QuestionQ119

Incident response

Your organization is performing a penetration test. The CISO has asked you to establish a real-time way to track cases originating from the penetration test and to clearly distinguish them from other security incidents. You need to recommend the most effective and efficient approach to accomplish this in Google Security Operations (SecOps). What should you do?

  • A Implement case tagging within Google SecOps and apply a unique tag (e.g., PenTest) to all cases related to the penetration test entities. Use this tag for filtering and monitoring.
  • B Create a dashboard that is connected to the Google SecOps data lake. Use pre-built templates to visualize case status based on the penetration testing IP address range.
  • C Create a custom Google SecOps SOAR playbook that automatically extracts case metadata, including key findings and risk scores, and sends an email summary to the CISO.
  • D Configure a custom alert rule that triggers a high-severity alert for all activity originating from the penetration testing team's source IP addresses and sends a notification for potential critical vulnerabilities. Verify that these alerts are immediately visible in the alert queue.
Explanation

Google SecOps case tags classify and organize cases, and case-queue filters support filtering by tags. Assigning a unique tag such as PenTest to cases associated with penetration-testing entities makes those cases immediately distinguishable and readily monitorable while preserving separation from ordinary security incidents.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!