Valid Professional-Cloud-Security-Engineer Dumps shared by ExamDiscuss.com for Helping Passing Professional-Cloud-Security-Engineer Exam! ExamDiscuss.com now offer the newest Professional-Cloud-Security-Engineer exam dumps, the ExamDiscuss.com Professional-Cloud-Security-Engineer exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com Professional-Cloud-Security-Engineer dumps with Test Engine here:
You work for a large organization where each business unit has thousands of users. You need to delegate management of access control permissions to each business unit. You have the following requirements: Each business unit manages access controls for their own projects. Each business unit manages access control permissions at scale. Business units cannot access other business units' projects. Users lose their access if they move to a different business unit or leave the company. Users and access control permissions are managed by the on-premises directory service. What should you do? (Choose two.)
Correct Answer: B,E
To delegate management of access control permissions to each business unit effectively, organizing projects into folders and assigning permissions to Google groups at the folder level allows for scalable and manageable access control. Using Google Cloud Directory Sync (GCDS) to synchronize users and groups from the on-premises directory service ensures that access controls are maintained and updated automatically as users change roles or leave the company. Steps: * Organize Projects in Folders: Create a folder structure in the Google Cloud Resource Manager to organize projects by business unit. * Assign Permissions to Google Groups: Use IAM to assign necessary permissions to Google Groups at the folder level, ensuring each business unit can manage access controls for their own projects. * Synchronize Users and Groups: Use GCDS to sync users and group memberships from your on- premises directory service to Google Cloud Identity, ensuring that changes in the on-premises directory are reflected in Google Cloud. References: * Google Cloud Resource Manager * Google Cloud Directory Sync