Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A multinational enterprise is updating its security posture in Cloud Identity and Google Cloud to protect privileged administrative access. The security architecture team must establish stringent policies for Super Administrator accounts to prevent credential theft, phishing, and unauthorized privilege escalation.
The policy must enforce the following security requirements:
Which set of controls should the organization implement?
This solution establishes a defense-in-depth security model for Cloud Identity Super Administrator accounts by isolating high-privilege identities into a dedicated Organizational Unit (OU). Within this OU, strict identity verification policies, session constraints, and role-delegation rules are uniformly applied.
Isolating Super Admin accounts into their own organizational unit with mandatory hardware security keys and delegated least-privilege roles directly enforces Google Cloud security best practices, eliminating shared account vulnerabilities and credential persistence risks.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.