Google Google Workspace Administrator Professional Google Workspace Administrator Online Training
Google Google Workspace Administrator Online Training
The questions for Google Workspace Administrator were last updated at May 04,2025.
- Exam Code: Google Workspace Administrator
- Exam Name: Professional Google Workspace Administrator
- Certification Provider: Google
- Latest update: May 04,2025
Your company is using Google Workspace Enterprise Plus, and the Human Resources (HR) department is asking for access to Work Insights to analyze adoption of Google Workspace for all company employees. You assigned a custom role with the work Insights permission set as “view data for all teams” to the HR group, but it is reporting an error when accessing the application.
What should you do?
- A . Allocate the “view data for all teams” permission to all employees of the company.
- B . Confirm that the Work Insights app is turned ON for all employees.
- C . Confirm in Security > API controls > App Access Controls that Work Insights API is set to “unrestricted.”
- D . Confirm in Reports > BigQuery Export that the job is enabled.
Your Security Officer ran the Security Health Check and found the alert that “Installation of mobile applications from unknown sources” was occurring. They have asked you to find a way to prevent that from happening.
Using Mobile Device Management (MDM), you need to configure a policy that will not allow mobile applications to be installed from unknown sources.
What MDM configuration is needed to meet this requirement?
- A . In the Application Management menu, configure the whitelist of apps that Android and iOS devices are allowed to install.
- B . In the Application Management menu, configure the whitelist of apps that Android, iOS devices, and Active Sync devices are allowed to install.
- C . In Android Settings, ensure that “Allow non-Play Store apps from unknown sources installation” is unchecked.
- D . In Device Management > Setup > Device Approvals menu, configure the “Requires Admin approval” option.
HR informs you that a user has been terminated and their account has been suspended. The user is part of a current legal investigation, and HR requires the user’s email data to remain on hold. The terminated user’s team is actively working on a critical project with files owned by the user. You need to ensure that the terminated user’s content is appropriately kept before provisioning their license to a new user.
What two actions should you take? (Choose two.)
- A . Extend the legal hold on the user’s email data.
- B . Move project files to a Team Drive or transfer ownership.
- C . Rename the account to the new user starting next week.
- D . Delete the account, freeing up a Google Workspace License.
- E . Assign the terminated user account an Archive User license.
Your company has decided to change SSO providers. Instead of authenticating into Google Workspace and other cloud services with an external SSO system, you will now be using Google as the Identity Provider (IDP) and SSO provider to your other third-party cloud services.
What two features are essential to reconfigure in Google Workspace? (Choose two.)
- A . Apps > add SAML apps to your domain.
- B . Reconfigure user provisioning via Google Cloud Directory Sync.
- C . Replace the third-party IDP verification certificate.
- D . Disable SSO with third party IDP.
- E . Enable API Permissions for Google Cloud Platform.
You are a Workspace Administrator with a mix of Business Starter and Standard Licenses for your users. A Business Starter User in your domain mentions that they are running out of Drive Storage Quota. Without deleting data from Drive, what two actions can you take to alleviate the quota concerns for this user? (Choose two.)
- A . Add other users as “Editors” on the Drive object, thus spreading the storage quota debt between all of them.
- B . Manually export and back up the data locally, and delete the affected files from Drive to alleviate the debt.
- C . Make another user the “Owner” of the Drive objects, thus transferring the storage quota debt to them.
- D . Perform an API query for large storage drive objects, and delete them, thus alleviating the quota debt.
- E . Move the affected items to a Shared Drive. Shared Drives transfer ownership of the drive item to the domain itself, which alleviates the quota debt from that user.
Your organization implemented Single Sign-On (SSO) for the multiple cloud-based services it uses. During authentication, one service indicates that access to the SSO provider is not possible due to invalid information.
What should you do?
- A . Update the validation certificate.
- B . Verify that the Audience element in the SAML Response matches the assertion consumer service (ACS) URL
- C . Run nslookup to confirm that the service exists.
- D . Ensure that Microsoft’s Active Directory Federation Services 2.0 sends encrypted SAML Responses in default configurations.
Your organization deployed Google Workspace Enterprise within the last year, with the support of a partner. The deployment was conducted in three stages: Core IT, Google Guides, and full organization. You have been tasked with developing a targeted ongoing adoption plan for your Google Workspace organization.
What should you do?
- A . Use Google Guides to deliver ad-hoc training to all of their co-workers and reports.
- B . Use Work Insights to gather adoption metrics and target your training exercises.
- C . Use Reports APIs to gather adoption metrics and Gmail APIs to deliver training content directly.
- D . Use a script to monitor Email attachment types and target users that aren’t using Drive sharing.
Your company has just received a shipment of ten Chromebooks to be deployed across the company, four of which will be used by remote employees. In order to prepare them for use, you need to register them in Google Workspace.
What should you do?
- A . Turn on the Chromebook and press Ctrl+Alt+E at the login screen to begin enterprise enrollment.
- B . In Chrome Management | Device Settings, enable Forced Re-enrollment for all devices.
- C . Turn on the chromebook and log in as a Chrome Device admin. Press Ctrl+Alt+E to begin enterprise enrollment.
- D . Instruct the employees to log in to the Chromebook. Upon login, the auto enrollment process will begin.
Your organization recently bought 1.000 licenses for Cloud Identity Premium. The company’s development team created an application in the enterprise service bus (ESB) that will read user data in the human resources information system (HRIS) and create accounts via the Google Directory REST API.
While doing the original test before production use, the team observes a 503 error coming from Google API response after a few users are created The team believes the ESB is not the cause, because it can perform 100 requests per second without any problems.
What advice would you give the development team in order to avoid the issue?
- A . Use the domain-wide delegation API to avoid the limitation per account.
- B . Use an exponential back-off algorithm to retry failed requests.
- C . Switch from REST API to gRPC protocol for performance improvement
- D . Use the batch request architecture, because it can pack 1,000 API calls in one HTTP request.
Security and Compliance has identified secure third-party applications that should have access to Google Workspace data. You need to restrict third-party access to only approved applications
What two actions should you take? (Choose two.)
- A . Whitelist Trusted Apps
- B . Disable the Drive SDK
- C . Restrict API scopes
- D . Disable add-ons for Gmail
- E . Whitelist Google Workspace Marketplace apps