Ngân hàng đề — Google Professional Cloud Architect

Tìm thấy 420 câu.

Câu 41

For this question, refer to the EHR Healthcare case study.

https://services.google.com/fh/files/misc/v6.1_pca_ehr_healthcare_case_study_english.pdf


The EHR Healthcare engineering team is responsible for securing a new web-based collaboration tool hosted in Google Cloud for its software development teams. The developers often work from different locations and need seamless and secure access to the tool. EHR wants to adopt the BeyondCorp access model and ensure that only authorized users with a Google Workspace account can access the collaboration tool. Additionally, EHR must verify device trust levels before granting access. What should you do?

  1. A

    Use a Cloud CDN and enable signed URLs to restrict unauthorized access to the collaboration tool.

  2. B

    Set up a Virtual Private Cloud (VPC) with private endpoints for the collaboration tool and configure a Google Workspace group policy.

  3. C

    Deploy a Cloud VPN gateway and use IAM permissions to restrict access to the collaboration tool.

  4. D

    Deploy an Identity-Aware Proxy (IAP) and configure it to enforce device trust and user authentication for the collaboration tool.

Xem giải thích

Đáp án

D — Triển khai Identity-Aware Proxy và bắt buộc kiểm tra độ tin cậy của thiết bị

Vì sao đúng

Đây là mô hình BeyondCorp / zero trust: quyền truy cập được quyết định theo danh tính người dùng và tình trạng thiết bị, chứ không theo việc họ đang ở trong mạng nào. IAP đứng trước ứng dụng, kiểm tra từng yêu cầu, và kết hợp với chính sách truy cập theo ngữ cảnh thì chặn được cả trường hợp đúng người nhưng dùng máy chưa được quản lý.

Vì sao các phương án khác sai

  • A. Cloud CDN với signed URL — dùng để phân phối nội dung tĩnh có giới hạn thời gian, không phải cơ chế kiểm soát truy cập ứng dụng.
  • B. VPC với điểm cuối riêng — bảo vệ ở tầng mạng, nhưng không biết gì về người dùng hay thiết bị.
  • C. Cloud VPN cộng IAM — quay lại mô hình "vào được mạng là tin", đúng thứ zero trust bỏ đi.
Câu 42

In your role as a cloud architect, you are in the process of designing a hybrid environment that is future-proof and necessitates a network connection between Google Cloud and your on-premises infrastructure. Your objective is to guarantee compatibility between the Google Cloud environment you are designing and your existing on-premises network environment. What course of action should you take?

  1. A

    You should create a network plan for your VPC in Google Cloud that uses non-overlapping CIDR ranges with your on-premises environment. Use a Cloud Interconnect connection between your on-premises environment and Google Cloud.

  2. B

    You should create a network plan for your VPC in Google Cloud that uses CIDR ranges that overlap with your on-premises environment. Use a Cloud Interconnect connection between your on-premises environment and Google Cloud.

  3. C

    You should use the default VPC in your Google Cloud project. Use a Cloud VPN connection between your on-premises environment and Google Cloud.

  4. D

    You should create a custom VPC in Google Cloud in auto mode. Use a Cloud VPN connection between your on-premises environment and Google Cloud.

Xem giải thích

Đáp án

A — Lập kế hoạch địa chỉ cho VPC sao cho dải CIDR không chồng lấn với mạng tại chỗ

Vì sao đúng

Đây là quyết định phải làm trước tiên và không sửa được về sau trong mọi thiết kế lai. Nếu VPC dùng dải địa chỉ trùng với mạng tại chỗ thì định tuyến không thể phân biệt đích đến, và cách chữa duy nhất là đánh lại địa chỉ cho cả một bên — cực kỳ tốn kém khi hệ thống đã chạy. Đề còn nói "bền vững cho tương lai", nghĩa là phải chừa sẵn dải cho các khu vực và subnet sẽ thêm sau.

Vì sao các phương án khác sai

  • B. Dùng dải CIDR chồng lấn — hỏng ngay ở bước định tuyến.
  • C. Dùng VPC mặc định — VPC mặc định có sẵn subnet ở mọi khu vực với dải địa chỉ cố định, gần như chắc chắn đụng mạng tại chỗ và bạn không kiểm soát được.
  • D. VPC tuỳ chỉnh ở chế độ auto — chế độ auto cũng tự cấp subnet theo dải định sẵn, mất quyền kiểm soát địa chỉ.
Câu 43

As a cloud architect, you are tasked with designing an architecture for an application that will operate on Compute Engine. It is essential to create a disaster recovery plan that ensures the application can seamlessly switch to another region in the event of a regional outage. What course of action should you take?

  1. A

    You should deploy the application on two Compute Engine instance groups, each in the same project but in a different region. Use the first instance group to serve traffic, and use the HTTP load balancing service to fail over to the standby instance group in case of a disaster.

  2. B

    You should deploy the application on two Compute Engine instances in the same project but in a different region. Use the first instance to serve traffic, and use the HTTP load balancing service to fail over to the standby instance in case of a disaster.

  3. C

    You should deploy the application on two Compute Engine instance groups, each in a separate project and a different region. Use the first instance group to serve traffic, and use the HTTP load balancing service to fail over to the standby instance group in case of a disaster.

  4. D

    You should deploy the application on a Compute Engine instance. Use the instance to serve traffic, and use the HTTP load balancing service to fail over to an instance on your premises in case of a disaster.

Xem giải thích

Đáp án

A — Hai instance group ở hai khu vực khác nhau trong cùng một dự án, dùng HTTP load balancing để chuyển đổi dự phòng

Vì sao đúng

Ba yếu tố phải có đủ: instance group (không phải máy lẻ) để co giãn và tự thay máy hỏng, hai khu vực khác nhau để sống sót qua sự cố cấp khu vực, và cùng một dự án để load balancer toàn cầu gom cả hai làm backend. Load balancer tự phát hiện khu vực hỏng và dồn lưu lượng sang khu vực còn lại.

Vì sao các phương án khác sai

  • B. Hai máy ảo lẻ — không co giãn, và một máy hỏng là mất luôn nửa năng lực.
  • **C. Hai instance group ở hai dự án khác nhau — backend của một load balancer phải nằm trong cùng dự án, nên cách này không ghép lại được.
  • D. Dự phòng bằng máy tại chỗ — không phải kiến trúc mà đề đang hỏng tới, và load balancer của Google không nhận backend ngoài như vậy.
Câu 44 Chọn nhiều đáp án

You are designing a high-availability solution for a global e-commerce website hosted on Google Cloud. The website handles a large volume of traffic and requires minimal downtime. You need to design the solution to ensure high availability and automatic failover in case of failure at the regional level. The design should also support horizontal scaling during traffic spikes and distribute the load across multiple regions. Which two components should you include in your design to ensure high availability and automatic failover? (Choose two)

  1. A

    Deploy a single VM in a multi-zone configuration with a regional persistent disk

  2. B

    Use Google Cloud Load Balancer with backend services deployed in multiple regions

  3. C

    Deploy a single instance of a Cloud SQL database in one region with automatic backups enabled

  4. D

    Use Compute Engine managed instance groups with autoscaling enabled

  5. E

    Use a regional Google Kubernetes Engine (GKE) cluster with a static IP for failover

Xem giải thích

Đáp án

B và D — Cloud Load Balancer với backend ở nhiều khu vực, và managed instance group có tự co giãn

Vì sao đúng

Hai mảnh bổ sung cho nhau:

  • B. Load balancer toàn cầu với backend nhiều khu vực — hứng lưu lượng ở biên mạng Google, đưa người dùng tới khu vực gần nhất, và tự bỏ qua khu vực đang hỏng.
  • D. Managed instance group có tự co giãn — thêm bớt máy theo tải thật, tự thay máy hỏng nên không cần ai can thiệp.

Vì sao các phương án khác sai

  • A. Một máy ảo với đĩa bền vùng — vẫn là một máy, tức một điểm hỏng duy nhất.
  • C. Một instance Cloud SQL ở một khu vực — tầng dữ liệu thành điểm hỏng duy nhất.
  • E. Cụm GKE vùng với IP tĩnh — cụm vùng chỉ trải trên các zone trong một khu vực, nên không chịu được sự cố cấp khu vực; IP tĩnh không giúp gì cho việc đó.
Câu 45

You provide a service that you need to open to everyone in your partner network and have a server and an IP address where the application is located. You do not want to have to change the IP address on your DNS server if your server goes down or is replaced. You also want to avoid downtime and deliver a solution with minimal cost and setup. What should you recommend?

  1. A

    You should reserve a static internal IP address, and assign it using Cloud DNS.

  2. B

    You should use the Bring Your Own IP (BYOIP) method to use your own IP address.

  3. C

    You should reserve a static external IP address, and assign it using Cloud DNS.

  4. D

    You should create a script that updates the domain's IP address when the server goes down or is replaced.

Xem giải thích

Đáp án

C — Đặt trước một địa chỉ IP ngoài tĩnh và trỏ tên miền tới nó bằng Cloud DNS

Vì sao đúng

Yêu cầu là đối tác bên ngoài truy cập được và địa chỉ không đổi. IP ngoài tĩnh giữ nguyên qua các lần khởi động lại hay tạo lại máy, nên bản ghi DNS trỏ tới nó không bao giờ phải sửa. Đây là cách làm chuẩn, không cần script hay cơ chế đặc biệt nào.

Vì sao các phương án khác sai

  • A. IP nội bộ tĩnh — chỉ truy cập được từ trong VPC, mà đối tác thì ở ngoài.
  • B. Bring Your Own IP — chỉ dành cho tổ chức đã sở hữu sẵn một dải IP công khai và muốn mang sang Google; quá nặng cho một dịch vụ đơn lẻ.
  • D. Viết script cập nhật DNS mỗi khi IP đổi — tự dựng lại thứ mà IP tĩnh cho sẵn, và có một khoảng thời gian tên miền trỏ sai trong lúc DNS lan truyền.
Câu 46

Your company is designing a multi-region application on Google Cloud. You need to ensure low-latency connectivity and high availability between two Google Cloud regions where your workloads are deployed. You also want to make sure that this setup can scale in the future without major reconfiguration. What should you do?

  1. A

    Use separate VPCs in each region and peer them using VPC Peering.

  2. B

    Use separate custom VPCs in each region and connect them using a VPN tunnel.

  3. C

    Use a single custom VPC with subnets in each region, and configure Cloud NAT for outbound access.

  4. D

    Use the default VPC and configure subnets in both regions.

Xem giải thích

Đáp án

C — Một VPC tuỳ chỉnh duy nhất, mỗi khu vực một subnet

Vì sao đúng

Điểm mấu chốt là VPC của Google Cloud mang tính toàn cầu, subnet mới gắn với khu vực. Vì vậy hai khu vực nằm trong cùng một VPC thì đã nói chuyện được với nhau bằng IP riêng, qua mạng xương sống của Google — độ trễ thấp, băng thông cao, không cần peering, không cần đường hầm, và dùng chung một bộ luật tường lửa.

Vì sao các phương án khác sai

  • A. Hai VPC riêng rồi peering — thêm một lớp cấu hình cho thứ vốn đã có sẵn; peering còn không có tính bắc cầu nên mở rộng về sau sẽ vướng.
  • B. Hai VPC riêng nối bằng VPN — VPN có trần băng thông theo đường hầm và tốn thêm chi phí, hoàn toàn thừa khi cả hai đầu đều ở trong Google Cloud.
  • D. Dùng VPC mặc định — chạy được nhưng dải địa chỉ do Google định sẵn, không kiểm soát được quy hoạch mạng.
Câu 47

For this question, refer to the EHR Healthcare case study.

https://services.google.com/fh/files/misc/v6.1_pca_ehr_healthcare_case_study_english.pdf


EHR Healthcare wants to allow its support engineers to remotely access internal troubleshooting tools hosted on Google Cloud, without requiring VPN access. These tools are deployed on internal App Engine services and are used exclusively by the support team. Each engineer uses a Google Workspace account and should only have access to the tools during business hours. What should you do to enable secure, time-bound access?

  1. A

    Configure a VPC peering connection and grant IAM roles to support engineers.

  2. B

    Configure Identity-Aware Proxy (IAP) to secure the App Engine services and enforce access using Google Workspace credentials with a custom access level based on time conditions.

  3. C

    Deploy an HTTP(S) Load Balancer in front of the App Engine services and protect it with Cloud Armor rate limiting policies.

  4. D

    Use Cloud VPN to tunnel traffic from engineers' devices to a bastion host in Google Cloud, and proxy requests from there to the App Engine services.

Xem giải thích

Đáp án

B — Dùng Identity-Aware Proxy để bảo vệ các dịch vụ App Engine

Vì sao đúng

IAP là cách chuẩn để đặt một lớp xác thực trước ứng dụng App Engine. Mỗi yêu cầu đều phải qua kiểm tra danh tính và chính sách IAM trước khi chạm tới ứng dụng, nên kỹ sư hỗ trợ đăng nhập bằng tài khoản công ty là dùng được, còn người ngoài thì không tới được ứng dụng dù biết địa chỉ. Không phải sửa mã ứng dụng, không phải dựng VPN.

Vì sao các phương án khác sai

  • A. VPC peering cộng vai IAM — App Engine Standard không nằm trong VPC của bạn theo cách đó, nên peering không phải công cụ kiểm soát truy cập ở đây.
  • C. Load balancer với Cloud Armor — Cloud Armor lọc theo IP và mẫu tấn công, không xác thực danh tính người dùng.
  • D. VPN tới bastion host — quay lại mô hình dựa vào vị trí mạng, và thêm một máy phải vận hành.
Câu 48

A media company plans to build a global video streaming platform on GCP. The platform needs to stream content to millions of users worldwide, offering low latency and high availability. The content is primarily video-on-demand (VOD), and the company wants to implement a solution that optimizes the delivery of videos based on the user's location. The platform must also support real-time analytics to monitor viewer engagement and optimize content delivery. Cost efficiency and the ability to scale automatically are critical requirements. Which architecture best meets the company’s requirements?

  1. A

    Implement the platform using App Engine Standard Environment, Cloud Spanner for metadata storage, and Cloud CDN for video delivery. Store videos in a multi-regional Cloud Storage bucket.

  2. B

    Use Google Kubernetes Engine (GKE) with multi-regional clusters, Cloud CDN for video delivery, and BigQuery for real-time analytics. Store videos in a single-region Cloud Storage bucket.

  3. C

    Deploy the video streaming application on Compute Engine with a global HTTP(S) Load Balancer and use Cloud SQL for storing metadata. Store videos in a multi-regional Cloud Storage bucket.

  4. D

    Use Cloud Run for the video streaming application, Firestore for metadata storage, and Cloud Storage with Object Versioning enabled for video storage. Implement Cloud CDN for content delivery.

Xem giải thích

Đáp án

A — App Engine Standard, Cloud Spanner cho siêu dữ liệu, Cloud CDN, video trong bucket đa vùng

Vì sao đúng

Với video theo yêu cầu quy mô toàn cầu, hai mảnh quyết định là:

  • Cloud CDN — video được nhớ đệm ở biên mạng gần người dùng, nên độ trễ thấp và máy chủ gốc không phải phục vụ lại cùng một tệp hàng triệu lần.
  • Bucket Cloud Storage đa vùng — dữ liệu gốc được nhân bản qua nhiều khu vực, nên vừa bền vừa gần người dùng khi CDN cần lấy lại.

Cloud Spanner lo siêu dữ liệu với tính nhất quán mạnh trên phạm vi toàn cầu, còn App Engine Standard co giãn tự động mà không phải vận hành máy nào.

Vì sao các phương án khác sai

  • **B. GKE nhiều khu vực nhưng bucket một vùng — điểm chí mạng nằm ở đây: nội dung gốc chỉ nằm ở một khu vực, nên người dùng ở châu lục khác chịu độ trễ cao mỗi lần CDN chưa có bản đệm, và mất khu vực đó là mất toàn bộ thư viện.
  • C. Máy ảo với Cloud SQL — phải tự vận hành, và Cloud SQL không phải CSDL đa vùng nhất quán mạnh.
  • D. Cloud Run với Object Versioning — versioning để giữ các bản cũ của tệp, chẳng liên quan tới việc phân phối video, mà còn làm phình chi phí lưu trữ.
Câu 49

As a cloud architect, your role involves developing an application using various microservices that should remain internal to the cluster. Your objective is to configure each microservice with a designated number of replicas. Additionally, you aim to establish a uniform addressing mechanism where any microservice can access a specific microservice, irrespective of its scaling level. This solution needs to be implemented on Google Kubernetes Engine. What course of action should you take in this situation?

  1. A

    Deploy each microservice as a Deployment. Expose the Deployment in the cluster using an Ingress, and use the Ingress IP address to address the Deployment from other microservices within the cluster.

  2. B

    Deploy each microservice as a Deployment. Expose the Deployment in the cluster using a Service, and use the Service DNS name to address it from other microservices within the cluster.

  3. C

    Deploy each microservice as a Pod. Expose the Pod in the cluster using a Service, and use the Service DNS name to address the microservice from other microservices within the cluster.

  4. D

    Deploy each microservice as a Pod. Expose the Pod in the cluster using an Ingress, and use the Ingress IP address name to address the Poda from other microservices within the cluster.

Xem giải thích

Đáp án

B — Mỗi microservice là một Deployment, mở ra bằng Service, và gọi nhau qua tên DNS của Service

Vì sao đúng

Ba mảnh khớp đúng ba yêu cầu của đề:

  • Deployment — cho khai số bản sao mong muốn và tự duy trì con số đó.
  • Service — cho một điểm truy cập ổn định đứng trước nhóm pod hay thay đổi.
  • Tên DNS của Service — cơ chế địa chỉ thống nhất mà đề yêu cầu: gọi ten-dich-vu.namespace là tới, không cần biết pod nào đang sống.

Service kiểu mặc định ClusterIP chỉ tồn tại trong cụm, đúng yêu cầu "nội bộ".

Vì sao các phương án khác sai

  • A và D. Dùng Ingress — Ingress dựng để đưa lưu lượng từ ngoài vào, trái hẳn yêu cầu giữ mọi thứ trong cụm.
  • C và D. Triển khai bằng Pod trần — pod trần không có khái niệm số bản sao và không được tạo lại khi chết.
Câu 50 Chọn nhiều đáp án

Your company is planning to migrate their legacy analytics platform to the cloud. They want to ensure that raw customer interaction data (500 TB) is securely archived for long-term compliance purposes. Additionally, they want to leverage the cloud to perform serverless analytics to identify key customer behavior patterns. Which two steps should they take? (Choose two)

  1. A

    Load data into BigQuery for analytics.

  2. B

    Load data directly into Cloud SQL for analysis.

  3. C

    Archive data in Cloud Datastore for long-term storage.

  4. D

    Upload the raw data files into Cloud Storage.

  5. E

    Store data in Cloud Spanner for scalable analytics.

Xem giải thích

Đáp án

A và D — nạp dữ liệu vào BigQuery để phân tích, và đưa tệp thô lên Cloud Storage

Vì sao đúng

Đề có hai nhu cầu tách bạch và mỗi dịch vụ lo một:

  • D. Cloud Storage cho 500 TB dữ liệu thô cần lưu trữ lâu dài — rẻ nhất cho khối lượng đó, và chính sách vòng đời tự đẩy dữ liệu cũ xuống tầng rẻ hơn.
  • A. BigQuery cho phần phân tích — truy vấn SQL ở quy mô lớn mà không phải vận hành cụm nào.

Đây là mô hình quen thuộc: Cloud Storage làm kho lưu trữ nguồn, BigQuery làm nơi phân tích.

Vì sao các phương án khác sai

  • B. Cloud SQL — CSDL giao dịch, không kham nổi 500 TB và không dựng cho phân tích.
  • C. Cloud Datastore để lưu trữ dài hạn — kho tài liệu cho ứng dụng, đắt hơn hẳn Cloud Storage cho mục đích lưu trữ.
  • E. Cloud Spanner — CSDL quan hệ phân tán nhất quán mạnh, rất đắt và sai mục đích ở đây.