Google

Associate Google Workspace Administrator Free Practice Questions — Page 2

Question 12

Your organization has acquired another company that used another email provider. Employees from the newly acquired company need to be able to send and receive emails from two domain names-your organization’s domain name and their former company’s domain name. You need to identify the best approach. What should you do?

A. Add the acquired company’s domain name as a Secondary Domain, and create user accounts with the new domain name.
B. Add the acquired company's domain name as an alias domain.
C. Change the MX records of the old domain to point to the new domain.
D. Create a mail routing rule in the new domain to route messages addressed to the old domain.
Show Answer
Correct Answer: B
Explanation:
Adding the acquired company's domain as a domain alias allows existing users to receive mail at both domain names and send mail using the alias, providing a single mailbox per user. A secondary domain creates separate user identities, while changing MX records or using mail routing alone does not provide unified dual-domain user identities.

Question 13

You work for a global organization that has offices in the United States and the European Union (EU). There is an organizational unit (OU) for employees in the United States and a separate OU for employees in the EU. Your company regulations need you to ensure that your users' data is located in the same region as their physical office. What should you do?

A. Set the OU data location to No preference.
B. Turn on advanced settings and select Enable features that may process data across multiple regions.
C. Turn on advanced settings and select Disable features that may process data across multiple regions.
D. Set a data region policy for each region’s OU.
Show Answer
Correct Answer: D
Explanation:
To meet data residency requirements for separate U.S. and EU organizational units, configure a data region policy for each OU so user data is stored in the appropriate geographic region. 'No preference' does not enforce residency, and enabling or disabling cross-region processing features does not itself assign storage locations.

Question 14

Your organization has detected a significant rise in unauthorized access to applications from personal devices. This poses a critical security risk and could lead to data loss. To mitigate this risk, you must immediately restrict user access to these applications. What should you do?

A. Enable data loss prevention rules.
B. Limit apps access to company-issued devices by using context-aware access.
C. Configure apps data access to Limited to only allow access to unrestricted services.
D. Enable multi-factor authentication for application access.
Show Answer
Correct Answer: B
Explanation:
Context-aware access can enforce device-based access policies so only company-issued or compliant devices can access applications, directly mitigating unauthorized access from personal devices. Data loss prevention focuses on protecting data rather than blocking device access, limiting data access to unrestricted services does not enforce device trust, and MFA strengthens authentication but does not restrict access based on device ownership.

Question 15

Your organization needs an approval application for purchases where a user can enter information on the purchase required and then submit it for management approval. You need to suggest a solution to create the application that must be available on both the web and mobile devices. Your organization does not have software developers or the budget to hire a third party. What should you do?

A. Suggest that the organization develop an application internally with a database, a backend service for data retrieval, and a frontend service for the application’s user interface.
B. Suggest that the organization continue to approve requests manually until budget is available to use a third-party application provider.
C. Suggest the organization use AppSheet to create the application.
D. Suggest that the organization use AppScript to create forms linked to a Google Sheet to store the purchase data.
Show Answer
Correct Answer: C
Explanation:
AppSheet is a no-code platform designed to build web and mobile applications from data sources without requiring software developers. It fits the organization's need for a purchase approval app that works across web and mobile within a limited budget. The other options either require custom development, delay the solution, or provide a more limited scripting/forms approach rather than a full cross-platform approval application.

Question 16

Your company provides shared Chromebook workstations for employees to access sensitive company data. You must configure the devices to ensure no sensitive data is stored locally and that browsing data is cleared after each use. What should you do?

A. Force ephemeral mode in Chrome. Disable offline access for sensitive Workspace apps like Docs, Sheets, and Drive.
B. Enable the Manage Guest Session functionality, and set the maximum user session length.
C. Force ephemeral mode in Chrome. Allow offline access for all Workspace apps with strict expiration times.
D. Disable offline access for all Workspace apps. Enable incognito mode for Chrome browsing sessions.
Show Answer
Correct Answer: A
Explanation:
For shared Chromebooks, forcing ephemeral mode ensures user data is not retained locally after sign-out. Disabling offline access for sensitive Google Workspace apps prevents local copies of sensitive data from being stored. Guest session management or Incognito mode alone does not prevent all local user data storage, and allowing offline access contradicts the requirement.

Question 17

Your organization wants to prevent a group of users from logging into their Google Drive when they are traveling internationally for business. You have added these users to an organizational unit (OU). You need to secure the users’ access to the Google Drive app to meet this requirement. What should you do?

A. Disable Google Drive for users in the OU.
B. Define location-based access levels. Assign the levels to the Google Drive app for the OU.
C. Require 2-step verification (2SV) when users in the OU sign in.
D. Define user-based access levels. Assign the levels to the Google Drive app for the OU.
Show Answer
Correct Answer: B
Explanation:
Context-Aware Access in Google Workspace allows administrators to define location-based access levels and assign them to specific apps such as Google Drive. This can restrict access based on the user's geographic location, preventing sign-in to Drive while users are traveling internationally. Disabling Drive blocks access entirely, 2SV does not enforce location restrictions, and user-based access levels do not address geographic travel conditions.

Question 18

Your company’s legal department has issued a litigation hold that requires you to preserve all data related to a specific project. You need to ensure that all data for this project, including emails, documents, and chats, are preserved indefinitely and cannot be deleted by users. What should you do?

A. Create a hold in Google Vault that includes all users and data sources associated with the project.
B. Assign an Archived User license to all users involved in the project.
C. Set up a retention rule in Google Vault that retains all data from Gmail and Drive indefinitely.
D. Export all project related data from Google Workspace and store the data in a separate, secure location.
Show Answer
Correct Answer: A
Explanation:
A Google Vault hold is designed for litigation and eDiscovery. A hold preserves data for specified users and services (such as Gmail, Drive, and Chat) regardless of retention rules, preventing deletion while the hold is active. An Archived User license is for former employees, a retention rule is broader and not the appropriate mechanism for a specific litigation hold, and exporting data does not prevent users from deleting the original content.

Question 19

Your organization allows employees to use their personal devices for work purposes. You want to ensure these devices follow the company’s security policies. You need to choose a mobile management solution that provides minimal passcode enforcement and allows for an admin to remotely wipe a user’s account from the device. You also want to avoid having to install agents on employees’ personal devices. What should you do?

A. Implement Google’s advanced management on mobile devices.
B. Implement Google’s basic management on mobile devices.
C. Enforce a strong password policy, and enforce the password policy at the next sign-in.
D. Deploy a third-party mobile device management (MDM) solution.
Show Answer
Correct Answer: B
Explanation:
Basic mobile management is designed for BYOD scenarios without requiring device agents. It provides essential controls such as basic passcode enforcement and the ability for an administrator to remotely wipe the managed work account from the device, while advanced management or third-party MDM are intended for more comprehensive device management.

Question 20

An employee is leaving your company and has numerous files stored in My Drive. Their manager wants to retain access to these files. You need to offboard the departing employee’s Google Workspace account while ensuring that the manager can still access the files while following Google-recommended practices. What should you do?

A. Use Google Vault to establish a retention policy for the organizational unit (OU) of the departing employee. Assign the Google Archived User license.
B. Instruct the departing employee to share their My Drive folder with the manager before leaving. Delete the Google Workspace account on the departing employee’s last day.
C. Download the departing employee’s Drive data by using Google Takeout. Upload the data to the manager’s Drive before deleting the departing employee’s Google Workspace account.
D. Transfer ownership of the departing employee’s files to the manager during the user deletion process.
Show Answer
Correct Answer: D
Explanation:
Google Workspace best practice when offboarding a user is to transfer ownership of the departing user's Google Drive files to another user during the account deletion process. This preserves access and ownership for the manager without relying on temporary sharing, Vault retention, or manual export/import. Google Vault is for retention/eDiscovery, not file access, and Archived User licenses preserve data but do not solve the manager's ownership requirement.

Question 21

You need to create an automated application or process that includes connectors to external data, leverages Google Sheets data, and is easily shared as a mobile application. What should you do?

A. Create an application by using App Engine. Connect the application to your Workspace environment
B. Copy the external data to BigQuery. Use a Connected Sheet to interact with the data.
C. Create an AppSheet application to connect the different data sources. Set up the mobile application.
D. Create an automation process by using Apps Script. Run the process through Google Sheets.
Show Answer
Correct Answer: C
Explanation:
AppSheet is designed to build no-code applications that connect to multiple external data sources, including Google Sheets and other connectors, and can be easily deployed and shared as mobile apps. App Engine requires custom development, Connected Sheets is for data analysis rather than mobile app creation, and Apps Script is suited for automation but not for building shareable mobile applications.

$19

Get all 55 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.