nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #295

Your organization is migrating business critical applications to Google Cloud across multiple projects. You only have the required IAM permission at the Google Cloud organization level. You want to…

The correct answer is C. Create two workforce identity pools for the partner IdPs. To grant project access to support engineers from partner organizations using their existing identity providers, create two workforce identity pools, one for each partner IdP.

Submitted by haruto_sh· Apr 18, 2026Configuring access within a cloud solution environment

Question

Your organization is migrating business critical applications to Google Cloud across multiple projects. You only have the required IAM permission at the Google Cloud organization level. You want to grant project access to support engineers from two partner organizations using their existing identity provider (IdP) credentials. What should you do?

Options

  • ACreate two single sign-on (SSO) profiles for the internal and partner IdPs by using SSO for Cloud
  • BCreate users manually by using the Google Cloud console. Assign the users to groups.
  • CCreate two workforce identity pools for the partner IdPs.
  • DSync user identities from their existing IdPs to Cloud Identity by using Google Cloud Directory

How the community answered

(50 responses)
  • A
    4% (2)
  • B
    8% (4)
  • C
    72% (36)
  • D
    16% (8)

Why each option

To grant project access to support engineers from partner organizations using their existing identity providers, create two workforce identity pools, one for each partner IdP.

ACreate two single sign-on (SSO) profiles for the internal and partner IdPs by using SSO for Cloud

SSO for Cloud Identity is typically used to federate your internal corporate directory with Google Cloud identities for your employees, not primarily for directly onboarding external partner organizations.

BCreate users manually by using the Google Cloud console. Assign the users to groups.

Manually creating users in the Google Cloud console for partner engineers is not scalable and bypasses their existing IdP credentials, which is explicitly a requirement.

CCreate two workforce identity pools for the partner IdPs.Correct

Workforce Identity Pools, part of Workforce Identity Federation, are designed specifically for external identities like partner organizations to access Google Cloud resources using their existing identity providers (IdPs), without needing Google identities managed by your Cloud Identity account.

DSync user identities from their existing IdPs to Cloud Identity by using Google Cloud Directory

Google Cloud Directory Sync (GCDS) is used to synchronize user identities from an on-premises directory to Cloud Identity, typically for an organization's own employees, not for federating external partner organizations' IdPs.

Concept tested: Workforce Identity Federation for partners

Source: https://cloud.google.com/identity/docs/enable-workforce-federation

Topics

#Workforce Identity Federation#IAM#External Identities#IdP Integration

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice