Ngân hàng đề — Google Professional Cloud Architect
Tìm thấy 420 câu.
You are managing an autoscaling instance group as the backend for a global HTTP(S) load balancer. The backend instances are private and use only internal IPs. After deployment, instances are repeatedly terminated and restarted. Health check logs indicate a "connection timeout" error when trying to reach the backend. What should you do?
-
A
Update the load balancer configuration to use a TCP-based health check instead of HTTP-based health checks.
-
B
Ensure the backend service is configured with the correct instance group and appropriate health check settings, and allow traffic from health check IP ranges via a firewall rule.
-
C
Increase the timeout threshold of the health check to reduce the frequency of health check failures.
-
D
Create a custom hostname for each backend instance and use this hostname in the health check configuration.
Xem giải thích
Đáp án
B — Kiểm tra backend service đã trỏ đúng instance group và cấu hình đúng chưa
Vì sao đúng
Với load balancer HTTP(S) toàn cầu và backend chỉ có IP nội bộ, health check không đi từ Internet mà đến từ hai dải riêng của Google (130.211.0.0/22 và 35.191.0.0/16). Backend báo hỏng gần như luôn do một trong mấy chuyện cấu hình: chưa mở luật tường lửa cho hai dải đó, sai cổng, sai đường dẫn kiểm tra, hoặc backend service chưa gắn đúng instance group. Đây là chỗ phải xem trước tiên.
Vì sao các phương án khác sai
- A. Đổi sang health check kiểu TCP — che triệu chứng: cổng mở không có nghĩa ứng dụng đang phục vụ đúng, nên bạn sẽ dồn lưu lượng vào máy hỏng.
- C. Nới thời gian chờ để giảm tần suất kiểm tra — không sửa nguyên nhân, chỉ khiến phát hiện sự cố chậm hơn.
- D. Đặt hostname riêng cho từng máy — health check gọi theo IP của máy, không dùng hostname.
A global enterprise uses Google Cloud and wants to centralize security and compliance controls while allowing different business units to manage their own projects independently.
Requirements:
-
Enforce organization-wide security policies (for example, restrict external IP usage).
-
Delegate billing and IAM management to business units.
-
Minimize operational overhead and policy duplication.
Which Google Cloud resource hierarchy design best meets these requirements?
-
A
Use separate organizations for each business unit
-
B
Create a single project for all workloads and manage IAM at the project level
-
C
Use labels on projects to separate business units and manage access
-
D
Use folders under an organization to represent business units and apply policies at the folder level
Xem giải thích
Đáp án
D — Dùng thư mục dưới tổ chức để đại diện cho từng đơn vị kinh doanh
Vì sao đúng
Thư mục là tầng trung gian trong cây tài nguyên, và nó giải đúng cái mâu thuẫn của đề: chính sách đặt ở tổ chức thì kế thừa xuống mọi thứ — đó là phần kiểm soát tập trung; còn quyền quản trị cấp ở từng thư mục thì mỗi đơn vị tự lo dự án của mình mà không đụng tới đơn vị khác. Một cây, hai tầng trách nhiệm.
Vì sao các phương án khác sai
- A. Mỗi đơn vị một tổ chức riêng — mất hẳn khả năng áp chính sách chung, vì không còn gốc chung.
- B. Gộp tất cả vào một dự án — không có ranh giới nào giữa các đơn vị.
- C. Dùng nhãn để phân biệt — nhãn dùng để phân loại và tính chi phí, chính sách IAM và Organization Policy không áp theo nhãn được.
Your company operates a global e-commerce platform that experiences seasonal spikes in traffic, particularly during holidays and sales events. The business requires a highly available and scalable infrastructure to handle traffic surges without any degradation in user experience. Additionally, the platform needs to support real-time data processing for personalized recommendations and analytics. The company plans to expand into new geographic regions over the next 12 months.
As the lead architect, you must design a cloud solution architecture that meets the following business requirements:
-
High Availability: Ensure 99.99% uptime for the platform.
-
Scalability: Automatically scale resources to handle sudden traffic spikes.
-
Low Latency: Deliver content with minimal latency to users worldwide.
-
Data Processing: Implement real-time data processing for recommendations and analytics.
-
Cost Optimization: Keep costs within a predetermined budget while ensuring performance.
Which combination of architectural decisions best meets the business requirements for your e-commerce platform? (Select two)
-
A
Implement a single-region deployment with autoscaling enabled.
-
B
Use pre-provisioned virtual machines to handle expected peak loads.
-
C
Use a multi-region deployment with load balancing across regions.
-
D
Host the database on a single VM to minimize costs.
-
E
Deploy a Content Delivery Network (CDN) to cache static content closer to users.
Xem giải thích
Đáp án
C và E — triển khai nhiều khu vực có cân bằng tải, và dùng CDN cho nội dung tĩnh
Vì sao đúng
- C. Nhiều khu vực có cân bằng tải — vừa chịu được đợt cao điểm bằng cách trải tải, vừa giữ dịch vụ sống khi mất một khu vực. Đây là nền của cả tính sẵn sàng lẫn khả năng co giãn.
- E. CDN cho nội dung tĩnh — ảnh sản phẩm, CSS và JavaScript được phục vụ từ biên mạng gần người dùng, nên vừa nhanh hơn vừa gỡ phần lớn tải khỏi máy chủ gốc — đúng lúc cần nhất là mùa cao điểm.
Vì sao các phương án khác sai
- A. Một khu vực duy nhất có tự co giãn — co giãn được nhưng vẫn chết cả hệ thống khi khu vực đó hỏng.
- B. Dựng sẵn máy ảo cho mức đỉnh — trả tiền cho mức đỉnh suốt cả năm, và vẫn hụt nếu đỉnh vượt dự đoán.
- D. CSDL trên một máy ảo cho rẻ — biến tầng dữ liệu thành điểm hỏng duy nhất, ngay giữa mùa bán hàng.
A data science team at a retail company wants to experiment with multiple pre-trained models for demand forecasting and product recommendations. They plan to fine-tune Gemini and other foundation models, compare their performance, and then deploy the best-performing model as a REST endpoint for downstream applications. Which approach should the Cloud Architect recommend?
-
A
Export pre-trained models from Model Garden and host them manually on Compute Engine for benchmarking.
-
B
Use BigQuery ML to train Gemini models directly on retail transaction data.
-
C
Use Vertex AI Model Garden to explore and fine-tune models, and deploy the best one using Vertex AI Endpoints.
-
D
Store models in Cloud Storage and expose them through a custom Flask API on Cloud Run.
Xem giải thích
Đáp án
C — Dùng Vertex AI Model Garden để thử và tinh chỉnh mô hình, rồi triển khai bản tốt nhất
Vì sao đúng
Model Garden là nơi tập hợp mô hình dựng sẵn của Google, của bên thứ ba và mã nguồn mở trong cùng một chỗ, kèm sẵn quy trình tinh chỉnh và triển khai lên điểm cuối được quản lý. Đúng thứ một đội khoa học dữ liệu cần khi giai đoạn hiện tại là thử nhiều mô hình rồi chọn: đổi mô hình chỉ là đổi cấu hình, không phải dựng lại hạ tầng.
Vì sao các phương án khác sai
- A. Tự tải mô hình về chạy trên máy ảo — phải tự lo GPU, phiên bản thư viện và việc phục vụ mô hình; chậm nhất cho giai đoạn thử nghiệm.
- B. Huấn luyện Gemini bằng BigQuery ML — BigQuery ML dựng cho các mô hình chạy trong SQL, và không phải nơi tinh chỉnh mô hình ngôn ngữ lớn.
- D. Để mô hình trong Cloud Storage rồi tự viết API Flask — tự dựng lại toàn bộ tầng phục vụ mô hình, kèm mọi việc vận hành đi theo.
For this question, refer to the Altostrat Media case study.
https://services.google.com/fh/files/misc/v6.1_pca_altostrat_media_case_study_english.pdf
Altostrat wants to standardize how its content-processing microservices run across environments. Today, latency-sensitive ingestion and compliance workflows still run on an on-premises Kubernetes cluster, while customer-facing services run on GKE. The platform team wants consistent Kubernetes operations, centralized policy enforcement, and simplified lifecycle management across on-premises and Google Cloud, without maintaining divergent tooling stacks. Which architecture best meets Altostrat’s requirement to provide scalable, performant Kubernetes environments both on-premises and in Google Cloud, while minimizing operational complexity?
-
A
Replace on-premises Kubernetes with Cloud Run and expose services to on-premises systems over VPN.
-
B
Migrate all on-premises workloads to Compute Engine–based self-managed Kubernetes clusters and decommission GKE.
-
C
Keep on-premises Kubernetes separate and use custom CI/CD pipelines to synchronize manifests between environments.
-
D
Deploy Anthos to manage both the on-premises Kubernetes clusters and GKE, using Anthos Config Management and a shared service mesh.
Xem giải thích
Đáp án
D — Triển khai Anthos để quản lý cả cụm Kubernetes tại chỗ lẫn GKE
Vì sao đúng
Bài toán là quản lý một cách thống nhất trên hai môi trường. Anthos cho đúng điều đó: một mặt phẳng điều khiển duy nhất, cấu hình được áp đồng nhất bằng chính sách, và giám sát gom về một chỗ. Cụm tại chỗ được giữ nguyên tại chỗ — không phải di chuyển gì trước — mà vẫn nằm chung một cách quản trị với GKE.
Vì sao các phương án khác sai
- A. Thay Kubernetes tại chỗ bằng Cloud Run — buộc phải di chuyển ngay, đúng thứ đề muốn tránh.
- B. Chuyển mọi thứ sang Kubernetes tự quản trên máy ảo — tự vác lấy việc vận hành mặt phẳng điều khiển, đi lùi so với dịch vụ được quản lý.
- C. Để hai bên tách rời rồi tự viết CI/CD đồng bộ — tự dựng lại thứ Anthos làm sẵn, và cấu hình hai bên sẽ trôi khỏi nhau theo thời gian.
An e-commerce company is building a new platform on Google Cloud Platform (GCP) that will handle order processing, inventory management, and customer notifications. The architecture must be event-driven to allow for decoupling of services, real-time processing, and scalability. The platform needs to handle high volumes of transactions during peak shopping times, such as Black Friday, and ensure that events are processed in the correct order. Additionally, the platform should be resilient to failure and capable of retrying failed events without duplication. Which architecture best supports the application’s design requirements?
-
A
Implement the architecture using Dataproc for processing events, Bigtable for storing event data, and Cloud Storage for archiving historical events.
-
B
Implement event-driven microservices using Cloud Functions, with Cloud Pub/Sub for messaging, and Cloud Storage for event persistence.
-
C
Use Cloud Run for running event-driven microservices, Cloud Pub/Sub for asynchronous messaging, and BigQuery for storing event logs and processing history.
-
D
Use Google Kubernetes Engine (GKE) to deploy event-driven microservices, Cloud Pub/Sub for event distribution, and Cloud Spanner for transactional data consistency.
Xem giải thích
Đáp án
D — Dùng GKE cho các microservice hướng sự kiện, kèm Cloud Pub/Sub
Vì sao đúng
Nền tảng thương mại điện tử với xử lý đơn hàng, quản lý tồn kho và thông báo khách hàng có đặc điểm: nhiều dịch vụ phụ thuộc nhau, một số phải chạy nền liên tục, và tất cả cần điều phối chặt. GKE cho khả năng điều phối đó cùng với co giãn từng dịch vụ độc lập, còn Pub/Sub tách rời các dịch vụ để một thành phần chậm không kéo sập cả chuỗi.
Vì sao các phương án khác sai
- B. Cloud Functions — hợp cho việc ngắn theo sự kiện; làm xương sống cho cả nền tảng thì vướng giới hạn thời gian chạy và khó điều phối luồng nhiều bước.
- C. Cloud Run — mạnh cho dịch vụ không trạng thái theo yêu cầu, nhưng hạn chế với tiến trình chạy nền lâu.
- A. Dataproc để xử lý sự kiện — Dataproc là cụm Hadoop/Spark cho xử lý theo lô, sai hẳn loại bài toán.
Your organization is deploying a data-intensive application on GCP. The application requires 50 TB of storage for data that will be infrequently accessed - once per quarter. The data must be available for immediate access when needed, but cost optimization is a key requirement. Which storage class should you use?
-
A
Standard Storage Class for Cloud Storage.
-
B
Coldline Storage Class for Cloud Storage
-
C
Nearline Storage Class for Cloud Storage.
-
D
Archive Storage Class for Cloud Storage
Xem giải thích
Đáp án
B — Lớp lưu trữ Coldline
Vì sao đúng
Google Cloud Storage phân tầng theo tần suất truy cập dự kiến, và mỗi tầng có thời gian lưu tối thiểu:
- Standard — truy cập thường xuyên
- Nearline — khoảng một lần mỗi tháng, tối thiểu 30 ngày
- Coldline — khoảng một lần mỗi quý, tối thiểu 90 ngày
- Archive — ít hơn một lần mỗi năm, tối thiểu 365 ngày
Đề nói rõ một lần mỗi quý, khớp đúng định nghĩa của Coldline.
Vì sao các phương án khác sai
- A. Standard — trả giá lưu trữ cao nhất cho dữ liệu gần như không đụng tới.
- C. Nearline — dành cho nhịp hàng tháng; dùng cho nhịp hàng quý thì trả thừa tiền lưu trữ.
- D. Archive — rẻ nhất khi lưu nhưng phí đọc cao và ràng buộc 365 ngày; đọc mỗi quý sẽ dính phí xoá sớm và phí truy xuất.
As a cloud architect, you are responsible for implementing a new application using a microservices architecture. You would like to run each microservice in containers. In addition, you want to minimize DevOps overhead and benefit from autoscaling. What should you recommend?
-
A
You should run the containers in Managed Instance Group.
-
B
You should run the containers in Unmanaged Instance Group.
-
C
You should use App Engine for this.
-
D
You should run the containers in Kubernetes Engine.
Xem giải thích
Đáp án
D — Chạy container trên Kubernetes Engine
Vì sao đúng
Kiến trúc microservice chạy bằng container cần điều phối: đặt container lên node nào, khởi động lại khi chết, co giãn từng dịch vụ, khám phá dịch vụ và cân bằng tải nội bộ, triển khai cuốn chiếu. GKE là nền tảng làm sẵn tất cả những việc đó.
Vì sao các phương án khác sai
- A. Managed Instance Group — quản lý máy ảo, không phải container; chạy được container nhưng bạn tự lo mọi việc điều phối.
- B. Unmanaged Instance Group — còn thiếu cả tự chữa lành và tự co giãn.
- C. App Engine — chạy được ứng dụng nhưng ràng buộc hơn và không cho kiểm soát mức container như đề đang muốn.
You are a cloud architect designing a new application for a global financial services company. The application will handle real-time transaction processing across multiple regions and should be resilient to regional outages. Your solution should also minimize latency. Which of the following is the most appropriate design for this use case?
-
A
Use Google Cloud Datastore as your primary database with multi-region distribution and Cloud CDN for cache optimization.
-
B
Use Google Cloud Bigtable as your primary database with regional replication and Cloud Load Balancing for distributing traffic.
-
C
Use Google Cloud Spanner as your primary database with multi-region configuration and Cloud Load Balancing to distribute the traffic.
-
D
Use Google Cloud SQL with multi-region replication and Cloud CDN for cache optimization.
Xem giải thích
Đáp án
C — Dùng Cloud Spanner ở cấu hình đa vùng
Vì sao đúng
Đề nêu ba điều kiện cùng lúc: giao dịch tài chính thời gian thực, nhiều khu vực, và ngầm định là dữ liệu phải luôn đúng. Cloud Spanner là CSDL duy nhất trong danh sách vừa phân tán toàn cầu vừa giữ giao dịch ACID và nhất quán mạnh — số dư đọc ở châu Âu và ở châu Á luôn khớp nhau. Với tiền bạc thì đó không phải tính năng cho có.
Vì sao các phương án khác sai
- A. Datastore/Firestore — nhất quán cuối cùng ở phạm vi truy vấn rộng, không đủ cho giao dịch tài chính.
- B. Bigtable — thông lượng rất cao nhưng không có giao dịch nhiều hàng, và nhân bản chỉ đạt nhất quán cuối cùng.
- D. Cloud SQL nhân bản đa vùng — bản sao ở khu vực khác là bản đọc chạy sau bản chính, nên đọc ra dữ liệu cũ; và ghi vẫn dồn về một nơi.
Your company has multiple GKE clusters running in different regions. You are tasked with setting up a centralized monitoring solution to have a single view of the health and performance of all the clusters. Which approach would you take?
-
A
Deploy a Prometheus server in each GKE cluster and configure them to push metrics to a central Grafana dashboard.
-
B
Use Google Cloud's Operations suite and set up a Workspace for each GKE cluster, then create a combined dashboard.
-
C
Use Anthos to centrally manage and monitor all GKE clusters.
-
D
Configure each GKE cluster to export logs and metrics to a central BigQuery dataset and create custom SQL queries to monitor the health.
Xem giải thích
Đáp án
C — Dùng Anthos để quản lý và giám sát tập trung mọi cụm GKE
Vì sao đúng
Với nhiều cụm GKE nằm ở các khu vực khác nhau, Anthos cho một mặt phẳng điều khiển duy nhất: trạng thái mọi cụm hiện trong cùng một bảng, chính sách được áp đồng nhất, và cấu hình không trôi khỏi nhau. Đó đúng là "một góc nhìn duy nhất" mà đề yêu cầu, và không phải tự dựng gì.
Vì sao các phương án khác sai
- A. Dựng Prometheus trong từng cụm — tự vận hành và tự ghép dữ liệu lại, tốn nhất.
- B. Mỗi cụm một Workspace riêng — làm ngược mục tiêu: vẫn phải mở nhiều nơi để xem, đúng thứ đề muốn bỏ.
- D. Đẩy log và số liệu về một dataset BigQuery — phân tích về sau thì được, nhưng không phải bảng giám sát thời gian thực và không có cảnh báo sẵn.