QuestionQ30

Platform operations

Your Google Security Operations (SecOps) case queue includes a case containing IP address entities. You need to establish whether the entities are internal or external assets and ensure that internal IP address entities are marked appropriately when ingested into Google SecOps SOAR. What should you do?

  • A Indicate your organization's known internal CIDR ranges in the Environment Networks list in the settings.
  • B Modify the connector logic to perform a secondary lookup against your CMDB and flag incoming entities as internal or external.
  • C Configure a feed to ingest enrichment data about the networks, and include these fields into your detection outcome.
  • D Create a custom action to ping the IP address entity from your Remote Agent. If successful, the custom action designates the IP address entity as internal.
Explanation

The Environment Networks configuration defines the organization’s internal CIDR ranges. Google SecOps SOAR uses those ranges during entity ingestion to classify matching IP address entities as internal.

Community Discussion

No comments yet. Be the first to start the discussion!