
[Dec 05, 2025] Google-Workspace-Administrator Free Exam Questions with Quality Guaranteed
Google-Workspace-Administrator Free Exam Files Downloaded Instantly
Google Workspace is a cloud-based productivity suite that enables teams to collaborate and communicate effectively. It includes tools like Gmail, Google Drive, Google Docs, Google Sheets, and more. Google Workspace is widely used by businesses of all sizes, educational institutions, and non-profit organizations to streamline their workflows and boost productivity. As the demand for Google Workspace continues to grow, the need for certified professionals who can manage and administer these tools is also increasing.
NEW QUESTION # 33
Your Security Officer ran the Security Health Check and found the alert that "Installation of mobile applications from unknown sources" was occurring. They have asked you to find a way to prevent that from happening.
Using Mobile Device Management (MDM), you need to configure a policy that will not allow mobile applications to be installed from unknown sources.
What MDM configuration is needed to meet this requirement?
- A. In Android Settings, ensure that "Allow non-Play Store apps from unknown sources installation" is unchecked.
- B. In the Application Management menu, configure the whitelist of apps that Android, iOS devices, and Active Sync devices are allowed to install.
- C. In Device Management > Setup > Device Approvals menu, configure the "Requires Admin approval" option.
- D. In the Application Management menu, configure the whitelist of apps that Android and iOS devices are allowed to install.
Answer: A
Explanation:
Reference: https://support.google.com/a/answer/7491893?hl=en
NEW QUESTION # 34
Your organization uses a third-party product to filter mail before it arrives at your Workspace Domain. How should you configure Gmail to ensure that inbound messages are not seen as a spam attack due to the volume of mail being received from this product?
- A. Add the product's IP addresses as an approved sender.
- B. List the IP addresses of the product as an Inbound Gateway.
- C. Add the product's IP addresses to your organization's SPF record.
- D. Allowlist the IP addresses of the third-party filtering product.
Answer: B
NEW QUESTION # 35
The organization has conducted and completed Security Awareness Training (SAT) for all employees. As part of a new security policy, employees who did not complete the SAT have had their accounts suspended. The CTO has requested to be informed of any accounts that have been re-enabled to ensure no one is in violation of the new security policy.
What should you do?
- A. Enable "Suspended user made active" rule and select "Deliver to" Super Administrator(s)
- B. Enable "Suspended user made active" rule - Other Recipients: CTO
- C. Enable "Email settings changed" rule - -Other Recipients: CTO
- D. Enable "Suspicious login" rule - Other Recipients: CTO
Answer: B
Explanation:
Access Admin Console: Log into your Google Workspace Admin Console.
Navigate to Alert Center: Go to Security > Alert Center.
Enable Alert Rule: Find and enable the "Suspended user made active" rule.
Configure Recipients: In the alert rule settings, add the CTO as an additional recipient under the "Other Recipients" section.
Save Settings: Save the configuration. The CTO will now receive notifications whenever a suspended user's account is re-enabled, ensuring compliance with the new security policy.
Reference
Google Support: Alert Center
NEW QUESTION # 36
Your organization has been using Google Workspace for almost a year, and your annual security and risk assessment initiative is approaching. In preparation for the risk assessment, you want to quickly review all the security-related settings for Gmail, Drive, and Calendar, and identify the ones that may be posing risk. What should you do?
- A. Review the Gmail, Drive, and Calendar reports in the Reporting section in the Admin console.
- B. Review the Security health page in the Admin console.
- C. Review all settings for each organizational unit (OU) separately because it is the only way to see the security settings for Workspace apps.
- D. Review all the alerts in the Alert center.
Answer: B
Explanation:
The Security health page in the Security Center provides a centralized overview of security settings and issues across various Google Workspace services, including Gmail, Drive, and Calendar.
NEW QUESTION # 37
Your organization does not allow users to share externally. The security team has recently approved an exemption for specific members of the marketing team and sales to share documents with external customers, prospects, and partners. How best would you achieve this?
- A. Create a configuration group with the approved users as members, and enable external sharing for this group.
- B. Enable external sharing only to allowlisted domains provided by marketing and sales teams.
- C. Create a configuration group with the approved users as members, and use it to create a target audience.
- D. Enable external sharing for the marketing and sales organizational units.
Answer: A
Explanation:
https://support.google.com/a/answer/9224126?hl=en#zippy=%2Coptions-for-configurations-groups:~:text=Using%20configurations%20groups,of%20your%20organization.
NEW QUESTION # 38
Users in your organization are routinely complaining that they receive messages containing words of profanity they find inappropriate in a professional setting. As the administrator, what steps should you take to prevent the messages from being delivered to users' mailboxes?
- A. Configure an attachment compliance rule.
- B. Set up a Gmail DLP policy.
- C. Enable optical character recognition (OCR).
- D. Configure an objectionable content rule.
Answer: D
Explanation:
https://support.google.com/a/answer/1346936?hl=en
NEW QUESTION # 39
Your organization has just appointed a new CISO. They have signed up to receive admin alerts and just received an alert for a suspicious login attempt. They are trying to determine how frequently suspicious login attempts occur within the organization. The CISO has asked you to provide details for each user account that has had a suspicious login attempt in the past year and the number of times it occurred for each account.
What action should you take to meet these requirements?
- A. Create a custom query in BigQuery showing all suspicious login details.
- B. Use the account activity report to export all suspicious login details for analysis.
- C. Use the login audit report to export all suspicious login details for analysis.
- D. Create a custom dashboard with the security investigation tool showing suspicious logins.
Answer: C
Explanation:
Login audit log Track user sign-in activity You can use the Login audit log to track user sign-ins to your domain. You can review all sign-ins from web browsers. If a user signs in from an email client or a non-browser application, you can only review reports of suspicious attempts. Forward log event data to the Google Cloud Platform You can opt in to share the log event data with Google Cloud Platform. If you turn on sharing, data is forwarded to Cloud Logging, where you can query and view your logs, and control how you route and store your logs https://support.google.com/a/answer/4580120?hl=en
NEW QUESTION # 40
Your organization is migrating to Google Workspace and wants to improve how newly created files are classified You must find a scalable solution to improve security and transparency on how to handle sensitive files What should you do?
- A. Set data loss prevention (DLP) policies to label data automatically disable label locking, and educate users
- B. Create classification labels enable automatic classification, and educate users
- C. Integrate with the Cloud DLP API map identifiers and classifications install the Google Drive label client and run the application
- D. Migrate data to Google Workspace map classifications and migrate with the Drive Labels API
Answer: B
Explanation:
Step by Step Comprehensive Detailed Explanation:
Access Admin Console: Log in to the Google Admin console using your administrator account.
Navigate to Labels: Go to Apps > Google Workspace > Drive and Docs > Labels.
Create Classification Labels: Define and create classification labels that correspond to different levels of sensitivity and types of files.
Enable Automatic Classification: Configure settings to enable automatic classification of newly created files based on predefined criteria and patterns.
Educate Users: Conduct training sessions or distribute documentation to educate users on how to use classification labels effectively and understand their importance in maintaining data security.
Reference:
Google Workspace Admin Help: Drive labels
Google Workspace DLP and Classification
NEW QUESTION # 41
A department at your company wants access to the latest AI-powered features in Google Workspace. You know that Gemini offers advanced capabilities and you need to provide the department with immediate access to Gemini's features while retaining control over its deployment to ensure that corporate data is not available for human review. What should you do?
- A. Enable Alpha features for the organization and assign Gemini licenses to all users.
- B. Enable Gemini for the department's organizational unit and assign Gemini licenses to users in the department.
- C. Enable Gemini for non-licensed users in that department so they have immediate access to the free service.
- D. Monitor Gemini adoption through the administrator console and wait for wider user adoption before assigning licenses.
Answer: B
Explanation:
To provide a specific department with immediate access to Gemini's features in Google Workspace while maintaining control and ensuring corporate data privacy, you need to enable Gemini for that department's organizational unit and assign the necessary licenses to the users within that OU. This approach allows for targeted deployment and ensures that the features are used within the governed Google Workspace environment.
Here's why option A is correct and why the others are not the appropriate solutions:
A . Enable Gemini for the department's organizational unit and assign Gemini licenses to users in the department.
Google Workspace allows administrators to manage services and features at the organizational unit (OU) level. By enabling Gemini specifically for the OU of the department that needs it, you grant access only to those users. Assigning Gemini licenses ensures that they have the required entitlements to use the advanced AI features. Importantly, when Gemini is enabled and used within a Google Workspace account with the appropriate controls, the data generated is governed by Google Workspace's data privacy and security commitments, ensuring corporate data is not available for human review in a way that compromises privacy. Administrators have controls over how Gemini for Workspace interacts with organizational data.
Associate Google Workspace Administrator topics guides or documents reference: The Google Workspace Admin Help documentation on "Turn Gemini for Google Workspace on or off for users" (or similar titles) explains how to control access to Gemini features at the organizational unit or group level. It also details the licensing requirements for Gemini for Workspace and how to assign these licenses to specific users. Furthermore, documentation on "Data privacy and security in Gemini for Google Workspace" outlines how user data is handled and protected when using these features within a Google Workspace environment, emphasizing controls to prevent inappropriate human review of corporate data.
B . Monitor Gemini adoption through the administrator console and wait for wider user adoption before assigning licenses.
This approach delays providing the requested access to the department that needs Gemini immediately. Monitoring adoption might be useful for broader rollouts, but it doesn't address the immediate need of the specific department.
Associate Google Workspace Administrator topics guides or documents reference: While the Admin console provides insights into usage and adoption of various Google Workspace services, it doesn't serve as the primary mechanism for granting initial access to new features like Gemini for specific teams.
C . Enable Gemini for non-licensed users in that department so they have immediate access to the free service.
There isn't a "free service" of Gemini directly integrated within Google Workspace that bypasses licensing and organizational controls in the way this option suggests. Gemini for Google Workspace is a licensed feature that needs to be enabled and assigned by the administrator. Enabling features for "non-licensed users" in a corporate environment without proper governance is not a standard or secure practice. It would likely mean users are accessing a consumer version of Gemini, which would not be subject to the same data privacy and security controls as the licensed Google Workspace version, potentially exposing corporate data to human review outside of the organization's policies.
Associate Google Workspace Administrator topics guides or documents reference: Google's documentation on Gemini for Workspace clearly outlines the licensing requirements and the integration within the Google Workspace environment, emphasizing administrative control over its deployment and usage.
D . Enable Alpha features for the organization and assign Gemini licenses to all users.
Enabling Alpha features for the entire organization carries significant risks as these features are still under development and may not be stable or fully secure. Assigning Gemini licenses to all users when only one department needs it is an unnecessary cost and expands the deployment before proper evaluation and targeted rollout. It also doesn't specifically address the need to limit access to the requesting department initially.
Associate Google Workspace Administrator topics guides or documents reference: Google's guidelines on release channels (Rapid, Scheduled, Alpha/Beta) strongly advise against enabling pre-release features like Alpha for production environments due to potential instability and lack of full support. Controlled rollouts to specific OUs are recommended for new features.
Therefore, the most appropriate action is to enable Gemini for the specific organizational unit of the requesting department and assign Gemini licenses to the users within that OU. This provides immediate access while maintaining administrative control and ensuring that the usage of AI features within the Google Workspace environment adheres to the organization's data privacy policies.
NEW QUESTION # 42
Several employees at your company received messages with links to malicious websites. The messages appear to have been sent by your company's human resources department. You need to identify which users received the emails and prevent a recurrence of similar incidents in the future. What should you do?
- A. Collect a list of users who received the messages. Search the recipients' email addresses in Google Vault. Export and download the malicious emails in PST file format. Add the sender's email address to a quarantine list setting in Gmail to quarantine any future emails from the sender.
- B. Search the sender's email address by using Email Log Search. Identify the users that received the messages. Instruct them to mark them as spam in Gmail, delete the messages, and empty the trash.
- C. Search for the sender's email address by using the security investigation tool. Delete the messages. Turn on the safety options for spoofing and authentication protection in Gmail settings.
- D. Search for the sender's email address by using the security investigation tool. Mark the messages as phishing. Add the sender's email address to the Blocked senders list in the Spam, Phishing and Malware setting in Gmail to automatically reject future messages.
Answer: D
Explanation:
The security investigation tool in Google Workspace allows you to identify the impacted users and messages. By marking the messages as phishing, you acknowledge their malicious nature, helping to protect the users. Adding the sender's email address to the Blocked senders list ensures that future messages from this sender will be automatically blocked, preventing recurrence of similar incidents.
NEW QUESTION # 43
You received this email from the head of marketing:
Hello Workspace Admin:
Next week, a new consultant will be starting on the "massive marketing mailing" project. We want to ensure that they can view contact details of the rest of the marketing team, but they should not have access to view contact details of anyone else here at our company. Is this something that you can help with?
What are two of the steps you need to perform to fulfill this request? (Choose two.)
- A. Apply the role of owner to the consultant in the group settings.
- B. Create a group that includes the contacts that the consultant is allowed to view.
- C. Create the consultant inside under the marketing OU.
- D. Create an isolated OU for the consultants who need the restricted contacts access.
- E. Ensure that you have the Administrator Privilege of Services > Services settings and that Services > Contacts > Contacts Settings Message is set.
Answer: B,D
NEW QUESTION # 44
The current data storage limit for the sales organizational unit (OU) at your company is set at 10GB per user.
A subset of sales representatives in that OU need 100GB of storage across shared services. You need to increase the storage for only the subset of sales representatives by using the least disruptive approach and the fewest configuration steps. What should you do?
- A. Create a configuration group, and add the subset of users to that group. Set the group storage limit to
100GB. - B. Move the subset of users to a sub-OU, and assign a 100GB storage limit to that sub-OU.
- C. Change the storage limit of the sales OU to 100GB.
- D. Instruct the subset of users to store their documents in a Shared Drive with a 100GB limit.
Answer: B
Explanation:
By moving the subset of sales representatives to a sub-organizational unit (OU) and assigning a 100GB storage limit to that sub-OU, you can efficiently increase the storage for those users without affecting the rest of the sales team. This approach allows you to target the specific users that require more storage, maintaining minimal disruption and configuration steps.
NEW QUESTION # 45
Your company has a broad, granular IT administration team, and you are in charge of ensuring proper administrative control. One of those teams, the security team, requires access to the Security Investigation Tool. What should you do?
- A. Assign the pre-built security admin role to the security team members.
- B. Create a Custom Admin Role with the Security Center privileges, and then assign the role to each of the security team members.
- C. Create a Custom Admin Role with the security settings privilege, and then assign the role to each of the security team members.
- D. Assign the Super Admin Role to the security team members.
Answer: B
NEW QUESTION # 46
Your organization has recently gone Google, but you are not syncing Groups yet. You plan to sync all of your Active Directory group objects to Google Groups with a single GCDS configuration.
Which scenario could require an alternative deployment strategy?
- A. Some of the Active Directory groups have members external to organization.
- B. Some of the Active Directory groups do not have email addresses.
- C. Some of your Active Directory groups have sensitive group membership.
- D. Some of the Active Directory groups do not have owners.
Answer: C
Explanation:
When planning to sync all Active Directory group objects to Google Groups using Google Cloud Directory Sync (GCDS), you must consider the sensitivity of the group memberships. If some of the groups contain sensitive information or membership, an alternative deployment strategy might be necessary.
* Sensitive Group Membership: If certain groups contain members or data that are sensitive, synchronizing these groups directly might expose this sensitive information to unauthorized users.
* Alternative Strategies:
* Implement separate synchronization settings for sensitive groups.
* Use security groups to control access to sensitive information.
* Manually manage sensitive groups to ensure tight control over membership and data access.
* Steps to Consider:
* Evaluate which groups contain sensitive information.
* Configure GCDS to exclude these sensitive groups from the general synchronization process.
* Synchronize sensitive groups separately or manage them manually to ensure data security and compliance with privacy policies.
References:
* Google Cloud Directory Sync Admin Help
* Best practices for using Google Cloud Directory Sync (GCDS)
NEW QUESTION # 47
An executive at your organization asked you to give their executive administrator access to their Workspace account. You need to ensure that this executive administrator can manage emails in the executive's account. You need to maintain security and privacy of the executive's account. What should you do?
- A. Instruct the executive to share their password with their executive administrator.
- B. Grant delegated access to the executive's Gmail account, and assign access to their executive administrator in Gmail settings.
- C. Create a Google Group, and add all executive administrators. Enable delegated access to the Group.
- D. Assist the executive in setting up email forwarding to their executive administrator.
Answer: B
Explanation:
Granting delegated access allows the executive administrator to manage the executive's emails without requiring access to the executive's password. This solution ensures security and privacy by limiting the permissions to email management only, while keeping the executive's account secure. The executive administrator will be able to send, read, and delete emails on behalf of the executive, but they won't have access to other aspects of the account.
NEW QUESTION # 48
Your Finance team has to share quarterly financial reports in Sheets with an external auditor. The external company is not a Workspace customer and allows employees to access public sites such as Gmail and Facebook. How can you provide the ability to securely share content to collaborators that do not have a Google Workspace or consumer (Gmail) account?
- A. Use the 'Publish' feature in the Sheets editor to share the contents externally.
- B. Allow external sharing with the auditor using the 'Trusted Domains' feature.
- C. Attach the Sheet file to an email message, and send to the external auditor.
- D. Enable the 'Visitor Sharing' feature, and demonstrate it to the Finance team.
Answer: D
Explanation:
https://support.google.com/drive/answer/9195194?hl=en#:~:text=Share%20with%20visitors,with%20one%20visitor.
NEW QUESTION # 49
Your organization is on Google Workspace Enterprise and allows for external sharing of Google Drive files to facilitate collaboration with other Google Workspace customers. Recently you have had several incidents of files and folders being broadly shared with external users and groups. Your chief security officer needs data on the scope of external sharing and ongoing alerting so that external access does not have to be disabled.
What two actions should you take to support the chief security officer's request? (Choose two.)
- A. Review who has viewed files using the Google Drive Activity Dashboard.
- B. Automatically block external sharing using DLP rules.
- C. Create an alert from Drive Audit reports to notify of external file sharing.
- D. Create a custom Dashboard for external sharing in the Security Investigation Tool.
- E. Review total external sharing in the Aggregate Reports section.
Answer: C,D
Explanation:
* Create an Alert for External Sharing:
* Access Google Admin Console: Go to admin.google.com and sign in with your administrator account.
* Navigate to Rules: Go to "Security" > "Alert Center" > "Manage Rules".
* Create a New Rule: Select "Create Rule" and choose "Drive Audit" as the event source.
* Configure Rule Settings: Set the conditions to trigger alerts when files or folders are shared externally.
* Set Notification Preferences: Configure who should receive the alerts and how they should be notified.
* Save the Rule: Save and activate the rule to start receiving alerts on external sharing activities.
* Create a Custom Dashboard for External Sharing:
* Access Security Investigation Tool: In the Admin console, go to "Security" > "Investigation
* Tool".
* Create a New Investigation: Click "Create" and select "Drive" as the data source.
* Set Up Investigation Parameters: Define the parameters to track external sharing activities (e.g., file shared externally, users involved).
* Create Dashboard: Save the investigation as a custom dashboard to continuously monitor external sharing activities.
* Review and Monitor: Regularly review the dashboard and set up automated reports if necessary.
References
* Google Workspace Admin Help - Create and manage alerts
* Google Workspace Admin Help - Use the security investigation tool
NEW QUESTION # 50
Several employees at your company received messages with links to malicious websites. The messages appear to have been sent by your company's human resources department. You need to identify which users received the emails and prevent a recurrence of similar incidents in the future. What should you do?
- A. Collect a list of users who received the messages. Search the recipients' email addresses in Google Vault. Export and download the malicious emails in PST file format. Add the sender's email address to a quarantine list setting in Gmail to quarantine any future emails from the sender.
- B. Search for the sender's email address by using the security investigation tool. Delete the messages.Turn on the safety options for spoofing and authentication protection in Gmail settings.
- C. Search the sender's email address by using Email Log Search. Identify the users that received the messages. Instruct them to mark them as spam in Gmail, delete the messages, and empty the trash.
- D. Search for the sender's email address by using the security investigation tool. Mark the messages as phishing. Add the sender's email address to the Blocked senders list in the Spam, Phishing and Malware setting in Gmail to automatically reject future messages.
Answer: D
Explanation:
The security investigation tool in Google Workspace allows you to identify the impacted users and messages.
By marking the messages as phishing, you acknowledge their malicious nature, helping to protect the users.
Adding the sender's email address to the Blocked senders list ensures that future messages from this sender will be automatically blocked, preventing recurrence of similar incidents.
NEW QUESTION # 51
A user joined your organization and is reporting that every time they start their computer they are asked to sign in. This behavior differs from what other users within the organization experience. Others are prompted to sign in biweekly. What is the first step you should take to troubleshoot this issue for the individual user?
- A. Reset the user's sign-in cookies
- B. Confirm that this user has their employee ID populated as a sign-in challenge.
- C. Check the session length duration for the organizational unit the user is provisioned in.
- D. Verify that 2-Step Verification is enforced for this user.
Answer: B
NEW QUESTION # 52
Your organization is concerned with the increasing threat of phishing attacks that may impact users.
Leadership has declined to force-enable 2-Step verification. You need to apply a security measure to prevent unauthorized access to user accounts.
What should you do?
- A. Enable Enforce Strong Password policy.
- B. Enable Employee ID Login Challenge.
- C. Decrease the Maximum User Session Length.
- D. Revoke token authorizations to external applications.
Answer: B
Explanation:
* Sign in to the Google Admin console.
* From the Admin console Home page, go to "Security" and then "Login challenges."
* Enable the "Employee ID login challenge" setting.
* Configure the challenge by defining the employee IDs that users need to provide during the login process.
Enabling Employee ID login challenges adds an additional layer of security without requiring 2-Step verification. This helps prevent unauthorized access by ensuring that users provide an additional piece of information known only to them.
References:
* Google Workspace Admin Help - Configure login challenges
* "?>>?b GF\]\rom the Admin console Home page, go to "Security."
* Under "Security," select "API controls."
* In the "API controls" section, click on "Manage Third-Party App Access."
* Find the Google Drive API in the list.
* Choose "Disable All Access" for Google Drive to ensure that no third-party apps have OAuth permissions to Google Drive.
This configuration adheres to the policy set by the Chief Information Security Officer by preventing third-party apps from accessing Google Drive via OAuth.
References:
* Google Workspace Admin Help - Manage API client access
NEW QUESTION # 53
You are in the middle of migrating email from on-premises Microsoft Exchange to Google Workspace. Users that you have already migrated are complaining of messages from internal users going into spam folders. What should you do to ensure that internal messages do not go into Gmail spam while blocking spoofing attempts?
- A. Force TLS for your domain.
- B. Add all users of your domain to an approved sender list.
- C. Train users to click on Not Spam button for emails.
- D. Ensure that your inbound gateway is configured with all of your Exchange server IP addresses.
Answer: B
Explanation:
Approved senders list-Approved senders are trusted users that send email to your organization. Create an address list of approved senders so messages from these users bypass Gmail's spam filters, and recipients can decide whether they are spam or not. Create the list with individual email addresses, or by adding an entire domain.
https://support.google.com/a/answer/60752?hl=en#:~:text=Approved%20senders%20list%E2%80%94,settings%20in%20Google%20Workspace.
NEW QUESTION # 54
......
Google Cloud Certified - Professional Google Workspace Administrator certification exam is an important credential for professionals who manage and administer Google Workspace. It validates your skills and knowledge in a wide range of areas, from basic setup and configuration to advanced automation and scripting. With the right training and experience, earning this certification can help you stand out in a competitive job market and demonstrate your value as a skilled and knowledgeable Google Workspace administrator.
Q&As with Explanations Verified & Correct Answers: https://www.fast2test.com/Google-Workspace-Administrator-premium-file.html
Practice Exams and Training Solutions for Certifications: https://drive.google.com/open?id=1SPceWGHlJUl-hA_0udStubNbdU1JfXOB