Courseiva

Google Cloud Associate Google Workspace Administrator (GWS-ADMIN) (GWS-ADMIN) — Questions 175

208 questions total · 3pages · All types, answers revealed

Page 1 of 3

Page 2
1
MCQeasy

What is the maximum number of custom aliases a user can have?

A.30
B.10
C.50
D.Unlimited
AnswerA

This is the official limit for aliases per user.

Why this answer

Google allows up to 30 aliases per user.

2
Multi-Selectmedium

Which TWO mechanisms can an administrator use to recover access if a Super Administrator loses their 2-Step Verification device and is locked out? (Choose two.)

Select 2 answers
A.Have another Super Administrator reset the locked admin's 2-Step Verification status in the Google Admin console.
B.Call Google Workspace technical support to instantly disable 2SV without verification.
C.Send a password reset request to the external SAML IdP to bypass Google 2SV.
D.Log in using the root domain controller administrative credentials.
E.Use pre-generated backup verification codes stored securely by the administrator.
AnswersA, E

Another Super Admin can navigate to the user's profile and turn off or reset 2SV settings.

Why this answer

Super admin account recovery can be achieved using backup verification codes generated in advance or by another Super Admin resetting 2SV.

3
Multi-Selectmedium

Which TWO of the following steps are required to offboard a user and protect company data?

Select 2 answers
A.Disable the domain
B.Transfer Drive data to another user
C.Change the user's password
D.Delete the OU
E.Add the user as an alias
AnswersB, C

This ensures critical data is retained.

Why this answer

Offboarding involves transferring ownership of Drive data and potentially revoking access to devices/apps.

4
MCQmedium

An employee is reporting that they cannot access corporate Gmail on their personal Android device. You have set up 'Advanced mobile management'. What is the most likely cause if the device is showing as 'Blocked' in the Admin console?

A.The device has not been enrolled in the corporate Wi-Fi network
B.The device is pending admin approval in the mobile devices list
C.The user's account is locked in the Admin console
D.The user has not installed the Google Device Policy app
AnswerB

Advanced management often requires manual approval for new devices.

Why this answer

Under Advanced mobile management, devices must be approved by an administrator or meet specific compliance rules before they can sync corporate data.

5
MCQeasy

How can you ensure that deleted emails are kept for 3 years even if the user empties their trash?

A.Enable endpoint management
B.Use an Admin Console report
C.Configure a Gmail filter
D.Set a Gmail retention rule in Google Vault
AnswerD

Vault retention rules preserve data regardless of user deletion actions.

Why this answer

A Vault retention rule for Gmail with a 3-year duration ensures all emails are preserved for that period, overriding user deletion.

6
MCQhard

You need to block a specific version of the Chrome browser because of a security vulnerability. Which setting do you use?

A.Device settings > Chrome > Version control
B.Admin console > Security > Browser blocking
C.User settings > Chrome > Update policy
D.Browser settings > Apps and extensions > Version pinning
AnswerD

This allows you to manage which versions are allowed.

Why this answer

Chrome browser management allows you to enforce version policies to ensure users are on secure versions.

7
MCQmedium

You need to prevent users from sharing Google Drive files with people outside the organization. Which setting should you modify?

A.Directory > Users > Sharing
B.Account > Organizational units > Restrictions
C.Security > Access and data control > Drive
D.Apps > Google Workspace > Drive and Docs > Sharing settings
AnswerD

This is where sharing permissions for external domains are controlled.

Why this answer

Sharing settings are controlled at the Organizational Unit level under Apps > Google Workspace > Drive and Docs > Sharing settings.

8
MCQhard

You are automating user creation via the Directory API. Which scope is required to create users?

A.https://www.googleapis.com/auth/admin.reports.audit.readonly
B.https://www.googleapis.com/auth/admin.directory.group
C.https://www.googleapis.com/auth/admin.directory.domain.readonly
D.https://www.googleapis.com/auth/admin.directory.user
AnswerD

This is the specific scope for managing user directory resources.

Why this answer

The admin.directory.user scope is required for CRUD operations on user objects.

9
MCQhard

You need to prevent users from installing third-party Marketplace apps that request access to their Gmail data. What is the best approach?

A.Disable the Google Workspace Marketplace for the entire domain.
B.Configure an endpoint verification policy.
C.Use the 'Allowlist' feature to block specific OAuth scopes globally.
D.Change the 'Sharing settings' in the Drive and Docs settings.
AnswerC

App Access Control allows you to manage app permissions and block specific scopes like Gmail.

Why this answer

The 'App Access Control' settings allow administrators to block third-party apps based on the OAuth scopes they request.

10
Multi-Selecthard

Which THREE security settings are commonly configured using Context-Aware Access?

Select 3 answers
A.Device security posture (e.g., screen lock)
B.User IP address
C.Email signature format
D.User password strength
E.Geographical location
AnswersA, B, E

Ensures the device meets security standards.

Why this answer

Context-aware access allows restricting access to apps based on device security posture, IP, and location.

11
MCQhard

An administrator needs to view all changes made to organizational units. Which report should they use?

A.User activity report
B.Login audit log
C.Admin audit log
D.OAuth token audit
AnswerC

The Admin audit log tracks all administrative actions in the console.

Why this answer

The Admin Audit log records all configuration changes within the Google Admin console.

12
MCQmedium

You are configuring Endpoint Verification. What is the primary purpose of the Endpoint Verification extension on a user's browser?

A.To collect device information for context-aware access
B.To enable remote wipe capabilities
C.To enforce password complexity
D.To block all malicious websites
AnswerA

The extension reports device state to Google to enable context-aware access policies.

Why this answer

Endpoint Verification collects device metadata (serial number, encryption, OS) and reports it to the Admin console for access context.

13
MCQmedium

A user is receiving an 'Access Denied' message when attempting to log into a SAML application managed via Google. Which log should you check first?

A.Admin Activity logs
B.OAuth token logs
C.Drive Audit logs
D.SAML application logs
AnswerD

These logs are designed to troubleshoot SSO and SAML integration errors.

Why this answer

The SAML app logs in the Admin console provide details regarding authentication failures for third-party SSO applications.

14
MCQhard

You want to prevent sensitive Drive documents from being printed. Which setting is appropriate?

A.Context-aware access
B.Drive sharing options for viewers/commenters
C.Endpoint management
D.DLP policy
AnswerB

This setting explicitly disables download, print, and copy for shared files.

Why this answer

Drive sharing settings include an option to disable downloading, printing, and copying for viewers and commenters.

15
MCQmedium

What is the primary function of an alias address?

A.To act as a mailing list
B.To bypass domain verification
C.To create a separate inbox
D.To provide an alternative email address for an existing user
AnswerD

Aliases allow users to receive mail at multiple addresses in one account.

Why this answer

An alias is an additional email address for an existing user that routes mail to the same inbox.

16
MCQmedium

Which feature prevents a user from being deleted during a directory sync?

A.OU locking
B.Account suspension
C.GCDS 'Do not delete' rule
D.Admin role assignment
AnswerC

This prevents accidental deletion via sync.

Why this answer

The 'Do not delete' flag in GCDS prevents the sync process from removing accounts that don't match the source directory.

17
MCQeasy

Your organization uses ChromeOS devices. You want to enforce a policy that prevents users from using guest mode on these devices. Where do you configure this?

A.Device settings
B.Network settings
C.Users & browsers settings
D.Apps & extensions settings
AnswerA

Guest mode is a device-level setting found under Chrome > Device settings.

Why this answer

ChromeOS device settings are managed under Devices > Chrome > Settings > Device settings.

18
Multi-Selectmedium

Which TWO actions can you take when a user account is under a Vault hold?

Select 2 answers
A.Automatically delete old emails
B.Prevent data deletion
C.Enable 2-Step Verification
D.Ensure data availability for eDiscovery
E.Allow the user to change their password
AnswersB, D

This is the core purpose of a hold.

Why this answer

A hold ensures the data is not deleted, even if the user attempts to delete it or if the account is suspended/deleted.

19
MCQeasy

Where do you go to view a list of all devices currently accessing your organization's data?

A.Reports > Audit > Mobile
B.Directory > Users > Device list
C.Devices > Mobile & endpoints > Devices
D.Security > Devices
AnswerC

This is the inventory page for all managed devices.

Why this answer

The 'Devices' section in the Admin console provides a centralized view of all mobile and desktop devices.

20
Multi-Selectmedium

Which TWO of the following can be restricted in Google Drive sharing settings?

Select 2 answers
A.The size of files shared via links
B.Sharing with users who do not have a Google account
C.The specific users who can use the Drive app
D.Sharing with users outside the organization
E.The number of files a user can share per day
AnswersB, D

Allows restricting to only authenticated Google accounts.

Why this answer

You can restrict sharing to external domains and prevent sharing with non-Google accounts.

21
MCQeasy

Which setting allows you to see what files are being shared externally across your entire domain?

A.Drive Audit Log
B.Apps > Google Workspace > Drive > Sharing audit
C.Report > User Reports > Drive
D.Security Investigation Tool
AnswerD

This tool provides visibility into Drive activity, including external sharing.

Why this answer

The Security Investigation Tool allows administrators to search and audit Drive file sharing activities across the organization.

22
Multi-Selecthard

Which THREE settings can be enforced on Android devices using Advanced mobile management?

Select 3 answers
A.Enable the device's GPS tracking
B.Managed application deployment
C.Force an OS update
D.Remote wipe of corporate data
E.Require a screen lock passcode
AnswersB, D, E

Administrators can push and manage apps on Android devices.

Why this answer

Advanced management allows for mandatory passcodes, managed applications, and remote wipe capabilities.

23
MCQeasy

A user claims they cannot share a file with an external partner. What is the most likely cause within the Admin console?

A.The Drive sharing settings for the user's OU restrict external sharing.
B.The user's password has expired.
C.The storage quota for the domain is full.
D.The partner does not have a Google account.
AnswerA

Administrators often configure sharing policies to prevent users from sharing outside the organization.

Why this answer

Sharing settings in Drive and Docs are controlled at the Organizational Unit (OU) level, which can restrict external sharing.

24
MCQmedium

Your organization uses Context-Aware Access to restrict access to Google Workspace based on IP address ranges. A remote employee traveling for business is unable to access Gmail from a trusted hotel Wi-Fi. How should the administrator temporarily grant access without compromising long-term security?

A.Permanently add the hotel IP subnet to the global Context-Aware Access access level.
B.Disable 2-Step Verification for the user's account.
C.Reset the user's OAuth tokens via the Admin SDK.
D.Temporarily move the user to an organizational unit that does not have the Context-Aware Access rule applied, or assign a temporary exception access level.
AnswerD

Moving the user to an exempted OU or updating group/OU assignments for CAA provides targeted, temporary relief.

Why this answer

Administrators can assign temporary access levels or temporarily move the user to an OU without the CAA restriction.

25
Multi-Selecthard

Which THREE settings can be configured within the Gmail Compliance section?

Select 3 answers
A.Content compliance
B.Profanity check
C.SPF record generation
D.Attachment compliance
E.Default signature settings
AnswersA, B, D

Allows scanning of email content based on rules.

Why this answer

Compliance includes content compliance, attachment compliance, and profanity checks.

26
MCQeasy

Your legal team requires that all emails from a specific user be preserved for an upcoming audit. Which tool should you use to ensure these messages are not deleted?

A.Data Loss Prevention (DLP) rules
B.Google Workspace Migration for Microsoft Outlook
C.Admin Console Reporting
D.Google Vault
AnswerD

Vault allows administrators to set retention rules and holds to preserve data for legal purposes.

Why this answer

Google Vault is designed for eDiscovery and retention. Setting a retention rule or hold in Vault ensures data is preserved regardless of user actions.

27
MCQhard

You need to ensure that administrative actions taken by Super Administrators trigger real-time alerts to the security team's email distribution list. Which tool should you use to set this up?

A.Google Cloud Logging exported to BigQuery with Cloud Pub/Sub triggers
B.Reporting > Audit logs > Set alert webhook
C.Security Center > Investigation Tool > Save search and set automatic notification schedule.
D.Alert Center > Custom rules > Create rule, selecting Admin log events as the datasource and specifying email recipients.
AnswerD

Alert Center custom rules allow you to monitor Workspace logs and trigger alerts and email notifications automatically.

Why this answer

Alert Center rules allow administrators to configure notification triggers for specific admin activity log events.

28
MCQeasy

Where do you manage the shared contacts for your organization?

A.Gmail settings
B.Directory > Directory settings > Sharing settings
C.Security settings
D.User profile settings
AnswerB

This is where directory sharing and shared contacts are configured.

Why this answer

Shared contacts are managed in the Directory settings of the Admin console.

29
MCQhard

You are implementing context-aware access and need to ensure that only devices with a disk-encrypted state are allowed to access Google Drive. Which feature enables this check?

A.Google Workspace Alert Center
B.Device policy profiles
C.Access Levels in Context-Aware Access
D.Chrome Enterprise Upgrade
AnswerC

Access Levels allow you to define rules based on device attributes like disk encryption.

Why this answer

Context-aware access policies use attributes provided by Endpoint Verification to grant or deny access based on device state.

30
Multi-Selectmedium

Which TWO of the following can be modified in the Admin console's 'Company Profile' section?

Select 2 answers
A.Individual user password requirements
B.Domain verification records
C.Support contact phone number
D.User licenses
E.Organization name
AnswersC, E

This is a standard company profile field.

Why this answer

The company profile section manages organization-wide details like the company name and support contact information.

31
MCQeasy

You need to ensure that all corporate-owned Android devices require a screen lock. Where should you configure this setting?

A.Apps > Google Workspace > Android settings
B.Devices > Mobile & endpoints > Settings > Android > Password settings
C.Security > Authentication > Password policy
D.Directory > Users > Security settings
AnswerB

This is the correct path to enforce screen lock requirements for Android devices.

Why this answer

Mobile settings in the Google Admin console are where device security policies like screen lock requirements are defined.

32
Multi-Selectmedium

Which TWO of the following can be configured in the Google Workspace Admin Console to restrict user access to Google Drive?

Select 2 answers
A.Restrict sharing settings for external domains
B.Limit the number of files a user can create
C.Restrict access to specific file types
D.Set a file size limit for all uploads
E.Disable Drive for specific Organizational Units
AnswersA, E

This restricts external collaboration.

Why this answer

Access to Drive is controlled by Sharing settings and Drive API controls.

33
MCQmedium

A user claims they cannot reset their password using the 'Forgot Password' link. What is the most likely cause?

A.The user is an admin
B.The user has 2FA enabled
C.The self-service reset feature is disabled in Security settings
D.The user account is in an OU without a license
AnswerC

This setting controls access to the self-service password tool.

Why this answer

If 'Allow users to reset their passwords' is disabled in the Security settings, they cannot use the self-service flow.

34
MCQhard

Which of the following is true regarding 'Advanced' mobile management for iOS?

A.It replaces the need for an Apple Push Certificate
B.It automatically removes the device after 30 days
C.It allows administrators to manage Wi-Fi profiles and certificates
D.It is required for all Android devices
AnswerC

These are key features of Advanced management for iOS.

Why this answer

Advanced management provides more control, such as certificate management and enterprise Wi-Fi configuration, compared to Basic management.

35
Multi-Selecteasy

A user is unable to access Google Drive. Which TWO of the following should you check first?

Select 2 answers
A.User's browser history
B.User account status (Suspended/Active)
C.The user's computer model
D.Google Workspace Status Dashboard
E.The user's printer configuration
AnswersB, D

A suspended account will cause access issues for all services.

Why this answer

Verifying the user's account status and checking the service status for the specific user are the first steps in troubleshooting access issues.

36
MCQmedium

You need to ensure that credit card numbers are not sent via Gmail by your employees. Which tool should you configure?

A.Context-aware access
B.DLP rules
C.Google Vault retention rules
D.Security center investigation tool
AnswerB

DLP rules scan for sensitive patterns and block or alert based on policy.

Why this answer

DLP rules in Google Workspace allow administrators to define content detectors to scan for sensitive information like credit card numbers.

37
MCQhard

You have enabled 'Google+ ' for your organization, but some users cannot see it. What is the most likely cause?

A.They are in the wrong OU
B.They need a higher license
C.The API is disabled
D.Their browser cache is full
AnswerA

If the service is off for their OU, they cannot use it.

Why this answer

Service visibility is controlled at the OU level; ensure the service is 'ON' for that specific OU.

38
Multi-Selectmedium

Which TWO practices are recommended when configuring organizational units (OUs) for security policy enforcement in Google Workspace? (Choose two.)

Select 2 answers
A.Assign Super Administrator privileges to the head of each organizational unit.
B.Override policies at every child OU level even when parent policies are identical to ensure redundancy.
C.Regularly audit OU membership and policy inheritance to ensure users receive appropriate security controls.
D.Place every single user in the root organizational unit to ensure uniform policy application.
E.Structure OUs hierarchically to mirror department or security requirement boundaries so policies inherit correctly.
AnswersC, E

Auditing ensures users who change roles are moved to appropriate OUs with correct security settings.

Why this answer

Best practices for OUs include inheriting policies from parent OUs where possible and structuring OUs logically by department or security requirement.

39
MCQeasy

You need to add a secondary domain to your Google Workspace account. What must you perform after adding the domain in the Admin console?

A.Verify domain ownership
B.Create a new OU
C.Set up SPF records
D.Provision user accounts
AnswerA

Verification via TXT or CNAME record is a prerequisite for domain use.

Why this answer

Verification is mandatory to prove domain ownership via DNS records.

40
Multi-Selecthard

An enterprise organization is planning its 2-Step Verification (2SV) rollout. Which THREE methods or tokens are natively supported by Google Workspace for 2SV authentication? (Choose three.)

Select 3 answers
A.Time-based One-Time Password (TOTP) authenticator apps (e.g., Google Authenticator)
B.Biometric retina scans processed by local BIOS firmware
C.Automatic voice call verification through landline pulse dialing tones
D.Google Prompts sent to trusted mobile devices
E.Security keys (FIDO2 / U2F hardware keys like Titan keys)
AnswersA, D, E

TOTP codes generated by authenticator apps are natively supported.

Why this answer

Google Workspace supports security keys (FIDO2/U2F), Google Prompts on mobile devices, and authenticator app OTP codes (TOTP).

41
MCQmedium

How can you prevent users from changing their profile photo?

A.Disable the Gmail service
B.Update Directory profile editing settings
C.Create a custom role
D.Delete the user's photo
AnswerB

This setting allows admins to restrict photo and other profile edits.

Why this answer

Directory profile settings allow admins to restrict which profile details users can modify.

42
MCQhard

You are seeing a 'Domain already in use' error when adding a domain. What is the most likely cause?

A.The domain is already verified in another Google Workspace account
B.The domain is a sub-domain
C.DNS is not propagated
D.You reached the domain limit
AnswerA

Google enforces domain exclusivity per workspace instance.

Why this answer

A domain can only be registered in one Google Workspace account at a time; it must be removed from the other instance first.

43
Multi-Selectmedium

Which TWO of the following are true regarding the Directory API?

Select 2 answers
A.It requires OAuth 2.0 for authentication
B.It does not support bulk operations
C.It is free to use with all licenses
D.It can be used to manage groups
E.It is only available to Super Admins
AnswersA, D

OAuth 2.0 is the standard for API security.

Why this answer

The Directory API uses OAuth 2.0 for authentication and requires specific scopes to function.

44
MCQmedium

You need to enforce 2-Step Verification for a specific department while allowing others to opt-in voluntarily. Which configuration path should you use?

A.Apply the enforcement policy at the root Organizational Unit level.
B.Use the Google Cloud Identity platform to create a conditional access policy for individual users.
C.Set the 'Allowed to opt-in' setting to 'Off' for the entire domain.
D.Move the department users into a dedicated Organizational Unit and enable 'Enforce' in the 2-Step Verification settings.
AnswerD

Applying the setting to a specific OU allows targeted enforcement for that department.

Why this answer

To enforce 2SV for specific users, you must use Organizational Units (OUs) or Groups and manage the enforcement settings under Security > Authentication > 2-step verification.

45
MCQmedium

Your organization wants to prevent users from sharing Google Drive files externally, but you need to make an exception for a specific partner domain. Where should you configure this allowed domain list?

A.Security > Authentication > Trusted domains
B.Directory > Organizational units > External sharing policy
C.Security > Access and data control > Whitelisted domains
D.Apps > Google Workspace > Drive and Docs > Sharing settings > Whitelisted domains
AnswerD

Drive sharing permissions and trusted external domains are configured directly in the Drive and Docs sharing settings.

Why this answer

Allowed external domains for sharing are managed under Apps > Google Workspace > Drive and Docs > Sharing settings.

46
MCQmedium

Your company uses a third-party Identity Provider (IdP) for Single Sign-On (SSO) via SAML. A newly hired employee is unable to sign in, and you suspect their account is not properly mapped or provisioned. Where can you check SAML sign-in activity and error logs in the Google Admin console?

A.Directory > Users > [User] > Activity > Sign-in activity
B.Reporting > Audit > SAML
C.Reporting > Audit > Admin log events
D.Security > Authentication > SAML log events
AnswerB

Reporting > Audit > SAML displays details regarding SSO sign-in attempts and SAML errors.

Why this answer

Log events related to SAML and SSO authentication failures are recorded in the SAML log events section of the Google Admin console.

47
MCQeasy

What is the difference between a primary domain and a secondary domain?

A.Primary is the identity foundation for the account
B.Secondary domains cost more
C.Secondary domains do not support OUs
D.Primary is for email; secondary is for Drive
AnswerA

Primary defines the account foundation and initial login.

Why this answer

The primary domain is the identity foundation of the Workspace account, used for initial setup and service naming.

48
Multi-Selectmedium

Which THREE features or tools in Google Workspace can be used to monitor and investigate suspicious sign-in activity or security anomalies? (Choose three.)

Select 3 answers
A.Apps > Google Workspace > Drive sharing settings
B.Security Center > Investigation Tool
C.Alert Center
D.Directory > Users > Bulk update via CSV
E.Reporting > Audit > Log events (e.g., Login, Admin, SAML)
AnswersB, C, E

The Investigation Tool allows administrators to query logs, devices, and user activities to remediate threats.

Why this answer

Suspicious activity can be tracked using Audit logs, the Security Center Investigation Tool, and Alert Center.

49
Multi-Selectmedium

Which THREE of the following are valid ways to manage Google Calendar resource availability?

Select 3 answers
A.Auto-accept invitations
B.Set resource visibility
C.Assign to specific buildings
D.Enable recurring meeting limits
E.Restrict resource access by device type
AnswersA, B, C

Configurable for room resources.

Why this answer

Resources are managed via building assignment, auto-accept rules, and visibility settings.

50
MCQmedium

You need to change the default language and region settings for all new users in a specific Organizational Unit. How do you do this?

A.Security > General > Account
B.Account > Account settings
C.Directory > Users > Account settings
D.Apps > Google Workspace > Profile
AnswerB

This is where you define default region and language settings for users in an OU.

Why this answer

Account settings, including time zone and language, are configured per OU under Account > Account settings.

51
MCQhard

You need to distribute a specific internal Android app to a subset of users. What is the most efficient way to achieve this using Google Workspace?

A.Enable 'Allow all apps' in the mobile device settings
B.Manually install the APK on every user's device
C.Add the app to the Managed Google Play store and assign to an OU
D.Send the APK via email to all employees
AnswerC

This allows for silent installation and controlled app distribution.

Why this answer

Adding the app to the managed Google Play store and assigning it to specific organizational units (OUs) allows for controlled distribution.

52
Multi-Selecthard

Which THREE of the following attributes can be used in Context-Aware Access policies?

Select 3 answers
A.OS version
B.Device encryption status
C.User's favorite browser
D.User's physical GPS location
E.Device management status (Basic/Advanced/Managed)
AnswersA, B, E

This ensures devices are updated and secure.

Why this answer

Device management status, encryption, and OS version are commonly used in access policies.

53
Multi-Selectmedium

Which TWO actions can you perform in Google Vault?

Select 2 answers
A.Configure DLP policies
B.Set up 2-Step Verification
C.Search and export user data
D.Manage user passwords
E.Place a hold on user data
AnswersC, E

Search and export are core Vault functions.

Why this answer

Vault allows you to place holds on data to prevent deletion and perform searches across user mail and files for eDiscovery.

54
MCQmedium

Your organization requires all contractors to use security keys for 2-Step Verification, while full-time employees can use prompts or authenticator apps. How should you configure this in the Google Admin console?

A.Modify the default domain-wide sign-in security policy to require security keys globally and grant exceptions via API.
B.Configure Context-Aware Access to block non-security key authentications for the contractors group.
C.Create an IAM custom role that revokes prompt-based authentication for external users.
D.Place contractors in a dedicated OU, navigate to Security > Authentication > 2-step verification, and configure the allowed methods to only include security keys.
AnswerD

Targeting policies via OUs allows you to restrict allowed 2SV methods exclusively to security keys for specific subsets of users.

Why this answer

Security key enforcement can be targeted to specific organizational units or security groups by setting the 2SV policy appropriately.

55
MCQhard

An administrator notices unusual login activity from a specific geographic location. What is the first step to prevent further unauthorized access?

A.Reset the user's password.
B.Suspend the user account.
C.Delete the user account.
D.Clear the user's browser cookies.
AnswerB

Suspending the account immediately terminates all active sessions.

Why this answer

Suspending the user account is the immediate action to stop ongoing unauthorized access while investigating.

56
MCQmedium

A user is unable to install a managed app on their iOS device. What is the first thing you should verify?

A.If the user's device is correctly enrolled in device management
B.If the user has updated their iOS version
C.If the App Store is restricted on the device
D.If the user has an iPhone 14 or later
AnswerA

Management status is the prerequisite for app deployment.

Why this answer

If the device is not enrolled or is in an 'Unmanaged' state, managed apps cannot be pushed to it.

57
MCQmedium

Your company has integrated Google Workspace with a third-party IdP using SAML. You want to make sure that when users sign out of Google Workspace, they are also signed out of their IdP session. What feature should you configure?

A.Context-Aware Access session termination
B.OAuth token revocation API
C.Automated user provisioning via SCIM
D.SAML Single Logout (SLO) URL configuration in the SSO profile.
AnswerD

Configuring the SLO URL in the Google Admin console enables Single Logout integration with the IdP.

Why this answer

Single Logout (SLO) allows users to terminate their session across both Google Workspace and the configured SAML IdP.

58
Multi-Selecthard

Which THREE items can be managed through the 'Directory' section in the Admin Console?

Select 3 answers
A.User profile editing permissions
B.Building resources
C.Device management policies
D.Gmail routing rules
E.Shared contacts
AnswersA, B, E

Managed under Directory > Profile editing.

Why this answer

Directory manages buildings, resources, and user profiles.

59
MCQhard

You want to require that all corporate-owned iOS devices are encrypted. How is this achieved?

A.Enable Advanced Mobile Management for all iOS users
B.Use an MDM profile to force file-level encryption
C.Configure a passcode policy in the iOS device management settings
D.Enable the 'Require disk encryption' setting in iOS mobile settings
AnswerC

Enforcing a passcode on iOS devices ensures the data partition is encrypted.

Why this answer

Apple devices (iOS) are encrypted by default when a passcode is set. Therefore, enforcing a passcode policy effectively enforces encryption.

60
Multi-Selecthard

When troubleshooting a SAML application error, which THREE of the following should you check?

Select 3 answers
A.SAML application metadata
B.The user's computer operating system
C.User attribute mapping
D.The user's physical location
E.Certificate expiration status
AnswersA, C, E

Incorrect metadata causes authentication failures.

Why this answer

The SAML metadata, user mapping, and certificate status are essential for SAML configuration.

61
MCQeasy

Where can an administrator view the status of a user's 2-Step Verification enrollment?

A.Security > Authentication > 2SV
B.Reports > Audit > Security
C.Directory > Users > [User] > Security
D.Account > Security Dashboard
AnswerC

This is where you view specific security status for an individual user.

Why this answer

User security information, including 2SV status, is found in the individual user's profile within the Directory.

62
MCQmedium

Your company has deployed a custom internal web application that integrates with Google Workspace via SAML. During testing, users receive a '403. That’s an error. Error: app_not_configured_for_user' message. What is the most likely cause of this error?

A.The IdP signing certificate has expired.
B.The user's password has expired and needs to be reset.
C.The SAML app service status is set to OFF for the user's organizational unit or access group.
D.The user does not have a Google Cloud Platform billing account attached.
AnswerC

Service status must be set to ON for everyone or turned on for specific OUs/groups to allow user access to custom SAML apps.

Why this answer

This error occurs when the SAML app is configured in the Google Admin console, but access is turned OFF for the user or their organizational unit.

63
MCQmedium

Your company wants to prevent employees from using personal Google accounts on company-owned ChromeOS devices. Which setting should you enable?

A.User settings > Accounts > Prevent adding accounts
B.Security > Chrome > Account management
C.App management > Block personal accounts
D.Device settings > Sign-in settings > Sign-in restriction
AnswerD

This policy allows you to restrict sign-in to specific domains.

Why this answer

Blocking accounts on managed ChromeOS devices is a standard device policy to prevent data exfiltration.

64
MCQhard

An organization is failing to receive emails from a specific sender. The logs show the messages were rejected by the 'Spam Filter'. What should you do?

A.Disable all spam filtering for the domain.
B.Add the sender to the 'Approved senders' list.
C.Delete the sender's email address.
D.Increase the domain storage limit.
AnswerB

This whitelist entry allows messages from trusted sources to bypass spam filters.

Why this answer

Adding the sender's domain or IP to the 'Approved senders' list in the Gmail settings will allow the messages to bypass spam filtering.

65
MCQmedium

You need to ensure that Chrome browsers on unmanaged devices are secure. What is a key step to take?

A.Force users to use Incognito mode
B.Use Chrome browser cloud management to enforce policies
C.Require a VPN for all browser traffic
D.Disable all extensions
AnswerB

Cloud management allows you to enforce security policies on browsers.

Why this answer

Enforcing Chrome browser management allows you to apply policies to the browser regardless of the OS of the underlying device.

66
MCQhard

You have a mix of company-owned and BYOD mobile devices. You want to apply different policies to each. What is the recommended strategy?

A.Create two separate OUs and apply different mobile settings to each
B.Create a Google Group and apply policies to the group
C.Use a third-party MDM for the BYOD devices only
D.Create a single OU and use groups for individual device settings
AnswerA

OUs are the standard way to apply granular policies.

Why this answer

Using different Organizational Units (OUs) allows you to apply different MDM policies to different groups of devices or users.

67
MCQeasy

A user has left the company. You need to migrate their data to another user. Which tool should you use?

A.Data Migration Service
B.Security Investigation Tool
C.Google Takeout
D.Google Vault
AnswerA

This is the correct tool for migrating email, calendar, and contacts.

Why this answer

The Data Migration Service is specifically designed for moving data from one Google account to another.

68
MCQhard

You need to ensure that users can only access Google Workspace services when they are connecting from corporate-owned devices managed by Endpoint Management and located within the corporate IP range. Which feature combination meets this requirement?

A.Context-Aware Access access levels referencing IP subnets and device policy compliance, assigned to targeted apps.
B.Google Cloud IAM conditions with Context-Aware Access and Security Health Analytics
C.Domain-wide SAML SSO with custom attribute mapping for IP addresses
D.Advanced Protection Program combined with Context-Aware Access
AnswerA

Context-Aware Access evaluates access levels containing attributes for both IP subnets and device policy status before granting access.

Why this answer

Context-Aware Access allows you to combine IP address subnets and device-policy compliance (corporate-owned status via endpoint management) to control access.

69
Multi-Selecthard

Which THREE of the following are types of reports available in the 'Reports' section of the Admin console regarding mobile devices?

Select 3 answers
A.Device security report
B.Data usage report
C.Mobile audit report
D.User password report
E.Device inventory report
AnswersA, C, E

This shows security status like encryption and passcodes.

Why this answer

Device usage, audit events, and compliance reports are standard reports in Google Workspace.

70
Multi-Selectmedium

Which TWO of the following are valid methods to audit file access in Google Drive?

Select 2 answers
A.Enable Google Vault for Drive exports
B.Set up alerts for all file deletions
C.Use the Security Investigation Tool
D.Review the Drive Audit logs in the Reports section
E.Check the user's 'My Drive' settings
AnswersC, D

Provides granular search for Drive activity.

Why this answer

Audit logs and the Investigation tool are the standard ways to monitor file activity.

71
Multi-Selecthard

Which THREE types of data can be managed using Vault retention rules?

Select 3 answers
A.Gmail messages
B.Google Drive files
C.User device logs
D.Google Chat messages
E.Third-party app tokens
AnswersA, B, D

Supported for retention.

Why this answer

Vault supports retention for Gmail, Drive, Chat, Groups, and Voice data.

72
MCQhard

You want to prevent users from copying data from managed apps into personal apps on their mobile devices. Which feature should you configure?

A.Endpoint verification data settings
B.Mobile management > Work profile data sharing settings
C.Context-Aware Access policies
D.Chrome browser management
AnswerB

These settings specifically control data flow between work and personal apps.

Why this answer

Data protection features within mobile management help restrict data movement between work and personal containers.

73
MCQeasy

A user needs to see their login history. Where can you find this information?

A.Google Analytics.
B.The user's Gmail inbox.
C.Account Activity report in the Admin Console.
D.Drive Audit logs.
AnswerC

This report provides detailed login information for users.

Why this answer

The user's security log in the Admin console shows login attempts and device information.

74
Multi-Selectmedium

Which TWO of the following are types of domains in Google Workspace?

Select 2 answers
A.Secondary domain
B.Root domain
C.External domain
D.Verified alias
E.Primary domain
AnswersA, E

This is an additional domain added to the account.

Why this answer

Google Workspace recognizes primary domains and secondary domains as types of managed domains.

75
MCQeasy

An administrator needs to delegate the role of creating and managing Google Groups across the entire domain without giving full admin rights. Which built-in role should be assigned?

A.Groups Admin
B.Directory Sync Admin
C.Helpdesk Admin
D.User Management Admin
AnswerA

Groups Admin allows creation, deletion, and management of Google Groups settings.

Why this answer

The Groups Admin role specifically grants privileges to manage Google Groups.

Page 1 of 3

Page 2

All pages