Cloud Digital Leader Exam QuestionsBrowse all questions from this exam

Cloud Digital Leader Exam - Question 15


Your organization uses Active Directory to authenticate users. Users' Google account access must be removed when their Active Directory account is terminated.

How should your organization meet this requirement?

Show Answer
Correct Answer: D

To ensure that users' Google account access is automatically removed when their Active Directory account is terminated, configuring single sign-on (SSO) in the Google domain is the most effective solution. This approach centralizes user authentication and management, leveraging Active Directory as the authoritative source. When a user's Active Directory account is deactivated, their Google account access will also be revoked, as the SSO setup relies on Active Directory for authentication.

Discussion

17 comments
Sign in to comment
JCEOption: D
Jan 7, 2022

D seems correct https://cloud.google.com/architecture/identity/federating-gcp-with-active-directory-configuring-single-sign-on

cookieMrOption: D
Jun 10, 2023

SSO allows for centralized user management, where user accounts and access permissions are managed in a single identity provider (such as Active Directory). When a user's Active Directory account is terminated, SSO provides a centralized point to revoke access across multiple applications and services, including Google accounts.

ucsdmiami2020Option: D
Dec 5, 2022

Per Google Docs article, Federating Google Cloud with Active Directory. "This article describes how you can configure Cloud Identity or Google Workspace to use Active Directory as IdP and authoritative source. The article compares the logical structure of Active Directory with the structure used by Cloud Identity and Google Workspace and describes how you can map Active Directory forests, domains, users, and groups. The article also provides a flowchart that helps you determine the best mapping approach for your scenario." https://cloud.google.com/architecture/identity/federating-gcp-with-active-directory-introduction

MonicaargOption: D
May 15, 2022

Your organization uses Active Directory to authenticate users. Then you need to use Single sign-on (SSO) is an authentication scheme that allows a user to log in with a single ID and password to different systems and software. SSO allows IT departments to administrator a single identity that can access many machines and cloud services.

SimonIt73
Nov 9, 2022

The correct answer should be "Setting up federation between Active Directory and Cloud Identity or Google Workspace". To do that, you have to enable automatic users provisioning and SSO.

ronietoOption: D
Nov 20, 2022

SSO means federation between AD and Cloud ID, so is the correct answer

haroldbenitesOption: D
Jun 18, 2022

Go for D

rikininetysixOption: C
Oct 15, 2022

The question asked to provide a solution to remove users' Google account access when their Active Directory account is terminated. So, option 'C' should be correct as BeyondCorp and Identity Aware Proxy are focused solutions to mage Identity and implement a Zero trust model.

hogtrough
Oct 24, 2022

The correct answer is D. If you have SSO configured, once a user's AD account is terminated, their access is removed from all services using AD.

NU_1234Option: D
Apr 1, 2022

SSO is the answer

Pou1zeOption: D
Dec 2, 2022

D is correct

KanikaAOption: D
Feb 8, 2023

Using SSO would help in removing access once the account is no longer active.

star2anandOption: D
Mar 21, 2023

D. Configure single sign-on in the Google domain

mdsarfraz69Option: D
Sep 25, 2023

D is correct

RajanOption: D
Oct 11, 2023

SSO is correct as deletion of AD account will remove access from GCP as well.

chai_gptOption: D
Nov 5, 2023

D is correct

SurekOption: D
Dec 25, 2023

Answer is D

joe03Option: D
Jul 6, 2024

When you use SSO, you are redirected to an external Identity Provider. In this question, it is Microsoft AD. SAML assertion is sent to Google Cloud once the user is authenticated.