Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise uses Cloud Identity to govern administrative access to Google Cloud projects hosting mission-critical workloads. A recent internal red-team assessment demonstrated that threat actors could execute adversary-in-the-middle (AitM) reverse-proxy phishing attacks to intercept session cookies and bypass standard multi-factor authentication methods, such as SMS codes and mobile authenticator push prompts.
The security architect must enforce an authentication policy for all privileged administrators that eliminates credential harvesting and AitM relay attacks.
Which 2-Step Verification (2SV) configuration should the architect implement?
Enforce Google prompt push notifications with number matching across all administrator mobile devices.
Configure Context-Aware Access policies requiring SMS-based verification codes paired with corporate IP subnet restrictions.
Assign privileged administrators to a dedicated Organizational Unit (OU) and configure the 2-Step Verification policy to enforce 'Only security key' using FIDO2/WebAuthn hardware keys.
Assign privileged administrators to a dedicated Organizational Unit (OU) and set 2-Step Verification enforcement to 'Any', mandating Time-based One-Time Password (TOTP) authenticator apps.
Enforce Google prompt push notifications with number matching across all administrator mobile devices.
Configure Context-Aware Access policies requiring SMS-based verification codes paired with corporate IP subnet restrictions.
Assign privileged administrators to a dedicated Organizational Unit (OU) and configure the 2-Step Verification policy to enforce 'Only security key' using FIDO2/WebAuthn hardware keys.
FIDO2/WebAuthn hardware security keys represent a cryptographically bound authentication standard designed by the FIDO Alliance and W3C. In Cloud Identity and Google Workspace, administrators can create targeted security policies applied to specific Organizational Units (OUs) or access groups, configuring the 2-Step Verification (2SV) enforcement setting specifically to Only security key. This policy restricts the acceptable second-factor method exclusively to physical, hardware-based cryptographic keys (such as Google Titan Security Keys or YubiKeys) or platform authenticators supporting FIDO2/WebAuthn protocols.
accounts.google.com) to the security key. The security key signs a challenge using the private key registered specifically for that domain. If an adversary proxies the traffic through a spoofed domain (such as login.attacker-domain.com), the origin signature fails, and the authentication request is instantly rejected.Enforcing Only security key at the OU level provides absolute phishing resistance against sophisticated AitM proxies and reverse-proxy credential harvesting kits. It represents the highest assurance level of multi-factor authentication supported in Google Cloud and Cloud Identity.
Assign privileged administrators to a dedicated Organizational Unit (OU) and set 2-Step Verification enforcement to 'Any', mandating Time-based One-Time Password (TOTP) authenticator apps.