QuestionQ124

Data management

You are responsible for selecting and prioritizing potential data sources to integrate with Google Security Operations (SecOps). Your company has recently begun using several Google Cloud services to strengthen security in its Google Cloud organization. You need to identify which logs should be ingested into Google SecOps to reduce the effort needed to write detections. What should you do?

  • A Ingest Google Cloud Armor logs by using Cloud Logging.
  • B Deploy a Bindplane agent to ingest event logs from Compute Engine VMs that provide endpoint visibility.
  • C Integrate Security Command Center (SCC) into Google SecOps to ingest logs originating from the Google Cloud services.
  • D Use Google Threat Intelligence to gain insight about threat group behavior and support threat hunting activities.
Explanation

Security Command Center aggregates security findings from Google Cloud services and can export those findings to Google SecOps. Google SecOps includes curated Cloud Threats rule sets that detect Security Command Center finding classes and findings from services such as Event Threat Detection and Cloud Armor, reducing the amount of custom detection logic required.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!