Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A financial services organization federates its workforce identity architecture with Cloud Identity and manages access across multiple Google Cloud projects using group-based IAM bindings. The security team must implement a group lifecycle and access governance strategy that satisfies the following requirements:
Which combination of Google Cloud identity and governance capabilities should the organization implement?
Dynamic groups in Cloud Identity, combined with locked group security controls and IAM Recommender export to BigQuery, provide an automated, tamper-resistant group lifecycle and access review architecture.
jobTitle, department, or location) synced from the primary identity system.Groups Admin), preventing local group owners, managers, or members from manually altering memberships and causing configuration drift from the source of truth.REMOVE_ROLE recommendations allows security teams to query, aggregate, and review unused privileges and access across all folders and projects at an enterprise scale.This architecture completely eliminates manual provisioning overhead, enforces strict group integrity, and automates periodic access reviews using native Google Cloud Policy Intelligence and Cloud Identity capabilities.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.