
Google CloudProfessional Security Operations Engineer
Domain 5Objective 2
5.2 Building, Implementing, and Using Response Playbooks PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice Questions (Page 3)
Part of the Incident response domain, which accounts for 21% of the PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER exam.
23questions here
5free pages
6concepts
21%of the exam
Questions 11–15
- 11
A playbook for a suspected data exfiltration includes several enrichment steps. Which enrichment should be prioritized to help decide whether to escalate to incident response?
Select an answer first - 12
A security team is building a playbook for automated incident triage. They want to integrate with a system that can automatically create a ticket and assign it to the appropriate analyst based on the incident type. Which integration should they select?
Select an answer first - 13
During a phishing investigation, which enrichment should be prioritized FIRST to support the playbook's initial triage decision?
Select an answer first - 14
What is a key input when designing a playbook for a new attack pattern identified from a postmortem?
Select an answer first - 15
A security team is implementing a playbook for critical incidents. They need to notify the on-call analyst immediately and escalate to management if the analyst does not acknowledge within 10 minutes. Which notification mechanism should they use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER” is a trademark of its owner, used for identification only.