PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #6
Your company recently adopted Security Command Center (SCC) but is not using Google Security Operations (SecOps). Your organization has thousands of active projects. You need to detect anomalous behav
Sign in or unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER to reveal the answer and full explanation for question #6. The question stem and answer options stay visible for context.
Question
Your company recently adopted Security Command Center (SCC) but is not using Google Security Operations (SecOps). Your organization has thousands of active projects. You need to detect anomalous behavior in your Google Cloud environment by windowing and aggregating data over a given time period, based on specific log events or advanced calculations. You also need to provide an interface for analysts to triage the alerts. How should you build this capability?
Options
- ASend the logs to Cloud SQL, and run a scheduled query against these events using a Cloud Run
- BSink the logs to BigQuery, and configure Cloud Run functions to execute a periodic job and
- CUse log-based metrics to generate event-driven alerts for the detection scenarios. Configure a
- DCreate a series of aggregated log sinks for each required finding, and send the normalized
Unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER to see the answer
You've previewed enough free PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER questions. Unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.