Skip to content

Data management Questions

Practice questions for Data management topic in Google Professional Security Operations Engineer. 28 questions covering this domain.

28 questions10 easy13 medium5 hard
Q1
hard

A parser extension extracts a value that does not fit any standard UDM field. Where should the engineer map it?

Q2
medium

A team creates a parser extension today and expects six months of previously ingested raw logs to be remapped automatically. What should the security ...

Q3
easy

A security engineering team has a custom application that must send telemetry directly into Google SecOps without deploying a forwarder. Which ingesti...

Q4
medium

Before validating a parser extension, what prerequisite must be met?

Q5
medium

Which statement about Google SecOps parser extensions is correct?

Q6
easy

What is the purpose of a parser extension in Google SecOps?

Q7
hard

Which statement best reflects the current Google SecOps guidance on reference lists?

Q8
medium

Which component is responsible for transforming raw vendor logs into Unified Data Model (UDM) records inside Google SecOps?

Q9
medium

Which approach should be used to send Google Cloud audit logs to Google SecOps for analysis?

Q10
medium

A security engineer needs to ingest logs in a vendor format that has no default Google SecOps parser. Which approach is recommended?

Q11
easy

Which Google SecOps ingestion component runs on customer infrastructure to collect logs from on-premises sources and forward them to the Google SecOps...

Q12
hard

A SOC must retain ingested raw logs in Google SecOps for 12 months for investigations while ensuring rules continue to function. Which configuration a...

Q13
easy

Which Google SecOps construct organizes events using a normalized schema with nouns such as principal, target, src, and observer?

Q14
medium

Which Google SecOps capability lets you maintain a curated list of values (such as IPs, domains, or hashes) referenced by rules without modifying rule...

Q15
medium

A Google SecOps engineer is building a custom parser for a new log source. The raw logs contain a field that maps to both a principal and a target IP ...

Q16
medium

A parsing engineer wants to add a new field extraction to an existing log type without touching the active parser code. The log type already has one p...

Q17
easy

When should a Google SecOps engineer use a CIDR-type reference list instead of a STRING-type reference list?

Q18
easy

A security engineer needs to assign a specific log type label to a new ingestion feed in Google SecOps so that the correct parser is applied to incomi...

Q19
hard

A security team ingests high volumes of noisy application debug logs that are not needed for threat detection and wants to reduce billed ingestion vol...

Q20
easy

A security engineer wants to ingest logs from a third-party firewall appliance into Google SecOps using a Pub/Sub topic. Which ingestion feed type sho...

Sign in to see all 28 questions

Create a free account to browse all questions — completely free during our launch phase.