GCP Professional Cloud Security Engineer Practice Question
You are implementing Google Cloud Directory Sync (GCDS) to synchronize 60,000 users and groups from the company's on-premises Microsoft Active Directory to a new Google Cloud organization. Security architects want to understand exactly how the tool will interact with the existing directory. Which statement accurately describes GCDS behavior that must be considered during the design?
By default, GCDS updates group memberships in both directions, so changes made in Google are automatically written to Active Directory.
GCDS requires secure LDAP to be disabled because it must make schema changes in Active Directory during synchronization.
GCDS performs a one-way read from Active Directory and writes changes only to Google; it never modifies the source directory.
GCDS establishes a trust that lets it push updated password hashes from Google back into Active Directory to keep credentials synchronized.
GCDS queries the on-premises LDAP directory, compares the results with the current state of Google accounts, and then uses Google administration APIs to create, update, suspend, or delete objects in Google Cloud. It never attempts to write, modify, or extend the schema of the source directory, so the risk of inadvertent changes to Active Directory is eliminated. GCDS also does not copy password hashes or perform bidirectional synchronization; any password verification still occurs against the identity provider used for authentication. Therefore, the correct choice is the statement that GCDS operates as a one-way, read-only consumer of LDAP data. The remaining options are incorrect because GCDS neither writes passwords back to AD, nor performs bidirectional updates, nor requires changes to the AD schema or disabling of secure LDAP.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
How does GCDS synchronize users and groups from Active Directory to Google Cloud?
Open an interactive chat with Bash
Does GCDS synchronize passwords between Google Cloud and Active Directory?
Open an interactive chat with Bash
Why is GCDS considered secure when interacting with Active Directory?
Open an interactive chat with Bash
What is Google Cloud Directory Sync (GCDS)?
Open an interactive chat with Bash
How does GCDS ensure secure synchronization?
Open an interactive chat with Bash
What types of changes can GCDS make in Google Cloud?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .