
Get Latest May-2024 Real Google-Workspace-Administrator Exam Questions and Answers FREE
Truly Beneficial For Your Google Exam (Updated 162 Questions)
NEW QUESTION # 91
Your organization implemented Single Sign-On (SSO) for the multiple cloud-based services it uses. During authentication, one service indicates that access to the SSO provider is not possible due to invalid information. What should you do?
- A. Update the validation certificate.
- B. Verify that the Audience element in the SAML Response matches the assertion consumer service (ACS) URL
- C. Ensure that Microsoft's Active Directory Federation Services 2.0 sends encrypted SAML Responses in default configurations.
- D. Run nslookup to confirm that the service exists.
Answer: B
NEW QUESTION # 92
After making a recent migration to Google Workspace, you updated your Google Cloud Directory Sync configuration to synchronize the global address list. Users are now seeing duplicate contacts in their global directory in Google Workspace. You need to resolve this issue.
What should you do?
- A. Update shared contact search rules to exclude internal users.
- B. Enable directory contact deduplication in the Google Workspace Admin panel.
- C. Train users to use Google Workspace's merge contacts feature.
- D. Create a new global directory, and delete the original.
Answer: A
Explanation:
https://support.google.com/a/answer/3075991#duplicatecontacts
"To resolve this issue, correct your shared contact search rules to exclude users in your own domain. On the next sync, GCDS attempts to delete the redundant contacts. You might need to adjust the shared contact deletion limit for that first sync.
NEW QUESTION # 93
Your client is a 5,000-employee company with a high turn-over rate that requires them to add and suspend user accounts. When new employees are onboarded, a user object is created in Active Directory. They have determined that manually creating the users in Google Workspace Admin Panel is time-consuming and prone to error. You need to work with the client to identify a method of creating new users that will reduce time and error.
What should you do?
- A. Install Google Apps Manager to automate add-user scripts.
- B. Install Google Cloud Directory Sync on a supported server.
- C. Install Google Workspace Sync for Microsoft Outlook on all employees' computers.
- D. Install Google Cloud Directory Sync on all Domain Controllers.
Answer: B
Explanation:
https://support.google.com/a/answer/6123896
NEW QUESTION # 94
Your Chief Information Security Officer is concerned about phishing. You implemented 2 Factor Authentication and forced hardware keys as a best practice to prevent such attacks. The CISO is curious as to how many such email phishing attempts you've avoided since putting the 2FA+Hardware Keys in place last month.
Where do you find the information your CISO is interested in seeing?
- A. Security > Advanced Security Settings > Phishing Attempts
- B. Reporting > Reports > Phishing
- C. Apps > Google Workspace > Gmail > Phishing Attempts
- D. Security > Dashboard > Spam Filter: Phishing
Answer: D
Explanation:
https://support.google.com/a/answer/7491892?hl=en
NEW QUESTION # 95
Your organization recently deployed Google Workspace. Your admin team has been very focused on configuring the core services for your environment, which has left you little time to pay attention to other areas. Your security team has just informed you that many users are leveraging unauthorized add-ons, and they are concerned about data exfiltration. The admin team wants you to cut off all add-ons access to Workspace data immediately and block all future add-ons until further notice. However, they approve of users leveraging their Workspace accounts to sign into third-party sites. What should you do?
- A. Set all API services to "restricted access" and ensure that all connected apps have limited access.
- B. Remove all client IDs and scopes from the list of domain-wide delegation API clients.
- C. Modify your Marketplace Settings to block users from installing any app from the Marketplace.
- D. Block each connected app's access.
Answer: B
Explanation:
https://support.google.com/a/answer/162106?hl=en#zippy=%2Cview-edit-or-delete-clients-and-scopes:~:text=View%2C%20edit%2C%20or,immediately%20stop%20working.
NEW QUESTION # 96
Your organization does not allow users to share externally. The security team has recently approved an exemption for specific members of the marketing team and sales to share documents with external customers, prospects, and partners. How best would you achieve this?
- A. Enable external sharing for the marketing and sales organizational units.
- B. Create a configuration group with the approved users as members, and use it to create a target audience.
- C. Create a configuration group with the approved users as members, and enable external sharing for this group.
- D. Enable external sharing only to allowlisted domains provided by marketing and sales teams.
Answer: C
Explanation:
https://support.google.com/a/answer/9224126?hl=en#zippy=%2Coptions-for-configurations-groups:~:text=Using%20configurations%20groups,of%20your%20organization.
NEW QUESTION # 97
Several customers have reported receiving fake collection notices from your company. The emails were received from [email protected], which is the valid address used by your accounting department for such matters, but the email audit log does not show the emails in question. You need to stop these emails from being sent.
What two actions should you take? (Choose two.)
- A. Disable mail delegation for the [email protected] account.
- B. Disable "Allow users to automatically forward incoming email to another address."
- C. Configure Domain Keys Identified Mail (DKIM) to authenticate email.
- D. Configure a Sender Policy Framework (SPF) record for your domain.
- E. Change the password for suspected compromised account [email protected].
Answer: C,D
Explanation:
https://support.google.com/a/answer/33786?hl=en
https://support.google.com/a/answer/174124?hl=en
NEW QUESTION # 98
Your organization has a new security requirement around data exfiltration on iOS devices. You have a requirement to prevent users from copying content from a Google app (Gmail, Drive, Docs, Sheets, and Slides) in their work account to a Google app in their personal account or a third-party app. What steps should you take from the admin panel to prevent users from copying data from work to non-work apps on iOS devices?
- A. Disable "Open Docs in Unmanaged Apps" setting in Google Admin Console's Device management section.
- B. Navigate to Devices > Mobile and endpoints > Universal Settings > General and turn on Basic Mobile Management.
- C. Navigate to "Data Protection" setting in Google Admin Console's Device management section and disable the "Allow users to copy data to personal apps" checkbox.
- D. Clear the "Allow items created with managed apps to open in unmanaged apps" checkbox.
Answer: C
Explanation:
https://support.google.com/a/answer/6328700?hl=en&ref_topic=6079327#managed_apps&zippy=%2Cdata-actions Allow users to copy Google Workspace items to personal apps Allows users to copy content from a Google app (such as Gmail, Drive, Docs, Sheets, Slides, Chat, and Meet) to a Google app in their personal account or a third-party app. Also allows users to drag content between Google apps, for any account.
To prevent users from copying or dragging information from their work account, or using the All inboxes feature (which combines messages from multiple Gmail accounts into one inbox), uncheck the box.
NEW QUESTION # 99
As the Workspace Administrator, you have been asked to enable the help desk team to share incoming support requests from end users The help desk team has ten users who need to respond to support requests that are sent to a help desk email address. The users must be able to respond by email and assign ownership of tickets. Finally, the help desk team is highly mobile and will need to manage help desk tickets from their mobile devices. How would you provide this functionality for the help desk team?
- A. Configure a Google Group as a collaborative inbox, and assign the required Groups permissions to the help desk team members.
- B. Create a help desk Workspace mail account, and set the help desk team as mail delegates to the help desk account.
- C. Create the help desk group as a Q&A Group, and add the "Manager role to the help desk team users.
- D. In Google Drive, create a help desk request form, and give the help desk team the ability to view the inbound requests.
Answer: A
NEW QUESTION # 100
All Human Resources employees at your company are members of the "HR Department" Team Drive. The HR Director wants to enact a new policy to restrict access to the "Employee Compensation" subfolder stored on that Team Drive to a small subset of the team.
What should you do?
- A. Move the subfolder to the HR Director's MyDrive and share it with the relevant team members.
- B. Use the Drive API to modify the permissions of the individual files contained within the subfolder.
- C. Use the Drive API to modify the permissions of the Employee Compensation subfolder.
- D. Move the contents of the subfolder to a new Team Drive with only the relevant team members.
Answer: D
Explanation:
"Inherited permissions can't be removed from a file or folder in a shared drive".
ref: https://developers.google.com/drive/api/v3/manage-sharing
NEW QUESTION # 101
Your organization has noticed several incidents of accidental oversharing inside the organization. Specifically, several users have shared sensitive Google Drive items with the entire organization by clicking 'anyone in this group with this link can view'. You have been asked by senior management to help users share more appropriately and also to prevent accidental oversharing to the entire organization. How would you best accomplish this?
- A. Temporarily disable the Google Drive service for individuals who continually overshare.
- B. Disable sharing to the entire organization so that users must consciously add every person who needs access.
- C. Determine sharing boundaries for users that work with sensitive information, and then implement target audiences.
- D. Create groups, add users accordingly, and educate users on how to share to specific groups of people.
Answer: C
Explanation:
https://support.google.com/a/answer/9934697?hl=en#zippy=:~:text=Why%20use%20target,for%20broad%20sharing.
NEW QUESTION # 102
Your Finance team has to share quarterly financial reports in Sheets with an external auditor. The external company is not a Workspace customer and allows employees to access public sites such as Gmail and Facebook. How can you provide the ability to securely share content to collaborators that do not have a Google Workspace or consumer (Gmail) account?
- A. Attach the Sheet file to an email message, and send to the external auditor.
- B. Use the 'Publish' feature in the Sheets editor to share the contents externally.
- C. Allow external sharing with the auditor using the 'Trusted Domains' feature.
- D. Enable the 'Visitor Sharing' feature, and demonstrate it to the Finance team.
Answer: D
Explanation:
https://support.google.com/drive/answer/9195194?hl=en#:~:text=Share%20with%20visitors,with%20one%20visitor.
NEW QUESTION # 103
Your-company.com finance departments want to create an internal application that needs to read data from spreadsheets. As the collaboration engineer, you suggest using App Maker. The Finance team is concerned about data security when creating applications with App Maker.
What security measures should you implement to secure data?
- A. Change owner access permissions to allow internal usage only.
- B. Use a service account with limited permissions to access each data source.
- C. Enable App Maker access only for the Finance department Organization Unit.
- D. Use Roles, Script, and Owner access permissions for operations on records and data relations.
Answer: D
Explanation:
https://developers.google.com/appmaker/security/overview
NEW QUESTION # 104
You have configured SSO using a third-party IDP with your Google Workspace domain. An end user has reported that they cannot sign in to Google Workspace after their username was changed in the third-party SSO product. They can sign in to their other internal applications that use SSO. and no other users are experiencing issues signing in. What could be causing the sign-in issue?
- A. The issued certificate for that user has been revoked and must be updated before the user can have another successful sign in.
- B. The SAML assertion is providing the user's previous password attached to their old username.
- C. The SAML assertion provided by the third-party IDP is presenting a username that conflicts with the current username configured in Google Workspace.
- D. The user's Google password was changed administratively, which is causing a sign-in failure.
Answer: C
NEW QUESTION # 105
Your organization is preparing to deploy Workspace and will continue using your company's existing identity provider for authentication and single sign-on (SSO). In order to migrate data from an external system, you were required to provision each user's account in advance. Your IT team and select users (~5% of the organization) have been using Workspace for configuration and testing purposes. The remainder of the organization can technically access their accounts now, but the IT team wants to block their access until the migrations are complete. What should your organization do?
- A. Remove Google Workspace license to prevent users from accessing their accounts now.
- B. Use Context-Aware Access to simultaneously block access to all services for all users and allow access to all services for the allowed users.
- C. Add the users to the OU with all services disabled.
- D. Suspend users that the organization does not wish to have access.
Answer: C
Explanation:
https://support.google.com/a/answer/182449?hl=en
NEW QUESTION # 106
Four weeks ago. you exported data from Google Vault and emailed the PST export file to your legal admin. They accidentally deleted the PST file and need it sent again. What steps should you take to re-send the PST file to the legal admin?
- A. Repeat the original search for the original timeframe, and export the data again.
- B. Return to the Email Log Search page, and download the PST file again.
- C. Ask the legal admin to return to Google Vault to download the PST file again.
- D. Return to the Google Vault export page, and download the ZIP file again.
Answer: A
NEW QUESTION # 107
Security and Compliance has identified secure third-party applications that should have access to Google Workspace dat a. You need to restrict third-party access to only approved applications What two actions should you take? (Choose two.)
- A. Whitelist Google Workspace Marketplace apps
- B. Restrict API scopes
- C. Whitelist Trusted Apps
- D. Disable the Drive SDK
- E. Disable add-ons for Gmail
Answer: B,C
NEW QUESTION # 108
Your organization is concerned with the increasing threat of phishing attacks that may impact users.
Leadership has declined to force-enable 2-Step verification. You need to apply a security measure to prevent unauthorized access to user accounts.
What should you do?
- A. Decrease the Maximum User Session Length.
- B. Revoke token authorizations to external applications.
- C. Enable Employee ID Login Challenge.
- D. Enable Enforce Strong Password policy.
Answer: C
Explanation:
You can use employee IDs as a login challenge. Employee IDs are more difficult to guess and phish than other types of identity challenges. To use the employee ID login challenge, you need to make sure that IDs are associated with your users' accounts. https://support.google.com/a/answer/6002699?hl=en
NEW QUESTION # 109
Your company (your-company.com) just acquired a new business (new-company.com) that is running their email on-premises. It is close to their peak season, so any major changes need to be postponed. However, you need to ensure that the users at the new business can receive email addressed to them using your- company.com into their on-premises email server. You need to set up an email routing policy to accomplish this.
What steps should you take?
- A. Set up accounts for the new employees, and use mail forwarding rules to send to the on-premises server.
- B. Set up a Default route with split delivery to route email to the on-premises server.
- C. Set up an Outbound Mail Gateway to route all outbound email to the on-premises server.
- D. Set up an Inbound Mail Gateway to reroute all inbound email to the on-premises server.
Answer: B
Explanation:
https://support.google.com/a/answer/2685650?hl=en
"...If you're migrating to Gmail from a legacy server, use split delivery to test Gmail with a subset of users. During the testing, the MX records for your domain point to Gmail. Users who have been added in the Admin console get messages in their Gmail inboxes. Set up a catch-all routing rule for unregistered users who need to get messages from the legacy mail server."
NEW QUESTION # 110
Your organization's information security team has asked you to determine and remediate if a user ([email protected]) has shared any sensitive documents outside of your organization. How would you audit access to documents that the user shared inappropriately?
- A. Open Security Investigation Tool-> Drive Log Events. Add two conditions: Visibility Is External, and Actor Is [email protected].
- B. Have the super administrator use the Security API to audit Drive access.
- C. Open Security Dashboard-> File Exposure Report-> Export to Sheet, and filter for [email protected].
- D. As a super administrator, change the access on externally shared Drive files manually under [email protected].
Answer: A
Explanation:
https://support.google.com/a/answer/11480192?hl=en&ref_topic=11479095#:~:text=View%20files%20shared,Click%20Search.
NEW QUESTION # 111
In the years prior to your organization moving to Google Workspace, it was relatively common practice for users to create consumer Google accounts with their corporate email address (for example, to monitor Analytics, manage AdSense, and collaborate in Docs with other partners who were on Google Workspace.) You were able to address active employees' use of consumer accounts during the rollout, and you are now concerned about blocking former employees who could potentially still have access to those services even though they don't have access to their corporate email account.
What should you do?
- A. Provide a list of all active employees to the managers of your company's Analytics, AdSense, etc. accounts, so they can clean up the respective access control lists.
- B. Use the Transfer Tool for Unmanaged Accounts to send requests to the former users to transfer their account to your domain as a managed account.
- C. Contact Google Enterprise Support to provide a list of all accounts on your domain(s) that access non-Google Workspace Google services and have them blocked.
- D. Provision former user accounts with Cloud Identity licenses, generate a new Google password, and place them in an OU with all Google Workspace and Other Google Services disabled.
Answer: B
Explanation:
https://support.google.com/a/answer/6178640?hl=en
NEW QUESTION # 112
Your organization has implemented Single Sign-On (SSO) for the multiple cloud-based services it utilizes. During authentication, one service indicates that access to the SSO provider cannot be accessed due to invalid information.
What should you do?
- A. Verify the Recipient attribute in the SAML Response matches the Assertion Consumer Service (ACS) URL.
- B. Verify the NameID Element in the SAML Response matches the Assertion Consumer Service (ACS) URL.
- C. Verify the Subject attribute in the SAML Response matches the Assertion Consumer Service (ACS) URL.
- D. Verify the Audience Element in the SAML Response matches the Assertion Consumer Service (ACS) URL.
Answer: D
Explanation:
Reference:
https://support.google.com/a/answer/2463723?hl=en
NEW QUESTION # 113
A user is reporting that after they sign in to Gmail, their labels are not loading and buttons are not responsive. What action should you take to troubleshoot this issue with the user?
- A. Check whether the issue occurs when the user authenticates on a different device or a new incognito window.
- B. Check whether a ping test to service.gmail.com (pop.gmail.com or imap.gmail.com) is successful.
- C. Check whether traceroute to service.gmail.com (pop.gmail.com or imap.gmail.com) is successful.
- D. Collect full message headers for examination.
Answer: A
NEW QUESTION # 114
Your Security Officer ran the Security Health Check and found the alert that "Installation of mobile applications from unknown sources" was occurring. They have asked you to find a way to prevent that from happening.
Using Mobile Device Management (MDM), you need to configure a policy that will not allow mobile applications to be installed from unknown sources.
What MDM configuration is needed to meet this requirement?
- A. In the Application Management menu, configure the whitelist of apps that Android, iOS devices, and Active Sync devices are allowed to install.
- B. In Device Management > Setup > Device Approvals menu, configure the "Requires Admin approval" option.
- C. In Android Settings, ensure that "Allow non-Play Store apps from unknown sources installation" is unchecked.
- D. In the Application Management menu, configure the whitelist of apps that Android and iOS devices are allowed to install.
Answer: C
NEW QUESTION # 115
......
Google-Workspace-Administrator dumps Free Test Engine Verified By It Certified Experts: https://www.exam-killer.com/Google-Workspace-Administrator-valid-questions.html
View All Google-Workspace-Administrator Actual Exam Questions, Answers and Explanations for Free: https://drive.google.com/open?id=1naOcCEPcEnFUlW2twMvV2DvSV_dUwHBq

