Skip to content

PCOA Practice Questions

Prepare for PCOA with more than an answer.

207 questions in the full set20 sample questionsUpdated Jan 18, 2026
Exam fee
$125 USD
Level
Professional
Valid for
Does not expire
Domains covered on the exam 5
  1. Perform actions from the Admin console25%
  2. Understand ChromeOS security processes20%
  3. Configure ChromeOS policies20%
  4. Identity Management15%
  5. Understand ChromeOS tenets20%
  1. 1

    A company is migrating from a legacy Windows environment to ChromeOS. They want to maintain their existing Public Key Infrastructure (PKI) for network authentication. An administrator has configured a SCEP profile in the Google Admin console to automatically issue certificates to devices. However, devices are failing to obtain certificates. The SCEP server logs show that requests are being received but are rejected as unauthorized. Which of the following is a mandatory component for SCEP that must be included in the SCEP profile configuration to authenticate the device's request to the SCEP server?

    Show answer details

    Correct answer: B

    The SCEP protocol requires a challenge password to authenticate enrollment requests. This can be a static password shared between the client and the SCEP server, or a dynamic, one-time password provided by the server. In the Google Admin console SCEP profile, the administrator must configure this challenge, which is then presented by the ChromeOS device during the certificate signing request to prove it is an authorized requester.

  2. 2

    During a security audit, you are asked to demonstrate how ChromeOS protects user data from other users on a shared device. Which fundamental security tenet of ChromeOS ensures that one user's data (like browser cache, cookies, and files in the Downloads folder) is cryptographically isolated and inaccessible to another user who logs into the same physical device?

    Show answer details

    Correct answer: C

    ChromeOS uses the device's Trusted Platform Module (TPM) to encrypt each user's local data. The encryption keys are derived from the user's login password. This means that User A's data is encrypted with keys tied to User A's password, making it unreadable without that password. When User B logs in, they use their own password to decrypt their separate storage area, and they have no cryptographic access to User A's data.

  3. 3

    A marketing firm uses ChromeOS devices for its graphic designers. These designers need access to the Linux development environment to run specific design software. The firm's security team is concerned about data exfiltration and wants to prevent designers from copying files from the Linux environment to their Google Drive. Which policy should be configured to achieve this specific restriction?

    Show answer details

    Correct answer: D

    The Google Admin console provides a specific policy to control the integration between the Linux environment and Google Drive. Setting 'Linux file sharing with Google Drive' to 'Disallow' prevents the 'Google Drive' folder from being mounted within the Linux file system. This effectively blocks users from directly copying or moving files from their Linux container to their cloud storage, addressing the data exfiltration concern.

  4. 4

    True or False: Setting up a test domain is a recommended best practice for ChromeOS administrators because it provides an isolated environment to validate new policies and configurations before deploying them to production devices.

    Show answer details

    Correct answer: A

    This is a core best practice. A test domain (or even a test OU within the production domain) allows administrators to safely test the impact of policy changes, app deployments, or OS updates on a small group of devices without risking disruption to the entire organization. It is essential for change management and stability.

  5. 5

    A company has a primary organizational unit (OU) for all its ChromeOS devices. They need to apply a more restrictive set of policies (e.g., disable guest mode, block specific URLs) to a subset of devices used by frontline workers, without affecting the other devices in the primary OU. What is the most efficient method to accomplish this?

    Show answer details

    Correct answer: A

    Organizational units are the primary mechanism for applying different sets of policies to different groups of users or devices. By creating a new child OU for the frontline workers and moving their devices into it, the administrator can apply specific, more restrictive policies that will override the inherited policies from the parent OU, without impacting any other devices.

  6. 6

    A financial services firm is deploying ChromeOS devices to its remote workforce. To comply with industry regulations, all network traffic from these devices must be routed through a corporate VPN that uses IKEv2 with certificate-based authentication. The firm uses a Microsoft Certificate Authority (CA) and a SCEP service for certificate distribution. What is the most critical prerequisite for successfully configuring the VPN on ChromeOS devices via the Google Admin console?

    Show answer details

    Correct answer: B

    For a ChromeOS device to trust the VPN server and the certificates issued by the SCEP service, the entire trust chain must be established. This requires uploading the Root CA and any Intermediate CA certificates to the Google Admin console and making them available to the devices. Without this trust anchor, the device will not be able to validate the server's certificate or its own client certificate, causing the VPN connection to fail.

  7. 7

    A multinational corporation uses a third-party SAML 2.0 Identity Provider (IdP) for all corporate applications. They are migrating to ChromeOS and want to enforce SSO for device login. During testing, they find that while SSO works, users are not automatically logged into their Google accounts for services like Gmail after the initial device login. What configuration step in the Google Admin console was most likely missed?

    Show answer details

    Correct answer: C

    When using a third-party IdP, enabling 'Use a domain-specific issuer' sends an issuer tag specific to your domain (google.com/a/your_domain.com) in the SAML request. This allows the IdP to distinguish requests from your Google Workspace account and return the correct assertion, which is crucial for seamless post-login authentication to Google services. Without it, the IdP may not correctly identify the service provider, leading to the behavior described.

  8. 8

    A school district is preparing for a 1:1 deployment of ChromeOS devices for students. To prevent device loss and unauthorized use, they have enabled the 'Forced re-enrollment' policy. A student's device is wiped by a technician for troubleshooting. Upon reboot, the device displays the enrollment screen as expected. The student tries to log in with their personal Gmail account instead of their school account. What will happen?

    Show answer details

    Correct answer: B

    Forced re-enrollment is a security feature tied to the device's hardware ID. Once a device is enrolled in a domain, this policy ensures it cannot be used without being re-enrolled into that same domain after a wipe. It prevents users from bypassing management by logging in with a personal account. The device is effectively locked to the original management domain until an authorized user from that domain enrolls it.

  9. 9

    An administrator is managing a fleet of ChromeOS devices used in a logistics warehouse. To optimize performance, they have pinned the OS version to a specific Long-term support (LTS) release for the entire fleet. A new set of devices arrives from the manufacturer with a newer version of ChromeOS pre-installed. What is the expected behavior when these new devices are enrolled into the organizational unit (OU) with the version pinning policy?

    Show answer details

    Correct answer: C

    ChromeOS does not support automatic version downgrades. The version pinning policy prevents devices from updating beyond the specified version. If a device is already on a newer version, it will remain on that version. It will not receive any further updates until the administrator changes the pin to a version number that is higher than the one currently installed on the device.

  10. 10

    A consultant is tasked with deploying 500 ChromeOS devices for a healthcare provider. The devices will be used as shared workstations in patient rooms and must not retain any user data between sessions. Additionally, a specific set of five web-based medical applications must be pre-loaded and easily accessible. Which session type policy should be configured in the Google Admin console to meet these requirements most effectively? (Select TWO)

    Show answer details

    Correct answer: A, C

    Managed Guest Sessions are designed for shared or public-use scenarios. They provide a controlled browsing experience without requiring a user to sign in, and all session data is wiped upon logout, meeting the data retention requirement.

    This policy, often called ephemeral mode, enforces that all local user data is deleted upon logout. While Managed Guest Sessions do this by default, explicitly setting this policy for regular user sessions is an alternative way to meet the data retention requirement if named user accounts were required.

Create an account to continue.