nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #108

Your organization recently adopted Google Security Operations (SecOps), and has configured ingestion, parsing and rules for their log sources. The security operations team is currently triaging…

The correct answer is D. Build a low-priority, catch-all playbook for enrichment of entities in a case using threat intelligence. The most efficient first step is to build a low-priority, catch-all playbook for enrichment of entities in a case using threat intelligence sources. This allows all cases to be automatically enriched with relevant context in Google SecOps, minimizing the need for analysts to pivo

SOAR Playbook Development

Question

Your organization recently adopted Google Security Operations (SecOps), and has configured ingestion, parsing and rules for their log sources. The security operations team is currently triaging alerts one at a time using several external product dashboards with alerts and enrichment data. You want to use the case management functionality in Google SecOps to reduce the amount of pivoting between products your SOC analysts are required to do. You want to minimize development effort. What should you do first?

Options

  • ABuild a playbook for each detection rule to enrich and remediate alerts relative to the particular
  • BBuild a playbook for each of the noisiest alert sources to gather additional context on the case
  • CBuild a job to periodically iterate over recent cases, determine relevant context, and enrich alerts.
  • DBuild a low-priority, catch-all playbook for enrichment of entities in a case using threat intelligence

How the community answered

(64 responses)
  • A
    16% (10)
  • B
    6% (4)
  • C
    3% (2)
  • D
    75% (48)

Explanation

The most efficient first step is to build a low-priority, catch-all playbook for enrichment of entities in a case using threat intelligence sources. This allows all cases to be automatically enriched with relevant context in Google SecOps, minimizing the need for analysts to pivot between external dashboards and reducing manual effort, without requiring extensive custom development per rule

Topics

#playbook design#entity enrichment#case management#catch-all playbook

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice