AGWA Practice Questions
Prepare for AGWA with more than an answer.
Unlock the full exam and previous versions
- v1Associate Google Workspace Administrator 135 questions Locked
- AGWALegacy Associate Google Workspace Administrator 231 questions Current
- 1
A new security initiative requires your company to prevent users from installing unapproved third-party apps from the Google Workspace Marketplace. However, you need to allow a specific CRM application that has been vetted by the security team for all users in the 'Sales' OU. What is the best practice to implement this policy?
Show answer details
Correct answer: C
This is the most secure and manageable approach. By changing the default Marketplace setting to only allow specific applications, you create a deny-by-default posture. You can then build an 'allowlist' of vetted applications. This allowlist can be applied to the entire domain or targeted to specific OUs, like the 'Sales' OU in this case, ensuring only they have access to the approved CRM app.
- 2
You are the administrator for a school district using Google Workspace for Education. To comply with student data privacy regulations, you must prevent all users in the 'Students' OU from using Google Takeout to export their data. How do you configure this?
Show answer details
Correct answer: B
Google Takeout is managed as a service within the Admin Console under 'Additional Google services'. Like other services, its availability can be controlled on a per-OU basis. The correct procedure is to navigate to this service, select the 'Students' OU, and set the service status to OFF. This will prevent users in that OU from accessing the Takeout page, while leaving it available for other OUs like 'Faculty'.
- 3
A user is complaining that their Google Drive for desktop application is not syncing files correctly and is consuming excessive CPU resources on their machine. You need to gather detailed diagnostic information to send to Google Support. What is the recommended method to collect these logs?
Show answer details
Correct answer: D
Google Drive for desktop has a built-in diagnostic mode for troubleshooting. The correct procedure is to have the user hold the Shift key while clicking the Settings gear in the application's menu. This reveals a hidden option, 'Create diagnostic logs', which packages all the necessary logs and performance data into a single zip file that can be easily attached to a support case.
- 4
Your company wants to apply a set of restrictive Chrome browser policies, such as blocking incognito mode and force-installing a specific security extension, to all company-owned laptops. These laptops are not managed by a traditional MDM. How can you ensure these policies are applied and enforced on the Chrome browsers?
Show answer details
Correct answer: B
Chrome Browser Cloud Management (CBCM) is the Google tool designed specifically for this purpose. By generating an enrollment token in the Admin Console and deploying it to the laptops (e.g., via a registry key or script), the browsers become managed entities. Once enrolled, they appear in a special OU in the Admin Console, where you can apply hundreds of browser-specific policies, including disabling incognito mode and force-installing extensions, regardless of the user signed in.
- 5
A law firm must retain all email communications for a period of seven years to comply with industry regulations. After seven years, the data should be permanently deleted. Some specific cases, however, are placed on an indefinite legal hold. How should an administrator configure Google Vault to meet these requirements?
gantt title Data Lifecycle Policy dateFormat YYYY axisFormat %Y section Standard Retention Data Creation : 2024, 1y 7-Year Retention Period : after Data Creation, 7y Permanent Deletion : after 7-Year Retention Period, 1d section Legal Hold Case Data Creation (Case) : 2025, 1y Legal Hold Applied : 2026, 6y Hold active... : after Legal Hold Applied, 5yShow answer details
Correct answer: B
This is the correct, multi-layered approach. First, a custom retention rule should be set for Gmail to 'Retain for a specific period' (7 years) and then 'Purge the data'. This automates the standard lifecycle. For the exceptions, you create a 'matter' in Vault for each legal case and place a 'hold' on the relevant mailboxes or data. A hold always overrides any retention rule, ensuring the data is preserved indefinitely until the hold is released, at which point the 7-year purge rule would apply.
- 6
A financial services company is implementing a strict data governance policy. They need to ensure that any Google Drive file containing a client's 'Tax Identification Number' (TIN) cannot be shared externally. The policy must also automatically warn the user attempting the share and notify the compliance team. Which combination of tools should the administrator configure to meet these requirements?
Show answer details
Correct answer: B
This scenario is a classic use case for Data Loss Prevention (DLP) rules. A Drive DLP rule can be configured to scan files for specific content using predefined detectors (like Tax Identification Numbers). The rule's actions can be set to block external sharing, display a custom warning to the user, and send an email alert to the compliance team, fulfilling all requirements. Vault is for retention/eDiscovery, trust rules manage sharing at a high level without content inspection, and content compliance is specific to Gmail.
- 7
During a routine audit, you discover that the 'Sales' organizational unit (OU) has overly permissive Google Drive sharing settings, allowing public sharing. The 'Sales-Managers' group, which is a subset of the Sales OU, needs to retain this ability for marketing purposes. All other Sales OU members should be restricted to sharing only within the domain. What is the most effective way to implement this policy with the least administrative effort?
Show answer details
Correct answer: D
The most direct and modern way to handle this is by using sharing policy exceptions based on groups, which overrides the OU's setting. You set the restrictive policy at the OU level (domain-only sharing) and then apply a more permissive policy specifically to the 'Sales-Managers' group. This avoids restructuring OUs, which can have wider implications. Target audiences are for suggesting shares, not enforcing permissions. Whitelisting domains is too restrictive if they need public sharing.
- 8
A user who was recently terminated needs their Google Workspace account and data preserved for potential legal action. The company wants to prevent any new emails from being received by this account and ensure no one can log in, while keeping all existing data in Gmail and Drive intact for eDiscovery. Which of the following account statuses should be used?
Show answer details
Correct answer: B
Suspending a user account is the correct action. It immediately blocks user sign-in access and stops new mail delivery. However, all existing data remains in place and is accessible to administrators and Google Vault for eDiscovery purposes. Deleting the account would permanently remove the data after a grace period. Archiving is a paid option that also preserves data but is designed for long-term storage, whereas suspension is the standard immediate action for terminated employees pending data review.
- 9
Your organization is migrating to Google Workspace from an on-premises Microsoft Exchange server. During the transition period, you need to configure a dual delivery setup where incoming emails are delivered to both the new Gmail inboxes and the legacy Exchange server simultaneously. What is the correct configuration step in the Google Admin console?
Show answer details
Correct answer: B
Dual delivery is configured in the Gmail 'Routing' settings. You create a new routing rule that applies to all inbound messages. In the rule's options, you select 'Also deliver to' and add a new recipient, which would be the mail host of the legacy Exchange server. This ensures a copy is sent to the on-premises server after it's delivered to the Gmail inbox. An inbound gateway is for processing mail coming from a specific gateway, not for routing outgoing copies.
- 10
A user is unable to log in to their Google Workspace account from their home network. They are certain their password is correct. From the office, they can log in without issue. The company has a policy to only allow logins from corporate IP addresses for users in the 'Finance' OU. Which security feature is most likely causing this issue?
Show answer details
Correct answer: C
Context-aware access policies are designed for this exact scenario. They allow administrators to create granular access control rules based on user identity, location (IP address), device security status, and other attributes. A policy restricting access to corporate IP addresses for a specific OU is a common implementation of context-aware access. 2SV would prompt for a second factor but not block based on IP. Session control manages what happens after login.
