GCP-PSOE Sample Questions & Answers
Building detection mechanisms and using threat intelligence to spot risks takes the biggest slice, alongside configuring access and platform operations, ingesting logs for a baseline, hunting threats across environments, response playbooks, and dashboards.
Launch the full GCP-PSOE simulator →Showing 6 of 12 free samples.
- Question 1Advanced
Platform Operations · Configuring Access
Your organization uses Workforce Identity Federation to allow external analysts to access the Google Security Operations console. An analyst reports they can log in but cannot see the 'SOAR' tab to access playbooks. You have confirmed their identity is correctly federated and mapped. What is the most likely cause of this issue?
Show answer & explanation
Correct answer: D
Google Security Operations SOAR maintains its own internal Role-Based Access Control (RBAC) separate from the main Google Cloud IAM roles used for the SIEM/Search interface. Even if a user has IAM access to the platform, they must be explicitly provisioned and assigned a role within the SOAR module settings to access SOAR features like playbooks and cases.
- Question 2IntermediateSelect 2
Platform Operations · Configuring Access
Which TWO of the following are valid methods to authenticate a Python script running on an on-premises server that needs to query the Google Security Operations Search API? (Select TWO)
Show answer & explanation
Correct answers: A, D
For on-premises workloads where Workload Identity Federation is not configured, a Service Account Key (JSON) is a standard method to authenticate to Google Cloud APIs.
Workload Identity Federation is the recommended best practice for external workloads. It allows the on-prem service to exchange external credentials (like OIDC or SAML) for a Google Cloud access token without managing long-lived service account keys.
- Question 3Intermediate
Platform Operations · Enhancing Detection and Response
An organization is using Cloud IDS (Intrusion Detection System) to monitor traffic in their VPC. They want to correlate Cloud IDS threat alerts with endpoint logs in Google Security Operations. What is the prerequisite step to enable this correlation?
Show answer & explanation
Correct answer: B
To correlate data in Google SecOps, disparate log sources must be ingested and normalized into the Unified Data Model (UDM). Once Cloud IDS logs are mapped to UDM fields (e.g.,
principal.iportarget.ip), they can be joined with endpoint logs sharing those same IPs in detection rules or searches. - Question 4Intermediate
Platform Operations · Enhancing Detection and Response
True or False: In Google Security Operations, the 'Ingestion Labels' can be used to route specific logs to different retention buckets or to filter them from being ingested entirely to manage costs.
Show answer & explanation
Correct answer: A
Ingestion labels in Google SecOps can be used to tag data streams. These labels can then be leveraged in ingestion filters to include or exclude specific data, effectively managing costs and data relevance.
- Question 5Intermediate
Data Management · Ingesting Logs for Security Tooling
You are creating a custom parser in Google Security Operations for a proprietary application log. The log contains a user ID field 'User: 12345' that you want to map to the Unified Data Model (UDM). Which UDM field is the MOST appropriate target for this data, assuming this user initiated the event?
Show answer & explanation
Correct answer: C
In UDM, the 'principal' noun represents the actor that initiated the event. Since the user initiated the event,
principal.user.useridis the correct field mapping.targetwould be the entity being acted upon. - Question 6Intermediate
Data Management · Ingesting Logs for Security Tooling
A security engineer notices that logs from a critical legacy application are arriving in Google SecOps but are not searchable by specific fields like 'Source IP' or 'Username'. They appear only as 'Unparsed' or 'Raw Log' entries. What is the correct remediation step?
Show answer & explanation
Correct answer: A
Logs appear as 'Unparsed' when the system does not recognize their format or does not have an associated parser. To make individual fields searchable (normalized), you must create a parser that extracts data from the raw log and maps it to the UDM schema.
Ready for the real thing?
The full GCP-PSOE simulator has every exam-style question, timed mode, and instant scoring.