PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #124
Your organization uses Google Security Operations (SecOps). You discover frequent file downloads from a shared workspace within a short time window. You need to configure a rule in Google SecOps…
The correct answer is B. Create a frequency-based YARA-L detection rule that assigns a risk outcome score and is. The correct approach is to create a frequency-based YARA-L detection rule in Google SecOps. Frequency-based rules allow you to detect repeated suspicious behavior, such as multiple file downloads within a short time window, and assign higher risk outcome scores accordingly…
Question
Your organization uses Google Security Operations (SecOps). You discover frequent file downloads from a shared workspace within a short time window. You need to configure a rule in Google SecOps that identifies these suspicious events and assigns higher risk scores to repeated anomalies. What should you do?
Options
- AConfigure a rule that flags file download events with the highest risk score, regardless of time
- BCreate a frequency-based YARA-L detection rule that assigns a risk outcome score and is
- CConfigure a single-event YARA-L detection rule that assigns a risk outcome score and is
- DEnable default curated detections, and use automatic alerting for single file download events.
How the community answered
(57 responses)- A4% (2)
- B75% (43)
- C14% (8)
- D7% (4)
Explanation
The correct approach is to create a frequency-based YARA-L detection rule in Google SecOps. Frequency-based rules allow you to detect repeated suspicious behavior, such as multiple file downloads within a short time window, and assign higher risk outcome scores accordingly. This ensures anomalies are prioritized based on their frequency and severity, rather than flagging isolated single events.
Topics
Community Discussion
No community discussion yet for this question.