PCEA Sample Questions & Answers
Built-in security, compliance, and ChromeOS protections carry the biggest weight, alongside policy and release management basics, enrolling devices and provisioning users, Chrome Enterprise Core setup with MDM integration, extensions, and directory authentication.
Launch the full PCEA simulator →Showing 9 of 19 free samples.
- Question 1AdvancedSelect 2
Extensions and Applications Management · Private Extensions
An administrator manages a fleet of corporate-owned Windows laptops with managed Chrome browsers. A custom-built, in-house extension is required for all users. The extension files (
.crxand manifest) are hosted on an internal web server. Which TWO policies must be configured to force-install this extension and ensure it updates correctly from the internal server? (Select TWO)Show answer & explanation
Correct answers: A, C
This policy is used to force-install extensions. The value must include the extension's ID and the URL pointing to its update manifest XML file on the internal server.
This policy must be configured to allowlist the URL of the internal server where the extension's
.crxfile is hosted. Without this, Chrome will not trust the source and will block the installation, even if it's in the forcelist. - Question 2Beginner
Chrome Enterprise Management Fundamentals · Release Channels
True or False: The 'Extended Stable' release channel for Chrome receives feature updates at a slower pace than the 'Stable' channel, but receives security updates at the same rapid pace.
Show answer & explanation
Correct answer: A
This is true. The Extended Stable channel is designed for enterprises that need more time to manage updates. It receives new features on a slower, 8-week cycle, but critical security fixes are backported and delivered as they become available, typically every 2 weeks, just like the regular Stable channel.
- Question 3Advanced
Device and User Management · Kiosk Mode Configuration
Case Study:
A global retail company,
ShopFast, is deploying 5,000 ChromeOS devices to its stores to be used as point-of-sale (POS) terminals. These devices must be heavily restricted for security and operational consistency.Current Situation: The IT team has successfully enrolled all devices into the Google Admin console and placed them in a dedicated 'POS Terminals' Organizational Unit (OU). The devices connect to a dedicated, secured Wi-Fi network in each store. The primary application is a Progressive Web App (PWA) that handles all sales transactions.
Requirements:
- The devices must boot directly into the PWA and run it in fullscreen mode.
- Users must not be able to exit the PWA or access any other part of ChromeOS.
- The devices must automatically log in to a predefined guest session; no employee should need to enter credentials on the device itself.
- After 15 minutes of inactivity, the session must be terminated and a new session started to ensure data privacy between transactions.
Which configuration in the Google Admin console will meet all these requirements for the 'POS Terminals' OU?
Show answer & explanation
Correct answer: C
This is the correct and most complete solution. Configuring the device to run as a single-app Kiosk meets the requirements of booting directly into the PWA and preventing users from exiting. Setting the Kiosk app to be the specific PWA ensures it runs fullscreen. The auto-login feature is inherent to Kiosk mode. The requirement for session termination after inactivity is met by configuring the 'Idle session timeout' action within the Kiosk settings, which logs out and restarts the session.
- Question 4Advanced
Chrome Enterprise Management Fundamentals · Policy Conflicts Resolution
An administrator is troubleshooting an issue where a specific policy,
URLBlocklist, is not applying to a user's managed Chrome browser on their Windows machine. The administrator has verified the user and the browser are in the correct OU where the policy is set. Usingchrome://policy, the administrator sees the policy listed, but its source is 'Platform' and not 'Cloud'. What is the most likely cause of this issue?Show answer & explanation
Correct answer: B
When
chrome://policyshows the source as 'Platform', it indicates the policy is being set by the underlying operating system's management framework, which for a domain-joined Windows machine is typically Active Directory Group Policy (GPO). Platform policies (like GPO) have a higher precedence than policies delivered from Chrome Browser Cloud Management ('Cloud'). The administrator must find and remove the conflicting GPO. - Question 5Beginner
Chrome Enterprise Core and Cloud Management · Enrollment Tokens
A new Chrome Enterprise Administrator is setting up Chrome Browser Cloud Management for the first time. To enroll browsers, they must generate a token. What is the validity period of a newly generated enrollment token?
Show answer & explanation
Correct answer: C
Enrollment tokens for Chrome Browser Cloud Management do not have an automatic expiration date. They remain valid and can be used to enroll an unlimited number of browsers until an administrator explicitly revokes the token in the Google Admin console. This is a key security consideration for managing token lifecycle.
- Question 6Beginner
Chrome Enterprise Management Fundamentals · Release Channels
A company wants to ensure that all managed Chrome browsers are protected against newly discovered vulnerabilities as quickly as possible, even if it means sacrificing some stability. Which release channel should the administrator assign to the browsers?
Show answer & explanation
Correct answer: D
The Beta channel provides users with a preview of new features and updates about a month before they are released to the Stable channel. It is updated more frequently than Stable and is the best choice for getting early access to fixes and features, accepting a higher risk of instability. Dev and Canary are even faster but are generally not recommended for broad production use.
- Question 7Intermediate
Device and User Management · Device States and Troubleshooting
An administrator is configuring a ChromeOS device for a shared workspace. The goal is to allow any employee to log in with their corporate Google account, but to wipe all local user data from the device upon logout to protect sensitive information. Which device-level policy should be enabled?
Show answer & explanation
Correct answer: C
The 'User data' policy, when set to 'Erase all local user data', enables ephemeral mode. In this mode, a user can sign in and use the device normally, but their entire local profile (including files, browser history, and settings) is completely wiped from the device upon signing out, ensuring no data is left behind for the next user.
- Question 8IntermediateSelect 3
Security and Compliance · Advanced Protection Program
To enhance security for high-risk users, an administrator wants to enroll them in Google's Advanced Protection Program. Which of the following restrictions are imposed on users once they are enrolled in this program? (Select THREE)
Show answer & explanation
Correct answers: A, B, C
The core of the Advanced Protection Program is the enforcement of phishing-resistant authentication, which requires the use of physical or phone-based security keys.
To prevent malicious code, the program restricts app installations to a curated list from whitelisted stores, primarily the Chrome Web Store and platform-native stores.
The program significantly limits which third-party applications can request access to sensitive user data like Gmail and Drive, blocking most except for a few trusted apps.
- Question 9Advanced
Security and Compliance · Data Protection and Compliance
A hospital is deploying managed Chrome browsers on clinical workstations. To comply with HIPAA, the administrator must prevent any browser data from being synchronized to users' personal Google accounts. However, they still want to allow users to sign into Google services like Gmail. Which policy should be configured to achieve this?
Show answer & explanation
Correct answer: D
The
RestrictSigninToPatternpolicy is the ideal solution. It allows users to sign into web services like Gmail but restricts the primary browser sign-in (which controls sync) to accounts matching a specific pattern (the corporate domain). This prevents browser data like history, bookmarks, and passwords from being synced to a personal@gmail.comaccount, while not blocking access to Google services.
Ready for the real thing?
The full PCEA simulator has every exam-style question, timed mode, and instant scoring.