Ngân hàng đề — Google Professional Cloud Architect

Tìm thấy 420 câu.

Câu 401

You are a cloud architect for a multinational corporation that has a wide array of legacy applications hosted on-premises. You have been tasked to devise a strategy to migrate these applications to Google Cloud. Considering the least disruption, the nature of the applications, and the organization's business objectives, which migration strategy should you recommend?

  1. A

    Use the Strangler pattern where a new system slowly replaces the old one over time.

  2. B

    Migrate all applications to serverless compute options, such as Google Cloud Functions or App Engine.

  3. C

    Lift-and-Shift strategy for all applications regardless of their complexity.

  4. D

    Prioritize a hybrid approach, maintaining a mix of on-premises and cloud-hosted applications.

Xem giải thích

Đáp án

A — Áp dụng mô hình Strangler, hệ thống mới thay dần hệ thống cũ theo thời gian

Vì sao đúng

Với nhiều ứng dụng cũ có độ phức tạp khác nhau, mô hình strangler là chiến lược có rủi ro thấp nhất: đặt một lớp trung gian trước hệ thống cũ, rồi chuyển từng chức năng sang bản mới phía sau lớp đó. Người dùng không thấy gì thay đổi, mỗi bước nhỏ nên hỏng thì lùi được, và hệ thống cũ chỉ bị gỡ khi phần cuối cùng đã có bản thay thế.

Vì sao các phương án khác sai

  • C. Bê nguyên tất cả lên bất kể độ phức tạp — bỏ qua sự khác nhau giữa các ứng dụng; có cái chuyển thẳng được, có cái thì không.
  • B. Chuyển hết sang nền tảng không máy chủ — ứng dụng cũ thường có trạng thái và tiến trình chạy nền, không khớp mô hình đó nếu chưa viết lại.
  • D. Chọn mô hình lai làm mục tiêu — lai là trạng thái trung gian trong quá trình chuyển, không phải chiến lược để nhắm tới.
Câu 402

For this question, refer to the Cymbal Retail case study.

https://services.google.com/fh/files/misc/v6.1_pca_cymbal_retail_case_study_english.pdf


Cymbal wants enriched product attributes (such as color, material, and use-case) to be available consistently across web, conversational commerce, and future AI-powered recommendation systems. The solution must support:

  • Near real-time updates when product data changes

  • A unified, authoritative enriched catalog

  • Easy integration with existing Kubernetes-based microservices

Which design best ensures a unified and scalable enriched product catalog?

  1. A

    Store enriched attributes back into each original source database to keep systems independent.

  2. B

    Use Cloud SQL as the single enriched catalog store and expose it directly to all consumer applications.

  3. C

    Maintain enriched product data in BigQuery and require all applications to query BigQuery directly.

  4. D

    Publish enriched product updates to Pub/Sub and persist them in a centralized API-backed service running on GKE.

Xem giải thích

Đáp án

D — Đăng bản cập nhật sản phẩm đã làm giàu lên Pub/Sub và lưu vào một kho tập trung

Vì sao đúng

Nhiều ứng dụng cần dữ liệu sản phẩm đã làm giàu, và Pub/Sub giải đúng bài toán phân phối đó: bên sản xuất đăng một lần, mọi bên tiêu thụ tự đăng ký nhận. Thêm một ứng dụng mới thì chỉ cần thêm một subscription, không phải sửa bên sản xuất. Kho tập trung giữ trạng thái hiện tại cho ai cần truy vấn trực tiếp.

Vì sao các phương án khác sai

  • A. Ghi ngược thuộc tính đã làm giàu vào từng CSDL nguồn — nhiều bản sao phải giữ đồng bộ, và làm ô nhiễm hệ thống nguồn.
  • C. Bắt mọi ứng dụng truy vấn thẳng BigQuery — BigQuery là kho phân tích, độ trễ tính bằng giây; không hợp đường phục vụ người dùng.
  • B. Dùng Cloud SQL làm kho duy nhất và cho mọi ứng dụng nối thẳng vào — thành nút thắt và điểm hỏng duy nhất khi số ứng dụng tăng lên.
Câu 403

For this question, refer to the EHR Healthcare case study.

https://services.google.com/fh/files/misc/v6.1_pca_ehr_healthcare_case_study_english.pdf


EHR Healthcare is transitioning from an on-prem data center to Google Cloud. For the transition period, some applications will remain hosted on-prem but need to be securely accessible by the remote workforce through a BeyondCorp access model. All employees use Google Workspace accounts for authentication. EHR also requires visibility into access logs for audit purposes. How should you configure access to these on-prem applications?

  1. A

    Configure a Cloud Load Balancer with private backend services and create firewall rules to control access.

  2. B

    Deploy Identity-Aware Proxy (IAP) TCP forwarding for the on-prem applications, and use Google Workspace for user authentication.

  3. C

    Set up a Cloud Interconnect connection to the on-prem data center and configure IAM policies to control access.

  4. D

    Create a static IP for each on-prem application and restrict access using Google Cloud Armor policies.

Xem giải thích

Đáp án

B — Dùng IAP TCP forwarding cho các ứng dụng tại chỗ

Vì sao đúng

IAP TCP forwarding cho phép truy cập ứng dụng nội bộ mà không cần VPN và không cần mở cổng nào ra Internet. Mỗi kết nối đi qua IAP và được kiểm tra bằng danh tính người dùng cộng chính sách IAM trước khi tới được ứng dụng. Với EHR thì đây là mô hình zero trust: quyền truy cập không phụ thuộc việc người dùng đang ở mạng nào.

Vì sao các phương án khác sai

  • A. Load balancer với backend riêng và luật tường lửa — kiểm soát ở tầng mạng, không biết gì về danh tính người dùng.
  • C. Cloud Interconnect — giải bài toán kết nối hai mạng, không phải bài toán kiểm soát ai được vào ứng dụng nào.
  • D. Gán IP tĩnh cho từng ứng dụng rồi lọc — lọc theo địa chỉ là quay về mô hình dựa vào vị trí mạng, và không mở rộng được với nhân viên làm việc từ xa.
Câu 404

Consider a scenario where a global financial services company wants to move their legacy monolithic application to the cloud. The application is currently hosted on-premise and relies on a combination of custom-built software, third-party software, and hardware appliances. The new cloud-based solution must meet the following requirements:

  • support high availability and disaster recovery

  • maintain the current level of security and compliance

  • ensure data privacy and data residency requirements are met for all regions

  • optimize cost while providing scalable and elastic resources

  • minimize downtime during migration

What is the most appropriate solution to meet the requirements outlined above?

  1. A

    Migrate the application to Google Cloud using Compute Engine virtual machines and Cloud Storage for data storage. Use Load Balancer for traffic management and Cloud VPN for secure communication between on-premise and cloud resources. Implement a multi-region deployment with active-active replication.

  2. B

    Rebuild the application using Cloud Functions and Firestore for data storage. Use Cloud CDN for traffic management and loud VPN for secure communication between on-premise and cloud resources. Implement a multi-region deployment with active-standby replication.

  3. C

    Rebuild the application using App Engine and Google Cloud SQL for data storage. Use Cloud CDN for traffic management and Cloud Interconnect for secure communication between on-premise and cloud resources. Implement a multi-zone deployment with active-standby replication.

  4. D

    Migrate the application to Google Cloud using Compute Engine virtual machines and Cloud Storage for data storage. Use Google Cloud DNS for traffic management and Virtual Private Cloud (VPC) for secure communication between on-premise and cloud resources. Implement a multizone deployment with active-active replication.

Xem giải thích

Đáp án

A — Chuyển lên Compute Engine với Cloud Storage, dùng Load Balancer và Cloud VPN

Vì sao đúng

Ứng dụng nguyên khối cũ có cả phần mềm tự viết, phần mềm bên thứ ba lẫn phụ thuộc phần cứng, nên viết lại là dự án nhiều năm với rủi ro rất cao. Chuyển nguyên trạng lên máy ảo là ánh xạ gần nhất với môi trường hiện có. Load Balancer lo phân phối lưu lượng, còn Cloud VPN giữ liên lạc an toàn với phần còn lại tại chỗ trong giai đoạn chuyển tiếp.

Vì sao các phương án khác sai

  • B và C. Viết lại bằng Cloud Functions hoặc App Engine — vi phạm điều kiện cốt lõi: ứng dụng phụ thuộc phần mềm bên thứ ba và phần cứng, không viết lại nhanh được.
  • D. Cùng chuyển lên máy ảo nhưng dùng Cloud DNS để "quản lý lưu lượng" — DNS phân giải tên chứ không cân bằng tải hay kiểm tra sức khoẻ backend; đây là điểm hỏng so với phương án A.
Câu 405

You are tasked with migrating an on-premise data warehouse to Google Cloud. The on-premise data warehouse supports structured data with complex SQL queries and must ensure scalability for future growth, seamless integration with analytics tools, and minimal downtime during the migration. Which Google Cloud service would best suit this use case?

  1. A

    Use Cloud Spanner to replicate the on-premise data warehouse schema and load the data.

  2. B

    Migrate to Cloud SQL using replication for data transfer.

  3. C

    Use Dataproc to set up a Hadoop cluster for data processing and querying.

  4. D

    Migrate to BigQuery using a batch data transfer approach.

Xem giải thích

Đáp án

D — Chuyển sang BigQuery bằng cách nạp dữ liệu theo lô

Vì sao đúng

Đề mô tả một kho dữ liệu: dữ liệu có cấu trúc, truy vấn SQL phức tạp. BigQuery là bản tương đương được quản lý — hỗ trợ SQL chuẩn nên phần lớn truy vấn chuyển sang không quá khó, tách lưu trữ khỏi tính toán nên mở rộng tới petabyte, và không có cụm nào phải dựng hay vá. Nạp theo lô là cách tự nhiên cho một lần chuyển kho dữ liệu.

Vì sao các phương án khác sai

  • A. Cloud Spanner — CSDL giao dịch phân tán, rất đắt và không tối ưu cho truy vấn phân tích quét nhiều dữ liệu.
  • B. Cloud SQL — CSDL một máy chủ, có trần mở rộng rõ ràng nên không thay được kho dữ liệu.
  • C. Dựng cụm Hadoop trên Dataproc — làm được nhưng quay lại đúng gánh nặng vận hành cụm mà việc lên đám mây định bỏ đi.
Câu 406

Your organization has a multi-tier application running on Google Cloud and follows an Agile development process. You are assigned the task of setting up a testing environment that is identical to the production environment. This testing environment should be isolated and must not impact the production environment in any way. It should also be easily reproducible and scalable to facilitate multiple parallel testing efforts. How should you approach this task?

  1. A

    Use Google Compute Engine to manually create and configure VMs for the testing environment that match the production environment.

  2. B

    Use Google Cloud Functions and create separate functions for testing.

  3. C

    Use Google Kubernetes Engine and set up a separate namespace for testing while using the same cluster as the production environment.

  4. D

    Use Google Deployment Manager to replicate the infrastructure of the production environment in the testing environment.

Xem giải thích

Đáp án

D — Dùng Deployment Manager để dựng lại hạ tầng giống hệt môi trường sản xuất

Vì sao đúng

Giá trị của một môi trường kiểm thử nằm ở chỗ nó giống sản xuất. Hạ tầng dạng mã đảm bảo điều đó theo cách duy nhất đáng tin: cùng một tệp cấu hình dựng ra cả hai môi trường, nên không có khác biệt do người quên bước nào. Với quy trình Agile thì môi trường còn phải dựng lên và dỡ đi liên tục, mà cả hai đều chỉ là một lệnh.

Vì sao các phương án khác sai

  • A. Tạo và cấu hình máy ảo bằng tay — chắc chắn sẽ lệch khỏi sản xuất theo thời gian, và "chạy được ở test nhưng hỏng ở prod" bắt nguồn từ đây.
  • C. Dùng namespace riêng trong cùng cụm GKE — tách logic nhưng vẫn dùng chung node và cùng mặt phẳng điều khiển; kiểm thử có thể ảnh hưởng sản xuất.
  • B. Tạo Cloud Functions riêng để kiểm thử — chỉ phủ một phần rất nhỏ của một ứng dụng nhiều tầng.
Câu 407

As a cloud architect, you have been assigned the task of setting up a Compute Engine application in a single Virtual Private Cloud (VPC) spanning across two regions for a global e-commerce company. The objective is to ensure high availability and seamless connectivity between instances in these two regions, while also keeping latency and cost to a minimum. Which approach would be the most effective to meet these requirements?

  1. A

    Create two separate VPCs, one for each region, and connect them using Cloud VPN.

  2. B

    Create a single VPC and deploy two regional subnets with custom dynamic routing.

  3. C

    Create a single VPC and deploy two unconnected regional subnets.

  4. D

    Use shared VPC to connect the two regions.

Xem giải thích

Đáp án

B — Một VPC duy nhất với hai subnet theo khu vực, dùng định tuyến động

Vì sao đúng

VPC của Google Cloud vốn đã toàn cầu, nên một VPC chứa subnet ở nhiều khu vực và chúng nói chuyện bằng IP riêng qua mạng xương sống của Google — không cần peering, không cần đường hầm. Định tuyến động (Cloud Router với BGP) khiến tuyến được học và cập nhật tự động khi mạng thay đổi, thay vì phải sửa tay.

Vì sao các phương án khác sai

  • A. Hai VPC riêng nối bằng Cloud VPN — tự dựng lại thứ đã có sẵn, kèm chi phí và trần băng thông của đường hầm.
  • **C. Một VPC với hai subnet không kết nối — mâu thuẫn với chính yêu cầu của đề là hai khu vực phải liên lạc được.
  • D. Dùng Shared VPC — cơ chế chia sẻ mạng giữa các dự án, không phải cơ chế nối các khu vực.
Câu 408

Your team manages a global e-commerce platform hosted on Google Cloud. You are preparing to deploy a new recommendation engine that uses Vertex AI and Cloud Run. The company emphasizes minimizing downtime, ensuring rapid rollback, and enabling continuous improvement through metrics and feedback loops. According to the Operational Excellence pillar of the Well-Architected Framework, which deployment approach aligns best with Google’s recommended practices?

  1. A

    Perform a full cutover deployment during low-traffic hours, monitor logs manually for failures, and roll back manually if needed.

  2. B

    Deploy the model directly to production through the Vertex AI console to minimize configuration complexity.

  3. C

    Use a blue/green deployment managed by Cloud Deploy, include automated rollbacks triggered by error-rate metrics in Cloud Monitoring, and maintain deployment configurations in Git.

  4. D

    Implement a rolling update on Cloud Run using manual image pushes and verify deployment health via ad hoc testing.

Xem giải thích

Đáp án

C — Blue/green do Cloud Deploy quản lý, kèm quay lui tự động

Vì sao đúng

Ba yếu tố khiến phương án này vượt hẳn: blue/green cho môi trường mới được kiểm thử đầy đủ trước khi nhận lưu lượng; Cloud Deploy biến việc phát hành thành quy trình có ghi vết, có phê duyệt và lặp lại được thay vì thao tác tay; và quay lui tự động nghĩa là khi số liệu xấu đi thì hệ thống tự lùi chứ không chờ người phát hiện.

Vì sao các phương án khác sai

  • A. Cắt chuyển toàn bộ vào giờ thấp điểm rồi theo dõi log bằng tay — vẫn là thay đổi một nhịp và việc phát hiện sự cố phụ thuộc người ngồi canh.
  • D. Rolling update với việc đẩy ảnh bằng tay — thao tác tay là chỗ sinh lỗi và không quay lui tự động được.
  • B. Triển khai thẳng lên sản xuất từ giao diện Vertex AI — không có lưới an toàn nào.
Câu 409

As a cloud architect for a rapidly growing e-commerce company, you are tasked with handling Payment Card Industry Data Security Standard (PCI DSS) compliance for the storage and processing of payment card data. The company uses Compute Engine for their application servers, Cloud SQL for their transaction databases, and Cloud Storage for long-term data retention. Which of the following strategies is the most suitable to address this requirement?

  1. A

    Implement a third-party key management system and utilize customer-supplied encryption keys for all storage systems.

  2. B

    Store all payment card data in Cloud Storage buckets configured with uniform bucket-level access.

  3. C

    Utilize Google Cloud's Data Loss Prevention (DLP) API to discover, classify, and de-identify sensitive data.

  4. D

    Restrict network access to all services using Firewall Rules and Cloud Armor.

Xem giải thích

Đáp án

C — Dùng Cloud DLP API để phát hiện, phân loại và bảo vệ dữ liệu thẻ

Vì sao đúng

Với PCI DSS, câu hỏi đầu tiên luôn là dữ liệu thẻ đang nằm ở đâu — và trong hệ thống lớn thì thường không ai biết hết. Cloud DLP quét và phát hiện số thẻ nằm rải trong log, bản sao lưu, bảng dữ liệu, rồi khử định danh bằng token hoá hoặc mã hoá giữ định dạng. Thay số thẻ bằng token còn thu hẹp phạm vi kiểm toán, vì hệ thống chỉ giữ token thì không còn thuộc môi trường dữ liệu chủ thẻ nữa.

Vì sao các phương án khác sai

  • B. Để dữ liệu thẻ trong bucket với quyền truy cập thống nhất — kiểm soát truy cập là cần nhưng chưa đủ; dữ liệu vẫn tồn tại ở dạng gốc.
  • D. Luật tường lửa và Cloud Armor — bảo vệ vành ngoài, không đụng tới bản thân dữ liệu.
  • A. Hệ quản lý khoá bên thứ ba với khoá do khách hàng cung cấp — làm được nhưng phức tạp hơn hẳn, và vẫn không trả lời câu hỏi dữ liệu thẻ đang nằm ở đâu.
Câu 410

You are a Google Professional Cloud Architect working with a large e-commerce company. The company wants to optimize its data processing workflows by implementing Google Cloud Dataflow. They aim to leverage the power of Dataflow to process large volumes of streaming and batch data efficiently and reliably. In the context of this complex scenario, which of the following statements about Google Cloud Dataflow is correct?

  1. A

    Cloud Dataflow is a managed service that supports only batch processing of data.

  2. B

    Dataflow pipelines are written using Apache Beam, an open-source unified programming model for batch and stream processing.

  3. C

    Dataflow is primarily designed for small-scale data processing and may not handle high-volume data efficiently.

  4. D

    Dataflow pipelines can only process data stored in Cloud Storage and Cloud Bigtable.

Xem giải thích

Đáp án

B — Pipeline của Dataflow viết bằng Apache Beam, một mô hình lập trình hợp nhất

Vì sao đúng

Đây là đặc điểm định danh của Dataflow: nó chạy pipeline viết theo Apache Beam, và Beam cho một mô hình lập trình dùng chung cho cả xử lý luồng lẫn xử lý theo lô. Nhờ vậy cùng một đoạn logic biến đổi chạy được ở hai chế độ, nên kết quả thời gian thực và kết quả tính lại trên dữ liệu cũ không thể lệch nhau.

Vì sao các phương án khác sai

  • A. Dataflow chỉ hỗ trợ xử lý theo lô — sai; nó xử lý luồng rất tốt, và đó là điểm mạnh chính.
  • C. Dataflow dựng cho quy mô nhỏ — sai ngược: nó tự co giãn tới hàng nghìn worker.
  • D. Dataflow chỉ đọc được dữ liệu từ Cloud Storage và Bigtable — sai; Beam có bộ kết nối cho Pub/Sub, BigQuery, Kafka, JDBC và nhiều nguồn khác.