QuestionQ23

Incident response

Your organization recently acquired Company A, which operates its own SOC and security tooling. You have already configured ingestion for Company A's security telemetry and migrated its detection rules into Google Security Operations (SecOps).

You now need to let Company A's analysts work their cases in Google SecOps. Ensure that Company A's analysts:

  • cannot access case data originating outside Company A
  • can repurpose playbooks previously developed by your organization's employees

You need to minimize the effort required to implement the solution. What should you do first?

  • A Acquire a second Google SecOps SOAR tenant for Company A.
  • B Provision a new service account for Company A.
  • C Define a new SOC role for Company A.
  • D Create a Google SecOps SOAR environment for Company A.
Explanation

Google SecOps SOAR environments segment customers, networks, or business units within one platform, isolating data, workflows, and visibility. Creating a Company A environment establishes the boundary needed to restrict Company A analysts to its own cases; analysts and appropriate playbook permissions can then be scoped to that environment, allowing reuse of existing playbooks without operating a separate tenant.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!