Google CloudProfessional

Professional Security Operations Engineer

PSOE

Detect, investigate and respond to threats using Google Security Operations (SecOps/Chronicle) and Google Cloud security tooling.

Duration
120 min
Exam questions
50–60
Passing score
Pass / Fail (undisclosed)
Exam fee
$200
Question formats:Multiple choiceMultiple response
Free plan
3 free papers
Free account
Mocks locked
Pro only
Upgrade to Pro
Every paper and mock exam.
See Pro

Start with free papers Free

You get 3 free practice papers with your plan.

Free
Mixed paper 1
Domain 1 · 25 questions
Free
Mixed paper 2
Domain 1 · 25 questions
Free
Mixed paper 3
Domain 1 · 25 questions

Domain papers 500 questions

Free
Mixed paper 1
25 questions · 60 min
Free
Mixed paper 2
25 questions · 60 min
Free
Mixed paper 3
25 questions · 60 min

Mock exams Pro

Full-length, exam-like practice tests. Available with Pro.

Mock exam 1
55 questions · 120 min
Mock exam 2
55 questions · 120 min
Mock exam 3
55 questions · 120 min

Try a sample question

All 10 sample questions →
Question 1Platform operations

Tarnwell Games protects its analytics datasets with a VPC Service Controls perimeter. After a contractor's laptop was compromised, the SOC wants Google Security Operations (formerly Chronicle) to show every request the perimeter blocked, so that repeated exfiltration attempts can be correlated with identity and endpoint telemetry. Direct ingestion still uses its default export filter. Which log source should you prioritize?

  1. A.

    VPC Flow Logs for the contractor subnets, which record connections to Google APIs.

  2. B.

    Policy Denied audit logs, added to the direct ingestion export filter for the organization.

  3. C.

    Admin Activity audit logs, which the default export filter already sends for every perimeter change.

  4. D.

    BigQuery Data Access audit logs, which record each query that runs against the protected datasets.

Show answer

Answer: B

Requests blocked by VPC Service Controls are written as Policy Denied audit logs, which direct ingestion into Google Security Operations (formerly Chronicle) supports but its default filter does not send.

  • A. Flow logs show addresses and ports; they carry no API method, resource or policy decision that shows what was blocked.
  • B. VPC Service Controls writes blocked requests to Policy Denied audit logs, a supported direct ingestion log that the default filter does not include.
  • C. Admin Activity logs record configuration changes such as edits to the perimeter, not the requests that the perimeter refused.
  • D. Perimeter refusals are written as Policy Denied entries, not Data Access entries, so this source misses the blocked attempts.

What's on the exam

6 domains · 13 task statements, straight from the official exam guide (as of 2026-09-14).

  1. 1.1Enhancing detection and response
    • Prioritizing telemetry sources (e.g., Security Command Center [SCC], Google Security Operations [SecOps], GTI, Cloud IDS) to detect incidents or misconfigurations within an enterprise environment
    • Integrating multiple tools (e.g., SCC, Google SecOps, GTI, Cloud IDS, downstream third-party system) in the security architecture to enhance detection capabilities
    • Justifying the use of tools with overlapping capabilities based on a set of requirements
    • Evaluating the effectiveness of existing tools to identify gaps in coverage and mitigate potential threats
    • Evaluating automation and cloud-based tools to enhance existing detection and response processes
  2. 1.2Configuring access
    • Configuring user and service account authentication to security tools (e.g., SCC, Google SecOps)
    • Configuring user and service account authorization for feature access using IAM roles and permissions
    • Configuring user and service account authorization for data access using IAM roles and permissions
    • Configuring and analyzing audit logs (e.g., Cloud Audit Logs, data access logs) for the solution
    • Configuring API access for automations within security tools (e.g., service accounts, API keys, SCC, Google SecOps, GTI)
    • Provisioning identities using Workforce Identity Federation

Outline reproduced from the vendor's public exam guide for study reference.Official guide

PSOE practice — frequently asked questions

Are these real PSOE exam questions?

No. Every question on CertifyCloudx is original, written by us against Google Cloud's publicly available PSOE exam guide to rehearse the skills it lists. None are actual exam questions, and CertifyCloudx is not affiliated with or endorsed by Google Cloud.

How many PSOE practice questions are there?

500 practice questions, including 3 full-length timed mock exams and 46 domain papers of up to 25 questions (mixed and by topic). Every question has a detailed explanation of why the right answer wins and why each distractor loses.

Is the content up to date with the current PSOE exam guide?

The questions are written against the PSOE exam guide dated 2026-09-14, and we revise them when Google Cloud updates the guide.

What question formats are covered?

The same formats the real PSOE uses: Multiple choice, Multiple response. Each is rendered and graded the way the exam does it.

How long is the PSOE exam and how many questions does it have?

According to Google Cloud's published exam details: 50–60 questions, 120 minutes, passing score Pass / Fail (undisclosed). Our mock exams use the same time limit, with a question count in the middle of that range. Always confirm current details with Google Cloud before booking.

Can I practise PSOE for free?

Yes. 3 papers are free, with up to 10 questions a day on the free plan and no card needed. Pro unlocks every paper and mock exam with no daily limit.

Does CertifyCloudx guarantee that I will pass?

No practice material can guarantee a result. CertifyCloudx helps you find and close your weak areas — accuracy by exam-guide domain and topic shows what to study next.