Ngân hàng đề — Google Professional Cloud Architect

Tìm thấy 420 câu.

Câu 391

A fintech company runs its core transaction processing system on GKE Autopilot clusters. After several outages due to misconfigured container updates, the SRE team decides to improve operational visibility, post-incident learning, and automation. As the Cloud Architect, you must propose a solution aligned with the Operational Excellence pillar. Which approach best supports these goals?

  1. A

    Schedule daily manual reviews of audit logs and publish summaries in shared documents.

  2. B

    Deploy a third-party monitoring tool and rely on team emails for incident communication.

  3. C

    Enable Cloud Logging for each namespace, create a manual spreadsheet of incidents, and conduct postmortems quarterly.

  4. D

    Configure Cloud Monitoring dashboards, enable Error Reporting and Cloud Trace, use Cloud Build triggers for config validation, and document findings in Blameless postmortems.

Xem giải thích

Đáp án

D — Dựng bảng điều khiển Cloud Monitoring, bật Error Reporting và Cloud Trace

Vì sao đúng

Đề nêu nguyên nhân là cấu hình container sai gây sự cố lặp lại, nên thứ cần là khả năng phát hiện sớm và chẩn đoán nhanh, tự động chứ không dựa vào người. Ba công cụ phủ ba góc: Monitoring cho số liệu và cảnh báo, Error Reporting gom lỗi ứng dụng thành nhóm để thấy ngay lỗi mới xuất hiện, Cloud Trace chỉ ra chặng nào chậm trong chuỗi microservice.

Vì sao các phương án khác sai

  • A. Rà nhật ký kiểm toán bằng tay mỗi ngày — phát hiện quá muộn và không mở rộng được.
  • C. Ghi lại sự cố vào bảng tính thủ công — quy trình thủ công sẽ bị bỏ quên đúng lúc bận nhất.
  • B. Dùng công cụ bên thứ ba rồi liên lạc bằng email — thêm hệ thống phải vận hành, và email không phải kênh xử lý sự cố.
Câu 392

For this question, refer to the KnightMotives Automotive case study.

https://services.google.com/fh/files/misc/v6.1_pca_knightmotives_automotive_case_study_english.pdf


KnightMotives wants to monetize vehicle and customer data by offering AI-driven insights to dealers, such as predictive maintenance and personalized sales recommendations. Dealers operate across the EU and have limited budgets for new infrastructure.

The solution must ensure GDPR compliance, strict data access separation between dealers, and low operational overhead while supporting rapid feature evolution. Which Google Cloud architecture best supports these requirements?

  1. A

    Deploy separate Google Cloud projects per dealer, each with its own full copy of the data.

  2. B

    Use a centralized data lake with Cloud Storage and allow dealers to query data directly using signed URLs.

  3. C

    Create a multi-tenant analytics platform using BigQuery with row-level security and authorized views, deployed in EU regions.

  4. D

    Build a shared BigQuery dataset for all dealers and restrict access using table-level IAM policies.

Xem giải thích

Đáp án

C — Nền tảng phân tích đa người thuê trên BigQuery với bảo mật ở mức hàng

Vì sao đúng

Bài toán là nhiều đại lý cùng dùng một nền tảng nhưng mỗi bên chỉ được thấy dữ liệu của mình. Bảo mật mức hàng làm đúng điều đó trên một bản dữ liệu duy nhất: chính sách gắn vào bảng quyết định mỗi người truy vấn thấy những dòng nào. Không nhân bản dữ liệu, nên không có bản sao nào lệch đi và không có chỗ nào rò thêm.

Vì sao các phương án khác sai

  • A. Mỗi đại lý một dự án với bản sao đầy đủ — chi phí và công bảo trì nhân lên theo số đại lý, và các bản sao sẽ trôi khỏi nhau.
  • D. Một dataset chung, hạn chế bằng quyền ở mức bảng — mức quá thô: hoặc thấy cả bảng hoặc không thấy gì, nên phải tách bảng cho từng đại lý và quay lại vấn đề nhân bản.
  • B. Data lake trên Cloud Storage cho đại lý tự truy vấn — phân quyền ở mức tệp, không tới được mức hàng.
Câu 393

You are designing the infrastructure for an e-commerce application that experiences significant fluctuations in traffic. During flash sales, the traffic can spike dramatically, but during off-peak hours, it is much lower. The application requires a consistent performance level to maintain customer satisfaction. You need to recommend a VM configuration strategy that ensures both cost-efficiency and high availability. Which configuration would best meet these requirements?

  1. A

    Use standard VMs for the base load and preemptible VMs to handle spikes, with autoscaling enabled.

  2. B

    Use only preemptible VMs with a fixed number of instances.

  3. C

    Use only preemptible VMs with autoscaling enabled.

  4. D

    Use only standard VMs with a fixed number of instances.

Xem giải thích

Đáp án

A — Máy thường cho tải nền, máy preemptible cho phần đỉnh, kèm tự co giãn

Vì sao đúng

Đây là cách ghép đúng với hình dạng tải mà đề mô tả: tải nền ổn định thì cần độ tin cậy, nên dùng máy thường; phần đỉnh khi flash sale thì ngắn và có thể chịu được việc một số máy bị thu hồi, nên dùng máy preemptible cho rẻ. Tự co giãn khiến số máy bám theo tải thật thay vì dự phòng cho mức đỉnh suốt cả năm.

Vì sao các phương án khác sai

  • C. Chỉ dùng preemptible có tự co giãn — rẻ nhưng nếu Google thu hồi hàng loạt đúng lúc flash sale thì không còn gì gánh tải nền.
  • B. Chỉ preemptible với số lượng cố định — vừa không đáng tin vừa không co giãn.
  • D. Chỉ máy thường với số lượng cố định — đắt nhất và vẫn hụt khi đỉnh vượt dự đoán.
Câu 394

You are a cloud architect for a healthcare organization that is required to retain medical records for at least 10 years due to regulatory requirements. The data must be stored securely and cost-effectively, with minimal access during the retention period. After 10 years, the data must be deleted automatically unless explicitly retained by an administrator. Your task is to design a Google Cloud Storage solution that meets these requirements while also optimizing costs. Which of the following configurations best meets the organization's needs?

  1. A

    Use a Coldline Storage class bucket with Object Versioning disabled and set a 10-year retention policy on the bucket.

  2. B

    Use a Standard Storage class bucket with Object Versioning enabled and set a 10-year retention policy on the bucket.

  3. C

    Use an Archive Storage class bucket with Object Versioning disabled, set a 10-year retention policy on the bucket, and configure Object Lifecycle Management to delete objects after 10 years.

  4. D

    Use a Nearline Storage class bucket with Object Versioning enabled, set a 10-year retention policy on the bucket, and configure Object Lifecycle Management to delete objects after 10 years.

Xem giải thích

Đáp án

C — Bucket lớp Archive, tắt Object Versioning, đặt chính sách giữ 10 năm

Vì sao đúng

Ba lựa chọn khớp ba yêu cầu:

  • Archive — hồ sơ y tế phải giữ 10 năm nhưng gần như không bao giờ đọc; đây là tầng rẻ nhất cho đúng mẫu đó.
  • Retention policy 10 năm — đây là cơ chế ngăn xoá trước hạn, kể cả bởi người có quyền quản trị. Với yêu cầu pháp lý thì đó chính là điểm mấu chốt.
  • Tắt versioning — dữ liệu lưu trữ không bị ghi đè, nên giữ nhiều phiên bản chỉ làm phình chi phí mà không thêm bảo vệ nào.

Vì sao các phương án khác sai

  • A. Coldline — dành cho nhịp truy cập hàng quý, đắt hơn Archive cho dữ liệu 10 năm không đọc.
  • B. Standard với versioning và giữ 1 năm — sai cả tầng giá lẫn thời hạn.
  • D. Nearline với versioning — Nearline dành cho nhịp hàng tháng, và versioning làm phình chi phí không cần thiết.
Câu 395

After creating multiple preemptible Linux VM instances through Google Compute Engine, your objective is to ensure the appropriate shutdown of the application prior to the VMs being preempted. What actions are recommended in this situation?

  1. A

    Create a shutdown script in the /etc/rc.6.d/ directory.

  2. B

    You should create a shutdown script, registered as a xinetd service in Linux, and use the gcloud compute instances add-metadata command to specify the service URL as the value for a new metadata entry with the key shutdown-script-url.

  3. C

    Create a shutdown script registered as a xinetd service in Linux and configure an endpoint check to call the service.

  4. D

    You should create a shutdown script and use it as the value for a new metadata entry with the key shutdown-script in the Cloud Platform Console when you create the new virtual machine instance.

Xem giải thích

Đáp án

D — Viết shutdown script và khai nó làm giá trị của khoá metadata shutdown-script

Vì sao đúng

Compute Engine có cơ chế sẵn cho đúng việc này: đặt script vào metadata với khoá shutdown-script thì agent trên máy sẽ chạy nó khi máy sắp dừng. Với máy preemptible, Google gửi tín hiệu báo trước khoảng 30 giây trước khi thu hồi — đủ để ứng dụng ghi nốt trạng thái và đóng kết nối cho tử tế.

Vì sao các phương án khác sai

  • A. Đặt script vào /etc/rc.6.d/ — đó là cơ chế của SysV init cho việc tắt máy thông thường; nó không được kích hoạt bởi tín hiệu thu hồi của Compute Engine.
  • B và C. Đăng ký script làm dịch vụ xinetd — xinetd là siêu máy chủ quản lý dịch vụ mạng, hoàn toàn không liên quan tới sự kiện tắt máy.
Câu 396

A multinational logistics company wants to deploy a multi-agent conversational system using Agent Builder with Gemini 2.0 Pro to handle customer inquiries across shipping, billing, and customs domains. The agents must integrate with BigQuery for data retrieval, comply with regional data residency requirements, and scale dynamically during high-traffic events (e.g., holiday seasons). What is the most appropriate architecture design?

  1. A

    Use a single global Agent Builder project with a shared Vertex AI endpoint for all agents, storing all logs in Cloud Storage multi-region buckets.

  2. B

    Host each domain-specific agent in separate regions, connect them via a global load balancer, and enforce region-specific data policies through VPC Service Controls.

  3. C

    Deploy all agents under one project and region to simplify management, and use Cloud Run to route requests between sub-agents.

  4. D

    Deploy each agent on GKE clusters, use service mesh to manage communication, and call Gemini APIs directly for intent processing.

Xem giải thích

Đáp án

B — Đặt mỗi tác nhân theo lĩnh vực ở khu vực riêng, nối lại bằng một lớp điều phối toàn cầu

Vì sao đúng

Với công ty logistics đa quốc gia, đặt tác nhân gần người dùng của nó giúp giảm độ trễ hội thoại — thứ người dùng cảm nhận ngay. Tách theo lĩnh vực cũng cho mỗi tác nhân được cập nhật và co giãn độc lập, còn lớp điều phối lo việc chuyển câu hỏi tới đúng tác nhân, nên người dùng vẫn thấy một trợ lý duy nhất.

Vì sao các phương án khác sai

  • C. Dồn mọi tác nhân vào một dự án và một khu vực — đơn giản để quản lý nhưng người dùng ở xa chịu độ trễ cao, và mất khu vực đó là mất toàn bộ.
  • A. Một dự án toàn cầu với một endpoint dùng chung — cùng vấn đề về độ trễ, cộng thêm việc mọi lĩnh vực bị buộc phát hành cùng nhịp.
  • D. Tự dựng trên GKE với service mesh — làm được nhưng bỏ đi phần được quản lý của Agent Builder và tự gánh việc vận hành cụm.
Câu 397

As a cloud architect, you have observed that a few API requests in your microservices application experience significant delays. You are aware that each API request may pass through multiple services. To identify the specific service causing the longest delays in such cases, what course of action should you pursue?

  1. A

    Instrument your application with Cloud Trace in order to break down the request latencies at each microservice.

  2. B

    Send custom metrics for each of your requests to Cloud Monitoring.

  3. C

    Use Cloud Monitoring to look for insights that show when your API latencies are high.

  4. D

    Set timeouts on your application so that you can fail requests faster.

Xem giải thích

Đáp án

A — Gắn Cloud Trace vào ứng dụng để bóc tách thời gian của từng chặng trong một yêu cầu

Vì sao đúng

Đề nói rõ mỗi yêu cầu đi qua nhiều dịch vụ, nên câu hỏi "chậm ở đâu" không trả lời được bằng cách nhìn từng dịch vụ riêng lẻ. Distributed tracing ghép các chặng lại thành một dòng thời gian duy nhất và chỉ ra chặng nào tốn bao nhiêu mili giây — đây là công cụ duy nhất trong danh sách trả lời đúng câu hỏi đó.

Vì sao các phương án khác sai

  • B. Gửi số liệu tuỳ chọn cho từng yêu cầu — cho biết tổng thời gian chậm, nhưng không bóc ra được phần nào trong chuỗi gây ra nó.
  • C. Tìm insight trong Cloud Monitoring — cho biết khi nào độ trễ tăng, không cho biết ở đâu.
  • D. Đặt timeout để yêu cầu hỏng nhanh hơn — che triệu chứng: người dùng nhận lỗi sớm hơn thay vì chờ lâu, còn nguyên nhân vẫn nguyên.
Câu 398

For this question, refer to the EHR Healthcare case study.

https://services.google.com/fh/files/misc/v6.1_pca_ehr_healthcare_case_study_english.pdf


EHR Healthcare currently uses multiple open-source monitoring tools with email-based alerts that are often ignored. As part of the migration to Google Cloud, the security team wants to improve compliance by ensuring all access to PHI is logged, retained appropriately, and monitored for suspicious activity across projects and regions. What is the best Google Cloud–native approach to improve compliance-focused monitoring and auditing for EHR Healthcare?

  1. A

    Enable Cloud Audit Logs for all services, route logs to a centralized logging project, and configure alerting based on log-based metrics.

  2. B

    Store audit logs locally within each GKE cluster to reduce cross-project dependencies.

  3. C

    Enable Cloud Logging and export logs to BigQuery for ad hoc analysis when incidents occur.

  4. D

    Use Cloud Monitoring with email alerts and rely on application logs for compliance audits.

Xem giải thích

Đáp án

A — Bật Cloud Audit Logs cho mọi dịch vụ và định tuyến log về một dự án ghi log tập trung

Vì sao đúng

Với dữ liệu y tế, yêu cầu tuân thủ là phải trả lời được ai đã làm gì, với dữ liệu nào, lúc nào. Cloud Audit Logs ghi lại đúng điều đó ở tầng nền tảng, và việc định tuyến về một dự án riêng có hai tác dụng: một chỗ duy nhất để tra cứu, và tách quyền — người bị kiểm toán không sửa được nhật ký kiểm toán về chính mình.

Vì sao các phương án khác sai

  • B. Giữ log trong từng cụm GKE — log mất theo cụm, không gộp được, và người quản trị cụm sửa được nhật ký về chính mình.
  • C. Chỉ xuất sang BigQuery khi có sự cố — nếu chưa bật thu thập từ trước thì lúc cần lại không có gì để xem.
  • D. Dựa vào log ứng dụng và cảnh báo email — log ứng dụng do chính ứng dụng ghi nên không đủ tin cậy cho mục đích kiểm toán.
Câu 399

You are working for an ad tech company that requires both real-time and batch processing of ad click data. The data needs to be analyzed in real-time for near instant reporting to advertisers, but also needs to be processed in a batch for daily and monthly reporting. Which combination of GCP services would be the most efficient for this use case?

  1. A

    Use Pub/Sub for real-time processing and Cloud Functions for batch processing.

  2. B

    Use Firestore for real-time processing and Cloud Spanner for batch processing.

  3. C

    Use BigQuery for real-time processing and Cloud Storage for batch processing.

  4. D

    Use Dataflow with both batch and streaming pipelines for processing data.

Xem giải thích

Đáp án

D — Dùng Dataflow với cả pipeline luồng lẫn pipeline theo lô

Vì sao đúng

Đề cần cả hai chế độ trên cùng một loại dữ liệu, và đó chính là điểm mạnh riêng của mô hình Apache Beam mà Dataflow chạy: cùng một đoạn logic biến đổi dùng được cho cả luồng lẫn lô. Nhờ vậy báo cáo gần thời gian thực và phân tích lịch sử không thể cho ra hai kết quả khác nhau — thứ rất hay xảy ra khi dựng hai đường ống riêng bằng hai công nghệ.

Vì sao các phương án khác sai

  • A. Pub/Sub cho thời gian thực, Cloud Functions cho xử lý lô — Pub/Sub chỉ truyền thông điệp chứ không xử lý, và Cloud Functions không kham nổi xử lý lô lớn.
  • C. BigQuery cho thời gian thực, Cloud Storage cho lô — cả hai là nơi lưu trữ, không phải công cụ xử lý.
  • B. Firestore và Cloud Spanner — đều là CSDL, sai hẳn loại công cụ.
Câu 400

As a cloud architect, you are tasked with designing a solution to backup an on-premises PostgreSQL database to Google Cloud Platform. The objective is to create a replica of the on-premises database on GCP for backup purposes, so the data is easily recoverable and accessible in case of an on-premises failure. Which method would be the most efficient way to accomplish this?

  1. A

    Use Google Cloud Storage to store PostgreSQL dump files

  2. B

    Use Cloud SQL for PostgreSQL and setup Cloud SQL external server replication

  3. C

    Use Cloud Dataflow to stream data from PostgreSQL to BigQuery

  4. D

    Use Cloud Spanner to replicate the PostgreSQL database

Xem giải thích

Đáp án

B — Dùng Cloud SQL for PostgreSQL với cơ chế nhân bản từ máy chủ bên ngoài

Vì sao đúng

Đề cần một bản sao của CSDL tại chỗ trên đám mây. Tính năng external server replication của Cloud SQL dựng đúng cho việc này: nó tạo một bản sao liên tục cập nhật từ máy chủ PostgreSQL bên ngoài, nên độ trễ dữ liệu tính bằng giây chứ không phải theo chu kỳ sao lưu. Bản sao đó cũng là CSDL thật, dùng ngay được nếu phải chuyển sang.

Vì sao các phương án khác sai

  • A. Đổ tệp dump vào Cloud Storage — đó là sao lưu định kỳ, không phải bản sao: luôn có khoảng dữ liệu bị mất giữa hai lần chạy, và muốn dùng thì phải khôi phục.
  • C. Dùng Dataflow đưa dữ liệu sang BigQuery — BigQuery là kho phân tích, không thay được CSDL giao dịch.
  • D. Nhân bản sang Cloud Spanner — Spanner không tương thích với PostgreSQL theo cách cho phép nhân bản trực tiếp như vậy.