🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 52 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your enterprise uses two external identity systems. Azure AD issues SAML 2.0 assertions, while an internal identity provider releases only OpenID Connect (OIDC) ID tokens. Company policy forbids copying user accounts into Cloud Identity; instead, you must rely on Workforce Identity Federation so both groups can obtain short-lived Google Cloud access tokens. Which configuration will meet the requirements with the least operational overhead?

  • Create a single workforce identity pool, add a SAML provider for Azure AD and an OIDC provider for the custom IdP, then grant IAM roles to identities in the pool.

  • Establish LDAP over Cloud VPN for each identity system and allow access through service account impersonation.

  • Create one workload identity pool and configure two OIDC providers, directing Azure AD users to authenticate through OIDC instead of SAML.

  • Deploy Google Cloud Directory Sync to import all users, then configure SAML single sign-on for both identity systems.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot