PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #79
You are using Google Security Operations (SecOps) to hunt for signs of lateral movement through Remote Desktop Protocol (RDP) in your organization. You suspect that a compromised account was used to…
The correct answer is B. Filter for events using protocol-level attributes that indicate RDP connections. C. Group events by user identity and time to identify repeated access patterns. Filtering for events using protocol-level attributes that indicate RDP connections ensures that the search specifically targets RDP sessions. Grouping events by user identity and time allows you to identify repeated access patterns, which is a strong indicator of lateral…
Question
You are using Google Security Operations (SecOps) to hunt for signs of lateral movement through Remote Desktop Protocol (RDP) in your organization. You suspect that a compromised account was used to access multiple internal systems within a short time window. You want to construct a UDM-based search to identify this activity. How should you build this query? (Choose two.)
Options
- AFilter for RDP connections with non-standard ports.
- BFilter for events using protocol-level attributes that indicate RDP connections.
- CGroup events by user identity and time to identify repeated access patterns.
- DCorrelate events based on the asset role or classification such as database or user workstation.
- EUse a saved search to identify all events with the LATERAL_MOVEMENT tag over the past 30
How the community answered
(28 responses)- A4% (1)
- B82% (23)
- D11% (3)
- E4% (1)
Explanation
Filtering for events using protocol-level attributes that indicate RDP connections ensures that the search specifically targets RDP sessions. Grouping events by user identity and time allows you to identify repeated access patterns, which is a strong indicator of lateral movement when a single account accesses multiple systems in a short timeframe.
Topics
Community Discussion
No community discussion yet for this question.