
Online Questions - Valid Practice Google-Workspace-Administrator Exam Dumps Test Questions
100% Real Google-Workspace-Administrator dumps - Brilliant Google-Workspace-Administrator Exam Questions PDF
Google Google-Workspace-Administrator Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
| Topic 10 |
|
| Topic 11 |
|
| Topic 12 |
|
| Topic 13 |
|
NEW QUESTION 26
Your company recently migrated to Google Workspace and wants to deploy a commonly used third-party app to all of finance. Your OU structure in Google Workspace is broken down by department. You need to ensure that the correct users get this app.
What should you do?
- A. For the Finance OU, enable the third-party app in SAML apps.
- B. At the root level, disable the third-party app. For the Finance OU, allow users to install any application from the Google Workspace Marketplace.
- C. At the root level, disable the third-party app. For the Finance OU, allow users to install only whitelisted apps from the Google Workspace Marketplace.
- D. For the Finance OU, enable the third-party app in Marketplace Apps.
Answer: D
NEW QUESTION 27
A company using Google Workspace has reports of cyber criminals trying to steal usernames and passwords to access critical business dat a. You need to protect the highly sensitive user accounts from unauthorized access.
What should you do?
- A. Enforce 2FA with Google Authenticator app.
- B. Use a third-party identity provider.
- C. Enforce 2FA with a physical security key.
- D. Turn on password expiration.
Answer: C
Explanation:
https://support.google.com/a/answer/175197?hl=en#keys&prompt&authentic&codes&phone&2sv&security
NEW QUESTION 28
The company's ten most senior executives are to have their offices outfitted with dedicated, standardized video conference cameras, microphones, and screens. The goal is to reduce the amount of technical support they require due to frequent, habitual switching between various mobile and PC devices throughout their busy days. You must ensure that it is easier for the executives to join Meet video conferences with the dedicated equipment instead of whatever device they happen to have available.
What should you do?
- A. Deploy Hangouts Meet Hardware Kits to each executive office, and associate the Meet hardware with the executives' calendars.
- B. Set up unmanaged Chromeboxes and set the executives' homepage to meet.google.com via Chrome settings.
- C. Set up the executive offices as reservable Calendar Resources, deploy Hangouts Meet Hardware Kits, and associate the Meet hardware with the room calendars.
- D. Provision managed Chromeboxes and set the executives' Chrome homepage to meet. google.com via device policy.
Answer: A
Explanation:
https://support.google.com/meethardware/answer/3341435?hl=en If the device is for a single user, such as in a home office or other remote location, you can associate the device with their personal calendar. Whenever an organizer adds that user to a Calendar event, the meeting name appears on their device.
NEW QUESTION 29
Your organization has implemented Single Sign-On (SSO) for the multiple cloud-based services it utilizes. During authentication, one service indicates that access to the SSO provider cannot be accessed due to invalid information.
What should you do?
- A. Verify the Audience Element in the SAML Response matches the Assertion Consumer Service (ACS) URL.
- B. Verify the Subject attribute in the SAML Response matches the Assertion Consumer Service (ACS) URL.
- C. Verify the NameID Element in the SAML Response matches the Assertion Consumer Service (ACS) URL.
- D. Verify the Recipient attribute in the SAML Response matches the Assertion Consumer Service (ACS) URL.
Answer: A
Explanation:
Reference:
https://support.google.com/a/answer/2463723?hl=en
NEW QUESTION 30
How can you monitor increases in user reported Spam as identified by Google?
- A. Review user-reported spam in the Investigation Tool.
- B. Review spike in user-reported spam in the Alert center.
- C. Review post-delivery activity in the BigQuery Export.
- D. Review post-delivery activity in the Email logs.
Answer: B
Explanation:
https://support.google.com/a/answer/9104586?hl=en
NEW QUESTION 31
Your company wants to provide secure access for its employees. The Chief Information Security Officer disabled peripheral access to devices, but wants to enable 2-Step verification. You need to provide secure access to the applications using Google Workspace.
What should you do?
- A. Enable authentication via the Google Authenticator.
- B. Enable additional security verification via email.
- C. Deploy browser or device certificates via Google Workspace.
- D. Configure USB Yubikeys for all users.
Answer: A
Explanation:
Enable authentication via the Google Authenticator is the only secure option since USB device aren't usable. Google Authenticator is the most secure option after physical key.
NEW QUESTION 32
Your client is a 5,000-employee company with a high turn-over rate that requires them to add and suspend user accounts. When new employees are onboarded, a user object is created in Active Directory. They have determined that manually creating the users in Google Workspace Admin Panel is time-consuming and prone to error. You need to work with the client to identify a method of creating new users that will reduce time and error.
What should you do?
- A. Install Google Cloud Directory Sync on all Domain Controllers.
- B. Install Google Cloud Directory Sync on a supported server.
- C. Install Google Workspace Sync for Microsoft Outlook on all employees' computers.
- D. Install Google Apps Manager to automate add-user scripts.
Answer: B
Explanation:
https://support.google.com/a/answer/6123896
NEW QUESTION 33
The organization has conducted and completed Security Awareness Training (SAT) for all employees. As part of a new security policy, employees who did not complete the SAT have had their accounts suspended. The CTO has requested to be informed of any accounts that have been re-enabled to ensure no one is in violation of the new security policy.
What should you do?
- A. Enable "Suspicious login" rule - Other Recipients: CTO
- B. Enable "Email settings changed" rule - -Other Recipients: CTO
- C. Enable "Suspended user made active" rule and select "Deliver to" Super Administrator(s)
- D. Enable "Suspended user made active" rule - Other Recipients: CTO
Answer: D
Explanation:
CTO must be informed when creating the Suspended user made active-A suspended user is made active by an admin Alert. Ref: https://support.google.com/a/answer/3230421?hl=en#zippy=%2Cuser-activity-alerts
NEW QUESTION 34
Your company has received help desk calls from users about a new interface in Gmail that they had not seen before. They determined that it was a new feature that Google released recently. In the future, you'll need time to review the new features so you can properly train employees before they see changes.
What action should you take?
- A. Company Profile > Profile > New User Features > Enable "Scheduled Release"
- B. Apps > Google Workspace > Gmail > Uncheck "Enable Gmail Labs for my users"
- C. Device Management > Chrome > Device Settings > Stop auto-updates
- D. Company Profile > Profile > New User Features > Enable "Rapid Release"
Answer: A
NEW QUESTION 35
Your cyber security team has requested that all email destined for external domains be scanned for credit card numbers, and if found, the email must be encrypted using your cloud-based third-party encryption provider. You are responsible for configuring to meet this request.
What should you do?
- A. Create a content compliance rule on outbound mail and internal-sending mail using the predefined rule for credit card numbers, and add a custom header that your third-party encryption provider can scan for and encrypt.
- B. Create a content compliance rule on outbound mail using the predefined rule for credit card numbers, and check "Change route" to send to your third-party encryption provider to encrypt.
- C. Create a content compliance rule on outbound mail using the predefined rule for credit card numbers, and add a custom header that your third-party encryption provider can scan for and encrypt.
- D. Create a content compliance rule on outbound mail using the predefined rule for credit card numbers, and check "Encrypt message if not encrypted".
Answer: B
Explanation:
https://support.google.com/a/answer/3540538?hl=en
NEW QUESTION 36
Your CISO is concerned about third party applications becoming compromised and exposing Google Workspace data you have made available to them. How could you provide granular insight into what data third party applications are accessing?
What should you do?
- A. Create a reporting using the API Permissions logs for Installed Apps.
- B. Create a report using the OAuth Token Audit Activity logs.
- C. Create a report using the Drive Audit Activity logs.
- D. Create a report using the Calendar Audit Activity logs.
Answer: B
Explanation:
https://support.google.com/a/answer/6124308?hl=en
NEW QUESTION 37
A user has traveled overseas for an extended trip to meet with several vendors. The user has reported that important draft emails have not been saved in Gmail, which is affecting their productivity. They have been constantly moving between hotels, vendor offices, and airport lounges.
You have been tasked with troubleshooting the issue remotely. Your first priority is diagnosing and preventing this from happening again, and your second priority is recovering the drafts if possible. Due to time zone differences, and the user's busy meeting schedule, you have only been able to arrange a brief Hangouts Meet with the user to gather any required troubleshooting inputs.
What two actions should be taken on this call with the user? (Choose two.)
- A. Record a HAR file of the user composing a new email.
- B. Use the Email log search in the Admin panel.
- C. Check the Users > App Users Activity report.
- D. Ask the user to send an email to you so you can check the headers.
- E. Take screenshots of the user's screen when composing an email.
Answer: A,E
NEW QUESTION 38
Your-company.com recently bought 2500 Chrome devices and wants to distribute them to various teams globally. You decided that enterprise enrollment would be the best way to enforce company policies for managed Chrome devices. You discovered that Chrome devices currently end up in the top-level organization unit, and this needs to change to the organizational unit of the device administrator.
What should you do?
- A. Change Enrollment Permissions to only allow users in this organization to re-enroll existing devices.
- B. Change Enrolment Permissions to not allow users in this organization to enroll new devices.
- C. Change Enrollment Controls to Place Chrome device in user organization.
- D. Change Enrollment Controls to Keep Chrome device in current location.
Answer: C
Explanation:
https://support.google.com/chrome/a/answer/2657289#auto_device_placement_enabled
NEW QUESTION 39
Your Security Officer ran the Security Health Check and found the alert that "Installation of mobile applications from unknown sources" was occurring. They have asked you to find a way to prevent that from happening.
Using Mobile Device Management (MDM), you need to configure a policy that will not allow mobile applications to be installed from unknown sources.
What MDM configuration is needed to meet this requirement?
- A. In the Application Management menu, configure the whitelist of apps that Android and iOS devices are allowed to install.
- B. In Android Settings, ensure that "Allow non-Play Store apps from unknown sources installation" is unchecked.
- C. In Device Management > Setup > Device Approvals menu, configure the "Requires Admin approval" option.
- D. In the Application Management menu, configure the whitelist of apps that Android, iOS devices, and Active Sync devices are allowed to install.
Answer: B
NEW QUESTION 40
Your client is a multinational company with a single email domain. The client has compliance requirements and policies that vary by country. You need to configure the environment so that each country has their own administrator and no administrator can manage another country.
What should you do?
- A. Establish a new Google Workspace tenant with their own admin for each region.
- B. Create a Team Drive per OU, and allow only country-specific administration of each folder.
- C. Create an OU for each country. Create an admin role and assign an admin with that role per OU.
- D. Create Admin Alerts, and use the Security Center to audit whether admins manage countries other than their own.
Answer: C
Explanation:
https://support.google.com/a/answer/6129577?hl=en#:~:text=Create%20and%20assign%20the%20role&text=Click%20Assign%20role.,organizational%20unit%20and%20click%20Done.
NEW QUESTION 41
Your company uses a whitelisting approach to manage third-party apps and add-ons. The Senior VP of Sales
& Marketing has urgently requested access to a new Marketplace app that has not previously been vetted. The company's Information Security policy empowers you, as a Google Workspace admin, to grant provisional access immediately if all of the following conditions are met:
Access to the app is restricted to specific individuals by request only.
The app does not have the ability to read or manage emails.
Immediate notice is given to the Infosec team, followed by the submission of a security risk analysis report within 14 days.
Which actions should you take first to ensure that you are compliant with Infosec policy?
- A. Move the Senior VP to a sub-OU before enabling Marketplace Settings > "Allow Users to Install Any App from Google Workspace Marketplace."
- B. Confirm that the Senior VP's OU has the following Gmail setting disabled before whitelisting the app: "Let users delegate access to their mailbox."
- C. Search the Google Workspace support forum for feedback about the app to include in the risk analysis report.
- D. Add the Marketplace app, then review the authorized scopes in Security > Manage API client access.
Answer: D
Explanation:
https://support.google.com/a/answer/7281227?hl=en
NEW QUESTION 42
Your company policy requires that managers be provided access to Drive data once an employee leaves the company.
How should you grant this access?
- A. Make the manager a delegate to the former employee's account.
- B. Copy the data from the former employee's My Drive to the manager's My Drive.
- C. Login as the user and add the manager to the file permissions using the "Is owner' privilege for all Drive files.
- D. Transfer ownership of all Drive data using the file transfer ownership tool in the Google Workspace Admin console.
Answer: D
Explanation:
https://support.google.com/a/answer/1247799?hl=en
NEW QUESTION 43
Your employer, a media and entertainment company, wants to provision Google Workspace Enterprise accounts on your domain for several world-famous celebrities. Leadership is concerned with ensuring that these VIPs are afforded a high degree of privacy. Only a small group of senior employees must be able to look up contact information and initiate collaboration with the VIPs using Google Workspace services such as Docs, Chat, and Calendar.
You are responsible for configuring to meet these requirements. What should you do?
- A. Create separate Custom Directories for the VIPs and regular employees.
- B. In the Users list, find the VIPs and turn off the User setting "Directory Sharing."
- C. Create a Group for the VIPs and their handlers, and set the Group Access Level to Restricted.
- D. In Directory Settings, disable Contact Sharing.
Answer: A
Explanation:
https://support.google.com/a/answer/7566446?hl=en
NEW QUESTION 44
Your-company.com recently started using Google Workspace. The CIO is happy with the deployment, but received notifications that some employees have issues with consumer Google accounts (conflict accounts). You want to put a plan in place to address this concern.
What should you do?
- A. Use the conflict account remove tool to remove the accounts from Google Workspace.
- B. Use the Transfer tool for unmanaged users to find the conflict accounts.
- C. Ask users to request a new Google Workspace account from your local admin.
- D. Rename the accounts to [email protected], and recreate the accounts.
Answer: B
Explanation:
https://gsuiteupdates.googleblog.com/2017/02/resolve-conflicting-accounts-with-new.html#:~:text=Using%20the%20new%20Transfer%20tool,accounts%20to%20G%20Suite%20accounts. https://support.google.com/a/answer/6178640?hl=en
NEW QUESTION 45
Security and Compliance has identified secure third-party applications that should have access to Google Workspace dat a. You need to restrict third-party access to only approved applications What two actions should you take? (Choose two.)
- A. Disable add-ons for Gmail
- B. Whitelist Google Workspace Marketplace apps
- C. Restrict API scopes
- D. Disable the Drive SDK
- E. Whitelist Trusted Apps
Answer: C,E
NEW QUESTION 46
Several customers have reported receiving fake collection notices from your company. The emails were received from [email protected], which is the valid address used by your accounting department for such matters, but the email audit log does not show the emails in question. You need to stop these emails from being sent.
What two actions should you take? (Choose two.)
- A. Configure a Sender Policy Framework (SPF) record for your domain.
- B. Disable mail delegation for the [email protected] account.
- C. Change the password for suspected compromised account [email protected].
- D. Configure Domain Keys Identified Mail (DKIM) to authenticate email.
- E. Disable "Allow users to automatically forward incoming email to another address."
Answer: A,D
Explanation:
https://support.google.com/a/answer/33786?hl=en
https://support.google.com/a/answer/174124?hl=en
NEW QUESTION 47
......
Google-Workspace-Administrator Exam PDF [2022] Tests Free Updated Today with Correct 78 Questions: https://prep4tests.pass4sures.top/Workspace-Administrator/Google-Workspace-Administrator-testking-braindumps.html