QuestionQ4
Threat huntingYou received an IOC from your threat-intelligence feed that is identified as a suspicious domain used for command and control (C2). You want to use Google Security Operations (SecOps) to investigate whether this domain has appeared in your environment. You want to search for this IOC using the most efficient approach. What should you do?
- A Run a raw log search to search for the domain string.
- B Configure a UDM search that queries the DNS section of the network noun.
- C Enable Group by Field in scan view to cluster events by hostname.
- D Enter the IOC into the IOC Search feature, and wait for detections with this domain to appear in the Case view.
Community Discussion