GCP-AGWA Sample Questions & Answers
Configuring Gmail, Drive, Docs, and Calendar carries the biggest weight, alongside the user life cycle, organizational units, and groups, Vault and DLP data governance, securing user access and reviewing audit logs, and mobile and Chrome device management.
Launch the full GCP-AGWA simulator →Free GCP-AGWA Sample Questions with Answers
Real questions from the Associate Google Workspace Administrator practice test — answers and explanations included. Showing 6 of 12 free samples.
- Question 1IntermediateSelect 2
Managing User Accounts, Domains, and Directory · Managing Groups
A large retail company uses dynamic groups to manage email distribution lists based on department attributes. The HR department recently updated the 'Department' attribute for 50 employees from 'Sales' to 'Marketing'. However, these employees are reporting that they are not receiving emails sent to the Marketing dynamic group. You have verified the attribute update in the user profiles. What is the most likely cause for this delay? (Select TWO)
Show answer & explanation
Correct answers: A, E
Dynamic group membership is calculated based on user attributes. While often fast, Google documentation states that changes can take up to 24 hours to fully propagate.
If a user is manually removed from a dynamic group (or blocked), they may not be automatically re-added even if they match the query, depending on how the exclusion was handled.
- Question 2Beginner
Managing User Accounts, Domains, and Directory · Managing Domains
You are configuring a new domain alias 'example-alias.com' for your primary domain 'example.com'. You need to verify domain ownership by adding a specific DNS record. The most common record type used for instant domain verification in the Google Admin Console is a _____ record.
Show answer & explanation
Correct answer: A
A TXT (Text) record is the standard method for verifying domain ownership with Google. You add a unique verification string provided by Google to your domain's DNS records.
- Question 3Advanced
Managing Core Workspace Services · Configuring Gmail
TechCorp is implementing a hybrid email environment during a migration phase. They want incoming mail to be delivered to Gmail first. If the recipient exists in Gmail, the mail should stay there. If the recipient does not exist in Gmail, the mail should be routed to the legacy on-premises Exchange server.
Which mail routing configuration should you implement?
Show answer & explanation
Correct answer: B
This scenario describes Split Delivery. Specifically, you want Gmail to accept mail for known users and forward only unknown users to the legacy system. This is achieved by configuring a route for 'unrecognized addresses' to the legacy server host. Dual Delivery would send mail to BOTH systems for ALL users, which is not what is requested.
- Question 4Advanced
Managing User Accounts, Domains, and Directory · Managing the User Life Cycle
CASE STUDY: GlobalLogistics Inc.
GlobalLogistics Inc. is a shipping company with 5,000 employees distributed across three regions: North America, Europe, and Asia. They have recently adopted Google Workspace Enterprise Standard.
Current Situation:
- The company uses a third-party IdP (Okta) for authentication.
- User provisioning is currently manual, which is causing delays.
- The security team requires that only corporate-owned devices can access Google Drive data.
- The legal team needs to retain all email for 7 years for compliance.
Requirement:
You need to automate user provisioning from their HR system (Workday) which flows into Okta. You also need to ensure that if a user is suspended in Workday/Okta, they are immediately suspended in Google Workspace.Question:
Which architecture provides the most streamlined solution for the provisioning requirement?Show answer & explanation
Correct answer: B
Since the identity flow is HR -> Okta -> Google Workspace, the most streamlined approach is to use the SCIM capabilities built into the Okta-Google integration. Okta can automatically create, update, and suspend users in Google Workspace via API (SCIM) as soon as changes happen in Okta. This eliminates the need for a separate GCDS server.
- Question 5Advanced
Managing Security Policies and Access Controls · Securing User Access
CASE STUDY: GlobalLogistics Inc.
(Refer to the GlobalLogistics scenario in the previous question)
Requirement:
The security team wants to enforce the rule: "Only corporate-owned mobile devices can access Google Drive data. Personal devices (BYOD) should only have access to Gmail and Calendar."Question:
Which combination of settings achieves this granular access control?Show answer & explanation
Correct answer: B
Context-Aware Access (CAA) allows granular control based on device state. By creating an access level that checks for the 'Company Owned' attribute and binding it specifically to the Google Drive application, you restrict Drive access to only those devices. Leaving Gmail and Calendar unbound (or bound to a less restrictive policy) allows BYOD access.
- Question 6Intermediate
Managing Security Policies and Access Controls · Reporting, Auditing, and Investigating Security Risks and Events
You need to investigate a reported phishing attack where several users clicked a link. You want to identify exactly which users received the email, which ones opened it, and which ones clicked the link. You decide to use the Security Investigation Tool. Which data source should you select to find the most detailed information about the message delivery and post-delivery events?
Show answer & explanation
Correct answer: A
The 'Gmail log events' data source in the Security Investigation Tool provides granular details including message delivery, spam classification, and post-delivery activities (if configured/available in Enterprise editions). It allows searching by Message ID, Sender, Recipient, and Subject to trace the exact scope of the attack.
flowchart TD Start[Start Investigation] --> SelectSource{Select Data Source} SelectSource -->|Audit Logs| AdminLog[Admin Activity] SelectSource -->|Gmail Logs| GmailLog[Gmail Log Events] SelectSource -->|Drive Logs| DriveLog[Drive Log Events] GmailLog --> Search[Search by Subject/Sender] Search --> Identify[Identify Affected Users] Identify --> Action[Bulk Delete/Quarantine]
Ready for the real thing?
The full GCP-AGWA simulator has every exam-style question, timed mode, and instant scoring.