PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #110
You received an IOC from your threat intelligence feed that is identified as a suspicious domain used for command and control (C2). You want to use Google Security Operations (SecOps) to investigate…
The correct answer is B. Configure a UDM search that queries the DNS section of the network noun.. The most efficient approach is to configure a UDM search that queries the DNS section of the network noun. This allows you to directly search normalized DNS queries and responses for the suspicious domain across all relevant logs, ensuring comprehensive and accurate results while
Question
You received an IOC from your threat intelligence feed that is identified as a suspicious domain used for command and control (C2). You want to use Google Security Operations (SecOps) to investigate whether this domain appeared in your environment. You want to search for this IOC using the most efficient approach. What should you do?
Options
- ARun a raw log search to search for the domain string.
- BConfigure a UDM search that queries the DNS section of the network noun.
- CEnable Group by Field in scan view to cluster events by hostname.
- DEnter the IOC into the IOC Search feature, and wait for detections with this domain to appear in
How the community answered
(38 responses)- A18% (7)
- B71% (27)
- C8% (3)
- D3% (1)
Explanation
The most efficient approach is to configure a UDM search that queries the DNS section of the network noun. This allows you to directly search normalized DNS queries and responses for the suspicious domain across all relevant logs, ensuring comprehensive and accurate results while minimizing noise and manual review.
Topics
Community Discussion
No community discussion yet for this question.