PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #79
You are using Google Security Operations (SecOps) to hunt for signs of lateral movement through Remote Desktop Protocol (RDP) in your organization. You suspect that a compromised account was used to a
The correct answer is B. Filter for events using protocol-level attributes that indicate RDP connections. C. Group events by user identity and time to identify repeated access patterns.. Filtering for events using protocol-level attributes that indicate RDP connections ensures that the search specifically targets RDP sessions. Grouping events by user identity and time allows you to identify repeated access patterns, which is a strong indicator of lateral movement
Question
You are using Google Security Operations (SecOps) to hunt for signs of lateral movement through Remote Desktop Protocol (RDP) in your organization. You suspect that a compromised account was used to access multiple internal systems within a short time window. You want to construct a UDM-based search to identify this activity. How should you build this query? (Choose two.)
Options
- AFilter for RDP connections with non-standard ports.
- BFilter for events using protocol-level attributes that indicate RDP connections.
- CGroup events by user identity and time to identify repeated access patterns.
- DCorrelate events based on the asset role or classification such as database or user workstation.
- EUse a saved search to identify all events with the LATERAL_MOVEMENT tag over the past 30
How the community answered
(28 responses)- A4% (1)
- B82% (23)
- D11% (3)
- E4% (1)
Explanation
Filtering for events using protocol-level attributes that indicate RDP connections ensures that the search specifically targets RDP sessions. Grouping events by user identity and time allows you to identify repeated access patterns, which is a strong indicator of lateral movement when a single account accesses multiple systems in a short timeframe.
Topics
Community Discussion
No community discussion yet for this question.