Google

Associate Google Workspace Administrator Free Practice Questions — Page 3

Question 21

Your organization has experienced a recent increase in unauthorized access attempts to your company’s Google Workspace instance. You need to enhance the security of user accounts while following Google-recommended practices. What should you do?

A. Disable password recovery options to prevent unauthorized individuals from accessing user accounts.
B. Implement a strong password policy and enable text messages as the 2-Step Verification (2SV) using text messages.
C. Enforce the use of physical security keys as the 2-Step Verification (2SV) method for all users.
D. Enforce a strong password policy that requires users to include special characters, numbers, and uppercase letters.
Show Answer
Correct Answer: C
Explanation:
Google-recommended best practices for securing Google Workspace accounts emphasize phishing-resistant multi-factor authentication. Physical security keys provide the strongest protection against unauthorized access and phishing, far exceeding SMS-based 2SV or password-only controls. Options that rely only on stronger passwords or SMS 2SV do not adequately address modern attack methods, and disabling recovery options can create account lockout risks without materially improving security.

Question 22

You are onboarding a new employee who will use a company-provided Android device. Your company requires the ability to enforce strong security policies on mobile devices, including password complexity requirements and remote device wipe capabilities. You need to choose the appropriate Google Workspace mobile device management solution. What should you do?

A. Use a third-party mobile device management (MDM) solution to manage the device.
B. Allow the employee to use their personal device without enrolling it in any mobile device management (MDM) solution.
C. Implement Google’s basic management solution for the mobile device.
D. Implement Google’s advanced management solution for the mobile device.
Show Answer
Correct Answer: D
Explanation:
Google’s advanced mobile device management is designed for company-owned Android devices and supports enforcing strong security policies such as password complexity, device-wide controls, and full remote wipe. Basic management lacks these advanced enforcement capabilities, and the other options do not meet the company’s security requirements.

Question 23

Your company wants to start using Google Workspace for email. Your domain is verified through a third-party provider. You need to route the email to Google Workspace. What should you do?

A. Change your domain’s A record to point to Google’s mail servers.
B. Configure a forwarding rule in your current email system to redirect all messages to Gmail.
C. Update your domain’s MX records to the Google Workspace MX records provided in the setup instructions.
D. Create a CNAME record that maps your domain to “gmail.com.”
Show Answer
Correct Answer: C
Explanation:
To route email to Google Workspace, you must tell the internet’s mail routing system where to deliver messages for your domain. This is done by updating the domain’s MX (Mail Exchanger) records to the Google Workspace MX records provided during setup. A records and CNAMEs are not used for mail routing, and forwarding from an existing system is unnecessary once Google Workspace is the primary mail service.

Question 24

You are configuring Google Chat for your organization. Using the Adin console, you want to enable employees to view their chat history by default and allow employees to turn off chat history. What should you do?

A. Configure Google Vault to retain all Chat messages, and exclude organizational units (OUs) with users who want to turn Chat history off.
B. Set the space history setting to OFF and chat history to ON.
C. Set the top-level default conversation history setting to ON and allow users to change their history setting.
D. Set the top-level default conversation history settings to OFF and allow users in each organizational unit (OU) to change their history setting.
Show Answer
Correct Answer: C
Explanation:
The requirement is to have chat history enabled by default for all employees while still allowing individual users to turn it off. This is achieved by setting the top-level (organization-wide) default conversation history setting to ON and permitting users to change their own history setting. Other options either disable history by default, rely on Vault (which controls retention, not user-facing history settings), or do not meet the default-on requirement.

Question 25

You’ve noticed an increase in phishing emails that contain links to malicious files hosted on external Google Drives. These files often mimic legitimate documents and trick users into granting access to their accounts. You need to prevent users from accessing these malicious external Drive files, but allow them to access legitimate external files. What should you do? (Choose two.)

A. Enforce stricter password policies.
B. Conduct regular security awareness training to educate users.
C. Create a Drive trust rule that blocks all external domains except for a pre-approved list of trusted partners.
D. Deploy advanced malware detection software on all user devices to scan and block malicious files.
E. Implement two-factor authentication for all users.
Show Answer
Correct Answer: B, C
Explanation:
Blocking malicious external Drive files while still allowing legitimate ones is best achieved by combining user education and technical controls. Security awareness training helps users recognize phishing attempts and avoid granting access to fake documents. Creating a Drive trust rule that blocks all external domains except a pre-approved list directly prevents access to untrusted external Drive content while preserving access to known, legitimate partners. Other options do not specifically address external Drive file access.

Question 26

Per regulatory requirements, your company is required to keep the data of employees located in Germany within Europe and the data of employees located in the US within the US. The employees in Germany are in a separate organizational unit (OU) than employees in the US. You need to ensure that where employee data is stored is in compliance with the location regulations. What should you do?

A. Instruct employees to use Drive for desktop to keep documents on their corporate computers.
B. Create two Groups. Assign employees into the Germany or US Group based on their location. Use Google Drive trust rules to prevent sharing between the Groups.
C. Navigate to the Data Regions function in the Admin console. Select the Europe region for employees in Germany, and select the US region for US employees.
D. Navigate to the Data Regions function in the Admin console. Select “No preference.”
Show Answer
Correct Answer: C
Explanation:
Google Workspace Data Regions allow you to control where covered user data is stored based on organizational units. Since employees in Germany and the US are already separated into different OUs, assigning Europe to the Germany OU and the US to the US OU ensures regulatory compliance. The other options do not enforce data residency requirements.

Question 27

An end user has thousands of files stored in Google Drive. Their files are well organized with Drive labels. You need to advise the end user on how to quickly identify all files that are contracts. What should you do?

A. Advise the user to use the Google Drive API to search for files with the keyword “contracts”
B. Advise the user to search in Drive for files with the keyword “contracts”, and use the “modified by me” filter.
C. Advise the user to search for files that are labeled as “contracts”.
D. Advise the user to use the Investigation tool to search for files with the keyword “contracts” and updated by you.
Show Answer
Correct Answer: C
Explanation:
The files are already well organized using Drive labels, which are designed for categorization and fast filtering. Searching by the specific label "contracts" in Google Drive will immediately return all contract files without relying on keywords, APIs, or administrative investigation tools.

Question 28

Your organization’s users are reporting that a large volume of legitimate emails are being misidentified as spam in Gmail. You want to troubleshoot this problem while following Google-recommended practices. What should you do?

A. Adjust the organization’s mail content compliance settings in the Admin console.
B. Advise users to individually allowlist senders.
C. Disable spam filtering for all users.
D. Contact Google Workspace support and report a suspected system-wide spam filter malfunction.
Show Answer
Correct Answer: A
Explanation:
Google recommends troubleshooting spam issues using Admin console controls first. Adjusting mail content compliance and related spam settings allows admins to fine-tune filtering centrally without weakening security. Allowlisting users individually or disabling spam filtering are not recommended, and contacting support is typically done after reviewing and adjusting admin settings.

Question 29

Your company handles sensitive client data and needs to maintain a high level of security to comply with strict industry regulations. You need to allow your company’s security team to investigate potential security breaches by using the security investigation tool in the Google Admin console. What should you do?

A. Create an activity rule that triggers email notifications to the security team whenever a high-risk security event occurs.
B. Assign the User Management Admin role to the security team.
C. Assign the super admin role to the security team
D. Create an administrator role with Security Center access. Assign the role to the security team.
Show Answer
Correct Answer: D
Explanation:
To let the security team investigate incidents using the Security Investigation tool in the Google Admin console, they need access to the Security Center. Creating a custom administrator role with Security Center access and assigning it to the team provides the required capabilities while following the principle of least privilege. Other options either grant insufficient permissions or overly broad access.

Question 30

Your organization’s security team has published a list of vetted third-party apps and extensions that can be used by employees. All other apps are prohibited unless a business case is presented and approved. The Chrome Web Store policy applied at the top-level organization allows all apps and extensions with an admin blocklist. You need to disable any unapproved apps that have already been installed and prevent employees from installing unapproved apps. What should you do?

A. Change the Chrome Web Store allow/block mode setting to allow all apps, admin manages blocklist, In the App access control card, block any existing web app that is not on the security team’s vetted list.
B. Change the Chrome Web Store allow/block mode setting to block all apps, admin manages allowlist. Add the apps on the security team’s vetted list to the allowlist.
C. Disable Extensions and Chrome packaged apps as Allowed types of apps and extensions for the top-level organizational unit. Selectively enable the appropriate extension types for each suborganization
D. Disable the Chrome Web Store service for the top-level organizational unit. Enable the Chrome Web Store service for organizations that require Chrome apps and extensions.
Show Answer
Correct Answer: B
Explanation:
The requirement is to immediately disable any unapproved apps already installed and prevent future installation of unapproved apps. The most effective and policy-aligned approach is to switch to a block-all, admin-managed allowlist model and explicitly allow only the vetted apps. This automatically removes or disables non-approved apps and prevents new ones unless added to the allowlist. Other options either rely on reactive blocking, are overly broad, or disrupt Chrome Web Store access unnecessarily.

$19

Get all 55 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.