Quay lại bộ đề
Question #140 Topic 1
You are migrating your on-premises data warehouse to BigQuery. One of the upstream data sources resides on a MySQL. database that runs in your on-premises data center with no public IP addresses. You want to ensure that the data ingestion into BigQuery is done securely and does not go through the public internet. What should you do?
Bạn đang di chuyển kho dữ liệu tại chỗ (on-premises) của mình sang BigQuery. Một trong các nguồn dữ liệu thượng nguồn nằm trên cơ sở dữ liệu MySQL chạy trong trung tâm dữ liệu tại chỗ của bạn không có địa chỉ IP công cộng. Bạn muốn đảm bảo việc nạp dữ liệu vào BigQuery được thực hiện một cách an toàn và không đi qua mạng internet công cộng. Bạn nên làm gì?
A
Update your existing on-premises ETL tool to write to BigQuery by using the BigQuery Open Database Connectivity (ODBC) driver. Set up the proxy parameter in the simba.googlebigqueryodbc.ini file to point to your data center’s NAT gateway.
Cập nhật công cụ ETL tại chỗ hiện tại của bạn để ghi vào BigQuery bằng cách sử dụng trình điều khiển BigQuery Open Database Connectivity (ODBC). Thiết lập tham số proxy trong tệp simba.googlebigqueryodbc.ini để trỏ tới cổng NAT của trung tâm dữ liệu của bạn.
B
Use Datastream to replicate data from your on-premises MySQL database to BigQuery. Set up Cloud Interconnect between your on-premises data center and Google Cloud. Use Private connectivity as the connectivity method and allocate an IP address range within your VPC network to the Datastream connectivity configuration. Use Server-only as the encryption type when setting up the connection profile in Datastream.
Sử dụng Datastream để sao chép dữ liệu từ cơ sở dữ liệu MySQL tại chỗ của bạn sang BigQuery. Thiết lập Cloud Interconnect giữa trung tâm dữ liệu tại chỗ và Google Cloud. Sử dụng kết nối riêng tư (Private connectivity) làm phương thức kết nối và phân bổ một dải địa chỉ IP trong mạng VPC của bạn cho cấu hình kết nối của Datastream. Sử dụng Server-only làm loại mã hóa khi thiết lập cấu hình kết nối trong Datastream.
C
Use Datastream to replicate data from your on-premises MySQL database to BigQuery. Use Forward-SSH tunnel as the connectivity method to establish a secure tunnel between Datastream and your on-premises MySQL database through a tunnel server in your on-premises data center. Use None as the encryption type when setting up the connection profile in Datastream.
Sử dụng Datastream để sao chép dữ liệu từ cơ sở dữ liệu MySQL tại chỗ của bạn sang BigQuery. Sử dụng đường hầm Forward-SSH làm phương thức kết nối để thiết lập đường hầm bảo mật giữa Datastream và cơ sở dữ liệu MySQL tại chỗ của bạn thông qua một máy chủ đường hầm trong trung tâm dữ liệu tại chỗ. Sử dụng None làm loại mã hóa khi thiết lập cấu hình kết nối trong Datastream.
D
Use Datastream to replicate data from your on-premises MySQL database to BigQuery. Gather Datastream public IP addresses of the Google Cloud region that will be used to set up the stream. Add those IP addresses to the firewall allowlist of your on-premises data center. Use IP Allowlisting as the connectivity method and Server-only as the encryption type when setting up the connection profile in Datastream.
Sử dụng Datastream để sao chép dữ liệu từ cơ sở dữ liệu MySQL tại chỗ của bạn sang BigQuery. Thu thập các địa chỉ IP công cộng của Datastream trong vùng Google Cloud sẽ được sử dụng để thiết lập luồng truyền. Thêm các địa chỉ IP đó vào danh sách cho phép của tường lửa trung tâm dữ liệu tại chỗ. Sử dụng IP Allowlisting làm phương thức kết nối và Server-only làm loại mã hóa khi thiết lập cấu hình kết nối trong Datastream.
Giải thích & Tài liệu tham khảo
Để sao chép dữ liệu từ một cơ sở dữ liệu MySQL tại chỗ không có IP công cộng vào BigQuery mà không đi qua internet công cộng:
- B là đúng: Cloud Interconnect cung cấp kết nối mạng vật lý trực tiếp, riêng tư và an toàn từ mạng tại chỗ đến Google Cloud, bỏ qua internet công cộng. Kết hợp với tính năng kết nối riêng tư (Private connectivity) của Datastream thông qua việc phân bổ địa chỉ IP trong mạng VPC của bạn, Datastream có thể kết nối trực tiếp đến cơ sở dữ liệu MySQL nội bộ. Tùy chọn mã hóa
Server-only(hoặc cao hơn) đảm bảo kết nối bảo mật. - A là sai: NAT Gateway tại chỗ vẫn định tuyến lưu lượng qua internet công cộng để ghi vào API BigQuery toàn cầu.
- C là sai: Đặt loại mã hóa là
Nonevi phạm yêu cầu truyền dữ liệu an toàn. - D là sai: Phương pháp IP Allowlisting yêu cầu cơ sở dữ liệu MySQL tại chỗ phải có thể truy cập được thông qua địa chỉ IP công cộng để Datastream kết nối vào, điều này vi phạm yêu cầu không sử dụng internet công cộng.
(Đáp án được gợi ý bởi AI)