QuestionQ20

Detection engineering

You are creating a security strategy for your organization. You plan to use Google Security Operations (SecOps) and Google Threat Intelligence (GTI). You need to improve detection and response across multi-cloud and on-premises systems. How should you integrate these products?

Choose two
  • A Ingest GTI IOCs into Google SecOps as security events.
  • B Ingest on-premises and cloud security logs into Google SecOps SIEM as events.
  • C Ingest on-premises and cloud security logs into Google SecOps SIEM as entities.
  • D Use Google SecOps SOAR integrations with GTI for event enrichment.
  • E Use Google SecOps SOAR integrations with GTI for entity enrichment.
Explanation

Google SecOps SIEM ingests security logs from cloud and on-premises sources and normalizes them into UDM events for centralized detection and investigation. The Google Threat Intelligence integration is used by Google SecOps SOAR to enrich entities—such as IP addresses, domains, URLs, and hashes—with GTI intelligence. GTI IoCs are handled as threat-intelligence entity/context data, not as security events.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!