PCSE Practice Question: Managing Operations in a Cloud Solution Environment
A company wants to use Chronicle to ingest logs from their on-premises firewalls into Google Cloud. They need to normalize logs into a common schema for analysis. Which Chronicle capability should they use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unified Data Model (UDM)
Chronicle uses the Unified Data Model (UDM) to normalize logs from various sources into a common schema. Log forwarders can collect and send logs to Chronicle, but UDM is the normalization engine. YARA-L rules are for detection, not normalization. The dashboard is for visualization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Log forwarders
Why it's wrong here
Forwarders collect and send logs but do not normalize; normalization happens via UDM.
- ✗
YARA-L rules
Why it's wrong here
YARA-L is a detection rule language, not a normalization engine.
- ✗
Chronicle dashboards
Why it's wrong here
Dashboards visualize data, they don't normalize.
- ✓
Unified Data Model (UDM)
Why this is correct
UDM normalizes logs into a common schema for analysis.
Go deeper
Related to this question
About these practice questions
One of 960 original PCSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCSE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCSE exam.