PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #30
You are writing a detection rule in Google Security Operations (SecOps) SIEM that sends a risk score to the alert. You have access to Google Threat Intelligence (GTI) data through your Google SecOps s
Sign in or unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER to reveal the answer and full explanation for question #30. The question stem and answer options stay visible for context.
Question
You are writing a detection rule in Google Security Operations (SecOps) SIEM that sends a risk score to the alert. You have access to Google Threat Intelligence (GTI) data through your Google SecOps subscription. You need to ensure that the threat score output in the detection logic informs the alert's risk score and is available for future detections. What should you do?
Options
- AUse the outcomes section of your detection logic to pull UDM enrichment fields from the event
- BUse the match section of your detection logic to filter out irrelevant entities. Store the remaining
- CConfigure a feed in Google SecOps SIEM to ingest GTI data to automatically enrich the
- DCreate a Google SecOps SOAR playbook to query GTI that uses the VirusTotal integration to
Unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER to see the answer
You've previewed enough free PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER questions. Unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.