PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #268
During a routine security review, your team discovered a suspicious login attempt to impersonate a highly privileged but regularly used service account by an unknown IP address. You need to…
The correct answer is D. Check Event Threat Detection in Security Command Center for any related alerts. Cross-. ETD automatically detects suspicious activity, such as anomalous service account usage or potential credential compromise, by analyzing logs in near real-time. Checking ETD alerts can quickly surface relevant insights about the suspicious activity. Cloud Audit Logs…
Question
Options
- AEnable Cloud Audit Logs for the resources that the service account interacts with. Review the
- BReview Cloud Audit Logs for activity related to the service account. Focus on the time period of
- CRun a vulnerability scan to identify potentially exploitable weaknesses in systems that use the
- DCheck Event Threat Detection in Security Command Center for any related alerts. Cross-
How the community answered
(65 responses)- A3% (2)
- B11% (7)
- C5% (3)
- D82% (53)
Explanation
ETD automatically detects suspicious activity, such as anomalous service account usage or potential credential compromise, by analyzing logs in near real-time. Checking ETD alerts can quickly surface relevant insights about the suspicious activity. Cloud Audit Logs: Cross-referencing findings in ETD with Cloud Audit Logs helps confirm the scope of the incident by providing a complete history of actions performed by the service account, including the time of the suspicious login attempt.
Topics
Community Discussion
No community discussion yet for this question.