QuestionQ101

Detection engineering

You are a security operations engineer at an enterprise that uses Google Security Operations (SecOps). Your organization recently experienced a cybersecurity breach. You need to increase threat analytics as quickly as possible. What should you do?

  • A Enable curated detections to identify threats.
  • B Design YARA-L detection rules based on Google SecOps Marketplace use cases.
  • C Develop YARA-L detection rules that focus on threat intelligence.
  • D Ingest data from a threat intelligence platform (TIP) into Google SecOps.
Explanation

Google Security Operations curated detections are Google-managed, predefined threat analytics delivered as YARA-L rule sets. Enabling the applicable rule sets applies immediately actionable detection intelligence to ingested data without the time required to author custom rules or integrate a separate threat-intelligence platform.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!