
Google-Workspace-Administrator PDF Exam Material 2023 Realistic Google-Workspace-Administrator Dumps Questions
Updated Google Google-Workspace-Administrator Dumps – PDF & Online Engine
NEW QUESTION # 11
Your IT team is being asked to fulfill a query by your organization's legal department that requires an MBOX file that will be shared to a third-party partner for eDiscovery. The query must be run on multiple users. Legal has no admin rights to Google Vault. What should you do to fulfil the request?
- A. Use the Investigation Too! to search for the data requested, and export for the legal department.
- B. Create a Google Vault matter, search for data, and run an export for the legal department.
- C. Search for the data in Gmail, and export for the legal department.
- D. Create a Google Vault matter for each user account, and share the matters to the legal admin.
Answer: B
Explanation:
https://support.google.com/vault/answer/2473458?hl=en
NEW QUESTION # 12
Your organization is on Google Workspace Enterprise and allows for external sharing of Google Drive files to facilitate collaboration with other Google Workspace customers. Recently you have had several incidents of files and folders being broadly shared with external users and groups. Your chief security officer needs data on the scope of external sharing and ongoing alerting so that external access does not have to be disabled.
What two actions should you take to support the chief security officer's request? (Choose two.)
- A. Review who has viewed files using the Google Drive Activity Dashboard.
- B. Review total external sharing in the Aggregate Reports section.
- C. Create a custom Dashboard for external sharing in the Security Investigation Tool.
- D. Automatically block external sharing using DLP rules.
- E. Create an alert from Drive Audit reports to notify of external file sharing.
Answer: C,E
NEW QUESTION # 13
A company using Google Workspace has reports of cyber criminals trying to steal usernames and passwords to access critical business dat a. You need to protect the highly sensitive user accounts from unauthorized access.
What should you do?
- A. Enforce 2FA with a physical security key.
- B. Turn on password expiration.
- C. Use a third-party identity provider.
- D. Enforce 2FA with Google Authenticator app.
Answer: A
Explanation:
https://support.google.com/a/answer/175197?hl=en#keys&prompt&authentic&codes&phone&2sv&security
NEW QUESTION # 14
Your sales team, which is organized as its own organizational unit, is prone to receiving malicious attachments. What action should you take, as an administrator, to apply an additional layer of protection in the admin console for your sales team without disrupting business operation?
- A. Update the Email Allowlist in the admin console to only include IP addresses of known senders.
- B. Configure the security sandbox feature on the sales team organizational unit.
- C. Configure an attachment compliance rule to strip any attachments received by users within the sales team organizational unit.
- D. Configure an attachment compliance rule to send any emails with attachments received by users within the sales team organizational unit to an administrator quarantine.
Answer: B
Explanation:
https://support.google.com/a/answer/7676854?hl=en#:~:text=As%20an%20administrator,malicious%20attachments.
NEW QUESTION # 15
Your organization's information security team has asked you to determine and remediate if a user ([email protected]) has shared any sensitive documents outside of your organization. How would you audit access to documents that the user shared inappropriately?
- A. As a super administrator, change the access on externally shared Drive files manually under [email protected].
- B. Have the super administrator use the Security API to audit Drive access.
- C. Open Security Investigation Tool-> Drive Log Events. Add two conditions: Visibility Is External, and Actor Is [email protected].
- D. Open Security Dashboard-> File Exposure Report-> Export to Sheet, and filter for [email protected].
Answer: C
Explanation:
https://support.google.com/a/answer/11480192?hl=en&ref_topic=11479095#:~:text=View%20files%20shared,Click%20Search.
NEW QUESTION # 16
Your CISO is concerned about third party applications becoming compromised and exposing Google Workspace data you have made available to them. How could you provide granular insight into what data third party applications are accessing?
What should you do?
- A. Create a report using the Drive Audit Activity logs.
- B. Create a reporting using the API Permissions logs for Installed Apps.
- C. Create a report using the Calendar Audit Activity logs.
- D. Create a report using the OAuth Token Audit Activity logs.
Answer: D
Explanation:
https://support.google.com/a/answer/6124308?hl=en
NEW QUESTION # 17
Your organization recently bought 1.000 licenses for Cloud Identity Premium. The company's development team created an application in the enterprise service bus (ESB) that will read user data in the human resources information system (HRIS) and create accounts via the Google Directory REST API.
While doing the original test before production use, the team observes a 503 error coming from Google API response after a few users are created The team believes the ESB is not the cause, because it can perform 100 requests per second without any problems. What advice would you give the development team in order to avoid the issue?
- A. Use the batch request architecture, because it can pack 1,000 API calls in one HTTP request.
- B. Switch from REST API to gRPC protocol for performance improvement
- C. Use the domain-wide delegation API to avoid the limitation per account.
- D. Use an exponential back-off algorithm to retry failed requests.
Answer: D
NEW QUESTION # 18
On which two platforms can you push WiFi connection information with Google Workspace? (Choose two.)
- A. Chrome OS
- B. Mac OS
- C. Windows
- D. Linux
- E. iOS
Answer: A,E
NEW QUESTION # 19
Your Accounts Payable department is auditing software license contracts companywide and has asked you to provide a report that shows the number of active and suspended users by organization unit, which has been set up to match the Regions and Departments within your company. You need to produce a Google Sheet that shows a count of all active user accounts and suspended user accounts by Org unit.
What should you do?
- A. From the Admin Console Users Menu, download a list of all user info columns and currently selected columns.
- B. From the Admin Console Users Menu, download a list of all Users to Google Sheets, and join that with a list of ORGIDs pulled from the Reports API.
- C. From the Google Workspace Reports Menu, run and download the Accounts Aggregate report, and export the data to Google Sheets.
- D. From the Admin Console Billing Menu, turn off auto-assign, and then click into Assigned Users and export the data to Sheets.
Answer: A
Explanation:
https://support.google.com/a/answer/7348070?hl=it
NEW QUESTION # 20
Your organization wants more visibility into actions taken by Google staff related to your data for audit and security reasons. They are specifically interested in understanding the actions performed by Google support staff with regard to the support cases you have opened with Google. What should you do to gain more visibility?
- A. From Google Admin Panel, go to Audit, and select Access Transparency Logs. Most Voted
- B. From Google Admin Panel, go to Audit, and select Rules Audit Log.
- C. From Google Admin Panel, go to Audit, and select Admin Audit Log.
- D. From Google Admin Panel, go to Audit, and select Login Audit Log.
Answer: A
Explanation:
Google staff logs related to accessing user content are stored in Access Transparency logs https://support.google.com/a/answer/9230474?hl=en
NEW QUESTION # 21
Your company is in the process of deploying Google Drive Enterprise for your sales organization. You have discovered that there are many unmanaged accounts across your domain. Your security team wants to manage these accounts moving forward.
What should you do?
- A. Use the Transfer Tool for unmanaged accounts to invite users into the domain.
- B. Open a support ticket to have Google transfer unmanaged accounts into your domain.
- C. Use the Data Migration Service to transfer the data to a managed account.
- D. Disable access to all "Other Services" in the Google Workspace Admin Console.
Answer: A
NEW QUESTION # 22
Your large organization, 80,000 users, has been on Google for two years. Your CTO wants to create an integrated team experience with Google Groups, Teams Drives, and Calendar. Users will use a Google Form and Apps Script to request a new "G-Team." A "G-Team' is composed of a Google Group and a Team Drive/ Secondary Calendar that is shared using that Google Group.
What two design decisions are required to implement this workflow securely? (Choose two.)
- A. The Google Form will need to enforce Group naming conventions.
- B. You will need a Cloud SQL instance to store "G-Team' data.
- C. The Apps Script will need to run on a timed interval to process new entries.
- D. The Apps Script will need to run as a Google Workspace admin.
- E. The Google Form will need to be limited to internal users only.
Answer: D,E
NEW QUESTION # 23
Your company recently migrated to Google Workspace and wants to deploy a commonly used third-party app to all of finance. Your OU structure in Google Workspace is broken down by department. You need to ensure that the correct users get this app.
What should you do?
- A. At the root level, disable the third-party app. For the Finance OU, allow users to install only whitelisted apps from the Google Workspace Marketplace.
- B. For the Finance OU, enable the third-party app in SAML apps.
- C. At the root level, disable the third-party app. For the Finance OU, allow users to install any application from the Google Workspace Marketplace.
- D. For the Finance OU, enable the third-party app in Marketplace Apps.
Answer: D
NEW QUESTION # 24
As the Workspace Administrator, you have been asked to enable the help desk team to share incoming support requests from end users The help desk team has ten users who need to respond to support requests that are sent to a help desk email address. The users must be able to respond by email and assign ownership of tickets. Finally, the help desk team is highly mobile and will need to manage help desk tickets from their mobile devices. How would you provide this functionality for the help desk team?
- A. Create the help desk group as a Q&A Group, and add the "Manager role to the help desk team users.
- B. Create a help desk Workspace mail account, and set the help desk team as mail delegates to the help desk account.
- C. In Google Drive, create a help desk request form, and give the help desk team the ability to view the inbound requests.
- D. Configure a Google Group as a collaborative inbox, and assign the required Groups permissions to the help desk team members.
Answer: D
NEW QUESTION # 25
Multiple users across the organization are experiencing video degradation in Meet video calls. As an administrator, what steps should you take to start troubleshooting?
- A. Update the Admin Console Meet settings to disable streaming.
- B. Troubleshoot network bandwidth for the organizer of the meeting.
- C. Push the Meet quality tool to end user devices and run local reports to determine connectivity issues.
- D. Locate the Meet quality tool, and review the output for issues with quality.
Answer: D
NEW QUESTION # 26
All Human Resources employees at your company are members of the "HR Department" Team Drive. The HR Director wants to enact a new policy to restrict access to the "Employee Compensation" subfolder stored on that Team Drive to a small subset of the team.
What should you do?
- A. Use the Drive API to modify the permissions of the Employee Compensation subfolder.
- B. Use the Drive API to modify the permissions of the individual files contained within the subfolder.
- C. Move the subfolder to the HR Director's MyDrive and share it with the relevant team members.
- D. Move the contents of the subfolder to a new Team Drive with only the relevant team members.
Answer: D
Explanation:
"Inherited permissions can't be removed from a file or folder in a shared drive".
ref: https://developers.google.com/drive/api/v3/manage-sharing
NEW QUESTION # 27
Security and Compliance has identified that data is being leaked through a third-party application connected to Google Workspace. You want to investigate using an audit log.
What log should you use?
- A. SAML audit log
- B. Drive usage audit log
- C. OAuth Token audit log
- D. Admin audit log
Answer: C
NEW QUESTION # 28
You are a Workspace Administrator with a mix of Business Starter and Standard Licenses for your users. A Business Starter User in your domain mentions that they are running out of Drive Storage Quot a. Without deleting data from Drive, what two actions can you take to alleviate the quota concerns for this user? (Choose two.)
- A. Make another user the "Owner" of the Drive objects, thus transferring the storage quota debt to them.
- B. Perform an API query for large storage drive objects, and delete them, thus alleviating the quota debt.
- C. Add other users as "Editors" on the Drive object, thus spreading the storage quota debt between all of them.
- D. Manually export and back up the data locally, and delete the affected files from Drive to alleviate the debt.
- E. Move the affected items to a Shared Drive. Shared Drives transfer ownership of the drive item to the domain itself, which alleviates the quota debt from that user.
Answer: A,E
NEW QUESTION # 29
A user is reporting that external, inbound messages from known senders are repeatedly being incorrectly classified as spam. What steps should the admin take to prevent this behavior in the future?
- A. Instruct the user to add the senders to their contacts.
- B. Modify the SPF record for your internal domain to include the IPs of the external user's mail servers.
- C. Add the sender's domain to an allowlist via approved senders in the Admin Console.
- D. Update the spam settings in the Admin Console to be less aggressive.
Answer: C
Explanation:
https://support.google.com/a/answer/60752?hl=en#:~:text=Approved%20senders%20list%E2%80%94,settings%20in%20Google%20Workspace.
NEW QUESTION # 30
You have configured your Google Workspace account on the scheduled release track to provide additional time to prepare for new product releases and determine how they will impact your users. There are some new features on the latest roadmap that your director needs you to test as soon as they become generally available without changing the release track for the entire organization.
What should you do?
- A. Ask Google for a demo account with beta access to the new features.
- B. Establish a separate Dev environment, and set it to rapid release.
- C. Create a new OU and tum on the rapid release track just for this OU.
- D. Create a new Google Group with test users and enable the rapid release track.
Answer: B
Explanation:
Tip for large organizations: Select the Scheduled Release track for your production account. Then set up Rapid Release on a test account to try new features before they're available to your users. https://support.google.com/a/answer/172177
NEW QUESTION # 31
......
Google Google-Workspace-Administrator Dumps PDF Are going to be The Best Score: https://www.actualtestsquiz.com/Google-Workspace-Administrator-test-torrent.html
Google-Workspace-Administrator.pdf - Questions Answers PDF Sample Questions Reliable: https://drive.google.com/open?id=1zWK_66a0d5G7gEOP_W7wi9f_qx-XPSX-

