QuestionQ78
Threat huntingYou are using Google Security Operations (SecOps) to hunt for indications of lateral movement through Remote Desktop Protocol (RDP) in your organization. You suspect a compromised account accessed multiple internal systems within a short time window. You want to build a UDM-based search to detect this activity. How should you construct this query?
Choose two
- A Filter for RDP connections with non-standard ports.
- B Filter for events using protocol-level attributes that indicate RDP connections.
- C Group events by user identity and time to identify repeated access patterns.
- D Correlate events based on the asset role or classification such as database or user workstation.
- E Use a saved search to identify all events with the LATERAL_MOVEMENT tag over the past 30 days.
Community Discussion