GCP Professional Cloud Security Engineer Practice Question
Your organization migrated to Cloud Identity and currently has four staff members who perform daily administration using Super Administrator privileges. A recent internal risk assessment highlights that this practice violates least-privilege principles and exposes the company if any of those credentials are phished. Security wants to (1) restrict routine use of Super Administrator power, (2) guarantee emergency recovery if the primary IdP or MFA service is unavailable, and (3) keep an auditable trail with minimal day-to-day overhead. Which strategy best satisfies all three goals?
Create two dedicated break-glass Super Administrator accounts that are excluded from SSO and 2-Step Verification, secured with long random passwords stored in an offline safe; assign the four staff members delegated admin roles matching their job duties and monitor any logins to the break-glass accounts.
Enable Privileged Access Manager so the four staff members request time-bound elevation to the Super Administrator role whenever needed, and disable all standing Super Administrator accounts.
Rotate the passwords of all four Super Administrator accounts monthly, require phone-based 2-Step Verification, and configure an automated rule that unlocks a fifth Super Administrator account if no admin logs in for 48 hours.
Keep one existing Super Administrator account for everyday work and enforce FIDO2 security-key MFA on it; demote the other three to Help Desk Admin and rely on Access Context Manager to restrict their logins to corporate IP ranges.
Limiting exposure means removing standing Super Administrator privileges from day-to-day identities and granting them only the narrow administrative roles required for routine tasks. Google recommends maintaining at least one (preferably two) emergency or "break-glass" Super Administrator accounts that are not subject to SSO or MFA enforcement, use strong randomly generated passwords stored offline, and are monitored for any sign-in activity. This arrangement ensures recovery even if the primary IdP or MFA infrastructure is unavailable, satisfies least-privilege by removing broad rights from everyday accounts, and keeps audit logs for the seldom-used break-glass logins. The other options either keep routine Super Administrator use, depend on the availability of MFA/IdP for recovery, or rely on features (like automatic unlocking) that do not provide controlled, auditable emergency access.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is 'least-privilege' and why is it important in cloud environments?
Open an interactive chat with Bash
What is a break-glass account and why would it bypass MFA and SSO?
Open an interactive chat with Bash
What is the role of audit logs in monitoring break-glass account usage?
Open an interactive chat with Bash
What are break-glass accounts in Cloud Identity?
Open an interactive chat with Bash
How does enforcing least-privilege principles improve security?
Open an interactive chat with Bash
Why are long, random passwords stored offline recommended for break-glass accounts?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .