Ngân hàng đề — Google Professional Cloud Architect

Tìm thấy 420 câu.

Câu 351

Your company is using a Google Kubernetes Engine (GKE) to run a mission-critical web application. The application's traffic patterns are inconsistent, with significant spikes in demand at unpredictable intervals. You are tasked with ensuring the application is highly available and responsive, while maintaining cost-effectiveness. Which of the following autoscaling configurations should you use?

  1. A

    Set up a custom autoscaling policy based on network traffic, triggering scaling at 90% of peak traffic.

  2. B

    Set up a custom autoscaling policy based on the number of incoming requests, triggering scaling after 1000 requests per second.

  3. C

    Configure GKE autoscaling to scale based on memory utilization, set at 70%.

  4. D

    Configure GKE autoscaling with CPU utilization as the primary metric, set at 80%.

Xem giải thích

Đáp án

D — Cấu hình tự co giãn của GKE theo mức dùng CPU, đặt ngưỡng 80%

Vì sao đúng

CPU là tín hiệu co giãn mặc định và đáng tin nhất cho ứng dụng web: nó phản ánh trực tiếp lượng công việc đang xử lý, có sẵn không phải dựng gì, và tăng giảm theo cả hai chiều nên co lên và co xuống đều hoạt động. Ngưỡng 80% để lại phần dự phòng đủ cho các đợt tăng đột ngột trong lúc pod mới khởi động.

Vì sao các phương án khác sai

  • C. Co giãn theo bộ nhớ ở mức 70% — bộ nhớ là tín hiệu tệ cho ứng dụng web: nó thường không giảm khi tải giảm vì bộ đệm và cơ chế thu gom rác giữ lại, nên hệ thống co lên rồi không bao giờ co xuống.
  • A và B. Tự dựng chính sách theo lưu lượng mạng hoặc số yêu cầu — số yêu cầu là tín hiệu tốt về mặt lý thuyết, nhưng phải dựng thêm đường ống số liệu tuỳ chọn; chỉ đáng khi CPU thật sự không phản ánh đúng tải.
Câu 352

You are working as a cloud architect for a global e-commerce company that expects its user base to grow significantly over the next three years. The company's operations span multiple regions, and it requires a storage solution that supports both high availability and data redundancy across regions. The company also needs to ensure that the storage system can scale effectively to accommodate data growth while optimizing costs. You are tasked with designing a Google Cloud Storage solution that meets these requirements. Additionally, the company wants to minimize the risk of data loss in case of regional outages and ensure that the solution is future-proof for anticipated data growth. Which Google Cloud Storage solution should you recommend, considering the need for multi-regional availability, scalability, data redundancy, and cost optimization?

  1. A

    Use Regional Cloud Storage with Standard storage class and configure Cross-Region Replication for redundancy.

  2. B

    Use Multi-Regional Cloud Storage with Nearline storage class and configure Object Lifecycle Management to delete objects after 365 days.

  3. C

    Use Regional Cloud Storage with Coldline storage class and create snapshots for redundancy across regions.

  4. D

    Use Multi-Regional Cloud Storage with Standard storage class and configure Object Versioning.

Xem giải thích

Đáp án

D — Cloud Storage đa vùng ở lớp Standard, kèm Object Lifecycle Management

Vì sao đúng

Hai mảnh khớp hai yêu cầu của một công ty thương mại điện tử toàn cầu đang tăng trưởng:

  • Đa vùng, lớp Standard — dữ liệu được nhân bản qua nhiều khu vực nên bền và gần người dùng ở mọi nơi; lớp Standard không có phí truy xuất, hợp với dữ liệu được đọc thường xuyên.
  • Object Lifecycle Management — tự động đẩy dữ liệu cũ xuống lớp lạnh hơn theo thời gian, nên chi phí không tăng tuyến tính theo khối lượng tích luỹ.

Vì sao các phương án khác sai

  • B. Đa vùng nhưng lớp Nearline — Nearline có phí truy xuất và ràng buộc lưu tối thiểu 30 ngày; áp cho dữ liệu đọc thường xuyên sẽ đắt hơn Standard.
  • A và C. Bucket theo vùng — không chịu được sự cố cấp khu vực và người dùng ở xa chịu độ trễ cao; riêng C còn dùng Coldline cho dữ liệu nóng, tức là chọn sai tầng hoàn toàn.
Câu 353

You are a cloud architect at a software company that has an application deployed on Google Cloud. The application has been experiencing performance issues both in the testing and production environments. The DevOps team is unsure if the problem is due to the application's code or the underlying infrastructure. You've been asked to identify an efficient way to isolate and diagnose these performance issues. Which approach would you suggest?

  1. A

    Use only Cloud Monitoring to analyze both the code and the infrastructure performance.

  2. B

    Create a detailed log for every function call in the application code to identify any bottlenecks.

  3. C

    Use Cloud Profiler to identify performance bottlenecks in the code, while also leveraging Cloud Monitoring and Logging to analyze infrastructure performance.

  4. D

    Upgrade the machine types of all Compute Engine instances in the project to increase performance.

Xem giải thích

Đáp án

C — Dùng Cloud Profiler để tìm nút thắt trong mã, kết hợp giám sát hạ tầng

Vì sao đúng

Đề nói vấn đề hiệu năng xuất hiện ở cả môi trường kiểm thử lẫn sản xuất, và nguyên nhân có thể nằm ở hai tầng khác nhau. Vì vậy cần cả hai góc nhìn: Cloud Profiler lấy mẫu liên tục trên ứng dụng đang chạy để chỉ ra hàm nào tốn CPU và bộ nhớ — với chi phí rất thấp nên bật được cả trên sản xuất; còn giám sát hạ tầng cho biết máy, mạng và đĩa có phải nút thắt hay không.

Vì sao các phương án khác sai

  • A. Chỉ dùng Cloud Monitoring cho cả mã lẫn hạ tầng — Monitoring nhìn ở mức tài nguyên, không chỉ ra được hàm nào chậm.
  • B. Ghi log cho mọi lời gọi hàm — chi phí ghi log bùng nổ và bản thân việc ghi làm ứng dụng chậm thêm, tức là làm sai lệch chính thứ đang đo.
  • D. Nâng cấu hình mọi máy — đoán mò và tốn tiền; nếu nút thắt nằm trong mã thì máy to hơn cũng không cứu được.
Câu 354

As a cloud architect, you've been tasked with setting up an e-commerce application on Google Cloud Platform for a multinational company. The application will handle credit card transactions and customer data, so security is of utmost importance. The application consists of various components running on Compute Engine, Cloud Storage, and Cloud SQL. What should be your primary focus in terms of security?

  1. A

    Utilize Cloud Armor to protect the application against DDoS attacks.

  2. B

    Apply IAM roles and policies at the organization level to manage resource access.

  3. C

    Use VPC Service Controls to establish a security perimeter around sensitive resources.

  4. D

    Enable Secure Boot on all Compute Engine instances to ensure the integrity of the boot process.

Xem giải thích

Đáp án

C — Dùng VPC Service Controls lập vành đai quanh tài nguyên nhạy cảm

Vì sao đúng

Với dữ liệu thẻ tín dụng, rủi ro đáng sợ nhất không phải người ngoài đột nhập mà là dữ liệu bị mang ra ngoài — bởi tài khoản bị chiếm, bởi cấu hình sai, hoặc bởi người bên trong. IAM không chặn được chuyện đó vì nó chỉ trả lời "ai được truy cập". Service Controls trả lời câu hỏi còn lại: "dữ liệu được phép đi tới đâu" — trong vành đai, ngay cả người có thông tin đăng nhập hợp lệ cũng không sao chép dữ liệu ra ngoài được.

Vì sao các phương án khác sai

  • A. Cloud Armor chống DDoS — biện pháp đúng đắn nhưng bảo vệ tính sẵn sàng, không bảo vệ dữ liệu khỏi bị mang đi.
  • B. Vai IAM ở mức tổ chức — nền tảng cần có, nhưng như trên: kiểm soát truy cập chứ không kiểm soát luồng dữ liệu.
  • D. Bật Secure Boot — bảo vệ tính toàn vẹn khi máy khởi động, phạm vi hẹp hơn nhiều so với yêu cầu.
Câu 355

You are leading the team responsible for managing an application hosted on Cloud Run. You are planning to release a new version of the application. To ensure minimal disruption and maintain high availability, you need to define a strategy for deploying the new version. Which of the following would be the most appropriate strategy for this scenario?

  1. A

    Shut down the application, deploy the new version, perform extensive testing, and then bring the application back online.

  2. B

    Perform a blue-green deployment, keeping the current version (blue) running while the new version (green) is fully deployed and tested. Once the new version is validated, traffic is redirected to it.

  3. C

    Perform a canary deployment, gradually directing a small percentage of traffic to the new version while monitoring for issues.

  4. D

    Deploy the new version directly to production, testing it in the live environment and rolling it back if issues are found.

Xem giải thích

Đáp án

C — Triển khai canary: chuyển dần một tỷ lệ nhỏ lưu lượng sang bản mới

Vì sao đúng

Cloud Run hỗ trợ sẵn việc chia lưu lượng theo tỷ lệ giữa các revision, nên canary chỉ là khai một con số. Bản mới nhận vài phần trăm lưu lượng thật, bạn theo dõi tỷ lệ lỗi và độ trễ, rồi mới mở rộng dần. Có vấn đề thì kéo tỷ lệ về 0 — không gián đoạn và chỉ một phần nhỏ người dùng bị ảnh hưởng.

Vì sao các phương án khác sai

  • B. Blue-green — quay lui nhanh, nhưng khi chuyển thì toàn bộ người dùng nhận bản mới cùng lúc, nên lỗi chạm tới tất cả trước khi bạn kịp nhận ra.
  • A. Tắt ứng dụng, triển khai, kiểm thử rồi bật lại — gây gián đoạn hoàn toàn, đúng thứ đề muốn tránh.
  • D. Đẩy thẳng lên sản xuất rồi kiểm thử trên môi trường thật — không có lưới an toàn nào.
Câu 356

For this question, refer to the Altostrat Media case study.

https://services.google.com/fh/files/misc/v6.1_pca_altostrat_media_case_study_english.pdf  


Altostrat plans to introduce AI-powered discovery features that allow users to search and interact with audio and video content using natural language. Before making content searchable and recommendable, Altostrat must reliably detect and filter inappropriate content (for example, hate speech, explicit language, or violent imagery) across both newly ingested media and their existing Cloud Storage–based library.

The solution must scale automatically, integrate with their current event-driven architecture, and minimize operational overhead. Which architecture best meets Altostrat’s requirements for detecting and filtering inappropriate content while following best practices?

  1. A

    Use Cloud Functions triggered by Cloud Storage events to send content to the Video Intelligence API with content moderation enabled, store results in BigQuery, and block flagged content via metadata.

  2. B

    Use Cloud Dataflow to batch-process all media files weekly and apply open-source NLP and computer vision models running on GKE.

  3. C

    Trigger Cloud Run services on Cloud Storage events to call the Vision API for video frames and the Speech-to-Text API for audio, then store moderation labels in BigQuery.

  4. D

    Deploy a custom TensorFlow-based moderation model on GKE and invoke it synchronously from user-facing APIs.

Xem giải thích

Đáp án

A — Cloud Functions kích hoạt bởi sự kiện Cloud Storage, gửi nội dung tới Video Intelligence API có bật kiểm duyệt

Vì sao đúng

Điểm phân biệt nằm ở đúng một API cho đúng loại nội dung. Video Intelligence API hiểu video như một chuỗi có thời gian và có sẵn tính năng phát hiện nội dung không phù hợp, xử lý cả hình lẫn tiếng trong một lần gọi. Kích hoạt theo sự kiện nghĩa là nội dung được kiểm duyệt ngay khi tải lên, trước khi kịp phơi ra cho người dùng.

Vì sao các phương án khác sai

  • C. Ghép Vision API cho khung hình với Speech-to-Text cho âm thanh — phương án nhiễu gần nhất. Nhưng Vision API xử lý ảnh tĩnh, nên bạn phải tự tách khung hình, tự chọn tần suất tách, và mất hoàn toàn ngữ cảnh theo thời gian. Hai API rời rạc cũng nghĩa là hai chỗ có thể sai lệch.
  • B. Xử lý theo lô hằng tuần — nội dung vi phạm phơi ra tới bảy ngày trước khi bị chặn.
  • D. Tự huấn luyện mô hình rồi gọi đồng bộ từ API người dùng — tốn công lớn, và gọi đồng bộ khiến người dùng phải chờ cả quá trình kiểm duyệt.
Câu 357

A company is planning to deploy a highly scalable and secure cloud infrastructure on Google Cloud Platform (GCP) to support their growing cloud-based product offerings. The infrastructure must be able to handle sudden spikes in demand, provide fast and reliable performance, and meet strict security and compliance requirements. Which of the following options would be the most effective approach to meet these requirements while also optimizing cost?

  1. A

    Use App Engine Flexible Environment with custom firewall rules and encrypted environment variables to host the application, and use Cloud Armor to protect against network threats.

  2. B

    Use Cloud Functions with encrypted secrets and environment variables to host the application, and use Cloud Load Balancer with SSL/TLS termination to provide secure access to the application.

  3. C

    Use Compute Engine instances with custom firewall rules and encrypted disks to host the application, and use Cloud VPN to securely connect to on-premises resources.

  4. D

    Use Google Kubernetes Engine with network security policies and encrypted secrets to host the application, and use Cloud Interconnect to securely connect to on-premises resources.

Xem giải thích

Đáp án

D — Google Kubernetes Engine với network policy và secret được mã hoá

Vì sao đúng

Đề đòi co giãn cao và an toàn cùng lúc. GKE cho co giãn ở cả mức pod và mức node, còn phần bảo mật thì có hai lớp đúng chỗ: network policy kiểm soát pod nào nói chuyện được với pod nào — mức chi tiết mà luật tường lửa VPC không với tới được; và secret được mã hoá giữ thông tin nhạy cảm ngoài mã nguồn lẫn ảnh container.

Vì sao các phương án khác sai

  • C. Máy ảo với luật tường lửa và đĩa mã hoá — an toàn ở mức máy, nhưng co giãn chậm hơn và bạn tự lo ảnh máy lẫn việc vá lỗi.
  • A. App Engine Flexible — co giãn chậm hơn vì phải khởi động máy ảo bên dưới, và kém linh hoạt khi hệ thống có nhiều thành phần.
  • B. Cloud Functions — hợp cho hàm ngắn theo sự kiện, không phải nền tảng cho cả một sản phẩm.
Câu 358

Your company is planning to design a new cloud solution architecture that not only addresses its current needs but is also robust enough to accommodate future improvements and technological advancements. As a Google Professional Cloud Architect, you are tasked with ensuring the solution is scalable, cost-effective, and able to integrate future cloud and technology innovations. Considering Google Cloud Platform's (GCP) capabilities, which of the following approaches would best align with these requirements?

  1. A

    Using Google Kubernetes Engine (GKE) to containerize and orchestrate microservices.

  2. B

    Relying solely on preemptible VMs to reduce costs, without considering high availability.

  3. C

    Implementing a monolithic architecture on Compute Engine for all services.

  4. D

    Designing the architecture to rely on a single region and availability zone for all services.

Xem giải thích

Đáp án

A — Dùng GKE để đóng gói và điều phối microservice

Vì sao đúng

Đề nhấn vào khả năng mở rộng trong tương lai, và microservice trên GKE là kiến trúc để lại nhiều đường phát triển nhất: thêm tính năng là thêm dịch vụ chứ không phải sửa vào khối chung, mỗi dịch vụ co giãn và phát hành độc lập, và nền tảng lo sẵn phần tự chữa lành cùng triển khai cuốn chiếu.

Vì sao các phương án khác sai

  • C. Kiến trúc nguyên khối trên máy ảo — mọi thay đổi đều phải phát hành lại toàn bộ, và không co giãn được từng phần.
  • D. Dựa vào một khu vực và một zone duy nhất — không chịu được sự cố ở bất kỳ cấp nào.
  • B. Chỉ dùng máy preemptible cho rẻ, bỏ qua tính sẵn sàng — chính phương án tự khai là bỏ qua yêu cầu về độ tin cậy.
Câu 359

For this question, refer to the EHR Healthcare case study.

https://services.google.com/fh/files/misc/v6.1_pca_ehr_healthcare_case_study_english.pdf


EHR Healthcare’s legacy insurance integrations use a mix of file transfers and synchronous APIs hosted on-premises. As Google Cloud workloads scale globally, EHR wants to decouple cloud-native services from legacy systems while ensuring that outages or latency in on-premises systems do not impact customer-facing applications. Which architecture best supports resilient integration between cloud services and on-premises legacy systems while aligning with best practices?

  1. A

    Replicate all legacy systems into Google Cloud using database replication tools.

  2. B

    Use Pub/Sub as an asynchronous integration layer between cloud workloads and on-premises systems.

  3. C

    Deploy a shared NFS file system mounted by both on-premises servers and Google Cloud VMs.

  4. D

    Direct synchronous API calls from GKE workloads to on-premises services over Interconnect.

Xem giải thích

Đáp án

B — Dùng Pub/Sub làm lớp tích hợp bất đồng bộ giữa khối lượng công việc trên đám mây và hệ thống cũ

Vì sao đúng

Tích hợp với hệ thống cũ có một rủi ro đặc trưng: hệ thống cũ chậm hoặc chết thì kéo theo phần mới. Pub/Sub cắt đúng sự phụ thuộc đó — bên gửi đẩy thông điệp rồi đi tiếp, bên nhận xử lý theo nhịp của mình, và khi hệ thống cũ tạm ngừng thì thông điệp nằm chờ chứ không mất. Đây là cách để phần mới không bị giới hạn bởi độ tin cậy của phần cũ.

Vì sao các phương án khác sai

  • D. Gọi API đồng bộ từ GKE xuống hệ thống tại chỗ — mọi độ trễ và sự cố của hệ thống cũ dội thẳng lên người dùng của hệ thống mới.
  • A. Nhân bản toàn bộ hệ thống cũ lên đám mây — dự án rất lớn, và bạn có hai bản dữ liệu phải giữ đồng bộ.
  • C. Dựng hệ tệp NFS dùng chung cho cả hai bên — chia sẻ tệp qua ranh giới mạng vừa chậm vừa mong manh, và tạo ra một điểm hỏng chung.
Câu 360

You are a cloud architect for a large e-commerce platform that experiences high traffic during peak seasons like Black Friday and Cyber Monday. The platform is built using microservices, each with different scaling requirements. Your team has decided to migrate these services to Google Kubernetes Engine (GKE) to take advantage of its managed service and autoscaling features. The following requirements have been identified:

  1. Automatic Scaling: The platform should scale automatically based on CPU utilization.

  2. Service Discovery: Microservices should be able to discover each other easily without needing a static IP or DNS management.

  3. High Availability: The application must remain available even if one of the GKE clusters fails.

  4. Cost Efficiency: Resource usage should be optimized to minimize costs.

What configuration should you implement to meet these requirements?

  1. A

    Deploy microservices across multiple GKE clusters in different regions, enable HPA, use Istio for service discovery and traffic management, and implement cluster autoscaler.

  2. B

    Deploy all microservices in a single GKE cluster, enable Vertical Pod Autoscaler (VPA), use Kubernetes Service for service discovery, and implement regional managed instance groups for high availability.

  3. C

    Deploy all microservices in a single GKE cluster, enable Horizontal Pod Autoscaler (HPA) for CPU-based scaling, and use Kubernetes Service for service discovery.

  4. D

    Deploy all microservices in a single GKE cluster, use StatefulSets for scaling, implement manual scaling policies, and use External Load Balancer for service discovery.

Xem giải thích

Đáp án

A — Triển khai microservice trên nhiều cụm GKE ở các khu vực khác nhau

Vì sao đúng

Đề nói về đỉnh tải mùa mua sắm trên một nền tảng toàn cầu. Nhiều cụm ở nhiều khu vực giải quyết cả hai chiều: tải được trải ra thay vì dồn vào một chỗ, người dùng được phục vụ từ khu vực gần nhất, và mất trọn một khu vực vẫn còn nơi khác. Với ngày như Black Friday thì việc không có điểm hỏng duy nhất quan trọng ngang việc chịu được tải.

Vì sao các phương án khác sai

  • C. Một cụm duy nhất với Horizontal Pod Autoscaler — co giãn tốt nhưng vẫn nằm trong một khu vực, nên sự cố cấp khu vực là sập toàn bộ đúng ngày cao điểm.
  • B. Một cụm với Vertical Pod Autoscaler — VPA điều chỉnh tài nguyên cho mỗi pod và thường khởi động lại pod; đó không phải cách đáp ứng tải tăng đột ngột.
  • D. Dùng StatefulSet để co giãn — StatefulSet dựng cho ứng dụng có trạng thái cần danh tính ổn định, không phải cơ chế co giãn.