Associate Cloud Workspace Administrator · Free Practice Question Medium

Question 31

Your company's compliance officer needs to review email traffic to ensure that sensitive data isn't being transmitted outside the organization. In the Google Admin Console, they have found several instances of emails with attachments being sent to external domains. What steps should they take to further investigate and control this potential data leak?

  • A

    In the Admin console, go to Reports > Audit > Email, filter by "External recipients" and attachments, then use the Email Log Search to investigate the specific emails.

  • B

    Directly access each user's Gmail account who sent an external email with attachments and review their sent items.

  • C

    In the Admin console, use the Reports > Dashboard to set an alert for any email with an attachment that is sent outside the organization.

  • D

    In the Admin console, navigate to Apps > G Suite > Settings for Gmail > Advanced settings, and set up a content compliance rule to block emails with attachments to external domains.

Reveal correct answer

Correct answer: A

A. This choice is correct because it provides a step-by-step process to investigate email traffic with attachments being sent to external domains. By filtering the email logs for external recipients and attachments, the compliance officer can identify specific emails that may contain sensitive data and take appropriate action.

B. This choice is incorrect because directly accessing each user's Gmail account to review sent items is a time-consuming and inefficient method of investigating email traffic. It also raises privacy and security concerns as it involves accessing individual user accounts without proper authorization.

C. This choice is incorrect because setting an alert for any email with an attachment sent outside the organization through the Reports > Dashboard does not provide a targeted approach to investigate the specific emails identified by the compliance officer. It may result in an overload of alerts and make it difficult to focus on the actual data leak incidents.

D. This choice is incorrect because setting up a content compliance rule to block emails with attachments to external domains is a preventive measure rather than an investigative one. While this rule can help prevent future data leaks, it does not address the immediate need to investigate and control the potential data leak identified by the compliance officer.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need