Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise manages its Google Cloud Identity user accounts and directory groups programmatically using automated service accounts and identity provisioning pipelines. The security operations center (SOC) must implement continuous auditing, standardized log parsing, and real-time alerting within Google Security Operations (SecOps / Chronicle) to detect unauthorized or anomalous additions to privileged administrative groups.
Which approach should the security engineer implement to properly standardize the audit logs and trigger real-time alerts on these programmatic identity modifications?
Configure Event Threat Detection in Security Command Center to inspect VPC Flow Logs and Cloud DNS queries for group assignment API requests, and create firewall rules to block anomalous IP addresses.
Standardize audit logs into Unified Data Model (UDM) events mapping group operations to target group identifiers and actor identities, then deploy a YARAL detection rule in the SecOps Detection Engine to alert on unauthorized actors.
Deploy OSSEC and auditd daemons on directory host instances to classify system call logs as SYSTEM_AUDIT_LOG_UNCATEGORIZED, and run CIS Ubuntu Benchmark compliance scripts.
Standardize directory audit logs into PROCESS_LAUNCH and PROCESS_TERMINATION UDM event types, and deploy Cloud IDS packet mirroring profiles to inspect API payloads for unauthorized group changes.
Configure Event Threat Detection in Security Command Center to inspect VPC Flow Logs and Cloud DNS queries for group assignment API requests, and create firewall rules to block anomalous IP addresses.
Standardize audit logs into Unified Data Model (UDM) events mapping group operations to target group identifiers and actor identities, then deploy a YARAL detection rule in the SecOps Detection Engine to alert on unauthorized actors.
Google Security Operations (SecOps / Chronicle) ingests structured and unstructured audit logs, normalizing disparate event schemas into the Unified Data Model (UDM). In UDM, identity lifecycle events (such as ADD_GROUP, ADD_USER, and group membership updates) are mapped to standardized event types (such as GROUP_CREATION or USER_RESOURCE_UPDATE_CONTENT) and schema fields such as principal.user.userid, target.group.product_object_id, and security_result.action.
principal) and the affected group (target).target.group.product_object_id matches sensitive administrative groups and the principal.user.userid is not an approved automation service account or authorized admin.principal.user.userid), target resources (target.group.product_object_id), and execution contexts.Leveraging UDM normalization paired with the SecOps Detection Engine and YARAL rules provides native, schema-aware security monitoring that scales with automated identity operations and delivers sub-minute alerting on unauthorized directory changes.
Deploy OSSEC and auditd daemons on directory host instances to classify system call logs as SYSTEM_AUDIT_LOG_UNCATEGORIZED, and run CIS Ubuntu Benchmark compliance scripts.
Standardize directory audit logs into PROCESS_LAUNCH and PROCESS_TERMINATION UDM event types, and deploy Cloud IDS packet mirroring profiles to inspect API payloads for unauthorized group changes.