PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #86
You have identified a new threat actor group that has several IOCs in Google Threat Intelligence. You want to use some of these IOCs in several detection rules in Google Security Operations (SecOps) t
The correct answer is B. Add the IOCs to a new or existing reference list, and update the YARA-L logic of detection rules. The most effective approach is to add the IOCs to a reference list in Google SecOps and then update the YARA-L logic of your detection rules to reference that list. This centralizes the IOCs for reuse across multiple rules, simplifies maintenance, and ensures consistency in detec
Question
You have identified a new threat actor group that has several IOCs in Google Threat Intelligence. You want to use some of these IOCs in several detection rules in Google Security Operations (SecOps) to help identify suspicious activity. You want to use the most effective approach. What should you do?
Options
- AIdentify the detection rules that apply to the new IOCs, and update the YARA-L logic to reference
- BAdd the IOCs to a new or existing reference list, and update the YARA-L logic of detection rules
- CSave the IOCs in a new collection in Google Threat Intelligence. Share this list with other
- DConfigure a new data feed in Google SecOps that includes the IOCs. Update the YARA-L logic to
How the community answered
(38 responses)- A8% (3)
- B79% (30)
- C11% (4)
- D3% (1)
Explanation
The most effective approach is to add the IOCs to a reference list in Google SecOps and then update the YARA-L logic of your detection rules to reference that list. This centralizes the IOCs for reuse across multiple rules, simplifies maintenance, and ensures consistency in detection logic without duplicating IOC entries in multiple places.
Topics
Community Discussion
No community discussion yet for this question.