Google

Associate Google Workspace Administrator Free Practice Questions — Page 2

Question 11

Your organization has acquired another company that used another email provider. Employees from the newly acquired company need to be able to send and receive emails from two domain names-your organization’s domain name and their former company’s domain name. You need to identify the best approach. What should you do?

A. Add the acquired company’s domain name as a Secondary Domain, and create user accounts with the new domain name.
B. Add the acquired company's domain name as an alias domain.
C. Change the MX records of the old domain to point to the new domain.
D. Create a mail routing rule in the new domain to route messages addressed to the old domain.
Show Answer
Correct Answer: B
Explanation:
Adding the acquired company’s domain as an alias domain allows existing users to send and receive email using both domain names from a single mailbox and account. This provides seamless dual-domain email identity without creating separate users or relying on forwarding-only solutions, and is the recommended approach for unified email management after an acquisition.

Question 12

You work for a global organization that has offices in the United States and the European Union (EU). There is an organizational unit (OU) for employees in the United States and a separate OU for employees in the EU. Your company regulations need you to ensure that your users' data is located in the same region as their physical office. What should you do?

A. Set the OU data location to No preference.
B. Turn on advanced settings and select Enable features that may process data across multiple regions.
C. Turn on advanced settings and select Disable features that may process data across multiple regions.
D. Set a data region policy for each region’s OU.
Show Answer
Correct Answer: D
Explanation:
The requirement is to ensure data residency based on users’ physical location. Applying a data region policy to each OU enforces where user data is stored (EU data in EU regions, U.S. data in U.S. regions). The other options either allow flexible storage or only limit processing features without guaranteeing region-specific data storage.

Question 13

Your organization has detected a significant rise in unauthorized access to applications from personal devices. This poses a critical security risk and could lead to data loss. To mitigate this risk, you must immediately restrict user access to these applications. What should you do?

A. Enable data loss prevention rules.
B. Limit apps access to company-issued devices by using context-aware access.
C. Configure apps data access to Limited to only allow access to unrestricted services.
D. Enable multi-factor authentication for application access.
Show Answer
Correct Answer: B
Explanation:
The immediate risk is unauthorized access from personal devices. Context-aware access allows you to restrict application access based on device attributes, ensuring only company-issued or compliant devices can access apps. This directly blocks personal devices right away. DLP focuses on data handling, not device access; limiting app data access does not enforce device restrictions; and MFA strengthens authentication but still permits access from personal devices.

Question 14

Your organization needs an approval application for purchases where a user can enter information on the purchase required and then submit it for management approval. You need to suggest a solution to create the application that must be available on both the web and mobile devices. Your organization does not have software developers or the budget to hire a third party. What should you do?

A. Suggest that the organization develop an application internally with a database, a backend service for data retrieval, and a frontend service for the application’s user interface.
B. Suggest that the organization continue to approve requests manually until budget is available to use a third-party application provider.
C. Suggest the organization use AppSheet to create the application.
D. Suggest that the organization use AppScript to create forms linked to a Google Sheet to store the purchase data.
Show Answer
Correct Answer: C
Explanation:
The organization needs a cross‑platform (web and mobile) approval app but lacks developers and budget. AppSheet is a no‑code platform designed for exactly this scenario, allowing business users to quickly build data‑driven applications with approval workflows without writing code. Option A requires developers, B does not solve the problem, and D (Apps Script with Forms) is more limited and not suited for a full approval application experience across platforms.

Question 15

Your company provides shared Chromebook workstations for employees to access sensitive company data. You must configure the devices to ensure no sensitive data is stored locally and that browsing data is cleared after each use. What should you do?

A. Force ephemeral mode in Chrome. Disable offline access for sensitive Workspace apps like Docs, Sheets, and Drive.
B. Enable the Manage Guest Session functionality, and set the maximum user session length.
C. Force ephemeral mode in Chrome. Allow offline access for all Workspace apps with strict expiration times.
D. Disable offline access for all Workspace apps. Enable incognito mode for Chrome browsing sessions.
Show Answer
Correct Answer: A
Explanation:
Ephemeral mode on ChromeOS ensures that all user data (including downloads, cache, and browsing data) is wiped when the user signs out, which is ideal for shared workstations. Disabling offline access for sensitive Workspace apps prevents local storage of company data. Together, these settings ensure no sensitive data persists on the device after each use.

Question 16

Your organization wants to prevent a group of users from logging into their Google Drive when they are traveling internationally for business. You have added these users to an organizational unit (OU). You need to secure the users’ access to the Google Drive app to meet this requirement. What should you do?

A. Disable Google Drive for users in the OU.
B. Define location-based access levels. Assign the levels to the Google Drive app for the OU.
C. Require 2-step verification (2SV) when users in the OU sign in.
D. Define user-based access levels. Assign the levels to the Google Drive app for the OU.
Show Answer
Correct Answer: B
Explanation:
To block access based on whether users are traveling internationally, access must be controlled by geographic location. Location-based access levels (Context-Aware Access) can restrict Google Drive access outside approved countries and can be applied to a specific OU. Disabling Drive is too broad, 2SV does not prevent access, and user-based access levels do not evaluate location.

Question 17

Your company’s legal department has issued a litigation hold that requires you to preserve all data related to a specific project. You need to ensure that all data for this project, including emails, documents, and chats, are preserved indefinitely and cannot be deleted by users. What should you do?

A. Create a hold in Google Vault that includes all users and data sources associated with the project.
B. Assign an Archived User license to all users involved in the project.
C. Set up a retention rule in Google Vault that retains all data from Gmail and Drive indefinitely.
D. Export all project related data from Google Workspace and store the data in a separate, secure location.
Show Answer
Correct Answer: A
Explanation:
A Google Vault hold is designed for litigation scenarios and preserves data indefinitely, overriding retention rules and preventing user deletion across Gmail, Drive, and other services for the scoped users or data. Archived User licenses are for former employees, retention rules don’t prevent deletion under a legal hold scenario, and exporting data does not ensure ongoing preservation.

Question 18

Your organization allows employees to use their personal devices for work purposes. You want to ensure these devices follow the company’s security policies. You need to choose a mobile management solution that provides minimal passcode enforcement and allows for an admin to remotely wipe a user’s account from the device. You also want to avoid having to install agents on employees’ personal devices. What should you do?

A. Implement Google’s advanced management on mobile devices.
B. Implement Google’s basic management on mobile devices.
C. Enforce a strong password policy, and enforce the password policy at the next sign-in.
D. Deploy a third-party mobile device management (MDM) solution.
Show Answer
Correct Answer: B
Explanation:
The scenario is BYOD, requires minimal passcode enforcement, the ability to remotely wipe only the user’s work account (not the entire device), and no agent installation on personal devices. Google’s basic mobile management is designed for BYOD and provides account-level controls such as remote account wipe and basic security enforcement without requiring an MDM agent. Advanced management and third-party MDMs typically require device enrollment or agents, and enforcing a strong password alone does not provide remote wipe capabilities.

Question 19

An employee is leaving your company and has numerous files stored in My Drive. Their manager wants to retain access to these files. You need to offboard the departing employee’s Google Workspace account while ensuring that the manager can still access the files while following Google-recommended practices. What should you do?

A. Use Google Vault to establish a retention policy for the organizational unit (OU) of the departing employee. Assign the Google Archived User license.
B. Instruct the departing employee to share their My Drive folder with the manager before leaving. Delete the Google Workspace account on the departing employee’s last day.
C. Download the departing employee’s Drive data by using Google Takeout. Upload the data to the manager’s Drive before deleting the departing employee’s Google Workspace account.
D. Transfer ownership of the departing employee’s files to the manager during the user deletion process.
Show Answer
Correct Answer: D
Explanation:
Google-recommended offboarding practice is to transfer ownership of a departing user’s Google Drive files during the account deletion process. This preserves file access, permissions, and sharing settings while ensuring continuity for the manager. Other options either rely on user action, create unnecessary data duplication, or address retention rather than active access.

Question 20

You need to create an automated application or process that includes connectors to external data, leverages Google Sheets data, and is easily shared as a mobile application. What should you do?

A. Create an application by using App Engine. Connect the application to your Workspace environment
B. Copy the external data to BigQuery. Use a Connected Sheet to interact with the data.
C. Create an AppSheet application to connect the different data sources. Set up the mobile application.
D. Create an automation process by using Apps Script. Run the process through Google Sheets.
Show Answer
Correct Answer: C
Explanation:
AppSheet is designed to quickly build and share mobile applications that connect to multiple data sources, including Google Sheets and external connectors, with minimal code. It supports automation and easy distribution to users, which fits all the requirements stated.

$19

Get all 55 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.