PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Exam Questions
141 real PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER exam questions with expert-verified answers and explanations. Page 2 of 3.
- Question #51Threat Detection and Investigation
You are a security analyst at a company that uses Google Security Operations (SecOps) Enterprise. Security Command Center Enterprise (SCCE), and Google Threat Intelligence (GTI). Y...
Applied Threat Intelligencefusion feedYARA-L rulesemerging threats - Question #52Security Orchestration and Automation
You are developing a playbook to respond to phishing reports from users at your company. You configured a UDM query action to identify all users who have connected to a malicious d...
playbook automationentity extractionUDM querypassword reset - Question #53Security Posture and Reporting
You are a security engineer at a financial technology company. You need to create a centralized dashboard to provide security posture visibility for your leadership team. The dashb...
SCC findingsBigQueryLooker Studiosecurity dashboard - Question #54Investigating threats and incidents
Your organization has mission-critical production Compute Engine VMS that you monitor daily. While performing a UDM search in Google Security Operations (SecOps), you discover seve...
IOC reputation lookupUDM searchAlerts & IOCs pagenetwork connection investigation - Question #55Configuring detections
You are responsible for identifying suspicious activity and security events in your organization's environment. You discover that some detection rules are being triggered for inter...
YARA-L rulesCIDR filteringfalse positive reductionnet.ip_in_range_cidr - Question #56Managing data ingestion and parsing
Your team has onboarded a new log source from a third-party DNS filtering solution. After ingestion, you observe that key UDM fields such as network.dns.questions.name and metadata...
custom parser extensionUDM field mappingDNS log ingestionthird-party log source - Question #57Configuring detections
You are ingesting and parsing logs from an SSO provider and an on-premises appliance using Google Security Operations (SecOps). Users are tagged as "restricted" by an internal proc...
custom enrichment feedmulti-event detection ruleuser restriction TTLSSO log correlation - Question #58Responding to threats and incidents
You are receiving security alerts from multiple connectors in your Google Security Operations (SecOps) instance. You need to identify which IP address entities are internal to your...
SOAR playbook enrichmentIP entity classificationinternal network labelingalert triage - Question #59Investigating threats and incidents
You have identified a common malware variant on a potentially infected computer. You need to find reliable IOCs and malware behaviors as quickly as possible to confirm whether the...
Google Threat Intelligencemalware hash lookupIOC researchindicator analysis - Question #60Configuring the environment
Your Google Security Operations (SecOps) SOAR integration with Security Command Center (SCC) uses a service account that currently has read access to the findings at the organizati...
IAM least privilegeSecurity Command Centerservice account permissionsfindings editor role - Question #61Configuring detections
You need to augment your organization's existing Security Command Center (SCC) implementation with additional detectors. You have a list of known IOCs and would like to include ext...
Event Threat Detectioncustom moduleIOC-based detectionSecurity Command Center - Question #62Monitoring and optimizing operations
Your organization recently implemented Google Security Operations (SecOps). You need to create a solution that allows the security team to monitor data ingestion into Google SecOps...
data ingestion monitoringSecOps SIEM dashboardsalerting policycost optimization - Question #63Configuring the environment
Your company's Google Security Operations (SecOps) instance has three roles: Tier 1, Tier 2, and Tier 3. Currently, analysts in all tiers can access all cases in Google SecOps. You...
Cross Environment Policycase access controlSOC role segmentationSOAR case management - Question #64Responding to threats and incidents
You are the lead engineer on your organization's incident response team. You are running CrowdStrike Falcon and SentinelOne to protect the Windows devices in different regions of y...
ransomware response automationEDR integrationSOAR playbookendpoint containment - Question #65Managing data ingestion and parsing
You need to ingest audit logs from your organization's entire Google Cloud environment into Google Security Operations (SecOps). This process must include Cloud NAT logs for worklo...
aggregated log sinkCloud NAT logsfolder-level ingestionGoogle Cloud audit logs - Question #66Responding to threats and incidents
You work for an organization that operates an ecommerce platform. You have identified a remote shell on your company's web host. The existing incident response playbook is outdated...
Gemini playbook generationincident response playbookremote shell incidentSOAR automation - Question #67Investigating threats and incidents
You recently joined a company that uses Google Security Operations (SecOps) with Applied Threat Intelligence enabled. You have alert fatigue from a recent red team exercise, and yo...
IOC mutingApplied Threat Intelligencealert fatigue reductionred team noise filtering - Question #68Configuring the environment
You are managing the integration of Security Command Center (SCC) with downstream tooling. You need to pull security findings from SCC and import those findings as part of Google S...
SCC integrationSecOps Marketplacefindings importSOAR connector configuration - Question #69Configuring the environment
You are configuring a new integration in Google Security Operations (SecOps) to perform enrichment actions in playbooks. This enrichment technology is located in a private data cen...
remote agentprivate data center connectivitySOAR integrationinbound-restricted network - Question #70Managing data ingestion and parsing
You use Google Security Operations (SecOps) curated detections and YARA-L rules to detect suspicious activity on Windows endpoints. Your source telemetry uses EDR and Windows Event...
Windows SysmonUDM field coverageprincipal.user.useridlog source selection - Question #71Configuring detections
You are an incident response engineer at an organization that uses Google Security Operations (SecOps). You recently started monitoring IOCs in Applied Threat Intelligence using YA...
IC-Score thresholdYARA-L tuningApplied Threat Intelligencefalse positive reduction - Question #72Monitoring and optimizing operations
You scheduled a Google Security Operations (SecOps) report to export results to a BigQuery dataset in your Google Cloud project. The report executes successfully in Google SecOps,...
BigQuery exportservice account IAMroles/bigquery.dataEditorreport pipeline troubleshooting - Question #73Managing data ingestion and parsing
Your organization's Google Security Operations (SecOps) tenant is ingesting a vendor's firewall logs in its default JSON format using the Google-provided parser for that log. The v...
parser extensionUDM field remappingfirewall log updateminimal change management - Question #74Identity and Access Management
Your company uses Cloud Identity to manage employee identities and has Google Security Operations (SecOps) linked to your Google Cloud project. You have assigned the roles/chronicl...
organization policyallowedPolicyMemberDomainsCloud Identityexternal accounts - Question #75Security Orchestration Automation and Response
Your company's SOC analysts frequently submit manual change requests to a system administrator to make changes to the firewall rules on a specific router. You have the integration...
SOAR playbookmanual approvalfirewall integrationworkflow design - Question #76Threat Detection and Investigation
You are conducting proactive threat hunting in your company's Google Cloud environment. You suspect that an attacker compromised a developer's credentials and is attempting to move...
threat huntingGKE lateral movementSecurity Command CenterIOC identification - Question #77Incident Response and Case Management
During a high-priority phishing incident at your company, Google Security Operations (SecOps) created and assigned the case to a Tier 1 analyst. The analyst added email headers and...
case managementSLA escalationphishing responseSOAR notification - Question #78Security Orchestration Automation and Response
You are writing a Google Security Operations (SecOps) SOAR playbook that uses the VirusTotal v3 integration to look up a URL that was reported by a threat hunter in an email. You n...
VirusTotal integrationSOAR playbookURL enrichmentconditional logic - Question #79Threat Hunting and Detection
You are using Google Security Operations (SecOps) to hunt for signs of lateral movement through Remote Desktop Protocol (RDP) in your organization. You suspect that a compromised a...
UDM searchRDP detectionlateral movementthreat hunting - Question #80Data Access Controls and Role-Based Access
You are configuring role-based data access controls for two groups of users in Google Security Operations (SecOps). Group A requires access to all data, and Group B requires access...
data access scopeRBACnamespace restrictionsGoogle SecOps SIEM - Question #81Log Ingestion and Parsing
You are responsible for developing and configuring data ingestion in Google Security Operations (SecOps) for your organization. Your organization is using a prebuilt parser to pars...
log parsingparser extensionUDM field mappingdata ingestion - Question #82Compliance Monitoring and Reporting
Your company's risk management and compliance team requires regular reporting on compliance with industry standard control frameworks for a regulated business unit that continuousl...
compliance reportingsecurity postureSecurity Command Centercontrol frameworks - Question #83Threat Intelligence and Detection Engineering
Your team hunts for threats in a large multinational corporation. You have subscriptions to threat intelligence feeds from third-party sources. You want to implement a solution to...
YARA-L rulesthreat intelligence feedsDNS monitoringIOC matching - Question #84Threat Detection - Curated Detections
Your company is adopting a multi-cloud environment. You need to configure comprehensive monitoring of threats using Google Security Operations (SecOps). You want to start identifyi...
curated detectionsmulti-cloud monitoringGoogle SecOpsthreat detection - Question #85Threat Hunting and Detection Engineering
You have a close relationship with a vendor who reveals to you privately that they have discovered a vulnerability in their web application that can be exploited in an XSS attack....
XSS detectionYARA-L rulesproactive threat huntingpre-CVE detection - Question #86Threat Intelligence Integration
You have identified a new threat actor group that has several IOCs in Google Threat Intelligence. You want to use some of these IOCs in several detection rules in Google Security O...
IOC managementreference listsYARA-L detectionGoogle Threat Intelligence - Question #87Detection Engineering and Rule Tuning
You have noticed that a Google Security Operations (SecOps) detection rule that detects excessive network connections is triggering too frequently and creating too many false posit...
YARA-L tuningthreshold configurationfalse positive reductiondetection rules - Question #88Threat Investigation and Incident Response
You are a SOC analyst at an organization that uses Google Security Operations (SecOps). You are investigating suspicious activity in your organization's environment. Alerts in Goog...
YARA-L correlationPowerShell detectionmulti-system investigationscope of compromise - Question #89Compliance Remediation
Your company requires PCI DSS v4.0 compliance for its cardholder data environment (CDE) in Google Cloud. You use a Security Command Center (SCC) security posture deployment based o...
PCI DSS complianceSecurity Command Center postureexternal IP remediationCompute Engine - Question #90Threat Intelligence Management
You are responsible for managing threat intelligence and IOC lists in your organization. You have compiled a list of IOCs from recent incidents. You want to quickly and efficiently...
IOC sharingthreat intelligence collectionsSecOps liststeam collaboration - Question #91Log Ingestion and Prioritization
You are planning log onboarding for a Google Security Operations (SecOps) SIEM deployment in a cloud-heavy enterprise environment. The detection engineering team is requesting log...
log prioritizationEDR logsidentity behaviorlateral movement visibility - Question #92Log Ingestion and Integration
You are responsible for selecting and prioritizing potential sources of data to integrate with Google Security Operations (SecOps). Your company has recently started using several...
log ingestionSCC integrationcurated detectionsGoogle Cloud services - Question #93Security Operations Architecture and Integration
You are developing a security strategy for your organization. You are planning to use Google Security Operations (SecOps) and Google Threat Intelligence (GTI). You need to enhance...
GTI integrationSOAR enrichmentmulti-cloud securitysecurity operations architecture - Question #94SOAR Automation and Case Management
Your organization is a Google Security Operations (SecOps) customer. The compliance team requires a weekly export of case resolutions and SLA metrics of high and critical severity...
SOAR reportingSLA metricsscheduled jobsCSV export - Question #95Security Investigation and Analysis
You are reviewing the results of a UDM search in Google Security Operations (SecOps). The UDM fields shown in the default view are not relevant to your search. You want to be able...
UDM searchcolumns featureevent analysisSIEM UI - Question #96Detection Engineering and Tuning
Your organization uses the curated detection rule set in Google Security Operations (SecOps) for high priority network indicators. You are finding a vast number of false positives...
rule exclusionsfalse positive tuningcurated detectionsUDM field mapping - Question #97Log Ingestion and Data Management
Your third-party application data is published in a Pub/Sub topic located in a separate Google Cloud project from your Google Security Operations (SecOps) instance. Your attempts t...
Pub/Sub ingestionCloud Runcross-project integrationChronicle API - Question #98SOAR Playbook Development
Your organization requires the SOC director to be notified by email of escalated incidents and their results before a case is closed. You need to create a process that automaticall...
playbook conditionscase closureincident escalationemail notification - Question #99Security Investigation and Threat Hunting
You are a security analyst at an organization that uses Google Security Operations (SecOps). You have identified a new IP address that is known to be used by a malicious threat act...
UDM searchIOC investigationnormalized logsthreat hunting - Question #100SOAR Playbook Development
You have been tasked with developing a new response process in a playbook to contain an endpoint. The new process should take the following actions: - Send an email to users who do...
external approval workflowGmail integrationplaybook approval linkscontainment automation