Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise uses Microsoft Entra ID as its authoritative identity provider (IdP) and federates authentication to Google Cloud using SAML Single Sign-On (SSO). The organization is designing an automated user lifecycle management architecture to synchronize employee provisioning, security group assignments for IAM access, and deprovisioning workflows upon employee departure.
The security team establishes the following design requirements:
Which solution should the enterprise implement?
Automated user lifecycle management between an external Identity Provider (Microsoft Entra ID) and Google Cloud Identity relies on System for Cross-domain Identity Management (SCIM) protocols. This architecture uses a dedicated provisioning service account in Cloud Identity to synchronize user identities, group memberships, and lifecycle status changes from the authoritative identity source into Google Cloud.
Users, Groups, and Organization Units > Read—allows the provisioning user (azuread-provisioning) to manage standard users and security groups without granting unrestricted super-admin privileges across the Google Cloud organization.This architecture establishes a secure, least-privilege administrative bridge while guaranteeing that deprovisioning signals in the authoritative directory immediately invalidate all access pathways into Google Cloud.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.