Ngân hàng đề — Google Professional Cloud Architect

Tìm thấy 420 câu.

Câu 71

An application needs to be migrated from your on-premise data center to Google Cloud App Engine. You modified your application to use Cloud Pub/Sub with a specific service account which has the necessary permissions to publish and subscribe on Pub/Sub. However, Cloud Pub/Sub API has not yet been enabled. What should you do?

  1. A

    You should use Deployment Manager to configure the App Engine to use a specific service account with the necessary permissions and rely on the automatic enablement of the Cloud Pub/Sub API on the first request to publish or subscribe.

  2. B

    You should configure the App Engine to use a specific service account with the necessary permissions and rely on the automatic enablement of the Cloud Pub/Sub API on the first request to publish or subscribe.

  3. C

    You should navigate to the APIs & Services section in Google Console and enable Cloud Pub/Sub API.

  4. D

    You should grant roles/pubsub.admin IAM role to the service account and modify the application code to enable the API before publishing or subscribing.

Xem giải thích

Đáp án

C — Vào mục APIs & Services trong Google Console và bật API của Pub/Sub

Vì sao đúng

Câu này kiểm tra một điều rất cơ bản mà hay bị bỏ qua: API phải được bật cho từng dự án trước khi dùng. Chưa bật thì mọi lời gọi đều thất bại, kể cả khi tài khoản dịch vụ đã có đủ quyền — và thông báo lỗi ở tình huống này rất dễ bị hiểu nhầm thành lỗi phân quyền, khiến người ta đi cấp thêm vai một cách vô ích.

Vì sao các phương án khác sai

  • A. Dùng Deployment Manager để cấu hình tài khoản dịch vụ — công cụ hạ tầng dạng mã, không liên quan tới việc API đã bật hay chưa.
  • B. Cấu hình App Engine dùng một tài khoản dịch vụ cụ thể — cần thiết nhưng chưa đủ nếu API chưa bật.
  • D. Cấp vai roles/pubsub.admin — cấp quyền rộng hơn mức cần, và vẫn không chạy nếu API chưa bật.
Câu 72

As a cloud architect, you've implemented an autoscaling group for a client's application on Google Cloud Compute Engine. The client now wants to increase the maximum number of instances in the autoscaling group to handle peak demand. Which of the following steps would you take to achieve this?

  1. A

    Increase the maximum number of vCPUs for the project.

  2. B

    Increase the disk size for the instance template used by the autoscaling group.

  3. C

    Increase the value of the maxNumReplicas parameter in the Autoscaler configuration.

  4. D

    Increase the number of zones in the region where the autoscaling group is deployed.

Xem giải thích

Đáp án

C — Tăng giá trị maxNumReplicas trong cấu hình Autoscaler

Vì sao đúng

maxNumReplicas chính là trần số máy mà bộ tự co giãn được phép tạo. Muốn nhóm mở rộng thêm thì phải nâng con số này — mọi thứ khác đều không ảnh hưởng tới giới hạn đó.

Vì sao các phương án khác sai

  • A. Tăng hạn mức vCPU của dự án — hạn mức là trần của cả dự án; nếu bạn đang chạm hạn mức thì phải xin thêm, nhưng nó không phải thứ giới hạn nhóm này khi maxNumReplicas còn thấp.
  • B. Tăng dung lượng đĩa trong instance template — chẳng liên quan tới số lượng máy.
  • D. Thêm zone cho khu vực — giúp phân bố máy đều hơn và tăng khả năng chịu lỗi, nhưng tổng số máy vẫn bị chặn bởi maxNumReplicas.
Câu 73

For this question, refer to the KnightMotives Automotive case study.

https://services.google.com/fh/files/misc/v6.1_pca_knightmotives_automotive_case_study_english.pdf


KnightMotives wants to improve real-time visibility into production status across geographically distributed plants. Some plants are located in rural areas with limited and inconsistent network connectivity. The solution must ensure reliable data transfer to headquarters and Google Cloud services, while optimizing costs and avoiding major infrastructure changes at dealer or plant locations. Which network architecture best meets KnightMotives’ requirements for reliability, scalability, and cost efficiency?

  1. A

    Use Dedicated Interconnect at all plant locations regardless of traffic volume

  2. B

    Deploy regional VPCs connected with VPC Network Peering and route plant traffic through headquarters

  3. C

    Centralize all data ingestion through a single region and rely on manual failover

  4. D

    Use Cloud VPN with high-availability tunnels and implement Cloud Router with dynamic routing

Xem giải thích

Đáp án

D — Cloud VPN với đường hầm sẵn sàng cao, kèm Cloud Router định tuyến động

Vì sao đúng

Với nhiều nhà máy có lưu lượng khác nhau, đây là phương án cân bằng đúng: HA VPN dùng hai đường hầm qua hai giao diện nên vẫn chạy khi mất một đường, còn Cloud Router dùng BGP để học và quảng bá tuyến tự động — thêm subnet mới không phải sửa cấu hình ở từng nhà máy, và khi một đường chết thì tuyến được tính lại ngay.

Vì sao các phương án khác sai

  • A. Dedicated Interconnect ở mọi nhà máy bất kể lưu lượng — chi phí và công lắp đặt rất lớn; chỉ đáng ở những nơi thực sự cần băng thông cao.
  • B. VPC vùng nối bằng peering — peering không có tính bắc cầu, nên mô hình nhiều nhà máy sẽ phải khai từng cặp một và phình rất nhanh.
  • C. Dồn về một khu vực rồi chuyển đổi dự phòng thủ công — vừa có điểm hỏng duy nhất, vừa dựa vào thao tác tay đúng lúc đang có sự cố.
Câu 74

As a cloud architect, you are responsible for the user management service for your global company. This service will perform basic operations such as viewing, adding, updating, deleting addresses. Each of these operations is implemented by a Docker container microservice. The processing load can vary from low to very high. You want to deploy the service on Google Cloud for scalability and minimal administration. What should you do?

  1. A

    You should deploy your Docker containers into GKE.

  2. B

    You should combine four microservices into a single Docker image, and deploy it to the App Engine instance.

  3. C

    You should start each Docker container as a Managed Instance Group (MIG).

  4. D

    You should deploy your Docker containers into Cloud Run.

Xem giải thích

Đáp án

D — Triển khai container lên Cloud Run

Vì sao đúng

Dịch vụ quản lý người dùng chỉ làm các thao tác cơ bản: xem, thêm, sửa, xoá. Đó là dịch vụ không trạng thái, chạy theo yêu cầu — đúng hình dạng mà Cloud Run phục vụ tốt nhất. Nó co giãn theo lưu lượng, co về 0 khi rảnh nên không trả tiền lúc không ai dùng, và không có cụm nào phải vận hành.

Vì sao các phương án khác sai

  • A. Đưa lên GKE — chạy được nhưng phải nuôi cả một cụm cho vài dịch vụ đơn giản.
  • B. Gộp bốn microservice vào một ảnh Docker — phá bỏ chính lý do tồn tại của microservice: không còn triển khai hay co giãn độc lập được nữa.
  • C. Mỗi container một Managed Instance Group — quản lý ở mức máy ảo, nặng nhất về vận hành.
Câu 75 Chọn nhiều đáp án

In order to cut down expenses, the chief engineering officer mandated that all developers shift their development infrastructure resources from on-premises virtual machines (VMs) to Google Cloud. These resources undergo frequent start/stop occurrences throughout the day and necessitate the persistence of their state. As a cloud architect, you have been tasked with designing a plan for running a development environment on Google Cloud that also allows the finance department to have clear visibility into the costs involved. Which two steps should you take? (Choose two)

  1. A

    Apply VM CPU utilization label and include it in the BigQuery billing export.

  2. B

    Store all state in a Local SSD, snapshot the persistent disks, and terminate the VM.

  3. C

    Use persistent disks to store the state. Start and stop the VM as needed.

  4. D

    Use the gcloud --auto-delete flag on all persistent disks before stopping the VM.

  5. E

    Use BigQuery billing export and labels to relate cost to groups.

Xem giải thích

Đáp án

C và E — dùng đĩa bền để giữ trạng thái rồi bật tắt máy khi cần, và dùng BigQuery billing export cùng nhãn để quy chi phí về từng nhóm

Vì sao đúng

Đề có hai vế — giảm chi phí và biết tiền đi đâu:

  • C. Trạng thái nằm trên đĩa bền, máy thì tắt khi không dùng — máy đã dừng thì không tính tiền vCPU và bộ nhớ, chỉ còn phí đĩa vốn rẻ hơn nhiều. Máy phát triển thường chỉ dùng trong giờ làm việc nên phần tiết kiệm rất lớn.
  • E. Billing export sang BigQuery kèm nhãn — cho phép cắt chi phí theo nhóm, theo dự án hay theo môi trường, tức là biết chính xác ai tiêu bao nhiêu.

Vì sao các phương án khác sai

  • A. Gắn nhãn "mức dùng CPU" cho máy ảo — nhãn là giá trị tĩnh do bạn đặt, không phải số liệu thay đổi theo thời gian; không dùng như vậy được.
  • B. Giữ trạng thái trên Local SSD — dữ liệu trên Local SSD mất khi máy dừng, đúng thứ phải tránh khi mục tiêu là tắt máy thường xuyên.
  • D. Đặt cờ --auto-delete cho đĩa bền — cờ này khiến đĩa bị xoá cùng máy, tức là mất sạch trạng thái.
Câu 76

In your customer support tool, all email and chat conversations are logged to Bigtable for storage and analysis purposes. However, to ensure data privacy and compliance, it is essential to sanitize this data by removing any Personally Identifiable Information (PII) or payment card information before it is initially stored. What approach would you recommend for accomplishing this task?

  1. A

    De-identify the data with the Cloud Data Loss Prevention API.

  2. B

    Hash all data using SHA256.

  3. C

    Use regular expressions to find and redact phone numbers, email addresses, and credit card numbers.

  4. D

    Encrypt all data using elliptic curve cryptography.

Xem giải thích

Đáp án

A — Khử định danh dữ liệu bằng Cloud Data Loss Prevention API

Vì sao đúng

Cloud DLP dựng riêng cho việc này: nó có sẵn hơn một trăm bộ nhận dạng cho số điện thoại, email, số thẻ, số định danh cá nhân theo từng quốc gia, và nhận ra chúng trong văn bản tự do — đúng thứ mà log hội thoại và email chứa đầy. Sau đó bạn chọn cách xử lý: che, thay bằng token, hoặc mã hoá giữ định dạng để dữ liệu vẫn phân tích được.

Vì sao các phương án khác sai

  • C. Tự viết biểu thức chính quy — bắt được vài định dạng phổ biến rồi sót phần còn lại; số điện thoại quốc tế và địa chỉ viết tay có vô số biến thể. Sót một mẫu là rò dữ liệu.
  • B. Băm toàn bộ dữ liệu bằng SHA256 — băm hết thì mất luôn phần nội dung cần phân tích.
  • D. Mã hoá toàn bộ — bảo vệ khi lưu trữ, nhưng ai giải mã được là thấy nguyên thông tin cá nhân; đề cần gỡ dữ liệu nhạy cảm chứ không chỉ khoá nó lại.
Câu 77

For this question, refer to the Cymbal Retail case study.

https://services.google.com/fh/files/misc/v6.1_pca_cymbal_retail_case_study_english.pdf


Cymbal wants to personalize product recommendations across web, chat, and call center channels to increase repeat purchases. Customer interaction data is currently fragmented across multiple databases and on-premises systems. The architecture must enable near-real-time insights into customer behavior while minimizing data duplication and operational overhead. Which solution best enables unified, engagement-driven personalization across customer touchpoints?

  1. A

    Continue using existing databases and allow each channel to implement its own personalization logic

  2. B

    Replicate all databases into a single Cloud SQL instance to create a unified customer profile

  3. C

    Periodically export customer data from all databases into Cloud Storage and run batch analytics jobs

  4. D

    Stream customer interaction events into BigQuery and use it as a centralized analytics and personalization platform

Xem giải thích

Đáp án

D — Đưa sự kiện tương tác của khách hàng vào BigQuery làm tầng phân tích tập trung

Vì sao đúng

Cymbal muốn cá nhân hoá, mà cá nhân hoá đòi một góc nhìn hợp nhất về khách hàng trải trên mọi kênh. Đưa sự kiện từ tất cả các kênh vào BigQuery tạo ra đúng chỗ đó: dữ liệu tới gần thời gian thực, truy vấn được ở quy mô lớn, và nối thẳng được sang các công cụ học máy để dựng mô hình gợi ý.

Vì sao các phương án khác sai

  • A. Mỗi kênh tự làm theo cách của mình — chính là vấn đề hiện tại: mỗi kênh chỉ thấy một mảnh của khách hàng.
  • B. Nhân bản mọi CSDL vào một instance Cloud SQL — Cloud SQL là CSDL giao dịch, không kham nổi phân tích ở quy mô này.
  • C. Xuất định kỳ ra Cloud Storage rồi chạy theo lô — dữ liệu luôn cũ, nên gợi ý không phản ứng được với hành vi vừa xảy ra.
Câu 78

Your company is deploying a critical application on Google Cloud Platform that requires high availability and a robust disaster recovery strategy. The application will handle large-scale, global user traffic and store sensitive data. What is the best approach to design the application’s infrastructure for these requirements?

  1. A

    Deploy the application across multiple GCP regions, use Multi-regional storage for data, and implement a global load balancer.

  2. B

    Use a hybrid cloud approach, hosting the application on GCP and another cloud provider simultaneously.

  3. C

    Utilize a single-region, single-zone approach with regular data backups to a different region.

  4. D

    Host the application in a single region using standard storage and manual scaling to handle traffic spikes.

Xem giải thích

Đáp án

A — Triển khai qua nhiều khu vực GCP, dùng lưu trữ đa vùng

Vì sao đúng

Đề đòi sẵn sàng cao và kế hoạch khôi phục thảm hoạ vững chắc. Chỉ có phương án này đáp ứng cả hai: ứng dụng chạy ở nhiều khu vực nên mất trọn một khu vực vẫn còn khu vực khác phục vụ, và lưu trữ đa vùng nhân bản dữ liệu qua nhiều khu vực nên dữ liệu không nằm cùng một rổ với ứng dụng.

Vì sao các phương án khác sai

  • B. Lai với một đám mây khác — về lý thuyết chịu lỗi tốt, nhưng vận hành hai nền tảng khác nhau tốn kém và phức tạp hơn nhiều so với phần lợi.
  • C. Một zone duy nhất, chỉ sao lưu định kỳ — mất zone là dừng dịch vụ, và khôi phục từ bản sao lưu tính bằng giờ.
  • D. Một khu vực, co giãn thủ công — không đạt cả tính sẵn sàng lẫn khả năng co giãn.
Câu 79

For this question, refer to the KnightMotives Automotive case study.

https://services.google.com/fh/files/misc/v6.1_pca_knightmotives_automotive_case_study_english.pdf


KnightMotives’ unreliable online vehicle ordering system is straining relationships with dealers. The system depends on outdated ERP logic for pricing, promotions, and built-to-order configurations. The company wants to modernize this capability using Google Cloud while keeping core transactional systems operational during the transition. The solution must support gradual replacement of legacy components and enable faster rollout of new digital features. Which modernization approach best aligns with Google Cloud best practices and KnightMotives’ business constraints?

  1. A

    Rebuild the entire ordering system as a monolithic application on Compute Engine and migrate all users at once.

  2. B

    Replicate ERP data into BigQuery and use scheduled batch jobs to drive the ordering workflow.

  3. C

    Use Cloud Functions for all business logic, directly replacing ERP pricing and configuration logic.

  4. D

    Implement a strangler pattern using APIs, exposing legacy ERP functionality while incrementally replacing components with cloud-native microservices on GKE.

Xem giải thích

Đáp án

D — Áp dụng mô hình strangler bằng API, bọc chức năng ERP cũ lại rồi thay dần

Vì sao đúng

Mô hình strangler (bóp nghẹt dần) là cách chuẩn để hiện đại hoá hệ thống lõi mà không phải dừng nó: đặt một lớp API trước ERP cũ, rồi từng chức năng một được chuyển sang dịch vụ mới phía sau lớp API đó. Người gọi không thấy gì thay đổi. Mỗi bước nhỏ nên hỏng thì lùi lại được, và hệ thống cũ chỉ bị gỡ bỏ khi phần cuối cùng đã có bản thay thế.

Vì sao các phương án khác sai

  • A. Viết lại toàn bộ thành một khối trên máy ảo — vừa là dự án viết lại toàn phần rủi ro nhất, vừa cho ra một khối nguyên mới thay vì kiến trúc hiện đại.
  • B. Nhân bản dữ liệu ERP sang BigQuery rồi chạy theo lô — BigQuery là kho phân tích, không thay được logic giao dịch của việc đặt hàng.
  • C. Đưa toàn bộ logic nghiệp vụ vào Cloud Functions ngay — thay thẳng phần định giá và quy tắc của ERP trong một lần, đúng kiểu cắt chuyển rủi ro cao mà mô hình strangler tránh.
Câu 80

A global media company is launching a new streaming service hosted on Google Cloud. The company has identified three primary business goals for the service:

  1. High availability: The service must be available 99.99% of the time to ensure a seamless user experience.

  2. Scalability: The service must handle sudden spikes in traffic during major events, such as sports finals or premieres, without performance degradation.

  3. User engagement: The company aims to increase user engagement by 20% within the first six months.

To measure the success of the new service, the company needs to define appropriate KPIs. Which set of KPIs should the company prioritize to effectively measure the success of the new streaming service?

  1. A

    Monthly operational costs, average time to resolution for technical issues, and churn rate of subscriptions.

  2. B

    Uptime percentage, number of concurrent users supported, and the average resolution of streamed content.

  3. C

    Time to market, cost per user acquisition, and the number of new subscriptions in the first month.

  4. D

    Uptime percentage, traffic scalability (requests per second during peak times), and user engagement metrics such as average session duration and content interaction rates.

Xem giải thích

Đáp án

D — Tỷ lệ thời gian hoạt động, khả năng co giãn theo lưu lượng (số yêu cầu mỗi giây lúc cao điểm), và độ trễ

Vì sao đúng

Chỉ số đo lường phải ánh xạ một–một với mục tiêu kinh doanh đã nêu. Ba mục tiêu là sẵn sàng cao, co giãn được, và hiệu năng tốt; ba chỉ số ở phương án D đo đúng ba thứ đó:

  • Tỷ lệ thời gian hoạt động ↔ tính sẵn sàng
  • Số yêu cầu mỗi giây lúc cao điểm ↔ khả năng co giãn
  • Độ trễ ↔ hiệu năng

Vì sao các phương án khác sai

  • A. Chi phí vận hành và thời gian xử lý sự cố — là chỉ số vận hành hữu ích, nhưng không đo thứ mà ba mục tiêu kinh doanh nói tới.
  • B — có tỷ lệ hoạt động và số người dùng đồng thời, nhưng thay hiệu năng bằng thời gian xử lý sự cố, nên thiếu mất một trụ.
  • C. Thời gian ra thị trường, chi phí thu hút người dùng, số thuê bao mới — chỉ số marketing, không phải chỉ số kỹ thuật của nền tảng.