For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeGCP Associate Cloud Engineer (ACE)GCP Associate Cloud Engineer Practice Exam 3Question 03
    Medium1 markMultiple Choice
    Domain 1.1: Setting up cloud projects and accountsDomain 1.1Cloud IdentityActive DirectoryGCDS

    GCP ACE · Question 03 · Domain 1.1: Setting up cloud projects and accounts

    Your company is migrating to Google Cloud. You currently manage all employee identities in an on-premises Microsoft Active Directory (AD). You want to use these existing identities to manage access to GCP resources without requiring users to remember a new set of passwords.

    Which TWO actions should you take to achieve this? (Select TWO)

    Answer options:

    A.

    Create a Cloud Identity domain to represent your organization in Google Cloud.

    B.

    Export users from Active Directory to a CSV file and upload it to Cloud IAM.

    C.

    Use Google Cloud Directory Sync (GCDS) to synchronize users and groups from AD to Cloud Identity.

    D.

    Configure Identity-Aware Proxy (IAP) to connect directly to your on-premises Active Directory.

    E.

    Create a VPC peering connection between your on-premises network and Google Cloud to share IAM policies.

    How to approach this question

    Identify the Google Cloud services designed for identity federation and synchronization from on-premises directories.

    Full Answer

    To federate identities from an on-premises Active Directory to Google Cloud, you must first establish a Cloud Identity (or Google Workspace) account to hold the identities. Then, you use Google Cloud Directory Sync (GCDS) to automatically provision and synchronize users and groups from AD to Cloud Identity.

    Common mistakes

    Thinking IAM can directly read from an on-premises AD without syncing to Cloud Identity first.
    Question 02All questionsQuestion 04

    Practice the full GCP Associate Cloud Engineer Practice Exam 3

    50 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01You are starting a new project in Google Cloud and need to create a new GCP project and enable th...EasyQ02A new team member has joined your operations team. They need to be able to view all Compute Engin...MediumQ04Your development team is experimenting with new GCP services in a sandbox project. The finance te...MediumQ05Your company wants to perform complex, custom SQL analysis on their Google Cloud billing data to ...EasyQ06You have just installed the Google Cloud SDK on your local workstation. You need to authenticate ...Easy
    View all 50 questions →