Courseiva

Google Cloud Associate Google Workspace Administrator (GWS-ADMIN) (GWS-ADMIN) — Questions 76150

208 questions total · 3pages · All types, answers revealed

Page 1

Page 2 of 3

Page 3
76
MCQmedium

You need to verify if an email was sent to an external address. Where can you see this in the Admin Console?

A.Vault search
B.Compliance reports
C.Security center
D.Email log search
AnswerD

This tool shows the journey and delivery status of emails.

Why this answer

The Email Log Search tool in the Admin Console allows administrators to trace email delivery and identify recipients.

77
MCQeasy

A user is seeing an 'Unable to verify account' error when signing in. What is the first thing to check?

A.User's password
B.Domain's DNS records
C.Account suspension status
D.User's mobile phone number
AnswerC

Suspended accounts will report as unable to be verified.

Why this answer

Checking if the account is suspended in the Admin console is the most common reason for this error.

78
MCQeasy

An administrator wants to ensure that users cannot use weak or commonly breached passwords. Where can password monitoring be enabled in the Google Admin console?

A.Security > Password management > Monitor password reuse and strength
B.Security Center > Security health page > Password strength
C.Account settings > Legal and compliance > Password audit
D.Directory > Users > Security alerts
AnswerA

Password monitoring settings are located under Security > Password management.

Why this answer

Password monitoring for breached credentials is enabled under Security > Password management.

79
MCQhard

You are troubleshooting an issue where a user is unable to authenticate via SAML SSO. You need to inspect the raw SAML request and response messages sent between the IdP and Google Workspace. What is the most effective way to capture this?

A.Use browser developer tools (Network tab) or a browser extension like SAML Tracer to capture and inspect the SAMLRequest and SAMLResponse POST parameters.
B.View the SAML audit logs in Reporting > Audit > SAML.
C.Run the Google Workspace SSO diagnostic tool in the Security Center.
D.Enable debug logging in Google Cloud Logging for the Workspace organization.
AnswerA

SAML protocol traffic is passed via browser HTTP POST bindings, making browser developer tools or tracer extensions ideal for viewing the raw XML assertions.

Why this answer

Browser developer tools with SAML tracer extensions or network log analysis capture the Base64 encoded SAMLAssertion payloads.

80
MCQmedium

An organization is using Google Workspace Sync for Microsoft Outlook (GWSMO). A user is experiencing sync delays. What tool should you use to check the GWSMO status?

A.Google Drive sync tool.
B.GWSMO Status tool on the user's machine.
C.Password reset tool.
D.Admin Console Reports
AnswerB

This tool shows the synchronization progress and any errors between Outlook and Google.

Why this answer

The GWSMO 'Set up a Google Workspace Sync user' tool or local log files are used to monitor and debug sync status.

81
Multi-Selecthard

Which THREE of the following are components of the Directory API 'group' resource?

Select 3 answers
A.Group members list
B.Group name
C.Group email address
D.Group creator ID
E.Group description
AnswersB, C, E

The name is a required field.

Why this answer

The group resource includes the group email, name, and description as standard fields.

82
MCQmedium

You want to automate user account creation based on a specific event. What is the recommended approach?

A.Use the Directory API with a service account
B.Use GCDS
C.Export/Import CSV daily
D.Use Google Forms
E.Manual input
AnswerA

Service accounts provide secure, automated access to the API.

Why this answer

Google Apps Script or the Directory API via a webhook/event-driven architecture is the standard method.

83
MCQhard

Your organization has configured third-party SAML SSO. However, you need to ensure that Super Administrators can always bypass SSO and sign in using their Google credentials in case the third-party IdP goes down. What configuration setting should you enable?

A.Disable SAML SSO entirely and rely exclusively on Google's built-in OAuth service.
B.Enable the 'Turn on SSO for administrative accounts' option and assign a backup password.
C.Configure SSO profile assignment to exclude Super Administrators or use the 'Allow users to sign in with Google password' option on the SSO profile page.
D.Create a Context-Aware Access rule that triggers emergency recovery mode when the IdP IP is unreachable.
AnswerC

Enabling the sign-in with Google password option for admins or assigning them to a separate OU without SSO enforcement ensures emergency access.

Why this answer

Google Workspace allows you to configure a secondary SSO profile or enable network/admin bypass settings to allow admin sign-in via Google credentials.

84
Multi-Selecthard

Which THREE features are part of the Security Center?

Select 3 answers
A.Security health page
B.Vault retention rules
C.DLP policy configuration
D.Security dashboard
E.Investigation tool
AnswersA, D, E

Shows best practices and configuration recommendations.

Why this answer

The Security Center provides tools for proactive security, incident investigation, and reporting on security metrics.

85
MCQhard

You are setting up Context-Aware Access. You want to deny access to Google Workspace if the device is not encrypted. Which tool identifies the 'is_encrypted' attribute?

A.Device policy controller
B.Endpoint Verification extension
C.Admin console audit logs
D.Google Cloud Identity sync
AnswerB

The extension collects the attribute and sends it to the server.

Why this answer

Endpoint Verification reports device attributes like encryption status back to Google, which Context-Aware Access then uses to evaluate policies.

86
MCQmedium

A department requires a custom building resource to be added to Google Calendar. Where do you add this?

A.Apps > Google Workspace > Directory > Calendar
B.Apps > Google Workspace > Calendar > Resources
C.Organization > Settings > Resources
D.Directory > Buildings and resources
AnswerD

This is the correct path to manage room and resource objects.

Why this answer

Building resources are managed under Directory > Buildings and resources.

87
Multi-Selecthard

Which THREE security settings can be enforced for Gmail in the Admin Console?

Select 3 answers
A.Force user to use specific email client
B.Attachment scanning for viruses
C.Automatic email deletion after 30 days
D.S/MIME encryption
E.Safe Browsing for links
AnswersB, D, E

Enforced by default, but configurable.

Why this answer

Gmail security supports S/MIME, attachment scanning, and link protection.

88
Multi-Selecthard

Which THREE of the following are benefits of using Organizational Units (OUs)?

Select 3 answers
A.Controlling access to shared files
B.Applying different service settings to different groups of users
C.Managing mobile device policies for specific departments
D.Applying different security settings to different user groups
E.Creating automatic email forwarding rules
AnswersB, C, D

Service customization is a core use of OUs.

Why this answer

OUs allow you to group users to apply different service settings, security policies, and mobile management settings.

89
MCQeasy

Where can you enable the automatic creation of Google Meet links for calendar events?

A.Security > Meet > Calendar sync
B.Apps > Google Workspace > Calendar
C.Apps > Google Workspace > Directory
D.Apps > Google Workspace > Google Meet
AnswerD

This is where you toggle the setting to automatically create Meet links for Calendar events.

Why this answer

This is enabled in the Google Meet service settings.

90
MCQmedium

You need to create a custom administrator role that allows specific users to manage Google Meet hardware devices and review their health status, but nothing else. Which privilege category should you select when building this custom role?

A.Services > Google Meet hardware
B.Organizational Units and Admin Roles
C.Mobile and Endpoints > Device Management
D.Security Center > Investigation Tool
AnswerA

Google Meet hardware management privileges are located under the Services category.

Why this answer

Privileges for managing Meet hardware and devices are found under the Services and Devices privilege trees.

91
MCQhard

An organization uses a third-party gateway to route email. Users report that emails are being marked as spam frequently. Which DNS record should you investigate to ensure Google trusts the gateway?

A.DKIM record
B.A record
C.SPF record
D.MX record
AnswerC

An SPF record specifies which hosts are authorized to send email on behalf of your domain.

Why this answer

The SPF record must include the IP addresses or include mechanism for the third-party gateway to prevent spoofing flags.

92
Multi-Selecthard

An administrator wants to configure security policies to protect corporate data on mobile devices. Which THREE actions can be enforced through Google Workspace Endpoint Management? (Choose three.)

Select 3 answers
A.Enforce containerization or work profile segregation on Android devices.
B.Require a screen lock and strong password on enrolled mobile devices.
C.Perform a remote wipe of corporate data (or full wipe) on lost or stolen devices.
D.Configure deep packet inspection on all cellular data traffic passing through the device.
E.Directly access and read personal text messages stored on the user's personal phone.
AnswersA, B, C

Advanced endpoint management supports Android work profiles to separate personal and corporate data.

Why this answer

Google Endpoint Management allows administrators to enforce device policies such as requiring a screen lock, wiping corporate data remotely, and enforcing password requirements on devices.

93
MCQmedium

You need to deploy a specific Android application to a subset of users. What is the correct procedure?

A.Instruct users to download it themselves from the Play Store
B.Upload the APK file to the server and email the link to users
C.Use a third-party MDM integration
D.Use the 'Apps' section in the Admin console to select the app from Managed Google Play and assign it to an OU
AnswerD

This is the standard, supported workflow for app deployment.

Why this answer

You must add the app via the Managed Google Play store and then assign it to the specific Organizational Unit (OU) or group.

94
MCQeasy

A new IT support staff member needs to manage user passwords but should not be able to delete users or modify billing settings. Which role should you assign?

A.Groups Admin
B.User Management Admin
C.Super Admin
D.Help Desk Admin
AnswerB

This role is designed for managing user accounts, including password resets, without billing or delete permissions.

Why this answer

The 'User Management Admin' role allows for password resets and basic user info updates without full super admin privileges.

95
MCQeasy

An employee has left the company. You need to migrate their email and calendar data to their manager's account. Which tool should you use?

A.Google Cloud Storage Transfer Service
B.GAM (Google Apps Manager)
C.Data Migration Service
D.Vault
AnswerC

This tool is designed for migrating email, contacts, and calendar data.

Why this answer

The Data Migration Service is the primary tool for migrating user data between Google Workspace accounts.

96
MCQmedium

You need to bulk upload 500 users using a CSV file. What is the required format for the CSV header row?

A.Email, Phone, Address
B.First Name, Last Name, Password, Email Address
C.FirstName, LastName, Password
D.Username, Role, OU
AnswerB

These are the mandatory fields for bulk user creation.

Why this answer

The Google Admin console bulk upload tool requires specific headers like First Name, Last Name, and Email Address to process the file.

97
Multi-Selecthard

Which THREE of the following settings are inherited by child OUs from the parent OU?

Select 3 answers
A.Admin roles assigned to the OU
B.Mobile management policies
C.Service status (ON/OFF)
D.Password strength requirements
E.User email address
AnswersB, C, D

Mobile settings are inherited.

Why this answer

Inheritance applies to most Google Workspace settings, including service status, mobile management, and security policies.

98
Multi-Selectmedium

Which TWO of the following actions can an administrator perform using the Google Workspace Data Migration Service?

Select 2 answers
A.Migrate email from another Gmail account
B.Automate password changes for migrated accounts
C.Migrate Drive files to a specific shared drive
D.Migrate calendar events from Microsoft Exchange
E.Sync browser bookmarks for migrated users
AnswersA, D

DMS supports this migration path.

Why this answer

DMS supports IMAP-based mail and calendar migration.

99
MCQeasy

You want to ensure that all users have a strong password policy. Where can you enforce password length and complexity requirements?

A.Directory > User settings
B.Security > Authentication > Password management
C.Security > Context-Aware Access
D.Account > Account settings
AnswerB

This is the correct path for setting password complexity and expiration policies.

Why this answer

Password policies are managed in the Security section under Password management.

100
MCQhard

You have a Data Region policy configured for the US. A user moves from the US to the EU. How do you trigger the migration of their existing data to the EU?

A.Manually run a data export in Vault
B.Re-provision the user account
C.Move the user to an OU configured for the EU data region
D.Contact Google Support to initiate a manual migration
AnswerC

Moving the user to an OU associated with the EU data region triggers the automated migration process.

Why this answer

Google Workspace automatically migrates data to the new region once the user's organizational unit (OU) is updated to a region mapped to the new location.

101
MCQhard

An auditor requests that you restrict administrative access to the Google Workspace Admin console to a specific set of IP addresses. What is the most effective way to implement this?

A.Create an 'Access Level' in Context-Aware Access and apply it to the Admin console app.
B.Disable 'Advanced Protection Program' for all users.
C.Apply a VPC Service Controls perimeter around the organization.
D.Configure 'Admin console sign-in restriction' under Security > Authentication.
AnswerD

This setting directly restricts access to the Admin console to specific allowed IP addresses.

Why this answer

The 'Admin console sign-in restriction' setting allows administrators to limit console access to trusted networks.

102
Multi-Selectmedium

A mobile device is not syncing corporate email. Which THREE of the following should you investigate?

Select 3 answers
A.User account password reset
B.Mobile management settings in the Admin console
C.Device compliance status
D.The user's home network speed
E.The user's browser plugin list
AnswersA, B, C

An expired or reset password will break mobile sync until updated.

Why this answer

Device compliance, sync settings, and the user's password/auth status are all critical for mobile sync.

103
MCQeasy

A user reports that they are not receiving emails from an external vendor. As an administrator, where should you first look to verify if the messages reached Google's servers?

A.Email Log Search
B.Security Dashboard
C.Reports > User usage
D.Gmail > Compliance settings
AnswerA

Email Log Search is the primary tool for investigating mail flow issues.

Why this answer

The Email Log Search tool allows administrators to track email delivery status, including whether messages were received, rejected, or routed to spam.

104
MCQmedium

You need to export a list of all users and their license status. What is the best method?

A.Use the Security investigation tool
B.Check the Billing report
C.Export via Admin console Users list
D.Use the Directory API
AnswerC

The 'Download users' button generates a CSV with license info.

Why this answer

The User report in the Admin console allows exporting user data to Google Sheets.

105
MCQmedium

A user is experiencing 'Storage full' errors. What is the best way to determine which files are using the most space?

A.Check the Gmail Audit logs.
B.Delete all files and re-upload.
C.Use the Security Investigation Tool.
D.View storage usage in the User management page.
AnswerD

This page provides a direct link to view and manage storage for the user.

Why this answer

The Drive storage management tool provides a clear breakdown of file usage by size for each user.

106
MCQhard

A user reports that their mobile device is no longer syncing corporate data. What is the most likely cause?

A.The device battery is low.
B.The user is on the wrong Wi-Fi network.
C.The mobile carrier has blocked the connection.
D.The device no longer meets security compliance requirements.
AnswerD

When devices fall out of compliance, the server blocks synchronization.

Why this answer

If a security policy change has occurred or the device has become non-compliant, sync will be automatically blocked by Google Workspace.

107
MCQeasy

Which report would you use to identify users who haven't logged in for more than 30 days?

A.Reports > Security > Login
B.Apps > Google Workspace > Reports
C.Reports > User Reports > User accounts
D.Directory > Users > Account status
AnswerC

This report displays the last login time for all users.

Why this answer

The 'User accounts' report, found under Reports, provides the last login timestamp for each user.

108
MCQeasy

Which Google Workspace service should you use to search and export user data for legal requests?

A.Google Vault
B.Google Cloud Storage
C.Data migrations
D.Security center
AnswerA

Vault is built for eDiscovery, search, and export.

Why this answer

Vault is the primary tool for eDiscovery and legal data requests in Google Workspace.

109
MCQeasy

What is required for a user to be able to manage their own mobile device in the Google Admin console?

A.User must be in the 'Everyone' group
B.There is no way for a user to manage devices
C.User must have the 'Mobile device manager' role
D.User must be an owner of the device
AnswerC

This administrative role grants the necessary permissions to manage devices.

Why this answer

Users do not manage their devices in the Admin console; that is for administrators only.

110
Multi-Selectmedium

Which TWO of the following are valid criteria for a Context-Aware Access level? (Choose two)

Select 2 answers
A.Device encryption status
B.User's browser history
C.User's favorite color
D.User's time zone
E.IP subnet
AnswersA, E

Device attributes like encryption status are valid criteria.

Why this answer

Context-Aware Access levels can be built using IP subnets and device attributes like encryption status or OS versions.

111
MCQmedium

You need to prevent users from sharing sensitive files outside the organization. Which setting should you modify?

A.Endpoint management
B.Vault retention settings
C.Drive sharing options in the Admin Console
D.App access control
AnswerC

You can restrict external sharing at the organizational unit level.

Why this answer

Drive sharing settings allow administrators to restrict sharing to internal users or specific whitelisted domains.

112
MCQmedium

A user in the 'Sales' OU is not receiving policy updates applied to that OU. What is the most likely cause?

A.Inheritance is disabled for the Sales OU
B.The user is in a group
C.The domain is not verified
D.The user has a suspended account
AnswerA

If inheritance is disabled, the OU stops receiving policies from its parent.

Why this answer

Inheritance is the default behavior; if it is broken, child OUs do not receive parent policies.

113
MCQmedium

You need to create a report showing which users have been affected by a specific DLP policy violation in the last month. Where can you find this?

A.Admin audit logs
B.Reports dashboard
C.Security center investigation tool
D.Vault matters
AnswerC

You can filter logs by DLP rule name or event type.

Why this answer

The Security Center investigation tool allows for queries specifically filtered by DLP rule violations.

114
Multi-Selecteasy

Which TWO actions should be taken when offboarding a user to protect organizational data?

Select 2 answers
A.Reset the user's billing settings
B.Suspend the user account
C.Apply a Vault hold if required
D.Grant user full email access
E.Delete the user account immediately
AnswersB, C

Prevents further access.

Why this answer

Suspending access and ensuring data is preserved or transferred are critical offboarding steps.

115
MCQhard

You need to grant a user permission to manage only the 'Marketing' OU. Which administrative role do you assign?

A.User Management Admin
B.Super Admin
C.Custom Admin role with OU scope
D.Group Admin
AnswerC

You can create a role and scope it to a specific OU.

Why this answer

Custom Admin roles allow granular control over OU access.

116
MCQmedium

A user is complaining that they cannot send emails to a specific external domain. Where do you check for blocklists or routing issues?

A.Security > Authentication > SPF
B.Apps > Google Workspace > Gmail > Compliance
C.Security > Gmail > Routing
D.Apps > Google Workspace > Gmail > Routing
AnswerD

This is the correct location for managing email routing and compliance rules.

Why this answer

Gmail routing, including blocklists and custom routing rules, is managed under Apps > Google Workspace > Gmail > Routing.

117
MCQeasy

A user reports that their Android work profile is no longer syncing corporate emails. As an administrator, which action should you perform first in the Google Admin console to investigate?

A.View the device details in the Device Management section of the Admin console
B.Force a factory reset on the user's device
C.Remove the user from the mobile management organizational unit
D.Disable the user's account in Google Workspace
AnswerA

Viewing device details allows you to see sync status, last sync time, and compliance alerts.

Why this answer

Checking the device status in the Admin console provides immediate insight into sync errors or compliance issues.

118
Multi-Selecthard

Which THREE actions should you take to secure your Google Workspace environment against unauthorized admin access? (Choose three)

Select 3 answers
A.Enable 'Admin console sign-in restriction' to trusted IPs.
B.Require a password change every 30 days for all users.
C.Configure Audit and Investigation logs to alert on unusual admin activity.
D.Require Security Keys for all Super Admin accounts.
E.Disable all non-Google apps in the Marketplace.
AnswersA, C, D

Limiting admin access by network location is a best practice.

Why this answer

Securing admin accounts involves multi-factor authentication, monitoring, and limiting the scope of privileges.

119
MCQmedium

You need to ensure that Google Chat messages are retained for 5 years. How do you do this?

A.Enable chat history for all users
B.Export Chat logs via the API
C.Create a Chat retention rule in Vault
D.Set a Gmail retention rule
AnswerC

Vault provides explicit support for Chat retention.

Why this answer

Vault supports retention rules for Google Chat, which can be configured for a specific time period.

120
MCQhard

You need to create a custom administrator role that allows a security analyst to use the Security Center Investigation Tool, view audit logs, and manage alerts, but prevents them from modifying user passwords or organizational unit structures. Which exact set of privileges should you assign?

A.Grant 'Super Admin' privileges and restrict access using Context-Aware Access.
B.Select privileges from Security Center (Investigation Tool, Alerts) and Reporting (Audit logs), while leaving User Management and OU privileges unchecked.
C.Assign the 'Helpdesk Admin' role combined with 'Security Center Reader'.
D.Assign the built-in 'Security Admin' role and remove user management privileges via override.
AnswerB

Selecting only specific monitoring and investigation privileges grants the desired visibility without granting destructive user management or structural modification rights.

Why this answer

Building a custom role requires selecting precise privileges from the Security Center and Reporting privilege categories.

121
MCQeasy

A user deleted a document from their Google Drive three days ago. As an administrator, what is the maximum time you can restore this file?

A.7 days
B.30 days
C.25 days
D.Unlimited
AnswerC

The restoration window for admins is 25 days.

Why this answer

Administrators can restore files deleted by users from the Admin Console for up to 25 days after the file has been emptied from the Trash.

122
Multi-Selectmedium

Which TWO of the following are prerequisites for setting up iOS device management?

Select 2 answers
A.Physical access to each device
B.Apple Push Certificate
C.A custom domain name
D.Advanced Mobile Management
E.Android Enterprise registration
AnswersB, D

The certificate is mandatory for communicating with Apple's servers.

Why this answer

An Apple Push Certificate and Advanced Mobile Management are required to manage iOS devices effectively.

123
Multi-Selecthard

An administrator is reviewing API controls and third-party app access in Google Workspace. Which THREE access states can be configured for third-party OAuth applications? (Choose three.)

Select 3 answers
A.Trusted (allowed access to all Google Workspace APIs and data scopes)
B.Supervised (requiring a Super Administrator to approve every API call in real time)
C.Read-Only Sandbox (running apps in an isolated container without data persistence)
D.Limited (allowed access only to specific whitelisted Google APIs or restricted data scopes)
E.Blocked (prevented from accessing any Google Workspace user data or APIs)
AnswersA, D, E

Trusted apps have unrestricted access to requested scopes.

Why this answer

Third-party OAuth applications can be configured as Trusted, Limited, or Blocked.

124
MCQhard

A user is receiving 'Account temporarily unavailable' messages. What is the primary thing to check?

A.The user's account status in the Admin console.
B.The user's browser version.
C.The user's internet connection.
D.The domain's MX records.
AnswerA

The status will indicate if the account is suspended or under restriction.

Why this answer

This error often occurs when an account has exceeded bandwidth limits or is undergoing a security review.

125
MCQeasy

An administrator needs to review recent security alerts and proactive recommendations for improving domain security. Where should they look first in the Google Admin console?

A.Security > Security Center > Dashboard
B.Directory > Users > Security status
C.Reporting > Audit logs > Security overview
D.Apps > Google Workspace > Security Center
AnswerA

The Security Center dashboard provides an overview of security health, alerts, and actionable recommendations.

Why this answer

The Security Center provides a centralized dashboard for security analytics, alerts, and recommendations.

126
Multi-Selectmedium

Which TWO of the following are common reasons for a user sync failure in GCDS?

Select 2 answers
A.Expired Google license
B.Incorrect password for the Google Admin
C.Incorrect LDAP query
D.Browser compatibility issues
E.Invalid OU mapping
AnswersC, E

If the query fails to find users, no sync happens.

Why this answer

Common sync issues include misconfigured LDAP queries and invalid OU mappings in the GCDS configuration.

127
MCQmedium

What happens when you delete an Organizational Unit?

A.Users inside are suspended
B.The OU cannot be deleted until it is empty
C.Users are deleted along with the OU
D.Users inside are automatically moved to root
AnswerB

Google prevents deletion of non-empty OUs.

Why this answer

Deleting an OU requires moving all users and sub-OUs out of it first.

128
MCQhard

You need to prevent users from installing third-party Marketplace apps that request Drive read/write access. How do you configure this?

A.Security > Access and data control > API controls > Manage Google Services
B.Apps > Google Workspace > Marketplace > Settings
C.Security > App access control
D.Apps > Google Workspace > Drive > API settings
AnswerA

This area allows you to control which OAuth scopes are granted to third-party apps.

Why this answer

This is managed in Security > Access and data control > API controls > Manage Google Services.

129
MCQmedium

You have configured a new transport rule, but it is not triggering as expected. What is the first troubleshooting step?

A.Delete and recreate the rule.
B.Change the priority of the rule.
C.Restart the Google Workspace service.
D.Check the Gmail Audit logs.
AnswerD

Logs show the results of rule processing for specific messages.

Why this answer

Checking the Gmail Audit logs for the specific message can confirm if the rule was applied or why it was skipped.

130
MCQmedium

You want to ensure that only company-managed ChromeOS devices can access your Google Workspace environment. Which setting should you modify?

A.Device enrollment settings
B.Security center dashboard
C.Chrome browser cloud management settings
D.Context-Aware Access levels
AnswerD

Access levels allow you to filter by 'Managed device' status.

Why this answer

Context-Aware Access allows you to restrict access based on whether the device is managed by the organization.

131
Multi-Selecthard

Which THREE criteria can you use to build a DLP rule in Google Workspace?

Select 3 answers
A.User password history
B.Network latency
C.Custom regular expressions
D.Predefined content detectors
E.Drive labels
AnswersC, D, E

Useful for finding organization-specific sensitive patterns.

Why this answer

DLP rules can be based on predefined content detectors, custom regex, and document metadata like labels.

132
MCQhard

A user reports that emails are not being sent to an external mailing list. The logs show '550 5.1.1'. What does this code indicate?

A.The sender is blocked.
B.The message was marked as spam.
C.The server is temporarily down.
D.The recipient address is invalid.
AnswerD

5.1.1 specifically means the mailbox is unavailable or does not exist.

Why this answer

A 550 5.1.1 error code indicates that the recipient address does not exist or is invalid.

133
MCQmedium

An administrator mistakenly deleted a user account 10 days ago. How can you restore this account?

A.Contact Google Support for data recovery
B.Restore from a Vault export
C.Create a new user with the same email
D.Use the Restore User tool in the Admin console
AnswerD

The Restore User tool allows restoration within the 20-day window.

Why this answer

Deleted users can be restored within 20 days via the Admin console.

134
MCQmedium

You need to prevent users from adding personal Google accounts to their company-managed devices. How do you restrict this?

A.Devices > Mobile and endpoints > Settings > iOS/Android
B.Apps > Google Workspace > Settings
C.Directory > Users > Device settings
D.Security > Account > Personal account restriction
AnswerA

This allows you to restrict the addition of accounts on managed mobile devices.

Why this answer

This is managed via Device Management settings, specifically under Devices > Mobile and endpoints > Settings > iOS/Android.

135
MCQmedium

Your organization requires that users can only access Google Drive when connected to the corporate VPN. How can you achieve this using Context-Aware Access?

A.Restrict Google Drive access via the 'OAuth app allowlist'.
B.Configure an IP-based access level and assign it to the Google Drive app.
C.Update the 'Password Strength' policy in the Admin console.
D.Enable 'Endpoint Verification' on all user devices.
AnswerB

Creating an access level based on IP ranges and assigning it to the Drive service restricts access accordingly.

Why this answer

Context-Aware Access levels are created in Security > Access and data control > Context-Aware access, then assigned to apps.

136
MCQmedium

A user claims their corporate data is not being wiped after they left the company. You previously issued a 'wipe device' command. What should you check to verify the outcome?

A.The Admin console audit log for mobile management
B.The Google Cloud Platform logs
C.The user's account status in the directory
D.The user's Gmail sent items
AnswerA

The audit log records all device commands and their statuses.

Why this answer

The device audit log provides the necessary visibility into whether a command was successfully executed by the server and acknowledged by the device.

137
Multi-Selectmedium

When managing ChromeOS devices, which TWO settings can be configured within the 'Device settings' section of the Admin console?

Select 2 answers
A.User password rotation
B.Browser history retention
C.Auto-update settings
D.Sign-in restrictions
E.Default home page for all users
AnswersC, D

This is a critical device-level setting.

Why this answer

Device settings allow for controlling device-level behaviors like Auto-update and sign-in restrictions.

138
MCQmedium

Your organization uses a third-party Identity Provider (IdP) for SSO. Users are reporting that they cannot sign in. Where do you verify the SAML configuration?

A.Security > Authentication > SSO with third-party IdP
B.Apps > Web and mobile apps
C.Directory > Users
D.Account > Domain settings
AnswerA

This is the correct location for configuring and troubleshooting third-party SAML SSO.

Why this answer

SAML configuration for third-party providers is managed in Security > Authentication > SSO with third-party IdP.

139
MCQmedium

An administrator has configured a new SAML SSO integration with a third-party IdP. Users are complaining that they can log in successfully, but after 30 minutes, they are unexpectedly forced to re-authenticate. Where can the administrator adjust the session duration for SAML apps?

A.Security > Access and data control > API controls
B.Apps > Web and mobile apps > [SAML App] > Service status
C.Security > Authentication > SSO with third-party IdP > Session length settings
D.Account settings > Profile > Session duration
AnswerC

Google Workspace allows you to configure session duration specifically within the SAML app configuration or enterprise app settings.

Why this answer

SAML session length settings for third-party applications are configured within the specific SAML app settings in the Google Admin console.

140
MCQhard

You need to investigate a potential data breach where a user downloaded a large number of sensitive files. Which tool provides the most granular audit logs for Drive file downloads?

A.Security center investigation tool
B.DLP policy logs
C.Vault eDiscovery search
D.Reports dashboard
AnswerA

This tool provides detailed event logs including 'download' actions.

Why this answer

The Investigation tool within the Security Center provides the most granular logs for file-level activities, including downloads.

141
MCQeasy

A user complains that they cannot access their work email. You see the device is marked as 'Blocked' in the Admin console. What should you do?

A.Approve the device in the mobile management list
B.Send a 'Sync' command
C.Factory reset the device
D.Delete the device record
AnswerA

Approving the device restores access to corporate services.

Why this answer

If a device is blocked, changing the status to 'Approved' or 'Unblocked' will restore access.

142
MCQhard

You need to ensure that Google Meet sessions created by your users always require a password/PIN for external participants. How do you enforce this?

A.Configure 'External participation' in Meet settings
B.This feature is not available in Google Workspace
C.Require 'Admin approval' for all meetings
D.Enable 'Meet Entry PIN' in Meet settings
AnswerB

Google Meet does not support meeting PINs for external users.

Why this answer

Google Meet does not use PINs for external participants; it uses host management and entry controls.

143
MCQmedium

You notice that a user's account is generating a large amount of spam. What is the immediate action you should take?

A.Rename the user account.
B.Reset the user's password and sign out of all sessions.
C.Delete the account.
D.Send a warning email to the user.
AnswerB

This terminates the attacker's access immediately.

Why this answer

Resetting the user's password and forcing a logout of all sessions is the fastest way to stop an account that has been compromised.

144
Multi-Selecthard

Which THREE actions can be performed using the Google Admin console's bulk user management tool?

Select 3 answers
A.Deleting user data
B.Suspending users
C.Assigning custom admin roles
D.Updating user information
E.Creating multiple users
AnswersB, D, E

Bulk suspension is supported.

Why this answer

The bulk upload tool allows creating new users, updating existing user information, and suspending/unsuspending multiple users via CSV.

145
Multi-Selecthard

When an email is reported as missing, which THREE logs or tools can help you track the issue?

Select 3 answers
A.Security Investigation Tool
B.Gmail Audit logs
C.Device audit logs
D.Email Log Search
E.Google Calendar logs
AnswersA, B, D

This tool can search across logs for specific message IDs or senders.

Why this answer

Email Log Search, Gmail Audit logs, and the Security Investigation tool are the core diagnostic tools for mail flow.

146
MCQhard

An employee is suspected of leaking data. You need to search their past Gmail and Drive files for specific terms. Which tool do you use?

A.Vault matter search
B.DLP incident report
C.Security investigation tool
D.Admin audit logs
AnswerA

Vault search is designed to find specific content within user data.

Why this answer

Vault allows for full-text search across Gmail, Drive, and other services to support eDiscovery investigations.

147
MCQmedium

You need to limit the number of participants in a Google Meet session to 10 for a specific organizational unit. How do you achieve this?

A.It is not possible to limit participant counts via Admin Console
B.Modify the OU policy in Apps > Google Workspace > Meet
C.Use a group policy for Meet access
D.Set 'Participant limit' in the Meet settings
AnswerA

Participant limits are determined by the Google Workspace edition, not by custom admin settings.

Why this answer

Google Meet does not support limiting the number of participants via the Admin Console.

148
MCQhard

Your company has an external contractor who needs temporary access to Google Workspace. You want to ensure their account automatically deactivates after 30 days without manual administrative intervention. How can you achieve this securely?

A.Enable the Advanced Protection Program, which automatically deletes inactive external accounts after 30 days.
B.Use Cloud Identity Premium automated user lifecycle management or the Admin SDK API to schedule account suspension after 30 days.
C.Set the user password expiration policy specifically for that user's OU to 30 days.
D.Configure a Context-Aware Access rule with a time-based expiration condition.
AnswerB

Cloud Identity features and the Admin SDK allow automated scheduling or provisioning lifecycle management for temporary accounts.

Why this answer

Google Workspace accounts do not have a native 'account expiration date' field by default, but you can manage this via Directory Sync or automated scripts using Admin SDK, or by setting calendar alerts. However, the standard administrative feature for automated lifecycle management is Directory Sync or Cloud Identity lifecycle features. Wait, looking at standard admin tools: Google Workspace allows setting user account expiration using the Admin SDK or automated lifecycle rules in cloud identity, or using Context-Aware Access temporary rules.

Let's look at the options.

149
MCQmedium

You need to add a custom attribute to user profiles. Where is this configured?

A.Account > Organization profile
B.Directory > Users > Manage custom attributes
C.Security > Profile settings
D.Directory > OU management
AnswerB

This is the path to define custom user schema fields.

Why this answer

Custom attributes are managed under Directory > Users > More > Manage custom attributes.

150
MCQeasy

An administrator needs to grant a helpdesk employee the ability to reset user passwords and view user information without granting them full super administrator privileges. Which built-in admin role should be assigned?

A.User Management Admin
B.Helpdesk Admin
C.Groups Admin
D.Services Admin
AnswerA

The User Management Admin role allows resetting passwords, suspending users, and editing user profiles.

Why this answer

The User Management Admin role grants permissions to reset passwords, manage user profiles, and view organizational units.

Page 1

Page 2 of 3

Page 3

All pages