nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #63

Your company's Google Security Operations (SecOps) instance has three roles: Tier 1, Tier 2, and Tier 3. Currently, analysts in all tiers can access all cases in Google SecOps. Your company's SOC…

The correct answer is C. Configure the Cross Environment Policy to allow users to move cases between environments. The correct solution is to use a separate environment for Tier 3 cases and configure Cross Environment Policy so that only Tier 3 analysts can access that environment. This ensures strict role-based access control, preventing Tier 1 and Tier 2 analysts from viewing Tier 3 cases…

Configuring the environment

Question

Your company's Google Security Operations (SecOps) instance has three roles: Tier 1, Tier 2, and Tier 3. Currently, analysts in all tiers can access all cases in Google SecOps. Your company's SOC has a new requirement to restrict access to cases assigned to the Tier 3 role from the other tiers. You need to ensure cases that are assigned to the Tier 3 role can only be accessed by Tier 3 analysts. What should you do?

Options

  • AInstruct analysts in Tier 1 and Tier 2 to create a case queue filter to exclude cases assigned to
  • BRevoke additional role access from Tier 1 and Tier 2 analysts.
  • CConfigure the Cross Environment Policy to allow users to move cases between environments.
  • DAssign the cases to a user in the Tier 3 role.

How the community answered

(50 responses)
  • A
    4% (2)
  • B
    12% (6)
  • C
    78% (39)
  • D
    6% (3)

Explanation

The correct solution is to use a separate environment for Tier 3 cases and configure Cross Environment Policy so that only Tier 3 analysts can access that environment. This ensures strict role-based access control, preventing Tier 1 and Tier 2 analysts from viewing Tier 3 cases while still allowing appropriate case management and escalation workflows.

Topics

#Cross Environment Policy#case access control#SOC role segmentation#SOAR case management

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice