GCP Professional Cloud Security Engineer Practice Question

Your company uses Cloud Identity Premium and synchronizes on-premises Active Directory accounts to Google Cloud with Google Cloud Directory Sync (GCDS). Contractors are frequently removed from AD, and security policy mandates that their Google Cloud access be revoked within 60 minutes of account removal. What is the most effective way to meet this requirement while keeping administrative effort low?

  • Replace GCDS with periodic CSV uploads of active users and instruct project owners to manually remove IAM bindings when contractors depart.

  • Create an alert that emails administrators when a terminated contractor attempts to sign in, and require them to delete the Cloud Identity account within an hour.

  • Deploy Cloud Functions in each project that call the Admin SDK Directory API hourly to compare Cloud Identity with Active Directory and remove missing users.

  • Configure the GCDS job to run every 15 minutes and set the User Deletion/Suspension action to suspend any account no longer found in Active Directory.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot