Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A global enterprise is integrating an external third-party Identity Provider (IdP) with Google Cloud to manage access for external security analysts. The security team has defined several key requirements:
Which identity and access architecture should the security engineer implement?
Workforce Identity Federation allows third-party identity providers (such as Okta, Microsoft Entra ID, or SAML 2.0/OIDC-compliant IdPs) to authenticate users directly into Google Cloud without requiring synchronized or managed Cloud Identity accounts. Privileged Access Manager (PAM) is an access governance service that manages just-in-time, time-bound privilege elevation with automated workflows and audit logging.
google.groups attribute in the workforce pool provider configuration (e.g., google.groups=assertion.attributes.groups), administrators can grant IAM roles to entire principal groups using principalSet://iam.googleapis.com/locations/global/workforcePools/.../group/GROUP_NAME.iam.serviceAccounts.actAs or token generation), PAM enables temporary, scoped role grants that automatically expire and leave detailed audit logs.Direct principal binding combined with PAM provides granular, auditable least privilege while eliminating credential synchronization overhead and avoiding the security risks associated with shared service accounts.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.