nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #64

You are the lead engineer on your organization's incident response team. You are running CrowdStrike Falcon and SentinelOne to protect the Windows devices in different regions of your organization…

The correct answer is A. Enable the Windows Threats category in curated detections to detect the latest Windows threats. C. Install SOAR EDR integrations for endpoint containment actions. Create a playbook to contain. Enabling the Windows Threats category in curated detections ensures that the latest ransomware and other Windows-specific threats are automatically detected without creating custom rules, improving detection speed. Installing SOAR EDR integrations allows automated containment…

Responding to threats and incidents

Question

You are the lead engineer on your organization's incident response team. You are running CrowdStrike Falcon and SentinelOne to protect the Windows devices in different regions of your organization. You are ingesting the following logs into Google Security Operations (SecOps):

  • Azure AD Directory Audit (AZURE_AD_AUDIT)
  • Crowdstrike Falcon (CS_EDR)
  • Microsoft Sysmon (WINDOWS_SYSMON)
  • SentinelOne (SENTINEL_EDR)
  • Windows Event (WINEVTLOG)

You notice that a high volume of ransomware incidents are impacting your team's SLAs. You need to automate the response to ransomware on Windows devices. How should you automate the detection and containment of ransomware incidents? (Choose two.)

Options

  • AEnable the Windows Threats category in curated detections to detect the latest Windows threats.
  • BEnable the Risk Analytics for User and Endpoint Behavioral Analytics (UEBA) category in curated
  • CInstall SOAR EDR integrations for endpoint containment actions. Create a playbook to contain
  • DInstall SOAR EDR jobs to execute remote endpoint containment actions. Create a playbook to
  • EInstall a SOAR remote agent on each Windows device for endpoint containment actions. Create a

How the community answered

(23 responses)
  • A
    74% (17)
  • B
    4% (1)
  • D
    4% (1)
  • E
    17% (4)

Explanation

Enabling the Windows Threats category in curated detections ensures that the latest ransomware and other Windows-specific threats are automatically detected without creating custom rules, improving detection speed. Installing SOAR EDR integrations allows automated containment actions (e.g., isolating impacted endpoints). Creating a playbook based on these curated detections automates response to ransomware incidents, reducing SLA impact and manual effort.

Topics

#ransomware response automation#EDR integration#SOAR playbook#endpoint containment

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice