Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise is integrating its corporate third-party Identity Provider (IdP) with Google Cloud using Cloud Identity as a Service Provider (SP). The security architect must satisfy the following technical requirements:
Which configuration strategy should the architect implement in Cloud Identity?
This configuration establishes a federated SAML 2.0 authentication trust between an external Identity Provider (IdP) and Cloud Identity acting as the Service Provider (SP), while using granular Organizational Unit (OU) policy assignments and session controls to enforce least privilege, resilience, and automated onboarding.
NameID and core user attributes) and dynamically instantiate new user accounts upon first successful logon without pre-synchronizing via GCDS.accounts.google.com/a/), super administrators can authenticate natively using local credentials if the third-party IdP suffers downtime.This architecture directly addresses identity lifecycle, security enforcement, and high availability by using native Cloud Identity features without introducing unnecessary external proxies or unmanaged credential silos.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.