
[Oct 17, 2024] Fully Updated Free Actual Google Google-Workspace-Administrator Exam Questions
Free Google-Workspace-Administrator Questions for Google Google-Workspace-Administrator Exam [Oct-2024]
The Google Google-Workspace-Administrator exam covers a range of topics, including user and group management, security and compliance, data migration, and automation. Candidates are tested on their ability to configure and troubleshoot various Google Workspace components, including Gmail, Drive, Docs, Sheets, and Slides. Additionally, the exam assesses candidates' knowledge of Google Workspace's advanced features, such as App Maker, App Scripts, and Google Cloud Platform integration.
Google Workspace is a suite of cloud-based productivity tools that helps individuals and teams collaborate, communicate, and get work done more efficiently. As more and more organizations are moving their operations to the cloud, the demand for skilled Google Workspace administrators is on the rise. Google has designed a certification program that validates the skills and expertise of professionals who can effectively manage and optimize Google Workspace environments. The Google-Workspace-Administrator (Google Cloud Certified - Professional Google Workspace Administrator) certification exam is one such program that tests the knowledge and abilities of individuals who want to demonstrate their proficiency in managing and optimizing Google Workspace environments.
NEW QUESTION # 98
Your organization is in the process of deploying Google Drive for desktop so that your users can access Drive files directly from their desktops. For security reasons, you want to restrict Drive for desktop to only company-owned devices. What two steps should you take from the admin panel to restrict Drive for desktop to only company-owned devices?
Choose 2 answers
- A. Install the Google Endpoint Verification extension on machines using Drive for Desktop.
- B. Devices > Endpoints > Add a filter-> Management Type > Drive for desktop > Apply
- C. Apps > Google Workspace > Drive and Docs > Features and Applications > Google Drive for Desktop
> Only Allow Google Drive for desktop on authorized devices - D. Create a company-owned device inventory using an asset tag.
- E. Create a company-owned device inventory using serial numbers of devices.
Answer: A,C
Explanation:
To restrict Drive for desktop to only company-owned devices, you should:
* Go to Apps > Google Workspace > Drive and Docs > Features and Applications > Google Drive for Desktop and select Only Allow Google Drive for desktop on authorized devices. This setting ensures that only authorized devices can use Drive for desktop.
* Install the Google Endpoint Verification extension on machines using Drive for Desktop. This extension helps manage and verify devices, ensuring that only company-owned devices are allowed access.
References:
* Google Workspace Admin Help - Set up Drive for desktop
* Google Workspace Admin Help - Google Endpoint Verification
NEW QUESTION # 99
Several customers have reported receiving fake collection notices from your company. The emails were received from [email protected], which is the valid address used by your accounting department for such matters, but the email audit log does not show the emails in question. You need to stop these emails from being sent.
What two actions should you take? (Choose two.)
- A. Change the password for suspected compromised account [email protected].
- B. Configure Domain Keys Identified Mail (DKIM) to authenticate email.
- C. Configure a Sender Policy Framework (SPF) record for your domain.
- D. Disable mail delegation for the [email protected] account.
- E. Disable "Allow users to automatically forward incoming email to another address."
Answer: B,C
Explanation:
https://support.google.com/a/answer/33786?hl=en
https://support.google.com/a/answer/174124?hl=en
NEW QUESTION # 100
A company has thousands of Chrome devices and bandwidth restrictions. They want to distribute the Chrome device updates over a period of days to avoid traffic spikes that would impact the low bandwidth network.
Where should you enable this in the Chrome management settings?
- A. Update over cellular.
- B. Randomly scatter auto-updates.
- C. Disable Auto update.
- D. Throttle the bandwidth.
Answer: B
Explanation:
* Admin Console: Log into the Google Admin console at admin.google.com.
* Devices Management: Navigate to Devices > Chrome > Settings.
* Configuration:
* Under the "Chrome management" section, select "User & browser settings".
* Choose the organizational unit where you want to apply this setting.
* Auto-Updates Settings:
* Scroll down to the "Auto-update settings" section.
* Enable the "Randomly scatter auto-updates" option. This setting will spread out the updates over a period of time, reducing the load on your network.
* Save Changes: Click "Save" to apply the changes.
References
* Google Workspace Admin: Manage automatic updates
NEW QUESTION # 101
As the Workspace Administrator, you have been asked to delete a temporary Google Workspace user account in the marketing department. This user has created Drive documents in My Documents that the marketing manager wants to keep after the user is gone and removed from Workspace. The data should be visible only to the marketing manager. As the Workspace Administrator, what should you do to preserve this user's Drive data?
- A. In the user deletion process, select "Transfer" in the data in other apps section and add the manager's email address.
- B. Use Google Vault to set a retention period on the OU where the users reside.
- C. Ask the user to create a folder under MyDrive, move the documents to be shared, and then share that folder with the marketing team manager.
- D. Before deleting the user, add the user to the marketing shared drive as a contributor and move the documents into the new location.
Answer: A
Explanation:
* Access Admin Console: Log into your Google Workspace Admin Console.
* Navigate to User Management: Go to Directory > Users.
* Select the User: Find and select the temporary user account you need to delete.
* Initiate Deletion Process: Click on the user to open the account details and select the option to delete the user.
* Transfer Data: During the deletion process, you will see an option to transfer data. Select "Transfer" in the data in other apps section and enter the marketing manager's email address.
* Complete Deletion: Complete the user deletion process. The user's Drive documents will be transferred to the marketing manager's account.
References
* Google Support: Delete a user from your organization
NEW QUESTION # 102
Your company's Google Workspace primary domain is "mycompany.com," and it has acquired a startup that is using another cloud provider with a domain named "mystartup.com." You plan to add all employees from the startup to your Google Workspace domain while preserving their current mail addresses. The startup CEO's email address is [email protected], which also matches your company CEO's email address as [email protected], even though they are different people. Each must keep the usage of their email. In addition, your manager asked to have all existing security policies applied for the new employees without any duplication. What should you do to implement the migration?
- A. Create an alias domain, mystartup.com, in your existing Google Workspace domain, set up necessary DNS records, and create all startup employees with the alias domain as their primary email addresses.
- B. Create a secondary domain, mystartup.com, within your current Google Workspace domain, set up necessary DNS records, and create all startup employees with the secondary domain as their primary email addresses.
- C. Create the startup employees in the "mycompany.com' domain, and add a number at the end of the user name whenever there is a conflict. In Gmail > Routing, define a specific route for the OU that targets the startup employees, which will modify the email address domain to "mystartup.com," and remove any numbers previously added. In addition, confirm that the SPF and DKIM records are properly set.
- D. Create a new Google Workspace domain with "mystartup.com," and create a trust between both domains for reusing the same security policies and sharing employee information within the companies.
Answer: B
NEW QUESTION # 103
Your company recently migrated to Google Workspace and wants to deploy a commonly used third-party app to all of finance. Your OU structure in Google Workspace is broken down by department. You need to ensure that the correct users get this app.
What should you do?
- A. At the root level, disable the third-party app. For the Finance OU, allow users to install any application from the Google Workspace Marketplace.
- B. For the Finance OU, enable the third-party app in Marketplace Apps.
- C. At the root level, disable the third-party app. For the Finance OU, allow users to install only whitelisted apps from the Google Workspace Marketplace.
- D. For the Finance OU, enable the third-party app in SAML apps.
Answer: B
NEW QUESTION # 104
Your company recently decided to use a cloud-based ticketing system for your customer care needs. You are tasked with rerouting email coming into your customer care address, [email protected] to the cloud platform's email address, [email protected]. As a security measure, you have mail forwarding disabled at the domain level.
What should you do?
- A. Create a recipient map in the Google Workspace Admin console that maps [email protected] to [email protected]
- B. Create a rule to forward mail in the [email protected] mailbox to your- [email protected]
- C. Create a mail contact in the Google Workspace directory that has an email address of your- [email protected]
- D. Create a content compliance rule in the Google Workspace Admin console to change route to your- [email protected]
Answer: D
Explanation:
* Access the Admin Console: Log into your Google Workspace Admin Console.
* Navigate to Apps: Go to Apps > Google Workspace > Gmail > Compliance.
* Create a Content Compliance Rule: Create a new content compliance rule.
* Set Conditions: Set the condition to apply to incoming mail for [email protected].
* Change Route: Configure the rule to change the route to [email protected]. This effectively reroutes emails without using traditional forwarding, which is disabled at the domain level.
* Save and Apply: Save the compliance rule and ensure it is applied to enforce the new routing policy.
References
* Google Support: Set up content compliance
NEW QUESTION # 105
A large enterprise that had a security breach is working with an external legal team to determine best practices for an investigation. Using Google Vault, the security team is tasked with exporting data for review by the legal team. What steps should you take to securely share the data in question?
- A. Suspend the user's account, search all associated users data in Google Vault, and export the data.
- B. Immediately suspend the user's account, assign an archived user license, and export data.
- C. Determine the scope of the investigation, create a Matter and Holds in Google Vault, and share with the legal team.
- D. Immediately suspend the user's account, search for all the email messages in question, and forward to the legal team.
Answer: C
NEW QUESTION # 106
Your company is using Google Workspace Enterprise Plus, and the Human Resources (HR) department is asking for access to Work Insights to analyze adoption of Google Workspace for all company employees. You assigned a custom role with the work Insights permission set as "view data for all teams" to the HR group, but it is reporting an error when accessing the application. What should you do?
- A. Confirm in Security > API controls > App Access Controls that Work Insights API is set to "unrestricted."
- B. Confirm that the Work Insights app is turned ON for all employees.
- C. Confirm in Reports > BigQuery Export that the job is enabled.
- D. Allocate the "view data for all teams" permission to all employees of the company.
Answer: A
NEW QUESTION # 107
Your organization is about to expand by acquiring two companies, both of which are using Google Workspace. The CISO has mandated that strict 'No external content sharing' policies must be in place and followed. How should you securely configure sharing policies to satisfy both the CISO's mandate while allowing external sharing with the newly acquired companies?
- A. Allow external sharing of Drive content for the IT group only.
- B. Create a Drive DLP policy that will allow sharing to only domains on an allowlist.
- C. Let users share files between the two companies by using the 'Trusted Domains' feature. Create an allowlist of the trusted domains, and choose sharing settings for the users.
- D. Use shared drives to store the content, and share only individual files externally.
Answer: C
Explanation:
* Access Admin Console: Log in to the Google Admin console.
* Navigate to Sharing Settings: Go to Apps > Google Workspace > Drive and Docs > Sharing settings.
* Set Up Trusted Domains: Enable the Trusted Domains feature and add the domains of the newly acquired companies to the allowlist.
* Adjust Sharing Settings: Configure the sharing settings to restrict external sharing but allow sharing with the trusted domains. This ensures compliance with the CISO's mandate while enabling collaboration with the newly acquired companies.
* Communicate Changes: Inform all users about the new sharing policies and the specific domains they are allowed to share content with.
* Monitor Compliance: Regularly monitor sharing activities to ensure compliance with the new policies and make adjustments as necessary.
References:
* Google Workspace Admin Help - Sharing Settings
* Google Workspace Admin Help - Allowlist Trusted Domains
NEW QUESTION # 108
A user reached out to the IT department about a Google Group that they own: [email protected]. The group is receiving mail, and each message is also delivered directly to the user's Gmail inbox. The user wants to be able to reply to messages directly from Gmail and have them sent on behalf of the group, not their individual account. Currently, their replies come from their individual account. What would you instruct the user to do?
- A. Set the group address to be the default sender within the group's posting policies.
- B. Add the user's individual account as a delegate to the group's inbox. They can then toggle between the accounts and use the Gmail interface on behalf of the group.
- C. Create a new content compliance rule that matches the user's outgoing messages with the group copied, and have it modify the sender to be the group address.
- D. Add the group as an email address that can be sent from within Gmail, and verify that the user has access. They can then choose to reply from the group.
Answer: D
Explanation:
* Send from Group Email:
* To send emails on behalf of a group, users must add the group's email address to their Gmail account and verify access.
* This allows them to select the group email as the sender when composing or replying to messages.
* Steps to Add Group Email:
* The user should go to their Gmail settings by clicking the gear icon and selecting "See all settings".
* Navigate to the "Accounts and Import" tab.
* Under "Send mail as," click "Add another email address".
* Enter the group email address ([email protected]) and follow the verification process, which may involve receiving and entering a confirmation code.
* Once verified, the user can select the group email address from the "From" dropdown menu when composing or replying to messages.
References
* Google Workspace Admin Help: Send Emails from a Group Alias
NEW QUESTION # 109
All Human Resources employees at your company are members of the "HR Department" Team Drive. The HR Director wants to enact a new policy to restrict access to the "Employee Compensation" subfolder stored on that Team Drive to a small subset of the team.
What should you do?
- A. Use the Drive API to modify the permissions of the Employee Compensation subfolder.
- B. Move the subfolder to the HR Director's MyDrive and share it with the relevant team members.
- C. Use the Drive API to modify the permissions of the individual files contained within the subfolder.
- D. Move the contents of the subfolder to a new Team Drive with only the relevant team members.
Answer: D
Explanation:
"Inherited permissions can't be removed from a file or folder in a shared drive".
ref: https://developers.google.com/drive/api/v3/manage-sharing
NEW QUESTION # 110
Users in your organization are routinely complaining that they receive messages containing words of profanity they find inappropriate in a professional setting. As the administrator what steps should you take to prevent the messages from being delivered to users mailboxes?
- A. Set up a Gmail DLP policy.
- B. Enable optical character recognition (OCR)
- C. Configure an attachment compliance rule
- D. Configure an objectionable content rule
Answer: D
Explanation:
To prevent messages containing profanity from being delivered to users' mailboxes, follow these steps:
* Sign in to the Google Admin console: Use an account with super administrator privileges.
* Navigate to the Gmail settings: Go to Apps > Google Workspace > Gmail > Manage settings.
* Create a new content compliance rule:
* Click on "Compliance" and then "Content compliance."
* Click on "Add another rule."
* Provide a name for the rule, such as "Profanity Filter."
* Set the conditions for the rule:
* In the "Add setting" section, choose "If ANY of the following match the message."
* Select "Metadata match" or "Advanced content match."
* For "Advanced content match," use predefined content filters or add custom words that are considered profane.
* Configure the actions:
* Set the action to "Reject message" or "Quarantine message."
* Optionally, you can notify an administrator or sender about the rejection or quarantine.
* Save the rule: Click on "Save" to activate the rule.
References:
* Google Workspace Admin Help - Configure content compliance
* Google Workspace Admin Help - Objectionable content
NEW QUESTION # 111
Your default Vault retention policy for Gmail is set to 365 days Your legal department has just informed you that emails sent and received by the customer support department are sensitive and must be retained for only
30 days You must enforce this new retention policy in the simplest way What should you do?
- A. Create a custom retention policy in Vault for Gmail for 30 days and apply it to the customer support organizational unit (OU)
- B. Create two custom retention policies in Vault one for 30 days that is applied to the customer support organizational unit (OU) and one for 365 days that is applied to all other OUs in your directory
- C. Change the current default retention policy in Vault for Gmail to 30 days and apply it to the customer support organizational unit (OU) Configure a custom retention policy for Gmail for 365 days for your domain
- D. Change the current default retention policy for Gmail to 30 days Configure two custom retention policies in Vault one for 30 days that is applied to the customer support organizational unit (OU) and one for 365 days that is applied to all other OUs in your directory
Answer: A
Explanation:
Step by Step Comprehensive Detailed Explanation:
* Access Google Vault: Sign in to Google Vault.
* Retention Policies: Navigate to "Retention" from the side menu.
* Create New Retention Rule: Click on "Create retention rule."
* Set Duration: Set the retention period to 30 days.
* Apply to OU: Apply this retention rule specifically to the organizational unit (OU) for the customer support department.
* Exclude Default Rule: Ensure that this custom rule overrides the default 365-day retention policy for the customer support OU.
* Save and Activate: Save the rule and ensure it is activated.
References:
* Google Vault Help: Set retention rules
NEW QUESTION # 112
You need to protect your users from untrusted senders sending encrypted attachments via email. You must ensure that these messages are not delivered to users' mailboxes. What step should be taken?
- A. Enable a safety rule to send these types of messages to a quarantine.
- B. Use Google Vault to remove these messages from users mailboxes.
- C. Use the security center to remove the messages from users' mailboxes
- D. Enable a safety rule to send these types of messages to spam.
Answer: A
NEW QUESTION # 113
What action should be taken to configure alerting related to phishing attacks?
- A. Set up an email settings changed alert.
- B. Set up an Admin audit log event alert.
- C. Set up a suspicious login event alert.
- D. Set up a Token audit log event alert.
Answer: C
Explanation:
* Admin Console: Log into the Google Admin console at admin.google.com.
* Security Settings: Navigate to Security > Investigation Tool.
* Create an Alert:
* Click on "Create activity rule".
* In the conditions section, select "Event is" and choose "Login".
* Set the condition to "Suspicious login".
* Alert Details: Configure the alert details, such as who will receive the alert and any additional notification settings.
* Save and Activate: Save the rule and activate it to start monitoring for suspicious login attempts.
References
* Google Workspace Admin: Manage Alerts
* Google Workspace Security: Investigation Tool
NEW QUESTION # 114
Employees at your organization frequently and mistakenly delete important emails that they receive from your payroll department The employees have to file support tickets for the IT team to find and restore these emails You must provide an automated solution that minimizes IT overhead and prevents these emails from being permanently deleted from their inboxes What should you do?
- A. Create a content compliance rule that targets internal messages Use an advanced content match for the sender header to match the payroll department's email Quarantine the message so that administrators can review the email before they release it to the user
- B. Create a content compliance rule that targets all internal messages that are sent from the payroll department Modify the message by prepending a custom subject line to all payroll emails so that employees know not to delete them
- C. Create an Apps Script project that uses the Gmail API to find any recently deleted emails and automatically restore them to the inboxes Set the script trigger to be time-driven and run every hour
- D. Create an activity rule by using Gmail log events with two conditions one for the event of an email deletion and another that matches the header address to the payroll department's email Create an action that restores messages Set the rule to run every hour
Answer: D
Explanation:
* Access Admin Console: Go to the Google Admin console and navigate to the 'Reports' section.
* Activity Rule Setup: Select 'Manage Rules' and create a new rule.
* Define Conditions:
* Condition 1: Event equals 'Email Deletion'.
* Condition 2: Header address matches the payroll department's email address.
* Set Action: Define the action to restore the messages to the inbox.
* Schedule the Rule: Set the rule to run every hour.
* Test and Monitor: Ensure the rule is working as expected by monitoring the results and making adjustments if necessary.
References
* Create and manage activity rules
* Gmail API
NEW QUESTION # 115
The CEO of your company heard about new security and collaboration features and wants to know how to stay up to date. You are responsible for testing and staying up to date with new features, and have been asked to prepare a presentation for management.
What should you do?
- A. Create a support ticket for the Google Workspace roadmap, and ask to enable the latest release of Google Workspace.
- B. Subscribe to the Google Workspace release calendar, and Join the Google Cloud Connect Community.
- C. Change Google Workspace release track to: Rapid Release for faster access to new features.
- D. Download the Google Workspace roadmap, and work together with a deployment specialist for new features.
Answer: B
NEW QUESTION # 116
The application development team has come to you requesting that a new, internal, domain-owned Google Workspace app be allowed to access Google Drive APIs. You are currently restricting access to all APIs using approved whitelists, per security policy. You need to grant access for this app.
What should you do?
- A. Add OAuth Client ID to Google Drive Trusted List.
- B. Whitelist the app in the Google Workspace Marketplace.
- C. Enable "trust domain owned apps" setting.
- D. Enable all API access for Google Drive.
Answer: A
NEW QUESTION # 117
Your organization is planning to remove any dependencies on Active Directory (AD) from all Cloud applications they are using You are currently using Google Cloud Directory Sync (GCDS) with on-premises AD as a source to provision user accounts in Google Workspace. Your organization is also using a software-as-a-service (SaaS) human resources information system (HRIS) that offers integration via CSV export and Open API standard.
Additional requirements for the solution include:
* It should not require a subscription to any additional third-party service.
* The process must be automated from beginning to end.
You are tasked with the design and implementation of a solution to address user provisioning with these requirements.
What solution should you implement?
- A. Export HRIS data to a CSV file every day. and build a solution to define the delta with the previous day; import the result as a CSV file via the Admin console.
- B. Modify the GCDS configuration to use the HRIS application as the data source and complete any necessary adjustments
- C. Build an application that will fetch updated data from the HRIS system via Open API. and then update Google Workspace with the Directory API accordingly.
- D. Set up Azure AD and federate on-premises AD with it. Provision user accounts from Azure AD with the Google-recommended process.
Answer: C
Explanation:
Given the requirements to eliminate dependencies on Active Directory, automate the process, and avoid third-party subscriptions, the best solution is to build an application that will fetch updated data from the HRIS system via its Open API. This application will then use the Directory API to update Google Workspace user accounts accordingly. This approach leverages existing tools (HRIS Open API and Google Directory API), ensures full automation from start to end, and does not require additional subscriptions.
References:
* Google Workspace Admin Help - Directory API
* Google Workspace Admin Help - Google Cloud Directory Sync overview
NEW QUESTION # 118
Your company has a broad, granular IT administration team, and you are in charge of ensuring proper administrative control. One of those teams, the security team, requires access to the Security Investigation Tool. What should you do?
- A. Assign the pre-built security admin role to the security team members.
- B. Assign the Super Admin Role to the security team members.
- C. Create a Custom Admin Role with the security settings privilege, and then assign the role to each of the security team members.
- D. Create a Custom Admin Role with the Security Center privileges, and then assign the role to each of the security team members.
Answer: D
Explanation:
To provide the security team with access to the Security Investigation Tool, the appropriate privileges must be granted through a custom admin role.
* Create Custom Admin Role:
* In the Google Admin console, navigate to Admin roles.
* Click on Create new role.
* Assign Security Center Privileges:
* Name the role appropriately, such as "Security Investigator".
* Under Privileges, expand the Security Center section.
* Select the necessary privileges, including access to the Security Investigation Tool.
* Assign Role to Users:
* After creating the role, go to the Admin roles section.
* Click on Assign users and add the relevant security team members to this custom role.
* Save and Verify:
* Save the role and verify that the assigned users have the correct access.
Creating a custom admin role with specific security privileges ensures that the security team has the necessary tools to perform their duties without granting excessive permissions.
References:
* Manage admin roles
* Security Center overview
NEW QUESTION # 119
As a team manager, you need to create a vacation calendar that your team members can use to share their time off. You want to use the calendar to visualize online status for team members, especially if multiple individuals are on vacation What should you do to create this calendar?
- A. Request the creation of a calendar resource, configure the calendar to "Automatically add all invitations to this calendar," and give your team "See only free/busy" access.
- B. Create a secondary calendar under your account, and give your team "See only free/busy" access
- C. Create a secondary calendar under your account, and give your team "Make changes to events" access.
- D. Request the creation of a calendar resource, configure the calendar to "Auto-accept invitations that do not conflict," and give your team "See all event details" access.
Answer: C
Explanation:
* Create Secondary Calendar: As the team manager, create a new calendar under your Google account specifically for tracking team vacations.
* Access Settings: Go to the calendar settings and navigate to "Share with specific people".
* Grant Access: Add your team members and give them "Make changes to events" access, allowing them to add their vacation times directly to the calendar.
* Educate Team: Inform team members on how to use this calendar to add their vacation times and check others' schedules.
* Monitor Usage: Regularly review the calendar to ensure it is being used correctly and effectively by all team members.
References:
* Google Workspace Admin Help - Share a Calendar
* Google Workspace Admin Help - Create a Team Calendar
NEW QUESTION # 120
HR informs you that a user has been terminated and their account has been suspended. The user is part of a current legal investigation, and HR requires the user's email data to remain on hold. The terminated user's team is actively working on a critical project with files owned by the user. You need to ensure that the terminated user's content is appropriately kept before provisioning their license to a new user.
What two actions should you take? (Choose two.)
- A. Delete the account, freeing up a Google Workspace License.
- B. Extend the legal hold on the user's email data.
- C. Move project files to a Team Drive or transfer ownership.
- D. Rename the account to the new user starting next week.
- E. Assign the terminated user account an Archive User license.
Answer: C,E
Explanation:
https://support.google.com/vault/answer/2473591?hl=en
NEW QUESTION # 121
Your organization has upgraded to a Google Workspace edition with Vault and has hired a new audit team You are configuring access for this audit team with these privileges
* Chief legal executive - reporting privileges
* Legal audit manager - full Vault privileges
* Data reviewer - searching privileges
You must enable access for these three roles What should you do?
- A. Set up an Admin role with minimal Vault privileges and assign the rote to all Vault users Approve additional privileges that are requested through a formal approval process
- B. Set up three different Admin roles with specific privileges that match the audit teams responsibilities Assign these Admin roles to the respective users.
- C. Assign Google Vault licenses to these users that allow all privileges required for access
- D. Set up Google Vault service as On for these specific users.
Answer: B
Explanation:
* Navigate to Admin Roles: Go to the Google Admin console and navigate to the 'Admin roles' section.
* Create Admin Roles: Create three separate admin roles:
* Chief Legal Executive: Assign reporting privileges only.
* Legal Audit Manager: Assign full Vault privileges.
* Data Reviewer: Assign searching privileges.
* Assign Roles to Users: Assign the created roles to the respective users (Chief Legal Executive, Legal Audit Manager, Data Reviewer).
* Set Up Google Vault Access: Ensure the Google Vault service is turned on for these users by navigating to 'Apps' > 'Google Workspace' > 'Google Vault' and verifying that the service is enabled for their organizational unit.
References
* Manage admin roles
* Google Vault permissions
NEW QUESTION # 122
Your admin quarantine is becoming a burden to manage due to a consistently high influx of messages that match the content compliance rule Your security team will not allow you to remove or relax this rule, and as a result, you need assistance processing the messages in the quarantine. What is the first step you should take to enable others to help manage the quarantine, while maintaining security?
- A. Give the users Services > Gmail > Access Admin Quarantine admin privileges.
- B. Give the users super admin rights to view the admin quarantine.
- C. Configure the admin quarantine to allow end users to release messages.
- D. Give the users Services > Security Center admin privileges.
Answer: A
Explanation:
To enable others to help manage the admin quarantine while maintaining security, give the users Services > Gmail > Access Admin Quarantine admin privileges. This specific privilege allows designated users to view and manage the admin quarantine without granting excessive administrative rights.
* Go to the Admin console.
* Navigate to Account > Admin roles.
* Select the role that you want to assign to users or create a new role.
* Assign the "Services > Gmail > Access Admin Quarantine" privilege to the role.
* Add the users to this role.
References:
* Google Workspace Admin Help: Admin quarantine
NEW QUESTION # 123
......
Google-Workspace-Administrator exam is designed for professionals who want to demonstrate their expertise in managing and administering Google Workspace solutions. Google Cloud Certified - Professional Google Workspace Administrator certification is ideal for IT administrators, system administrators, and technical professionals who want to showcase their ability to leverage Google Workspace to drive business success.
Validate your Google-Workspace-Administrator Exam Preparation with Google-Workspace-Administrator Practice Test: https://examsboost.validbraindumps.com/Google-Workspace-Administrator-exam-prep.html