
Google CloudProfessional Security Operations Engineer
Domain 5Objective 2
5.2 Building, Implementing, and Using Response Playbooks PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice Questions (Page 2)
Part of the Incident response domain, which accounts for 21% of the PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER exam.
23questions here
5free pages
6concepts
21%of the exam
Questions 6–10
- 6
A security team wants to automate the creation of incident tickets in their existing ITSM tool. Which integration should they add to the playbook?
Select an answer first - 7
A security team is designing a playbook for automated containment of a worm that spreads via SMB. The playbook must isolate infected endpoints and block the SMB port on the firewall. The team has an EDR tool and a firewall management system. They want to minimize the time to containment. What should they do?
Select an answer first - 8
A security team notices that their SOAR platform does not have a playbook for a common alert type. What is this an example of?
Select an answer first - 9
A security analyst is reviewing a response playbook for a malware infection. Which step is the BEST candidate for full automation?
Select an answer first - 10
What is the purpose of performing a gap analysis on a SOAR implementation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER” is a trademark of its owner, used for identification only.