PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #51
You are a security analyst at a company that uses Google Security Operations (SecOps) Enterprise. Security Command Center Enterprise (SCCE), and Google Threat Intelligence (GTI). You need to leverage
The correct answer is B. Configure an Applied Threat Intelligence Fusion Feed in Google SecOps, and develop YARA-L. The correct solution is to configure an Applied Threat Intelligence Fusion Feed in Google SecOps and then develop YARA-L detection rules to search your Google Cloud telemetry for attack patterns tied to this intelligence. This enables proactive, near real-time hunting of novel an
Question
You are a security analyst at a company that uses Google Security Operations (SecOps) Enterprise. Security Command Center Enterprise (SCCE), and Google Threat Intelligence (GTI). You need to leverage threat intelligence to improve threat hunting capabilities to proactively identify novel and emerging attack patterns targeting your Google Cloud environment in near real-time. What should you do?
Options
- AUse the built-in threat intelligence of Event Threat Detection in SCCE to detect relevant threats.
- BConfigure an Applied Threat Intelligence Fusion Feed in Google SecOps, and develop YARA-L
- CRoute all Google Cloud logs to a dedicated BigQuery dataset, and use scheduled queries with
- DConfigure Google Cloud Armor security policies with preconfigured web application firewall (WAF)
How the community answered
(33 responses)- A3% (1)
- B79% (26)
- C6% (2)
- D12% (4)
Explanation
The correct solution is to configure an Applied Threat Intelligence Fusion Feed in Google SecOps and then develop YARA-L detection rules to search your Google Cloud telemetry for attack patterns tied to this intelligence. This enables proactive, near real-time hunting of novel and emerging threats by correlating threat intelligence with your organization's ingested data.
Topics
Community Discussion
No community discussion yet for this question.