10 free Google Associate Google Workspace Administrator practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 108 questions. Work through them, then open each answer to check your reasoning.
Get all 108 questions (US$39) · Download these 10 as a PDF
Question 1
Your company is undergoing a regulatory compliance audit. As part of the audit, you are required to demonstrate that you can preserve all electronic communications related to a specific project for a potential legal discovery process. You need to configure Google Vault to accomplish this goal.
What should you do?
Show answer and explanation
Correct answer: C. Create a matter and a hold on all project-related data sources such as Email, Chat, and Drive within Google Workspace.
Creating a matter and hold in Google Vault is the proper legal discovery procedure that preserves all relevant communications across multiple data sources. A matter establishes the legal context, and a hold ensures all related data in Email, Chat, and Drive is preserved and cannot be deleted during the litigation hold period. This is the standard approach for compliance audits and legal discovery requirements.
Why the other options are wrong
- A. Security investigation reports show Vault log events but do not preserve data or establish legal holds.
- B. Search and export functionality can identify communications but does not preserve them or prevent deletion.
- D. Custom retention policies manage data lifecycle but do not establish the legal hold required for discovery.
Question 2
Several employees from your finance department are collaborating on a long-term, mult-hase project. You need to create a confidential group for this project as quickly as possible. You also want to minimize management overhead.
What should you do?
Show answer and explanation
Correct answer: B. Create a dynamic group and define the Department user attribute as a condition for membership with the value as the finance department.
A dynamic group automatically maintains membership based on defined user attributes, eliminating the need for manual management. By setting the Department attribute to finance department, the group self-populates with all finance employees and automatically adds or removes members as their department changes. This minimizes management overhead while ensuring confidentiality and quick deployment.
Why the other options are wrong
- A. GCDS is designed for bulk synchronization but requires more setup and ongoing manual management than dynamic groups.
- C. Allowing anyone to join contradicts the confidential requirement and defeats the purpose of restricting to the finance team.
- D. Appointing a group admin requires ongoing manual management of membership, which does not minimize overhead.
Question 3
Today your company signed up for Google Workspace Business Starter with an existing domain name. You want to add team members and manage their access to email and other services. However, you are unable to create new user accounts or change user settings. You need to fix this problem.
What should you do?
Show answer and explanation
Correct answer: B. Check domain ownership in the DNS settings.
Unable to create user accounts or change settings after signing up typically indicates that domain ownership has not been verified in DNS settings. Google Workspace requires domain ownership verification before administrative functions become available. Checking and completing the DNS verification is the necessary step to unlock full admin functionality.
Why the other options are wrong
- A. The Transfer tool is for migrating unmanaged users but does not solve the initial setup access issue.
- C. While some features may take time, domain verification is the actual blocker for admin access.
- D. Upgrading editions does not resolve the underlying domain verification requirement.
Question 4
A team of temporary employees left your organization after completing a shared project. Per company policy, you need to disable their Google Workspace accounts while preserving all project data and related communications in Google Vault for a minimum of two years. You want to comply with this policy while minimizing cost.
What should you do?
Show answer and explanation
Correct answer: A. Purchase and assign Archived User licenses to the former employees.
Archived User licenses are specifically designed for this scenario: they allow organizations to disable accounts and preserve data in Google Vault while incurring minimal cost. Archived User licenses cost significantly less than active user licenses while maintaining data preservation for the required two-year retention period, meeting both the compliance policy and cost minimization goals.
Why the other options are wrong
- B. Deleting accounts violates data preservation requirements and removes audit trail access.
- C. Suspending accounts with regular licenses still incurs full licensing costs without cost optimization.
- D. Disabling OU access does not preserve the accounts or their data in Vault for the required retention period.
Question 5
The legal department at your organization is working on a time-critical merger and acquisition (M&A) deal. They urgently require access to specific email communications from an employee who is currently on leave. The organization’s current retention policy is set to indefinite. You need to retrieve the required emails for the legal department in a manner that ensures data privacy.
What should you do?
Show answer and explanation
Correct answer: D. Use Google Vault to create a matter specific to the M&A deal. Search for relevant emails within the employee's mailbox. Export and share relevant emails with your legal department.
M&A deal. Search for relevant emails within the employee's mailbox. Export and share relevant emails with your legal department. Google Vault is the proper tool for legal and compliance purposes. Creating a matter for the M&A deal, searching the specific employee's mailbox for relevant emails, and exporting results to the legal department maintains a proper chain of custody, ensures data privacy through controlled access, and creates an audit trail. This approach protects sensitive information while meeting legal discovery requirements.
Why the other options are wrong
- A. Direct IT access and forwarding bypasses proper discovery procedures and creates privacy and audit concerns.
- B. Granting account access is excessive, creates security risks, and does not follow proper legal discovery procedures.
- C. Using delegate access bypasses the proper legal discovery process and does not create proper audit documentation.
Question 6
Your company distributes an internal newsletter that contains sensitive information to all employees by email. You’ve noticed unauthorized forwarding of this newsletter to external addresses, potentially leading to data leaks. To prevent this, you need to implement a solution that automatically detects and blocks such forwarding while allowing legitimate internal sharing.
What should you do?
Show answer and explanation
Correct answer: B. Create a Gmail content compliance rule that targets the internal newsletter, identifying instances of external forwarding. Configure the rule to reject the message when such forwarding is detected
Gmail content compliance rules can detect patterns and automatically block messages meeting specific criteria. A rule targeting the newsletter that identifies external forwarding attempts and rejects those messages prevents data leaks while being automatically enforced, allowing legitimate internal sharing through normal email forwarding mechanisms.
Why the other options are wrong
- A. Warnings alone do not prevent forwarding and rely on user compliance without technical enforcement.
- C. Building custom Apps Script solutions is overly complex and difficult to maintain compared to native compliance rules.
- D. Modifying subject lines provides no technical prevention of forwarding behavior.
Question 7
Your organization has hired temporary employees to work on a sensitive internal project. You need to ensure that the sensitive project data in Google Drive is limited to only internal domain sharing. You do not want to be overly restrictive.
What should you do?
Show answer and explanation
Correct answer: A. Configure the Drive sharing options for the domain to internal only.
Configuring Drive sharing options to internal domain only directly restricts sharing to employees within the organization while maintaining reasonable flexibility for legitimate internal collaboration. This is the standard, least restrictive approach that prevents external sharing of sensitive project data without requiring allowlisting of specific domains.
Why the other options are wrong
- B. Allowlisting requires identifying and maintaining a list of approved domains, adding administrative overhead.
- C. A DLP rule using project name as a detector is overly complex and requires ongoing refinement of detection patterns.
- D. Turning off Drive sharing entirely prevents legitimate internal collaboration, which is overly restrictive.
Question 8
Several employees at your company received messages with links to malicious websites. The messages appear to have been sent by your company’s human resources department. You need to identify which users received the emails and prevent a recurrence of similar incidents in the future.
What should you do?
Show answer and explanation
Correct answer: D. Search for the sender’s email address by using the security investigation tool. Delete the messages. Turn on the safety options for spoofing and authentication protection in Gmail settings.
The security investigation tool is the appropriate tool for investigating phishing incidents. Deleting the malicious messages removes the threat, and enabling spoofing and authentication protection in Gmail settings (SPF, DKIM, DMARC) prevents future impersonation of the HR department domain. This addresses both immediate threat removal and long-term prevention through email authentication.
Why the other options are wrong
- A. Email Log Search and instructing users to manually mark as spam does not prevent future incidents and relies on user action.
- B. Blocking a spoofed sender address is ineffective because the attacker can use different spoofed addresses in future attacks.
- C. Exporting to PST and quarantine lists do not address spoofing prevention, which is the root cause of this type of attack.
Question 9
Your organization’s users are reporting that a large volume of legitimate emails are being misidentified as spam in Gmail. You want to troubleshoot this problem while following Google-recommended practices.
What should you do?
Show answer and explanation
Correct answer: D. Contact Google Workspace support and report a suspected system-wide spam filter malfunction.
When legitimate emails are being systematically misidentified as spam across an organization, this indicates a potential system-wide issue that requires investigation by Google's support team. Contacting Google Workspace support allows trained specialists to investigate the spam filter behavior, review logs, and determine if there's a configuration issue, IP reputation problem, or actual filter malfunction. This is the Google-recommended practice for diagnosing organization-wide email delivery problems.
Why the other options are wrong
- A. Mail content compliance settings control outbound filtering, not inbound spam classification problems.
- B. Having users individually allowlist senders is a workaround, not a solution, and doesn't address the underlying system-wide issue.
- C. Disabling spam filtering entirely removes critical security protection and violates best practices; it should only be considered as a last resort diagnostic step.
Question 10
Your organization’s security team has published a list of vetted third-party apps and extensions that can be used by employees. All other apps are prohibited unless a business case is presented and approved. The Chrome Web Store policy applied at the top-level organization allows all apps and extensions with an admin blocklist. You need to disable any unapproved apps that have already been installed and prevent employees from installing unapproved apps.
What should you do?
Show answer and explanation
Correct answer: B. Change the Chrome Web Store allow/block mode setting to block all apps, admin manages allowlist. Add the apps on the security team’s vetted list to the allowlist.
To enforce an allowlist-based security model where only approved apps are available, you must change the Chrome Web Store policy from a blocklist approach to a blocklist approach inverted to an allowlist approach. This involves setting the allow/block mode to 'block all apps, admin manages allowlist,' then adding only the security team's vetted applications to the allowlist. This prevents both installation of unapproved apps and ensures existing unauthorized apps cannot run.
Why the other options are wrong
- A. Keeping the blocklist mode does not prevent installation of new unapproved apps; it only blocks specific apps rather than enforcing an allowlist model.
- C. Disabling extension types at the organizational level is too blunt and removes all extensions, rather than selectively controlling which ones are allowed.
- D. Disabling the Chrome Web Store entirely prevents access to necessary approved apps and extensions; this is not a selective control mechanism.
That was 10 of 108.
The full Google Associate Google Workspace Administrator pack has all 108 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.
