Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 101 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 101

Select 3Google Cloud Platform

Your company uses Google Workspace for identity management and you need to configure access to an internal application hosted on Google Cloud. The application requires users to authenticate via SAML, but you also want to enable API access for automation using OAuth tokens. What steps should you take to set this up securely?

  1. A

    Configure a SAML identity provider (IdP) in Google Workspace and link it to the application.

  2. B

    Set up an OAuth 2.0 client ID in Google Cloud and configure the application to use it for API access.

  3. C

    Enable Google Cloud's Identity-Aware Proxy (IAP) for the application to enforce OAuth-based authentication.

  4. D

    Create service accounts for each user and distribute private keys to them for API access.

  5. E

    Configure the application's metadata in the IdP to establish a trust relationship for SAML authentication.

Show answer and explanation

Correct answers: A, B, E

Explanation

To securely configure both SAML authentication for user access and OAuth for API access, you must set up a SAML identity provider (IdP) in Google Workspace, configure the application's metadata in the IdP, and establish an OAuth 2.0 client ID for API usage. These steps ensure that user authentication and API access are handled securely and according to best practices.

  • A. Correct.

    Correct: Setting up a SAML identity provider (IdP) in Google Workspace is necessary to enable SAML-based authentication for the application.

  • B. Correct.

    Correct: To enable API access via OAuth, you need to configure an OAuth 2.0 client ID in Google Cloud.

  • C. Incorrect.

    Incorrect: Identity-Aware Proxy (IAP) is not required in this scenario. While it can provide additional security, the question does not specify its use.

  • D. Incorrect.

    Incorrect: Distributing private keys for service accounts to users is not a secure or recommended practice for API access.

  • E. Correct.

    Correct: The application's metadata must be configured in the IdP to establish a trust relationship, which is a key component of SAML authentication.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam