Search icon
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Official Google Cloud Certified Professional Cloud Security Engineer Exam Guide

You're reading from  Official Google Cloud Certified Professional Cloud Security Engineer Exam Guide

Product type Book
Published in Aug 2023
Publisher Packt
ISBN-13 9781835468869
Pages 496 pages
Edition 1st Edition
Languages
Authors (2):
Ankush Chowdhary Ankush Chowdhary
Profile icon Ankush Chowdhary
Prashant Kulkarni Prashant Kulkarni
Profile icon Prashant Kulkarni
View More author details

Table of Contents (19) Chapters

Preface 1. Chapter 1: About the GCP Professional Cloud Security Engineer Exam 2. Chapter 2: Google Cloud Security Concepts 3. Chapter 3: Trust and Compliance 4. Chapter 4: Resource Management 5. Chapter 5: Understanding Google Cloud Identity 6. Chapter 6: Google Cloud Identity and Access Management 7. Chapter 7: Virtual Private Cloud 8. Chapter 8: Advanced Network Security 9. Chapter 9: Google Cloud Key Management Service 10. Chapter 10: Cloud Data Loss Prevention 11. Chapter 11: Secret Manager 12. Chapter 12: Cloud Logging 13. Chapter 13: Image Hardening and CI/CD Security 14. Chapter 14: Security Command Center 15. Chapter 15: Container Security 16. Google Professional Cloud Security Engineer Exam – Mock Exam I
17. Google Professional Cloud Security Engineer Exam – Mock Exam II 18. Other Books You May Enjoy

5

Understanding Google Cloud Identity

In this chapter, we will look at Google Cloud Identity, which is Google’s Identity as a Service (IDaaS) and Enterprise Mobility Management (EMM) product. We will cover aspects such as directory management, how to create and manage user accounts and groups, and how to sync directory services such as Active Directory using Google Cloud Directory Sync (GCDS). There are other features and services that will be covered, including Single Sign-On (SSO) and device and application management.

Furthermore, we will look at how you can use Google Cloud Identity to enforce 2-step verification (2SV), password management, session management, and reporting and admin log activity. As the topics within Cloud Identity are very broad and cover some aspects that are related to Google Workspace (formerly known as G Suite), we will limit our discussion in this chapter to the topics that are relevant to the Google Professional Cloud Security Engineer exam...

Overview of Cloud Identity

Google Cloud Identity is different from some of the other cloud security products that we will cover in this book. What makes it different is that it covers two different platforms: Google Workspace and Google Cloud. Google Workspace is out of scope as it’s not covered in the Google Professional Cloud Security Engineer exam; the features and aspects that we will cover will only pertain to the use of Cloud Identity with regard to Google Cloud.

First, let’s understand a few aspects of Cloud Identity. Cloud Identity is accessed via a separate console (admin.google.com). Cloud Identity is also the first product that you will interact with when you configure your Google Cloud environment, as the super administrator account exists in Cloud Identity. There’ll be more on the super administrator account later in this chapter. Cloud Identity only provides an authentication service and not authorization. The authorization aspect is covered by...

Securing your account

Google Cloud Identity provides a number of different options that can help you secure your account and enforce strong security controls. In this section, we will look at how to enforce 2SV using security keys, enforce a password policy and password recovery options, and configure user security settings such as session length, as well as doing a walk-through of the Google security center.

2-step verification

With 2SV, users log in to their accounts using their username and password (also referred to as something the users know) as well as a second factor (something they have), which could be a physical security token or a mobile phone that can generate a key. Google Cloud Identity supports a number of methods that can be used as a second factor for authentication. These methods include the following:

  • Security keys: A physical security key, such as Google’s Titan Security Key or a YubiKey.
  • Google prompt: Users can set up their mobile phone...

Directory management

This is one of the most important sections of the entire chapter. We will learn how to configure identity provisioning, in particular, how to integrate Microsoft Active Directory (AD) with Google Cloud Identity using the GCDS tool. We will look at some other directory management tasks, such as how to create users and groups and assign admin permissions and how we can provision and de-provision user access using Google Cloud Identity and third-party IdPs. Finally, we will have a look at how to automate user lifecycle management.

Google Cloud Directory Sync

This section will be a deep dive into GCDS. We will start by understanding what GCDS is, the benefits of using it, how it works, and how to configure it using Configuration Manager.

GCDS helps you to synchronize your Microsoft AD or LDAP objects, such as security users and groups, to your Google Cloud Identity account.

Note

To look at the entire list of content that is synced, you can check this...

Summary

In this chapter, we covered Google Cloud Identity. We looked at what services and features are available and how to design and build your authentication strategy on Google Cloud using Cloud Identity. The topics covered included domain setup, super administrator best practices, account security, how to enforce 2SV, how to configure user security settings, session management, how to configure SSO using SAML, how to use GCDS to federate AD with Cloud Identity, user and group provisioning, automated user lifecycle management, identity federation, and SSO.

In the next chapter, we will cover Google Cloud Identity and Access Management, looking at the authorization aspect of Google Cloud.

Further reading

For more information on Google Cloud Identity, refer to the following links:

lock icon The rest of the chapter is locked
You have been reading a chapter from
Official Google Cloud Certified Professional Cloud Security Engineer Exam Guide
Published in: Aug 2023 Publisher: Packt ISBN-13: 9781835468869
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €14.99/month. Cancel anytime}