
Google CloudProfessional Security Operations Engineer
Domain 5Objective 1
5.1 Containing and Investigating Security Incidents PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice Questions (Page 3)
Part of the Incident response domain, which accounts for 21% of the PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER exam.
21questions here
5free pages
7concepts
21%of the exam
Questions 11–15
- 11
During an incident, the security team discovers that a compromised application is running on a Kubernetes cluster managed by the platform engineering team. What is the most important reason to collaborate with the platform engineering team?
Select an answer first - 12
A security analyst is investigating a phishing email that led to a credential compromise. The analyst has the email header and the URL from the email. What is the most effective way to determine if the URL is malicious?
Select an answer first - 13
During an incident, an analyst needs to preserve a compromised Linux VM's disk for later analysis. Which action best aligns with forensically sound evidence collection?
Select an answer first - 14
A security analyst is investigating a compromised Linux VM. The analyst needs to collect evidence for a forensic investigation. The VM is still running, and the analyst wants to minimize disruption. What is the best way to collect a forensic image of the VM's disk?
Select an answer first - 15
An analyst finds a suspicious file hash during an investigation. Which resource is most appropriate to determine if this hash is associated with known malware?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER” is a trademark of its owner, used for identification only.