QuestionQ35

Observability

Your organization has recently deployed Google Security Operations (SecOps). You must create a solution that enables the security team to monitor data ingestion into Google SecOps in real time. You must also configure a solution that automatically sends a notification when one of the data sources stops ingesting data. You need to minimize the cost of these configurations. What should you do?

  • A Create Looker dashboards to visualize the data ingestion, and configure an alerting policy in Looker to send a notification in case of failure.
  • B Create Looker dashboards to visualize the data ingestion, and configure an alerting policy in Cloud Monitoring to send a notification in case of failure.
  • C Use Google SecOps SIEM dashboards to visualize the data ingestion and configure an alerting policy in Cloud Logging to send a notification in case of failure.
  • D Use Google SecOps SIEM dashboards to visualize the data ingestion, and configure an alerting policy in Cloud Monitoring to send a notification in case of failure.
Explanation

Google SecOps SIEM provides native ingestion-health visibility through its Health Hub and Data Ingestion dashboard, avoiding the additional cost and operational overhead of Looker. Cloud Monitoring supports alerting policies for Google SecOps ingestion metrics, including metric-absence conditions that notify when logs stop flowing from a source. Check data ingestion health Analyze ingestion with Cloud Monitoring

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!