Associate Cloud Workspace Administrator · Free Practice Question Hard
Question 21
You are the Google Workspace Administrator for a large organization. Considering the recent surge in cyber-attacks, you decide to enforce advanced 2-step Verification methods for all high-risk accounts, including administrators. Which of the following configurations will ensure that only physical security keys can be used for 2-step Verification, thereby disabling other less secure methods like SMS?
-
A
Configure a Context-Aware Access level to require physical security keys for high-risk groups.
-
B
Set up a password vaulting system and enforce its usage for all administrators.
-
C
Enforce a universal 2-step Verification policy and turn off SMS verification in the Google Admin console.
-
D
Use Google Cloud Identity Platform to mandate physical security keys for select user groups.
Reveal correct answer
Correct answer: A
A. Configuring a Context-Aware Access level to require physical security keys for high-risk groups ensures that only physical security keys can be used for 2-step Verification. This setting allows for a more granular control over authentication methods based on user groups and their risk levels, effectively disabling less secure methods like SMS.
B. Setting up a password vaulting system and enforcing its usage for all administrators does not directly address the requirement of using physical security keys for 2-step Verification. While password vaulting enhances password security, it does not specifically disable less secure methods like SMS for 2-step Verification.
C. Enforcing a universal 2-step Verification policy and turning off SMS verification in the Google Admin console may disable SMS as a verification method, but it does not ensure that only physical security keys can be used for 2-step Verification. This approach may impact all users, not just high-risk accounts.
D. Using Google Cloud Identity Platform to mandate physical security keys for select user groups is a valid approach, but it does not specifically address the requirement of enforcing physical security keys for high-risk accounts, including administrators. This method may be suitable for certain user groups, but it does not provide the necessary granularity to target only high-risk accounts.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
