nerdexam
Google

GOOGLE-WORKSPACE-ADMINISTRATOR · Question #11

Your organization has just appointed a new CISO. They have signed up to receive admin alerts and just received an alert for a suspicious login attempt. They are trying to determine how frequently…

The correct answer is A. Use the login audit report to export all suspicious login details for analysis. Login audit log Track user sign-in activity You can use the Login audit log to track user sign-ins to your domain. You can review all sign-ins from web browsers. If a user signs in from an email client or a non-browser application, you can only review reports of suspicious…

Security Operations and Incident Management

Question

Your organization has just appointed a new CISO. They have signed up to receive admin alerts and just received an alert for a suspicious login attempt. They are trying to determine how frequently suspicious login attempts occur within the organization. The CISO has asked you to provide details for each user account that has had a suspicious login attempt in the past year and the number of times it occurred for each account. What action should you take to meet these requirements?

Options

  • AUse the login audit report to export all suspicious login details for analysis.
  • BCreate a custom dashboard with the security investigation tool showing suspicious logins.
  • CUse the account activity report to export all suspicious login details for analysis.
  • DCreate a custom query in BigQuery showing all suspicious login details.

How the community answered

(22 responses)
  • A
    77% (17)
  • B
    5% (1)
  • C
    14% (3)
  • D
    5% (1)

Explanation

Login audit log Track user sign-in activity You can use the Login audit log to track user sign-ins to your domain. You can review all sign-ins from web browsers. If a user signs in from an email client or a non-browser application, you can only review reports of suspicious attempts. Forward log event data to the Google Cloud Platform You can opt in to share the log event data with Google Cloud Platform. If you turn on sharing, data is forwarded to Cloud Logging, where you can query and view your logs, and control how you route and store your logs. https://support.google.com/a/answer/4580120?hl=en

Topics

#login audit#suspicious activity#security reporting#user monitoring

Community Discussion

No community discussion yet for this question.

Full GOOGLE-WORKSPACE-ADMINISTRATOR Practice