Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise organization is designing a centralized logging, threat detection, and security analytics architecture across Google Cloud and hybrid environments. The Security Operations Center (SOC) team needs to achieve the following requirements:
Which logging and threat detection strategy should the organization implement?
Google SecOps (formerly Chronicle SIEM) is a cloud-native Security Information and Event Management platform designed to ingest, normalize, and analyze massive volumes of security telemetry at scale. Central to its architecture is the Unified Data Model (UDM), a standardized data schema that structures and normalizes heterogeneous logs—such as proxy logs, authentication events, firewall traffic, and endpoint telemetry—into consistent entity and event objects (for example, principal, target, network, and security_result).
principal.ip, principal.user.userid, target.process.file.full_path). This enables unified, high-speed querying across disparate log formats without custom per-source syntax.security_result), creating a unified security analytics pane for comprehensive threat hunting.Compared to constructing custom data pipelines using databases or monitoring metrics, Google SecOps natively delivers purpose-built SIEM functionality, normalized data models, rule engines, and threat intelligence mapping specifically engineered for enterprise SOC threat hunting and detection engineering.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.