exam questions

Exam Professional Cloud Security Engineer All Questions

View all questions & answers for the Professional Cloud Security Engineer exam

Exam Professional Cloud Security Engineer topic 1 question 97 discussion

Actual exam question from Google's Professional Cloud Security Engineer
Question #: 97
Topic #: 1
[All Professional Cloud Security Engineer Questions]

Your organization has implemented synchronization and SAML federation between Cloud Identity and Microsoft Active Directory. You want to reduce the risk of
Google Cloud user accounts being compromised. What should you do?

  • A. Create a Cloud Identity password policy with strong password settings, and configure 2-Step Verification with security keys in the Google Admin console.
  • B. Create a Cloud Identity password policy with strong password settings, and configure 2-Step Verification with verification codes via text or phone call in the Google Admin console.
  • C. Create an Active Directory domain password policy with strong password settings, and configure post-SSO (single sign-on) 2-Step Verification with security keys in the Google Admin console.
  • D. Create an Active Directory domain password policy with strong password settings, and configure post-SSO (single sign-on) 2-Step Verification with verification codes via text or phone call in the Google Admin console.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
coco10k
Highly Voted 1 year, 5 months ago
Answer C: "We recommend against using text messages. The National Institute of Standards and Technology (NIST) no longer recommends SMS-based 2SV due to the hijacking risk from state-sponsored entities."
upvoted 6 times
gcpengineer
11 months, 2 weeks ago
user account doesnt need admin console access
upvoted 1 times
...
...
uiuiui
Most Recent 5 months, 2 weeks ago
Selected Answer: C
"C" Please
upvoted 2 times
...
[Removed]
9 months ago
Selected Answer: C
"C" Because it's federated access, the password policy stays with the origin IDP (Active Directory in this case) while the post-sso behavior/controls are in Google Cloud. In terms of the actual second factor, security keys are far more secure than otp via text since those can be defeated through smishing or other types of attacks. https://cloud.google.com/architecture/identity/federating-gcp-with-active-directory-introduction#implementing_federation https://cloud.google.com/identity/solutions/enforce-mfa#use_security_keys
upvoted 4 times
...
AwesomeGCP
1 year, 6 months ago
Selected Answer: C
C. Create an Active Directory domain password policy with strong password settings, and configure post-SSO (single sign-on) 2-Step Verification with security keys in the Google Admin console.
upvoted 3 times
...
jitu028
1 year, 6 months ago
Answer is - C https://cloud.google.com/identity/solutions/enforce-mfa#use_security_keys Use security keys We recommend requiring security keys for those employees who create and access data that needs the highest level of security. You should require 2SV for all other employees and encourage them to use security keys. Security keys offer the most secure form of 2SV. They are based on the open standard developed by Google as part of the Fast Identity Online (FIDO) Alliance. Security keys require a compatible browser on user devices.
upvoted 2 times
AzureDP900
1 year, 5 months ago
Agree with C and explanation
upvoted 1 times
...
...
szl0144
1 year, 11 months ago
C is the answer because security key is securer than 2FA code
upvoted 4 times
...
mT3
1 year, 11 months ago
Selected Answer: C
C:correct answer
upvoted 4 times
...
mouchu
1 year, 11 months ago
Answer = B
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago