PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #3
Your organization uses Google Security Operations (SecOps). You need to identify the most commonly occurring processes and applications across your organization's large number of servers so you can…
The correct answer is B. Run a UDM search, and review aggregations for relevant process-related UDM fields. The most efficient method is to run a UDM search and use aggregations on process-related UDM fields. This allows you to quickly identify the most common processes and applications across all servers, providing accurate data to establish baselines and exclusion lists without…
Question
Your organization uses Google Security Operations (SecOps). You need to identify the most commonly occurring processes and applications across your organization's large number of servers so you can implement baselines and exclusion lists on a regular basis. You want to use the most efficient approach. What should you do?
Options
- AUse the UDM lookup feature to identify relevant process-related UDM fields and values.
- BRun a UDM search, and review aggregations for relevant process-related UDM fields.
- CReview the Google SecOps SIEM Rules & Detections, and identify the most common processes
- DGenerate a Google SecOps SIEM dashboard based on relevant UDM fields, such as processes,
How the community answered
(53 responses)- A8% (4)
- B74% (39)
- C4% (2)
- D15% (8)
Explanation
The most efficient method is to run a UDM search and use aggregations on process-related UDM fields. This allows you to quickly identify the most common processes and applications across all servers, providing accurate data to establish baselines and exclusion lists without relying only on alerts or dashboards.
Topics
Community Discussion
No community discussion yet for this question.