PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #119
Your Google Security Operations (SecOps) case queue contains a case with IP address entities. You need to determine whether the entities are internal or external assets and ensure that internal IP…
The correct answer is A. Indicate your organization's known internal CIDR ranges in the Environment Networks list in the. You should indicate your organization's known internal CIDR ranges in the Environment Networks list in the settings. This enables Google SecOps SOAR to automatically recognize and mark IP address entities as internal upon ingestion, ensuring correct tagging and context for case…
Question
Your Google Security Operations (SecOps) case queue contains a case with IP address entities. You need to determine whether the entities are internal or external assets and ensure that internal IP address entities are marked accordingly upon ingestion into Google SecOps SOAR. What should you do?
Options
- AIndicate your organization's known internal CIDR ranges in the Environment Networks list in the
- BModify the connector logic to perform a secondary lookup against your CMDB and flag incoming
- CConfigure a feed to ingest enrichment data about the networks, and include these fields into your
- DCreate a custom action to ping the IP address entity from your Remote Agent. If successful, the
How the community answered
(26 responses)- A77% (20)
- B8% (2)
- C4% (1)
- D12% (3)
Explanation
You should indicate your organization's known internal CIDR ranges in the Environment Networks list in the settings. This enables Google SecOps SOAR to automatically recognize and mark IP address entities as internal upon ingestion, ensuring correct tagging and context for case management and response.
Topics
Community Discussion
No community discussion yet for this question.