PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #4
You work for an organization that uses Security Command Center (SCC) with Event Threat Detection (ETD) enabled. You need to enable ETD detections for data exfiltration attempts from designated…
The correct answer is A. Enable "data read" audit logs only for the designated sensitive Cloud Storage buckets and. To detect data exfiltration attempts from sensitive Cloud Storage buckets and BigQuery datasets using ETD, you only need "data read" audit logs. These logs capture access and read events (which indicate potential exfiltration). Enabling them only for the designated sensitive…
Question
You work for an organization that uses Security Command Center (SCC) with Event Threat Detection (ETD) enabled. You need to enable ETD detections for data exfiltration attempts from designated sensitive Cloud Storage buckets and BigQuery datasets. You want to minimize Cloud Logging costs. What should you do?
Options
- AEnable "data read" audit logs only for the designated sensitive Cloud Storage buckets and
- BEnable "data read" and "data write" audit logs only for the designated sensitive Cloud Storage
- CEnable "data read" and "data write" audit logs for all Cloud Storage buckets and BigQuery
- DEnable VPC Flow Logs for the VPC networks containing resources that access the sensitive
How the community answered
(51 responses)- A75% (38)
- B4% (2)
- C6% (3)
- D16% (8)
Explanation
To detect data exfiltration attempts from sensitive Cloud Storage buckets and BigQuery datasets using ETD, you only need "data read" audit logs. These logs capture access and read events (which indicate potential exfiltration). Enabling them only for the designated sensitive resources minimizes Cloud Logging costs while still providing the necessary visibility for detections.
Topics
Community Discussion
No community discussion yet for this question.