GCP Professional Cloud Security Engineer Practice Question

Your company uses Google Workspace with users and groups synchronized from an on-premises Microsoft Active Directory domain through Google Cloud Directory Sync (GCDS). Security architects now have two additional requirements:

  1. Internal employees must continue to sign in with their on-premises credentials when accessing Google Cloud services.
  2. External consultants whose identities live in the partner's Azure AD tenant must be able to access the Google Cloud Console for a single project without creating or synchronizing local accounts, and their credentials must remain short-lived.

Which solution satisfies both requirements while following Google-recommended identity security practices?

  • Keep GCDS for provisioning, configure Google as a SAML service provider that delegates employee logins to AD FS, and create a Workforce Identity Federation pool with an Azure AD SAML provider for the consultants.

  • Create break-glass super-administrator accounts and share them with the partner; configure OpenID Connect sign-in for employees through Google OAuth.

  • Enable GCDS password synchronization so employees authenticate directly with Google, and add the partner's Azure AD tenant to Cloud Identity as a secondary domain.

  • Replace GCDS with a SCIM-based connector, then set up Workload Identity Federation for the partner so their users obtain service account tokens.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot