QuestionQ85

Data management

You receive security alerts from multiple connectors in your Google Security Operations (SecOps) instance. You need to determine which IP address entities are internal to your network and assign each entity its specific network name. This network name will serve as the trigger for the playbook. What should you do?

  • A Configure each network in the Google SecOps SOAR settings.
  • B Enrich the IP address entities as the initial step of the playbook.
  • C Modify the entity attribute in the alert overview.
  • D Create an outcome variable in the rule to assign the network name.
Explanation

Google SecOps SOAR networks are configured as CIDR subnets with network names. The platform uses those definitions to recognize IP entities as internal, displays the associated network name, and supports Network Name as a playbook trigger for entities within a defined subnet.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!