QuestionQ22

Threat hunting

You are performing proactive threat hunting in your company’s Google Cloud environment. You suspect an attacker has compromised a developer’s credentials and is trying to move laterally from a development Google Kubernetes Engine (GKE) cluster to critical production systems. You need to identify IOCs and prioritize investigative actions with Google Cloud security tools before analyzing raw logs in detail. What should you do next?

Explanation

Security Command Center centralizes findings that can be filtered to the affected cluster and reviewed for indicators of compromise. Attack exposure scores and associated attack paths show how detected issues could expose high-value resources, enabling the highest-risk potential paths toward production systems to be prioritized for investigation and remediation.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!