Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 22 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 22

Select 3Google Cloud Platform

Your organization uses Google Workspace for managing users. The security team has requested that the user lifecycle management process be automated to ensure compliance with company policies and to reduce manual intervention. Specifically, when an employee leaves the organization, their access to Google Cloud resources should be automatically revoked. Which combination of actions should you take to automate this process?

  1. A

    Integrate Google Workspace with Google Cloud Identity and use directory sync.

  2. B

    Set up a Cloud Function that triggers on Google Workspace user deletion events to revoke IAM roles.

  3. C

    Use Google Cloud's IAM Recommender to automatically remove access for inactive users.

  4. D

    Configure a Pub/Sub topic to monitor Google Workspace user lifecycle events and trigger necessary actions.

  5. E

    Implement a third-party Identity Provider (IdP) to manage user lifecycle events and synchronize with Google Cloud.

Show answer and explanation

Correct answers: A, B, D

Explanation

To automate the user lifecycle management process, it is essential to integrate Google Workspace with Google Cloud Identity to ensure central user management. Additionally, setting up a Cloud Function and using Pub/Sub for event-driven automation provides the required mechanisms to handle user lifecycle events such as deprovisioning. IAM Recommender and third-party IdPs are not mandatory or sufficient for this specific use case.

  • A. Correct.

    Integrating Google Workspace with Google Cloud Identity and using directory sync ensures that user accounts are centrally managed and synchronized, which is foundational for automating user lifecycle management.

  • B. Correct.

    Setting up a Cloud Function to trigger on user deletion events allows you to programmatically revoke IAM roles and access, which is critical for automating the deprovisioning process.

  • C. Incorrect.

    IAM Recommender identifies permissions that are not being used, but it does not provide real-time automation for user lifecycle events such as terminations.

  • D. Correct.

    Configuring a Pub/Sub topic to monitor user lifecycle events in Google Workspace enables a scalable and event-driven approach to trigger actions like access revocation.

  • E. Incorrect.

    While third-party IdPs can be used for user lifecycle management, they are not a required solution in this scenario, given that Google Cloud Identity and Google Workspace can handle these tasks natively.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam