Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 24 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 24

Select 3Google Cloud Platform

You are a security engineer tasked with automating the user lifecycle management process for your organization in Google Cloud. The organization uses Google Workspace for identity management and wants to ensure that users are automatically provisioned and deprovisioned in a secure and efficient manner. Which of the following steps should you take to achieve this goal?

  1. A

    Use Google Cloud Directory Sync (GCDS) to synchronize user accounts between the on-premises directory and Google Workspace.

  2. B

    Leverage Identity and Access Management (IAM) policies to automatically assign roles to new users based on their group membership in Google Workspace.

  3. C

    Configure Cloud Identity Groups to manage access to resources and use the Groups API to automate updates to group membership.

  4. D

    Enable the Organization Policy Service to enforce user deprovisioning policies across all projects automatically.

  5. E

    Implement a custom solution using a Pub/Sub topic and a Cloud Function to trigger actions when users are created or deleted in Google Workspace.

Show answer and explanation

Correct answers: A, C, E

Explanation

Automating user lifecycle management in Google Cloud involves integrating tools like Google Cloud Directory Sync (GCDS) for directory synchronization, leveraging Cloud Identity Groups for access management, and implementing event-driven automation using Pub/Sub and Cloud Functions. These approaches ensure that user accounts are provisioned and deprovisioned securely and efficiently, aligning with organizational policies and reducing manual effort.

  • A. Correct.

    Correct: Google Cloud Directory Sync (GCDS) is a recommended tool for synchronizing user accounts between an on-premises directory and Google Workspace, ensuring consistency and automation in user provisioning.

  • B. Incorrect.

    Incorrect: While IAM policies are essential for access control, they do not inherently automate the assignment of roles based on new user creation. This requires separate automation mechanisms.

  • C. Correct.

    Correct: Cloud Identity Groups and the Groups API allow for efficient group-based access management, and automating group membership updates is key to a streamlined user lifecycle management process.

  • D. Incorrect.

    Incorrect: The Organization Policy Service is used to enforce high-level policies within the organization, but it does not handle user lifecycle management directly, such as user provisioning or deprovisioning.

  • E. Correct.

    Correct: Using a Pub/Sub topic and Cloud Function provides a flexible and automated way to respond to user lifecycle events in Google Workspace, such as provisioning or deprovisioning users.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam