
Google CloudProfessional Security Operations Engineer
Domain 5Objective 2
5.2 Building, Implementing, and Using Response Playbooks PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice Questions (Page 5)
Part of the Incident response domain, which accounts for 21% of the PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER exam.
23questions here
5free pages
6concepts
21%of the exam
Questions 21–23
- 21
A playbook for a suspected data exfiltration incident includes enrichment steps: checking the user's access history, querying threat intelligence for the destination IP, and reviewing the data classification of the files accessed. The playbook must prioritize enrichments to quickly determine if the incident is a true positive. Which enrichment should be performed first?
Select an answer first - 22
A security team is building a playbook for phishing email triage. The playbook includes steps to extract URLs, detonate them in a sandbox, and block malicious domains. The team wants to automate as many steps as possible without introducing risk. Which step is the best candidate for full automation?
Select an answer first - 23
Which characteristic makes a response step a good candidate for automation in a playbook?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER” is a trademark of its owner, used for identification only.