PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #66
You work for an organization that operates an ecommerce platform. You have identified a remote shell on your company's web host. The existing incident response playbook is outdated and lacks…
The correct answer is B. Use the playbook creation feature in Gemini, and enter details about the intended objectives. Add. The fastest and most effective way to create a functional playbook for junior analysts is to use Gemini's playbook creation feature, provide the intended objectives, and then customize it for your environment. Testing the generated playbook against a simulated remote shell…
Question
You work for an organization that operates an ecommerce platform. You have identified a remote shell on your company's web host. The existing incident response playbook is outdated and lacks specific procedures for handling this attack. You want to create a new, functional playbook that can be deployed as soon as possible by junior analysts. You plan to use available tools in Google Security Operations (SecOps) to streamline the playbook creation process. What should you do?
Options
- AAdd instruction actions to the existing incident response playbook that include updated
- BUse the playbook creation feature in Gemini, and enter details about the intended objectives. Add
- CUse Gemini to generate a playbook based on a template from a standard incident response plan
- DCreate a new custom playbook based on industry best practices, and work with an offensive
How the community answered
(50 responses)- A2% (1)
- B84% (42)
- C6% (3)
- D8% (4)
Explanation
The fastest and most effective way to create a functional playbook for junior analysts is to use Gemini's playbook creation feature, provide the intended objectives, and then customize it for your environment. Testing the generated playbook against a simulated remote shell alert ensures it is practical and ready for deployment, streamlining creation while leveraging Google SecOps
Topics
Community Discussion
No community discussion yet for this question.