Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Google Professional Security Operations Engineer Exam - Topic 5 Question 17 Discussion

Your organization has recently onboarded to Google Cloud with Security Command Center Enterprise (SCCE) and is now integrating it with your organization's SOC. You want to automate the response process within SCCE and integrate with the existing SOC ticketing system. You want to use the most efficient solution. How should you implement this functionality?
C) Disable the generic posture finding playbook in Google Security Operations (SecOps) SOAR and enable the playbook for the ticketing system. Add a step in your Google SecOps SOAR playbook to generate a ticket based on the event type.
A) Use the SCC notifications feed to send alerts to Pub/Sub. Ingest these feeds using the relevant SIEM connector.
B) Evaluate each event within the SCC console. Create a ticket for each finding in the ticketing system, and include the remediation steps.
D) Configure the SCC notifications feed to send alerts to a Cloud Storage bucket. Create a Dataflow job to read the new files, extract the relevant information, and send the information to the SOC ticketing system.

Google Professional Security Operations Engineer Exam - Topic 5 Question 17 Discussion

Actual exam question for Google's Professional Security Operations Engineer exam
Question #: 17
Topic #: 5
[All Professional Security Operations Engineer Questions]

Your organization has recently onboarded to Google Cloud with Security Command Center Enterprise (SCCE) and is now integrating it with your organization's SOC. You want to automate the response process within SCCE and integrate with the existing SOC ticketing system. You want to use the most efficient solution. How should you implement this functionality?

Show Suggested Answer Hide Answer
Suggested Answer: C

Comprehensive and Detailed Explanation

The correct answer is Option C. The prompt asks for the most efficient and automated solution for handling SCCE findings and integrating with a ticketing system. This is the primary use case for Google Security Operations SOAR.

The native workflow is as follows:

SCCE detects a finding.

The finding is automatically ingested into Google SecOps SIEM, which creates an alert.

The alert is automatically sent to SecOps SOAR, which creates a case.

The SOAR case automatically triggers a playbook.

Option C describes this process perfectly. An administrator would disable the default playbook and enable a specific playbook that uses a pre-built integration (from the Marketplace) for the organization's ticketing system (e.g., ServiceNow, Jira). This playbook would contain an automated step to generate a ticket, thus fulfilling the requirement efficiently.

Option B is a manual process. Options A and D describe complex, custom-built data engineering pipelines, which are far less efficient than using the built-in SOAR capabilities.

Exact Extract from Google Security Operations Documents:

SOAR Playbooks and Integrations: Google SecOps SOAR is designed to automate and orchestrate responses to alerts. When an alert from a source like Security Command Center (SCC) is ingested and creates a case, it can be configured to automatically trigger a playbook.

Ticketing Integration: A common playbook use case is integration with an external ticketing system. Using a pre-built integration from the SOAR Marketplace, an administrator can add a step to the playbook (e.g., Create Ticket). This action will automatically generate a ticket in the external system and populate it with details from the alert, such as the finding, the affected resources, and the recommended remediation steps. This provides a seamless, automated workflow from detection to ticketing.


Google Cloud Documentation: Google Security Operations > Documentation > SOAR > Use cases > Case Management

Google Cloud Documentation: Google Security Operations > Documentation > SOAR > Marketplace integrations

Contribute your Thoughts:

0/2000 characters
Colette
1 day ago
Wait, can SCCE really handle all that? Sounds too good to be true.
upvoted 0 times
...
Titus
7 days ago
Totally agree with A, it’s efficient and straightforward!
upvoted 0 times
...
Carey
12 days ago
D sounds complicated, not sure it’s worth the effort.
upvoted 0 times
...
Annalee
17 days ago
I disagree, B seems more thorough for tracking.
upvoted 0 times
...
Gail
22 days ago
A looks like the best option for automation!
upvoted 0 times
...
Elfrieda
27 days ago
I recall that using Cloud Storage with Dataflow can be powerful, but option D seems a bit complex for just sending alerts to the ticketing system. I wonder if it’s really necessary.
upvoted 0 times
...
Charlesetta
1 month ago
I think we practiced something similar with integrating ticketing systems before. Option C sounds familiar, but I’m not clear on how disabling the generic playbook affects the overall process.
upvoted 0 times
...
Cristal
1 month ago
I'm not entirely sure about the best approach here. Option B feels a bit manual since it requires evaluating each event individually, which could slow things down.
upvoted 0 times
...
Lorrie
1 month ago
I remember we discussed using Pub/Sub for alerting in our last practice session. It seems like option A could be the most efficient way to automate responses.
upvoted 0 times
...

Save Cancel