You have been asked to describe ChromeOS’s built-in security features. What benefit does enabling Verified Boot provide on a ChromeOS device?
AIt ensures that the OS is uncompromised
BIt allows updates to happen in the background
CRunning both operating systems on one device at the same time makes it twice as powerful
DIt installs the known safe backup OS every time the device is started up
An administrator wants to use a custom extension to install a client certificate on a ChromeOS device so it can connect to the corporate Wi-Fi.
Which action is required to achieve this?
AInstall on the device via guest mode
BDistribute through the Chrome Web Store
CForce-install to the device
DEncode the certificate in DER-encoded format
You need to configure a policy that stops the device from shutting down when it is idle at the sign-in screen. Where should you go?
AUser Settings > Idle settings
BUser Settings > User Experience
CDevice Settings > Allow shutdown
DDevice Settings > Power management
You have been asked to select a third-party IdP to enable sign-in to ChromeOS devices. Your ChromeOS devices display an "Unable to sign in to Google" message. How should you troubleshoot this?
AEnsure the identity provider is using an SAML compliant connection
BCheck Multi-Factor Authentication for the user account in the Google Admin console
CDisable the SSO connection in the Google Admin console
DApply the SSO certificate to the ChromeOS device
QuestionQ6
Manage apps and extensions
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Configure ChromeOS policies and settings
QuestionQ8
Manage apps and extensions
QuestionQ9
Configure ChromeOS policies and settings
QuestionQ10
Configure ChromeOS policies and settings
QuestionQ11
Manage apps and extensions
QuestionQ12
Manage ChromeOS devices
QuestionQ13
Manage ChromeOS devices
QuestionQ14
Configure ChromeOS policies and settings
QuestionQ15
Manage apps and extensions
QuestionQ16
Manage users, groups, and organizational units
QuestionQ17
Configure ChromeOS policies and settings
QuestionQ18
Manage ChromeOS devices
QuestionQ19
Configure ChromeOS policies and settings
QuestionQ20
Configure ChromeOS policies and settings
QuestionQ21
Manage ChromeOS devices
QuestionQ22
Manage ChromeOS devices
QuestionQ23
Manage ChromeOS devices
QuestionQ24
Manage apps and extensions
QuestionQ25
Manage ChromeOS devices
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
You are working with the finance team, which has requested a specialized application to reconcile month-end revenue. As the ChromeOS Administrator, you see that the application is available for Android. Before deploying this application to the finance team, what considerations should you make?
ARoll out the application for the entire finance team immediately and gather feedback
BTest the application for devices in a pilot organizational unit (OU) before rolling it out to everyone
CContact the application development team of the finance application for binaries that allow for user testing
DProvide a subset of the finance team with another dedicated device to test the application and gather feedback
You are configuring a proof of concept in an email-verified trial environment instead of a domain-verified environment. When you attempt to integrate the existing third-party Identity Provider (IdP) to provision user accounts, an error occurs. What is the most likely reason?
AYou need to purchase Google Workspace licenses to be able to integrate with third party IdPs.
BYou are only able to manage devices in an email-verified domain, not users.
CEmail-verified domain environments only allow for a single managed user per domain.
DYou need to verify a domain in order to integrate with third party IdPs.
You rely on a number of applications and want to ensure they continue to run smoothly with every new version of Chrome. What should you do?
AAsk users to provide feedback on the applications within a week of a new Chrome release.
BAdvise them to take no action. All applications are automatically supported on the latest version of Chrome.
CAlways install the latest version of those applications when they become available so they are always compatible with the latest version of Chrome.
DImplement a QA strategy and put their IT group and 5% of users on the beta channel of ChromeOS so they can find and report bugs early for upcoming Chrome releases.
Your organization’s security protocols require that users are logged out of any unattended devices after 24 hours. You need to manage 1000 ChromeOS devices. How would you implement this with the least administrative effort?
AEnable the "User and Browser Settings" and update "Maximum user session length" to any time up to 24 hours
BCreate a corporate policy stating the users are to manually sign out after the end of every shift
CYou can remotely access each device and sign out of the user account using Chrome Remote Desktop
DForce-install a custom app to each device in question that notifies the user that they need to sign out of their device after 24 hours
All kiosk devices must update only within specified hours. Which setting is required?
ARollout plan
BVersion pinning
CRelease channel
DBlackout windows
Your security team requests deployment of only one specific Android app on ChromeOS for the security department. As a ChromeOS Administrator, you must determine how to block every other Android app except the required one. How should you proceed?
AFrom the "Apps & extensions" page, add the Android app on the security team user OU
BOn the "Users & Browser Settings" tab, for the Play Store, use the "Block all apps admin manages allowlist" policy and allow only the Android app that you want from "Apps & extensions"
COn the "Users & Browser Settings" tab, for the Chrome Web Store, use the "Block all apps, admin manages allowlist" policy and allow only the Android app that you want on "Apps & extensions"
DFrom the "Apps & extensions" page, add the Android app on the security team user OU and select "Force Install + pin to ChromeOS taskbar"
You plan to purchase new ChromeOS devices for your sales team and want to use Zero-Touch Enrollment (ZTE). You want the new devices to enroll directly into an organization unit named ‘Sales Devices’. How can you generate the correct ZTE token in the Admin console with the least administrative effort?
AAt the “ChromeOS devices” page, click on the “Enroll devices” button and navigate to the “ChromeOS tokens” page.
BFrom the “ChromeOS devices” page select the “Sales Devices” organization unit. Click on the “Enroll devices” button followed by the “Generate token” button to generate the ZTE token.
CClick on the “Enroll devices” button followed by the “Generate token” button from the “ChromeOS devices” page. Once the devices have been enrolled, you can move them into the Sales Devices organization unit.
DContact your Google Partner to request the ZTE token. You will need to specify that the ZTE token is to be applied to the Sales Devices organization unit.
Your company’s network team has reported Wi‑Fi problems on certain ChromeOS devices. To troubleshoot, you must reproduce the issue and also gather network logs. How will you proceed?
AFrom chrome://network, use the “Network Logs” tab, select the “Wi-Fi debug” mode, open a new tab and reproduce the issue.Once completed, go back to the original tab, then export the “system_logs.txt" file and all log files collected by debugd.
BFrom chrome://network, use the “Network Logs” tab and select the policies.json, all logs files collected by debugd, and all Chrome log files.
CFrom chrome://network, use the “Network Logs” tab, select the “Wi-fi debug" mode, then export the “system_logs.txt” file and all log files collected by debugd.
DFrom the Chrome Browser, use the “chrome://system" page and check the “wifi_status_no_anonymize" attribute
A super admin is configuring third-party SSO for their organization. When testing with their own account, they do not see the SSO screen.
What is responsible for this behavior?
ASSO settings are misconfigured
BThe account is in the wrong OrgUnit
CThird-party SSO is not enabled
DSuper admin bypassed the third-party
You have received a new, custom, mission-critical web app from your development team. As the ChromeOS Administrator responsible for deploying the application to one particular business unit, it has been decided to use ChromeOS to complete this rollout.
What should you do to support this deployment?
AReach out to Chrome Enterprise support and create a ticket to deploy the custom web application to those business users.
BLeverage partners to develop software deployment pipelines scoped only to the OU.
CAllow the installation of the web app from the Chrome Web Store to users within that business unit.
DWith the business unit scoped to its own organizational unit (OU), force the installation of the app and extension to your users and browsers via the URL of the web application.
An organization has created organizational units in the Google Admin console to provide additional management structure. What is the most effective way to manage each OU without affecting the top-level OU policy?
ADelete sublevel OUs and only work from the top level OU
BDisable auto updates
COverride the inheritance for a given policy
DForce inheritance from top level OU to all OUs
You must schedule automatic reboots for every digital-signage ChromeOS device each week. You have created a Digital Signage child organization to tailor kiosk device policies for this deployment. How can you enforce scheduled reboots for the digital-signage devices every Friday?
AIn the “Digital Signage” child organization, disable scheduled reboots except on Friday.
BIn the “Digital Signage” child organization, set the policy to always reboot on Friday on user sign-out.
CIn the “Digital Signage” child organization, apply reboot after the uptime limit on Friday.
DIn the “Digital Signage” child organization, set the policy to enable scheduled reboots on Friday.
How can you use Chrome Remote Desktop from the Google Admin console to connect to a user?
AFind the user account and click remote desktop
BOpen Chrome Remote Desktop and type the device serial number
COpen Chrome Remote Desktop and type the user's username
DFind the device and click remote desktop
After deploying your Android VPN client, you want to enforce an always-on VPN. Where do you configure it?
ADevice settings - Always-on VPN
Bvia JSON configuration with the deployed application
CNetwork settings - Always-on VPN
DUser settings - Always-on VPN
Which two methods can customers use to open a support case for ChromeOS?
Choose two
AChat support via the Admin console
BContact the device manufacturer
CFile feedback on the device with Alt + Shift + i
DFile case through Customer Care Portal
ESend an email to ChromeOS support
How can a ChromeOS administrator capture logs remotely?
AEnable device system log upload device settings
BFind the user and click Capture logs
CEnable user log upload in user settings
DFind the device and click Capture logs
Your organization receives several refurbished ChromeOS devices that you intend to roll out in your Google Admin tenant. After starting the devices and completing OOBE, each device automatically enrolls in a different domain. What is causing this behavior?
AThe device has a script set to run that automatically enrolls the device
BThe previous owner of the device enabled the “forced re-enrollment” policy
CChromeOS is installed with the previous organization’s custom image
DThe device has not been powerwashed
As your organization’s administrator, you want to assign a delegated-admin custom role to perform only a limited set of ChromeOS device-management tasks for the Marketing organizational unit. What should you do?
ACreate and assign a custom role with “Chrome Management permissions" for the root OU
BCreate and assign a super admin role
CCreate and assign a custom role with “Chrome Management permissions" for the Marketing Users OU
DCreate and assign a custom role with “Chrome Management permissions" for the Marketing devices OU
In the Apps & extensions menu, which two methods can an administrator use to specify the users to whom the application policy applies?
Choose two
ASelect the Organizational Unit
BAuto-launch app function
CUpload JSON file in the app policy
DApply to the desired Google group
EEnsure the user and device are in the same OU
A large marketing company employs interns in its IT department. The interns need to view only information from ChromeOS devices, but they must not be able to manage or update any devices.
How should an administrator assign this role to the interns?
ACreate a custom services admin role and enable 2FA
BCreate Custom role under Chrome management and assign Telemetry API role
CCreate Custom role under Chrome management and assign Settings role
DCreate Custom role under Chrome management and assign Manage ChromeOS devices role
Community Discussion