nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #91

You are planning log onboarding for a Google Security Operations (SecOps) SIEM deployment in a cloud-heavy enterprise environment. The detection engineering team is requesting log sources that support

The correct answer is B. EDR logs. EDR (Endpoint Detection and Response) logs should be prioritized because they provide direct visibility into user identity behavior, lateral movement, and privilege escalation attempts on endpoints. These logs capture process execution, authentication events, and anomalous activi

Log Ingestion and Prioritization

Question

You are planning log onboarding for a Google Security Operations (SecOps) SIEM deployment in a cloud-heavy enterprise environment. The detection engineering team is requesting log sources that support visibility into:

  • User identity behavior
  • Lateral movement
  • Privilege escalation attempts

You need to determine which telemetry sources are ingested first. Which log source should you prioritize?

Options

  • ACloud access security broker (CASB) logs
  • BEDR logs
  • CIAM logs
  • DNetwork firewall logs

How the community answered

(45 responses)
  • A
    4% (2)
  • B
    78% (35)
  • C
    4% (2)
  • D
    13% (6)

Explanation

EDR (Endpoint Detection and Response) logs should be prioritized because they provide direct visibility into user identity behavior, lateral movement, and privilege escalation attempts on endpoints. These logs capture process execution, authentication events, and anomalous activities, which are critical for early detection of threats before other systems, such as CASB or network firewalls, report related events.

Topics

#log prioritization#EDR logs#identity behavior#lateral movement visibility

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice