Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise configured SAML 2.0 federation with a third-party Identity Provider (IdP) using Workforce Identity Federation to allow external corporate users to access Google Cloud resources. After rolling out an update to the IdP's claim schema, several users report that they cannot sign in, receiving authorization errors during the token exchange process.
The security team needs to inspect the incoming SAML assertion claims, identify any mismatched attribute mappings (such as google.subject and google.groups), and verify why the token exchange is failing.
Which troubleshooting approach should the security engineer take?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.