Be able to design detection and response pipelines: route findings and logs to the right destination, automate quarantine actions, and enforce admission policies. The most important thing is knowing which Google Cloud mechanism delivers events reliably without losing data.
Start practicing
Managing Operations in a Cloud Solution Environment — choose a session length
Free · No account required
Domain overview
This domain covers operating security in Google Cloud: Security Command Center findings and automation, Cloud Logging and log sinks, Chronicle SIEM, and admission control for GKE. Questions present operational scenarios and ask you to choose the correct Google Cloud service, integration, or configuration to detect, route, or respond to security events.
Exam objectives
Configuring Security Command Center findings and Pub/Sub notifications to trigger Cloud Functions or Cloud Run responses
Building log sinks and Log Router exports to Pub/Sub, Cloud Storage, or BigQuery for SIEM ingestion
Using Binary Authorization with Cloud KMS attestations to enforce signed container images at GKE admission
Writing Chronicle SIEM rules and YARA-L detections over aggregated GCP and on-premises log sources
Assuming Cloud Audit Logs are retained indefinitely; default retention is limited, so export sinks are needed for long-term SIEM storage
Confusing Security Command Center notification configs with log sinks; SCC findings require Pub/Sub notification configs, not Log Router sinks
Believing GKE admission control enforces image signing by default; Binary Authorization must be explicitly enabled on the cluster
Click any question to see the full explanation and answer options, or start a focused practice session above.
A company wants to receive real-time notifications when Security Command Center (SCC) detects a high-severity vulnerability in their Google Cloud projects. They need to integrate with their existing SIEM. Which approach should they use?
2A DevOps team is implementing Binary Authorization for a GKE cluster. They want to ensure that only container images signed by a specific attestor can be deployed. They have created the attestor and configured Cloud KMS for signing. Which additional step is required to enforce the policy?
3A company is using Security Command Center (SCC) Standard tier and wants to detect threats like crypto mining attacks and anomalous IAM activity in their GCP environment. Which built-in service should they enable?
4An organization uses Chronicle SIEM to ingest logs from multiple GCP projects and on-premises firewalls. They need to write a detection rule that triggers when an IP address makes more than 100 failed login attempts across different GCP projects within 10 minutes. Which Chronicle feature should they use?
5A company wants to scan all container images stored in Artifact Registry for vulnerabilities before deployment. Which Google Cloud service should they use?
6Which Security Command Center (SCC) tier provides built-in compliance monitoring for standards like CIS and PCI DSS?
7A company is using Security Command Center (SCC) Premium tier and wants to automatically remediate certain high-severity findings. Which two services can be used together to achieve this? (Choose two.)
8A security team needs to detect anomalous outbound traffic from Compute Engine instances. They want to enable logging and analyze the data. Which three steps should they take? (Choose three.)
9A company wants to implement a vulnerability management program for their Google Cloud environment. They need to scan Compute Engine instances for OS vulnerabilities and container images for known vulnerabilities. Which two services should they use? (Choose two.)
10Your organization wants to monitor and audit IAM permission changes in real time. Which type of Cloud Audit Log is enabled by default and cannot be disabled?
11A security engineer wants to export Cloud Audit Logs to a third-party SIEM in real time. Which log sink destination should they configure?
12An organization uses Security Command Center Premium tier. They want to receive notifications when a finding of type 'Cryptomining' is detected in their Compute Engine instances. What should they configure?
13Which Security Command Center tier includes Event Threat Detection and Container Threat Detection?
14An organization uses Binary Authorization with multiple attestors. They want to allow a deployment only if at least two attestors have signed the image. Which policy type should be used?
15A security engineer needs to automatically remediate a high-severity finding in Security Command Center. The remediation involves restarting a Compute Engine instance. What is the recommended approach?
16Which Google Cloud service should be used for long-term archival of Audit Logs that must be immutable and stored for 10 years for compliance?
17An organization wants to use Chronicle for SIEM. They need to ingest logs from an on-premises firewall. Which method should they use?
18A security engineer wants to review all IAM permission changes made in the last 30 days. Which type of Cloud Audit Log should they query?
19A company uses Security Command Center (SCC) Premium tier and wants to automatically trigger a Cloud Function to remediate a threat finding. Which approach should they use?
20A security engineer needs to archive Cloud Audit Logs for regulatory compliance for 7 years. The logs should be immutable and cost-effective. Which solution should they choose?
21Which Security Command Center tier provides Event Threat Detection and Container Threat Detection?
22A security team wants to analyze VPC Flow Logs for potential data exfiltration. They need a solution that allows querying with SQL and requires minimal setup. Which approach should they take?
23An organization needs to scan container images stored in Artifact Registry for vulnerabilities before deployment. They want to use a managed service that integrates with their CI/CD pipeline. Which Google Cloud service should they use?
24A company wants to use Chronicle to ingest logs from their on-premises firewalls into Google Cloud. They need to normalize logs into a common schema for analysis. Which Chronicle capability should they use?
25Which type of Cloud Audit Logs must be explicitly enabled and incur additional cost?
26A security engineer needs to implement a logging pipeline that sends real-time Cloud Audit Logs to a third-party SIEM. They must ensure that if the SIEM is unavailable, logs are not lost. Which approach should they use?
27An organization wants to use Security Command Center to detect misconfigurations in their Google Cloud resources. They need a service that can automatically check for common security issues like open firewall ports and IAM policy violations. Which SCC feature should they enable?
28An incident responder needs to collect forensic evidence from a compromised Compute Engine instance for later analysis. They want to preserve disk state and network logs. Which THREE actions should they take?
29A security engineer wants to monitor all actions that create or modify resources in a Google Cloud project. Which type of audit log is enabled by default and cannot be disabled?
30An organization wants to enforce that all container images deployed to a GKE cluster must be signed by an approved authority. They have set up Binary Authorization with a policy that requires attestation. Where should the signing key be stored to meet security best practices?
31Which Google Cloud SIEM solution ingests logs from various sources, normalizes them into the Unified Data Model (UDM), and allows detection using YARA-L rules?
32A security team needs to automatically respond to high-severity vulnerability findings in Security Command Center. They want to trigger a Cloud Function that quarantines the affected VM. What is the recommended way to connect SCC findings to Cloud Functions?
33During a security incident, a forensic investigator needs to analyze a compromised Compute Engine instance without affecting the live environment. The instance has persistent disks with critical data. What is the best first step to preserve evidence?
34A company uses Chronicle as their SIEM. They need to ingest logs from an on-premises firewall that does not support direct integration with Chronicle. What is the recommended approach to ingest these logs?
35An organization wants to detect and respond to potential data exfiltration attempts via VPC Flow Logs. They plan to export VPC Flow Logs to BigQuery for analysis. Which TWO actions should they take to enable this? (Choose TWO.)
36A company wants to ensure compliance with PCI DSS by monitoring access to BigQuery datasets containing sensitive data. They need to log all read operations and enable real-time alerting for anomalous access. Which TWO actions should they take? (Choose TWO.)
37Your company uses Security Command Center (SCC) Standard tier and wants to detect threats like cryptocurrency mining or anomalous network behavior in real-time. You need to recommend an upgrade to SCC Premium tier and configure the appropriate module. Which SCC Premium module should be enabled?
38A DevOps team wants to enforce that only container images signed by a specific authority can be deployed in a GKE cluster. They plan to use Binary Authorization. Which configuration is required?
39Your organization wants to use Chronicle SIEM to analyze security events from both Google Cloud and on-premises firewalls. They want to normalize firewall logs into a common schema. Which Chronicle feature should they use?
40A company needs to archive Cloud Audit Logs for compliance purposes for 7 years. The logs are rarely accessed after the first year. Which storage option is the most cost-effective?
41You need to configure automated remediation for high-severity SCC findings. When a finding of type 'VULNERABILITY' with severity 'HIGH' is created, a Cloud Function should execute a script to patch the vulnerable VM. Which architecture is correct?
42A security team wants to use Web Security Scanner to find vulnerabilities in their web application hosted on Compute Engine. They need to scan the public-facing URL weekly and receive a report of findings. Which configuration is required?
43A security analyst needs to mute a recurring false positive finding in Security Command Center so that it no longer appears in the active findings list. The analyst wants to keep the finding for historical reference. What should they do?
44Your company needs to implement real-time monitoring of security events from Google Cloud resources. They want to ingest logs into a third-party SIEM system. Which two services should they use together? (Choose two.)
45A security engineer is investigating a potential data exfiltration incident. They suspect that a compromised VM is sending sensitive data to an external IP. Which three data sources should they examine to trace the exfiltration? (Choose three.)
46Your organization uses VM Manager for patch management. You need to configure patch deployments to run weekly on all Windows VMs. Which two resources must be configured? (Choose two.)
47A security engineer needs to ensure that all container images deployed to a GKE cluster are signed by a trusted authority. The organization uses Cloud KMS for key management and wants to enforce the policy at admission time. Which two components are essential to implement this requirement? (Choose two.)
48A financial services company uses Security Command Center (SCC) Premium tier to monitor its GCP environment. The security team wants to automatically respond to high-severity threat findings, such as 'Cryptomining' from Event Threat Detection. The response should include isolating the affected VM by removing its external IP and applying a firewall rule to block egress traffic. Which two steps should the team implement? (Choose two.)
49A multinational organization uses Chronicle SIEM to aggregate and analyze security logs from multiple GCP projects and on-premises systems. The security team wants to detect a known threat pattern: a user authenticating from an anomalous geographic location followed by a large data egress from a Compute Engine instance within 10 minutes. Which three steps are necessary to create this detection? (Choose three.)
50A healthcare organization uses Google Cloud and must comply with HIPAA. They need to ensure that all access to patient data stored in Cloud Storage is logged and that any unauthorized access attempts are detected in near real-time. They also want to minimize false positives. Which approach should they take?
51A company has a Google Kubernetes Engine (GKE) cluster with several workloads. They want to ensure that only container images that have been scanned for vulnerabilities and signed by a trusted authority are deployed. They also want to receive alerts when an unsigned image is attempted to be deployed. Which Google Cloud service should they use?
52A security engineer at a financial services company needs to ensure that all VPC Flow Logs and Cloud Audit Logs generated in their Google Cloud organization are retained for seven years and are immutable, even if a project owner attempts to delete them. They also need the ability to prove to auditors that the logs have not been altered. Which combination of Google Cloud services should they use?
53Your organization uses Google Cloud and wants to ensure that all security-related logs, such as Cloud Audit Logs and VPC Flow Logs, are retained for at least 365 days for compliance. Currently, logs are stored in Cloud Logging's default buckets with a 30-day retention period. You need a solution that automatically exports logs to a cost-effective storage service and allows for easy retrieval if needed. What should you do?
54Your organization uses Google Cloud and wants to ensure that all VPC network firewall rule changes are logged for later analysis and alerting. You need to enable the appropriate logging and route the logs to a central project for analysis. What should you do?
55A security operations team needs to monitor for IAM policy changes across all projects in their Google Cloud organization. They want to be alerted within minutes when a user is granted the Owner role on any project. They have enabled Cloud Audit Logs for all services and want to use a native Google Cloud service that can aggregate and filter logs across the organization. What should they do?
56A cloud security engineer needs to grant a service account the ability to publish messages to a Cloud Pub/Sub topic. The service account is used by an application running on Compute Engine. Following the principle of least privilege, which IAM role should be granted?
57Your organization uses Security Command Center (SCC) Premium across 15 Google Cloud projects managed under a single organization node. A security analyst needs to receive near-real-time alerts in a Slack channel whenever a new HIGH severity finding is created. You want a low-maintenance, serverless approach that does not require managing a Compute Engine instance. What should you do?
58Your security team uses Security Command Center (SCC) Premium. You need to automatically remediate a specific misconfiguration: a Cloud Storage bucket that has public access. When SCC detects this finding, you want to automatically remove the public access. What should you do?
59A security team wants to detect and respond to suspicious network traffic in near real-time across multiple VPC networks. They need to capture packet-level data for forensic analysis without impacting performance. Which Google Cloud service should they use?
60Your organization wants to monitor and audit all administrative activities across multiple Google Cloud projects. You need to ensure that audit logs are retained for at least 1 year and can be queried easily. What should you do?
61A security engineer needs to monitor for anomalous IAM activity in a Google Cloud organization. They want to detect when a service account key is created for a highly privileged service account and alert the security team in near real-time. They also want to minimize false positives. Which approach should they use?
62A security team needs to monitor for anomalous IAM activity in their Google Cloud organization. They want to detect when a service account key is created outside of normal change windows. Which Google Cloud service should they use to set up an alert?
63Your company has a Google Kubernetes Engine (GKE) cluster with Binary Authorization enabled. You want to ensure that only container images that have been attested by a specific attestor can be deployed. You have already created the attestor and the attestation. What should you do next to enforce this?
64A security operations team wants to automatically receive a notification whenever a new high-severity vulnerability finding is created in Security Command Center. They need the notification delivered to a Pub/Sub topic that already exists in the same organization. Which configuration should they use?
65Your organization has a requirement to ensure that all Compute Engine instances have the latest security patches applied within 30 days of release. You want to monitor compliance and receive alerts for non-compliant instances. Which Google Cloud service should you use to achieve this with minimal effort?
66Your organization runs a production Google Kubernetes Engine (GKE) cluster. A security analyst reports that the PodSecurityPolicy `restricted` is not being enforced, allowing pods to run as root. You need to determine which GKE cluster configuration is responsible. Which of the following should you check first?
67Your security team needs to ensure that all Google Cloud resources across your organization are compliant with a set of security policies. You want to use Security Command Center (SCC) to detect violations. Which TWO steps should you take to enable SCC to detect policy violations? (Choose two.)
68Your security team uses VPC Service Controls to protect a sensitive project containing BigQuery datasets. An engineer reports that they can still export BigQuery data to a Cloud Storage bucket in a different project that is inside the same perimeter. You need to block this data exfiltration path while still allowing legitimate analytics jobs. Which configuration change should you make?
69A security engineer is configuring VPC Service Controls to protect a project that contains sensitive data in Cloud Storage and BigQuery. They need to allow access from a specific set of on-premises IP addresses while blocking access from all other external networks. Which TWO steps should they take to meet this requirement? (Choose two.)
70A company wants to ensure that their security team is alerted when a new project is created in their Google Cloud organization. They need a centralized, low-maintenance solution that requires minimal custom code. What should they do?
71A company wants to ensure that all data stored in Cloud Storage buckets is encrypted with customer-managed encryption keys (CMEK) rather than Google-managed keys. They need to enforce this policy across the organization. Which Google Cloud service should they use to define and enforce this requirement?
72A security team wants to reduce the risk of compromised service account keys in their Google Cloud organization. They have many workloads running on Compute Engine and GKE that currently use exported JSON keys stored on disk. Which TWO changes should they make to eliminate long-lived credentials while preserving functionality? (Choose two.)
73A security engineer at a financial services company needs to ensure that all administrative activity in their Google Cloud organization is captured and stored immutably for 7 years. The organization uses a single folder hierarchy with multiple projects. They want to minimize configuration effort and ensure logs cannot be altered or deleted by any user, including project owners. What should they do?
74A security team is using Cloud Audit Logs to investigate an incident. They need to determine which user deleted a specific Compute Engine instance. The instance was deleted within the last 30 days. Which log type should they query to find this information?
75An organization uses Cloud IDS in a Shared VPC environment to inspect traffic between the host project and service projects. A security engineer notices that no alerts are appearing for traffic between two service projects. The Cloud IDS endpoint was created in the host project with a packet mirroring policy targeting the host project's subnets. What is the most likely cause?
76A security team needs to ensure that when a Google Cloud service account key is created in any project within the organization, an alert is generated and the key is automatically disabled within 5 minutes. They want a centralized, automated response. What should they do?
77A company wants to detect and respond to suspicious network activity in their Google Cloud environment. They need to capture VPC Flow Logs, analyze them for anomalies, and trigger automated responses. They want to minimize operational overhead. What should they do?
78A company needs to grant a security analyst read-only access to all Security Command Center findings across their organization. The analyst should not be able to modify findings or access other resources. Which IAM role should be granted?
79A security team wants to ensure that all Compute Engine instances in their organization have the latest OS patches applied. They want to automate the process and receive reports on compliance status. They also want to minimize the risk of patches breaking applications. What should they do?
80A security analyst needs to review all administrative activity performed on Compute Engine resources in a Google Cloud project over the last 30 days. The project has default audit log configuration. Which log should the analyst query?
81Your security team wants to detect when a service account key is created for any project in the organization and immediately disable that key. You need a solution that reacts in near real time and requires the least custom code. Which approach should you take?
82A security operations team is building a centralized logging architecture. They want to export audit logs from all projects in the organization to a single destination for long-term retention and analysis, and they need to ensure that log data cannot be modified or deleted by project-level administrators. Which two actions should they take? (Choose two.)
83A small startup uses Google Cloud and wants to monitor for suspicious activity in their single project. They have limited security expertise and want a managed service that provides built-in detectors for threats like compromised credentials and malware. They also want to receive email alerts for high-severity findings. What should they do?
84A healthcare company must ensure that no one can delete or shorten the retention of their Cloud Audit Logs for seven years, even a project owner or a compromised org admin. They have created a user-defined log bucket named 'compliance-logs' with a 2555-day retention period at the organization level. Which additional control provides the strongest guarantee against tampering with the logs?
85A startup's security team wants to be notified within one minute whenever a new Security Command Center finding of severity HIGH or CRITICAL is created in any of their projects. They already use Security Command Center Premium and want the least operational effort. What should they do?
86A company needs to ensure that all Google Cloud audit logs are immutable and cannot be deleted by any user, including administrators, for a period of 7 years. They want a simple, managed solution. What should they do?
Be able to design detection and response pipelines: route findings and logs to the right destination, automate quarantine actions, and enforce admission policies. The most important thing is knowing which Google Cloud mechanism delivers events reliably without losing data.
The Courseiva PCSE question bank contains 86 questions in the Managing Operations in a Cloud Solution Environment domain, covering the 19% of the exam attributed to this domain in the official Google Cloud blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Managing Operations in a Cloud Solution Environment domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included