Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam Professional Cloud Security Engineer topic 1 question 156 discussion

Actual exam question from Google's Professional Cloud Security Engineer
Question #: 156
Topic #: 1
[All Professional Cloud Security Engineer Questions]

Your company plans to move most of its IT infrastructure to Google Cloud. They want to leverage their existing on-premises Active Directory as an identity provider for Google Cloud. Which two steps should you take to integrate the company's on-premises Active Directory with Google Cloud and configure access management? (Choose two.)

  • A. Use Identity Platform to provision users and groups to Google Cloud.
  • B. Use Cloud Identity SAML integration to provision users and groups to Google Cloud.
  • C. Install Google Cloud Directory Sync and connect it to Active Directory and Cloud Identity.
  • D. Create Identity and Access Management (IAM) roles with permissions corresponding to each Active Directory group.
  • E. Create Identity and Access Management (IAM) groups with permissions corresponding to each Active Directory group.
Show Suggested Answer Hide Answer
Suggested Answer: BC 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
GHOST1985
Highly Voted 1 year, 7 months ago
Selected Answer: CE
https://cloud.google.com/architecture/identity/federating-gcp-with-active-directory-synchronizing-user-accounts?hl=en https://cloud.google.com/architecture/identity/federating-gcp-with-active-directory-synchronizing-user-accounts?hl=en#deciding_where_to_deploy_gcds
upvoted 8 times
Test114
1 year, 7 months ago
How about BE? https://cloud.google.com/architecture/identity/federating-gcp-with-active-directory-introduction "Single sign-on: Whenever a user needs to authenticate, Google Cloud delegates the authentication to Active Directory by using the Security Assertion Markup Language (SAML) protocol."
upvoted 1 times
zellck
1 year, 7 months ago
SAML is used for authentication, not provisioning.
upvoted 4 times
...
...
AzureDP900
1 year, 6 months ago
CE sounds good
upvoted 2 times
...
...
AwesomeGCP
Highly Voted 1 year, 7 months ago
Selected Answer: CE
C. Install Google Cloud Directory Sync and connect it to Active Directory and Cloud Identity. E. Create Identity and Access Management (IAM) groups with permissions corresponding to each Active Directory group.
upvoted 6 times
...
Roro_Brother
Most Recent 1 week, 6 days ago
Selected Answer: CD
GCDS is already creating the groups automatically. We need to create the IAM roles to assign to those groups. So D, not E
upvoted 1 times
...
Bettoxicity
1 month, 2 weeks ago
Selected Answer: CD
CD Why not E?: IAM groups in Google Cloud are separate entities from IAM roles. While you could create IAM groups that mirror Active Directory groups, directly mapping permissions to IAM roles based on the corresponding Active Directory groups offers a more efficient and granular approach to access control.
upvoted 1 times
...
glb2
1 month, 3 weeks ago
Selected Answer: CD
Answer is C and D.
upvoted 1 times
...
PTC231
2 months, 2 weeks ago
ANSWER C and E C. Install Google Cloud Directory Sync and connect it to Active Directory and Cloud Identity: Google Cloud Directory Sync (GCDS) is used to synchronize user and group information from on-premises Active Directory to Google Cloud Identity. This step ensures that user and group information is consistent across both environments. E. Create Identity and Access Management (IAM) groups with permissions corresponding to each Active Directory group: Once the synchronization is set up, you can create IAM groups in Google Cloud that mirror the Active Directory groups. Assign permissions to these IAM groups based on the roles and access levels required for each group. This approach simplifies access management by aligning Google Cloud permissions with existing Active Directory groups.
upvoted 2 times
...
PhuocT
2 months, 3 weeks ago
Selected Answer: CD
C and D I think, we don't need to create group, as it will be synced from AD, we only need to focus on creating the role for the group.
upvoted 2 times
...
desertlotus1211
3 months, 1 week ago
Answers: B & C... There is NO such thing as IAM groups in GCP
upvoted 1 times
...
mjcts
3 months, 1 week ago
Selected Answer: CD
GCDS is already creating the groups automatically. We need to create the IAM roles to assign to those groups. So D, not E
upvoted 2 times
...
GoReplyGCPExam
4 months, 1 week ago
Bard says CE. User and Groups are already imported with GCDS, so you need to focus on creating roles
upvoted 1 times
...
aygitci
7 months, 1 week ago
Selected Answer: CD
Not Ek as the groups are already synced and retrieved, so roles will be attached to them
upvoted 5 times
...
gkarthik1919
7 months, 3 weeks ago
CE are seems to be coorect. B is required only for SSO. GCDS would also provision user and group.
upvoted 1 times
...
Mithung30
9 months, 1 week ago
Selected Answer: CD
CD is correct
upvoted 3 times
...
a190d62
9 months, 2 weeks ago
Selected Answer: CD
There is a possibility to synchronize groups between AD and Google Cloud so why not to use it and focus on creating roles https://cloud.google.com/architecture/identity/federating-gcp-with-active-directory-introduction?hl=en#mapping_groups
upvoted 2 times
...
tauseef71
1 year, 2 months ago
CD is the right answer. C> sync with AD user and groups ; D> give users and groups the roles in IAM.
upvoted 4 times
...
theereechee
1 year, 4 months ago
Selected Answer: BD
GCDS is required to sync users and groups. Once these get synced, you don't need E anymore because the groups will already be available in cloud identity. The next thing will be to map (create) roles to the groups already available in Active Directory.
upvoted 1 times
theereechee
1 year, 4 months ago
I meant C and D
upvoted 2 times
...
...
rotorclear
1 year, 7 months ago
Selected Answer: BC
Roles should be provided by Auth provider
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...