QuestionQ64

Incident response

You are an incident response team member in a global enterprise. You need to identify all potential Google Threat Intelligence IOCs in your organization's data by using Google Security Operations (SecOps). What should you do?

  • A Use the Cases page in Google SecOps.
  • B Create YARA-L rules to detect and alert when Google Threat Intelligence identifies potential threats.
  • C Use Gemini to perform a search for potential cybersecurity threats against your organization's data.
  • D Use the Alerts & IOCs page in Google SecOps.
Explanation

The Alerts & IOCs page includes the IOC Matches tab, which displays indicators observed in the enterprise that Google SecOps has matched against known suspicious indicators from configured threat-intelligence feeds. Google-provided feeds include Google Threat Intelligence, enabling the built-in correlation needed to identify potential IOCs across ingested organizational data.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!