PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #34
Your organization recently implemented Google Security Operations (SecOps) with Applied Threat Intelligence enabled. You were notified by the networking team about potentially anomalous communications
Sign in or unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER to reveal the answer and full explanation for question #34. The question stem and answer options stay visible for context.
Question
Your organization recently implemented Google Security Operations (SecOps) with Applied Threat Intelligence enabled. You were notified by the networking team about potentially anomalous communications to external domains in the last 30 days. You plan to start your threat hunting by looking at communications to external domains. You are ingesting the following logs into Google SecOps:
- Firewall logs
- Proxy logs
- DNS logs
- DHCP logs
What should you do? (Choose two.)
Options
- APerform a UDM search across the logs for domains with geolocations that were first seen in the
- BPerform a UDM search across the logs for domains with low prevalence that were first seen in the
- CPerform a raw log search across the logs for domains with low prevalence that were first seen in
- DIdentify the domains with the higher normalized risk in Risk Analytics. Drill down into those
- ENavigate to the IOC Matches page and filter based on domain type over the last 30 days. Look for
Unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER to see the answer
You've previewed enough free PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER questions. Unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.