Associate Cloud Workspace Administrator · Free Practice Question Medium
Question 16
Recently, the security team identified a third-party application, “DocAnalyzer”, that employees have been using to analyze document contents. This application has access to the Google Drive files of many employees. However, upon a detailed security review, concerns arise about the way the app handles and stores data externally. How would you proceed to protect organizational data?
-
A
Use the Google Workspace Admin Console to revoke “DocAnalyzer” access, remove it from connected applications, and notify affected users.
-
B
Archive all sensitive documents in Google Drive to prevent further access by “DocAnalyzer.”
-
C
Directly contact the developer of “DocAnalyzer” and ask them to delete any stored organizational data.
-
D
Send an email to the users and ask them to not upload sensitive documents to “DocAnalyzer.”
Reveal correct answer
Correct answer: A
A. Using the Google Workspace Admin Console to revoke access to the third-party application, "DocAnalyzer," is the most immediate and effective way to protect organizational data. By removing the app from connected applications and notifying affected users, you can prevent any further unauthorized access to sensitive information stored in Google Drive.
B. Archiving sensitive documents in Google Drive to prevent further access by "DocAnalyzer" may not address the root issue of unauthorized access by the third-party application. While archiving documents may limit access to certain files, it is essential to revoke access to the application itself through the Admin Console to ensure the protection of all organizational data.
C. Directly contacting the developer of "DocAnalyzer" and asking them to delete any stored organizational data may not guarantee the complete protection of sensitive information. It is important to take immediate action within the organization's control, such as revoking access through the Admin Console, to prevent any further unauthorized access to data.
D. Sending an email to users and asking them not to upload sensitive documents to "DocAnalyzer" may not be sufficient to protect organizational data. Users may still inadvertently upload sensitive information, and relying on user compliance alone may not be the most secure approach to addressing the security concerns raised by the third-party application.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
