Question 1
Multiple choice
What are two ways customers can open a support case for ChromeOS? Choose 2 answers
-
A
Chat support via the Admin console
-
B
Contact the device manufacturer
-
C
File feedback on the device with Alt + Shift +1
-
D
File case through Customer Care Portal
-
E
Send an email to ChromeOS support
Reveal answer details
Close answer details
Correct answersB, D
ExplanationB. Contact the device manufacturer: ChromeOS devices are manufactured by various companies like Acer, HP, Lenovo, etc. Each manufacturer provides its own support channels, including phone, email, or chat support. Customers can contact the manufacturer for hardware-related issues or specific device configurations. D. File a case through the Customer Care Portal: Google provides a customer care portal where customers can submit support cases online. This portal allows users to describe their issues, attach relevant files, and track the progress of their case. Why other options are incorrect: A. Chat support via the Admin console: Chat support is usually available for enterprise customers with Chrome Enterprise Upgrade or Google Workspace, not individual ChromeOS users. C. File feedback on the device with Alt + Shift + 1: This keyboard shortcut is used to capture screenshots and send feedback to Google, but it doesn't directly open a support case. E. Send an email to ChromeOS support: While Google has support channels, sending a general email might not be the most efficient way to open a case and get a timely response. References: Get support - Chrome Enterprise and Education Help: (https://support.google.com/chrome/a/answer/4594885?hl=en)
As your organization's administrator, you want to assign a delegated admin custom role in order to perform a limited set of ChromeOS device management tasks only for the Marketing organizational unit. What should you do?
-
A
Create and assign a super admin role
-
B
Create and assign a custom role with "Chrome Management permissions" for the root OU
-
C
Create and assign a custom role with "Chrome Management permissions" for the Marketing devices OU
-
D
Create and assign a custom role with "Chrome Management permissions" for the Marketing Users OU
Reveal answer details
Close answer details
Correct answerC
ExplanationTo delegate ChromeOS device management specifically for theMarketing OU, create a custom rolewith"Chrome Management permissions"and assign it specifically to the Marketing devices OU. This ensures that the delegated admin can manage only the devices within that specific OU without impacting the entire organization. Verified Answer from Official Source: The correct answer is verified from theGoogle Admin Console Role Management Guide , which recommends assigning roles at the appropriate OU level for granular access control. "Assign roles to specific OUs to limit administrative control to relevant organizational units, such as the Marketing devices OU." By targeting the role to the Marketing devices OU, you ensure that the delegated admin does not have unnecessary access to devices in other parts of the organization, maintaining the principle of least privilege. Objectives: Implement delegated administration for specific OUs. Limit administrative scope to enhance security. References: Google Admin Console Role Management Guide
You want to enterprise enroll a device that has existing consumer accounts. What should you do first?
-
A
Contact Google support to convert the device into an enterprise device
-
B
Delete all consumer accounts, and then follow the same steps for enrolling a brand new device
-
C
follow the same steps for enrolling a brand new device
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationDevice State: Before you can enroll a ChromeOS device into an enterprise environment, it's crucial that it's not associated with any personal Google accounts. Existing consumer accounts can interfere with the enrollment process and the application of enterprise policies. Data Backup (Optional): If the existing consumer accounts on the device contain important data, advise the users to back up their information before proceeding. Account Removal: Sign in to the device with each consumer account and remove the account from the device. This ensures a clean slate for the enterprise enrollment process. Powerwash (Optional): While not strictly necessary after removing accounts, performing a powerwash (factory reset) is a recommended step. It further erases any remaining data or configurations linked to the consumer accounts, ensuring a completely fresh start for the device. Enrollment: Once the consumer accounts are removed (and optionally, after powerwashing), follow the standard enterprise enrollment steps for your organization. This typically involves entering enterprise credentials at the login screen, or using a unique enrollment token, depending on your company's setup. References: Enroll ChromeOS devices: (https://support.google.com/chrome/a/answer/1360534?hl=en) This guide provides step-by-step instructions on enrolling ChromeOS devices into an enterprise environment, including details on prerequisites and different enrollment methods.
Your customer is deploying ChromeOS devices in their environment and requires those ChromeOS devices to adhere to web filtering via TLS (or SSL) Inspection. What recommendations should you make to your customer in setting up the requirements for ChromeOS devices?
-
A
Configure a hostname allowlist, set up a TLS (or SSL) certificate, then verify TLS (or SSL) inspection is working
-
B
Reach out lo Google Workspace Security and Compliance for tailored configurations for your customer
-
C
Configure a transparent proxy, set up your allowlist to use * google com. then verify TLS (or SSL) inspection is working
-
D
ChromeOS devices are preconfigured to adhere to company TLS (or SSL) inspection by default and can therefore be deployed with no additional configuration
Reveal answer details
Close answer details
Correct answerA
ExplanationTo set up TLS (or SSL) inspection for web filtering on ChromeOS devices, you need to follow these steps: Configure Hostname Allowlist: Create an allowlist of hostnames (e.g., *.google.com, *[invalid URL removed]) that should bypass TLS inspection. This ensures that essential services like Google services and your own domain can function properly. Set up TLS Certificate: Obtain the required TLS/SSL certificate from your web filter provider and install it on your web filter. ChromeOS devices need this certificate to establish a secure connection with the web filter for TLS inspection. Verify TLS Inspection: Once the configuration is in place, test and verify that TLS inspection is working as expected. This involves checking if the web filter can correctly intercept and decrypt HTTPS traffic for websites not on the allowlist. Why other options are not correct: Option B: While reaching out to Google Workspace Security and Compliance can be helpful, it's not the primary step in setting up TLS inspection. The configuration needs to be done on the web filter and ChromeOS devices. Option C: Transparent proxies are generally not recommended for ChromeOS devices as they can interfere with certain functionalities. While it might work with an allowlist for Google domains, it's not the best practice. Option D: ChromeOS devices do not come preconfigured to adhere to company TLS inspection. This configuration needs to be set up explicitly by the administrator. References: About TLS (or SSL) inspection on ChromeOS devices: (https://support.google.com/chrome/a/answer/3504942) Verify TLS (or SSL) inspection works: (https://support.google.com/chrome/a/answer/3504943)
The finance team for an organization buys a new printer to print sensitive documents without using the main office printer. How should you automatically configure the printer for finance team users?
-
A
Deploy correct drivers to the finance devices
-
B
Deploy the printer via Groups
-
C
Add the printer directly to the user
-
D
Plug the new printer directly into the router
Reveal answer details
Close answer details
Correct answerB
ExplanationTo configure the printer specifically for finance team users, the most efficient approach is to deploy the printer via Groups. By assigning the printer to a Google Group that contains finance team members, the printer will automatically be available to all users in that group without manual configuration for each device. Verified Answer from Official Source: The correct answer is verified from theGoogle Admin Console Printing Configuration Guide, which recommends using Groups to deploy printers for specific user sets. "Deploy printers to user groups to ensure that only specified users have access. Use the Groups feature to manage printer availability efficiently." Using Groups for printer deployment ensures that only authorized users (in this case, finance team members) can print sensitive documents, maintaining security and ease of access. Objectives: Secure printer access for specific user groups. Simplify printer configuration for departments. References: Google Admin Console Printing Configuration Guide
How would you deploy a Progressive Web Application to all managed user accounts?
-
A
Force-install the Progressive Web Application URL in the "Chrome Apps & extensions" page
-
B
Set up Chrome Imprivata shared apps & extensions to force-install the Progressive Web Application URL
-
C
Go to "User & Browser Settings" and add the Progressive Web Application URL in the "Legacy Browser Support" site list
-
D
Open "Additional Google services" to force-install the Progressive Web Application URL
Reveal answer details
Close answer details
Correct answerA
ExplanationTo deploy a Progressive Web Application (PWA) to all managed user accounts, follow these steps in the Google Admin console: Sign in to Google Admin console: Use your administrator credentials to access the console. Navigate to Device Management: Go to Devices > Chrome > Settings > Apps & extensions. Select User or Group: Choose the top-level organizational unit or a specific group to apply the PWA deployment. Add by URL: Click on the yellow "+" icon and select "Add by URL." Enter PWA URL: Paste the URL of the PWA you want to deploy. Configure Installation Policy: Select "Force install" to ensure the PWA is automatically installed for all users within the selected scope. This method allows you to centrally manage and deploy PWAs across your organization, making them easily accessible to users on their ChromeOS devices.
You have been asked to explain the built-in security features of ChromeOS. What i3 the benefit of having verified boot enabled on a ChromeOS device?
-
A
It ensures that the OS is uncompromised
-
B
It allows updates to happen in the background
-
C
Running both operating systems on one device at the same time makes It twice as powerful
-
D
It installs the known safe backup OS every time the device is slatted up.
Reveal answer details
Close answer details
Correct answerA
ExplanationVerified Boot in ChromeOS is a security mechanism that checks the integrity of the operating system during startup. If it detects any unauthorized modifications or compromises, it can initiaterecovery processes to restore the OS to a known good state, ensuring that the device boots up with a secure and untampered operating system. Option B is incorrectbecause background updates are a separate feature. Option C is incorrectbecause dual-boot is not related to Verified Boot. Option D is incorrectbecause Verified Boot doesn't install a backup OS but verifies the existing one. Verified Boot: https://www.chromium.org/chromium-os/chromiumos-design-docs/verified-boot/
Your administration team is about to deploy a fleet of ChromeOS devices. Your users have their own peripherals, and you would like them to use what they have if possible. You also would like to let your users know what peripherals work and what peripherals do not. What should you do for your users?
-
A
Send them all new peripherals and have your users send in their old equipment even if the old equipment works
-
B
Tell your users that every peripheral works with ChromeOS
-
C
Create Change Management documentation that provides them with information on how to check their current peripherals and instructions on how to get new equipment
-
D
Tell your users to try what they have and to start an IT support ticket if something isn't working right
Reveal answer details
Close answer details
Correct answerC
ExplanationThe best way to handle this situation is to createChange Management documentation that clearly outlines how users can check the compatibility of their peripherals with ChromeOS. This documentation should also include instructions on how to obtain new peripherals if needed. This proactive approach reduces confusion and ensures that users know how to verify their existing equipment. Verified Answer from Official Source: The correct answer is verified from theGoogle Workspace Deployment Guide, which emphasizes proactive user communication through change management documentation during device rollouts. "To ensure smooth transitions, provide users with detailed change management documentation, including steps to verify peripheral compatibility and obtain replacements if necessary." Creating clear documentation helps reduce support requests and empowers users to verify their own equipment, streamlining the deployment process. Objectives: Facilitate smooth ChromeOS device rollout. Enhance user self-service with comprehensive guidance. References: Google Workspace Deployment Guide
Your organization is using a third-party IdP. Users report that they can only log in to the device when connected to the Internet. Which setting is causing this problem?
-
A
-
B
Single sign-on cookie behavior
-
C
SAML single sign-on login frequency
-
D
Single sign-on IdP redirection
Reveal answer details
Close answer details
Correct answerC
ExplanationWhen using athird-party Identity Provider (IdP)with SAML-based Single Sign-On (SSO), users might only be able to log in when connected to the Internet if theSAML single sign-on login frequencysetting is configured in a way that requires online authentication. This configuration means that users must reauthenticate against the IdP whenever they log in, rather than using cached credentials. Verified Answer from Official Source: The correct answer is verified from theGoogle ChromeOS SSO Configuration Guide, which specifies that configuring login frequency to "Always" forces online reauthentication. "If the SAML single sign-on login frequency is set to 'Always', users must be online to authenticate through the third-party IdP each time they log in." To allow offline login, configure the setting to allow cached credentials, which enables users to log in even without an active Internet connection. Objectives: Enable offline login for SAML-based SSO. Manage login frequency settings effectively. References: Google ChromeOS SSO Configuration Guide
Question 10
Single choice
As a ChromeOS Administrator, you are tasked with blocking incognito mode in the ChromeOS Browser. How would you prevent users from using incognito mode?
-
A
Navigate to "Users & Browser Security Settings" and set the "Disallow incognito mode" policy.
-
B
Go to "User & Browser Settings" to restrict sign-in to pattern and "Disallow incognito mode."
-
C
From "Device Settings", change Kiosk settings to "Disallow incognito mode."
-
D
In "Enrollment Settings", disable verified access and incognito mode for content protection.
Reveal answer details
Close answer details
Correct answerA
ExplanationTo block incognito mode in ChromeOS, administrators need to configure the policy under "Users & Browser Security Settings". The specific policy to disable incognito mode ensures that users can only browse in regular mode, allowing for better tracking and compliance. Verified Answer from Official Source: The correct answer is verified from theGoogle Admin Console Policies Guide, which details managing incognito mode via User & Browser settings. "To disable incognito mode, go to Admin console > Devices > Chrome > Settings > Users & browsers > Security settings, and select 'Disallow incognito mode'." Disabling incognito mode is essential for compliance and security, especially in educational and enterprise environments where browsing history must be retained. Objectives: Manage browser settings for security compliance. Disable incognito mode on ChromeOS devices. References: Google Admin Console Policies Guide
Question 11
Single choice
A customer is setting up a new Google tenant. You have been tasked with creating the organization unit structure for the Google Admin console. Following Google best practices, how should you set up the new organization units?
-
A
Recreate the same OU structure as the current LDAP implementation
-
B
Combine Devices and Users into single OUs to avoid operational overhead
-
C
Follow a hierarchical OU structure
-
D
Use shortest possible names for OUs to avoid confusion
Reveal answer details
Close answer details
Correct answerC
ExplanationFollowinga hierarchical OU structureallows for clear and organized management of devices and users. This structure mirrors real-world organizational layouts (such as departments or geographical locations), which makes applying policies and managing devices more straightforward. Verified Answer from Official Source: The correct answer is verified from theGoogle Admin Console Best Practices Guide, which recommends using hierarchical OUs for clarity and ease of management. "Using a hierarchical OU structure makes it easier to manage devices and users separately, especially when applying specific policies." A well-organized OU structure improves scalability and simplifies policy management, reducing administrative complexity. Objectives: Implement structured and manageable OU setups. Follow best practices for organizational hierarchy in Google Admin Console. References: Google Admin Console Best Practices Guide
Question 12
Single choice
You have been tasked to deploy shared devices using Managed Guest Sessions. Your IT policy requires blocking access to "google.com" at the parent organization. How would you prevent users from accessing "google.com" for all Managed Guest Sessions at the parent organization?
-
A
Add "google.com" to "allow insecure content on these sites"
-
B
Add "google.com" to "disallowed URLs in content settings"
-
C
Add "google.com" to "the blocked URL exceptions"
-
D
Add "google.com" to "the list of blocked URLs"
Reveal answer details
Close answer details
Correct answerD
ExplanationTo block access to a specific website across all managed guest sessions, you need to add the site to the"list of blocked URLs". This ensures that regardless of the session type, users cannot access the specified site. Verified Answer from Official Source: The correct answer is verified from theGoogle ChromeOS Managed Guest Session Guide, which explains that adding URLs to the blocked list restricts access across all sessions. "To enforce web filtering policies during Managed Guest Sessions, add the URL to the blocked list in the Admin console under User & Browser Settings." By configuring the blocked URL list, you enforce consistent access policies even when devices are used in guest mode. Objectives: Implement web filtering for Managed Guest Sessions. Enforce consistent security policies across sessions. References: Google ChromeOS Managed Guest Session Guide
Question 13
Single choice
To allow remote users to securely connect to an internal network, the organization you're supporting is using a VPN. The organization would like you to configure the ChromeOS devices so that the Android VPN clients deployed are automatically configured with the correct hostname. How should you configure this in the Admin Console according to Google best practice?
-
A
Download the Android app on a ChromeOS device, add the hostname manually then re-upload the app in the organization's private Google Play Store and deploy it lo all ChromeOS devices
-
B
Contact the VPN provider and ask them to provide you with a custom installable client with the correct configuration pre-configured. Then deploy that installable
-
C
Add a managed configuration using JSON to the Android app
-
D
Upload a JSON file with the configuration into the Google Play Store
Reveal answer details
Close answer details
Correct answerC
ExplanationThis is the most efficient and scalable way to automatically configure Android VPN clients on ChromeOS devices with the correct hostname: Obtain Configuration: Get the required VPN configuration details (hostname, authentication methods, etc.) from the VPN provider or your organization's network administrator. This configuration is typically in JSON format. Create Managed Configuration: In the Google Admin console, navigate to Devices > Chrome > Settings > Android Apps > Managed Configurations. Select the VPN App: Choose the specific Android VPN app you want to configure. Add JSON Configuration: Paste the JSON configuration into the provided field. Ensure the configuration is valid and accurate. Save and Deploy: Save the managed configuration and apply it to the desired organizational units (OUs) containing the ChromeOS devices. This method allows you to centrally manage VPN configurations for Android apps on ChromeOS devices, ensuring consistency and reducing the manual effort required from users.
Question 14
Single choice
You have 150 Chrome Enterprise Upgrades (CEU) in your Google Admin console. You decide to purchase 20 Chromebook Enterprise devices (CBE). After enrollment, you would like to identify the type of licenses used by your devices. What should you do?
-
A
From the "Device information" page, check the "Device Type" attribute content
-
B
Check your "Billing subscription" page to identify devices with CBE and CEU
-
C
Check directly from the device through the "About Chrome OS" page
-
D
Check from the device through chrome://policy
Reveal answer details
Close answer details
Correct answerA
ExplanationTo distinguish betweenChrome Enterprise Upgrades (CEU)andChromebook Enterprise (CBE)devices, go to theDevice informationpage in the Admin console and check the "Device Type"attribute. This attribute clearly indicates whether the device has a CBE or CEU license. Verified Answer from Official Source: The correct answer is verified from theGoogle Chrome Enterprise Licensing Guide, which specifies how to identify device types based on licensing information. "To check the licensing type, go to the Admin console, navigate to Devices > Chrome > Devices, and check the 'Device Type' attribute on the device information page." This method provides a clear distinction between devices with built-in licenses (CBE) and those upgraded with a separate license (CEU). Objectives: Identify license types for ChromeOS devices. Efficiently manage device inventory and licensing. References: Google Chrome Enterprise Licensing Guide
Question 15
Single choice
At a specific location in your organization, users cannot log in to their ChromeOS devices. The ChromeOS Administrator has also noticed that devices have not synced in the past 24 hours. You have updated policies In the Admin console for your fleet of ChromeOS devices, but the devices are not getting the updated policies. What is a probable change in the environment that can cause these issues?
-
A
A different location enrolled a large number of new devices
-
B
Your network administrator has blocked all network traffic to Google services
-
C
Your root Certificate Authority expired
-
D
Your organization's licenses have recently expired
Reveal answer details
Close answer details
Correct answerB
ExplanationBlocking all network traffic to Google services would prevent ChromeOS devices from communicating with Google servers. This would lead to several issues: Login failures:ChromeOS devices require access to Google services for user authentication and login. Sync failures:ChromeOS relies on Google services to sync user data, settings, and policies. Policy updates not received:ChromeOS devices fetch policy updates from Google servers, so blocking access would prevent them from getting updates. Why other options are less likely: A. New devices enrolled:While enrolling new devices might cause some temporary network congestion, it wouldn't typically block all communication with Google services. C. Root CA expiration:This would affect secure connections to websites, but not necessarily prevent all communication with Google services. D. Expired licenses:Expired licenses would restrict access to some features but wouldn't prevent basic login and sync functionality.
Question 16
Single choice
What is a feature of Verified Boot?
-
A
Eliminates the need for strict policy controls
-
B
Protects anonymous guests from using the device
-
C
Prevents the user from accessing unauthorized websites
-
D
Makes sure that the firmware and OS have not been tampered with
Reveal answer details
Close answer details
Correct answerD
ExplanationVerified Boot is a security feature in ChromeOS that ensures the integrity of the operating system every time the device starts. It checks the OS for modifications or corruptions, preventing tampered systems from booting and automatically repairing them if necessary. Verified Answer from Official Source: The correct answer is verified from theChromeOS Security Guide, which highlights Verified Boot as a core feature for maintaining the OS's integrity. "Verified Boot ensures that the firmware and OS on ChromeOS devices have not been tampered with. If an anomaly is detected, the system reverts to a known good state." This feature is crucial for protecting the system from malicious software or unauthorized changes, maintaining the device's security posture. Objectives: Enhance device security through integrity checks. Understand ChromeOS boot protection mechanisms. References: ChromeOS Security Guide
Question 17
Single choice
Your security department wants to mitigate the risk of data loss in the case of stolen equipment. As a ChromeOS Administrator, you want to ensure that your ChromeOS devices will be able to stay enterprise-managed. What should you do?
-
A
Add a disabled device return instruction message.
-
B
Enable the Autocomplete domain feature.
-
C
Force devices to automatically re-enroll after wiping.
-
D
Allow users into your organization to enroll new or re-enroll existing devices.
Reveal answer details
Close answer details
Correct answerC
ExplanationEnabling Forced Re-enrollment ensures that even if a device is wiped (Powerwashed), it will automatically re-enroll into the management domain once it connects to the internet. This feature is crucial for maintaining control and management over devices, particularly in cases of theft or loss. Verified Answer from Official Source: The correct answer is verified from theGoogle ChromeOS Management Best Practices, where it states that forced re-enrollment helps maintain device management post-wipe. "When forced re-enrollment is enabled, devices that are wiped are automatically re-enrolled into your domain when connected to the internet." This setting ensures that the device will always be managed by the organization, regardless of whether it has been wiped, thus mitigating data loss risks. Objectives: Manage device security and data integrity. Implement forced re-enrollment for ChromeOS devices. References: ChromeOS Management Best Practices
Question 18
Single choice
A user reports that their Chrome device has been stolen. What should the administrator do?
-
A
Use the Google Admin console to turn on the stolen Chromebook's webcam
-
B
Use the Google Android Device Manager to locate the Chromebook
-
C
Set the stolen Chromebook lo disabled mode to prevent user sign-ins
-
D
Remotely wipe user data from the Chromebook
Reveal answer details
Close answer details
Correct answerC
ExplanationWhen a Chrome device is reported stolen, the administrator should immediately take action to protect the data and prevent unauthorized access. The most effective step is to disable the device through the Google Admin console. This will prevent anyone from signing in to the device, rendering it unusable. Here's how to disable a stolen Chrome device: Sign in to Google Admin console: Use your administrator credentials. Navigate to Devices: Go to Devices > Chrome > Devices. Locate the Device: Find the stolen device using its serial number or other identifying information. Disable the Device: Click on the device and select "Disable." This will disable the device and prevent anyone from signing in, even if they try to reset the device.
|