PCEA Practice Questions
Prepare for PCEA with more than an answer.
- Level
- Professional
- Valid for
- Not specified
Domains covered on the exam 6
- Chrome Enterprise Management Fundamentals20%
- Security and Compliance25%
- Device and User Management20%
- Chrome Enterprise Core and Cloud Management15%
- Extensions and Applications Management10%
- Integration and Authentication10%
- 1
What is the primary function of the Chrome Enterprise Connector for VMware Workspace ONE?
Show answer details
Correct answer: B
The Chrome Enterprise Connector for VMware Workspace ONE (and other UEMs) allows administrators to manage Chrome browser policies using their existing device management platform. It bridges the gap, enabling policy configuration within the Workspace ONE console, which then syncs those policies to the Google Admin console for enforcement on managed browsers.
- 2
An administrator wants to block users from installing any extension that requests the 'history' permission. Which policy should be used to achieve this?
Show answer details
Correct answer: D
The
ExtensionSettingspolicy is a powerful and flexible policy that can control various aspects of extensions. To block installations based on permissions, you would use this policy to set a default behavior (installation_mode: 'blocked') for any extension that requests the specified permission ('history'). This is more effective than manually blocklisting every such extension. - 3
True or False: A Chrome browser managed via Chrome Browser Cloud Management (CBCM) requires a paid Chrome Enterprise Upgrade license.
Show answer details
Correct answer: B
This is false. Chrome Browser Cloud Management, which allows centralized policy management for Chrome browsers across Windows, Mac, and Linux, is available at no cost. A paid Chrome Enterprise Upgrade license is required for managing ChromeOS devices, but not for managing the browser on other operating systems.
- 4
A school district is managing a large fleet of Chromebooks. An administrator needs to remotely capture logs from a specific student's device to troubleshoot a performance issue. The student is currently using the device in a classroom. What is the most efficient method to collect these logs without physically accessing the device?
Show answer details
Correct answer: C
The Google Admin console provides a 'Capture Logs' command for managed ChromeOS devices. This feature allows an administrator to remotely trigger the device to collect a comprehensive set of system and user logs and upload them to the Admin console for analysis. This is the most direct and efficient method that does not require user interaction.
- 5
Case Study:
HealthCorp, a large healthcare provider, is rolling out Chrome Enterprise to all clinical and administrative staff across multiple hospitals. They have a hybrid environment with an on-premises Active Directory (AD) for identity management and are also licensed for Google Workspace.Environment: All workstations are Windows-based and joined to the
healthcorp.localAD domain. The company uses Okta as its primary SAML Identity Provider (IdP) for single sign-on (SSO).Requirements:
- All Chrome browsers must be centrally managed via Chrome Browser Cloud Management (CBCM).
- User policies must be applied based on the user's AD group membership (e.g., 'Doctors', 'Nurses', 'AdminStaff').
- Users must authenticate to their Chrome profile using their AD credentials via the Okta SSO flow.
- The solution must not require manual creation of thousands of user accounts in the Google Admin console.
How should the administrator design the integration to meet all requirements?
graph TD subgraph On-Premises AD[Active Directory] GCDS[GCDS Server] end subgraph Cloud CBCM[Chrome Browser Cloud Mgt] Okta[Okta IdP] GWorkspace[Google Workspace] end subgraph Users User[Clinician on Windows PC] end User -->|Chrome Sign-in| Okta Okta -->|SAML Auth| AD AD -->|User/Group Sync| GCDS GCDS -->|Provisioning| GWorkspace GWorkspace -->|Policies| CBCM CBCM -->|Policy Enforcement| UserShow answer details
Correct answer: C
This is the most comprehensive and automated solution. 1) GCDS handles the automatic provisioning of users and, crucially, security groups from AD into Google Workspace, eliminating manual work. 2) Configuring SAML with Okta handles the authentication requirement. 3) Assigning Chrome policies to the synchronized Google Groups (not OUs) allows for dynamic policy application based on the user's role in AD, which is the most flexible and scalable approach.
- 6
A financial services company is using Chrome Browser Cloud Management to enforce policies. A security audit requires that any attempt to upload files containing credit card numbers from a managed Chrome browser to a non-approved web service be blocked and logged. The company already uses Google Workspace and has its DLP rules configured there. What is the most direct way to meet this requirement?
Show answer details
Correct answer: D
Chrome Browser Cloud Management can integrate directly with Google Workspace. This allows the powerful content-aware DLP rules already defined in Workspace (such as detecting credit card numbers) to be extended to the Chrome browser, providing seamless enforcement without requiring a separate third-party solution. Blocking URLs is too broad, and Safe Browsing does not perform content inspection for DLP purposes.
- 7
A university is deploying Linux apps via Crostini on managed ChromeOS devices for its computer science department. The administrator needs to prevent students from using the
sudocommand to gain root access within the Linux container, but still allow them to install a predefined list of packages. Which policy should the administrator configure in the Google Admin console?Show answer details
Correct answer: A
The
CrostiniSudoAccessAllowedpolicy specifically controls whether users can use thesudocommand to gain root privileges within the Linux (Crostini) container. Setting this policy to 'false' effectively prevents privilege escalation while still allowing the Linux environment to function for other purposes. - 8
An organization uses a third-party Identity Provider (IdP) that supports SAML 2.0 for single sign-on (SSO). An administrator needs to configure managed Chrome browsers to use this IdP for all Google services. They have already configured SSO in the Google Admin console. What additional Chrome policy must be configured to ensure that users are always redirected to the third-party IdP login page and cannot use a standard Google account login?
Show answer details
Correct answer: D
The
BrowserSigninpolicy (specifically setting it to 'Force users to sign-in to use the browser') combined with the domain-level SAML SSO configuration ensures that users are required to authenticate via the configured third-party IdP before they can use the browser. This prevents bypassing the SSO flow by using a personal Google account or browsing as a guest. - 9
A company is transitioning to ChromeOS Flex for a large number of older desktops. The network team requires that these devices use a specific PAC (Proxy Auto-Config) file hosted at
http://proxy.internal/config.pacfor internet access. The administrator needs to apply this setting to all ChromeOS Flex devices in a specific Organizational Unit. Which policy setting should be used?Show answer details
Correct answer: B
To enforce the use of a specific PAC file, the administrator must select the 'Use a proxy auto-config (PAC) file' option within the Proxy mode settings and then enter the URL of the PAC file. This ensures all devices in the target OU will fetch and apply the proxy rules from that specific location.
