Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Google Professional Cloud Security Engineer Exam - Topic 1 Question 119 Discussion

While migrating your organization's infrastructure to GCP, a large number of users will need to access GCP Console. The Identity Management team already has a well-established way to manage your users and want to keep using your existing Active Directory or LDAP server along with the existing SSO password.What should you do?
B) Use Google Cloud Directory Sync to synchronize the data in Google domain with your existing Active Directory or LDAP server.
A) Manually synchronize the data in Google domain with your existing Active Directory or LDAP server.
C) Users sign in directly to the GCP Console using the credentials from your on-premises Kerberos compliant identity provider.
D) Users sign in using OpenID (OIDC) compatible IdP, receive an authentication token, then use that token to log in to the GCP Console.

Google Professional Cloud Security Engineer Exam - Topic 1 Question 119 Discussion

Actual exam question for Google's Professional Cloud Security Engineer exam
Question #: 119
Topic #: 1
[All Professional Cloud Security Engineer Questions]

While migrating your organization's infrastructure to GCP, a large number of users will need to access GCP Console. The Identity Management team already has a well-established way to manage your users and want to keep using your existing Active Directory or LDAP server along with the existing SSO password.

What should you do?

Show Suggested Answer Hide Answer
Suggested Answer: B

To allow a large number of users to access the GCP Console while keeping the existing Active Directory or LDAP server for identity management, use Google Cloud Directory Sync (GCDS).

Install GCDS:

Download and install Google Cloud Directory Sync from here.

Configure GCDS:

Set up the synchronization by specifying the LDAP server details and the Google domain.

Map the LDAP attributes to Google attributes to ensure user data is synchronized correctly.

Run Synchronization:

Perform an initial synchronization to populate the Google domain with existing users from the LDAP server.

Schedule regular synchronizations to keep the data up-to-date.

Benefits:

Automated Sync: Ensures that user data is consistently updated without manual intervention.

Secure Access: Users can log in to the GCP Console using their existing credentials, enhancing security and user experience.

Google Cloud Directory Sync Documentation

GCDS Administration Guide


Contribute your Thoughts:

0/2000 characters
Willard
2 days ago
C sounds interesting, but is it really secure enough?
upvoted 0 times
...
Twanna
7 days ago
I think A is too much manual work, not efficient.
upvoted 0 times
...
Brande
12 days ago
B is the way to go, super easy sync!
upvoted 0 times
...
Yvonne
18 days ago
I recall that using an OIDC compatible IdP could simplify the login process, but I’m not sure if it’s the best choice for our existing setup.
upvoted 0 times
...
Rosalind
23 days ago
I’m a bit confused about the Kerberos option. I know it’s secure, but does it really integrate well with GCP?
upvoted 0 times
...
Pete
28 days ago
I think Google Cloud Directory Sync sounds familiar from our practice questions. It might be the most efficient option for keeping everything in sync.
upvoted 0 times
...
Emogene
1 month ago
I remember discussing the importance of synchronizing user data, but I'm not sure if manual synchronization is the best approach.
upvoted 0 times
...

Save Cancel