QuestionQ109

Data management

You manage threat intelligence and IOC lists for your organization. You have compiled IOCs from recent incidents and want to share them quickly and efficiently with other teams for collaboration and integration into their operational processes. What should you do?

  • A Create a list in Google Security Operations (SecOps), and grant the required access to the other teams.
  • B Export the IOCs from Google Threat Intelligence in CSV or JSON format, and email the file to the other teams.
  • C Add the IOCs to a collection in Google Threat Intelligence, and share the collection with the other teams.
  • D Create a new threat graph in Google Threat Intelligence, and share the graph with the other teams.
Explanation

Google Threat Intelligence IoC Collections are live reports that group file hashes, URLs, domains, and IP addresses, and they can be shared with other users. This enables teams to collaborate on the same IOC set while retaining continuously updated threat-intelligence analysis and context, supporting operational use beyond a static emailed export.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!