Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Google Cloud logo

Google CloudProfessional Security Operations Engineer

Domain 2Objective 2

2.2 Identifying a Baseline of User, Asset, and Entity Context PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice Questions (Page 4)

Part of the Data management domain, which accounts for 14% of the PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER exam.

32questions here
7free pages
7concepts
14%of the exam

Questions 16–20

  1. 16foundation · easy

    In security analytics, which of the following best describes the role of event data?

    Select an answer first
  2. 17foundation · easy

    What is the primary purpose of enriching event data with entity context?

    Select an answer first
  3. 18application · medium

    A security analyst is investigating a suspicious login event from an IP address. The event log contains the user's email address, but the identity provider (IdP) logs use a numeric user ID. The asset inventory uses hostnames, while the endpoint logs use IP addresses. To enrich the login event with the user's department and asset owner, which aliasing fields should the analyst use to correlate the data?

    Select an answer first
  4. 19foundation · easy

    A security analyst is setting up a threat intelligence ingestion pipeline. Which of the following is a standardized protocol for exchanging cyber threat intelligence in a machine-readable format?

    Select an answer first
  5. 20application · medium

    A security analyst is creating a dashboard to show the number of failed login attempts per user. Which data source should be used for this metric?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER” is a trademark of its owner, used for identification only.