New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Google Cloud Certified - Professional Security Operations Engineer (PSOE) Exam Security-Operations-Engineer Question # 17 Topic 2 Discussion

Google Cloud Certified - Professional Security Operations Engineer (PSOE) Exam Security-Operations-Engineer Question # 17 Topic 2 Discussion

Security-Operations-Engineer Exam Topic 2 Question 17 Discussion:
Question #: 17
Topic #: 2

You are a platform engineer at an organization that is migrating from a third-party SIEM product to Google Security Operations (SecOps). You previously manually exported context data from Active Directory (AD) and imported the data into your previous SIEM as a watchlist when there were changes in AD's user/asset context data. You want to improve this process using Google SecOps. What should you do?


A.

Ingest AD organizational context data as user/asset context to enrich user/asset information in your security events.


B.

Configure a Google SecOps SOAR integration for AD to enrich user/asset information in your security alerts.


C.

Create a data table that contains AD context data. Use the data table in your YARA-L rule to find user/asset data that can be correlated within each security event.


D.

Create a data table that contains the AD context data. Use the data table in your YARA-L rule to find user/asset information for each security event.


Get Premium Security-Operations-Engineer Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.