Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A global enterprise is integrating an external third-party Identity Provider (IdP) with Google Cloud to manage access for external security analysts. The security team has defined several key requirements:
Which identity and access architecture should the security engineer implement?
Configure Workforce Identity Federation to map all external assertion identities to a shared central service account and grant analysts the Service Account Token Creator role.
Create individual user accounts in Cloud Identity, place analysts into self-managed access groups, and apply overlapping context-aware access bindings across multiple group tiers.
Configure a Workforce Identity Federation pool provider mapping google.subject and google.groups to IdP assertions, grant IAM roles directly to federated principal sets, and use Privileged Access Manager (PAM) for time-bound privilege elevation.
Assign Compute Instance Admin roles at the project level and populate instance metadata with external SSH public keys for direct host-level authentication.
Configure Workforce Identity Federation to map all external assertion identities to a shared central service account and grant analysts the Service Account Token Creator role.
Create individual user accounts in Cloud Identity, place analysts into self-managed access groups, and apply overlapping context-aware access bindings across multiple group tiers.
Configure a Workforce Identity Federation pool provider mapping google.subject and google.groups to IdP assertions, grant IAM roles directly to federated principal sets, and use Privileged Access Manager (PAM) for time-bound privilege elevation.
Workforce Identity Federation allows third-party identity providers (such as Okta, Microsoft Entra ID, or SAML 2.0/OIDC-compliant IdPs) to authenticate users directly into Google Cloud without requiring synchronized or managed Cloud Identity accounts. Privileged Access Manager (PAM) is an access governance service that manages just-in-time, time-bound privilege elevation with automated workflows and audit logging.
google.groups attribute in the workforce pool provider configuration (e.g., google.groups=assertion.attributes.groups), administrators can grant IAM roles to entire principal groups using principalSet://iam.googleapis.com/locations/global/workforcePools/.../group/GROUP_NAME.iam.serviceAccounts.actAs or token generation), PAM enables temporary, scoped role grants that automatically expire and leave detailed audit logs.Direct principal binding combined with PAM provides granular, auditable least privilege while eliminating credential synchronization overhead and avoiding the security risks associated with shared service accounts.
Assign Compute Instance Admin roles at the project level and populate instance metadata with external SSH public keys for direct host-level authentication.