Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 98 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 98

Select 2Google Cloud Platform

Your organization wants to allow employees to access a third-party SaaS application using their Google Workspace credentials. The SaaS application supports SAML for single sign-on (SSO) and OAuth for API access. Which of the following steps should you take to implement this integration securely?

  1. A

    Configure the SaaS application as a SAML service provider and set up Google Workspace as the identity provider.

  2. B

    Generate OAuth 2.0 client credentials in Google Cloud and provide them to the SaaS application.

  3. C

    Enable SAML in Google Workspace Admin Console and share the metadata with the SaaS application.

  4. D

    Use a third-party OAuth provider to bridge the authentication between Google Workspace and the SaaS application.

  5. E

    Configure role-based access control (RBAC) in the SaaS application to restrict API access based on OAuth scopes.

Show answer and explanation

Correct answers: A, C

Explanation

To set up SAML-based SSO between Google Workspace and a third-party SaaS application, you need to configure the SaaS application as a SAML service provider and Google Workspace as the identity provider. Additionally, enabling SAML in the Google Workspace Admin Console and sharing metadata with the SaaS application is required to establish trust and ensure authentication flows are properly configured. OAuth and RBAC are not directly relevant to setting up SAML SSO in this context.

  • A. Correct.

    Correct: Configuring the SaaS application as a SAML service provider and Google Workspace as the identity provider is essential for enabling SAML-based SSO.

  • B. Incorrect.

    Incorrect: OAuth 2.0 client credentials are not required for SAML SSO. They are typically used for API access, which is not the focus of this question.

  • C. Correct.

    Correct: Enabling SAML in Google Workspace Admin Console and sharing metadata with the SaaS application is necessary to establish trust and enable SSO.

  • D. Incorrect.

    Incorrect: Using a third-party OAuth provider is unnecessary in this scenario, as Google Workspace supports both SAML and OAuth natively.

  • E. Incorrect.

    Incorrect: While RBAC is a good security practice, it is unrelated to the setup of SAML SSO between Google Workspace and the SaaS application.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam