The Best Practice Test Preparation for the Google-Workspace-Administrator Certification Exam Google-Workspace-Administrator Exam Dumps, Practice Test Questions BUNDLE PACK Google Workspace Administrator certification exam is a challenging exam that requires a deep understanding of Google Workspace services and their administration. To prepare for the exam, candidates can take advantage of various study [...]

The Best Practice Test Preparation for the Google-Workspace-Administrator Certification Exam [Q38-Q63]

Share

The Best Practice Test Preparation for the Google-Workspace-Administrator Certification Exam

Google-Workspace-Administrator Exam Dumps, Practice Test Questions BUNDLE PACK


Google Workspace Administrator certification exam is a challenging exam that requires a deep understanding of Google Workspace services and their administration. To prepare for the exam, candidates can take advantage of various study materials such as online courses, practice exams, and study guides. Successful completion of the Google Workspace Administrator certification exam will demonstrate the candidate's expertise in administering and managing Google Workspace and will enhance their career prospects in the field of cloud computing.

 

NEW QUESTION # 38
A user joined your organization and is reporting that every time they start their computer they are asked to sign in. This behavior differs from what other users within the organization experience. Others are prompted to sign in biweekly. What is the first step you should take to troubleshoot this issue for the individual user?

  • A. Check the session length duration for the organizational unit the user is provisioned in.
  • B. Verify that 2-Step Verification is enforced for this user.
  • C. Reset the user's sign-in cookies
  • D. Confirm that this user has their employee ID populated as a sign-in challenge.

Answer: A

Explanation:
The first step to troubleshoot this issue is to check the session length duration for the organizational unit the user is provisioned in. Differences in session length settings can cause variations in how often users are prompted to sign in.
Go to the Admin console.
Navigate to Security > Settings.
Under Session control, check the session length settings for the organizational unit.
Adjust the session length duration if necessary to match the organization's standard setting.
Reference:
Google Workspace Admin Help: Control session length


NEW QUESTION # 39
As a team manager, you need to create a vacation calendar that your team members can use to share their time off. You want to use the calendar to visualize online status for team members, especially if multiple individuals are on vacation What should you do to create this calendar?

  • A. Create a secondary calendar under your account, and give your team "Make changes to events" access.
  • B. Request the creation of a calendar resource, configure the calendar to "Auto-accept invitations that do not conflict," and give your team "See all event details" access.
  • C. Create a secondary calendar under your account, and give your team "See only free/busy" access
  • D. Request the creation of a calendar resource, configure the calendar to "Automatically add all invitations to this calendar," and give your team "See only free/busy" access.

Answer: D

Explanation:
https://support.google.com/a/answer/1034381?hl=en#:~:text=Automatically%20add%20all%20invitations%20to%20this%20calendar%E2%80%94All%20invitations%20show%20up%20on%20the%20resource%27s%20calendar%20even%20if%20some%20of%20them%20are%20for%20events%20that%20take%20place%20at%20the%20same%20time.


NEW QUESTION # 40
You are configuring Chrome browser security policies for your organization. These policies must restrict certain Chrome apps and extensions.
You need to ensure that these policies are applied on the devices regardless of which user logs into the device.
What should you do?

  • A. Configure the allowed list of apps in the Devices page in the apps and extensions settings.
  • B. Require 2SV for user logins.
  • C. Configure the Policy Precedence to override the domain-wide policy applied for apps and extensions.
  • D. Configure the Chrome user setting to require users to sign in to use Chrome apps and extensions.

Answer: A

Explanation:
To ensure that Chrome apps and extension policies are applied regardless of which user logs into the device, you should configure the allowed list of apps in the Devices section of the apps and extensions settings. This policy applies at the device level, ensuring that the restrictions are enforced for any user who logs into that device, providing consistent security across the organization.


NEW QUESTION # 41
Your organization has a group of users who interact with sensitive information and their accounts contain valuable files You need to protect these users from targeted online attacks What should you do?

  • A. Disable password recovery for end users
  • B. Enroll all accounts for those users in the Advanced Protection Program
  • C. Enable 2-Step Verification for those users and recommend they use Google Authenticator
  • D. Enable 2-Step Verification for those users and recommend they use SMS codes

Answer: B

Explanation:
* Understanding the Requirement:
* The scenario involves a group of users who handle sensitive information and have valuable files in their accounts.
* The goal is to protect these users from targeted online attacks.
* Options Analysis:
* Option A: Enable 2-Step Verification for those users and recommend they use Google Authenticator
* 2-Step Verification (2SV) enhances security by adding an extra layer of authentication.
Google Authenticator is a reliable method, but it may not be sufficient against highly targeted attacks.
* Option B: Enable 2-Step Verification for those users and recommend they use SMS codes
* While SMS codes are a form of 2SV, they are considered less secure than other methods due to potential vulnerabilities like SIM swapping.
* Option C: Disable password recovery for end users
* Disabling password recovery can prevent unauthorized access through recovery options but does not provide active protection against targeted attacks.
* Option D: Enroll all accounts for those users in the Advanced Protection Program
* The Advanced Protection Program (APP) is designed specifically to protect users at high risk of targeted attacks. It includes strong measures such as requiring a physical security key for login, blocking unauthorized access attempts, and restricting access to sensitive data.
* Recommended Solution:
* Enrolling users in the Advanced Protection Program (APP):
* Step 1: Identify High-Risk Users:
* Identify users who handle sensitive information and have valuable files.
* Step 2: Enroll in APP:
* Go to the Google Admin console.
* Navigate to the Security section and find the Advanced Protection Program.
* Enroll the identified high-risk users in APP.
* Step 3: Implement Security Keys:
* Ensure users have security keys (e.g., Titan Security Keys) for login.
* Guide users through the process of setting up and using security keys.
* Step 4: User Education:
* Educate users on the importance of APP and how it protects their accounts.
* Provide training on recognizing phishing attempts and other security best practices.
* Benefits of APP:
* Enhanced Security:
* APP provides the highest level of security for Google accounts, requiring security keys for authentication.
* Protection Against Phishing:
* Security keys are highly resistant to phishing attacks, which are common in targeted online attacks.
* Limited Access:
* APP restricts access to sensitive data, ensuring that only trusted apps and services can interact with the protected accounts.
References:
* Google Workspace Admin Help: Advanced Protection Program
* Google Workspace Security: Advanced Protection Program
* Google Security Blog: Advanced Protection Program


NEW QUESTION # 42
Your company has been engaged in a lawsuit, and the legal department has been asked to discover and hold all email for two specific users. Additionally, they have been asked to discover and hold any email referencing "Secret Project 123." What steps should you take to satisfy this request?

  • A. Create a Matter and a Hold.
    Set the Hold to Gmail, set it to the top level Organization, and set the search terms to "secret project 123." Create a second Hold.
    Set the second Hold to Gmail, set it to Accounts, and enter: user1 @your-company.com, [email protected].
    Save.
  • B. Create a Matter and a Hold.
    Set the Hold to Gmail, set it to Accounts, and set the usernames to:
    [email protected], user2@your-company.
    Set the search terms to: (secret project 123).
    Save.
  • C. Create a Matter and a Hold.
    Set the Hold to Gmail, set it to Accounts, and set the usernames to:
    [email protected], user2@your-company.
    Set the search terms to secret OR project OR 123.
    Save.
  • D. Create a Matter and a Hold.
    Set the Hold to Gmail, set it to Accounts, and enter: [email protected] AND [email protected].
    Set the search terms to: secret AND project AND 123.
    Save.

Answer: A

Explanation:
The correct way to search for the esact term is in quotes ("project 123" and not (project 123)).
Ref: https://support.google.com/vault/answer/2474474?hl=en.
Also, afeter doing this ytou must create the retention rule using comas to separate user from user.


NEW QUESTION # 43
Your organization wants more visibility into actions taken by Google staff related to your data for audit and security reasons. They are specifically interested in understanding the actions performed by Google support staff with regard to the support cases you have opened with Google. What should you do to gain more visibility?

  • A. From Google Admin Panel, go to Audit, and select Access Transparency Logs. Most Voted
  • B. From Google Admin Panel, go to Audit, and select Login Audit Log.
  • C. From Google Admin Panel, go to Audit, and select Rules Audit Log.
  • D. From Google Admin Panel, go to Audit, and select Admin Audit Log.

Answer: A

Explanation:
Google staff logs related to accessing user content are stored in Access Transparency logs https://support.google.com/a/answer/9230474?hl=en


NEW QUESTION # 44
Your company's sales team writes many business proposals in Google Docs. They want to streamline the proposal process by using templates. You need to create a document template with pre-populated sections that the sales team can access. What should you do?

  • A. Create the templates in Google Drive. Make a copy for each sales representative. Transfer ownership of each template to the sales representatives.
  • B. Create the templates in Google Drive and download the files as PDFs. Upload PDF files to a drive shared with your sales team.
  • C. Enable organization branding in the Admin console. Create the templates in Google Drive. Add the templates to default themes and templates for the entire organization.
  • D. Create the templates in Google Drive. Grant edit access to the sales team.

Answer: C

Explanation:
To create document templates with pre-populated sections that the sales team can easily access and use to streamline their proposal process, the most efficient and centrally managed approach is to utilize the Google Workspace template gallery. This involves enabling organization branding (though not strictly required for basic templates, it's often associated with organizational templates) and then adding the created templates to the default themes and templates for the entire organization or specific groups.
Here's a breakdown of why option C is correct and why the others are not the ideal solutions:
C). Enable organization branding in the Admin console. Create the templates in Google Drive. Add the templates to default themes and templates for the entire organization.
This option leverages the built-in template gallery feature of Google Workspace. By creating the templates in Google Docs (which are stored in Google Drive) and then adding them to the organization's default themes and templates through the Google Admin console, you make these templates easily discoverable by all users (or a specific organizational unit) when they go to create a new document from the template gallery. Enabling organization branding can help customize the look and feel, but the crucial part is adding the templates to the gallery.
Associate Google Workspace Administrator topics guides or documents reference: The official Google Workspace Admin Help documentation provides detailed instructions on "Create and manage document templates for your organization." This documentation explains how to prepare a document as a template in Google Drive and then submit it through the Admin console to the template gallery, making it available to users within the organization. Topics covered include:Submitting templates to your organization's gallery:
This process involves going to Apps > Google Workspace > Drive and Docs > Templates in the Admin console.
Setting up a custom template gallery: The documentation guides administrators on how to manage the templates that appear for their users.
Organizational units: Templates can often be made available to specific organizational units, allowing for tailored templates for different teams like the sales team.
A). Create the templates in Google Drive. Grant edit access to the sales team.
Granting edit access to the sales team on the master templates is problematic. It could lead to accidental or intentional modifications of the original templates, causing inconsistencies and requiring ongoing management to ensure the templates remain in their intended state. Users should ideally create copies of the template to work on, leaving the original template untouched.
Associate Google Workspace Administrator topics guides or documents reference: Best practices for file sharing and collaboration in Google Drive emphasize providing appropriate levels of access. For templates, the goal is usually for users to use the template to create new documents, not to edit the original.
B). Create the templates in Google Drive. Make a copy for each sales representative. Transfer ownership of each template to the sales representatives.
This approach is inefficient and difficult to manage. Creating and transferring ownership of individual copies of the template to each sales representative would be time-consuming for the administrator. Furthermore, if the template needs to be updated, each individual copy would need to be modified, leading to version control issues and inconsistencies across the sales team.
Associate Google Workspace Administrator topics guides or documents reference: Google Drive's sharing and ownership features are designed for collaborative work on documents, not for distributing and managing templates in this manner. Centralized management through the template gallery is the recommended method.
D). Create the templates in Google Drive and download the files as PDFs. Upload PDF files to a drive shared with your sales team.
Saving the templates as PDFs defeats the purpose of having editable templates. The sales team would not be able to easily modify the pre-populated sections or add their specific proposal details to a PDF. Templates are meant to be starting points for new, editable documents.
Associate Google Workspace Administrator topics guides or documents reference: Google Docs is designed for creating and editing documents. Templates are a feature within this editable format, allowing users to start with a pre-structured document that they can then customize. PDFs are for final, non-editable versions.
Therefore, the correct approach is to leverage the Google Workspace template gallery to provide a streamlined and centrally managed way for the sales team to access and use the proposal templates. This is achieved by creating the templates in Google Drive and then adding them to the organizational templates through the Admin console. While enabling organization branding is mentioned in option C, the core functionality relies on the template gallery feature.


NEW QUESTION # 45
The Google Analytics service is set to OFF for your entire organization. All users in the marketing team OU and a subset of users in the sales OU need access to Analytics. The rest of the organization should not have access. You must configure access in Additional Google services.
What should you do?

  • A. Enable Google Analytics for the marketing and sales OUs. Create a group to deny access to Google Analytics and assign it to the sales users who should not have access.
  • B. Enable Google Analytics for the marketing OU. Create a group from the Admin console that includes the sales users, and set Google Analytics to On for that group.
  • C. Enable Google Analytics for the marketing OU. Create a sub-OU for the sales users under the marketing OU.
  • D. Enable Google Analytics at the top of the OU structure.

Answer: B

Explanation:
This is the most efficient solution as it directly targets the users who need access without unnecessary complications.


NEW QUESTION # 46
Your organization is in the process of deploying Google Drive for desktop so that your users can access Drive files directly from their desktops. For security reasons, you want to restrict Drive for desktop to only company-owned devices. What two steps should you take from the admin panel to restrict Drive for desktop to only company-owned devices? (Choose two.)

  • A. Install the Google Endpoint Verification extension on machines using Drive for Desktop.
  • B. Create a company-owned device inventory using an asset tag.
  • C. Apps > Google Workspace > Drive and Docs > Features and Applications > Google Drive for Desktop > Only Allow Google Drive for desktop on authorized devices
  • D. Create a company-owned device inventory using serial numbers of devices.
  • E. Devices > Endpoints > Add a filter > Management Type > Drive for desktop > Apply

Answer: C,D

Explanation:
https://support.google.com/a/answer/9299541?hl=en


NEW QUESTION # 47
Your organization has offices in Canada, Italy, and the United States. You want to ensure that employees can access corporate Gmail and Drive from these three geographic locations only.
What should you do?

  • A. Create data protection rules in Google Workspace that allow data access from only three geographic locations.
  • B. Create address lists to restrict the delivery of incoming and outgoing messages, and to block notifications from Google Doc comments.
  • C. Use context-aware access to create access levels based on the geographic location, and assign them to corporate Gmail and Drive.
  • D. Require the use of corporate devices for any access to corporate Gmail and Drive.

Answer: C


NEW QUESTION # 48
The Google Analytics service is set to OFF for your entire organization All users in the marketing team OU and a subset of users in the sales OU need access to Analytics The rest of the organization should not have access You must configure access in Additional Google services What should you do?

  • A. Enable Google Analytics for the marketing OU Create a group from the Admin console that includes the sales users, and set GoogleAnalytics to On for that group
  • B. Enable Google Analytics for the marketing OU. Create a sub-OU for the sales users under the marketing OU
  • C. Enable Google Analytics for the marketing and sales OUs Create a group to deny access to Google Analytics and assign it to the sales users who should not have access
  • D. Enable Google Analytics at the top of the OU structure
  • E. Enable Google Analytics for the marketing OU Create a group from the Admin console that includes the sales users, and set GoogleAnalytics to On for that group The Google Analytics service is set to OFF for your entire organization All users in the marketing team OU and a subset of users in the sales OU need access to Analytics The rest of the organization should not have access You must configure access in Additional Google services What should you do?
  • F. Enable Google Analytics for the marketing OU. Create a sub-OU for the sales users under the marketing OU
  • G. Enable Google Analytics at the top of the OU structure
  • H. Enable Google Analytics for the marketing and sales OUs Create a group to deny access to Google Analytics and assign it to the sales users who should not have access

Answer: E

Explanation:
* Access Admin Console: Log in to the Google Admin console using your administrator account.
* Navigate to Additional Google Services: Go to Apps > Additional Google services > Google Analytics.
* Enable for Marketing OU: Select the marketing OU and turn on Google Analytics.
* Create Group for Sales Users: Go to Directory > Groups and create a new group for the sales users who need access to Google Analytics.
* Assign Google Analytics Access: In the Google Analytics settings, turn on access for the newly created sales group.
* Verify Settings: Ensure that only users in the marketing OU and the specific sales group have access to Google Analytics while the rest of the organization does not.
References:
* Google Workspace Admin Help: Turn Additional Google services On or Off
* Google Workspace Service Access Management


NEW QUESTION # 49
Your company is using Google Workspace Enterprise Plus, and the Human Resources (HR) department is asking for access to Work Insights to analyze adoption of Google Workspace for all company employees. You assigned a custom role with the work Insights permission set as "view data for all teams" to the HR group, but it is reporting an error when accessing the application. What should you do?

  • A. Allocate the "view data for all teams" permission to all employees of the company.
  • B. Confirm in Reports > BigQuery Export that the job is enabled.
  • C. Confirm that the Work Insights app is turned ON for all employees.
  • D. Confirm in Security > API controls > App Access Controls that Work Insights API is set to "unrestricted."

Answer: C

Explanation:
Access Admin Console: Log in to the Google Admin console.
Navigate to Work Insights Settings: Go to Apps > Additional Google services > Work Insights.
Turn On Work Insights: Ensure that the Work Insights app is enabled for all employees in the organization.
Verify Permissions: Confirm that the custom role with "view data for all teams" permission is correctly assigned to the HR group.
Test Access: Ask HR users to try accessing Work Insights again to ensure that the error is resolved.
Monitor and Review: Monitor the access and usage to ensure that HR can analyze the adoption of Google Workspace without further issues.
Reference:
Google Workspace Admin Help - Turn Work Insights On or Off
Google Workspace Admin Help - Work Insights Permissions


NEW QUESTION # 50
Your CISO is concerned about third party applications becoming compromised and exposing Google Workspace data you have made available to them. How could you provide granular insight into what data third party applications are accessing?
What should you do?

  • A. Create a report using the OAuth Token Audit Activity logs.
  • B. Create a reporting using the API Permissions logs for Installed Apps.
  • C. Create a report using the Drive Audit Activity logs.
  • D. Create a report using the Calendar Audit Activity logs.

Answer: A

Explanation:
* Access Admin Console: Log into your Google Workspace Admin Console.
* Navigate to Reports: Go to the Reports section within the Admin Console.
* OAuth Token Audit Log: Access the OAuth Token Audit Activity logs. This log provides detailed information about third-party applications that have been granted access to your Google Workspace data.
* Review Data Access: Review the logs to see which applications have accessed what type of data. This includes details on the scopes of access requested by the applications.
* Generate Report: Create a report from these logs to provide granular insight into the data accessed by third-party applications. This report can be used to assess and mitigate any potential risks.
References
* Google Support: Token audit log


NEW QUESTION # 51
You are in the middle of migrating email from on-premises Microsoft Exchange to Google Workspace. Users that you have already migrated are complaining of messages from internal users going into spam folders. What should you do to ensure that internal messages do not go into Gmail spam while blocking spoofing attempts?

  • A. Force TLS for your domain.
  • B. Add all users of your domain to an approved sender list.
  • C. Ensure that your inbound gateway is configured with all of your Exchange server IP addresses.
  • D. Train users to click on Not Spam button for emails.

Answer: C

Explanation:
* Inbound Gateway Configuration:
* An inbound mail gateway ensures that all incoming emails are routed through specified servers.
* Configuring the inbound gateway to recognize your Exchange server IP addresses prevents internal emails from being marked as spam.
* Steps to Configure:
* Go to the Google Admin console.
* Navigate to Apps > Google Workspace > Gmail > Advanced settings.
* Scroll to the "Spam, Phishing, and Malware" section.
* Configure the "Inbound Gateway" settings:
* Add your Exchange server IP addresses.
* Ensure these addresses are listed as trusted sources.
References
* Google Workspace Admin Help: Configure Inbound Mail Gateway


NEW QUESTION # 52
Your company has just received a shipment of ten Chromebooks to be deployed across the company, four of which will be used by remote employees. In order to prepare them for use, you need to register them in Google Workspace.
What should you do?

  • A. In Chrome Management | Device Settings, enable Forced Re-enrollment for all devices.
  • B. Instruct the employees to log in to the Chromebook. Upon login, the auto enrollment process will begin.
  • C. Turn on the Chromebook and press Ctrl+Alt+E at the login screen to begin enterprise enrollment.
  • D. Turn on the chromebook and log in as a Chrome Device admin. Press Ctrl+Alt+E to begin enterprise enrollment.

Answer: C


NEW QUESTION # 53
You want to create a list of IP addresses that are approved to send email to your domain. To accomplish this, what section of the Google Workspace Admin console should you update?

  • A. Content compliance rule
  • B. Email allowlist
  • C. Approved email denylist
  • D. Bypass spam filter

Answer: B


NEW QUESTION # 54
You have enabled Automatic Room Replacement for your calendar resources, but it is not working for any instances of a conflict booking. What could be the issue?

  • A. The events have more than 20 attendees.
  • B. This feature requires calendar event owners to have the Buildings and resources administrator privilege
  • C. The calendar resources do not have the Resource Category configured as CONFERENCE_ROOM
  • D. Automatic Room Replacement does not work on recurring events.

Answer: D


NEW QUESTION # 55
Your organization is about to conduct its biannual risk assessment. You need to help identify security risks by quickly reviewing all security settings for Gmail, Drive, and Calendar. What should you do?

  • A. In the reporting section of the Admin console, review the Gmail, Drive, and Calendar reports.
  • B. In each individual organizational unit (OU), review the security settings.
  • C. In the alert center, review all of the alerts.
  • D. In the Google Admin console, review the security health page.

Answer: D

Explanation:
Thesecurity health pagein the Google Admin console provides an overview of security settings and highlights potential risks across various services, including Gmail, Drive, and Calendar. This page offers a consolidated view of the security posture of your organization, making it the most efficient option for quickly identifying security risks in preparation for a risk assessment.


NEW QUESTION # 56
Your organization is increasingly concerned about its environmental impact. You want to assess the environmental impact of using Google Workspace services. Which report should you use?

  • A. Accounts report
  • B. Carbon footprint report
  • C. Apps Monthly Uptime report
  • D. Google Environmental Report

Answer: B

Explanation:
To assess the environmental impact of using Google Workspace services, you should refer to the Google Environmental Report. Google publishes comprehensive reports detailing its environmental efforts, including the energy efficiency of its data centers, its use of renewable energy, and its overall carbon footprint, which includes the impact of services like Google Workspace.
Here's why option B is the correct choice and why the others are not relevant to assessing the overall environmental impact of using Google Workspace:
B). Google Environmental Report
Google regularly publishes detailed environmental reports that cover various aspects of its sustainability initiatives, including its progress towards using renewable energy, its efforts to improve energy efficiency in its operations (which power Google Workspace), and its overall carbon footprint. These reports provide insights into the environmental impact associated with using Google services.
Associate Google Workspace Administrator topics guides or documents reference: While there might not be a specific "Google Workspace Environmental Impact Report" as a standalone document within the Admin console, Google's overarching "Environmental Report" (often found on Google's sustainability or environmental responsibility websites) encompasses the infrastructure and practices that support all Google services, including Google Workspace. Administrators looking for this information would be directed to these publicly available Google reports.
A). Carbon footprint report
While the concept of a "carbon footprint report" is relevant to environmental impact, Google typically includes this information within its broader "Environmental Report" rather than providing a separate report specifically for Google Workspace usage within an organization's Admin console. You would likely find data related to the carbon efficiency of Google's infrastructure in their main environmental disclosures.
Associate Google Workspace Administrator topics guides or documents reference: Google's communication about its carbon footprint and environmental efforts is usually consolidated in their public sustainability reports.
C). Apps Monthly Uptime report
The Apps Monthly Uptime report provides information about the reliability and availability of Google Workspace services. It focuses on service performance and uptime metrics, not on environmental impact or sustainability.
Associate Google Workspace Administrator topics guides or documents reference: The Google Workspace Admin Help documentation on service-level agreements (SLAs) and service status provides information about uptime guarantees and how to monitor service availability, which is the focus of the Apps Monthly Uptime report.
D). Accounts report
The Accounts report in the Google Admin console provides details about user accounts within your organization, such as the number of active users, account status, and other user-related information. It does not contain any data or analysis related to the environmental impact of using Google Workspace services.
Associate Google Workspace Administrator topics guides or documents reference: The Google Workspace Admin Help documentation on reporting and user accounts describes the information available in the Accounts report, which is focused on user management and activity metrics.
Therefore, to assess the environmental impact of using Google Workspace services, your organization should refer to the publicly available Google Environmental Report, which details Google's sustainability efforts and overall environmental performance.


NEW QUESTION # 57
A company has reports of users sharing sensitive Google Drive content outside their domain through third-party add-ons. You need to control which third-party apps are allowed to access users' Google Workspace data. Which security feature should you use to achieve this?

  • A. In the Drive SDK section, clear 'Allow users to access Google Drive with the Drive SDK API.'
  • B. Block specific API scopes for each user.
  • C. OAuth Whitelisting
  • D. Configure DLP policies to prevent sharing of sensitive content with external parties.

Answer: C

Explanation:
A is correct because, when using OAuth Whitelisting, admins specifically select which third-party apps are allowed to access users' G Suite data.
B is not correct because DLP is used to scan and protect sensitive files and not to prevent granting access to third-party apps.
C is not correct because this setting does not affect apps from the G Suite Marketplace.
D is not correct because API Scopes cannot be specified on a per user
basis.
Reference:
https://www.blog.google/products/g-suite/manage-access-third-party-apps-new-g-suite-security- controls/


NEW QUESTION # 58
Your company wants to start using Google Workspace for email. Your domain is verified through a third- party provider. You need to route the email to Google Workspace. What should you do?

  • A. Update your domain's MX records to the Google Workspace MX records provided in the setup instructions.
  • B. Create a CNAME record that maps your domain to "gmail.com."
  • C. Configure a forwarding rule in your current email system to redirect all messages to Gmail.
  • D. Change your domain's A record to point to Google's mail servers.

Answer: A

Explanation:
To route your email to Google Workspace, you need to update your domain'sMX (Mail Exchange) recordsto point to Google's mail servers. This step ensures that emails sent to your domain are delivered to your Google Workspace Gmail accounts. The MX records are provided in the setup instructions during the Google Workspace configuration process.


NEW QUESTION # 59
An employee has been leaking confidential salary information to an external party. You must use Vault to preserve the messages for an investigation. What should you do?

  • A. Use the search and export features to find all the messages sent externally
  • B. Create a matter and add a hold on the employee's email
  • C. Use the security investigation tool to find the messages Create a hold to preserve the messages
  • D. Create a custom retention policy Use the audit feature to view captured email logs

Answer: B

Explanation:
Access Google Vault: Go to Google Vault from the Google Admin console.
Create a Matter: Click on "Matters" and create a new matter to hold the case details and any relevant information.
Add a Hold: Within the matter, create a hold specifically on the employee's email account. This ensures that all emails sent and received by the employee are preserved.
Configure the Hold: Specify the criteria for the hold, such as the employee's email address, and set the scope to include all messages.
Save the Hold: Once configured, save the hold. This will preserve all relevant messages for the investigation.
Reference:
Google Vault Help: Create and manage matters
Google Vault Help: Place data on hold


NEW QUESTION # 60
You are the administrator for a 30.000-user organization. You have multiple Workspace licensing options available to end users in your domain, according to their work responsibilities. A user may be transitioned to a different license type multiple times in a given year. Your organization has a high turnover rate for employees.
What is the most efficient way to manage your organization's licensing?

  • A. Use Google Cloud Directory Sync to modify user licensing with each sync, according to information available in the organization's LDAP
  • B. Update user licensing in the user portion of the Admin console on an as-needed basis.
  • C. Use the Directory API to create a custom batch script that modifies the users license on a daily basis
  • D. Create a license assignment rule in the Google Admin console to set user licensing based on directory attributes.

Answer: D

Explanation:
To efficiently manage licensing in an organization with a high turnover rate and multiple license types, the best approach is to create a license assignment rule in the Google Admin console based on directory attributes.
This method automates the process of assigning licenses according to the user's role and other directory attributes, ensuring that each user gets the appropriate license type without manual intervention. This approach is scalable and minimizes the administrative overhead associated with frequent changes in user roles and turnover.
References:
* Google Workspace Admin Help - Assign, change, or remove a user's license
* Google Workspace Admin Help - Set up automated user provisioning to third-party applications


NEW QUESTION # 61
An employee at your organization is having trouble playing a video stored in Google Drive that is embedded in their Google Slides presentation. You need to collect the necessary details to troubleshoot the issue. What should you do?

  • A. Confirm that the source video is in a supported format and resolution and that the user has permission to play the video. Have a screen share session to confirm the behavior.
  • B. Instruct the employee to give you edit access to the presentation to review the revision history.
    See if the error message changes when you delete and add the slides back.
  • C. Create a copy of the presentation to see if you can replicate the problem, and document any errors you see.
  • D. Check the Google Drive audit logs for any error entries on the Slides presentation. Check the help center for the appropriate error message.

Answer: A


NEW QUESTION # 62
Your organization wants to grant Google Vault access to an external regulatory authority. In an effort to comply with an investigation, the external group needs the ability to view reports in Google Vault. What should you do?

  • A. Assign an Archived User license to the external users.
  • B. Share Vault access with external users.
  • C. Temporarily assign the super admin role to the users
  • D. Create accounts for external users and assign Vault privileges.

Answer: D

Explanation:
* Create External Accounts: In the Google Admin console, create new Google Workspace accounts for the external regulatory authority members.
* Assign Vault Privileges: Navigate to the Admin roles and assign the necessary Google Vault privileges to these accounts, ensuring they have the access needed to view reports and data for the investigation.
* Configure Security Settings: Ensure that the external users have secure access, potentially with additional security measures such as two-factor authentication.
* Monitor Access: Regularly audit and monitor the activity of the external users to ensure compliance with your organization's data policies and security requirements.
* Revoke Access When Done: Once the investigation is complete, promptly revoke access to ensure continued security of your data.
References:
* Google Vault Help - Assign Vault Privileges
* Google Workspace Admin Help - Add Users


NEW QUESTION # 63
......

Prepare for the Actual Workspace Administrator Google-Workspace-Administrator Exam Practice Materials Collection: https://www.realvalidexam.com/Google-Workspace-Administrator-real-exam-dumps.html

Workspace Administrator Certification Google-Workspace-Administrator Sample Questions Reliable: https://drive.google.com/open?id=1yu78RASm7qiPOufkCzNgz3XEP6hQQMH_