Ngân hàng đề — Google Professional Cloud Architect

Tìm thấy 420 câu.

Câu 361

You are designing a data pipeline for an e-commerce company. User events (clicks, searches, purchases) are sent from web clients and mobile apps. These events must be processed and aggregated for dashboards within minutes. The client also wants to retain raw events for at least 6 months for auditing and machine learning purposes. You are asked to optimize cost and performance. Which solution best meets the requirements?

  1. A

    Ingest via Cloud Pub/Sub, process with Cloud Dataflow, write aggregates to BigQuery, and archive raw events to Cloud Storage

  2. B

    Use Firebase Analytics for data collection and export reports to BigQuery

  3. C

    Ingest events via Cloud Pub/Sub, stream into BigQuery, and store raw data in Firestore

  4. D

    Use Cloud Functions to write incoming events directly to BigQuery

Xem giải thích

Đáp án

A — Nhận qua Pub/Sub, xử lý bằng Dataflow, ghi số liệu tổng hợp vào BigQuery

Vì sao đúng

Ba tầng lo ba việc và không tầng nào làm thay được tầng kia: Pub/Sub hấp thụ sự kiện từ web và ứng dụng di động, chịu được tải bùng phát và không mất tin; Dataflow xử lý luồng với cửa sổ thời gian, tổng hợp được và xử lý được sự kiện tới muộn — chuyện luôn xảy ra với thiết bị di động mất sóng; BigQuery giữ kết quả để truy vấn.

Vì sao các phương án khác sai

  • D. Cloud Functions ghi thẳng sự kiện vào BigQuery — không có lớp đệm nên tải tăng đột ngột là mất dữ liệu, và không có chỗ nào để tổng hợp.
  • C. Pub/Sub rồi đổ thẳng vào BigQuery, dữ liệu thô để Firestore — thiếu hẳn tầng xử lý, và Firestore không phải nơi chứa sự kiện thô khối lượng lớn.
  • B. Dùng Firebase Analytics — công cụ phân tích ứng dụng dựng sẵn, không phải đường ống dữ liệu tuỳ biến mà đề đang thiết kế.
Câu 362

You are tasked with designing a cost-effective, scalable compute infrastructure for a new batch processing system in Google Cloud. The system processes large datasets overnight when demand is lower and can tolerate occasional interruptions. The processing jobs can be paused and resumed without data loss. Your primary goal is to minimize costs while ensuring the jobs complete within the allocated time window. Which configuration should you choose for the virtual machines (VMs) running the batch processing jobs, and why?

  1. A

    Use only standard VMs with autoscaling enabled.

  2. B

    Use only standard VMs without autoscaling.

  3. C

    Use a mix of preemptible and standard VMs, with autoscaling enabled on both types.

  4. D

    Use only preemptible VMs without autoscaling.

Xem giải thích

Đáp án

C — Kết hợp máy preemptible với máy thường, bật tự co giãn cho cả hai

Vì sao đúng

Đây là cách cân bằng đúng giữa chi phí và độ tin cậy cho công việc theo lô. Máy thường làm nền móng đảm bảo công việc luôn tiến tới kể cả khi nguồn máy preemptible cạn; máy preemptible gánh phần lớn khối lượng với giá rẻ hơn nhiều. Tự co giãn khiến số máy bám theo lượng việc thật thay vì cố định.

Vì sao các phương án khác sai

  • D. Chỉ dùng preemptible, không tự co giãn — rẻ nhất nhưng nếu Google thu hồi hàng loạt thì công việc đứng hẳn, không có gì gánh.
  • A. Chỉ dùng máy thường có tự co giãn — chạy được và đáng tin, nhưng bỏ qua phần tiết kiệm lớn mà công việc theo lô hoàn toàn có thể hưởng.
  • B. Chỉ máy thường, không co giãn — đắt nhất và kém linh hoạt nhất.
Câu 363

You are designing a Google Cloud solution where a multi-tier application consists of a web tier, an API tier, and a database tier. The web tier instances must communicate with the API tier instances, and the API tier instances must communicate with the database instances. Communication between the web tier and the database tier is strictly prohibited. What is the best way to enforce this traffic flow?

  1. A

    Add each tier to a different subnet and configure firewall rules to enforce traffic restrictions.

  2. B

    Use network tags for each tier and apply firewall rules to control traffic between them.

  3. C

    Use separate VPCs for each tier and set up VPC peering with appropriate firewall rules.

  4. D

    Assign unique IP ranges to each tier and configure VPC firewall rules to restrict traffic flow.

Xem giải thích

Đáp án

B — Dùng network tag cho từng tầng và viết luật tường lửa theo tag

Vì sao đúng

Network tag mô tả vai trò nên bám theo máy khi nhóm co giãn: máy mới sinh ra thừa hưởng tag và luật áp dụng ngay, không phải sửa gì. Kết hợp với mặc định chặn mọi lưu lượng đi vào của VPC, bạn chỉ khai đúng những luồng cần — web tới API, API tới CSDL — và mọi thứ khác tự động bị chặn.

Vì sao các phương án khác sai

  • A và D. Lọc theo subnet hoặc theo dải địa chỉ — làm được nhưng luật gắn với địa chỉ, mà địa chỉ thay đổi khi máy được tạo lại; kém linh hoạt hơn tag rõ rệt.
  • C. Mỗi tầng một VPC rồi peering — cô lập rất mạnh nhưng phải dựng và duy trì nhiều bộ luật tường lửa, phức tạp hơn nhiều so với nhu cầu phân đoạn ba tầng trong một ứng dụng.
Câu 364

You are a cloud architect of a global online retail company that uses a production database hosted on Cloud SQL. You received an alert that the database is about to run out of storage space. What is the best approach to ensure that the production database does not run out of storage and there is minimal impact on the performance of the application?

  1. A

    Create a snapshot of the database, delete some data from the production database, and then restore the data from the snapshot if needed.

  2. B

    Increase the size of the database instance manually.

  3. C

    Export the data to BigQuery and delete the data from the production database.

  4. D

    Enable automatic storage increases for the database instance.

Xem giải thích

Đáp án

D — Bật tự động tăng dung lượng lưu trữ cho instance

Vì sao đúng

Cloud SQL có sẵn tính năng tự tăng dung lượng: khi ổ sắp đầy, nó tự nới thêm mà không gián đoạn dịch vụ và không cần ai thức dậy lúc nửa đêm. Với CSDL sản xuất đang sắp hết chỗ thì đây là biện pháp vừa xử lý được ngay vừa ngăn sự việc lặp lại.

Vì sao các phương án khác sai

  • B. Tăng dung lượng bằng tay — giải quyết được lần này, nhưng lần sau vẫn phải có người canh và kịp phản ứng.
  • A. Chụp snapshot rồi xoá bớt dữ liệu — xoá dữ liệu sản xuất là thao tác rủi ro và thường không phải điều nghiệp vụ cho phép.
  • C. Xuất sang BigQuery rồi xoá khỏi CSDL — có thể là chiến lược lưu trữ dài hạn hợp lý, nhưng là dự án riêng chứ không phải cách xử lý một cảnh báo sắp đầy ổ.
Câu 365

A financial company wants to move its existing data warehouse infrastructure to Google Cloud Platform to take advantage of its scalability and cost-effectiveness. The data warehouse processes large amounts of financial data and the company wants to ensure the data is secure and available at all times. Which of the following is the best solution for this requirement in Google Cloud Platform?

  1. A

    Using BigQuery for data warehousing

  2. B

    Using Cloud SQL for data warehousing

  3. C

    Using Cloud Storage for data warehousing

  4. D

    Using Cloud Datastore for data warehousing

Xem giải thích

Đáp án

A — Dùng BigQuery làm kho dữ liệu

Vì sao đúng

BigQuery là kho dữ liệu không máy chủ: tách lưu trữ khỏi tính toán nên mở rộng tới petabyte mà không phải dựng cụm, trả tiền theo lượng dữ liệu quét nên chi phí bám theo mức dùng thật thay vì theo năng lực dự phòng, và hỗ trợ SQL chuẩn nên đội phân tích không phải học lại. Đúng hai thứ đề nêu: khả năng mở rộng và hiệu quả chi phí.

Vì sao các phương án khác sai

  • B. Cloud SQL — CSDL giao dịch một máy chủ, có trần mở rộng rõ ràng.
  • C. Cloud Storage — nơi chứa dữ liệu rẻ và bền, nhưng tự nó không truy vấn được; thường đóng vai kho nguồn bên cạnh BigQuery chứ không thay được.
  • D. Cloud Datastore — kho tài liệu cho ứng dụng, không dựng cho phân tích.
Câu 366

You are a cloud architect working for a global enterprise that runs an e-commerce application. As part of the design, the application layer is hosted on Compute Engine and needs to be scalable to handle potential spikes in traffic during high-usage times. In this scenario, you decided to implement a managed instance group (MIG) for automated scaling. You need to create a process to automate the creation of the managed instance group, ensure it scales based on load, is distributed across multiple zones for high availability, and uses predefined instance templates for uniformity. What should you do?

  1. A

    Use Terraform to create a regional managed instance group using an instance template. Configure autoscaling based on Cloud Monitoring metrics.

  2. B

    Use Cloud Functions to create an instance template and a zonal managed instance group. Configure autoscaling based on Cloud Monitoring metrics.

  3. C

    Use Deployment Manager to create and manage a zonal managed instance group. Configure autoscaling based on HTTP load balancing.

  4. D

    Use the Cloud SDK to create a zonal managed instance group with a template, and then manually add instances when needed.

Xem giải thích

Đáp án

A — Dùng Terraform tạo managed instance group theo vùng từ một instance template

Vì sao đúng

Hai lựa chọn đều quan trọng:

  • Nhóm theo vùng (regional MIG) — máy được trải qua nhiều zone trong khu vực, nên mất một zone vẫn còn năng lực phục vụ. Nhóm theo zone thì không có điều đó.
  • Terraform — hạ tầng dạng mã, nên cấu hình được rà soát, ghi vết và dựng lại y hệt ở mọi môi trường.

Vì sao các phương án khác sai

  • C và **D. Dùng nhóm theo zone — dù công cụ nào thì nhóm theo zone cũng không chịu được sự cố cấp zone; đây là điểm hỏng chung của cả hai.
  • B. Dùng Cloud Functions để tạo hạ tầng — sai công cụ: đó là nền tảng chạy mã theo sự kiện, không phải công cụ quản lý hạ tầng.
Câu 367 Chọn nhiều đáp án

A financial institution is planning to migrate its core banking system from a legacy mainframe to Google Cloud. The system is critical, handling daily transactions for millions of customers. The institution also needs to integrate this system with modern cloud-based services for data analytics, fraud detection, and customer engagement. The migration must be done in phases to avoid disruptions to banking services. Additionally, the institution must comply with stringent regulatory requirements, including data residency and security protocols. Which two strategies should you incorporate into your migration plan to meet these requirements? (Choose two)

  1. A

    Use Transfer Appliance to securely move large datasets from the mainframe to Google Cloud Storage for backup and archival.

  2. B

    Migrate the entire core banking system to Google Cloud Spanner in a single cutover.

  3. C

    Set up a hybrid environment with interconnectivity between the mainframe and Google Cloud using Cloud VPN.

  4. D

    Use Google Cloud's Anthos to extend the mainframe's services to the cloud while gradually migrating individual components.

  5. E

    Implement a data masking strategy for sensitive data during the migration process to comply with regulatory requirements.

Xem giải thích

Đáp án

D và E — dùng Anthos để mở rộng dịch vụ của mainframe ra đám mây, và áp chiến lược che dữ liệu nhạy cảm trong quá trình di chuyển

Vì sao đúng

Hệ thống ngân hàng lõi trên mainframe là loại không được phép cắt chuyển một lần:

  • D. Anthos — cho phép chạy song song và chuyển dần từng phần, hệ thống cũ vẫn phục vụ trong suốt quá trình. Rủi ro được chia nhỏ thay vì dồn vào một đêm.
  • E. Che dữ liệu nhạy cảm — trong lúc di chuyển, dữ liệu đi qua nhiều môi trường và nhiều tay hơn bình thường; đây đúng là lúc dễ rò rỉ nhất.

Vì sao các phương án khác sai

  • B. Chuyển toàn bộ sang Cloud Spanner trong một lần cắt chuyển — rủi ro cao nhất có thể, trên hệ thống không được phép sai.
  • A. Dùng Transfer Appliance — công cụ chuyển khối dữ liệu lớn một lần, không giải quyết bài toán chuyển đổi hệ thống đang chạy.
  • C. Dựng môi trường lai có kết nối — cần thiết nhưng chỉ là điều kiện nền, không phải chiến lược di chuyển.
Câu 368

A multinational retail company is building a cloud-native analytics platform to centralize data collected from various regional systems (e.g., sales, inventory, customer behavior). The company anticipates exponential data growth over the next two years and needs a cost-effective, highly scalable, and durable storage solution that integrates with data processing and analytics tools. Which GCP storage solution best fits these requirements?

  1. A

    Persistent Disks attached to Compute Engine

  2. B

    Cloud Storage with Lifecycle Management and Nearline/Coldline tiers

  3. C

    Cloud Storage in Multi-Regional class

  4. D

    Cloud SQL with automatic backups enabled

Xem giải thích

Đáp án

B — Cloud Storage với Lifecycle Management và các tầng Nearline/Coldline

Vì sao đúng

Nền tảng phân tích tích luỹ dữ liệu rất nhanh, và phần lớn dữ liệu nguội đi theo thời gian. Lifecycle Management tự động đẩy dữ liệu cũ xuống tầng rẻ hơn theo tuổi hoặc theo lần truy cập cuối, nên chi phí không tăng tuyến tính với khối lượng tích luỹ — mà không cần ai nhớ làm.

Vì sao các phương án khác sai

  • C. Cloud Storage lớp đa vùng cho tất cả — bền và gần người dùng, nhưng trả giá cao nhất cho cả phần dữ liệu chẳng ai đụng tới.
  • A. Đĩa bền gắn vào máy ảo — đắt hơn Cloud Storage nhiều lần cho lưu trữ, và phải giữ máy.
  • D. Cloud SQL với sao lưu tự động — CSDL giao dịch, không phải nơi chứa dữ liệu phân tích thô.
Câu 369

You have configured an HTTP(S) load balancer to distribute traffic to a backend managed instance group. However, after deployment, the load balancer returns 502 errors for all client requests. You confirmed that the backend VMs are healthy when accessed directly using SSH and curl from within the network. What should you do next to resolve the issue?

  1. A

    Enable Cloud NAT to allow the instance group to access the internet for external health checks.

  2. B

    Check the load balancer’s health check configuration to ensure it matches the application’s response settings.

  3. C

    Ensure that backend services are configured with instance group autohealing policies.

  4. D

    Assign a public IP address to each VM and test using their external addresses.

Xem giải thích

Đáp án

B — Kiểm tra cấu hình health check của load balancer có khớp với ứng dụng không

Vì sao đúng

Lỗi 502 cho mọi yêu cầu nghĩa là load balancer không có backend nào được coi là khoẻ để chuyển tiếp. Nguyên nhân gần như luôn nằm ở health check: sai cổng, sai đường dẫn, sai giao thức, hoặc chưa mở luật tường lửa cho dải IP kiểm tra của Google. Đây là chỗ phải xem đầu tiên.

Vì sao các phương án khác sai

  • C. Bật autohealing cho instance group — autohealing thay máy bị coi là hỏng; nếu health check vốn đã sai thì nó chỉ khiến máy bị thay liên tục, làm tình hình tệ hơn.
  • A. Bật Cloud NAT — cho máy đi ra Internet; lỗi 502 là chuyện lưu lượng đi vào.
  • D. Gán IP công khai cho từng máy rồi thử trực tiếp — có thể dùng để chẩn đoán, nhưng không phải cách sửa, và phơi máy ra Internet.
Câu 370

For this question, refer to the Altostrat Media case study.

https://services.google.com/fh/files/misc/v6.1_pca_altostrat_media_case_study_english.pdf  


Altostrat plans to expand globally and expects continued growth in its media catalog. Historical media content must be retained for regulatory reasons but is rarely accessed. Finance teams want predictable long-term storage costs, while engineering wants to avoid re-architecting existing ingestion and playback pipelines. Occasionally, archived content must be restored for analytics or re-release campaigns, with retrieval times of several hours being acceptable. Which storage approach best balances cost optimization, compliance, and operational simplicity?

  1. A

    Store all historical media in Cloud Storage Coldline and manually promote objects when access is required.

  2. B

    Replicate all historical media across multiple regions using Standard storage for durability.

  3. C

    Export historical media to BigQuery tables for long-term retention and analysis.

  4. D

    Archive long-term media using Cloud Storage Archive with lifecycle rules, accepting higher retrieval latency when needed.

Xem giải thích

Đáp án

D — Lưu trữ dài hạn bằng Cloud Storage Archive kèm lifecycle rule

Vì sao đúng

Nội dung phương tiện cũ phải giữ lại nhưng gần như không bao giờ được xem. Archive là tầng rẻ nhất cho đúng mẫu đó, và khác với băng từ, dữ liệu vẫn lấy ra được ngay khi bất chợt có người cần. Lifecycle rule khiến việc chuyển tầng diễn ra tự động theo tuổi của đối tượng, không cần ai nhớ làm.

Vì sao các phương án khác sai

  • A. Để ở Coldline rồi nâng tầng bằng tay khi cần — thao tác tay không mở rộng được với kho nội dung lớn, và Coldline vẫn đắt hơn Archive cho dữ liệu gần như không đọc.
  • B. Nhân bản toàn bộ ở lớp Standard — trả giá cao nhất cho phần dữ liệu nguội nhất.
  • C. Xuất nội dung phương tiện sang BigQuery — BigQuery không phải nơi chứa tệp video hay âm thanh; sai loại lưu trữ.