PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #76
You are conducting proactive threat hunting in your company's Google Cloud environment. You suspect that an attacker compromised a developer's credentials and is attempting to move laterally from a…
The correct answer is A. In the Security Command Center (SCC) console, apply filters for the cluster and analyze the. The most effective next step is to use Security Command Center (SCC) to filter for the relevant GKE cluster and analyze the aggregated findings. By examining the timeline and attack exposure scores, you can quickly identify potential IOCs and prioritize investigative actions…
Question
You are conducting proactive threat hunting in your company's Google Cloud environment. You suspect that an attacker compromised a developer's credentials and is attempting to move laterally from a development Google Kubernetes Engine (GKE) cluster to critical production systems. You need to identify IOCs and prioritize investigative actions by using Google Cloud's security tools before analyzing raw logs in detail. What should you do next?
Options
- AIn the Security Command Center (SCC) console, apply filters for the cluster and analyze the
- BReview threat intelligence feeds within Google Security Operations (SecOps), and enrich any
- CInvestigate Virtual Machine (VM) Threat Detection findings in Security Command Center (SCC).
- DCreate a Google SecOps SOAR playbook that automatically isolates any GKE resources
How the community answered
(36 responses)- A72% (26)
- B8% (3)
- C17% (6)
- D3% (1)
Explanation
The most effective next step is to use Security Command Center (SCC) to filter for the relevant GKE cluster and analyze the aggregated findings. By examining the timeline and attack exposure scores, you can quickly identify potential IOCs and prioritize investigative actions. This approach leverages Google Cloud's built-in security tools for initial triage before diving into raw log analysis.
Topics
Community Discussion
No community discussion yet for this question.