Ngân hàng đề — Google Professional Cloud Architect

Tìm thấy 420 câu.

Câu 381

You are creating SLOs for a global e-commerce platform deployed on Google Cloud. The platform must handle high traffic during seasonal sales and deliver a seamless shopping experience. What SLOs should you define to achieve this goal?

  1. A

    Define one SLO as 95% of API requests returning valid results. Define the other SLO as an average backend response time of less than 200 ms.

  2. B

    Define one SLO as server CPU utilization never exceeding 80%. Define the other SLO as disk I/O latency under 10 ms.

  3. C

    Define one SLO as 99% of product search requests processed within 200 ms. Define the other SLO as 99.9% of checkout requests returning 2xx status codes.

  4. D

    Define one SLO as 100% uptime for all services globally. Define the other SLO as less than 50 ms latency for any API request.

Xem giải thích

Đáp án

C — Một SLO là 99% yêu cầu tìm sản phẩm được xử lý trong vòng 200 ms

Vì sao đúng

SLO tốt phải đo thứ người mua cảm nhận trực tiếp và phải đặt dưới 100%. Tốc độ tìm sản phẩm là bước đầu tiên của mọi hành trình mua hàng, nên nó phản ánh trải nghiệm sát hơn bất kỳ chỉ số hạ tầng nào. Phần 1% còn lại chính là ngân sách lỗi cho phép đội tiếp tục phát hành.

Vì sao các phương án khác sai

  • D. 100% thời gian hoạt động toàn cầu — mục tiêu 100% là bất khả thi và phản tác dụng: ngân sách lỗi bằng 0 nghĩa là mọi thay đổi đều vi phạm SLO.
  • B. Mức dùng CPU không bao giờ vượt 80% — đây là chỉ số hạ tầng, không phải thứ người dùng cảm nhận; CPU thấp mà trang vẫn chậm là chuyện thường.
  • A. 95% yêu cầu API trả kết quả hợp lệ — đo được nhưng thiếu vế thời gian, mà với sàn thương mại điện tử thì chậm cũng là hỏng.
Câu 382

Your company is planning to deploy a new web application on Google Cloud Platform (GCP). The application is expected to have fluctuating usage patterns and significant spikes in traffic. The development team is committed to following best practices for continuous integration and continuous deployment (CI/CD) to enhance the application’s scalability and manageability. As a cloud architect, you are tasked with recommending a CI/CD strategy that ensures the application is always available, scalable, and up to date. Which of the following CI/CD strategies is most appropriate for this scenario?

  1. A

    Configure a blue-green deployment model using Kubernetes Engine to allow testing in a live environment before full rollout.

  2. B

    Manually deploy updated versions to App Engine standard environment during off-peak hours to minimize disruption.

  3. C

    Use Cloud Build to automate deployments, employing Cloud Functions for lightweight processing tasks that scale automatically.

  4. D

    Implement a rolling update strategy using Compute Engine managed instance groups to ensure zero downtime during deployments.

Xem giải thích

Đáp án

A — Mô hình triển khai blue-green trên Kubernetes Engine

Vì sao đúng

Đề nêu hai thứ: lưu lượng biến động mạnh có đỉnh lớn, và nhu cầu kiểm thử trước khi phát hành. Blue-green cho phép dựng trọn môi trường mới bên cạnh, kiểm thử đầy đủ trên đó, rồi chuyển lưu lượng trong một nhịp — và quay lui cũng chỉ là chuyển ngược lại. GKE là nền tảng làm việc này gọn nhất vì cả hai môi trường cùng chạy trong một cụm và việc chuyển chỉ là đổi selector của Service.

Vì sao các phương án khác sai

  • D. Rolling update trên managed instance group — không gián đoạn, nhưng không có môi trường riêng để kiểm thử trước: bản mới ra thẳng với người dùng thật.
  • B. Triển khai tay ngoài giờ cao điểm — thao tác tay không mở rộng được và vẫn không có bước kiểm chứng.
  • C. Cloud Build với Cloud Functions — nói về công cụ tự động hoá chứ không trả lời câu hỏi chiến lược triển khai.
Câu 383

For this question, refer to the EHR Healthcare case study.

https://services.google.com/fh/files/misc/v6.1_pca_ehr_healthcare_case_study_english.pdf


EHR Healthcare is storing sensitive healthcare analytics data in BigQuery. To comply with international data protection regulations, they must ensure that data in the us-central1 region remains within that region and cannot be accessed from external sources outside the organization. What should you do?

  1. A

    Use Identity and Access Management (IAM) to grant the BigQuery Admin role to all authorized users.

  2. B

    Configure VPC Service Controls to create a service perimeter around BigQuery resources in the us-central1 region.

  3. C

    Enable audit logs for BigQuery and monitor logs for access attempts outside the us-central1 region.

  4. D

    Enable customer-managed encryption keys (CMEK) for BigQuery datasets in the us-central1 region.

Xem giải thích

Đáp án

B — Cấu hình VPC Service Controls lập vành đai quanh tài nguyên BigQuery

Vì sao đúng

Yêu cầu là dữ liệu y tế không rời khỏi phạm vi cho phép, và đó chính là thứ IAM không làm được. IAM trả lời "ai được truy cập"; Service Controls trả lời "dữ liệu được phép đi tới đâu". Trong vành đai, ngay cả người có thông tin đăng nhập hợp lệ cũng không sao chép dữ liệu ra ngoài được — lớp phòng thủ đúng cho trường hợp tài khoản bị chiếm hoặc cấu hình sai.

Vì sao các phương án khác sai

  • A. Cấp vai BigQuery Admin qua IAM — kiểm soát truy cập, nhưng người được cấp vẫn xuất dữ liệu ra ngoài thoải mái; vai Admin còn quá rộng.
  • C. Bật nhật ký kiểm toán rồi theo dõi — chỉ báo cho bạn sau khi chuyện đã xảy ra.
  • D. Bật khoá mã hoá do khách hàng quản lý — biện pháp tốt và thường bắt buộc, nhưng bảo vệ dữ liệu khi lưu, không ngăn được việc dữ liệu bị mang đi.
Câu 384

A logistics enterprise wants to integrate Gemini 2 Flash into its existing analytics pipeline. The company stores shipment telemetry data in BigQuery, runs daily analytics using Dataflow, and needs to provide real-time conversational insights to regional managers.
Requirements:

  • Queries must remain compliant with EU data residency laws.

  • Gemini 2 Flash must analyze BigQuery summaries without copying data outside the EU.

  • The system must scale on demand and maintain end-to-end audit logging.

Which solution satisfies these constraints?

  1. A

    Move BigQuery data to a local on-premises PostgreSQL instance and call Gemini 2 Flash via API Gateway for inference.

  2. B

    Connect Gemini 2 Flash through BigQuery Remote Functions, hosting the LLM in a US-central region for better latency and throughput.

  3. C

    Export BigQuery data to Cloud Storage (EU), then feed it to Gemini 2 Flash using Vertex AI batch prediction jobs running in the same region.

  4. D

    Use Vertex AI Extensions for BigQuery with Gemini 2 Flash hosted in the same EU region, enabling federated inference while retaining data locality.

Xem giải thích

Đáp án

D — Dùng Vertex AI Extensions cho BigQuery, với Gemini 2 Flash đặt trong cùng khu vực EU

Vì sao đúng

Hai yêu cầu được thoả cùng lúc: dữ liệu không rời khỏi EU vì cả kho dữ liệu lẫn mô hình đều nằm trong khu vực đó, và không phải chuyển dữ liệu đi đâu vì phần suy luận được gọi ngay từ trong BigQuery. Ít bản sao dữ liệu hơn cũng có nghĩa là ít bề mặt rủi ro hơn.

Vì sao các phương án khác sai

  • C. Xuất dữ liệu sang Cloud Storage rồi mới đưa vào mô hình — tạo thêm một bản sao dữ liệu nhạy cảm và thêm một chặng trong đường ống.
  • A. Chuyển dữ liệu về PostgreSQL tại chỗ rồi gọi mô hình — đi ngược hẳn hướng, và mất mọi lợi ích của kho dữ liệu đám mây.
  • B. Tự host mô hình để gọi qua BigQuery Remote Function — Remote Function là cơ chế hợp lệ, nhưng tự vận hành mô hình lớn là gánh nặng không cần thiết khi đã có bản được quản lý trong EU.
Câu 385

You are managing a MySQL database running on a Compute Engine instance. The application workload involves heavy read and write operations, and users report performance bottlenecks during peak usage hours. The database is hosted on an n2-standard-16 virtual machine with a 100 GB SSD persistent disk. The system cannot be restarted until the next scheduled maintenance window. What action should you take to improve performance immediately in a cost-effective way?

  1. A

    Dynamically resize the SSD persistent disk to 1 TB.

  2. B

    Increase the virtual machine's vCPUs to 32 using live migration.

  3. C

    Migrate the database to a zonal HDD persistent disk to save costs.

  4. D

    Upgrade the MySQL database to a managed Cloud SQL instance.

Xem giải thích

Đáp án

A — Nới dung lượng đĩa bền SSD lên 1 TB ngay khi máy đang chạy

Vì sao đúng

Trên đĩa bền của Google Cloud, IOPS và thông lượng tỉ lệ thuận với dung lượng. CSDL có tải đọc ghi nặng thì nút thắt gần như luôn nằm ở tầng đĩa, nên nới đĩa lớn hơn là cách nâng trần hiệu năng trực tiếp nhất — kể cả khi bạn không cần thêm chỗ chứa. Thao tác này làm được không cần dừng máy.

Vì sao các phương án khác sai

  • B. Tăng lên 32 vCPU — thêm CPU không giải quyết được nghẽn ở đĩa; và việc thay loại máy vẫn cần khởi động lại chứ không "live migration" như phương án mô tả.
  • C. Chuyển sang đĩa HDD cho rẻ — HDD có IOPS thấp hơn SSD rất nhiều; đi ngược hẳn mục tiêu.
  • D. Chuyển sang Cloud SQL — hướng đi tốt về lâu dài, nhưng là một dự án di chuyển chứ không phải cách xử lý nghẽn hiệu năng ngay lúc này, và tự nó không đảm bảo hết nghẽn nếu cấu hình lưu trữ vẫn nhỏ.
Câu 386

You are the cloud architect for a multinational company that collects IoT sensor data from multiple regions worldwide. The data needs to be aggregated and processed in Google Cloud. The company requires:

  1. Efficient and cost-effective data transfer from multiple global locations to Google Cloud.

  2. Low latency for data transfer, especially between regions where data needs to be processed in near real-time.

  3. The ability to manage network costs while ensuring data integrity.

  4. Encryption during data transfer.

  5. A network setup that can scale as the number of IoT devices grows.

Which of the following strategies best addresses the company’s needs?

  1. A

    Implement multiple Dedicated Interconnects in key regions, configure GCS buckets with the Regional storage class in each region, and use managed SSL/TLS for encryption. Set up VPC peering between regions for efficient data transfer.

  2. B

    Set up individual Cloud VPN tunnels from each global location to a centralized GCS bucket in the us-central1 region, use the Multi-Regional storage class, and implement TCP with standard congestion control.

  3. C

    Establish Dedicated Interconnects in key regions, configure GCS buckets with the Multi-Regional storage class, and use Cloud Interconnect to manage cross-region data transfer. Enable BBR congestion control for optimized data transfer rates.

  4. D

    Use a CDN (Content Delivery Network) to collect data at edge locations, store the data temporarily in edge caches, and periodically transfer it to a Multi-Regional GCS bucket. Use Cloud VPN for secure transfer between edge locations and Google Cloud.

Xem giải thích

Đáp án

A — Nhiều Dedicated Interconnect ở các khu vực chính, bucket GCS lớp Regional đặt tại từng khu vực

Vì sao đúng

Điểm phân biệt nằm ở lớp lưu trữ. Dữ liệu cảm biến được nạp vào từ nhiều nơi trên thế giới, nên mỗi nguồn nên ghi vào bucket đặt ngay gần nó: độ trễ ghi thấp nhất và chi phí lưu trữ rẻ nhất. Nhân bản rộng ra nhiều khu vực là thứ không cần cho khâu nạp dữ liệu — dữ liệu sẽ được gom về xử lý sau.

Vì sao các phương án khác sai

  • **C. Cùng dùng Dedicated Interconnect nhưng bucket lớp đa vùng — đây là phương án nhiễu gần nhất. Đa vùng nhân bản dữ liệu ra nhiều khu vực và tính giá cao hơn, trong khi ở khâu nạp thì chẳng ai đọc dữ liệu từ khu vực khác.
  • B. VPN từ mỗi nơi về một bucket duy nhất ở us-central1 — mọi nguồn trên thế giới ghi về một điểm ở Mỹ: độ trễ cao nhất trong bốn phương án.
  • D. Dùng CDN để thu thập dữ liệu — CDN dựng để phân phối nội dung ra, không phải để nhận dữ liệu vào.
Câu 387

You are working on a project for a large multinational company that has numerous APIs with different processing requirements. The architecture team decided to host each API on a separate set of instances and use a single Global HTTP(S) Load Balancer to route requests to the appropriate backend. To ensure the requests reach the right backend service, what should you do?

  1. A

    Create a separate VPC network for each API path and configure the Load Balancer to route based on VPC.

  2. B

    Use separate backend services for each API path and configure URL maps to route requests.

  3. C

    Create separate subnetworks for each API backend and route requests based on the subnetwork IP range.

  4. D

    Assign different static external IP addresses to each API backend.

Xem giải thích

Đáp án

B — Dùng backend service riêng cho từng đường dẫn API và khai URL map để định tuyến

Vì sao đúng

Đây đúng là công dụng của load balancer tầng 7: URL map đọc đường dẫn của yêu cầu rồi chuyển tới backend service tương ứng. Mỗi API có backend riêng nên co giãn độc lập, cấu hình health check riêng, và triển khai riêng — tất cả nằm sau một địa chỉ IP và một chứng chỉ TLS duy nhất.

Vì sao các phương án khác sai

  • D. Gán IP tĩnh khác nhau cho từng backend — thành nhiều điểm truy cập, người gọi phải biết gọi đúng nơi; đúng thứ URL map sinh ra để tránh.
  • A. Mỗi API một VPC riêng — cô lập mạng không giải quyết bài toán định tuyến theo đường dẫn, mà còn làm kiến trúc phức tạp hẳn.
  • C. Mỗi backend một subnet rồi định tuyến theo đó — subnet là khái niệm tầng mạng, không nhìn thấy đường dẫn HTTP.
Câu 388

You are designing a big data analytics platform for a media company that processes large volumes of data daily. The platform must efficiently handle data ingestion, processing, and querying tasks. The company expects data processing workloads to vary significantly, with some periods of low activity and others requiring substantial computational power, especially when generating reports or running complex queries. The platform needs to be cost-effective, with the ability to scale compute resources according to the workload, and should integrate seamlessly with Google Cloud’s data services like BigQuery and Dataflow. What compute resource provisioning strategy would you recommend for the big data analytics platform?

  1. A

    Utilize Google Cloud Dataproc with preemptible VMs for cost savings and configure autoscaling clusters based on workload metrics.

  2. B

    Provision a static number of Google Kubernetes Engine (GKE) nodes with horizontal pod autoscaling disabled to maintain consistent performance.

  3. C

    Deploy the analytics platform on Google Kubernetes Engine (GKE) with fixed node pools and manual scaling based on expected workload patterns.

  4. D

    Use Google Compute Engine (GCE) instances with fixed machine types and provision a large number of VMs to handle peak workloads.

Xem giải thích

Đáp án

A — Dataproc với máy preemptible để tiết kiệm, kèm cấu hình tự co giãn

Vì sao đúng

Nền tảng phân tích xử lý dữ liệu lớn hằng ngày có hai đặc điểm khiến lựa chọn này hợp: khối lượng công việc chịu được việc mất một node vì Spark tự chạy lại phần việc đó, và lượng việc thay đổi theo ngày nên co giãn có ích thật. Máy preemptible cắt mạnh chi phí tính toán mà không làm hỏng kết quả.

Vì sao các phương án khác sai

  • B và C. Cụm GKE với số node cố định — trả tiền cho năng lực đỉnh suốt thời gian còn lại, và bạn tự dựng phần chia việc mà Spark đã có sẵn.
  • D. Máy ảo cấu hình cố định dựng sẵn — đắt nhất và kém linh hoạt nhất.
Câu 389

How would you design a solution for running a large-scale, multi-cloud, and secure disaster recovery plan for a global enterprise, considering the requirement for real-time data replication, low recovery time objective (RTO), and the ability to handle multiple TBs of data from multiple locations?

  1. A

    Use Cloud Storage Transfer Service for data replication, with Cloud VPN for network connectivity and Cloud Storage for database management.

  2. B

    Use Cloud Storage Transfer Service for data replication, with Cloud Dedicated Interconnect for network connectivity and Cloud Filestore for database management.

  3. C

    Use Cloud Storage Transfer Service for data replication, with Cloud Dedicated Interconnect for network connectivity and Cloud Spanner for database management.

  4. D

    Use Cloud Functions for data replication, with Cloud Interconnect for network connectivity and Cloud Bigtable for database management.

Xem giải thích

Đáp án

C — Storage Transfer Service để nhân bản dữ liệu, Dedicated Interconnect cho kết nối, Cloud Spanner cho tầng CSDL

Vì sao đúng

Ba yêu cầu của đề — nhân bản thời gian thực, RTO thấp, nhiều terabyte từ nhiều nơi — cần ba mảnh và mảnh quyết định là tầng CSDL. Cloud Spanner nhân bản đồng bộ qua nhiều khu vực và vẫn giữ nhất quán mạnh, nên khi chuyển sang nơi dự phòng thì không mất dữ liệu và không phải khôi phục gì — đó chính là cách đạt RTO thấp. Dedicated Interconnect cho băng thông và độ trễ ổn định để chuyển hàng terabyte.

Vì sao các phương án khác sai

  • B. Cùng Interconnect nhưng dùng Cloud Filestore cho tầng CSDL — Filestore là hệ tệp NFS, không phải cơ sở dữ liệu; nó không có nhân bản đa vùng hay ngữ nghĩa giao dịch.
  • A. Dùng Cloud VPN và Cloud Storage cho tầng CSDL — sai cả hai: VPN có độ trễ biến động, và kho đối tượng không phải CSDL.
  • D. Dùng Cloud Functions để nhân bản dữ liệu — không kham nổi việc nhân bản liên tục nhiều terabyte.
Câu 390

You are designing a microservices-based application deployed on GKE (Google Kubernetes Engine). The services communicate internally using REST APIs. Your security team requires that all service-to-service communication must be encrypted in transit, and access should be restricted to authorized services only, without hardcoding credentials or managing certificates manually. What is the best approach to meet these requirements?

  1. A

    Enable Istio on GKE and enforce mTLS for internal traffic

  2. B

    Use HTTPS between services and store service credentials in ConfigMaps

  3. C

    Allow all internal traffic through firewall rules and monitor with VPC Flow Logs

  4. D

    Use Basic Authentication with encrypted environment variables for credentials

Xem giải thích

Đáp án

A — Bật Istio trên GKE và bắt buộc mTLS cho lưu lượng nội bộ

Vì sao đúng

mTLS qua service mesh cho hai thứ mà các phương án khác thiếu: lưu lượng giữa các dịch vụ được mã hoá, và mỗi bên đều xác thực danh tính của bên kia bằng chứng chỉ. Quan trọng không kém là mesh lo phần cấp phát và xoay vòng chứng chỉ tự động, nên không có thông tin đăng nhập nào nằm trong mã hay cấu hình để mà rò rỉ.

Vì sao các phương án khác sai

  • B. HTTPS giữa các dịch vụ, thông tin đăng nhập để trong ConfigMap — ConfigMap không phải nơi chứa bí mật: nó lưu dạng văn bản thường và ai đọc được namespace là thấy.
  • D. Basic Authentication với biến môi trường đã mã hoá — Basic Auth truyền thông tin đăng nhập ở mỗi lời gọi và không xác thực hai chiều.
  • C. Cho phép mọi lưu lượng nội bộ rồi theo dõi bằng VPC Flow Logs — không mã hoá, không xác thực, chỉ ghi lại việc đã xảy ra.