Courseiva
Trust and security with Google CloudeasyMultiple ChoiceObjective-mapped

Cloud Digital Leader Trust and security with Google Cloud Practice Question

A company's employees use Google Workspace for email, documents, and collaboration. The IT team wants to require all employees to use a physical security key (like a YubiKey) as their second authentication factor when signing in — eliminating phishing-vulnerable SMS and authenticator app codes. Which Google Workspace security capability supports this requirement?

⚠ Common exam trap

Google Cloud often tests the distinction between a user-level program (Advanced Protection Program) and an organization-wide policy (2-Step Verification policy), leading candidates to choose Option A because it mentions hardware security keys, but they miss that it is not a blanket enforcement for all employees.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Google Workspace 2-Step Verification policy configured to require hardware security keys (FIDO2/WebAuthn) for all employees, making it impossible to sign in without a physical key

Google Workspace's 2-Step Verification policy allows administrators to enforce the use of hardware security keys (FIDO2/WebAuthn) as the sole second factor. This policy can be configured to require a physical security key for all employees, effectively blocking sign-ins that use SMS or authenticator app codes, which are vulnerable to phishing. The policy directly meets the IT team's requirement to eliminate phishing-vulnerable authentication methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Google Workspace Advanced Protection Program, which enforces hardware security key requirements for high-risk users

    Why it's wrong here

    The Advanced Protection Program (APP) is a Google-wide security offering aimed at individually high-risk accounts (for example, journalists or executives), and it is not an administrator-controlled policy that can be mandated for an entire Workspace domain. It enforces security keys and restricts third-party app access, but enrollment is per-user and managed by each account owner, not enforced by a Workspace admin through the Admin Console. For organizational-wide mandatory hardware key use, the correct control is the Workspace 2-Step Verification policy, which lets admins require security keys and disable all other second-step methods for every employee.

  • Google Workspace 2-Step Verification policy configured to require hardware security keys (FIDO2/WebAuthn) for all employees, making it impossible to sign in without a physical key

    Why this is correct

    Google Workspace administrators can configure the 2SV enrollment and method requirements in the Admin Console. Setting the policy to require security keys (and disabling other 2SV methods) enforces hardware key use organization-wide. Hardware keys are phishing-resistant because they cryptographically verify the site they're authenticating to.

  • Google Cloud Identity-Aware Proxy, which enforces hardware key authentication for all Google Workspace apps

    Why it's wrong here

    Google Cloud Identity-Aware Proxy (IAP) controls access to your own applications hosted on Google Cloud, not to Google Workspace's authentication flows. It can apply context-aware access rules to your custom web apps, but it cannot enforce hardware key requirements for Google Workspace sign-in because Workspace identity policies are managed separately in the Admin Console. Even if you attempted to front a Workspace app with IAP, it would not override the Workspace-level 2-Step Verification method settings, so it is not the appropriate mechanism for organization-wide FIDO2 enforcement.

  • Cloud Armor, which blocks sign-in attempts that don't come from corporate IP addresses, eliminating the need for 2FA

    Why it's wrong here

    Cloud Armor is a network security and DDoS protection service that filters traffic to Google Cloud load-balanced resources; it does not sit in front of Google Workspace's login endpoints, which are managed by Google's identity infrastructure. Therefore, it cannot block sign-in attempts to Workspace based on corporate IP addresses. Even if IP-based restrictions were feasible, filtering by source IP does not mitigate phishing: an attacker who steals a password can authenticate from an allowed corporate host, whereas hardware security keys provide cryptographic phishing resistance that IP allowlisting cannot replicate.

About these practice questions

One of 829 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.