What is the maximum number of custom aliases a user can have?
This is the official limit for aliases per user.
Why this answer
Google allows up to 30 aliases per user.
208 questions total · 3pages · All types, answers revealed
Page 1 of 3
Page 2What is the maximum number of custom aliases a user can have?
This is the official limit for aliases per user.
Why this answer
Google allows up to 30 aliases per user.
Which TWO mechanisms can an administrator use to recover access if a Super Administrator loses their 2-Step Verification device and is locked out? (Choose two.)
Another Super Admin can navigate to the user's profile and turn off or reset 2SV settings.
Why this answer
Super admin account recovery can be achieved using backup verification codes generated in advance or by another Super Admin resetting 2SV.
Which TWO of the following steps are required to offboard a user and protect company data?
This ensures critical data is retained.
Why this answer
Offboarding involves transferring ownership of Drive data and potentially revoking access to devices/apps.
An employee is reporting that they cannot access corporate Gmail on their personal Android device. You have set up 'Advanced mobile management'. What is the most likely cause if the device is showing as 'Blocked' in the Admin console?
Advanced management often requires manual approval for new devices.
Why this answer
Under Advanced mobile management, devices must be approved by an administrator or meet specific compliance rules before they can sync corporate data.
How can you ensure that deleted emails are kept for 3 years even if the user empties their trash?
Vault retention rules preserve data regardless of user deletion actions.
Why this answer
A Vault retention rule for Gmail with a 3-year duration ensures all emails are preserved for that period, overriding user deletion.
You need to block a specific version of the Chrome browser because of a security vulnerability. Which setting do you use?
This allows you to manage which versions are allowed.
Why this answer
Chrome browser management allows you to enforce version policies to ensure users are on secure versions.
You need to prevent users from sharing Google Drive files with people outside the organization. Which setting should you modify?
This is where sharing permissions for external domains are controlled.
Why this answer
Sharing settings are controlled at the Organizational Unit level under Apps > Google Workspace > Drive and Docs > Sharing settings.
You are automating user creation via the Directory API. Which scope is required to create users?
This is the specific scope for managing user directory resources.
Why this answer
The admin.directory.user scope is required for CRUD operations on user objects.
You need to prevent users from installing third-party Marketplace apps that request access to their Gmail data. What is the best approach?
App Access Control allows you to manage app permissions and block specific scopes like Gmail.
Why this answer
The 'App Access Control' settings allow administrators to block third-party apps based on the OAuth scopes they request.
Which THREE security settings are commonly configured using Context-Aware Access?
Ensures the device meets security standards.
Why this answer
Context-aware access allows restricting access to apps based on device security posture, IP, and location.
An administrator needs to view all changes made to organizational units. Which report should they use?
The Admin audit log tracks all administrative actions in the console.
Why this answer
The Admin Audit log records all configuration changes within the Google Admin console.
You are configuring Endpoint Verification. What is the primary purpose of the Endpoint Verification extension on a user's browser?
The extension reports device state to Google to enable context-aware access policies.
Why this answer
Endpoint Verification collects device metadata (serial number, encryption, OS) and reports it to the Admin console for access context.
A user is receiving an 'Access Denied' message when attempting to log into a SAML application managed via Google. Which log should you check first?
These logs are designed to troubleshoot SSO and SAML integration errors.
Why this answer
The SAML app logs in the Admin console provide details regarding authentication failures for third-party SSO applications.
You want to prevent sensitive Drive documents from being printed. Which setting is appropriate?
This setting explicitly disables download, print, and copy for shared files.
Why this answer
Drive sharing settings include an option to disable downloading, printing, and copying for viewers and commenters.
What is the primary function of an alias address?
Aliases allow users to receive mail at multiple addresses in one account.
Why this answer
An alias is an additional email address for an existing user that routes mail to the same inbox.
Which feature prevents a user from being deleted during a directory sync?
This prevents accidental deletion via sync.
Why this answer
The 'Do not delete' flag in GCDS prevents the sync process from removing accounts that don't match the source directory.
Your organization uses ChromeOS devices. You want to enforce a policy that prevents users from using guest mode on these devices. Where do you configure this?
Guest mode is a device-level setting found under Chrome > Device settings.
Why this answer
ChromeOS device settings are managed under Devices > Chrome > Settings > Device settings.
Which TWO actions can you take when a user account is under a Vault hold?
This is the core purpose of a hold.
Why this answer
A hold ensures the data is not deleted, even if the user attempts to delete it or if the account is suspended/deleted.
Where do you go to view a list of all devices currently accessing your organization's data?
This is the inventory page for all managed devices.
Why this answer
The 'Devices' section in the Admin console provides a centralized view of all mobile and desktop devices.
Which TWO of the following can be restricted in Google Drive sharing settings?
Allows restricting to only authenticated Google accounts.
Why this answer
You can restrict sharing to external domains and prevent sharing with non-Google accounts.
Which setting allows you to see what files are being shared externally across your entire domain?
This tool provides visibility into Drive activity, including external sharing.
Why this answer
The Security Investigation Tool allows administrators to search and audit Drive file sharing activities across the organization.
Which THREE settings can be enforced on Android devices using Advanced mobile management?
Administrators can push and manage apps on Android devices.
Why this answer
Advanced management allows for mandatory passcodes, managed applications, and remote wipe capabilities.
A user claims they cannot share a file with an external partner. What is the most likely cause within the Admin console?
Administrators often configure sharing policies to prevent users from sharing outside the organization.
Why this answer
Sharing settings in Drive and Docs are controlled at the Organizational Unit (OU) level, which can restrict external sharing.
Your organization uses Context-Aware Access to restrict access to Google Workspace based on IP address ranges. A remote employee traveling for business is unable to access Gmail from a trusted hotel Wi-Fi. How should the administrator temporarily grant access without compromising long-term security?
Moving the user to an exempted OU or updating group/OU assignments for CAA provides targeted, temporary relief.
Why this answer
Administrators can assign temporary access levels or temporarily move the user to an OU without the CAA restriction.
Which THREE settings can be configured within the Gmail Compliance section?
Allows scanning of email content based on rules.
Why this answer
Compliance includes content compliance, attachment compliance, and profanity checks.
Your legal team requires that all emails from a specific user be preserved for an upcoming audit. Which tool should you use to ensure these messages are not deleted?
Vault allows administrators to set retention rules and holds to preserve data for legal purposes.
Why this answer
Google Vault is designed for eDiscovery and retention. Setting a retention rule or hold in Vault ensures data is preserved regardless of user actions.
You need to ensure that administrative actions taken by Super Administrators trigger real-time alerts to the security team's email distribution list. Which tool should you use to set this up?
Alert Center custom rules allow you to monitor Workspace logs and trigger alerts and email notifications automatically.
Why this answer
Alert Center rules allow administrators to configure notification triggers for specific admin activity log events.
Where do you manage the shared contacts for your organization?
This is where directory sharing and shared contacts are configured.
Why this answer
Shared contacts are managed in the Directory settings of the Admin console.
You are implementing context-aware access and need to ensure that only devices with a disk-encrypted state are allowed to access Google Drive. Which feature enables this check?
Access Levels allow you to define rules based on device attributes like disk encryption.
Why this answer
Context-aware access policies use attributes provided by Endpoint Verification to grant or deny access based on device state.
Which TWO of the following can be modified in the Admin console's 'Company Profile' section?
This is a standard company profile field.
Why this answer
The company profile section manages organization-wide details like the company name and support contact information.
You need to ensure that all corporate-owned Android devices require a screen lock. Where should you configure this setting?
This is the correct path to enforce screen lock requirements for Android devices.
Why this answer
Mobile settings in the Google Admin console are where device security policies like screen lock requirements are defined.
Which TWO of the following can be configured in the Google Workspace Admin Console to restrict user access to Google Drive?
This restricts external collaboration.
Why this answer
Access to Drive is controlled by Sharing settings and Drive API controls.
A user claims they cannot reset their password using the 'Forgot Password' link. What is the most likely cause?
This setting controls access to the self-service password tool.
Why this answer
If 'Allow users to reset their passwords' is disabled in the Security settings, they cannot use the self-service flow.
Which of the following is true regarding 'Advanced' mobile management for iOS?
These are key features of Advanced management for iOS.
Why this answer
Advanced management provides more control, such as certificate management and enterprise Wi-Fi configuration, compared to Basic management.
A user is unable to access Google Drive. Which TWO of the following should you check first?
A suspended account will cause access issues for all services.
Why this answer
Verifying the user's account status and checking the service status for the specific user are the first steps in troubleshooting access issues.
You need to ensure that credit card numbers are not sent via Gmail by your employees. Which tool should you configure?
DLP rules scan for sensitive patterns and block or alert based on policy.
Why this answer
DLP rules in Google Workspace allow administrators to define content detectors to scan for sensitive information like credit card numbers.
You have enabled 'Google+ ' for your organization, but some users cannot see it. What is the most likely cause?
If the service is off for their OU, they cannot use it.
Why this answer
Service visibility is controlled at the OU level; ensure the service is 'ON' for that specific OU.
Which TWO practices are recommended when configuring organizational units (OUs) for security policy enforcement in Google Workspace? (Choose two.)
Auditing ensures users who change roles are moved to appropriate OUs with correct security settings.
Why this answer
Best practices for OUs include inheriting policies from parent OUs where possible and structuring OUs logically by department or security requirement.
You need to add a secondary domain to your Google Workspace account. What must you perform after adding the domain in the Admin console?
Verification via TXT or CNAME record is a prerequisite for domain use.
Why this answer
Verification is mandatory to prove domain ownership via DNS records.
An enterprise organization is planning its 2-Step Verification (2SV) rollout. Which THREE methods or tokens are natively supported by Google Workspace for 2SV authentication? (Choose three.)
TOTP codes generated by authenticator apps are natively supported.
Why this answer
Google Workspace supports security keys (FIDO2/U2F), Google Prompts on mobile devices, and authenticator app OTP codes (TOTP).
How can you prevent users from changing their profile photo?
This setting allows admins to restrict photo and other profile edits.
Why this answer
Directory profile settings allow admins to restrict which profile details users can modify.
You are seeing a 'Domain already in use' error when adding a domain. What is the most likely cause?
Google enforces domain exclusivity per workspace instance.
Why this answer
A domain can only be registered in one Google Workspace account at a time; it must be removed from the other instance first.
Which TWO of the following are true regarding the Directory API?
OAuth 2.0 is the standard for API security.
Why this answer
The Directory API uses OAuth 2.0 for authentication and requires specific scopes to function.
You need to enforce 2-Step Verification for a specific department while allowing others to opt-in voluntarily. Which configuration path should you use?
Applying the setting to a specific OU allows targeted enforcement for that department.
Why this answer
To enforce 2SV for specific users, you must use Organizational Units (OUs) or Groups and manage the enforcement settings under Security > Authentication > 2-step verification.
Your organization wants to prevent users from sharing Google Drive files externally, but you need to make an exception for a specific partner domain. Where should you configure this allowed domain list?
Drive sharing permissions and trusted external domains are configured directly in the Drive and Docs sharing settings.
Why this answer
Allowed external domains for sharing are managed under Apps > Google Workspace > Drive and Docs > Sharing settings.
Your company uses a third-party Identity Provider (IdP) for Single Sign-On (SSO) via SAML. A newly hired employee is unable to sign in, and you suspect their account is not properly mapped or provisioned. Where can you check SAML sign-in activity and error logs in the Google Admin console?
Reporting > Audit > SAML displays details regarding SSO sign-in attempts and SAML errors.
Why this answer
Log events related to SAML and SSO authentication failures are recorded in the SAML log events section of the Google Admin console.
What is the difference between a primary domain and a secondary domain?
Primary defines the account foundation and initial login.
Why this answer
The primary domain is the identity foundation of the Workspace account, used for initial setup and service naming.
Which THREE features or tools in Google Workspace can be used to monitor and investigate suspicious sign-in activity or security anomalies? (Choose three.)
The Investigation Tool allows administrators to query logs, devices, and user activities to remediate threats.
Why this answer
Suspicious activity can be tracked using Audit logs, the Security Center Investigation Tool, and Alert Center.
Which THREE of the following are valid ways to manage Google Calendar resource availability?
Configurable for room resources.
Why this answer
Resources are managed via building assignment, auto-accept rules, and visibility settings.
You need to change the default language and region settings for all new users in a specific Organizational Unit. How do you do this?
This is where you define default region and language settings for users in an OU.
Why this answer
Account settings, including time zone and language, are configured per OU under Account > Account settings.
You need to distribute a specific internal Android app to a subset of users. What is the most efficient way to achieve this using Google Workspace?
This allows for silent installation and controlled app distribution.
Why this answer
Adding the app to the managed Google Play store and assigning it to specific organizational units (OUs) allows for controlled distribution.
Which THREE of the following attributes can be used in Context-Aware Access policies?
This ensures devices are updated and secure.
Why this answer
Device management status, encryption, and OS version are commonly used in access policies.
Which TWO actions can you perform in Google Vault?
Search and export are core Vault functions.
Why this answer
Vault allows you to place holds on data to prevent deletion and perform searches across user mail and files for eDiscovery.
Your organization requires all contractors to use security keys for 2-Step Verification, while full-time employees can use prompts or authenticator apps. How should you configure this in the Google Admin console?
Targeting policies via OUs allows you to restrict allowed 2SV methods exclusively to security keys for specific subsets of users.
Why this answer
Security key enforcement can be targeted to specific organizational units or security groups by setting the 2SV policy appropriately.
An administrator notices unusual login activity from a specific geographic location. What is the first step to prevent further unauthorized access?
Suspending the account immediately terminates all active sessions.
Why this answer
Suspending the user account is the immediate action to stop ongoing unauthorized access while investigating.
A user is unable to install a managed app on their iOS device. What is the first thing you should verify?
Management status is the prerequisite for app deployment.
Why this answer
If the device is not enrolled or is in an 'Unmanaged' state, managed apps cannot be pushed to it.
Your company has integrated Google Workspace with a third-party IdP using SAML. You want to make sure that when users sign out of Google Workspace, they are also signed out of their IdP session. What feature should you configure?
Configuring the SLO URL in the Google Admin console enables Single Logout integration with the IdP.
Why this answer
Single Logout (SLO) allows users to terminate their session across both Google Workspace and the configured SAML IdP.
Which THREE items can be managed through the 'Directory' section in the Admin Console?
Managed under Directory > Profile editing.
Why this answer
Directory manages buildings, resources, and user profiles.
You want to require that all corporate-owned iOS devices are encrypted. How is this achieved?
Enforcing a passcode on iOS devices ensures the data partition is encrypted.
Why this answer
Apple devices (iOS) are encrypted by default when a passcode is set. Therefore, enforcing a passcode policy effectively enforces encryption.
When troubleshooting a SAML application error, which THREE of the following should you check?
Incorrect metadata causes authentication failures.
Why this answer
The SAML metadata, user mapping, and certificate status are essential for SAML configuration.
Where can an administrator view the status of a user's 2-Step Verification enrollment?
This is where you view specific security status for an individual user.
Why this answer
User security information, including 2SV status, is found in the individual user's profile within the Directory.
Your company has deployed a custom internal web application that integrates with Google Workspace via SAML. During testing, users receive a '403. That’s an error. Error: app_not_configured_for_user' message. What is the most likely cause of this error?
Service status must be set to ON for everyone or turned on for specific OUs/groups to allow user access to custom SAML apps.
Why this answer
This error occurs when the SAML app is configured in the Google Admin console, but access is turned OFF for the user or their organizational unit.
Your company wants to prevent employees from using personal Google accounts on company-owned ChromeOS devices. Which setting should you enable?
This policy allows you to restrict sign-in to specific domains.
Why this answer
Blocking accounts on managed ChromeOS devices is a standard device policy to prevent data exfiltration.
An organization is failing to receive emails from a specific sender. The logs show the messages were rejected by the 'Spam Filter'. What should you do?
This whitelist entry allows messages from trusted sources to bypass spam filters.
Why this answer
Adding the sender's domain or IP to the 'Approved senders' list in the Gmail settings will allow the messages to bypass spam filtering.
You need to ensure that Chrome browsers on unmanaged devices are secure. What is a key step to take?
Cloud management allows you to enforce security policies on browsers.
Why this answer
Enforcing Chrome browser management allows you to apply policies to the browser regardless of the OS of the underlying device.
You have a mix of company-owned and BYOD mobile devices. You want to apply different policies to each. What is the recommended strategy?
OUs are the standard way to apply granular policies.
Why this answer
Using different Organizational Units (OUs) allows you to apply different MDM policies to different groups of devices or users.
A user has left the company. You need to migrate their data to another user. Which tool should you use?
This is the correct tool for migrating email, calendar, and contacts.
Why this answer
The Data Migration Service is specifically designed for moving data from one Google account to another.
You need to ensure that users can only access Google Workspace services when they are connecting from corporate-owned devices managed by Endpoint Management and located within the corporate IP range. Which feature combination meets this requirement?
Context-Aware Access evaluates access levels containing attributes for both IP subnets and device policy status before granting access.
Why this answer
Context-Aware Access allows you to combine IP address subnets and device-policy compliance (corporate-owned status via endpoint management) to control access.
Which THREE of the following are types of reports available in the 'Reports' section of the Admin console regarding mobile devices?
This shows security status like encryption and passcodes.
Why this answer
Device usage, audit events, and compliance reports are standard reports in Google Workspace.
Which TWO of the following are valid methods to audit file access in Google Drive?
Provides granular search for Drive activity.
Why this answer
Audit logs and the Investigation tool are the standard ways to monitor file activity.
Which THREE types of data can be managed using Vault retention rules?
Supported for retention.
Why this answer
Vault supports retention for Gmail, Drive, Chat, Groups, and Voice data.
You want to prevent users from copying data from managed apps into personal apps on their mobile devices. Which feature should you configure?
These settings specifically control data flow between work and personal apps.
Why this answer
Data protection features within mobile management help restrict data movement between work and personal containers.
A user needs to see their login history. Where can you find this information?
This report provides detailed login information for users.
Why this answer
The user's security log in the Admin console shows login attempts and device information.
Which TWO of the following are types of domains in Google Workspace?
This is an additional domain added to the account.
Why this answer
Google Workspace recognizes primary domains and secondary domains as types of managed domains.
An administrator needs to delegate the role of creating and managing Google Groups across the entire domain without giving full admin rights. Which built-in role should be assigned?
Groups Admin allows creation, deletion, and management of Google Groups settings.
Why this answer
The Groups Admin role specifically grants privileges to manage Google Groups.
Page 1 of 3
Page 2Practice GWS-ADMIN by domain
Target a specific domain to shore up weak areas.