QuestionQ22

Threat hunting

You are performing proactive threat hunting in your company’s Google Cloud environment. You suspect an attacker has compromised a developer’s credentials and is trying to move laterally from a development Google Kubernetes Engine (GKE) cluster to critical production systems. You need to identify IOCs and prioritize investigative actions with Google Cloud security tools before analyzing raw logs in detail. What should you do next?

  • A In the Security Command Center (SCC) console, apply filters for the cluster and analyze the resulting aggregated findings' timeline and details for IOCs. Examine the attack path simulations associated with attack exposure scores to prioritize subsequent actions.
  • B Review threat intelligence feeds within Google Security Operations (SecOps), and enrich any anomalies with context on known IOCs, attacker tactics, techniques, and procedures (TTPs), and campaigns.
  • C Investigate Virtual Machine (VM) Threat Detection findings in Security Command Center (SCC). Filter for VM Threat Detection findings to target the Compute Engine instances that serve as the nodes for the cluster, and look for malware or rootkits on the nodes.
  • D Create a Google SecOps SOAR playbook that automatically isolates any GKE resources exhibiting unusual network connections to production environments and triggers an alert to the incident response team.
Explanation

Security Command Center centralizes findings that can be filtered to the affected cluster and reviewed for indicators of compromise. Attack exposure scores and associated attack paths show how detected issues could expose high-value resources, enabling the highest-risk potential paths toward production systems to be prioritized for investigation and remediation.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!