Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise uses Cloud Identity to govern administrative access to Google Cloud projects hosting mission-critical workloads. A recent internal red-team assessment demonstrated that threat actors could execute adversary-in-the-middle (AitM) reverse-proxy phishing attacks to intercept session cookies and bypass standard multi-factor authentication methods, such as SMS codes and mobile authenticator push prompts.
The security architect must enforce an authentication policy for all privileged administrators that eliminates credential harvesting and AitM relay attacks.
Which 2-Step Verification (2SV) configuration should the architect implement?
FIDO2/WebAuthn hardware security keys represent a cryptographically bound authentication standard designed by the FIDO Alliance and W3C. In Cloud Identity and Google Workspace, administrators can create targeted security policies applied to specific Organizational Units (OUs) or access groups, configuring the 2-Step Verification (2SV) enforcement setting specifically to Only security key. This policy restricts the acceptable second-factor method exclusively to physical, hardware-based cryptographic keys (such as Google Titan Security Keys or YubiKeys) or platform authenticators supporting FIDO2/WebAuthn protocols.
accounts.google.com) to the security key. The security key signs a challenge using the private key registered specifically for that domain. If an adversary proxies the traffic through a spoofed domain (such as login.attacker-domain.com), the origin signature fails, and the authentication request is instantly rejected.Enforcing Only security key at the OU level provides absolute phishing resistance against sophisticated AitM proxies and reverse-proxy credential harvesting kits. It represents the highest assurance level of multi-factor authentication supported in Google Cloud and Cloud Identity.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.