Professional Security Operations Engineer: Professional Security Operations Engineer — Free Practice Questions
10 free sample questions from a bank of 10, with the correct answers and explanations. No signup required — start practising right now.
1You are responsible for identifying suspicious activity and security events at your organization. You have been asked to search in Google Security Operations (SecOps) for network traffic associated with an active HTTP backdoor that runs on TCP port 5555. You want to use the most effective approach to identify traffic originating from the server that is running the backdoor. What should you do?
Detect on events where network.ApplicationProtocol is HTTP.
Detect on events where target.port is 5555.
Detect on events where principal.port is 5555.
Detect on events where network.ip_protocol is TCP.
Answer: C
2You are an incident responder at your organization using Google Security Operations (SecOps) for monitonng and investigation. You discover that a critical production server, which handles financial transactions, shows signs of unauthorized file changes and network scanning from a suspicious IP address. You suspect that persistence mechanisms may have been installed. You need to use Google SecOps to immediately contain the threat while ensuring that forensic data remains available for investigation. What should you do first?
Use the firewall integration to submit the IP address to a network block list to inhibit internet access from that machine.
Deploy emergency patches, and reboot the server to remove malicious persistence.
Use the EDR integration to quarantine the compromised asset.
Use VirusTotal to enrich the IP address and retrieve the domain. Add the domain to the proxy block list.
Answer: C
3Your organization uses Google Security Operations (SecOps). You discover frequent file downloads from a shared workspace within a short time window. You need to configure a rule in Google SecOps that identifies these suspicious events and assigns higher risk scores to repeated anomalies. What should you do?
Configure a rule that flags file download events with the highest risk score, regardless of time frame.
Create a frequency-based YARA-L detection rule that assigns a risk outcome score and is triggered when multiple suspicious downloads occur within a defined time frame.
Configure a single-event YARA-L detection rule that assigns a risk outcome score and is triggered when a user downloads a large number of files in 24 hours.
Enable default curated detections, and use automatic alerting for single file download events.
Answer: B
4You are implementing Google Security Operations (SecOps) at your organization. You discover that the current detection rules are too noisy. Due to the high volume of alerts, some true positives might be missed. You want to ingest additional context sources to reduce false positives in your security detections and to improve the overall positive ratio of the alerts. What should you do?
Ingest high-value asset (HVA) data from your configuration management database (CMDB) system to increase the priority of the alerts based on the sensitivity of the assets found in the detection rules.
Ingest dark web forum handlers from your threat intelligence system to match dark web principals within the detection rules.
Ingest IOCs from your threat intelligence system to validate the IP addresses, domains and hashes with the detection rules.
Ingest tactics, techniques, and procedures (TTPs) from your threat intelligence system to validate the processes and tools with the detection rules.
Answer: A
5You are developing a new detection rule in Google Security Operations (SecOps). You are defining the YARA-L logic that includes complex event, match, and condition sections. You need to develop and test the rule to ensure that the detections are accurate before the rule is migrated to production. You want to minimize impact to production processes. What should you do?
Develop the rule logic in the UDM search, review the search output to inform changes to filters and logic, and copy the rule into the Rules Editor.
Use Gemini in Google SecOps to develop the rule by providing a description of the parameters and conditions, and transfer the rule into the Rules Editor.
Develop the rule in the Rules Editor, define the sections the rule logic, and test the rule using the test rule feature.
Develop the rule in the Rules Editor, define the sections of the rule logic, and test the rule by setting it to live but not alerting. Run a YARA-L retrohunt from the rules dashboard.
Answer: C
6Your organization has recently acquired Company A, which has its own SOC and security tooling. You have already configured ingestion of Company A's security telemetry and migrated their detection rules to Google Security Operations (SecOps). You now need to enable Company A's analysts to work their cases in Google SecOps. You need to ensure that Company A's analysts:
do not have access to any case data originating from outside of Company A.
are able to re-purpose playbooks previously developed by your organization's employees.
You need to minimize effort to implement your solution. What is the first step you should take?
Acquire a second Google SecOps SOAR tenant for Company A.
Provision a new service account for Company A.
Define a new SOC role for Company A.
Create a Google SecOps SOAR environment for Company A.
Answer: D
7You have identified and isolated a new malware sample installed by an advanced threat group that you believe was developed specifically for an attack against your organization. You want to quickly and efficiently analyze this malware to get IOCs without alerting the threat group. What should you do?
Search for the threat group in Google Threat Intelligence.
Upload the malware to Google Threat Intelligence by using VirusTotal.
Upload the malware to Google Threat Intelligence by using Private Scanning.
Calculate the file checksum for the malware, and search for the checksum in GoogleThreat Intelligence by using VirusTotal.
Answer: C
8Your organization uses Cloud Identity as their identity provider (IdP) and is a Google Security Operations (SecOps) customer You need to grant a group of users access to the Google SecOps instance with read-only access to all resources, including detection engine rules. How should this be configured?
Create a Google Group and add the required users. Grant the roles/chronicle.Viewer IAM role to the group on the project associated with your Google SecOps Instance.
Create a Google Group and add the required users. Grant the roles/chronicle.limitedViewer IAM role to the group on the project associated with your Google SecOps instance.
Create a workforce identity pool at the organization level. Grant the roles/chronicle.editor IAM role to the principalSet://iam.googleapis.com/locations/global/workforcePools/POOL_ID/group/GROUP_ID principal set on the project associated with your Google SecOps instance.
Create a workforce identity pool at the organization level Grant the roles/chronicle.limitedViewer IAM role to the principalSet://iam.googleapis.com/locations/global/workforcePools/POOL_ID/group/GROUP_ID principal set on the project associated with your Google SecOps Instance.
Answer: A
9Your team is responsible for cybersecurity for a large multinational corporation. You have been tasked with identifying unknown command and control nodes (C2s) that are potentially active in your organization's environment. You need to generate a list of potential matches within the next 24 hours. What should you do?
Write a rule in Google Security Operations (SecOps) that scans historic network outbound connections against ingested threat intelligence Run the rule in a retrohunt against the full tenant.
Load network records into BigQuery to identify endpoints that are communicating with domains outside three standard deviations of normal.
Review Security Health Analytics (SHA) findings in Security Command Center (SCC).
Write a YARA-L rule in Google Security Operations (SecOps) that compares network traffic of endpoints to low prevalence domains against recent WHOIS registrations.
Answer: D
10You received an alert from Container Threat Detection that an added binary has been executed in a business critical workload. You need to investigate and respond to this incident. What should you do? (Choose two.)
Notify the workload owner. Follow the response playbook, and ask the threat hunting team to identify the root cause of the incident.
Review the finding, investigate the pod and related resources, and research the related attack and response methods.
Review the finding, quarantine the cluster containing the running pod, and delete the running pod to prevent further compromise.
Silence the alert in the Security Command Center (SCC) console, as the alert is a low severity finding.
Keep the cluster and pod running, and investigate the behavior to determine whether the activity is malicious.