Google PCA Designing for Security and Compliance Practice Question
An organization uses Active Directory (AD) on-premises. They want to synchronize user accounts and groups to Google Cloud Identity so that users can sign in with their existing AD credentials. Which service should they use?
⚠ Common exam trap
PCA often tests the distinction between directory synchronization (GCDS) and authentication federation (SAML), and candidates may choose Cloud Identity Platform or IAP thinking they handle AD sync.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Google Cloud Directory Sync
Google Cloud Directory Sync (GCDS) is the official tool for synchronizing users, groups, and other directory data from an on-premises Active Directory or LDAP directory to Google Cloud Identity or Google Workspace. It runs on-premises, reads from AD, and provisions accounts in Google Cloud, allowing users to sign in with their existing AD credentials (often via SAML federation or password sync).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud Identity Platform
Why it's wrong here
Cloud Identity Platform handles application authentication and federation, not directory synchronisation of AD users and groups into Cloud Identity. It is tempting because it connects identities to apps. Google Cloud Directory Sync performs the one-way provisioning this scenario describes.
- ✓
Google Cloud Directory Sync
Why this is correct
Google Cloud Directory Sync provisions users and groups from on-premises Active Directory into Cloud Identity, letting accounts authenticate with existing AD credentials. It synchronises directory data rather than federating sign-in, which suits the stated requirement to mirror accounts and groups.
- ✗
Cloud Identity-Aware Proxy
Why it's wrong here
Identity-Aware Proxy enforces access control to applications and VMs behind a load balancer; it does not synchronise directory objects. It is tempting because it consumes Cloud Identity identities. Google Cloud Directory Sync is the provisioning tool that mirrors AD users and groups.
- ✗
Security Command Center
Why it's wrong here
Security Command Center aggregates security findings and asset inventory; it neither provisions nor synchronises identities. It is tempting because it is a central Google Cloud security service. Google Cloud Directory Sync is the component that replicates AD accounts and groups into Cloud Identity.
Go deeper
Related to this question
Learn chapter
Google Cloud Resource Hierarchy and Organization
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.