Google GCP-SOE-B 考試概覽:
| 認證廠商: | |
|---|---|
| 考試名稱: | 安全營運工程師 (Beta) |
| 考試代碼: | GCP-SOE-B |
| 相關認證: | Google Cloud Security Engineer Google Cloud Professional Cloud Security Engineer |
| 支援語言: | English |
| 實際考試題數: | 84-87 |
| 考試時間: | 180 分鐘 |
| 考試形式: | 複選題, 單選題, 情境題 |
| 考試費用: | 120美元 (Beta 優惠價,原價200美元的6折) |
| 證照有效期限: | 2年 |
| 及格分數: | 70% |
| 推薦課程: | 專業安全營運工程師考試指南 Google Cloud 安全營運學習路徑 |
| 考試報名: | Google Cloud 認證報名 |
| 範例考題: | Google GCP-SOE-B 範例考題 |
| 考試方式: | 線上遠端監考或實體考試中心應考 |
| 必備條件: | 建議條件:具備3年以上資安產業經驗、1年以上 Google Cloud 資安工具實務操作經驗;無強制先備條件 |
| 官方大綱網址: | https://cloud.google.com/learn/certification/security-operations-engineer |
Google GCP-SOE-B 考試大綱主題:
| 章節 | 權重 | 目標 |
|---|---|---|
| 事件回應 | 18% | - 協調與自動化回應動作 - 進行鑑識分析與根本原因判定 - 記錄事件並支援復原作業 - 分類、排定優先順序與調查安全警示 |
| 可觀測性與報告 | 8% | - 監控平台健康狀態與效能 - 產生法規遵循與營運報告 - 建置安全態勢儀表板與指標 |
| 威脅狩獵 | 18% | - 運用威脅情資辨識異常與威脅 - 記錄與回報狩獵發現 - 有效運用 UDM 搜尋與查詢語言 - 設計與執行威脅狩獵方法 |
| 平台營運 | 14% | - 管理 Google Threat Intelligence (GTI) 整合 - 管理 Google Security Operations (SecOps) 平台設定 - 設定與管理 Security Command Center (SCC) 資源 |
| 偵測工程 | 20% | - 實作自動化偵測工作流程 - 將偵測結果與警示及個案管理整合 - 驗證與調整偵測邏輯以降低誤判 - 開發與維護偵測規則 (YARA-L、Sigma) |
| 資料管理 | 22% | - 管理資料保留、儲存與存取原則 - 將資料標準化並對應至 Unified Data Model (UDM) - 最佳化日誌與事件資料以利分析 - 規劃與實作資料擷取管線 |
最新的 Google Cloud Certified GCP-SOE-B 免費考試真題:
問題 #1
You have identified a new threat actor group that has several IOCs in Google Threat Intelligence. You want to use some of these IOCs in several detection rules in Google Security Operations (SecOps) to help identify suspicious activity. You want to use the most effective approach. What should you do?
A. Identify the detection rules that apply to the new IOCS, and update the YARA-L logic to reference the threat actor group.
B. Save the IOCs in a new collection in Google Threat Intelligence. Share this list with other members of the security team to facilitate their searches and rule creation.
C. Add the IOCs to a new or existing reference list, and update the YARA-L logic of detection rules to include the reference list.
D. Configure a new data feed in Google SecOps that includes the IOCS. Update the YARA-L logic to reference the new IOCS against applicable UDM fields.
問題 #2
You are responsible for developing and configuring data ingestion in Google Security Operations (SecOps) for your organization. Your organization is using a prebuilt parser to parse a complex but stable and common log source. The parser is working correctly. However, your organization now wants you to change the configuration to parse additional fields from the raw logs and map them to UDM fields. What should you do?
A. Apply any pending updates to the prebuilt parser.
B. Implement middleware to modify the underlying data structure.
C. Design and develop a custom parser.
D. Implement a parser extension on top of the prebuilt parser.
問題 #3
You are an incident responder at your organization using Google Security Operations (SecOps) for monitonng and investigation. You discover that a critical production server, which handles financial transactions, shows signs of unauthorized file changes and network scanning from a suspicious IP address. You suspect that persistence mechanisms may have been installed. You need to use Google SecOps to immediately contain the threat while ensuring that forensic data remains available for investigation. What should you do first?
A. Use the firewall integration to submit the IP address to a network block list to inhibit internet access from that machine.
B. Use the EDR integration to quarantine the compromised asset.
C. Deploy emergency patches, and reboot the server to remove malicious persistence.
D. Use VirusTotal to enrich the IP address and retrieve the domain. Add the domain to the proxy block list.
問題 #4
Your Google Security Operations (SecOps) SOAR integration with Security Command Center (SCC) uses a service account that currently has read access to the findings at the organization level. Google SecOps SOAR successfully reads SCC finding data, but actions attempting to update the finding states consistently fail with a permission denied error. You need to resolve this error while following the principle of least privilege. What should you do?
A. Grant the service account the roles/iam.serviceAccountUser IAM role to itself.
B. Grant the service account the roles/securitycenter.findings Editor IAM role at the organization level.
C. Regenerate the service account key, and update the credentials in Google SecOps SOAR.
D. Grant the service account the roles/securitycenter.findingsBulkMuteEditor IAM role at the organization level.
問題 #5
You work for a telecommunications company that wants to monitor their multi-region 5G network logs in Google Security Operations (SecOps). The logs are currently only available on- premises and are stored in a standalone network-attached storage (NAS) located in four different regions.
You need to ingest the logs into Google SecOps and tag each NAS as a specific log source to avoid IP address aliasing. What should you do?
A. Configure feed management to pull data from each log's location, and configure a namespace for each log source.
B. Configure feed management to pull data from each log's location, and configure an ingestion label for each log source.
C. Configure a Bindplane agent that collects Syslog from each log's location and configure an ingestion label for each log source.
D. Configure a Bindplane agent that collects Syslog from each log's location, and configure a namespace for each log source.
問題與答案:
| 問題 #1 答案: C | 問題 #2 答案: D | 問題 #3 答案: B | 問題 #4 答案: B | 問題 #5 答案: B |

下載最新試用版
916位客戶反饋
我們對我們的產品非常有信心,所以我們不提供会给客户带去麻煩的產品。








1.162.41.* -
你們的GCP-SOE-B題庫很不錯,覆蓋了考試中95%的問題。