PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #106
You are responsible for monitoring the ingestion of critical Windows server logs to Google Security Operations (SecOps) by using the Bindplane agent. You want to receive an immediate notification when
The correct answer is C. Create a new alert policy in Cloud Monitoring that triggers a notification based on the absence of. The most efficient solution is to create an alert policy in Cloud Monitoring that triggers a notification when no logs are ingested from the server's hostname for over 30 minutes. Cloud Monitoring can natively monitor log ingestion and absence, providing real-time alerts with min
Question
You are responsible for monitoring the ingestion of critical Windows server logs to Google Security Operations (SecOps) by using the Bindplane agent. You want to receive an immediate notification when no logs have been ingested for over 30 minutes. You want to use the most efficient notification solution. What should you do?
Options
- ACreate a new YARA-L rule in Google SecOps SIEM to detect the absence of logs from the server
- BConfigure a Bindplane agent to send a heartbeat signal to Google SecOps every 15 minutes, and
- CCreate a new alert policy in Cloud Monitoring that triggers a notification based on the absence of
- DConfigure the Windows server to send an email notification if there is an error in the Bindplane
How the community answered
(42 responses)- A7% (3)
- B5% (2)
- C74% (31)
- D14% (6)
Explanation
The most efficient solution is to create an alert policy in Cloud Monitoring that triggers a notification when no logs are ingested from the server's hostname for over 30 minutes. Cloud Monitoring can natively monitor log ingestion and absence, providing real-time alerts with minimal setup and integration effort.
Topics
Community Discussion
No community discussion yet for this question.