Google Google-Workspace-Administrator Exam Info and Free Practice Test Exam-Killer [Q42-Q66]

Share

Google Google-Workspace-Administrator Exam Info and Free Practice Test | Exam-Killer

Pass Google Google-Workspace-Administrator Premium Files Test Engine pdf - Free Dumps Collection


Google Workspace Administrator Certification Exam is a challenging exam that requires candidates to have a deep understanding of Google Workspace applications. Candidates should have experience working with Google Workspace applications and should be familiar with the latest Google Workspace updates and features. Google-Workspace-Administrator exam is designed to assess the candidate’s ability to manage and deploy Google Workspace applications effectively and efficiently.

 

NEW QUESTION # 42
You are the administrator for a 30.000-user organization. You have multiple Workspace licensing options available to end users in your domain, according to their work responsibilities. A user may be transitioned to a different license type multiple times in a given year. Your organization has a high turnover rate for employees. What is the most efficient way to manage your organization's licensing?

  • A. Use Google Cloud Directory Sync to modify user licensing with each sync, according to information available in the organization's LDAP
  • B. Update user licensing in the user portion of the Admin console on an as-needed basis.
  • C. Create a license assignment rule in the Google Admin console to set user licensing based on directory attributes.
  • D. Use the Directory API to create a custom batch script that modifies the users license on a daily basis

Answer: C


NEW QUESTION # 43
Your company recently migrated to Google Workspace and wants to deploy a commonly used third-party app to all of finance. Your OU structure in Google Workspace is broken down by department. You need to ensure that the correct users get this app.
What should you do?

  • A. For the Finance OU, enable the third-party app in SAML apps.
  • B. For the Finance OU, enable the third-party app in Marketplace Apps.
  • C. At the root level, disable the third-party app. For the Finance OU, allow users to install any application from the Google Workspace Marketplace.
  • D. At the root level, disable the third-party app. For the Finance OU, allow users to install only whitelisted apps from the Google Workspace Marketplace.

Answer: B


NEW QUESTION # 44
An employee has been leaking confidential salary information to an external party. You must use Vault to preserve the messages for an investigation. What should you do?

  • A. Use the search and export features to find all the messages sent externally
  • B. Create a custom retention policy Use the audit feature to view captured email logs
  • C. Use the security investigation tool to find the messages Create a hold to preserve the messages
  • D. Create a matter and add a hold on the employee's email

Answer: D

Explanation:
Access Google Vault: Go to Google Vault from the Google Admin console.
Create a Matter: Click on "Matters" and create a new matter to hold the case details and any relevant information.
Add a Hold: Within the matter, create a hold specifically on the employee's email account. This ensures that all emails sent and received by the employee are preserved.
Configure the Hold: Specify the criteria for the hold, such as the employee's email address, and set the scope to include all messages.
Save the Hold: Once configured, save the hold. This will preserve all relevant messages for the investigation.
Reference:
Google Vault Help: Create and manage matters
Google Vault Help: Place data on hold


NEW QUESTION # 45
Your organization is part of a highly regulated industry with a very high turnover. In order to recycle licenses for new employees and comply with data retention regulations, it has been determined that certain Google Workspace data should be stored in a separate backup environment.
How should you store data for this situation?

  • A. Write a script and use Google Workspace APIs to access and download user data.
  • B. Use a third-party tool to configure secure backup of Google Workspace data.
  • C. Use routing rules to dual-deliver mail to an on-premises SMTP server and Google Workspace.
  • D. Train users to use Google Takeout and store their archives locally.

Answer: B

Explanation:
https://cloud.google.com/solutions/partners/backing-up-g-suite-data-with-spinbackup


NEW QUESTION # 46
You've noticed an increase in phishing emails that contain links to malicious files hosted on external Google Drives. These files often mimic legitimate documents and trick users into granting access to their accounts. You need to prevent users from accessing these malicious external Drive files, but allow them to access legitimate external files. What should you do? (Choose two.)

  • A. Create a Drive trust rule that blocks all external domains except for a pre-approved list of trusted partners.
  • B. Conduct regular security awareness training to educate users.
  • C. Enforce stricter password policies.
  • D. Deploy advanced malware detection software on all user devices to scan and block malicious files.

Answer: A,B

Explanation:
E Implement two-factor authentication for all users
Explanation:
Conduct regular security awareness training to educate users: Educating users about phishing threats and safe online practices can help them recognize and avoid phishing attempts, reducing the chances of them falling for such scams.
Create a Drive trust rule that blocks all external domains except for a pre-approved list of trusted partners: By setting up a Drive trust rule to limit access to files from external domains, you can block links to malicious files hosted on untrusted external Google Drives while still allowing access to legitimate external files from trusted sources.


NEW QUESTION # 47
The executive team for your company has an extended retention policy of two years in place so that they have access to email for a longer period of time. Your COO has found this useful in the past but when they went to find an email from last year to prove details of a contract in dispute, they were unable to find it. itis no longer in the Trash. They have requested that you recover it.
What should you do?

  • A. Using the Message ID, contact Google Google Workspace support to recover the email, then import with Google Workspace Migration for Microsoft Outlook.
  • B. Using the Vault Audit log, perform a search for the email, export the results. then import with Google Workspace Migration for Microsoft Outlook.
  • C. Using Vault, perform a search for the email and export the content to a standard format to provide for investigation.

Answer: C

Explanation:
Access Google Vault:
Go to Google Vault by navigating to vault.google.com.
Perform a Search:
In Vault, create a new search query specifying the criteria (e.g., date range, email address, keywords) to locate the missing email.
Use search operators to refine the search and ensure you find the correct email.
Export the Email:
Once the email is located, select it and choose the export option.
Export the email data in a standard format, such as MBOX or PST, which can be used for investigation and recovery purposes.
Provide the Exported Data:
Provide the exported email data to the COO for their review and use in the contract dispute.
Reference
Google Vault Help: Search for and export data


NEW QUESTION # 48
You work for a midsize organization Your compliance and audit learn sees that users are frequently resetting their passwords You must provide accurate information and ensure that the compliance team is informed every time a user changes their password What should you do?

  • A. Enable user account recovery and forward any alert to the compliance team through the alert center
  • B. Disable user account recovery so users must contact you before a reset
  • C. Check the User's password changed alert in the alert center and include the compliance team in the email notifications
  • D. Create a new alert by using user log events and check that event Login type is Google password and include the compliance team in the email notifications

Answer: C

Explanation:
Step by Step Comprehensive Detailed Explanation:
Access the Admin Console: Sign in to your Google Admin console.
Navigate to the Alert Center: Click on "Security" and then "Alert Center." Create New Alert: In the Alert Center, click on "Manage alerts" and then "Add alert rule." Configure Alert Rule: Select "User's password changed" as the event type.
Include Compliance Team: In the alert configuration, add the compliance team's email addresses to the notification recipients.
Save the Alert: Save the configuration to ensure the compliance team is informed every time a user changes their password.
Reference:
Google Workspace Admin Help: Alert Center


NEW QUESTION # 49
You have configured Secure Transport (TLS) Compliance for all messages coming to and from an external domain, altostrat.com, that your end users communicate with via Gmail. What will your end users experience when messages are delivered to them from altostrat.com without TLS enabled?

  • A. The message will not be delivered to the end user in any form.
  • B. The user will receive a failure message informing them that the message could not be delivered to their inbox and that they will need to work with their Workspace administrator to resolve the issue.
  • C. The message will be delivered to their spam folder.
  • D. A warning banner will appear on the message informing the user that the message was not sent securely.

Answer: A

Explanation:
Incoming messages from non-TLS connections are rejected without any notification to you. The sender gets a non-delivery report.
https://support.google.com/a/answer/2520500?hl=en#zippy=%2Cunderstand-what-happens-to- messages-sent-to-or-from-servers-that-dont-use-tls


NEW QUESTION # 50
User A is a Basic License holder. User B is a Business License holder. These two users, along with many additional users, are in the same organizational unit at the same company. When User A attempts to access Drive, they receive the following error: "We are sorry, but you do not have access to Google Docs Editors. Please contact your Organization Administrator for access." User B is not presented with the same error and accesses the service without issues.
How do you provide access to Drive for User A?

  • A. Select User A in the Directory, and under the Apps section, check whether Drive and Docs is disabled. If so, enable it in the User record.
  • B. In Apps > Google Workspace > Drive and Docs, select the organizational unit the users are in and enable Drive for the organizational unit.
  • C. In Apps > Google Workspace, determine the Group that has Drive and Docs enabled as a service. Add User A to this group.
  • D. Select User A in the Directory, and under the Licenses section, change their license from Basic to Business to add the Drive and Docs service.

Answer: D

Explanation:
Access the Admin Console: Log into your Google Workspace Admin Console.
Select User A: Navigate to the Directory and select User A's account.
Check Licenses: Under the Licenses section, check the current license type of User A. As User A holds a Basic License, they lack access to certain services available to Business License holders.
Change License: Change User A's license from Basic to Business. This can be done by assigning the Business License to User A within the Licenses section.
Verify Access: After changing the license, verify that User A can now access Google Drive and Docs without any errors.
Reference
Google Support: Assign or remove a user license


NEW QUESTION # 51
Your organization has a strict requirement that your temporary employees can only send emails to and receive emails from specific external domains You must define a policy in Google Workspace that meets this requirement for users in the temporary employee organizational unit (OU) What should you do?

  • A. Restrict sending and receiving to Google Groups, and carefully curate the temporary employees" memberships
  • B. Add the allowed domains when configuring the restrict delivery setting in Gmail settings, and select the box to bypass for internal emails
  • C. Create a policy in Gmail settings that rewrites the recipient for outbound messages and quarantines incoming messages to review before delivery
  • D. Configure the restrict delivery setting to limit domains that the temporary employees can communicate with Allow Google Docs sharing

Answer: B

Explanation:
* Access the Admin Console: Sign in to your Google Admin console.
* Navigate to Apps: Click on "Apps" and then "Google Workspace."
* Select Gmail: In the Google Workspace section, click on "Gmail."
* Gmail Settings: Click on "Compliance" under the "Advanced settings" section.
* Restrict Delivery Setting: Scroll down to the "Restrict delivery" section and click "Configure."
* Define Policy: Enter the specific external domains you want to allow the temporary employees to communicate with.
* Bypass for Internal Emails: Make sure to select the option to bypass the restriction for internal emails, ensuring internal communication is not affected.
* Apply to OU: Apply this setting to the organizational unit (OU) containing the temporary employees.
* Save the Configuration: Save the changes and ensure the policy is active.
References:
* Google Workspace Admin Help: Set up compliance rules for Gmail


NEW QUESTION # 52
Your company is using Google Workspace Business Plus edition, and the security team has reported several unsuccessful attempts to sign in to your Google Workspace domain from countries where you have no local employees. The affected accounts are from several executives in the main office.
You are asked to take measures to mitigate this security risk. Although budget is not a concern, your company prefers a minimal financial outlay to fix the issue, which you are tasked with managing. Which two solutions would help you mitigate the risk at minimal cost?
Choose 2 answers

  • A. For all executives, create new accounts with random characters to match Google best practices, migrate
  • B. Subscribe to Cloud Identity Premium for all accounts, and define Context-Aware Access levels to only a list of countries where the company has employees.
  • C. Deploy 2-Step Verification for all users who have security keys.
  • D. Upgrade to Google Workspace Enterprise Plus for all accounts, and define Context-Aware Access levels to only a list of countries where the company has employees.
  • E. Deploy Google Cloud Armor on a dedicated project, and create a rule to allow access to Google Workspace only from specific locations.

Answer: C,D

Explanation:
data from the former accounts, and then delete them.


NEW QUESTION # 53
You are configuring Chrome browser security policies for your organization. These policies must restrict certain Chrome apps and extensions.
You need to ensure that these policies are applied on the devices regardless of which user logs into the device.
What should you do?

  • A. Configure the Policy Precedence to override the domain-wide policy applied for apps and extensions.
  • B. Configure the Chrome user setting to require users to sign in to use Chrome apps and extensions.
  • C. Configure the allowed list of apps in the Devices page in the apps and extensions settings.
  • D. Require 2SV for user logins.

Answer: C

Explanation:
To ensure that Chrome apps and extension policies are applied regardless of which user logs into the device, you should configure the allowed list of apps in the Devices section of the apps and extensions settings. This policy applies at the device level, ensuring that the restrictions are enforced for any user who logs into that device, providing consistent security across the organization.


NEW QUESTION # 54
Your organization deployed Google Workspace Enterprise within the last year, with the support of a partner. The deployment was conducted in three stages: Core IT, Google Guides, and full organization. You have been tasked with developing a targeted ongoing adoption plan for your Google Workspace organization.
What should you do?

  • A. Use Reports APIs to gather adoption metrics and Gmail APIs to deliver training content directly.
  • B. Use Work Insights to gather adoption metrics and target your training exercises.
  • C. Use Google Guides to deliver ad-hoc training to all of their co-workers and reports.
  • D. Use a script to monitor Email attachment types and target users that aren't using Drive sharing.

Answer: C

Explanation:
[https://static.googleusercontent.com/media/www.google.com/en//support/enterprise/static/gapps/docs/admin/en/gapps_transition/gapps_transition_guide.pdf] identifies Google Guides as early adopters and champions that can help co-workers get up to speed quickly


NEW QUESTION # 55
Your organization's information security team has asked you to determine and remediate if a user ([email protected]) has shared any sensitive documents outside of your organization. How would you audit access to documents that the user shared inappropriately?

  • A. Have the super administrator use the Security API to audit Drive access.
  • B. As a super administrator, change the access on externally shared Drive files manually under [email protected].
  • C. Open Security Dashboard-> File Exposure Report-> Export to Sheet, and filter for [email protected].
  • D. Open Security Investigation Tool-> Drive Log Events. Add two conditions: Visibility Is External, and Actor Is [email protected].

Answer: D

Explanation:
To audit if [email protected] has shared any sensitive documents outside the organization, use the Security Investigation Tool in the Google Admin console. This tool allows administrators to investigate and take action on security issues within the organization.
* Open Security Investigation Tool:
* Go to the Google Admin console.
* Navigate to Security > Investigation tool.
* Set Conditions in Drive Log Events:
* In the Investigation Tool, select the data source as "Drive Log Events".
* Add the following conditions:
* Visibility Is External: This filters the events to show only documents that have been shared externally.
* Actor Is [email protected]: This specifies that the actions performed by the [email protected] should be displayed.
* Run the Investigation:
* Click on "Search" to run the investigation with the specified conditions.
* Review the results to identify any documents that have been shared externally by the user.
* Remediate:
* For any documents that were shared inappropriately, you can take corrective actions such as changing permissions or removing external sharing.
References:
* Security Investigation Tool
* Audit Drive log events


NEW QUESTION # 56
Your company has been engaged in a lawsuit, and the legal department has been asked to discover and hold all email for two specific users. Additionally, they have been asked to discover and hold any email referencing "Secret Project 123." What steps should you take to satisfy this request?

  • A. Create a Matter and a Hold.
    Set the Hold to Gmail, set it to the top level Organization, and set the search terms to "secret project 123." Create a second Hold.
    Set the second Hold to Gmail, set it to Accounts, and enter: user1 @your-company.com, [email protected].
    Save.
  • B. Create a Matter and a Hold.
    Set the Hold to Gmail, set it to Accounts, and enter: [email protected] AND [email protected].
    Set the search terms to: secret AND project AND 123.
    Save.
  • C. Create a Matter and a Hold.
    Set the Hold to Gmail, set it to Accounts, and set the usernames to:
    [email protected], user2@your-company.
    Set the search terms to secret OR project OR 123.
    Save.
  • D. Create a Matter and a Hold.
    Set the Hold to Gmail, set it to Accounts, and set the usernames to:
    [email protected], user2@your-company.
    Set the search terms to: (secret project 123).
    Save.

Answer: A

Explanation:
The correct way to search for the esact term is in quotes ("project 123" and not (project 123)).
Ref: https://support.google.com/vault/answer/2474474?hl=en.
Also, afeter doing this ytou must create the retention rule using comas to separate user from user.


NEW QUESTION # 57
Your organization collects credit card information in customer files. You need to implement a policy for your organization's Google Drive data that prevents the accidental sharing of files that contain credit card numbers with external users. You also need to record any sharing incidents for reporting. What should you do?

  • A. Enable Gmail content compliance, and create a rule to block email attachments containing credit card numbers from being sent to external recipients.
  • B. Implement a third-party data loss prevention solution to integrate with Drive and provide advanced content detection capabilities.
  • C. Configure a data retention policy to automatically delete files containing credit card numbers after a specified period.
  • D. Create a data loss prevention (DLP) rule that uses the predefined credit card number detector, sets the action to "block external sharing", and enables the "Log event" option.

Answer: D

Explanation:
A data loss prevention (DLP) rule with the predefined credit card number detector will help you identify and prevent the accidental sharing of files that contain sensitive credit card information. Setting the action to
"block external sharing" ensures that such files cannot be shared externally. Enabling the "Log event" option will record any incidents of external sharing for auditing and reporting purposes, fulfilling both the security and reporting requirements.


NEW QUESTION # 58
After a recent transition to Google Workspace, helpdesk has received a high volume of password reset requests and cannot respond in a timely manner. Your manager has asked you to determine how to resolve these requests without relying on additional staff.
What should you do?

  • A. Enable non-admin password recovery.
  • B. Use a third-party tool for password recovery.
  • C. Create a Google form to submit reset requests.
  • D. Create a custom Apps Script to reset passwords.

Answer: A

Explanation:
Reference: https://support.google.com/a/answer/33382?hl=en


NEW QUESTION # 59
A company using Google Workspace has reports of cyber criminals trying to steal usernames and passwords to access critical business data.
You need to protect the highly sensitive user accounts from unauthorized access.
What should you do?

  • A. Enforce 2FA with Google Authenticator app.
  • B. Turn on password expiration.
  • C. Use a third-party identity provider.
  • D. Enforce 2FA with a physical security key.

Answer: D

Explanation:
Reference:
https://support.google.com/a/answer/175197?hl=en#keys&prompt&authentic&codes&phone&2sv
&security
https://support.google.com/a/answer/175197?hl=en


NEW QUESTION # 60
Your company frequently hires from five to ten interns for short contract engagements and makes use of the same generically named Google Workspace accounts (e.g., [email protected], [email protected], [email protected]). The manager of this program wants all email to these accounts routed to the manager's mailbox account also.
What should you do?

  • A. Configure an Inbound Gateway route.
  • B. Set up recipient address mapping in GMail Advanced Settings.
  • C. Setup address forwarding in each account's GMail setting menu.
  • D. Give the manager delegated access to the mailboxes.

Answer: B

Explanation:
https://support.google.com/a/answer/6297084#address


NEW QUESTION # 61
The compliance team at your organization is conducting a legal investigation into some concerning sales activities of an employee eight months ago. The compliance team contacted you for assistance on the situation. You set up the default Google Vault retention rules so all data is retained only for one year. You must assist the compliance team with the investigation. What should you do?

  • A. Assign the compliance team a Google Vault administrator role and change the default retention rules to three years.
  • B. Assign the compliance team a Google Vault administrator role and create a legal hold for the employee.
  • C. Suspend the employee and export all data by using Google Takeout.
  • D. Do nothing. The retention period has already ended and the evidence has already been purged.

Answer: B


NEW QUESTION # 62
Your organization implemented Single Sign-On (SSO) for the multiple cloud-based services it uses. During authentication, one service indicates that access to the SSO provider is not possible due to invalid information. What should you do?

  • A. Ensure that Microsoft's Active Directory Federation Services 2.0 sends encrypted SAML Responses in default configurations.
  • B. Verify that the Audience element in the SAML Response matches the assertion consumer service (ACS) URL
  • C. Update the validation certificate.
  • D. Run nslookup to confirm that the service exists.

Answer: B


NEW QUESTION # 63
A user does not follow their usual sign-in pattern and signs in from an unusual location.
What type of alert is triggered by this event?

  • A. User sign-in alert.
  • B. Leaked password alert.
  • C. Suspicious mobile activity alert.
  • D. Suspicious login activity alert.

Answer: D


NEW QUESTION # 64
Your company is using Google Workspace Business Standard. The company has five meeting rooms that are all registered as resources in Google Workspace and used on a daily basis by the employees when organizing meetings. The office layout was changed last weekend, and one of the meeting rooms is now a dedicated room for management. The CEO is complaining that anyone can book the room and requested this room to be used only by the management team and their executive assistants (EAs). No one else must be allowed to book it via Google Calendar. What should you do?

  • A. As a super administrator, create a group calendar named "Management Room," and share it only with the management and the EAs.
  • B. As a super administrator, modify the room calendar sharing settings, and limit it to the management and EAs group.
  • C. Move the room resource to the management and EAs group so that only they can use it.
  • D. Delete the room from Google Workspace resources, and suggest using a spreadsheet shared with the management and EAs only for the room schedule.

Answer: B

Explanation:
* Access Room Calendar Settings:
* Navigate to the Google Admin console.
* Go to Buildings and resources > Manage resources.
* Find and select the specific meeting room.
* Modify Sharing Settings:
* Click on the room resource to open its settings.
* Under "Sharing settings," restrict access to the management and EAs group.
* Ensure only these groups have the permission to book the room.
* Save Changes:
* Save the updated settings to apply the new restrictions.
This ensures that only the designated group members can book the management room via Google Calendar.
References
* Google Workspace Admin Help: Control Room Booking


NEW QUESTION # 65
With the help of a partner, you deployed Google Workspace last year and have seen the rapid pace of innovation and development within the platform. Your CIO has requested that you develop a method of staying up-to-date on all things Google Workspace so that you can be prepared to take advantage of new features and ensure that your organization gets the most out of the platform.
What should you do?

  • A. Create a Feature Release alert in the Alert Center to be alerted to new functionality.
  • B. Develop a cadence of regular roadmap and business reviews with your partner.
  • C. Put half of your organization on the Rapid Release Schedule to highlight differences.
  • D. Regularly scan the admin console and keep track of any new features you identify.

Answer: B

Explanation:
Schedule regular meetings with your Google Workspace partner.
During these meetings, review the Google Workspace roadmap and upcoming features.
Discuss how new features can be leveraged to benefit your organization.
Plan business reviews to ensure that you are making the most of the platform's capabilities and staying up-to-date with developments.
Establishing a regular cadence of roadmap and business reviews ensures continuous alignment with the latest Google Workspace innovations and allows your organization to take full advantage of new features.
Reference:
Google Workspace Admin Help - Google Workspace Partners


NEW QUESTION # 66
......

Updated Official licence for Google-Workspace-Administrator Certified by Google-Workspace-Administrator Dumps PDF: https://www.exam-killer.com/Google-Workspace-Administrator-valid-questions.html

New 2025 Realistic Google-Workspace-Administrator Dumps Test Engine Exam Questions in here: https://drive.google.com/open?id=1J227fRp_BYy8ByMAbFn-A001ceYxFCBn