Practice GWS-ADMIN Security Policies And Access Controls questions with full explanations on every answer.
Start practicing
Security Policies And Access Controls — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
Your organization requires all contractors to use security keys for 2-Step Verification, while full-time employees can use prompts or authenticator apps. How should you configure this in the Google Admin console?
2You need to create a custom administrator role that allows specific users to manage Google Meet hardware devices and review their health status, but nothing else. Which privilege category should you select when building this custom role?
3An administrator needs to configure password requirements, such as minimum length and expiration policies, for all users in the domain. Where is this configured in the Google Admin console?
4Your organization has configured third-party SAML SSO. However, you need to ensure that Super Administrators can always bypass SSO and sign in using their Google credentials in case the third-party IdP goes down. What configuration setting should you enable?
5You need to ensure that users can only access Google Workspace services when they are connecting from corporate-owned devices managed by Endpoint Management and located within the corporate IP range. Which feature combination meets this requirement?
6An administrator needs to grant a helpdesk employee the ability to reset user passwords and view user information without granting them full super administrator privileges. Which built-in admin role should be assigned?
7Your company uses a third-party Identity Provider (IdP) for Single Sign-On (SSO) via SAML. A newly hired employee is unable to sign in, and you suspect their account is not properly mapped or provisioned. Where can you check SAML sign-in activity and error logs in the Google Admin console?
8An administrator needs to enforce 2-Step Verification for all users in the Sales organizational unit (OU). Where in the Google Admin console should the administrator navigate to configure this setting?
9An organization wants to prevent users from signing in to their Google Workspace accounts from outside their home country. Which feature should the administrator configure?
10Your organization wants to prevent users from sharing Google Drive files externally, but you need to make an exception for a specific partner domain. Where should you configure this allowed domain list?
11An administrator has configured a new SAML SSO integration with a third-party IdP. Users are complaining that they can log in successfully, but after 30 minutes, they are unexpectedly forced to re-authenticate. Where can the administrator adjust the session duration for SAML apps?
12Your company requires that any user attempting to access Google Drive from an unmanaged mobile device must be blocked, while desktop browsers on unmanaged devices are permitted read-only access via Context-Aware Access. How should you structure your Access Levels and assignments?
13Your company has an external contractor who needs temporary access to Google Workspace. You want to ensure their account automatically deactivates after 30 days without manual administrative intervention. How can you achieve this securely?
14An administrator needs to view a report showing which users in the organization have not enabled 2-Step Verification. Where should the administrator look in the Google Admin console?
15You need to ensure that administrative actions taken by Super Administrators trigger real-time alerts to the security team's email distribution list. Which tool should you use to set this up?
16An administrator wants to ensure that users cannot use weak or commonly breached passwords. Where can password monitoring be enabled in the Google Admin console?
17Your company has deployed a custom internal web application that integrates with Google Workspace via SAML. During testing, users receive a '403. That’s an error. Error: app_not_configured_for_user' message. What is the most likely cause of this error?
18An administrator needs to restrict access to Google Workspace apps so that users can only log in from corporate-managed Chromebooks and Windows devices enrolled in Endpoint Management, while blocking all mobile devices entirely. How should this be implemented?
19You are troubleshooting an issue where a user is unable to authenticate via SAML SSO. You need to inspect the raw SAML request and response messages sent between the IdP and Google Workspace. What is the most effective way to capture this?
20Your security team requires that all administrators must use a hardware security key (FIDO2) for 2-Step Verification and are prohibited from using SMS or phone prompts. Where can you enforce this requirement specifically for admin accounts?
21An administrator needs to delegate the role of creating and managing Google Groups across the entire domain without giving full admin rights. Which built-in role should be assigned?
22Your company has integrated Google Workspace with a third-party IdP using SAML. You want to make sure that when users sign out of Google Workspace, they are also signed out of their IdP session. What feature should you configure?
23An administrator wants to ensure that users cannot reuse any of their last 5 passwords when changing their password. Where is this setting configured?
24You need to create a custom administrator role that allows a security analyst to use the Security Center Investigation Tool, view audit logs, and manage alerts, but prevents them from modifying user passwords or organizational unit structures. Which exact set of privileges should you assign?
25Your organization uses Context-Aware Access to restrict access to Google Workspace based on IP address ranges. A remote employee traveling for business is unable to access Gmail from a trusted hotel Wi-Fi. How should the administrator temporarily grant access without compromising long-term security?
26An administrator needs to review recent security alerts and proactive recommendations for improving domain security. Where should they look first in the Google Admin console?
27An organization wants to integrate Google Workspace with an external SAML IdP. However, some users (such as external contractors) should continue authenticating directly against Google's native login page using their Google password and 2SV. How should the administrator configure SSO to support this mixed environment?
28Which TWO actions should an administrator take to secure administrative accounts against credential theft and unauthorized access? (Choose two.)
29When setting up SAML SSO with a third-party Identity Provider (IdP), which THREE pieces of information must typically be exchanged or configured in the Google Admin console? (Choose three.)
30Which THREE features or tools in Google Workspace can be used to monitor and investigate suspicious sign-in activity or security anomalies? (Choose three.)
31An administrator is configuring Context-Aware Access to secure corporate data. Which TWO criteria can be evaluated within a Context-Aware Access access level expression? (Choose two.)
32Which TWO mechanisms can an administrator use to recover access if a Super Administrator loses their 2-Step Verification device and is locked out? (Choose two.)
33Which TWO practices are recommended when configuring organizational units (OUs) for security policy enforcement in Google Workspace? (Choose two.)
34An enterprise organization is planning its 2-Step Verification (2SV) rollout. Which THREE methods or tokens are natively supported by Google Workspace for 2SV authentication? (Choose three.)
35An administrator wants to configure security policies to protect corporate data on mobile devices. Which THREE actions can be enforced through Google Workspace Endpoint Management? (Choose three.)
36An administrator is reviewing API controls and third-party app access in Google Workspace. Which THREE access states can be configured for third-party OAuth applications? (Choose three.)
37An organization wants to configure SSO with a third-party SAML IdP. Which THREE advanced settings can be configured within the Google Workspace SAML application settings? (Choose three.)
38You need to enforce 2-Step Verification for a specific department while allowing others to opt-in voluntarily. Which configuration path should you use?
39Which TWO reports or logs should an administrator check to verify whether Context-Aware Access rules are successfully blocking unauthorized connection attempts? (Choose two.)
40Your organization requires that users can only access Google Drive when connected to the corporate VPN. How can you achieve this using Context-Aware Access?
41An auditor requests that you restrict administrative access to the Google Workspace Admin console to a specific set of IP addresses. What is the most effective way to implement this?
42A new IT support staff member needs to manage user passwords but should not be able to delete users or modify billing settings. Which role should you assign?
43Your organization uses a third-party Identity Provider (IdP) for SSO. Users are reporting that they cannot sign in. Where do you verify the SAML configuration?
44You need to prevent users from installing third-party Marketplace apps that request access to their Gmail data. What is the best approach?
45You want to ensure that all users have a strong password policy. Where can you enforce password length and complexity requirements?
46Which TWO of the following are valid criteria for a Context-Aware Access level? (Choose two)
47Which THREE actions should you take to secure your Google Workspace environment against unauthorized admin access? (Choose three)
48Which TWO of the following are valid methods to verify domain ownership in Google Workspace? (Choose two)
The Security Policies And Access Controls domain covers the key concepts tested in this area of the GWS-ADMIN exam blueprint published by Google Cloud. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all GWS-ADMIN domains — no account required.
The Courseiva GWS-ADMIN question bank contains 48 questions in the Security Policies And Access Controls domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security Policies And Access Controls domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included