nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #51

You are a security analyst at a company that uses Google Security Operations (SecOps) Enterprise. Security Command Center Enterprise (SCCE), and Google Threat Intelligence (GTI). You need to leverage

The correct answer is B. Configure an Applied Threat Intelligence Fusion Feed in Google SecOps, and develop YARA-L. The correct solution is to configure an Applied Threat Intelligence Fusion Feed in Google SecOps and then develop YARA-L detection rules to search your Google Cloud telemetry for attack patterns tied to this intelligence. This enables proactive, near real-time hunting of novel an

Threat Detection and Investigation

Question

You are a security analyst at a company that uses Google Security Operations (SecOps) Enterprise. Security Command Center Enterprise (SCCE), and Google Threat Intelligence (GTI). You need to leverage threat intelligence to improve threat hunting capabilities to proactively identify novel and emerging attack patterns targeting your Google Cloud environment in near real-time. What should you do?

Options

  • AUse the built-in threat intelligence of Event Threat Detection in SCCE to detect relevant threats.
  • BConfigure an Applied Threat Intelligence Fusion Feed in Google SecOps, and develop YARA-L
  • CRoute all Google Cloud logs to a dedicated BigQuery dataset, and use scheduled queries with
  • DConfigure Google Cloud Armor security policies with preconfigured web application firewall (WAF)

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    79% (26)
  • C
    6% (2)
  • D
    12% (4)

Explanation

The correct solution is to configure an Applied Threat Intelligence Fusion Feed in Google SecOps and then develop YARA-L detection rules to search your Google Cloud telemetry for attack patterns tied to this intelligence. This enables proactive, near real-time hunting of novel and emerging threats by correlating threat intelligence with your organization's ingested data.

Topics

#Applied Threat Intelligence#fusion feed#YARA-L rules#emerging threats

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice