Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 89 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 89

Single answerGoogle Cloud Platform

Your organization uses Google Cloud to host a critical web application. To enhance security, you are tasked with implementing an authentication mechanism that ensures users cannot access the application unless they are authenticated via a third-party Identity Provider (IdP). Additionally, this authentication mechanism must support multi-factor authentication (MFA). Which of the following is the most appropriate approach to meet these requirements?

  1. A

    Configure Identity-Aware Proxy (IAP) with an external Identity Provider (IdP) that supports MFA.

  2. B

    Enable Cloud Identity and configure it to enforce password policies for all user accounts.

  3. C

    Use Google Cloud IAM roles to enforce authentication requirements for the application.

  4. D

    Set up a VPN to restrict access to the web application and require user authentication.

Show answer and explanation

Correct answer: A

Explanation

To ensure users authenticate via a third-party Identity Provider (IdP) with multi-factor authentication (MFA), Identity-Aware Proxy (IAP) is the appropriate tool. IAP enables secure access to applications hosted on Google Cloud by integrating with external IdPs that support advanced authentication mechanisms like MFA. This approach directly addresses the requirements outlined in the scenario, ensuring robust authentication and security for the web application.

  • A. Correct.

    This is the correct answer because Identity-Aware Proxy (IAP) provides an authentication layer for applications hosted on Google Cloud. By integrating IAP with a third-party Identity Provider (IdP) that supports MFA, you can enforce both authentication and MFA requirements.

  • B. Incorrect.

    This option is incorrect because enabling Cloud Identity and enforcing password policies does not directly integrate with an application or enforce third-party IdP authentication and MFA.

  • C. Incorrect.

    This option is incorrect because IAM roles are used for authorization, not authentication. IAM cannot directly enforce authentication via a third-party IdP or MFA.

  • D. Incorrect.

    This option is incorrect because setting up a VPN restricts network access but does not enforce authentication via a third-party IdP or MFA.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam