nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #110

You received an IOC from your threat intelligence feed that is identified as a suspicious domain used for command and control (C2). You want to use Google Security Operations (SecOps) to investigate…

The correct answer is B. Configure a UDM search that queries the DNS section of the network noun.. The most efficient approach is to configure a UDM search that queries the DNS section of the network noun. This allows you to directly search normalized DNS queries and responses for the suspicious domain across all relevant logs, ensuring comprehensive and accurate results while

Security Investigation and Threat Hunting

Question

You received an IOC from your threat intelligence feed that is identified as a suspicious domain used for command and control (C2). You want to use Google Security Operations (SecOps) to investigate whether this domain appeared in your environment. You want to search for this IOC using the most efficient approach. What should you do?

Options

  • ARun a raw log search to search for the domain string.
  • BConfigure a UDM search that queries the DNS section of the network noun.
  • CEnable Group by Field in scan view to cluster events by hostname.
  • DEnter the IOC into the IOC Search feature, and wait for detections with this domain to appear in

How the community answered

(38 responses)
  • A
    18% (7)
  • B
    71% (27)
  • C
    8% (3)
  • D
    3% (1)

Explanation

The most efficient approach is to configure a UDM search that queries the DNS section of the network noun. This allows you to directly search normalized DNS queries and responses for the suspicious domain across all relevant logs, ensuring comprehensive and accurate results while minimizing noise and manual review.

Topics

#UDM search#domain IOC#C2 investigation#DNS fields

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice