PSOE sample questions with answers

10 free practice questions for the Professional Security Operations Engineer exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Platform operations

Tarnwell Games protects its analytics datasets with a VPC Service Controls perimeter. After a contractor's laptop was compromised, the SOC wants Google Security Operations (formerly Chronicle) to show every request the perimeter blocked, so that repeated exfiltration attempts can be correlated with identity and endpoint telemetry. Direct ingestion still uses its default export filter. Which log source should you prioritize?

  1. A.

    VPC Flow Logs for the contractor subnets, which record connections to Google APIs.

  2. B.

    Policy Denied audit logs, added to the direct ingestion export filter for the organization.

  3. C.

    Admin Activity audit logs, which the default export filter already sends for every perimeter change.

  4. D.

    BigQuery Data Access audit logs, which record each query that runs against the protected datasets.

Show answer

Answer: B

Requests blocked by VPC Service Controls are written as Policy Denied audit logs, which direct ingestion into Google Security Operations (formerly Chronicle) supports but its default filter does not send.

  • A. Flow logs show addresses and ports; they carry no API method, resource or policy decision that shows what was blocked.
  • B. VPC Service Controls writes blocked requests to Policy Denied audit logs, a supported direct ingestion log that the default filter does not include.
  • C. Admin Activity logs record configuration changes such as edits to the perimeter, not the requests that the perimeter refused.
  • D. Perimeter refusals are written as Policy Denied entries, not Data Access entries, so this source misses the blocked attempts.
Question 2Platform operations

During 2026 budget planning, a consultant urges Ashby Foods to activate Security Command Center Enterprise, arguing that its bundled Google Security Operations (formerly Chronicle) features make a separate SIEM unnecessary. The SOC needs twelve months of searchable history, multi-event correlation rules, and ingestion of on-premises firewall and endpoint logs. What should you recommend?

  1. A.

    Activate the Enterprise tier now and plan to migrate once the SOC outgrows its bundled SIEM limits.

  2. B.

    Activate the Enterprise tier, because its SecOps features include full SIEM retention and correlation.

  3. C.

    Activate Security Command Center Standard and forward its findings to the on-premises firewall.

  4. D.

    Activate Security Command Center Premium and a Google SecOps package, not the deprecated Enterprise tier.

Show answer

Answer: D

Security Command Center Enterprise is deprecated with a May 21, 2027 shutdown and its bundled Google Security Operations (formerly Chronicle) features cannot meet the requirements, so a Premium activation plus a full Google SecOps package is the justified choice.

  • A. This commits to a tier that shuts down on May 21, 2027 and already fails the stated retention, correlation and on-premises requirements.
  • B. Enterprise's SecOps features are limited to cloud data only, three months of retention and 20 single-event custom rules, and the tier itself is deprecated.
  • C. Standard offers basic posture only, and a firewall is not a place to search, correlate or retain security telemetry.
  • D. The Enterprise tier is deprecated and shuts down on May 21, 2027, and its bundled SecOps features are limited to cloud data, three months of retention and single-event rules.
Question 3Platform operations

An investigator at Hartfell Media holds the Editor and Logs Viewer roles on the Google Security Operations (formerly Chronicle) bound project. In Logs Explorer she can see Admin Activity entries for rule changes, but no data_access entries for searches, even though a colleague with more access sees them in the same project. What should you grant her?

  1. A.

    The Private Logs Viewer role on the project, which can read Data Access audit logs.

  2. B.

    The Owner role on the project, because only Owner can read Data Access entries.

  3. C.

    Access to a log sink that copies Data Access entries into a separate BigQuery dataset.

  4. D.

    The Chronicle API Admin role, which allows reading every audit log the instance writes.

Show answer

Answer: A

Data Access audit logs require the Private Logs Viewer role to read; Editor and Logs Viewer do not include that permission.

  • A. Reading Data Access audit logs in the _Default bucket needs Private Logs Viewer; neither Editor nor Logs Viewer includes that permission.
  • B. Owner is far broader than needed; Private Logs Viewer is the role designed for reading these logs.
  • C. A sink duplicates data and adds cost; the investigator only lacks permission to read the logs that already exist.
  • D. Chronicle roles control Google SecOps features; they do not grant access to Data Access audit logs in Cloud Logging.
Question 4Platform operations

Heron Bay Bank finished configuring Workforce Identity Federation and single sign-on for Google Security Operations (formerly Chronicle). Analysts in the soc-analysts identity provider group authenticate successfully but are then refused access to the application. The group is already mapped on the SOAR side. The SecOps-bound project's IAM policy has no binding for the group. What should you do?

  1. A.

    Recreate the workforce provider with a new metadata file, because the assertion must be invalid.

  2. B.

    Grant the IAM Workforce Pool Admin role so the analysts can manage their own pool membership.

  3. C.

    Grant the basic Viewer role to the group at the organization so it inherits access everywhere.

  4. D.

    Grant the Chronicle API Viewer role to the group's principal set on the SecOps-bound project.

Show answer

Answer: D

Authentication succeeded, so the missing piece is authorization: the group needs a role such as Chronicle API Viewer on the project bound to Google Security Operations (formerly Chronicle).

  • A. Authentication already succeeds, so the assertion is valid; the failure happens at authorization, not at the provider.
  • B. Pool administration permissions manage the federation configuration; they do not authorize use of the Google SecOps application.
  • C. The basic Viewer role contains no Chronicle permissions, and granting broad organization-wide access violates least privilege.
  • D. Access to the Google SecOps application requires a Chronicle role such as Chronicle API Viewer on the bound project; without any binding, authenticated users are refused.
Question 5Platform operations

Most analysts at Quillon Media are new to the Unified Data Model and struggle to write searches, so investigations wait for two senior engineers. The company uses the Google Security Operations (formerly Chronicle) Enterprise package. The manager wants analysts to describe what they are looking for in plain language and get a runnable search. Which capability should you enable?

  1. A.

    A reference list of common field names that analysts copy into their searches.

  2. B.

    Saved searches written by the senior engineers and shared with the rest of the team.

  3. C.

    Raw log search, which accepts free text and does not require any UDM field names.

  4. D.

    Gemini in Google SecOps, which generates UDM searches from natural language prompts.

Show answer

Answer: D

Gemini in Google Security Operations (formerly Chronicle) generates and refines UDM searches from natural language, which removes the syntax barrier for new analysts, and it is included in the Enterprise package.

  • A. A list of field names still requires analysts to write correct query syntax and logic themselves.
  • B. Saved searches help only with questions the seniors anticipated; they do not translate new questions into searches.
  • C. Raw log search matches strings in unparsed logs; it does not interpret intent or produce a structured UDM search.
  • D. Gemini in Google SecOps builds, edits and runs searches from natural language prompts, and it is included in the Enterprise package.
Question 6Platform operations

Engineers at Brisk Couriers run customer-facing services on Google Kubernetes Engine nodes that use Container-Optimized OS. A red-team report shows that a reverse shell started inside a running container went unnoticed, because the SOC watches only GKE audit logs and VPC Flow Logs. Security Command Center Premium is active. Which source should you prioritize for container runtime attacks?

  1. A.

    Container Threat Detection findings, which observe runtime behaviour inside the containers on the nodes.

  2. B.

    Security Health Analytics findings for the clusters' node pools and their configuration.

  3. C.

    GKE control-plane audit logs with Data Access logging enabled for every cluster in the fleet.

  4. D.

    VPC Flow Logs at full sampling so that every outbound connection from a node is recorded.

Show answer

Answer: A

Runtime attacks inside containers need runtime telemetry, and Container Threat Detection supplies it for Container-Optimized OS nodes.

  • A. Container Threat Detection monitors Container-Optimized OS node images for runtime attacks such as reverse shells and unexpected binaries, which audit and flow logs cannot see.
  • B. Security Health Analytics reports configuration weaknesses; it does not observe processes executing inside running containers.
  • C. Audit logs record calls to the Kubernetes API; a shell spawned inside an already running container makes no control-plane call.
  • D. Flow logs show that a connection happened but not which process inside which container opened it, and a reverse shell can mimic normal traffic.
Question 7Platform operations

Bramhope Energy's SOC is evaluating the Gemini Summary widget in Google Security Operations (formerly Chronicle) to speed up triage. During incident peaks it opens about 300 cases an hour, and many cases are created manually or from Your Workdesk requests. The lead asks whether every case will get an AI summary. What should you tell the lead?

  1. A.

    Yes; the widget summarizes every case immediately, whatever its source and however many arrive.

  2. B.

    No; it handles about two cases a minute, at most 100 an hour, and skips manual and request cases.

  3. C.

    No; the widget works only for cases that contain a single alert, so grouped cases are skipped.

  4. D.

    Yes, as long as each case carries the enrichment that a SOAR playbook adds before the summary.

Show answer

Answer: B

The Gemini Summary widget has throughput limits of about two cases per minute and 100 per hour and does not appear on manually created or request cases, so not every case gets a summary.

  • A. Documented throughput limits and case-type exclusions mean some cases will not receive a summary.
  • B. The widget supports about two cases per minute, with a maximum of 100 per hour, and isn't displayed for manually created or request cases.
  • C. The widget also appears for multi-alert cases; single-alert cases simply require opening the Case Overview tab.
  • D. Enrichment improves summary content but does not lift the throughput limits or the manual and request case exclusions.
Question 8Platform operations

Auditors at Maybury Health require that a departing analyst lose access to Google Security Operations (formerly Chronicle) as soon as HR terminates them in the corporate identity provider. Sign-in uses Workforce Identity Federation. An engineer proposes building a nightly job that deletes the analyst's Google account, or adopting SCIM to deprovision it. What should you recommend?

  1. A.

    Disable the user in the IdP; federation stores no Google account that must be deleted.

  2. B.

    Remove the analyst's role bindings from IAM by hand as part of every leaver ticket.

  3. C.

    Build the nightly job to delete the analyst's Google account after each termination.

  4. D.

    Configure SCIM on the workforce pool so terminations are pushed to Google SecOps immediately.

Show answer

Answer: A

Workforce Identity Federation is sync-less, so disabling the user in the identity provider removes access with no Google account to deprovision.

  • A. Workforce Identity Federation is sync-less, so disabling the user at the identity provider stops new sign-ins with no Google account to remove.
  • B. With group-based bindings there are usually no per-user bindings to remove, and manual steps are the slow path auditors worry about.
  • C. Federated users have no Google account to delete, and a nightly job would add up to a day of delay.
  • D. SCIM support for Workforce Identity Federation applies only to Gemini Enterprise, not to Google SecOps.
Question 9Platform operations

A platform engineer at Wendover Health granted a detection engineer the Chronicle API Editor role on the organization's shared security-tools project, where the team keeps its scripts and dashboards. The engineer still cannot create detection rules in Google Security Operations (formerly Chronicle). The instance is bound to a different project called secops-prod. What should you do?

  1. A.

    Grant the role at the organization so that every project, including secops-prod, inherits it.

  2. B.

    Enable the Chronicle API in the security-tools project so the existing grant takes effect.

  3. C.

    Add the engineer to the SOAR Group Mapping page with an administrator permission group.

  4. D.

    Grant the Chronicle API Editor role on the secops-prod project, which is bound to the instance.

Show answer

Answer: D

Feature roles must be granted on the Google Cloud project bound to the Google Security Operations (formerly Chronicle) instance; a grant on another project has no effect.

  • A. An organization-level grant would reach secops-prod but gives the role in every project, far more than the job needs.
  • B. Enabling the API in an unrelated project does not bind it to the instance; the grant is still on the wrong resource.
  • C. SOAR group mapping governs SOAR-side access such as cases and environments, not rule management in the SIEM.
  • D. Google SecOps checks IAM policies on the project bound to the instance, and Google recommends defining them there at the project level.
Question 10Platform operations

Northgate Clinics licenses Google Threat Intelligence and wants every SOAR playbook in Google Security Operations (formerly Chronicle) to enrich hashes, domains and addresses with it, and to let analysts submit suspicious files for private analysis from a case. Engineers ask what must be configured before playbooks can call it. What should you do first?

  1. A.

    Enable Applied Threat Intelligence curated detections for all rule sets in the Google SecOps instance.

  2. B.

    Grant the SOAR service agent the Chronicle API Viewer role on the Google SecOps project.

  3. C.

    Configure a Google Threat Intelligence integration instance with the organization's API key.

  4. D.

    Create a reference list of Google Threat Intelligence indicators and look entities up against it.

Show answer

Answer: C

Playbooks call Google Threat Intelligence through its response integration, which must first be configured as an instance with the organization's API key.

  • A. Applied Threat Intelligence matches telemetry in the SIEM; it does not provide SOAR playbook actions for enrichment or file submission.
  • B. An IAM role for the service agent does not authenticate calls to Google Threat Intelligence, which the integration authenticates with its own API key.
  • C. The Google Threat Intelligence integration requires an API key and API root; once an instance is configured, its actions can be used in playbooks and manual actions.
  • D. A static list cannot provide on-demand context or private file submission and would be stale as soon as it was created.

Keep going with 490 more PSOE questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

PSOE sample questions with answers (10 free) · CertifyCloudx