What the Associate Google Workspace Administrator exam covers
- Managing user accounts, domains, and Directory161 questions
- Managing core Workspace services161 questions
- Managing data governance and compliance140 questions
- Managing security policies and access controls162 questions
- Managing browsers and endpoints94 questions
- Monitoring and troubleshooting common issues144 questions
Free Associate Google Workspace Administrator sample questions
A sample of 10 questions with answers and explanations. Sign up free to practice all 862.
-
Larkspur Design is leaving a hosted IMAP email provider and wants to copy existing mail into Gmail. IT has no on-premises servers and wants to run the whole migration from the Admin console. Which Google tool should the administrator use?
- AGoogle Cloud Directory Sync
- BData Migration ServiceCorrect
- CGoogle Workspace Migration for Microsoft Outlook
- DGoogle Takeout
✓ Correct answer: BData Migration Service is the Admin console tool for importing email from sources such as a generic IMAP server, with no local server software to install. It connects to the source, copies messages into Gmail, and is managed entirely from the console.
Why the other options are wrong- AGCDS synchronizes directory identities from an LDAP source and does not copy mailbox contents.
- CGWMMO runs on an individual Windows workstation against an Outlook profile, not as a console-based IMAP mailbox migration.
- DTakeout exports a user's own data out of Workspace and does not import mail from another provider.
-
After a phishing incident at Vantage Realty, IT must force every user in the Corporate organizational unit to set a new password the next time they sign in. What is the most efficient way?
- ASelect the users in that organizational unit and apply 'Require password change' as a bulk action.Correct
- BOpen each account and manually type a new password for every user.
- CSet the organization's password expiration policy to zero days.
- DTurn on enforced 2-Step Verification for the organizational unit.
✓ Correct answer: AIn Directory > Users you can filter to the organizational unit, select the affected users, and apply 'Require password change' in one bulk action. That forces each of them to set a new password at their next sign-in without editing accounts one at a time.
Why the other options are wrong- BEditing every account by hand is slow and unnecessary when a bulk action exists.
- CA zero-day expiration is not the intended control and does not cleanly force a one-time reset.
- DEnforcing 2-Step Verification adds a second factor but does not require a password change.
-
During a coexistence period, Tailspin Toys wants every inbound message delivered to the user's new Gmail mailbox and, as an additional copy, to a legacy archiving server. Which mail flow delivers the same message to two separate systems?
- ADual deliveryCorrect
- BSplit delivery
- CSMTP relay service
- DA default routing catch-all
✓ Correct answer: ADual delivery sends the primary message to the Gmail mailbox and also delivers a copy to a second system such as a legacy archive. It is commonly used during migration or coexistence so both platforms receive every message.
Why the other options are wrong- BSplit delivery sends each message to only one system based on the recipient, not a copy to two systems.
- CThe SMTP relay service relays outbound mail from apps and devices through Google; it does not duplicate inbound mail.
- DA default routing catch-all handles mail to unmatched addresses; it does not copy every message to a second system.
-
Fjord Bank must block external sharing entirely for its Finance organizational unit, but allow its Marketing group to share only with two named partner agencies, with different rules for other teams. A single external-sharing on/off toggle is too coarse. Which capability lets the administrator express these granular source-to-target relationships?
- ADrive trust rulesCorrect
- BThe Drive and Docs general sharing settings
- CContext-Aware Access levels
- DDLP rules for Drive
✓ Correct answer: ATrust rules let an administrator define who (a scope such as an OU or group) can share with which target (internal units or specific external domains) and in which direction. This granularity goes well beyond the single on/off/allowlist choices of the basic sharing settings.
Why the other options are wrong- BGeneral sharing settings apply broad on, off, or allowlist choices per OU but cannot model per-group source-to-target rules against specific external domains.
- CContext-Aware Access gates access by device and location attributes; it does not control who may share content with which organizations.
- DDLP rules inspect content and block sharing of sensitive data, but they do not define trusted sharing relationships between units and domains.
-
How does a Vault hold interact with an existing retention rule that would otherwise purge a user's data at Fernwood Realty?
- ABoth apply, so the data is purged on whichever period ends first
- BThe retention rule overrides the hold, because retention rules are organization-wide
- CThe hold pauses the retention rule for 30 days and then allows the purge
- DThe hold preserves the data indefinitely, overriding the rule until the hold is removedCorrect
✓ Correct answer: DA hold takes precedence over any retention rule and preserves the covered data indefinitely, blocking purge. Only when the hold is removed does the data become subject to retention rules again.
Why the other options are wrong- AThe hold does not race the retention period; it blocks purge entirely while active.
- BHolds override retention rules regardless of the rule's scope.
- CHolds do not expire after 30 days; they preserve data until an administrator releases them.
-
An administrator needs to explain precisely what the Data regions policy governs. Which statement is accurate?
- AIt sets the geographic location of covered data at rest for supported servicesCorrect
- BIt restricts which countries users are allowed to sign in from
- CIt sets the region from which Takeout archives are emailed
- DIt fixes the physical route mail takes in transit between servers
✓ Correct answer: AThe Data regions policy determines the geographic location of covered data at rest for supported Workspace services. It is a data residency control, not a login, export, or routing control.
Why the other options are wrong- BRestricting sign-in locations is handled by context-aware access, not Data regions.
- CTakeout does not email archives from a chosen region, and the policy does not govern that.
- DData regions applies to data at rest, not to the path data takes in transit.
-
An administrator at Pemberton Retail is defining Context-Aware Access levels. Which of the following are valid conditions the administrator can use? (Select all that apply.)
- AIP subnet ranges in CIDR notationCorrect
- BThe recipient's email domain on outbound messages
- CGeographic regionCorrect
- DDevice policy attributes such as encryption and screen lockCorrect
- EThe sending server's SPF record status
✓ Correct answer: A, C, DContext-Aware Access levels can be built from network attributes (IP subnets in CIDR notation), the geographic region a request originates from, and device-policy attributes such as encryption, screen lock, and OS version. These are the building blocks the level evaluates when a user tries to reach an assigned app.
Why the other options are wrong- BAn outbound recipient domain is a mail-routing and DLP concern, not a Context-Aware Access condition.
- ESPF is an email-authentication mechanism evaluated on inbound mail, not a device or network access condition.
-
After switching to allowlist-only mode, an administrator at Brightwater Labs needs to make a specific project-tracking add-on installable by users. Where in the Admin console is the app added to the allowlist?
- AApps > Google Workspace Marketplace apps > Apps listCorrect
- BApps > Web and mobile apps
- CSecurity > Access and data control > API controls > App access control
- DApps > Additional Google services
✓ Correct answer: AThe Marketplace allowlist is managed under Apps, Google Workspace Marketplace apps, in the Apps list, where an administrator adds each approved app. Once an app is on the allowlist, users can install it while allowlist-only mode is active.
Why the other options are wrong- BWeb and mobile apps is where SAML, Android, iOS, and web apps are configured, not where the Marketplace allowlist is maintained.
- CApp access control governs OAuth API access levels for third-party apps, not the Marketplace install allowlist.
- DAdditional Google services controls Google-owned services such as YouTube, not the Marketplace add-on allowlist.
-
An administrator at Auric Mining is preparing to enroll browsers into Chrome Browser Cloud Management using an enrollment token. Which statements about the enrollment token are correct? (Select all that apply.)
- AThe token registers the browser (the machine), not an individual user account.Correct
- BA token can be generated within a specific browser OU so enrolled browsers land in that OU.Correct
- COn Windows it is deployed through the CloudManagementEnrollmentToken policy or registry value.Correct
- DEach user must type the token when they sign in to Chrome.
- ERevoking the token immediately un-enrolls every browser that previously used it.
✓ Correct answer: A, B, CAn enrollment token registers the browser itself, can be created inside a chosen browser OU to control placement, and is delivered on Windows through the CloudManagementEnrollmentToken policy or registry value. Users never enter it, and revoking it only stops future enrollments.
Why the other options are wrong- DEnrollment is silent and machine-based; users do not type the token during sign-in.
- ERevoking a token blocks new enrollments but leaves already-enrolled browsers managed.
-
A Coastline Media user lost their only 2-step verification device. Which of the following are supported ways for an administrator to help the user sign in again? (Select all that apply.)
- AGenerate backup verification codes for the user from their Security pageCorrect
- BTemporarily turn off 2-step verification enforcement for that user so they can re-enroll a new deviceCorrect
- CMove the user to an organizational unit where 2-step verification enforcement is currently off, then have them re-enrollCorrect
- DReset the user's password, which also clears the second-factor requirement
- EDelete the user account and recreate it to remove the 2-step verification binding
✓ Correct answer: A, B, CAn admin can generate one-time backup codes for the user, temporarily turn off enforcement for that single user, or move them to an OU where enforcement is off so they can re-enroll a new device. Each restores access while keeping 2-step verification in place for the rest of the organization.
Why the other options are wrong- DA password reset changes only the first factor; the second-factor prompt still blocks the user.
- EDeleting and recreating the account destroys the user's data and is never a supported way to handle a lost 2-step verification device.
Related Google resources
- Google practice examsAll Google
- Certification pathWhere this fits
- Certification exam guides & tipsBlog
- Plans & pricingFree & paid
- Google Cloud Professional Cloud Security Engineer practice examRelated
- Google Cloud Professional Cloud Network Engineer practice examRelated
- Google Cloud Professional Data Engineer practice examRelated
Associate Google Workspace Administrator practice exam FAQ
How many questions are in the Associate Google Workspace Administrator practice exam on CertGrid?
CertGrid has 862 practice questions for Associate Google Workspace Administrator, covering 6 exam domains. The real Associate Google Workspace Administrator exam is 50-60 qs in 120 min. CertGrid's timed mock is a fixed 50 questions.
What is the passing score for Associate Google Workspace Administrator?
Google does not publish a fixed passing score for this exam; CertGrid uses readiness scoring for practice. You have about 120 min to complete it. CertGrid tracks your readiness against the exam objectives so you know where to focus.
Are these official Associate Google Workspace Administrator exam questions?
No. CertGrid is an independent practice platform. We do not provide real or leaked exam questions. Our questions are original and designed to help you practice the concepts, scenarios, and difficulty style of the Associate Google Workspace Administrator exam.
Can I practice Associate Google Workspace Administrator for free?
Yes. You can start practicing Associate Google Workspace Administrator for free with daily practice and sample questions. Paid plans unlock full timed exams, complete explanations, and domain analytics.
What CertGrid is (and is not)
CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.
Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by Google. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.