🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 51 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your company has 9,000 employees who authenticate to Google Cloud through an on-premises SAML 2.0 identity provider that already enforces multifactor authentication (MFA). In addition, the security team maintains two non-federated "break-glass" super administrator accounts that must never rely on the on-premises IdP. Compliance now requires that all super administrators use only FIDO2 security keys as a second factor, while ordinary users must continue to authenticate via the existing IdP workflow without being challenged twice for MFA. What should you do to meet these requirements with the least disruption?

  • Generate app passwords for the break-glass accounts, store them in Secret Manager, and configure an Access Transparency alert whenever they are used.

  • Place the two break-glass super admin accounts in their own organizational unit and enable the Enforce 2-Step Verification policy for that OU, allowing only FIDO2 security keys; keep SAML SSO unchanged for all other users.

  • Disable SAML SSO for the entire domain and turn on mandatory 2-Step Verification with security keys at the organization level so every user must register a key at next sign-in.

  • Create a context-aware access level that requires an MFA assertion and apply it to all Google Cloud services; leave 2-Step Verification optional in Google Workspace.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot