nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #76

You are conducting proactive threat hunting in your company's Google Cloud environment. You suspect that an attacker compromised a developer's credentials and is attempting to move laterally from a…

The correct answer is A. In the Security Command Center (SCC) console, apply filters for the cluster and analyze the. The most effective next step is to use Security Command Center (SCC) to filter for the relevant GKE cluster and analyze the aggregated findings. By examining the timeline and attack exposure scores, you can quickly identify potential IOCs and prioritize investigative actions…

Threat Detection and Investigation

Question

You are conducting proactive threat hunting in your company's Google Cloud environment. You suspect that an attacker compromised a developer's credentials and is attempting to move laterally from a development Google Kubernetes Engine (GKE) cluster to critical production systems. You need to identify IOCs and prioritize investigative actions by using Google Cloud's security tools before analyzing raw logs in detail. What should you do next?

Options

  • AIn the Security Command Center (SCC) console, apply filters for the cluster and analyze the
  • BReview threat intelligence feeds within Google Security Operations (SecOps), and enrich any
  • CInvestigate Virtual Machine (VM) Threat Detection findings in Security Command Center (SCC).
  • DCreate a Google SecOps SOAR playbook that automatically isolates any GKE resources

How the community answered

(36 responses)
  • A
    72% (26)
  • B
    8% (3)
  • C
    17% (6)
  • D
    3% (1)

Explanation

The most effective next step is to use Security Command Center (SCC) to filter for the relevant GKE cluster and analyze the aggregated findings. By examining the timeline and attack exposure scores, you can quickly identify potential IOCs and prioritize investigative actions. This approach leverages Google Cloud's built-in security tools for initial triage before diving into raw log analysis.

Topics

#threat hunting#GKE lateral movement#Security Command Center#IOC identification

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice