PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #83
Your team hunts for threats in a large multinational corporation. You have subscriptions to threat intelligence feeds from third-party sources. You want to implement a solution to continuously compare
The correct answer is C. Create a YARA-L rule in Google Security Operations (SecOps) to track matches between the. The best solution is to create a YARA-L rule in Google SecOps that correlates ingested EDR log entries (including DNS calls) with the entity graph populated by your threat intelligence feeds. This enables continuous monitoring and automated detection of endpoint activity that mat
Question
Your team hunts for threats in a large multinational corporation. You have subscriptions to threat intelligence feeds from third-party sources. You want to implement a solution to continuously compare DNS calls on endpoints to your threat intelligence feeds. What should you do?
Options
- AUse custom modules in Event Threat Detection in Security Command Center (SCC) to correlate
- BPush endpoint logs to BigQuery and use scripts to compare entries to Google Threat intelligence
- CCreate a YARA-L rule in Google Security Operations (SecOps) to track matches between the
- DCreate a YARA-L rule in Google Security Operations (SecOps) to track matches between the
How the community answered
(52 responses)- A8% (4)
- B2% (1)
- C79% (41)
- D12% (6)
Explanation
The best solution is to create a YARA-L rule in Google SecOps that correlates ingested EDR log entries (including DNS calls) with the entity graph populated by your threat intelligence feeds. This enables continuous monitoring and automated detection of endpoint activity that matches known malicious domains or indicators, supporting proactive threat hunting at scale.
Topics
Community Discussion
No community discussion yet for this question.