QuestionQ23
Incident responseYour organization recently acquired Company A, which operates its own SOC and security tooling. You have already configured ingestion for Company A's security telemetry and migrated its detection rules into Google Security Operations (SecOps).
You now need to let Company A's analysts work their cases in Google SecOps. Ensure that Company A's analysts:
- cannot access case data originating outside Company A
- can repurpose playbooks previously developed by your organization's employees
You need to minimize the effort required to implement the solution. What should you do first?
- A Acquire a second Google SecOps SOAR tenant for Company A.
- B Provision a new service account for Company A.
- C Define a new SOC role for Company A.
- D Create a Google SecOps SOAR environment for Company A.
Community Discussion