Professional Google Workspace Administrator Exam QuestionsBrowse all questions from this exam

Professional Google Workspace Administrator Exam - Question 47


A disgruntled employee has left your company and deleted all their email messages and files in Google Drive. The security team is aware that some intellectual property may have surfaced on a public social media site. What is the first step to start an investigation into this leak?

Show Answer
Correct Answer: CD

The first step in starting an investigation into the potential leak is to preserve all relevant data to prevent any further deletion or modification. Instructing a Google Vault admin to create a matter and place all the user data on hold ensures that the data is retained and safeguarded, allowing a thorough investigation to be conducted. This process is crucial as it maintains the integrity of the data, which is necessary for analyzing the potential leak of intellectual property.

Discussion

7 comments
Sign in to comment
jaxclainOption: C
Dec 16, 2022

If it was me, I would just search for the users data then share it with the security team. If there is not any retention policy applied then yes a Hold but most companies have Vault retention to indefinite so there is no need to use a Hold but for this question (bad elaborated) then yes, the correct answer is C, because there is no mention of what retention policies they are using. https://support.google.com/vault/answer/7664657?hl=en#zippy=%2Cwhats-the-difference-between-a-hold-and-a-retention-rule

jitu028Option: C
Dec 1, 2022

correct answer - C

karl19Option: C
Jun 14, 2023

The first step to start an investigation into the potential intellectual property leak is: C. Instruct a Google Vault admin to create a matter and place all the user data on 'hold.' By creating a matter in Google Vault and placing the user's data on hold, you ensure that any relevant information related to the disgruntled employee's actions is preserved and cannot be modified or deleted. This allows the security team to analyze the data and investigate the potential leak.

sticklineOption: C
Jun 5, 2023

Agree with C

danaracenaOption: C
Jul 29, 2023

First proper step is to create the investigation. If the question was "There's an emergency and need to check information right away" could be D. But as a first adecuate, secure, and auditable step. Must create the hold first.

virat_kohliOption: C
Nov 8, 2023

C. Instruct a Google Vault admin to create a matter, and place all the user data on ‘hold.’

05fe736Option: C
Jul 3, 2024

As a "first step to start an investigation into this leak" it sounds like creating a matter and placing ALL the user data on hold would be correct.