Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Google Associate Google Workspace Administrator Exam - Topic 2 Question 20 Discussion

You recently noticed a suspicious trend in your organization's Google Drive usage. Several users have shared sensitive documents outside the organization, potentially violating your company's data security policy. You need to identify the responsible users and the extent of the unauthorized sharing. What should you do?
C) Use the security investigation tool to analyze Drive logs and identify the users.
A) Review the organization's sharing policies in the Admin console, and update the policies to prevent external sharing.
B) Use the security health page to identify misconfigured sharing settings in Drive.
D) Create an activity rule in the Security Center to alert you of future external sharing events.

Google Associate Google Workspace Administrator Exam - Topic 2 Question 20 Discussion

Actual exam question for Google's Associate Google Workspace Administrator exam
Question #: 20
Topic #: 2
[All Associate Google Workspace Administrator Questions]

You recently noticed a suspicious trend in your organization's Google Drive usage. Several users have shared sensitive documents outside the organization, potentially violating your company's data security policy. You need to identify the responsible users and the extent of the unauthorized sharing. What should you do?

Show Suggested Answer Hide Answer
Suggested Answer: C

The core of the problem is to identify the responsible users and the extent of past unauthorized sharing. The Security Investigation Tool is designed precisely for this purpose. It allows administrators to search and analyze various audit logs, including Drive logs, to pinpoint specific events, users, and data.

Here's why the other options are less appropriate as the first or most direct action for this specific problem:

A . Review the organization's sharing policies in the Admin console, and update the policies to prevent external sharing. This is a crucial preventative measure for the future, and a necessary step after identifying the scope of the problem. However, it won't help you identify who shared what in the past.

B . Use the security health page to identify misconfigured sharing settings in Drive. The security health page provides an overview of your security posture and can highlight general misconfigurations. While useful for identifying potential vulnerabilities, it won't give you the granular details of specific users and shared documents that have already occurred, which is what the question asks for.

D . Create an activity rule in the Security Center to alert you of future external sharing events. Similar to option A, this is a future-oriented preventative and monitoring measure. It will help catch future violations but won't provide information about the past unauthorized sharing that has already happened.

Reference from Google Workspace Administrator:

Security investigation tool: This tool is explicitly designed for identifying, triaging, and taking action on security issues. It allows administrators to search and analyze logs from various Google Workspace services, including Drive, to investigate specific events like external sharing.


Drive audit log events: The security investigation tool leverages audit logs. Drive audit logs capture events such as document sharing, changes in sharing permissions, and access.

Contribute your Thoughts:

0/2000 characters
Winifred
28 minutes ago
Wait, people are actually sharing sensitive info outside? That's wild!
upvoted 0 times
...
Rosio
5 days ago
I think we should focus on the logs to find out who did it.
upvoted 0 times
...
Chanel
10 days ago
Definitely need to check the sharing settings first.
upvoted 0 times
...
Emiko
16 days ago
The security health page is a good start, but we need to dig deeper!
upvoted 0 times
...
Carli
21 days ago
I disagree, updating policies won't help if users are already misusing them.
upvoted 0 times
...
Tonette
26 days ago
Wait, are people really sharing sensitive info outside? That's alarming!
upvoted 0 times
...
Teri
2 months ago
I think using the security investigation tool is the best way to pinpoint the users.
upvoted 0 times
...
Art
3 months ago
Definitely need to check the sharing policies first.
upvoted 0 times
...
Gracia
3 months ago
I wonder if creating an activity rule in the Security Center would be enough. It seems proactive, but I think we need to know who did it first.
upvoted 0 times
...
Val
3 months ago
I feel like we practiced a similar question where we had to identify users based on their activity. The security health page could be useful too, but I'm leaning towards option C.
upvoted 0 times
...
Nidia
3 months ago
I'm not entirely sure, but I remember something about reviewing sharing policies in the Admin console. Would that help prevent this in the future?
upvoted 0 times
...
Helene
4 months ago
I think we might need to use the security investigation tool to really dig into the logs and find out who shared those documents.
upvoted 0 times
...

Save Cancel