PCOA Sample Questions & Answers
Running day-to-day tasks from the Admin console ties with understanding ChromeOS best practices and hardware selection for the top weighting, alongside deploying certificates and security fundamentals, configuring policies correctly, and identity-feature setup.
Launch the full PCOA simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Perform actions from the Admin console · Remote troubleshooting and diagnostics
An IT administrator receives a support ticket stating that a user's ChromeOS device is running slowly and frequently shows 'low disk space' warnings. The user primarily works with cloud-based applications and does not intentionally download large files. From the Google Admin console, which remote command would be most useful for initial diagnosis of the problem?
Show answer & explanation
Correct answer: D
Requesting device logs is the most effective first step for diagnosis. The logs, specifically the
chrome_user_log, contain detailed information about system performance, disk usage statistics, and potential errors from applications or extensions that might be consuming excessive space (e.g., through caching). This allows the admin to identify the root cause without wiping the user's profile. - Question 2Beginner
Perform actions from the Admin console · Deprovisioning devices
True or False: When a ChromeOS device is deprovisioned from the Google Admin console, the associated Chrome Enterprise Upgrade license is immediately returned to the license pool and can be used for another device.
Show answer & explanation
Correct answer: A
This is true. Deprovisioning a device removes it from management and returns its Chrome Enterprise Upgrade (or Education/Nonprofit Upgrade) license to the available pool. This allows the license to be reused for a new or different device. This is the standard procedure for retiring or replacing hardware.
- Question 3Intermediate
Understand ChromeOS tenets · Hardware capabilities of ChromeOS Flex
A university wants to repurpose a lab of older Windows laptops for student use by installing ChromeOS Flex. The university's security policy requires that all managed devices use Verified Boot to ensure the OS has not been tampered with. What is the status of Verified Boot on these ChromeOS Flex devices?
Show answer & explanation
Correct answer: B
While ChromeOS Flex benefits from many ChromeOS security features like sandboxing and read-only OS, it cannot implement the full Verified Boot process. This is because Verified Boot on native ChromeOS devices relies on firmware and the Google Security Chip (or equivalent TPM integration), which are not present on the diverse range of third-party hardware that Flex runs on. The bootloader of the original device remains unlocked.
- Question 4Beginner
Configure ChromeOS policies · Understanding policy inheritance
A new ChromeOS administrator is reviewing the organizational unit (OU) structure. They notice that the 'Block camera access' policy is set to 'Block' at the root OU. However, users in the 'Marketing' child OU report that they are able to use their webcams in video conferences. What is the most likely reason for this discrepancy?
graph TD RootOU["Root OU (Block Camera: true)"] --> SalesOU["Sales OU (Inherited)"] RootOU --> MarketingOU["Marketing OU (Block Camera: false)"] RootOU --> EngineeringOU["Engineering OU (Inherited)"]Show answer & explanation
Correct answer: B
Policies in the Google Admin console are inherited from parent OUs to child OUs. However, a policy set on a child OU will always override the setting inherited from its parent. In this case, the only way for Marketing users to have camera access is if the policy was specifically changed from 'Inherit' to 'Allow' (or the equivalent setting) directly on their OU.
- Question 5Intermediate
Perform actions from the Admin console · Creating Zero-Touch Enrollment tokens
A company is preparing for Zero-Touch Enrollment (ZTE). The administrator has generated a pre-provisioning token from the Google Admin console. What is the next critical step that must be taken to ensure devices automatically enroll upon their first boot and connection to the internet?
Show answer & explanation
Correct answer: B
Zero-Touch Enrollment is a partnership between the customer, Google, and the device reseller/OEM. The administrator generates the token, which acts as an authorization key, and provides it to the partner. The partner then uploads a list of the device hardware IDs to Google's database and associates them with the customer's domain using the token. This flags the devices for automatic enrollment.
- Question 6Advanced
Configure ChromeOS policies · Applying multiple policies for a complex use case
Case Study:
A global retail company, 'StyleStream', is overhauling its in-store technology. They plan to use ChromeOS devices for two distinct purposes: as interactive customer kiosks and as employee-facing point-of-sale (POS) systems. The company has strict security and operational requirements for both use cases.
Kiosk Requirements: The customer kiosks must boot directly into a specific web application that showcases the company's catalog. Customers should not be able to navigate away from this application or access any system settings. All browsing data must be wiped after 15 minutes of inactivity to protect customer privacy.
POS Requirements: The POS systems must run a dedicated Android POS application. Employees will log into the device using their corporate Google accounts to access the application. For security, these devices must be prevented from installing any other applications, and USB storage access must be blocked. All POS devices need to connect to a specific WPA2-Enterprise Wi-Fi network using EAP-TLS authentication.
Which combination of policies and configurations in the Google Admin console will meet all of StyleStream's requirements?
Show answer & explanation
Correct answer: B
This option correctly addresses all requirements. Single-App Kiosk mode locks the kiosk devices to the specified web app. The inactivity timeout handles data wiping. For the POS devices, force-installing the Android app while blocking all others prevents unauthorized installations. Blocking external storage and configuring the specific WPA2-Enterprise network with a device certificate (implied by EAP-TLS) meets the security and connectivity needs.
- Question 7Intermediate
Perform actions from the Admin console · Creating a custom admin role
An administrator needs to delegate limited permissions to the help desk team. The team needs the ability to perform basic troubleshooting actions like rebooting devices, clearing user profiles, and capturing logs, but they should NOT be able to wipe devices or change any device policies. What is the best practice to achieve this?
Show answer & explanation
Correct answer: B
This follows the principle of least privilege. Creating a custom admin role allows the administrator to grant only the specific permissions required for the help desk's job function (e.g., Reboot, Clear Profile, Get Logs) without granting more powerful and potentially destructive permissions like Wipe Device (Reset) or the ability to modify policies. Built-in roles are often too broad for such specific needs.
- Question 8Advanced
Identity Management · Context-Aware Access
A company is using Google as its Identity Provider. For enhanced security, they want to ensure that users can only log into their managed ChromeOS devices from the corporate office network. Attempts to log in from any other network should be blocked. Which feature should be configured to enforce this policy?
Show answer & explanation
Correct answer: C
Context-Aware Access is a Google Workspace feature that allows administrators to create granular access control policies for apps based on user identity and context, such as location (IP address), device security status, and OS. To meet this requirement, an administrator would create an access level based on the corporate IP address range and then apply a policy that requires this access level for logging into ChromeOS.
- Question 9IntermediateSelect 2
Configure ChromeOS policies · Controlling Android and Linux environments
A developer at your company reports that they are unable to test their new Android application on their managed ChromeOS device. When they try to enable Linux or install the APK, they receive a message that the action is blocked by the administrator. Which TWO policies in the Google Admin console are most likely preventing this? (Select TWO)
Show answer & explanation
Correct answers: A, E
This policy directly controls whether users can enable and use the Linux development environment (Crostini) on their ChromeOS devices. If disallowed, the option will be blocked.
Sideloading is the process of installing an Android application from an APK file instead of the Google Play Store. This is essential for developers testing their own apps. If this policy is disallowed, the developer will be blocked from installing their test APK.
- Question 10Beginner
Perform actions from the Admin console · Troubleshooting customer concerns
The command
chrome://policyis used to ______.Show answer & explanation
Correct answer: B
Navigating to
chrome://policyin the Chrome browser on a device provides a detailed view of all policies currently in effect for that session. It shows the policy name, its source (e.g., from the cloud), its value, and whether it applies at the machine or user level. It is an essential local troubleshooting tool for verifying policy application.
Ready for the real thing?
The full PCOA simulator has every exam-style question, timed mode, and instant scoring.