About the Exam

This Google Cloud certification is for security professionals who detect, monitor, analyze, investigate, and respond to threats against workloads, endpoints, and infrastructure. The exam covers platform operations, data management, threat hunting, detection engineering, incident response, and observability. Passing demonstrates hands-on ability to use Google Cloud security resources and tooling for detection and response in an enterprise environment.

Exam Topics

  • Platform operations14%
  • Data management14%
  • Threat hunting19%
  • Detection engineering22%
  • Incident response21%
  • Observability10%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated March 19, 2026 at 11:29 PM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Observability

You work for a large international company with several Compute Engine instances running in production. You must configure monitoring and alerting for Compute Engine instances that are tagged compliance=pci and have an external IP address assigned. What should you do?

Explanation

The built-in Security Health Analytics PUBLIC_IP_ADDRESS detector generates a finding when a Compute Engine instance has a public IP address. The affected instances can be checked for the compliance=pci tag so that monitoring and alerting apply to the required subset without creating a redundant custom detector.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Incident response

The organization requires that the SOC director be notified by email about escalated incidents and their results before a case is closed. You need to create a process that automatically sends this email when an escalated case is closed. You must ensure that the email is sent reliably for the appropriate cases. Which process should you use?

Explanation

Cortex XSOAR playbooks automate security workflows, and conditional tasks direct the workflow based on field values or parameters. A conditional branch can check the escalation status, send the director an email containing the relevant notes for escalated cases, and close cases without that email when they were not escalated. This makes notification part of the controlled closure workflow.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Data management

You work for a telecommunications company that needs to monitor logs from its multi-region 5G network in Google Security Operations (SecOps). The logs are currently available only on-premises and reside on standalone network-attached storage (NAS) in four different regions. You need to ingest these logs into Google SecOps and tag each NAS as a distinct log source to prevent IP address aliasing. What should you do?

Explanation

Bindplane agents collect and send on-premises telemetry, including Syslog, to Google SecOps. A namespace identifies assets from separate network environments and deconflicts overlapping IP addresses; ingestion labels instead provide metadata for identifying or filtering log streams.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Threat hunting

You received an IOC from your threat-intelligence feed that is identified as a suspicious domain used for command and control (C2). You want to use Google Security Operations (SecOps) to investigate whether this domain has appeared in your environment. You want to search for this IOC using the most efficient approach. What should you do?

Explanation

A UDM search limited to the DNS portion of the network event data directly examines normalized DNS telemetry for the domain, avoiding the unnecessary breadth of a raw-log string search. Google SecOps supports searches over normalized UDM events and provides domain-focused investigation capabilities for determining whether a domain is present in enterprise data.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Data management

You manage the integration of Security Command Center (SCC) with downstream tooling. You need to retrieve security findings from SCC and import those findings as part of Google Security Operations (SecOps) SOAR actions. You must configure the connection between SCC and Google SecOps. What should you do?

Explanation

Google SecOps SOAR provides a Google Security Command Center Marketplace integration and a Findings connector for retrieving SCC findings and using them in SOAR alerts and actions. The supported integration requires appropriate IAM-authorized service-account or Workload Identity access to SCC. Pub/Sub notification configurations are not the primary SOAR Marketplace-connector configuration described for pulling findings into SOAR.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home