Objective 4.1
AGWASecuring user access
Objective 4.1 sits in Managing security policies and access controls, which carries 20% of the Google Workspace Admin exam. The questions below are original, written from the official objective title above, and each explanation cites the Google Cloud page it rests on.
Objective title verbatim from the official objectives. Google Cloud exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
In two-step verification, a user signs in with their password and one more factor. What category is that second factor?
Correct.
Concept
Two-step verification combines a knowledge factor with a possession factor. The second step is a device or key the user holds.
Why B
The second step is something the user has, such as a phone or security key.
Source
Google Workspace, Protect your business with 2-Step Verification, checked August 2026With 2SV, your users sign in to their account in two steps with something they know (their password) and something they have (their phone or a Security Key).
Now you: objective 4.1 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
You shorten the web session length for a high-risk OU. What do users in that OU see when a session expires?
Sample question 2 of 3
You need a help desk technician to reset passwords for regular staff but not touch other administrators' accounts. Which prebuilt role fits best?
Sample question 3 of 3
Only one role can create and assign other administrator roles in your tenant. Which role is it?
That’s 3 of the full Google Workspace Admin bank.
Keep going free: 10 questions per certification in bank practice, with no account.
Continue practisingRead the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.