QuestionQ29

Detection engineering

Your organization has recently acquired a Google Security Operations (SecOps) Enterprise Plus license. It is already ingesting Cloud Audit Logs, firewall logs, proxy logs, and endpoint logs, but no threat intelligence feeds are being ingested into the Google SecOps environment. You need to design and deploy a solution that rapidly alerts your team when an IOC from an active breach is observed in your environment. What should you do?

  • A Write, enable, and configure alerting on a custom multi-event rule.
  • B Write, enable, and configure alerting on a custom single-event rule.
  • C Enable and configure alerting for relevant curated detection rule sets.
  • D Create and schedule a dashboard to send periodic summaries of the active breach IOCs and their associated events.
Explanation

Google SecOps Enterprise Plus supports Applied Threat Intelligence curated detections, which evaluate ingested event data against Mandiant threat intelligence. The Active Breach Priority network and host indicator rule sets generate alerts when they match an IOC labeled Active breach, so enabling and configuring the relevant curated detection rule sets provides the required rapid alerting without separately ingesting a threat-intelligence feed.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!