Ngân hàng đề — Google Professional Cloud Architect

Tìm thấy 420 câu.

Câu 331

You have configured an autoscaling managed instance group (MIG) to serve traffic for your e-commerce website. The MIG is connected to an HTTP(S) load balancer. However, you notice that all requests to the backend are failing with a 502 (Bad Gateway) error. You confirmed that each VM in the instance group is healthy and serving traffic when accessed directly. What should you do to fix the issue?

  1. A

    Increase the health check interval and timeout settings to avoid frequent health check failures.

  2. B

    Ensure that a firewall rule allows traffic from the load balancer’s health check IP ranges to the VM instances.

  3. C

    Configure the backend service to use a TCP load balancer instead of an HTTP(S) load balancer.

  4. D

    Assign a static external IP to each VM instance in the group.

Xem giải thích

Đáp án

B — Đảm bảo có luật tường lửa cho phép lưu lượng từ dải IP health check của load balancer

Vì sao đúng

Đây là nguyên nhân phổ biến nhất khiến backend bị đánh dấu hỏng. Health check không đến từ Internet mà từ hai dải riêng của Google: 130.211.0.0/22 và 35.191.0.0/16. VPC mặc định chặn mọi lưu lượng đi vào, nên nếu chưa khai luật cho hai dải đó thì mọi lần kiểm tra đều thất bại và máy không bao giờ được coi là khoẻ.

Vì sao các phương án khác sai

  • A. Nới khoảng thời gian và thời gian chờ của health check — chỉ làm việc phát hiện chậm đi, không giải quyết chuyện gói tin không tới được máy.
  • C. Đổi sang load balancer TCP — che triệu chứng: cổng mở không có nghĩa ứng dụng phục vụ được.
  • D. Gán IP công khai tĩnh cho từng máy — phơi máy ra Internet mà vẫn không sửa đúng nguyên nhân.
Câu 332

For this question, refer to the EHR Healthcare case study.

https://services.google.com/fh/files/misc/v6.1_pca_ehr_healthcare_case_study_english.pdf


EHR Healthcare is migrating its customer-facing, containerized web applications from multiple colocation facilities to Google Cloud. The applications store and process protected health information (PHI) and must comply with healthcare regulations such as HIPAA. EHR operates in multiple countries and must ensure strong data protection, auditable access controls, and encryption without slowing down rapid application deployments on Kubernetes. Which architecture best helps maintain regulatory compliance for PHI while supporting scalable, container-based workloads on Google Cloud?

  1. A

    Deploy applications on GKE, store data in Cloud SQL, and restrict network access using firewall rules only.

  2. B

    Use GKE with Workload Identity, store data in Cloud SQL with customer-managed encryption keys (CMEK), centralize audit logs in Cloud Logging, and restrict access using IAM roles.

  3. C

    Deploy applications on GKE, store data in Cloud SQL and Firestore, enable default encryption, and rely on application-level logging for audits.

  4. D

    Run applications on Compute Engine VMs, encrypt disks manually using OpenSSL, and manage access using OS-level accounts.

Xem giải thích

Đáp án

B — GKE với Workload Identity, dữ liệu trong Cloud SQL dùng khoá mã hoá do khách hàng quản lý

Vì sao đúng

Hai mảnh này là điểm khác biệt thật so với các phương án còn lại:

  • Workload Identity — pod lấy quyền truy cập dịch vụ Google bằng danh tính của chính nó, nên không còn khoá tài khoản dịch vụ dạng tệp nằm trong cụm. Khoá tĩnh là thứ hay bị rò rỉ nhất.
  • Khoá mã hoá do khách hàng quản lý (CMEK) — bạn kiểm soát vòng đời khoá, xoay vòng và thu hồi được; với dữ liệu y tế thì đây thường là yêu cầu tuân thủ chứ không phải tuỳ chọn.

Vì sao các phương án khác sai

  • A và C. Dùng mã hoá mặc định của Google — vẫn mã hoá, nhưng khoá do Google giữ nên không đạt yêu cầu về quyền kiểm soát khoá.
  • D. Tự mã hoá đĩa bằng OpenSSL trên máy ảo — làm tay, không xoay vòng được, không kiểm toán được, và rất dễ sai.
Câu 333

A research team at a healthcare startup uses NotebookLM to summarize clinical studies and draft reports. They now want to extend their workflow by integrating Gemini Enterprise AI Agents, so that researchers can:

  1. Automatically ingest new papers from Cloud Storage.

  2. Summarize and reference key findings in NotebookLM.

  3. Ask context-aware questions across all uploaded documents.

As a Cloud Architect, how should you design this integration?

  1. A

    Configure Gemini AI Agents to automatically index new documents via Vertex AI Search, connect them to NotebookLM’s source documents, and provide conversational access via Gemini API.

  2. B

    Deploy NotebookLM within a separate VPC and restrict Gemini Agents to on-premises data only for compliance.

  3. C

    Upload all documents manually into NotebookLM, then export summaries via BigQuery for Gemini Agents to analyze.

  4. D

    Use Gemini AI Agents to continuously poll Cloud Storage, download files locally, and re-upload them into NotebookLM workspaces.

Xem giải thích

Đáp án

A — Cấu hình Gemini AI Agents tự đánh chỉ mục tài liệu mới qua Vertex AI Search

Vì sao đúng

Đội nghiên cứu muốn mở rộng quy trình hiện có, nên điều quan trọng là tài liệu mới được đưa vào kho tri thức tự động. Vertex AI Search lo phần đánh chỉ mục và truy xuất theo ngữ nghĩa, còn tác nhân dựa vào đó để trả lời có dẫn nguồn. Không có bước thủ công nào, nên kho tri thức không bao giờ lạc hậu so với tài liệu thật.

Vì sao các phương án khác sai

  • C. Tải tài liệu lên bằng tay rồi xuất tóm tắt — quy trình thủ công không mở rộng được và sẽ bị bỏ quên.
  • D. Cho tác nhân hỏi vòng Cloud Storage rồi tải tệp về máy — hỏi vòng tốn kém, có độ trễ, và việc tải dữ liệu lâm sàng xuống máy cục bộ là rủi ro bảo mật.
  • B. Tách NotebookLM sang VPC riêng và giới hạn tác nhân ở tại chỗ — cắt luôn khả năng tích hợp mà đề đang muốn xây.
Câu 334

As a cloud architect, you are designing a hybrid cloud setup where you need to connect on-premises infrastructure with Google Cloud. The on-premises network uses the IP range 192.168.0.0/16. You need to ensure that the IP range used on Google Cloud does not overlap with the on-premises range to avoid IP conflicts. Which of the following strategies should you adopt?

  1. A

    Choose an IP range of 192.168.0.0/16 for the Google Cloud network.

  2. B

    Choose an IP range of 192.168.0.0/24 for the Google Cloud network.

  3. C

    Choose an IP range of 10.0.0.0/16 for the Google Cloud network.

  4. D

    Choose an IP range of 192.168.1.0/24 for the Google Cloud network.

Xem giải thích

Đáp án

C — Chọn dải 10.0.0.0/16 cho mạng trên Google Cloud

Vì sao đúng

Mạng tại chỗ đang dùng dải 192.168.x.x, nên dải cho VPC phải không chồng lấn với nó. Trong ba dải địa chỉ riêng theo RFC 1918 — 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 — chọn nhánh 10.x là tách bạch hoàn toàn, và /16 còn để lại rất nhiều chỗ cho các subnet thêm sau.

Chồng dải địa chỉ là lỗi không sửa được về sau: định tuyến không phân biệt được đích đến, và cách chữa duy nhất là đánh lại địa chỉ cho cả một bên.

Vì sao các phương án khác sai

  • A. 192.168.0.0/16 — trùng nguyên khối với mạng tại chỗ; hỏng ngay lập tức.
  • B. 192.168.0.0/24 và D. 192.168.1.0/24 — đều nằm bên trong dải mà mạng tại chỗ đang dùng, nên vẫn chồng lấn dù nhỏ hơn.
Câu 335

You are a cloud architect working on an application that makes HTTP requests to a third-party API. To make your application more resilient, you decide to implement retry logic using a truncated exponential backoff strategy. Which of the following approaches would be the most effective way to implement this in your application?

  1. A

    Use the Retry class from the Google API client library, and configure it to use exponential backoff.

  2. B

    Implement a static wait time between retries, irrespective of the number of attempts made.

  3. C

    Implement a linear backoff strategy, increasing the wait time by a fixed amount after each failed attempt.

  4. D

    Immediately retry the request upon each failure without any wait time.

  5. E

    Use the Retry class from the Google API client library, and configure it to use a constant backoff strategy.

Xem giải thích

Đáp án

A — Dùng lớp Retry của thư viện Google API client, cấu hình theo exponential backoff

Vì sao đúng

Đề nêu đích danh truncated exponential backoff, và điểm cốt lõi của nó là thời gian chờ tăng theo cấp số nhân sau mỗi lần thất bại, có trần trên, kèm một chút ngẫu nhiên. Cách này giảm dần áp lực lên dịch vụ đang gặp sự cố thay vì dồn thêm vào. Dùng thư viện có sẵn tốt hơn tự viết vì phần khó — trần thời gian, độ lệch ngẫu nhiên, số lần thử tối đa — đã được xử lý đúng.

Vì sao các phương án khác sai

  • **E. Cùng lớp Retry nhưng cấu hình backoff hằng số — dùng đúng thư viện nhưng sai chiến lược; đây là phương án nhiễu gần nhất.
  • C. Backoff tuyến tính — có giãn ra nhưng chậm hơn cấp số nhân nhiều; dịch vụ đang quá tải vẫn bị dồn.
  • B. Thời gian chờ cố định — không thích ứng gì với mức độ sự cố.
  • D. Thử lại ngay không chờ — tệ nhất: dồn thêm tải vào đúng dịch vụ đang hỏng.
Câu 336

Your company is rapidly expanding its operations globally and the amount of data you need to store and analyze is increasing at an exponential rate. The data is highly variable, comprising structured and unstructured data, and comes from various sources such as logs, user-generated content, and IoT devices. As a cloud architect, you are tasked with devising a strategy to store and analyze this data in a cost-effective manner, while ensuring performance, scalability, and data accessibility. Which of the following options would be most suitable?

  1. A

    Store all data in Cloud Spanner and use BigQuery for analysis.

  2. B

    Use Cloud Bigtable for both storing and analyzing the data.

  3. C

    Store all data in Google Cloud Storage (GCS) and use Google BigQuery for analysis.

  4. D

    Store structured data in Cloud SQL and unstructured data in Cloud Storage, using BigQuery for analysis.

Xem giải thích

Đáp án

C — Lưu toàn bộ dữ liệu trong Cloud Storage và dùng BigQuery để phân tích

Vì sao đúng

Đề nói dữ liệu tăng theo cấp số nhân và đa dạng về loại. Cloud Storage nhận được mọi định dạng, không có trần dung lượng thực tế, và là nơi rẻ nhất để giữ. BigQuery truy vấn được — kể cả truy vấn thẳng trên tệp trong bucket bằng bảng ngoài, nên không phải nạp bản sao thứ hai. Đây là mô hình kho dữ liệu tách lưu trữ khỏi tính toán, hợp nhất với tăng trưởng khó đoán.

Vì sao các phương án khác sai

  • A. Lưu tất cả trong Cloud Spanner — Spanner là CSDL giao dịch nhất quán mạnh, rất đắt và không phải nơi chứa dữ liệu thô khối lượng lớn.
  • B. Bigtable cho cả lưu trữ lẫn phân tích — không hỗ trợ SQL phân tích.
  • D. Chia đôi Cloud SQL và Cloud Storage — Cloud SQL có trần mở rộng, thành nút thắt khi dữ liệu tăng nhanh.
Câu 337

You are architecting a web application on Google Cloud that is expected to store and process personal data from users in the European Union (EU), thus it must meet the General Data Protection Regulation (GDPR) requirements. Which of the following strategies would you adopt?

  1. A

    Store all personal data in a multi-regional storage bucket, and leverage Google Cloud Data Loss Prevention (DLP) to discover, classify, and redact sensitive data.

  2. B

    Store all personal data in a regional storage bucket in an EU country, leverage Google Cloud Armor for data protection, and use Cloud Audit Logs for auditing.

  3. C

    Implement user authentication and authorization using Firebase Authentication, and store all personal data in a multi-regional storage bucket.

  4. D

    Store all personal data in a regional storage bucket in the United States, and leverage Google's built-in data protection features.

Xem giải thích

Đáp án

B — Lưu dữ liệu cá nhân trong bucket theo vùng đặt tại một quốc gia thuộc EU

Vì sao đúng

Yêu cầu về nơi lưu trữ dữ liệu phải được thực thi bằng kiến trúc chứ không bằng quy trình. Bucket theo vùng cho bạn khai đích danh khu vực, nên dữ liệu cá nhân của người dùng châu Âu nằm lại trong EU và bạn chứng minh được điều đó khi bị hỏi.

Vì sao các phương án khác sai

  • A. Bucket đa vùng — nghe an toàn hơn vì nhân bản rộng, nhưng chính điều đó là vấn đề: bạn mất quyền kiểm soát chính xác dữ liệu được đặt ở đâu.
  • D. Bucket theo vùng đặt tại Mỹ — vi phạm thẳng yêu cầu về nơi lưu trữ.
  • C. Dùng Firebase Authentication để xác thực và phân quyền — cần thiết cho phần truy cập, nhưng không trả lời câu hỏi dữ liệu nằm ở đâu, mà đó mới là điều quy định quan tâm.
Câu 338

For this question, refer to the Altostrat Media case study.

https://services.google.com/fh/files/misc/v6.1_pca_altostrat_media_case_study_english.pdf 


Altostrat wants the chatbot to deliver highly personalized assistance, such as:

  • Recommending content based on recent user behavior

  • Tailoring responses according to subscription tier and preferred genres

  • Continuously improving response quality using historical conversation data

The solution must respect data security best practices, support real-time interactions, and allow data scientists to iterate quickly on personalization logic. What is the most appropriate approach to enable real-time personalization for the chatbot?

  1. A

    Export all user data to Cloud Storage and perform batch personalization using scheduled Dataflow jobs.

  2. B

    Hard-code personalization rules directly into Dialogflow intents and entities.

  3. C

    Store user interaction data in BigQuery, use Vertex AI feature stores for real-time features, and invoke Vertex AI models from Cloud Run during chatbot interactions.

  4. D

    Cache all personalization logic in Memorystore and periodically refresh it from on-premises systems.

Xem giải thích

Đáp án

C — Dữ liệu tương tác trong BigQuery, dùng Vertex AI Feature Store cho phần phục vụ thời gian thực

Vì sao đúng

Cá nhân hoá cần đặc trưng ở hai tốc độ khác nhau, và Feature Store tồn tại đúng vì lý do đó: BigQuery giữ dữ liệu lịch sử để tính đặc trưng và huấn luyện mô hình, còn Feature Store phục vụ chính những đặc trưng đó ở độ trễ thấp lúc người dùng đang thao tác. Quan trọng hơn, nó đảm bảo đặc trưng lúc huấn luyện và lúc phục vụ được tính giống hệt nhau — chênh lệch giữa hai bên là lỗi kinh điển khiến mô hình chạy tốt khi thử mà tệ khi thật.

Vì sao các phương án khác sai

  • A. Xuất dữ liệu ra Cloud Storage rồi cá nhân hoá theo lô — kết quả luôn cũ, không phản ứng được với hành vi vừa xảy ra.
  • D. Nhồi toàn bộ logic cá nhân hoá vào Memorystore rồi làm mới định kỳ — bộ đệm không thay được tầng đặc trưng, và vẫn có độ trễ dữ liệu.
  • B. Viết cứng luật cá nhân hoá vào intent của Dialogflow — không phải cá nhân hoá dựa trên dữ liệu, và không mở rộng được.
Câu 339

You are a cloud architect for a large-scale company that is transitioning its monolithic applications to a microservices-based architecture on Google Cloud. You have been tasked with recommending an optimal strategy for deploying, managing, and scaling these microservices. Which of the following approaches would be most effective?

  1. A

    Use Compute Engine to individually manage each microservice, utilizing autoscaling groups to handle scaling.

  2. B

    Deploy each microservice as a separate App Engine application, utilizing App Engine's automatic scaling and load balancing capabilities.

  3. C

    Use Cloud Functions for each microservice, utilizing the event-driven nature of Cloud Functions to manage and scale services.

  4. D

    Deploy the microservices on Google Kubernetes Engine (GKE), utilizing the orchestration capabilities of Kubernetes to manage and scale services.

Xem giải thích

Đáp án

D — Triển khai microservice trên Google Kubernetes Engine

Vì sao đúng

Chuyển từ ứng dụng nguyên khối sang microservice thì thứ cần nhất là năng lực điều phối: đặt container ở đâu, khởi động lại khi chết, co giãn từng dịch vụ độc lập, khám phá dịch vụ, cân bằng tải nội bộ, triển khai cuốn chiếu và quay lui. GKE làm sẵn tất cả những việc đó, và với một tổ chức lớn có nhiều dịch vụ thì đây là nền tảng có đường phát triển rõ ràng nhất.

Vì sao các phương án khác sai

  • A. Tự quản lý từng microservice trên máy ảo — bạn tự dựng lại toàn bộ phần điều phối, nhiều việc vận hành nhất.
  • B. Mỗi microservice là một ứng dụng App Engine riêng — một dự án chỉ có một ứng dụng App Engine; đúng ra phải dùng khái niệm service bên trong một ứng dụng.
  • C. Mỗi microservice là một Cloud Function — hợp cho việc ngắn theo sự kiện, vướng giới hạn thời gian chạy và khó điều phối khi các dịch vụ gọi lẫn nhau.
Câu 340

Your organization has a web application running on a single virtual machine (VM) in Google Compute Engine. The application is experiencing high traffic and the VM is struggling to handle the load. You want to scale the application to multiple VMs to increase performance and availability. However, the application requires access to a shared file system for storing user data. What is the most efficient and cost-effective way to scale the application while still maintaining access to the shared file system?

  1. A

    Modify the application to store user data in a distributed database, such as Cloud Spanner, and configure each VM to access the database.

  2. B

    Use a managed file storage service, such as Google Cloud Filestore, and configure each VM to mount the shared file system.

  3. C

    Create a dedicated VM to host the shared file system and configure each VM in the auto-scaling group to mount the file system.

  4. D

    Use Google Cloud Storage to store user data and modify the application to access the data through the Cloud Storage API.

Xem giải thích

Đáp án

B — Dùng dịch vụ lưu trữ tệp được quản lý như Cloud Filestore

Vì sao đúng

Khi mở rộng từ một máy ra nhiều máy, vấn đề mới xuất hiện là các máy phải thấy chung một tập tệp. Filestore cung cấp hệ tệp NFS được quản lý mà mọi máy gắn vào cùng lúc, nên ứng dụng không phải sửa mã — nó vẫn đọc ghi theo đường dẫn tệp như trước. Đây là con đường ngắn nhất từ một máy sang nhiều máy.

Vì sao các phương án khác sai

  • C. Tự dựng một máy ảo làm máy chủ tệp — làm được nhưng thành điểm hỏng duy nhất, và bạn tự lo sao lưu, vá lỗi, co giãn.
  • A. Chuyển dữ liệu người dùng sang CSDL phân tán và D. Chuyển sang Cloud Storage — cả hai đều là hướng đi tốt về lâu dài, nhưng đòi sửa ứng dụng: phải đổi từ thao tác tệp sang gọi API. Đề đang tìm cách mở rộng ngay.