ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 94 - Professional Google Workspace Administrator discussion

Report
Export

Your company uses a whitelisting approach to manage third-party apps and add-ons. The Senior VP of Sales & Marketing has urgently requested access to a new Marketplace app that has not previously been vetted. The company's Information Security policy empowers you, as a Google Workspace admin, to grant provisional access immediately if all of the following conditions are met:

Access to the app is restricted to specific individuals by request only.

The app does not have the ability to read or manage emails.

Immediate notice is given to the Infosec team, followed by the submission of a security risk analysis report within 14 days.

Which actions should you take first to ensure that you are compliant with Infosec policy?

A.
Move the Senior VP to a sub-OU before enabling Marketplace Settings > ''Allow Users to Install Any App from Google Workspace Marketplace.''
Answers
A.
Move the Senior VP to a sub-OU before enabling Marketplace Settings > ''Allow Users to Install Any App from Google Workspace Marketplace.''
B.
Confirm that the Senior VP's OU has the following Gmail setting disabled before whitelisting the app: ''Let users delegate access to their mailbox.''
Answers
B.
Confirm that the Senior VP's OU has the following Gmail setting disabled before whitelisting the app: ''Let users delegate access to their mailbox.''
C.
Add the Marketplace app, then review the authorized scopes in Security > Manage API client access.
Answers
C.
Add the Marketplace app, then review the authorized scopes in Security > Manage API client access.
D.
Search the Google Workspace support forum for feedback about the app to include in the risk analysis report.
Answers
D.
Search the Google Workspace support forum for feedback about the app to include in the risk analysis report.
Suggested answer: C

Explanation:

Step by Step Comprehensive Detailed Explanation: To comply with the company's Information Security policy while granting provisional access to a new Marketplace app, follow these steps:

Add the Marketplace App: Start by adding the requested app to your Google Workspace Marketplace.

Review Authorized Scopes:

Go to the Admin console.

Navigate to Security > API controls > Manage third-party app access.

Add the app and review the scopes it requests. Ensure it doesn't request permission to read or manage emails.

Compliance Steps:

Restrict Access: Configure the app to be accessible only to the specific individuals as per the request.

Immediate Notification: Inform the Infosec team immediately about the provisional access granted.

Security Risk Analysis Report: Prepare and submit a security risk analysis report within 14 days, detailing the app's functionality and security implications.

Verification: Ensure that the Gmail setting 'Let users delegate access to their mailbox' is disabled if the app's authorized scopes are compliant with the policy.

Manage third-party app access to Google Workspace data

Google Workspace Security: API Controls

asked 18/09/2024
Moraes, Jefferson
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first