Courseiva

Google PCA Designing for Security and Compliance Practice Question

An organization uses Active Directory (AD) on-premises. They want to synchronize user accounts and groups to Google Cloud Identity so that users can sign in with their existing AD credentials. Which service should they use?

⚠ Common exam trap

PCA often tests the distinction between directory synchronization (GCDS) and authentication federation (SAML), and candidates may choose Cloud Identity Platform or IAP thinking they handle AD sync.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Google Cloud Directory Sync

Google Cloud Directory Sync (GCDS) is the official tool for synchronizing users, groups, and other directory data from an on-premises Active Directory or LDAP directory to Google Cloud Identity or Google Workspace. It runs on-premises, reads from AD, and provisions accounts in Google Cloud, allowing users to sign in with their existing AD credentials (often via SAML federation or password sync).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cloud Identity Platform

    Why it's wrong here

    Cloud Identity Platform handles application authentication and federation, not directory synchronisation of AD users and groups into Cloud Identity. It is tempting because it connects identities to apps. Google Cloud Directory Sync performs the one-way provisioning this scenario describes.

  • ✓

    Google Cloud Directory Sync

    Why this is correct

    Google Cloud Directory Sync provisions users and groups from on-premises Active Directory into Cloud Identity, letting accounts authenticate with existing AD credentials. It synchronises directory data rather than federating sign-in, which suits the stated requirement to mirror accounts and groups.

  • ✗

    Cloud Identity-Aware Proxy

    Why it's wrong here

    Identity-Aware Proxy enforces access control to applications and VMs behind a load balancer; it does not synchronise directory objects. It is tempting because it consumes Cloud Identity identities. Google Cloud Directory Sync is the provisioning tool that mirrors AD users and groups.

  • ✗

    Security Command Center

    Why it's wrong here

    Security Command Center aggregates security findings and asset inventory; it neither provisions nor synchronises identities. It is tempting because it is a central Google Cloud security service. Google Cloud Directory Sync is the component that replicates AD accounts and groups into Cloud Identity.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.