GCP Professional Cloud Security Engineer Practice Question
Your organization syncs Active Directory users and groups to Cloud Identity with GCDS every 4 hours. After an employee is terminated, their AD account is disabled immediately, yet they can still sign in to the Google Cloud Console until the next GCDS run, which violates policy. You must redesign the identity architecture so that a disabled AD account loses Google access within minutes, while still automating provisioning and avoiding major changes to the AD schema. What should you do?
Increase the GCDS job frequency to every 5 minutes and change its deletion handling rules to suspend users instead of deleting them.
Replace GCDS with a SCIM 2.0 connector that pushes updates from AD directly to Cloud Identity in real time.
Have HR export disabled users to a CSV file and run a scheduled script that calls the Cloud Identity Directory API to suspend the accounts.
Configure Cloud Identity for SAML single sign-on that uses AD FS as the identity provider, and keep GCDS only for periodic account provisioning.
Delegating authentication to Active Directory through SAML SSO means Google Cloud no longer validates the user's password itself; instead, it trusts a SAML assertion issued by AD FS. When the employee's AD account is disabled, AD FS will refuse to create a valid assertion, so Google sign-in fails immediately. GCDS can continue to run on its existing schedule to handle provisioning and group membership updates. Simply shortening the GCDS interval or bulk-suspending users still leaves a potential gap and introduces operational overhead, while SCIM-based real-time sync is not natively available from on-prem AD to Cloud Identity without third-party tooling.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SAML SSO and how does it work?
Open an interactive chat with Bash
What is GCDS and why is it used?
Open an interactive chat with Bash
What is AD FS, and what role does it play in this solution?
Open an interactive chat with Bash
What is SAML single sign-on (SSO) and why is it used in identity management?
Open an interactive chat with Bash
How does AD FS (Active Directory Federation Services) work as an identity provider?
Open an interactive chat with Bash
Why is SCIM 2.0 unsuitable for direct real-time sync between Active Directory and Cloud Identity?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .