PSOE Sample Questions & Answers
Detection engineering, including threat-intelligence-driven risk identification, takes the biggest slice, alongside platform access management, log ingestion for a baseline, cross-environment threat hunting, containment and case-management playbooks, and dashboards.
Launch the full PSOE simulator →Showing 10 of 20 free samples.
- Question 1AdvancedSelect 2
Platform Operations · Configuring Access
Select TWO primary benefits of using Workforce Identity Federation when configuring access to Google Cloud security tools for your operations team.
Show answer & explanation
Correct answers: A, D
You can map attributes (claims) from the external IdP token to Google Cloud attributes, enabling precise access control policies based on the user's role or group in the external system.
Workforce Identity Federation allows you to use an external Identity Provider (IdP) (like Azure AD or Okta) to authenticate users directly without synchronizing user accounts to Google Cloud, simplifying identity management.
- Question 2Intermediate
Detection Engineering · Developing and Implementing Detection Mechanisms
You are investigating a data exfiltration incident. You have identified a suspicious IP address communicating with your Compute Engine instances. You want to visualize the flow of traffic to understand which internal assets communicated with this IP over the last 48 hours. Which Google SecOps feature provides this visualization?
Show answer & explanation
Correct answer: B
While Asset/Domain views show lists, the Enterprise Insights (or specialized graph views within the investigation console) and the Entity Graph capabilities allow analysts to visually map relationships and traffic flows between entities (assets) and external indicators (IPs) over time.
- Question 3Beginner
Observability · Health Monitoring and Alerting
True or False: In Google SecOps, the 'silent source detection' feature automatically alerts you when a log source that was previously sending data stops sending data for a specified period.
Show answer & explanation
Correct answer: A
True. Silent source detection is a health monitoring feature that monitors data ingestion rates and generates an alert if a specific log stream or forwarder stops sending data or drops below a defined threshold, indicating a potential collection failure.
- Question 4Advanced
Observability · Dashboards and Reports for Security Insights
You are creating a dashboard in Looker Studio to visualize security metrics from Google SecOps. You need to join security alerts with HR data to display alerts by department. The HR data is updated daily and stored in a CSV file in Cloud Storage. What is the most efficient way to achieve this?
Show answer & explanation
Correct answer: A
BigQuery can query data directly from Cloud Storage using external tables. By creating a view that joins the live SecOps data (exported to BigQuery) with the HR CSV external table, Looker Studio can query this unified view. This avoids manual imports and ensures data freshness.
- Question 5Beginner
Threat Hunting · Leveraging Threat Intelligence for Threat Hunting
A new zero-day vulnerability has been announced. The CISO asks you to determine if any internal hosts have communicated with a list of 50 known bad IP addresses associated with this threat over the past 30 days. Which Google SecOps feature is designed to perform this retrospective analysis most efficiently?
Show answer & explanation
Correct answer: A
Retrohunt (now integrated with Google Threat Intelligence) is specifically designed to take a set of IOCs (like IPs) and scan historical log data to see if those indicators were present in the environment before they were known to be malicious.
- Question 6Intermediate
Incident Response · Building and Using Response Playbooks
You are configuring a Google SecOps SOAR playbook to handle phishing alerts. You need to extract the URL from the alert, scan it with VirusTotal, and if the reputation score is bad, block the domain on the firewall. Which SOAR concept handles the data transfer of the URL from the 'Trigger' phase to the 'VirusTotal Action' phase?
Show answer & explanation
Correct answer: B
In SOAR playbooks, data passed between steps is managed via Context Keys or Placeholders (e.g., [Alert.URL]). The output of one step is stored in the context and referenced by subsequent steps.
- Question 7Intermediate
Threat Hunting · Performing Threat Hunting Across Environments
Case Study: A retail company uses Google Cloud for their e-commerce platform. They have enabled Cloud Audit Logs for all services. Recently, they noticed a spike in 'Permission Denied' errors in the logs. You suspect an internal service account has been compromised and is attempting to access resources it shouldn't.
Which specific log stream and filter in Logs Explorer would best help you isolate the source of these failed API calls?
Show answer & explanation
Correct answer: B
Admin Activity logs (activity) record API calls that modify resources. However, failed authorization attempts are often captured here or in Data Access logs depending on configuration. A filter for
protoPayload.status.code=403(Permission Denied) andseverity=ERRORwill isolate the failed attempts. TheprotoPayload.authenticationInfo.principalEmailfield will reveal the service account. - Question 8Intermediate
Data Management · Ingesting Logs for Security Tooling
You are designing a data ingestion strategy for Google SecOps. You have a requirement to filter out high-volume, low-value debug logs from your application servers BEFORE they are ingested into SecOps to save on costs. Where should this filtering logic be applied?
Show answer & explanation
Correct answer: B
To save ingestion costs, data must be filtered before it enters the SecOps platform. This is best done at the edge (agent configuration) or in the Cloud Logging Log Router using exclusion filters before the sink to SecOps.
- Question 9Beginner
Detection Engineering · Developing and Implementing Detection Mechanisms
Which of the following Google Cloud services is required to enable 'Event Threat Detection' in Security Command Center?
Show answer & explanation
Correct answer: B
Event Threat Detection (ETD), which uses logic and threat intelligence to detect threats in log data (like Cloud Audit Logs), is a feature available only in the Premium and Enterprise tiers of SCC, not the Standard tier.
- Question 10Advanced
Detection Engineering · Developing and Implementing Detection Mechanisms
You are writing a YARA-L rule. You want to define a variable
$userthat captures theprincipal.user.useridfield, but ONLY if theprincipal.location.country_or_regionis NOT 'US'. Which syntax correctly defines this in the events section?Show answer & explanation
Correct answer: D
In the events section, you define event variables (like $e). You assign UDM fields to placeholder variables ($user) using '='. Conditions on the event (filtering) are applied using standard comparison operators like '!='. Both lines are required: one to capture the value, one to filter the event.
Ready for the real thing?
The full PSOE simulator has every exam-style question, timed mode, and instant scoring.