QuestionQ12
Platform operationsYour company's SOC analysts frequently submit manual change requests to a system administrator to modify firewall rules on a specific router. The firewall integration is installed and configured with credentials. You want to use the integration to trigger firewall-rule changes directly from Google Security Operations (SecOps) SOAR. Your system administrator requires the ability to manually approve requested changes before deployment. How should you implement the on-demand workflow for analysts to trigger?
- A Create an email template for the analyst to get approval for the change from the system administrator. Have the analyst fill out the needed fields, and send the email for approval. Once approved, use a manual action to make the change to the firewall rule from any open case.
- B Create an account for the system administrator in your Google SecOps instance to allow the system administrator to make the changes from Google SecOps directly. Add an escalation step to enable the analyst to assign the case to the system administrator.
- C Create a playbook where the firewall rule change is a manual step, allowing the analyst to edit the firewall rule as a pending action. Have the analyst email the system administrator with the change. Once approved, the analyst lets the playbook continue.
- D Create a request in the Google SecOps SOAR settings that includes a field for the firewall rule. Create a playbook that is triggered by this request. Configure the playbook step that makes the firewall rule change to send an approval request from the system administrator. The approval request must include the parameter being changed.
Community Discussion