nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #25

You need to provide a corporate user account in Google Cloud for each of your developers and operational staff who need direct access to GCP resources. Corporate policy requires you to maintain the…

The correct answer is A. Use Google Cloud Directory Sync to synchronize your local identity management system to Cloud D. Use the Transfer Tool for Unmanaged Users (TTUU) to find users with conflicting accounts and. Two actions are required: (A) Use Google Cloud Directory Sync (GCDS) to synchronize identities from the corporate LDAP/IdP to Google Cloud IAM, which enables SSO federation and keeps the authoritative identity in the third-party provider as required by policy. (D) Use the…

Submitted by skyler.x· Apr 18, 2026Configuring access within a cloud solution environment

Question

You need to provide a corporate user account in Google Cloud for each of your developers and operational staff who need direct access to GCP resources. Corporate policy requires you to maintain the user identity in a third-party identity management provider and leverage single sign- on. You learn that a significant number of users are using their corporate domain email addresses for personal Google accounts, and you need to follow Google recommended practices to convert existing unmanaged users to managed accounts. Which two actions should you take? (Choose two.)

Options

  • AUse Google Cloud Directory Sync to synchronize your local identity management system to Cloud
  • BUse the Google Admin console to view which managed users are using a personal account for
  • CAdd users to your managed Google account and force users to change the email addresses
  • DUse the Transfer Tool for Unmanaged Users (TTUU) to find users with conflicting accounts and
  • ESend an email to all of your employees and ask those users with corporate email addresses for

How the community answered

(33 responses)
  • A
    85% (28)
  • B
    3% (1)
  • C
    3% (1)
  • E
    9% (3)

Explanation

Two actions are required: (A) Use Google Cloud Directory Sync (GCDS) to synchronize identities from the corporate LDAP/IdP to Google Cloud IAM, which enables SSO federation and keeps the authoritative identity in the third-party provider as required by policy. (D) Use the Transfer Tool for Unmanaged Users (TTUU), which is Google's recommended tool for identifying users who have created personal Google accounts using a corporate email address and converting them to managed accounts under the corporate domain. Option B uses the Admin console to view managed users but does not address unmanaged/personal accounts. Option C forcibly changes email addresses, which is disruptive and not the recommended approach. Option E (sending emails manually) is not a technical solution and does not follow Google best practices.

Topics

#Identity Management#Single Sign-On#User Provisioning#Conflicting Accounts

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice