Ngân hàng đề — Google Professional Cloud Architect
Tìm thấy 420 câu.
For this question, refer to the EHR Healthcare case study.
https://services.google.com/fh/files/misc/v6.1_pca_ehr_healthcare_case_study_english.pdf
EHR Healthcare is expanding its operations and wants to establish connectivity between its data center and Google Cloud. The data center is located over 150 kilometers from the nearest Google point of presence, and high bandwidth is a critical requirement. They have a service provider offering private connectivity with guaranteed SLAs and no need for additional hardware at the data center. What connectivity option should you recommend?
-
A
Use Cloud VPN to establish a secure tunnel over the public Internet connection.
-
B
Use Carrier Peering for high-bandwidth, SLA-backed connectivity between the data center and Google Cloud.
-
C
Use Partner Interconnect to leverage the service provider's private connectivity.
-
D
Use Dedicated Interconnect for direct high-bandwidth communication between the data center and Google Cloud.
Xem giải thích
Đáp án
C — Partner Interconnect, tận dụng hạ tầng riêng của nhà cung cấp dịch vụ
Vì sao đúng
EHR cần kết nối riêng tư cho dữ liệu y tế, nhưng chưa tới mức phải đặt thiết bị tại cơ sở colocation của Google. Partner Interconnect là điểm cân bằng: nối qua nhà cung cấp đối tác đã có sẵn kết nối tới Google, chọn băng thông linh hoạt, và lưu lượng không đi qua Internet công cộng.
Vì sao các phương án khác sai
- A. Cloud VPN qua Internet công cộng — có mã hoá nhưng độ trễ và băng thông biến động.
- D. Dedicated Interconnect — băng thông cao nhất nhưng đòi hiện diện tại colocation và bắt đầu từ 10 Gbps; nặng hơn nhu cầu.
- B. Carrier Peering — cho truy cập dịch vụ công khai của Google qua nhà mạng, không vào được VPC riêng, nên không dùng để tích hợp hệ thống nội bộ.
For this question, refer to the EHR Healthcare case study.
https://services.google.com/fh/files/misc/v6.1_pca_ehr_healthcare_case_study_english.pdf
EHR Healthcare is migrating its customer-facing applications from multiple colocation facilities to Google Cloud. Several legacy file-based and API-based integrations with insurance providers must remain on-premises for the next few years. These integrations require low-latency, private, and highly reliable connectivity between on-premises systems and newly deployed workloads in Google Cloud. The lease for one of the on-premises data centers is expiring, but the remaining data centers will continue to operate. What is the most appropriate architecture to maintain secure and reliable connectivity between on-premises legacy systems and Google Cloud while minimizing operational risk and future rework?
-
A
Establish a site-to-site Cloud VPN from each on-premises data center directly to GKE clusters.
-
B
Use Partner Interconnect with a single VLAN attachment and route traffic over the public internet.
-
C
Use VPC Peering between on-premises networks and Google Cloud VPCs.
-
D
Deploy Dedicated Interconnect with redundant connections and use Cloud Router for dynamic routing.
Xem giải thích
Đáp án
D — Dedicated Interconnect với kết nối dự phòng, kèm Cloud Router
Vì sao đúng
So với câu trên, đề này nhấn vào băng thông cao và tính dự phòng cho việc di chuyển ở quy mô lớn. Ba mảnh khớp ba yêu cầu: Dedicated Interconnect cho đường riêng dung lượng lớn; kết nối dự phòng để mất một đường vẫn còn đường kia; và Cloud Router dùng BGP để tuyến được học và tính lại tự động khi có sự cố, thay vì chờ người sửa tay.
Vì sao các phương án khác sai
- B. Partner Interconnect với một VLAN attachment — một đường là một điểm hỏng duy nhất.
- A. VPN từ mỗi trung tâm dữ liệu — băng thông có trần theo đường hầm và chạy trên Internet công cộng.
- C. VPC Peering giữa mạng tại chỗ và VPC — peering chỉ nối hai VPC trong Google Cloud; đây là bẫy lặp lại nhiều lần trong bộ đề này.
Your company's development team is using a monorepo for their codebase. They need to set up a CI/CD pipeline that is capable of triggering a build only when changes are made to a certain directory in the repo. Which option below will achieve this?
-
A
Use Google Cloud Functions to monitor the Git repo and manually trigger a build process when changes are detected.
-
B
Utilize Cloud Build and create a trigger that filters on file changes within the desired directory.
-
C
Use Google Cloud Storage to store the repo and set up object change notifications.
-
D
Use Cloud Scheduler to execute the build process at a specific time regardless of the changes.
Xem giải thích
Đáp án
B — Dùng Cloud Build và tạo trigger lọc theo thay đổi tệp trong thư mục cụ thể
Vì sao đúng
Vấn đề đặc trưng của monorepo là một lần commit có thể chạm vào bất kỳ dịch vụ nào, và dựng lại toàn bộ mỗi lần là lãng phí lớn. Trigger của Cloud Build hỗ trợ lọc theo đường dẫn tệp, nên chỉ những dịch vụ có tệp thật sự thay đổi mới được dựng. Đây là tính năng có sẵn, không phải tự viết.
Vì sao các phương án khác sai
- A. Cloud Function theo dõi kho mã rồi kích hoạt bằng tay — tự dựng lại thứ đã có, và "bằng tay" thì không còn là tích hợp liên tục.
- D. Cloud Scheduler dựng theo giờ cố định bất kể có thay đổi hay không — dựng cả khi không có gì đổi, và phản hồi cho lập trình viên bị trễ tới lần chạy kế tiếp.
- C. Để mã nguồn trong Cloud Storage và dùng thông báo đổi đối tượng — kho đối tượng không phải hệ quản lý mã nguồn; mất lịch sử, nhánh và rà soát.
For this question, refer to the EHR Healthcare case study.
https://services.google.com/fh/files/misc/v6.1_pca_ehr_healthcare_case_study_english.pdf
EHR Healthcare has internal tools used by financial auditors, which are hosted on Compute Engine VMs behind an internal HTTP(S) Load Balancer. The auditors are third-party contractors who authenticate via external identity providers and use company-issued Chromebooks. The security team wants to ensure only these approved devices can access the tools. What should you do?
-
A
Deploy a public Load Balancer and restrict access with signed URLs.
-
B
Configure the internal load balancer with firewall rules to only allow traffic from specific IP address ranges.
-
C
se Identity-Aware Proxy (IAP) with context-aware access policies enforcing device-based conditions.
-
D
Enable Cloud Armor rules to filter requests based on request headers sent from Chromebooks.
Xem giải thích
Đáp án
C — Identity-Aware Proxy với chính sách truy cập theo ngữ cảnh, kiểm tra độ tin cậy của thiết bị
Vì sao đúng
Đây là mô hình zero trust: quyền truy cập quyết định theo danh tính người dùng cộng tình trạng thiết bị, chứ không theo việc họ đang ở trong mạng nào. IAP kiểm tra từng yêu cầu trước khi nó chạm tới ứng dụng, và chính sách theo ngữ cảnh chặn được cả trường hợp đúng người nhưng dùng máy chưa được quản lý hoặc chưa mã hoá ổ đĩa — đúng thứ dữ liệu y tế cần.
Vì sao các phương án khác sai
- A. Load balancer công khai với signed URL — signed URL dùng để chia sẻ tài nguyên tĩnh có hạn thời gian, không phải cơ chế kiểm soát truy cập ứng dụng.
- B. Load balancer nội bộ với luật tường lửa — quay về mô hình "vào được mạng là tin", đúng thứ zero trust bỏ đi.
- D. Cloud Armor lọc theo header — lọc theo IP và mẫu tấn công, không xác thực danh tính.
A healthcare analytics startup wants to integrate a BioMed-specific LLM available in Model Garden for extracting medical terms and summarizing clinical reports. The team must:
-
Keep all PHI (Protected Health Information) within Google Cloud.
-
Use the model in Vertex AI Workbench notebooks for experimentation.
-
Later deploy the model to Vertex AI Endpoints for serving in production.
As the Cloud Architect, which integration path should you recommend?
-
A
Export the model artifact from Model Garden and deploy it manually on an external GPU server for cost control.
-
B
Train a new LLM using Vertex AI Training on PHI data and manually tune it for medical summarization tasks.
-
C
Access the third-party BioMed model through Model Garden, deploy it to a Vertex AI Endpoint using managed infrastructure, and restrict access with VPC Service Controls and IAM roles.
-
D
Call the third-party model’s API directly from Workbench notebooks using public internet endpoints to avoid deployment steps.
Xem giải thích
Đáp án
C — Truy cập mô hình BioMed qua Model Garden rồi triển khai lên endpoint của Vertex AI
Vì sao đúng
Đây là con đường được hỗ trợ chính thức: mô hình của bên thứ ba dùng qua Model Garden và triển khai lên endpoint được quản lý, nên bạn được thừa hưởng nguyên bộ kiểm soát của Vertex AI — dữ liệu ở lại trong dự án của bạn, IAM quyết định ai gọi được, nhật ký kiểm toán ghi lại mọi lượt gọi, và endpoint tự co giãn. Với dữ liệu bệnh nhân thì phần kiểm soát này quan trọng ngang chất lượng mô hình.
Vì sao các phương án khác sai
- D. Gọi thẳng API của bên thứ ba qua Internet công khai — đưa dữ liệu bệnh nhân ra ngoài phạm vi kiểm soát; rủi ro tuân thủ nghiêm trọng nhất.
- A. Xuất mô hình ra rồi tự triển khai bên ngoài — thường vi phạm điều khoản cấp phép, và bạn tự gánh mọi việc vận hành lẫn bảo mật.
- B. Tự huấn luyện một mô hình mới trên dữ liệu bệnh nhân — cực kỳ tốn kém, và huấn luyện trên dữ liệu y tế còn kéo theo một tầng nghĩa vụ tuân thủ nữa.
As a new cloud architect, you need to manage your first GCP project. The project will involve product owners, developers and testers. You need to make sure that only specific members of the development team have access to sensitive information (PII data). To do this, you want to assign the appropriate IAM roles. What should you do?
-
A
You should assign a basic role to each user.
-
B
You should create groups. Assign an IAM Predefined role to each group as required, including those who should have access to sensitive data. Than, assign users to groups.
-
C
You should create groups. Assign a Custom role to each group, including those who should have access to sensitive data. Then, assign users to groups.
-
D
You should create groups. Assign a basic role to each group, and then assign users to groups.
Xem giải thích
Đáp án
B — Tạo nhóm, gán vai dựng sẵn (predefined role) cho từng nhóm theo nhu cầu
Vì sao đúng
Hai quyết định, và cả hai đều theo khuyến nghị chuẩn của Google Cloud:
- Gán cho nhóm, không cho từng người — nhân sự thay đổi thì chỉ sửa thành viên nhóm, không phải sửa chính sách IAM.
- Dùng vai dựng sẵn — chúng được Google thiết kế theo nguyên tắc quyền tối thiểu cho từng công việc cụ thể, và được cập nhật khi có tính năng mới.
Vì sao các phương án khác sai
- A. Gán vai cơ bản cho từng người — vai cơ bản (Owner, Editor, Viewer) rất rộng, và gán cho từng người thì không quản lý nổi.
- D. Gán vai cơ bản cho nhóm — đúng phần nhóm nhưng vẫn cấp quyền quá rộng.
- C. Tự tạo vai tuỳ chỉnh cho mọi nhóm — dùng được khi vai dựng sẵn thật sự không khớp, nhưng bạn phải tự bảo trì danh sách quyền mỗi khi Google thêm API mới; đừng bắt đầu từ đây.
Your company has two Google Cloud projects - Project A and Project B. The goal is to move data from a Cloud Storage bucket in Project A to another bucket in Project B on a regular schedule. Which of the following is the best way to achieve this?
-
A
Use the
gsutil cpcommand to manually copy the objects from the source bucket to the destination bucket. -
B
Use the Storage Transfer Service to schedule and manage the data transfer between the source and destination buckets.
-
C
Use Cloud Dataflow to create a pipeline that reads from the source bucket and writes to the destination bucket.
-
D
Use Cloud Functions to trigger a Cloud Storage event whenever data is added to the source bucket, which then copies the data to the destination bucket.
Xem giải thích
Đáp án
B — Dùng Storage Transfer Service để lên lịch và quản lý việc chuyển dữ liệu
Vì sao đúng
Đề cần chuyển dữ liệu giữa hai bucket theo lịch định kỳ. Storage Transfer Service là dịch vụ được quản lý dựng cho đúng việc đó: chạy theo lịch, tự thử lại khi lỗi, kiểm tra toàn vẹn, và ở những lần sau chỉ chuyển phần thay đổi. Không có mã nào phải viết và không có gì phải vận hành.
Vì sao các phương án khác sai
- A. Chép tay bằng
gsutil cp— thao tác tay không đáp ứng được yêu cầu định kỳ. - C. Tự viết pipeline Dataflow — dựng lại bằng tay thứ đã có dịch vụ làm sẵn, và phải trả tiền cho tài nguyên xử lý.
- D. Cloud Function kích hoạt theo sự kiện đối tượng mới — chạy theo sự kiện, không phải theo lịch; và bạn tự lo phần thử lại lẫn kiểm tra toàn vẹn.
For this question, refer to the Altostrat Media case study.
https://services.google.com/fh/files/misc/v6.1_pca_altostrat_media_case_study_english.pdf
Altostrat wants to increase user engagement and content virality by introducing a conversational experience that allows users to discover podcasts, videos, and documentaries through natural language queries (for example, “Show me short political podcasts similar to what I listened to yesterday”). The solution must integrate with their existing Google Cloud environment, scale automatically with traffic spikes, and leverage user behavior data already stored in BigQuery. Latency must remain low to support real-time interactions across web and mobile clients. Which architecture best enables personalized, conversational content discovery while aligning with best practices?
-
A
Use Vertex AI Gemini models with a retrieval-augmented generation (RAG) pattern, sourcing embeddings from BigQuery and Cloud Storage, and expose the conversational interface through Cloud Run.
-
B
Deploy a custom LLM on GKE, expose it through a Kubernetes service, and query Cloud Storage metadata directly for recommendations.
-
C
Deploy an open-source chatbot framework on Compute Engine and integrate it with BigQuery using scheduled jobs.
-
D
Use Dialogflow CX backed by a rules-based intent system and periodically batch-export recommendations from BigQuery.
Xem giải thích
Đáp án
A — Mô hình Vertex AI Gemini theo mẫu retrieval-augmented generation (RAG)
Vì sao đúng
RAG là cách đúng khi trợ lý phải trả lời dựa trên nội dung riêng của công ty: thay vì huấn luyện lại mô hình, hệ thống tìm ra những đoạn tài liệu liên quan rồi đưa vào ngữ cảnh cho mô hình sinh câu trả lời. Nhờ vậy nội dung mới có hiệu lực ngay khi được đánh chỉ mục, câu trả lời dẫn được nguồn, và nguy cơ bịa giảm hẳn.
Vì sao các phương án khác sai
- D. Dialogflow CX theo intent khai sẵn cộng cập nhật theo lô — chỉ trả lời được câu hỏi đã lường trước, và nội dung luôn chậm so với thực tế.
- B. Tự chạy một mô hình lớn trên GKE — bạn phải tự lo GPU, tối ưu suy luận và cập nhật mô hình.
- C. Chatbot mã nguồn mở trên máy ảo — tốn công nhất và gần như chắc chắn kém hơn mô hình được quản lý.
Your company has implemented a microservices architecture on Google Cloud and needs to streamline their deployment processes. They want to implement a Continuous Integration/Continuous Deployment (CI/CD) pipeline. What is the most appropriate action to take?
-
A
Use Cloud Functions to automate the deployment of services.
-
B
Utilize Google Cloud Source Repositories and set up triggers to automatically deploy code to App Engine.
-
C
Use Cloud Scheduler to schedule deployments.
-
D
Manually deploy code to Compute Engine instances.
Xem giải thích
Đáp án
B — Dùng Cloud Source Repositories và đặt trigger tự động triển khai
Vì sao đúng
Cốt lõi của tích hợp và triển khai liên tục là thay đổi mã tự động kích hoạt quy trình dựng và triển khai. Kho mã kết hợp trigger tạo ra đúng vòng lặp đó: đẩy mã lên là quy trình chạy, không ai phải nhớ bấm gì. Với kiến trúc microservice, đây cũng là cách để mỗi dịch vụ có đường phát hành riêng.
Vì sao các phương án khác sai
- C. Cloud Scheduler đặt lịch triển khai — triển khai theo giờ chứ không theo thay đổi; phản hồi cho lập trình viên bị trễ và có khi triển khai cả khi chẳng có gì mới.
- A. Dùng Cloud Functions để tự động hoá triển khai — tự viết lại một phần của công cụ CI/CD, thiếu phần theo dõi, phê duyệt và quay lui.
- D. Triển khai tay lên máy ảo — đúng thứ đề muốn bỏ.
You are the cloud architect for a large retail company that is migrating its on-premises data to Google Cloud. The company has three distinct projects: Production, Staging, and Development. They need to store sensitive customer data in Google Cloud Storage (GCS) and ensure that access to this data is strictly controlled. The following requirements must be met:
-
Only the
Productionproject team should have access to the customer data stored in GCS. -
Data must be encrypted both at rest and in transit.
-
The data should be accessible via a custom application running on Google Kubernetes Engine (GKE) in the
Productionproject. -
The company wants to ensure that the storage buckets are protected from accidental deletion or unauthorized access.
-
All access should be logged for auditing purposes.
Which of the following is the best approach to meet the company’s requirements?
-
A
Create a GCS bucket in the
Stagingproject, share it with theProductionproject using a bucket policy, and use Google-managed encryption keys. Use VPC Service Controls to restrict access and enable Object Versioning to protect against deletion. -
B
Create a GCS bucket in the
Productionproject, apply an IAM policy grantingroles/storage.objectViewerto theProductionproject, and use a customer-managed encryption key (CMEK) for encryption. Enable Object Versioning and use the--no-deletionsflag to prevent deletions. -
C
Create a GCS bucket in the
Productionproject, enforce IAM roles at the bucket level to grant access only to theProductionteam, use CMEK for encryption, enable Object Versioning, and enable detailed logging using Access Transparency and Data Access logs. -
D
Create a GCS bucket in a shared
Securityproject, grant access to theProductionproject team withroles/storage.admin, and use a CMEK for encryption. Implement bucket-level access policies and enable audit logs.
Xem giải thích
Đáp án
C — Tạo bucket trong dự án Production và siết vai IAM ngay ở mức bucket
Vì sao đúng
Hai quyết định đều hợp lý:
- Đặt bucket ở dự án Production — dữ liệu sản xuất nằm cùng ranh giới với tài nguyên sản xuất, nên quyền, hạn mức và chi phí quy về đúng chỗ.
- Cấp quyền ở mức bucket — mịn hơn cấp ở mức dự án, nên dự án Staging và Development được cấp đúng phần chúng cần mà không thấy tài nguyên khác trong Production.
Vì sao các phương án khác sai
- **B. Đặt bucket ở Production nhưng cấp quyền ở mức dự án — quyền lan ra mọi tài nguyên khác trong dự án sản xuất, rộng hơn nhiều so với nhu cầu.
- A. Đặt bucket ở dự án Staging — dữ liệu sản xuất nằm trong ranh giới của môi trường kém được bảo vệ hơn.
- D. Dựng một dự án Security riêng chỉ để chứa bucket — thêm một tầng quản trị mà đề không nêu nhu cầu nào biện minh.