PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #60
Your Google Security Operations (SecOps) SOAR integration with Security Command Center (SCC) uses a service account that currently has read access to the findings at the organization level. Google…
The correct answer is B. Grant the service account the roles/securitycenter.findingsEditor IAM role at the organization. To allow Google SecOps SOAR to update SCC findings while adhering to least privilege, you should grant the service account the roles/securitycenter.findingsEditor IAM role at the organization level. This role permits modifying the state of findings without granting broader…
Question
Your Google Security Operations (SecOps) SOAR integration with Security Command Center (SCC) uses a service account that currently has read access to the findings at the organization level. Google SecOps SOAR successfully reads SCC finding data, but actions attempting to update the finding states consistently fail with a permission denied error. You need to resolve this error while following the principle of least privilege. What should you do?
Options
- AGrant the service account the roles/securitycenter.findingsBulkMuteEditor IAM role at the
- BGrant the service account the roles/securitycenter.findingsEditor IAM role at the organization
- CGrant the service account the roles/iam.serviceAccountUser IAM role to itself.
- DRegenerate the service account key, and update the credentials in Google SecOps SOAR.
How the community answered
(36 responses)- A6% (2)
- B83% (30)
- C3% (1)
- D8% (3)
Explanation
To allow Google SecOps SOAR to update SCC findings while adhering to least privilege, you should grant the service account the roles/securitycenter.findingsEditor IAM role at the organization level. This role permits modifying the state of findings without granting broader administrative privileges.
Topics
Community Discussion
No community discussion yet for this question.