nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #92

You are responsible for selecting and prioritizing potential sources of data to integrate with Google Security Operations (SecOps). Your company has recently started using several Google Cloud service

The correct answer is C. Integrate Security Command Center (SCC) into Google SecOps to ingest logs originating from. Integrating Security Command Center (SCC) into Google Security Operations (SecOps) provides a centralized source of security findings from Google Cloud services. SCC normalizes and correlates data from multiple native Google Cloud sources (e.g., IAM, VPC, GKE, VM Threat Detection

Log Ingestion and Integration

Question

You are responsible for selecting and prioritizing potential sources of data to integrate with Google Security Operations (SecOps). Your company has recently started using several Google Cloud services to increase security in its Google Cloud organization. You need to determine which logs should be ingested into Google SecOps to reduce the effort required to write detections. What should you do?

Options

  • AIngest Google Cloud Armor logs by using Cloud Logging.
  • BDeploy a Bindplane agent to ingest event logs from Compute Engine VMs that provide endpoint
  • CIntegrate Security Command Center (SCC) into Google SecOps to ingest logs originating from
  • DUse Google Threat Intelligence to gain insight about threat group behavior and support threat

How the community answered

(50 responses)
  • A
    12% (6)
  • B
    2% (1)
  • C
    82% (41)
  • D
    4% (2)

Explanation

Integrating Security Command Center (SCC) into Google Security Operations (SecOps) provides a centralized source of security findings from Google Cloud services. SCC normalizes and correlates data from multiple native Google Cloud sources (e.g., IAM, VPC, GKE, VM Threat Detection, Cloud Armor), which reduces the effort required to write detections since findings are already standardized and security-focused. This is more effective than ingesting individual service logs or only using threat intelligence.

Topics

#log ingestion#SCC integration#curated detections#Google Cloud services

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice