Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A company is implementing a zero-trust authentication policy across its Google Cloud organization using Cloud Identity. The security architect must configure 2-Step Verification (2SV) enforcement for developers and administrators while satisfying the following requirements:
Which set of configuration actions should the security architect take?
This configuration establishes a secure, automated 2-Step Verification (2SV) rollout lifecycle using Cloud Identity enforcement groups, administrative enrollment grace periods, and session lifetime controls for Google Cloud services.
whoCanLeaveGroup attribute to NONE_CAN_LEAVE via the Groups Settings API enforces mandatory access control, preventing users from opting out of the security enforcement group.This approach directly leverages Cloud Identity's built-in authentication lifecycle settings and Google Cloud session management best practices without relying on brittle custom scripts or insecure administrative exceptions.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.