Ngân hàng đề — Google Professional Cloud Architect
Tìm thấy 420 câu.
Your client wants to offload their existing on-premises archive of 80 TB of customer support call transcripts to the cloud. These files will rarely be accessed, but should be searchable using SQL for quarterly business reviews. What two solutions best meet these requirements with minimal operational overhead and cost? (Choose two)
-
A
Use BigQuery external tables to query data stored in Cloud Storage.
-
B
Upload files to Cloud Storage in Archive or Coldline class.
-
C
Upload files into Persistent Disks attached to Compute Engine instances.
-
D
Load data into BigQuery using federated data sources.
-
E
Use Cloud Dataflow to transform the data and stream it into Pub/Sub.
Xem giải thích
Đáp án
A và B — đưa tệp lên Cloud Storage lớp Archive hoặc Coldline, và dùng bảng ngoài của BigQuery để truy vấn
Vì sao đúng
Hai mảnh khớp đúng hai yêu cầu:
- B. Cloud Storage lớp lạnh — 80 TB hiếm khi đọc thì đây là nơi rẻ nhất, và dữ liệu vẫn truy cập ngay được chứ không phải chờ khôi phục như băng từ.
- A. Bảng ngoài của BigQuery — cho chạy SQL thẳng trên tệp đang nằm ở Cloud Storage, không phải nạp bản sao thứ hai vào BigQuery. Nhờ vậy tìm kiếm được khi cần mà không trả tiền lưu trữ hai lần.
Vì sao các phương án khác sai
- C. Đĩa bền gắn vào máy ảo — đắt hơn Cloud Storage nhiều lần cho lưu trữ nguội, và phải giữ máy ảo.
- D. Nạp hẳn vào BigQuery — trả tiền lưu trữ BigQuery cho dữ liệu hiếm khi đụng tới.
- E. Dataflow đẩy sang Pub/Sub — Pub/Sub là kênh truyền thông điệp, không phải nơi lưu trữ.
You have completed the deployment of a brand new regional Kubernetes Engine cluster, where the default pool in the first zone consists of four machines. Additionally, you have maintained the default number of zones during the deployment. How many Compute Engine instances have been deployed and are being billed to your account?
-
A
8
-
B
12
-
C
16
-
D
4
Xem giải thích
Đáp án
B — 12 máy
Vì sao đúng
Điểm mấu chốt nằm ở chữ regional (cụm theo khu vực). Với cụm loại này, mỗi node pool được nhân bản sang cả ba zone của khu vực, chứ không nằm ở một zone. Con số bạn khai là số máy mỗi zone, nên tổng số máy thực tế là:
4 máy mỗi zone × 3 zone = 12 máy
Đây là chỗ rất hay gây bất ngờ khi nhìn hoá đơn: khai 4 mà trả tiền 12.
Vì sao các phương án khác sai
- D. 4 — là con số bạn khai, đúng cho cụm zonal, không đúng cho cụm regional.
- A. 8 — ứng với hai zone, nhưng cụm regional dùng ba.
- C. 16 — ứng với bốn zone.
As a cloud architect responsible for preparing a migration strategy, you are confronted with a scenario where a company possesses sensitive data that must be encrypted using keys under their control. The objective is to store the data in GCP while minimizing costs and operational overhead. What recommendations would you propose in this scenario?
-
A
You should use a custom encryption algorithm for the data.
-
B
You should use Google default encryption for the data.
-
C
You should use Cloud KMS for sensitive data.
-
D
You cannot use your own keys with GCP.
Xem giải thích
Đáp án
C — Dùng Cloud KMS cho dữ liệu nhạy cảm
Vì sao đúng
Đề yêu cầu mã hoá bằng khoá do bạn quản lý. Cloud KMS cho tạo, xoay vòng, phân quyền và huỷ khoá theo ý bạn, đồng thời ghi lại mọi lần khoá được dùng vào nhật ký kiểm toán. Các dịch vụ khác của Google Cloud nhận trực tiếp khoá KMS làm khoá mã hoá do khách hàng quản lý, nên không phải tự ghép gì.
Vì sao các phương án khác sai
- A. Tự viết thuật toán mã hoá — tự cài mật mã học là cách hỏng kinh điển; luôn dùng thư viện và dịch vụ đã được kiểm chứng.
- B. Dùng mã hoá mặc định của Google — vẫn mã hoá, nhưng khoá do Google quản lý, không thoả yêu cầu "khoá của bạn".
- D. Không dùng khoá riêng được trên GCP — sai; đó chính là công dụng của Cloud KMS.
You are running an analytics workload on Compute Engine that reads from a large disk with mostly sequential read operations. Your client initially requested SSD persistent disks for performance, but cost has become a concern. You are asked to reduce storage costs while maintaining acceptable read performance. What should you do?
-
A
Use SSD persistent disks (pd-ssd) and reduce the disk size to cut cost
-
B
Move data to Cloud Storage and access it with FUSE mounts for the same performance at lower cost
-
C
Switch to standard persistent disks (pd-standard) since they are cheaper and better for sequential reads
-
D
Use local SSDs, as they are cheaper than persistent disks and provide high read throughput
Xem giải thích
Đáp án
C — Chuyển sang đĩa bền tiêu chuẩn (pd-standard)
Vì sao đúng
Chỗ này rất dễ theo cảm tính chọn nhầm. Đĩa SSD thắng áp đảo ở IOPS, tức là số thao tác đọc ghi ngẫu nhiên nhỏ mỗi giây. Nhưng khối lượng công việc trong đề là đọc tuần tự trên đĩa lớn, mà ở đó thứ quyết định là thông lượng, và đĩa tiêu chuẩn đạt thông lượng tuần tự rất tốt với giá rẻ hơn nhiều lần.
Nói cách khác: khách hàng đã chọn SSD theo phản xạ "SSD thì nhanh hơn", nhưng phản xạ đó chỉ đúng với truy cập ngẫu nhiên.
Vì sao các phương án khác sai
- A. Giữ SSD nhưng thu nhỏ đĩa — trên đĩa bền, hiệu năng tỉ lệ thuận với dung lượng, nên thu nhỏ là vừa tốn tiền vừa chậm đi.
- B. Chuyển sang Cloud Storage rồi gắn bằng FUSE — FUSE tiện nhưng độ trễ cao hơn hẳn hệ tệp thật, không giữ được hiệu năng như đề nói.
- D. Local SSD — nhanh nhất nhưng đắt hơn, và dữ liệu mất khi máy dừng; sai cả hai vế.
Consider a scenario where a large online retailer needs to implement a highly available and scalable NoSQL solution for its e-commerce platform. The solution must handle large amounts of traffic during peak periods, provide fast and reliable performance, and ensure the security of customer data. What is the most appropriate solution for the large online retailer to implement a highly available and scalable solution for its e-commerce platform while handling large amounts of traffic during peak periods, providing fast and reliable performance, and ensuring the security of customer data?
-
A
Use Compute Engine VM single instance for the e-commerce platform and use Cloud SQL for storage.
-
B
Use Google Kubernetes Engine for the e-commerce platform with autoscaling and use Cloud Firestore for storage.
-
C
Use App Engine for the e-commerce platform with a single instance and use Cloud Storage for storage.
-
D
Use Compute Engine with autoscaling and load balancing for the e-commerce platform and use Cloud SQL for storage.
Xem giải thích
Đáp án
B — GKE có tự co giãn cho ứng dụng, kèm giải pháp NoSQL được quản lý
Vì sao đúng
Đề đòi sẵn sàng cao và co giãn được cho một nền tảng thương mại điện tử lớn. GKE cho co giãn ở cả mức pod và mức node, tự thay thành phần hỏng, và triển khai được mà không dừng dịch vụ. Ghép với CSDL NoSQL được quản lý thì cả tầng ứng dụng lẫn tầng dữ liệu đều tự co giãn, không có nút thắt nào phải chỉnh tay.
Vì sao các phương án khác sai
- A. Một máy ảo duy nhất — điểm hỏng duy nhất, không co giãn.
- C. App Engine với một bản chạy duy nhất — tự tay vô hiệu hoá đúng ưu điểm co giãn của App Engine.
- D. Máy ảo có tự co giãn và cân bằng tải — chạy được nhưng phải tự lo ảnh máy, vá hệ điều hành và triển khai; nhiều việc vận hành hơn hẳn container.
You are designing a cloud solution for a financial services company that requires strict compliance with data security regulations. Your application needs to handle sensitive customer data, and you must ensure all data at rest and in transit is appropriately encrypted. Which of the following approaches best aligns with security and compliance standards for managing encryption keys and secrets?
-
A
Embed encryption keys directly into application code to ensure they are readily available for use in encryption and decryption processes.
-
B
Use Cloud Key Management Service (KMS) to manage encryption keys and Cloud Identity-Aware Proxy (IAP) to handle access to those keys.
-
C
Store encryption keys in a regular cloud storage bucket and manage access using IAM roles.
-
D
Utilize self-managed encryption keys stored on-premises, and use VPN connections to access these keys from cloud services as needed.
Xem giải thích
Đáp án
B — Dùng Cloud KMS quản lý khoá, kết hợp Cloud IAM kiểm soát truy cập
Vì sao đúng
Hai lớp bổ sung nhau và đó là điểm chính: KMS giữ khoá trong module bảo mật phần cứng, cho xoay vòng theo lịch và ghi nhật ký mọi lần dùng; IAM quyết định ai được dùng khoá nào. Tách "khoá nằm ở đâu" khỏi "ai được chạm vào khoá" chính là cấu trúc mà các quy định về dữ liệu tài chính đòi hỏi.
Vì sao các phương án khác sai
- A. Nhúng khoá thẳng vào mã nguồn — khoá sẽ nằm trong kho mã, trong ảnh container và trong bản sao lưu; đây là cách rò rỉ phổ biến nhất.
- C. Để khoá trong một bucket thường — bucket là nơi lưu tệp, không có xoay vòng, không có nhật ký dùng khoá, và ai đọc được bucket là có khoá.
- D. Tự giữ khoá tại chỗ rồi nối bằng VPN — làm được nhưng bạn tự gánh toàn bộ việc bảo vệ và vận hành khoá, cộng thêm một điểm hỏng ở đường truyền.
Your organization hosts a 3-tier application (frontend, backend, and database) in Google Cloud using Compute Engine instances in the same Virtual Private Cloud (VPC). The frontend tier should only communicate with the backend tier, and the backend tier should only communicate with the database tier. All inter-tier traffic must follow the principle of least privilege. How should you configure the network to enforce these requirements efficiently?
-
A
Set up VPC Service Controls to restrict traffic between tiers.
-
B
Create individual custom routes for each tier to control traffic flow between them.
-
C
Use network tags to assign each tier and configure firewall rules to allow specific traffic flows.
-
D
Create separate subnetworks for each tier and configure firewall rules to allow the required traffic.
Xem giải thích
Đáp án
C — Gắn network tag cho từng tầng và viết luật tường lửa theo tag
Vì sao đúng
Network tag mô tả vai trò chứ không mô tả địa chỉ. Gắn tag frontend, backend, database rồi viết luật kiểu "chỉ nguồn mang tag backend mới tới được cổng CSDL của đích mang tag database". Máy mới sinh ra từ cùng một mẫu thì thừa hưởng tag, nên luật áp dụng ngay mà không phải sửa gì — điều rất quan trọng khi các tầng co giãn.
Vì sao các phương án khác sai
- B. Viết route riêng cho từng tầng — route quyết định gói tin đi đường nào, không quyết định gói tin có được phép hay không; lọc là việc của tường lửa.
- D. Mỗi tầng một subnet — giúp tổ chức địa chỉ, nhưng tự nó không chặn gì; vẫn phải viết luật, và viết theo dải địa chỉ thì kém linh hoạt hơn theo tag.
- A. VPC Service Controls — dựng để lập vành đai quanh dịch vụ được quản lý như BigQuery hay Cloud Storage nhằm chống rò dữ liệu, không phải công cụ lọc giữa các máy ảo.
A retail company is migrating its monolithic e-commerce application to Google Cloud. The CTO wants the new architecture to:
-
Scale automatically during seasonal traffic spikes
-
Minimize downtime during upgrades
-
Keep costs predictable and controllable
-
Improve security posture compared to their on-premises setup
You are asked which initial approach best applies the Google Cloud Well-Architected Framework when designing the solution. Which option should you choose?
-
A
Prioritize security only by enabling organization policies and VPC Service Controls; treat scalability and reliability as nonfunctional details that can be tuned post-launch.
-
B
Lift and shift the monolith into a single large Compute Engine instance, then rely on autoscaling and Cloud Monitoring alerts to resolve performance and availability issues reactively.
-
C
Start by mapping each requirement to the relevant Well-Architected pillar (performance, reliability, security, cost optimization, operations) and design the architecture with explicit trade-offs documented for each pillar.
-
D
Focus first on minimizing costs by choosing the cheapest machine types and preemptible VMs, then address reliability and security later if issues arise.
Xem giải thích
Đáp án
C — Ánh xạ từng yêu cầu sang trụ cột tương ứng của khung Well-Architected
Vì sao đúng
Đề đưa ra nhiều mục tiêu cùng lúc — co giãn theo mùa, bảo mật, chi phí, vận hành — và chúng mâu thuẫn nhau. Khung Well-Architected tồn tại đúng để xử lý chuyện đó: đặt từng yêu cầu vào trụ cột của nó (hiệu năng, bảo mật, tối ưu chi phí, vận hành xuất sắc, độ tin cậy) rồi ra quyết định đánh đổi một cách tường minh, thay vì tối ưu một chiều rồi phát hiện đã hỏng chiều khác.
Vì sao các phương án khác sai
- A. Chỉ ưu tiên bảo mật — bỏ qua các yêu cầu còn lại mà giám đốc kỹ thuật đã nêu rõ.
- B. Bê nguyên khối lên một máy ảo lớn rồi tính sau — không đạt mục tiêu tự co giãn, và "tính sau" thường có nghĩa là không bao giờ.
- D. Chỉ tối ưu chi phí bằng máy rẻ nhất và máy preemptible — máy preemptible bị thu hồi bất cứ lúc nào, phá thẳng yêu cầu về độ tin cậy.
Your company is developing a multi-region, customer-facing application hosted on Google Cloud. It uses Cloud SQL (PostgreSQL), Compute Engine VMs in managed instance groups behind global HTTP(S) load balancers, and stores assets in Cloud Storage. Recently, customers in Europe have complained about increased latency during peak hours. What is the most effective solution to reduce latency for these customers without duplicating infrastructure or compromising data consistency?
-
A
Migrate the application backend to App Engine flexible environment with autoscaling in a European region.
-
B
Deploy Cloud CDN in front of the global HTTP(S) load balancer and enable cacheable content delivery from Cloud Storage.
-
C
Create a new instance of the application in a European region and set up active-active database replication.
-
D
Move the Cloud SQL instance to the Europe region and leave the application backend in the US.
Xem giải thích
Đáp án
B — Đặt Cloud CDN trước load balancer HTTP(S) toàn cầu và bật nhớ đệm
Vì sao đúng
Với người dùng ở xa khu vực đặt hệ thống, phần lớn độ trễ đến từ quãng đường vật lý. CDN cắt đúng phần đó: nội dung được phục vụ từ điểm biên gần người dùng thay vì đi vòng nửa vòng trái đất. Đây cũng là thay đổi ít xâm lấn nhất — bật thêm một lớp trước load balancer, không phải động vào kiến trúc hay dữ liệu.
Vì sao các phương án khác sai
- A. Chuyển backend sang App Engine Flexible — đổi cả nền tảng chạy mà không giải quyết quãng đường mạng.
- C. Dựng bản sao chủ động – chủ động ở châu Âu — hiệu quả nhưng phức tạp và tốn hơn hẳn; chỉ nên tính tới sau khi CDN không đủ.
- D. Chuyển Cloud SQL sang châu Âu — chỉ dời vấn đề: người dùng khu vực cũ giờ chịu độ trễ.
For this question, refer to the KnightMotives Automotive case study.
https://services.google.com/fh/files/misc/v6.1_pca_knightmotives_automotive_case_study_english.pdf
KnightMotives wants to modernize its IT infrastructure to support a consistent, AI-driven automotive experience across all vehicle models. Core systems such as supply chain management and ERP run on an on-premises mainframe and are tightly coupled to manufacturing operations. Network connectivity to manufacturing plants is reliable but latency-sensitive, while cloud adoption must be incremental to minimize operational risk and disruption to dealers, who have no budget for new hardware. KnightMotives wants to gradually modernize these legacy systems while enabling new digital services on Google Cloud. What is the most appropriate hybrid cloud architecture to modernize KnightMotives’ legacy systems while improving agility and minimizing risk?
-
A
Lift and shift the mainframe-based ERP and supply chain systems directly into Compute Engine VMs.
-
B
Use Google Distributed Cloud (GDC) connected to Google Cloud, and incrementally refactor legacy systems into containerized services on GKE.
-
C
Fully replace the on-premises ERP with a SaaS ERP solution immediately and decommission all legacy systems.
-
D
Migrate legacy systems to BigQuery and use SQL-based transformations to modernize business logic.
Xem giải thích
Đáp án
B — Dùng Google Distributed Cloud nối với Google Cloud, rồi hiện đại hoá dần
Vì sao đúng
Hệ thống ERP và chuỗi cung ứng chạy trên mainframe không thể chuyển trong một lần: chúng gắn chặt với vận hành nhà máy, và một lần cắt chuyển hỏng là dừng sản xuất. Google Distributed Cloud cho chạy dịch vụ Google ngay tại chỗ, nối liền với đám mây, nên hệ thống cũ vẫn ở nơi nó cần ở trong khi từng phần được đưa lên dần. Rủi ro được chia nhỏ thay vì dồn vào một đêm cắt chuyển.
Vì sao các phương án khác sai
- A. Bê nguyên mainframe lên máy ảo — kiến trúc mainframe không ánh xạ thẳng sang máy ảo x86; đây thường là dự án thất bại.
- C. Thay ngay bằng ERP dạng SaaS — thay hệ thống lõi trong một lần là rủi ro cao nhất có thể.
- D. Chuyển hệ thống cũ sang BigQuery — BigQuery là kho phân tích, không thay được hệ thống giao dịch.