PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #127
Your organization has recently acquired Company A, which has its own SOC and security tooling. You have already configured ingestion of Company A's security telemetry and migrated their detection…
The correct answer is C. Define a new SOC role for Company A. The correct first step is to define a new SOC role for Company A within Google SecOps. By assigning appropriate role-based access controls, you can ensure Company A's analysts only see case data originating from their own telemetry, while still being able to reuse existing…
Question
Your organization has recently acquired Company A, which has its own SOC and security tooling. You have already configured ingestion of Company A's security telemetry and migrated their detection rules to Google Security Operations (SecOps). You now need to enable Company A's analysts to work their cases in Google SecOps. You need to ensure that Company A's analysts:
- do not have access to any case data originating from outside of Company A.
- are able to re-purpose playbooks previously developed by your organization's employees.
You need to minimize effort to implement your solution. What is the first step you should take?
Options
- AAcquire a second Google SecOps SOAR tenant for Company A.
- BProvision a new service account for Company A.
- CDefine a new SOC role for Company A.
- DCreate a Google SecOps SOAR environment for Company A.
How the community answered
(32 responses)- A3% (1)
- B9% (3)
- C75% (24)
- D13% (4)
Explanation
The correct first step is to define a new SOC role for Company A within Google SecOps. By assigning appropriate role-based access controls, you can ensure Company A's analysts only see case data originating from their own telemetry, while still being able to reuse existing playbooks from your organization. This approach minimizes effort compared to acquiring or creating new environments or tenants.
Topics
Community Discussion
No community discussion yet for this question.