Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 19 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 19

Select 4Google Cloud Platform

Your organization uses Google Workspace for identity management and Google Cloud for its infrastructure. The organization wants to automate the user lifecycle management process, including user account creation, role assignment, and account deactivation when employees leave. Which set of tools and practices should you implement to achieve this goal effectively?

  1. A

    Use Google Cloud Directory Sync (GCDS) to synchronize user accounts from an external directory service with Google Cloud.

  2. B

    Implement a Cloud Function triggered by Pub/Sub to automatically deactivate Google Cloud IAM roles when a user is marked as 'inactive' in the HR system.

  3. C

    Leverage Google Workspace APIs to integrate with the HR system for automatic account provisioning and deprovisioning.

  4. D

    Manually assign and revoke IAM roles in Google Cloud using the Google Cloud Console.

  5. E

    Enable Cloud Identity and configure automated workflows for user account management based on lifecycle events from the HR system.

Show answer and explanation

Correct answers: A, B, C, E

Explanation

To automate user lifecycle management in Google Cloud, you should use a combination of tools like Google Cloud Directory Sync (GCDS), Google Workspace APIs, Cloud Functions with Pub/Sub for automation, and Cloud Identity for advanced user management. These tools and practices together ensure efficient, secure, and automated handling of user accounts. Manual processes are not recommended as they are error-prone and lack scalability.

  • A. Correct.

    Google Cloud Directory Sync (GCDS) is a tool that can synchronize user accounts from an external directory (like Active Directory) with Google Cloud and Google Workspace, which is helpful for managing user lifecycle.

  • B. Correct.

    Using a Cloud Function triggered by Pub/Sub ensures automated deactivation of IAM roles when a user leaves the organization, improving efficiency and security.

  • C. Correct.

    Google Workspace APIs allow programmatic integration with the HR system for automating account provisioning and deprovisioning, reducing manual effort.

  • D. Incorrect.

    Manually assigning and revoking IAM roles through the console is not scalable or efficient for managing user lifecycles, especially in larger organizations.

  • E. Correct.

    Cloud Identity provides advanced features for automating user account management and integrates well with lifecycle events from HR systems, making it a suitable choice for this requirement.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam