QuestionQ26

Incident response

Your organization uses Google Security Operations (SecOps) for security analysis and investigation. It has decided that every security case related to Data Loss Prevention (DLP) events must be categorized with a defined root cause for one of five DLP event types when the case is closed in Google SecOps. How should you accomplish this?

  • A Customize the Close Case dialog and add the five DLP event types as root cause options.
  • B Customize the Case Name format to include the DLP event type.
  • C Create a Google SecOps SOAR playbook that automatically assigns case tags where each tag contains the unique definition of one of the five DLP event types.
  • D Create case tags in Google SecOps SOAR where each tag contains a unique definition of each of the five DLP event types, and have analysts assign them to cases manually.
Explanation

Google SecOps SOAR lets administrators customize the Close Case dialog and add root causes to the Root Cause menu. Defining the five DLP event types as root-cause options ensures analysts select the required standardized root cause during case closure.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!