CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 25: Google Cloud Professional Security Operations Engineer

You are conducting a proactive threat hunt in Google Security Operations (SecOps). You observe multiple login events with the same principal.user.userid field that originate from different countries within a short time window. You need to validate whether the account has been compromised. What should you do?

Nội dung câu hỏi

You are conducting a proactive threat hunt in Google Security Operations (SecOps). You observe multiple login events with the same principal.user.userid field that originate from different countries within a short time window. You need to validate whether the account has been compromised. What should you do?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Use the entity graph to correlate the user's risk score with linked assets, and review any active alerts. — đáp án hiện tại
  2. B. Perform a YARA-L 2.0 search for login events and their associated principal.location.country field. Use an outcome field to aggregate the number of failed logins.
  3. C. Perform a UDM search for login events, and pivot to group results by user and country of origin.
  4. D. Run a YARA-L retrohunt rule that detects users who are logging in from multiple regions using multiple entity contexts.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề