Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise organization is hardening its Google Cloud and Cloud Identity access governance model. A security audit reveals that several administrators hold permanent Super Admin privileges for day-to-day administrative tasks, creating critical risks of configuration tampering, accidental service disruption, and broad privilege abuse.
The security team must implement a robust access control architecture meeting these requirements:
Which set of controls should the organization implement?
Enforce Single Sign-On (SSO) with an external IdP for all super admin accounts; configure IAM session length policies to 1 hour; grant permanent Organization Administrator roles to the primary administrative user accounts.
Configure domain-wide delegation for all administrator accounts to impersonate the super administrator identity; use Cloud Functions to automatically disable the accounts after 8 hours; enable basic audit logging on the organization root node.
Disable service account key creation across the organization; enforce OS Login with two-step verification for all Compute Engine instances; configure Chrome Enterprise Premium certificate-based access for the super admin accounts.
Assign granular pre-built or custom administrative roles for daily administrative tasks; configure Privileged Access Manager (PAM) entitlements with time-bound grants and mandatory justification for infrastructure privilege elevation; maintain dedicated, non-federated break-glass super admin accounts protected by split operations and monitored via automated security alerts.
Enforce Single Sign-On (SSO) with an external IdP for all super admin accounts; configure IAM session length policies to 1 hour; grant permanent Organization Administrator roles to the primary administrative user accounts.
Configure domain-wide delegation for all administrator accounts to impersonate the super administrator identity; use Cloud Functions to automatically disable the accounts after 8 hours; enable basic audit logging on the organization root node.
Disable service account key creation across the organization; enforce OS Login with two-step verification for all Compute Engine instances; configure Chrome Enterprise Premium certificate-based access for the super admin accounts.
Assign granular pre-built or custom administrative roles for daily administrative tasks; configure Privileged Access Manager (PAM) entitlements with time-bound grants and mandatory justification for infrastructure privilege elevation; maintain dedicated, non-federated break-glass super admin accounts protected by split operations and monitored via automated security alerts.
This architecture combines least-privilege role segregation, just-in-time (JIT) privileged access management, and governed break-glass procedures to eliminate standing super administrator accounts while preserving operational continuity.
admin-breakglass@example.com) ensures emergency recovery if identity federation fails. Enforcing split operations (where one individual holds the credentials and another holds the hardware MFA token or approval authority) prevents unilateral account abuse.This solution directly implements cloud security best practices by decoupling everyday administrative responsibilities from super admin access, establishing dual-control emergency recovery paths, and enforcing temporary elevation via Privileged Access Manager.