🔥 40% Off Crucial Exams Memberships — Deal ends today!

10 minutes, 59 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

Your company must let 300 external consultants from a partner that uses Azure Active Directory view Cloud Monitoring dashboards in a single Google Cloud project for six months. Requirements: consultants sign in with their Azure AD credentials; no Google Workspace or Cloud Identity accounts or directory sync; access limited to the Monitoring Viewer role and revocable from Azure AD. Which approach best meets these needs while following Google best practices?

  • Enable Cloud Identity, synchronize the consultants' Azure AD accounts with Google Cloud Directory Sync, and assign them the Monitoring Viewer role in the project.

  • Create a workforce identity pool, add Azure AD as a SAML (or OIDC) provider, map Azure user attributes to Google principals, and grant the Monitoring Viewer role to the external identities via a principalSet binding.

  • Configure traditional SAML single sign-on between Cloud Identity and Azure AD, create Google accounts for each consultant, and grant them the Monitoring Viewer role with two-step verification enforced.

  • Set up Workload Identity Federation with an Azure AD OIDC provider, create a service-account key, share the key with the consultants, and map the service account to the Monitoring Viewer role.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot