PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #308
Your organization is developing an application that will have both corporate and public end-users. You want to centrally manage those customers' identities and authorizations. Corporate end users…
The correct answer is D. Use a customer identity and access management tool (CIAM) like Identity Platform. To centrally manage identities and authorizations for both corporate and public end-users of an application, enabling corporate users to access via their corporate credentials, you should use a customer identity and access management (CIAM) tool like Identity Platform.
Question
Options
- AAdd the corporate and public end-user domains to domain restricted sharing on the organization.
- BFederate the customers' identity provider (IdP) with Workforce Identity Federation in your
- CDo nothing. Google Workspace identities will allow you to filter personal accounts and disable
- DUse a customer identity and access management tool (CIAM) like Identity Platform.
How the community answered
(39 responses)- A3% (1)
- B13% (5)
- C5% (2)
- D79% (31)
Why each option
To centrally manage identities and authorizations for both corporate and public end-users of an application, enabling corporate users to access via their corporate credentials, you should use a customer identity and access management (CIAM) tool like Identity Platform.
Domain restricted sharing is a security policy to control resource sharing, not an identity management system for application end-users.
Workforce Identity Federation is for granting access to Google Cloud resources for external workforces (like partners or vendors), not primarily for managing end-user identities for custom applications.
Google Workspace identities are for an organization's internal employees and do not provide a general CIAM solution for both corporate and public end-users of a custom application.
Google Cloud Identity Platform is a CIAM solution designed for managing identities and authentication for applications, supporting various identity providers (including corporate federated identities for corporate users and social logins for public users) to centrally manage access for diverse customer bases.
Concept tested: Customer Identity and Access Management (CIAM)
Source: https://cloud.google.com/identity-platform/docs
Topics
Community Discussion
No community discussion yet for this question.