QuestionQ108

Threat hunting

Your company is moving to a multi-cloud environment. You need to set up comprehensive threat monitoring with Google Security Operations (SecOps) and want to begin identifying threats as quickly as possible. What should you do?

  • A Use Gemini to generate YARA-L rules for multi-cloud use cases.
  • B Use curated detections from the Cloud Threats category to monitor your cloud environment.
  • C Use curated detections for Applied Threat Intelligence to monitor your company's cloud environment.
  • D Ask Cloud Customer Care to provide a set of rules recommended by Google to monitor your company's cloud environment.
Explanation

The Cloud Threats category provides Google-managed curated detections for Google Cloud, AWS, and Azure data. These prebuilt rule sets can be enabled to evaluate incoming cloud telemetry and produce detections and alerts, providing broad multi-cloud threat coverage without first developing custom rules.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!