How to Manage Temporary Partner Access on Google Cloud?
Your organization has hired a small, temporary partner team for 18 months. The temporary team will work alongside your DevOps team to develop your organization's application that is hosted on Google Cloud. You must give the temporary partner team access to your application's resources on Google Cloud and ensure that partner employees lose access. If they are removed from their employer's organization. What should you do?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests external identity delegation by highlighting that federated workforce pools eliminate manual deprovisioning risks when temporary staff leave their employer.
This scenario evaluates workforce identity federation for external contractors on Google Cloud, confirming that linking a partner’s IdP guarantees automatic access revocation when employees depart.
Candidates frequently select Option D, assuming native IdP integration offers tighter control, but it requires manual offboarding and delays access termination.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Workforce identity federation is explicitly designed for external users like contractors and partners who need secure, time-bound access to cloud resources. By creating an identity pool and federating it with the partner’s existing IdP, Google Cloud delegates authentication entirely to the vendor’s system. When a contractor leaves their employer, their credentials become invalid at the source IdP, instantly cutting off all GCP access without any administrative intervention. This aligns perfectly with the requirement for automatic revocation.Why the Other Options Are Wrong
Option A relies on static credentials that are insecure and impossible to automatically sync with an external company’s HR system. Option C describes just-in-time access, which is intended for short-term privilege escalation for internal staff rather than sustained project collaboration. Option D suggests migrating external identities into your internal IdP, which creates orphaned accounts that persist until manually deleted, violating the automatic removal requirement.Community Comment Notes
The community consensus strongly favors this approach, with multiple learners confirming the solution points directly to official Google documentation. As noted by several contributors, workforce identity federation is the standard pattern for managing third-party access in cloud environments. Participants also highlighted that this method eliminates password fatigue while maintaining strict compliance boundaries between organizations.Official Reference
Exam Strategy
When dealing with external teams or contractors, always look for federation-based solutions that delegate authentication to the partner’s IdP. Avoid manual account creation or long-lived credentials, as they introduce compliance risks and increase administrative overhead during offboarding.
Frequently Asked Questions
Why can't I just add partner users to my internal IdP?
Adding external users to your IdP creates permanent accounts that require manual deletion. Federation delegates authentication to their IdP, enabling instant automatic revocation.
Is JIT access suitable for an 18-month contract?
No. JIT is designed for short-term privilege escalation for internal staff. Workforce federation supports sustained, policy-driven access for long-term external collaborations.