GCP Prep

Security Operations Engineer Practice Test

2 original questions · Timed mock exam

Question 1 of 2

0 answered · 2 remaining

04:00

Securityhard

A detection rule for a known attack technique has never fired, although the technique has been observed in the environment during a red team exercise. What should be investigated first?

Select one answer

What this test covers

One concept per question, across the topics Security Operations Engineer draws on.

  • Most detection failures are data problems, not rule problems
  • Detecting anomalous behaviour requires analysing activity logs, not configuration
These questions are written by GCP Prep to test understanding of publicly documented concepts. They are not real exam questions and are not a prediction of what any exam contains.