Courseiva

Cloud Digital Leader Trust and security with Google Cloud Practice Question

A company's security policy requires all employees to verify their identity using more than just a password when accessing Google Cloud resources. What security feature enforces this requirement?

⚠ Common exam trap

It's easy for candidates to confuse 'stronger authentication' with 'stronger passwords' (Option A) or 'access restrictions' (Option C), failing to recognize that the core requirement is adding an independent second factor, not just hardening the single password factor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Multi-factor authentication (MFA) / Two-step verification (2SV).

Multi-factor authentication (MFA) / Two-step verification (2SV) is the correct answer because it explicitly requires users to provide two or more verification factors (e.g., something you know, something you have, something you are) to access Google Cloud resources. This directly enforces the policy of verifying identity beyond just a password, as MFA/2SV adds an additional layer of security by requiring a second factor such as a time-based one-time password (TOTP) from an authenticator app, a hardware security key (e.g., FIDO2), or a push notification. Google Cloud Identity Platform supports this via security key enforcement and 2SV policies, ensuring that password compromise alone is insufficient for access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Password complexity requirements — enforcing long, complex passwords.

    Why it's wrong here

    Enforcing long, complex passwords increases the search space for brute-force attacks and slows down password guessing, but it remains a single knowledge factor. If a user's password is phished or lifted by a keylogger, complexity does nothing to stop reuse of that stolen credential. MFA adds a second independent factor that an attacker cannot obtain from the same breach.

  • ✓

    Multi-factor authentication (MFA) / Two-step verification (2SV).

    Why this is correct

    MFA requires a second factor—something you have (TOTP app, hardware security key) or something you are (biometric)—in addition to the password. This means that even if the password is stolen through phishing or credential stuffing, the attacker cannot authenticate without the second factor. It directly protects against the most common credential-based attacks.

  • ✗

    IP allowlisting — only allowing access from office IP addresses.

    Why it's wrong here

    IP allowlisting restricts access to traffic originating from approved network ranges, but network location is not a user attribute and can be shared, spoofed, or reached via VPN. It also breaks legitimate access for remote employees on non-approved networks. MFA verifies possession or inherence factors tied to the user, not the originating network address.

  • ✗

    Session timeout — automatically logging out users after 30 minutes of inactivity.

    Why it's wrong here

    A 30-minute session timeout is a session management control that terminates an authenticated session after inactivity, limiting the damage from an abandoned workstation. It does not verify the user's identity during login; an attacker with a valid password can still authenticate. MFA strengthens the initial authentication step rather than managing post-login session lifecycle.

About these practice questions

This GCDL question is part of Courseiva's 848-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.