Courseiva

PCSE Practice Question: Configuring Access Within a Cloud Solution Environment

An organization uses Cloud Directory Sync to synchronize users from on-premises Active Directory to Cloud Identity. After syncing, a user reports they cannot access a Google Cloud project even though they are a member of the correct AD group. The group has been assigned the roles/compute.admin role on the project. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The group was not synced as a Google Group; only users were synced

Cloud Directory Sync synchronizes users and groups, but group membership changes may take time to propagate. Additionally, the group must be synced as a Google Group or Cloud Identity group with the proper membership synced. If the group is not recognized in Cloud Identity, the IAM binding will not apply to the users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The role was assigned at the organization level instead of the project level

    Why it's wrong here

    The role was assigned at the project level as stated, so this is not the issue.

  • The user needs to log out and log back in to refresh their session

    Why it's wrong here

    While session refresh might help, the root cause is likely the group not being synced.

  • The user is not a direct member of the group; they are a nested group member

    Why it's wrong here

    Nested group memberships are supported in Cloud Identity, so this is less likely.

  • The group was not synced as a Google Group; only users were synced

    Why this is correct

    If the group object is not synced, the IAM policy binding to the group will have no effect because the group does not exist in Cloud Identity.

About these practice questions

One of 960 original PCSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCSE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCSE exam.