Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Google Cloud logo

Google CloudProfessional Security Operations Engineer

Domain 2Objective 2

2.2 Identifying a Baseline of User, Asset, and Entity Context PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice Questions (Page 3)

Part of the Data management domain, which accounts for 14% of the PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER exam.

32questions here
7free pages
7concepts
14%of the exam

Questions 11–15

  1. 11application · medium

    A security operations center (SOC) wants to automatically enrich firewall logs with the business unit and criticality of the affected asset. The asset inventory contains the asset's IP address, hostname, business unit, and criticality. Which approach would enable this enrichment?

    Select an answer first
  2. 12expert · hard

    A global enterprise with offices in multiple regions receives threat intelligence feeds from various sources. The security team notices that many IOCs are outdated or not applicable to their environment. They want to implement a process to filter out irrelevant intelligence while preserving potentially useful data. Which approach best balances relevance and completeness?

    Select an answer first
  3. 13foundation · easy

    A security analyst receives a threat intelligence report about a malware campaign targeting a specific type of industrial control system (ICS) software. The enterprise does not use any ICS software. What is the most appropriate action regarding this intelligence?

    Select an answer first
  4. 14application · medium

    A security operations team receives a daily threat feed containing indicators of compromise (IOCs) for malware families targeting point-of-sale (POS) systems. The team's enterprise is a healthcare provider with no retail operations. The team lead wants to reduce alert fatigue by filtering out irrelevant IOCs. Which action best aligns with the principle of threat intelligence relevance assessment?

    Select an answer first
  5. 15application · medium

    A security team is implementing a data enrichment pipeline to add asset owner information to firewall logs. Which entity data source would provide the asset owner information?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER” is a trademark of its owner, used for identification only.