nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #23

You are a security analyst at an organization that uses Google Security Operations (SecOps). You notice suspicious login attempts on several user accounts. You need to determine whether these…

The correct answer is D. Look for correlations across impacted users in the Risk Analytics dashboard. The fastest way to assess whether suspicious login attempts are part of a coordinated attack is to use the Risk Analytics dashboard in Google SecOps. This dashboard correlates activity across multiple users, accounts, and entities, allowing you to quickly identify shared…

Investigating Threats

Question

You are a security analyst at an organization that uses Google Security Operations (SecOps). You notice suspicious login attempts on several user accounts. You need to determine whether these attempts are part of a coordinated attack as quickly as possible. What action should you take first?

Options

  • AEnable default curated detections to automatically block suspicious IP addresses.
  • BUse UDM Search to query historical logs for recent IOCs associated with the suspicious login
  • CRemove user accounts that have repeated invalid login attempts.
  • DLook for correlations across impacted users in the Risk Analytics dashboard.

How the community answered

(51 responses)
  • A
    10% (5)
  • B
    4% (2)
  • C
    2% (1)
  • D
    84% (43)

Explanation

The fastest way to assess whether suspicious login attempts are part of a coordinated attack is to use the Risk Analytics dashboard in Google SecOps. This dashboard correlates activity across multiple users, accounts, and entities, allowing you to quickly identify shared patterns or indicators of compromise across affected accounts.

Topics

#Risk Analytics#coordinated attack detection#login anomaly#threat correlation

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice