A fully updated 2025 Google-Workspace-Administrator Exam Dumps exam guide from training expert Prep4sures [Q40-Q63]

Share

A fully updated 2025 Google-Workspace-Administrator Exam Dumps exam guide from training expert Prep4sures

Provides complete coverage of every objective on exam and exam preparation Google-Workspace-Administrator

NEW QUESTION # 40
Your organization needs an approval application for purchases where a user can enter information on the purchase required and then submit it for management approval. You need to suggest a solution to create the application that must be available on both the web and mobile devices. Your organization does not have software developers or the budget to hire a third party. What should you do?

  • A. Suggest that the organization develop an application internally with a database, a backend service for data retrieval, and a frontend service for the application's user interface.
  • B. Suggest the organization use AppSheet to create the application.
  • C. Suggest that the organization use AppScript to create forms linked to a Google Sheet to store the purchase data.
  • D. Suggest that the organization continue to approve requests manually until budget is available to use a third-party application provider.

Answer: B

Explanation:
AppSheet is a no-code platform that allows users to create custom applications without the need for software development skills. It is capable of building applications that can be used both on the web and mobile devices.
AppSheet would allow the organization to create the approval application efficiently,meeting the requirements of the purchase process, and would be a cost-effective solution that does not require hiring developers or using a third-party application provider.


NEW QUESTION # 41
Your Finance team has to share quarterly financial reports in Sheets with an external auditor. The external company is not a Workspace customer and allows employees to access public sites such as Gmail and Facebook. How can you provide the ability to securely share content to collaborators that do not have a Google Workspace or consumer (Gmail) account?

  • A. Attach the Sheet file to an email message, and send to the external auditor.
  • B. Use the 'Publish' feature in the Sheets editor to share the contents externally.
  • C. Enable the 'Visitor Sharing' feature, and demonstrate it to the Finance team.
  • D. Allow external sharing with the auditor using the 'Trusted Domains' feature.

Answer: C

Explanation:
https://support.google.com/drive/answer/9195194?hl=en#:~:text=Share%20with%20visitors,with%20one%20visitor.


NEW QUESTION # 42
Your organization is working on a confidential project with details that cannot be shared through email with anyone outside your organization You want to add controls in Gmail that prevent any mention of the project from being sent by employees Only the CEO and the CFO can send information about the project over email and without a delay What should you do?

  • A. Configure the Gmail Restrict delivery setting for all outgoing messages, except the internal emails Add the CEO and CFO email
  • B. Configure a Gmail Content compliance rule for outbound email that quarantines all email mentioning the project Manually review all quarantined emails and choose to deliver the ones sent by the CEO and CFO
  • C. Configure the Gmail Restrict delivery setting and add an allowlist with all domains that your employees are allowed to send emails to Include the CEO and CFO email addresses to the allowlist
  • D. Configure a Gmail Content compliance rule for outbound email that quarantines all email mentioning the project Bypass the rule by using the address list with the CEO and CFO email addresses.

Answer: D

Explanation:
Access Admin Console: Log in to the Google Admin console using your administrator account.
Navigate to Gmail Settings: Go to Apps > Google Workspace > Gmail > Compliance.
Create Content Compliance Rule: Click on Configure and select Add another rule under Content compliance.
Set Conditions: Define conditions to detect mentions of the confidential project in outbound emails.
Set Actions: Configure the rule to quarantine emails that match the conditions.
Bypass Rule for Specific Users: Use the address list feature to bypass the rule for the CEO and CFO email addresses.
Save and Implement: Save the rule and ensure it is activated. This will quarantine emails about the project, except those sent by the CEO and CFO.
Reference:
Google Workspace Admin Help: Set up rules for content compliance
Google Workspace Email Compliance Best Practices


NEW QUESTION # 43
Your company is using macOS devices for all employees and has built a process to allow a Google account to be used as credentials for the device. Your company wants to manage newly acquired Windows 10 devices with Google Workspace endpoint management and have employees use their Google Workspace account as login credentials for Windows 10. Which steps should you take to enable this? (Choose two.)

  • A. Enable Windows device management in Devices > Mobile & endpoints > Settings > Windows setting.
  • B. Install and configure Google Credential Provider for Windows (GCPW) on each device.
  • C. Install and configure Password Sync on each Active Directory (AD) domain controller.
  • D. Sync the Google Accounts and password to AD via Google Cloud Directory Sync V1 (GCDS).
  • E. Configure Chrome policies on Windows to push advanced device management policies.

Answer: A,B


NEW QUESTION # 44
All Human Resources employees at your company are members of the "HR Department" Team Drive. The HR Director wants to enact a new policy to restrict access to the "Employee Compensation" subfolder stored on that Team Drive to a small subset of the team.
What should you do?

  • A. Move the subfolder to the HR Director's MyDrive and share it with the relevant team members.
  • B. Use the Drive API to modify the permissions of the Employee Compensation subfolder.
  • C. Use the Drive API to modify the permissions of the individual files contained within the subfolder.
  • D. Move the contents of the subfolder to a new Team Drive with only the relevant team members.

Answer: D

Explanation:
"Inherited permissions can't be removed from a file or folder in a shared drive".
ref: https://developers.google.com/drive/api/v3/manage-sharing


NEW QUESTION # 45
Your organization is about to expand by acquiring two companies, both of which are using Google Workspace. The CISO has mandated that strict 'No external content sharing' policies must be in place and followed. How should you securely configure sharing policies to satisfy both the CISO's mandate while allowing external sharing with the newly acquired companies?

  • A. Let users share files between the two companies by using the 'Trusted Domains' feature. Create an allowlist of the trusted domains, and choose sharing settings for the users.
  • B. Allow external sharing of Drive content for the IT group only.
  • C. Create a Drive DLP policy that will allow sharing to only domains on an allowlist.
  • D. Use shared drives to store the content, and share only individual files externally.

Answer: A

Explanation:
https://support.google.com/a/answer/6160020?hl=en#zippy=%2Cgive-sharing-access-to-trusted-domains:~:text=only%20trusted%20domains-,Allow%20external%20sharing%20with%20only%20trusted%20domains,-Help%20and%20tips


NEW QUESTION # 46
Your organization recently bought 1.000 licenses for Cloud Identity Premium. The company's development team created an application in the enterprise service bus (ESB) that will read user data in the human resources information system (HRIS) and create accounts via the Google Directory REST API.
While doing the original test before production use, the team observes a 503 error coming from Google API response after a few users are created The team believes the ESB is not the cause, because it can perform 100 requests per second without any problems. What advice would you give the development team in order to avoid the issue?

  • A. Switch from REST API to gRPC protocol for performance improvement
  • B. Use the batch request architecture, because it can pack 1,000 API calls in one HTTP request.
  • C. Use an exponential back-off algorithm to retry failed requests.
  • D. Use the domain-wide delegation API to avoid the limitation per account.

Answer: C


NEW QUESTION # 47
You have configured your Google Workspace account on the scheduled release track to provide additional time to prepare for new product releases and determine how they will impact your users. There are some new features on the latest roadmap that your director needs you to test as soon as they become generally available without changing the release track for the entire organization.
What should you do?

  • A. Create a new Google Group with test users and enable the rapid release track.
  • B. Establish a separate Dev environment, and set it to rapid release.
  • C. Ask Google for a demo account with beta access to the new features.
  • D. Create a new OU and tum on the rapid release track just for this OU.

Answer: B

Explanation:
Tip for large organizations: Select the Scheduled Release track for your production account. Then set up Rapid Release on a test account to try new features before they're available to your users. https://support.google.com/a/answer/172177


NEW QUESTION # 48
The executive team for your company has an extended retention policy of two years in place so that they have access to email for a longer period of time. Your COO has found this useful in the past but when they went to find an email from last year to prove details of a contract in dispute, they were unable to find it. itis no longer in the Trash. They have requested that you recover it.
What should you do?

  • A. Using the Message ID, contact Google Google Workspace support to recover the email, then import with Google Workspace Migration for Microsoft Outlook.
  • B. Using Vault, perform a search for the email and export the content to a standard format to provide for investigation.
  • C. Using the Vault Audit log, perform a search for the email, export the results. then import with Google Workspace Migration for Microsoft Outlook.

Answer: B

Explanation:
* Access Google Vault:
* Go to Google Vault by navigating to vault.google.com.
* Perform a Search:
* In Vault, create a new search query specifying the criteria (e.g., date range, email address, keywords) to locate the missing email.
* Use search operators to refine the search and ensure you find the correct email.
* Export the Email:
* Once the email is located, select it and choose the export option.
* Export the email data in a standard format, such as MBOX or PST, which can be used for investigation and recovery purposes.
* Provide the Exported Data:
* Provide the exported email data to the COO for their review and use in the contract dispute.
References
* Google Vault Help: Search for and export data


NEW QUESTION # 49
A user has reported that they did not receive an email from one of their normal correspondents. What information do you need to collect from the user to investigate the cause of the issue?

  • A. The sender's domain so you can review their SPF and DKIM configuration.
  • B. The sender's IP address, mail client, and mail platform.
  • C. The type of device the individual is using, including the OS version, browser, and browser version.
  • D. The email address of the sender and the subject and date/time of the missing message.

Answer: D


NEW QUESTION # 50
In the years prior to your organization moving to Google Workspace, it was relatively common practice for users to create consumer Google accounts with their corporate email address (for example, to monitor Analytics, manage AdSense, and collaborate in Docs with other partners who were on Google Workspace.) You were able to address active employees' use of consumer accounts during the rollout, and you are now concerned about blocking former employees who could potentially still have access to those services even though they don't have access to their corporate email account.
What should you do?

  • A. Provide a list of all active employees to the managers of your company's Analytics, AdSense, etc.
    accounts, so they can clean up the respective access control lists.
  • B. Contact Google Enterprise Support to provide a list of all accounts on your domain(s) that access non-Google Workspace Google services and have them blocked.
  • C. Provision former user accounts with Cloud Identity licenses, generate a new Google password, and place them in an OU with all Google Workspace and Other Google Services disabled.
  • D. Use the Transfer Tool for Unmanaged Accounts to send requests to the former users to transfer their account to your domain as a managed account.

Answer: D

Explanation:
* Access the Transfer Tool:
* In the Google Workspace Admin console, go to "Users" > "Transfer tool for unmanaged users".
* Identify Unmanaged Accounts:
* Use the tool to search for unmanaged accounts (consumer Google accounts) that have corporate email addresses.
* Send Transfer Requests:
* Send transfer requests to the identified unmanaged accounts, asking the former users to transfer their accounts to your managed domain.
* Monitor and Complete Transfers:
* Monitor the transfer process and ensure that the accounts are successfully transferred.
* Verify that the transferred accounts are now managed under your Google Workspace domain, preventing unauthorized access to services.
References
* Google Workspace Admin Help: Transfer tool for unmanaged users


NEW QUESTION # 51
Your team uses Google Drive for collaborating with external companies and partners. A sensitive project with an external organization is about to begin. You are creating the new labels for the project. You must ensure that all labeled documents have the label visible to everyone who has access to the project files. What should you do?

  • A. Create Drive labels and apply data protection rules to all project file.
  • B. Create Drive labels and add the users from the external organization to your domain.
  • C. Create Drive labels and a separate Shared Drive for the project.
  • D. Create Drive labels and add the permissions for all users in the project, including the external users, to view these labels.

Answer: D

Explanation:
https://support.google.com/a/answer/13127870?hl=en


NEW QUESTION # 52
You are the administrator of a domain that requires iOS mobile device management. What initial steps should be taken to ensure that you can properly manage end-user iOS devices?

  • A. Configure an Apple Push Certificate, and be sure to use a work address that can be accessed in the future.
  • B. Configure an Apple Push Certificate, and select "certificate never expires."
  • C. In the Admin console, navigate to iOS management, and enable the Apple Push Certificate connector.
  • D. Follow the prompts under "company owned devices," and select "iOS Management." Select the option to "enforce management on iOS devices."

Answer: A

Explanation:
To ensure proper management of iOS devices, follow these steps:
Sign in to the Google Admin console: Use an account with super administrator privileges.
Navigate to Device Management: Go to Devices > Mobile and endpoints > Settings > iOS settings.
Configure Apple Push Certificate:
Click on "Apple Push Certificate."
Follow the instructions to create and upload an Apple Push Certificate. Ensure that you use a work email address that will be accessible in the future for renewal purposes.
Enable iOS Management:
Once the Apple Push Certificate is configured, enable iOS device management.
Optionally, enforce management on iOS devices to ensure all devices are compliant.
Reference:
Google Workspace Admin Help - Set up Apple Push Certificate
Google Workspace Admin Help - Manage iOS devices


NEW QUESTION # 53
Your organization has enabled spoofing protection against unauthenticated domains. You are receiving complaints that email from multiple partners is not being received. While investigating this issue, you find that emails are all being sent to quarantine due to the configured safety setting. What should be the next step to allow uses to review these emails and reduce the internal complaints while keeping your environment secure?

  • A. Change the spoofing protection to deliver the emails to spam instead of quarantining them.
  • B. Add your partner domains IPs to the Inbound Gateway setting.
  • C. Add your partner sending IP addresses to an allowlist.
  • D. Change the spoofing protection to deliver the emails to inboxes with a custom warning instead of quarantining them.

Answer: D

Explanation:
Access Admin Console: Log into your Google Workspace Admin Console.
Navigate to Security Settings: Go to Security > Gmail > Safety.
Modify Spoofing Protection: Locate the spoofing protection settings.
Change Delivery Method: Change the setting from quarantining emails to delivering them to inboxes with a custom warning. This way, users can review the emails and determine if they are legitimate while still being alerted to potential issues.
Save Settings: Save the changes to apply the new delivery method.
Reference
Google Support: Protect against spoofing & identity deception


NEW QUESTION # 54
Users in your organization have seen a high volume of customer invoices ending up in spam. A customer has provided the following message header for an email that was sent to spam (please see image above.) You need to prevent these emails from going to spam. What should you do?

  • A. Enable DKIM signing to add a DKIM signature to all outgoing messages.
  • B. Set the DMARC Percent Option to 100%.
  • C. Update SPF records to include all IPs.
  • D. Ask the customer to create an approved sender list.

Answer: C

Explanation:
A is not correct because a message from an approved sender can still be blocked by the sender's DMARC policy.
B is not correct because the message will still fail an spf check.
C is correct because the message failed spf check, and updating spf records will allow invoices to pass spf check.
D is not correct because a DKIM signature may prevent spoofing, but alone may not stop the message from being marked as spam.


NEW QUESTION # 55
In the years prior to your organization moving to Google Workspace, it was relatively common practice for users to create consumer Google accounts with their corporate email address (for example, to monitor Analytics, manage AdSense, and collaborate in Docs with other partners who were on Google Workspace.) You were able to address active employees' use of consumer accounts during the rollout, and you are now concerned about blocking former employees who could potentially still have access to those services even though they don't have access to their corporate email account.
What should you do?

  • A. Provide a list of all active employees to the managers of your company's Analytics, AdSense, etc. accounts, so they can clean up the respective access control lists.
  • B. Contact Google Enterprise Support to provide a list of all accounts on your domain(s) that access non-Google Workspace Google services and have them blocked.
  • C. Provision former user accounts with Cloud Identity licenses, generate a new Google password, and place them in an OU with all Google Workspace and Other Google Services disabled.
  • D. Use the Transfer Tool for Unmanaged Accounts to send requests to the former users to transfer their account to your domain as a managed account.

Answer: D

Explanation:
https://support.google.com/a/answer/6178640?hl=en


NEW QUESTION # 56
Your CISO is concerned about third party applications becoming compromised and exposing Google Workspace data you have made available to them. How could you provide granular insight into what data third party applications are accessing?
What should you do?

  • A. Create a report using the Drive Audit Activity logs.
  • B. Create a report using the OAuth Token Audit Activity logs.
  • C. Create a reporting using the API Permissions logs for Installed Apps.
  • D. Create a report using the Calendar Audit Activity logs.

Answer: B

Explanation:
Access Admin Console: Log into your Google Workspace Admin Console.
Navigate to Reports: Go to the Reports section within the Admin Console.
OAuth Token Audit Log: Access the OAuth Token Audit Activity logs. This log provides detailed information about third-party applications that have been granted access to your Google Workspace data.
Review Data Access: Review the logs to see which applications have accessed what type of data. This includes details on the scopes of access requested by the applications.
Generate Report: Create a report from these logs to provide granular insight into the data accessed by third-party applications. This report can be used to assess and mitigate any potential risks.
Reference
Google Support: Token audit log


NEW QUESTION # 57
Your Security Officer ran the Security Health Check and found the alert that "Installation of mobile applications from unknown sources" was occurring. They have asked you to find a way to prevent that from happening.
Using Mobile Device Management (MDM), you need to configure a policy that will not allow mobile applications to be installed from unknown sources.
What MDM configuration is needed to meet this requirement?

  • A. In Device Management > Setup > Device Approvals menu, configure the "Requires Admin approval" option.
  • B. In the Application Management menu, configure the whitelist of apps that Android, iOS devices, and Active Sync devices are allowed to install.
  • C. In Android Settings, ensure that "Allow non-Play Store apps from unknown sources installation" is unchecked.
  • D. In the Application Management menu, configure the whitelist of apps that Android and iOS devices are allowed to install.

Answer: C

Explanation:
* Access the Admin Console: Log into your Google Workspace Admin Console.
* Navigate to Device Management: Go to the Device Management section.
* Android Settings: Within Device Management, access the Android settings.
* Configure Application Settings: Ensure that the setting "Allow non-Play Store apps from unknown sources installation" is unchecked. This will prevent users from installing apps from unknown sources, thereby enhancing security.
* Save Configuration: Save the configuration changes to apply the policy across all managed Android devices.


NEW QUESTION # 58
You are the administrator of a domain that requires iOS mobile device management. What initial steps should be taken to ensure that you can properly manage end-user iOS devices?

  • A. Configure an Apple Push Certificate, and be sure to use a work address that can be accessed in the future.
  • B. Configure an Apple Push Certificate, and select "certificate never expires."
  • C. In the Admin console, navigate to iOS management, and enable the Apple Push Certificate connector.
  • D. Follow the prompts under "company owned devices," and select "iOS Management." Select the option to "enforce management on iOS devices."

Answer: A

Explanation:
To manage end-user iOS devices, you need to configure an Apple Push Certificate, which allows Google to communicate with your devices and enforce security policies1. The certificate expires annually, so you need to renew it before it expires1. You should use a work address that can be accessed in the future, because you will receive email notifications from Apple when the certificate is about to expire1. The other options are incorrect because:
There is no option to "enforce management on iOS devices" under "company owned devices" in the Admin console2.
You cannot select "certificate never expires" when configuring an Apple Push Certificate. The certificate always expires after one year1.
There is no option to enable the Apple Push Certificate connector in the Admin console. You need to download the public key from Google and upload it to Apple Business Manager or Apple School Manager2.


NEW QUESTION # 59
Your Security Officer ran the Security Health Check and found the alert that "Installation of mobile applications from unknown sources" was occurring. They have asked you to find a way to prevent that from happening.
Using Mobile Device Management (MDM), you need to configure a policy that will not allow mobile applications to be installed from unknown sources.
What MDM configuration is needed to meet this requirement?

  • A. In Device Management > Setup > Device Approvals menu, configure the "Requires Admin approval" option.
  • B. In the Application Management menu, configure the whitelist of apps that Android, iOS devices, and Active Sync devices are allowed to install.
  • C. In Android Settings, ensure that "Allow non-Play Store apps from unknown sources installation" is unchecked.
  • D. In the Application Management menu, configure the whitelist of apps that Android and iOS devices are allowed to install.

Answer: C

Explanation:
Reference: https://support.google.com/a/answer/7491893?hl=en


NEW QUESTION # 60
Your organization implemented Single Sign-On (SSO) for the multiple cloud-based services it uses. During authentication, one service indicates that access to the SSO provider is not possible due to invalid information.
What should you do?

  • A. Run nslookup to confirm that the service exists.
  • B. Verify that the Audience element in the SAML Response matches the assertion consumer service (ACS) URL
  • C. Ensure that Microsoft's Active Directory Federation Services 2.0 sends encrypted SAML Responses in default configurations.
  • D. Update the validation certificate.

Answer: B

Explanation:
If a service indicates that access to the SSO provider is not possible due to invalid information, you should verify that the Audience element in the SAML Response matches the assertion consumer service (ACS) URL.
This check ensures that the SAML Response is directed to the correct service, resolving the issue with authentication.
References:
* Google Workspace Admin Help - Troubleshoot SSO issues
* Google Workspace Admin Help - SAML SSO setup


NEW QUESTION # 61
Your company recently decided to use a cloud-based ticketing system for your customer care needs. You are tasked with rerouting email coming into your customer care address, [email protected] to the cloud platform's email address, [email protected]. As a security measure, you have mail forwarding disabled at the domain level.
What should you do?

Answer: B

Explanation:
Disable automatic forwarding https://support.google.com/a/answer/2491924?hl=en Redirect incoming messages to another email address https://support.google.com/a/answer/4524505?hl=en (Optional) To send the message to the original recipient as well as the new address, under Routing options, check the Also route to original destination box.


NEW QUESTION # 62
The compliance team at your organization is conducting a legal investigation into some concerning sales activities of an employee eight months ago The compliance team contacted you for assistance on the situation You set up the default Google Vault retention rules so all data is retained only for one year You must assist the compliance team with the investigation What should you do1?

  • A. Assign the compliance team a Google Vault administrator role and create a legal hold for the employee
  • B. Suspend the employee and export all data by using Google Takeout
  • C. Do nothing The retention period has already ended and the evidence has already been purged
  • D. Assign the compliance team a Google Vault administrator role and change the default retention rules to three years.

Answer: A

Explanation:
Assign Vault Administrator Role: In the Google Admin console, assign the compliance team members the Google Vault administrator role to give them the necessary permissions.
Access Google Vault: Have the compliance team access Google Vault.
Create a Matter: In Google Vault, create a new matter for the investigation.
Create a Hold: Within the matter, create a legal hold specifically targeting the employee's email and any other relevant data. This will preserve all the necessary information beyond the default retention period.
Review Data: The compliance team can now review the preserved data as part of their investigation.
Reference:
Google Vault Help: Assign Vault privileges
Google Vault Help: Create and manage holds


NEW QUESTION # 63
......


Google Workspace Administrator certification exam is designed for professionals who are responsible for managing and administering Google Workspace services in an organization. Google Cloud Certified - Professional Google Workspace Administrator certification validates the skills and knowledge required to successfully deploy, configure, and manage Google Workspace services to meet organizational needs. Google-Workspace-Administrator exam covers a wide range of topics, including user and group management, security and compliance, data migration, and collaboration tools.

 

Tested Material Used To Google-Workspace-Administrator: https://www.prep4sures.top/Google-Workspace-Administrator-exam-dumps-torrent.html

Steps Necessary To Pass The Google-Workspace-Administrator Exam: https://drive.google.com/open?id=18uN5rhpJnqh6zL-XmeQ9Ro0KD6hSDhSt