Ngân hàng đề — Google Professional Cloud Architect
Tìm thấy 420 câu.
A large financial institution is migrating their trading platform to the cloud to handle increased volume and improve performance. The platform must meet the following requirements:
-
provide real-time access to market data and trade execution capabilities
-
ensure data privacy and compliance with regulatory requirements
-
have the ability to handle peak loads during trading hours while minimizing costs
-
ensure high availability and disaster recovery
-
enable auditing and compliance reporting
Which solution would you recommend to meet these requirements?
-
A
Implementing a managed solution using Cloud Bigtable for real-time market data and trade execution, Cloud Storage for auditing and reporting, and Cloud Pub/Sub for real-time messaging.
-
B
Implementing a serverless solution using Cloud Functions for real-time market data and trade execution, BigQuery for auditing and reporting, and Cloud Pub/Sub for real-time messaging.
-
C
Implementing a hybrid solution using Cloud Bigtable for real-time market data and trade execution, Cloud SQL for auditing and reporting, and Cloud VPN to connect with on-premises storage.
-
D
Implementing a custom-built solution using Compute Engine instances, Cloud Storage, and Cloud Pub/Sub.
Xem giải thích
Đáp án
A — Giải pháp được quản lý: Cloud Bigtable cho dữ liệu thị trường thời gian thực
Vì sao đúng
Nền tảng giao dịch có đặc điểm rất riêng: thông lượng ghi cực cao, độ trễ tính bằng mili giây, dữ liệu chuỗi thời gian. Bigtable dựng đúng cho hình dạng đó — hàng triệu thao tác mỗi giây với độ trễ ổn định, mở rộng bằng cách thêm node mà không phải chia mảnh thủ công. Chọn dịch vụ được quản lý cũng đúng vì tổ chức tài chính cần dồn sức vào nghiệp vụ chứ không phải vận hành cụm.
Vì sao các phương án khác sai
- B. Cloud Functions cho dữ liệu thị trường thời gian thực — có độ trễ khởi động lạnh và giới hạn thời gian chạy, không hợp luồng dữ liệu liên tục tốc độ cao.
- C. Giải pháp lai — giữ một phần tại chỗ thì vẫn phải vận hành hạ tầng cũ, đi ngược mục tiêu của việc chuyển lên đám mây.
- D. Tự xây trên máy ảo — tự gánh việc chia mảnh, nhân bản và vá lỗi cho một hệ thống đòi độ trễ mili giây; rủi ro cao nhất.
You are designing a multi-region hybrid network for an organization with offices in multiple global locations. Your design must ensure secure connectivity between Google Cloud and on-premises networks, minimize operational overhead, and comply with the following requirements:
-
Prevent IP address conflicts.
-
Provide a scalable and manageable network architecture.
What should you do?
-
A
Use an auto-mode VPC in Google Cloud, and establish connectivity with Cloud VPN and Static IP routes.
-
B
Create a custom VPC in Google Cloud with non-overlapping CIDR ranges and use Dedicated Interconnect for connectivity.
-
C
Configure peering between Google Cloud regions and route traffic through the on-premises environment.
-
D
Use a custom VPC in Google Cloud with globally distributed CIDR ranges and connect using Partner Interconnect.
Xem giải thích
Đáp án
B — VPC tuỳ chỉnh với dải CIDR không chồng lấn, nối bằng Dedicated Interconnect
Vì sao đúng
Hai quyết định nền của mọi thiết kế lai:
- Dải CIDR không chồng lấn — nếu VPC trùng địa chỉ với mạng văn phòng thì định tuyến không phân biệt được đích, và cách chữa duy nhất là đánh lại địa chỉ cả một bên. Đây là thứ không sửa được về sau.
- Dedicated Interconnect — đường riêng vào mạng Google, băng thông cao và độ trễ ổn định, không đi qua Internet công cộng.
Vì sao các phương án khác sai
- A. VPC chế độ auto — Google tự cấp subnet ở mọi khu vực theo dải định sẵn, gần như chắc chắn đụng mạng tại chỗ và bạn không kiểm soát được.
- C. Peering giữa các khu vực rồi định tuyến qua văn phòng — VPC vốn đã toàn cầu nên không cần peering giữa các khu vực; đẩy lưu lượng vòng qua văn phòng còn làm độ trễ tệ hơn.
- D. Dải CIDR "phân bố toàn cầu" — không giải quyết đúng vấn đề là chồng lấn với mạng tại chỗ.
You are advising a logistics company planning to retrain a large transformer-based model weekly. They want to reduce model training time and improve iteration speed. Which AI Hypercomputer capability provides the most significant performance benefit in this scenario?
-
A
Relying on Cloud Functions to trigger training jobs
-
B
Running training on Colab Pro+ with GPU acceleration
-
C
Multislice Cloud TPU architecture, enabling parallel training across slices
-
D
Using Dataflow for preprocessing data with low memory requirements
Xem giải thích
Đáp án
C — Kiến trúc Multislice Cloud TPU, huấn luyện song song trên nhiều lát
Vì sao đúng
Mô hình transformer lớn phải huấn luyện lại hằng tuần thì nút thắt là thời gian huấn luyện. TPU được thiết kế riêng cho phép nhân ma trận quy mô lớn — chính là phần nặng nhất của transformer. Multislice cho gộp nhiều lát TPU lại thành một công việc huấn luyện duy nhất, nên quy mô mở rộng vượt xa một pod và thời gian mỗi vòng lặp giảm mạnh.
Vì sao các phương án khác sai
- A. Dùng Cloud Functions để kích hoạt công việc huấn luyện — chỉ là cái nút bấm, không ảnh hưởng gì tới tốc độ huấn luyện.
- B. Colab Pro+ với GPU — hợp cho thử nghiệm cá nhân, không phải nền tảng huấn luyện sản xuất định kỳ.
- D. Dataflow để tiền xử lý dữ liệu — tăng tốc khâu chuẩn bị dữ liệu, không tăng tốc khâu huấn luyện mà đề đang hỏng tới.
Your company, HealthSecure, is migrating a healthcare application to Google Cloud. The application stores and processes sensitive patient data, including personal health information (PHI). The company must comply with the Health Insurance Portability and Accountability Act (HIPAA) and ensure that all data storage, processing, and transmission meet HIPAA requirements. Additionally, the company wants to use Google Cloud's managed services to reduce operational overhead while maintaining full control over security and compliance monitoring. Which of the following strategies would best ensure compliance with HIPAA while minimizing operational overhead?
-
A
Use Google Cloud Storage (GCS) with a multi-regional storage class and enable client-side encryption before uploading PHI.
-
B
Implement a hybrid architecture where PHI is stored on-premises and only non-sensitive data is processed in Google Cloud, using Pub/Sub for messaging between on-premises and cloud systems.
-
C
Deploy the application on Compute Engine VMs within a custom VPC and use Cloud VPN to connect to an on-premises data center. Enable flow logs and use third-party encryption for data at rest.
-
D
Use Google Cloud Healthcare API for storing and processing PHI and enable Cloud Audit Logs to monitor access and changes to the data.
Xem giải thích
Đáp án
D — Dùng Cloud Healthcare API để lưu và xử lý dữ liệu sức khoẻ, kết hợp Cloud DLP
Vì sao đúng
Cloud Healthcare API dựng riêng cho dữ liệu y tế: hiểu các chuẩn FHIR, HL7v2 và DICOM, có sẵn kiểm soát truy cập và nhật ký kiểm toán ở mức phù hợp với yêu cầu tuân thủ. Ghép với Cloud DLP thì thông tin định danh bệnh nhân được phát hiện và khử định danh trước khi dùng cho phân tích hay huấn luyện mô hình. Đây là hai dịch vụ được dựng cho đúng bài toán, không phải giải pháp chắp vá.
Vì sao các phương án khác sai
- A. Cloud Storage đa vùng — lưu được tệp nhưng không hiểu định dạng y tế, không có công cụ khử định danh, và tuân thủ thì phải tự dựng hết.
- B. Giữ dữ liệu bệnh nhân tại chỗ — né tránh vấn đề thay vì giải quyết, và mất phần lớn lợi ích của việc chuyển lên đám mây.
- C. Máy ảo trong VPC tuỳ chỉnh — tự vận hành mọi thứ, kể cả phần tuân thủ khó nhất.
As a cloud architect, you are managing a complex deployment scenario involving several Google Cloud projects under a single organization. You have a new team member who needs to view metadata about the organization and projects, but should not be allowed to modify resources. Which combination of IAM roles would best fulfill this requirement?
-
A
Assign 'Organization Viewer' at the organization level and 'Project Viewer' at the project level.
-
B
Assign 'Project Viewer' at both the organization and project levels.
-
C
Assign 'Project Viewer' at the organization level and 'Organization Viewer' at the project level.
-
D
Assign 'Organization Viewer' at the organization level and 'Project Editor' at the project level.
Xem giải thích
Đáp án
A — Gán 'Organization Viewer' ở mức tổ chức và 'Project Viewer' ở mức dự án
Vì sao đúng
Đề yêu cầu chỉ xem, không sửa, ở cả hai tầng. Mỗi vai phải được gán ở đúng tầng của nó:
Organization Viewergán ở mức tổ chức cho phép xem siêu dữ liệu của tổ chức.Project Viewergán ở mức dự án cho phép xem tài nguyên trong dự án.
Cả hai đều là vai chỉ đọc, nên thoả nguyên tắc quyền tối thiểu.
Vì sao các phương án khác sai
- C. Gán chéo hai vai — đảo tầng của nhau, không có tác dụng như mong muốn.
- B. Gán 'Project Viewer' ở cả hai tầng — thiếu quyền xem siêu dữ liệu ở mức tổ chức.
- D. 'Project Editor' ở mức dự án — vai này cho phép sửa tài nguyên, vi phạm thẳng điều kiện của đề.
For this question, refer to the Altostrat Media case study.
https://services.google.com/fh/files/misc/v6.1_pca_altostrat_media_case_study_english.pdf
Altostrat plans to modernize legacy on-premises content ingestion workflows and integrate them with new AI-driven services on Google Cloud. Development teams want a consistent deployment model that enables fast iteration, minimal infrastructure configuration, and easy promotion between environments. The platform team also wants built-in observability and reduced alerting complexity compared to their current mix of tools. Which solution best simplifies infrastructure management while enabling rapid deployment and observability for Altostrat’s modernized applications?
-
A
Deploy ingestion and AI services as Cloud Functions and manage observability using custom Prometheus exporters
-
B
Use Cloud Run for all stateless services, integrate Cloud Build for CI/CD, and rely on Cloud Monitoring and Logging
-
C
Standardize all services on GKE Autopilot and manage deployments using manual kubectl workflows
-
D
Maintain on-premises ingestion systems and connect them to Google Cloud using VPN and custom monitoring tools
Xem giải thích
Đáp án
B — Cloud Run cho mọi dịch vụ không trạng thái, kèm Cloud Build cho CI/CD
Vì sao đúng
Các dịch vụ nạp dữ liệu và AI của Altostrat là không trạng thái, tức là đúng hình dạng Cloud Run phục vụ tốt nhất: co giãn theo lưu lượng, co về 0 khi rảnh, và không có cụm nào phải vận hành. Ghép với Cloud Build thì mỗi lần đẩy mã là tự động dựng ảnh và triển khai — đúng nhu cầu phát hành nhanh và đều.
Vì sao các phương án khác sai
- A. Dựng mọi thứ bằng Cloud Functions — giới hạn thời gian chạy và bộ nhớ khiến các tác vụ AI nặng không chạy nổi.
- **C. Dồn hết lên GKE Autopilot nhưng triển khai thủ công — Autopilot thì tốt, nhưng thao tác tay là chỗ sinh lỗi và làm chậm nhịp phát hành.
- D. Giữ hệ thống nạp dữ liệu tại chỗ — vẫn phải vận hành hạ tầng cũ, không đạt mục tiêu hiện đại hoá.
Your organization plans to deploy workloads across a hybrid environment. You want to set up a scalable, secure networking architecture with redundancy for connectivity between Google Cloud and your on-premises data center. What should you do?
-
A
Create a custom VPC in custom mode, ensuring CIDR ranges do not overlap with on-premises. Deploy multiple redundant Cloud Interconnect connections.
-
B
Use the default VPC provided by Google Cloud and enable multiple VPC peering connections for redundancy.
-
C
Deploy a custom VPC in custom mode with overlapping CIDR ranges and use two redundant Cloud VPN connections for secure connectivity.
-
D
Deploy two redundant Cloud VPN connections and use auto mode for your Google Cloud VPC.
Xem giải thích
Đáp án
A — VPC tuỳ chỉnh ở chế độ custom, dải CIDR không chồng lấn, có đường dự phòng
Vì sao đúng
Ba điều kiện của đề — co giãn được, an toàn, và có dự phòng — đều nằm ở phương án này. Chế độ custom cho bạn tự quyết định subnet nào ở khu vực nào và dùng dải nào, nên quy hoạch được cho cả phần mở rộng sau này. Dải không chồng lấn là điều kiện bắt buộc để định tuyến lai hoạt động. Và hai đường kết nối song song là cách duy nhất để mất một đường vẫn còn liên lạc.
Vì sao các phương án khác sai
- B. Dùng VPC mặc định — dải địa chỉ do Google định sẵn, không kiểm soát được và dễ đụng mạng tại chỗ.
- **C. Dải CIDR chồng lấn — hỏng ngay ở bước định tuyến, dù có bao nhiêu đường dự phòng.
- D. Chế độ auto — mất quyền quy hoạch địa chỉ, gặp đúng vấn đề như VPC mặc định.
Your marketing team uses Looker dashboards connected to a BigQuery dataset with billions of rows. Users report long load times when filtering by date or campaign. As a cloud architect, you're asked to improve dashboard performance and cost-efficiency, especially for frequently viewed reports. What should you do?
-
A
Enable federated queries to pull in data from Cloud Storage directly into Looker
-
B
Remove caching so users always get the most recent data, improving trust in metrics
-
C
Use Looker Persistent Derived Tables (PDTs) scheduled during off-peak hours to pre-aggregate data
-
D
Switch the connection from BigQuery to Cloud SQL to reduce query complexity
Xem giải thích
Đáp án
C — Dùng Persistent Derived Tables của Looker, lên lịch chạy vào giờ thấp điểm
Vì sao đúng
Vấn đề là hàng tỷ dòng bị tính lại từ đầu mỗi lần người dùng đổi bộ lọc. PDT giải đúng chỗ đó: kết quả được tính sẵn và vật chất hoá thành bảng thật trong BigQuery, nên truy vấn của người dùng chỉ đọc bảng đã tổng hợp. Chạy vào giờ thấp điểm khiến phần tính toán nặng không đụng vào lúc mọi người đang dùng.
Vì sao các phương án khác sai
- A. Bật truy vấn liên kết tới Cloud Storage — thêm một nguồn dữ liệu ngoài, thường chậm hơn bảng gốc chứ không nhanh hơn.
- B. Tắt nhớ đệm để dữ liệu luôn mới — làm mọi thứ chậm đi, đúng ngược vấn đề đang gặp.
- D. Chuyển từ BigQuery sang Cloud SQL — Cloud SQL không kham nổi hàng tỷ dòng cho phân tích; đây là bước lùi rõ rệt.
For this question, refer to the KnightMotives Automotive case study.
https://services.google.com/fh/files/misc/v6.1_pca_knightmotives_automotive_case_study_english.pdf
KnightMotives wants to offer anonymized, aggregated driving-pattern insights to partners such as insurers and city planners. The solution must strictly separate customer-identifiable data from monetized datasets, support regional data residency, and allow ML models to scale as data volume grows. Security teams require centralized policy enforcement and continuous monitoring for data access violations. Which Google Cloud approach best satisfies these security, privacy, and AI/ML scalability requirements?
-
A
Use a single global BigQuery dataset with project-level IAM and rely on application-level logic to anonymize data before sharing it externally.
-
B
Use Dataplex to define data zones, store sensitive data in restricted BigQuery datasets with policy tags, create anonymized views for partners, and train models in Vertex AI using private service access.
-
C
Process data with Dataflow and immediately delete raw data after generating partner reports to reduce compliance risk.
-
D
Export all data to partner-managed environments and require partners to enforce anonymization and compliance controls.
Xem giải thích
Đáp án
B — Dùng Dataplex để định nghĩa các vùng dữ liệu, dữ liệu nhạy cảm nằm trong dataset BigQuery có hạn chế
Vì sao đúng
Dataplex là lớp quản trị dữ liệu: nó cho chia kho dữ liệu thành các vùng theo mức độ nhạy cảm và mục đích sử dụng, gắn siêu dữ liệu và chính sách vào từng vùng, rồi áp quyền một cách nhất quán trên nhiều dataset và bucket. Nhờ vậy dữ liệu nhạy cảm được cô lập bằng chính sách tập trung chứ không phụ thuộc vào việc từng ứng dụng có tự lọc đúng hay không.
Vì sao các phương án khác sai
- A. Một dataset toàn cầu, dựa vào ứng dụng tự lọc — bảo mật nằm trong tay mã ứng dụng, chỉ cần một truy vấn viết ẩu là rò dữ liệu.
- C. Xoá dữ liệu thô ngay sau khi xử lý — mất khả năng kiểm toán và không tính toán lại được khi phát hiện lỗi.
- D. Xuất hết cho đối tác tự quản — trao dữ liệu nhạy cảm ra ngoài rồi hy vọng bên kia làm đúng; mất quyền kiểm soát.
You are designing a real-time analytics platform for a media streaming company that processes millions of events per second. The platform must ingest, process, and analyze data with minimal latency to provide real-time insights into user behavior. The company has a limited budget but requires high performance and availability for the analytics platform. Your design must balance cost, performance, and scalability while ensuring that the system can handle peak traffic loads efficiently. Which combination of services and configurations should you recommend?
-
A
Use Google Cloud Pub/Sub for event ingestion, Google Cloud Functions for processing, and store the processed data in Firestore for fast access.
-
B
Use Google Kubernetes Engine (GKE) to deploy Apache Kafka for event ingestion and processing, and store the processed data in a managed MySQL database on Cloud SQL.
-
C
Use Google Cloud Pub/Sub for event ingestion, Google Cloud Dataflow for real-time processing, and store the processed data in BigQuery with streaming inserts.
-
D
Use Google Cloud Pub/Sub for event ingestion, Apache Beam on a self-managed Compute Engine cluster for processing, and store the processed data in Cloud Spanner.
Xem giải thích
Đáp án
C — Pub/Sub để nạp sự kiện, Dataflow để xử lý thời gian thực, BigQuery để phân tích
Vì sao đúng
Với hàng triệu sự kiện mỗi giây, đây là bộ ba chuẩn và cả ba đều không máy chủ:
- Pub/Sub hấp thụ luồng sự kiện, đảm bảo không mất tin khi tải bùng phát.
- Dataflow xử lý luồng dựa trên Apache Beam, tự co giãn và xử lý được dữ liệu tới muộn — chuyện luôn xảy ra với người dùng toàn cầu.
- BigQuery nhận dữ liệu theo luồng và truy vấn được ngay ở quy mô lớn.
Vì sao các phương án khác sai
- A. Cloud Functions để xử lý — chi phí gọi hàm ở mức hàng triệu sự kiện mỗi giây là không khả thi, và không có cửa sổ thời gian hay xử lý trạng thái.
- B. Tự dựng Kafka trên GKE — làm được nhưng phải tự vận hành cụm Kafka, việc rất nặng.
- D. Apache Beam trên máy ảo tự quản — chính là Dataflow nhưng bỏ đi phần được quản lý.