PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #48
Your company works with an external Managed Service Provider (MSP) that requires its users to have the ability to list findings from Security Command Center (SCC) using the Google Cloud SDK. You…
The correct answer is D. Create a workforce identity pool and federate with the identity provider (IdP) of the managed. The best solution is to create a Workforce Identity Pool and federate with the MSP's IdP. This allows the MSP's users to authenticate with their own identity provider while receiving the necessary IAM roles in your environment. It minimizes your lifecycle management overhead…
Question
Your company works with an external Managed Service Provider (MSP) that requires its users to have the ability to list findings from Security Command Center (SCC) using the Google Cloud SDK. You need to configure the required access for the managed service provider while minimizing your involvement in their external user lifecycle management processes. What should you do?
Options
- ACreate a user account in your Cloud Identity instance using a subdomain indicating they are
- BCreate a service account in a SCC project. Grant the MSP user permission to impersonate this
- CCreate a workload identity pool in a SCC project. Grant the MSP user the permission to
- DCreate a workforce identity pool and federate with the identity provider (IdP) of the managed
How the community answered
(24 responses)- A8% (2)
- B13% (3)
- C4% (1)
- D75% (18)
Explanation
The best solution is to create a Workforce Identity Pool and federate with the MSP's IdP. This allows the MSP's users to authenticate with their own identity provider while receiving the necessary IAM roles in your environment. It minimizes your lifecycle management overhead since you don't need to create or manage individual external user accounts, while still providing secure, role-based access to SCC findings.
Topics
Community Discussion
No community discussion yet for this question.