nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #41

You are a security operations engineer in an enterprise that uses Google Security Operations (SecOps). Your organization recently faced a cybersecurity breach. You need to increase the threat…

The correct answer is A. Enable curated detections to identify threats. The fastest way to increase threat analytics in Google SecOps after a breach is to enable curated detections. These are prebuilt, continuously updated detection rules maintained by Google that provide immediate coverage against a wide range of threats, requiring no custom…

Threat Detection and Investigation

Question

You are a security operations engineer in an enterprise that uses Google Security Operations (SecOps). Your organization recently faced a cybersecurity breach. You need to increase the threat analytics as quickly as possible. What should you do?

Options

  • AEnable curated detections to identify threats.
  • BDesign YARA-L detection rules based on Google SecOps Marketplace use cases.
  • CDevelop YARA-L detection rules that focus on threat intelligence.
  • DIngest data from a threat intelligence platform (TIP) into Google SecOps.

How the community answered

(23 responses)
  • A
    70% (16)
  • B
    9% (2)
  • C
    17% (4)
  • D
    4% (1)

Explanation

The fastest way to increase threat analytics in Google SecOps after a breach is to enable curated detections. These are prebuilt, continuously updated detection rules maintained by Google that provide immediate coverage against a wide range of threats, requiring no custom development and delivering quick improvements in visibility and response.

Topics

#curated detections#threat analytics#SecOps SIEM#detection rules

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice