Associate Google Workspace Administrator Free Practice Questions
This is the free Google Associate Google Workspace Administrator practice question bank —
30 of 55 total questions, each with a full explanation, free to
read with no signup required. Updated 2026-08-06.
Every answer is verified against official Google documentation —
see our methodology.
Question 1
Your company wants to improve the security of online meetings. You need to prevent unauthorized access to Google Meet meetings and protect sensitive information that is being shared during these meetings. What should you do?
A. Enable and configure the Meet safety settings for the Google Workspace environment.
B. Enable Meet Gemini settings for additional security.
C. Use the Meet audit log to set up alerts when an external participant has joined a meeting.
D. Instruct employees to only use the dial-in phone numbers.
Show Answer
Correct Answer: A
Explanation: Meet safety settings (host controls and related safety features) are designed to prevent unauthorized access, control participant actions, and protect information shared during meetings. Gemini settings are not a primary security control, audit logs are for monitoring after events rather than preventing access, and relying on dial-in numbers does not improve meeting security.
Question 3
The human resources department notified you of a legal investigation that was started for an employee in the finance department. You need to ensure that this employee's Google Drive data is preserved for at least one year and does not get deleted by the user or by other means. The Google Vault default retention rules for Drive are set for five years. What should you do?
A. Create a hold in Vault for the employee's Drive.
B. Place the employee into a separate organizational unit (OU). Create a custom one-year retention rule for this OU.
C. Change the Vault default retention rule to one year instead of five.
D. Confirm that the Vault default retention rule is set for five years.
Show Answer
Correct Answer: A
Explanation: A Google Vault hold is the correct mechanism for legal preservation. A hold preserves the specified user's Drive data regardless of retention rules or user deletion until the hold is removed. The existing five-year default retention rule already exceeds one year but does not replace the need for a legal hold during an investigation. Changing retention rules or moving the user to another OU is unnecessary or incorrect for this scenario.
Question 4
You’ve received multiple reports about a suspicious email from someone who is pretending to be from your organization’s human resources department. The email is prompting employees to click a link for a password update. You want to remediate this sender’s emails. What should you do?
A. Use the security investigation tool to search for users who received the suspicious email, and select Mark message as phishing.
B. Use the security investigation tool to action the suspicious email and select Mark message as spam.
C. Create an activity rule to alert administrators to similar emails from that sender.
D. Notify all employees and request that they report this email as spam.
Show Answer
Correct Answer: A
Explanation: To remediate a phishing campaign, use the security investigation tool to locate affected messages and take a remediation action by marking the message as phishing. This classifies the message correctly and enables appropriate handling/remediation across affected mailboxes. Marking it as spam is less appropriate for a credential-harvesting attack, while creating an alert or relying on users to report it does not remediate existing messages.
Question 5
External sharing at your company is only permitted for the sales and marketing department. Engineering is not allowed to share externally. You need to configure the sharing settings to comply with this policy. What should you do?
A. Use a data loss prevention (DLP) solution to control external sharing based on user groups.
B. Create separate shared drives for each department with different external sharing settings.
C. Create organizational units (OUs) for each department. Configure different external sharing settings for each OU.
D. Configure Drive trust rules to restrict the engineering department from sharing externally.
Show Answer
Correct Answer: D
Explanation: Drive trust rules provide granular controls over Google Drive external sharing based on users, groups, or organizational units. This directly satisfies the requirement to allow sales and marketing to share externally while preventing engineering from doing so. DLP is for content inspection rather than primary sharing permissions, shared drive settings alone do not enforce user-based departmental policy, and OU-based external sharing settings are less appropriate than the purpose-built trust rules for granular sharing restrictions.
Question 6
Your company’s help desk is receiving technical support tickets from employees who report that messages from known external contacts are being sent to the spam label in Gmail. You need to correct the issue and ensure delivery of legitimate emails without introducing additional risk as soon as possible. What should you do?
A. Ask employees to select the messages in Gmail that are being delivered to spam and mark them as Not spam.
B. Contact the external senders, and tell them to authenticate their sent mail by using domain-based message authentication, reporting, and conformance (DMARC).
C. Turn off more aggressive spam filtering in spam policies that are applied to the users’ organizational unit and add the senders’ mail system IP addresses to the email allowlist.
D. Create an address list of approved senders so messages from these users bypass Gmail’s spam filters and recipients can decide whether they are spam or not.
Show Answer
Correct Answer: D
Explanation: Creating an approved sender address list (Approved senders) allows mail from trusted external contacts to bypass Gmail spam filtering for recipients, addressing false positives quickly without broadly weakening spam protections. Marking 'Not spam' is user-by-user, DMARC depends on external senders and is not immediate, and disabling aggressive filtering plus allowlisting IPs is broader and increases risk.
Question 7
Your security team is concerned about disgruntled employees downloading large amounts of intellectual property. You need to create an automatic notification if any user downloads more than 500 files from Google Drive within a one-hour period. What should you do?
A. Configure a Data Loss Prevention (DLP) rule for Drive.
B. Use the alert center to review Drive audit logs for instances where users download a large number of files.
C. Create an activity rule in the security investigation tool to monitor Drive download events. Set a threshold to trigger an alert.
D. Set up an alert within Google Cloud Monitoring to track the number of Drive API calls and trigger a notification when a user makes an excessive number of download requests.
Show Answer
Correct Answer: C
Explanation: Activity rules in the Google Workspace Security Center can monitor Drive events, apply thresholds over a time window (such as more than 500 downloads in one hour), and automatically generate alerts. DLP focuses on content, the Alert Center does not provide this kind of custom threshold rule, and Google Cloud Monitoring is not used for Google Workspace user download activity.
Question 8
Your company recently installed a free email marketing platform from the Google Workspace Marketplace. The marketing team is unable to access customer contact information or send emails through the platform. You need to identify the cause of the problem. What should you do first?
A. Use the security investigation tool to review Gmail logs.
B. Confirm that the "Manage Third-Party App Access" setting in the Admin console is enabled.
C. Check the OAuth scopes that are granted to the email marketing platform and ensure the platform has access to Contacts and Gmail.
D. Verify that the email marketing platform's subscription is active and up-to-date.
Show Answer
Correct Answer: C
Explanation: A newly installed Google Workspace Marketplace app that cannot access contacts or send email most commonly lacks the necessary OAuth permissions. The first step is to verify the OAuth scopes granted to the app include access to Google Contacts and Gmail. Reviewing Gmail logs does not diagnose app authorization, third-party app access settings govern whether apps may connect rather than the specific permissions granted, and a free Marketplace app does not typically require checking a subscription.
Question 9
A team of employees in your organization is collaborating on a project with an external organization. Employees of the external organization need access to project documents in your Google Workspace domain, however they don't currently have a Google account. You need to enable secure file sharing while preventing unauthorized access. What should you do?
A. Enable external sharing for the organizational unit (OU) that is created for the external organization.
B. Add the external organization's domain to the trusted domain allowlist.
C. Create and assign user accounts to the external users of your Workspace domain.
D. Enable visitor sharing for the organizational unit (OU) in your Workspace domain.
Show Answer
Correct Answer: D
Explanation: Visitor sharing is designed specifically for sharing Google Drive files with people who do not have Google accounts. It uses secure identity verification (such as a one-time PIN sent to the recipient's email) to grant access while preventing unauthorized access. Simply enabling external sharing or allowlisting a domain does not solve the lack of Google accounts, and creating Workspace accounts for external collaborators is unnecessary and adds administrative overhead.
Question 10
You recently noticed a suspicious trend in your organization's Google Drive usage. Several users have shared sensitive documents outside the organization, potentially violating your company's data security policy. You need to identify the responsible users and the extent of the unauthorized sharing. What should you do?
A. Create an activity rule in the Security Center to alert you of future external sharing events.
B. Use the security health page to identify misconfigured sharing settings in Drive.
C. Review the organization's sharing policies in the Admin console, and update the policies to prevent external sharing.
D. Use the security investigation tool to analyze Drive logs and identify the users.
Show Answer
Correct Answer: D
Explanation: The Security Investigation Tool is designed to query Drive audit logs and investigate historical events, including external file sharing. It allows you to identify which users shared sensitive documents, when the sharing occurred, and other relevant details. The other options either provide preventive controls or future alerting rather than investigating an existing incident.
Question 11
Your organization wants to ensure that all employees who use Chrome browsers for work adhere to specific security and configuration settings. You need to manage and control the Chrome browsers used within the company while using the least expensive solution. What should you do?
A. Remotely wipe all employee devices to ensure that they are using the latest Chrome browser version.
B. Enroll the Chrome browsers in your organization's domain and apply Chrome browser policies.
C. Use a third-party software deployment solution to manage the Chrome browser.
D. Disable all extensions on employee Chrome browsers to prevent any potential security risks.
Show Answer
Correct Answer: B
Explanation: Enrolling Chrome browsers in the organization's domain enables centralized browser management through Chrome Browser Cloud Management/Chrome Enterprise Core, allowing administrators to enforce security and configuration policies at low or no additional cost compared with third-party management. The other options either do not provide centralized policy management or are unnecessarily restrictive or expensive.
$19
Get all 55 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.