Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Google Cloud Certified - Professional Security Operations Engineer (PSOE) Exam

Last Update 16 hours ago Total Questions : 60

The Google Cloud Certified - Professional Security Operations Engineer (PSOE) Exam content is now fully updated, with all current exam questions added 16 hours ago. Deciding to include Security-Operations-Engineer practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our Security-Operations-Engineer exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these Security-Operations-Engineer sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Google Cloud Certified - Professional Security Operations Engineer (PSOE) Exam practice test comfortably within the allotted time.

Question # 11

You have a custom-built YARA-L rule in Google Security Operations (SecOps) correlating observed IP addresses in network and EDR logs against threat intelligence findings ingested from a Malware Information Sharing Platform (MISP) over a 2-minute time window. Your company ' s SOC reported that the rule generates too many false positives. You want to reduce the number of false positives generated by the rule while continuing to use threat intelligence.

What should you do?

A.

Convert the rule to a dashboard, and use a match window of 24 hours to visualize entities in a bar chart.

B.

Modify the rule to alert only when the graph.metadata.threat.severity value is critical or high.

C.

Modify the rule to trigger only when the ICCs graph.risk_score.risk_score field exceeds 500.

D.

Adjust the match window in the rule to 24 hours to aggregate IP addresses by asset once a day.

Question # 12

Your organization has mission-critical production Compute Engine VMs that you monitor daily. While performing a UDM search in Google Security Operations (SecOps), you discover several outbound network connections from one of the production VMs to an unfamiliar external IP address occurring over the last 48 hours. You need to use Google SecOps to quickly gather more context and assess the reputation of the external IP address. What should you do?

A.

Search for the external IP address in the Alerts & IoCs page in Google SecOps.

B.

Perform a UDM search to identify the specific user account that was logged into the production VM when the connections occurred.

C.

Examine the Google SecOps Asset view details for the production VM.

D.

Create a new detection rule to alert on future traffic from the external IP address.

Question # 13

You are part of a cybersecurity team at a large multinational corporation that uses Google Security Operations (SecOps). You have been tasked with identifying unknown command and control nodes (C2s) that are potentially active in your organization ' s environment. You need to generate a list of potential matches for the unknown C2s within the next 24 hours. What should you do?

A.

Review Security Health Analytics (SHA) findings in Security Command Center (SCC).

B.

Load network records into BigQuery to identify endpoints that are communicating with domains outside three standard deviations of normal.

C.

Write a YARA-L rule in Google SecOps that scans historic network outbound connections against ingested threat intelligence. Run the rule in a retrohunt against the full tenant.

D.

Write a YARA-L rule in Google SecOps that compares network traffic from endpoints to recent WHOIS registrations. Run the rule in a retrohunt against the full tenant.

Question # 14

You are a SOC manager at an organization that recently implemented Google Security Operations (SecOps). You need to monitor your organization ' s data ingestion health in Google SecOps. Data is ingested with Bindplane collection agents. You want to configure the following:

• Receive a notification when data sources go silent within 15 minutes.

• Visualize ingestion throughput and parsing errors.

What should you do?

A.

Configure automated scheduled delivery of an ingestion health report in the Data Ingestion and Health dashboard. Monitor and visualize data ingestion metrics in this dashboard.

B.

Configure silent source alerts based on rule detections for anomalous data ingestion activity in Risk Analytics. Monitor and visualize the alert metrics in the Risk Analytics dashboard.

C.

Configure notifications in Cloud Monitoring when ingestion sources become silent in Bindplane. Monitor and visualize Google SecOps data ingestion metrics using Bindplane Observability Pipeline (OP).

D.

Configure silent source notifications for Google SecOps collection agents in Cloud Monitoring. Create a Cloud Monitoring dashboard to visualize data ingestion metrics.

Question # 15

You are an incident responder at your organization using Google Security Operations (SecOps) for monitoring and investigation. You discover that a critical production server, which handles financial transactions, shows signs of unauthorized file changes and network scanning from a suspicious IP address. You suspect that persistence mechanisms may have been installed. You need to use Google SecOps to immediately contain the threat while ensuring that forensic data remains available for investigation. What should you do first?

A.

Use the firewall integration to submit the IP address to a network block list to inhibit internet access from that machine.

B.

Deploy emergency patches, and reboot the server to remove malicious persistence.

C.

Use the EDR integration to quarantine the compromised asset.

D.

Use VirusTotal to enrich the IP address and retrieve the domain. Add the domain to the proxy block list.

Question # 16

You are implementing Google Security Operations (SecOps) for your organization. Your organization has their own threat intelligence feed that has been ingested to Google SecOps by using a native integration with a Malware Information Sharing Platform (MISP). You are working on the following detection rule to leverage the command and control (C2) indicators that were ingested into the entity graph.

What code should you add in the detection rule to filter for the domain IOCS?

A.

$ioc.graph.metadata.entity_type = MDOMAlN_NAME "

$ioc.graph.metadata.scurce_type = " ElfelTYj^ONTEXT "

B.

$ioc.graph.metadata.entity_type = " DOMAlN_NAME "

Sioc.graph.metadata.source_type = " GLOBAL_CONTEXT "

C.

$ioc.graph.metadata.entity_type = " D0MAIN_NAME "

$ioc.graph.metadata.source_type = MDERIVED_CONTEXT "

D.

$ioc.graph.metadata.entity_type = , ' D0MAIN_NAME* '

$ioc.graph.metadata.source type = " source type unspecified "

Question # 17

Your company is adopting a multi-cloud environment. You need to configure comprehensive monitoring of threats using Google Security Operations (SecOps). You want to start identifying threats as soon as possible. What should you do?

A.

Use Gemini to generate YARA-L rules for multi-cloud use cases.

B.

Use curated detections from the Cloud Threats category to monitor your cloud environment.

C.

Use curated detections for Applied Threat Intelligence to monitor your company ' s cloud environment.

D.

Ask Cloud Customer Care to provide a set of rules recommended by Google to monitor your company ' s cloud environment.

Question # 18

You are responsible for evaluating the level of effort required to integrate a new third-party endpoint detection tool with Google Security Operations (SecOps). Your organization ' s leadership wants to minimize customization for the new tool for faster deployment. You need to verify that the Google SecOps SOAR and SIEM support the expected workflows for the new third-party tool. You must recommend a tool to your leadership team as quickly as possible. What should you do?

Choose 2 answers

A.

Review the architecture of the tool to identify the cloud provider that hosts the tool.

B.

Review the documentation to identify if default parsers exist for the tool, and determine whether the logs are supported and able to be ingested.

C.

Identify the tool in the Google SecOps Marketplace, and verify support for the necessary actions in the workflow.

D.

Develop a custom integration that uses Python scripts and Cloud Run functions to forward logs and orchestrate actions between the third-party tool and Google SecOps.

E.

Configure a Pub/Sub topic to ingest raw logs from the third-party tool, and build custom YARA-L rules in Google SecOps to extract relevant security events.

Go to page: