PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Exam Questions
141 real PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER exam questions with expert-verified answers and explanations. Page 3 of 3.
- Question #101Log Ingestion and Data Management
Your organization plans to ingest logs from an on-premises MySQL database as a new log source into its Google Security Operations (SecOps) instance. You need to create a solution t...
SecOps forwarderon-premises ingestionlog collectionMySQL logs - Question #102Threat Intelligence
Your organization is a Google Security Operations (SecOps) customer. You use Google Threat Intelligence to identify cyber threats within your organization's threat profile. You bel...
Google Threat IntelligenceIOC extractionReports and Analysisthreat actor profiling - Question #103Detection Engineering
You are implementing Google Security Operations (SecOps) for your organization. Your organization has their own threat intelligence feed that has been ingested to Google SecOps by...
YARA-L rulesentity graphMISP integrationdomain IOC filtering - Question #104Log Ingestion and Data Management
You are using Google Security Operations (SecOps) to identify and report a repetitive sequence of brute force SSH login attempts on a Compute Engine image that did not result in a...
VPC Flow LogsSSH brute forceingestion quotalog source selection - Question #105SOAR Automation and Case Management
You are a SOC analyst working a case in Google Security Operations (SecOps). The case contains a file hash that your playbooks have automatically enriched with VirusTotal context a...
file hash investigationUDM searchplaybook automationSOAR case enrichment - Question #106Platform Operations and Monitoring
You are responsible for monitoring the ingestion of critical Windows server logs to Google Security Operations (SecOps) by using the Bindplane agent. You want to receive an immedia...
ingestion health monitoringCloud MonitoringBindplane agentalert policy - Question #107Security Investigation and Threat Hunting
You observe several distinct, low-severity suspicious activities associated with a single internal server. You determine that no single event is a high-confidence IOC. You need to...
watchlistentity monitoringlow-severity alertsthreat hunting - Question #108SOAR Playbook Development
Your organization recently adopted Google Security Operations (SecOps), and has configured ingestion, parsing and rules for their log sources. The security operations team is curre...
playbook designentity enrichmentcase managementcatch-all playbook - Question #109SOC Operations and Reporting
You were recently hired as a SOC manager at an organization with an existing Google Security Operations (SecOps) implementation. You need to understand the current performance by c...
MTTRSOC metricsdashboard widgetscase performance - Question #110Security Investigation and Threat Hunting
You received an IOC from your threat intelligence feed that is identified as a suspicious domain used for command and control (C2). You want to use Google Security Operations (SecO...
UDM searchdomain IOCC2 investigationDNS fields - Question #111Security Investigation and Threat Hunting
You are a senior SOC analyst in your organization. You are receiving alerts of traffic to a command and control (C2) IP address. You want to use Google Security Operations (SecOps)...
C2 investigationUDM src.ip target.ipnetwork traffic analysisIP threat hunting - Question #112SOAR Playbook Development
You are working with your company's analyst team to automate the investigation of phishing alerts ingested directly into Google Security Operations (SecOps) SOAR from an email inbo...
playbook SIEM integrationphishing investigationcase enrichmentno-code automation - Question #113Detection Engineering and Tuning
Your Google Security Operations (SecOps) instance is generating alerts for unusual login times from multiple user accounts. Your SOC analysts are reporting a high number of the ale...
detection tuningservice account exclusionprincipal.user.typefalse positive reduction - Question #114Detection Engineering and Threat Intelligence
You are building a detection rule in Google Security Operations (SecOps) to alert on requests to potentially malicious domains. You are planning to use the logs from your network d...
detection rulesthreat intelligence platformNDR logslog ingestion - Question #115Security Operations Configuration and Administration
You are helping a new Google Security Operations (SecOps) customer configure access for their SOC team. The Google SecOps administrators currently have access to the instance. The...
Google SecOps IAMidentity providerchronicle.viewer roleSOAR permissions - Question #116Incident Response and Investigation
You are a security analyst at an organization that uses Google Security Operations (SecOps). Google SecOps triggered a medium severity alert of Unusual Cloud Storage Access - High...
incident investigationuser timelineCloud Storagealert triage - Question #117Security Monitoring and Threat Detection
Your company uses Google-managed images on Compute Engine VM instances extensively and has deployed Security Command Center Enterprise (SCCE) at the organization level Due to a rec...
VM ManagerSecurity Command Centervulnerability managementCompute Engine - Question #118Security Monitoring and Threat Detection
You work at a financial services company. You need to detect in near real-time when a Cloud Run functions service agent modifies the IAM policy of an Artifact Registry repository....
Event Threat DetectionSecurity Command CenterIAM policy changesArtifact Registry - Question #119Security Operations Configuration and Administration
Your Google Security Operations (SecOps) case queue contains a case with IP address entities. You need to determine whether the entities are internal or external assets and ensure...
SOAR configurationIP classificationenvironment networksasset enrichment - Question #120Security Orchestration and Automation
Your organization has a standard set of Google Security Operations (SecOps) playbooks that are applied to alerts in different circumstances. One playbook uses an "All" trigger that...
SOAR playbooksplaybook prioritytrigger configurationalert routing - Question #121Log Ingestion and Data Management
You work for a telecommunications company that wants to monitor their multi-region 5G network logs in Google Security Operations (SecOps). The logs are currently only available on-...
log ingestionfeed managementingestion labelsnamespace configuration - Question #122Detection Engineering and Threat Intelligence
You are responsible for identifying suspicious activity and security events at your organization. You have been asked to search in Google Security Operations (SecOps) for network t...
YARA-LUDM searchnetwork traffic analysisbackdoor detection - Question #123Incident Response and Investigation
You are an incident responder at your organization using Google Security Operations (SecOps) for monitonng and investigation. You discover that a critical production server, which...
incident containmentEDR integrationforensic preservationthreat response - Question #124Detection Engineering and Threat Intelligence
Your organization uses Google Security Operations (SecOps). You discover frequent file downloads from a shared workspace within a short time window. You need to configure a rule in...
YARA-L rulesfrequency-based detectionrisk scoringbehavioral detection - Question #125Detection Engineering and Threat Intelligence
You are implementing Google Security Operations (SecOps) at your organization. You discover that the current detection rules are too noisy. Due to the high volume of alerts, some t...
false positive reductionhigh-value assetsCMDB integrationdetection tuning - Question #126Detection Engineering and Threat Intelligence
You are developing a new detection rule in Google Security Operations (SecOps). You are defining the YARA-L logic that includes complex event, match, and condition sections. You ne...
YARA-L developmentrule testingUDM searchdetection rule lifecycle - Question #127Security Operations Configuration and Administration
Your organization has recently acquired Company A, which has its own SOC and security tooling. You have already configured ingestion of Company A's security telemetry and migrated...
SOAR environmentsmulti-tenancySOC rolesaccess control - Question #128Threat Intelligence and Analysis
You have identified and isolated a new malware sample installed by an advanced threat group that you believe was developed specifically for an attack against your organization. You...
malware analysisprivate scanningthreat intelligenceIOC extraction - Question #129Security Operations Configuration and Administration
Your organization uses Cloud Identity as their identity provider (IdP) and is a Google Security Operations (SecOps) customer You need to grant a group of users access to the Google...
IAM roleschronicle.ViewerGoogle GroupsCloud Identity - Question #130Threat Hunting and Investigation
Your team is responsible for cybersecurity for a large multinational corporation. You have been tasked with identifying unknown command and control nodes (C2s) that are potentially...
C2 detectionYARA-L rulesretrohuntthreat hunting - Question #131Incident Response and Investigation
You received an alert from Container Threat Detection that an added binary has been executed in a business critical workload. You need to investigate and respond to this incident....
Container Threat Detectionincident responseSecurity Command Centercontainer security - Question #132Incident Response and Investigation
An organization detects a successful login to a Google Cloud IAM user from an unfamiliar country, followed by the creation of multiple new service account keys within minutes. No m...
account compromiseincident responsecredential revocationIAM security - Question #133Security Monitoring and Threat Detection
Which Google Cloud log source is MOST critical for detecting unauthorized IAM role changes?
Cloud Audit LogsAdmin Activity logsIAM monitoringlog sources - Question #134Threat Detection and Monitoring
A security analyst wants to detect lateral movement between Compute Engine instances using valid credentials. Which data source is MOST useful?
VPC Flow Logslateral movement detectionnetwork traffic analysisCompute Engine security - Question #135Incident Investigation and Response
A SOC team notices repeated outbound HTTPS connections from a Compute Engine instance to an external IP every 60 seconds. CPU usage is normal and no malware signatures trigger. Wha...
beaconing detectionC2 traffic analysisincident investigationprocess attribution - Question #136Threat Detection and Monitoring
Which approach BEST improves detection of compromised service accounts in Google Cloud?
service account monitoringbehavioral baselininganomaly detectionIAM security - Question #137Incident Analysis and Security Control Assessment
A phishing campaign successfully convinces users to grant OAuth permissions to a malicious third-party application. Which control failure MOST likely allowed this?
OAuth consent phishingthird-party app riskidentity security controlscontrol failure analysis - Question #138Identity and Access Management
Which Google Cloud security feature MOST helps enforce the principle of least privilege at scale?
least privilegeIAM predefined rolesconditional IAM policiesaccess control at scale - Question #139Cloud Forensics and Incident Response
A workload is created and terminated within five minutes and later linked to cryptomining activity. What MOST complicates the investigation?
ephemeral resourcescloud forensicscryptomining detectionincident investigation complexity - Question #140Security Operations and SIEM Management
A SOC uses Chronicle SIEM and wants to reduce alert fatigue without lowering detection coverage. What is the BEST strategy?
alert fatigueChronicle SIEMrisk-based scoringentity correlation - Question #141Incident Response and Post-Incident Review
After resolving a confirmed security incident in Google Cloud, what action provides the GREATEST long-term security improvement?
post-incident reviewlessons learneddetection tuningincident response lifecycle