nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #311

Your organization is using a third-party identity and authentication provider to centrally manage users. You want to use this identity provider to grant access to the Google Cloud console without…

The correct answer is A. Configure the central identity provider as a workforce identity pool provider in Workforce Identity. https://cloud.google.com/iam/docs/workforce-identity-federation Workforce Identity Federation lets you use an external identity provider (IdP) to authenticate and authorize a workforce - a group of users, such as employees, partners, and contractors - using IAM, so that the…

Submitted by layla.eg· Apr 18, 2026Configuring access within a cloud solution environment

Question

Your organization is using a third-party identity and authentication provider to centrally manage users. You want to use this identity provider to grant access to the Google Cloud console without syncing identities to Google Cloud. Users should receive permissions based on attributes. What should you do?

Options

  • AConfigure the central identity provider as a workforce identity pool provider in Workforce Identity
  • BConfigure a periodic synchronization of relevant users and groups with attributes to Cloud
  • CSet up the Google Cloud Identity Platform. Configure an external authentication provider by using
  • DActivate external identities on the Identity-Aware Proxy. Use the Security Assertion Markup

How the community answered

(32 responses)
  • A
    81% (26)
  • B
    6% (2)
  • C
    9% (3)
  • D
    3% (1)

Explanation

https://cloud.google.com/iam/docs/workforce-identity-federation Workforce Identity Federation lets you use an external identity provider (IdP) to authenticate and authorize a workforce - a group of users, such as employees, partners, and contractors - using IAM, so that the users can access Google Cloud services. With Workforce Identity Federation you don't need to synchronize user identities from your existing IdP to Google Cloud identities, as you would with Cloud Identity's Google Cloud Directory Sync (GCDS). Workforce Identity Federation extends Google Cloud's identity capabilities to support syncless, attribute-based single sign on.

Topics

#Workforce Identity Federation#Identity and Access Management (IAM)#Federated Identity#External IdP Integration

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice