Free Google Associate Google Workspace Administrator practice questions

10 free Google Associate Google Workspace Administrator practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 108 questions. Work through them, then open each answer to check your reasoning.

Question 1

Your company is undergoing a regulatory compliance audit. As part of the audit, you are required to demonstrate that you can preserve all electronic communications related to a specific project for a potential legal discovery process. You need to configure Google Vault to accomplish this goal.

What should you do?

  1. Use the security investigation report to show Vault log events.
  2. Use the search and export functionality to identify all relevant communications within the project timeframe.
  3. Create a matter and a hold on all project-related data sources such as Email, Chat, and Drive within Google Workspace.
  4. Create a custom retention policy for the project data. Ensure that the policy covers the required retention period.
Show answer and explanation

Correct answer: C. Create a matter and a hold on all project-related data sources such as Email, Chat, and Drive within Google Workspace.

sources such as Email, Chat, and Drive within Google Workspace. Creating a matter and hold in Google Vault is the proper legal discovery procedure that preserves all relevant communications across multiple data sources. A matter establishes the legal context, and a hold ensures all related data in Email, Chat, and Drive is preserved and cannot be deleted during the litigation hold period. This is the standard approach for compliance audits and legal discovery requirements.

Why the other options are wrong

  • A. Security investigation reports show Vault log events but do not preserve data or establish legal holds.
  • B. Search and export functionality can identify communications but does not preserve them or prevent deletion.
  • D. Custom retention policies manage data lifecycle but do not establish the legal hold required for discovery.

Question 2

Several employees from your finance department are collaborating on a long-term, multi- phase project. You need to create a confidential group for this project as quickly as possible. You also want to minimize management overhead.

What should you do?

  1. Create a Google Group by using Google Cloud Directory Sync (GCDS) to automatically sync the members.
  2. Create a dynamic group and define the Department user attribute as a condition for membership with the value as the finance department.
  3. Create a Google Group and update the settings to allow anyone in the organization to join the group.
  4. Create a Google Group and appoint a group admin to manage the membership of this group.
Show answer and explanation

Correct answer: B. Create a dynamic group and define the Department user attribute as a condition for membership with the value as the finance department.

user attribute as a condition for membership with the value as the finance department. A dynamic group automatically maintains membership based on defined user attributes, eliminating the need for manual management. By setting the Department attribute to finance department, the group self-populates with all finance employees and automatically adds or removes members as their department changes. This minimizes management overhead while ensuring confidentiality and quick deployment.

Why the other options are wrong

  • A. GCDS is designed for bulk synchronization but requires more setup and ongoing manual management than dynamic groups.
  • C. Allowing anyone to join contradicts the confidential requirement and defeats the purpose of restricting to the finance team.
  • D. Appointing a group admin requires ongoing manual management of membership, which does not minimize overhead.

Question 3

Today your company signed up for Google Workspace Business Starter with an existing domain name. You want to add team members and manage their access to email and other services. However, you are unable to create new user accounts or change user settings. You need to fix this problem.

What should you do?

  1. Run the Transfer tool to bring unmanaged users to your Workspace account.
  2. Check domain ownership in the DNS settings.
  3. Wait 24 hours after signing up for the features to become active.
  4. Upgrade to a Google Workspace Enterprise edition.
Show answer and explanation

Correct answer: B. Check domain ownership in the DNS settings.

Unable to create user accounts or change settings after signing up typically indicates that domain ownership has not been verified in DNS settings. Google Workspace requires domain ownership verification before administrative functions become available. Checking and completing the DNS verification is the necessary step to unlock full admin functionality.

Why the other options are wrong

  • A. The Transfer tool is for migrating unmanaged users but does not solve the initial setup access issue.
  • C. While some features may take time, domain verification is the actual blocker for admin access.
  • D. Upgrading editions does not resolve the underlying domain verification requirement.

Question 4

A team of temporary employees left your organization after completing a shared project. Per company policy, you need to disable their Google Workspace accounts while preserving all project data and related communications in Google Vault for a minimum of two years. You want to comply with this policy while minimizing cost.

What should you do?

  1. Purchase and assign Archived User licenses to the former employees.
  2. Transfer the former employees’ files and data to active user accounts. Delete the former employees’ Workspace accounts.
  3. Purchase additional user licenses and suspend the former employees’ accounts.
  4. Move the former employees to their own organizational unit (OU) and disable access to Google services for that OU.
Show answer and explanation

Correct answer: A. Purchase and assign Archived User licenses to the former employees.

former employees. Archived User licenses are specifically designed for this scenario: they allow organizations to disable accounts and preserve data in Google Vault while incurring minimal cost. Archived User licenses cost significantly less than active user licenses while maintaining data preservation for the required two-year retention period, meeting both the compliance policy and cost minimization goals.

Why the other options are wrong

  • B. Deleting accounts violates data preservation requirements and removes audit trail access.
  • C. Suspending accounts with regular licenses still incurs full licensing costs without cost optimization.
  • D. Disabling OU access does not preserve the accounts or their data in Vault for the required retention period.

Question 5

The legal department at your organization is working on a time-critical merger and acquisition (M&A) deal. They urgently require access to specific email communications from an employee who is currently on leave. The organization’s current retention policy is set to indefinite. You need to retrieve the required emails for the legal department in a manner that ensures data privacy.

What should you do?

  1. Instruct the IT department to directly access and forward the relevant emails to the legal department.
  2. Temporarily grant the legal department access to the employee’s email account with a restricted scope that is limited to the M&A-related emails.
  3. Ask a colleague with delegate access to the employee's mailbox to identify and forward the relevant emails to the legal department.
  4. Use Google Vault to create a matter specific to the M&A deal. Search for relevant emails within the employee's mailbox. Export and share relevant emails with your legal department.
Show answer and explanation

Correct answer: D. Use Google Vault to create a matter specific to the M&A deal. Search for relevant emails within the employee's mailbox. Export and share relevant emails with your legal department.

M&A deal. Search for relevant emails within the employee's mailbox. Export and share relevant emails with your legal department. Google Vault is the proper tool for legal and compliance purposes. Creating a matter for the M&A deal, searching the specific employee's mailbox for relevant emails, and exporting results to the legal department maintains a proper chain of custody, ensures data privacy through controlled access, and creates an audit trail. This approach protects sensitive information while meeting legal discovery requirements.

Why the other options are wrong

  • A. Direct IT access and forwarding bypasses proper discovery procedures and creates privacy and audit concerns.
  • B. Granting account access is excessive, creates security risks, and does not follow proper legal discovery procedures.
  • C. Using delegate access bypasses the proper legal discovery process and does not create proper audit documentation.

Question 6

Your company distributes an internal newsletter that contains sensitive information to all employees by email. You’ve noticed unauthorized forwarding of this newsletter to external addresses, potentially leading to data leaks. To prevent this, you need to implement a solution that automatically detects and blocks such forwarding while allowing legitimate internal sharing.

What should you do?

  1. Add a banner to the newsletter that warns users that external sharing is prohibited.
  2. Create a Gmail content compliance rule that targets the internal newsletter, identifying instances of external forwarding. Configure the rule to reject the message when such forwarding is detected
  3. Develop an Apps Script project by using the Gmail API to scan sent emails for the newsletter content and external recipients. Automatically revoke access for violating users.
  4. Create a content compliance rule to modify the newsletter subject line, adding a warning against external forwarding.
Show answer and explanation

Correct answer: B. Create a Gmail content compliance rule that targets the internal newsletter, identifying instances of external forwarding. Configure the rule to reject the message when such forwarding is detected

the internal newsletter, identifying instances of external forwarding. Configure the rule to reject the message when such forwarding is detected Gmail content compliance rules can detect patterns and automatically block messages meeting specific criteria. A rule targeting the newsletter that identifies external forwarding attempts and rejects those messages prevents data leaks while being automatically enforced, allowing legitimate internal sharing through normal email forwarding mechanisms.

Why the other options are wrong

  • A. Warnings alone do not prevent forwarding and rely on user compliance without technical enforcement.
  • C. Building custom Apps Script solutions is overly complex and difficult to maintain compared to native compliance rules.
  • D. Modifying subject lines provides no technical prevention of forwarding behavior.

Question 7

Your organization has hired temporary employees to work on a sensitive internal project. You need to ensure that the sensitive project data in Google Drive is limited to only internal domain sharing. You do not want to be overly restrictive.

What should you do?

  1. Configure the Drive sharing options for the domain to internal only.
  2. Restrict the Drive sharing options for the domain to allowlisted domains.
  3. Create a Drive DLP rule, and use the sensitive internal Project name as the detector.
  4. Turn off the Drive sharing setting from the Team dashboard.
Show answer and explanation

Correct answer: A. Configure the Drive sharing options for the domain to internal only.

internal only. Configuring Drive sharing options to internal domain only directly restricts sharing to employees within the organization while maintaining reasonable flexibility for legitimate internal collaboration. This is the standard, least restrictive approach that prevents external sharing of sensitive project data without requiring allowlisting of specific domains.

Why the other options are wrong

  • B. Allowlisting requires identifying and maintaining a list of approved domains, adding administrative overhead.
  • C. A DLP rule using project name as a detector is overly complex and requires ongoing refinement of detection patterns.
  • D. Turning off Drive sharing entirely prevents legitimate internal collaboration, which is overly restrictive.

Question 8

Several employees at your company received messages with links to malicious websites. The messages appear to have been sent by your company’s human resources department. You need to identify which users received the emails and prevent a recurrence of similar incidents in the future.

What should you do?

  1. Search the sender’s email address by using Email Log Search. Identify the users that received the messages. Instruct them to mark them as spam in Gmail, delete the messages, and empty the trash.
  2. Search for the sender’s email address by using the security investigation tool. Mark the messages as phishing. Add the sender’s email address to the Blocked senders list in the Spam, Phishing and Malware setting in Gmail to automatically reject future messages.
  3. Collect a list of users who received the messages. Search the recipients’ email addresses in Google Vault. Export and download the malicious emails in PST file format. Add the sender’s email address to a quarantine list setting in Gmail to quarantine any future emails from the sender.
  4. Search for the sender’s email address by using the security investigation tool. Delete the messages. Turn on the safety options for spoofing and authentication protection in Gmail settings.
Show answer and explanation

Correct answer: D. Search for the sender’s email address by using the security investigation tool. Delete the messages. Turn on the safety options for spoofing and authentication protection in Gmail settings.

security investigation tool. Delete the messages. Turn on the safety options for spoofing and authentication protection in Gmail settings. The security investigation tool is the appropriate tool for investigating phishing incidents. Deleting the malicious messages removes the threat, and enabling spoofing and authentication protection in Gmail settings (SPF, DKIM, DMARC) prevents future impersonation of the HR department domain. This addresses both immediate threat removal and long-term prevention through email authentication.

Why the other options are wrong

  • A. Email Log Search and instructing users to manually mark as spam does not prevent future incidents and relies on user action.
  • B. Blocking a spoofed sender address is ineffective because the attacker can use different spoofed addresses in future attacks.
  • C. Exporting to PST and quarantine lists do not address spoofing prevention, which is the root cause of this type of attack.

Question 9

Your organization’s users are reporting that a large volume of legitimate emails are being misidentified as spam in Gmail. You want to troubleshoot this problem while following Google-recommended practices.

What should you do?

  1. Adjust the organization’s mail content compliance settings in the Admin console.
  2. Advise users to individually allowlist senders.
  3. Disable spam filtering for all users.
  4. Contact Google Workspace support and report a suspected system-wide spam filter malfunction.
Show answer and explanation

Correct answer: D. Contact Google Workspace support and report a suspected system-wide spam filter malfunction.

suspected system-wide spam filter malfunction. When legitimate emails are being systematically misidentified as spam across an organization, this indicates a potential system-wide issue that requires investigation by Google's support team. Contacting Google Workspace support allows trained specialists to investigate the spam filter behavior, review logs, and determine if there's a configuration issue, IP reputation problem, or actual filter malfunction. This is the Google-recommended practice for diagnosing organization-wide email delivery problems.

Why the other options are wrong

  • A. Mail content compliance settings control outbound filtering, not inbound spam classification problems.
  • B. Having users individually allowlist senders is a workaround, not a solution, and doesn't address the underlying system-wide issue.
  • C. Disabling spam filtering entirely removes critical security protection and violates best practices; it should only be considered as a last resort diagnostic step.

Question 10

Your organization’s security team has published a list of vetted third-party apps and extensions that can be used by employees. All other apps are prohibited unless a business case is presented and approved. The Chrome Web Store policy applied at the top-level organization allows all apps and extensions with an admin blocklist. You need to disable any unapproved apps that have already been installed and prevent employees from installing unapproved apps.

What should you do?

  1. Change the Chrome Web Store allow/block mode setting to allow all apps, admin manages blocklist, In the App access control card, block any existing web app that is not on the security team’s vetted list.
  2. Change the Chrome Web Store allow/block mode setting to block all apps, admin manages allowlist. Add the apps on the security team’s vetted list to the allowlist.
  3. Disable Extensions and Chrome packaged apps as Allowed types of apps and extensions for the top-level organizational unit. Selectively enable the appropriate extension types for each suborganization
  4. Disable the Chrome Web Store service for the top-level organizational unit. Enable the Chrome Web Store service for organizations that require Chrome apps and extensions.
Show answer and explanation

Correct answer: B. Change the Chrome Web Store allow/block mode setting to block all apps, admin manages allowlist. Add the apps on the security team’s vetted list to the allowlist.

setting to block all apps, admin manages allowlist. Add the apps on the security team’s vetted list to the allowlist. To enforce an allowlist-based security model where only approved apps are available, you must change the Chrome Web Store policy from a blocklist approach to a blocklist approach inverted to an allowlist approach. This involves setting the allow/block mode to 'block all apps, admin manages allowlist,' then adding only the security team's vetted applications to the allowlist. This prevents both installation of unapproved apps and ensures existing unauthorized apps cannot run.

Why the other options are wrong

  • A. Keeping the blocklist mode does not prevent installation of new unapproved apps; it only blocks specific apps rather than enforcing an allowlist model.
  • C. Disabling extension types at the organizational level is too blunt and removes all extensions, rather than selectively controlling which ones are allowed.
  • D. Disabling the Chrome Web Store entirely prevents access to necessary approved apps and extensions; this is not a selective control mechanism.

That was 10 of 108.

The full Google Associate Google Workspace Administrator pack has all 108 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.

Get the full pack