Google GCP-SOE-B 시험 개요:
| 인증 벤더: | |
|---|---|
| 시험명: | Security Operations Engineer (베타) |
| 시험 번호: | GCP-SOE-B |
| 시험 형식: | 객관식 단일 선택, 객관식 다중 선택, 시나리오 기반 문항 |
| 시험 시간: | 180분 |
| 지원 언어: | English |
| 실제 시험 문항 수: | 84-87 |
| 자격증 유효 기간: | 2년 |
| 합격 점수: | 70% |
| 응시료: | $120 USD (베타 가격, 정가 $200 USD에서 40% 할인 적용) |
| 관련 자격증: | Google Cloud Security Engineer Google Cloud Professional Cloud Security Engineer |
| 권장 교육: | Google Cloud Security Operations 학습 과정 Professional Security Operations Engineer 시험 안내서 |
| 시험 등록: | Google Cloud 자격증 등록 |
| 샘플 문제: | Google GCP-SOE-B 샘플 문제 |
| 응시 방법: | 온라인 원격 감독 방식 또는 지정 시험장 방문 응시 |
| 전제 조건: | 권장 요건: 보안 분야 실무 경력 3년 이상, Google Cloud 보안 도구 실제 사용 경험 1년 이상; 필수 선수 요건 없음 |
| 공식 요강 URL: | https://cloud.google.com/learn/certification/security-operations-engineer |
Google GCP-SOE-B 시험 요강 주제:
| 섹션 | 비중 | 목표 |
|---|---|---|
| 주제 1: 관찰 가능성 및 보고 | 8% | - 규정 준수 및 운영 현황 보고서 작성 - 플랫폼 상태 및 성능 모니터링 - 보안 상태 파악을 위한 대시보드 및 지표 구축 |
| 주제 2: 탐지 엔지니어링 | 20% | - 오탐지 감소를 위한 탐지 로직 검증 및 조정 - 탐지 규칙 개발 및 유지 관리 (YARA-L, Sigma) - 알림 및 사건 관리 기능과 탐지 기능 연동 - 자동화된 탐지 워크플로우 구현 |
| 주제 3: 사고 대응 | 18% | - 사고 내용 문서화 및 복구 조치 지원 - 포렌식 분석 및 근본 원인 규명 수행 - 대응 조치의 조정 및 자동화 실행 - 보안 알림 분류, 우선순위 지정 및 조사 |
| 주제 4: 데이터 관리 | 22% | - 데이터 수집 파이프라인 설계 및 구현 - 분석에 적합하도록 로그 및 이벤트 데이터 최적화 - 통합 데이터 모델(UDM)에 맞춰 데이터 정규화 및 매핑 - 데이터 보존, 저장 및 접근 정책 관리 |
| 주제 5: 위협 헌팅 | 18% | - 헌팅 결과 문서화 및 보고 - 위협 인텔리전스를 활용하여 이상 현상 및 위협 식별 - 위협 헌팅 방법론 설계 및 실행 - UDM 검색 및 쿼리 언어 효과적으로 활용 |
| 주제 6: 플랫폼 운영 | 14% | - Google Security Operations (SecOps) 플랫폼 설정 관리 - Google Threat Intelligence (GTI) 연동 관리 - Security Command Center (SCC) 리소스 구성 및 관리 |
최신 Google Cloud Certified GCP-SOE-B 무료샘플문제
문제 #1
Your organization is a Google Security Operations (SecOps) customer and monitors critical assets using a SIEM dashboard. You need to dynamically monitor the assets based on a specific asset tag. What should you do?
A. Export the dashboard configuration to a file, modify the file to add a custom filter, and import the file into Google SecOps.
B. Ask Cloud Customer Care to add a custom filter to the dashboard.
C. Add a custom filter to the dashboard.
D. Copy an existing dashboard and add a custom filter.
문제 #2
Which approach BEST improves detection of compromised service accounts in Google Cloud?
A. Alerting on login failures only
B. Disabling all service accounts You are managing the integration of Security Command Center (SCC) with downstream tooling.
C. Baseline service account behavior and alert on deviations
D. Monitoring VM uptime
문제 #3
A SOC team notices repeated outbound HTTPS connections from a Compute Engine instance to an external IP every 60 seconds. CPU usage is normal and no malware signatures trigger. What is the BEST next analytical step?
A. Notify executive leadership
B. Identify the process and service account generating the traffic
C. Block the destination IP immediately
D. Power off the instance
문제 #4
Your organization uses Google Security Operations (SecOps). You need to identify the most commonly occurring processes and applications across your organization's large number of servers so you can implement baselines and exclusion lists on a regular basis. You want to use the most efficient approach. What should you do?
A. Use the UDM lookup feature to identify relevant process- related UDM fields and values.
B. Run a UDM search, and review aggregations for relevant process-related UDM fields.
C. Review the Google SecOps SIEM Rules & Detections, and identify the most common processes appearing in alerts that are marked as false positives.
D. Generate a Google SecOps SIEM dashboard based on relevant UDM fields, such as processes, that provides the counts for process names and files.
문제 #5
A SOC uses Chronicle SIEM and wants to reduce alert fatigue without lowering detection coverage. What is the BEST strategy?
A. Disable medium-severity rules
B. Apply risk-based alert scoring and entity correlation
C. Limit alerts to business hours
D. Increase alert thresholds globally
질문과 대답:
| 문제 #1 정답: C | 문제 #2 정답: C | 문제 #3 정답: B | 문제 #4 정답: B | 문제 #5 정답: B |














1124 개 고객 리뷰
품질과 가치ITCertKR 의 높은 정확도를 보장하는 최고품질의 덤프는 IT인증시험에 대비하여 제작된것으로서 높은 적중율을 자랑하고 있습니다.
테스트 및 승인ITCertKR 의 덤프는 모두 엘리트한 전문가들이 실제시험문제를 분석하여 답을 작성한 만큼 시험문제의 적중률은 아주 높습니다.
쉽게 시험패스ITCertKR의 테스트 엔진을 사용하여 시험을 준비한다는것은 첫 번째 시도에서 인증시험 패스성공을 의미합니다.
주문하기전 체험ITCertKR의 각 제품은 무료 데모를 제공합니다. 구입하기로 결정하기 전에 덤프샘플문제로 덤프품질과 실용성을 검증할수 있습니다.
