Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 32 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 32

Select 3Google Cloud Platform

Your organization uses an external identity provider (IdP) for authentication and plans to enable secure access to Google Cloud resources using Workforce Identity Federation. As a Professional Cloud Security Engineer, which steps should you take to configure Workforce Identity Federation correctly?

  1. A

    Create a Google Cloud IAM workload identity pool and configure the external IdP to trust it.

  2. B

    Create a service account in Google Cloud and assign it to the workforce identity pool.

  3. C

    Define an OIDC identity provider in the workload identity pool to establish the trust with the external IdP.

  4. D

    Update the external IdP to include a claim mapping that maps users to Google Cloud roles.

  5. E

    Configure an IAM policy binding to associate the workload identity pool with specific permissions for Google Cloud resources.

Show answer and explanation

Correct answers: A, C, E

Explanation

Configuring Workforce Identity Federation involves creating a workload identity pool, defining an identity provider in the pool to establish trust with the external IdP, and configuring IAM policy bindings to grant permissions to the federated identities. Service accounts are not used in this process, and claim mapping is managed within the workload identity pool configuration, not directly in the external IdP.

  • A. Correct.

    Correct. Creating a workload identity pool is the first step in configuring Workforce Identity Federation. This pool acts as the intermediary between Google Cloud and the external IdP.

  • B. Incorrect.

    Incorrect. Service accounts are not involved in the Workforce Identity Federation setup. The federation is meant to use existing user identities from the external IdP, not service accounts.

  • C. Correct.

    Correct. Defining an OIDC identity provider (or SAML, depending on the external IdP) within the workload identity pool is required to establish trust between the external IdP and Google Cloud.

  • D. Incorrect.

    Incorrect. Claim mapping is configured in the workload identity pool, not updated directly in the external IdP.

  • E. Correct.

    Correct. An IAM policy binding is necessary to assign permissions to the identities in the workload identity pool so they can access Google Cloud resources.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam