ExamGecko
Home Home / Google / Professional Google Workspace Administrator

Google Professional Google Workspace Administrator Practice Test - Questions Answers, Page 18

Question list
Search
Search

List of questions

Search

Related questions











Your organization is migrating to Google Workspace and wants to improve how newly created files are classified You must find a scalable solution to improve security and transparency on how to handle sensitive files What should you do?

A.
Set data loss prevention (DLP) policies to label data automatically disable label locking, and educate users
A.
Set data loss prevention (DLP) policies to label data automatically disable label locking, and educate users
Answers
B.
Create classification labels enable automatic classification, and educate users
B.
Create classification labels enable automatic classification, and educate users
Answers
C.
Migrate data to Google Workspace map classifications and migrate with the Drive Labels API
C.
Migrate data to Google Workspace map classifications and migrate with the Drive Labels API
Answers
D.
Integrate with the Cloud DLP API map identifiers and classifications install the Google Drive label client and run the application
D.
Integrate with the Cloud DLP API map identifiers and classifications install the Google Drive label client and run the application
Answers
Suggested answer: B

Explanation:

Step by Step Comprehensive Detailed Explanation:

Access Admin Console: Log in to the Google Admin console using your administrator account.

Navigate to Labels: Go to Apps > Google Workspace > Drive and Docs > Labels.

Create Classification Labels: Define and create classification labels that correspond to different levels of sensitivity and types of files.

Enable Automatic Classification: Configure settings to enable automatic classification of newly created files based on predefined criteria and patterns.

Educate Users: Conduct training sessions or distribute documentation to educate users on how to use classification labels effectively and understand their importance in maintaining data security.

Google Workspace Admin Help: Drive labels

Google Workspace DLP and Classification

As a Workspace Administrator you want to keep an inventory of the computers and mobile devices your company owns in order to track details such as device type and who the device is assigned to. How should you add the devices to the company-owned inventory?

A.
Download the company-owned inventory template CSV file from the Admin panel enter the serial number of the devices and upload the
A.
Download the company-owned inventory template CSV file from the Admin panel enter the serial number of the devices and upload the
Answers
B.
completed file to the company-owned inventory in the admin panel B O Download the company-owned inventory template CSV file from the Admin panel enter the device OSs. and serial numbers and upload the
B.
completed file to the company-owned inventory in the admin panel B O Download the company-owned inventory template CSV file from the Admin panel enter the device OSs. and serial numbers and upload the
Answers
C.
completed file to the company-owned inventory in the admin panel. C O Download the company-owned inventory template CSV file from the Admin panel enter the asset tags of the devices, and upload the
C.
completed file to the company-owned inventory in the admin panel. C O Download the company-owned inventory template CSV file from the Admin panel enter the asset tags of the devices, and upload the
Answers
D.
completed file to the company-owned inventory in the admin panel D O Download the company-owned inventory template CSV file from the Admin panel, enter the device OSs. and asset tags, and upload the
D.
completed file to the company-owned inventory in the admin panel D O Download the company-owned inventory template CSV file from the Admin panel, enter the device OSs. and asset tags, and upload the
Answers
Suggested answer: A

Explanation:

Access Admin Console: Log in to the Google Admin console using your administrator account.

Navigate to Devices: Go to Devices > Mobile and endpoints.

Download Inventory Template: Click on Manage company-owned inventory > Download template CSV.

Enter Device Details: Fill in the template with the serial numbers and other relevant information of the devices.

Upload Completed File: Once the CSV file is completed with all device details, upload it back to the Admin console under Manage company-owned inventory.

Verify and Save: Ensure that the uploaded data is correct and save the inventory. This keeps a record of all company-owned devices.

Google Workspace Admin Help: Manage company-owned devices

Google Workspace Device Inventory Management

The Google Analytics service is set to OFF for your entire organization All users in the marketing team OU and a subset of users in the sales OU need access to Analytics The rest of the organization should not have access You must configure access in Additional Google services What should you do?

A.
Enable Google Analytics at the top of the OU structure
A.
Enable Google Analytics at the top of the OU structure
Answers
B.
Enable Google Analytics for the marketing and sales OUs Create a group to deny access to Google Analytics and assign it to the sales users who should not have access
B.
Enable Google Analytics for the marketing and sales OUs Create a group to deny access to Google Analytics and assign it to the sales users who should not have access
Answers
C.
Enable Google Analytics for the marketing OU. Create a sub-OU for the sales users under the marketing OU
C.
Enable Google Analytics for the marketing OU. Create a sub-OU for the sales users under the marketing OU
Answers
D.
Enable Google Analytics for the marketing OU Create a group from the Admin console that includes the sales users, and set GoogleAnalytics to On for that group
D.
Enable Google Analytics for the marketing OU Create a group from the Admin console that includes the sales users, and set GoogleAnalytics to On for that group
Answers
Suggested answer: D

Explanation:

Access Admin Console: Log in to the Google Admin console using your administrator account.

Navigate to Additional Google Services: Go to Apps > Additional Google services > Google Analytics.

Enable for Marketing OU: Select the marketing OU and turn on Google Analytics.

Create Group for Sales Users: Go to Directory > Groups and create a new group for the sales users who need access to Google Analytics.

Assign Google Analytics Access: In the Google Analytics settings, turn on access for the newly created sales group.

Verify Settings: Ensure that only users in the marketing OU and the specific sales group have access to Google Analytics while the rest of the organization does not.

Google Workspace Admin Help: Turn Additional Google services On or Off

Google Workspace Service Access Management

Your organization has a strict requirement that your temporary employees can only send emails to and receive emails from specific external domains You must define a policy in Google Workspace that meets this requirement for users in the temporary employee organizational unit (OU) What should you do?

A.
Create a policy in Gmail settings that rewrites the recipient for outbound messages and quarantines incoming messages to review before delivery
A.
Create a policy in Gmail settings that rewrites the recipient for outbound messages and quarantines incoming messages to review before delivery
Answers
B.
Add the allowed domains when configuring the restrict delivery setting in Gmail settings, and select the box to bypass for internal emails
B.
Add the allowed domains when configuring the restrict delivery setting in Gmail settings, and select the box to bypass for internal emails
Answers
C.
Restrict sending and receiving to Google Groups, and carefully curate the temporary employees' memberships
C.
Restrict sending and receiving to Google Groups, and carefully curate the temporary employees' memberships
Answers
D.
Configure the restrict delivery setting to limit domains that the temporary employees can communicate with Allow Google Docs sharing
D.
Configure the restrict delivery setting to limit domains that the temporary employees can communicate with Allow Google Docs sharing
Answers
Suggested answer: B

Explanation:

Access the Admin Console: Sign in to your Google Admin console.

Navigate to Apps: Click on 'Apps' and then 'Google Workspace.'

Select Gmail: In the Google Workspace section, click on 'Gmail.'

Gmail Settings: Click on 'Compliance' under the 'Advanced settings' section.

Restrict Delivery Setting: Scroll down to the 'Restrict delivery' section and click 'Configure.'

Define Policy: Enter the specific external domains you want to allow the temporary employees to communicate with.

Bypass for Internal Emails: Make sure to select the option to bypass the restriction for internal emails, ensuring internal communication is not affected.

Apply to OU: Apply this setting to the organizational unit (OU) containing the temporary employees.

Save the Configuration: Save the changes and ensure the policy is active.

Google Workspace Admin Help: Set up compliance rules for Gmail

Your default Vault retention policy for Gmail is set to 365 days Your legal department has just informed you that emails sent and received by the customer support department are sensitive and must be retained for only 30 days You must enforce this new retention policy in the simplest way What should you do?

A.
Change the current default retention policy in Vault for Gmail to 30 days and apply it to the customer support organizational unit (OU) Configure a custom retention policy for Gmail for 365 days for your domain
A.
Change the current default retention policy in Vault for Gmail to 30 days and apply it to the customer support organizational unit (OU) Configure a custom retention policy for Gmail for 365 days for your domain
Answers
B.
Create two custom retention policies in Vault one for 30 days that is applied to the customer support organizational unit (OU) and one for 365 days that is applied to all other OUs in your directory
B.
Create two custom retention policies in Vault one for 30 days that is applied to the customer support organizational unit (OU) and one for 365 days that is applied to all other OUs in your directory
Answers
C.
Change the current default retention policy for Gmail to 30 days Configure two custom retention policies in Vault one for 30 days that is applied to the customer support organizational unit (OU) and one for 365 days that is applied to all other OUs in your directory
C.
Change the current default retention policy for Gmail to 30 days Configure two custom retention policies in Vault one for 30 days that is applied to the customer support organizational unit (OU) and one for 365 days that is applied to all other OUs in your directory
Answers
D.
Create a custom retention policy in Vault for Gmail for 30 days and apply it to the customer support organizational unit (OU)
D.
Create a custom retention policy in Vault for Gmail for 30 days and apply it to the customer support organizational unit (OU)
Answers
Suggested answer: D

Explanation:

Step by Step Comprehensive Detailed Explanation:

Access Google Vault: Sign in to Google Vault.

Retention Policies: Navigate to 'Retention' from the side menu.

Create New Retention Rule: Click on 'Create retention rule.'

Set Duration: Set the retention period to 30 days.

Apply to OU: Apply this retention rule specifically to the organizational unit (OU) for the customer support department.

Exclude Default Rule: Ensure that this custom rule overrides the default 365-day retention policy for the customer support OU.

Save and Activate: Save the rule and ensure it is activated.

Google Vault Help: Set retention rules

Your organization has confidential internal content for which only authorized employees are allowed to access Access to this content is managed by using Google Groups Only administrators can create and manage membership You need to provide only the necessary functionality and follow the principle of least privilege What should you do?

A.
Make a dynamic group so security team members are automatically added
A.
Make a dynamic group so security team members are automatically added
Answers
B.
Make a moderated group so all incoming communications can be monitored
B.
Make a moderated group so all incoming communications can be monitored
Answers
C.
Use a group as a collaborative inbox that allows easier sharing
C.
Use a group as a collaborative inbox that allows easier sharing
Answers
D.
Make a security group to apply access policies
D.
Make a security group to apply access policies
Answers
Suggested answer: D

Explanation:

Navigate to Groups: Go to the Google Admin console and navigate to 'Groups'.

Create a Security Group: Create a new group and set it as a security group.

Assign Permissions: Set the appropriate permissions and policies that restrict access to only authorized employees.

Manage Membership: Ensure that only administrators can manage the group membership, adhering to the principle of least privilege.

Apply Policies: Apply access policies to the security group, ensuring that the confidential content is accessible only to authorized members.

Create and manage security groups

Google Groups for Business

An employee has left your organization and their Drive data must be retained for three years The retention rule has been set for three years You must ensure the employee's data is visible in Vault and accessible to the Vault Administrator in the most cost-effective way What should you do?

A.
Export the users Drive data from Vault, then delete the user.
A.
Export the users Drive data from Vault, then delete the user.
Answers
B.
Assign an Archive User (AU) license to the user
B.
Assign an Archive User (AU) license to the user
Answers
C.
Change ownership of the Drive data to the user's Manager, then delete the user
C.
Change ownership of the Drive data to the user's Manager, then delete the user
Answers
D.
Suspend the user until the end of the three-year period
D.
Suspend the user until the end of the three-year period
Answers
Suggested answer: B

Explanation:

Step by Step Comprehensive Detailed Explanation

Navigate to Users: Go to the Google Admin console and navigate to the 'Users' section.

Select the User: Find and select the user who has left the organization.

Assign Archive User License: Assign an Archive User (AU) license to the user, ensuring their data is retained and accessible in Vault.

Verify Access in Vault: Go to Google Vault and verify that the data is visible and accessible to the Vault Administrator.

Cost-effective Data Retention: Using an AU license is cost-effective as it retains the data without needing an active Google Workspace license.

Assign licenses to users

Google Vault Archive User

Recently your organization has had an increase in messages marked as spam You need to quickly and efficiently obtain detailed information regarding each message What should you do?

A.
Create an investigation by using a SQL query to search for all spam audit logs exported to BigQuery
A.
Create an investigation by using a SQL query to search for all spam audit logs exported to BigQuery
Answers
B.
Send an alert to all users to mark all suspicious Gmail messages as spam and review the Alert center messages
B.
Send an alert to all users to mark all suspicious Gmail messages as spam and review the Alert center messages
Answers
C.
Use Google Vault to put all messages marked as spam in a legal hold and review the messages
C.
Use Google Vault to put all messages marked as spam in a legal hold and review the messages
Answers
D.
Use the spam filter report in the security dashboard to see messages Google's spam filter marked as spam during a specific time period
D.
Use the spam filter report in the security dashboard to see messages Google's spam filter marked as spam during a specific time period
Answers
Suggested answer: D

Explanation:

Access Security Dashboard: Go to the Google Admin console and navigate to the 'Security' section.

Open Spam Filter Report: In the security dashboard, open the spam filter report.

Filter by Time Period: Select the specific time period you want to analyze.

Review Spam Messages: Review the detailed information regarding each message marked as spam by Google's spam filter.

Take Necessary Actions: Use the information from the report to adjust spam filters, user alerts, or take other necessary actions to manage spam more effectively.

Security Dashboard

Email Log Search

You work for a midsize organization Your compliance and audit learn sees that users are frequently resetting their passwords You must provide accurate information and ensure that the compliance team is informed every time a user changes their password What should you do?

A.
Create a new alert by using user log events and check that event Login type is Google password and include the compliance team in the email notifications
A.
Create a new alert by using user log events and check that event Login type is Google password and include the compliance team in the email notifications
Answers
B.
Check the User's password changed alert in the alert center and include the compliance team in the email notifications
B.
Check the User's password changed alert in the alert center and include the compliance team in the email notifications
Answers
C.
Disable user account recovery so users must contact you before a reset
C.
Disable user account recovery so users must contact you before a reset
Answers
D.
Enable user account recovery and forward any alert to the compliance team through the alert center
D.
Enable user account recovery and forward any alert to the compliance team through the alert center
Answers
Suggested answer: B

Explanation:

Step by Step Comprehensive Detailed Explanation:

Access the Admin Console: Sign in to your Google Admin console.

Navigate to the Alert Center: Click on 'Security' and then 'Alert Center.'

Create New Alert: In the Alert Center, click on 'Manage alerts' and then 'Add alert rule.'

Configure Alert Rule: Select 'User's password changed' as the event type.

Include Compliance Team: In the alert configuration, add the compliance team's email addresses to the notification recipients.

Save the Alert: Save the configuration to ensure the compliance team is informed every time a user changes their password.

Google Workspace Admin Help: Alert Center

Your global marketing team has over 500 employees. They recently started working with Google Analytics and want to move to managed accounts You decide to use Google Cloud Directory Sync (GCDS) to sync users from your current identity provider Your organization currently has no Google Workspace licenses linked to the Admin console You run GCDS for the first lime and receive the following error. 'Domain user limit reached ' You need to identify and fix the problem What should you do?

A.
Ensure that there is a subscription available and enough licenses to sync the new users
A.
Ensure that there is a subscription available and enough licenses to sync the new users
Answers
B.
Check if GCDS has the correct permissions to run a sync on your domain
B.
Check if GCDS has the correct permissions to run a sync on your domain
Answers
C.
Wait 48 hours until the domain is fully provisioned
C.
Wait 48 hours until the domain is fully provisioned
Answers
D.
Update the delete limits of GCDS and try again
D.
Update the delete limits of GCDS and try again
Answers
Suggested answer: A

Explanation:

Verify License Availability: Check the number of available licenses in your Google Workspace subscription.

Purchase Additional Licenses: If necessary, purchase additional licenses to cover the number of users you plan to sync.

Configure GCDS: Ensure that Google Cloud Directory Sync (GCDS) is properly configured to sync users from your identity provider.

Run GCDS: Run the GCDS sync again to sync the new users now that sufficient licenses are available.

Google Cloud Directory Sync Admin Help

Total 197 questions
Go to page: of 20