ExamGecko
Home Home / Google / ChromeOS Administrator

Google ChromeOS Administrator Practice Test - Questions Answers, Page 5

Question list
Search
Search

List of questions

Search

Related questions











Your security team asks you to deploy on ChromeOS only a specific Android app for your security department. As a ChromeOS Administrator, you need to find a way to block all other Android apps except the one that you need. How are you going to proceed?

A.
From the 'Apps & extensions' page add the Android app on the security team user OU
A.
From the 'Apps & extensions' page add the Android app on the security team user OU
Answers
B.
On the 'Users & Browser Settings'' tab. for the Play Store, use the 'Block all apps, admin manages allowlist' policy and allow only the
B.
On the 'Users & Browser Settings'' tab. for the Play Store, use the 'Block all apps, admin manages allowlist' policy and allow only the
Answers
C.
Android app that you want from 'Apps & extensions ' On the 'Users & Browser Settings'' tab. for the Chrome Web Store use the 'Block all apps, admin manages allowlist' policy and allow only the Android app that you want on 'Apps & extensions '
C.
Android app that you want from 'Apps & extensions ' On the 'Users & Browser Settings'' tab. for the Chrome Web Store use the 'Block all apps, admin manages allowlist' policy and allow only the Android app that you want on 'Apps & extensions '
Answers
D.
From trio 'Apps & extensions' page add the Android app on the security team user OU and select 'Force Install * pin to ChromeOS taskbar'
D.
From trio 'Apps & extensions' page add the Android app on the security team user OU and select 'Force Install * pin to ChromeOS taskbar'
Answers
Suggested answer: B

Explanation:

Access Google Admin Console:Sign in to your Google Admin console.

Navigate to Device Management:Go to Devices > Chrome > Settings > Users & browsers.

Locate Play Store Settings:Find the section related to the Play Store.

Enable Allowlist Policy:Activate the policy 'Block all apps,admin manages allowlist.'

Add the Security App:Go to the 'Apps & extensions' section and add the specific Android app that you want to allow for the security team's organizational unit (OU).

This configuration ensures that all other Android apps are blocked from installation on ChromeOS devices, except the specified security app. This provides granular control over app deployment and enhances security by preventing unauthorized app usage.

What is a best practice for admin accounts on the Google Admin console?

A.
Super Admins should be used for all changes to the domain
A.
Super Admins should be used for all changes to the domain
Answers
B.
Group Admins should have 2FA enabled only if given security policy controls
B.
Group Admins should have 2FA enabled only if given security policy controls
Answers
C.
Super Admins should use a separate user account tor day-to-day activities
C.
Super Admins should use a separate user account tor day-to-day activities
Answers
D.
Group Admins should have access to multiple groups
D.
Group Admins should have access to multiple groups
Answers
Suggested answer: C

Explanation:

The principle of least privilege dictates that users should only have the minimum access necessary to perform their job functions. This applies to super admins as well. Using a separate user account for daily activities reduces the risk of accidental misconfiguration or unauthorized changes due to the elevated privileges associated with the super admin role.

Security:By using a separate account,super admins limit the potential attack surface in case their regular account is compromised.

Accountability:It's easier to track actions and changes when different accounts are used for different purposes.

Recovery:If the super admin account is locked or disabled,having a separate account allows for easier recovery.

You need to create a recovery image on a USB stick. Which two steps should you take?

Choose 2 answers

A.
Go to Device Settings
A.
Go to Device Settings
Answers
B.
Go lo google com/chromebooks
B.
Go lo google com/chromebooks
Answers
C.
Go to Google Play store
C.
Go to Google Play store
Answers
D.
Go to Chrome Web Store on a Chrome device
D.
Go to Chrome Web Store on a Chrome device
Answers
E.
Install Chrome Recovery Utility and download the image for the coned device model to a USB stick
E.
Install Chrome Recovery Utility and download the image for the coned device model to a USB stick
Answers
Suggested answer: D, E

Explanation:

To create a recovery image on a USB stick, you need to:

Access Chrome Web Store:Open the Chrome Web Store on a Chrome device (either a Chromebook or a computer with the Chrome browser installed).

Install Chromebook Recovery Utility:Search for and install the 'Chromebook Recovery Utility' extension.

Launch the Utility:Open the installed extension.

Identify Device:Enter the model number of the ChromeOS device for which you want to create the recovery image.

Insert USB Stick:Insert a USB stick with sufficient storage capacity (at least 4GB).

Download and Create:Follow the on-screen instructions in the utility to download the correct recovery image and create the bootable USB stick.

This process will prepare a USB stick that can be used to recover or reinstall ChromeOS on a device that is not functioning properly.

Recover your Chromebook:https://support.google.com/chromebook/answer/1080595?hl=en

An admin is setting up third-party SSO for their organization as the super admin. When they test with their account, they do not see the SSO screen.

What is causing this behavior?

A.
SSO settings are misconfigured
A.
SSO settings are misconfigured
Answers
B.
The account is in the wrong OrgUnit
B.
The account is in the wrong OrgUnit
Answers
C.
Third-party SSO is not enabled
C.
Third-party SSO is not enabled
Answers
D.
Super admin bypassed the thud-patty
D.
Super admin bypassed the thud-patty
Answers
Suggested answer: D

Explanation:

Super administrators in Google Workspace have special privileges that allow them to bypass certain security features, including third-party SSO. This is to ensure that they can always access the Admin console for troubleshooting or critical changes, even if the SSO system is malfunctioning. Therefore, when a super admin tests third-party SSO, they won't be prompted with the SSO login screen, but will directly access the console using their Google credentials.

What is needed for an admin to remote desktop to a user or managed guest session devices with the Admin console?

A.
The user must accept the connection request
A.
The user must accept the connection request
Answers
B.
The user must share the session pin with the admin
B.
The user must share the session pin with the admin
Answers
C.
Both the admin and the remote device must be on the same network
C.
Both the admin and the remote device must be on the same network
Answers
D.
The admin must be in the same OU as the remote device
D.
The admin must be in the same OU as the remote device
Answers
Suggested answer: A

Explanation:

To initiate a remote desktop session to a ChromeOS device using the Admin console, the administrator needs the user's consent. The remote desktop feature works by sending a connection request to the user's device, which they must explicitly accept before the session can start. This ensures user privacy and prevents unauthorized access.

A user reports that their Chrome device has been stolen. What should the administrator do?

A.
Use the Google Admin console to turn on the stolen Chromebook's webcam
A.
Use the Google Admin console to turn on the stolen Chromebook's webcam
Answers
B.
Use the Google Android Device Manager to locate the Chromebook
B.
Use the Google Android Device Manager to locate the Chromebook
Answers
C.
Set the stolen Chromebook lo disabled mode to prevent user sign-ins
C.
Set the stolen Chromebook lo disabled mode to prevent user sign-ins
Answers
D.
Remotely wipe user data from the Chromebook
D.
Remotely wipe user data from the Chromebook
Answers
Suggested answer: C

Explanation:

When a Chrome device is reported stolen, the administrator should immediately take action to protect the data and prevent unauthorized access. The most effective step is to disable the device through the Google Admin console. This will prevent anyone from signing in to the device, rendering it unusable.

Here's how to disable a stolen Chrome device:

Sign in to Google Admin console:Use your administrator credentials.

Navigate to Devices:Go to Devices > Chrome > Devices.

Locate the Device:Find the stolen device using its serial number or other identifying information.

Disable the Device:Click on the device and select 'Disable.'

This will disable the device and prevent anyone from signing in, even if they try to reset the device.

Your hardware OEM issues a recall for a safety issue. You need to deprovision devices from management before returning to the OEM. They will replace your existing ChromeOS devices with a different model. Which option should you choose when deprovisioning to make sure you can reuse your Chrome Education/Enterprise Upgrade and remain compliant?

A.
Retiring from fleet
A.
Retiring from fleet
Answers
B.
Different model replacement
B.
Different model replacement
Answers
C.
ChromeOS Flex upgrade transfer
C.
ChromeOS Flex upgrade transfer
Answers
D.
Same model replacement
D.
Same model replacement
Answers
Suggested answer: B

Explanation:

When deprovisioning ChromeOS devices for a hardware recall and replacement with different models, choosing the 'Different model replacement' option is crucial to retain the Chrome Education/Enterprise Upgrade license compliance. This option ensures that the license is transferred to the new device correctly, avoiding any compliance issues or the need to repurchase licenses.

Here's why this option is important:

License Transfer:It specifically designates the deprovisioning as being due to a hardware replacement with a different model.This triggers the system to transfer the license to the new device upon enrollment.

Compliance:It maintains the compliance of your Chrome Education/Enterprise Upgrade licenses,ensuring you don't violate any licensing terms.

Cost Savings:It avoids the need to purchase new licenses for the replacement devices,saving your organization money.

A customer has a mission-critical workload running on ChromeOS and needs devices configured to reduce ChromeOS changes. How can an admin reduce the risk of an unexpected change in an OS update affecting the customer's entire ChromeOS device domain while maintaining security and minimizing admin workload?

A.
Force auto reboot after update
A.
Force auto reboot after update
Answers
B.
Enable variations
B.
Enable variations
Answers
C.
Move to a Long-term Support channel
C.
Move to a Long-term Support channel
Answers
D.
Add an update rollout plan
D.
Add an update rollout plan
Answers
Suggested answer: D

Explanation:

Update rollout plans in the Google Admin console allow administrators to gradually roll out ChromeOS updates to a subset of devices first. This allows for testing in a controlled environment before deploying to the entire fleet, reducing the risk of unexpected issues impacting all devices.

Steps to add an update rollout plan:

Access Google Admin Console:Sign in with your administrator credentials.

Navigate to Device Management:Go to Devices > Chrome > Settings > Updates.

Create Rollout Plan:Click on 'Add an update rollout plan.'

Select Devices:Choose the specific devices or organizational units (OUs) to include in the initial rollout.

Set Timeline:Define the start and end dates for the rollout.

Save and Apply:Save the plan and apply it to the selected devices.

How should you use Chrome Remote Desktop from the Google Admin console to connect a user?

A.
Find the user account and click remote desktop
A.
Find the user account and click remote desktop
Answers
B.
Open Chrome Remote Desktop and type the device serial number
B.
Open Chrome Remote Desktop and type the device serial number
Answers
C.
Open Chrome Remote Desktop and type the user's user name
C.
Open Chrome Remote Desktop and type the user's user name
Answers
D.
Find the device and click remote desktop
D.
Find the device and click remote desktop
Answers
Suggested answer: D

Explanation:

To initiate a remote desktop session to a ChromeOS device using the Google Admin console, follow these steps:

Sign in to Google Admin console:Use your administrator credentials.

Navigate to Devices:Go to Devices > Chrome > Devices.

Locate the Device:Find the device you want to connect to using its serial number or other identifying information.

Start Remote Desktop Session:Click on the device and select 'Remote desktop.' This will send a connection request to the user,who must accept it before the session can start.

You are tasked with converting hundreds of Windows & Mac machines across multiple locations to ChromeOS Flex and enrolling them into the Admin console. The available network bandwidth Is limited at many of the locations and the devices are not currently managed with any endpoint management system. Which two operations are required to perform the task?

Choose 2 answers

A.
Create a dedicated enrollment account tor each location and place them into the OUs you want the devices enrolled into then enable the 'Place ChromeOS device in user organization' policy and enroll the devices using the respective enrollment account for each location
A.
Create a dedicated enrollment account tor each location and place them into the OUs you want the devices enrolled into then enable the 'Place ChromeOS device in user organization' policy and enroll the devices using the respective enrollment account for each location
Answers
B.
Install the Recovery Tool extension on all devices that are to be converted and follow the step-by-step installer to convert each device directly without the need of USB drives
B.
Install the Recovery Tool extension on all devices that are to be converted and follow the step-by-step installer to convert each device directly without the need of USB drives
Answers
C.
Use PXE boot to load the ChromeOS Flex image onto devices and have them automatically convert across all locations after they're restarted
C.
Use PXE boot to load the ChromeOS Flex image onto devices and have them automatically convert across all locations after they're restarted
Answers
D.
Contact an authorized Zero-Touch Enrollment (ZTE) reseller and share the serial numbers of the devices you're converting and the domain you're enrolling them into to have them pre-provisioned into the Admin console
D.
Contact an authorized Zero-Touch Enrollment (ZTE) reseller and share the serial numbers of the devices you're converting and the domain you're enrolling them into to have them pre-provisioned into the Admin console
Answers
E.
Distribute USB flash drives with the ChromeOS Flex image to the different locations and ask local personnel or a services partner to manually convert each device
E.
Distribute USB flash drives with the ChromeOS Flex image to the different locations and ask local personnel or a services partner to manually convert each device
Answers
Suggested answer: A, E

Explanation:

Create Dedicated Enrollment Accounts:Create separate enrollment accounts for each location,placing them in the respective OUs where the converted devices should be enrolled.

Enable Policy:Turn on the 'Place ChromeOS device in user organization' policy.This ensures devices are automatically enrolled into the correct OU based on the enrollment account used.

Enroll Devices:Use the dedicated enrollment account for each location to enroll the converted devices.This allows for organized management based on location.

Option E:

Distribute USB Drives:Prepare USB flash drives with the ChromeOS Flex image and distribute them to the different locations.

Manual Conversion:Instruct local personnel or a service partner to manually convert each device using the provided USB drives.This method is suitable when network bandwidth is limited and doesn't rely on existing endpoint management infrastructure.

Reasons for not choosing other options:

Option B:The Recovery Tool is primarily used for creating recovery media for ChromeOS devices,not converting other operating systems.

Option C:PXE boot is a network-based installation method,not ideal for locations with limited bandwidth.

Option D:While zero-touch enrollment (ZTE) streamlines enrollment,it requires pre-provisioning devices with the vendor or reseller,which might not be feasible in this scenario.

By combining options A and E, you can efficiently convert and enroll devices in multiple locations with limited network resources and no existing management systems.

Total 60 questions
Go to page: of 6