Courseiva

CCNA Data Governance And Compliance Questions

28 questions · Data Governance And Compliance topic · All types, answers revealed

1
MCQeasy

How can you ensure that deleted emails are kept for 3 years even if the user empties their trash?

A.Enable endpoint management
B.Use an Admin Console report
C.Configure a Gmail filter
D.Set a Gmail retention rule in Google Vault
AnswerD

Vault retention rules preserve data regardless of user deletion actions.

Why this answer

A Vault retention rule for Gmail with a 3-year duration ensures all emails are preserved for that period, overriding user deletion.

2
Multi-Selecthard

Which THREE security settings are commonly configured using Context-Aware Access?

Select 3 answers
A.Device security posture (e.g., screen lock)
B.User IP address
C.Email signature format
D.User password strength
E.Geographical location
AnswersA, B, E

Ensures the device meets security standards.

Why this answer

Context-aware access allows restricting access to apps based on device security posture, IP, and location.

3
MCQhard

You want to prevent sensitive Drive documents from being printed. Which setting is appropriate?

A.Context-aware access
B.Drive sharing options for viewers/commenters
C.Endpoint management
D.DLP policy
AnswerB

This setting explicitly disables download, print, and copy for shared files.

Why this answer

Drive sharing settings include an option to disable downloading, printing, and copying for viewers and commenters.

4
Multi-Selectmedium

Which TWO actions can you take when a user account is under a Vault hold?

Select 2 answers
A.Automatically delete old emails
B.Prevent data deletion
C.Enable 2-Step Verification
D.Ensure data availability for eDiscovery
E.Allow the user to change their password
AnswersB, D

This is the core purpose of a hold.

Why this answer

A hold ensures the data is not deleted, even if the user attempts to delete it or if the account is suspended/deleted.

5
MCQeasy

Your legal team requires that all emails from a specific user be preserved for an upcoming audit. Which tool should you use to ensure these messages are not deleted?

A.Data Loss Prevention (DLP) rules
B.Google Workspace Migration for Microsoft Outlook
C.Admin Console Reporting
D.Google Vault
AnswerD

Vault allows administrators to set retention rules and holds to preserve data for legal purposes.

Why this answer

Google Vault is designed for eDiscovery and retention. Setting a retention rule or hold in Vault ensures data is preserved regardless of user actions.

6
MCQmedium

You need to ensure that credit card numbers are not sent via Gmail by your employees. Which tool should you configure?

A.Context-aware access
B.DLP rules
C.Google Vault retention rules
D.Security center investigation tool
AnswerB

DLP rules scan for sensitive patterns and block or alert based on policy.

Why this answer

DLP rules in Google Workspace allow administrators to define content detectors to scan for sensitive information like credit card numbers.

7
Multi-Selectmedium

Which TWO actions can you perform in Google Vault?

Select 2 answers
A.Configure DLP policies
B.Set up 2-Step Verification
C.Search and export user data
D.Manage user passwords
E.Place a hold on user data
AnswersC, E

Search and export are core Vault functions.

Why this answer

Vault allows you to place holds on data to prevent deletion and perform searches across user mail and files for eDiscovery.

8
Multi-Selecthard

Which THREE types of data can be managed using Vault retention rules?

Select 3 answers
A.Gmail messages
B.Google Drive files
C.User device logs
D.Google Chat messages
E.Third-party app tokens
AnswersA, B, D

Supported for retention.

Why this answer

Vault supports retention for Gmail, Drive, Chat, Groups, and Voice data.

9
MCQmedium

You need to verify if an email was sent to an external address. Where can you see this in the Admin Console?

A.Vault search
B.Compliance reports
C.Security center
D.Email log search
AnswerD

This tool shows the journey and delivery status of emails.

Why this answer

The Email Log Search tool in the Admin Console allows administrators to trace email delivery and identify recipients.

10
Multi-Selecthard

Which THREE features are part of the Security Center?

Select 3 answers
A.Security health page
B.Vault retention rules
C.DLP policy configuration
D.Security dashboard
E.Investigation tool
AnswersA, D, E

Shows best practices and configuration recommendations.

Why this answer

The Security Center provides tools for proactive security, incident investigation, and reporting on security metrics.

11
MCQhard

You have a Data Region policy configured for the US. A user moves from the US to the EU. How do you trigger the migration of their existing data to the EU?

A.Manually run a data export in Vault
B.Re-provision the user account
C.Move the user to an OU configured for the EU data region
D.Contact Google Support to initiate a manual migration
AnswerC

Moving the user to an OU associated with the EU data region triggers the automated migration process.

Why this answer

Google Workspace automatically migrates data to the new region once the user's organizational unit (OU) is updated to a region mapped to the new location.

12
MCQeasy

Which Google Workspace service should you use to search and export user data for legal requests?

A.Google Vault
B.Google Cloud Storage
C.Data migrations
D.Security center
AnswerA

Vault is built for eDiscovery, search, and export.

Why this answer

Vault is the primary tool for eDiscovery and legal data requests in Google Workspace.

13
MCQmedium

You need to prevent users from sharing sensitive files outside the organization. Which setting should you modify?

A.Endpoint management
B.Vault retention settings
C.Drive sharing options in the Admin Console
D.App access control
AnswerC

You can restrict external sharing at the organizational unit level.

Why this answer

Drive sharing settings allow administrators to restrict sharing to internal users or specific whitelisted domains.

14
MCQmedium

You need to create a report showing which users have been affected by a specific DLP policy violation in the last month. Where can you find this?

A.Admin audit logs
B.Reports dashboard
C.Security center investigation tool
D.Vault matters
AnswerC

You can filter logs by DLP rule name or event type.

Why this answer

The Security Center investigation tool allows for queries specifically filtered by DLP rule violations.

15
Multi-Selecteasy

Which TWO actions should be taken when offboarding a user to protect organizational data?

Select 2 answers
A.Reset the user's billing settings
B.Suspend the user account
C.Apply a Vault hold if required
D.Grant user full email access
E.Delete the user account immediately
AnswersB, C

Prevents further access.

Why this answer

Suspending access and ensuring data is preserved or transferred are critical offboarding steps.

16
MCQmedium

You need to ensure that Google Chat messages are retained for 5 years. How do you do this?

A.Enable chat history for all users
B.Export Chat logs via the API
C.Create a Chat retention rule in Vault
D.Set a Gmail retention rule
AnswerC

Vault provides explicit support for Chat retention.

Why this answer

Vault supports retention rules for Google Chat, which can be configured for a specific time period.

17
Multi-Selecthard

Which THREE criteria can you use to build a DLP rule in Google Workspace?

Select 3 answers
A.User password history
B.Network latency
C.Custom regular expressions
D.Predefined content detectors
E.Drive labels
AnswersC, D, E

Useful for finding organization-specific sensitive patterns.

Why this answer

DLP rules can be based on predefined content detectors, custom regex, and document metadata like labels.

18
MCQhard

You need to investigate a potential data breach where a user downloaded a large number of sensitive files. Which tool provides the most granular audit logs for Drive file downloads?

A.Security center investigation tool
B.DLP policy logs
C.Vault eDiscovery search
D.Reports dashboard
AnswerA

This tool provides detailed event logs including 'download' actions.

Why this answer

The Investigation tool within the Security Center provides the most granular logs for file-level activities, including downloads.

19
MCQhard

An employee is suspected of leaking data. You need to search their past Gmail and Drive files for specific terms. Which tool do you use?

A.Vault matter search
B.DLP incident report
C.Security investigation tool
D.Admin audit logs
AnswerA

Vault search is designed to find specific content within user data.

Why this answer

Vault allows for full-text search across Gmail, Drive, and other services to support eDiscovery investigations.

20
MCQeasy

Where do you go in the Admin Console to view the current data region for your organization?

A.Vault > Settings
B.Apps > Google Workspace
C.Account > Account settings > Data regions
D.Security > Data protection
AnswerC

This is the correct path for viewing and managing data region policies.

Why this answer

The 'Account settings' section under 'Account' contains the data regions configuration.

21
MCQeasy

When a user leaves the company, which status should you set their account to if you want to keep their data but stop them from logging in?

A.Reset the 2-Step Verification
B.Suspend the account
C.Change the password
D.Delete the account
AnswerB

Suspension removes access while maintaining the account and data.

Why this answer

Suspending a user account prevents access but keeps the account and data intact for admins to access or migrate.

22
Multi-Selectmedium

Which TWO tools in the Admin Console help you identify potentially compromised accounts?

Select 2 answers
A.Vault search
B.Group settings
C.Security dashboard
D.Investigation tool
E.Data regions
AnswersC, D

Shows alerts for suspicious login events.

Why this answer

The Security dashboard and the Investigation tool are the primary means of identifying suspicious activity in user accounts.

23
MCQhard

You have a Data Region policy, but a user is still showing data in the global region. What is the most likely cause?

A.The user's OU is not in a region-mapped group
B.The account is suspended
C.The user hasn't logged in recently
D.Vault hold is preventing the move
AnswerA

Migration is driven by the OU's mapped location.

Why this answer

Data region policies require the user's OU to be updated to match the intended region. If the OU is not updated, the migration process does not begin.

24
Multi-Selectmedium

Which TWO settings in Drive sharing can help prevent data leakage?

Select 2 answers
A.Prevent viewers from downloading, printing, or copying
B.Limit sharing to specific domains
C.Allow external sharing for all users
D.Enable 'Allow user to set their own sharing'
E.Disable all Drive sharing
AnswersA, B

This protects document content from unauthorized distribution.

Why this answer

Restricting sharing to the organization and preventing viewers from downloading files are effective ways to protect data.

25
MCQmedium

A user is leaving the company. You need to keep their data for 7 years. What is the best practice?

A.Export all data to a PST file
B.Transfer Drive ownership to another user
C.Suspend the user account and keep it
D.Create a Vault hold for the user's account
AnswerD

A Vault hold preserves all data for the user account for as long as the hold is active.

Why this answer

Placing a legal hold in Vault ensures all of a user's data is preserved indefinitely or until the hold is removed, which is appropriate for offboarding.

26
MCQhard

You need to restrict access to the Admin Console to only users connecting from your corporate office IP address. Which tool do you use?

A.DLP policy
B.Context-aware access
C.2-Step Verification
D.Vault access settings
AnswerB

You can create an access level based on IP and assign it to the Admin Console.

Why this answer

Context-aware access allows you to define access levels based on IP ranges and apply them to the Admin Console.

27
MCQeasy

Which dashboard provides a summary of security incidents and potential policy violations?

A.Vault dashboard
B.Compliance reports
C.User management dashboard
D.Security center dashboard
AnswerD

This dashboard provides alerts and reports on security events.

Why this answer

The Security Center dashboard provides an overview of security-related events and policy violations across the workspace.

28
MCQhard

You need to monitor for potentially malicious third-party apps accessing Drive data. Which feature should you use?

A.App access control
B.DLP rules
C.Context-aware access
D.Vault matters
AnswerA

This allows you to whitelist or block apps based on their requested access levels.

Why this answer

App access control allows admins to review and restrict third-party apps that have OAuth scopes to access Drive files.

Ready to test yourself?

Try a timed practice session using only Data Governance And Compliance questions.