Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 33 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 33

Select 4Google Cloud Platform

Your organization uses an external identity provider (IdP) to manage employee authentication. You need to configure Workforce Identity Federation on Google Cloud to allow employees to access Google Cloud resources without creating Google Cloud IAM users. Which of the following steps are required to properly configure Workforce Identity Federation?

  1. A

    Create an identity provider in Google Cloud using the configuration details of the external IdP.

  2. B

    Enable the 'Allow All OAuth Scopes' option to grant broad access to Google Cloud resources.

  3. C

    Add a workload identity pool and configure the external IdP with the pool ID.

  4. D

    Map external identities to Google Cloud roles by creating an IAM policy binding.

  5. E

    Configure the external IdP to issue tokens compatible with Google's token exchange endpoint.

Show answer and explanation

Correct answers: A, C, D, E

Explanation

To configure Workforce Identity Federation, you must establish trust between Google Cloud and the external IdP by creating an identity provider and configuring a workload identity pool. You also need to map external identities to specific Google Cloud roles using IAM policy bindings. Additionally, the external IdP must issue tokens that are compatible with Google's token exchange endpoint. Enabling 'Allow All OAuth Scopes' is not recommended as it unnecessarily broadens access and violates security best practices.

  • A. Correct.

    Correct: You need to create an identity provider in Google Cloud to establish trust between the external IdP and Google Cloud, enabling token exchange.

  • B. Incorrect.

    Incorrect: 'Allow All OAuth Scopes' is not a recommended or required step, as it goes against the principle of least privilege.

  • C. Correct.

    Correct: A workload identity pool is required to group identities from the external IdP and manage access to Google Cloud resources.

  • D. Correct.

    Correct: Mapping external identities to Google Cloud roles via IAM policy bindings allows you to define the permissions external users will have.

  • E. Correct.

    Correct: The external IdP must issue tokens that comply with Google's token exchange endpoint requirements so that the authentication process can succeed.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam