PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #11
Your company uses Google Security Operations (SecOps) Enterprise and is ingesting various logs. You need to proactively identify potentially compromised user accounts. Specifically, you need to…
The correct answer is D. Enable curated detection rules for User and Endpoint Behavioral Analytics (UEBA), and use the. The most effective and least effort solution is to enable curated UEBA (User and Endpoint Behavioral Analytics) detection rules in Google SecOps and use the Risk Analytics dashboard. UEBA automatically establishes user baselines and detects anomalies such as unusually large…
Question
Your company uses Google Security Operations (SecOps) Enterprise and is ingesting various logs. You need to proactively identify potentially compromised user accounts. Specifically, you need to detect when a user account downloads an unusually large volume of data compared to the user's established baseline activity. You want to detect this anomalous data access behavior using the least amount of effort. What should you do?
Options
- AInspect Security Command Center (SCC) default findings for data exfiltration in Google SecOps.
- BCreate a log-based metric in Cloud Monitoring, and configure an alert to trigger if the data
- CDevelop a custom YARA-L detection rule in Google SecOps that counts download bytes per user
- DEnable curated detection rules for User and Endpoint Behavioral Analytics (UEBA), and use the
How the community answered
(22 responses)- A5% (1)
- B5% (1)
- C14% (3)
- D77% (17)
Explanation
The most effective and least effort solution is to enable curated UEBA (User and Endpoint Behavioral Analytics) detection rules in Google SecOps and use the Risk Analytics dashboard. UEBA automatically establishes user baselines and detects anomalies such as unusually large data downloads, removing the need to manually define thresholds or build custom rules.
Topics
Community Discussion
No community discussion yet for this question.