Associate Cloud Workspace Administrator · Free Practice Question Hard

Question 21

You are the Google Workspace Administrator for a large organization. Considering the recent surge in cyber-attacks, you decide to enforce advanced 2-step Verification methods for all high-risk accounts, including administrators. Which of the following configurations will ensure that only physical security keys can be used for 2-step Verification, thereby disabling other less secure methods like SMS?

  • A

    Configure a Context-Aware Access level to require physical security keys for high-risk groups.

  • B

    Set up a password vaulting system and enforce its usage for all administrators.

  • C

    Enforce a universal 2-step Verification policy and turn off SMS verification in the Google Admin console.

  • D

    Use Google Cloud Identity Platform to mandate physical security keys for select user groups.

Reveal correct answer

Correct answer: A

A. Configuring a Context-Aware Access level to require physical security keys for high-risk groups ensures that only physical security keys can be used for 2-step Verification. This setting allows for a more granular control over authentication methods based on user groups and their risk levels, effectively disabling less secure methods like SMS.

B. Setting up a password vaulting system and enforcing its usage for all administrators does not directly address the requirement of using physical security keys for 2-step Verification. While password vaulting enhances password security, it does not specifically disable less secure methods like SMS for 2-step Verification.

C. Enforcing a universal 2-step Verification policy and turning off SMS verification in the Google Admin console may disable SMS as a verification method, but it does not ensure that only physical security keys can be used for 2-step Verification. This approach may impact all users, not just high-risk accounts.

D. Using Google Cloud Identity Platform to mandate physical security keys for select user groups is a valid approach, but it does not specifically address the requirement of enforcing physical security keys for high-risk accounts, including administrators. This method may be suitable for certain user groups, but it does not provide the necessary granularity to target only high-risk accounts.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need