PSOE Practice Exam: Professional Security Operations Engineer
SecOps on GCP: Chronicle, detection rules, incident response, and hunting threats before lunch.
What you'll be tested on
- Threat Detection
- Incident Response
- SIEM and SOAR
- Vulnerability Management
- Cloud Security Posture
Sample PSOE questions
You are responsible for identifying suspicious activity and security events at your organization. You have been asked to search in Google Security Operations (SecOps) for network traffic associated with an active HTTP backdoor that runs on TCP port 5555. You want to use the most effective approach to identify traffic originating from the server that is running the backdoor. What should you do?
- Detect on events where network.ApplicationProtocol is HTTP.
- Detect on events where target.port is 5555.
- Detect on events where principal.port is 5555.
- Detect on events where network.ip_protocol is TCP.
Show answer
C — Detect on events where principal.port is 5555.In UDM, the principal is the entity that originates an event, while the target is the entity it connects to. Since the goal is to identify traffic originating from the server running the backdoor listening on TCP 5555, you should match events where principal.port is 5555, meaning connections leaving from that server's backdoor port. Matching target.port 5555 would show inbound connections to the backdoor, not traffic sourced from it. Filtering only on HTTP application protocol or TCP protocol is far too broad and would generate massive noise without tying traffic to the backdoor.
You are an incident responder at your organization using Google Security Operations (SecOps) for monitonng and investigation. You discover that a critical production server, which handles financial transactions, shows signs of unauthorized file changes and network scanning from a suspicious IP address. You suspect that persistence mechanisms may have been installed. You need to use Google SecOps to immediately contain the threat while ensuring that forensic data remains available for investigation. What should you do first?
- Use the firewall integration to submit the IP address to a network block list to inhibit internet access from that machine.
- Deploy emergency patches, and reboot the server to remove malicious persistence.
- Use the EDR integration to quarantine the compromised asset.
- Use VirusTotal to enrich the IP address and retrieve the domain. Add the domain to the proxy block list.
Show answer
C — Use the EDR integration to quarantine the compromised asset.The first priority is containment that preserves forensic evidence. Using the EDR integration in Google SecOps to quarantine the compromised asset isolates it from the network immediately, stopping attacker lateral movement and C2 traffic while keeping the disk, memory, and persistence artifacts intact for later forensic analysis. Rebooting and patching destroys volatile forensic data such as memory-resident malware and active sessions. Blocking the suspicious IP at the firewall or proxy only limits one indicator and does not contain the already compromised host itself. Quarantine first, then investigate.
Your organization uses Google Security Operations (SecOps). You discover frequent file downloads from a shared workspace within a short time window. You need to configure a rule in Google SecOps that identifies these suspicious events and assigns higher risk scores to repeated anomalies. What should you do?
- Configure a rule that flags file download events with the highest risk score, regardless of time frame.
- Create a frequency-based YARA-L detection rule that assigns a risk outcome score and is triggered when multiple suspicious downloads occur within a defined time frame.
- Configure a single-event YARA-L detection rule that assigns a risk outcome score and is triggered when a user downloads a large number of files in 24 hours.
- Enable default curated detections, and use automatic alerting for single file download events.
Show answer
B — Create a frequency-based YARA-L detection rule that assigns a risk outcome score and is triggered when multiple suspicious downloads occur within a defined time frame.The requirement is to detect repeated download activity within a short time window and score repeated anomalies higher. A frequency-based (multi-event) YARA-L rule uses a match section to group events over a defined window and a condition requiring multiple downloads, while the outcome section assigns a risk score. Option A ignores the time-frame requirement. Option C describes a single-event rule with a 24-hour window, which neither matches the short time frame nor the repeated-frequency logic. Option D relies on generic curated detections for single events, which does not meet the aggregation and scoring requirement.
Access plans
| Access | Price |
|---|---|
| 3 months | |
| 1 year | |
| Lifetime |
Free preview inside — try 5 questions before you pay anything.
FAQ
How many practice questions are in this PSOE bank?
133 questions covering the current PSOE Professional Security Operations Engineer syllabus, every one with the correct answer and an explanation.How long is the real PSOE exam?
The official PSOE exam gives you 120 minutes. Our timed exam mode uses the same limit so the pace feels familiar.What does PSOE access cost?
Plans start at $3.99 for 3 months. One payment, no subscription — and far cheaper than retaking the real exam.