ExamGecko
Home Home / Google / Professional Google Workspace Administrator

Google Professional Google Workspace Administrator Practice Test - Questions Answers, Page 19

Question list
Search
Search

List of questions

Search

Related questions











Your organization has users in the United States and Europe For compliance reasons you want to ensure that user data is always stored in the region where the user is located What should you do?

A.
Create two Google Groups titled 'United States' and 'Europe ' Assign users to either group based on location
A.
Create two Google Groups titled 'United States' and 'Europe ' Assign users to either group based on location
Answers
B.
Specify a data region policy for each Organizational Unit (OU) where users are grouped by location
B.
Specify a data region policy for each Organizational Unit (OU) where users are grouped by location
Answers
C.
Populate the Address field on each user record ensuring the country information is accurate
C.
Populate the Address field on each user record ensuring the country information is accurate
Answers
D.
Do nothing No extra configuration is needed because user data is always stored in the region the user is located
D.
Do nothing No extra configuration is needed because user data is always stored in the region the user is located
Answers
Suggested answer: B

Explanation:

Step by Step Comprehensive Detailed Explanation:

Access the Admin Console: Sign in to your Google Admin console.

Navigate to Data Regions: Click on 'Account' and then 'Data Regions.'

Create Data Region Policy: Create a data region policy specifying where data should be stored.

Apply to OUs: Apply the data region policy to the organizational units (OUs) based on user location, ensuring data is stored in the respective regions.

Save Configuration: Save the settings to enforce the data region policies.

Google Workspace Admin Help: Data Regions

Several users in your organization reported an issue with receiving emails from one particular external sender You want to troubleshoot the issue and determine whether Google received these emails What should you do?

A.
Check if your Google Workspace domain registration expired
A.
Check if your Google Workspace domain registration expired
Answers
B.
Search for missing email messages by using email Log Search {ELS) and determine why messages weren't delivered
B.
Search for missing email messages by using email Log Search {ELS) and determine why messages weren't delivered
Answers
C.
Update your MX records to make sure they point to Google mail servers
C.
Update your MX records to make sure they point to Google mail servers
Answers
D.
Open a support ticket with Google Workspace Support
D.
Open a support ticket with Google Workspace Support
Answers
Suggested answer: B

Explanation:

Step by Step Comprehensive Detailed Explanation:

Access Email Log Search: Sign in to the Google Admin console and navigate to 'Reports' then 'Audit' and select 'Email Log Search.'

Perform a Search: Enter the details of the external sender and the date range to search for the missing emails.

Analyze Results: Review the search results to see if the emails were received, bounced, or filtered.

Determine Cause: Identify any issues such as delivery errors or spam filtering that might have affected the emails.

Google Workspace Admin Help: Email Log Search

You are configuring a customer relationship management (CRM) solution to integrate with Google Workspace services for the sales department at your organization The CRM solution is in the Google Workspace Marketplace and you deploy the specific CRM solution Employees report that there are no contacts and documents visible in the CRM solution You must identify and fix the problem What should you do?

A.
Check the OAuth scopes and ensure that Drive and Gmail scopes are granted for the CRM solution
A.
Check the OAuth scopes and ensure that Drive and Gmail scopes are granted for the CRM solution
Answers
B.
Check if Manage access to apps is set to Allow users to install and run any app from the Marketplace
B.
Check if Manage access to apps is set to Allow users to install and run any app from the Marketplace
Answers
C.
Revoke all OAuth scopes and reinstall the CRM solution for just the sales department.
C.
Revoke all OAuth scopes and reinstall the CRM solution for just the sales department.
Answers
D.
Check if the App distribution settings are set to ON for everyone in your organization
D.
Check if the App distribution settings are set to ON for everyone in your organization
Answers
Suggested answer: A

Explanation:

Access the Admin Console: Sign in to your Google Admin console.

Navigate to Security Settings: Click on 'Security' and then 'API controls.'

Manage Third-Party App Access: Click on 'Manage third-party app access.'

Check OAuth Scopes: Locate the CRM solution and ensure that it has the necessary OAuth scopes, particularly for Google Drive and Gmail.

Grant Access: If necessary, adjust the settings to grant the required scopes.

Verify Integration: Confirm that the CRM solution now has access to the necessary data and that employees can see contacts and documents.

Google Workspace Admin Help: Manage third-party app access

You have implemented a data loss prevention (DLP) policy for a specific finance organizational unit. You want to apply the same security policy to a shared drive owned by the finance department in the most efficient manner. What should you do?

A.
In the Admin console sharing settings, select the finance organizational unit and deselect Allow users outside the domain to access files in shared drives
A.
In the Admin console sharing settings, select the finance organizational unit and deselect Allow users outside the domain to access files in shared drives
Answers
B.
Assign the Shared Drive to the finance organizational unit
B.
Assign the Shared Drive to the finance organizational unit
Answers
C.
Create a new DLP policy for shared drive users
C.
Create a new DLP policy for shared drive users
Answers
D.
Change the scope of the policy to apply to all in the domain
D.
Change the scope of the policy to apply to all in the domain
Answers
Suggested answer: C

Explanation:

Access the Admin Console: Sign in to your Google Admin console.

Navigate to DLP Settings: Click on 'Security' and then 'Data protection' to access Data Loss Prevention (DLP) settings.

Create New DLP Policy: Click on 'Create policy' and configure the policy specifically for shared drive data.

Define Rules: Set up the necessary rules and conditions to match the existing DLP policy for the finance organizational unit.

Apply to Shared Drive: Apply this new policy to the shared drive used by the finance department.

Save and Activate: Save the policy and ensure it is active and enforced for the shared drive.

Google Workspace Admin Help: Set up and manage DLP

Your organization has a group of users who interact with sensitive information and their accounts contain valuable files You need to protect these users from targeted online attacks What should you do?

A.
Enable 2-Step Verification for those users and recommend they use Google Authenticator
A.
Enable 2-Step Verification for those users and recommend they use Google Authenticator
Answers
B.
Enable 2-Step Verification for those users and recommend they use SMS codes
B.
Enable 2-Step Verification for those users and recommend they use SMS codes
Answers
C.
Disable password recovery for end users
C.
Disable password recovery for end users
Answers
D.
Enroll all accounts for those users in the Advanced Protection Program
D.
Enroll all accounts for those users in the Advanced Protection Program
Answers
Suggested answer: D

Explanation:

Understanding the Requirement:

The scenario involves a group of users who handle sensitive information and have valuable files in their accounts.

The goal is to protect these users from targeted online attacks.

Options Analysis:

Option A: Enable 2-Step Verification for those users and recommend they use Google Authenticator

2-Step Verification (2SV) enhances security by adding an extra layer of authentication. Google Authenticator is a reliable method, but it may not be sufficient against highly targeted attacks.

Option B: Enable 2-Step Verification for those users and recommend they use SMS codes

While SMS codes are a form of 2SV, they are considered less secure than other methods due to potential vulnerabilities like SIM swapping.

Option C: Disable password recovery for end users

Disabling password recovery can prevent unauthorized access through recovery options but does not provide active protection against targeted attacks.

Option D: Enroll all accounts for those users in the Advanced Protection Program

The Advanced Protection Program (APP) is designed specifically to protect users at high risk of targeted attacks. It includes strong measures such as requiring a physical security key for login, blocking unauthorized access attempts, and restricting access to sensitive data.

Recommended Solution:

Enrolling users in the Advanced Protection Program (APP):

Step 1: Identify High-Risk Users:

Identify users who handle sensitive information and have valuable files.

Step 2: Enroll in APP:

Go to the Google Admin console.

Navigate to the Security section and find the Advanced Protection Program.

Enroll the identified high-risk users in APP.

Step 3: Implement Security Keys:

Ensure users have security keys (e.g., Titan Security Keys) for login.

Guide users through the process of setting up and using security keys.

Step 4: User Education:

Educate users on the importance of APP and how it protects their accounts.

Provide training on recognizing phishing attempts and other security best practices.

Benefits of APP:

Enhanced Security:

APP provides the highest level of security for Google accounts, requiring security keys for authentication.

Protection Against Phishing:

Security keys are highly resistant to phishing attacks, which are common in targeted online attacks.

Limited Access:

APP restricts access to sensitive data, ensuring that only trusted apps and services can interact with the protected accounts.

Google Workspace Admin Help: Advanced Protection Program

Google Workspace Security: Advanced Protection Program

Google Security Blog: Advanced Protection Program

Your organization is moving from a legacy mail system to Google Workspace This move will happen in phases During the first phase, some of the users in the domain are set up to use a different identity provider (IdP) for logging in You need to set up multiple idPs for various users What should you do?

A.
Enable single sign-on (SSO) with third-party identity providers and exclude the users who are using a different provider
A.
Enable single sign-on (SSO) with third-party identity providers and exclude the users who are using a different provider
Answers
B.
Enable single sign-on (SSO) with Cloud Identity and use Cloud Directory Sync to manage multiple identity providers
B.
Enable single sign-on (SSO) with Cloud Identity and use Cloud Directory Sync to manage multiple identity providers
Answers
C.
Create Security Assertion Markup Language (SAML) based single sign-on (SSO) profiles and assign them to specific organizational units or groups of users.
C.
Create Security Assertion Markup Language (SAML) based single sign-on (SSO) profiles and assign them to specific organizational units or groups of users.
Answers
D.
Nothing Google uses cookies to establish a user's relationship to a device This will cover multiple identity providers
D.
Nothing Google uses cookies to establish a user's relationship to a device This will cover multiple identity providers
Answers
Suggested answer: C

Explanation:

Access Admin Console: Sign in to your Google Admin console.

Navigate to Security: Click on 'Security' and then 'Set up single sign-on (SSO) with a third party IdP.'

Add SAML Apps: Click on 'Add SAML app' and select the app to configure.

Create SSO Profiles: Set up SSO profiles for each identity provider by entering the required SAML details such as ACS URL, Entity ID, etc.

Assign to OUs/Groups: Assign the created SSO profiles to specific organizational units (OUs) or groups of users based on their IdP.

Verify Configuration: Ensure that each profile is properly configured and tested.

Google Workspace Admin Help: Set up SSO via SAML for single sign-on

An employee at your organization is having trouble playing a video stored in Google Drive that is embedded in their Google Slides presentation You need to collect the necessary details to troubleshoot the issue What should you do?

A.
Confirm that the source video is in a supported format and resolution and that the user has permission to play the video Have a screen share session to confirm the behavior
A.
Confirm that the source video is in a supported format and resolution and that the user has permission to play the video Have a screen share session to confirm the behavior
Answers
B.
Instruct the employee to give you edit access to the presentation to review the revision history See if the error message changes when you delete and add the slides back
B.
Instruct the employee to give you edit access to the presentation to review the revision history See if the error message changes when you delete and add the slides back
Answers
C.
Check the Google Drive audit logs for any error entries on the Slides presentation Check the help center for the appropriate error message
C.
Check the Google Drive audit logs for any error entries on the Slides presentation Check the help center for the appropriate error message
Answers
D.
Create a copy of the presentation to see if you can replicate the problem, and document any errors you see
D.
Create a copy of the presentation to see if you can replicate the problem, and document any errors you see
Answers
Suggested answer: A

Explanation:

Verify Video Format: Ensure that the video format is supported by Google Drive (e.g., .mp4, .mov).

Check Video Resolution: Make sure the video resolution is supported and not too high for smooth playback.

Permission Check: Confirm that the user has the necessary permissions to access and play the video.

Screen Share Session: Arrange a screen sharing session with the user to observe the issue firsthand.

Replication of Issue: During the session, attempt to play the video to confirm the behavior and identify any error messages.

Troubleshoot: Based on the findings, guide the user on possible fixes such as re-uploading the video, adjusting permissions, or converting the video to a supported format.

Google Workspace Admin Help: Supported video formats

The helpdesk at your organization reports that many users in multiple locations are not able to access Gmail, but can access other Workspace services. You must troubleshoot the issue What should you do first?

A.
Open a ticket with Google Support listing the affected users.
A.
Open a ticket with Google Support listing the affected users.
Answers
B.
Check the Google Workspace status dashboard to see whether there is a disruption in Gmail service availability
B.
Check the Google Workspace status dashboard to see whether there is a disruption in Gmail service availability
Answers
C.
Check the Google Workspace release calendar to ensure there's not a Gmail upgrade scheduled
C.
Check the Google Workspace release calendar to ensure there's not a Gmail upgrade scheduled
Answers
D.
Check network connectivity of the affected users
D.
Check network connectivity of the affected users
Answers
Suggested answer: B

Explanation:

Access Status Dashboard: Open the Google Workspace Status Dashboard.

Check Service Status: Look for any reported issues or outages specifically for Gmail.

Verify Timing: Check the timing of the reported issues to see if they correlate with the time when users reported problems.

Additional Information: Review any additional details or updates provided by Google regarding the service disruption.

Communicate Status: Inform the affected users about the service status and any expected resolution time.

Open Ticket if Necessary: If no issues are reported on the status dashboard, proceed with other troubleshooting steps such as checking network connectivity or opening a ticket with Google Support.

Google Workspace Status Dashboard

An employee has been leaking confidential salary information to an external party. You must use Vault to preserve the messages for an investigation. What should you do?

A.
Create a matter and add a hold on the employee's email
A.
Create a matter and add a hold on the employee's email
Answers
B.
Use the security investigation tool to find the messages Create a hold to preserve the messages
B.
Use the security investigation tool to find the messages Create a hold to preserve the messages
Answers
C.
Create a custom retention policy Use the audit feature to view captured email logs
C.
Create a custom retention policy Use the audit feature to view captured email logs
Answers
D.
Use the search and export features to find all the messages sent externally
D.
Use the search and export features to find all the messages sent externally
Answers
Suggested answer: A

Explanation:

Access Google Vault: Go to Google Vault from the Google Admin console.

Create a Matter: Click on 'Matters' and create a new matter to hold the case details and any relevant information.

Add a Hold: Within the matter, create a hold specifically on the employee's email account. This ensures that all emails sent and received by the employee are preserved.

Configure the Hold: Specify the criteria for the hold, such as the employee's email address, and set the scope to include all messages.

Save the Hold: Once configured, save the hold. This will preserve all relevant messages for the investigation.

Google Vault Help: Create and manage matters

Google Vault Help: Place data on hold

An employee at your company does not need access to their Workspace account while they are on leave for a year When they return you need to ensure they have access to their account and that all their data and current emails remain intact Also their shared documents must be available to other users You must accomplish this goal in the most cost-effective way What should you do?

A.
Assign an Archive User license
A.
Assign an Archive User license
Answers
B.
Suspend their account in the Admin console
B.
Suspend their account in the Admin console
Answers
C.
Delete the user after copying their emails and reassigning their documents to their manager
C.
Delete the user after copying their emails and reassigning their documents to their manager
Answers
D.
Remove the user license in the Admin console
D.
Remove the user license in the Admin console
Answers
Suggested answer: B

Explanation:

Access the Admin Console: Sign in to your Google Admin console.

Navigate to Users: Click on 'Directory' and then 'Users.'

Find the User Account: Locate the user who is going on leave.

Suspend Account: Click on the user's name to open their account details, then click 'Suspend user.'

Confirm Suspension: Confirm the suspension, which retains all data and settings while disabling access to the account.

Shared Documents: Ensure that their shared documents remain accessible to other users without any interruptions.

Google Workspace Admin Help: Suspend a user


Total 197 questions
Go to page: of 20