủ động báo cho ai; phải có người ngồi xem.