nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #132

Your company has been creating users manually in Cloud Identity to provide access to Google Cloud resources. Due to continued growth of the environment, you want to authorize the Google Cloud…

The correct answer is A. 1. Configure the option to suspend domain users not found in LDAP. 2. Set up a recurring GCDS. To achieve the requirement "Disable any manually created users in Cloud Identity", configure GCDS to suspend rather than delete accounts if user accounts are not found in the LDAP directory in GCDS. Ref: https://support.google.com/a/answer/7177267

Submitted by alyssa_d· Apr 18, 2026Configuring access within a cloud solution environment

Question

Your company has been creating users manually in Cloud Identity to provide access to Google Cloud resources. Due to continued growth of the environment, you want to authorize the Google Cloud Directory Sync (GCDS) instance and integrate it with your on-premises LDAP server to onboard hundreds of users. You are required to: - Replicate user and group lifecycle changes from the on-premises LDAP server in Cloud Identity. - Disable any manually created users in Cloud Identity. You have already configured the LDAP search attributes to include the users and security groups in scope for Google Cloud. What should you do next to complete this solution?

Options

  • A
    1. Configure the option to suspend domain users not found in LDAP. 2. Set up a recurring GCDS
  • B
    1. Configure the option to delete domain users not found in LDAP. 2. Run GCDS after user and
  • C
    1. Configure the LDAP search attributes to exclude manually created Cloud Identity users not
  • D
    1. Configure the LDAP search attributes to exclude manually created Cloud Identity users not

How the community answered

(35 responses)
  • A
    71% (25)
  • B
    3% (1)
  • C
    9% (3)
  • D
    17% (6)

Explanation

To achieve the requirement "Disable any manually created users in Cloud Identity", configure GCDS to suspend rather than delete accounts if user accounts are not found in the LDAP directory in GCDS. Ref: https://support.google.com/a/answer/7177267

Topics

#Cloud Identity#Google Cloud Directory Sync (GCDS)#User Provisioning#Identity Synchronization

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice