nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #19

Your company's SOC recently responded to a ransomware incident that began with the execution of a malicious document. EDR tools contained the initial infection. However, multiple privileged service ac

Sign in or unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER to reveal the answer and full explanation for question #19. The question stem and answer options stay visible for context.

Responding to Threats

Question

Your company's SOC recently responded to a ransomware incident that began with the execution of a malicious document. EDR tools contained the initial infection. However, multiple privileged service accounts continued to exhibit anomalous behavior, including credential dumping and scheduled task creation. You need to design an automated playbook in Google Security Operations (SecOps) SOAR to minimize dwell time and accelerate containment for future similar attacks. Which action should you take in your Google SecOps SOAR playbook to support containment and escalation?

Options

  • AConfigure a step that revokes OAuth tokens and suspends sessions for high-privilege accounts
  • BAdd an approval step that requires an analyst to validate the alert before executing a containment
  • CCreate an external API call to VirusTotal to submit hashes from forensic artifacts.
  • DAdd a YARA-L rule that sends an alert when a document is executed using a scripting engine

Unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER to see the answer

You've previewed enough free PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER questions. Unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#SOAR playbook#ransomware containment#privileged account response#automated remediation
Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice