Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise organization is establishing baseline authentication security controls across its Cloud Identity and Google Cloud environment. The security engineering team needs to enforce hardened authentication and recovery policies for privileged accounts (super administrators) while maintaining standard policies for general workforce users.
Specifically, the implementation must achieve the following requirements:
Which configuration strategy should the security engineer implement in the Google Admin console?
This solution establishes a structured identity governance model in Cloud Identity by isolating privileged super administrator accounts into a dedicated Organizational Unit (OU). By applying targeted policies to this OU, administrators can mandate hardware security keys (such as Titan Security Keys) for 2-Step Verification (2SV) and restrict insecure self-service account recovery channels.
Isolating privileged identities into an administrative OU is the Google Cloud standard architecture for enforcing elevated controls. Applying FIDO2/Titan Security Key enforcement exclusively to this OU guarantees maximum identity assurance for privileged accounts while preventing account takeovers via legacy recovery mechanisms.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.