PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Exam Questions
141 real PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER exam questions with expert-verified answers and explanations. Page 1 of 3.
- Question #1Google Security Operations Management
You are reviewing the security analyst team's playbook action process. Currently, security analysts navigate to the Playbooks tab in Google Security Operations (SecOps) for each al...
SecOps playbookspending actionsSOARalert triage - Question #2Google Security Operations Log Ingestion
You are managing a Google Security Operations (SecOps) implementation for a regional customer. Your customer informs you that logs are appearing in the platform after a consistent...
log parsingparser extensiontime zone correctionSecOps ingestion - Question #3Google Security Operations Investigation
Your organization uses Google Security Operations (SecOps). You need to identify the most commonly occurring processes and applications across your organization's large number of s...
UDM searchfield aggregationsprocess baseliningSIEM investigation - Question #4Security Command Center Configuration
You work for an organization that uses Security Command Center (SCC) with Event Threat Detection (ETD) enabled. You need to enable ETD detections for data exfiltration attempts fro...
Event Threat Detectiondata access audit logsdata exfiltrationCloud Logging cost optimization - Question #5Security Command Center and SecOps Integration
Your company uses Security Command Center (SCC) and Google Security Operations (SecOps). Last week, an attacker attempted to establish persistence by generating a key for an unused...
dormant service accountsSCC findingsautomated remediationservice account key management - Question #6Security Operations Architecture
Your company recently adopted Security Command Center (SCC) but is not using Google Security Operations (SecOps). Your organization has thousands of active projects. You need to de...
anomaly detection pipelineBigQuery log sinkCloud Run functionscustom detection without SecOps - Question #7Google Security Operations Management
Your organization is a Google Security Operations (SecOps) customer and monitors critical assets using a SIEM dashboard. You need to dynamically monitor the assets based on a speci...
SecOps dashboardcustom filtersasset tag monitoringSIEM dashboards - Question #8Security Command Center Configuration
A business unit in your organization plans to use Vertex AI to develop models within Google Cloud. The security team needs to implement detective and preventative guardrails to ens...
security posture managementorganization policiesSCC postureVertex AI security guardrails - Question #9Google Security Operations Log Ingestion
You are implementing Google Security Operations (SecOps) with multiple log sources. You want to closely monitor the health of the ingestion pipeline's forwarders and collection age...
ingestion pipeline monitoringmetric-absence alertCloud Monitoringsilent source detection - Question #10Google Security Operations Detection Rules
A Google Security Operations (SecOps) detection rule is generating frequent false positive alerts. The rule was designed to detect suspicious Cloud Storage enumeration by triggerin...
YARA-L rulesfalse positive reductiondetection tuningrule exclusion conditions - Question #11Google Security Operations Investigation
Your company uses Google Security Operations (SecOps) Enterprise and is ingesting various logs. You need to proactively identify potentially compromised user accounts. Specifically...
UEBA curated detectionsanomalous download detectionuser behavior baselinedata exfiltration detection - Question #12Security Command Center Investigation
Your organization uses Security Command Center (SCC) and relies on Compute Engine instances to run business-critical workloads. SCC has flagged a particular instance for exhibiting...
Event Threat Detectionnetwork threat analysisinstance compromiseoutbound connection investigation - Question #13Security Command Center and SecOps Integration
Your company wants to enhance its detection capabilities to prevent insider threat incidents. You need to be alerted when a privileged Google Group is modified to allow access to t...
insider threat detectionGoogle Workspace audit logsEvent Threat DetectionGoogle Groups access control - Question #14Investigating Threats
You are using Google Security Operations (SecOps) to investigate suspicious activity linked to a specific user. You want to identify all assets the user has interacted with over th...
UDM Searchentity relationshipsuser investigationasset discovery - Question #15Detecting Threats
Your organization recently acquired a Google Security Operations (SecOps) Enterprise Plus license. Your organization is already ingesting Cloud Audit Logs, firewall logs, proxy log...
curated detectionsIOC alertingthreat intelligence feedsdetection rule sets - Question #16Configuring the Google SecOps Environment
Your company has deployed two on-premises firewalls. You need to configure the firewalls to send logs to Google Security Operations (SecOps) using Syslog. What should you do?
log ingestionSyslog forwardingon-premises forwarderBindPlane agent - Question #17Configuring the Google SecOps Environment
You are a platform engineer at an organization that is migrating from a third-party SIEM product to Google Security Operations (SecOps). You previously manually exported context da...
user asset contextActive Directory enrichmentUEBAorganizational context ingestion - Question #18Detecting Threats
You manage a large fleet of Compute Engine instances. Security Health Analytics (SHA) has generated a CONFIDENTIAL_COMPUTING_DISABLED finding within Security Command Center (SCC)....
Security Command CenterSecurity Health Analyticsfinding remediationConfidential Computing - Question #19Responding to Threats
Your company's SOC recently responded to a ransomware incident that began with the execution of a malicious document. EDR tools contained the initial infection. However, multiple p...
SOAR playbookransomware containmentprivileged account responseautomated remediation - Question #20Managing SOC Operations
Your organization uses Google Security Operations (SecOps) for security analysis and investigation. Your organization has decided that all security cases related to Data Loss Preve...
case managementclose case dialogroot cause classificationDLP event types - Question #21Investigating Threats
You are investigating an alert in Google Security Operations (SecOps). You want to view previous enrichment attributes and relevant historical cases for an entity using the fewest...
Entity Explorerentity enrichmenthistorical casesinvestigation workflow - Question #22Investigating Threats
During a proactive threat hunting exercise, you discover that a critical production project has an external identity with a highly privileged IAM role. You suspect that this is par...
Cloud Audit LogsBigQuery log analysisexternal identityIAM investigation - Question #23Investigating Threats
You are a security analyst at an organization that uses Google Security Operations (SecOps). You notice suspicious login attempts on several user accounts. You need to determine wh...
Risk Analyticscoordinated attack detectionlogin anomalythreat correlation - Question #24Detecting Threats
Your Google Security Operations (SecOps) instance is generating a high volume of alerts related to an IP address that recently appeared in a threat intelligence feed. The IP addres...
alert fatiguedetection exceptionsasset group exclusionC2 detection tuning - Question #25Hunting for Threats
You are threat hunting for an advanced threat group known for targeted, novel attacks by deploying campaign-specific infrastructure. You want to develop detections based on the thr...
TTP-based detectionGoogle Threat IntelligenceAPT profilingbehavioral detection - Question #26Detecting Threats
You work for a large international company that has several Compute Engine instances running in production. You need to configure monitoring and alerting for Compute Engine instanc...
custom SHA moduleSecurity Health AnalyticsCompute Engine compliancePCI tagging - Question #27Managing SOC Operations
Your company's analyst team uses a playbook to make necessary changes to external systems that are integrated with the Google Security Operations (SecOps) platform. You need to aut...
SOAR automationCron Scheduled Connectorplaybook schedulingmaintenance overhead - Question #28Investigating Threats
You have discovered that a server that hosts an internal web application has been accidentally exposed to the internet for 48 hours. Logging is enabled on the server. You want to u...
UDM Searchprocess launch detectionexploitation indicatorsweb application security - Question #29Detecting Threats
You have been tasked with creating a YARA-L detection rule in Google Security Operations (SecOps). The rule should identify when an internal host initiates a network connection to...
YARA-L ruleApplied Threat Intelligence Fusion FeedAPT41 detectionindicator relationships - Question #30Detecting Threats
You are writing a detection rule in Google Security Operations (SecOps) SIEM that sends a risk score to the alert. You have access to Google Threat Intelligence (GTI) data through...
YARA-L outcomesrisk scoringGTI enrichmentUDM enrichment fields - Question #31Managing SOC Operations
You are a SOC manager, and your company recently migrated to Google Security Operations (SecOps). As the team grows, you want to monitor all audit logs related to data feeds in Goo...
SecOps audit logsdata feed monitoringSIEM log ingestionadministrative activity - Question #32Detecting Threats
Your company is taking a more proactive approach to security. You want to generate an alert when a binary hash first appears in your environment. What should you do?
first-seen hash detectionentity context graphYARA-L rulesbinary hash alerting - Question #33Managing SOC Operations
You are a SOC manager guiding an implementation of your existing incident response plan (IRP) into Google Security Operations (SecOps). You need to capture time duration data for e...
case stagescase duration trackingSOAR configurationincident response workflow - Question #34Threat Detection and Investigation
Your organization recently implemented Google Security Operations (SecOps) with Applied Threat Intelligence enabled. You were notified by the networking team about potentially anom...
threat huntingUDM searchIOC matchesdomain prevalence - Question #35Data Ingestion and Parsing
Your company recently started pulling JSON logs from a third-party system into Google Security Operations (SecOps). You noticed that some fields are missing, and you want to parse...
log parsingUDM fieldsparser extensionsno-code parsing - Question #36Security Operations Configuration
You are a security engineer at a managed security service provider (MSSP) that is onboarding to Google Security Operations (SecOps). You need to ensure that cases for each customer...
MSSPSOAR environmentscase managementmulti-tenancy - Question #37Threat Detection and Investigation
Your organization recently conducted a penetration test on their environment. You have been tasked with identifying a successful attack chain. The required log sources have been in...
C2 detectionnetwork prevalenceUDM searchthreat hunting - Question #38Incident Response and Case Management
Your organization is conducting a penetration test. The CISO has asked you to implement a real- time method to track cases that originate from the penetration test, and clearly dif...
case taggingpenetration testingincident trackingSecOps SOAR - Question #39Security Orchestration and Automation
You are tasked with building a workflow in Google Security Operations (SecOps) SOAR. The documentation you are using requires a logical split that has eight different possible path...
SOAR playbooksflow conditionsworkflow branchingautomation - Question #40Threat Detection and Investigation
You are a member of the incident response team working in a global enterprise. You need to identify all potential Google Threat Intelligence IOCs within your organization's data us...
IOC identificationGoogle Threat IntelligenceAlerts and IOCsthreat intelligence - Question #41Threat Detection and Investigation
You are a security operations engineer in an enterprise that uses Google Security Operations (SecOps). Your organization recently faced a cybersecurity breach. You need to increase...
curated detectionsthreat analyticsSecOps SIEMdetection rules - Question #42Threat Detection and Investigation
You are investigating whether an advanced persistent threat (APT) actor has operated in your organization's environment undetected. You have received threat intelligence that inclu...
APT detectionYARA-L multi-eventprocess correlationSysmon logs - Question #43Data Ingestion and Monitoring
You are a SOC manager at an organization that recently implemented Google Security Operations (SecOps). You need to monitor your organization's data ingestion health in Google SecO...
data ingestion healthBindplaneCloud Monitoringsilent source alerts - Question #44Security Operations Integration
Your organization has recently onboarded to Google Cloud with Security Command Center Enterprise (SCCE) and is now integrating it with your organization's SOC. You want to automate...
Security Command CenterSOAR integrationPub/SubCloud Run automation - Question #45Security Orchestration and Automation
You are creating a playbook for the SOC. The SOC requires that each Google Security Operations (SecOps) role sees different information for the alert that the playbook runs on. You...
playbook designrole-based viewsSOARalert presentation - Question #46Security Operations Integration
You are responsible for evaluating the level of effort required to integrate a new third-party endpoint detection tool with Google Security Operations (SecOps). Your organization's...
SecOps Marketplacedefault parsersthird-party integrationSOAR actions - Question #47Security Operations Management
You are the SOC manager at a large enterprise that uses Google Security Operations (SecOps). You need to create a report that shows the Return on Investment (ROI) attributed to ana...
SOAR reportsROI reportinganalyst benchmarkingSOC metrics - Question #48Identity and Access Management
Your company works with an external Managed Service Provider (MSP) that requires its users to have the ability to list findings from Security Command Center (SCC) using the Google...
workforce identity federationexternal IdPSCC accessIAM least privilege - Question #49Threat Detection and Investigation
You are conducting a proactive threat hunt in Google Security Operations (SecOps). You observe multiple login events with the same principal.user.userid field that originate from d...
threat huntingimpossible travelUDM searchaccount compromise - Question #50Data Ingestion and Parsing
You are using a Google-managed image on a Compute Engine instance in Google Cloud to run an application. You need to ingest the application's log output into Google Security Operat...
log ingestionOps AgentCloud LoggingGoogle SecOps