PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #1
You are reviewing the security analyst team's playbook action process. Currently, security analysts navigate to the Playbooks tab in Google Security Operations (SecOps) for each alert and manually…
The correct answer is C. Use the Pending Actions widget in the Default Case View in settings. The correct approach is to use the Pending Actions widget in the Default Case View. This widget consolidates all manual playbook actions that require analyst input, allowing them to be executed from a single location. This streamlines the workflow, reduces manual navigation…
Question
You are reviewing the security analyst team's playbook action process. Currently, security analysts navigate to the Playbooks tab in Google Security Operations (SecOps) for each alert and manually run steps assigned to a user. You need to present all actions from alerts awaiting user input in one location for the analyst to execute. What should you do?
Options
- AEnable approval links in the manual action and display them as clickable links to the user in a
- BAdd a general insight in your playbook to display manual action details to the user.
- CUse the Pending Actions widget in the Default Case View in settings.
- DCreate an Alert View with the playbook that incorporates the Pending Actions widget.
How the community answered
(27 responses)- A4% (1)
- B4% (1)
- C81% (22)
- D11% (3)
Explanation
The correct approach is to use the Pending Actions widget in the Default Case View. This widget consolidates all manual playbook actions that require analyst input, allowing them to be executed from a single location. This streamlines the workflow, reduces manual navigation, and ensures analysts don't miss pending steps across multiple alerts.
Topics
Community Discussion
No community discussion yet for this question.