QuestionQ55

Detection engineering

You are a security operations engineer at an enterprise that uses Google Security Operations (SecOps). You need to improve detection coverage and reduce the false-positive detection ratio as quickly as possible. What should you do?

  • A Enable curated detections to identify threats.
  • B Develop YARA-L detection rules that focus on threat intelligence.
  • C Ingest data from your threat intelligence platform (TIP) into Google SecOps.
  • D Design YARA-L detection rules based on Google SecOps Marketplace use cases.
Explanation

Google Security Operations curated detections provide prebuilt, managed threat-detection logic, enabling organizations to add broad, tuned detection coverage quickly without the development and validation time required for custom YARA-L rules.

Community Discussion

No comments yet. Be the first to start the discussion!