QuestionQ62

Data management

You are a platform engineer at an organization migrating from a third-party SIEM product to Google Security Operations (SecOps). Previously, when AD user/asset context data changed, you manually exported the context data from Active Directory (AD) and imported it into the prior SIEM as a watchlist. You want to improve this process by using Google SecOps. What should you do?

  • A Configure a Google SecOps SOAR integration for AD to enrich user/asset information in your security alerts.
  • B Create a reference list that contains the AD context data. Use the reference list in your YARA-L rule to find user/asset information for each security event.
  • C Create a data table that contains AD context data. Use the data table in your YARA-L rule to find user/asset data that can be correlated within each security event.
  • D Ingest AD organizational context data as user/asset context to enrich user/asset information in your security events.
Explanation

Google SecOps can ingest Microsoft Active Directory organizational context as entity context data. This supplies user and asset attributes that enrich security events and replaces manual exports and watchlist imports when directory context changes.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!