GCP Associate Cloud Engineer Practice Question

Your company has just activated Cloud Identity to manage Google Cloud access. The on-premises Microsoft Active Directory holds about 1,000 user accounts and 50 security groups that must appear in Cloud Identity and stay synchronized. The security team requires that new and deleted AD accounts be reflected in Cloud Identity within one hour, and they do not want to maintain any custom code. Which approach satisfies these requirements with the least ongoing effort?

  • Install Google Cloud Directory Sync on an on-premises server, configure it to read from Active Directory, and schedule it to run every hour to synchronize users and groups to Cloud Identity.

  • Export users and groups from Active Directory to a CSV file each day and use the Cloud Identity Admin Console to import the file.

  • Write a Cloud Function triggered hourly that calls the Cloud Identity Admin SDK Directory API to add or delete users and update group memberships based on an exported AD list.

  • Enable Secure LDAP in Cloud Identity and configure it to query the on-premises Active Directory, allowing identities to be pulled automatically.

GCP Associate Cloud Engineer
Setting up a cloud solution environment
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot