PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #37
Your organization recently conducted a penetration test on their environment. You have been tasked with identifying a successful attack chain. The required log sources have been ingested into Google S
Sign in or unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER to reveal the answer and full explanation for question #37. The question stem and answer options stay visible for context.
Question
Your organization recently conducted a penetration test on their environment. You have been tasked with identifying a successful attack chain. The required log sources have been ingested into Google Security Operations (SecOps). You discover anomalous outbound traffic to external domains. You suspect that the finding is a communication to a command and control (C2) infrastructure. You need to identify the least common network communications over the last 14 days. What should you do?
Options
- APerform a Google SecOps SIEM UDM search that looks for NETWORK_CONNECTION or
- BPerform a Google SecOps SIEM UDM search that looks for NETWORK_CONNECTION or
- CPerform a Google SecOps SOAR search that looks for cases with low rolling prevalence of
- DPerform a Google SecOps SIEM raw log search that looks for low rolling prevalence domains with
Unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER to see the answer
You've previewed enough free PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER questions. Unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.