Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise organization federates user authentication with an external third-party SAML 2.0 Identity Provider (IdP) to access Google Cloud console and web applications. The security team must implement Context-Aware Access (CAA) and session governance to satisfy the following requirements:
Which configuration strategy should the cloud security engineer implement to achieve these requirements?
Combine context-aware access levels and session lifetime settings into multiple overlapping access bindings assigned across standard Cloud Identity access groups.
Define an access level requiring all context attributes (AND logic), assign it using non-modifiable enforcement groups, and create a dedicated, separate access binding specifically for session length controls.
Implement IAM Conditions on service account impersonation privileges to evaluate device posture, geographical IP origin, and session duration limits.
Create individual access bindings for each contextual factor (one for device posture, one for IP, and one for location) so they combine using strict logical AND evaluation across all user groups.
Combine context-aware access levels and session lifetime settings into multiple overlapping access bindings assigned across standard Cloud Identity access groups.
Define an access level requiring all context attributes (AND logic), assign it using non-modifiable enforcement groups, and create a dedicated, separate access binding specifically for session length controls.
This strategy establishes a robust Context-Aware Access (CAA) and session management architecture in Cloud Identity and Google Cloud by combining unified context policies, immutable group structures, and dedicated session governance bindings.
AND semantics, ensuring all conditions (device security posture via Chrome Enterprise Premium, approved IP subnets, and allowed geographic locations) must be satisfied simultaneously.OR rule evaluations and last-updated overwrite issues.OR logic that occurs when assigning multiple discrete access levels to an application.This approach aligns with Google Cloud security best practices by preventing overlapping bindings, eliminating policy circumvention via group manipulation, and ensuring explicit, comprehensive evaluation of contextual attributes alongside session lifecycles.
Implement IAM Conditions on service account impersonation privileges to evaluate device posture, geographical IP origin, and session duration limits.
Create individual access bindings for each contextual factor (one for device posture, one for IP, and one for location) so they combine using strict logical AND evaluation across all user groups.