Free PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Google PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice Test Question

Loading demo links...

Showing 1–3 of 4 questions

Question 1 (Topic 1)

You use Google Security Operations (SecOps) curated detections and YARA-L rules to detect suspicious activity on Windows endpoints. Your source telemetry uses EDR and Windows Events logs. Your rules match on the principal.user.userid UDM field. You need to ingest an additional log source for this field to match all possible log entries from your EDR and Windows Event logs. What should you do?

Select an option, then click Submit answer.

  • Ingest logs from Windows Sysmon.
  • Ingest logs from Microsoft Entra ID.
  • Ingest logs from Windows PowerShell.
  • Ingest logs from Windows Procmon.
Question 2 (Topic 1)

You have noticed that a Google Security Operations (SecOps) detection rule that detects excessive network connections is triggering too frequently and creating too many false positive alerts. You want to improve the rule to reduce the noise without reducing the effectiveness of the rule. What change to the detection rule should you implement?

Select an option, then click Submit answer.

  • Add a threshold in the YARA-L condition: section to ensure that the rule only alerts after a certain number of connections.
  • Assign a risk score in the YARA-L outcome: section to prioritize alerts more effectively in the alert queue.
  • Include a 10 minute timeframe for the same source and destination of network connections in the YARA-L match: section to aggregate the alerts.
  • Update the YARA-L events: section to exclude the most common IP addresses involved in the network connection alerts to reduce the number of alerts.
Question 3 (Topic 1)

You are planning log onboarding for a Google Security Operations (SecOps) SIEM deployment in a cloud-heavy enterprise environment. The detection engineering team is requesting log sources that support visibility into: User identity behavior - Lateral movement - Privilege escalation attempts - You need to determine which telemetry sources are ingested first. Which log source should you prioritize?

Select an option, then click Submit answer.

  • Cloud access security broker (CASB) logs
  • EDR logs
  • IAM logs
  • Network firewall logs