Courseiva
Security Policies And Access ControlshardMultiple ChoiceObjective-mapped

GWS-ADMIN Security Policies And Access Controls Practice Question

Your company has an external contractor who needs temporary access to Google Workspace. You want to ensure their account automatically deactivates after 30 days without manual administrative intervention. How can you achieve this securely?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use Cloud Identity Premium automated user lifecycle management or the Admin SDK API to schedule account suspension after 30 days.

Google Workspace accounts do not have a native 'account expiration date' field by default, but you can manage this via Directory Sync or automated scripts using Admin SDK, or by setting calendar alerts. However, the standard administrative feature for automated lifecycle management is Directory Sync or Cloud Identity lifecycle features. Wait, looking at standard admin tools: Google Workspace allows setting user account expiration using the Admin SDK or automated lifecycle rules in cloud identity, or using Context-Aware Access temporary rules. Let's look at the options.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable the Advanced Protection Program, which automatically deletes inactive external accounts after 30 days.

    Why it's wrong here

    Advanced Protection does not automatically delete accounts based on a 30-day clock.

  • Use Cloud Identity Premium automated user lifecycle management or the Admin SDK API to schedule account suspension after 30 days.

    Why this is correct

    Cloud Identity features and the Admin SDK allow automated scheduling or provisioning lifecycle management for temporary accounts.

  • Set the user password expiration policy specifically for that user's OU to 30 days.

    Why it's wrong here

    Password expiration forces a password reset, it does not suspend or deactivate the user account.

  • Configure a Context-Aware Access rule with a time-based expiration condition.

    Why it's wrong here

    Context-Aware Access evaluates connection attributes, not user account lifecycle expiration dates.

About these practice questions

Courseiva writes every GWS-ADMIN question from scratch — 208 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Google Cloud exam blueprint

This GWS-ADMIN practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GWS-ADMIN exam.