nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #45

You are creating a playbook for the SOC. The SOC requires that each Google Security Operations (SecOps) role sees different information for the alert that the playbook runs on. You need to ensure…

The correct answer is A. Add a view to the playbook for each Google SecOps role. The correct approach is to add a view to the playbook for each Google SecOps role. Views allow you to control what information is displayed based on the role, ensuring that each SOC role only sees the relevant details for their responsibilities during alert handling.

Security Orchestration and Automation

Question

You are creating a playbook for the SOC. The SOC requires that each Google Security Operations (SecOps) role sees different information for the alert that the playbook runs on. You need to ensure that the playbook presents the relevant information for each Google SecOps role. What should you do?

Options

  • AAdd a view to the playbook for each Google SecOps role.
  • BAdd the Case Comment action to the playbook for each Google SecOps role.
  • CAdd the Create Siemplify Task action to the playbook to assign a task to each Google SecOps
  • DAdd the Add General insight action to the playbook for each Google SecOps role.

How the community answered

(64 responses)
  • A
    73% (47)
  • B
    3% (2)
  • C
    17% (11)
  • D
    6% (4)

Explanation

The correct approach is to add a view to the playbook for each Google SecOps role. Views allow you to control what information is displayed based on the role, ensuring that each SOC role only sees the relevant details for their responsibilities during alert handling.

Topics

#playbook design#role-based views#SOAR#alert presentation

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice