PWA — Frequently Asked Questions
Community-vetted answers to 15 common questions about this exam.
The administrator should first check the security settings in the Google Admin console. Navigate to Apps > Google Workspace > Drive and Docs > Sharing settings. Verify if there is a 'Block list' of file types that includes the extension of the file the user is trying to access. If the file type is blocked, the admin can remove it from the list to restore access.
The first step is to determine the scope of the issue. The administrator should check the Google Workspace Status Dashboard to see if there is a known service outage or degradation affecting Google Meet. If the service is healthy, the issue is likely local to the user's network, device, or browser, and troubleshooting should focus there (e.g., checking bandwidth, clearing cache).
This can be achieved using Approved Senders for the temporary employees' organizational unit (OU). In the Admin console, go to Apps > Google Workspace > Gmail > Compliance. Create a new rule, set the scope to the specific OU for temporary employees, and under 'Approved senders', specify the list of allowed domains. This ensures they can only receive mail from those trusted sources.
The most secure method is to use Restricted access with a passcode. When sharing the file, select 'Restricted', then click 'Copy link' and choose 'Share with a passcode'. Set a passcode and share the link and the passcode with the external user through separate communication channels. This prevents anyone with the link from accessing the file without the passcode.
An administrator can configure data regions in the Admin console. Navigate to Account > Account settings > Data regions. From there, you can select the primary and secondary data regions for core Google Workspace services like Gmail and Drive. This setting dictates where Google stores your organization's data at rest.
Edit the existing DLP rule. In the Admin console, go to Security > Data protection > DLP. Find the rule you want to apply and click to edit it. In the 'Scope' or 'Rules' section, add the specific Finance shared drive to the list of locations where the rule should be enforced. This is more efficient than creating a new rule from scratch.
Create a dedicated Organizational Unit (OU) for the test users and enroll it in the Rapid Release Program. Move the test user accounts into this new OU. Then, go to Account > Account settings, select the new OU, and change the 'Release track' from 'Scheduled Release' to 'Rapid Release'. This gives them access to new features as soon as they are available.
Users should adjust their calendar sharing settings. In Google Calendar, go to Settings and sharing for the calendar. Under 'Access permissions for events', select 'See only free/busy (hide details)'. Share the calendar with the team or specific individuals. This allows others to see when they are busy but not the title or description of the events.
This can be configured using advanced sharing rules. In the Admin console, navigate to Apps > Google Workspace > Drive and Docs > Sharing settings. Under 'Sharing options', you can create rules to restrict sharing between specific Organizational Units (OUs). Set up a rule that prevents the OU for the first department from sharing files with the OU for the second department.
The Security Center Dashboard is the primary tool for this. It provides a centralized view of the organization's security posture, highlighting potential risks and configuration issues across Gmail, Drive, Meet, and other Workspace apps. It offers actionable insights and recommendations to improve security.
Within the DLP rule configuration, you can set specific restrictions. When creating or editing a DLP rule in Security > Data protection > DLP, add a 'Restrictions' action. Here, you can select options to block users from downloading, printing, and copying the content of the file that triggers the rule.
This can be automated using Dynamic Groups. In the Admin console, go to Directory > Groups and create a new group. Set the 'Group type' to 'Dynamic'. Then, define the membership rules, such as User's Location equals 'New York'. The group membership will be automatically updated as user profiles are changed.
Create a content compliance rule in Gmail. Navigate to Apps > Google Workspace > Gmail > Compliance. Create a new rule that scans outbound emails. Set the condition to look for the specific project codename in the email body or subject. Set the action to 'Reject message' or 'Quarantine message' to prevent it from being sent.
This is done using Context-Aware Access. In the Admin console, go to Security > Access and data control > Context-Aware Access. Create an access level based on IP address ranges or regions. Then, create an access policy that applies this access level to specific apps, blocking users who are accessing from unauthorized geographic locations.
Create a custom admin role with specific Vault privileges. In the Admin console, go to Account > Admin roles > Create admin role. Under 'Privileges', find Google Vault and selectively grant only the necessary permissions, such as 'Matters - Read Only' or 'Search - Run Searches', instead of assigning the full Vault Administrator role.
← Back to Mastering the Professional Google Workspace Administrator Exam