GWS-ADMIN · domain
Security Policies And Access Controls
Practise Google Cloud Associate Google Workspace Administrator (GWS-ADMIN) Security Policies And Access Controls practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Security Policies And Access Controls questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Security Policies And Access Controls
Security Policies And Access Controls questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Security Policies And Access Controls exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Security Policies And Access Controls questions (48)
Click any question to see the full explanation, or start a practice session above.
Which TWO mechanisms can an administrator use to recover access if a Super Administrator loses their 2-Step Verification device and is locked out? (Choose two.)
Medium2You need to prevent users from installing third-party Marketplace apps that request access to their Gmail data. What is the best approach?
Hard3Your organization uses Context-Aware Access to restrict access to Google Workspace based on IP address ranges. A remote employee traveling for business is unable to access Gmail from a trusted hotel Wi-Fi. How should the administrator temporarily grant access without compromising long-term security?
Medium4You need to ensure that administrative actions taken by Super Administrators trigger real-time alerts to the security team's email distribution list. Which tool should you use to set this up?
Hard5Which TWO practices are recommended when configuring organizational units (OUs) for security policy enforcement in Google Workspace? (Choose two.)
Medium6An enterprise organization is planning its 2-Step Verification (2SV) rollout. Which THREE methods or tokens are natively supported by Google Workspace for 2SV authentication? (Choose three.)
Hard7You need to enforce 2-Step Verification for a specific department while allowing others to opt-in voluntarily. Which configuration path should you use?
Medium8Your organization wants to prevent users from sharing Google Drive files externally, but you need to make an exception for a specific partner domain. Where should you configure this allowed domain list?
Medium9Your company uses a third-party Identity Provider (IdP) for Single Sign-On (SSO) via SAML. A newly hired employee is unable to sign in, and you suspect their account is not properly mapped or provisioned. Where can you check SAML sign-in activity and error logs in the Google Admin console?
Medium10Which THREE features or tools in Google Workspace can be used to monitor and investigate suspicious sign-in activity or security anomalies? (Choose three.)
Medium11Your organization requires all contractors to use security keys for 2-Step Verification, while full-time employees can use prompts or authenticator apps. How should you configure this in the Google Admin console?
Medium12Your company has integrated Google Workspace with a third-party IdP using SAML. You want to make sure that when users sign out of Google Workspace, they are also signed out of their IdP session. What feature should you configure?
Medium13Your company has deployed a custom internal web application that integrates with Google Workspace via SAML. During testing, users receive a '403. That’s an error. Error: app_not_configured_for_user' message. What is the most likely cause of this error?
Medium14You need to ensure that users can only access Google Workspace services when they are connecting from corporate-owned devices managed by Endpoint Management and located within the corporate IP range. Which feature combination meets this requirement?
Hard15An administrator needs to delegate the role of creating and managing Google Groups across the entire domain without giving full admin rights. Which built-in role should be assigned?
Easy16An administrator wants to ensure that users cannot use weak or commonly breached passwords. Where can password monitoring be enabled in the Google Admin console?
Easy17You are troubleshooting an issue where a user is unable to authenticate via SAML SSO. You need to inspect the raw SAML request and response messages sent between the IdP and Google Workspace. What is the most effective way to capture this?
Hard18Your organization has configured third-party SAML SSO. However, you need to ensure that Super Administrators can always bypass SSO and sign in using their Google credentials in case the third-party IdP goes down. What configuration setting should you enable?
Hard19You need to create a custom administrator role that allows specific users to manage Google Meet hardware devices and review their health status, but nothing else. Which privilege category should you select when building this custom role?
Medium20An administrator wants to configure security policies to protect corporate data on mobile devices. Which THREE actions can be enforced through Google Workspace Endpoint Management? (Choose three.)
Hard21A new IT support staff member needs to manage user passwords but should not be able to delete users or modify billing settings. Which role should you assign?
Easy22You want to ensure that all users have a strong password policy. Where can you enforce password length and complexity requirements?
Easy23An auditor requests that you restrict administrative access to the Google Workspace Admin console to a specific set of IP addresses. What is the most effective way to implement this?
Hard24Which TWO of the following are valid criteria for a Context-Aware Access level? (Choose two)
Medium25Which THREE actions should you take to secure your Google Workspace environment against unauthorized admin access? (Choose three)
Hard26You need to create a custom administrator role that allows a security analyst to use the Security Center Investigation Tool, view audit logs, and manage alerts, but prevents them from modifying user passwords or organizational unit structures. Which exact set of privileges should you assign?
Hard27An administrator is reviewing API controls and third-party app access in Google Workspace. Which THREE access states can be configured for third-party OAuth applications? (Choose three.)
Hard28An administrator needs to review recent security alerts and proactive recommendations for improving domain security. Where should they look first in the Google Admin console?
Easy29Your organization requires that users can only access Google Drive when connected to the corporate VPN. How can you achieve this using Context-Aware Access?
Medium30Your organization uses a third-party Identity Provider (IdP) for SSO. Users are reporting that they cannot sign in. Where do you verify the SAML configuration?
Medium31An administrator has configured a new SAML SSO integration with a third-party IdP. Users are complaining that they can log in successfully, but after 30 minutes, they are unexpectedly forced to re-authenticate. Where can the administrator adjust the session duration for SAML apps?
Medium32Your company has an external contractor who needs temporary access to Google Workspace. You want to ensure their account automatically deactivates after 30 days without manual administrative intervention. How can you achieve this securely?
Hard33An administrator needs to grant a helpdesk employee the ability to reset user passwords and view user information without granting them full super administrator privileges. Which built-in admin role should be assigned?
Easy34An administrator wants to ensure that users cannot reuse any of their last 5 passwords when changing their password. Where is this setting configured?
Easy35An organization wants to integrate Google Workspace with an external SAML IdP. However, some users (such as external contractors) should continue authenticating directly against Google's native login page using their Google password and 2SV. How should the administrator configure SSO to support this mixed environment?
Hard36When setting up SAML SSO with a third-party Identity Provider (IdP), which THREE pieces of information must typically be exchanged or configured in the Google Admin console? (Choose three.)
Hard37An organization wants to prevent users from signing in to their Google Workspace accounts from outside their home country. Which feature should the administrator configure?
Easy38An administrator needs to restrict access to Google Workspace apps so that users can only log in from corporate-managed Chromebooks and Windows devices enrolled in Endpoint Management, while blocking all mobile devices entirely. How should this be implemented?
Hard39An administrator needs to view a report showing which users in the organization have not enabled 2-Step Verification. Where should the administrator look in the Google Admin console?
Easy40Your company requires that any user attempting to access Google Drive from an unmanaged mobile device must be blocked, while desktop browsers on unmanaged devices are permitted read-only access via Context-Aware Access. How should you structure your Access Levels and assignments?
Hard41An administrator needs to configure password requirements, such as minimum length and expiration policies, for all users in the domain. Where is this configured in the Google Admin console?
Easy42An organization wants to configure SSO with a third-party SAML IdP. Which THREE advanced settings can be configured within the Google Workspace SAML application settings? (Choose three.)
Hard43An administrator needs to enforce 2-Step Verification for all users in the Sales organizational unit (OU). Where in the Google Admin console should the administrator navigate to configure this setting?
Easy44An administrator is configuring Context-Aware Access to secure corporate data. Which TWO criteria can be evaluated within a Context-Aware Access access level expression? (Choose two.)
Hard45Your security team requires that all administrators must use a hardware security key (FIDO2) for 2-Step Verification and are prohibited from using SMS or phone prompts. Where can you enforce this requirement specifically for admin accounts?
Medium46Which TWO reports or logs should an administrator check to verify whether Context-Aware Access rules are successfully blocking unauthorized connection attempts? (Choose two.)
Medium47Which TWO actions should an administrator take to secure administrative accounts against credential theft and unauthorized access? (Choose two.)
Medium48Which TWO of the following are valid methods to verify domain ownership in Google Workspace? (Choose two)
MediumOther domains
All GWS-ADMIN exam domains
Frequently asked questions
- What does the Security Policies And Access Controls domain cover on the GWS-ADMIN exam?
- Security Policies And Access Controls questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 48 Security Policies And Access Controls questions in the GWS-ADMIN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security Policies And Access Controls questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.