QuestionQ16

Detection engineering

Your organization uses the curated detection rule set in Google Security Operations (SecOps) for high-priority network indicators. You are seeing a very large number of false positives from your on-premises proxy servers. You need to decrease the number of alerts. What should you do?

  • A Configure a rule exclusion for the network.asset.ip field.
  • B Configure a rule exclusion for the principal.ip field.
  • C Configure a rule exclusion for the target.domain field.
  • D Configure a rule exclusion for the target.ip field.
Explanation

For network activity recorded by an on-premises proxy, the proxy is represented as the event’s principal. A curated-detection rule exclusion on principal.ip can filter events from the known proxy IP addresses and reduce false-positive alerts. Google Security Operations documentation lists principal.ip as a supported example field for curated-detection rule exclusions.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!