PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #31
You are a SOC manager, and your company recently migrated to Google Security Operations (SecOps). As the team grows, you want to monitor all audit logs related to data feeds in Google SecOps. What…
The correct answer is B. Ingest the Google SecOps audit logs into Google SecOps SIEM for monitoring. The correct approach is to ingest Google SecOps audit logs into Google SecOps SIEM. These audit logs capture all activity related to data feeds and platform operations, allowing centralized monitoring, alerting, and investigation of administrative or feed-related actions within…
Question
You are a SOC manager, and your company recently migrated to Google Security Operations (SecOps). As the team grows, you want to monitor all audit logs related to data feeds in Google SecOps. What should you do?
Options
- AEnable Data Access and Admin Activity audit logs in Cloud Logging, and ingest those logs into
- BIngest the Google SecOps audit logs into Google SecOps SIEM for monitoring.
- CMonitor Google SecOps SOAR user activity logs for administrative activity.
- DConfigure the Cloud Logging filter to ingest audit logs related to data feeds into Google SecOps
How the community answered
(61 responses)- A7% (4)
- B70% (43)
- C5% (3)
- D18% (11)
Explanation
The correct approach is to ingest Google SecOps audit logs into Google SecOps SIEM. These audit logs capture all activity related to data feeds and platform operations, allowing centralized monitoring, alerting, and investigation of administrative or feed-related actions within the SecOps
Topics
Community Discussion
No community discussion yet for this question.