PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #20
Your organization uses Google Security Operations (SecOps) for security analysis and investigation. Your organization has decided that all security cases related to Data Loss Prevention (DLP) events…
The correct answer is A. Customize the Close Case dialog and add the five DLP event types as root cause options. The correct solution is to customize the Close Case dialog in Google SecOps to include the five defined DLP event types as selectable root cause options. This enforces consistent categorization at case closure, ensuring analysts must assign the correct DLP event type root cause…
Question
Your organization uses Google Security Operations (SecOps) for security analysis and investigation. Your organization has decided that all security cases related to Data Loss Prevention (DLP) events must be categorized with a defined root cause specific to one of five DLP event types when the case is closed in Google SecOps. How should you achieve this?
Options
- ACustomize the Close Case dialog and add the five DLP event types as root cause options.
- BCustomize the Case Name format to include the DLP event type.
- CCreate a Google SecOps SOAR playbook that automatically assigns case tags where each tag
- DCreate case tags in Google SecOps SOAR where each tag contains a unique definition of each of
How the community answered
(26 responses)- A77% (20)
- B4% (1)
- C15% (4)
- D4% (1)
Explanation
The correct solution is to customize the Close Case dialog in Google SecOps to include the five defined DLP event types as selectable root cause options. This enforces consistent categorization at case closure, ensuring analysts must assign the correct DLP event type root cause before completing the workflow.
Topics
Community Discussion
No community discussion yet for this question.