QuestionQ4

Threat hunting

You received an IOC from your threat-intelligence feed that is identified as a suspicious domain used for command and control (C2). You want to use Google Security Operations (SecOps) to investigate whether this domain has appeared in your environment. You want to search for this IOC using the most efficient approach. What should you do?

  • A Run a raw log search to search for the domain string.
  • B Configure a UDM search that queries the DNS section of the network noun.
  • C Enable Group by Field in scan view to cluster events by hostname.
  • D Enter the IOC into the IOC Search feature, and wait for detections with this domain to appear in the Case view.
Explanation

A UDM search limited to the DNS portion of the network event data directly examines normalized DNS telemetry for the domain, avoiding the unnecessary breadth of a raw-log string search. Google SecOps supports searches over normalized UDM events and provides domain-focused investigation capabilities for determining whether a domain is present in enterprise data.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!