nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #15

Your organization recently acquired a Google Security Operations (SecOps) Enterprise Plus license. Your organization is already ingesting Cloud Audit Logs, firewall logs, proxy logs and endpoint…

The correct answer is C. Enable and configure alerting for relevant curated detection rule sets. The fastest and most effective way to alert on IOCs in Google SecOps is to enable and configure curated detection rule sets. These curated rules are maintained by Google and automatically updated with the latest threat intelligence, ensuring that if an IOC from an active breach…

Detecting Threats

Question

Your organization recently acquired a Google Security Operations (SecOps) Enterprise Plus license. Your organization is already ingesting Cloud Audit Logs, firewall logs, proxy logs and endpoint logs, but there are no threat intelligence feeds being ingested into your Google SecOps environment. You need to design and deploy a solution that alerts your team quickly if an IOC of an active breach is observed in your environment. What should you do?

Options

  • AWrite, enable, and configure alerting on a custom multi-event rule.
  • BWrite, enable, and configure alerting on a custom single-event rule.
  • CEnable and configure alerting for relevant curated detection rule sets.
  • DCreate and schedule a dashboard to send periodic summaries of the active breach IOCs and

How the community answered

(55 responses)
  • A
    9% (5)
  • B
    5% (3)
  • C
    84% (46)
  • D
    2% (1)

Explanation

The fastest and most effective way to alert on IOCs in Google SecOps is to enable and configure curated detection rule sets. These curated rules are maintained by Google and automatically updated with the latest threat intelligence, ensuring that if an IOC from an active breach is observed in your ingested logs, your team will receive alerts without the need to manually create or maintain custom rules.

Topics

#curated detections#IOC alerting#threat intelligence feeds#detection rule sets

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice