PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #12
Your organization uses Security Command Center (SCC) and relies on Compute Engine instances to run business-critical workloads. SCC has flagged a particular instance for exhibiting a high volume of…
The correct answer is D. Analyze Event Threat Detection findings. Review the events and the outbound network. The correct action is to analyze Event Threat Detection (ETD) findings in SCC, which provide detailed insights into suspicious activities such as unusual outbound network connections. Reviewing these findings allows you to correlate the flagged activity with the instance's…
Question
Your organization uses Security Command Center (SCC) and relies on Compute Engine instances to run business-critical workloads. SCC has flagged a particular instance for exhibiting a high volume of outbound network connections to geographically diverse and unknown IP addresses. You need to determine whether the instance has been compromised by malware. What should you do?
Options
- AExamine the IAM roles assigned to the service account that are associated with the instance.
- BReview the Google Cloud Service Health dashboard to identify any ongoing Google Cloud
- CDisable and re-enable the instances' network interface and determine whether the unusual
- DAnalyze Event Threat Detection findings. Review the events and the outbound network
How the community answered
(19 responses)- A5% (1)
- B16% (3)
- C5% (1)
- D74% (14)
Explanation
The correct action is to analyze Event Threat Detection (ETD) findings in SCC, which provide detailed insights into suspicious activities such as unusual outbound network connections. Reviewing these findings allows you to correlate the flagged activity with the instance's outbound traffic patterns, helping determine whether the instance is compromised by malware.
Topics
Community Discussion
No community discussion yet for this question.