PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #58
You are receiving security alerts from multiple connectors in your Google Security Operations (SecOps) instance. You need to identify which IP address entities are internal to your network and label…
The correct answer is B. Enrich the IP address entities as the initial step of the playbook. The correct approach is to enrich the IP address entities as the initial step of the playbook. Enrichment lets you identify whether an IP is internal and tag it with the appropriate network name. This enriched network name can then be used as the trigger condition for…
Question
You are receiving security alerts from multiple connectors in your Google Security Operations (SecOps) instance. You need to identify which IP address entities are internal to your network and label each entity with its specific network name. This network name will be used as the trigger for the playbook. What should you do?
Options
- AConfigure each network in the Google SecOps SOAR settings.
- BEnrich the IP address entities as the initial step of the playbook.
- CModify the entity attribute in the alert overview.
- DCreate an outcome variable in the rule to assign the network name.
How the community answered
(32 responses)- A3% (1)
- B75% (24)
- C6% (2)
- D16% (5)
Explanation
The correct approach is to enrich the IP address entities as the initial step of the playbook. Enrichment lets you identify whether an IP is internal and tag it with the appropriate network name. This enriched network name can then be used as the trigger condition for subsequent playbook actions.
Topics
Community Discussion
No community discussion yet for this question.