Instiq

Google Cloud Professional Security Operations EngineerStudy guide

The professional certification for detecting, hunting, investigating, and responding to threats with Google SecOps (SIEM/SOAR) and Security Command Center (Professional Security Operations Engineer).

About Google Cloud Professional Security Operations Engineer (GCP-PSOE)

Google Cloud Professional Security Operations Engineer (GCP-PSOE) is a Professional / Expert-level certification from Google Cloud. This page organizes the exam scope into a 6-chapter, 12-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."

Exam domains (approximate weighting)

  • Platform operations~14%
  • Data management~14%
  • Threat hunting~19%
  • Detection engineering~22%
  • Incident response~21%
  • Observability~10%

Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.

Official exam information: https://cloud.google.com/learn/certification/security-operations-engineer

1Platform operations

  • 1.1Enhancing detection/response and tool integration

    Understand prioritizing telemetry sources (Security Command Center [SCC], Google SecOps, Google Threat Intelligence [GTI], Cloud IDS), integrating multiple tools to enhance detection, justifying tools with overlapping capabilities, evaluating coverage gaps of existing tools, and evaluating automation/cloud tools to enhance detection/response processes.

  • 1.2Configuring access and auditing

    Understand user/service account authentication to security tools (SCC, Google SecOps), authorizing feature access and data access via IAM roles/permissions, configuring/analyzing audit logs (Cloud Audit Logs, data access logs), configuring API access for automation (service accounts, API keys, SCC/SecOps/GTI), and provisioning identities with Workforce Identity Federation.

2Data management

  • 2.1Ingesting logs for security tooling

    Understand determining data-ingestion approaches in security tools (SCC, Google SecOps), configuring ingestion tools/features, assessing required logs for detection/response (incl. automated sources, SCC Event Threat Detection), evaluating Google SecOps parsers and configuring parser modifications/extensions, data normalization (UDM) from log sources, evaluating new labels, and managing log/ingestion costs.

  • 2.2User, asset, and entity context

    Understand identifying relevant threat intelligence in the enterprise, differentiating event vs entity data log sources (Cloud Audit Logs, Active Directory organizational context), and evaluating event/entity data matches for enrichment using aliasing fields.

3Threat hunting

  • 3.1Threat hunting across environments

    Understand developing queries across environment logs to find anomalous activity, analyzing user behavior for anomalies, investigating network/endpoints/services for IOCs with Google Cloud tools (Logs Explorer, Log Analytics, BigQuery, Google SecOps), collaborating with incident response, and developing hypotheses from behavior/threat intel/posture/incident data.

  • 3.2Leveraging threat intelligence and retrohunt

    Understand searching IOCs in historical logs, identifying new attack patterns/techniques in real time using threat intelligence and risk assessments (GTI, detection rules, SCC toxic combinations), analyzing entity risk score for anomalies, retrohunting historical events with newly enriched logs (Google SecOps rules engine, BigQuery, Cloud Logging), and proactively searching for underlying threats with threat intelligence.

4Detection engineering

  • 4.1Developing and implementing detection mechanisms

    Understand reconciling threat intelligence with user/asset activity, analyzing logs/events for anomalies, detection rules and searches across timelines, detection rules using risk values (Google SecOps reference lists), assigning risk values (Google SecOps Risk Analytics, curated detection rules), detecting posture/risk-profile changes (SCC Security Health Analytics, posture management), identifying low-prevalence processes/domains/IPs (YARA-L rules), using entity/context data (SecOps entity graph), and SCC Event Threat Detection custom detectors.

  • 4.2Leveraging threat intelligence for detection and reducing false positives

    Understand scoring alerts based on the risk level of IOCs, searching ingested security telemetry with the latest IOCs, and measuring the frequency of repetitive alerts to identify and reduce false positives.

5Incident response

  • 5.1Containing and investigating security incidents

    Understand collecting evidence on incident scope (forensic images/artifacts), observing/analyzing alerts (SCC, Google SecOps), analyzing scope with tools (Logs Explorer, Log Analytics, BigQuery, Cloud Logging, Cloud Monitoring), collaborating with teams, isolating affected services/processes, forensic analysis (Hash, IP, URL, binaries via GTI), and root cause analysis (SCC, Google SecOps SIEM).

  • 5.2Response playbooks and case management

    Understand determining response steps for automation, prioritizing high-value enrichments by threat profile, evaluating integrations for playbooks, designing new processes for new attack patterns, recommending new orchestrations/automation playbooks based on gaps (Google SecOps SOAR), notifying analysts/stakeholders, and the case management lifecycle (assigning response stages, escalation workflows, assessing handoff effectiveness).

6Observability

  • 6.1Dashboards and reports

    Understand identifying key security analytics (metrics, KPIs, trends), implementing dashboards to visualize security telemetry, ingestion metrics, detections, alerts, and IOCs (Google SecOps SOAR, SIEM, Looker Studio), and generating/customizing reports.

  • 6.2Health monitoring and alerting

    Understand identifying important metrics for health monitoring/alerts, creating dashboards that centralize metrics, creating threshold alerts for specific metrics, configuring notifications with Google Cloud tools (Cloud Monitoring), identifying health issues with Google Cloud tools (Cloud Logging), and configuring silent source detection.