QuestionQ95
Threat huntingYou are using Google Security Operations (SecOps) to investigate suspicious activity associated with a specific user. You want to identify every asset the user interacted with during the past seven days to assess the potential impact. You need to understand the user's relationships to endpoints, service accounts, and cloud resources. How should you identify user-to-asset relationships in Google SecOps?
- A Use the Raw Log Scan view to group events by asset ID.
- B Query for hostnames in UDM Search and filter the results by user.
- C Generate an ingestion report to identify sources where the user appeared in the last seven days.
- D Run a retrohunt to find rule matches triggered by the user.
Community Discussion