Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A security engineer is troubleshooting a newly deployed SAML 2.0 single sign-on (SSO) integration between an external Identity Provider (IdP) and Cloud Identity for workforce access to Google Cloud.
During testing, provisioned users authenticate successfully at the external IdP login screen. However, upon being redirected to Google Sign-In, the authentication process fails and returns an identity resolution error. A review of the SAML response XML and directory settings reveals the following:
contains a element with the value John.Doe@example.com.john.doe@example.com and an email alias jdoe@example.com.email set to john.doe@example.com and a groups claim containing gcp-engineers.What is causing this authentication failure, and how should it be resolved?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.