
Google CloudProfessional Security Operations Engineer
Domain 2Objective 2
2.2 Identifying a Baseline of User, Asset, and Entity Context PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice Questions (Page 6)
Part of the Data management domain, which accounts for 14% of the PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER exam.
32questions here
7free pages
7concepts
14%of the exam
Questions 26–30
- 26
A security operations team is building a UEBA solution and needs to import user context such as job title, department, and manager. Which entity data source should they use?
Select an answer first - 27
A security team is evaluating threat intelligence sources to improve detection of phishing campaigns targeting their employees. Which source would be most directly applicable to this goal?
Select an answer first - 28
Which of the following event data sources is most likely to provide information about network connections and traffic patterns?
Select an answer first - 29
An analyst enriches a firewall log entry with the asset owner's name from an asset management system. What is this process called?
Select an answer first - 30
A security analyst is correlating authentication events from multiple sources. The VPN logs use the username 'jdoe', the cloud identity provider uses the email 'john.doe@example.com', and the HR system uses employee ID 'E12345'. The analyst needs to enrich authentication events with the user's job role. Which approach is most effective for establishing a reliable correlation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER” is a trademark of its owner, used for identification only.