Ngân hàng đề — Google Professional Cloud Architect
Tìm thấy 420 câu.
When considering strong security during the operation of fully autonomous vehicles within your agricultural division, there are two key architecture characteristics that should be taken into account. Which two characteristics should you prioritize in your architecture design? (Choose two)
-
A
Require IPv6 for connectivity to ensure a secure address space.
-
B
Use a Trusted Platform Module (TPM) and verify firmware and binaries on boot.
-
C
Treat every microservice call between modules on the vehicle as untrusted.
-
D
Use a functional programming language to isolate code execution cycles.
-
E
Use multiple connectivity subsystems for redundancy.
Xem giải thích
Đáp án
B và C — dùng Trusted Platform Module để xác minh firmware và mã nhị phân lúc khởi động, và coi mọi lời gọi giữa các module trên xe là không đáng tin
Vì sao đúng
Xe tự hành là hệ thống mà kẻ tấn công có thể chạm tay vào phần cứng, nên hai lớp này bổ sung nhau:
- B. TPM xác minh lúc khởi động — đảm bảo phần mềm đang chạy đúng là bản đã ký, chưa bị thay thế. Đây là gốc của chuỗi tin cậy; thiếu nó thì mọi lớp bên trên đều xây trên nền không chắc.
- C. Coi mọi lời gọi nội bộ là không đáng tin — đây là zero trust áp vào bên trong chính chiếc xe: một module bị chiếm cũng không tự động điều khiển được module khác.
Vì sao các phương án khác sai
- A. Bắt buộc IPv6 để có không gian địa chỉ an toàn — IPv6 không mang lại tính an toàn tự thân.
- E. Nhiều hệ thống kết nối để dự phòng — tốt cho tính sẵn sàng, nhưng thêm đường kết nối là thêm bề mặt tấn công chứ không phải bớt.
- D. Dùng ngôn ngữ lập trình hàm để cô lập chu trình chạy — lựa chọn ngôn ngữ không phải đặc tính kiến trúc bảo mật ở tầng này.
Your organization is planning to migrate a large on-premise data warehouse to Google Cloud Platform. The data warehouse is currently hosted on a Hadoop cluster with Hive. The management decided to migrate to Google Cloud to use the managed services offered by Google. Which service should you choose?
-
A
Use BigQuery as it provides a highly scalable, serverless, and cost-effective multi-cloud data warehouse.
-
B
Use Cloud Storage as it provides unified object storage.
-
C
Use Cloud Bigtable as it offers low latency access to large datasets.
-
D
Use Cloud Spanner as it provides strong transactional consistency.
Xem giải thích
Đáp án
A — Dùng BigQuery
Vì sao đúng
Đề chuyển một kho dữ liệu chạy trên Hadoop với Hive, tức là khối lượng công việc truy vấn phân tích bằng SQL. BigQuery là bản tương đương được quản lý: cùng mô hình SQL nên phần lớn truy vấn Hive chuyển sang không quá khó, nhưng không còn cụm nào phải dựng, chỉnh hay vá, và mở rộng tới petabyte là chuyện của nền tảng chứ không của bạn.
Vì sao các phương án khác sai
- B. Cloud Storage — thay được HDFS ở vai trò kho lưu trữ, nhưng không thay được Hive: nó không truy vấn gì cả.
- C. Bigtable — đọc theo khoá rất nhanh nhưng không hỗ trợ SQL phân tích.
- D. Cloud Spanner — CSDL giao dịch nhất quán mạnh, sai loại khối lượng công việc và rất đắt cho mục đích này.
Your company is migrating its data analytics pipeline to Google Cloud. A Data Engineering team needs to manage BigQuery datasets and run Dataflow jobs, but they should not be able to create or delete GCP projects, manage billing, or alter IAM policies. Which IAM design adheres to the principle of least privilege while supporting the team’s workflows?
-
A
Use a custom role that combines Editor and Billing Admin privileges
-
B
Grant the BigQuery Admin role at the folder level and Viewer role at the org level
-
C
Grant the Dataflow Admin and BigQuery Admin roles at the organization level
-
D
Grant Dataflow Developer and BigQuery DataEditor roles at the project level
Xem giải thích
Đáp án
**D — Cấp Dataflow Developer và BigQuery Data Editor ở mức dự án
Vì sao đúng
Hai chiều đều phải đúng: phạm vi và mức quyền. Cấp ở mức dự án giới hạn ảnh hưởng đúng nơi đội làm việc, và hai vai này cho đủ thứ họ cần — chạy job Dataflow và quản lý dữ liệu trong BigQuery — mà không kèm quyền quản trị dự án hay quyền chạm vào tài nguyên khác.
Vì sao các phương án khác sai
- **C. Cấp vai Admin ở mức tổ chức — sai cả hai chiều: quyền quản trị rộng hơn nhu cầu, và phạm vi trải ra toàn bộ tổ chức.
- B.
BigQuery Adminở mức thư mục cộngViewerở mức tổ chức — vẫn quá rộng, và thiếu phần quyền chạy Dataflow. - A. Vai tuỳ chỉnh ghép
EditorvớiBilling Admin—Editorlà vai cơ bản rất rộng, còn quyền quản trị thanh toán thì hoàn toàn không liên quan tới công việc của đội dữ liệu.
For this question, refer to the Altostrat Media case study.
https://services.google.com/fh/files/misc/v6.1_pca_altostrat_media_case_study_english.pdf
Altostrat plans to use generative AI to boost content virality by automatically generating personalized summaries, shareable captions, and recommended hashtags for audio and video content. These outputs should be tailored to each user’s interests and consumption history, derived from analytics in BigQuery. The solution must minimize data duplication, support near real-time generation, and integrate cleanly with existing event-driven workflows. What is the most appropriate architecture to meet these requirements?
-
A
Trigger Cloud Run services via Pub/Sub events to call Vertex AI generative models, enriching prompts with user context from BigQuery.
-
B
Use Dataflow streaming pipelines to call an external LLM API and write generated captions to Cloud Storage.
-
C
Precompute all summaries nightly using Cloud Composer and store them in Firestore.
-
D
Run batch jobs in BigQuery ML to generate text summaries and store results back into BigQuery tables.
Xem giải thích
Đáp án
A — Cloud Run được kích hoạt qua sự kiện Pub/Sub, gọi mô hình sinh của Vertex AI
Vì sao đúng
Mô hình này khớp đúng đặc điểm của việc sinh nội dung bằng AI: tải đến theo đợt và không đều. Pub/Sub đệm sự kiện lại, Cloud Run co giãn theo số thông điệp và co về 0 khi rảnh, nên chỉ trả tiền cho phần thật sự xử lý. Pub/Sub cũng tự thử lại khi một lượt gọi mô hình thất bại — chuyện thường xảy ra khi gặp giới hạn tần suất.
Vì sao các phương án khác sai
- C. Sinh trước toàn bộ bản tóm tắt hằng đêm bằng Cloud Composer — trả tiền suy luận cho cả nội dung chẳng ai đọc, và nội dung mới phải chờ tới đêm.
- B. Dataflow gọi API mô hình bên ngoài trong pipeline luồng — Dataflow dựng cho biến đổi dữ liệu; gọi mô hình có độ trễ cao trong luồng làm nghẽn cả pipeline.
- D. Sinh tóm tắt bằng BigQuery ML theo lô — không phải công cụ cho việc sinh văn bản dạng này, và vẫn vướng vấn đề xử lý theo lô.
You are a cloud architect working for a large e-commerce company. The company is generating massive amounts of clickstream data from its online platform and wants to implement an efficient and scalable solution for storing and analyzing this data. The primary goal is to gain insights into user behavior and improve the overall user experience. Which of the following approaches would be the most suitable for storing and analyzing the clickstream data in this complex scenario?
-
A
Use Cloud Storage for storing the raw clickstream data and BigQuery for performing real-time analytics.
-
B
Implement a serverless architecture using Cloud Functions to directly process and store the clickstream data in Cloud Firestore.
-
C
Store the raw clickstream data in Cloud Spanner and use Cloud Dataflow for batch processing and analysis.
-
D
Set up a self-managed Apache Hadoop cluster on Compute Engine to handle the storage and analysis of the clickstream data.
Xem giải thích
Đáp án
A — Cloud Storage giữ dữ liệu luồng nhấp chuột thô, BigQuery để phân tích
Vì sao đúng
Đây là mô hình kho dữ liệu tách bạch hai vai: Cloud Storage là nơi rẻ nhất giữ dữ liệu thô ở khối lượng lớn, và giữ nguyên bản gốc để tính lại khi phát hiện lỗi; BigQuery truy vấn phân tích ở quy mô petabyte, kể cả truy vấn thẳng trên tệp trong bucket bằng bảng ngoài nên không phải nạp bản sao thứ hai.
Vì sao các phương án khác sai
- C. Lưu dữ liệu thô trong Cloud Spanner — Spanner là CSDL giao dịch nhất quán mạnh, cực kỳ đắt và sai mục đích cho dữ liệu nhấp chuột.
- B. Cloud Functions xử lý thẳng từng sự kiện — chi phí gọi hàm ở khối lượng luồng nhấp chuột là không khả thi.
- D. Tự dựng cụm Hadoop trên máy ảo — quay lại đúng gánh nặng vận hành mà đám mây bỏ đi.
You deployed a Google Cloud internal TCP/UDP load balancer with a backend managed instance group. However, no traffic is reaching your backend instances, even though they are running and healthy when accessed from other internal VMs in the same VPC. What is the most likely cause?
-
A
The backend instances are in different zones from the load balancer.
-
B
You did not configure a firewall rule to allow traffic from the load balancer to the backend instances.
-
C
You forgot to associate a backend service with the load balancer’s forwarding rule.
-
D
You did not assign public IP addresses to the backend instances.
Xem giải thích
Đáp án
B — Chưa cấu hình luật tường lửa cho phép lưu lượng từ load balancer
Vì sao đúng
VPC mặc định chặn mọi lưu lượng đi vào, và load balancer nội bộ không phải ngoại lệ. Máy khoẻ mà không nhận được lưu lượng nào gần như luôn có nghĩa là gói tin bị chặn ở tường lửa — cần luật cho phép cả lưu lượng từ load balancer lẫn từ dải IP health check của Google.
Vì sao các phương án khác sai
- A. Máy backend nằm ở zone khác với load balancer — load balancer nội bộ hoạt động ở phạm vi khu vực, nên máy ở các zone khác nhau trong cùng khu vực là bình thường.
- D. Chưa gán IP công khai cho máy backend — load balancer nội bộ làm việc bằng IP riêng; gán IP công khai là sai hướng và không cần thiết.
- C. Quên gắn backend service vào forwarding rule — nếu vậy thì load balancer không dựng nổi chứ không phải dựng xong rồi không có lưu lượng.
A retail company operates multiple on-premises data centers that need to connect to Google Cloud. Their main data center is located 75 kilometers away from the nearest Google Cloud point of presence (PoP). The company has limited budget flexibility and would like to use their existing routers and firewalls, which are compatible with standard BGP configuration. They also shared the following details:
-
The connection must support hybrid workloads and allow private RFC 1918 IP addresses to communicate between on-premises servers and resources hosted on Google Cloud.
-
They require an SLA-backed solution that offers high reliability.
-
The workload involves intermittent data transfers, so high throughput is not a critical requirement.
What connectivity option should this company choose?
-
A
Provision a Dedicated Interconnect connection.
-
B
Provision Carrier Peering.
-
C
Provision a direct Internet connection.
-
D
Provision a VPN connection using Cloud VPN
Xem giải thích
Đáp án
D — Dựng kết nối VPN bằng Cloud VPN
Vì sao đúng
Dữ kiện quyết định là 75 km tới điểm kết nối gần nhất của Google. Dedicated Interconnect đòi bạn có thiết bị đặt tại chính cơ sở colocation đó, nên khoảng cách này biến nó thành một dự án kéo cáp tốn kém chứ không phải lựa chọn thực tế. Cloud VPN dựng được ngay trên đường Internet sẵn có, mã hoá lưu lượng, và đủ cho nhu cầu kết nối thông thường.
Vì sao các phương án khác sai
- A. Dedicated Interconnect — vướng đúng ràng buộc về khoảng cách và hiện diện vật lý.
- B. Carrier Peering — cho truy cập dịch vụ công khai của Google, không vào được VPC riêng.
- C. Đường Internet trần — không mã hoá và không có kết nối riêng tới VPC.
As a cloud architect, you are responsible for setting up a continuous deployment pipeline for a project hosted in a Git source repository. Your objective is to guarantee that code modifications can be validated prior to being deployed to the production environment. What steps should you take to achieve this?
-
A
Use Jenkins to build the staging branches and the master branch. Build and deploy changes to production for 10% of users before doing a complete rollout.
-
B
Use Spinnaker to deploy builds to production using the red/black deployment strategy so that changes can easily be rolled back.
-
C
Use Spinnaker to deploy builds to production and run tests on production deployments.
-
D
Use Jenkins to monitor tags in the repository. Deploy staging tags to a staging environment for testing. After testing, tag the repository for production and deploy that to the production environment.
Xem giải thích
Đáp án
D — Dùng Jenkins theo dõi tag: tag staging thì triển khai lên môi trường staging, kiểm thử xong mới tag production
Vì sao đúng
Đề yêu cầu thay đổi phải được kiểm chứng trước khi lên production, và chỉ phương án này có một môi trường staging thật sự đứng giữa. Dùng tag làm cơ chế phát hành cũng đúng: tag là mốc bất biến trỏ tới đúng một trạng thái mã, nên thứ được kiểm thử ở staging chính xác là thứ sẽ lên production — không có nhánh nào kịp thay đổi ở giữa.
Vì sao các phương án khác sai
- A. Triển khai lên production cho 10% người dùng trước — đó là canary, tức là kiểm thử trên chính production; đề muốn kiểm chứng trước khi tới đó.
- B. Red/black để dễ quay lui — quay lui nhanh là tốt, nhưng lỗi vẫn phải chạm tới production rồi mới bị phát hiện.
- C. Chạy kiểm thử trên bản đã triển khai lên production — nói thẳng ra là kiểm thử trên người dùng thật.
As a cloud architect, your company has asked you to architect and deploy a highly scalable web application using Google App Engine. The application will be used globally and should be able to handle large spikes in traffic. The application also needs to be updated frequently with zero downtime. Moreover, the company is very cost-conscious and wants to ensure that they are only billed for the compute resources they actually use. Which of the following App Engine environment and scaling type combinations would you recommend for this situation?
-
A
App Engine Standard Environment with Manual Scaling.
-
B
App Engine Flexible Environment with Automatic Scaling.
-
C
App Engine Standard Environment with Automatic Scaling.
-
D
App Engine Flexible Environment with Basic Scaling.
Xem giải thích
Đáp án
C — App Engine Standard với Automatic Scaling
Vì sao đúng
Hai lựa chọn khớp hai đặc điểm của ứng dụng toàn cầu có lưu lượng khó đoán:
- Standard — co giãn rất nhanh (tính bằng giây) và co được về 0 khi rảnh, nên không trả tiền lúc không ai dùng.
- Automatic Scaling — số bản chạy bám theo tốc độ yêu cầu thật.
Vì sao các phương án khác sai
- B. Flexible với Automatic Scaling — co giãn chậm hơn vì phải khởi động máy ảo bên dưới, và luôn giữ ít nhất một bản chạy nên vẫn tốn tiền lúc rảnh.
- A. Standard với Manual Scaling — cố định số bản chạy, tức là không co giãn.
- D. Flexible với Basic Scaling — Basic Scaling dựng cho tải thưa, không nhạy với tốc độ yêu cầu như ứng dụng toàn cầu cần.
A Google Cloud customer is running large-scale AI model training on AI Hypercomputer using Vertex AI Training. The team notices high GPU utilization but variable step latency during gradient synchronization. They suspect network bandwidth contention across training nodes. You are asked to optimize performance without rewriting the training code. What should you do?
-
A
Increase the number of GPUs per node to reduce inter-node communication
-
B
Switch to Cloud TPU v5e instances to reduce network overhead
-
C
Manually configure a custom VPC with dedicated interconnects between nodes
-
D
Enable Vertex AI Training’s NCCL topology optimization feature
Xem giải thích
Đáp án
D — Bật tính năng tối ưu topology NCCL của Vertex AI Training
Vì sao đúng
Triệu chứng trong đề rất cụ thể: GPU sử dụng cao nhưng độ trễ mỗi bước dao động. GPU bận nghĩa là phần tính toán không phải nút thắt; dao động giữa các bước là dấu hiệu kinh điển của khâu đồng bộ giữa các node. NCCL là thư viện lo việc trao đổi gradient giữa các GPU, và tối ưu topology sắp xếp đường trao đổi theo đúng cách các node được nối vật lý — nên bước đồng bộ nhanh và đều hơn.
Vì sao các phương án khác sai
- A. Tăng số GPU mỗi node — giảm được số node nhưng là thay đổi phần cứng tốn kém, và không sửa cách trao đổi dữ liệu.
- B. Chuyển sang Cloud TPU v5e — đổi cả nền tảng tăng tốc, việc rất lớn cho một vấn đề đã có công tắc sẵn.
- C. Tự dựng VPC riêng với interconnect giữa các node — không phải thứ bạn kiểm soát được trong môi trường huấn luyện được quản lý.