Medium1 markMultiple Choice
Domain 1.1: Setting up cloud projects and accountsDomain 1.1Cloud IdentityActive DirectoryGCDS

GCP ACE · Question 03 · Domain 1.1: Setting up cloud projects and accounts

Your company is migrating to Google Cloud. You currently manage all employee identities in an on-premises Microsoft Active Directory (AD). You want to use these existing identities to manage access to GCP resources without requiring users to remember a new set of passwords.

Which TWO actions should you take to achieve this? (Select TWO)

Answer options:

A.

Create a Cloud Identity domain to represent your organization in Google Cloud.

B.

Export users from Active Directory to a CSV file and upload it to Cloud IAM.

C.

Use Google Cloud Directory Sync (GCDS) to synchronize users and groups from AD to Cloud Identity.

D.

Configure Identity-Aware Proxy (IAP) to connect directly to your on-premises Active Directory.

E.

Create a VPC peering connection between your on-premises network and Google Cloud to share IAM policies.

How to approach this question

Identify the Google Cloud services designed for identity federation and synchronization from on-premises directories.

Full Answer

Create a Cloud Identity domain, Use Google Cloud Directory Sync (GCDS)
To federate identities from an on-premises Active Directory to Google Cloud, you must first establish a Cloud Identity (or Google Workspace) account to hold the identities. Then, you use Google Cloud Directory Sync (GCDS) to automatically provision and synchronize users and groups from AD to Cloud Identity.

Common mistakes

Thinking IAM can directly read from an on-premises AD without syncing to Cloud Identity first.

Practice the full GCP Associate Cloud Engineer Practice Exam 3

50 questions · hints · full answers · grading

More questions from this exam