nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #357

There is a vendor who needs access to your company's Google Cloud environment. The vendor uses a third-party identity provider (IdP). You need to integrate this IdP with your company's Google Cloud…

The correct answer is C. Connect the vendor's IdP with Google Cloud using Workforce Identify Federation. Workforce Identity Federation lets you federate a third-party IdP (SAML or OIDC) so vendor users can sign in via SSO and get IAM access without provisioning or syncing Google identities, eliminating lifecycle management on your side.

Submitted by takeshi77· Apr 18, 2026Configuring access within a cloud solution environment

Question

There is a vendor who needs access to your company's Google Cloud environment. The vendor uses a third-party identity provider (IdP). You need to integrate this IdP with your company's Google Cloud environment to enable single sign-on (SSO) for the vendor's users in the most secure way. You don't want to manage any of the vendor users' lifecycle management. What should you do?

Options

  • AUse Google Cloud Directory Sync to synchronize user accounts from the IdP to Google
  • BDevelop a custom application that queries the IdP for user authentication and then
  • CConnect the vendor's IdP with Google Cloud using Workforce Identify Federation.
  • DCreate Google Cloud accounts for each user and synchronize their passwords with the third-party

How the community answered

(45 responses)
  • A
    4% (2)
  • B
    13% (6)
  • C
    73% (33)
  • D
    9% (4)

Explanation

Workforce Identity Federation lets you federate a third-party IdP (SAML or OIDC) so vendor users can sign in via SSO and get IAM access without provisioning or syncing Google identities, eliminating lifecycle management on your side.

Topics

#Workforce Identity Federation#SSO#External Identities#IAM

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice