FreeCourse Logo
FreeCourse.io
Verified CouponsFree CoursesJobsBlog
Categories
Home/Courses/[NEW] GPM-b™ Certified Green Project Manager
[NEW] GPM-b™  Certified Green Project Manager
IT & Software100% OFF

[NEW] GPM-b™ Certified Green Project Manager

Udemy Instructor
0(4 students)
Self-paced
All Levels

About this course

Detailed Exam Domain CoverageThe GPM-b™ (Certified Green Project Manager – Basic) exam evaluates your understanding of sustainable project management across two core domains. This practice test course is designed to mirror these weights and focus areas exactly:Sustainable Methods (70% of the exam)Sustainability initiatives and fundamental green concepts. The core fundamentals of the PRiSM® (Projects Integrating Sustainable Methods) methodology.

PRiSM® supporting processes and organizational integration. Sustainability ethics, corporate social responsibility, and core values. The P5™ Standard impact lenses: Product, Process, Social, Environmental, and Prosperity.

Delivery Methods (30% of the exam)PRiSM® fundamentals mapped specifically to project delivery methods. Management activities within each distinct phase of a PRiSM® project lifecycle. Supporting delivery processes, documentation, and reporting.

Governance practices, compliance, and sustainability frameworks. Applying concrete sustainability considerations to traditional constraints: project budgeting, scheduling, and procurement. Course DescriptionEarning the GPM-b™ certification proves you understand how to decouple project delivery from environmental degradation and social exploitation.

Because this exam is governed by GPM Global and aligned with the rigorous ISO 17024 standard, memorizing terms isn't enough. You need to know how to apply the PRiSM® methodology, utilize the P5™ Standard, and balance Environmental, Social, and Governance (ESG) factors against traditional constraints like time, scope, and cost. I built this practice question bank to bridge the gap between reading the theory and passing the actual exam.

Every question is authored to mimic the situational complexity and thematic distribution of the real test. Rather than giving you simple true/false answers, I break down why the correct choice aligns with GPM standards and why the distractors are incorrect. This approach helps you spot patterns, eliminate weak choices systematically, and build the confidence required to pass on your first attempt.

Practice Questions PreviewQuestion 1A project team is evaluating a new manufacturing process for a consumer electronics project. They are using the GPM P5™ Standard to assess the long-term impact of potential toxic emissions during production. Under which specific impact lens and sub-category of the P5 Standard does this evaluation primarily fall?

A) Product Impact / ServicingB) Process Impact / EnergyC) Environmental Impact / TransportD) Environmental Impact / Pollution & EmissionsE) Social Impact / Community InfluxF) Prosperity Impact / Business AgilityCorrect Answer: DDetailed Explanation:A is incorrect: Product Impact / Servicing focuses on how the final deliverable is maintained or repaired during its operational life, not the manufacturing emissions of the process itself. B is incorrect: While manufacturing is a process, the "Energy" sub-category deals with energy consumption, efficiency, and renewable sourcing, rather than chemical or toxic emissions. C is incorrect: The Environmental Impact / Transport sub-category focuses specifically on the carbon footprint and ecological impact of moving goods, materials, or personnel.

D is correct: The P5™ Standard explicitly categorizes toxic manufacturing emissions under the Environmental Impact lens, specifically within the Pollution & Emissions sub-category. This measures the project’s direct physical impact on air, land, and water quality. E is incorrect: Social Impact / Community Influx deals with how local populations are affected by incoming workforces or shifting demographics due to the project, not ecological toxins.

F is incorrect: Prosperity Impact / Business Agility deals with the financial and strategic adaptability of the organization, not physical environmental degradation. Question 2During the planning phase of a infrastructure project utilizing the PRiSM® methodology, the project manager insists on creating a Sustainability Management Plan (SMP). A stakeholder objects, stating that the project already has an approved Environmental Management Plan (EMP).

How should the project manager justify the necessity of the SMP? A) The SMP replaces the project charter to give the project manager more authority over resource allocation. B) An EMP only covers local environmental regulations, while the SMP focuses exclusively on corporate financial profitability.

C) The SMP is broader than an EMP because it integrates all P5™ lenses—including social, product, and prosperity impacts—directly into the project lifecycle. D) The PRiSM® methodology dictates that an EMP cannot be used if an organization wants to align with ISO 17024 standards. E) The SMP is a mandatory document required by ISO 14001 that must be signed off by external regulatory auditors before any delivery activities begin.

F) The SMP is used strictly to track the procurement of carbon offsets and has no overlap with traditional project scheduling or budgeting. Correct Answer: CDetailed Explanation:A is incorrect: The SMP does not replace the project charter. The project charter remains the foundational document that authorizes the project's existence.

B is incorrect: The SMP does not focus exclusively on financial profitability; its entire purpose is to balance the triple bottom line (People, Planet, Prosperity). C is correct: Under the PRiSM® methodology, a Sustainability Management Plan (SMP) is comprehensive. While a traditional EMP focuses heavily on ecological compliance, the SMP synthesizes all aspects of the P5™ Standard (Product, Process, Society, Environment, and Prosperity) into the overall project management framework, ensuring sustainability is woven into every delivery thread.

D is incorrect: PRiSM® does not ban EMPs; rather, it incorporates or builds upon environmental documentation to form a more holistic sustainability strategy. E is incorrect: The SMP is a PRiSM®-specific artifact aligned with GPM standards; it is not a direct, universally mandated statutory sign-off document for ISO 14001, though it supports environmental management goals. F is incorrect: The SMP is a core management tool that directly influences budgeting, scheduling, risk logs, and procurement pipelines, rather than acting as a simple ledger for carbon offsets.

Question 3When integrating sustainability considerations into project procurement activities for a Delivery Methods domain element, which action best demonstrates the application of PRiSM® governance practices? A) Choosing the vendor with the lowest initial bid price regardless of their supply chain transparency. B) Requiring all prospective vendors to submit a P5™ Impact Assessment of their own internal manufacturing processes during the bidding stage.

C) Postponing all procurement decisions until the final closeout phase of the project lifecycle to minimize risk. D) Outsourcing procurement entirely to a third party to remove the project team's liability for unethical supply chain practices. E) Using qualitative scoring criteria that evaluate vendors solely on their corporate philanthropy programs, ignoring product lifecycles.

F) Eliminating standard service level agreements (SLAs) to allow vendors to focus entirely on carbon reduction targets. Correct Answer: BDetailed Explanation:A is incorrect: Selecting a vendor based solely on the lowest cost without assessing sustainability factors directly violates the foundational principles of sustainable procurement and ESG integration. B is correct: Incorporating a P5™ Impact Assessment into the procurement process reflects strong PRiSM® governance.

It ensures that suppliers are evaluated not just on cost and time, but on how their products and processes impact social, environmental, and prosperity benchmarks throughout the delivery lifecycle. C is incorrect: Delaying procurement until closeout is structurally impossible, as materials and services must be procured during the execution phases to deliver the project. D is incorrect: Outsourcing does not absolve a project or organization of liability; true sustainability governance requires visibility and accountability throughout the entire value chain.

E is incorrect: Corporate philanthropy is only a small slice of social sustainability. Good governance requires assessing the actual product lifecycle and material impacts, not just charitable donations. F is incorrect: Sustainable project management does not abandon traditional controls like SLAs; instead, it integrates sustainability metrics into those standard project performance indicators.

Welcome to the Mock Exam Practice Tests Academy to help you prepare for your GPM-b™ | Certified Green Project Manager exam. You can retake the exams as many times as you wantThis is a huge original question bankYou get support from instructors if you have questionsEach question has a detailed explanationMobile-compatible with the Udemy appI hope that by now you're convinced! And there are a lot more questions inside the course.

Skills you'll gain

IT CertificationsEnglish

Available Coupons

Loading...

Course Information

Level: All Levels

Suitable for learners at this level

Duration: Self-paced

Total course content

Instructor: Udemy Instructor

Expert course creator

This course includes:

  • 📹Video lectures
  • 📄Downloadable resources
  • 📱Mobile & desktop access
  • 🎓Certificate of completion
  • ♾️Lifetime access
$0$85.99

Save $85.99 today!

Enroll Now - Free

Redirects to Udemy • Limited free enrollments

Share this course

https://freecourse.io/courses/new-gpm-btm-certified-green-project-manager

You May Also Like

Explore more courses similar to this one

[NEW] HashiCorp Certified Consul Associate
IT & Software
0% OFF

[NEW] HashiCorp Certified Consul Associate

Udemy Instructor

Detailed Exam Domain CoverageUnderstand the pillars of service networking (10%)Describe Consul architecture (10%)Deploy a single datacenter (10%)Service discovery and service registration (10%)Service mesh (10%)Secure agent communication (10%)Access Control Lists (ACLs) and service security (10%)Secure and connect service mesh applications at scale (10%)Monitor Consul (10%)Operate and maintain Consul (10%)I have created this comprehensive question bank to help you master the HashiCorp Certified: Consul Associate certification, This practice test course provides a realistic testing environment to validate your foundational knowledge of HashiCorp Consul, I designed these questions to ensure you can confidently deploy, configure, secure, and operate Consul in production environments,By taking these tests, you will evaluate your grasp of Consul Enterprise features, server high availability, and the pillars of service networking, I have ensured that every topic from service discovery to access control lists is covered in depth, I want to help you identify your weak areas so you can focus your study time effectively and pass on your first attempt,Sample Practice Questions PreviewQuestion 1: Which of the following components in a HashiCorp Consul architecture is primarily responsible for maintaining the cluster state and responding to RPC queries from other agentsOption A: Consul Client AgentOption B: Consul Server AgentOption C: Connect Sidecar ProxyOption D: Consul Mesh GatewayOption E: Consul Ingress GatewayOption F: Consul Terminating GatewayCorrect Answer: Option BExplanation: Option B is correct because Consul Server Agents are the core components that maintain the cluster state, participate in the Raft consensus algorithm, and handle RPC queries, Option A is incorrect because client agents route requests to servers but do not maintain cluster state, Option C is incorrect as the sidecar proxy manages service mesh traffic rather than cluster state, Option D, Option E, and Option F are incorrect because gateways manage specialized traffic routing, not the core internal cluster state,Question 2: How do applications primarily query the Consul service catalog to discover available services within a datacenterOption A: By reading a static JSON configuration file on the host machineOption B: By querying a central relational database managed by ConsulOption C: Via the Consul HTTP API or the Consul DNS interfaceOption D: By broadcasting UDP multicast requests across the networkOption E: By polling the Consul UI dashboard metricsOption F: By parsing the local Consul agent log filesCorrect Answer: Option CExplanation: Option C is correct because Consul natively supports service discovery through its HTTP API and a built-in DNS server, allowing applications to easily find services, Option A is incorrect because Consul is a dynamic service registry, not a static file, Option B is incorrect as Consul uses its own distributed key-value store, not a traditional relational database, Option D is incorrect because Consul uses gossip protocol for internal agent communication, not for application service discovery queries, Option E and Option F are incorrect because logs and dashboards are strictly for observability,Question 3: In a Consul service mesh, what is the primary mechanism utilized to secure service-to-service communicationOption A: IPsec VPN tunnels between all nodesOption B: Basic Access Authentication via HTTP headersOption C: Symmetric key encryption using a static shared secretOption D: Mutual TLS (mTLS) using certificates distributed by ConsulOption E: SSH tunneling between client and server agentsOption F: MAC address filtering at the network switch levelCorrect Answer: Option DExplanation: Option D is correct because Consul service mesh relies on mutual TLS (mTLS) to automatically encrypt and authenticate service-to-service traffic using built-in certificate management, Option A is incorrect because IPsec is a network-layer VPN technology, whereas Consul Connect operates at the application and transport layers, Option B is incorrect as basic authentication does not encrypt the underlying traffic payload, Option C is incorrect because Consul uses asymmetric cryptography via TLS certificates rather than static symmetric keys, Option E and Option F are incorrect as they represent legacy infrastructure-level controls that do not integrate dynamically with Consul services,Course FeaturesWelcome to the Mock Exam Practice Tests Academy to help you prepare for your HashiCorp Certified: Consul Associate courseYou can retake the exams as many times as you wantThis is a huge original question bankYou get support from instructors if you have questionsEach question has a detailed explanationMobile-compatible with the Udemy appI hope that by now you're convinced, And there are a lot more questions inside the course,

0.0•52•Self-paced
FREE$89.99
Enroll
[NEW] Google Cloud Professional Cloud Database Engineer
IT & Software
0% OFF

[NEW] Google Cloud Professional Cloud Database Engineer

Udemy Instructor

Detailed Exam Domain CoverageDesign innovative, scalable, and highly available cloud database solutions (32%)Analyze relevant variables to perform database capacity and usage planning.Evaluate performance and cost trade‑offs of different database configurations.Determine how applications will connect to the database.Deploy scalable and highly available databases in Google Cloud (32%)Apply concepts to implement scalable and highly available databases in Google Cloud.Provision highly available database solutions in Google Cloud.Test high availability and disaster recovery strategies.Manage a solution that can span multiple database solutions (20%)Evaluate trade‑offs between multi‑regional, regional, and zonal database deployment strategies.Define maintenance windows and notifications based on application availability requirements.Assess auditing policies for managed services.Migrate data solutions (16%)Evaluate appropriate database solutions on Google Cloud.Differentiate between managed and unmanaged database services.Analyze the cost of running database solutions in Google Cloud.Course DescriptionPassing the Google Cloud Professional Cloud Database Engineer certification requires more than just memorizing documentation. It demands a deep, practical understanding of how to architect, migrate, and manage robust database solutions across the entire Google Cloud ecosystem. I designed these practice tests to mirror the complexity, format, and domain weighting of the actual exam so you can step into your testing session with absolute confidence.Whether you are evaluating the nuances between Cloud Spanner and Cloud SQL, planning a zero-downtime migration, or determining the most cost-effective disaster recovery strategy, these questions will test your limits. I have carefully crafted every scenario to challenge your troubleshooting and architectural design skills. Instead of just telling you which answer is correct, I break down the technical reasoning behind every single option, ensuring you understand exactly why a specific configuration works and why the alternatives fall short.By working through this comprehensive question bank, you will identify your knowledge gaps, reinforce your understanding of multi-regional deployments, and learn how to translate complex business requirements into scalable Google Cloud database architectures.Practice Questions PreviewQuestion 1: You are planning to migrate an on-premises MySQL database to Google Cloud. The application requires strict relational consistency, high availability (HA) across multiple zones to survive a zone failure, and automated failover. The database size is roughly 2 TB. Which solution should you implement?Options:A. Cloud SQL for MySQL with Regional High Availability (HA) enabled.B. Cloud Spanner configured for a single regional deployment.C. Compute Engine instances running MySQL with asynchronous replication.D. Cloud SQL for MySQL in a single zone with multiple read replicas.E. Bare Metal Solution running Oracle.F. Cloud Bigtable with a multi-cluster routing profile.Correct Answer: A. Cloud SQL for MySQL with Regional High Availability (HA) enabled.Detailed Explanation:Option A is correct: Cloud SQL with Regional HA creates a primary instance and a standby instance in a different zone within the same region. It uses synchronous replication and provides automated failover, perfectly matching the 2 TB size and MySQL engine requirement.Option B is incorrect: While Spanner offers HA and relational consistency, migrating a standard 2 TB MySQL database directly to Spanner requires significant schema and application code changes. Cloud SQL is the direct, appropriate path for a lift-and-shift MySQL migration of this size.Option C is incorrect: Running unmanaged MySQL on Compute Engine introduces heavy operational overhead. You would have to manually configure, monitor, and manage the HA and failover mechanisms, which defeats the purpose of utilizing Google Cloud's managed services.Option D is incorrect: Read replicas provide horizontal scaling for read queries but do not provide automated failover for high availability in the event of a zone failure.Option E is incorrect: Bare Metal Solution is designed specifically for specialized, legacy workloads like Oracle databases that cannot easily be modernized or virtualized. It is entirely unnecessary for a standard MySQL workload.Option F is incorrect: Cloud Bigtable is a NoSQL wide-column store. It does not support relational consistency or SQL queries, making it fundamentally incompatible with a MySQL database migration.Question 2: Your IoT application generates millions of events per second. You need a database capable of handling massive, high-throughput write operations with single-digit millisecond latency. The data is time-series in nature and structured as wide columns. Which Google Cloud database is the best fit?Options:A. Cloud BigtableB. Firestore in Native ModeC. Cloud SpannerD. Cloud SQL for PostgreSQLE. Firestore in Datastore ModeF. BigQueryCorrect Answer: A. Cloud BigtableDetailed Explanation:Option A is correct: Cloud Bigtable is a fully managed, scalable NoSQL wide-column store specifically designed for massive scale, single-digit millisecond latency, and extremely high write throughput (like IoT and time-series data).Option B is incorrect: Firestore in Native Mode is an excellent NoSQL document database for web and mobile apps offering real-time synchronization, but it is not optimized for millions of writes per second or time-series data at the scale of IoT workloads.Option C is incorrect: Cloud Spanner is a strongly consistent, globally distributed relational database. While highly scalable, it is designed for relational data and transactions, not as a specialized time-series or wide-column store.Option D is incorrect: Cloud SQL for PostgreSQL is a traditional relational database. It will quickly become a bottleneck and fail to support millions of write operations per second without severe scaling issues.Option E is incorrect: Firestore in Datastore Mode is highly scalable for key-value and NoSQL document data but does not offer the wide-column structure or the sheer write-throughput optimization required for heavy IoT time-series ingestion.Option F is incorrect: BigQuery is an enterprise data warehouse designed for complex analytical queries (OLAP) on large datasets. It is not an operational database (OLTP) and cannot serve single-digit millisecond latency reads/writes for application ingestion.Question 3: You are evaluating the performance of a newly deployed Cloud SQL for PostgreSQL database. Monitoring alerts show that the primary instance's CPU utilization frequently hits 95% during business hours due to heavy application read traffic. Write traffic remains minimal and constant. What is the most cost-effective way to stabilize performance?Options:A. Create a read replica and route the application's read traffic to it.B. Upgrade the primary instance to a higher tier with double the vCPUs.C. Migrate the database to Cloud Spanner for horizontal write scaling.D. Enable High Availability (HA) to distribute the load across multiple zones.E. Move the database to Compute Engine to apply custom OS-level caching.F. Change the instance storage type from SSD to Standard HDD to offset costs while upgrading CPU.Correct Answer: A. Create a read replica and route the application's read traffic to it.Detailed Explanation:Option A is correct: Because the CPU spike is caused explicitly by read traffic, offloading those read queries to a read replica is the standard, most cost-effective architectural pattern. This instantly reduces the load on the primary instance.Option B is incorrect: Scaling up (increasing vCPUs on the primary) will solve the problem temporarily, but it is generally more expensive than adding a read replica and does not isolate analytical/read workloads from operational writes.Option C is incorrect: Migrating to Cloud Spanner is a massive, complex undertaking. Since the issue is just read-heavy traffic on a PostgreSQL instance, moving to Spanner is complete overkill and highly cost-inefficient.Option D is incorrect: Enabling High Availability (HA) in Cloud SQL provides an active-passive configuration for disaster recovery. The standby instance cannot be used to serve read traffic, so this would not solve the CPU utilization issue.Option E is incorrect: Moving to an unmanaged Compute Engine instance increases administrative burden dramatically and is contrary to cloud-native best practices. Managed Cloud SQL already provides better scalability options.Option F is incorrect: Changing SSD to HDD will drastically reduce IOPS and overall database performance, likely causing massive latency bottlenecks. It is terrible practice for an active operational database.What You Get With This Course:Welcome to the Mock Exam Practice Tests Academy to help you prepare for your Google Cloud Professional Cloud Database Engineer certification.You can retake the exams as many times as you want.This is a huge original question bank.You get support from instructors if you have questions.Each question has a detailed explanation.Mobile-compatible with the Udemy app.I hope that by now you're convinced! And there are a lot more questions inside the course.

0.0•5•Self-paced
FREE$89.99
Enroll
[NEW] Google Cloud Professional Security Operations Engineer
IT & Software
0% OFF

[NEW] Google Cloud Professional Security Operations Engineer

Udemy Instructor

Detailed Exam Domain CoverageBefore diving into the practice questions, here is the exact breakdown of the domains covered in this question bank to align with the official exam guide:Platform operations (14%): Enhancing detection and response capabilities, configuring user and service account authentication and authorization, prioritizing telemetry sources (SCC, SecOps, GTI, Cloud IDS), integrating multiple security tools into the architecture, and evaluating automation and cloud‑based tools for detection.Data management (14%): Log ingestion and normalization, establishing baselines for security telemetry, prioritizing and triaging log data, configuring data retention and access controls, and using Cloud Logging and Audit Logs for investigation.Threat hunting (19%): Proactive threat hunting using YARA‑L language, leveraging threat intelligence feeds, behavioral analytics and anomaly detection, developing hunting hypotheses and playbooks, and validating findings against security posture.Detection engineering (22%): Writing detection rules in YARA‑L, implementing detection mechanisms across SecOps and SCC, testing and tuning detection rules for false positives, mapping detections to MITRE ATT&CK techniques, and automating response actions for detections.Incident response (21%): Containment strategies for cloud incidents, investigation workflow using Security Command Center, developing and executing incident response playbooks, coordinating response automation and orchestration, and post‑incident analysis and lessons learned.Observability (10%): Designing dashboards for security monitoring, configuring alerts and notifications, monitoring key security metrics and KPIs, integrating observability data with incident response, and using Cloud Monitoring and Logging for visibility.Course DescriptionI built this practice test suite to give you a realistic, challenging environment to prepare for the Google Cloud Professional Security Operations Engineer certification. Passing this exam requires more than just memorizing cloud concepts; you need to demonstrate hands-on proficiency in detecting, analyzing, and responding to threats using Google Cloud's security suite.When creating these practice tests, I focused heavily on practical scenarios. You will find extensive questions that test your ability to write complex YARA-L rules, prioritize log ingestion for SecOps, and orchestrate rapid incident containment using Security Command Center. I have included detailed explanations for every single option—both correct and incorrect—so you understand the exact technical reasoning behind every architecture choice and security workflow. My goal is to help you build the muscle memory required to evaluate logs, correlate telemetry sources, and automate responses exactly as you would in a live enterprise environment.Sample Practice Questions PreviewHere is a glimpse of the type of scenario-based questions you will find inside the course:Question 1: Detection Engineering You are writing a YARA-L rule in Google SecOps to detect potential privilege escalation. You want to trigger an alert whenever an existing user account is unexpectedly granted the roles/iam.serviceAccountKeyAdmin role. Which approach ensures the most accurate detection while minimizing false positives?A) Create a rule that scans all VPC Flow Logs for traffic originating from the Identity and Access Management (IAM) API.B) Write a YARA-L rule analyzing target.user fields in Cloud Audit Logs to identify any API calls containing "serviceAccountKeyAdmin".C) Write a YARA-L rule using metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS" filtering for the specific role addition in the Cloud Audit Logs (Admin Activity).D) Configure a Cloud Monitoring alert that triggers whenever the IAM API quota utilization spikes abruptly.E) Develop a YARA-L rule that triggers on any USER_LOGIN event originating from an IP address outside your corporate network.F) Write a YARA-L rule that monitors Google Workspace logs for password resets on administrator accounts.Correct Answer: COverall Explanation: Admin Activity Cloud Audit Logs capture API calls that modify resource configurations or metadata, including IAM policy changes. YARA-L is specifically designed to parse these structured logs in Google SecOps.Explanation A (Incorrect): VPC Flow Logs record network traffic details (IPs, ports), not IAM policy modifications.Explanation B (Incorrect): Searching for string matches without specifying the event type or context is inefficient and will likely result in a massive amount of false positives.Explanation C (Correct): This accurately targets the specific audit event type (USER_RESOURCE_UPDATE_PERMISSIONS) generated when IAM policies change, ensuring high-fidelity detection.Explanation D (Incorrect): Quota utilization spikes do not provide context on what specific roles were granted; they only show API usage volume.Explanation E (Incorrect): A remote login event does not indicate that a privilege escalation or IAM role change has occurred.Explanation F (Incorrect): Google Workspace password resets do not track Google Cloud IAM role assignments.Question 2: Incident Response During a routine monitoring shift, Security Command Center (SCC) Premium triggers a high-severity alert indicating that a Compute Engine instance is actively communicating with a known crypto-mining command-and-control server. What is the most effective immediate containment strategy to stop the exfiltration while preserving evidence for investigation?A) Immediately delete the Compute Engine instance to remove the threat from the network.B) Restart the Compute Engine instance to terminate the active malicious processes.C) Apply a restrictive VPC firewall rule to the instance's network tag that blocks all egress and ingress traffic except for forensic access.D) Disable the Cloud Billing account associated with the project to freeze all resource activity.E) Export the instance's Cloud Audit Logs to a Cloud Storage bucket and then suspend the project.F) Change the compromised instance's machine type to an f1-micro to limit the computational power available for mining.Correct Answer: COverall Explanation: Incident containment aims to stop the immediate threat from spreading or communicating while preserving the state of the compromised machine for root cause analysis and forensic investigation.Explanation A (Incorrect): Deleting the instance destroys volatile memory and disk evidence necessary for investigating how the breach occurred.Explanation B (Incorrect): Restarting clears the RAM, destroying running malicious processes and vital forensic data, and the malware may just run again on boot.Explanation C (Correct): Isolating the instance using strict firewall rules immediately stops the C2 communication while keeping the instance running for forensic memory capture and disk imaging.Explanation D (Incorrect): Disabling billing impacts all resources in the project, causing a massive, unnecessary denial of service for legitimate workloads.Explanation E (Incorrect): Suspending the entire project impacts all other operational instances and services, not just the compromised one.Explanation F (Incorrect): Changing the machine type requires a reboot (destroying evidence) and does not stop the network communication with the C2 server.Question 3: Data Management Your SOC is ingesting telemetry into Google SecOps. To establish a strong baseline for behavioral analytics and anomaly detection while keeping storage costs optimized, which combination of log sources should you prioritize first?A) Cloud Storage Data Access logs and Cloud Load Balancing request logs.B) VPC Flow Logs and Google Kubernetes Engine (GKE) container stdout logs.C) Cloud Audit Logs (Admin Activity and Data Access) and Google Cloud Identity logs.D) Compute Engine serial console logs and Cloud SQL slow query logs.E) App Engine application logs and Cloud Functions execution logs.F) Cloud CDN cache hit logs and Cloud Armor WAF rule evaluation logs.Correct Answer: COverall Explanation: For security operations, establishing identity behavior and administrative actions is the highest priority for detecting unauthorized access, lateral movement, and privilege escalation.Explanation A (Incorrect): While useful for specific investigations, these are high-volume logs that do not establish core user identity baselines.Explanation B (Incorrect): stdout logs contain application data, and VPC Flow logs are network-centric; neither provides the rich identity context needed as a primary baseline.Explanation C (Correct): Admin Activity logs track all infrastructure changes, Data Access logs track who accessed what data, and Cloud Identity logs provide authentication context. These are critical for mapping user behavior.Explanation D (Incorrect): Serial console and slow query logs are operational/troubleshooting logs, not foundational security telemetry sources.Explanation E (Incorrect): Application and execution logs are developer-focused and lack the centralized IAM and resource modification context needed for a SOC baseline.Explanation F (Incorrect): CDN and WAF logs are edge-focused. They are important for perimeter defense but do not establish internal behavioral baselines.Welcome to the Mock Exam Practice Tests Academy to help you prepare for your Google Cloud Professional Security Operations Engineer certification.You can retake the exams as many times as you wantThis is a huge original question bankYou get support from instructors if you have questionsEach question has a detailed explanationMobile-compatible with the Udemy appI hope that by now you're convinced! And there are a lot more questions inside the course.

0.0•85•Self-paced
FREE$97.99
Enroll
FreeCourse LogoFreeCourse

Freecourse.io brings you high-quality online courses with free certificates to help you upskill, boost your career, and achieve your goals anytime, anywhere.

Resources

  • Courses
  • Jobs
  • Categories
  • Features

Company

  • About
  • Blog
  • Contact

Legal

  • Privacy
  • Terms
  • Cookies
  • Licenses

© 2026 FreeCourse. All rights reserved.