Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 34 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 34

Select 3Google Cloud Platform

Your organization wants to allow its employees to access Google Cloud resources using their existing third-party identity provider (IdP) without creating Google accounts for each employee. You have decided to use Workforce Identity Federation for this purpose. Which of the following steps are required to configure Workforce Identity Federation in Google Cloud?

  1. A

    Create a Workforce Identity Federation pool and configure a provider for the third-party IdP.

  2. B

    Grant the 'roles/iam.workloadIdentityUser' role to the users in the Workforce Identity Federation pool.

  3. C

    Establish a trust relationship between the third-party IdP and the Workforce Identity Federation pool by enabling OpenID Connect (OIDC) or SAML.

  4. D

    Create a service account and associate it directly with the third-party IdP.

  5. E

    Configure IAM policies on Google Cloud resources to allow access based on identities from the Workforce Identity Federation pool.

Show answer and explanation

Correct answers: A, C, E

Explanation

To configure Workforce Identity Federation, you must first create a pool and a provider for your third-party IdP. A trust relationship must be established using protocols like OIDC or SAML. Finally, IAM policies must be set up on Google Cloud resources to recognize and grant access to identities from the Workforce Identity Federation pool. Steps like granting roles for Workload Identity Federation or associating service accounts with the IdP are unrelated to this process and are not required.

  • A. Correct.

    This is correct. Creating a Workforce Identity Federation pool and configuring a provider for the third-party IdP is a necessary step to enable identity federation.

  • B. Incorrect.

    This is incorrect. The 'roles/iam.workloadIdentityUser' role is used for Workload Identity Federation, not Workforce Identity Federation, which is specific to human users.

  • C. Correct.

    This is correct. Establishing a trust relationship between the third-party IdP and the Workforce Identity Federation pool is required, and this is typically done using OIDC or SAML protocols.

  • D. Incorrect.

    This is incorrect. Service accounts are not directly associated with the third-party IdP in Workforce Identity Federation. Instead, human identities from the IdP are mapped to the pool.

  • E. Correct.

    This is correct. Configuring IAM policies on Google Cloud resources to recognize and permit access to identities from the Workforce Identity Federation pool is necessary to manage access control.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam