Skip to content

GCP-PSOE Google Cloud Professional Security Operations Engineer Practice Questions

Prepare for GCP-PSOE with more than an answer.

135 questions in the full set12 sample questionsUpdated Mar 12, 2026

Unlock the full exam and previous versions

  • v1Google Cloud Professional Security Operations Engineer 135 questions Current
  • PSOELegacy Professional Security Operations Engineer 2026 299 questions Locked
Exam fee
$200 USD
Time limit
120 minutes
Questions on the exam
50-60
Passing score
70% (scale Not publicly disclosed (pass/fail result))
Level
Professional
Valid for
2 years
Domains covered on the exam 6
  1. Platform Operations14%
  2. Data Management14%
  3. Threat Hunting19%
  4. Detection Engineering22%
  5. Incident Response21%
  6. Observability10%
  1. 1

    A security engineer notices that logs from a critical legacy application are arriving in Google SecOps but are not searchable by specific fields like 'Source IP' or 'Username'. They appear only as 'Unparsed' or 'Raw Log' entries. What is the correct remediation step?

    Show answer details

    Correct answer: B

    Logs appear as 'Unparsed' when the system does not recognize their format or does not have an associated parser. To make individual fields searchable (normalized), you must create a parser that extracts data from the raw log and maps it to the UDM schema.

  2. 2

    You are managing log ingestion costs. You want to ingest Cloud Audit Logs but exclude 'DATA_READ' operations for a specific high-volume storage bucket to save costs, while keeping 'DATA_WRITE' and 'ADMIN_ACTIVITY' logs. What is the most effective way to achieve this before the logs reach Google SecOps?

    Show answer details

    Correct answer: B

    The most cost-effective method is to filter logs at the source or during transport. By configuring an exclusion filter on the Cloud Logging Sink (e.g., resource.type="gcs_bucket" AND protoPayload.methodName="storage.objects.get"), you prevent the high-volume 'DATA_READ' logs from ever being exported to SecOps, avoiding ingestion costs entirely.

  3. 3

    Which of the following best describes the purpose of 'Aliasing' in the context of Google Security Operations Data Management?

    Show answer details

    Correct answer: B

    Aliasing is the process of associating different identifiers (like an IP address that changes via DHCP, a static Hostname, and a MAC address) to a single Asset entity. This allows SecOps to present a unified timeline of activity for that asset, even as its IP address changes.

  4. 4

    You need to ingest logs from a third-party SaaS application that only offers a REST API for log retrieval. Google SecOps does not have a native 'Feed' integration for this specific vendor. Which tool is recommended to act as the bridge to fetch these logs and forward them to Google SecOps?

    Show answer details

    Correct answer: B

    BindPlane OP is a widely used observability pipeline tool (often partnered with Google Cloud) that can fetch data from various third-party APIs and sources, transform it, and forward it to destinations like Google Cloud Logging or Google SecOps.

  5. 5

    A multinational enterprise is deploying Google Security Operations (SecOps) and needs to ingest logs from various on-premises firewalls and cloud-native services. The security architect needs to visualize the architecture to ensure high availability and secure transport for the on-premises logs.

    Based on the architecture diagram below, which component is missing or misconfigured in the flow for the On-Premises Firewall logs to reach the Google SecOps Ingestion API securely?

    Show answer details

    Correct answer: B

    On-premises logs typically require a Google SecOps Forwarder (deployed as a container or binary) to collect syslog or file-based logs, encrypt them, and transmit them securely to the Google SecOps Ingestion API over HTTPS. Direct transmission from legacy firewalls to the API is often not supported or secure without the intermediate forwarder to handle authentication and buffering.

    flowchart LR FW[On-Prem Firewall] -->|Syslog/TCP| FWD[SecOps Forwarder] FWD -->|HTTPS/TLS| API[Google SecOps Ingestion API] Cloud[Google Cloud Logs] -->|Sink| API
  6. 6

    You are configuring access control for a team of Tier 1 SOC analysts in Google Security Operations. These analysts require the ability to search logs and view detections but must strictly be prevented from modifying parsers, detection rules, or system configurations. Which Identity and Access Management (IAM) role or permission set approach is most appropriate to enforce the Principle of Least Privilege?

    Show answer details

    Correct answer: B

    The 'Chronicle Viewer' role provides read-only access to the Google Security Operations platform. This allows analysts to search UDM data, view detections, and access dashboards without granting permissions to modify configurations, rules, or parsers, aligning perfectly with the Principle of Least Privilege for Tier 1 analysts.

Create an account to continue.