Ngân hàng đề — Google Professional Cloud Architect
Tìm thấy 420 câu.
For this question, refer to the Altostrat Media case study.
https://services.google.com/fh/files/misc/v6.1_pca_altostrat_media_case_study_english.pdf
Altostrat plans to extend its natural language support to include personalized explanations for pricing changes and content availability. Responses must consider user identity, historical usage patterns in BigQuery, and current subscription context, while complying with enterprise security and identity standards already in place. Which solution best supports secure, context-aware natural language interactions at scale?
-
A
Use Vertex AI Agent Builder integrated with Identity-Aware Proxy (IAP), enrich prompts with BigQuery data, and deploy the service behind Cloud Run.
-
B
Store user interaction context in Cloud Storage JSON files and load them into the model prompt on each request.
-
C
Deploy a publicly accessible generative AI endpoint on GKE and pass user identifiers directly in request headers.
-
D
Use a third-party SaaS chatbot platform and synchronize user data nightly from BigQuery via batch exports.
Xem giải thích
Đáp án
A — Vertex AI Agent Builder tích hợp với Identity-Aware Proxy
Vì sao đúng
Trợ lý AI có ngữ cảnh người dùng thì phải trả lời đúng theo quyền của chính người đang hỏi. Ghép Agent Builder với IAP cho đúng điều đó: IAP xác thực người dùng trước khi yêu cầu tới được tác nhân, nên danh tính là thật và có thể dùng để giới hạn dữ liệu được lấy ra. Không có bước nào để lộ thông tin của người này cho người khác.
Vì sao các phương án khác sai
- C. Điểm cuối AI công khai trên GKE, danh tính truyền theo yêu cầu — danh tính do máy khách tự khai thì giả mạo được; đây là lỗ hổng nghiêm trọng.
- B. Lưu ngữ cảnh trong tệp JSON trên Cloud Storage — không có mô hình phân quyền theo người dùng và không cập nhật kịp thời.
- D. Dùng chatbot SaaS bên thứ ba, đồng bộ dữ liệu hằng đêm — dữ liệu luôn cũ và bạn đưa thông tin người dùng ra ngoài phạm vi kiểm soát.
You are tasked with deploying a global e-commerce application on Google Cloud. To ensure optimal latency and high availability, you decided to use the Global HTTP(S) Load Balancer. The application needs to route incoming requests to the nearest healthy backend that has sufficient capacity to handle the load. How should you configure the load balancer?
-
A
Configure Global HTTP(S) Load Balancer with backend services in a single region and enable Cloud CDN.
-
B
Configure Global HTTP(S) Load Balancer with a single instance group and enable Cross-Region load balancing.
-
C
Configure Global HTTP(S) Load Balancer with backend services in multiple regions and use a balancing mode based on the capacity of the backends.
-
D
Configure Global HTTP(S) Load Balancer with instance groups in different regions and enable session affinity.
Xem giải thích
Đáp án
C — Backend service ở nhiều khu vực, dùng balancing mode dựa trên năng lực của backend
Vì sao đúng
Load balancer toàn cầu tự đưa người dùng tới khu vực gần nhất, nhưng chỉ khi có backend ở nhiều khu vực để mà chọn. Phần thứ hai cũng quan trọng: balancing mode theo năng lực khiến load balancer biết khi nào một khu vực đã đầy và tự tràn lưu lượng sang khu vực kế tiếp, thay vì tiếp tục dồn vào chỗ đang quá tải.
Vì sao các phương án khác sai
- A. Backend chỉ ở một khu vực — dù load balancer là toàn cầu, người dùng ở xa vẫn phải đi tới đúng khu vực đó; và mất khu vực là mất tất cả.
- B. Một instance group duy nhất — cùng vấn đề, và "cross-region load balancing" không phải cơ chế bù được việc thiếu backend ở nơi khác.
- D. Instance group ở nhiều khu vực nhưng bật session affinity — affinity ghim người dùng vào một backend cố định, đi ngược lại mục tiêu luôn định tuyến tới backend khoẻ gần nhất.
Your objective is to decrease the frequency of unscheduled rollbacks for flawed production deployments within your company's web hosting platform. By enhancing QA/Test processes, you were able to achieve a substantial 80% reduction in rollbacks. Now, what are two additional approaches you can adopt to further minimize the occurrence of rollbacks? (Choose two)
-
A
Replace the QA environment with canary releases.
-
B
Reduce the platform's dependency on relational database systems.
-
C
Implement a green-blue deployment strategy.
-
D
Replace the platform's relational database systems with a NoSQL database.
-
E
Decompose the monolithic platform into microservices.
Xem giải thích
Đáp án
C và E — áp dụng chiến lược triển khai xanh–lam, và tách nền tảng nguyên khối thành microservice
Vì sao đúng
Mục tiêu là giảm số lần phải quay lui khẩn cấp, và hai phương án này tấn công hai nguyên nhân khác nhau:
- C. Xanh–lam — bản mới được dựng và kiểm thử trọn vẹn trước khi nhận lưu lượng, và nếu hỏng thì chuyển ngược lại là xong. Việc quay lui không còn là sự kiện khẩn cấp nữa.
- E. Tách thành microservice — thu hẹp phạm vi của mỗi lần phát hành: một dịch vụ hỏng chỉ ảnh hưởng phần của nó, thay vì buộc quay lui toàn bộ nền tảng.
Vì sao các phương án khác sai
- A. Thay môi trường QA bằng canary — bỏ khâu kiểm chứng trước để kiểm thử trên người dùng thật; đi ngược mục tiêu.
- B và D. Bớt phụ thuộc CSDL quan hệ hoặc đổi sang NoSQL — lựa chọn CSDL không liên quan tới tần suất phải quay lui bản phát hành.
A multinational corporation has a large number of remote employees working in different countries. They need to provide secure access to company resources, such as Google Workspace and GCP resources, to these employees. The solution should also meet the following requirements:
-
provide a secure and scalable solution that can handle a large number of remote users
-
enforce strong authentication and authorization policies
-
automatically provide employees with the appropriate level of access to company resources based on their job function
-
provide centralized management and auditing of user access
-
be cost-effective
Which solution would you recommend to meet these requirements and why?
-
A
Implementing Google Workspace Groups and Google Cloud IAM roles
-
B
Implementing Google Workspace Domain-Wide Delegation of Authority and Google Cloud Identity-Aware Proxy (IAP)
-
C
Implementing Google Workspace Domain-Wide Delegation of Authority and Google Cloud VPN
-
D
Implementing Google Workspace Single Sign-On (SSO) and Google Cloud IAM roles
Xem giải thích
Đáp án
B — Domain-Wide Delegation của Google Workspace kết hợp Identity-Aware Proxy
Vì sao đúng
Nhân viên làm việc từ xa ở nhiều nước thì mô hình đúng là kiểm soát theo danh tính, không theo vị trí mạng. IAP kiểm tra từng yêu cầu bằng danh tính công ty cộng chính sách theo ngữ cảnh, nên nhân viên truy cập được từ bất cứ đâu mà không cần dựng VPN cho từng người — và người ngoài không tới được ứng dụng dù biết địa chỉ.
Vì sao các phương án khác sai
- C. Cùng Domain-Wide Delegation nhưng dùng Cloud VPN — VPN quay về mô hình "vào được mạng là tin", và không mở rộng nổi với hàng loạt nhân viên ở nhiều quốc gia.
- A và D. Nhóm Workspace, SSO cộng vai IAM — cần thiết cho phần quản lý danh tính, nhưng không tạo ra lớp kiểm soát đứng trước ứng dụng như IAP.
Your company is developing an application that requires a high volume of read and write operations on the database. The application will be hosted on Google Compute Engine instances. However, the database is expected to grow significantly over time, and the management wants to ensure that the disk performance remains high. As a cloud architect, what type of persistent disk would you recommend for optimal performance?
-
A
Use Cloud Storage instead of a persistent disk for high performance.
-
B
SSD persistent disk, because it provides high IOPS and throughput.
-
C
Local SSD, because it provides high IOPS and low latency.
-
D
Standard persistent disk, because it provides cost-effective storage.
Xem giải thích
Đáp án
B — Đĩa bền SSD, vì cho IOPS và thông lượng cao
Vì sao đúng
Đề có hai điều kiện: đọc ghi nhiều, và ngầm định là dữ liệu của CSDL phải còn sau khi khởi động lại. Đĩa bền SSD đạt cả hai — IOPS cao nhất trong các loại đĩa bền, và dữ liệu tồn tại độc lập với vòng đời máy ảo.
Vì sao các phương án khác sai
- C. Local SSD — nhanh hơn nữa, nhưng mất sạch dữ liệu khi máy dừng. Với CSDL thì đó là điều kiện loại trừ, không phải đánh đổi.
- D. Đĩa standard — rẻ nhưng IOPS thấp, sai hẳn yêu cầu về tải đọc ghi nặng.
- A. Dùng Cloud Storage thay đĩa — kho đối tượng không phải nơi CSDL đặt tệp dữ liệu; độ trễ cao hơn hệ tệp rất nhiều.
You are a cloud architect at a multinational company and have been asked to set up an HTTP(S) load balancer to route traffic to backends in multiple regions. However, the company wants to ensure that user requests are always routed to the closest healthy backend to minimize latency. Additionally, there should be a fallback mechanism if the closest backend is unhealthy. Which of the following strategies would you implement to fulfill these requirements?
-
A
Configure HTTP(S) Load Balancer with multiple backend services in each region and implement Global Load Balancing.
-
B
Configure HTTP(S) Load Balancer with a single global backend service and use Global Load Balancing.
-
C
Configure HTTP(S) Load Balancer with a single backend service and health checks.
-
D
Configure HTTP(S) Load Balancer with multiple backend services in each region and utilize Cross-Region Load Balancing.
Xem giải thích
Đáp án
A — HTTP(S) Load Balancer với backend ở mỗi khu vực, bật Global Load Balancing
Vì sao đúng
Yêu cầu là yêu cầu của người dùng luôn đi tới backend khoẻ gần nhất, và điều đó cần hai thứ cùng lúc: có backend hiện diện ở nhiều khu vực để mà chọn, và cân bằng tải toàn cầu để việc chọn diễn ra ở biên mạng ngay khi kết nối bắt đầu. Health check lo phần "khoẻ", còn định tuyến theo vị trí lo phần "gần nhất".
Vì sao các phương án khác sai
- C. Một backend service với health check — có phần kiểm tra sức khoẻ nhưng thiếu hẳn phần định tuyến theo vị trí.
- D. Backend ở nhiều khu vực nhưng dùng "Cross-Region Load Balancing" — cách gọi này không phải cơ chế thay thế cho cân bằng tải toàn cầu của Google.
Một điểm cần nói thẳng
Phương án B — "một backend service toàn cầu duy nhất cộng Global Load Balancing" — thực ra mô tả sát hơn cách một global HTTP(S) load balancer được cấu hình trong thực tế: thường chỉ có một backend service, và chính nó chứa các backend nằm ở nhiều khu vực. Khoá đáp án của nguồn chọn A; điều đáng nhớ ở đây là thành phần bắt buộc vẫn là cân bằng tải toàn cầu cộng backend ở nhiều khu vực, chứ không phải số lượng backend service.
A company is looking to process real-time data from multiple sources in order to provide real-time analytics to their clients. The company is expecting to process a large volume of data with an estimated peak of up to 1 million requests per second. The solution must be able to scale elastically to handle varying levels of incoming data, ensure low latency processing, and support the processing of data in real-time. Which of the following options would be the most effective approach to meet these requirements?
-
A
Use Cloud Pub/Sub to ingest the data and feed it into Cloud Dataflow for real-time processing.
-
B
Use Cloud Dataflow to ingest the data and feed it into Cloud Bigtable for real-time processing.
-
C
Use Cloud Dataflow with Apache Beam to process the data in batch mode and store the results in Cloud Bigtable.
-
D
Use Cloud Dataproc with Apache Spark Streaming to process the data in real-time.
Xem giải thích
Đáp án
A — Pub/Sub nhận dữ liệu, đưa vào Dataflow xử lý thời gian thực
Vì sao đúng
Ba yêu cầu — nhiều nguồn, khối lượng lớn, phân tích thời gian thực — khớp đúng bộ đôi này. Pub/Sub là điểm nhận duy nhất cho mọi nguồn, hấp thụ được tải bùng phát và không mất tin. Dataflow xử lý luồng với cửa sổ thời gian và xử lý được dữ liệu tới muộn — chuyện luôn xảy ra khi thu thập từ nhiều nơi. Cả hai đều không máy chủ.
Vì sao các phương án khác sai
- B. Dùng Dataflow để nhận dữ liệu — Dataflow là công cụ xử lý; thiếu lớp đệm thì tải tăng đột ngột là mất dữ liệu.
- **C. Dataflow ở chế độ theo lô — mâu thuẫn thẳng với yêu cầu thời gian thực.
- D. Dataproc với Spark Streaming — làm được nhưng phải vận hành cụm, và co giãn kém hơn hẳn so với dịch vụ không máy chủ.
You have configured a regional managed instance group as a backend for your global HTTP(S) load balancer to host your company's application. The instance template used does not assign public IP addresses to the VM instances. After deployment, you notice that the load balancer backend status is marked as unhealthy, and no traffic is reaching the application. You confirm that the application is running properly on the instances using a local command line. What should you do?
-
A
Add a firewall rule to allow traffic from the load balancer's health check IP ranges to the instance group.
-
B
Configure the backend service health check to use TCP instead of HTTP.
-
C
Add a firewall rule to allow traffic from
0.0.0.0/0on ports 80 and 443 to the instance group. -
D
Ensure that the instance group has public IPs assigned to each instance.
Xem giải thích
Đáp án
A — Thêm luật tường lửa cho phép lưu lượng từ dải IP health check của load balancer
Vì sao đúng
Đề nói rõ instance template không gán IP công khai, tức là máy chỉ có IP nội bộ. Health check của load balancer không đến từ Internet mà từ hai dải riêng của Google: 130.211.0.0/22 và 35.191.0.0/16. VPC mặc định chặn mọi lưu lượng đi vào, nên phải khai luật cho hai dải đó thì gói tin kiểm tra mới tới được máy.
Vì sao các phương án khác sai
- D. Gán IP công khai cho từng máy — không cần thiết và phơi máy ra Internet; health check vẫn đến từ dải nội bộ của Google.
- C. Mở luật cho
0.0.0.0/0trên cổng 80 và 443 — cho lưu lượng từ mọi nơi trên Internet, quá rộng so với mức cần. - B. Đổi health check sang TCP — che triệu chứng: cổng mở không có nghĩa ứng dụng phục vụ được, và gói tin vẫn bị tường lửa chặn.
Your team is developing a high-performance computing application that specifically needs to run on a Debian Linux environment. The application is compute-intensive and processes a large amount of data. Given the need for compute resources to be scaled up and down in response to the changing volume of data, as a cloud architect, what deployment strategy would you suggest on Google Cloud?
-
A
Deploy the application on App Engine standard environment.
-
B
Use Cloud Functions with a custom runtime to mimic the Debian Linux environment.
-
C
Use Compute Engine with Debian Linux images and configure them in a Managed Instance Group.
-
D
Deploy the application on Google Kubernetes Engine with Debian containers.
Xem giải thích
Đáp án
C — Compute Engine với ảnh Debian Linux, đặt trong managed instance group
Vì sao đúng
Đề có một ràng buộc cứng: ứng dụng phải chạy trên môi trường Debian Linux cụ thể. Compute Engine là lựa chọn duy nhất cho bạn toàn quyền về hệ điều hành và các thư viện hệ thống bên dưới. Đặt trong managed instance group thì vẫn có tự co giãn và tự chữa lành cho phần tính toán nặng.
Vì sao các phương án khác sai
- A. App Engine Standard — chạy ứng dụng trong môi trường có sẵn và ràng buộc, bạn không kiểm soát hệ điều hành.
- B. Cloud Functions với runtime tuỳ chỉnh để "mô phỏng" Debian — không phải cách Cloud Functions hoạt động, và vướng giới hạn thời gian chạy với tải nặng.
- D. GKE với container Debian — gần đúng, nhưng container dùng chung nhân của node; nếu ứng dụng phụ thuộc vào chính môi trường hệ điều hành thì đây không phải bảo đảm chắc chắn.
As a cloud architect, your client has informed you that their recently updated App Engine application is experiencing prolonged loading times of around 30 seconds for certain users. This issue was not present prior to the update. What approach should you adopt to address this problem effectively?
-
A
You should open a support ticket to ask for network capture and flow data to diagnose the problem, then roll back your application.
-
B
You should roll back to an earlier known good release initially, then use Cloud Trace and Logging to diagnose the problem in a development/test/staging environment.
-
C
You should roll back to an earlier known good release, then push the release again at a quieter period to investigate. Then use Cloud Trace and Logging to diagnose the problem.
-
D
You should work with your Internet Service Provider (ISP) to diagnose the problem.
Xem giải thích
Đáp án
B — Quay về bản phát hành tốt đã biết trước, rồi mới dùng Cloud Trace để tìm nguyên nhân
Vì sao đúng
Đây là thứ tự xử lý sự cố đúng: khôi phục dịch vụ trước, điều tra sau. Người dùng đang chịu độ trễ 30 giây, nên việc đầu tiên là đưa họ về trạng thái dùng được. Quay lui trên App Engine chỉ là chuyển lưu lượng về phiên bản cũ, gần như tức thì. Sau khi hết áp lực mới dùng Cloud Trace để bóc tách xem chặng nào trong yêu cầu gây chậm.
Vì sao các phương án khác sai
- C. Quay lui rồi đẩy lại bản đó lần nữa — đẩy lại đúng bản đang hỏng thì sự cố tái diễn.
- A. Mở phiếu hỗ trợ xin dữ liệu bắt gói tin — quá chậm, và bạn có sẵn công cụ chẩn đoán trong tay.
- D. Làm việc với nhà cung cấp Internet — triệu chứng xuất hiện sau khi cập nhật ứng dụng, nên nguyên nhân gần như chắc chắn nằm ở bản phát hành chứ không ở đường truyền.