QuestionQ1
ObservabilityYou work for a large international company with several Compute Engine instances running in production. You must configure monitoring and alerting for Compute Engine instances that are tagged compliance=pci and have an external IP address assigned. What should you do?
QuestionQ2
Incident responseThe organization requires that the SOC director be notified by email about escalated incidents and their results before a case is closed. You need to create a process that automatically sends this email when an escalated case is closed. You must ensure that the email is sent reliably for the appropriate cases. Which process should you use?
Community Discussion
QuestionQ3
Data managementYou work for a telecommunications company that needs to monitor logs from its multi-region 5G network in Google Security Operations (SecOps). The logs are currently available only on-premises and reside on standalone network-attached storage (NAS) in four different regions. You need to ingest these logs into Google SecOps and tag each NAS as a distinct log source to prevent IP address aliasing. What should you do?
Community Discussion
QuestionQ4
Threat huntingYou received an IOC from your threat-intelligence feed that is identified as a suspicious domain used for command and control (C2). You want to use Google Security Operations (SecOps) to investigate whether this domain has appeared in your environment. You want to search for this IOC using the most efficient approach. What should you do?
Community Discussion
QuestionQ5
Data managementYou manage the integration of Security Command Center (SCC) with downstream tooling. You need to retrieve security findings from SCC and import those findings as part of Google Security Operations (SecOps) SOAR actions. You must configure the connection between SCC and Google SecOps. What should you do?
Community Discussion