Courseiva

GWS-ADMIN · topic practice

Security Policies And Access Controls practice questions

Practise Google Cloud Associate Google Workspace Administrator (GWS-ADMIN) Security Policies And Access Controls practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Security Policies And Access Controls

What the exam tests

What to know about Security Policies And Access Controls

Security Policies And Access Controls questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Security Policies And Access Controls exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Security Policies And Access Controls questions

20 questions · select your answer, then reveal the explanation

Which THREE built-in administrator roles in Google Workspace grant privileges to manage user accounts and reset passwords? (Choose three.)

Your organization requires all contractors to use security keys for 2-Step Verification, while full-time employees can use prompts or authenticator apps. How should you configure this in the Google Admin console?

You need to create a custom administrator role that allows specific users to manage Google Meet hardware devices and review their health status, but nothing else. Which privilege category should you select when building this custom role?

An administrator needs to configure password requirements, such as minimum length and expiration policies, for all users in the domain. Where is this configured in the Google Admin console?

Your organization has configured third-party SAML SSO. However, you need to ensure that Super Administrators can always bypass SSO and sign in using their Google credentials in case the third-party IdP goes down. What configuration setting should you enable?

You need to ensure that users can only access Google Workspace services when they are connecting from corporate-owned devices managed by Endpoint Management and located within the corporate IP range. Which feature combination meets this requirement?

An administrator needs to grant a helpdesk employee the ability to reset user passwords and view user information without granting them full super administrator privileges. Which built-in admin role should be assigned?

Your company uses a third-party Identity Provider (IdP) for Single Sign-On (SSO) via SAML. A newly hired employee is unable to sign in, and you suspect their account is not properly mapped or provisioned. Where can you check SAML sign-in activity and error logs in the Google Admin console?

An administrator needs to enforce 2-Step Verification for all users in the Sales organizational unit (OU). Where in the Google Admin console should the administrator navigate to configure this setting?

An organization wants to prevent users from signing in to their Google Workspace accounts from outside their home country. Which feature should the administrator configure?

Your organization wants to prevent users from sharing Google Drive files externally, but you need to make an exception for a specific partner domain. Where should you configure this allowed domain list?

An administrator has configured a new SAML SSO integration with a third-party IdP. Users are complaining that they can log in successfully, but after 30 minutes, they are unexpectedly forced to re-authenticate. Where can the administrator adjust the session duration for SAML apps?

Your company requires that any user attempting to access Google Drive from an unmanaged mobile device must be blocked, while desktop browsers on unmanaged devices are permitted read-only access via Context-Aware Access. How should you structure your Access Levels and assignments?

Your company has an external contractor who needs temporary access to Google Workspace. You want to ensure their account automatically deactivates after 30 days without manual administrative intervention. How can you achieve this securely?

An administrator needs to view a report showing which users in the organization have not enabled 2-Step Verification. Where should the administrator look in the Google Admin console?

You need to ensure that administrative actions taken by Super Administrators trigger real-time alerts to the security team's email distribution list. Which tool should you use to set this up?

An administrator wants to ensure that users cannot use weak or commonly breached passwords. Where can password monitoring be enabled in the Google Admin console?

Your company has deployed a custom internal web application that integrates with Google Workspace via SAML. During testing, users receive a '403. That’s an error. Error: app_not_configured_for_user' message. What is the most likely cause of this error?

An administrator needs to restrict access to Google Workspace apps so that users can only log in from corporate-managed Chromebooks and Windows devices enrolled in Endpoint Management, while blocking all mobile devices entirely. How should this be implemented?

You are troubleshooting an issue where a user is unable to authenticate via SAML SSO. You need to inspect the raw SAML request and response messages sent between the IdP and Google Workspace. What is the most effective way to capture this?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security Policies And Access Controls sessions

Start a Security Policies And Access Controls only practice session

Every question in these sessions is drawn from the Security Policies And Access Controls domain — nothing else.

Related practice questions

Related GWS-ADMIN topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GWS-ADMIN exam test about Security Policies And Access Controls?
Security Policies And Access Controls questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security Policies And Access Controls questions in a focused session?
Yes — the session launcher on this page draws every question from the Security Policies And Access Controls domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GWS-ADMIN topics?
Use the topic links above to move to related areas, or go back to the GWS-ADMIN question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GWS-ADMIN exam covers. They are not copied from any real exam or dump site.