nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #105

You are a SOC analyst working a case in Google Security Operations (SecOps). The case contains a file hash that your playbooks have automatically enriched with VirusTotal context and categorized as li

The correct answer is A. Build a playbook to perform a UDM search matching on the file hash in Google SecOps SIEM.. The most effective approach is to build a playbook to perform a UDM search matching on the file hash in Google SecOps SIEM. This will automatically search across your ingested telemetry to identify all devices and users that have interacted with the file, accelerating response an

SOAR Automation and Case Management

Question

You are a SOC analyst working a case in Google Security Operations (SecOps). The case contains a file hash that your playbooks have automatically enriched with VirusTotal context and categorized as likely malicious. You need to quickly identify devices and users in your organization who have interacted with this file. What should you do?

Options

  • ABuild a playbook to perform a UDM search matching on the file hash in Google SecOps SIEM.
  • BBuild a playbook to query your threat intelligence platform (TIP) for the presence of the file hash.
  • CUse a manual action in Google SecOps SOAR to perform a UDM search matching on the file
  • DUse a manual action in Google SecOps SOAR to query your threat intelligence platform (TIP) for

How the community answered

(35 responses)
  • A
    83% (29)
  • B
    3% (1)
  • C
    11% (4)
  • D
    3% (1)

Explanation

The most effective approach is to build a playbook to perform a UDM search matching on the file hash in Google SecOps SIEM. This will automatically search across your ingested telemetry to identify all devices and users that have interacted with the file, accelerating response and investigation without requiring manual intervention.

Topics

#file hash investigation#UDM search#playbook automation#SOAR case enrichment

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice