Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 85 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 85

Single answerGoogle Cloud Platform

Your organization uses Google Cloud to host multiple applications. One of these applications requires secure user authentication using an identity federation setup, allowing users from your corporate Active Directory (AD) to access the application without creating new Google identities. As a Professional Cloud Security Engineer, how should you configure authentication for this requirement?

  1. A

    Set up Cloud Identity and configure SAML 2.0 federation with your corporate Active Directory (AD).

  2. B

    Enable Google Workspace and synchronize user accounts with Active Directory using Directory Sync.

  3. C

    Configure Identity-Aware Proxy (IAP) to authenticate users directly with your corporate Active Directory.

  4. D

    Use OAuth 2.0 to connect Active Directory with Google Cloud IAM for user authentication.

Show answer and explanation

Correct answer: A

Explanation

To enable secure user authentication using identity federation with a corporate Active Directory, the best approach is to set up Cloud Identity and configure SAML 2.0 federation. This allows users to authenticate with their corporate credentials without the need for separate Google identities, meeting the organization's requirements.

  • A. Correct.

    This is the correct approach. By setting up Cloud Identity and configuring SAML 2.0 federation, you can enable identity federation, allowing users to authenticate with their corporate AD credentials securely.

  • B. Incorrect.

    While Google Workspace can synchronize user accounts with Active Directory, it is not necessary for enabling identity federation. This approach does not meet the stated requirement of reusing AD credentials for authentication.

  • C. Incorrect.

    Identity-Aware Proxy (IAP) is used to secure access to applications but does not directly handle authentication with a corporate Active Directory in this scenario.

  • D. Incorrect.

    OAuth 2.0 is a protocol for authorization, not authentication, and cannot be used to connect Active Directory with Google Cloud IAM for this purpose.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam