Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise enforces mandatory 2-Step Verification (2SV) across all user accounts in Cloud Identity. A security team needs to establish a secure recovery workflow for users who lose their physical security keys and want to proactively detect security exceptions, such as unauthorized disabling of 2SV or suspicious account activity.
Which combination of administrative delegation and auditing controls should the security team implement?
Temporarily disable 2-Step Verification policy enforcement on the affected Organizational Unit during recovery, and use VPC Flow Logs to trace anomalous sign-in attempts.
Generate long-lived Service Account keys to bypass user authentication during lockouts, and use Cloud Data Loss Prevention (DLP) API to scan audit logs for authentication exceptions.
Grant helpdesk personnel the Super Admin role at the root Organizational Unit, and configure Cloud Monitoring alert policies on IAM System Event audit logs to detect 2SV bypasses.
Assign a custom delegated administrator role with User Management privileges to support staff to generate temporary security codes, and enable Event Threat Detection in Security Command Center to monitor Google Workspace audit logs for 2-step verification modifications.
Temporarily disable 2-Step Verification policy enforcement on the affected Organizational Unit during recovery, and use VPC Flow Logs to trace anomalous sign-in attempts.
Generate long-lived Service Account keys to bypass user authentication during lockouts, and use Cloud Data Loss Prevention (DLP) API to scan audit logs for authentication exceptions.
Grant helpdesk personnel the Super Admin role at the root Organizational Unit, and configure Cloud Monitoring alert policies on IAM System Event audit logs to detect 2SV bypasses.
Assign a custom delegated administrator role with User Management privileges to support staff to generate temporary security codes, and enable Event Threat Detection in Security Command Center to monitor Google Workspace audit logs for 2-step verification modifications.
This solution combines least-privilege delegated administration in Cloud Identity / Google Workspace with automated threat monitoring via Event Threat Detection (ETD) in Security Command Center.
Granting scoped delegated admin roles prevents operational bottlenecks while safeguarding the organization root. Pairing this with ETD's dedicated 2-step verification detector ensures real-time alerting whenever authentication policies are bypassed or tampered with.