Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 31 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 31

Select 3Google Cloud Platform

Your organization uses an external identity provider (IdP) to manage workforce identities and wants to grant users access to Google Cloud resources without creating and managing separate Google accounts. As a Professional Cloud Security Engineer, you need to configure Workforce Identity Federation to achieve this. Which of the following steps are required to set up Workforce Identity Federation correctly?

  1. A

    Create a Google Cloud IAM workload identity pool and configure the external IdP.

  2. B

    Assign roles to the workload identity pool to grant access to Google Cloud resources.

  3. C

    Create a Google Cloud-managed service account and map it to external identities using a workload identity pool provider.

  4. D

    Enable the Google Identity and Access Management (IAM) API in the Google Cloud project.

  5. E

    Configure the external IdP to issue SAML or OIDC tokens for authentication.

Show answer and explanation

Correct answers: A, C, E

Explanation

Workforce Identity Federation allows organizations to grant access to Google Cloud resources by federating external identities from an external IdP. Configuring this requires creating a workload identity pool, mapping external identities to a Google-managed service account, and ensuring the external IdP is set up to issue SAML or OIDC tokens. Roles are assigned to identities, not to the workload identity pool itself, and enabling the IAM API is not a specific step for this configuration.

  • A. Correct.

    Correct. You must create a workload identity pool in Google Cloud IAM and configure it to trust the external identity provider.

  • B. Incorrect.

    Incorrect. Roles are assigned to identities (e.g., service accounts or workload identity pool subjects), not directly to the workload identity pool itself.

  • C. Correct.

    Correct. A Google Cloud-managed service account is typically mapped to external identities to allow them to access Google Cloud resources via the workload identity pool provider.

  • D. Incorrect.

    Incorrect. While enabling the IAM API is a general prerequisite for using IAM features, it is not specific to configuring Workforce Identity Federation.

  • E. Correct.

    Correct. The external IdP must be configured to issue SAML or OIDC tokens that authenticate users and allow them to federate their identity with Google Cloud.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam