PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #23
You are a security analyst at an organization that uses Google Security Operations (SecOps). You notice suspicious login attempts on several user accounts. You need to determine whether these…
The correct answer is D. Look for correlations across impacted users in the Risk Analytics dashboard. The fastest way to assess whether suspicious login attempts are part of a coordinated attack is to use the Risk Analytics dashboard in Google SecOps. This dashboard correlates activity across multiple users, accounts, and entities, allowing you to quickly identify shared…
Question
You are a security analyst at an organization that uses Google Security Operations (SecOps). You notice suspicious login attempts on several user accounts. You need to determine whether these attempts are part of a coordinated attack as quickly as possible. What action should you take first?
Options
- AEnable default curated detections to automatically block suspicious IP addresses.
- BUse UDM Search to query historical logs for recent IOCs associated with the suspicious login
- CRemove user accounts that have repeated invalid login attempts.
- DLook for correlations across impacted users in the Risk Analytics dashboard.
How the community answered
(51 responses)- A10% (5)
- B4% (2)
- C2% (1)
- D84% (43)
Explanation
The fastest way to assess whether suspicious login attempts are part of a coordinated attack is to use the Risk Analytics dashboard in Google SecOps. This dashboard correlates activity across multiple users, accounts, and entities, allowing you to quickly identify shared patterns or indicators of compromise across affected accounts.
Topics
Community Discussion
No community discussion yet for this question.