Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise organization is establishing baseline authentication security controls across its Cloud Identity and Google Cloud environment. The security engineering team needs to enforce hardened authentication and recovery policies for privileged accounts (super administrators) while maintaining standard policies for general workforce users.
Specifically, the implementation must achieve the following requirements:
Which configuration strategy should the security engineer implement in the Google Admin console?
Keep all administrator and standard users in the root Organizational Unit (OU), configure global 2-Step Verification using SMS or voice codes, and enable automated email password recovery.
Use Policy Analyzer on the root organization node to enforce session expiration intervals, and configure automated OAuth client ID secret rotation every 24 hours.
Create a dedicated Organizational Unit (OU) for super administrator accounts, enforce 2-Step Verification requiring Security Keys only on that OU, and disable automated non-admin account recovery.
Configure Workload Identity Federation with SAML 2.0 assertion encryption for all super administrators and grant them the Service Account Token Creator role on host project service accounts.
Keep all administrator and standard users in the root Organizational Unit (OU), configure global 2-Step Verification using SMS or voice codes, and enable automated email password recovery.
Use Policy Analyzer on the root organization node to enforce session expiration intervals, and configure automated OAuth client ID secret rotation every 24 hours.
Create a dedicated Organizational Unit (OU) for super administrator accounts, enforce 2-Step Verification requiring Security Keys only on that OU, and disable automated non-admin account recovery.
This solution establishes a structured identity governance model in Cloud Identity by isolating privileged super administrator accounts into a dedicated Organizational Unit (OU). By applying targeted policies to this OU, administrators can mandate hardware security keys (such as Titan Security Keys) for 2-Step Verification (2SV) and restrict insecure self-service account recovery channels.
Isolating privileged identities into an administrative OU is the Google Cloud standard architecture for enforcing elevated controls. Applying FIDO2/Titan Security Key enforcement exclusively to this OU guarantees maximum identity assurance for privileged accounts while preventing account takeovers via legacy recovery mechanisms.
Configure Workload Identity Federation with SAML 2.0 assertion encryption for all super administrators and grant them the Service Account Token Creator role on host project service accounts.