Google certification preparation
SECURITY-OPERATIONS-ENGINEER Practice Questions
Practice exam-style questions, check your answers, and review explanations and source references where they are available.
- Exam
- SECURITY-OPERATIONS-ENGINEER
- Provider
- Full set
- 60 questions
- Last Update Check
Your organization has recently onboarded to Google Cloud with Security Command Center Enterprise
(SCCE) and is now integrating it with your organization's SOC. You want to automate the response
process within SCCE and integrate with the existing SOC ticketing system. You want to use the most
efficient solution. How should you implement this functionality?
Question 1 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
You are receiving security alerts from multiple connectors in your Google Security Operations
(SecOps) instance. You need to identify which IP address entities are internal to your network and
label each entity with its specific network name. This network name will be used as the trigger for
the playbook.
Question 2 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
You are writing a Google Security Operations (SecOps) SOAR playbook that uses the VirusTotal v3
integration to look up a URL that was reported by a threat hunter in an email. You need to use the
results to make a preliminary recommendation on the maliciousness of the URL and set the severity
of the alert based on the output. What should you do?
Choose 2 answers
Question 3 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
You are implementing Google Security Operations (SecOps) for your organization. Your organization
has their own threat intelligence feed that has been ingested to Google SecOps by using a native
integration with a Malware Information Sharing Platform (MISP). You are working on the following
detection rule to leverage the command and control (C2) indicators that were ingested into the
entity graph.
What code should you add in the detection rule to filter for the domain IOCS?
What code should you add in the detection rule to filter for the domain IOCS?Question 4 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
You are a SOC manager at an organization that recently implemented Google Security Operations
(SecOps). You need to monitor your organization's data ingestion health in Google SecOps. Data is
ingested with Bindplane collection agents. You want to configure the following:
• Receive a notification when data sources go silent within 15 minutes.
• Visualize ingestion throughput and parsing errors.
What should you do?
Question 5 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
You are a security operations engineer in an enterprise that uses Google Security Operations
(SecOps). You need to improve your detection coverage and reduce the false positive detection ratio
as quickly as possible.
What should you do?
Question 6 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Your organization has mission-critical production Compute Engine VMs that you monitor daily. While
performing a UDM search in Google Security Operations (SecOps), you discover several outbound
network connections from one of the production VMs to an unfamiliar external IP address occurring
over the last 48 hours. You need to use Google SecOps to quickly gather more context and assess the
reputation of the external IP address. What should you do?
Question 7 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Your company requires PCI DSS v4.0 compliance for its cardholder data environment (CDE) in Google
Cloud. You use a Security Command Center (SCC) security posture deployment based on the PCI DSS
v4.0 template to monitor for configuration drift.1 This posture generates a finding indicating that a
Compute Engine VM within the CDE scope has been configured with an external IP address. You need
to take an immediate action to remediate the compliance drift identified by this specific SCC posture
finding. What should you do?
Question 8 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
You work for an organization that uses Security Command Center (SCC) with Event Threat Detection
(ETD) enabled. You need to enable ETD detections for data exfiltration attempts from designated
sensitive Cloud Storage buckets and BigQuery datasets. You want to minimize Cloud Logging costs.
What should you do?
Question 9 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
You are a security engineer at a managed security service provider (MSSP) that is onboarding to
Google Security Operations (SecOps). You need to ensure that cases for each customer are logically
separated. How should you configure this logical separation?
Question 10 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 10
Source context
How this practice set is maintained
Maintained by the CertMage content team, this page loads questions from the exam dataset connected to its preparation resource. When an answer includes a supporting reference, it is shown with that answer so you can review the underlying vendor documentation.
Certification objectives, interfaces, and vendor services can change. Verify important details against the provider's current exam guide and documentation before your exam.
