Objective 1.1

PCSE

Managing Cloud Identity

Objective 1.1 sits in Configuring access, which carries 25% of the Cloud Security Engineer exam. The questions below are original, written from the official objective title above, and each explanation cites the Google Cloud page it rests on.

Objective title verbatim from the official objectives. Google Cloud exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

1-1Configuring access

A new hire at your company authenticates through the corporate SAML provider for the first time and the sign-in fails. What was missed?

Adding her address as an alias on an existing accountAn alias address is not an identity and cannot be signed in with.
Placing her into the correct organizational unit firstOU placement governs configuration and cannot stand in for the record itself.
Granting her group membership in the domainGroup membership confers access after sign-in and plays no part in authenticating.
Provisioning a user account with that identity beforehandCorrect · your answerCorrect. The record has to exist first.

Correct.

Concept

Federation links two directories rather than populating one from the other. The provider vouches for a person, but the service still needs its own record to hang configuration and access on.

Why D

Two prerequisites apply: the external provider must recognize the identity, and Cloud Identity must already contain a user account using that identity before the first single sign-on attempt.

Source

Your external IdP must recognize the identity alice@example.com and allow it to be used for single sign-on. Your Cloud Identity or Google Workspace account must contain a user account that uses alice@example.com as its identity. This user account must exist before the first single sign-on attempt.

Google Cloud: Overview of Google identity management, checked August 2026
#gcp#cloud-identity#federation#sso

Now you: objective 1.1 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

1-1Configuring access

A managed user account has a primary address, an alias address, and a recovery address configured. Which of them can be used to sign in?

Sample question 2 of 3

1-1Configuring access

An administrator wants one account to inherit settings from two organizational units at once. What does Cloud Identity actually allow?

Sample question 3 of 3

1-1Configuring access

A contractor signed up for a Google account using an address in a domain your organization later verified in Cloud Identity. What is that account called?

Full Cloud Security Engineer question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Configuring access