QuestionQ103

Detection engineering

You notice several separate, low-severity suspicious activities linked to one internal server. You conclude that no individual event is a high-confidence IOC. You need to implement a solution that provides ongoing, heightened scrutiny of this server. What should you do?

  • A Schedule a daily Google Security Operations (SecOps) report detailing all activity on this server.
  • B Develop a YARA-L detection rule specific to this server.
  • C Add the server to a Google Security Operations (SecOps) watchlist, and monitor the watchlist closely for the next few weeks.
  • D Create a case, isolate the server from the network, and escalate the case for forensic investigation.
Explanation

Adding the server to a Google Security Operations watchlist enables targeted monitoring and correlation of subsequent activity involving that entity. This is appropriate when weak, individually inconclusive signals collectively justify heightened observation but do not yet warrant containment or forensic escalation.

Community Discussion

No comments yet. Be the first to start the discussion!