▸case-05 Our compliance team wants to prevent sensitive financial data like credit card numbers and Social Security numbers from being shared externally via Google Drive and Docs. How do we configure Data Loss Prevention (DLP) rules in Google Workspace Admin Console to scan files and block external sharing of sensitive data? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 I am looking for the Enhanced Safe Browsing setting in Google Admin Console to enable real-time URL protection for Gmail. I assumed it was under Apps > Google Workspace > Gmail > Safety along with the other safety settings. Where is this setting located in the Google Admin Console menu tree? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-02 I need an operational checklist for configuring advanced threat protection in Google Admin Console for Gmail. Please walk me through the complete setup process covering anti-phishing controls, pre-delivery scanning settings, attachment restrictions, and the authentication protocols required to ensure our domain is fully secured against impersonation. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 We need to set up SAML 2.0 single sign-on (SSO) in Google Workspace using Microsoft Entra ID as our primary identity provider. Please provide the step-by-step procedure in Google Admin Console to configure third-party SSO, upload the IdP certificate, and configure the SSO profile for users. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 We are upgrading our organization's email defense posture in Google Workspace. Please outline a detailed configuration plan that details how to enable safety controls for lookalike domains and employee impersonation, set up link and file protections, enroll critical users into high-security account programs, and validate our SPF/DKIM/DMARC setup. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 We completed configuring Gmail Safety and Enhanced Safe Browsing. What specific validation steps should we execute to confirm that our spoofing and URL protection settings are operating correctly? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 When enabling inbound domain spoofing protection in Gmail Safety for messages that mimic our official company domain, what enforcement actions are recommended for detected spoofed messages? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 We are drafting our SPF DNS record for Google Workspace outbound mail delivery. A developer suggested using `v=spf1 include:_spf.google.com +all` to make sure all Google servers pass without restriction. What exact SPF record mechanism string should be published in DNS for Google Workspace email sending? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 Our helpdesk reports a 5-10 second delay in email delivery after enabling Enhanced pre-delivery message scanning. Is this delay normal, and what security benefit does this setting provide? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 Attackers are sending emails using the CEO's display name from generic non-company email accounts to scam finance staff. What feature inside Gmail Safety specifically addresses executive name impersonation? | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-08 We are setting up DMARC for our domain in Google Workspace for the first time. Our security lead suggests starting immediately with `p=reject` to block all unauthorized mail right away. How should the initial DMARC TXT record be configured when first deploying email authentication? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 Our company is hardening our Google Workspace email security following a recent phishing simulation. Can you provide a comprehensive step-by-step deployment guide for configuring our Gmail environment to block domain spoofing, scan suspicious attachments and links, protect high-privilege executive accounts, and properly set up outbound email authentication? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 We noticed phishing emails containing malicious links hidden inside image attachments or using short links getting past basic filters. Which specific pre-delivery scanning features in Gmail Safety need to be enabled to catch these evasion techniques? | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-06 We have an internal application server that needs to send outbound transactional emails using Google Workspace as an SMTP relay. How do we set up the SMTP relay service setting in Google Admin Console, including allowed IP addresses and authentication requirements? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-18 We are preparing to configure advanced phishing and malware safety controls across our Google Workspace organization. What Google Workspace licensing tier and administrator privileges are required to configure these Gmail Safety settings? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 After enrolling our finance leadership in the Advanced Protection Program, an executive complained that a third-party reporting tool lost access to their Google Drive files. Is this expected behavior under APP, and how does APP treat third-party app access? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 We are enrolling our executive team into Google's Advanced Protection Program (APP). An IT admin proposed using SMS 2FA codes for these accounts so executives don't lose physical keys. What authentication factor is required for accounts enrolled in APP? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 We want to tighten attachment controls in Gmail Safety to prevent zero-day ransomware delivered via scripts or unusual file extensions. What specific options exist under Attachment protection in Gmail Safety to handle script files and non-standard file types? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 An admin wants to turn off all encrypted attachment protection in Gmail Safety because vendor password-protected zip files were being flagged. What is the recommended configuration approach for handling encrypted attachments from untrusted senders while allowing known business partners? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 Where in the Google Admin Console do administrators generate the DKIM domain key and enable DKIM email signing for outbound domain messages? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 We configured SPF, DKIM, and DMARC DNS records for our domain. How do we validate that our outbound email flow is properly authenticated according to email security standards? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-22 What added file security benefits does Google's Advanced Protection Program provide for Google Drive and Gmail downloads beyond standard attachment scanning? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |