Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 84 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 84

Single answerGoogle Cloud Platform

Your organization uses Google Cloud and wants to ensure secure authentication practices for internal applications. The security team requires that users authenticate using their company's identity provider (IdP) while maintaining granular control over access to resources. Which authentication approach should you recommend?

  1. A

    Use Google Cloud Identity-Aware Proxy (IAP) with the company IdP for Single Sign-On (SSO)

  2. B

    Create service account keys and share them with users to authenticate

  3. C

    Use Google-managed OAuth 2.0 tokens without integrating the company IdP

  4. D

    Implement a custom authentication mechanism using client-side certificates

Show answer and explanation

Correct answer: A

Explanation

To meet the organization's requirements for secure authentication and granular access control, integrating the company's IdP with Google Cloud Identity-Aware Proxy (IAP) is the best solution. IAP allows the organization to enforce authentication via SSO through their IdP while controlling access to specific applications and resources using IAM policies.

  • A. Correct.

    This is the correct approach. Google Cloud Identity-Aware Proxy (IAP) integrates with external identity providers to enforce user authentication and access control. Using the company IdP ensures users authenticate securely via SSO, and granular controls can be managed through IAP policies.

  • B. Incorrect.

    Service account keys should not be used for user authentication as they are intended for application-to-application communication. Sharing keys with users introduces significant security risks and is not a best practice.

  • C. Incorrect.

    Using Google-managed OAuth 2.0 tokens without integrating the company IdP does not meet the requirement of using the organization's identity provider. This approach also lacks the desired level of granular control.

  • D. Incorrect.

    Implementing a custom authentication mechanism using client-side certificates is complex, error-prone, and unnecessary when Google Cloud provides built-in solutions like IAP that integrate with external IdPs.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam