PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #115
You are helping a new Google Security Operations (SecOps) customer configure access for their SOC team. The Google SecOps administrators currently have access to the instance. The customer is…
The correct answer is D. Grant the roles/chronicle.viewer role to the SOC team's IdP group in IAM. E. Grant the Basic permission to the appropriate IdP groups in the Google SecOps SOAR Advanced. Granting the roles/chronicle.viewer role to the SOC team's IdP group in IAM provides the necessary permissions for users to access the Google SecOps instance. Granting the Basic permission to the appropriate IdP groups in the Google SecOps SOAR Advanced Settings ensures that…
Question
You are helping a new Google Security Operations (SecOps) customer configure access for their SOC team. The Google SecOps administrators currently have access to the instance. The customer is reporting that new Google SecOps users are not getting authorized to access the instance, but they are able to authenticate to the third-party identity provider (IdP). How should you fix the issue? (Choose two.)
Options
- ALink Google SecOps to a Google Cloud project with the Chronicle API.
- BIntegrate Google SecOps with the third-party IdP using Workforce Identity Federation.
- CGrant the appropriate data access scope to the SOC team's IdP group in IAM.
- DGrant the roles/chronicle.viewer role to the SOC team's IdP group in IAM.
- EGrant the Basic permission to the appropriate IdP groups in the Google SecOps SOAR Advanced
How the community answered
(52 responses)- A4% (2)
- B12% (6)
- C6% (3)
- D79% (41)
Explanation
Granting the roles/chronicle.viewer role to the SOC team's IdP group in IAM provides the necessary permissions for users to access the Google SecOps instance. Granting the Basic permission to the appropriate IdP groups in the Google SecOps SOAR Advanced Settings ensures that these users have the correct access at the application level.
Topics
Community Discussion
No community discussion yet for this question.