Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Google Professional Cloud Security Engineer Exam - Topic 1 Question 120 Discussion

A customer wants to make it convenient for their mobile workforce to access a CRM web interface that is hosted on Google Cloud Platform (GCP). The CRM can only be accessed by someone on the corporate network. The customer wants to make it available over the internet. Your team requires an authentication layer in front of the application that supports two-factor authenticationWhich GCP product should the customer implement to meet these requirements?
A) Cloud Identity-Aware Proxy
B) Cloud Armor
C) Cloud Endpoints
D) Cloud VPN

Google Professional Cloud Security Engineer Exam - Topic 1 Question 120 Discussion

Actual exam question for Google's Professional Cloud Security Engineer exam
Question #: 120
Topic #: 1
[All Professional Cloud Security Engineer Questions]

A customer wants to make it convenient for their mobile workforce to access a CRM web interface that is hosted on Google Cloud Platform (GCP). The CRM can only be accessed by someone on the corporate network. The customer wants to make it available over the internet. Your team requires an authentication layer in front of the application that supports two-factor authentication

Which GCP product should the customer implement to meet these requirements?

Show Suggested Answer Hide Answer
Suggested Answer: A

Cloud Identity-Aware Proxy (Cloud IAP) provides a way to control access to your web applications and resources running on Google Cloud. It works by verifying the identity of a user trying to access the application and supports multi-factor authentication (MFA). Cloud IAP can restrict access to users on the corporate network and also supports access over the internet securely.

Steps:

Enable Cloud IAP: In the Google Cloud Console, navigate to the IAP section and enable IAP for your web application.

Configure OAuth Consent Screen: Set up the OAuth consent screen to manage how users grant access.

Set Up Authentication: Use Google Identity Platform to manage users and enable two-factor authentication.

Add Users: Grant users access to the application by adding their identities in the IAP settings.


Google Cloud: Identity-Aware Proxy

Setting up IAP

Contribute your Thoughts:

0/2000 characters
Jeannetta
1 day ago
Isn't Cloud Endpoints more for API management? Not sure it fits here.
upvoted 0 times
...
Lettie
7 days ago
Totally agree, IAP is the way to go for secure access!
upvoted 0 times
...
Val
12 days ago
Wait, can Cloud Armor handle authentication? I doubt it.
upvoted 0 times
...
Moira
17 days ago
I think Cloud VPN could work too, but not ideal for web access.
upvoted 0 times
...
Heike
22 days ago
Definitely Cloud Identity-Aware Proxy for that setup.
upvoted 0 times
...
Sheridan
27 days ago
Cloud Armor seems more focused on security against attacks, so I doubt it's the right choice for this scenario.
upvoted 0 times
...
Lenna
1 month ago
I feel like we practiced a similar question where we discussed how Cloud Identity-Aware Proxy could help with remote access.
upvoted 0 times
...
Jolene
1 month ago
I'm not entirely sure, but I remember something about Cloud VPN being more about secure connections rather than authentication layers.
upvoted 0 times
...
Claribel
1 month ago
I think the answer might be Cloud Identity-Aware Proxy since it provides access control and supports two-factor authentication.
upvoted 0 times
...

Save Cancel