QuestionQ103
Detection engineeringYou notice several separate, low-severity suspicious activities linked to one internal server. You conclude that no individual event is a high-confidence IOC. You need to implement a solution that provides ongoing, heightened scrutiny of this server. What should you do?
- A Schedule a daily Google Security Operations (SecOps) report detailing all activity on this server.
- B Develop a YARA-L detection rule specific to this server.
- C Add the server to a Google Security Operations (SecOps) watchlist, and monitor the watchlist closely for the next few weeks.
- D Create a case, isolate the server from the network, and escalate the case for forensic investigation.
Community Discussion