Valid Professional-Cloud-Security-Engineer Dumps shared by EduDump.com for Helping Passing Professional-Cloud-Security-Engineer Exam! EduDump.com now offer the newest Professional-Cloud-Security-Engineer exam dumps, the EduDump.com Professional-Cloud-Security-Engineer exam questions have been updated and answers have been corrected get the newest EduDump.com Professional-Cloud-Security-Engineer dumps with Test Engine here:
Your organization has hired a small, temporary partner team for 18 months. The temporary team will work alongside your DevOps team to develop your organization's application that is hosted on Google Cloud. You must give the temporary partner team access to your application's resources on Google Cloud and ensure that partner employees lose access if they are removed from their employer's organization. What should you do?
Correct Answer: D
The core requirement is to grant temporary, external users access to your Google Cloud environment while ensuring access control remains managed by their employer's identity provider (IdP). This allows your organization to follow the principle of least privilege and ensures access is revoked automatically when the user leaves the partner company (or is removed from the partner's IdP). Workforce Identity Federation is the service specifically designed for granting external identities (partners, vendors, customers) access to Google Cloud resources without needing to sync or create managed Google accounts for them. Extracts: "Workforce Identity Federation is designed for the scenario where a partner organization needs to access your Google Cloud resources... it lets you use an external IdP to authenticate and authorize access to Google Cloud." (Source 1.1) "Using Workforce Identity Federation is the most secure and efficient way to give external users access. Because authentication is handled by the external IdP, access is automatically revoked or suspended if the user is deactivated in the partner's IdP." (Source 1.2) Option C would require your organization to manage the partner identities, violating the requirement for the partner's IdP to control the access lifecycle.