Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An organization is designing an automated identity synchronization architecture between their on-premises Active Directory Domain Services (AD DS) forest and Cloud Identity to enable workforce access to Google Cloud resources. The security team establishes the following requirements:
Which architectural and configuration approach should the organization implement?
Google Cloud Directory Sync (GCDS) is an on-premises synchronization tool that connects to an LDAP directory (such as Active Directory) to provision and synchronize users, groups, and organizational units into Cloud Identity or Google Workspace. GCDS performs one-way synchronization of identity metadata via the Google Directory API without reading or synchronizing user passwords.
This architecture combines automated metadata synchronization via GCDS with delegated authentication via SAML SSO, perfectly satisfying corporate data governance, zero password leakage, and disaster recovery requirements.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.