nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #29

A customer wants to use Cloud Identity as their primary IdP. The customer wants to use other non-GCP SaaS products for CRM, messaging, and customer ticketing management. The customer also wants to…

The correct answer is B. Configure third-party applications to federate authentication and authorization to the GCP IdP. A is not correct because Users should continue to be in Cloud Identity as central source of truth. B is correct because cloud identity will serve as SAML auth for third party apps. C is not correct because it doesn't help to automate user provisioning. D is not correct because…

Submitted by fatima_kr· Apr 18, 2026Configuring access within a cloud solution environment

Question

A customer wants to use Cloud Identity as their primary IdP. The customer wants to use other non-GCP SaaS products for CRM, messaging, and customer ticketing management. The customer also wants to improve employee experience with Single Sign-On (SSO) capabilities to securely access GCP and non-GCP applications. Only authorized individuals should be able to access these third-party applications. What action should the customer take to meet these requirements?

Options

  • ARemove the employee from Cloud Identity, set the correct license for the individuals, and resync
  • BConfigure third-party applications to federate authentication and authorization to the GCP IdP.
  • CRemove the individuals from the third-party applications, add the license to Cloud Identity, and
  • DCopy user personas from Cloud Identity to all third-party applications for the domain.

How the community answered

(34 responses)
  • A
    9% (3)
  • B
    79% (27)
  • C
    3% (1)
  • D
    9% (3)

Explanation

A is not correct because Users should continue to be in Cloud Identity as central source of truth. B is correct because cloud identity will serve as SAML auth for third party apps. C is not correct because it doesn't help to automate user provisioning. D is not correct because it doesn't help to automate user provisioning and deprovisioning on a continual basis. https://cloud.google.com/identity/solutions/enable-sso

Topics

#Cloud Identity#SSO#Identity Federation#Third-party Application Integration

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice