Google Cloud · Free Practice Questions · Last reviewed May 2026
36real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
Which setting allows you to see what files are being shared externally across your entire domain?
Drive Audit Log
Apps > Google Workspace > Drive > Sharing audit
Report > User Reports > Drive
Security Investigation Tool
This tool provides visibility into Drive activity, including external sharing.
You need to prevent users from sharing Google Drive files with people outside the organization. Which setting should you modify?
Directory > Users > Sharing
Account > Organizational units > Restrictions
Security > Access and data control > Drive
Apps > Google Workspace > Drive and Docs > Sharing settings
This is where sharing permissions for external domains are controlled.
You want to ensure that all internal Google Calendar invites include a link to a Google Meet session. Where do you configure this?
Apps > Google Workspace > Google Meet > Meet video settings
This setting allows you to automatically add video calls to Calendar events.
Apps > Google Workspace > Calendar > Settings
Security > Calendar > Video call settings
Apps > Google Workspace > Calendar > Sharing options
You need to limit the number of participants in a Google Meet session to 10 for a specific organizational unit. How do you achieve this?
It is not possible to limit participant counts via Admin Console
Participant limits are determined by the Google Workspace edition, not by custom admin settings.
Modify the OU policy in Apps > Google Workspace > Meet
Use a group policy for Meet access
Set 'Participant limit' in the Meet settings
A user deleted a document from their Google Drive three days ago. As an administrator, what is the maximum time you can restore this file?
7 days
30 days
25 days
The restoration window for admins is 25 days.
Unlimited
Your organization requires that all Google Meet recordings be saved to a specific shared folder. How can you automate this?
Set the 'Default storage' path in Apps > Google Workspace > Meet
It is not possible to change the default location via Admin Console settings
Meet recordings are stored in the organizer's personal Drive; there is no global setting to redirect them.
Configure the 'Recording location' in Meet settings
Create a Drive retention policy for Meet
Want more Core Workspace Services practice?
Practice this domainA user is leaving the company. You need to keep their data for 7 years. What is the best practice?
Export all data to a PST file
Transfer Drive ownership to another user
Suspend the user account and keep it
Create a Vault hold for the user's account
A Vault hold preserves all data for the user account for as long as the hold is active.
You need to ensure that credit card numbers are not sent via Gmail by your employees. Which tool should you configure?
Context-aware access
DLP rules
DLP rules scan for sensitive patterns and block or alert based on policy.
Google Vault retention rules
Security center investigation tool
You need to prevent users from sharing sensitive files outside the organization. Which setting should you modify?
Endpoint management
Vault retention settings
Drive sharing options in the Admin Console
You can restrict external sharing at the organizational unit level.
App access control
How can you ensure that deleted emails are kept for 3 years even if the user empties their trash?
Enable endpoint management
Use an Admin Console report
Configure a Gmail filter
Set a Gmail retention rule in Google Vault
Vault retention rules preserve data regardless of user deletion actions.
Your legal team requires that all emails from a specific user be preserved for an upcoming audit. Which tool should you use to ensure these messages are not deleted?
Data Loss Prevention (DLP) rules
Google Workspace Migration for Microsoft Outlook
Admin Console Reporting
Google Vault
Vault allows administrators to set retention rules and holds to preserve data for legal purposes.
You need to investigate a potential data breach where a user downloaded a large number of sensitive files. Which tool provides the most granular audit logs for Drive file downloads?
Security center investigation tool
This tool provides detailed event logs including 'download' actions.
DLP policy logs
Vault eDiscovery search
Reports dashboard
Want more Data Governance And Compliance practice?
Practice this domainYou need to ensure that all corporate-owned Android devices require a screen lock. Where should you configure this setting?
Apps > Google Workspace > Android settings
Devices > Mobile & endpoints > Settings > Android > Password settings
This is the correct path to enforce screen lock requirements for Android devices.
Security > Authentication > Password policy
Directory > Users > Security settings
You want to require that all corporate-owned iOS devices are encrypted. How is this achieved?
Enable Advanced Mobile Management for all iOS users
Use an MDM profile to force file-level encryption
Configure a passcode policy in the iOS device management settings
Enforcing a passcode on iOS devices ensures the data partition is encrypted.
Enable the 'Require disk encryption' setting in iOS mobile settings
You are configuring Endpoint Verification. What is the primary purpose of the Endpoint Verification extension on a user's browser?
To collect device information for context-aware access
The extension reports device state to Google to enable context-aware access policies.
To enable remote wipe capabilities
To enforce password complexity
To block all malicious websites
You are setting up Context-Aware Access. You want to deny access to Google Workspace if the device is not encrypted. Which tool identifies the 'is_encrypted' attribute?
Device policy controller
Endpoint Verification extension
The extension collects the attribute and sends it to the server.
Admin console audit logs
Google Cloud Identity sync
You need to deploy a specific Android application to a subset of users. What is the correct procedure?
Instruct users to download it themselves from the Play Store
Upload the APK file to the server and email the link to users
Use a third-party MDM integration
Use the 'Apps' section in the Admin console to select the app from Managed Google Play and assign it to an OU
This is the standard, supported workflow for app deployment.
A user claims their corporate data is not being wiped after they left the company. You previously issued a 'wipe device' command. What should you check to verify the outcome?
The Admin console audit log for mobile management
The audit log records all device commands and their statuses.
The Google Cloud Platform logs
The user's account status in the directory
The user's Gmail sent items
Want more Endpoint Management practice?
Practice this domainYour organization requires all contractors to use security keys for 2-Step Verification, while full-time employees can use prompts or authenticator apps. How should you configure this in the Google Admin console?
Modify the default domain-wide sign-in security policy to require security keys globally and grant exceptions via API.
Configure Context-Aware Access to block non-security key authentications for the contractors group.
Create an IAM custom role that revokes prompt-based authentication for external users.
Place contractors in a dedicated OU, navigate to Security > Authentication > 2-step verification, and configure the allowed methods to only include security keys.
Targeting policies via OUs allows you to restrict allowed 2SV methods exclusively to security keys for specific subsets of users.
You need to create a custom administrator role that allows specific users to manage Google Meet hardware devices and review their health status, but nothing else. Which privilege category should you select when building this custom role?
Services > Google Meet hardware
Google Meet hardware management privileges are located under the Services category.
Organizational Units and Admin Roles
Mobile and Endpoints > Device Management
Security Center > Investigation Tool
An administrator needs to configure password requirements, such as minimum length and expiration policies, for all users in the domain. Where is this configured in the Google Admin console?
Apps > Google Workspace > Gmail > Security
Directory > Users > Password settings
Security > Password management
Security > Password management is the correct location to enforce length, expiration, and strong password requirements.
Account settings > Personalization > Passwords
Your organization has configured third-party SAML SSO. However, you need to ensure that Super Administrators can always bypass SSO and sign in using their Google credentials in case the third-party IdP goes down. What configuration setting should you enable?
Disable SAML SSO entirely and rely exclusively on Google's built-in OAuth service.
Enable the 'Turn on SSO for administrative accounts' option and assign a backup password.
Configure SSO profile assignment to exclude Super Administrators or use the 'Allow users to sign in with Google password' option on the SSO profile page.
Enabling the sign-in with Google password option for admins or assigning them to a separate OU without SSO enforcement ensures emergency access.
Create a Context-Aware Access rule that triggers emergency recovery mode when the IdP IP is unreachable.
You need to ensure that users can only access Google Workspace services when they are connecting from corporate-owned devices managed by Endpoint Management and located within the corporate IP range. Which feature combination meets this requirement?
Context-Aware Access access levels referencing IP subnets and device policy compliance, assigned to targeted apps.
Context-Aware Access evaluates access levels containing attributes for both IP subnets and device policy status before granting access.
Google Cloud IAM conditions with Context-Aware Access and Security Health Analytics
Domain-wide SAML SSO with custom attribute mapping for IP addresses
Advanced Protection Program combined with Context-Aware Access
An administrator needs to grant a helpdesk employee the ability to reset user passwords and view user information without granting them full super administrator privileges. Which built-in admin role should be assigned?
User Management Admin
The User Management Admin role allows resetting passwords, suspending users, and editing user profiles.
Helpdesk Admin
Groups Admin
Services Admin
Want more Security Policies And Access Controls practice?
Practice this domainA user is unable to sync their Google Drive files to their local machine using Drive for Desktop. What is the first step you should recommend?
Reset the user's password.
Reinstall the entire Google Workspace account.
Disable multi-factor authentication.
Check the Drive for Desktop application status and error logs.
The application logs provide specific error codes that indicate why the sync is failing.
An organization uses a third-party gateway to route email. Users report that emails are being marked as spam frequently. Which DNS record should you investigate to ensure Google trusts the gateway?
DKIM record
A record
SPF record
An SPF record specifies which hosts are authorized to send email on behalf of your domain.
MX record
A user is receiving an 'Access Denied' message when attempting to log into a SAML application managed via Google. Which log should you check first?
Admin Activity logs
OAuth token logs
Drive Audit logs
SAML application logs
These logs are designed to troubleshoot SSO and SAML integration errors.
A user has left the company. You need to migrate their data to another user. Which tool should you use?
Data Migration Service
This is the correct tool for migrating email, calendar, and contacts.
Security Investigation Tool
Google Takeout
Google Vault
A user claims they cannot see a shared calendar. What should you check to resolve this?
User's secondary email
Calendar sharing permissions
The owner must grant appropriate access (e.g., 'See all event details') for others to see the calendar.
User's password
Browser cache
A user reports that they are not receiving emails from an external vendor. As an administrator, where should you first look to verify if the messages reached Google's servers?
Email Log Search
Email Log Search is the primary tool for investigating mail flow issues.
Security Dashboard
Reports > User usage
Gmail > Compliance settings
Want more Troubleshooting practice?
Practice this domainYou are automating user creation via the Directory API. Which scope is required to create users?
https://www.googleapis.com/auth/admin.reports.audit.readonly
https://www.googleapis.com/auth/admin.directory.group
https://www.googleapis.com/auth/admin.directory.domain.readonly
https://www.googleapis.com/auth/admin.directory.user
This is the specific scope for managing user directory resources.
Which tool would you use to sync local Active Directory users to Google Workspace?
Google Workspace Migrate
Google Cloud Directory Sync
GCDS keeps Google Directory in sync with local AD.
Directory API
Admin SDK
An administrator mistakenly deleted a user account 10 days ago. How can you restore this account?
Contact Google Support for data recovery
Restore from a Vault export
Create a new user with the same email
Use the Restore User tool in the Admin console
The Restore User tool allows restoration within the 20-day window.
You have multiple domains in a single Google Workspace account. How can you provision users in a specific sub-domain?
Rename the primary domain
Use a group alias
Create an OU for the domain
Select the domain from the dropdown in the 'Add user' dialog
The Admin console allows choosing any verified domain during user creation.
You need to bulk upload 500 users using a CSV file. What is the required format for the CSV header row?
Email, Phone, Address
First Name, Last Name, Password, Email Address
These are the mandatory fields for bulk user creation.
FirstName, LastName, Password
Username, Role, OU
You need to add a secondary domain to your Google Workspace account. What must you perform after adding the domain in the Admin console?
Verify domain ownership
Verification via TXT or CNAME record is a prerequisite for domain use.
Create a new OU
Set up SPF records
Provision user accounts
Want more User Accounts Domains And Directory practice?
Practice this domainThe GWS-ADMIN exam has 200 questions and must be completed in 120 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 6 domains: Core Workspace Services, Data Governance And Compliance, Endpoint Management, Security Policies And Access Controls, Troubleshooting, User Accounts Domains And Directory. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Google Cloud GWS-ADMIN exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.