nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #104

You are using Google Security Operations (SecOps) to identify and report a repetitive sequence of brute force SSH login attempts on a Compute Engine image that did not result in a successful login. Yo

The correct answer is A. VPC Flow Logs. VPC Flow Logs provide network-level visibility into traffic such as repetitive SSH connection attempts, regardless of login success. Ingesting VPC Flow Logs lets you identify brute force patterns while minimizing ingestion volume, since you don't need full authentication logs or

Log Ingestion and Data Management

Question

You are using Google Security Operations (SecOps) to identify and report a repetitive sequence of brute force SSH login attempts on a Compute Engine image that did not result in a successful login. You need to gain visibility into this activity while minimizing impact on your ingestion quota. Which log type should you ingest into Google SecOps?

Options

  • AVPC Flow Logs
  • BSecurity Command Center Premium (SCCP) findings
  • CCloud IDS logs
  • DCloud Audit Logs

How the community answered

(61 responses)
  • A
    79% (48)
  • B
    13% (8)
  • C
    5% (3)
  • D
    3% (2)

Explanation

VPC Flow Logs provide network-level visibility into traffic such as repetitive SSH connection attempts, regardless of login success. Ingesting VPC Flow Logs lets you identify brute force patterns while minimizing ingestion volume, since you don't need full authentication logs or Cloud Audit Logs for unsuccessful login attempts. This approach gives you the necessary insight into SSH brute force activity without high log ingestion costs.

Topics

#VPC Flow Logs#SSH brute force#ingestion quota#log source selection

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice