nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #37

Your organization recently conducted a penetration test on their environment. You have been tasked with identifying a successful attack chain. The required log sources have been ingested into Google S

Sign in or unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER to reveal the answer and full explanation for question #37. The question stem and answer options stay visible for context.

Threat Detection and Investigation

Question

Your organization recently conducted a penetration test on their environment. You have been tasked with identifying a successful attack chain. The required log sources have been ingested into Google Security Operations (SecOps). You discover anomalous outbound traffic to external domains. You suspect that the finding is a communication to a command and control (C2) infrastructure. You need to identify the least common network communications over the last 14 days. What should you do?

Options

  • APerform a Google SecOps SIEM UDM search that looks for NETWORK_CONNECTION or
  • BPerform a Google SecOps SIEM UDM search that looks for NETWORK_CONNECTION or
  • CPerform a Google SecOps SOAR search that looks for cases with low rolling prevalence of
  • DPerform a Google SecOps SIEM raw log search that looks for low rolling prevalence domains with

Unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER to see the answer

You've previewed enough free PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER questions. Unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#C2 detection#network prevalence#UDM search#threat hunting
Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice