PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #102
Your organization is a Google Security Operations (SecOps) customer. You use Google Threat Intelligence to identify cyber threats within your organization's threat profile. You believe your organizati
The correct answer is B. In the Reports & Analysis feature, extract the IOCs from the recent reports, and implement. To determine whether your organization has already been targeted or compromised by a cyber crime group, you need to take actionable intelligence (IOCs) and check your own environment for evidence of activity. In Google Threat Intelligence, the Reports & Analysis feature provides
Question
Your organization is a Google Security Operations (SecOps) customer. You use Google Threat Intelligence to identify cyber threats within your organization's threat profile. You believe your organization may have been targeted by a cyber crime group. You need to identify whether your organization has been the victim of an attack. What should you do?
Options
- AImplement monitors in the Digital Threat Monitoring feature to identify new compromised
- BIn the Reports & Analysis feature, extract the IOCs from the recent reports, and implement
- CReview the Threat Landscape feature to identify threat groups that are active in your industry,
- DIn the Vulnerability Intelligence feature, identify new high and critical vulnerabilities in products or
How the community answered
(53 responses)- A6% (3)
- B81% (43)
- C11% (6)
- D2% (1)
Explanation
To determine whether your organization has already been targeted or compromised by a cyber crime group, you need to take actionable intelligence (IOCs) and check your own environment for evidence of activity. In Google Threat Intelligence, the Reports & Analysis feature provides threat reports that include IOCs. By extracting those IOCs and implementing detection rules and lists in Google SecOps, you can search historical and current telemetry to identify whether the attack group has operated against your systems.
Topics
Community Discussion
No community discussion yet for this question.