GCP Professional Cloud Security Engineer Practice Question

Your organization is deploying Google Cloud Directory Sync (GCDS) to provision users and groups from its on-premises Active Directory but wants every sign-in to Google Workspace and the Cloud Console to occur against the existing Okta tenant. During a design review, you are asked to clarify what role SAML 2.0 plays in this solution. Which statement correctly describes how SAML enables single sign-on in this architecture?

  • SAML is used only to encrypt passwords before GCDS pushes them to Google; the actual authentication step still occurs in Google Cloud using the replicated password hash.

  • SAML allows Google Cloud to act as the service provider, redirecting users to Okta (the identity provider) for authentication and trusting the returned SAML assertion that conveys the user's identity and attributes without exposing their password to Google.

  • SAML makes Google Cloud the primary identity provider, so user passwords must be stored in Google and synchronized back to Okta after each successful login.

  • SAML creates a bidirectional directory synchronization between Okta and Google, eliminating the need for Google Cloud Directory Sync and handling both provisioning and authentication.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot