Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A security operations center (SOC) detects that an attacker compromised a developer's workstation and exfiltrated active gcloud CLI OAuth tokens to an external host to execute unauthorized Google Cloud API requests. The organization uses Cloud Identity federated with an external Identity Provider (IdP) using SAML 2.0 for Single Sign-On (SSO).
The security team needs to achieve the following:
gcloud CLI access and refresh tokens.gcloud CLI.Which set of actions should the security team take?
Run gcloud auth revoke locally on the developer's machine, apply the iam.allowedPolicyMemberDomains organization policy, and configure network masks within Cloud Identity single sign-on settings.
Reset the user's password, reset their sign-in cookies in the Admin Console, configure the session length for Google services to 8 hours, and enable OS Login 2FA across all Compute Engine projects.
Suspend the compromised user account in Cloud Identity, configure a VPC Service Controls perimeter around the Developer project, and set the external IdP session length to 24 hours while setting Google Cloud session length to 8 hours.
Remove the gcloud CLI (Google Cloud SDK) from the user's connected applications, configure Google Cloud session control to require re-authentication (1–24 hours), and set the external IdP session duration to be shorter than the Google Cloud session length.
Run gcloud auth revoke locally on the developer's machine, apply the iam.allowedPolicyMemberDomains organization policy, and configure network masks within Cloud Identity single sign-on settings.
Reset the user's password, reset their sign-in cookies in the Admin Console, configure the session length for Google services to 8 hours, and enable OS Login 2FA across all Compute Engine projects.
Suspend the compromised user account in Cloud Identity, configure a VPC Service Controls perimeter around the Developer project, and set the external IdP session length to 24 hours while setting Google Cloud session length to 8 hours.
Remove the gcloud CLI (Google Cloud SDK) from the user's connected applications, configure Google Cloud session control to require re-authentication (1–24 hours), and set the external IdP session duration to be shorter than the Google Cloud session length.
This remediation and hardening strategy combines OAuth token revocation via connected application management with Google Cloud session control and Identity Provider (IdP) session alignment to eliminate compromised credentials and enforce periodic re-authentication.
Alternative measures—such as resetting account passwords or web sign-in cookies—do not invalidate existing OAuth access tokens that an attacker has already copied. Aligning IdP session lengths with Google Cloud re-authentication policies guarantees that session terminations enforce actual user challenges rather than silent automated renewals.