Browse all practice questions for the Google SecOps Professional Engineer Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Google SecOps Professional Engineer Practice Test course image
All questions

These questions are part of the practice quiz. Start practicing

  • UDM search shows outbound connections from a production VM to an unfamiliar external IP over the last 48 hours. What is the quickest way to gather context and assess the IP's reputation?
  • When a medium severity alert indicates unusual cloud storage access by a senior developer outside working hours, what should you do first?
  • In a ransomware incident, which containment action is recommended to include in an automated SOAR playbook when privileged accounts show anomalous activity?
  • To automate updating IOC sources based on IC-Score thresholds, which automation construct would you implement?
  • When anomalous external-domain communications are detected, which action provides the best single path to assess context?
  • To grant a group read-only access to all resources, including detection engine rules, which configuration is correct?
  • SecOps alerts indicate repeated PowerShell activity and outbound connections to a domain not in your threat feeds across multiple systems and users. You need to search across impacted systems and identities to identify the malicious user and scope. What should you do?
  • When investigating a malware incident in a Kubernetes workload, what should be your first action?
  • For continuous DNS comparison to threat feeds, most effective approach?
  • Which action augments SCC with additional detectors using known IOCs and external signals?
  • Which approach should you use to validate a Gemini-generated playbook against a simulated remote shell alert?
  • You are hunting for lateral movement via RDP. Which approach best informs a UDM-based query for detection?
  • Which option best enables consistent weekly export of high-priority case resolutions and SLA metrics as CSV attachments for distribution?
  • To analyze a malware sample efficiently for IOCs without alerting the threat group, which Threat Intelligence action should you take?
  • You are writing a SecOps SIEM rule that sends a risk score to the alert. You have GTI data via subscription. You need the threat score in detection logic to inform alert risk score and be available for future detections. What should you do?
  • You received a suspicious C2 domain IOC and want to investigate whether it appeared in your environment using the most efficient approach. What should you do?
  • For monitoring ingestion health with Bindplane, which steps ensure you get notified about silent sources within 15 minutes and have a clear view of throughput and parsing errors?
  • To minimize analyst effort when containing an endpoint via Gmail integration and require approval, which playbook design is most effective?
  • Which log source should be prioritized to gain visibility into user identity behavior, lateral movement, and privilege escalation in a cloud-heavy SecOps onboarding?
  • You use GTI to identify cyber threats and think your organization may have been targeted by a cyber crime group. What should you do to determine if your organization has been victimized?
  • You notice suspicious login attempts on several user accounts. You need to determine whether these attempts are part of a coordinated attack quickly. What action first?
  • You want to reduce pivoting when triaging alerts using SecOps case management. Which approach should you take first?
  • You need to automate a SOAR playbook task to run once every day at a specific time with minimal overhead. What should you do?
  • Which approach should you take to generate a list of unknown command and control (C2) nodes within 24 hours?
  • Which change reduces false positives when a detection rule triggers on Cloud Storage object listing due to automation activity?
  • To reduce false positives from service accounts in unusual login alerts, which is most effective?
  • Why would a multi-event YARA-L rule be preferred over a single-event rule in SecOps detection?
  • Ingesting multi-region on-prem NAS logs into SecOps, which configuration ensures each NAS is tagged as a distinct log source to prevent IP aliasing?
  • If you suspect anomalous outbound traffic to external domains is C2 communications, which search identifies least common network communications over the last 14 days?
  • If default UDM search columns are not relevant, what is an effective way to reduce false positives when a curated high-priority network indicators rule set flags issues due to on-prem proxies?
  • For near real-time detection when a Cloud Run service agent modifies the IAM policy of an Artifact Registry repository, what is the recommended approach?
  • If phishing alerts feed into SecOps SOAR and you want to automatically include the SIEM query results in the case without writing code, which action should you implement?
  • To minimize the effort required to write detections when integrating Google Cloud services with SecOps, which action should you take?
  • In a standard set of playbooks, where an All trigger should apply if no more specific playbooks have triggered, how should you ensure the specific playbook is attached when multiple triggers match?
  • To prevent false positives when detections trigger on 192.0.2.0/8, which YARA-L condition best fits?
  • When your case queue contains IP address entities, how should you determine internal vs external and mark internal IPs during ingestion into SOAR?
  • To pull SCC findings into SecOps for SOAR actions, how should you configure the connection?
  • For enrichment actions where the enrichment tech is in a private data center that cannot accept inbound connections, how should you connect SecOps?
  • When evaluating a new endpoint detection tool for SecOps integration, which step is most directly tied to interoperability with existing workflows?
  • Create a YARA-L detection rule to identify when an internal host initiates a network connection to an external IP that the Applied Threat Intelligence Fusion Feed associates with APT41. You must flag IP if it has a documented relationship to other APT41 indicators within the Fusion Feed. How should you configure?
  • An external identity with a highly privileged IAM role exists in a critical project. You need to determine whether actions were taken by this identity. Logs are centralized in Cloud Logging, and historical logs exported to BigQuery. What should you do?
  • You monitor critical Windows server logs via Bindplane and want immediate notification when no logs are ingested for over 30 minutes. Most efficient notification solution?
  • Which log source is needed to expand detection coverage when using curated detections and YARA-L rules on Windows endpoints?
  • Which option provides built-in posture for the compliance framework within SCC posture?
  • When leveraging a MISP feed to detect Command-and-Control domain indicators in the entity graph, which of the following entity settings should you apply to filter for domain IOCs?
  • When you see multiple login events with the same principal.user.userid from different countries within a short time window, you need to validate whether the account is compromised. What should you do?
  • PCI DSS v4.0 posture in SCC flags a Compute Engine VM in the CDE with an external IP. Immediate remediation?
  • Your SecOps instance has roles Tier 1, Tier 2, Tier 3. New requirement: restrict access to Tier 3 cases from other tiers. What should you do?
  • Which workflow supports time-windowed anomaly detection and analyst triage by using BigQuery, Cloud Run, Pub/Sub, and log-based metrics with SCC findings?
  • You want a new playbook deployable quickly by junior analysts using SecOps tools to address a remote shell alert. What should you do?
  • Which option ensures each NAS log source is uniquely tagged in SecOps by applying an ingestion label?
  • Group A requires access to all data. Which action should you take in IAM to satisfy this requirement?
  • A rule that detects excessive network connections is too noisy. You want to reduce noise without reducing effectiveness. What change?
  • For MSSP onboarding, which configuration ensures separate case data by client within SecOps?
  • In a multi-region NAS log ingestion scenario, which option uses a Bindplane agent collecting Syslog and an ingestion label per log source?
  • With SecOps Enterprise Plus but no threat intelligence feeds ingested, which approach should you take to quickly alert on an IOC of an active breach?
  • To quickly reduce noise when detecting requests to potentially malicious domains from NDR logs, which approach is most appropriate?
  • A Vertex AI deployment requires detective and preventative guardrails; how should you secure this environment?
  • When JSON logs from a third-party system have missing fields, what should you do to parse them quickly into UDM?
  • When you need to contain a compromised production server while preserving forensic data, what should you do first?
  • You observe multiple distinct, low-severity suspicious activities on a single internal server; no single event is a high-confidence IOC. You want ongoing heightened scrutiny. What should you do?
  • To reduce alert noise from repetitive SecOps alerts, which configuration should you apply?
  • To reduce alert noise by prioritizing alerts based on asset sensitivity, which data should you ingest into Google SecOps?
  • Which approach uses feed management to pull data and an ingestion label per log source to distinguish logs from all NAS devices?
  • To reduce false positives from high-priority network indicators related to on-prem proxies, which exclusion is most appropriate?
  • Which approach best enables low-latency ingestion of data from a Pub/Sub topic in a separate project into SecOps using a dedicated ingestion key?
  • In the security analyst team's playbook action process, which step consolidates all actions awaiting user input in one location?
  • To reduce false positives when monitoring with YARA-L, which approach is recommended?
  • During an incident investigation, which UDM search field best captures network activity tied to rarely seen commands?
  • Which method would you use to identify all assets a specific user interacted with over the past seven days in Google SecOps?
  • What method helps monitor forwarders and collection agents and detect silent sources within five minutes?
  • A firewall parser fails to recognize fields after a patch introduces a new field and renames another. Which approach minimizes change management impact while restoring parsing capability?
  • A third-party application's data is published to a Pub/Sub topic in a separate project; push attempts to SecOps fail. Which low-latency approach is robust?
  • For a SIEM dashboard, how do you dynamically monitor assets based on a specific asset tag?
  • To detect when a user account downloads unusually large volumes relative to baseline with minimal effort, which approach should you implement?
  • MSSP onboarding to SecOps; how should you configure to logically separate cases by client?
  • To identify all potential GTI IOCs within your organization's data using SecOps, which page should you use?
  • Upon noticing a high-volume, unusual download event from a cloud storage bucket, which action should you take first?
  • To monitor audit logs related to data feeds in Google SecOps, which action should you take?
  • When receiving alerts from multiple connectors in SecOps, which approach helps identify internal IP entities and assign a specific network name to trigger a playbook?
  • When writing a detection rule using a MISP feed to filter for domain indicators in the entity graph, which condition filters for domain IOCs?
  • What BigQuery setting controls how long exported data remains available in a dataset for retention purposes?
  • All DLP-related cases should include a defined root cause specific to one of five DLP event types when closed in SecOps. How would you implement this?
  • Which step ensures external analysts can access the SecOps environment with read-only access to all resources, including detection engine rules?
  • You need to calculate MTTR for cases. What should you do?
  • A case contains a file hash enriched with VirusTotal context and categorized as likely malicious. You need to quickly identify devices and users in your org who interacted with this file. What should you do?
  • What approach supports a centralized leadership dashboard that combines SCC findings with Cloud Logging security events using managed services and supports historical data and joins?
  • In a cloud-first SecOps environment, which of the following is a key step to reduce detection-writing effort when integrating with Google Cloud services?
  • To capture time duration data for each case stage with minimal overhead, what should you do?
  • Which technique enables rapid identification of unknown C2 nodes by examining historic outbound connections against ingested threat intel?
  • When building a playbook, how should you ensure that different SecOps roles see appropriate information for the alert the playbook handles?
  • Which option would you use to monitor data feed audit logs by ingesting into SecOps SIEM?
  • What is the recommended first action to enable SecOps access for new users who authenticate via a third-party IdP?
  • Which order of steps best ensures detections reflect threat actor TTPs in GTI?
  • For avoiding IP aliasing across NAS locations, which approach is recommended: feed management with an ingestion label per log source?
  • For ETD detections focusing on data exfiltration from sensitive Cloud Storage and BigQuery, which action minimizes Cloud Logging costs?
  • How should you configure two on-prem firewalls to forward logs to Google SecOps via Syslog?
  • What is the recommended approach to create a centralized leadership dashboard that combines SCC findings with Cloud Audit Logs using managed services?
  • A server is added to a SecOps watchlist after suspicious activity is detected. What is the primary purpose of this action?
  • Which integration step best supports GTI-based enrichment when coordinating detection across on-prem and cloud environments?
  • Phishing alerts are ingested directly into SecOps SOAR from an email inbox, and analysts currently use a SIEM query; you want the query results to be automatically included in the case without writing new code. What should you do?
  • You want to automate responses from SCCE to an existing ticketing system. Which implementation best achieves this?
  • You are adopting multi-cloud and want comprehensive monitoring of threats using SecOps quickly. What should you do?
  • What is the first step to enable Company A analysts to work in Google SecOps with data isolation and reuse of playbooks?
  • To extend parsing without rebuilding, what approach should you take?
  • External MSP users must list SCC findings with minimal involvement in external user lifecycle. What is the recommended approach?
  • An outbound connection from a production VM to an unfamiliar external IP is observed. Which action is the quickest to gather context and assess IP reputation?
  • You need monitoring and alerting for Compute Engine instances tagged with compliance=pci that have an external IP. What should you do?
  • You identified a new malicious IP address used by a threat actor. You need to search for this IP in SecOps across all normalized logs to determine malicious activity. Which method is most effective?
  • To identify and alert on a repetitive sequence of brute force SSH login attempts on a Compute Engine image that did not result in successful login, while minimizing ingestion quota impact. Which log type should you ingest into SecOps?
  • To generate an alert when a binary hash first appears, which approach should you implement?
  • When enriching data from a third-party DNS filter for UDM compatibility, which approach aligns with the least effort and maintainability?
  • After a red team exercise, which action best reduces IOC noise by muting exercise-related IOC matches?
  • When suspecting lateral movement from a development GKE cluster to production, which initial action helps identify IOCs and prioritize investigation before deep raw log analysis?
  • Group B requires access to all data except the 'restricted' namespace. Which data access scope design would satisfy this?
  • Which notification method is suitable to detect missing data from forwarders within five minutes?
  • In Cloud Identity + SecOps, external Google accounts are added to a group with project-level roles but cannot access SecOps, while internal users can. Which configuration most likely causes this?
  • In a SOAR playbook using VirusTotal v3 to set alert severity, which practice best informs severity?
  • You run an app on a Compute Engine instance (Google-managed image) and need to ingest the app's logs into SecOps with minimal cost/time. Logs have a valid label/parser in SecOps. What should you do?
  • Your SOC triages alerts one at a time using several external dashboards. You want to use SecOps case management to reduce pivoting, with minimal development effort. What should you do first?
  • To quickly evaluate a new third-party endpoint detection tool for SecOps integration with minimal customization, which action is most appropriate?
  • You identified a new threat actor group with several IOCs in GTI and want to use some IOCs in several SecOps detection rules. Most effective approach?
  • In policy terms, which constraint explains why an external identity with project-level access cannot access SecOps?
  • SHA generated a CONFIDENTIAL_COMPUTING_DISABLED finding. What is an appropriate quick remediation?
  • To proactively identify novel/emerging attack patterns targeting Google Cloud in near real-time, which configuration should you implement? (Variant)
  • When a breach is detected, what is the fastest way to boost threat analytics?
  • When designing an automated SOAR playbook to minimize dwell time in a ransomware incident with anomalous privileged service accounts, which action should be included?
  • What language is used in Google SecOps to define complex detections with events, matches, and conditions?
  • For ingestion health monitoring, which approach provides the best visibility into throughput and parsing errors?
  • To view previous enrichment attributes and relevant historical cases for an entity with the fewest steps, what should you do?
  • SecOps SOAR integration with SCC uses a service account with read access at the org level. Actions to update finding states fail due to permission issues. Which least-privilege change should you implement?
  • Which Security Command Center feature helps identify misconfigurations and vulnerabilities across Google Cloud assets?
  • Which configuration is recommended for multi-region NAS log ingestion to tag each log source with an ingestion label?
  • To receive an alert when a privileged Google Group is modified to grant public access, which configuration is most appropriate?
  • To detect anomalous behavior by windowing and aggregating data over time and provide an interface for analysts to triage, which architecture is recommended?
  • In threat hunting with YARA-L, what is retrohunt used for?
  • Which approach should be used to govern Vertex AI in a business unit, including predefined and custom organization policies and modules scoped to the business unit folder?
  • Which option would you implement to use a Bindplane agent collecting Syslog from each location and assign a namespace per log source to avoid IP aliasing?
  • You are threat hunting for an advanced group using campaign-specific infrastructure. You want detections based on behavior to detect whether they have attacked your org. What should you do?
  • To differentiate four regional NAS log sources for SecOps, which configuration assigns a unique ingestion label per log source?
  • Users are restricted by a process with five-day restrictions from most recent flagging time. When ingesting SSO provider logs and on-prem appliance logs, what rule design supports quick implementation and easy maintenance to detect restricted user logins?
  • To minimize false positives from service accounts in login alerts, which approach is most precise?
  • When you need to surface relevant data quickly in a UDM search, which approach is most effective if default columns are not useful?
  • SOC director must be notified by email of escalated incidents and their results before a case is closed. Create a process to automatically send the email upon closing an escalated case. Ensure reliability. What process?
  • For broad detection/response coverage across on-prem and cloud environments using SecOps and GTI, which single action best advances event-based integration?
  • Which SecOps component must be enabled to receive logs routed from Google Cloud Pub/Sub?
  • To ingest Cloud NAT logs for workloads in a designated folder while minimizing integration complexity, what is the correct configuration?
  • A vendor privately reveals their web app has an XSS vulnerability exploitable; app runs on servers in cloud and on-prem. Before the CVE is released, you want to look for signs of exploitation. What should you do?
  • For real-time tracking of pen-test cases and clear differentiation from other incidents, which practice should you implement?
  • To ensure DLP-related changes are detectable in SecOps, which option supports capturing admin actions and supporting automated detection?
  • Onboarding logs from a third-party DNS filtering solution, key UDM fields are missing. What should you do to enable downstream detection rules?
  • Which change reduces false positives when a detection rule triggers on Cloud Storage enumeration by automation?
  • If threat actor TTPs are documented in GTI, which approach best informs your detections?
  • To gain better visibility into OS risks for all VMs using Google-managed images with minimal effort, what should you do?
  • To identify repeated suspicious file downloads within a defined time window, which approach should you implement?
  • When Container Threat Detection alerts that an added binary has been executed in a business-critical workload, which two actions are most appropriate?
  • Which module is used to augment detectors with external IP indicators in SecOps?
  • For an ROI report on analyst activity in SecOps SOAR for the previous month, which option should you use?
  • If a Compute Engine instance is flagged for a high volume of outbound connections to diverse unknown IPs, what should you do to determine if it is compromised by malware?
  • A SecOps report export to a BigQuery dataset runs successfully but the dataset remains empty. Which action should you take to fix the export with correct permissions?
  • Which approach is NOT appropriate for sending on-prem firewall logs to Google SecOps via Syslog?
  • To share IOC lists quickly for collaboration/integration, what should you do?
  • If you were to configure a Bindplane agent and an ingestion label per log source, which statement matches this setup?
  • Which setting should you configure to automatically identify internal CIDR ranges for IP addresses during ingestion into SecOps?
  • You identify a common malware variant and need reliable IOCs and behaviors quickly to confirm infection and search for signs on other machines. What is the best first step?
  • To efficiently implement eight logical workflow branches in a SOAR playbook, which approach should you take?
  • What is the first step to fix access for new SecOps users who authenticate to SecOps via a third-party IdP?
  • Which setup applies an ingestion label per log source when pulling data from multiple NAS locations into SecOps?
  • Which category provides curated detections for cloud threats across services?
  • Which configuration would you implement if your goal is to pull data and tag using an ingestion label per log source?
  • Which configuration involves using feed management to pull data from each location and applying a label per log source?
  • Which approach helps you identify all GTI threats within your data by using SecOps?
  • What is the recommended approach to ensuring DLP case closures record a standardized root cause?
  • Your organization uses a prebuilt parser for a complex but stable log source and needs additional fields mapped to UDM. What should you do?
  • Which steps are required to configure the SCC integration for pulling findings into SecOps?
  • You manage threat intelligence and IOC lists. You compiled IOCs from recent incidents and want to share quickly for collaboration/integration. What should you do?
  • If you previously exported AD context data and imported as watchlists in another SIEM, what should you do to improve SecOps usage?
  • Logs are delayed due to a time zone issue; which parser-related action is recommended?
  • Which component enables a playbook to run on a regular schedule with minimal overhead by generating cases for the operator to handle?
  • To ingest on-prem MySQL logs into SecOps with minimal effort, which action is recommended?
  • A server hosting an internal web app was exposed to the internet for 48 hours. You want to run a UDM search to identify successful exploitations. What event field search should you use?
  • To proactively identify novel/emerging attack patterns targeting Google Cloud in near real-time, which configuration should you implement?
  • How should you implement on-demand approvals for firewall changes requested by SOC analysts?
  • In Google SecOps, to identify traffic originating from the server hosting an HTTP backdoor on TCP port 5555, which event attribute should you monitor?
  • To investigate outbound and inbound traffic to a known C2 IP address, which search approach should you use in SecOps?
  • Which configuration should be used when you want to avoid IP aliasing across four NAS regions and tag each as a log source?
  • Which approach reduces alert fatigue by excluding known IOC matches while preserving visibility for future events?
  • Which configuration uses feed management to pull data and configure an ingestion label per log source?
  • You need real-time monitoring of data ingestion into SecOps and automatic notification if any data source stops ingesting, minimizing cost. What should you do?
  • Compliance team requires regular reporting on compliance with standard control frameworks for a regulated business unit that continuously adds projects. You need a report including evidence of non-compliant resources. How should you generate this?
  • Which strategy automatically remediates dormant service account keys when a finding is ingested into SecOps?
  • You have ransomware incidents and need automated detection and containment. Which single action would most effectively achieve automated detection and containment?
  • In SecOps, which approach would you use to identify all assets touched by a particular user within a given timeframe?
  • Which configuration should be used to tag each NAS as a distinct log source to avoid IP aliasing in multi-region NAS log ingestion?
  • Your SecOps instance generates many alerts related to a C2 IP in a threat feed, but the queries originate from sandbox/test environments. You want to avoid alert fatigue while preserving visibility if the IOC reappears in production telemetry. What should you do?
  • To determine whether your organization has been victimized based on threat intel, which action provides quick coverage?
  • You need eight logical workflow paths in a SOAR playbook efficiently. What should you do?
  • In a SOAR playbook, after a UDM query finds users who connected to a malicious domain, how should you add those users as entities in an alert to reset passwords with minimal analyst effort?
  • Detection rules triggering on internal IPs within 192.0.2.0/8 can cause false positives. Which YARA-L condition should you use to fix this?
  • Which action best reduces IOC noise from a known exercise by muting matches?
  • To automatically remediate dormant service account keys when a relevant finding is detected, which approach is recommended?
  • Which action helps you track case stages and compute elapsed time with minimal overhead?
  • During a high-priority phishing incident, what workflow helps ensure timely escalation if analysts fail to escalate within SLA?
  • You are reviewing a UDM search result and find that the default columns are not helpful. Which action should you take to quickly surface relevant data?
  • In monitoring, what is the benefit of a metric-absence alert for critical Windows server logs?
  • When developing a new YARA-L rule while minimizing impact on production, what workflow is recommended?
  • Why is it important to verify default parsers when evaluating a log source for SecOps ingestion?
  • An APT actor is suspected with IOCs including a SHA256 of a malicious DLL, a C2 domain, and rundll32.exe spawning powershell.exe with obfuscated arguments. If Sysmon data is inconsistent and process hashes are unreliable, which approach is best?
  • You have third-party threat intelligence subscriptions and want to continuously compare DNS calls on endpoints to your feeds. What should you do?
  • What is the most efficient approach to identify the most commonly occurring processes across organization servers for baselining?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy