QuestionQ69

Observability

You are a SOC manager, and your company has recently migrated to Google Security Operations (SecOps). As the team expands, you want to monitor all audit logs associated with data feeds in Google SecOps. What should you do?

  • A Enable Data Access and Admin Activity audit logs in Cloud Logging, and ingest those logs into Google SecOps SIEM.
  • B Ingest the Google SecOps audit logs into Google SecOps SIEM for monitoring.
  • C Monitor Google SecOps SOAR user activity logs for administrative activity.
  • D Configure the Cloud Logging filter to ingest audit logs related to data feeds into Google SecOps for monitoring.
Explanation

Google SecOps writes audit logs for product activity, including feed-management operations, as Cloud Audit Logs. To monitor those events centrally, ingest the Google SecOps audit logs into Google SecOps SIEM, where they can be searched, correlated, and monitored.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!