nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #297

You work for a large organization that is using Cloud Identity as the identity provider (IdP) on Google Cloud. Your InfoSec team has mandated the enforcement of a strong password with a length…

The correct answer is B. Review the organization password management setting and select Enforce password policy at. In Google Admin Console, configuring a password strength policy (minimum length, complexity) only applies to passwords set after the policy was configured. Existing user accounts with non-compliant passwords continue to work until their password is changed. To retroactively…

Submitted by tom_us· Apr 18, 2026Configuring access within a cloud solution environment

Question

You work for a large organization that is using Cloud Identity as the identity provider (IdP) on Google Cloud. Your InfoSec team has mandated the enforcement of a strong password with a length between 12 and 16 characters for all users. After configuring this requirement, users are still able to access the Google Cloud console with passwords that are less than 12 characters. You need to fix this problem within the Admin console. What should you do?

Options

  • AReview each user's password configuration and reset existing passwords.
  • BReview the organization password management setting and select Enforce password policy at
  • CReview each user's password configuration and select Enforce strong password.
  • DReview the organization password management setting and select Enforce strong password.

How the community answered

(29 responses)
  • A
    10% (3)
  • B
    83% (24)
  • C
    3% (1)
  • D
    3% (1)

Explanation

In Google Admin Console, configuring a password strength policy (minimum length, complexity) only applies to passwords set after the policy was configured. Existing user accounts with non-compliant passwords continue to work until their password is changed. To retroactively enforce the new policy, an administrator must select 'Enforce password policy at next sign-in' in the organization's password management settings. This forces all users whose current passwords do not meet the policy to create a new compliant password on their next login attempt. Option A resets individual passwords manually, which is impractical at scale. Option C sets 'Enforce strong password' per user, which is similarly manual and doesn't enforce minimum length. Option D enables 'Enforce strong password' at the org level but does not trigger immediate re-enrollment of existing non-compliant passwords.

Topics

#Cloud Identity#Password Policies#Policy Enforcement#Identity Management Configuration

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice