
[2025年01月] 試験Google-Workspace-Administrator最新ブレーン専門問題集はここ
無料で使えるGoogle-Workspace-Administrator試験問題集試験点数を伸ばそう
Google Workspace管理者の認証は、Google Workspace展開を管理する責任があるITプロフェッショナルにとって重要な資格です。この認証を取得することで、候補者はGoogle Workspaceサービスの展開、設定、管理における専門知識を証明することができ、キャリアアップや組織への価値の向上につながるでしょう。
Google-Workspace-Ministrator(Google Cloud Certified-Professional Google Workspace Administrator)試験は、Google Workspace環境の管理を担当する個人のスキルと知識をテストするように設計されています。この認定は、Google Workspaceを主要な生産性スイートとして使用する組織で働くIT専門家にとって理想的です。この試験では、管理者がGoogle Workspaceサービスを構成および管理し、問題をトラブルシューティングし、セキュリティとコンプライアンスのためのベストプラクティスを実装する機能を検証します。
質問 # 52
Your marketing department needs an easy way for users to share items more appropriately. They want to easily link-share Drive files within the marketing department, without sharing them with your entire company.
What should you do to fulfil this request? (Choose two.)
- A. In the admin panel Drive settings, create a target audience that has all of marketing as members.
- B. Create a shared drive that's shared internally organization-wide.
- C. Update the link sharing default to the marketing team when creating a document.
- D. Update Drive sharing for the marketing department to restrict to internal.
- E. Create a shared drive for internal marketing use.
正解:A、E
解説:
To enable the marketing department to easily share items within their team without exposing them to the entire company, the following steps should be taken:
* Create a Shared Drive for Marketing:
* In the Google Admin console, navigate to Apps > Google Workspace > Drive and Docs.
* Create a new shared drive specifically for the marketing department.
* Add all relevant marketing team members to this shared drive, ensuring that it is used for internal purposes only.
* Set Up a Target Audience:
* In the Admin console, go to Apps > Google Workspace > Drive and Docs > Sharing settings.
* Create a target audience that includes all members of the marketing department.
* This allows for easier link sharing within the department by setting the target audience as the default sharing option.
* Steps to Configure:
* Shared Drive: Ensure that the shared drive permissions are set to limit access to the marketing team.
* Target Audience: Configure the target audience so that marketing team members can easily share files internally without defaulting to company-wide sharing.
By setting up a dedicated shared drive and configuring a target audience, you ensure that file sharing is streamlined and restricted to the appropriate team members.
References:
* Set up target audiences
* Create and manage shared drives
質問 # 53
The application development team has come to you requesting that a new, internal, domain-owned Google Workspace app be allowed to access Google Drive APIs. You are currently restricting access to all APIs using approved whitelists, per security policy. You need to grant access for this app.
What should you do?
- A. Enable all API access for Google Drive.
- B. Whitelist the app in the Google Workspace Marketplace.
- C. Add OAuth Client ID to Google Drive Trusted List.
- D. Enable "trust domain owned apps" setting.
正解:C
質問 # 54
Your company is using Google Workspace Business Plus edition, and the security team has reported several unsuccessful attempts to sign in to your Google Workspace domain from countries where you have no local employees. The affected accounts are from several executives in the main office.
You are asked to take measures to mitigate this security risk. Although budget is not a concern, your company prefers a minimal financial outlay to fix the issue, which you are tasked with managing. Which two solutions would help you mitigate the risk at minimal cost?
Choose 2 answers
- A. Deploy 2-Step Verification for all users who have security keys.
- B. Upgrade to Google Workspace Enterprise Plus for all accounts, and define Context-Aware Access levels to only a list of countries where the company has employees.
- C. Subscribe to Cloud Identity Premium for all accounts, and define Context-Aware Access levels to only a list of countries where the company has employees.
- D. For all executives, create new accounts with random characters to match Google best practices, migrate
- E. Deploy Google Cloud Armor on a dedicated project, and create a rule to allow access to Google Workspace only from specific locations.
正解:A、B
解説:
data from the former accounts, and then delete them.
質問 # 55
Your organization's information security team has asked you to determine and remediate if a user ([email protected]) has shared any sensitive documents outside of your organization. How would you audit access to documents that the user shared inappropriately?
- A. As a super administrator, change the access on externally shared Drive files manually under [email protected].
- B. Have the super administrator use the Security API to audit Drive access.
- C. Open Security Investigation Tool-> Drive Log Events. Add two conditions: Visibility Is External, and Actor Is [email protected].
- D. Open Security Dashboard-> File Exposure Report-> Export to Sheet, and filter for [email protected].
正解:C
解説:
https://support.google.com/a/answer/11480192?hl=en&ref_topic=11479095#:~:text=View%20files%20shared,Click%20Search.
質問 # 56
Your company has just acquired a new group of users. They have been provisioned into the Google Workspace environment with your primary domain as their primary email address. These new users still need to receive emails from their previous domain. What is the best way to achieve this for these new users, without updating the information of preexisting users?
- A. Update the Google-provided test domain to be the domain of the acquired company, and then update the email information of all new users with alias emails.
- B. Add the acquired domain as an alias to the primary Google Workspace domain.
- C. Add the acquired domain as a secondary domain to the primary Google Workspace domain, and then update the email information of all new users with alias emails.
- D. Without adding a domain, update each user's email information with the previous domain.
正解:B
質問 # 57
Your company has just received a shipment of ten Chromebooks to be deployed across the company, four of which will be used by remote employees. In order to prepare them for use, you need to register them in Google Workspace.
What should you do?
- A. Turn on the Chromebook and press Ctrl+Alt+E at the login screen to begin enterprise enrollment.
- B. In Chrome Management | Device Settings, enable Forced Re-enrollment for all devices.
- C. Instruct the employees to log in to the Chromebook. Upon login, the auto enrollment process will begin.
- D. Turn on the chromebook and log in as a Chrome Device admin. Press Ctrl+Alt+E to begin enterprise enrollment.
正解:A
解説:
To prepare the Chromebooks for use and register them in Google Workspace, enterprise enrollment is required. This process ensures that the devices are managed under your organization's policies.
* Enterprise Enrollment: This is a process that ties a Chromebook to your organization's Google Workspace account, applying policies and settings you've configured in the Google Admin console.
* Steps for Enrollment:
* Turn on the Chromebook: Start the device and wait for the login screen to appear.
* Initiate Enrollment: Press Ctrl + Alt + E at the login screen. This key combination is specifically designed to start the enterprise enrollment process.
* Sign In: Use the credentials of an account that has the necessary permissions to enroll devices (typically a Google Workspace admin account).
* Complete Enrollment: Follow the prompts to complete the process. The device will now be managed under your organization's policies.
* Re-enrollment Settings: It's recommended to enable forced re-enrollment in the Google Admin console to ensure that devices cannot be used without being enrolled again if they are wiped.
References:
* Enroll ChromeOS devices before deployment
質問 # 58
Your company recently decided to use a cloud-based ticketing system for your customer care needs. You are tasked with rerouting email coming into your customer care address, [email protected] to the cloud platform's email address, [email protected]. As a security measure, you have mail forwarding disabled at the domain level.
What should you do?
- A. Create a content compliance rule in the Google Workspace Admin console to change route to your- [email protected]
- B. Create a mail contact in the Google Workspace directory that has an email address of your- [email protected]
- C. Create a rule to forward mail in the [email protected] mailbox to your- [email protected]
- D. Create a recipient map in the Google Workspace Admin console that maps [email protected] to [email protected]
正解:A
解説:
* Access the Admin Console: Log into your Google Workspace Admin Console.
* Navigate to Apps: Go to Apps > Google Workspace > Gmail > Compliance.
* Create a Content Compliance Rule: Create a new content compliance rule.
* Set Conditions: Set the condition to apply to incoming mail for [email protected].
* Change Route: Configure the rule to change the route to [email protected]. This effectively reroutes emails without using traditional forwarding, which is disabled at the domain level.
* Save and Apply: Save the compliance rule and ensure it is applied to enforce the new routing policy.
References
* Google Support: Set up content compliance
質問 # 59
You have implemented a data loss prevention (DLP) policy for a specific finance organizational unit. You want to apply the same security policy to a shared drive owned by the finance department in the most efficient manner. What should you do?
- A. In the Admin console sharing settings, select the finance organizational unit and deselect Allow users outside the domain to access files in shared drives
- B. Assign the Shared Drive to the finance organizational unit
- C. Change the scope of the policy to apply to all in the domain
- D. Create a new DLP policy for shared drive users
正解:D
解説:
* Access the Admin Console: Sign in to your Google Admin console.
* Navigate to DLP Settings: Click on "Security" and then "Data protection" to access Data Loss Prevention (DLP) settings.
* Create New DLP Policy: Click on "Create policy" and configure the policy specifically for shared drive data.
* Define Rules: Set up the necessary rules and conditions to match the existing DLP policy for the finance organizational unit.
* Apply to Shared Drive: Apply this new policy to the shared drive used by the finance department.
* Save and Activate: Save the policy and ensure it is active and enforced for the shared drive.
References:
* Google Workspace Admin Help: Set up and manage DLP
質問 # 60
You need to protect your users from untrusted senders sending encrypted attachments via email. You must ensure that these messages are not delivered to users' mailboxes. What step should be taken?
- A. Enable a safety rule to send these types of messages to spam.
- B. Enable a safety rule to send these types of messages to a quarantine.
- C. Use the security center to remove the messages from users' mailboxes
- D. Use Google Vault to remove these messages from users mailboxes.
正解:B
解説:
To protect users from untrusted senders sending encrypted attachments:
* Go to the Google Admin Console.
* Navigate to Apps > Google Workspace > Gmail > Advanced settings.
* Create a new safety rule that identifies messages with encrypted attachments from untrusted senders.
* Configure the rule to send these messages to a quarantine instead of delivering them to users' mailboxes.
This measure ensures that potentially harmful emails are intercepted and reviewed before reaching the users.
References:
* Google Workspace Admin Help: Configure email safety settings
質問 # 61
Your organization wants to grant Google Vault access to an external regulatory authority. In an effort to comply with an investigation, the external group needs the ability to view reports in Google Vault. What should you do?
- A. Share Vault access with external users.
- B. Assign an Archived User license to the external users.
- C. Temporarily assign the super admin role to the users
- D. Create accounts for external users and assign Vault privileges.
正解:D
解説:
* Create External Accounts: In the Google Admin console, create new Google Workspace accounts for the external regulatory authority members.
* Assign Vault Privileges: Navigate to the Admin roles and assign the necessary Google Vault privileges to these accounts, ensuring they have the access needed to view reports and data for the investigation.
* Configure Security Settings: Ensure that the external users have secure access, potentially with additional security measures such as two-factor authentication.
* Monitor Access: Regularly audit and monitor the activity of the external users to ensure compliance with your organization's data policies and security requirements.
* Revoke Access When Done: Once the investigation is complete, promptly revoke access to ensure continued security of your data.
References:
* Google Vault Help - Assign Vault Privileges
* Google Workspace Admin Help - Add Users
質問 # 62
Your company has a broad, granular IT administration team, and you are in charge of ensuring proper administrative control. One of those teams, the security team, requires access to the Security Investigation Tool. What should you do?
- A. Assign the pre-built security admin role to the security team members.
- B. Create a Custom Admin Role with the security settings privilege, and then assign the role to each of the security team members.
- C. Assign the Super Admin Role to the security team members.
- D. Create a Custom Admin Role with the Security Center privileges, and then assign the role to each of the security team members.
正解:D
解説:
To provide the security team with access to the Security Investigation Tool, the appropriate privileges must be granted through a custom admin role.
* Create Custom Admin Role:
* In the Google Admin console, navigate to Admin roles.
* Click on Create new role.
* Assign Security Center Privileges:
* Name the role appropriately, such as "Security Investigator".
* Under Privileges, expand the Security Center section.
* Select the necessary privileges, including access to the Security Investigation Tool.
* Assign Role to Users:
* After creating the role, go to the Admin roles section.
* Click on Assign users and add the relevant security team members to this custom role.
* Save and Verify:
* Save the role and verify that the assigned users have the correct access.
Creating a custom admin role with specific security privileges ensures that the security team has the necessary tools to perform their duties without granting excessive permissions.
References:
* Manage admin roles
* Security Center overview
質問 # 63
Your Accounts Payable department is auditing software license contracts companywide and has asked you to provide a report that shows the number of active and suspended users by organization unit, which has been set up to match the Regions and Departments within your company. You need to produce a Google Sheet that shows a count of all active user accounts and suspended user accounts by Org unit.
What should you do?
- A. From the Admin Console Users Menu, download a list of all user info columns and currently selected columns.
- B. From the Admin Console Users Menu, download a list of all Users to Google Sheets, and join that with a list of ORGIDs pulled from the Reports API.
- C. From the Google Workspace Reports Menu, run and download the Accounts Aggregate report, and export the data to Google Sheets.
- D. From the Admin Console Billing Menu, turn off auto-assign, and then click into Assigned Users and export the data to Sheets.
正解:A
解説:
https://support.google.com/a/answer/7348070?hl=it
質問 # 64
Several users in your organization reported an issue with receiving emails from one particular external sender You want to troubleshoot the issue and determine whether Google received these emails What should you do?
- A. Open a support ticket with Google Workspace Support
- B. Search for missing email messages by using email Log Search {ELS) and determine why messages weren't delivered
- C. Check if your Google Workspace domain registration expired
- D. Update your MX records to make sure they point to Google mail servers
正解:B
解説:
Step by Step Comprehensive Detailed Explanation:
* Access Email Log Search: Sign in to the Google Admin console and navigate to "Reports" then
"Audit" and select "Email Log Search."
* Perform a Search: Enter the details of the external sender and the date range to search for the missing
* emails.
* Analyze Results: Review the search results to see if the emails were received, bounced, or filtered.
* Determine Cause: Identify any issues such as delivery errors or spam filtering that might have affected the emails.
References:
* Google Workspace Admin Help: Email Log Search
質問 # 65
You need to protect your users from untrusted senders sending encrypted attachments via email. You must ensure that these messages are not delivered to users' mailboxes. What step should be taken?
- A. Enable a safety rule to send these types of messages to spam.
- B. Enable a safety rule to send these types of messages to a quarantine.
- C. Use the security center to remove the messages from users' mailboxes
- D. Use Google Vault to remove these messages from users mailboxes.
正解:B
質問 # 66
The helpdesk at your organization reports that many users in multiple locations are not able to access Gmail, but can access other Workspace services. You must troubleshoot the issue What should you do first?
- A. Check network connectivity of the affected users
- B. Check the Google Workspace release calendar to ensure there's not a Gmail upgrade scheduled
- C. Check the Google Workspace status dashboard to see whether there is a disruption in Gmail service availability
- D. Open a ticket with Google Support listing the affected users.
正解:C
解説:
* Access Status Dashboard: Open the Google Workspace Status Dashboard.
* Check Service Status: Look for any reported issues or outages specifically for Gmail.
* Verify Timing: Check the timing of the reported issues to see if they correlate with the time when users reported problems.
* Additional Information: Review any additional details or updates provided by Google regarding the service disruption.
* Communicate Status: Inform the affected users about the service status and any expected resolution time.
* Open Ticket if Necessary: If no issues are reported on the status dashboard, proceed with other troubleshooting steps such as checking network connectivity or opening a ticket with Google Support.
References:
* Google Workspace Status Dashboard
質問 # 67
As a team manager, you need to create a vacation calendar that your team members can use to share their time off. You want to use the calendar to visualize online status for team members, especially if multiple individuals are on vacation What should you do to create this calendar?
- A. Request the creation of a calendar resource, configure the calendar to "Auto-accept invitations that do not conflict," and give your team "See all event details" access.
- B. Create a secondary calendar under your account, and give your team "See only free/busy" access
- C. Request the creation of a calendar resource, configure the calendar to "Automatically add all invitations to this calendar," and give your team "See only free/busy" access.
- D. Create a secondary calendar under your account, and give your team "Make changes to events" access.
正解:D
解説:
* Create Secondary Calendar: As the team manager, create a new calendar under your Google account specifically for tracking team vacations.
* Access Settings: Go to the calendar settings and navigate to "Share with specific people".
* Grant Access: Add your team members and give them "Make changes to events" access, allowing them to add their vacation times directly to the calendar.
* Educate Team: Inform team members on how to use this calendar to add their vacation times and check others' schedules.
* Monitor Usage: Regularly review the calendar to ensure it is being used correctly and effectively by all team members.
References:
* Google Workspace Admin Help - Share a Calendar
* Google Workspace Admin Help - Create a Team Calendar
質問 # 68
The compliance team at your organization is conducting a legal investigation into some concerning sales activities of an employee eight months ago The compliance team contacted you for assistance on the situation You set up the default Google Vault retention rules so all data is retained only for one year You must assist the compliance team with the investigation What should you do1?
- A. Do nothing The retention period has already ended and the evidence has already been purged
- B. Assign the compliance team a Google Vault administrator role and create a legal hold for the employee
- C. Assign the compliance team a Google Vault administrator role and change the default retention rules to three years.
- D. Suspend the employee and export all data by using Google Takeout
正解:B
解説:
* Assign Vault Administrator Role: In the Google Admin console, assign the compliance team members the Google Vault administrator role to give them the necessary permissions.
* Access Google Vault: Have the compliance team access Google Vault.
* Create a Matter: In Google Vault, create a new matter for the investigation.
* Create a Hold: Within the matter, create a legal hold specifically targeting the employee's email and any other relevant data. This will preserve all the necessary information beyond the default retention period.
* Review Data: The compliance team can now review the preserved data as part of their investigation.
References:
* Google Vault Help: Assign Vault privileges
* Google Vault Help: Create and manage holds
質問 # 69
Recently your organization has had an increase in messages marked as spam You need to quickly and efficiently obtain detailed information regarding each message What should you do?
- A. Use the spam filter report in the security dashboard to see messages Google's spam filter marked as spam during a specific time period
- B. Use Google Vault to put all messages marked as spam in a legal hold and review the messages
- C. Create an investigation by using a SQL query to search for all spam audit logs exported to BigQuery
- D. Send an alert to all users to mark all suspicious Gmail messages as spam and review the Alert center messages
正解:A
解説:
* Access Security Dashboard: Go to the Google Admin console and navigate to the 'Security' section.
* Open Spam Filter Report: In the security dashboard, open the spam filter report.
* Filter by Time Period: Select the specific time period you want to analyze.
* Review Spam Messages: Review the detailed information regarding each message marked as spam by Google's spam filter.
* Take Necessary Actions: Use the information from the report to adjust spam filters, user alerts, or take other necessary actions to manage spam more effectively.
References
* Security Dashboard
* Email Log Search
質問 # 70
Your organization recently deployed Google Workspace. Your admin team has been very focused on configuring the core services for your environment, which has left you little time to pay attention to other areas. Your security team has just informed you that many users are leveraging unauthorized add-ons, and they are concerned about data exfiltration. The admin team wants you to cut off all add-ons access to Workspace data immediately and block all future add-ons until further notice. However, they approve of users leveraging their Workspace accounts to sign into third-party sites. What should you do?
- A. Set all API services to "restricted access" and ensure that all connected apps have limited access.
- B. Block each connected app's access.
- C. Modify your Marketplace Settings to block users from installing any app from the Marketplace.
- D. Remove all client IDs and scopes from the list of domain-wide delegation API clients.
正解:D
解説:
https://support.google.com/a/answer/162106?hl=en#zippy=%2Cview-edit-or-delete-clients-and-scopes:~:text=View%2C%20edit%2C%20or,immediately%20stop%20working.
質問 # 71
As a Workspace Administrator, you want to keep an inventory of the computers and mobile devices your company owns in order to track details such as device type and who the device is assigned to. How should you add the devices to the company-owned inventory?
- A. Download the company owned inventory template CSV file from the admin panel, enter the Device OS, serial number and upload it back to the company owned inventory in the admin panel.
- B. Download the company owned inventory template CSV file from the admin panel, enter the asset tag of the devices, and upload it back to the company owned inventory in the admin panel.
- C. Download the company owned inventory template CSV file from the admin panel, enter the serial number of the devices, and upload it back to the company owned inventory in the admin panel.
- D. Download the company owned inventory template CSV file from the admin panel, enter the Device OS, asset tag and upload it back to the company owned inventory in the admin panel.
正解:C
解説:
https://support.google.com/a/answer/7129612?hl=en#zippy=%2Cassigning-devices%2Cadd-android-devices-for-the-most-management-features:~:text=Add%20devices%20to,and%20upload%20status.
質問 # 72
User A is a Basic License holder. User B is a Business License holder. These two users, along with many additional users, are in the same organizational unit at the same company. When User A attempts to access Drive, they receive the following error: "We are sorry, but you do not have access to Google Docs Editors. Please contact your Organization Administrator for access." User B is not presented with the same error and accesses the service without issues.
How do you provide access to Drive for User A?
- A. In Apps > Google Workspace, determine the Group that has Drive and Docs enabled as a service. Add User A to this group.
- B. Select User A in the Directory, and under the Apps section, check whether Drive and Docs is disabled. If so, enable it in the User record.
- C. In Apps > Google Workspace > Drive and Docs, select the organizational unit the users are in and enable Drive for the organizational unit.
- D. Select User A in the Directory, and under the Licenses section, change their license from Basic to Business to add the Drive and Docs service.
正解:A
解説:
https://support.google.com/a/answer/9050643
質問 # 73
The CEO of your company has indicated that messages from trusted contacts are being delivered to spam, and it is significantly affecting their work. The messages from these contacts have not always been classified as spam. Additionally, you recently configured SPF, DKIM, and DMARC for your domain. You have been tasked with troubleshooting the issue.
What two actions should you take? (Choose two.)
- A. Obtain the message header and analyze using Google Workspace Toolbox.
- B. Conduct an Email log search to trace the message route.
- C. Set up a Gmail routing rule to whitelist the sender.
- D. Validate that your domain is not on the Spamhaus blacklist.
- E. Review the contents of the messages in Google Vault.
正解:A、C
質問 # 74
The nature of your organization's business makes your users susceptible to malicious email attachments. How should you implement a scan of all incoming email attachments?
- A. In the security sandbox section, enable virtual execution of attachments for the entire organization.
- B. In the security sandbox section, enable virtual execution of attachments for (he targeted OU
- C. Configure a safety rule to protect against encrypted attachments from untrusted senders
- D. Configure a safety rule to protect against attachments with scripts from untrusted senders.
正解:A
解説:
To implement a scan of all incoming email attachments effectively, you should enable virtual execution of attachments in the security sandbox for the entire organization. This feature allows Google Workspace to execute attachments in a sandbox environment to detect malicious behavior before the email reaches the user's inbox. By applying this to the entire organization, you ensure that all users are protected regardless of their organizational unit.
References:
* Google Workspace Admin Help - Security Sandbox
* Google Workspace Admin Help - Protect your organization from attachments with scripts
質問 # 75
......
Google-Workspace-Administrator(Google Cloud Certified - Professional Google Workspace Administrator)認定試験は、Google Workspaceの管理と管理に関する個人の知識とスキルをテストするために設計されています。この認定試験は、自分の組織でGoogle Workspaceを展開、設定、管理する責任があるITプロフェッショナル、管理者、およびマネージャーに最適です。試験は、ユーザーとグループの管理、セキュリティとコンプライアンス、データ移行と管理、コラボレーションとコミュニケーションツールなど、幅広いトピックをカバーしています。
心強いGoogle-Workspace-AdministratorのPDF問題集はGoogle-Workspace-Administrator問題:https://www.passtest.jp/Google/Google-Workspace-Administrator-shiken.html
2025年最新の実際に出るGoogle-Workspace-Administrator問題集には試験のコツがあるPDF試験材料:https://drive.google.com/open?id=10MMFXo05Ojjpv_n-GCawDNEwPxejRQTh