GCP Professional Cloud Security Engineer Practice Question
Your organization syncs 40,000 Active Directory users and groups into Cloud Identity with GCDS, but only about 2,000 ever sign in to Google services. Each synchronized user consumes a Cloud Identity license, increasing cost and audit overhead. Leadership wants a new design that 1) keeps ADFS SAML SSO with AD credentials and 2) avoids creating standing Google accounts for the other 38,000 users while still exposing their AD group memberships for IAM policies. Which solution best meets these requirements with minimal ongoing effort?
Replace GCDS with a groups-only sync tool and rely on just-in-time provisioning to create Cloud Identity users the first time they single sign-on.
Enable Google account linking so employees authenticate with personal Gmail accounts federated to their corporate email addresses, eliminating directory synchronization.
Continue using GCDS for all users and groups but run it only quarterly and enable password-hash sync so users authenticate with their AD passwords.
Create a Workforce Identity Federation pool and SAML provider that trusts ADFS, include AD group claims in the SAML assertion, and turn off user-account synchronization in GCDS.
GCDS copies users and groups into Cloud Identity, so every synchronized user becomes a licensed Google account that must be managed. Workforce Identity Federation lets Google Cloud trust ADFS and issue short-lived, non-persistent identities at sign-in. By disabling user sync in GCDS and configuring a workforce identity pool that passes AD group claims in SAML assertions, you eliminate unnecessary accounts yet keep group information available for IAM bindings. The other options either continue to create Google accounts or break the requirement to use corporate credentials.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Workforce Identity Federation in Google Cloud?
Open an interactive chat with Bash
What are SAML assertions, and how do they help in IAM policies?
Open an interactive chat with Bash
How does GCDS differ from Workforce Identity Federation?
Open an interactive chat with Bash
What is Workforce Identity Federation in Google Cloud?
Open an interactive chat with Bash
How does SAML assertion work in Workforce Identity Federation?
Open an interactive chat with Bash
What are the benefits of turning off GCDS user synchronization?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .