PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #125
You are implementing Google Security Operations (SecOps) at your organization. You discover that the current detection rules are too noisy. Due to the high volume of alerts, some true positives…
The correct answer is A. Ingest high-value asset (HVA) data from your configuration management database (CMDB). Ingesting high-value asset (HVA) data from the CMDB allows Google SecOps to prioritize alerts based on the sensitivity and criticality of the affected systems. This reduces noise by helping analysts focus on detections involving critical assets, improving the signal-to-noise…
Question
You are implementing Google Security Operations (SecOps) at your organization. You discover that the current detection rules are too noisy. Due to the high volume of alerts, some true positives might be missed. You want to ingest additional context sources to reduce false positives in your security detections and to improve the overall positive ratio of the alerts. What should you do?
Options
- AIngest high-value asset (HVA) data from your configuration management database (CMDB)
- BIngest dark web forum handlers from your threat intelligence system to match dark web principals
- CIngest IOCs from your threat intelligence system to validate the IP addresses, domains and
- DIngest tactics, techniques, and procedures (TTPs) from your threat intelligence system to validate
How the community answered
(42 responses)- A81% (34)
- B7% (3)
- C10% (4)
- D2% (1)
Explanation
Ingesting high-value asset (HVA) data from the CMDB allows Google SecOps to prioritize alerts based on the sensitivity and criticality of the affected systems. This reduces noise by helping analysts focus on detections involving critical assets, improving the signal-to-noise ratio and ensuring true positives on important systems are not missed.
Topics
Community Discussion
No community discussion yet for this question.