Associate Google Workspace Administrator Free Practice Questions — Page 3
Question 22
Your organization has experienced a recent increase in unauthorized access attempts to your company’s Google Workspace instance. You need to enhance the security of user accounts while following Google-recommended practices. What should you do?
A. Disable password recovery options to prevent unauthorized individuals from accessing user accounts.
B. Implement a strong password policy and enable text messages as the 2-Step Verification (2SV) using text messages.
C. Enforce the use of physical security keys as the 2-Step Verification (2SV) method for all users.
D. Enforce a strong password policy that requires users to include special characters, numbers, and uppercase letters.
Show Answer
Correct Answer: C
Explanation: Google recommends phishing-resistant multi-factor authentication where possible. Physical security keys provide the strongest protection against phishing and account takeover attempts. SMS-based 2-Step Verification is less secure due to SIM swapping and phishing risks. Strong password composition rules alone are less effective than modern MFA, and disabling password recovery is not a recommended primary security measure.
Question 23
You are onboarding a new employee who will use a company-provided Android device. Your company requires the ability to enforce strong security policies on mobile devices, including password complexity requirements and remote device wipe capabilities. You need to choose the appropriate Google Workspace mobile device management solution. What should you do?
A. Use a third-party mobile device management (MDM) solution to manage the device.
B. Allow the employee to use their personal device without enrolling it in any mobile device management (MDM) solution.
C. Implement Google’s basic management solution for the mobile device.
D. Implement Google’s advanced management solution for the mobile device.
Show Answer
Correct Answer: D
Explanation: Advanced mobile device management in Google Workspace supports enforcing stronger security policies such as password complexity requirements and enhanced administrative controls including remote wipe for company-managed Android devices. Basic management provides more limited controls, while no MDM or relying solely on a third-party solution does not match the requested built-in Google Workspace management choice.
Question 24
Your company wants to start using Google Workspace for email. Your domain is verified through a third-party provider. You need to route the email to Google Workspace. What should you do?
A. Change your domain’s A record to point to Google’s mail servers.
B. Configure a forwarding rule in your current email system to redirect all messages to Gmail.
C. Update your domain’s MX records to the Google Workspace MX records provided in the setup instructions.
D. Create a CNAME record that maps your domain to “gmail.com.”
Show Answer
Correct Answer: C
Explanation: To route email for a verified domain to Google Workspace, you must update the domain's MX (Mail Exchange) records to the Google Workspace MX records provided during setup. MX records determine where inbound email is delivered. A records map hostnames to IP addresses, CNAME records alias hostnames, and forwarding rules in an existing mail system are not the correct way to establish Google Workspace as the primary mail receiver.
Question 25
You are configuring Google Chat for your organization. Using the Adin console, you want to enable employees to view their chat history by default and allow employees to turn off chat history. What should you do?
A. Configure Google Vault to retain all Chat messages, and exclude organizational units (OUs) with users who want to turn Chat history off.
B. Set the space history setting to OFF and chat history to ON.
C. Set the top-level default conversation history setting to ON and allow users to change their history setting.
D. Set the top-level default conversation history settings to OFF and allow users in each organizational unit (OU) to change their history setting.
Show Answer
Correct Answer: C
Explanation: To have chat history enabled by default while still allowing employees to disable it, configure the top-level default conversation history setting to ON and enable users to change their own history setting. This matches the requirement of a default-on policy with user choice. The other options either rely on Vault retention (which is separate from the user history setting), configure space history incorrectly, or default history to OFF.
Question 26
You’ve noticed an increase in phishing emails that contain links to malicious files hosted on external Google Drives. These files often mimic legitimate documents and trick users into granting access to their accounts. You need to prevent users from accessing these malicious external Drive files, but allow them to access legitimate external files. What should you do? (Choose two.)
A. Enforce stricter password policies.
B. Conduct regular security awareness training to educate users.
C. Create a Drive trust rule that blocks all external domains except for a pre-approved list of trusted partners.
D. Deploy advanced malware detection software on all user devices to scan and block malicious files.
E. Implement two-factor authentication for all users.
Show Answer
Correct Answer: B, C
Explanation: A Drive trust rule that restricts access to external Drive content to an approved allowlist directly addresses the risk while still permitting legitimate external sharing. Regular security awareness training helps users recognize phishing attempts and malicious sharing requests. Password policies and 2FA improve account security but do not prevent access to malicious external Drive files, and endpoint malware scanning is not the targeted Google Drive control described.
Question 27
Per regulatory requirements, your company is required to keep the data of employees located in Germany within Europe and the data of employees located in the US within the US. The employees in Germany are in a separate organizational unit (OU) than employees in the US. You need to ensure that where employee data is stored is in compliance with the location regulations.
What should you do?
A. Instruct employees to use Drive for desktop to keep documents on their corporate computers.
B. Create two Groups. Assign employees into the Germany or US Group based on their location. Use Google Drive trust rules to prevent sharing between the Groups.
C. Navigate to the Data Regions function in the Admin console. Select the Europe region for employees in Germany, and select the US region for US employees.
D. Navigate to the Data Regions function in the Admin console. Select “No preference.”
Show Answer
Correct Answer: C
Explanation: Use Google Workspace Data Regions to assign storage locations by organizational unit. Since employees in Germany and the US are already separated into different OUs, configure the Germany OU to use the Europe data region and the US OU to use the US data region. Trust rules control sharing, not data residency; Drive for desktop does not determine backend storage location; 'No preference' does not enforce regional storage.
Question 28
An end user has thousands of files stored in Google Drive. Their files are well organized with Drive labels. You need to advise the end user on how to quickly identify all files that are contracts. What should you do?
A. Advise the user to use the Google Drive API to search for files with the keyword “contracts”
B. Advise the user to search in Drive for files with the keyword “contracts”, and use the “modified by me” filter.
C. Advise the user to search for files that are labeled as “contracts”.
D. Advise the user to use the Investigation tool to search for files with the keyword “contracts” and updated by you.
Show Answer
Correct Answer: C
Explanation: Because the files are already well organized with Google Drive labels, the fastest and most accurate method is to search using the label assigned to contract files. Keyword searches may miss files or return irrelevant results, the 'modified by me' filter is unrelated, the Drive API is unnecessary for an end user, and the Investigation tool is an admin security feature rather than an end-user search tool.
Question 29
Your organization’s users are reporting that a large volume of legitimate emails are being misidentified as spam in Gmail. You want to troubleshoot this problem while following Google-recommended practices. What should you do?
A. Adjust the organization’s mail content compliance settings in the Admin console.
B. Advise users to individually allowlist senders.
C. Disable spam filtering for all users.
D. Contact Google Workspace support and report a suspected system-wide spam filter malfunction.
Show Answer
Correct Answer: A
Explanation: The recommended first step is to review and adjust the organization's mail handling and content compliance configuration in the Admin console, as overly restrictive policies can cause legitimate mail to be treated as spam. Individually allowlisting senders does not address an organization-wide issue, disabling spam filtering is not recommended, and contacting support is appropriate only after verifying configuration and ruling out administrative causes.
Question 30
Your company handles sensitive client data and needs to maintain a high level of security to comply with strict industry regulations. You need to allow your company’s security team to investigate potential security breaches by using the security investigation tool in the Google Admin console.
What should you do?
A. Create an activity rule that triggers email notifications to the security team whenever a high-risk security event occurs.
B. Assign the User Management Admin role to the security team.
C. Assign the super admin role to the security team
D. Create an administrator role with Security Center access. Assign the role to the security team.
Show Answer
Correct Answer: D
Explanation: The security investigation tool is part of the Google Admin console's Security Center. Following the principle of least privilege, the appropriate approach is to create or use an administrator role that includes Security Center access and assign it to the security team. User Management Admin does not grant Security Center investigation capabilities, and Super Admin is unnecessarily broad. Activity rules with email notifications do not provide access to the investigation tool.
Question 31
Your organization’s security team has published a list of vetted third-party apps and extensions that can be used by employees. All other apps are prohibited unless a business case is presented and approved. The Chrome Web Store policy applied at the top-level organization allows all apps and extensions with an admin blocklist. You need to disable any unapproved apps that have already been installed and prevent employees from installing unapproved apps. What should you do?
A. Change the Chrome Web Store allow/block mode setting to allow all apps, admin manages blocklist, In the App access control card, block any existing web app that is not on the security team’s vetted list.
B. Change the Chrome Web Store allow/block mode setting to block all apps, admin manages allowlist. Add the apps on the security team’s vetted list to the allowlist.
C. Disable Extensions and Chrome packaged apps as Allowed types of apps and extensions for the top-level organizational unit. Selectively enable the appropriate extension types for each suborganization
D. Disable the Chrome Web Store service for the top-level organizational unit. Enable the Chrome Web Store service for organizations that require Chrome apps and extensions.
Show Answer
Correct Answer: B
Explanation: To enforce that only security-approved apps and extensions can be used, configure Chrome Web Store access to 'block all apps, admin manages allowlist' and add only the vetted apps/extensions to the allowlist. This both prevents installation of unapproved apps and disables previously installed unapproved apps because anything not on the allowlist is blocked. The other options either rely on blocklisting every unwanted app, change app types rather than approval policy, or disable the Web Store too broadly.
$19
Get all 55 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.