Cloud Digital Leader Google Cloud Security Practice Question
Which Google Cloud service provides threat intelligence and incident response capabilities, including access to Mandiant expertise?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mandiant
Mandiant is Google Cloud's threat intelligence and incident response service. Security Command Center provides vulnerability scanning but not Mandiant expertise. Chronicle is a SIEM. Cloud IDS is network intrusion detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security Command Center
Why it's wrong here
Google Cloud Security Command Center is a security and risk management platform that continuously monitors cloud assets, identifies misconfigurations, and surfaces vulnerability and threat findings. However, it does not deliver Mandiant's curated threat intelligence or provide hands-on incident response consulting; it is a detection and posture management tool rather than a threat intelligence and response service.
- ✗
Chronicle
Why it's wrong here
Chronicle is Google Cloud's cloud-native SIEM that ingests petabytes of telemetry, normalizes data, and enables accelerated search and detection across historical and real-time logs. While it can consume threat intelligence feeds to enrich detections, it is fundamentally a log analysis and investigation platform, not a provider of proprietary threat intelligence or expert incident response from Mandiant.
- ✓
Mandiant
Why this is correct
Mandiant is Google Cloud's front-line threat intelligence and incident response unit, offering curated cyber threat intelligence, threat actor research, and on-demand incident response consulting. Its services include digital forensics, compromise assessments, and strategic intelligence, making it the direct match for this question's description of providing threat intelligence and incident response.
- ✗
Cloud IDS
Why it's wrong here
Cloud IDS is a managed intrusion detection service that monitors network traffic against signature-based detection rules, applying the Palo Alto Networks Threat Prevention technology. It inspects east-west traffic for known exploit patterns and malware but does not offer strategic threat intelligence, threat actor attribution, or incident response expertise; its scope is narrowly network-level detection and prevention.
Go deeper
Related to this question
Learn chapter
Cloud Digital Transformation
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
Security Command Center
Security Command Center is a centralized cloud security management platform that helps organizations detect, investigate, and respond to threats across their cloud infrastructure.
About these practice questions
Courseiva writes every GCDL question from scratch — 829 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.