nerdexam
Google

ASSOCIATE-GOOGLE-WORKSPACE-ADMINISTRATOR · Question #32

You've noticed an increase in phishing emails that contain links to malicious files hosted on external Google Drives. These files often mimic legitimate documents and trick users into granting…

The correct answer is B. Conduct regular security awareness training to educate users. C. Create a Drive trust rule that blocks all external domains except for a pre-approved list of trusted. Two measures are needed that specifically address phishing via malicious external Drive files while still allowing legitimate external file access. Option B (security awareness training) is essential-educated users can recognize and avoid clicking suspicious links, directly…

Security and Access Management

Question

You've noticed an increase in phishing emails that contain links to malicious files hosted on external Google Drives. These files often mimic legitimate documents and trick users into granting access to their accounts. You need to prevent users from accessing these malicious external Drive files, but allow them to access legitimate external files. What should you do? (Choose two.)

Options

  • AEnforce stricter password policies.
  • BConduct regular security awareness training to educate users.
  • CCreate a Drive trust rule that blocks all external domains except for a pre-approved list of trusted
  • DDeploy advanced malware detection software on all user devices to scan and block malicious files.
  • EImplement two-factor authentication for all users

How the community answered

(70 responses)
  • A
    13% (9)
  • B
    80% (56)
  • D
    3% (2)
  • E
    4% (3)

Explanation

Two measures are needed that specifically address phishing via malicious external Drive files while still allowing legitimate external file access. Option B (security awareness training) is essential-educated users can recognize and avoid clicking suspicious links, directly reducing the attack surface. Option C (Drive trust rules allowing only pre-approved external domains) is a technical control that directly blocks access to files hosted on untrusted external Google Drives while permitting access to approved ones, precisely matching the requirement. Option A (stronger passwords) does not prevent users from clicking links to external files. Option D (endpoint malware detection) is less effective against cloud-hosted social engineering lures. Option E (2FA) is good security hygiene but does not prevent a user from willingly opening a malicious file link.

Topics

#Phishing Prevention#Google Drive Security#Security Awareness Training#Access Control Policies

Community Discussion

No community discussion yet for this question.

Full ASSOCIATE-GOOGLE-WORKSPACE-ADMINISTRATOR Practice