CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 10: Google Cloud Professional Security Operations Engineer

You are a platform engineer at an organization that is migrating from a third-party SIEM product to Google Security Operations (SecOps). You previously manually exported context data from Active Directory (AD) and imported the data into your previous SIEM as a watchlist when there were changes in AD's user/asset conte…

Nội dung câu hỏi

You are a platform engineer at an organization that is migrating from a third-party SIEM product to Google Security Operations (SecOps). You previously manually exported context data from Active Directory (AD) and imported the data into your previous SIEM as a watchlist when there were changes in AD's user/asset context data. You want to improve this process using Google SecOps. What should you do?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Configure a Google SecOps SOAR integration for AD to enrich user/asset information in your security alerts.
  2. B. Create a reference list that contains the AD context data. Use the reference list in your YARA-L rule to find user/asset information for each security event.
  3. C. Create a data table that contains AD context data. Use the data table in your YARA-L rule to find user/asset data that can be correlated within each security event.
  4. D. Ingest AD organizational context data as user/asset context to enrich user/asset information in your security events. — đáp án hiện tại

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề