Câu 37: Google Cloud Professional Security Operations Engineer
You received an alert from Container Threat Detection that an added binary has been executed in a business critical workload. You need to investigate and respond to this incident. What should you do? (Choose two.)
Nội dung câu hỏi
You received an alert from Container Threat Detection that an added binary has been executed in a business critical workload. You need to investigate and respond to this incident. What should you do? (Choose two.)
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Notify the workload owner. Follow the response playbook, and ask the threat hunting team to identify the root cause of the incident. — đáp án hiện tại
- B. Review the finding, investigate the pod and related resources, and research the related attack and response methods. — đáp án hiện tại
- C. Review the finding, quarantine the cluster containing the running pod, and delete the running pod to prevent further compromise.
- D. Silence the alert in the Security Command Center (SCC) console, as the alert is a low severity finding.
- E. Keep the cluster and pod running, and investigate the behavior to determine whether the activity is malicious.
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.
Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.