PSOE Practice Questions
Prepare for PSOE with more than an answer.
Unlock the full exam and previous versions
- v1Google Cloud Professional Security Operations Engineer 135 questions Locked
- PSOELegacy Professional Security Operations Engineer 2026 299 questions Current
- Exam fee
- $200 USD
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 6
- Platform Operations14%
- Data Management14%
- Threat Hunting19%
- Detection Engineering22%
- Incident Response21%
- Observability10%
- 1
Which of the following Google Cloud services is required to enable 'Event Threat Detection' in Security Command Center?
Show answer details
Correct answer: A
Event Threat Detection (ETD), which uses logic and threat intelligence to detect threats in log data (like Cloud Audit Logs), is a feature available only in the Premium and Enterprise tiers of SCC, not the Standard tier.
- 2
You are writing a YARA-L rule. You want to define a variable
$userthat captures theprincipal.user.useridfield, but ONLY if theprincipal.location.country_or_regionis NOT 'US'. Which syntax correctly defines this in the events section?Show answer details
Correct answer: A
In the events section, you define event variables (like $e). You assign UDM fields to placeholder variables ($user) using '='. Conditions on the event (filtering) are applied using standard comparison operators like '!='. Both lines are required: one to capture the value, one to filter the event.
- 3
Select TWO methods to reduce the number of false positives generated by a specific YARA-L detection rule without modifying the rule logic itself.
Show answer details
Correct answer: A, B
Reference lists allow you to manage lists of strings (like allowed IPs or Users) externally. Updating the list updates the rule's behavior without rewriting the rule code.
Platform-level exclusions or allowlists can suppress detections for known safe entities across multiple rules or specific rules, effectively reducing noise.
- 4
You are performing a threat hunt and want to find all processes that executed from the 'Temp' directory. In UDM Search, which field would you query?
Show answer details
Correct answer: A
In the UDM, process execution events typically map the process being executed to the 'target' object. The full path of the executable is stored in
target.process.file.full_path. You would search for this field containing 'Temp'. - 5
When integrating Google SecOps with Google Cloud Identity for 'Aliasing' (Context Enrichment), which common identifier is primarily used to link user activity events with the user's directory profile information?
Show answer details
Correct answer: A
The email address is the primary key used to associate events (which often contain the user's email in
principal.user.email_addresses) with the user entity context imported from Cloud Identity or Active Directory. - 6
You are investigating a potential compromise of a GKE cluster. You want to see if any pods have established connections to known crypto-mining pools. Which Security Command Center (SCC) service would most likely generate a high-fidelity finding for this specific behavior?
Show answer details
Correct answer: A
Event Threat Detection analyzes Cloud Logging (including VPC Flow Logs and DNS logs) and uses threat intelligence to identify connections to bad IPs/domains, such as known crypto-mining pools. Container Threat Detection is also valid but ETD specifically targets the network connection aspect visible in logs.
- 7
What is the primary purpose of the 'outcome' section in a YARA-L rule?
Show answer details
Correct answer: A
The outcome section allows you to aggregate data (e.g.,
sum($risk_value)) or define descriptive variables (e.g.,$risk_score = 85) that are attached to the generated detection alert. This is crucial for risk-based alerting and prioritization. - 8
You are a Security Engineer configuring Google Security Operations (SecOps) to ingest logs from an on-premises firewall. You need to ensure that the raw logs are correctly mapped to the Unified Data Model (UDM) for effective searching and detection. You are creating a custom parser. Which specific UDM field should you map the source IP address of the traffic to, assuming the firewall logs represent outbound traffic from your internal network?
Show answer details
Correct answer: A
In the Unified Data Model (UDM), 'principal' typically refers to the actor initiating the event. For outbound traffic, the internal source IP initiating the connection is mapped to 'principal.ip'. The destination would be mapped to 'target.ip'.
- 9
A multinational corporation is implementing Security Command Center (SCC) Premium. They require a centralized view of vulnerabilities across multiple Google Cloud organizations and folders. What is the most effective architectural approach to achieve this centralized visibility while maintaining strict IAM boundaries?
Show answer details
Correct answer: A
SCC is activated at the Organization level. To aggregate findings across multiple distinct Organizations, the best practice is to configure Continuous Exports from each SCC instance to a centralized BigQuery dataset. This allows for cross-organization querying and dashboarding without breaking IAM boundaries or requiring complex peering.
- 10
You are writing a YARA-L detection rule to identify potential brute-force attacks. You want to trigger a detection when a user fails to login 10 times within a 5-minute window, followed by a successful login. Which section of the YARA-L rule is responsible for defining the time window logic?
Show answer details
Correct answer: A
The 'match' section in YARA-L is used to group events by specific fields (like user ID) and define the time window (e.g., 'over 5m') over which the condition must be met. The 'events' section filters the raw events, and the 'condition' section defines the logic (e.g., count > 10).
