PCSE Practice Question: Configuring Access Within a Cloud Solution Environment
An organization uses Cloud Directory Sync to synchronize users from on-premises Active Directory to Cloud Identity. After syncing, a user reports they cannot access a Google Cloud project even though they are a member of the correct AD group. The group has been assigned the roles/compute.admin role on the project. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The group was not synced as a Google Group; only users were synced
Cloud Directory Sync synchronizes users and groups, but group membership changes may take time to propagate. Additionally, the group must be synced as a Google Group or Cloud Identity group with the proper membership synced. If the group is not recognized in Cloud Identity, the IAM binding will not apply to the users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The role was assigned at the organization level instead of the project level
Why it's wrong here
The role was assigned at the project level as stated, so this is not the issue.
- ✗
The user needs to log out and log back in to refresh their session
Why it's wrong here
While session refresh might help, the root cause is likely the group not being synced.
- ✗
The user is not a direct member of the group; they are a nested group member
Why it's wrong here
Nested group memberships are supported in Cloud Identity, so this is less likely.
- ✓
The group was not synced as a Google Group; only users were synced
Why this is correct
If the group object is not synced, the IAM policy binding to the group will have no effect because the group does not exist in Cloud Identity.
Go deeper
Related to this question
About these practice questions
One of 960 original PCSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCSE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCSE exam.