QuestionQ15

Incident response

You are a security analyst at an organization that uses Google Security Operations (SecOps). You observe suspicious login attempts on several user accounts. You need to determine as quickly as possible whether these attempts are part of a coordinated attack. What action should you take first?

  • A Enable default curated detections to automatically block suspicious IP addresses.
  • B Use UDM Search to query historical logs for recent IOCs associated with the suspicious login attempts.
  • C Remove user accounts that have repeated invalid login attempts.
  • D Look for correlations across impacted users in the Risk Analytics dashboard.
Explanation

The Risk Analytics dashboard provides a risk-based view of user entities and unusual behavior across the environment. Its 24-hour risk-calculation window is specifically useful for making brute-force attacks more apparent, enabling rapid comparison of the impacted users to identify a coordinated pattern.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!