🔥 40% Off Crucial Exams Memberships — Deal ends today!

2 hours, 59 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your company uses Microsoft Active Directory as the authoritative directory. Google Cloud Directory Sync (GCDS) currently provisions users and groups into Cloud Identity, so employees authenticate with passwords stored in Google. Security now requires that:

  1. Google must stop storing or validating user passwords,
  2. Password changes in Active Directory must take effect immediately when users access Google Workspace,
  3. Existing group synchronization must continue. Which approach best satisfies all requirements while introducing the fewest changes to the existing Google identities?
  • Enable Google Cloud Secure LDAP for authentication and disable SAML single sign-on while leaving GCDS in place for groups.

  • Retain GCDS for user and group provisioning but configure Google Workspace for SAML single sign-on that redirects authentication to an AD FS identity provider.

  • Export users from Active Directory to a CSV file, import them into Cloud Identity, disable GCDS, and have users reset their Google passwords.

  • Replace GCDS with Workforce Identity Federation so Google Workspace relies on short-lived tokens issued by Active Directory and stop synchronizing directory objects.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot