Google

Associate Google Workspace Administrator Free Practice Questions

This is the free Google Associate Google Workspace Administrator practice question bank — 30 of 55 total questions, each with a full explanation, free to read with no signup required. Updated 2026-04-24.

Every answer is verified against official Google documentation — see our methodology.

Question 1

Your company wants to improve the security of online meetings. You need to prevent unauthorized access to Google Meet meetings and protect sensitive information that is being shared during these meetings. What should you do?

A. Enable and configure the Meet safety settings for the Google Workspace environment.
B. Enable Meet Gemini settings for additional security.
C. Use the Meet audit log to set up alerts when an external participant has joined a meeting.
D. Instruct employees to only use the dial-in phone numbers.
Show Answer
Correct Answer: A
Explanation:
Configuring Google Meet safety (host) settings directly controls who can join, present, share, or record meetings, and helps prevent unauthorized access and data leakage. The other options do not proactively secure meetings in real time or are unrelated to meeting access control.

Question 2

The human resources department notified you of a legal investigation that was started for an employee in the finance department. You need to ensure that this employee's Google Drive data is preserved for at least one year and does not get deleted by the user or by other means. The Google Vault default retention rules for Drive are set for five years. What should you do?

A. Create a hold in Vault for the employee's Drive.
B. Place the employee into a separate organizational unit (OU). Create a custom one-year retention rule for this OU.
C. Change the Vault default retention rule to one year instead of five.
D. Confirm that the Vault default retention rule is set for five years.
Show Answer
Correct Answer: A
Explanation:
A Google Vault hold should be created on the employee’s Drive data. A hold overrides all retention rules and prevents deletion by the user or automated policies for as long as the hold is in place, which is the correct mechanism for preserving data during a legal investigation. Changing retention rules or OUs is unnecessary and could reduce protection or affect other users.

Question 3

You’ve received multiple reports about a suspicious email from someone who is pretending to be from your organization’s human resources department. The email is prompting employees to click a link for a password update. You want to remediate this sender’s emails. What should you do?

A. Use the security investigation tool to search for users who received the suspicious email, and select Mark message as phishing.
B. Use the security investigation tool to action the suspicious email and select Mark message as spam.
C. Create an activity rule to alert administrators to similar emails from that sender.
D. Notify all employees and request that they report this email as spam.
Show Answer
Correct Answer: A
Explanation:
The goal is to remediate a phishing sender by finding and taking action on the malicious messages already delivered. Using the security investigation tool to search for recipients and marking the message as phishing both removes/quarantines the emails and improves detection. Marking as spam is less accurate for credential-harvesting attacks, while creating rules or notifying users does not directly remediate the existing emails.

Question 4

External sharing at your company is only permitted for the sales and marketing department. Engineering is not allowed to share externally. You need to configure the sharing settings to comply with this policy. What should you do?

A. Use a data loss prevention (DLP) solution to control external sharing based on user groups.
B. Create separate shared drives for each department with different external sharing settings.
C. Create organizational units (OUs) for each department. Configure different external sharing settings for each OU.
D. Configure Drive trust rules to restrict the engineering department from sharing externally.
Show Answer
Correct Answer: D
Explanation:
Drive trust rules allow you to granularly control external sharing based on users, groups, or organizational units. You can specifically restrict the engineering department from sharing externally while allowing sales and marketing to do so, without restructuring Drive or relying on less precise controls. This is the recommended and most flexible approach.

Question 5

Your company’s help desk is receiving technical support tickets from employees who report that messages from known external contacts are being sent to the spam label in Gmail. You need to correct the issue and ensure delivery of legitimate emails without introducing additional risk as soon as possible. What should you do?

A. Ask employees to select the messages in Gmail that are being delivered to spam and mark them as Not spam.
B. Contact the external senders, and tell them to authenticate their sent mail by using domain-based message authentication, reporting, and conformance (DMARC).
C. Turn off more aggressive spam filtering in spam policies that are applied to the users’ organizational unit and add the senders’ mail system IP addresses to the email allowlist.
D. Create an address list of approved senders so messages from these users bypass Gmail’s spam filters and recipients can decide whether they are spam or not.
Show Answer
Correct Answer: A
Explanation:
Marking the messages as Not spam is the fastest and lowest-risk way to correct false positives. This action feeds Gmail’s spam detection signals and helps improve filtering without weakening domain-wide spam protections. The other options either introduce security risk (allowlists or reduced filtering) or are slower and outside your administrative control (requiring external senders to change authentication).

Question 6

Your security team is concerned about disgruntled employees downloading large amounts of intellectual property. You need to create an automatic notification if any user downloads more than 500 files from Google Drive within a one-hour period. What should you do?

A. Configure a Data Loss Prevention (DLP) rule for Drive.
B. Use the alert center to review Drive audit logs for instances where users download a large number of files.
C. Create an activity rule in the security investigation tool to monitor Drive download events. Set a threshold to trigger an alert.
D. Set up an alert within Google Cloud Monitoring to track the number of Drive API calls and trigger a notification when a user makes an excessive number of download requests.
Show Answer
Correct Answer: C
Explanation:
The requirement is an automatic alert based on a specific user activity threshold (more than 500 Drive file downloads within one hour). Google Workspace’s Security Investigation Tool supports activity rules for Drive events, where conditions and thresholds can be defined and alerts triggered automatically. DLP focuses on sensitive content, the Alert Center alone cannot define custom thresholds, and Cloud Monitoring does not track user-level Drive activity.

Question 7

Your company recently installed a free email marketing platform from the Google Workspace Marketplace. The marketing team is unable to access customer contact information or send emails through the platform. You need to identify the cause of the problem. What should you do first?

A. Use the security investigation tool to review Gmail logs.
B. Confirm that the "Manage Third-Party App Access" setting in the Admin console is enabled.
C. Check the OAuth scopes that are granted to the email marketing platform and ensure the platform has access to Contacts and Gmail.
D. Verify that the email marketing platform's subscription is active and up-to-date.
Show Answer
Correct Answer: C
Explanation:
When a Workspace Marketplace app cannot read contacts or send email after installation, the most common cause is missing or insufficient OAuth scopes. Even if the app is installed, it must be granted Gmail and Contacts scopes to access customer data and send messages. Checking the OAuth scopes in the Admin console directly addresses this root cause before investigating logs or subscription status.

Question 8

A team of employees in your organization is collaborating on a project with an external organization. Employees of the external organization need access to project documents in your Google Workspace domain, however they don't currently have a Google account. You need to enable secure file sharing while preventing unauthorized access. What should you do?

A. Enable external sharing for the organizational unit (OU) that is created for the external organization.
B. Add the external organization's domain to the trusted domain allowlist.
C. Create and assign user accounts to the external users of your Workspace domain.
D. Enable visitor sharing for the organizational unit (OU) in your Workspace domain.
Show Answer
Correct Answer: D
Explanation:
The external collaborators do not have Google accounts, so traditional external sharing or trusted domains will not work. Visitor sharing allows secure access to Google Drive files for users without Google accounts using PIN-based email verification, preventing unauthorized access without creating or licensing new user accounts.

Question 9

You recently noticed a suspicious trend in your organization's Google Drive usage. Several users have shared sensitive documents outside the organization, potentially violating your company's data security policy. You need to identify the responsible users and the extent of the unauthorized sharing. What should you do?

A. Create an activity rule in the Security Center to alert you of future external sharing events.
B. Use the security health page to identify misconfigured sharing settings in Drive.
C. Review the organization's sharing policies in the Admin console, and update the policies to prevent external sharing.
D. Use the security investigation tool to analyze Drive logs and identify the users.
Show Answer
Correct Answer: D
Explanation:
To identify who shared sensitive Drive files externally and assess the scope of the incident, you need detailed, user-level audit data. The Security Investigation Tool lets you query Drive audit logs to see which users shared files, when the sharing occurred, and with whom. The other options focus on future alerts, general configuration health, or prevention, not investigating an existing incident.

Question 10

Your organization wants to ensure that all employees who use Chrome browsers for work adhere to specific security and configuration settings. You need to manage and control the Chrome browsers used within the company while using the least expensive solution. What should you do?

A. Remotely wipe all employee devices to ensure that they are using the latest Chrome browser version.
B. Enroll the Chrome browsers in your organization's domain and apply Chrome browser policies.
C. Use a third-party software deployment solution to manage the Chrome browser.
D. Disable all extensions on employee Chrome browsers to prevent any potential security risks.
Show Answer
Correct Answer: B
Explanation:
Enrolling Chrome browsers in the organization’s domain enables centralized management through Chrome Browser Cloud Management or the Google Admin console. This allows enforcement of security and configuration policies (updates, extensions, settings) at low or no additional cost, making it the least expensive and most appropriate solution.

$19

Get all 55 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.