GOOGLE · Professional Security Operations Engineer

Google Professional Security Operations Engineer Exam Practice Questions

133 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 133 questions in this pack

Question 1

You are responsible for identifying suspicious activity and security events at your organization. You have been asked to search in Google Security Operations (SecOps) for network traffic associated with an active HTTP backdoor that runs on TCP port 5555. You want to use the most effective approach to identify traffic originating from the server that is running the backdoor. What should you do?

  1. Detect on events where network. ApplicationProtocol is HTTP.
  2. Detect on events where target.port is 5555.
  3. Detect on events where principal.port is 5555.
  4. Detect on events where network.ip_protocol is TCP.
Show answer and explanation

Correct answer: C. Detect on events where principal.port is 5555.

To identify traffic originating from the server running the backdoor, you need to detect on the source port (principal.port) being 5555. The principal represents the source of the traffic, so principal.port 5555 will capture outbound traffic from the compromised server. This is more effective than checking the application protocol or IP protocol alone, as multiple services could use HTTP or TCP, and target.port would only catch inbound traffic to that port rather than traffic originating from the backdoor server.

Why the other options are wrong

  • A. Detecting on HTTP protocol is too broad and will generate excessive false positives from legitimate HTTP traffic.
  • B. target.port represents the destination port, not the source port where the backdoor is running.
  • D. Detecting on TCP protocol alone is insufficiently specific and will capture all TCP traffic.

Question 2

You are an incident responder at your organization using Google Security Operations (SecOps) for monitonng and investigation. You discover that a critical production server, which handles financial transactions, shows signs of unauthorized file changes and network scanning from a suspicious IP address. You suspect that persistence mechanisms may have been installed. You need to use Google SecOps to immediately contain the threat while ensuring that forensic data remains available for investigation. What should you do first?

  1. Use the firewall integration to submit the IP address to a network block list to inhibit internet access from that machine.
  2. Deploy emergency patches, and reboot the server to remove malicious persistence.
  3. Use the EDR integration to quarantine the compromised asset.
  4. Use VirusTotal to enrich the IP address and retrieve the domain. Add the domain to the proxy block list.
Show answer and explanation

Correct answer: C. Use the EDR integration to quarantine the compromised asset.

compromised asset. Using EDR integration to quarantine the compromised asset is the correct first action because it immediately isolates the threat while preserving forensic data on the endpoint. Quarantine prevents further lateral movement and data exfiltration while maintaining the ability to conduct forensic investigation. This approach balances containment with forensic preservation, unlike rebooting which destroys volatile memory, or blocking at the firewall which doesn't prevent local lateral movement.

Why the other options are wrong

  • A. Firewall blocking alone does not contain threats already present on the compromised system and does not prevent local network access.
  • B. Rebooting the server destroys critical forensic evidence in memory and defeats the investigation purpose.
  • D. Using VirusTotal and proxy blocking addresses only external communication and does not contain the already-compromised asset.

Question 3

Your organization uses Google Security Operations (SecOps). You discover frequent file downloads from a shared workspace within a short time window. You need to configure a rule in Google SecOps that identifies these suspicious events and assigns higher risk scores to repeated anomalies. What should you do?

  1. Configure a rule that flags file download events with the highest risk score, regardless of time frame.
  2. Create a frequency-based YARA-L detection rule that assigns a risk outcome score and is triggered when multiple suspicious downloads occur within a defined time frame.
  3. Configure a single-event YARA-L detection rule that assigns a risk outcome score and is triggered when a user downloads a large number of files in 24 hours.
  4. Enable default curated detections, and use automatic alerting for single file download events.
Show answer and explanation

Correct answer: B. Create a frequency-based YARA-L detection rule that assigns a risk outcome score and is triggered when multiple suspicious downloads occur within a defined time frame.

assigns a risk outcome score and is triggered when multiple suspicious downloads occur within a defined time frame. A frequency-based YARA-L detection rule is designed to detect patterns of repeated suspicious events within a specific time window and assign risk scores accordingly. This approach identifies the anomalous behavior of multiple downloads in a short period, escalating the risk score as suspicious activity accumulates. Frequency-based detection is specifically intended for scenarios where individual events are not suspicious but repeated occurrences within a time window indicate malicious activity.

Why the other options are wrong

  • A. Flagging all file downloads with highest risk regardless of time frame generates excessive false positives.
  • C. Single-event rules cannot effectively detect frequency-based patterns across multiple events within a time window.
  • D. Default curated detections and single file download alerting do not address the need for frequency-based analysis or custom risk scoring.

See all 10 free questions Get the full pack, US$39

133 practice questions for Google Cloud Professional Security Operations Engineer, with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 133 questions mapped to the Professional Security Operations Engineer exam guide
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A Professional Security Operations Engineer attempt costs US$200. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 133 questions

What makes the Professional Security Operations Engineer hard

This is effectively an exam on Google Security Operations, the SIEM and SOAR platform formerly known as Chronicle, and Security Command Center, with Google Threat Intelligence and Cloud IDS feeding both. Candidates who know general SOC theory but have never written a YARA-L rule or built a SOAR playbook tend to struggle with the detection engineering and response material.

Detection engineering is the largest section at about 22%: reconciling threat intelligence with user and asset activity, designing detection rules with reference lists and risk values, Risk Analytics, posture and risk profile change detection through SCC Security Health Analytics, finding low prevalence processes and domains with YARA-L, and reducing repetitive false positives. Incident response, at about 21%, covers evidence collection, scoping with Logs Explorer and BigQuery, isolating affected services, root cause analysis and SOAR playbooks.

Threat hunting, at about 19%, covers hypothesis driven hunting, entity risk scores and retrohunts. Platform operations and data management are about 14% each, and observability is about 10%.

About the exam

The Professional Security Operations Engineer certification covers platform operations, data management, threat hunting, detection engineering, incident response and observability using Google Security Operations and Security Command Center. There are no prerequisites, though Google recommends three or more years of security experience including one or more using Google Cloud security tooling.

Exam domains

  • Platform operations: about 14%
  • Data management: about 14%
  • Threat hunting: about 19%
  • Detection engineering: about 22%
  • Incident response: about 21%
  • Observability: about 10%

50 to 60 multiple choice and multiple select questions, 120 minutes, US$200 per attempt, online proctored or at a test centre, valid for two years. Google does not publish a fixed passing score.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the Google Professional Security Operations Engineer pack?

133 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.