nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #16

Your company has deployed two on-premises firewalls. You need to configure the firewalls to send logs to Google Security Operations (SecOps) using Syslog. What should you do?

The correct answer is C. Deploy a third-party agent (e.g Bindplane, NXLog) on your on-premises environment, and set the. On-premises firewalls cannot send logs directly to Google SecOps. The correct approach is to deploy a third-party agent (such as Bindplane or NXLog) in your on-premises environment and configure the firewalls to forward Syslog data to that agent. The agent then reliably…

Configuring the Google SecOps Environment

Question

Your company has deployed two on-premises firewalls. You need to configure the firewalls to send logs to Google Security Operations (SecOps) using Syslog. What should you do?

Options

  • APull the firewall logs by using a Google SecOps feed integration.
  • BSet the Google SecOps URL instance as the Syslog destination.
  • CDeploy a third-party agent (e.g Bindplane, NXLog) on your on-premises environment, and set the
  • DDeploy a Google Ops Agent on your on-premises environment, and set the agent as the Syslog

How the community answered

(21 responses)
  • A
    14% (3)
  • B
    10% (2)
  • C
    71% (15)
  • D
    5% (1)

Explanation

On-premises firewalls cannot send logs directly to Google SecOps. The correct approach is to deploy a third-party agent (such as Bindplane or NXLog) in your on-premises environment and configure the firewalls to forward Syslog data to that agent. The agent then reliably forwards the logs to Google SecOps for ingestion.

Topics

#log ingestion#Syslog forwarding#on-premises forwarder#BindPlane agent

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice