GCP-PSOE Sample Questions

GCP-PSOE Sample Questions & Answers

Building detection mechanisms and using threat intelligence to spot risks takes the biggest slice, alongside configuring access and platform operations, ingesting logs for a baseline, hunting threats across environments, response playbooks, and dashboards.

Launch the full GCP-PSOE simulator →

Showing 6 of 12 free samples.

  1. Question 1Advanced

    Platform Operations · Configuring Access

    Your organization uses Workforce Identity Federation to allow external analysts to access the Google Security Operations console. An analyst reports they can log in but cannot see the 'SOAR' tab to access playbooks. You have confirmed their identity is correctly federated and mapped. What is the most likely cause of this issue?

    Show answer & explanation

    Correct answer: D

    Google Security Operations SOAR maintains its own internal Role-Based Access Control (RBAC) separate from the main Google Cloud IAM roles used for the SIEM/Search interface. Even if a user has IAM access to the platform, they must be explicitly provisioned and assigned a role within the SOAR module settings to access SOAR features like playbooks and cases.

  2. Question 2IntermediateSelect 2

    Platform Operations · Configuring Access

    Which TWO of the following are valid methods to authenticate a Python script running on an on-premises server that needs to query the Google Security Operations Search API? (Select TWO)

    Show answer & explanation

    Correct answers: A, D

    For on-premises workloads where Workload Identity Federation is not configured, a Service Account Key (JSON) is a standard method to authenticate to Google Cloud APIs.

    Workload Identity Federation is the recommended best practice for external workloads. It allows the on-prem service to exchange external credentials (like OIDC or SAML) for a Google Cloud access token without managing long-lived service account keys.

  3. Question 3Intermediate

    Platform Operations · Enhancing Detection and Response

    An organization is using Cloud IDS (Intrusion Detection System) to monitor traffic in their VPC. They want to correlate Cloud IDS threat alerts with endpoint logs in Google Security Operations. What is the prerequisite step to enable this correlation?

    Show answer & explanation

    Correct answer: B

    To correlate data in Google SecOps, disparate log sources must be ingested and normalized into the Unified Data Model (UDM). Once Cloud IDS logs are mapped to UDM fields (e.g., principal.ip or target.ip), they can be joined with endpoint logs sharing those same IPs in detection rules or searches.

  4. Question 4Intermediate

    Platform Operations · Enhancing Detection and Response

    True or False: In Google Security Operations, the 'Ingestion Labels' can be used to route specific logs to different retention buckets or to filter them from being ingested entirely to manage costs.

    Show answer & explanation

    Correct answer: A

    Ingestion labels in Google SecOps can be used to tag data streams. These labels can then be leveraged in ingestion filters to include or exclude specific data, effectively managing costs and data relevance.

  5. Question 5Intermediate

    Data Management · Ingesting Logs for Security Tooling

    You are creating a custom parser in Google Security Operations for a proprietary application log. The log contains a user ID field 'User: 12345' that you want to map to the Unified Data Model (UDM). Which UDM field is the MOST appropriate target for this data, assuming this user initiated the event?

    Show answer & explanation

    Correct answer: C

    In UDM, the 'principal' noun represents the actor that initiated the event. Since the user initiated the event, principal.user.userid is the correct field mapping. target would be the entity being acted upon.

  6. Question 6Intermediate

    Data Management · Ingesting Logs for Security Tooling

    A security engineer notices that logs from a critical legacy application are arriving in Google SecOps but are not searchable by specific fields like 'Source IP' or 'Username'. They appear only as 'Unparsed' or 'Raw Log' entries. What is the correct remediation step?

    Show answer & explanation

    Correct answer: A

    Logs appear as 'Unparsed' when the system does not recognize their format or does not have an associated parser. To make individual fields searchable (normalized), you must create a parser that extracts data from the raw log and maps it to the UDM schema.

Ready for the real thing?

The full GCP-PSOE simulator has every exam-style question, timed mode, and instant scoring.