CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 33: Google Cloud Professional Security Operations Engineer

Your organization recently implemented Google Security Operations (SecOps) with Applied Threat Intelligence enabled. You were notified by the networking team about potentially anomalous communications to external domains in the last 30 days. You plan to start your threat hunting by looking at communications to externa…

Nội dung câu hỏi

Your organization recently implemented Google Security Operations (SecOps) with Applied Threat Intelligence enabled. You were notified by the networking team about potentially anomalous communications to external domains in the last 30 days. You plan to start your threat hunting by looking at communications to external domains. You are ingesting the following logs into Google SecOps:Firewall logs -Proxy logs -DNS logs -DHCP logs -What should you do? (Choose two.)

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Perform a UDM search across the logs for domains with geolocations that were first seen in the last 30 days.
  2. B. Perform a UDM search across the logs for domains with low prevalence that were first seen in the last 30 days. — đáp án hiện tại
  3. C. Perform a raw log search across the logs for domains with low prevalence that were first seen in the last 30 days.
  4. D. Identify the domains with the higher normalized risk in Risk Analytics. Drill down into those entities to determine their prevalence and if they were first seen in the last 30 days.
  5. E. Navigate to the IOC Matches page and filter based on domain type over the last 30 days. Look for the first seen and last seen timestamps for the reported domains. Investigate these domains using the IOC drilldown link. — đáp án hiện tại

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề