ASSOCIATE-GOOGLE-WORKSPACE-ADMINISTRATOR · Question #59
Your security team is concerned about disgruntled employees downloading large amounts of intellectual property. You need to create an automatic notification if any user downloads more than 500 files…
The correct answer is A. Create an activity rule in the security investigation tool to monitor Drive download events. Set a. Activity rules in the Security Investigation Tool are the correct mechanism for threshold-based behavioral alerts on Drive events. You can create a rule that monitors Drive audit log events of type 'Download,' applies a threshold condition (more than 500 events within one…
Question
Your security team is concerned about disgruntled employees downloading large amounts of intellectual property. You need to create an automatic notification if any user downloads more than 500 files from Google Drive within a one-hour period. What should you do?
Options
- ACreate an activity rule in the security investigation tool to monitor Drive download events. Set a
- BUse the alert center to review Drive audit logs for instances where users download a large number
- CConfigure a Data Loss Prevention (DLP) rule for Drive.
- DSet up an alert within Google Cloud Monitoring to track the number of Drive API calls and trigger a
How the community answered
(40 responses)- A80% (32)
- B13% (5)
- C3% (1)
- D5% (2)
Explanation
Activity rules in the Security Investigation Tool are the correct mechanism for threshold-based behavioral alerts on Drive events. You can create a rule that monitors Drive audit log events of type 'Download,' applies a threshold condition (more than 500 events within one hour), and triggers an automated alert or action. This is purpose-built for detecting anomalous user behavior like data exfiltration. Option B (Alert Center) is for reviewing existing alerts, not creating threshold-based behavioral rules. Option C (DLP rules) targets data content classification, not volume-based download activity. Option D (Cloud Monitoring) tracks infrastructure metrics and API call counts at the platform level, not per-user behavioral thresholds in Drive. Activity rules in the Security Investigation Tool are the right fit.
Topics
Community Discussion
No community discussion yet for this question.