You are a security operations engineer in an enterprise that uses Google Security Operations (SecOps). Your organization recently faced a cybersecurity breach. You need to increase the threat analytics as quickly as possible. What should you do?
A. Design YARA-L detection rules based on Google SecOps Marketplace use cases.
B. Develop YARA-L detection rules that focus on threat intelligence.
C. Enable curated detections to identify threats.
D. Ingest data from a threat intelligence platform (TIP) into Google SecOps.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
Your organization has recently onboarded to Google Cloud with Security Command Center Enterprise (SCCE) and is now integrating it with your organization's SOC. You want to automate the response process and integrate with the existing SOW ticketing system. How should you implement this functionality?
A. Disable the generic posture finding playbook in Google Security Operations (SecOps) SOAR and enable the playbook for the ticketing system. Add a step in your Google SecOps SOAR playbook to generate a ticket based on the event type.
B. Configure the SCC notifications feed to use Pub/Sub for alerts. Create a Cloud Run function to trigger when an event arrives in the topic and generate a ticket by calling the API endpoint in the SOC ticketing system.
C. Use the SCC notifications feed to send alerts to Pub/Sub. Ingest these feeds using the relevant SIEM connector.
D. Evaluate each event within the SCC console. Create a ticket for each finding in the ticketing system, and include the remediation steps.
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
Your company's Google Security Operations (SecOps) instance has three roles: Tier 1, Tier 2, and Tier 3. Currently, analysts in all tiers can access all cases in Google SecOps. Your company's SOC has a new requirement to restrict access to cases assigned to the Tier 3 role from the other tiers. You need to ensure cases that are assigned to the Tier 3 role can only be accessed by Tier 3 analysts. What should you do?
A. Assign the cases to a user in the Tier 3 role.
B. Configure the Cross Environment Policy to allow users to move cases between environments.
Move Tier 3 cases to an environment that only Tier 3 analysts can access.
C. Revoke additional role access from Tier 1 and Tier 2 analysts.
D. Instruct analysts in Tier 1 and Tier 2 to create a case queue filter to exclude cases assigned to the Tier 3 role.
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
You are an incident responder at your organization using Google Security Operations (SecOps) for monitonng and investigation. You discover that a critical production server, which handles financial transactions, shows signs of unauthorized file changes and network scanning from a suspicious IP address. You suspect that persistence mechanisms may have been installed. You need to use Google SecOps to immediately contain the threat while ensuring that forensic data remains available for investigation. What should you do first?
A. Use the EDR integration to quarantine the compromised asset.
B. Deploy emergency patches, and reboot the server to remove malicious persistence.
C. Use VirusTotal to enrich the IP address and retrieve the domain. Add the domain to the proxy block list.
D. Use the firewall integration to submit the IP address to a network block list to inhibit internet access from that machine.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
During a proactive threat hunting exercise, you discover that a critical production project has an external identity with a highly privileged IAM role. You suspect that this is part of a larger intrusion, and it is unknown how long this identity has had access. All logs are enabled and routed to a centralized organization-level Cloud Logging bucket, and historical logs have been exported to BigQuery datasets. You need to determine whether any actions were taken by this external identity in your environment. What should you do?
A. Use Policy Analyzer to identity the resources that are accessible by the external identity. Examine the logs related to these resources in the centralized Cloud Logging bucket and the BigQuery dataset.
B. Analyze VPC Flow Logs exported to BigQuery, and correlate source IP addresses with potential login events for the external identity.
C. Analyze IAM recommender insights and Security Command Center (SCC) findings associated with the external identity.
D. Execute queries against the centralized Cloud Logging bucket and the BigQuery dataset to filter for logs for where the principal email matches the external identity.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
Your company has deployed two on-premises firewalls. You need to configure the firewalls to send logs to Google Security Operations (SecOps) using Syslog. What should you do?
A. Pull the firewall logs by using a Google SecOps feed integration.
B. Set the Google SecOps URL instance as the Syslog destination.
C. Deploy a Google Ops Agent on your on-premises environment, and set the agent as the Syslog destination.
D. Deploy a third-party agent (e.g Bindplane, NXLog) on your on-premises environment, and set the agent as the Syslog destination.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
You are writing a detection rule in Google Security Operations (SecOps) SIEM that sends a risk score to the alert. You have access to Google Threat Intelligence (GTI) data through your Google SecOps subscription. You need to ensure that the threat score output in the detection logic informs the alert's risk score and is available for future detections. What should you do?
A. Configure a feed in Google SecOps SIEM to ingest GTI data to automatically enrich the appropriate entities.
B. Create a Google SecOps SOAR playbook to query GTI that uses the VirusTotal integration to enrich the alert. Modify the risk_score context value to match.
C. Use the match section of your detection logic to filter out irrelevant entities. Store the remaining entities as the risk_score variable.
D. Use the outcomes section of your detection logic to pull UDM enrichment fields from the event data. Apply logic to determine the total risk outcome, and store the risk score as the risk_score variable
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
1042 お客様のコメント





Ishii -
Professional-Machine-Learning-Engineer比較して検討したが、各問題について最も詳しく書かれており、問題も豊富なのでSecurity-Operations-Engineerひとつでも合格できそう。Googleの問題集はいつも信頼しています。