Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise manages its Google Cloud Identity user accounts and directory groups programmatically using automated service accounts and identity provisioning pipelines. The security operations center (SOC) must implement continuous auditing, standardized log parsing, and real-time alerting within Google Security Operations (SecOps / Chronicle) to detect unauthorized or anomalous additions to privileged administrative groups.
Which approach should the security engineer implement to properly standardize the audit logs and trigger real-time alerts on these programmatic identity modifications?
Google Security Operations (SecOps / Chronicle) ingests structured and unstructured audit logs, normalizing disparate event schemas into the Unified Data Model (UDM). In UDM, identity lifecycle events (such as ADD_GROUP, ADD_USER, and group membership updates) are mapped to standardized event types (such as GROUP_CREATION or USER_RESOURCE_UPDATE_CONTENT) and schema fields such as principal.user.userid, target.group.product_object_id, and security_result.action.
principal) and the affected group (target).target.group.product_object_id matches sensitive administrative groups and the principal.user.userid is not an approved automation service account or authorized admin.principal.user.userid), target resources (target.group.product_object_id), and execution contexts.Leveraging UDM normalization paired with the SecOps Detection Engine and YARAL rules provides native, schema-aware security monitoring that scales with automated identity operations and delivers sub-minute alerting on unauthorized directory changes.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.