PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #88
You are a SOC analyst at an organization that uses Google Security Operations (SecOps). You are investigating suspicious activity in your organization's environment. Alerts in Google SecOps indicate r
The correct answer is A. Perform a YARA-L 2.0 search to correlate activity across impacted systems and users.. The most effective approach is to perform a YARA-L 2.0 search that correlates activity across impacted systems and user identities. YARA-L rules can link PowerShell execution events, outbound connections, and user activity, enabling you to identify the malicious user and the scop
Question
You are a SOC analyst at an organization that uses Google Security Operations (SecOps). You are investigating suspicious activity in your organization's environment. Alerts in Google SecOps indicate repeated PowerShell activity on a set of endpoints. Outbound connections are made to a domain that does not appear in your threat intelligence feeds. The activity occurs across multiple systems and user accounts. You need to search across impacted systems and user identities to identify the malicious user and understand the scope of the compromise. What should you do?
Options
- APerform a YARA-L 2.0 search to correlate activity across impacted systems and users.
- BPerform a raw log search for the suspicious domain string, and manually pivot to related user
- CUse the User Sign-In Overview dashboard to monitor authentication trends and anomalies across
- DUse the Behavioral Analytics dashboard in Risk Analytics to identify abnormal IP-based activity
How the community answered
(46 responses)- A72% (33)
- B4% (2)
- C7% (3)
- D17% (8)
Explanation
The most effective approach is to perform a YARA-L 2.0 search that correlates activity across impacted systems and user identities. YARA-L rules can link PowerShell execution events, outbound connections, and user activity, enabling you to identify the malicious user and the scope of the compromise efficiently, rather than relying on manual log searches or only analyzing authentication trends.
Topics
Community Discussion
No community discussion yet for this question.