🔥 40% Off Crucial Exams Memberships — Deal ends today!

2 hours, 59 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization is starting a three-month project with an external research institute. The researchers authenticate with their own Azure Active Directory tenant, but they need temporary access to invoke Cloud Run services and read specific Cloud Storage buckets in your Google Cloud project. Company policy forbids creating Google accounts for them and bans distributing any long-lived credentials. Which approach best satisfies all requirements while following least-privilege practices?

  • Generate user-managed keys for a dedicated service account that has the required IAM roles and distribute the keys to the institute's researchers for the duration of the project.

  • Use Google Cloud Directory Sync to import the institute's Azure AD users into Cloud Identity and enable SAML-based single sign-on for them.

  • Create a workforce identity pool that trusts the institute's Azure AD as an OIDC provider, map researcher groups to narrowly scoped IAM roles on the project, and let researchers obtain short-lived Google credentials on demand.

  • Provision temporary Google Workspace accounts for the researchers, place them in a group with the necessary IAM roles, and enforce two-step verification on those accounts.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot