nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #5

Your company uses Security Command Center (SCC) and Google Security Operations (SecOps). Last week, an attacker attempted to establish persistence by generating a key for an unused service account…

The correct answer is B. Use the Initial Access: Dormant Service Account Key Created finding from SCC, and ingest this. The most efficient solution is to use the built-in SCC detection "Initial Access: Dormant Service Account Key Created", ingest the finding into Google SecOps, and automate the response with a custom SOAR action that deletes the key. This leverages existing SCC findings for…

Security Command Center and SecOps Integration

Question

Your company uses Security Command Center (SCC) and Google Security Operations (SecOps). Last week, an attacker attempted to establish persistence by generating a key for an unused service account. You need to confirm that you are receiving alerts when keys are created for unused service accounts and that newly created keys are automatically deleted. You want to minimize the amount of manual effort required. What should you do?

Options

  • AGenerate a YARA-L rule in Google SecOps that detects when a service account key is created.
  • BUse the Initial Access: Dormant Service Account Key Created finding from SCC, and ingest this
  • CConfigure a Cloud Logging sink to write logs to a Pub/Sub topic that filters for the methodName:
  • DUse the Initial Access: Dormant Service Account Key Created finding from SCC, and write this

How the community answered

(49 responses)
  • A
    4% (2)
  • B
    71% (35)
  • C
    16% (8)
  • D
    8% (4)

Explanation

The most efficient solution is to use the built-in SCC detection "Initial Access: Dormant Service Account Key Created", ingest the finding into Google SecOps, and automate the response with a custom SOAR action that deletes the key. This leverages existing SCC findings for accurate detection, integrates directly with Google SecOps for centralized alerting, and minimizes manual effort by automating remediation.

Topics

#dormant service accounts#SCC findings#automated remediation#service account key management

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice