Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise is configuring automated synchronization from Microsoft Entra ID to Cloud Identity to manage security groups and enforce least-privilege access policies across Google Cloud resources. The corporate security policy specifies the following requirements:
Which configuration should the administrator implement to meet these requirements?
Grant the Identity Platform Admin role (roles/identityplatform.admin) to the provisioning user and configure SAML group attribute mapping during user login.
Assign the IAM Security Admin role (roles/iam.securityAdmin) at the organization node to the provisioning user, and set up dynamic groups using CEL queries.
Create a custom delegated administrator role with Admin API privileges enabled for Organization Units (Read), Users, and Groups for the provisioning user, and configure the groups as enforcement groups.
Grant the super-admin role to the provisioning user and configure the provisioned groups as standard access groups with domain-wide delegation enabled.
Grant the Identity Platform Admin role (roles/identityplatform.admin) to the provisioning user and configure SAML group attribute mapping during user login.
Assign the IAM Security Admin role (roles/iam.securityAdmin) at the organization node to the provisioning user, and set up dynamic groups using CEL queries.
Create a custom delegated administrator role with Admin API privileges enabled for Organization Units (Read), Users, and Groups for the provisioning user, and configure the groups as enforcement groups.
This configuration establishes a delegated administrator role in the Google Admin Console with specific Admin API privileges and utilizes enforcement groups to secure membership and prevent policy circumvention.
azuread-provisioning) strictly to the required API permissions: Organization Units > Read, Users, and Groups.Delegated administration provides the exact administrative boundary required for external directory synchronization, satisfying least privilege while enforcement groups ensure that context-aware access and IAM policies cannot be bypassed by end-user actions.
Grant the super-admin role to the provisioning user and configure the provisioned groups as standard access groups with domain-wide delegation enabled.