QuestionQ21

Securing communications and establishing boundary protection

The company recently enabled Security Command Center at the organization level. You need to implement runtime threat detection for applications running in containers in projects within the production folder. Specifically, you must be notified when additional libraries are loaded or malicious scripts are executed in these running containers. Configure Security Command Center to satisfy this requirement while ensuring that findings are visible in Security Command Center. What should you do?

  • A Create log-based metrics and alerts in Cloud Logging and Cloud Monitoring for suspicious container activity within the production folder.
  • B Configure Security Health Analytics within Security Command Center to monitor container runtime vulnerabilities in the production folder.
  • C Ensure that the containers in the production folder are running on hosts that are using Container-Optimized OS.
  • D Enable Container Threat Detection in Security Command Center Premium tier for the projects within the production folder.
Explanation

Container Threat Detection monitors container runtime activity and produces Security Command Center findings for events such as added-library loading and malicious script execution. It is a Security Command Center Premium-tier capability, so enabling it for the projects in the production folder provides the required detection and makes the resulting findings available in Security Command Center.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!