PSOE Sample Questions

PSOE Sample Questions & Answers

Detection engineering, including threat-intelligence-driven risk identification, takes the biggest slice, alongside platform access management, log ingestion for a baseline, cross-environment threat hunting, containment and case-management playbooks, and dashboards.

Launch the full PSOE simulator →

Showing 10 of 20 free samples.

  1. Question 1AdvancedSelect 2

    Platform Operations · Configuring Access

    Select TWO primary benefits of using Workforce Identity Federation when configuring access to Google Cloud security tools for your operations team.

    Show answer & explanation

    Correct answers: A, D

    You can map attributes (claims) from the external IdP token to Google Cloud attributes, enabling precise access control policies based on the user's role or group in the external system.

    Workforce Identity Federation allows you to use an external Identity Provider (IdP) (like Azure AD or Okta) to authenticate users directly without synchronizing user accounts to Google Cloud, simplifying identity management.

  2. Question 2Intermediate

    Detection Engineering · Developing and Implementing Detection Mechanisms

    You are investigating a data exfiltration incident. You have identified a suspicious IP address communicating with your Compute Engine instances. You want to visualize the flow of traffic to understand which internal assets communicated with this IP over the last 48 hours. Which Google SecOps feature provides this visualization?

    Show answer & explanation

    Correct answer: B

    While Asset/Domain views show lists, the Enterprise Insights (or specialized graph views within the investigation console) and the Entity Graph capabilities allow analysts to visually map relationships and traffic flows between entities (assets) and external indicators (IPs) over time.

  3. Question 3Beginner

    Observability · Health Monitoring and Alerting

    True or False: In Google SecOps, the 'silent source detection' feature automatically alerts you when a log source that was previously sending data stops sending data for a specified period.

    Show answer & explanation

    Correct answer: A

    True. Silent source detection is a health monitoring feature that monitors data ingestion rates and generates an alert if a specific log stream or forwarder stops sending data or drops below a defined threshold, indicating a potential collection failure.

  4. Question 4Advanced

    Observability · Dashboards and Reports for Security Insights

    You are creating a dashboard in Looker Studio to visualize security metrics from Google SecOps. You need to join security alerts with HR data to display alerts by department. The HR data is updated daily and stored in a CSV file in Cloud Storage. What is the most efficient way to achieve this?

    Show answer & explanation

    Correct answer: A

    BigQuery can query data directly from Cloud Storage using external tables. By creating a view that joins the live SecOps data (exported to BigQuery) with the HR CSV external table, Looker Studio can query this unified view. This avoids manual imports and ensures data freshness.

  5. Question 5Beginner

    Threat Hunting · Leveraging Threat Intelligence for Threat Hunting

    A new zero-day vulnerability has been announced. The CISO asks you to determine if any internal hosts have communicated with a list of 50 known bad IP addresses associated with this threat over the past 30 days. Which Google SecOps feature is designed to perform this retrospective analysis most efficiently?

    Show answer & explanation

    Correct answer: A

    Retrohunt (now integrated with Google Threat Intelligence) is specifically designed to take a set of IOCs (like IPs) and scan historical log data to see if those indicators were present in the environment before they were known to be malicious.

  6. Question 6Intermediate

    Incident Response · Building and Using Response Playbooks

    You are configuring a Google SecOps SOAR playbook to handle phishing alerts. You need to extract the URL from the alert, scan it with VirusTotal, and if the reputation score is bad, block the domain on the firewall. Which SOAR concept handles the data transfer of the URL from the 'Trigger' phase to the 'VirusTotal Action' phase?

    Show answer & explanation

    Correct answer: B

    In SOAR playbooks, data passed between steps is managed via Context Keys or Placeholders (e.g., [Alert.URL]). The output of one step is stored in the context and referenced by subsequent steps.

  7. Question 7Intermediate

    Threat Hunting · Performing Threat Hunting Across Environments

    Case Study: A retail company uses Google Cloud for their e-commerce platform. They have enabled Cloud Audit Logs for all services. Recently, they noticed a spike in 'Permission Denied' errors in the logs. You suspect an internal service account has been compromised and is attempting to access resources it shouldn't.

    Which specific log stream and filter in Logs Explorer would best help you isolate the source of these failed API calls?

    Show answer & explanation

    Correct answer: B

    Admin Activity logs (activity) record API calls that modify resources. However, failed authorization attempts are often captured here or in Data Access logs depending on configuration. A filter for protoPayload.status.code=403 (Permission Denied) and severity=ERROR will isolate the failed attempts. The protoPayload.authenticationInfo.principalEmail field will reveal the service account.

  8. Question 8Intermediate

    Data Management · Ingesting Logs for Security Tooling

    You are designing a data ingestion strategy for Google SecOps. You have a requirement to filter out high-volume, low-value debug logs from your application servers BEFORE they are ingested into SecOps to save on costs. Where should this filtering logic be applied?

    Show answer & explanation

    Correct answer: B

    To save ingestion costs, data must be filtered before it enters the SecOps platform. This is best done at the edge (agent configuration) or in the Cloud Logging Log Router using exclusion filters before the sink to SecOps.

  9. Question 9Beginner

    Detection Engineering · Developing and Implementing Detection Mechanisms

    Which of the following Google Cloud services is required to enable 'Event Threat Detection' in Security Command Center?

    Show answer & explanation

    Correct answer: B

    Event Threat Detection (ETD), which uses logic and threat intelligence to detect threats in log data (like Cloud Audit Logs), is a feature available only in the Premium and Enterprise tiers of SCC, not the Standard tier.

  10. Question 10Advanced

    Detection Engineering · Developing and Implementing Detection Mechanisms

    You are writing a YARA-L rule. You want to define a variable $user that captures the principal.user.userid field, but ONLY if the principal.location.country_or_region is NOT 'US'. Which syntax correctly defines this in the events section?

    Show answer & explanation

    Correct answer: D

    In the events section, you define event variables (like $e). You assign UDM fields to placeholder variables ($user) using '='. Conditions on the event (filtering) are applied using standard comparison operators like '!='. Both lines are required: one to capture the value, one to filter the event.

Ready for the real thing?

The full PSOE simulator has every exam-style question, timed mode, and instant scoring.

Go to the PSOE simulator →