CLOUD-DIGITAL-LEADER · Question #291
Your organization uses Active Directory to authenticate users. Users' Google account access must be removed when their Active Directory account is terminated. How should your organization meet this…
The correct answer is D. Configure single sign-on in the Google domain. Configuring Single Sign-On (SSO) between the Google domain and Active Directory (using Google Cloud Directory Sync and SAML federation) means Google authentication is delegated to Active Directory as the identity provider. When an employee's Active Directory account is disabled…
Question
Your organization uses Active Directory to authenticate users. Users' Google account access must be removed when their Active Directory account is terminated. How should your organization meet this requirement?
Options
- AConfigure two-factor authentication in the Google domain
- BRemove the Google account from all IAM policies
- CConfigure BeyondCorp and Identity-Aware Proxy in the Google domain
- DConfigure single sign-on in the Google domain
How the community answered
(51 responses)- A2% (1)
- B6% (3)
- C10% (5)
- D82% (42)
Explanation
Configuring Single Sign-On (SSO) between the Google domain and Active Directory (using Google Cloud Directory Sync and SAML federation) means Google authentication is delegated to Active Directory as the identity provider. When an employee's Active Directory account is disabled or terminated, they can no longer authenticate via SSO, which immediately revokes their access to all Google services. This provides automatic, centralized access revocation. Option B (removing from IAM policies) would be a manual, error-prone process across every policy. Option A (two-factor authentication) adds a security layer but doesn't automate deprovisioning. Option C (BeyondCorp/IAP) controls access to specific applications but doesn't centrally revoke Google account authentication.
Topics
Community Discussion
No community discussion yet for this question.