nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #56

Your team has onboarded a new log source from a third-party DNS filtering solution. After ingestion, you observe that key UDM fields such as network.dns.questions.name and metadata.product_event_type

Sign in or unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER to reveal the answer and full explanation for question #56. The question stem and answer options stay visible for context.

Managing data ingestion and parsing

Question

Your team has onboarded a new log source from a third-party DNS filtering solution. After ingestion, you observe that key UDM fields such as network.dns.questions.name and metadata.product_event_type are missing from the parsed events in Google Security Operations (SecOps). You suspect that the default parser does not fully align with the source format. You need to ensure these fields are available for downstream detection rules that rely on DNS query telemetry and event categorization. What should you do?

Options

  • AModify the ingestion source definition to remap raw fields directly to UDM by using the UDM
  • BEnable asset enrichment for the log source to infer missing fields based on correlated host
  • CUse a custom parser that outputs all fields as raw JSON for detection.
  • DCreate a parser extension that maps the missing source fields to the correct UDM fields and

Unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER to see the answer

You've previewed enough free PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER questions. Unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#custom parser extension#UDM field mapping#DNS log ingestion#third-party log source
Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice