Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A multinational enterprise is updating its security posture in Cloud Identity and Google Cloud to protect privileged administrative access. The security architecture team must establish stringent policies for Super Administrator accounts to prevent credential theft, phishing, and unauthorized privilege escalation.
The policy must enforce the following security requirements:
Which set of controls should the organization implement?
Place Super Administrator accounts in a dedicated Organizational Unit (OU) enforcing 2-Step Verification with Security Keys only, disable the 'Allow user to trust the device' setting, assign pre-built or custom administrative roles to separate daily accounts, and enable administrative audit logging.
Configure Single Sign-On (SSO) with a third-party Identity Provider for Super Administrator accounts, allow SMS-based verification as a backup method, and grant all senior engineers the Super Administrator role to ensure continuous operational coverage.
Deploy a single shared break-glass Super Administrator account with a rotating static password, disable multi-factor authentication to avoid device lockouts, and restrict access exclusively using IP-based VPC Service Controls.
Assign Super Administrator privileges directly to primary corporate email accounts, enable Google Prompt on personal mobile devices, and extend session lengths to 30 days with device trusting enabled to prevent frequent re-authentication.
Place Super Administrator accounts in a dedicated Organizational Unit (OU) enforcing 2-Step Verification with Security Keys only, disable the 'Allow user to trust the device' setting, assign pre-built or custom administrative roles to separate daily accounts, and enable administrative audit logging.
This solution establishes a defense-in-depth security model for Cloud Identity Super Administrator accounts by isolating high-privilege identities into a dedicated Organizational Unit (OU). Within this OU, strict identity verification policies, session constraints, and role-delegation rules are uniformly applied.
Isolating Super Admin accounts into their own organizational unit with mandatory hardware security keys and delegated least-privilege roles directly enforces Google Cloud security best practices, eliminating shared account vulnerabilities and credential persistence risks.
Configure Single Sign-On (SSO) with a third-party Identity Provider for Super Administrator accounts, allow SMS-based verification as a backup method, and grant all senior engineers the Super Administrator role to ensure continuous operational coverage.
Deploy a single shared break-glass Super Administrator account with a rotating static password, disable multi-factor authentication to avoid device lockouts, and restrict access exclusively using IP-based VPC Service Controls.
Assign Super Administrator privileges directly to primary corporate email accounts, enable Google Prompt on personal mobile devices, and extend session lengths to 30 days with device trusting enabled to prevent frequent re-authentication.