QuestionQ118

Observability

Your organization has recently seen an increase in security incidents. You need to build a near-real-time visualization of activity from the last hour for users and assets that triggered alerts, grouped by the highest risk scores. What should you do?

  • A Navigate to the Alerts & IOCs panel in Google Security Operations (SecOps). Set the showing time to the last hour, and sort by risk score.
  • B Create a dashboard to display all alerts from the last hour, broken down by entity type and sorted by risk score.
  • C Navigate to the Risk Analytics dashboard in Google Security Operations (SecOps). Sort the entities by normalized change.
  • D Create a report using the events table in the BigQuery export that shows all alerts over the last hour broken out by entity type and ordered by risk score.
Explanation

A Google Security Operations dashboard can visualize alerts for a selected one-hour time range, break the results down by entity type, and prioritize them by risk score. This provides an operational view of the users and assets associated with the highest-risk recent alerts. Risk Analytics is limited to 24-hour or 7-day risk-calculation windows, so it does not meet a last-hour requirement.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!