Courseiva

CCNA Security Policies And Access Controls Questions

48 questions · Security Policies And Access Controls topic · All types, answers revealed

1
Multi-Selectmedium

Which TWO mechanisms can an administrator use to recover access if a Super Administrator loses their 2-Step Verification device and is locked out? (Choose two.)

Select 2 answers
A.Have another Super Administrator reset the locked admin's 2-Step Verification status in the Google Admin console.
B.Call Google Workspace technical support to instantly disable 2SV without verification.
C.Send a password reset request to the external SAML IdP to bypass Google 2SV.
D.Log in using the root domain controller administrative credentials.
E.Use pre-generated backup verification codes stored securely by the administrator.
AnswersA, E

Another Super Admin can navigate to the user's profile and turn off or reset 2SV settings.

Why this answer

Super admin account recovery can be achieved using backup verification codes generated in advance or by another Super Admin resetting 2SV.

2
MCQhard

You need to prevent users from installing third-party Marketplace apps that request access to their Gmail data. What is the best approach?

A.Disable the Google Workspace Marketplace for the entire domain.
B.Configure an endpoint verification policy.
C.Use the 'Allowlist' feature to block specific OAuth scopes globally.
D.Change the 'Sharing settings' in the Drive and Docs settings.
AnswerC

App Access Control allows you to manage app permissions and block specific scopes like Gmail.

Why this answer

The 'App Access Control' settings allow administrators to block third-party apps based on the OAuth scopes they request.

3
MCQmedium

Your organization uses Context-Aware Access to restrict access to Google Workspace based on IP address ranges. A remote employee traveling for business is unable to access Gmail from a trusted hotel Wi-Fi. How should the administrator temporarily grant access without compromising long-term security?

A.Permanently add the hotel IP subnet to the global Context-Aware Access access level.
B.Disable 2-Step Verification for the user's account.
C.Reset the user's OAuth tokens via the Admin SDK.
D.Temporarily move the user to an organizational unit that does not have the Context-Aware Access rule applied, or assign a temporary exception access level.
AnswerD

Moving the user to an exempted OU or updating group/OU assignments for CAA provides targeted, temporary relief.

Why this answer

Administrators can assign temporary access levels or temporarily move the user to an OU without the CAA restriction.

4
MCQhard

You need to ensure that administrative actions taken by Super Administrators trigger real-time alerts to the security team's email distribution list. Which tool should you use to set this up?

A.Google Cloud Logging exported to BigQuery with Cloud Pub/Sub triggers
B.Reporting > Audit logs > Set alert webhook
C.Security Center > Investigation Tool > Save search and set automatic notification schedule.
D.Alert Center > Custom rules > Create rule, selecting Admin log events as the datasource and specifying email recipients.
AnswerD

Alert Center custom rules allow you to monitor Workspace logs and trigger alerts and email notifications automatically.

Why this answer

Alert Center rules allow administrators to configure notification triggers for specific admin activity log events.

5
Multi-Selectmedium

Which TWO practices are recommended when configuring organizational units (OUs) for security policy enforcement in Google Workspace? (Choose two.)

Select 2 answers
A.Assign Super Administrator privileges to the head of each organizational unit.
B.Override policies at every child OU level even when parent policies are identical to ensure redundancy.
C.Regularly audit OU membership and policy inheritance to ensure users receive appropriate security controls.
D.Place every single user in the root organizational unit to ensure uniform policy application.
E.Structure OUs hierarchically to mirror department or security requirement boundaries so policies inherit correctly.
AnswersC, E

Auditing ensures users who change roles are moved to appropriate OUs with correct security settings.

Why this answer

Best practices for OUs include inheriting policies from parent OUs where possible and structuring OUs logically by department or security requirement.

6
Multi-Selecthard

An enterprise organization is planning its 2-Step Verification (2SV) rollout. Which THREE methods or tokens are natively supported by Google Workspace for 2SV authentication? (Choose three.)

Select 3 answers
A.Time-based One-Time Password (TOTP) authenticator apps (e.g., Google Authenticator)
B.Biometric retina scans processed by local BIOS firmware
C.Automatic voice call verification through landline pulse dialing tones
D.Google Prompts sent to trusted mobile devices
E.Security keys (FIDO2 / U2F hardware keys like Titan keys)
AnswersA, D, E

TOTP codes generated by authenticator apps are natively supported.

Why this answer

Google Workspace supports security keys (FIDO2/U2F), Google Prompts on mobile devices, and authenticator app OTP codes (TOTP).

7
MCQmedium

You need to enforce 2-Step Verification for a specific department while allowing others to opt-in voluntarily. Which configuration path should you use?

A.Apply the enforcement policy at the root Organizational Unit level.
B.Use the Google Cloud Identity platform to create a conditional access policy for individual users.
C.Set the 'Allowed to opt-in' setting to 'Off' for the entire domain.
D.Move the department users into a dedicated Organizational Unit and enable 'Enforce' in the 2-Step Verification settings.
AnswerD

Applying the setting to a specific OU allows targeted enforcement for that department.

Why this answer

To enforce 2SV for specific users, you must use Organizational Units (OUs) or Groups and manage the enforcement settings under Security > Authentication > 2-step verification.

8
MCQmedium

Your organization wants to prevent users from sharing Google Drive files externally, but you need to make an exception for a specific partner domain. Where should you configure this allowed domain list?

A.Security > Authentication > Trusted domains
B.Directory > Organizational units > External sharing policy
C.Security > Access and data control > Whitelisted domains
D.Apps > Google Workspace > Drive and Docs > Sharing settings > Whitelisted domains
AnswerD

Drive sharing permissions and trusted external domains are configured directly in the Drive and Docs sharing settings.

Why this answer

Allowed external domains for sharing are managed under Apps > Google Workspace > Drive and Docs > Sharing settings.

9
MCQmedium

Your company uses a third-party Identity Provider (IdP) for Single Sign-On (SSO) via SAML. A newly hired employee is unable to sign in, and you suspect their account is not properly mapped or provisioned. Where can you check SAML sign-in activity and error logs in the Google Admin console?

A.Directory > Users > [User] > Activity > Sign-in activity
B.Reporting > Audit > SAML
C.Reporting > Audit > Admin log events
D.Security > Authentication > SAML log events
AnswerB

Reporting > Audit > SAML displays details regarding SSO sign-in attempts and SAML errors.

Why this answer

Log events related to SAML and SSO authentication failures are recorded in the SAML log events section of the Google Admin console.

10
Multi-Selectmedium

Which THREE features or tools in Google Workspace can be used to monitor and investigate suspicious sign-in activity or security anomalies? (Choose three.)

Select 3 answers
A.Apps > Google Workspace > Drive sharing settings
B.Security Center > Investigation Tool
C.Alert Center
D.Directory > Users > Bulk update via CSV
E.Reporting > Audit > Log events (e.g., Login, Admin, SAML)
AnswersB, C, E

The Investigation Tool allows administrators to query logs, devices, and user activities to remediate threats.

Why this answer

Suspicious activity can be tracked using Audit logs, the Security Center Investigation Tool, and Alert Center.

11
MCQmedium

Your organization requires all contractors to use security keys for 2-Step Verification, while full-time employees can use prompts or authenticator apps. How should you configure this in the Google Admin console?

A.Modify the default domain-wide sign-in security policy to require security keys globally and grant exceptions via API.
B.Configure Context-Aware Access to block non-security key authentications for the contractors group.
C.Create an IAM custom role that revokes prompt-based authentication for external users.
D.Place contractors in a dedicated OU, navigate to Security > Authentication > 2-step verification, and configure the allowed methods to only include security keys.
AnswerD

Targeting policies via OUs allows you to restrict allowed 2SV methods exclusively to security keys for specific subsets of users.

Why this answer

Security key enforcement can be targeted to specific organizational units or security groups by setting the 2SV policy appropriately.

12
MCQmedium

Your company has integrated Google Workspace with a third-party IdP using SAML. You want to make sure that when users sign out of Google Workspace, they are also signed out of their IdP session. What feature should you configure?

A.Context-Aware Access session termination
B.OAuth token revocation API
C.Automated user provisioning via SCIM
D.SAML Single Logout (SLO) URL configuration in the SSO profile.
AnswerD

Configuring the SLO URL in the Google Admin console enables Single Logout integration with the IdP.

Why this answer

Single Logout (SLO) allows users to terminate their session across both Google Workspace and the configured SAML IdP.

13
MCQmedium

Your company has deployed a custom internal web application that integrates with Google Workspace via SAML. During testing, users receive a '403. That’s an error. Error: app_not_configured_for_user' message. What is the most likely cause of this error?

A.The IdP signing certificate has expired.
B.The user's password has expired and needs to be reset.
C.The SAML app service status is set to OFF for the user's organizational unit or access group.
D.The user does not have a Google Cloud Platform billing account attached.
AnswerC

Service status must be set to ON for everyone or turned on for specific OUs/groups to allow user access to custom SAML apps.

Why this answer

This error occurs when the SAML app is configured in the Google Admin console, but access is turned OFF for the user or their organizational unit.

14
MCQhard

You need to ensure that users can only access Google Workspace services when they are connecting from corporate-owned devices managed by Endpoint Management and located within the corporate IP range. Which feature combination meets this requirement?

A.Context-Aware Access access levels referencing IP subnets and device policy compliance, assigned to targeted apps.
B.Google Cloud IAM conditions with Context-Aware Access and Security Health Analytics
C.Domain-wide SAML SSO with custom attribute mapping for IP addresses
D.Advanced Protection Program combined with Context-Aware Access
AnswerA

Context-Aware Access evaluates access levels containing attributes for both IP subnets and device policy status before granting access.

Why this answer

Context-Aware Access allows you to combine IP address subnets and device-policy compliance (corporate-owned status via endpoint management) to control access.

15
MCQeasy

An administrator needs to delegate the role of creating and managing Google Groups across the entire domain without giving full admin rights. Which built-in role should be assigned?

A.Groups Admin
B.Directory Sync Admin
C.Helpdesk Admin
D.User Management Admin
AnswerA

Groups Admin allows creation, deletion, and management of Google Groups settings.

Why this answer

The Groups Admin role specifically grants privileges to manage Google Groups.

16
MCQeasy

An administrator wants to ensure that users cannot use weak or commonly breached passwords. Where can password monitoring be enabled in the Google Admin console?

A.Security > Password management > Monitor password reuse and strength
B.Security Center > Security health page > Password strength
C.Account settings > Legal and compliance > Password audit
D.Directory > Users > Security alerts
AnswerA

Password monitoring settings are located under Security > Password management.

Why this answer

Password monitoring for breached credentials is enabled under Security > Password management.

17
MCQhard

You are troubleshooting an issue where a user is unable to authenticate via SAML SSO. You need to inspect the raw SAML request and response messages sent between the IdP and Google Workspace. What is the most effective way to capture this?

A.Use browser developer tools (Network tab) or a browser extension like SAML Tracer to capture and inspect the SAMLRequest and SAMLResponse POST parameters.
B.View the SAML audit logs in Reporting > Audit > SAML.
C.Run the Google Workspace SSO diagnostic tool in the Security Center.
D.Enable debug logging in Google Cloud Logging for the Workspace organization.
AnswerA

SAML protocol traffic is passed via browser HTTP POST bindings, making browser developer tools or tracer extensions ideal for viewing the raw XML assertions.

Why this answer

Browser developer tools with SAML tracer extensions or network log analysis capture the Base64 encoded SAMLAssertion payloads.

18
MCQhard

Your organization has configured third-party SAML SSO. However, you need to ensure that Super Administrators can always bypass SSO and sign in using their Google credentials in case the third-party IdP goes down. What configuration setting should you enable?

A.Disable SAML SSO entirely and rely exclusively on Google's built-in OAuth service.
B.Enable the 'Turn on SSO for administrative accounts' option and assign a backup password.
C.Configure SSO profile assignment to exclude Super Administrators or use the 'Allow users to sign in with Google password' option on the SSO profile page.
D.Create a Context-Aware Access rule that triggers emergency recovery mode when the IdP IP is unreachable.
AnswerC

Enabling the sign-in with Google password option for admins or assigning them to a separate OU without SSO enforcement ensures emergency access.

Why this answer

Google Workspace allows you to configure a secondary SSO profile or enable network/admin bypass settings to allow admin sign-in via Google credentials.

19
MCQmedium

You need to create a custom administrator role that allows specific users to manage Google Meet hardware devices and review their health status, but nothing else. Which privilege category should you select when building this custom role?

A.Services > Google Meet hardware
B.Organizational Units and Admin Roles
C.Mobile and Endpoints > Device Management
D.Security Center > Investigation Tool
AnswerA

Google Meet hardware management privileges are located under the Services category.

Why this answer

Privileges for managing Meet hardware and devices are found under the Services and Devices privilege trees.

20
Multi-Selecthard

An administrator wants to configure security policies to protect corporate data on mobile devices. Which THREE actions can be enforced through Google Workspace Endpoint Management? (Choose three.)

Select 3 answers
A.Enforce containerization or work profile segregation on Android devices.
B.Require a screen lock and strong password on enrolled mobile devices.
C.Perform a remote wipe of corporate data (or full wipe) on lost or stolen devices.
D.Configure deep packet inspection on all cellular data traffic passing through the device.
E.Directly access and read personal text messages stored on the user's personal phone.
AnswersA, B, C

Advanced endpoint management supports Android work profiles to separate personal and corporate data.

Why this answer

Google Endpoint Management allows administrators to enforce device policies such as requiring a screen lock, wiping corporate data remotely, and enforcing password requirements on devices.

21
MCQeasy

A new IT support staff member needs to manage user passwords but should not be able to delete users or modify billing settings. Which role should you assign?

A.Groups Admin
B.User Management Admin
C.Super Admin
D.Help Desk Admin
AnswerB

This role is designed for managing user accounts, including password resets, without billing or delete permissions.

Why this answer

The 'User Management Admin' role allows for password resets and basic user info updates without full super admin privileges.

22
MCQeasy

You want to ensure that all users have a strong password policy. Where can you enforce password length and complexity requirements?

A.Directory > User settings
B.Security > Authentication > Password management
C.Security > Context-Aware Access
D.Account > Account settings
AnswerB

This is the correct path for setting password complexity and expiration policies.

Why this answer

Password policies are managed in the Security section under Password management.

23
MCQhard

An auditor requests that you restrict administrative access to the Google Workspace Admin console to a specific set of IP addresses. What is the most effective way to implement this?

A.Create an 'Access Level' in Context-Aware Access and apply it to the Admin console app.
B.Disable 'Advanced Protection Program' for all users.
C.Apply a VPC Service Controls perimeter around the organization.
D.Configure 'Admin console sign-in restriction' under Security > Authentication.
AnswerD

This setting directly restricts access to the Admin console to specific allowed IP addresses.

Why this answer

The 'Admin console sign-in restriction' setting allows administrators to limit console access to trusted networks.

24
Multi-Selectmedium

Which TWO of the following are valid criteria for a Context-Aware Access level? (Choose two)

Select 2 answers
A.Device encryption status
B.User's browser history
C.User's favorite color
D.User's time zone
E.IP subnet
AnswersA, E

Device attributes like encryption status are valid criteria.

Why this answer

Context-Aware Access levels can be built using IP subnets and device attributes like encryption status or OS versions.

25
Multi-Selecthard

Which THREE actions should you take to secure your Google Workspace environment against unauthorized admin access? (Choose three)

Select 3 answers
A.Enable 'Admin console sign-in restriction' to trusted IPs.
B.Require a password change every 30 days for all users.
C.Configure Audit and Investigation logs to alert on unusual admin activity.
D.Require Security Keys for all Super Admin accounts.
E.Disable all non-Google apps in the Marketplace.
AnswersA, C, D

Limiting admin access by network location is a best practice.

Why this answer

Securing admin accounts involves multi-factor authentication, monitoring, and limiting the scope of privileges.

26
MCQhard

You need to create a custom administrator role that allows a security analyst to use the Security Center Investigation Tool, view audit logs, and manage alerts, but prevents them from modifying user passwords or organizational unit structures. Which exact set of privileges should you assign?

A.Grant 'Super Admin' privileges and restrict access using Context-Aware Access.
B.Select privileges from Security Center (Investigation Tool, Alerts) and Reporting (Audit logs), while leaving User Management and OU privileges unchecked.
C.Assign the 'Helpdesk Admin' role combined with 'Security Center Reader'.
D.Assign the built-in 'Security Admin' role and remove user management privileges via override.
AnswerB

Selecting only specific monitoring and investigation privileges grants the desired visibility without granting destructive user management or structural modification rights.

Why this answer

Building a custom role requires selecting precise privileges from the Security Center and Reporting privilege categories.

27
Multi-Selecthard

An administrator is reviewing API controls and third-party app access in Google Workspace. Which THREE access states can be configured for third-party OAuth applications? (Choose three.)

Select 3 answers
A.Trusted (allowed access to all Google Workspace APIs and data scopes)
B.Supervised (requiring a Super Administrator to approve every API call in real time)
C.Read-Only Sandbox (running apps in an isolated container without data persistence)
D.Limited (allowed access only to specific whitelisted Google APIs or restricted data scopes)
E.Blocked (prevented from accessing any Google Workspace user data or APIs)
AnswersA, D, E

Trusted apps have unrestricted access to requested scopes.

Why this answer

Third-party OAuth applications can be configured as Trusted, Limited, or Blocked.

28
MCQeasy

An administrator needs to review recent security alerts and proactive recommendations for improving domain security. Where should they look first in the Google Admin console?

A.Security > Security Center > Dashboard
B.Directory > Users > Security status
C.Reporting > Audit logs > Security overview
D.Apps > Google Workspace > Security Center
AnswerA

The Security Center dashboard provides an overview of security health, alerts, and actionable recommendations.

Why this answer

The Security Center provides a centralized dashboard for security analytics, alerts, and recommendations.

29
MCQmedium

Your organization requires that users can only access Google Drive when connected to the corporate VPN. How can you achieve this using Context-Aware Access?

A.Restrict Google Drive access via the 'OAuth app allowlist'.
B.Configure an IP-based access level and assign it to the Google Drive app.
C.Update the 'Password Strength' policy in the Admin console.
D.Enable 'Endpoint Verification' on all user devices.
AnswerB

Creating an access level based on IP ranges and assigning it to the Drive service restricts access accordingly.

Why this answer

Context-Aware Access levels are created in Security > Access and data control > Context-Aware access, then assigned to apps.

30
MCQmedium

Your organization uses a third-party Identity Provider (IdP) for SSO. Users are reporting that they cannot sign in. Where do you verify the SAML configuration?

A.Security > Authentication > SSO with third-party IdP
B.Apps > Web and mobile apps
C.Directory > Users
D.Account > Domain settings
AnswerA

This is the correct location for configuring and troubleshooting third-party SAML SSO.

Why this answer

SAML configuration for third-party providers is managed in Security > Authentication > SSO with third-party IdP.

31
MCQmedium

An administrator has configured a new SAML SSO integration with a third-party IdP. Users are complaining that they can log in successfully, but after 30 minutes, they are unexpectedly forced to re-authenticate. Where can the administrator adjust the session duration for SAML apps?

A.Security > Access and data control > API controls
B.Apps > Web and mobile apps > [SAML App] > Service status
C.Security > Authentication > SSO with third-party IdP > Session length settings
D.Account settings > Profile > Session duration
AnswerC

Google Workspace allows you to configure session duration specifically within the SAML app configuration or enterprise app settings.

Why this answer

SAML session length settings for third-party applications are configured within the specific SAML app settings in the Google Admin console.

32
MCQhard

Your company has an external contractor who needs temporary access to Google Workspace. You want to ensure their account automatically deactivates after 30 days without manual administrative intervention. How can you achieve this securely?

A.Enable the Advanced Protection Program, which automatically deletes inactive external accounts after 30 days.
B.Use Cloud Identity Premium automated user lifecycle management or the Admin SDK API to schedule account suspension after 30 days.
C.Set the user password expiration policy specifically for that user's OU to 30 days.
D.Configure a Context-Aware Access rule with a time-based expiration condition.
AnswerB

Cloud Identity features and the Admin SDK allow automated scheduling or provisioning lifecycle management for temporary accounts.

Why this answer

Google Workspace accounts do not have a native 'account expiration date' field by default, but you can manage this via Directory Sync or automated scripts using Admin SDK, or by setting calendar alerts. However, the standard administrative feature for automated lifecycle management is Directory Sync or Cloud Identity lifecycle features. Wait, looking at standard admin tools: Google Workspace allows setting user account expiration using the Admin SDK or automated lifecycle rules in cloud identity, or using Context-Aware Access temporary rules.

Let's look at the options.

33
MCQeasy

An administrator needs to grant a helpdesk employee the ability to reset user passwords and view user information without granting them full super administrator privileges. Which built-in admin role should be assigned?

A.User Management Admin
B.Helpdesk Admin
C.Groups Admin
D.Services Admin
AnswerA

The User Management Admin role allows resetting passwords, suspending users, and editing user profiles.

Why this answer

The User Management Admin role grants permissions to reset passwords, manage user profiles, and view organizational units.

34
MCQeasy

An administrator wants to ensure that users cannot reuse any of their last 5 passwords when changing their password. Where is this setting configured?

A.Directory > Users > Security > Passwords
B.Account settings > Security > Password recycling
C.Apps > Google Workspace > Settings > Password policy
D.Security > Password management > Password history
AnswerD

Password history restrictions are configured in the Password management section.

Why this answer

Password history and restriction settings are located under Security > Password management.

35
MCQhard

An organization wants to integrate Google Workspace with an external SAML IdP. However, some users (such as external contractors) should continue authenticating directly against Google's native login page using their Google password and 2SV. How should the administrator configure SSO to support this mixed environment?

A.Use Context-Aware Access to redirect contractor sign-ins to the third-party IdP while routing employees to Google.
B.Assign the SAML SSO profile selectively to specific organizational units or access groups, leaving the contractor OU on 'Deactivated' SSO settings.
C.Set up two separate Google Workspace domains, one for contractors and one for employees.
D.Configure domain-wide SAML SSO and check the box to allow emergency Google passwords for all users.
AnswerB

SSO profile assignment can be targeted to specific OUs or groups, enabling hybrid authentication models.

Why this answer

Google Workspace allows you to assign SSO profiles to specific organizational units or groups, allowing some users to use SAML and others to use Google login.

36
Multi-Selecthard

When setting up SAML SSO with a third-party Identity Provider (IdP), which THREE pieces of information must typically be exchanged or configured in the Google Admin console? (Choose three.)

Select 3 answers
A.Entity ID (Issuer) provided by the IdP
B.The third-party IdP database connection string (SQL connection)
C.Sign-in URL of the third-party IdP
D.Google Workspace master database encryption key
E.X.509 signing certificate
AnswersA, C, E

The Entity ID uniquely identifies the IdP issuer in SAML assertions.

Why this answer

SAML setup requires configuring the IdP sign-in URL, entity ID (issuer), and X.509 signing certificate.

37
MCQeasy

An organization wants to prevent users from signing in to their Google Workspace accounts from outside their home country. Which feature should the administrator configure?

A.Data Region Policy
B.Context-Aware Access
C.Advanced Protection Program
D.Password Monitoring
AnswerB

Context-Aware Access allows administrators to restrict access based on geographic location attributes.

Why this answer

Context-Aware Access supports restricting access based on geographic location (country/region).

38
MCQhard

An administrator needs to restrict access to Google Workspace apps so that users can only log in from corporate-managed Chromebooks and Windows devices enrolled in Endpoint Management, while blocking all mobile devices entirely. How should this be implemented?

A.Use Context-Aware Access with access levels checking for device policy compliance and specific operating systems (desktop OS only).
B.Set up IAM conditions in the Google Cloud console for Google Workspace endpoints.
C.Apply an Advanced Protection policy for all mobile users.
D.Configure mobile device management settings to turn off Google sync for iOS and Android.
AnswerA

CAA allows filtering by OS (Windows, ChromeOS, macOS) and device compliance status, effectively excluding mobile OS types.

Why this answer

Context-Aware Access rules can evaluate device OS and management state to block mobile devices and permit only managed corporate devices.

39
MCQeasy

An administrator needs to view a report showing which users in the organization have not enabled 2-Step Verification. Where should the administrator look in the Google Admin console?

A.Account settings > Security metrics > Export
B.Security > Authentication > Dashboard > User status
C.Reporting > Reports > Security > 2-Step Verification adoption
D.Directory > Users > Filter > 2SV Status
AnswerC

The 2-Step Verification adoption report shows which users have 2SV enabled or unenforced.

Why this answer

The Security dashboard and reports provide visibility into 2SV adoption status across users.

40
MCQhard

Your company requires that any user attempting to access Google Drive from an unmanaged mobile device must be blocked, while desktop browsers on unmanaged devices are permitted read-only access via Context-Aware Access. How should you structure your Access Levels and assignments?

A.Set up Alert Center policies to automatically revoke OAuth tokens when an unmanaged mobile device accesses Drive.
B.Create two access levels (one for mobile compliant devices, one for desktop OS/browsers) and assign them conditionally using advanced CAA expressions.
C.Configure mobile device management (MDM) basic rules to block Drive synchronization on unmanaged iOS/Android.
D.Create a single access level checking for device policy compliance and assign it to Google Drive for all devices.
AnswerB

Advanced CEL (Common Expression Language) expressions in Context-Aware Access allow differentiation based on device type (mobile vs desktop) and compliance status.

Why this answer

Context-Aware Access requires creating separate access levels for device policy compliance and assigning them selectively to apps.

41
MCQeasy

An administrator needs to configure password requirements, such as minimum length and expiration policies, for all users in the domain. Where is this configured in the Google Admin console?

A.Apps > Google Workspace > Gmail > Security
B.Directory > Users > Password settings
C.Security > Password management
D.Account settings > Personalization > Passwords
AnswerC

Security > Password management is the correct location to enforce length, expiration, and strong password requirements.

Why this answer

Password policies are managed under Security > Password management in the Google Admin console.

42
Multi-Selecthard

An organization wants to configure SSO with a third-party SAML IdP. Which THREE advanced settings can be configured within the Google Workspace SAML application settings? (Choose three.)

Select 3 answers
A.Direct database connection pool size for real-time user lookup
B.Custom SSL cipher suites for the Google Workspace login button rendering
C.Name ID format selection (e.g., EMAIL, PERSISTENT)
D.Signed response option (requiring Google to sign authentication requests or verify signed assertions)
E.Start URL (deep link URL where users are redirected after authentication)
AnswersC, D, E

Administrators can choose the format of the Name ID attribute passed in SAML assertions.

Why this answer

Advanced SAML settings include configuring Start URL, Name ID format, and Signed requests/responses.

43
MCQeasy

An administrator needs to enforce 2-Step Verification for all users in the Sales organizational unit (OU). Where in the Google Admin console should the administrator navigate to configure this setting?

A.Account settings > Security settings > 2SV
B.Directory > Users > Security > Access control
C.Security > Authentication > 2-step verification
D.Devices > Mobile & endpoints > Settings > Universal settings
AnswerC

This is the correct path to manage and enforce 2-Step Verification for specific OUs or domains.

Why this answer

Enforcing 2-Step Verification requires navigating to Security > Authentication > 2-step verification in the Google Admin console.

44
Multi-Selecthard

An administrator is configuring Context-Aware Access to secure corporate data. Which TWO criteria can be evaluated within a Context-Aware Access access level expression? (Choose two.)

Select 2 answers
A.The number of unread emails in the user's Gmail inbox.
B.The user's local operating system password complexity and history length.
C.The user's direct manager name listed in the directory schema.
D.User's current geographic location (country/region).
E.Device policy compliance (e.g., encrypted disk, screen lock enabled).
AnswersD, E

CAA supports geographic location attributes to allow or deny access by country.

Why this answer

Context-Aware Access evaluates attributes such as device security status (screen lock, encryption, management) and IP subnets.

45
MCQmedium

Your security team requires that all administrators must use a hardware security key (FIDO2) for 2-Step Verification and are prohibited from using SMS or phone prompts. Where can you enforce this requirement specifically for admin accounts?

A.Directory > Admin roles > Security policies
B.Security > Authentication > 2-step verification > Allow only security keys for administrators
C.Security > Admin security > Enforce 2-Step Verification and specify security keys.
D.Account settings > Administrator privileges > Authentication
AnswerC

Security > Admin security provides dedicated controls to mandate specific 2SV mechanisms like security keys for admin accounts.

Why this answer

Admin security policies, including strict 2SV methods for administrators, are configured under Security > Admin security.

46
Multi-Selectmedium

Which TWO reports or logs should an administrator check to verify whether Context-Aware Access rules are successfully blocking unauthorized connection attempts? (Choose two.)

Select 2 answers
A.Apps > Google Workspace > Marketplace apps > Activity
B.Directory > Users > Organizational unit history
C.Security > Security Center > Billing and subscriptions log
D.Reporting > Audit > Login audit log events
E.Reporting > Audit > Context-Aware Access
AnswersD, E

Login audit events record sign-in successes and failures, including policy block reasons.

Why this answer

Context-Aware Access blocks and evaluations are recorded in the Context-Aware Access log events and Audit log reports.

47
Multi-Selectmedium

Which TWO actions should an administrator take to secure administrative accounts against credential theft and unauthorized access? (Choose two.)

Select 2 answers
A.Enforce hardware security keys as the only allowed 2-Step Verification method for administrator accounts.
B.Enable SMS-based 2SV verification as a mandatory fallback for all admin accounts.
C.Configure Context-Aware Access to restrict administrator console access to corporate IP ranges or managed devices.
D.Disable password expiration policies for all admin accounts to prevent administrative lockout.
E.Assign the 'Super Admin' role to all members of the IT helpdesk to ensure fast incident response.
AnswersA, C

Hardware security keys provide phishing-resistant 2SV, making them ideal for securing high-privilege admin accounts.

Why this answer

Securing admin accounts involves mandating strict 2SV methods and restricting admin access to known IPs or devices.

48
Multi-Selectmedium

Which TWO of the following are valid methods to verify domain ownership in Google Workspace? (Choose two)

Select 2 answers
A.Enabling SSO via a SAML metadata file.
B.Adding a TXT or CNAME record to your DNS settings.
C.Uploading an HTML file to the root directory of your website.
D.Sending an email to the registrar's abuse alias.
E.Creating a new admin account with the '@gmail.com' suffix.
AnswersB, C

DNS verification is the most common method.

Why this answer

Google Workspace provides multiple methods for domain verification, including DNS records and file uploads.

Ready to test yourself?

Try a timed practice session using only Security Policies And Access Controls questions.