Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 11 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 11

Select 4Google Cloud Platform

Your organization uses a third-party identity provider (IdP) for user authentication and authorization. You need to configure Single Sign-On (SSO) for your Google Workspace and synchronize user data from your on-premises Active Directory to Google Cloud Identity. Which steps should you take to successfully implement this setup?

  1. A

    Install and configure Google Cloud Directory Sync (GCDS) to synchronize user data from Active Directory to Google Cloud.

  2. B

    Enable the 'Federated Login' feature in the Google Admin console and configure the SSO URL provided by the third-party IdP.

  3. C

    Generate a SAML metadata file in Google Cloud and upload it to the third-party IdP for configuration.

  4. D

    Disable 2-step verification for all users in the Google Admin console to avoid conflicts with the IdP.

  5. E

    Test the SSO configuration by attempting to log in to Google Workspace using an account managed by the third-party IdP.

Show answer and explanation

Correct answers: A, B, C, E

Explanation

To implement SSO with a third-party IdP and synchronize user data from on-premises Active Directory to Google Cloud, you must configure Google Cloud Directory Sync (GCDS) to handle user synchronization. Additionally, configuring the 'Federated Login' feature and exchanging SAML metadata ensures proper integration with the IdP. Testing the SSO setup validates the configuration. Disabling 2-step verification is neither necessary nor recommended, as it weakens security.

  • A. Correct.

    Correct. Google Cloud Directory Sync (GCDS) is required to synchronize user data from on-premises Active Directory to Google Cloud Identity, ensuring consistent user data across systems.

  • B. Correct.

    Correct. Enabling the 'Federated Login' feature and configuring the SSO URL allows Google Workspace to delegate authentication to the third-party IdP.

  • C. Correct.

    Correct. SAML metadata is essential for establishing trust and ensuring both parties (Google Workspace and the IdP) are properly configured for SAML-based SSO.

  • D. Incorrect.

    Incorrect. Disabling 2-step verification is not required for SSO implementation. Google Workspace supports 2-step verification alongside SSO, and disabling it would reduce security.

  • E. Correct.

    Correct. Testing the SSO configuration verifies that the setup works as expected and identifies any misconfigurations or issues in the SSO process.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam